CharityControl.org

Policy templates / Serious Incident Reporting Policy

Charity Serious Incident Reporting Policy Template (Free, UK)

free template · For Trustees, chief executive or charity manager, safeguarding lead, data protection lead · England & Wales · Sources checked 2026-08-01

Not sure which size? Size it by your charity number

Highlighted parts are yours to complete. A starting point to adapt, not legal advice.

Small charity
Use in CharityControl

1. Purpose and scope

This policy sets out how [your charity] identifies a serious incident and reports it to the Charity Commission and to any other body that needs to know. Reporting serious incidents is a Charity Commission requirement for every registered charity, whatever its income.

It applies to all trustees, employees, volunteers and anyone acting on the charity's behalf. It covers incidents that have actually happened as well as those that are alleged or suspected.

2. What counts as a serious incident

A serious incident is an adverse event, whether it has actually happened, is alleged, or is suspected, that results in, or risks, significant harm to:

  • people who come into contact with the charity: beneficiaries, staff, volunteers or others;
  • the charity's money, assets or property;
  • the charity's work or reputation.

"Significant" means significant in the context of [your charity], its people, operations, finances and reputation. The main things the Commission expects to be reported are:

  • incidents that harm people, including safeguarding concerns about children or adults at risk;
  • fraud, theft, cyber-crime or money laundering, including a ransomware attack that locks up or steals the charity's data;
  • a large donation from an unknown or unverified source, or one you have concerns about;
  • links to terrorism or extremism;
  • other significant events, such as the loss of key premises or of a major delivery partner.

As a current benchmark, confirm the figures on gov.uk, the Commission treats a financial loss of £25,000 or more, or more than 20% of the charity's income, and an unverified donation of £25,000 or more, as serious.1 Use judgement below those figures: report if the impact on [your charity] is significant. A reportable personal data breach also counts as a serious incident; judge it against this same test, and follow our Data Protection Policy to contain the breach and decide whether to tell the ICO.

3. Who decides and who reports

The trustees are responsible for making sure serious incidents are reported. In practice, [name the decision-maker, for example the chair, a named trustee or the manager] assesses whether an incident meets the threshold and makes the report. The trustees remain responsible even where the task is delegated.

Anyone at [your charity] who becomes aware of a possible serious incident must tell [name or role] without delay, so that a reporting decision can be made.

If the incident involves [name or role], or they are otherwise conflicted, the concern goes instead to the chair. If it involves the chair, it goes to [the vice-chair or another named trustee]. Nobody assesses or decides on a report about themselves, and the rest of the board is told. The point is that the person who would normally control whether a report is filed must step aside when the incident is about them, so the decision is never theirs to bury.

4. When to report

Keep people safe first, then report promptly. Deal with any immediate risk first: get medical help, make people safe, secure money or property. Then report.

Report promptly, as soon as reasonably possible after the incident happens, or after [your charity] becomes aware of it. Do not wait until an internal investigation is finished. If you are unsure whether something crosses the threshold, the safer course is to report it and explain your reasoning.

5. How to report to the Charity Commission

Report to the Charity Commission using its online "Report a serious incident" form (linked in the sources below). Give a prompt, full and frank account: what happened, when, the harm or loss involved, who has been affected, and what [your charity] is doing in response. Keep a copy of everything you submit.

6. Reporting to other authorities

Reporting to the Charity Commission does not replace reports you must make elsewhere. Depending on the incident, also contact:

  • Safeguarding: the local authority (and its designated officer for concerns about someone working with children) and, where a crime may have happened, the police, for any concern about a child or adult at risk. Assess and act on this under our Safeguarding Policy.
  • Police or Action Fraud: for theft, fraud, cyber-crime or other crime.
  • The Information Commissioner's Office (ICO): for a personal data breach that is reportable, within 72 hours of becoming aware of it.3 See our Data Protection Policy for how to contain a breach and make the reporting decision.
  • The Disclosure and Barring Service (DBS): a barring referral can be a legal duty where the charity removes, or would have removed, someone from regulated activity because they caused harm or posed a risk.4 Assess and make this referral under our Safeguarding Policy.
  • The Health and Safety Executive (HSE): for a death, a serious work-related injury or a dangerous occurrence that is reportable under RIDDOR.5 A RIDDOR-reportable event may also be a Charity Commission serious incident, so consider both.
  • [Other bodies relevant to your charity]: for example a funder, your insurer, or another regulator.

Make these reports in parallel. Do not treat a report to the police or another regulator as a substitute for reporting to the Charity Commission.

7. Records and the annual return

Keep a simple record of every serious incident: what happened, the decision on whether to report and why, the reports made and their dates, and the action taken. [Your charity] must state on its annual return whether there were any serious incidents that were not reported during the year, so an accurate record protects the trustees.

8. Reviewing this policy

The trustees review this policy at least every two years and after any serious incident, and update it in line with current Charity Commission guidance. This policy was last approved on [date] by [the board or name].

What you'll fill in (7)

Replace or confirm each highlighted part before your board adopts it:

  • your charity
  • name the decision-maker, for example the chair, a named trustee or the manager
  • name or role
  • the vice-chair or another named trustee
  • Other bodies relevant to your charity
  • date
  • the board or name

See how CharityControl fills these →

Use in CharityControl

More about this policy

When you need it

Reporting serious incidents to the Charity Commission is a regulatory requirement for every registered charity in England and Wales, whatever its income. There is no "too small to report", and it is not optional good practice.

Every charity that files an annual return has to declare whether any serious incident went unreported during the year, so trustees need a reliable way to spot, decide on and record incidents. Some reports are also legal duties in their own right. For example, notifying the Information Commissioner's Office of a reportable personal data breach within 72 hours[3], and safeguarding referrals to the local authority or police.

All trustees share responsibility. The task can be delegated to a named lead, but the trustees remain accountable for making sure reports are made.

This template is a starting point to adapt for your charity, not legal advice. For a real incident, take proper advice before you act.

What it protects against5 examples

A safeguarding incident happens (a volunteer is accused of harming a child, or a beneficiary is seriously hurt) and the trustees deal with it quietly in-house because they hope it will settle down or they do not want the embarrassment. The Charity Commission is never told, or is told months late once it has become a bigger problem.

The reader knows a serious incident must be reported to the Commission promptly, usually within days, and that hoping it goes away is not a decision. The policy makes late or non-reporting the thing the charity is scared of, not the report itself.

The serious incident is about the person who would normally handle reporting. The chief officer takes money, or a trustee is the subject of the safeguarding concern, and that same person controls whether it gets reported. It never reaches the rest of the board.

When the usual decision-maker is involved in the incident, it automatically goes to another named trustee (the chair, or the vice-chair if the chair is involved). Nobody decides on a report about themselves.

A bookkeeper or fundraiser is found to have taken money. The treasurer wants to quietly recover it, avoid police and avoid telling the Commission, so it does not look bad to funders. Theft, fraud and significant loss go unreported.

The reader treats fraud, theft and significant financial loss as reportable serious incidents, and knows that reporting to the Commission, and where relevant the police and the bank, is separate from recovering the money.

A staff member emails a spreadsheet of beneficiaries or donors to the wrong person, or a laptop is lost. It gets tidied up locally and nobody checks whether it is a serious incident, whether the ICO needs telling within 72 hours, or whether trustees should know.

The policy links data breaches to serious incident thinking: someone assesses each breach, the 72-hour ICO clock is understood, and a breach that risks real harm reaches the trustees rather than being closed off by one person.

An incident is reported to the Commission but everyone forgets the other people who need to know: the funder whose grant conditions require disclosure, the insurer, the police, the DBS, or the local authority safeguarding team. The charity later loses the grant or the cover for not telling them.

The reader has a short checklist of who else may need telling for a given incident, so reporting to the Commission is not treated as the whole job.

Swipe or scroll for more

How to enforce it

Practical steps to make it live, not just filed:

  • Name one person as the point of contact for incidents, usually the chair or a designated trustee, and put their name and how to reach them on a single page everyone has seen. If the incident involves that person, it goes to a named backup instead.
  • Make 'any incidents since last time?' a standing item at every trustee meeting. Keep a simple incident log with the date, what happened, what was decided, and whether it was reported and to whom.
  • For each incident that might be serious, one person writes down the decision to report or not report and the reason. 'We decided not to report because...' is a recorded decision, not a silence.
  • Put it in induction. New trustees, staff and volunteers are told in plain words what counts as a serious incident, who to tell, and that raising a worry early is always fine.
  • Once a year, read back through the incident log and ask two questions: did we spot the serious ones, and did we report them in time? Fix the gap before the next real one.
What larger charities add5

Pull one in only when it matches something you actually do:

  • Named lead and internal escalation Mid-size (£1m to £10m)+
  • Learning from incidents Mid-size (£1m to £10m)+
  • Board oversight Mid-size (£1m to £10m)+
  • Subsidiaries, partners and overseas activity Large (£10m+)+
  • Major-incident response and communications Large (£10m+)+
What people get wrong
  • Copying a large charity's serious-incident procedure, a multi-page crisis-management manual with a standing response team, media protocol and overseas-partner clauses, into a small charity that will never run it.. For a charity under £1m, keep it to the essentials: what counts, who decides, when to report, how to report to the Commission, the other bodies to tell, and a simple record. Add a response team and communications plan only if your size and risk actually need them.
  • Under-covering the duty by treating this as a 'tell the Charity Commission' policy and leaving out the parallel reports.. Spell out the other mandatory routes in the same policy: safeguarding referrals to the local authority and police, Action Fraud for financial crime, a RIDDOR report to the HSE for a death or serious work injury, a DBS barring referral (assessed under your safeguarding policy) where you remove someone from regulated activity for causing harm, and the ICO within 72 hours for a reportable data breach. The Commission report does not discharge those.
  • Assuming there is an income threshold, that 'we're too small to have to report'.. Serious incident reporting applies to every registered charity whatever its income. The £25,000 figures are benchmarks for what counts as 'significant', not a size exemption for the charity.
  • Reporting to the police or another regulator and thinking that covers it, or waiting until an internal investigation is complete.. Report to the Charity Commission in parallel and promptly, as soon as you reasonably can after becoming aware, even if the police or another body are already involved and even before you have all the facts.
  • Deciding as a board to keep a reportable incident in-house, handling it quietly to avoid embarrassment or to protect the charity's reputation, so no report is ever filed.. The decision not to report is itself a serious governance failure, and the annual return asks whether any serious incident went unreported. Report promptly and record the reasoning. Protecting reputation is never a reason to withhold a report.
  • Keeping no record of incidents or of decisions not to report, then facing the annual return declaration.. Log every serious incident and every judgement call, including why you decided something did not meet the threshold, so the annual return answer is accurate and the trustees are protected.
Terms used here5
serious incident
An event the Charity Commission expects trustees to report, such as significant harm, fraud or a major loss.
ICO
The Information Commissioner's Office, the UK regulator for data protection. Serious data breaches are reported to it within 72 hours.
DBS
Disclosure and Barring Service, the UK criminal-record check for people working with children or adults at risk.
regulated activity
Work with children or adults at risk that is close or frequent enough to require an enhanced DBS check.
RIDDOR
The rules requiring certain workplace injuries and dangerous events to be reported to the Health and Safety Executive.
Sources8
Suggest a change to this template

Spotted something missing, out of date, or wrong for a charity of a given size? Tell us. We read every suggestion and keep these current.

Free to use and adapt for your charity. Not legal advice; check the cited sources for the current rules.