
Companies can verify nonprofits at scale by separating identity, regulatory status, sanctions, program eligibility, and payout readiness into repeatable checks. The process should run at onboarding, monitor changes, recheck before disbursement, and preserve the source, date, result, and reviewer for every decision.
Verification is not one universal badge. The evidence required for a product discount, corporate grant, cause marketing campaign, customer donation, or platform payout can differ, so companies need a policy tied to each use case.
Start with identity. Match legal name, employer identification number or other registration number, address, aliases, and authorized contacts. Display names are not reliable unique identifiers.
For U.S. organizations, use the IRS Tax Exempt Organization Search and associated data to evaluate federal tax-exempt status, deductibility, filings, and automatic revocation.
Check the state sources required by the program. A cause campaign or online platform may need charity registration or good-standing checks in addition to IRS status. California, for example, publishes a list of charities that may not operate or solicit.
Screen applicable sanctions and watch lists using an approved process. The U.S. Treasury's OFAC search tool covers the Specially Designated Nationals list and non-SDN consolidated lists, but a company should define how it reviews and resolves possible matches.
Add program-specific requirements last. Geography, public charity classification, mission, nondiscrimination policy, financial thresholds, grant restrictions, bank ownership, and supporting documents may matter to one program but not another.
Manual review can work for a small, infrequent list. It becomes difficult when the company must check thousands of organizations, combine several sources, monitor changes, support business users, and explain every result later.
Names create false matches and duplicates. Organizations can use abbreviations, assumed names, local chapter names, fiscal sponsors, or old names. A reviewer who searches by display name alone can approve the wrong entity.
Sources update on different schedules and use different identifiers. A federal record may be active while a state registration is delinquent. A bank record may not match the legal entity. A sanctions search may require human resolution.
Point-in-time spreadsheets become stale. The IRS automatically revokes federal status when a required organization fails to file for three consecutive years, and state status can change after onboarding.
Inconsistent reviewer judgment also creates fairness and audit problems. Two employees may reach different results from the same evidence when the policy does not define required sources, match thresholds, escalation, and exceptions.
| Stage | Core check | Output |
|---|---|---|
| Identity | Entity and identifier | Canonical record |
| Eligibility | Tax and state status | Decision |
| Risk | Sanctions and exceptions | Review queue |
| Monitoring | Status changes | Alert |
| Payout | Fresh eligibility check | Release or hold |
Source: IRS, OFAC, state regulator guidance, and Change verification workflow. Reviewed September 24, 2026.
Normalize source data into one nonprofit record without hiding provenance. Each field should retain the source, retrieval time, raw value, normalized value, and transformation rule.
Use deterministic rules for routine outcomes and a human review queue for ambiguous identity matches, conflicting sources, sanctions candidates, missing documents, or policy exceptions.
Return reason codes instead of a bare pass or fail. A business user should know whether the issue is federal revocation, state delinquency, sanctions review, unsupported geography, missing documentation, or a program-specific rule.
Monitor approved organizations and trigger review when a source changes. Decide whether the program pauses new activity, holds a payout, contacts the nonprofit, requests documents, or permits a defined grace period.
Evaluate source coverage, update frequency, identity resolution, API reliability, batch processing, reason codes, manual review, monitoring, audit history, security, privacy, and support. Ask the provider to demonstrate edge cases, not only a clean active charity.
Confirm how the service handles fiscal sponsors, chapters, name changes, mergers, automatic revocations, state deficiencies, sanctions candidates, international organizations, and organizations that cannot receive electronic payment.
Check the output against the company's actual policy. A broad directory is useful, but the company still needs to define which organizations qualify for each program and which sources are legally required.
Change's nonprofit verification product supports access to more than 1.3 million U.S. nonprofits, configurable eligibility data, recurring monitoring, and checks before disbursement. Confirm the current coverage and implementation for the intended use case during evaluation.
Teams building donation products can also review the donation integration guide for the records and exception states that connect verification to checkout, receipts, refunds, and payouts.
Begin with a written scope that identifies the legal entities, program owners, users, nonprofit population, jurisdictions, solicitation channels, funds flow, vendors, and launch date. A clear scope lets counsel and operations distinguish the rules that apply from controls that are simply good practice. Record open questions and the person responsible for resolving each one.
Create a source register for every recurring decision. For federal tax information, use the IRS Tax Exempt Organization Search and retain the date and result. For state requirements, use the National Association of State Charity Officials directory to locate the responsible regulator, then link the current form, instruction, statute, or guidance. Note that databases can update on different schedules and may use different organization identifiers.
Translate the research into a control matrix. For each requirement, document the trigger, jurisdiction, owner, due date, evidence, renewal rule, exception path, and review date. Connect the matrix to the underlying agreement, consent, registration, disclosure, transaction ledger, receipt, payout, accounting, complaint, and report. A status such as complete should always point to evidence.
Use technology for repeatable collection, validation, reminders, and records while preserving human review for classification and exceptions. Change's charitable registration workflows can help organize multistate filing data, and its nonprofit verification tools can support identity and eligibility checks. The organization and its advisers remain responsible for the policy and legal conclusions.
Set change triggers before launch. Re-review the workflow when the product, public language, nonprofit, state coverage, payment path, vendor, fee, or campaign mechanic changes. Monitor regulator notices, filing deficiencies, status changes, complaints, failed payouts, and unreconciled balances. Schedule a periodic control test in addition to deadline reminders, because a timely filing does not prove that customer disclosures, records, calculations, and disbursements still match the approved program.
Keep the current matrix accessible to every operational owner.
Not always. The program may also require state standing, sanctions screening, organizational documents, bank verification, or its own eligibility criteria.
Check at onboarding, monitor on a defined schedule, and recheck at material events such as campaign launch or payout when required by the program or law.
Routine matches and clear outcomes can be automated. Ambiguous identities, conflicting sources, sanctions candidates, and exceptions need documented human review.
Return the canonical identity, source-specific status, reason code, source date, decision time, policy version, and any review or expiration state needed by the product.
Follow the approved policy for pausing activity, holding or redirecting funds when legally permitted, contacting the organization, resolving the issue, and documenting the outcome.
This article provides general information, not legal advice. Verification requirements depend on the program, jurisdiction, funds flow, and risk policy.

.png)
