A donor gives ten million riyals for winter kit distribution. A grant of three million comes with restrictions to health programmes. General donations sit in an unrestricted pool. The staff canteen bill hits at the end of the month.

A weak system produces one report at year-end that tries to reconstruct which riyal went where. A strong system refuses the canteen bill against the winter fund before the button is even pressed.

Enforce at the transaction layer

A disbursement without a matching donor budget line does not compile. This is the entire principle. The system does not warn; it does not colour the row yellow; it does not queue a compliance review. It rejects.

That single design decision removes an entire class of auditor headaches and, more importantly, an entire class of accidental breaches. The finance team stops being the last line of defence against a mistake.

What has to be in the model

A donor entity. A fund with restrictions attached (or explicitly unrestricted). A budget expressed as a set of allowable expense categories, projects, and locations. Every payable references a fund; every payment traces to a budget line.

When the model is right, reporting is a query. When the model is wrong, reporting is an argument.