NPO Risk Scoring
Calculator

A risk-based scoring framework for evaluating nonprofit legitimacy and donation integrity in corporate social responsibility programs — designed to bring structure, consistency, and defensibility to a space where dedicated fraud operations infrastructure is still maturing.

Risk Scoring Fraud Operations NPO / CSR Decision Frameworks AML Compliance FINTRAC

Industry context

The challenge

A gap common across the CSR industry

CSR platforms sit at a complex intersection: corporate clients, employee donors, and thousands of nonprofits receiving funds. Fraud risk is real and growing — but dedicated fraud operations infrastructure in this space is still relatively rare. Most platforms reach a point where NPO concerns are escalating faster than informal processes can handle them.

Without a structured framework, investigation outcomes can vary by analyst, by urgency, and by whatever precedent happened to exist from the last similar case. Decisions that feel right in the moment become difficult to explain to legal or leadership — and impossible to defend consistently at scale.

The solution

A scoring model that takes subjectivity out of the equation

The framework evaluates NPOs across five risk categories — investigation request, platform activity, financial health, media profile, and public trust — producing an additive score that maps to a tier and a recommended action.

Every decision is grounded in documented signals rather than instinct. The score doesn't replace analyst judgment — it structures it, making outcomes consistent across cases, explainable to stakeholders, and defensible if challenged. When the same process is applied to every investigation, precedent builds naturally and the program scales.

Without a framework
Investigation outcomes vary by analyst and urgency
No consistent criteria to apply across cases
Escalations difficult to defend to legal and leadership
No structured audit trail for actioned organizations
Precedent accumulates inconsistently over time
After
Additive scoring across five risk categories
Same criteria applied to every investigation
Score and flagged factors justify every decision
Full record of what was assessed and why
Auto-escalation triggers remove edge-case ambiguity
5
Risk categories assessed
4
Tiers with mapped actions
4
Auto-escalation triggers

Framework

Built on three principles

01
Platform neutrality — never integrity neutrality
The platform takes no position on the cause an NPO champions. It takes a firm position on whether that NPO is who it says it is, and whether funds are reaching the intended recipients.
02
Collective safety over individual cases
Decisions are made with the broader platform ecosystem in mind — not just the organization under review. A pattern that looks minor in isolation may be part of a coordinated scheme across multiple entities.
03
Objective, precedent-aware action
Every decision sets a precedent. The scoring model takes emotion out of the equation by anchoring outcomes to documented signals — making it possible to act consistently, explain clearly, and defend confidently.
01 Risk calculator Select factors present in the investigation
platform-integrity / npo-risk-calculator
NPO risk scorer Beta
Investigation agent
Case reports
Low — no action
Moderate — RFI/EDD
High — suspend
Critical — terminate

NPO Risk Scoring Calculator

Portfolio demo
Portfolio demonstration only. Scoring weights and thresholds are intentional placeholders — they do not reflect any real organizational methodology, proprietary process, or production system. Designed to help practitioners in the NPO/CSR space structure their investigative thinking.
Recommended action
LowModerateHighCritical
Auto-escalation triggered. One or more factors override the total score. Escalate immediately regardless of other findings.

Decision logic

Why four tiers

Low — no action
The platform does not action on discomfort or low-signal noise alone. A low score may still warrant monitoring, but it does not justify restricting an organization's access. Emotional reactions to isolated complaints are not a basis for action.
Moderate — request for information
Something warrants a closer look, but the evidence isn't there yet. A Request for Information (RFI) or Enhanced Due Diligence (EDD) gives the organization an opportunity to respond before any restrictive action is taken.
High — suspend with right to appeal
The weight of evidence supports a restriction, but legal frameworks including the Digital Services Act (DSA), GDPR, and DORA require an appeals mechanism. Suspension is not termination — the organization retains the right to contest the decision.
Critical — terminate, no appeal
Reserved for the most severe cases only: confirmed fraud, sanctions exposure, active law enforcement involvement, or confirmed identity misrepresentation. The bar is deliberately high — termination without appeal is a significant action and must be fully defensible.
Back to portfolio