Contact Us

Update Record

VersionDateOwnerApprover
1.0October 16, 2025Risk Assurance LeadBoard of Directors

SOP Details

Business Function
Ethics, Compliance, and Safeguarding Policy
Relevant Teams
All staff, volunteers, contractors, board members, partners, and vendors acting on behalf of Kilimora CLG
Policy Owner
Risk Assurance Lead
Current Version
1.0 — October 16, 2025
Geographic Scope
Kenya, Rwanda, Tanzania, Uganda, and all future expansion markets
Review Cycle
Annual — or upon material regulatory, safeguarding, or donor requirement changes

Purpose and Scope

This Ethics, Compliance, and Safeguarding Policy establishes Kilimora CLG's commitment to conducting operations with integrity, protecting vulnerable populations, ensuring regulatory compliance, and maintaining ethical standards in all organisational activities. The policy provides a comprehensive framework for ethical decision-making, safeguarding mechanisms protecting beneficiaries and staff from harm, compliance systems ensuring adherence to legal and donor requirements, and risk management processes identifying and mitigating threats to organisational mission and sustainability.

This policy applies universally to all individuals and entities associated with Kilimora CLG and covers all organisational activities including programme implementation, business development, financial management, human resources, technology operations, and stakeholder engagement.

Acknowledgment Requirement
All personnel must acknowledge receipt and understanding of this policy through signed forms maintained in personnel files. Acknowledgments are renewed annually. Failure to acknowledge may result in access restrictions until acknowledgment is completed.
Non-Compliance Consequences
Violations may result in criminal liability, civil fines, termination of donor funding, reputational damage, and disciplinary action up to and including immediate dismissal and referral for prosecution. Senior leadership and the board of directors bear ultimate responsibility for policy implementation and enforcement.

All personnel must conduct themselves professionally and ethically in all organisational activities and interactions with stakeholders. Conduct standards apply during working hours, at organisational events, in field locations, and in any settings where persons represent the organisation.

01
Respect and Dignity
All individuals treated with courtesy, fairness, and consideration regardless of background. Discrimination, harassment, or abusive conduct based on any protected characteristic is strictly prohibited.
02
Professional Competence
Duties performed diligently, skills maintained, guidance sought when uncertain. Negligence or reckless disregard for duty constitutes an ethical violation particularly when affecting beneficiary services.
03
Integrity in Relationships
Honest, transparent communication with all stakeholders. Accurate information provided, errors corrected promptly, commitments fulfilled. Deception or misrepresentation damages trust even when motivated by perceived benefit.
04
Confidentiality
Sensitive information safeguarded including beneficiary data, donor information, financial records, and strategic plans. Personnel leaving the organisation remain bound by confidentiality obligations.
05
Conflicts of Interest
Financial interests in vendors, family relationships with contractors, outside employment, gift acceptance, and romantic relationships with subordinates must be disclosed. Unmanageable conflicts may require employment termination.
06
Use of Resources
Organisational equipment, funds, facilities, and information used only for work-related purposes. Prohibited misuse includes theft, unauthorised vehicle use, and conducting outside business using organisational resources.
Substance Abuse
Personnel must report to work free from influence of alcohol or illegal drugs. Possession, distribution, or use of illegal drugs on organisational premises results in immediate termination and potential law enforcement notification.

Safeguarding encompasses all measures protecting beneficiaries, particularly children and vulnerable adults, from harm caused by organisational activities, personnel conduct, or failures to prevent foreseeable risks. Safeguarding responsibilities apply to all personnel regardless of role.

01
Child Safeguarding
Protects individuals under 18 years from all forms of harm including physical, emotional, and sexual abuse, neglect, and exploitation. Photography of children requires parental consent. Personal contact information exchange between personnel and beneficiary children is prohibited.
Child Protection
02
Sexual Exploitation and Abuse Prevention
Any actual or attempted abuse of position for sexual purposes is prohibited including sexual activity with beneficiaries regardless of consent, and transactional sex where assistance is conditioned on sexual favours. Power differentials make genuine consent impossible when one party controls access to services.
Zero Tolerance
03
Background Screening
All positions involving beneficiary contact require criminal record checks, reference verification, and employment history confirmation. Candidates with histories of violence, sexual offences, fraud, or other disqualifying conduct are not hired regardless of qualifications.
Pre-Employment Required
04
Incident Response — 24-Hour Mandatory Reporting
Personnel witnessing or receiving reports of abuse must report immediately to supervisors, the Chief Executive Officer, or the board chairperson. Immediate actions prioritise victim safety including medical attention, psychological support, separation from alleged perpetrators, and law enforcement notification for criminal conduct.
24 Hours Maximum
Feedback and Complaints Mechanisms
Multiple reporting channels are available: in-person communication with field staff, telephone hotlines with translation services, written complaints to project offices, SMS messaging to dedicated numbers, and community meeting forums. Retaliation against complainants is strictly prohibited and itself constitutes serious misconduct warranting termination.

International sanctions restrict financial transactions and business relationships with designated individuals, entities, and countries. Sanctions violations carry severe consequences including criminal penalties, civil fines, reputational damage, and donor funding termination.

Sanctions Regime
UN Security Council
Binding on all member states. Cross-referenced against OFAC, EU, and Kenyan sanctions lists in consolidated screening.
Screening Frequency
Quarterly
All active counterparty relationships rescreened quarterly. Automated alerts notify Finance Manager when sanctions list updates match organisational counterparty names.
Pre-Engagement
Before All
Partners, vendors, consultants, and beneficiaries screened before establishment of any financial or operational relationship. Chief Commercial Officer approves results.
Violation Response
Immediate
Transaction suspension, internal investigation, self-disclosure to appropriate authorities, and remedial process improvements including enhanced screening and staff training.
Enhanced Due Diligence
Screening covers not only direct counterparties but also beneficial owners, family members of designated individuals where sanctions specify such extensions, and geographic locations where sanctioned parties operate. Transactions involving sanctioned goods or services are prohibited even when parties themselves are not designated.

Fraud encompasses intentional deception for personal gain including asset misappropriation, financial statement manipulation, corruption, and identity theft. Prevention relies on strong internal controls, ethical organisational culture, and detection mechanisms identifying anomalies suggesting fraudulent activity.

Key Controls Framework

Control Area Mechanism Threshold / Frequency Responsibility
Dual Approval All expenditures require two-signatory authorisation Above $500 Finance Manager + CEO
Bank Transfers Online dual authorisation through banking system All transfers Finance Manager initiates; CEO approves
Audit Log Review Transaction logs checked for anomalies Monthly Finance Manager
Payroll Reconciliation Payroll register vs HR records comparison Each cycle Finance Manager + HR
Petty Cash Surprise counts by Finance Manager Random Finance Manager
Vendor Due Diligence Legitimacy verification before payment All new vendors Finance Officer
Fraud Red Flags — Report Immediately
Lifestyle changes inconsistent with salary, reluctance to take vacations, unusual closeness to vendors, defensive behaviour when questioned about transactions, unexplained accounting discrepancies, and anonymous complaints alleging financial misconduct must all be reported to management immediately.

Comprehensive risk management identifies, assesses, mitigates, and monitors threats to organisational mission achievement, sustainability, reputation, and stakeholder interests. Risks span strategic, operational, financial, compliance, and reputational categories.

ID
Risk Identification
Quarterly risk workshops, board strategic planning sessions, project planning processes, and stakeholder consultations. Multiple mechanisms capture diverse perspectives about potential threats.
AS
Risk Assessment
Likelihood and impact evaluated using consistent criteria enabling prioritisation. Risk scoring multiplies both ratings — highest-scored risks receive greatest management attention and resource allocation.
MT
Risk Mitigation
Avoidance, reduction, transfer, or acceptance depending on risk nature and organisational tolerance. Controls implemented as preventive, detective, or corrective measures appropriate to each identified risk.
"Risk appetite is conservative for compliance and safeguarding where violations cause severe consequences, moderate for operational risks inherent in programme delivery, and higher for strategic risks necessary for innovation and growth."
Kilimora CLG — Risk Appetite Statement, 2025
Risk Tolerance Thresholds
Fraud losses exceeding $5,000 trigger mandatory board escalation. Safeguarding incidents causing serious harm require immediate CEO and board notification. Compliance violations risking donor funding loss require external legal counsel engagement within 48 hours. Annual tabletop exercises test crisis response plan effectiveness.

Regulatory compliance encompasses adherence to all applicable laws, regulations, donor requirements, and voluntary standards governing organisational operations. Compliance obligations span company law, employment law, tax law, data protection, anti-money laundering, counter-terrorism financing, procurement regulations, and donor terms.

Obligations Inventory
All legal and regulatory requirements documented in centralised registry. Legal counsel reviews annually confirming completeness and incorporating recent legislative developments.
Monthly Monitoring
Compliance checklists verify completion of recurring obligations including tax filings, regulatory reports, and donor financial reporting.
Quarterly Reviews
Higher-level obligations assessed including policy updates for regulatory changes, training completion verification, and control testing confirming effectiveness.
Annual Audits
Internal or external auditors provide independent assurance about compliance programme adequacy and identify deficiencies requiring remediation.
Donor Compliance
Finance Manager maintains compliance files for each grant including original agreements, approved budgets, and correspondence documenting donor approvals. Pre-expenditure reviews verify allowable costs before processing.
Violation Response
Immediate corrective action suspending non-compliant activities. Root cause analysis informs response. Serious violations disclosed to regulators and donors per self-reporting obligations.

Personal data protection safeguards information privacy rights of beneficiaries, employees, partners, and other stakeholders. Kilimora complies with the Kenya Data Protection Act 2019, Rwanda Law on Protection of Personal Data and Privacy, and GDPR principles where applicable.

01
Lawful Processing
Consent must be freely given, specific, informed, and unambiguous before data collection. Sensitive data including health information and biometric data requires explicit separate consent.
02
Data Minimisation
Collection limited to information necessary for specified purposes. Registration forms collect only essential information. Aggregate data used where individual-level data is unnecessary for analysis.
03
Data Security
Complex passwords changed quarterly, encryption for sensitive data, access controls, backup systems, confidentiality agreements, clear desk policies, and locked filing cabinets for paper records.
04
Data Subject Rights
Individuals may access personal data, request corrections, object to processing, request deletion, and receive data in portable formats. Rights requests processed within 30 days with identity verification.
05
Breach Response
Immediate containment isolating compromised systems and changing access credentials. Impact assessment determines breach severity. Statutory notifications fulfilled within required timeframes for serious breaches.
06
Sovereignty Commitment
Kilimora's commitment to data sovereignty means farmers own their data and control how it is used. Communications must reflect farmers as active agents, not passive recipients of services.

Whistleblowing mechanisms enable personnel, beneficiaries, partners, and stakeholders to report concerns about policy violations, legal non-compliance, safeguarding risks, or misconduct. Multiple reporting channels ensure no concern goes unreported. The organisation investigates all reports promptly and protects whistleblowers from retaliation.

Channel 01
Direct Supervisor
First point of contact for transparent reporting when comfortable. Escalation to department heads or senior management for concerns involving supervisors.
Channel 02
CEO Confidential
Dedicated email at hello@kilimora.africa monitored exclusively by CEO and board chairperson for sensitive or senior-level concerns.
Channel 03
Anonymous Hotline
Third-party operated web portal providing translated services for anonymous submissions. Anonymous reports accepted — identity not required to trigger investigation.
Channel 04
Board Audit Committee
Written communication to board audit committee chairperson for concerns involving executive management. Highest governance escalation pathway.
Whistleblower Protection — Zero Retaliation Policy
Retaliation is strictly prohibited including employment termination, demotion, salary reduction, reassignment, exclusion from meetings, or social ostracism motivated by reporting. Protection extends to reasonable but mistaken beliefs about policy violations. Retaliation complaints trigger separate investigations with disciplinary action against retaliating parties including termination.
Investigation Standards
All reports are assessed for credibility, urgency, and appropriate investigation approach. Investigations include document review, witness interviews, forensic analysis where financial misconduct is suspected, and legal counsel consultation regarding potential law violations. Accused individuals are informed at appropriate stages and provided opportunity to respond. Investigation findings are documented in written reports with disciplinary recommendations.

This policy undergoes annual review assessing continued adequacy, incorporating regulatory changes, addressing lessons learned from incidents, and adopting evolving best practices. Review processes include staff consultations, donor requirement alignment, legal counsel review, and peer benchmarking.

01
Annual Review Process
Staff consultations gathering frontline perspectives, donor requirement alignment ensuring policies meet funding source expectations, legal counsel review confirming regulatory compliance, beneficiary feedback incorporation ensuring protection mechanisms prove effective, and peer benchmarking identifying improvement opportunities.
Annual Cycle
02
Amendment Approval Process
Policy amendments require board audit committee recommendation and full board approval. Proposed amendments circulate to board members 14 days before approval meetings. Emergency amendments addressing urgent compliance or safeguarding issues may be implemented by CEO pending board ratification at next scheduled meeting.
Board Approved
03
Distribution and Training
Updated policy versions distributed to all staff with training on material changes. Approved amendments documented through board resolutions noting effective dates and superseded provisions. Annual refresher training updates all staff on regulatory changes and lessons learned from compliance incidents or audit findings.
All Personnel
Policy Questions & Reporting
General enquiries and policy clarifications: hello@kilimora.africa
Baraza Media Lab, Keystone Park, 95 Riverside Drive, Nairobi, Kenya