Fraud Proofing FCRA Funds: The Hidden Cost of Direct Implementation
Many large donor agencies stopped sub granting FCRA funds to NGOs around 2020, moving instead to direct implementation, recruiting their own staff and opening project offices across India. For most agencies, this shift has worked well operationally. But it has also introduced new risks that were less visible under the earlier sub granting model, chief among them, an increased exposure to fraud.
Also Read: FCRA 2027: NGOs Must Now Select States and Programs, What You Need to Know
How the Risk Has Shifted
Under the sub granting model, fraud risk was fragmented. It resided outside the donor agency, at the level of the implementing NGO. Any misuse of funds was, in the first instance, a problem for the grantee organisation to detect, disclose, and remedy.
With direct implementation, that risk has moved inside the donor agency itself. The agency is now directly responsible for anything that goes wrong, whether it is misappropriation, falsified expenses, or diversion of project funds. There is no longer an intermediary NGO absorbing the first layer of exposure.
Also Read: The Foreign Contribution Trail: When Public Records Reveal FCRA Gaps
Why the Risk Has Intensified
Two structural features of direct implementation make this risk more acute:
Distance from oversight. Project offices are typically located far from Head Office, and are rarely visited by internal or statutory auditors. Day to day financial control at these locations often rests with a small, unsupervised team.
Concentration of control. The same small set of people frequently handles receipt, custody, and disbursement of project funds at a given location. This concentration removes the natural checks that come from separation of duties, making both error and intentional fraud harder to catch.
Also Read: FCRA and the 'Key Functionary' Question: Finally Getting Some Clarity
What Agencies Should Do
Agencies operating on a direct implementation model should treat this as a distinct risk category requiring active management, not something automatically covered by their existing donor facing compliance processes. Practical steps include:
- Reassessing the risk of FC funds being misappropriated by employees or third parties at each project location, rather than assuming uniform risk across all offices.
- Building systems to deter, detect, and defend against fraud, including segregation of duties, spending limits, dual authorisation for payments, and surprise field visits.
- Backing these systems with regular, genuinely independent audits of project offices, not just Head Office consolidated accounts.
- Having a considered response protocol ready before fraud occurs, so that if an incident does surface, the agency can weigh its legal, regulatory, and donor reporting options carefully, rather than reacting impulsively.
Also Read: FCRA Renewal Denied: The Oxfam India Case and What It Signals for NGO Compliance
Conclusion
Direct implementation has solved one compliance problem, that of relying on the FCRA status and internal controls of external grantees, but it has created a new one: concentrated financial risk with limited field level oversight. Agencies that have made this shift should treat internal fraud risk as a standing item on their compliance agenda, not a one time transition concern.
Frequently Asked Questions
Why did donor agencies move away from sub granting FCRA funds to NGOs?
Many large donor agencies shifted to direct implementation around 2020, recruiting their own staff and opening project offices in India, rather than routing funds through implementing NGOs.
How does direct implementation change an agency's exposure to fraud?
Under sub granting, fraud risk was largely external, sitting with the implementing NGO. Under direct implementation, the donor agency itself becomes directly responsible for any misuse of funds at the project level.
What practical steps can agencies take to manage this risk?
Agencies should reassess fraud risk at each project office, build internal controls such as segregation of duties and dual authorisation, conduct regular independent audits of field offices, and have a considered response plan ready in case fraud is detected.
Disclaimer: This article is for general informational purposes only and does not constitute legal or professional advice. Readers should consult a qualified professional for guidance specific to their organisation's circumstances.