CharityControl.org

Policy templates / Financial Controls Policy

Charity Financial Controls Policy Template (Free, UK)

free template · For Trustees, treasurer, finance staff or volunteers · England & Wales · Sources checked 2026-08-01

Not sure which size? Size it by your charity number

Highlighted parts are yours to complete. A starting point to adapt, not legal advice.

Small charity
Use in CharityControl

1. Purpose and scope

This policy sets out how [your charity] looks after its money and assets, keeps accurate records, and guards against fraud and error. It reflects the trustees' legal duty to manage the charity's resources responsibly.3

It applies to everyone who handles the charity's money, makes payments, or keeps its financial records. It covers all of the charity's income, spending, bank accounts, cash and assets.

The trustees own this policy. The treasurer makes sure it is followed day to day. If your charity has no treasurer, name the person or role that does this.

2. Roles and separating duties

No one person should control a financial transaction from start to finish. Wherever we can, we split the tasks so that a mistake or dishonesty by one person is caught by another. For example, the person who authorises a payment should not also be the only person who sets it up in the bank.

We are a small charity, so we cannot always split every task. Where we can't, the trustees provide the check instead. For example, a trustee who is not involved in day-to-day finances reviews the bank statements and payments. This is a normal and accepted approach for small charities.

  • The treasurer oversees the charity's finances and reports to the trustees.
  • One person prepares payments; a different person or trustee authorises them.
  • Cash and cheques are handled by a named person and checked by a second person.

3. Budget and trustee oversight

The trustees approve an annual budget before the start of each financial year and use it to monitor spending.

At every trustee meeting, and at least quarterly, the trustees receive and discuss a short finance report showing income and spending against budget, the bank balance, and anything unusual. The trustees keep a written record of these discussions in the minutes.

The trustees review any significant difference between the budget and actual figures and agree what to do about it.

4. Income and cash handling

All money the charity receives is recorded promptly and paid into the charity's bank account. We do not pay expenses out of cash received before banking it. These are our cash controls, and other policies point here for them.

  • Cash and cheques are counted by two people where possible, and the amount is recorded and agreed.1
  • Cash is banked promptly, within 5 working days, and kept securely until then.
  • We give a receipt when asked, and keep a record of donations, including any Gift Aid declarations.
  • Online and card income is reconciled to the bank account regularly.

5. Spending, authorisation and payments

All spending must support the charity's purposes and be approved before it is committed.

  • No one may authorise their own expenses, payments to themselves, or payments to a connected person. Those go to another trustee or the chair or treasurer.
  • As a starting point, spending over £500 needs approval by two authorised people, and anything over £5,000 needs trustee approval in advance. Set limits that suit your charity's size and change them as it grows.
  • Every payment is supported by an invoice or receipt, checked against what was ordered or expected before it is paid.
  • Bank payments need two authorisers. We do not use blank signed cheques or share banking passwords or card PINs.

6. Bank accounts and reconciliation

The charity's money is held in a bank or building society account in the charity's name. Personal accounts are never used to hold charity money.

  • The bank mandate requires two people to authorise payments.
  • When someone joins or leaves a role that handles money, the trustees update the mandate and their online banking access. For a leaver, we remove banking and system access on the day they leave the role, under our Data Protection Policy.
  • At least once a year the trustees review the mandate and who has banking and system access, and remove anything no longer needed.
  • The account is reconciled to the charity's records at least monthly, ideally by someone who does not also make the payments.
  • If the charity holds a debit or credit card, the statement is checked each month against receipts.
  • A trustee who is not involved day to day reviews the bank statements and reconciliation periodically and confirms this in the minutes.
  • We limit how much cash we hold and keep any petty cash small, logged and reconciled.

7. Expenses and trustee payments

We reimburse only genuine costs that people have actually paid to carry out the charity's work, supported by receipts. Expense claims are approved by someone other than the claimant.

Trustees may claim legitimate out-of-pocket expenses but are not paid for being trustees unless the governing document or the Charity Commission specifically allows it. Any payment to a trustee or connected person is authorised, declared and recorded under our Trustee Expenses Policy, which sets out the authority test and how such payments are disclosed in the accounts.7 A conflict of interest is handled under our Conflicts of Interest Policy.

8. Payroll (if you employ staff)

[Include this section if your charity employs anyone.] We pay staff correctly and on time, operate PAYE, and keep payroll records secure.

  • New starters, leavers and pay changes are authorised in writing by [the responsible role] and checked by a second person before payroll is run.
  • The person who processes payroll does not also authorise it alone.
  • Pension contributions and PAYE and National Insurance are paid to the pension provider and HMRC by their deadlines.

9. Assets and equipment

We keep a simple list of the charity's significant equipment and other valuable assets, and check periodically that they still exist and are in use. Assets are kept secure and, where appropriate, insured. We record it when an asset is bought, disposed of or written off, and any disposal is approved by the trustees.

10. Restricted and designated funds

Money given for a specific purpose (restricted funds) is only spent on that purpose. We record restricted and designated funds separately from general (unrestricted) funds so we can show each has been spent correctly, and we report the balances to the trustees. We do not borrow from restricted funds to cover general costs. For example, a grant given for a named project is never quietly used to plug a general cash-flow gap.

11. Accounting records, reporting and independent scrutiny

We keep accurate accounting records that explain all the charity's transactions and show its financial position. We keep these records, and supporting documents like invoices and bank statements, for at least six years.4

  • We prepare annual accounts in the form the law requires for our type and size of charity.5
  • We arrange independent examination or audit of the accounts where this is required, and act on any points the examiner raises. The income thresholds that decide whether you need an independent examination or a full audit change from time to time, so as a current benchmark, confirm the figures on gov.uk.
  • We file our accounts, trustees' annual report and annual return with the Charity Commission (and Companies House if we are a charitable company) by the deadline.

12. Preventing and reporting fraud

Trustees stay alert to the risk of fraud, theft and error, and treat the controls in this policy as the main defence.6 We take extra care with anything unusual, such as a request to change a supplier's bank details or pressure to make an urgent payment. Before acting on a request to change bank details, we confirm it by phoning a number we already hold for that contact, never a phone number or link given in the message itself.

Anyone who suspects fraud, theft or serious financial wrongdoing reports it to the chair (or another trustee) straight away, and can raise it under our Whistleblowing Policy. Where an incident is serious, the trustees assess and report it under our Serious Incident Reporting Policy.

13. Reviewing this policy

The trustees review this policy at least every two years, and sooner if the charity's income, staffing or activities change significantly, or after any financial incident. We record the review and the date of the next one.

Approved by the trustees of [your charity] on [date]. Next review due: [date].

What you'll fill in (4)

Replace or confirm each highlighted part before your board adopts it:

  • your charity
  • Include this section if your charity employs anyone.
  • the responsible role
  • date

See how CharityControl fills these →

Use in CharityControl

More about this policy

When you need it

The underlying controls are a legal duty, even though no single document is named in law. Trustees must protect their charity's money and assets and manage its resources responsibly (Charities Act 2011; The essential trustee, CC3), and every charity must keep proper accounting records.[4] The Charity Commission's guidance Internal financial controls for charities (CC8) sets out the controls it expects every charity to have "in proportion to its size and activities", from a tiny volunteer-run group to a large charity with a finance team.[1]

A written policy is not itself required by statute, but it is how trustees show they have met the duty. The Commission asks about your controls, and CC8 is clear that controls must actually operate in practice, not just exist on paper. Every charity should have one. The difference is length and formality, not whether you need it.

This template is a starting point to adapt, not legal advice. Change the wording, thresholds and roles to fit your charity, and take professional advice if you are unsure.

What it protects against5 examples

One person controls the whole money chain. The treasurer (or a single staff member) can set up a new payee, approve the payment and release it from the bank, with nobody else looking. Fraud or an honest mistake runs for months before anyone spots it.

Payments over a set amount need two named people to approve and release them, and the person who requests a payment can never be the one who approves it. Online banking is set up for dual authorisation.

Mandate fraud. An email arrives, apparently from a regular supplier or a trustee, saying 'our bank details have changed, please pay to this new account'. Someone updates the payee and pays a fraudster.

Any change to a supplier's or payee's bank details is verified by phoning a known number the charity already holds, never a number or link in the email itself, before the first payment goes out.

Restricted money spent on the wrong thing. A grant given for a specific project gets used to cover general running costs or a cash-flow gap, so the charity can't show the funder the money did what it was given for.

Restricted and designated funds are tracked separately from general funds, and money is only spent on the purpose it was given for. The treasurer reports fund balances to trustees.

Bank access is never tidied up. A treasurer or trustee leaves but keeps their online banking login and stays on the bank mandate. Old signatories can still move money.

Bank mandate and system access are reviewed at least once a year and whenever anyone joins or leaves, and access is removed the same week someone leaves the role.

Expenses and card spend with no evidence. People claim cash back without receipts, buy personal items on the charity card, or self-approve their own expenses. Small leaks add up and set a bad tone.

Every claim needs a receipt and is approved by someone other than the claimant. Card statements and direct debits are checked line by line each month against what was actually bought.

Swipe or scroll for more

How to enforce it

Practical steps to make it live, not just filed:

  • Set up dual authorisation in online banking so two named people are needed to release any payment over the agreed limit, and take the leaving person off the mandate the same week they leave.
  • The treasurer reconciles the bank account against the accounts every month and brings actual-versus-budget figures, including restricted fund balances, to every trustee meeting so overspends get questioned.
  • One named person checks each expense or card claim has a receipt and was not approved by the person claiming it, before it is paid.
  • Once a year, the trustees review who is on the bank mandate, who has online banking access and who holds cards, and remove anyone who no longer needs it.
  • When a supplier says their bank details have changed, the person paying phones the number the charity already holds to confirm it, and notes that they checked, before paying.
What larger charities add8

Pull one in only when it matches something you actually do:

  • Scheme of delegation and authorisation limits Mid-size (£1m to £10m)+
  • Purchasing, procurement and cards Mid-size (£1m to £10m)+
  • Fixed asset register and investments Mid-size (£1m to £10m)+
  • Finance sub-committee Mid-size (£1m to £10m)+
  • Internal audit and assurance Large (£10m+)+
  • Audit committee Large (£10m+)+
  • Treasury and counterparty management Large (£10m+)+
  • Group and subsidiary controls Large (£10m+)+
What people get wrong
  • Copying a large charity's finance manual. A small volunteer-run charity adopts a 25-page policy with procurement tiers, an audit committee and a treasury framework it has no capacity to run, so the controls exist on paper but nobody follows them. This is exactly what CC8 warns against.. Use only the sections you can actually operate. For most charities under £1m that is sections 1 to 13 (plus 8 if you have staff). Add the mid and large sections later, when the charity genuinely grows into them.
  • Cutting out the core controls because "we're small" or "we trust each other". For example, letting one person receive cash, pay bills and reconcile the bank alone, or dropping dual authorisation of payments.. These are the heart of the duty and must stay, whatever your size. Where you genuinely can't split a task between two people, add the compensating control in section 2: a trustee who is not involved day to day reviews the statements and payments and records it in the minutes.
  • Treating the policy as a document to file and forget, while the actual practice drifts (shared banking logins, blank signed cheques, no reconciliation for months).. CC8 is clear that controls must work in reality. Test them: at least yearly, a trustee checks that payments really were dual-authorised, cash really was banked promptly, and reconciliations were done. Fix any gaps and record it.
  • Leaving out restricted funds, so money given for one purpose gets spent on general running costs. For example, a grant given for a named project is used to cover general overheads or a cash-flow gap.. Keep restricted and designated funds recorded separately (section 10) and report the balances to trustees, so you can always show each fund was spent as the donor intended.
Terms used here5
conflict of interest
Anything that could stop a trustee acting only in the charity's best interests, or could reasonably look as if it might.
restricted funds
Money that must be spent on a specific purpose set by the donor or funder.
independent examination
A lighter-touch external check of the accounts than a full audit, available to most smaller charities.
trustees' annual report
The report trustees prepare each year alongside the accounts, explaining what the charity did and the difference it made.
serious incident
An event the Charity Commission expects trustees to report, such as significant harm, fraud or a major loss.
Sources8
Suggest a change to this template

Spotted something missing, out of date, or wrong for a charity of a given size? Tell us. We read every suggestion and keep these current.

Free to use and adapt for your charity. Not legal advice; check the cited sources for the current rules.