Charitable Donations and Sponsorship Risks

Charitable giving and sponsorship are normal activities for a bank. A bank may fund financial-literacy programmes, disaster relief, community projects, universities, arts and cultural organisations, environmental initiatives, health programmes or local sporting events. It may also sponsor conferences, professional associations, technology events, sports teams or cultural institutions to promote its brand. The existence of a social purpose, however, does not remove anti-bribery and corruption risk. A legitimate charity can be used as the route for an improper benefit, and an apparently commercial sponsorship can be structured so that a customer, public official, employee or intermediary receives an advantage that would have been unacceptable if paid directly.

The practical control problem is therefore not to ask whether the recipient calls itself a charity or whether the invoice says sponsorship. The bank must understand why value is being provided, who requested it, who ultimately benefits, what the bank receives in return, what business or official decisions are pending, how the recipient is connected to relevant people, how the money will be paid and what evidence will remain after the event. Those questions turn a vague ethical concern into something a front-line employee, compliance reviewer, business analyst, architect, tester and auditor can work with.

The Wolfsberg Group's 2023 Anti-Bribery and Corruption Guidance treats donations, charitable contributions and corporate sponsorships as forms of “anything of value” that belong inside a financial institution's ABC control environment. That framing is useful because bribery risk does not depend on whether the benefit is cash in an envelope. It depends on whether value is offered, promised, authorised or transferred with an improper purpose, directly or indirectly. Wolfsberg specifically highlights the risk of an illegitimate charity being used as a vehicle for a bribe, a legitimate charity being supported to influence one of its supporters or directors, and sponsorship being used to influence the award or retention of business or to create exclusive entertainment opportunities.

At the same time, the bank must avoid a second error: treating the non-profit sector as inherently suspicious. FATF Recommendation 8 and the associated 2023 best-practices paper emphasise a focused, proportionate and risk-based approach to terrorist-financing abuse of non-profit organisations. FATF explicitly rejects a one-size-fits-all view of the sector and notes that the majority of organisations may represent low risk. Anti-bribery controls for the bank's own giving and sponsorship activity must therefore be precise. They should identify the features that create an influence, diversion, sanctions or integrity concern without turning charitable status itself into a red flag.

A donation or sponsorship moves through classification, due diligence, influence checks, approval, payment and post-event verification before the file is closed.

The simplest mental model

A useful way to analyse a request is to separate six questions that are often mixed together.

Purpose asks why the bank is providing the value. A donation normally seeks a philanthropic or community outcome. A sponsorship normally has a commercial or brand objective and gives the sponsor identifiable rights or benefits. A grant may fund a defined programme subject to conditions. An event package may combine sponsorship, hospitality, advertising and tickets. Classification matters because a request that is described as a donation but includes naming rights, VIP access and customer entertainment is not operationally the same as an unrestricted philanthropic gift.

Recipient asks who legally receives and controls the value. The answer should be a verified organisation, not simply a familiar name on an email. The bank should understand legal status, registration where relevant, governance, responsible officers, normal activities and the account to which payment will be made. A famous cause can still be represented by an unauthorised intermediary, event organiser or local chapter with different legal identity.

Connections asks who requested the support and who is linked to the recipient. A donation requested by a public official, regulator, customer decision-maker, vendor, introducer or employee requires a different level of scrutiny from a centrally selected contribution with no live relationship. The relevant connection may sit with a trustee, director, founder, fundraiser, event chair, beneficiary or related organisation. The point is not to presume wrongdoing because a public official or customer has a connection. The point is to understand whether the support could create, reward or appear to create improper influence.

Timing asks what else is happening. A request can become materially more sensitive when the bank is bidding for a public mandate, seeking a licence, negotiating a regulatory matter, renewing a corporate relationship, selecting a vendor, pursuing a financing transaction or resolving a dispute. Timing rarely proves intent by itself, but it can transform an otherwise ordinary contribution into one that requires independent review and documented rationale.

Value and consideration asks what leaves the bank and what comes back. For sponsorships, this means identifying branding, advertising, tickets, hospitality, speaking opportunities, access to participants, exclusivity, data rights or other benefits. For donations it means confirming that there is no hidden personal benefit, side agreement or commercially valuable return disguised as philanthropy. The total value should include non-cash elements where policy requires it; splitting the cash fee from hospitality or tickets can understate the real benefit package.

Evidence and payment route asks whether the transaction can be reconstructed later. The recipient name, verified bank account, business rationale, due diligence, conflicts, approvals, contract or grant terms, payment record and post-event evidence should tell the same story. If the payment is routed to an individual's account, an unrelated company, a cash collector or a newly introduced intermediary, the bank needs a documented explanation and usually escalation before funds move.

These six questions can be remembered as a chain rather than a score. Weakness at one point changes how the rest of the evidence should be viewed. A small contribution to a long-established local charity may require limited diligence when centrally selected and unrelated to business. The same amount may justify enhanced review if requested by a public official while a licence application is pending and payment is requested to an event promoter rather than the charity itself.

Donation, sponsorship, grant and hospitality are not interchangeable

A strong control begins with classification. Banks often have separate budgets and systems for corporate social responsibility, foundations, marketing, events, client entertainment and business development. If each function uses different labels, the same activity can fall through the gaps. A sponsorship may be booked as marketing while its VIP tickets are managed as hospitality. A local contribution may be recorded as an expense reimbursement. An employee fundraiser may use match funding from the bank. A disaster-relief payment may be accelerated under an emergency procedure. All can be legitimate, but the classification should determine the right control path rather than allow the requester to choose the lightest path.

A charitable donation is generally value given without a commercial return of equivalent nature. The exact legal and tax definition varies by jurisdiction, so the bank should not build one global legal test into a workflow. Operationally, the important features are philanthropic purpose, recipient legitimacy, absence of hidden personal benefit and a clear explanation of why the bank selected or accepted the request.

A corporate sponsorship normally has an exchange element. The bank may receive brand visibility, media exposure, event access or other contractual rights. In the United Kingdom, tax and VAT rules draw distinctions that can be useful for accounting, but those rules are not a universal definition for ABC purposes. An ABC reviewer cares about the full package: who receives the money, who benefits from tickets or access, whether the price is commercially defensible, who requested the arrangement and whether pending business creates influence risk.

A grant may sit between pure philanthropy and a commercial relationship. It can be restricted to a project, released in tranches and subject to reporting. Programme restrictions can strengthen controls because they create evidence of intended use, but restrictive terms do not eliminate corruption or diversion risk. If the recipient is controlled by a connected person or the project itself provides a personal or political benefit, the bank still needs to understand that relationship.

Hospitality linked to sponsorship should not disappear inside the sponsorship fee. Premium seats, travel, accommodation, access to players or artists, closed dinners, backstage passes, speaking invitations and guest allocations can create separate gift and hospitality questions. A bank that approves a sponsorship fee but never records who used the associated benefits has only assessed half of the transaction.

Political contributions sit in a separate category in many banks because laws vary sharply by jurisdiction and restrictions can be much tighter. A payment should not be moved into the charitable or sponsorship process merely because the receiving entity has a social or community purpose. Where a political party, candidate, government office-holder or political organisation is involved, the bank should route the request to the applicable political-contribution rules and Legal or Compliance review.

The decision flow separates genuine philanthropy and commercial sponsorship from cases where connections, timing, personal benefit or unusual payment routes require enhanced review or refusal.

Why banks face distinctive exposure

Financial institutions combine several characteristics that make these activities sensitive. They seek licences and regulatory approvals, bid for public-sector and state-owned-enterprise business, compete for large corporate mandates, manage vendor relationships, operate through local branches, employ people with extensive external networks and possess substantial marketing and community budgets. A modest community contribution can therefore intersect with a valuable business decision even when the philanthropy team has no intention of influencing it.

The risk is especially easy to miss when information is fragmented. The community-investment team may know the recipient, Relationship Management may know that the recipient's chair is the chief executive of a potential customer, Government Affairs may know that a local official requested the contribution, and Procurement may know that the official's relative owns the event agency. If those facts live in separate systems, each team can approve its narrow part while nobody sees the combined picture.

The control must also work at speed. Disaster response and humanitarian emergencies create legitimate pressure to release support quickly. Sponsorship opportunities can have fixed event deadlines. Local business teams may argue that an approval delay will damage community relationships. Speed is not a reason to abandon control; it is a reason to design a pre-agreed accelerated route with defined due-diligence minimums, senior decision rights and post-payment verification.

The regulatory and standards context

There is no single global “charitable donation rule” for banks. The legal analysis depends on the jurisdictions involved, the bank entity, the recipient, the people connected to it and the conduct in question. Global standards are best used as a control baseline, with local law and policy layered on top.

Wolfsberg's ABC Guidance is particularly relevant to financial institutions. It recommends risk-based controls for charitable giving, including limitations where appropriate, identification of higher-risk circumstances such as requests from public officials, vendors, customers or potential customers, recipient due diligence, risk-based pre-approval and documentation. For sponsorships, it points to the risk created where the arrangement can influence a supporter or director of the sponsored entity or provides opportunities to invite third parties to exclusive entertainment events. These are not transaction-level legal conclusions; they are control-design principles.

In the United Kingdom, the Bribery Act 2010 and Ministry of Justice guidance provide the legal framework, while public-sector counter-bribery guidance emphasises risk assessment, due diligence, financial controls, record keeping and policies that cover donations and sponsorship. FCA-regulated firms also need systems and controls appropriate to their financial-crime risks. Whether a particular donation constitutes an offence depends on facts and law; a bank's workflow should therefore surface relevant facts rather than automate a criminal-law conclusion.

In the United States, the Foreign Corrupt Practices Act is particularly relevant where value may be provided to influence a foreign official, and the DOJ/SEC Resource Guide discusses compliance programme expectations and the importance of accurate books and records and internal controls for issuers. DOJ's FCPA Opinion Procedure releases include a specific index for charitable contributions. Those releases are fact-specific and are not a safe-harbour template for every bank; their educational value is that charitable purpose does not remove the need to understand recipient legitimacy, official connections and the purpose of the contribution.

The sanctions and terrorist-financing overlay is distinct. If a recipient, controller, intermediary or payment route creates sanctions exposure, the applicable sanctions regime may restrict or prohibit the transaction regardless of the ABC rationale. OFSI's January 2026 UK guidance for charities and NGOs illustrates the point for UK sanctions: organisations must consider designated persons, ownership and control, licensing and exceptions. Other jurisdictions have their own sanctions frameworks. The bank should not treat an ABC approval as a sanctions clearance or vice versa.

FATF Recommendation 8 adds another important discipline. It focuses on protecting the subset of non-profit organisations within FATF's functional definition from terrorist-financing abuse through focused, proportionate, risk-based measures. FATF explicitly warns against measures that unduly disrupt legitimate NPO activity. For bank design, that means recipient due diligence should be driven by risk attributes such as geography, activities, counterparties, governance, payment methods and delivery model rather than a blanket assumption that “charity equals high risk.”

Where risk appears across the lifecycle

The first risk point is origination. Who proposed the support? A centrally planned annual giving programme creates a different risk profile from an unsolicited request by a relationship manager after a customer asks the bank to support a foundation. Systems should capture the request source, not merely the recipient name. If an employee selects “business sponsored” but the actual request came from a government official, the control has lost a critical fact before review starts.

The second point is classification and aggregation. The workflow should identify whether the request is a donation, sponsorship, grant, membership, event package or another form of value. It should also look for related requests. Five local contributions below an approval threshold to the same organisation or connected organisations can create a risk that is invisible when each is reviewed separately.

The third point is recipient and connected-party due diligence. The bank should establish the legal recipient, its purpose, governance and relevant controllers or senior office-holders to a level proportionate to risk. Screening for sanctions, politically exposed persons where relevant to the bank's policy, negative news and conflicts should use reliable identifiers rather than name-only matching. A “hit” is not a conclusion. The reviewer must resolve identity and understand why the connection matters.

The fourth point is business-context review. The reviewer should know whether the bank has pending or recent business with people connected to the request. Useful context can include public tenders, mandates, licensing matters, regulatory examinations, major credit decisions, vendor selections and disputed transactions. This is where integration with CRM, procurement and government-relations data can materially improve the control.

The fifth point is approval and contracting. Approval should reflect risk, not just amount. A low-value request tied to a public official and pending business can justify more senior review than a larger centrally budgeted donation to an established organisation. Sponsorship agreements should state the benefits the bank receives, the payment destination, permitted use where appropriate, cancellation rights and any conditions needed by policy. Donations may need a grant letter or acknowledgement rather than a commercial contract, but the rationale and conditions should still be clear.

The sixth point is payment. Accounts payable or the payment platform should receive enough structured information to verify that the payee, account and amount match the approved request. A late request to change the beneficiary account should not be treated as an administrative amendment. It should trigger re-verification and, where material, re-approval. Payments to personal accounts, unrelated entities or cash collectors should be prohibited or escalated under clearly defined exceptional procedures.

The seventh point is post-payment verification. For a donation, verification can include acknowledgement, programme reporting or evidence that conditions were met, depending on risk. For a sponsorship, it can include confirmation that the event occurred, the contracted branding or services were delivered and hospitality benefits were allocated and recorded correctly. Post-event evidence is not designed to prove the absence of bribery; it demonstrates that the transaction occurred as approved and helps identify material deviations.

The control architecture joins request workflow, recipient and relationship data, screening, CRM and procurement context, approval records, payments and monitoring so that no team sees only part of the risk.

Due diligence that answers the real questions

Recipient due diligence should start with legal existence and identity. The bank may check the organisation's official registration where available, legal name, address, governing documents, website, published reports and responsible officers. The level of verification should reflect the risk and local context. A long-established national charity with transparent audited accounts may require less investigation than a newly formed local foundation with little public information.

Legitimacy is not the same as independence. A perfectly legitimate foundation can still create influence risk if its founder, trustee or major supporter is deciding whether the bank wins a mandate. The workflow therefore needs a connected-person view. Relevant connections may include public officials, employees of customers or potential customers, vendors, intermediaries, bank employees and their close relatives where policy and law permit such data to be used. The purpose is not to create an unlimited social graph. It is to identify relationships that are reasonably relevant to the bank's decision.

The bank should also understand what the recipient will do with the value. For high-risk or restricted grants, this may involve a project description, geographic scope, downstream delivery partners, expected beneficiaries and budget. For ordinary low-risk donations, a proportionate explanation may be enough. The same principle applies to sponsorship: the reviewer should know what the payment buys. Vague descriptions such as “community partnership” or “strategic event support” are weak evidence if the actual arrangement includes tickets, travel, VIP access or introductions.

Negative news should be assessed for relevance and reliability rather than counted. Allegations concerning fraud, diversion of funds, corruption, governance disputes or links to sanctioned or criminal actors can justify deeper review. Old or unrelated criticism may not. A good case file records the source, date, allegation, identity match and disposition rather than a simple “adverse media clear” flag.

A practical risk model

Risk scoring can support consistency, but the model should not replace judgement. A useful design considers factors such as the request source, recipient transparency, public-official or customer connections, pending business, jurisdiction and delivery geography, payment method, use of intermediaries, size relative to normal activity, sponsorship benefits, urgency and any history of prior support.

Some combinations should operate as hard escalation triggers rather than simply add points. Examples include a request by a public official during a pending business decision, a personal-benefit concern, payment to an account that does not belong to the approved recipient, inability to establish the recipient's legal identity, sanctions concerns, materially false information, or repeated attempts to split a request below approval thresholds. Whether the outcome is refusal, hold, enhanced review or Legal escalation depends on the facts and policy.

Low risk should also be visible. A mature control can identify cases that need a lighter route: for example, a pre-approved annual contribution to a long-established organisation, no relevant business or public-official connection, payment to a verified organisational account, transparent use of funds and no adverse information. Risk-based design protects capacity for the cases that genuinely need attention.

From alert to investigation

Unlike payment sanctions screening, charitable giving is often a pre-approval control rather than a high-volume transaction-monitoring process. Even so, monitoring can detect patterns that individual reviewers miss. Useful analytics can identify repeated support to the same recipient across business units, concentrations around public tenders or mandate awards, threshold splitting, frequent bank-account changes, unusually high sponsorship pricing, repeated sponsorships requested by the same external person, or entertainment benefits allocated to people involved in business decisions.

An alert should not automatically become a misconduct case. Triage asks whether the pattern has an innocent explanation, whether the data is complete and whether the issue is a policy breach, a control weakness or a possible integrity concern. If escalation is justified, the investigator should preserve the original request, communications, recipient due diligence, relationship context, approval chain, payment evidence and post-event records. Investigations involving employees require careful handling of confidentiality, employment law and privilege according to local rules and bank policy.

If the facts suggest a potential bribery, corruption, sanctions, fraud, money-laundering or other offence, the reporting route is jurisdiction-specific. Internal ABC escalation is not the same as a suspicious transaction or suspicious activity report, and a possible sanctions breach follows a different legal process again. Systems should maintain separate outcome codes and routes so that one generic “financial crime escalated” status does not obscure the obligation.

Books, records and the evidence timeline

A recurring weakness in donations and sponsorships is that each control step exists but the evidence cannot be joined. An email approval sits in one mailbox, the recipient check in a spreadsheet, the sponsorship contract in document storage, the invoice in procurement and the payment in the general ledger. Months later, the bank cannot demonstrate that the approver saw the key risk facts before value moved.

The case record should therefore capture the chronology. When was the request received? When did the bank learn about the relevant connection? Which information was available to each approver? Was the contract signed before payment? Did the payee change after approval? Were hospitality benefits assigned before or after the guest list was known? Did a business award, licence or other decision occur close to the contribution? Chronology is often more informative than a static checklist.

A defensible file preserves the chronology from request and diligence through approval, agreement, payment and post-event evidence so later reviewers can see what was known when.

Roles and governance

The business requester owns the legitimate business or community rationale and is responsible for complete and accurate disclosure. Corporate Affairs, Sustainability or a foundation team may own charitable strategy. Marketing may own sponsorship objectives. Procurement may control contracting, and Finance or Accounts Payable controls disbursement. Compliance owns ABC policy interpretation and risk challenge; Legal advises on applicable law and high-risk cases. Sanctions and AML specialists may need to resolve separate screening or financial-crime questions. Internal Audit provides independent assurance rather than transaction approval.

Segregation matters because a requester should not be able to create the recipient, approve the request, change the payee and release the payment alone. High-risk cases may require independent approval from a senior business leader and Compliance or Legal. The model should also define who can approve exceptions, what cannot be waived, and which issues must be reported to senior committees.

Management information should tell leaders whether the control is working rather than merely how many requests were processed. Useful measures include request volume and value by type and geography, high-risk cases, public-official or customer-requested cases, declines and withdrawals, payee changes after approval, repeat recipients, ageing and SLA breaches, policy exceptions, control failures, monitoring alerts and investigation outcomes. A rising approval rate is not automatically good; a rising exception rate is not automatically bad. The point is to identify patterns that require explanation.

Governance separates the requester and business owner from specialist challenge, payment execution and independent assurance while preserving clear escalation for high-risk cases.

Operational and customer impact

Controls that are too weak create legal and reputational exposure. Controls that are badly designed can also create harm. A legitimate community organisation may lose time-sensitive funding because the bank repeatedly asks for information it already has. A humanitarian partner may be unable to respond to an emergency because a generic country rule blocks every request. A small charity may struggle to provide the same documentation as a large international organisation even when its governance is sound. The answer is not to lower standards blindly; it is to distinguish essential evidence from bureaucracy and scale the process to the actual risk.

The bank should explain information requests in plain language and avoid implying that a charity is suspected of wrongdoing merely because due diligence is required. Where a request cannot proceed, the external explanation should follow Legal and policy guidance, especially when sanctions, confidential investigations or employee concerns are involved.

What good looks like

A strong donations and sponsorship control can answer a difficult case quickly because the information is already connected. It knows what type of value is being provided, who requested it, who the legal recipient is, who controls or is closely connected to that recipient, what business decisions are pending, what the sponsorship package contains, who will receive hospitality, which account will be paid, who approved the exception and what happened after payment.

It also knows its boundaries. ABC approval does not replace sanctions screening. Charity status does not prove low risk or high risk. A public-official connection does not prove bribery. A clean screening result does not prove proper purpose. A commercial sponsorship contract does not eliminate the need to understand personal benefits. The control works because those different questions are kept separate and then brought together for a reasoned decision.

For banking professionals, the central lesson is simple: follow the purpose, the people, the timing, the value and the money route together. A legitimate donation or sponsorship should become easier to defend when those facts are transparent. A problematic arrangement usually becomes harder to explain as the evidence is joined. That is exactly what a well-designed bank control should achieve.

Operational deep dive: risk-based donation and sponsorship control

The base chapter established the central idea: charitable purpose and commercial sponsorship labels do not answer the anti-bribery question. A bank needs an operating model that distinguishes ordinary community support from cases where influence, personal benefit, diversion, sanctions exposure or opaque payment routing changes the risk. This deep dive moves from principle into the review decisions that create most of the operational difficulty.

Start with a risk taxonomy, not one approval threshold

Many weak policies use monetary value as the main trigger for review. Amount matters, but it is rarely the most important fact in a bribery analysis. A small donation to a foundation connected to an official who controls a valuable licence can be more sensitive than a large contribution to a well-established national charity selected through the bank's central philanthropy programme. A mature model therefore combines value with qualitative triggers.

The first dimension is influence risk. Who requested the support, and can that person affect a decision relevant to the bank? Public officials, employees of state-owned entities, regulators, procurement officers, customer executives and vendor decision-makers can all create different forms of influence risk. The exact legal significance of the person's role depends on jurisdiction and facts. The workflow should capture the role and connection so Compliance and Legal can apply the correct standard rather than having the requester decide whether somebody “counts” as a public official.

The second dimension is recipient integrity. A reviewer needs enough confidence that the organisation exists, conducts the activity it claims to conduct and has governance capable of receiving and using the funds. This does not mean every recipient requires forensic due diligence. The level of work should reflect legal form, longevity, public information, geography, programme model, amount, payment method and other risk factors. Strong controls allow simple cases to remain simple.

The third dimension is beneficiary and diversion risk. A donation can be made to a legitimate organisation and still create a problem if a connected person receives a personal advantage, if funds are channelled onward to an undisclosed entity, or if the stated programme is a convenient route to pay a third party. Sponsorships add another layer because benefits can flow in both directions: the bank pays the sponsored entity and receives branding, tickets, access and hospitality. The control should identify who receives those secondary benefits.

The fourth dimension is business-context risk. Pending tenders, client mandates, licensing applications, regulatory matters, credit decisions, disputes, vendor selections and other live decisions can make timing significant. A system does not need to replicate every business platform to use this information. A simple structured question, supported by selected integrations for higher-risk business lines, can materially improve the decision.

The fifth dimension is delivery risk. International programmes, humanitarian work, use of local implementation partners, cash-intensive environments, difficult sanctions contexts and countries with elevated corruption risks can require additional controls. Those factors are not a basis for treating all work in a jurisdiction as improper. They tell the bank where evidence about downstream parties, payment routes, licences or safeguards may matter more.

A practical policy can translate these dimensions into three or four review tiers. Low-risk centrally selected contributions may require standard recipient verification and budget approval. Medium-risk cases may add connected-party checks and Compliance pre-approval. High-risk cases may require enhanced due diligence, Legal review, senior approval, documented business-context checks and post-payment monitoring. Certain prohibited features can sit outside scoring entirely, such as knowingly paying a personal account where policy forbids it or proceeding despite an unresolved sanctions prohibition.

Public officials, PEPs and connected persons

Public-official analysis and PEP controls overlap but are not interchangeable. PEP frameworks are primarily part of AML/CFT customer due diligence and vary by law and policy. Anti-bribery laws may define public officials differently and can include employees of state-owned or state-controlled entities, officials of public international organisations, political party officials or others depending on the regime. A bank should therefore avoid a system rule that says “no PEP hit means no public-official risk.”

For a donation or sponsorship, the useful question is whether someone connected to the recipient or request can exercise public or commercial influence relevant to the bank. The person may be a trustee, founder, honorary patron, fundraiser, director, major donor or event chair. Their involvement does not prove an improper purpose. It determines what the reviewer needs to understand.

Consider a city mayor who asks a bank to support a long-established children's hospital foundation while the bank has no business pending with the city. The request is sensitive because it came from a public official, but the facts may support approval with enhanced review. Change the context so that the bank is simultaneously bidding for the city's treasury-services contract, the mayor's sibling chairs the foundation and the contribution is presented as urgent. The charity's legitimacy has not changed, but the influence and timing risks have changed significantly.

A good workflow records the request source separately from the beneficiary connection. It should also allow reviewers to describe the relationship rather than force every connection into a binary flag. “Official is an unpaid patron with no operational authority” is different from “official's spouse founded and manages the recipient.” The evidence should support the distinction.

Recipient identity and governance

Entity verification starts with legal identity. Names used publicly can differ from the registered organisation that signs the agreement or owns the bank account. Local chapters, fundraising arms, foundations, friends-of organisations and event promoters may share branding. The bank should know which legal person is being approved and paid.

Useful evidence can include an official registry extract where available, governing documents, published annual reports, audited or reviewed financial statements where proportionate, regulator or charity-register information, names of trustees or directors, principal address, website, programme information and verified bank-account details. The absence of a sophisticated website should not by itself become a negative conclusion, particularly for small local organisations. What matters is whether the evidence is coherent and appropriate to the context.

Governance review asks whether the people who control the organisation are visible and whether conflicts are managed. A reviewer may need to understand founders, trustees, directors, executive management and significant connected entities. For a higher-risk case, the bank may also examine whether the organisation is newly formed, whether its stated mission matches proposed use of funds, whether it has credible operating history, and whether negative information suggests diversion, fraud or political misuse.

The bank should distinguish between recipient due diligence for its own ABC decision and the recipient's own legal obligations. It is not the bank's role to conduct a regulator's full charity-supervision examination. The objective is to gather enough evidence to decide whether the bank can provide value safely and transparently.

The non-profit terrorist-financing overlay without overreach

FATF's Recommendation 8 framework matters because some charitable activity can be exposed to terrorist-financing abuse, especially where funds are raised, moved or spent in difficult environments. But FATF's 2023 best-practices paper is equally important for what it says not to do. It emphasises that Recommendation 8 does not apply indiscriminately to every organisation in the not-for-profit realm and that focused, proportionate, risk-based measures should avoid unduly disrupting legitimate NPO activity.

For a bank reviewing its own donation, that means due diligence should respond to actual delivery features. Cross-border transfers to conflict areas, use of informal delivery networks, downstream local partners, cash distribution or operations close to designated groups may require more information. A domestic literacy charity with transparent governance and ordinary bank payments should not inherit the same control burden simply because both organisations are non-profits.

The ABC and TF questions should remain separate in the case file. A recipient can present no bribery concern but require sanctions or CFT analysis. Conversely, a domestic charity can present a bribery concern because of its connection to a customer decision-maker even when there is no ML/TF issue at all. A single “high-risk charity” label destroys that distinction and makes control outcomes harder to defend.

Sanctions screening in charitable activity

Sanctions controls operate according to the regimes applicable to the bank and transaction. The UK OFSI guidance for charities and NGOs, updated in January 2026, is a useful illustration of the additional questions that can arise: designated persons, ownership and control, licensing, exceptions and humanitarian activity. A global bank must map those concepts to the law applicable to each legal entity and payment; the UK position must not be applied as if it were universal.

Screening should cover the parties that the sanctions framework and bank policy require. Depending on the case, that can include the recipient organisation, relevant controllers, payment intermediaries and identified downstream parties. Name matching should use available identifiers and should be resolved by trained reviewers. A possible match should not be converted automatically into an allegation that a charity is sanctioned.

Humanitarian cases need particular care. Some sanctions regimes include exceptions or licensing grounds for humanitarian activity, but their scope varies. If a proposed donation reaches a sanctioned environment, the bank should route the case to sanctions specialists early enough to assess the legal path before operational teams promise funding or announce a public campaign.

Sponsorship economics and hidden benefits

Sponsorship controls fail when reviewers look only at the invoice amount. The bank should understand the commercial package. What brand exposure is provided? How many tickets? What type of hospitality? Are travel or accommodation included? Does the bank receive speaking rights, introductions to participants, access to attendee data, exclusive meetings or other benefits? Are those benefits proportionate to the fee and consistent with the stated marketing objective?

The purpose of this analysis is not to turn Compliance into a marketing valuation team. It is to identify obvious mismatches and hidden benefits. A substantial payment for minimal brand exposure, accompanied by premium access to people deciding a bank mandate, warrants challenge. So does a sponsorship recommended by a customer executive when the majority of value consists of VIP hospitality for that executive and colleagues.

Hospitality should be allocated to named or identifiable recipients through the bank's applicable gifts and entertainment process where required. The sponsorship approval should not become a blanket permission for whatever guest list appears later. If the final guest list changes the risk materially, the bank should be able to re-review before the event.

Sponsorship agents and event organisers can introduce third-party risk. If a bank pays an agency rather than the sponsored organisation, the file should explain the agency's role, contractual basis and payment destination. Success-fee structures, unexplained mark-ups, payments to unrelated jurisdictions or requests to divide the fee among multiple entities can require enhanced review.

Emergency and disaster-relief giving

Disasters create a difficult control trade-off: humanitarian need increases while ordinary due diligence may become harder. A control designed only for normal conditions will either delay legitimate aid or be bypassed under pressure. Banks should pre-design an emergency route.

That route can identify preferred established recipients, minimum verification requirements, approved payment methods, accelerated decision rights, sanctions escalation, maximum provisional limits and post-payment evidence. It can also explain when new local partners may be used and what additional checks are required. The objective is controlled speed, not reduced accountability.

Employee fundraising and matching programmes also need boundaries. If employees choose eligible organisations, the bank should define qualification criteria and prevent match funding from being used to circumvent corporate donation controls. A high-risk requester should not be able to route a corporate contribution through an employee campaign to avoid Compliance review.

Fiscal sponsors, community foundations and intermediaries

Not every charitable project is a separate legal entity. A project may operate under a fiscal sponsor, community foundation, university or umbrella organisation that legally receives funds and administers them. That arrangement can be entirely legitimate. The bank should understand both the legal recipient and the intended programme, including the relationship between them and who controls disbursement.

The same principle applies when a customer asks the bank to contribute through an event organiser or fundraising platform. The platform can solve collection and administration, but it changes the payment chain. The bank should know whether the intermediary is merely processing the payment, legally receiving the donation, retaining fees or exercising discretion over onward distribution.

Conflicts of interest inside the bank

Internal conflicts are easy to overlook because the external recipient may be legitimate. An employee may sit on the charity's board, have a family relationship with its leadership, be seeking a role with the sponsored organisation or have a personal interest in the event. The conflict does not automatically bar support, but it can affect who should sponsor the request, who may approve it and what disclosure is needed.

The workflow should therefore ask for relevant employee connections and integrate with the bank's conflict-of-interest process where appropriate. Self-declared conflicts should be visible to the reviewer, and the conflicted employee should not control approval or payment. Where data-protection rules limit the use of personal information, the bank should design the process with Legal and Privacy rather than collecting unlimited relationship data.

Payment and accounting controls

The payment instruction is the final point at which the bank can prevent a badly routed transaction. The approved legal recipient, beneficiary account, currency, amount and purpose should flow from the approval record into procurement or accounts payable wherever possible. Manual re-keying creates opportunities for error and unauthorised change.

Beneficiary-account verification is critical. A request to pay a director, fundraiser or personal account should be treated as a material deviation, not normal convenience. So should an account in an unrelated country or the last-minute substitution of a different legal entity. If legitimate local circumstances require an exception, the rationale, legal analysis and approval should be explicit.

Accounting descriptions should be meaningful. Generic labels such as “consultancy,” “marketing support” or “community expense” can conceal the nature of the payment and weaken books-and-records controls. The expense category, recipient and supporting agreement should allow Finance, Compliance and Audit to identify donations and sponsorships reliably.

Monitoring across requests

Monitoring should look across time and business units. Useful tests include multiple contributions to the same recipient, clusters just below approval thresholds, repeated requests from the same public official or customer executive, high-risk cases approved unusually quickly, late payee changes, large sponsorship packages with unrecorded hospitality, and donations concentrated around tender or licence dates.

A pattern is a reason to review, not proof of bribery. For example, a bank may support the same national charity every year because it is part of a long-term social strategy. The control should recognise that established rationale. The value of monitoring is to surface patterns that deserve explanation before they become invisible routine.

Investigation evidence

When a case escalates, investigators need both the transaction and the context. The evidence set can include request forms, emails and messaging records preserved lawfully, due-diligence results, relationship data, tender timelines, contract terms, guest lists, invoices, general-ledger entries, payment details, bank-account changes, conflict declarations, adverse-media findings and post-event evidence.

The investigator should construct a chronology and test competing explanations. Was the contribution part of an annual programme planned before the business opportunity existed, or was it created after a decision-maker made the request? Did the recipient independently choose the programme, or did a connected official direct the funds toward a personal project? Was the sponsorship price commercially consistent, or did it include an unexplained premium? Were approvals based on complete facts, or did the requester omit a known relationship?

Conclusions should distinguish policy breaches, process failures and suspected misconduct. A late approval may be a control breach without evidence of corrupt intent. A hidden connected-party relationship may require a different response. Where legal reporting or law-enforcement engagement may be required, Compliance and Legal should determine the route under the applicable jurisdiction rather than using a generic global rule.

Designing proportionality into the procedure

The strongest procedure makes it easy to do the right thing. It gives requesters examples of activities in scope, asks a small number of meaningful questions, reuses reliable entity data, routes higher-risk cases automatically and shows why extra information is required. It does not force every branch donation through the same questionnaire as a complex cross-border sponsorship.

Proportionality should be visible in system logic and policy, not improvised by reviewers. Minimum controls can apply to every case: clear purpose, verified recipient, payment to an approved account, conflict disclosure, accurate recording and evidence of approval. Additional controls are then triggered by risk. This creates a programme that can support legitimate giving while making it difficult to hide an improper benefit inside a socially attractive label.

Advanced practice: data, architecture, controls and testing

Charitable donation and sponsorship risk looks like a policy subject until a bank tries to operate it across dozens of legal entities, thousands of employees, different procurement systems and fragmented relationship data. The quality of the control then depends on architecture as much as on policy. A reviewer can only make a reasoned decision if the system assembles the right facts before approval and preserves them after payment.

The minimum data model

A practical data model begins with the request. The request record should have a unique identifier, activity type, requesting employee and business unit, legal entity providing the value, amount and currency, purpose, budget owner, date required, request source and whether the proposal was solicited by an external person. Free text is useful for explanation, but core facts should be structured so that monitoring and routing can work consistently.

The recipient entity should be represented separately from the request. Useful attributes include legal name, trading or public name, legal form, country of incorporation or registration, registration number where available, principal address, website, stated purpose, date established, relevant regulator or registry and verified bank-account relationship. Storing recipient data separately allows reuse across repeated contributions while preserving the historic snapshot used for each decision.

The connected-person model should record only relationships relevant to the control. It can identify trustees, directors, founders, executives, significant controllers or other persons that policy requires, together with the relationship type and source. The system should also capture the person who requested the donation or sponsorship even if that person has no formal role in the recipient. A requester, patron or customer executive can create influence risk without appearing on a corporate registry.

The business-context model links the request to relevant customer, prospect, government or vendor relationships. For high-risk business lines, integration can surface whether the bank has an active tender, mandate pursuit, licensing issue, material complaint, vendor selection or other decision involving a connected party. The architecture should avoid indiscriminate data collection. The purpose is to identify a reasonable nexus to the support request, not to build a permanent dossier on everyone connected to a charity.

The benefit model is especially important for sponsorship. It should record the assets the bank receives: brand exposure, advertising, ticket allocations, hospitality, travel, accommodation, speaking opportunities, access rights, exclusivity and other consideration. Where guest benefits are subject to gifts and hospitality rules, the sponsorship case should link to those records rather than duplicating or losing them.

The decision model records risk tier, triggered controls, due-diligence evidence, sanctions or other screening results, conflict declarations, approvers, decision date, conditions, exceptions and rationale. High-risk cases should preserve which facts were shown to each approver. An approval timestamp without the evidence snapshot does not prove that the approver knew about the relevant official or business opportunity.

Finally, the payment and post-event model records beneficiary account, payment date, amount, ledger reference, any payee changes, contractual deliverables and post-event evidence. The result is a traceable line from proposal to disbursement rather than a collection of loosely connected documents.

Workflow architecture

A common architecture has five logical components even when the bank implements them inside fewer applications.

The first is a request and case workflow. It captures structured data, controls status, prevents payment until required approvals are complete and routes exceptions. It should support both planned programmes and ad-hoc requests, including emergency workflows.

The second is entity and relationship intelligence. This may use the bank's customer master, third-party master, PEP and sanctions screening platforms, external registry data, CRM and procurement records. Entity resolution is essential. A charity name typed by a user should not be assumed to match the screened entity until identifiers support the match.

The third is a risk and rules service. Rules can identify triggers such as public-official requests, active business opportunities, high-risk geographies, unusual payment methods, new recipients, large values, repeated requests or connected employees. Rules should route work, not replace human legal judgement. A rule can say “Compliance approval required”; it should not say “this is bribery.”

The fourth is financial execution through procurement, accounts payable, treasury or another disbursement platform. The approved recipient and payment instructions should transfer electronically where feasible. If the payment system accepts a beneficiary that differs from the approved entity, the control needs a blocking validation or explicit exception route.

The fifth is monitoring, case management and assurance. Data from requests, approvals and payments feeds analytics and enables investigators and auditors to reconstruct decisions. Monitoring should work across business lines and legal entities where law and data-governance rules permit it.

Integration with CRM and business-pipeline data

Relationship context is one of the hardest facts to collect reliably. A request form that asks “Do we have business pending with anyone connected to this recipient?” depends entirely on the requester's knowledge and honesty. For sensitive businesses, the bank can supplement self-declaration with selected automated checks.

For example, a corporate-banking CRM may show active opportunities with an organisation whose executive sits on the recipient's board. A public-sector pipeline may show a tender involving the official who requested the contribution. A vendor system may show that the event organiser is participating in a procurement exercise. These signals do not create an automatic prohibition. They tell the reviewer that the timing and connection should be assessed independently.

The integration needs temporal logic. An opportunity that closed three years ago may be less relevant than one currently at final selection. A tender opened after a long-standing annual sponsorship was approved may create a different narrative from a donation first requested during the tender. Storing effective dates enables this analysis.

Entity resolution and false connections

Connection analytics can produce serious false positives. Common names, outdated board lists and shared addresses can cause a system to link the wrong person or entity. Reviewers should see why a match was generated and which identifiers support it. A board-member name alone should not be treated as a confirmed relationship to a PEP or customer executive.

A robust matching service keeps the raw screening result, identifiers used, match score where appropriate and final disposition. Manual overrides should be reasoned and auditable. If the same false match recurs across many requests, the bank should tune or suppress it under controlled governance rather than forcing reviewers to resolve it repeatedly.

Duplicate and threshold-splitting detection

Donations and sponsorships can be fragmented across branches, countries and budget owners. A bank should therefore monitor at more than one aggregation level. The same legal recipient may appear under multiple display names. Related foundations may share controllers. A large event may be supported by marketing, a regional business unit and a bank foundation separately.

Aggregation logic can look at recipient legal identity, bank account, connected organisation, event name, requester and time period. It should identify patterns such as repeated amounts just below approval thresholds or multiple requests submitted close together after a higher-value request was challenged. Detection does not prove deliberate circumvention; the reviewer should determine whether separate business reasons exist.

Threshold design should avoid perverse incentives. If EUR 10,000 triggers enhanced review, policy should state how linked requests are aggregated and who decides whether they are related. The system should display previous support to the recipient so the approver can see cumulative exposure.

Payee-control design

The cleanest design transfers approved beneficiary details into the payment system and prevents free-form substitution. If a new account is introduced after approval, the system should require independent verification and return the case to the right approval stage. The original and changed details should both remain visible.

Bank-account verification can use documentation, trusted master data or confirmation with an independently sourced contact. The method should reflect fraud risk and local capabilities. Merely accepting bank details from the same email that submitted the sponsorship invoice is weak control because a compromised mailbox can alter both request and payment instruction.

If an intermediary must be paid, the case should identify the intermediary's legal role. Is it an event organiser collecting sponsorship fees, a fiscal sponsor administering a project, a fundraising platform or an unrelated third party? The contract and invoice should support the route. Unexplained accounts in different jurisdictions require challenge before value moves.

Control-state design

Statuses need to represent the real lifecycle. Useful states can include Draft, Submitted, Due Diligence In Progress, Awaiting Information, Compliance Review, Legal Review, Approved with Conditions, Approved, Declined, Withdrawn, Payment Pending, Paid, Post-Event Review and Closed. A single “Approved” flag cannot express whether the approval is conditional or whether payment conditions remain outstanding.

State transitions should have guards. A case should not move to Payment Pending if mandatory sanctions screening is unresolved, required approvers are missing or the recipient account is unverified. Emergency overrides should be explicit actions with a named authority, reason and expiry, not administrator-level edits to the status table.

Segregation of duties and access control

The requester should not be able to approve their own case. A person who maintains the recipient master should not be able to change beneficiary data and release payment without independent control. Compliance reviewers should be able to challenge or return a case without altering the requester's original narrative. Audit users should have read-only access to historical evidence.

Role design becomes more complex in small branches. Where headcount makes perfect separation impractical, the bank should define compensating controls such as regional approval, post-event review or independent payment release. The exception should be designed rather than left to local improvisation.

Sensitive investigation information should not automatically be visible to every requester. If a donation is escalated because of an employee allegation or law-enforcement concern, the case architecture may need restricted sub-cases or references so that the operational workflow can be stopped without exposing confidential intelligence.

Rules, models and human judgement

A scoring model can help route cases consistently. The model might weight request source, recipient maturity, public-official connection, active business, geography, payment route, intermediary use, sponsorship benefits, urgency and prior history. But the model requires governance like any other decision tool: documented logic, ownership, test cases, change control, versioning and periodic performance review.

Hard rules should be reserved for facts that truly require deterministic treatment under policy or law. Examples may include missing mandatory approval, unresolved sanctions prohibition or a prohibited payment method. Many other facts are contextual. A public official's connection may trigger enhanced review rather than automatic rejection. This distinction keeps automation useful without pretending that complex intent can be calculated from a score.

Testing the happy path

Positive functional testing should prove that an ordinary low-risk donation can move through the workflow without unnecessary friction. A test case can use an established domestic charity, centrally selected annual programme, verified organisational account, no relevant business connection and no adverse screening. The expected result is standard due diligence, appropriate budget approval, payment and closure with complete evidence.

A normal sponsorship test should include a clear commercial package, marketing owner, contract, reasonable benefits, guest allocation handled through the gifts-and-hospitality process and no sensitive relationship. Testers should confirm that sponsorship benefits are visible and that the payment system receives the approved recipient and amount.

Testing higher-risk scenarios

A strong test pack includes facts that cross system boundaries. One scenario should involve a public official requesting support for a charity chaired by a relative while a public-sector tender is active. The workflow should identify the official connection, retrieve or capture the tender context, route to Compliance and Legal and prevent payment until a reasoned decision is recorded.

Another scenario should involve a legitimate charity whose bank-account details change after approval. The system should not silently update the payee. It should require independent verification and, depending on policy, re-approval.

A third scenario should test threshold splitting: three related requests below the enhanced-review threshold for the same organisation in a short period. Monitoring or pre-approval logic should aggregate the exposure and surface the pattern.

A fourth scenario should test a sponsorship with premium tickets and hospitality. The sponsorship itself may be acceptable, but the guest list includes people involved in awarding a customer mandate. The system should route those individual benefits through the applicable hospitality controls rather than assuming the sponsorship approval covers them.

A fifth scenario should test a sanctions or ownership-and-control issue. The expected result depends on the applicable regime and specialist decision; the key system requirement is that the ABC reviewer cannot override a sanctions hold merely by approving the donation rationale.

Negative and boundary testing

Negative testing proves that controls do not generate needless escalation. A common name should not create a confirmed PEP connection without identifier resolution. A historic customer relationship with no live business should not automatically be treated like an active tender. A charity working internationally should not become high risk solely because it crosses borders.

Boundary tests are especially valuable around amounts and dates. Test the exact approval threshold, cumulative thresholds, currency conversion rules, expired due diligence and opportunities that open or close close to the request date. Testing should verify which date and FX rate the policy intends to use rather than assume implementation detail.

Failure-mode testing

The workflow must also behave safely when dependencies fail. What happens if sanctions screening is unavailable? Can the requester submit but not obtain final approval? Does the system queue the check, or can a controlled manual route be used? What if CRM integration times out? The bank should distinguish a technical failure from a clean result.

Payment-interface failures need idempotency. A retry should not create duplicate payments. The case should receive a stable payment reference and reconcile against the finance system. If a payment fails, the case should not show “Paid” merely because an instruction was sent.

Document-storage failures should not allow a case to close without preserving required evidence. Access-control tests should confirm that unauthorised users cannot view restricted investigation material or alter historic approvals.

Acceptance criteria for business analysts

A good requirement says more than “screen charities before payment.” It defines the trigger, data, source, decision and evidence. For example: when a request is identified as a charitable donation or sponsorship, the application must capture the external requester, recipient legal entity, relevant connected persons, business rationale, value, currency, intended payment account and any sponsorship benefits before risk routing. If the request is made by a public official or by an employee of a customer, vendor or prospective customer, the workflow must require the user to record the relationship and must invoke the enhanced-review rule set.

Another requirement might state: when approved beneficiary details are changed after approval, the case must return to Payment Verification, preserve the previous values, require independent verification and block release until the required approval is restored. These statements are testable and connect control intent to system behaviour.

Requirements should also specify evidence retention. The application should preserve the version of due diligence and screening results used at decision time, the identity of approvers, timestamps, conditions and the final payment reference. Without that history, an audit months later sees current data instead of the facts on which the original decision was based.

Operational resilience and change management

The programme changes over time. Sanctions lists and legal regimes change, charity records change, customers change roles, recipients change bank accounts and business opportunities open after an annual sponsorship has been approved. The bank needs rules for when a change triggers re-screening, re-diligence or re-approval.

Policy changes should be versioned so historic cases remain interpretable. If approval thresholds change, an auditor should be able to tell which threshold applied when the decision was made. The same principle applies to scoring models and screening configuration.

Monitoring should feed back into design. If investigators repeatedly find that requesters omit who solicited a donation, the form should change. If threshold splitting is common, aggregation logic should improve. If reviewers receive too many irrelevant PEP matches, entity resolution should be tuned. Control effectiveness is not demonstrated by having a workflow; it is demonstrated by learning from how that workflow succeeds and fails.

Assurance evidence

Second-line monitoring can sample cases for recipient verification, connection disclosure, risk routing, approval quality, payment consistency and post-event evidence. The sample should include low-risk as well as high-risk cases so assurance can identify over-control and under-control.

Internal Audit can test the design independently, including data lineage and access controls. Audit should be able to reproduce the case from source data to ledger entry. If an approval report cannot explain where a relationship flag came from, or if payment data cannot be linked back to the approval, the technical control is incomplete even if the policy language is excellent.

For a mature bank, the end-state is a control that is both strict and usable: ordinary community support moves efficiently, genuinely sensitive cases receive independent challenge, payment cannot outrun approval, and the evidence remains coherent long after the people involved have changed roles.

Practice close: challenge the file, not the label

A learner should finish this chapter able to review a real request without relying on shortcuts such as “charity is low risk” or “public official means reject.” The skill is to assemble the facts and reach a proportionate decision another reviewer can reconstruct.

Start with what the bank is providing: donation, grant, sponsorship, hospitality, in-kind support or a mixture. Identify the external person who proposed it, confirm the legal recipient and payment account, map relationships that can create influence or personal benefit, and place the request against tenders, mandates, licensing matters or other live decisions.

The case file should explain why the bank is providing value, why the recipient was selected, who asked, what relevant connections exist, what sponsorship benefits the bank receives and whether value moved to the approved payee. High-risk approvals need a reasoned explanation of mitigating facts and residual risk; “Compliance approved” is not enough.

Facts such as a public-official request, connected trustee, unusual urgency, active business decision, sponsorship premium, intermediary payment or beneficiary-account change require context rather than automatic conclusions. The outcome may be ordinary approval, enhanced review, conditions, deferral, hold or decline.

Business analysts should ensure important policy statements have a data source, trigger, decision owner and evidence outcome. Testers should cover a sensitive requester, false PEP match, threshold splitting, changed payee, premium hospitality and unavailable screening dependency.

Before closing, ask whether an auditor reading the record in two years could understand what the bank knew, why it decided to proceed or not proceed, who accepted the risk and whether value moved as approved. If yes, the control is creating a transparent account of how legitimate giving was kept separate from improper influence.

Masterclass: the foundation, the tender and the gala sponsorship

This fictional case is designed to show how several individually ordinary facts can become significant when joined. It is not based on a real enforcement action, and none of the facts alone proves bribery. The learning objective is to build a defensible decision from purpose, people, timing, value, payment route and evidence.

The request

Northbridge Bank operates a corporate and public-sector business in the country of Ardia. Its local office has supported community education projects for years. The bank's public-sector team is currently one of three bidders for a four-year cash-management and payments mandate from the City of Lydon. The mandate would be commercially important but is not material to the group.

Three weeks before final bid presentations, the head of the local business receives a call from the city's deputy mayor. The deputy mayor asks whether Northbridge would support the annual gala of the Lydon Children's Future Foundation, describing the foundation as one of the city's most respected youth charities. The requested sponsorship is equivalent to EUR 35,000. The deputy mayor says all major employers are expected to “show commitment to the city.”

The relationship manager submits the request through the bank's sponsorship workflow. The initial description says: “Brand sponsorship of children's education gala. High-profile community event. Strong relationship value.” The event package includes the bank's logo on the stage, a table for ten guests, two invitations to a private reception before the gala and a speaking opportunity for a senior bank executive.

At first glance, the transaction has a clear commercial and community rationale. The recipient is a real foundation with a ten-year operating history. Its published annual report shows education grants and audited accounts. The bank has supported unrelated education initiatives in the same city before. None of that ends the review because the request source and timing create a separate influence question.

The first-line review

The workflow captures that the request was solicited by a public official. It also asks whether the bank has current business involving that person's government body. The relationship manager selects Yes and links the city tender. That response automatically requires Compliance pre-approval regardless of amount.

Recipient verification confirms the foundation's legal identity and bank account. Registry data shows five trustees. One is the deputy mayor's adult sister, who is also the unpaid chair. The relationship is disclosed in the foundation's public annual report, so there is no evidence of concealment. Screening identifies the deputy mayor as a domestic politically exposed person under the bank's AML policy, but the foundation itself is not a bank customer and is not treated as “a PEP.” The reviewer records the connection precisely rather than applying that label to the organisation.

No sanctions matches are identified. Adverse-media review finds positive coverage of the foundation and one two-year-old article questioning whether city contractors receive disproportionate visibility at its gala. The article contains no allegation of illegal payments. The reviewer records it as context, not a finding.

The facts become more complicated

Compliance asks Marketing to provide the sponsorship valuation. Marketing explains that the gala normally sells table sponsorships for about EUR 15,000. The additional EUR 20,000 reflects the stage branding, private reception and speaking opportunity. That explanation is plausible, but Compliance asks for the standard sponsor prospectus and confirmation that comparable sponsors are paying similar rates.

The prospectus shows that the highest published package is EUR 25,000. The EUR 35,000 package was created after the deputy mayor spoke to the foundation's chair and event organiser. The event organiser tells Marketing that the premium reflects “the bank's particular visibility needs.” Marketing says it did not request a bespoke package.

At the same time, the public-sector deal team confirms that the deputy mayor is not formally on the tender evaluation committee. However, the deputy mayor has political responsibility for the city's finance modernisation programme and regularly attends steering meetings. The tender decision is made by a procurement committee with technical scoring, but the deputy mayor can influence policy priorities and senior appointments. Legal advises that the facts justify treating the interaction as sensitive even though the official does not cast the tender vote.

Payment-route surprise

Two days later, the event organiser asks Accounts Payable to send the sponsorship fee to its own account rather than the foundation's verified account. It explains that it collects all gala sponsorships and pays suppliers centrally. The organiser is a small event-management company that has worked with the foundation for three years. The approved request, however, names the foundation as recipient.

The payee-control rule blocks the change and returns the case to review. Due diligence on the event organiser confirms its legal existence. One of its directors previously worked as an adviser in the deputy mayor's political office but left four years earlier. There is no evidence of current employment or family relationship. The organiser's fee under its contract with the foundation is a fixed percentage of event revenue.

This fact is relevant but should not be exaggerated. Former government employment is not proof of a corrupt relationship. The reviewer records the history and asks why the foundation cannot receive the sponsorship directly. The foundation responds that all event sponsorship payments are contractually collected by the organiser and provides the agreement and prior-year accounts showing the same arrangement for multiple sponsors.

Guest allocation creates a second control problem

The relationship manager proposes inviting the city's chief procurement officer, two finance officials, the deputy mayor, three corporate customers and three bank employees to the sponsored table. The private reception invitations would go to the deputy mayor and chief procurement officer.

This changes the analysis again. The sponsorship and the hospitality are related but distinct. The bank's sponsorship approval does not automatically approve benefits to individual officials. The guest allocation is routed to the gifts and hospitality policy. The bank's Legal and Compliance teams conclude that inviting people directly involved in the pending procurement to premium hospitality before the award creates an unacceptable risk and appearance of influence under the bank's policy. The decision does not depend on proving corrupt intent.

The business suggests replacing the city officials with representatives from local education organisations and using the speaking opportunity to discuss financial literacy. That change removes one of the most sensitive benefits but does not resolve the original donation/sponsorship request by the deputy mayor.

The decision meeting

The case is escalated to the country chief executive, Head of Compliance and Legal because several high-risk factors are present: solicitation by a public official, an active city mandate, the official's close family connection to the foundation's chair, a bespoke premium above the published sponsorship package, and hospitality initially intended for people linked to the tender.

There are also important mitigating facts. The foundation is established and transparent. The family relationship is public. Its programmes are genuine. The event organiser's collection model is documented and applies to other sponsors. The bank has a history of supporting education initiatives. There is no sanctions concern, no hidden account and no evidence that any individual would receive the sponsorship fee personally.

The committee considers three options. The first is to approve the sponsorship after removing the official hospitality and documenting the rationale. The second is to defer any support until the tender is concluded. The third is to decline the current sponsorship but invite the foundation to apply under the bank's next centrally managed community programme after the procurement decision.

The bank chooses the third option. The reason is not a conclusion that the request was a bribe. The committee considers the combined timing, solicitation, connected family relationship and bespoke commercial package too difficult to separate from the live public-sector decision. Deferral alone could still leave a perception that the support was linked to the outcome. A later application through the ordinary philanthropy process provides a cleaner separation.

Communication and evidence

The relationship manager is instructed not to tell the deputy mayor that Compliance “suspected bribery.” The external message states that the bank cannot participate in the gala sponsorship under its current governance process but remains committed to community programmes and will consider future opportunities through its normal cycle. The tender team is told only what it needs to know: the sponsorship will not proceed and no city officials are to receive event hospitality from the proposed package.

The case file preserves the original request, public-official connection, tender link, recipient due diligence, trustee relationship, sponsorship prospectus, event-organiser documents, proposed guest list, reviewer questions, Legal advice reference, committee decision and withdrawal communication. The payment system shows no disbursement.

The post-case review

Three months later, after the city awards the mandate to another bank, Northbridge's annual philanthropy committee considers a separate application from the foundation for a financial-literacy programme. The application is for EUR 20,000, paid directly to the foundation, with defined programme reporting. The deputy mayor is not involved in the request. The bank still records the family connection and prior case, but the changed timing and structure materially reduce the influence concern. After ordinary enhanced review, the committee approves the grant.

This later approval is important to the learning. A risk-based programme is not a permanent blacklist. The earlier refusal addressed a particular combination of facts. When those facts changed, the bank reassessed the case rather than treating the recipient as contaminated forever.

What the case teaches

The case demonstrates why a control should not ask only “Is this a genuine charity?” The foundation was genuine throughout. The difficult questions concerned solicitation, timing, personal connections, sponsorship pricing and hospitality. It also shows why a PEP-screening result cannot decide the case. The deputy mayor's status was relevant, but the decision depended on the live tender and the relationship to the foundation.

The payee change illustrates another lesson. An intermediary account can be legitimate if the role is documented and consistent with the event structure. The correct response was to stop, verify and understand the route, not to assume that every third-party account is corrupt.

Finally, the case shows the value of integrated data. Without the tender link, trustee relationship, sponsorship-benefit breakdown and guest list, each team could have approved a plausible fragment. The risk became visible only when the bank joined those facts before payment.

References and further reading

The sources below were used to frame the chapter. They are public, authoritative or first-party materials. Jurisdiction-specific obligations must be applied through the law and approved policy relevant to the bank entity and transaction; the sources are not interchangeable global legal rules.