MI MOHAMUD IBRAHIM · FIELD FILE ← Exit to Articles
For Review
File No. 026 — Horn of Africa MEAL Series

5 Signs Your M&E System Won't Survive a Donor Audit

A practitioner's checklist, built from evaluation and MEAL assignments across Mogadishu, Puntland, Jubbaland, Galmudug, and South-West State — where access, not budget, is usually the real constraint.

Page 01 / 05

The audit doesn't break the system. It just finally looks at it.

In donor-funded programming across the sector — whether EU, UK aid, GIZ, or UN-funded — the same question eventually comes from a compliance or audit team: can you show me where this number came from? Whether it's a formal compliance audit, a data spot-check, or an evaluation assessed against OECD-DAC criteria, the underlying test is the same: can this be defended, not just reported.

In Somalia's operating environment, that question is harder to answer than it looks. Access is uneven across Banadir, Puntland, Jubbaland, Galmudug, and South-West State; security and clan dynamics shape which communities field teams can physically reach; climate shocks and drought cycles can shift a data collection window with almost no notice; and weak local administrative systems mean the population registries and sampling frames other contexts take for granted often don't exist. Displacement disrupts the same-household tracking that baseline-to-endline comparisons depend on. And because international staff frequently manage programmes remotely, a large share of data collection runs through local enumerators and partners who themselves turn over often — which is exactly why several of the flags below are as much about people as they are about data.

None of that is an excuse an auditor will accept — and it shouldn't be. A monitoring system that can't survive contact with Somalia's realities usually wasn't built around those realities in the first place; it was likely built around a standard template, then adapted on the fly once the programme was already underway. What follows are six weaknesses worth checking for in any Somalia-based MEAL system, drawn from common patterns across the sector — before a donor ever asks the hard question first.

Field note A system that "worked fine" for eighteen months of donor reporting can still fail an audit in a single afternoon. Reporting cadence and audit-readiness are not the same test — one asks whether the numbers arrived on time, the other asks whether they can be defended.
Page 02 / 05

Where the data trail breaks first

Audit-Flag-01

Indicators can't be traced to raw data

If a number in the report can't be walked back to a source file, it isn't evidence — it's an assertion.

What this looks like in the field Across multiple evaluations, the pattern repeats: a KoboToolbox or SurveyCTO dataset gets cleaned, aggregated, and never archived in a form the original enumerator's submissions — or their metadata: timestamp, GPS stamp, device ID — can be matched against. The report states a confident, round number of households reached. Nobody can produce the underlying rows.
An auditor tests this by picking one reported figure at random and asking to see the raw submission behind it — not the summary sheet.
Audit-Flag-02

Context shifted, and nobody logged it

A signed logframe is a contractual instrument — it shouldn't move without a formal amendment. But the monitoring plan and Theory of Change behind it should be revisited constantly, and any drift documented, not left to memory.

What this looks like in the field Access to a district in Middle Shabelle or Jubbaland shifts mid-programme, forcing a change in delivery approach — but no change log, no dated note, no formal amendment request records it. The original Theory of Change is still what's quoted in this quarter's donor report, quietly disconnected from what actually happened on the ground.
An auditor tests this by asking for the change log behind the monitoring plan — not just the current version of the logframe.
Page 03 / 05

Where good intentions don't hold up

The first two flags are about your data. These next two are about who gets counted, and who's accountable when something breaks.

Audit-Flag-03

GESI lives in the narrative, not the indicators

A paragraph about inclusion in the final report is not the same as inclusion built into the design from day one.

What this looks like in the field No sex- or disability-disaggregated data collected at baseline — often not even using a recognized instrument like the Washington Group Short Set — and no mapping of which communities faced access barriers to begin with. GESI reads as intention, not evidence, and that distinction is exactly what an audit is trained to test.
An auditor tests this by asking for disaggregated baseline figures, not the GESI paragraph in the narrative report.
Audit-Flag-04

One person holds the whole system in their head

If that person leaves, resigns, or is simply unreachable for two weeks, so does your evidence chain. This is what risk managers call key-person risk, and MEAL systems carry more of it than most people admit.

What this looks like in the field Commonly seen across the sector: a single field officer's personal laptop and a spreadsheet only they update. No handover protocol, no shared drive, no second person who could reconstruct how a figure was calculated.
An auditor tests this by asking a second team member — not the system's owner — to walk them through how a figure was produced.
Page 04 / 05

The dashboard nobody uses, and the dataset nobody checked

Audit-Flag-05

The dashboard is polished. Nobody in the field opens it.

A dashboard built for donor optics rather than programme decisions is itself evidence of an accountability gap — which is precisely what auditors are trained to notice.

What this looks like in the field A Power BI or GIS dashboard refreshed monthly for reporting, while field teams are still making real-time decisions off a WhatsApp thread. When asked what the dashboard is for, "reporting" is not the answer that protects the programme.
An auditor tests this by asking a field-level user, unannounced, to pull up the dashboard and use it live.
Audit-Flag-06

Nobody forensically checked the dataset itself

The first five flags are about governance around the data. This one lives inside it — and it's the one most systems never test for at all.

What this looks like in the field GPS coordinates from supposedly independent household interviews clustering at the same point. Near-identical response patterns across respondents who were never in the same room. Partner-submitted figures with no independent spot-check or back-check ever run against them. And, increasingly, qualitative responses that read like they were drafted by a generative AI tool under time pressure rather than collected in the field — a risk few systems have any process for catching at all.
An auditor — or a rigorous data quality assurance exercise — tests this by clustering GPS points, scanning for duplicate or straight-lined responses, and independently re-verifying a sample of partner-submitted records.
Page 05 / 05

Same six weaknesses, side by side with the fix

Audit-Vulnerable
  • Reported figures live only in the final report
  • Context shifts, but nothing gets logged
  • GESI is a paragraph, not a dataset
  • One person is the entire system
  • Dashboard built for donors, not for field use
  • Nobody has ever forensically checked the dataset
Audit-Ready
  • Every figure links to an archived, dated source file
  • Drift is dated, justified, and formally amended
  • GESI disaggregation set before data collection starts
  • At least two people can reconstruct any figure
  • Dashboard used weekly by the people it was built for
  • GPS, duplicates, and partner data are routinely spot-checked

None of these six flags are exotic. They're what happens when a monitoring system is built to satisfy a proposal template rather than to survive contact with a real, moving programme. The fix isn't more paperwork — it's building five things in from the start:

01

A traceable chain, not just a clean number

Every reported figure should link back to an archived, dated source file — not a memory of how it was calculated.

02

A monitoring plan treated as a living document

Revisited at every major context shift, with drift dated, justified, and formally logged — not left to memory.

03

GESI indicators set before data collection starts

Disaggregation and access-barrier mapping built into tools from day one, not added to the narrative afterward.

04

Redundancy, not heroics

At least two people who can reconstruct how any given figure was produced, with data stored somewhere other than one laptop.

05

Routine forensic checks, not blind trust

GPS clustering, duplicate detection, and independent spot-checks of partner-submitted data built into every collection cycle, not added only when something looks wrong.

Closing note None of these six flags require more money to fix — they require deciding, before the audit, what the system needs to survive contact with the field. An audit-ready system isn't built for the auditor. It's built so the people the programme was meant to reach are still the ones the numbers are actually about.