Policy templates / Risk Management Policy
Charity Risk Management Policy Template (Free, UK)
Filled in from your workspace when you adopt it in CharityControl. A starting point to adapt, not legal advice.
1. Purpose and scope
This policy sets out how the trustees of your charity identify, assess and manage the risks that could stop us achieving our purpose or could harm our people, beneficiaries, money or reputation.
It applies to all trustees, staff and volunteers. Managing risk well is not about avoiding every risk. It is about understanding the risks we face and making sensible decisions about them.
2. What we mean by risk
A risk is anything that could get in the way of us doing what we set out to do, or could cause harm. Risks can affect, for example:
- the people we help and our staff and volunteers (safety, wellbeing, safeguarding);
- our money (reserves running low, fraud, or the loss of a key grant);
- concentration: relying too much on one funder, one supplier or one key person, so that losing any one of them would hurt badly;
- how we are run (poor decisions, breaking a rule);
- our reputation and the trust people place in us.
Some risks are also opportunities. We weigh both when we make decisions.
3. Who is responsible
The trustees are responsible for managing risk. This cannot be handed over completely. It stays with the board.
- The trustees agree the main risks, decide how much risk we are willing to take, and check that risks are being managed.
- from your register keeps the risk register up to date and brings changes to the board.
- Everyone involved in your charity is expected to flag new or growing risks to the lead.
4. How we identify and record our risks
We keep a simple risk register, a list of our main risks. For each risk we record:
- what the risk is and what could cause it;
- how likely it is and how serious it would be;
- what we are already doing about it;
- who is keeping an eye on it;
- the date we last reviewed it, so we can see at a glance which risks have actually been looked at and which have gone stale.
Two risks we watch closely are relying too heavily on a single funder and depending on one key person, because losing either would set us back badly and neither shows up on its own until it bites. We name who watches each of these and expect them to raise a concern early, before it becomes a crisis. If free reserves fall below our agreed reserves target, the treasurer brings it to the next trustee meeting as a decision, not a note.
We do not try to list every possible risk. We focus on the ones that matter most to a charity of our size and type. A short register that we use is worth more than a long one that we do not.
5. How we assess each risk
For each risk we make a simple judgement on two things:
- Likelihood: how likely is it to happen? (for example: low, medium, high)
- Impact: if it did happen, how bad would it be? (for example: low, medium, high)
Risks that are both likely and serious get the most attention. This is a judgement, not a science. The point is to agree which risks we act on first.
6. How we respond to a risk
For each significant risk we choose one or more of these responses:
- Reduce it: put controls in place to make it less likely or less serious (most risks).
- Transfer it: for example, take out insurance.
- Avoid it: stop or change the activity that creates the risk.
- Accept it: decide the risk is small enough, or the cost of acting is too high, and record that we have consciously accepted it.
We write down what we have decided and who is doing it.
7. How much risk we are willing to take
We take a cautious approach to anything that affects the safety of people or the money entrusted to us, and we are more open to risk when trying new ways to achieve our charitable purpose.
In plain terms, we will not take chances on safeguarding or on the reserves that keep us solvent. But we will back a well-planned new service even if it might not work, because taking sensible, considered risks is how we grow our impact.
8. How often we review our risks
Risk is a standing item at every trustee meeting. This means a new concern, a funder giving notice or a safeguarding issue reaches the board straight away, without anyone having to call a special review.
The trustees also review the whole risk register in depth at least once a year, and sooner if something significant changes, for example a new activity, a funding change, or an incident. We hold this full review at the same meeting each year, for example the autumn trustee meeting set which, and record it in the minutes.
9. Serious problems and reporting
If a risk turns into a serious incident, for example harm to a person, a significant loss of money, fraud, or serious damage to our reputation, the lead tells the trustees straight away.
The trustees then assess and report it under our Serious Incident Reporting Policy, which holds the reporting threshold and the decision on what to tell the Charity Commission.4 That policy also covers when other bodies, such as the police, the ICO or a funder, must be told.
10. Approving and reviewing this policy
The trustees approve this policy and review it at least every two years, or sooner if the law or our activities change.
Approved by the trustees of your charity on your review date. Next review due: your review date. Policy owner: from your register.
More about this policy
When you need it
There is no single law that says every charity must have a written risk management policy. But trustees have a legal duty to act with reasonable care and to protect their charity's people, money and reputation.[2] You cannot protect what you have not thought about, so in practice every trustee board must identify its main risks and decide what to do about them. The Charity Commission's guidance Charities and risk management (CC26) recommends a written approach,[1] and the Charity Governance Code expects boards to manage risk actively.[6]
It becomes a firm legal requirement at a size threshold. A charity that must have a statutory audit must include a risk management statement in its trustees' annual report, confirming the board has reviewed the major risks and has systems to manage them.[3] As a current benchmark, a charity must have an audit if its income is over £1m, or over £250,000 with gross assets over £3.26m; these thresholds change, so confirm the current figures on gov.uk before you rely on them.[3]
A small charity can meet its duty with a short, practical policy and a one-page risk register it actually reviews. This template is a starting point to adapt to your charity. It is not legal advice.
What it protects against5 examples
The board only talks about risk once a year, at the AGM or when the accounts are signed off. A funder gives notice they are pulling out, or a safeguarding concern is raised, and it does not reach trustees until the damage is done.
The policy makes risk a standing item at every trustee meeting, and lets any trustee, staff member or volunteer raise a new risk between meetings so it does not wait for the annual review.
The charity depends on one person or one source of money. The treasurer holds all the financial knowledge, or a single grant funds most of the work. When that person leaves or the grant ends, nobody saw it coming.
The policy tells trustees to look for concentration risk (one funder, one supplier, one key person) and to name who is responsible for reducing it, not just to list operational risks.
Reserves quietly run down and a sudden cost or a late grant payment leaves the charity unable to pay wages. No one was tracking how many months of running costs were left.
The policy links to reserves and cash, so financial risk is scored and reviewed with a clear owner, and low reserves trigger a decision rather than a note.
A serious incident happens (a safeguarding allegation, a data breach, a fraud) and nobody knows who acts, who tells the Charity Commission, or whether it meets the serious incident reporting threshold.
The policy names who decides, who reports, and points to the serious incident reporting duty, so the response is agreed before an incident, not invented during one.
A risk register exists because the auditor asked for one. It is filled in once, never dated, never owned, and nothing on it ever changes. It satisfies a tick box but changes no decision.
The policy requires each risk to have a named owner and a last-reviewed date, and makes the board check that high risks have actually been updated, so the register drives action.
Swipe or scroll for more
How to enforce it
Practical steps to make it live, not just filed:
- Put 'top risks' as a standing item on every trustee meeting agenda. The board looks at the highest-scored risks, checks each still has the right owner, and records any change in the minutes.
- Keep one risk register (a spreadsheet or a single document) with, for each risk: a plain description, a score, what is being done, who owns it, and the date it was last reviewed. Undated risks are treated as overdue.
- Give each significant risk a named owner (a specific trustee or staff member), not a committee. That person updates their risk before the meeting and flags if it is getting worse.
- Let anyone raise a new risk between meetings by telling the chair or a named trustee, so a fresh problem does not have to wait for the next quarterly review.
- Once a year, do a deeper review alongside the annual report and reserves check, since trustees must confirm in the annual report that major risks are reviewed and managed.
What larger charities add7
Pull one in only when it matches something you actually do:
- Risk register format and risk owners Mid-size (£1m to £10m)+
- Risk statement in our trustees' annual report Mid-size (£1m to £10m)+
- Categories of risk we consider Mid-size (£1m to £10m)+
- Assurance and internal controls Mid-size (£1m to £10m)+
- Our risk management framework Large (£10m+)+
- Board oversight of risk Large (£10m+)+
- Emerging risk and horizon scanning Large (£10m+)+
What people get wrong
- Copying a large charity's risk policy, with heat maps, a risk committee, "three lines of defence" and a scoring matrix, when you are a small charity that will never run it.. Use only the "small" clauses. A one-page register listing your top handful of risks, with an owner and a yearly review, meets the duty. You can add the heavier machinery if and when you grow.
- Under-covering the duty: having no risk register at all, or a policy document that is written once and never looked at again.. The duty is met by actually identifying and managing risk, not by owning a document. Fill in a short register, name who watches each risk, and review it at a trustee meeting each year and record it in the minutes.
- Assuming a written risk policy is legally required for every charity, or assuming it is never required.. For a small charity it flows from the general duty of prudence and is strongly recommended (CC26), not a standalone law. It becomes a firm legal requirement, a risk statement in the annual report, once your charity must be audited.
- Scoring risks but never acting on them, so the register becomes a scoring exercise.. For every significant risk, record a response (reduce, transfer, avoid or consciously accept) and who is doing it. The score is only there to help you prioritise the action.
- Treating risk management as a one-off task at policy-writing time.. Keep risk as a standing item at every trustee meeting, set a fixed point each year for a full review, and update the register whenever something significant changes, such as a new activity, a funding change, or an incident.
- Keeping risk separate from serious incident reporting, so a crisis is handled without anyone checking whether it must be reported.. Build the link in: when a risk becomes a serious incident, the trustees assess and report it under our Serious Incident Reporting Policy, which holds the threshold and the reporting decision. Do not judge the threshold from memory in the moment.
Terms used here4
- trustees' annual report
- The report trustees prepare each year alongside the accounts, explaining what the charity did and the difference it made.
- free reserves
- Money the charity can spend freely: unrestricted funds, minus anything tied up in fixed assets.
- serious incident
- An event the Charity Commission expects trustees to report, such as significant harm, fraud or a major loss.
- ICO
- The Information Commissioner's Office, the UK regulator for data protection. Serious data breaches are reported to it within 72 hours.
Sources6
Numbered to match the [n] citations in the template.
- Charities and risk management (CC26), Charity Commission guidance Commission guidance
- The essential trustee: what you need to know, what you need to do (CC3), trustees' duty of prudence and to protect assets legal duty
- Prepare a charity trustees' annual report, risk management statement required for audited charities legal duty
- How to report a serious incident in your charity, Charity Commission legal duty
- Internal financial controls for charities (CC8), managing financial risk Commission guidance
- Charity Governance Code, boards should manage risk (integrity and effectiveness) good practice