For NGOs operating in sanctioned and conflict-affected jurisdictions

Your compliance program shouldn't be built for the first time when a bank, donor, or auditor asks to see it.

The Conflict-Zone Compliance Operating System is a deployable operating framework for NGOs operating in complex, sanctioned, and conflict-affected environments.

Built from twenty years of donor-side oversight and field leadership — including experience on both sides of the vetting table.

The problem

Most organizations find out what they don't know at the worst possible moment.

  • A correspondent bank asks how you screen counterparties.
  • A donor wants to see the decision trail behind an elevated-risk partner.
  • A board member asks who actually has authority to decline restricted funding.
  • A country team needs to know whether a transaction can proceed tomorrow.

These are bad moments to discover that the policy exists, but the operating system behind it doesn't.

In sanctioned and conflict-affected environments, compliance has to work under pressure — across field operations, finance, partnerships, donor requirements, banking relationships, leadership decisions, and board oversight.

The question isn't simply whether your organization has policies. It's whether your organization can show how compliance decisions are actually made, documented, escalated, reviewed, and defended.

Why this is different

Built from both sides of the vetting table.

The Conflict-Zone Compliance Operating System was developed from experience both assessing organizational risk and managing operations inside complex humanitarian environments.

On the donor side, Impact Signal founder Paul Wagner spent six years inside the U.S. Government's Syria humanitarian response with USAID's Bureau for Humanitarian Assistance, first as Syria Program Coordinator and later as Syria Team Lead. His work included NGO vetting, partner-risk assessment, donor oversight, and leadership responsibility across a large and complex humanitarian portfolio.

On the field side, his experience includes serving as Country Director in Eritrea and Sudan and Chief of Party in Pakistan, alongside broader operational leadership across Africa, Asia, and the Middle East.

The system reflects both perspectives:

What does a funder, bank, auditor, or regulator need to see?

And:

What can an NGO realistically operate in a difficult field environment?

The result is not a theoretical compliance framework. It is a system designed to be used.

What's inside

One system. Three working components.

The Conflict-Zone Compliance Operating System combines doctrine, deployable controls, and working tools so organizations can understand the standard, install the system, and produce evidence through normal operations.

01

Field Manual

Know what good looks like.

94 pages of doctrine, reasoning, and practical guidance. Designed as a working reference rather than a training course.

  • enterprise compliance programme design and board governance
  • sanctions and counter-terrorism controls
  • country files covering Gaza, Syria, Yemen, Sudan, Somalia, Afghanistan, Lebanon, Iran, and Eritrea
  • financial crime, bribery, and partner-fraud typologies drawn from real cases
  • organizational profile risk, including faith-affiliated, diaspora-led, nationally led, and federated structures
  • guidance written from both funder and partner perspectives
  • a five-stage compliance maturity model
  • a three-year organizational development path
  • ten practical appendices
02

Operating Kit

Install the system.

47 pages designed to turn compliance principles into organizational practice.

  • eight adoptable policies
  • named control owners
  • defined evidence locations
  • review cadences
  • a six-phase, 180-day deployment path
  • sanctions-screening workflows
  • screening service levels down to the hour
  • a donor-acceptance framework designed so refusal is actually possible
  • escalation and decision structures
  • a board reporting pack built to support decisions, not simply report activity
03

Working Tools Workbook

Run it — and produce the evidence.

An 18-tab, formula-driven Excel workbook that turns routine compliance operations into an evidence trail.

  • donor-acceptance scoring
  • partner-risk tiering
  • screening alert logs
  • automatic service-level tracking
  • escalation records
  • board metrics populated from operational data
  • compliance maturity assessment
  • 18 evidence-based maturity test statements

The workbook is designed so that operating the system helps produce the evidence file a donor, bank, board, or auditor may later ask to see.

Together

Understand the standard Install the controls Operate the system Produce the evidence.

Proof of depth

Built around the hard cases.

The case studies are drawn from real vetting decisions and real partner-fraud patterns rather than generic hypotheticals.

Medical-sector examples are used deliberately because humanitarian health programming concentrates many of the hardest compliance challenges in one operating environment:

  • pharmaceutical diversion
  • cold-chain integrity
  • dual-use equipment
  • health-worker payroll
  • procurement risk
  • partner oversight
  • operations involving contested or de facto authorities

The cases are sector-specific. The reasoning is designed to transfer.

What changes

From compliance documents to a compliance operating system.

After deployment, your organization has a defined way to:

  • 01screen and escalate higher-risk counterparties
  • 02document sanctions and partner-risk decisions
  • 03assess whether new funding should be accepted
  • 04assign ownership for core compliance controls
  • 05establish evidence locations and review cadences
  • 06give leadership and the board meaningful compliance visibility
  • 07maintain an evidence trail for donor, bank, and audit scrutiny
  • 08identify where the compliance program needs to mature next

The objective is not more policy. It is a compliance system your organization can actually operate.

Who this is for

Built for organizations where compliance has become operational.

Strong fit

Typically, organizations that:

  • For organizations that need to build compliance infrastructure, and organizations that already have it but need it to work better.
  • operate directly or through partners in jurisdictions where designated entities, de facto authorities, armed groups, sanctions, or access constraints create elevated compliance exposure
  • have meaningful institutional donor, banking, partner, or board accountability
  • need a system that can operate without building a large standalone compliance department

Often there is a specific trigger:

  • a new institutional donor with enhanced vetting requirements
  • a correspondent bank asking questions
  • expansion into a higher-risk jurisdiction
  • a compliance near miss
  • a new Executive Director, Country Director, CCO, or board chair
  • a failed or difficult audit
  • rapid organizational growth
  • donor diversification that has outpaced existing controls

Probably not a fit

Organizations whose operations are:

  • domestic-only or confined to relatively low-risk jurisdictions
  • already supported by a mature, fully staffed enterprise compliance function
  • looking only for generic compliance training
  • seeking a document that can be adopted without organizational adaptation
  • interested in “improving compliance” but without the leadership commitment or operational capacity to implement a functioning system
Honest positioning

No one can promise you compliance.

And anyone who does should be the first thing you distrust.

The Conflict-Zone Compliance Operating System doesn't make that promise either.

What it is designed to do is dramatically reduce the work required to stand up a structured, defensible compliance program and organize that work so your organization produces the evidence a bank, donor, board, or auditor may actually ask to see.

The system requires adaptation to your organization's circumstances.

Policies and controls should be reviewed by your organization's own legal counsel before formal adoption where appropriate.

That's not a limitation of the system. It's how a credible compliance system is supposed to work.

Choose your level of support

Start with the system. Add support where you need it.

The Kit

USD 1,150

For organizations with the internal expertise and capacity to deploy independently.

Includes

  • Volume I: Field Manual
  • Volume II: Operating Kit
  • full Working Tools Workbook
  • single-entity licence
Most organizations start here

Kit + Deployment

USD 2,950

For teams that want the system and experienced guidance installing it. Includes everything in The Kit, plus three guided working sessions focused on adapting and installing the system within your organization.

Use the sessions to work through

  • organizational context and priority exposures
  • implementation sequencing
  • ownership and governance
  • adaptation of key controls and workflows
  • practical deployment questions

This is the core offering for organizations ready to move from compliance documents to an operating system.

Need more hands-on support?

The Kit can become the foundation for a broader compliance function.

For organizations that want hands-on delivery rather than a primarily self-directed rollout, additional support is available.

Six-Month Implementation Advisory

USD 12,000

Hands-on delivery of the full 180-day deployment path across two three-month implementation blocks.

Ongoing Advisory

from USD 3,500 / month

Post-deployment support for organizations that need continued compliance advisory, board-pack review, working sessions, or additional operational support.

Extension Modules

USD 450–500 each

Additional modules developed around specific areas of organizational risk and confirmed client demand, including:

  • Cash and Voucher Assistance
  • Country Deep Dives
  • Procurement and Supply Chain Integrity
  • Safeguarding / PSEA
  • Board and Executive Briefing
Get in touch

Operating in a high-risk environment?

Whether you're evaluating the Kit, responding to a specific compliance trigger, or trying to understand where your current system may be exposed, tell us a little about your situation.

You don't need to know which level of support you need before getting in touch.