How to Organise NGO Compliance Documents Digitally
November 28, 2025
A governance meeting at a small Indian NGO usually has the same shape. A trustee asks for the annual return. Somebody produces a printed copy from a folder on a shelf. The finance trustee asks for the last three grant utilisation reports. There is a pause, because they were emailed in March and nobody has replied. The meeting moves on.
Nothing here is a governance failure. The records exist. The problem is that finding them is manual, and manual means it depends on one person's memory, and memory is the least reliable document store in the building.
Why this matters more than it sounds
Compliance documentation has a specific property: it is needed rarely, urgently, and often by someone who was not there when it was created. That combination is exactly where paper and memory fail.
The realistic failure modes we see are all mundane. A registrar asks for Form 8 and it cannot be located. A funder's compliance clause requires evidence of expenditure and the finance team reconstructs it from a bank statement over a weekend. A new trustee arrives and it takes two weeks to establish what decisions the board has actually taken. A statutory filing deadline is met, but only after a phone call to a former employee.
None of these are dramatic. All of them are avoidable, and all of them consume disproportionate time in an organisation that does not have spare time.
Know what you are actually required to keep
Before organising anything, separate what you must retain from what you merely tend to keep. The list below is a practical starting point for an Indian NGO. The specifics depend on your legal form, your funding agreements and your state registration, so confirm the position for your organisation rather than adopting this wholesale.
Registration and legal identity
- Trust deed, memorandum of association or society bye-laws, as applicable.
- Registration certificate and all amendments.
- 12A and 12AB approval correspondence, with validity dates.
- FCRA registration certificate, prior approval letters and validity dates.
- PAN and TAN records.
- Darpan registration, where applicable.
Governance
- Minutes of board, trustee and general body meetings, with attendance.
- Annual returns and their filing acknowledgements.
- Trustee and office bearer appointments, with terms.
- Conflict of interest declarations.
- Constituent or member records where you have members.
Finance
- Audited financial statements for every year, filed with the auditor's report.
- Books of accounts and ledgers, retained per statutory requirements.
- Bank statements and reconciliation records.
- Fixed asset registers.
- Donor contribution records with receipts issued.
Programme and funding
- Grant agreements and MoUs, including every funder-specific compliance clause.
- Utilisation certificates and progress reports as submitted.
- Correspondence where it evidences a funder commitment or a variation.
- FCRA annual returns and the Form FC-4 filings.
- Procurement records for grants that require them.
People and safeguarding
- Staff and volunteer files, including background check records where the role requires them.
- Child protection policy and any incident records, subject to strict access control.
- Training records.
- Data protection documentation, including your record of processing activities.
That last group needs saying explicitly: incident records and case notes are not "compliance documentation" to be moved into shared storage and broadly accessible. They need tighter access control than your audited accounts, not looser.
A structure that survives
Two decisions. Where things live, and who can reach them.
One location, named by function
One shared storage location, structured by function rather than by year or by person. Nine top-level folders is the right order of magnitude: governance, registration, finance, grants, people, programme, policy, compliance correspondence, and a small archive.
Within grants, structure by funder with the year inside. Within programme, by programme with the year inside. This is the structure that answers the question people actually ask, which is "everything to do with this grant".
Naming that makes search work
Filename conventions do more for findability than any folder depth. A predictable pattern beats perfection. For example:
[Funder]_[Type]_[Subject]_[FinancialYear]_[Version], giving something like Infosys_Utilisation_Q2_FY2025-26_v2.pdf.
Version discipline is the harder half. One current file, previous versions moved out of the current folder rather than accumulating as final_v2_REVISED_actually_final.xlsx.
Two tiers of access, deliberately
Most of the material above is appropriate for a broad internal audience. Some of it is not. Draw the line explicitly:
- Broad access. Registration documents, audited statements, minutes, policies, utilisation reports.
- Restricted access. Beneficiary records, case notes, incident reports, staff personal files, donor KYC and bank details, anything under a funder confidentiality clause.
Write down which folder is which and who is in each group. An access model that exists only in somebody's head is not an access model.
The habits that matter more than the software
- File it, do not forward it. Every attachment somebody emailed should end up in the right folder with the right name. Forwarding is how documents die.
- File it within a day. A stack of unfiled documents on one laptop is not a filing system, it is a delay system.
- One person owns the structure. Not the governance committee. One person who decides where things go.
- Meeting papers go out in advance. Circulated three days before, numbered, with an agenda. This single change removes most of the pressure that leads to documents being produced in a panic during a meeting.
- File the acknowledgement too. The filing receipt is often the only proof you met a deadline. It goes in the same place as the document.
- Paper where it matters. Your deed, your registration certificates and your governing document should exist in physical form as well as digitally, in a fire-resistant place, regardless of what the technology is.
Retention, and what to throw away
An archive that only grows becomes an archive nobody searches, so it stops working the way a filing system is supposed to. Keep by statutory requirement where one applies, otherwise adopt a stated rule.
In practice, a small organisation can usually discard working copies of superseded documents, duplicates where no unique signature or annotation is lost, and drafts after the final version is filed. What it should never discard without a decision is the record that something was submitted, what was submitted, and when.
Write the rule down and apply it on a schedule. Most small NGOs have never consciously deleted anything, and that has a cost in search quality and in the risk of retaining beneficiary data longer than they should.
A ninety-minute audit you can do on your own
- Write down every place you know records might be: shared drives, individual laptops, email inboxes, WhatsApp, paper files, the freelancer's drive.
- Check what proportion of your required documents you could produce within one hour, without asking anyone.
- Find any document that exists in exactly one place.
- Check who has access to the folder holding beneficiary and staff records, and whether that list matches your current staff list.
- Identify your next three statutory or funder deadlines and confirm each document is already locatable.
- Write down the naming convention and put it where people will actually see it.
- Agree who owns the structure going forward, by name.
Step two produces the number that matters. If you can produce your last audited statements and your current grant utilisation reports within an hour without asking anyone, your filing system is working. If you cannot, no software purchase will fix it until the structure and the habits are in place.
Want a second pair of eyes on how your organisation actually stores records? Ask digiSarathi about a fractional CTO assessment.