Policy templates / Serious Incident Reporting Policy
Charity Serious Incident Reporting Policy Template (Free, UK)
Filled in from your workspace when you adopt it in CharityControl. A starting point to adapt, not legal advice.
1. Purpose and scope
This policy sets out how your charity identifies a serious incident and reports it to the Charity Commission and to any other body that needs to know. Reporting serious incidents is a Charity Commission requirement for every registered charity, whatever its income.
It applies to all trustees, employees, volunteers and anyone acting on the charity's behalf. It covers incidents that have actually happened as well as those that are alleged or suspected.
2. What counts as a serious incident
A serious incident is an adverse event, whether it has actually happened, is alleged, or is suspected, that results in, or risks, significant harm to:
- people who come into contact with the charity: beneficiaries, staff, volunteers or others;
- the charity's money, assets or property;
- the charity's work or reputation.
"Significant" means significant in the context of your charity, its people, operations, finances and reputation. The main things the Commission expects to be reported are:
- incidents that harm people, including safeguarding concerns about children or adults at risk;
- fraud, theft, cyber-crime or money laundering, including a ransomware attack that locks up or steals the charity's data;
- a large donation from an unknown or unverified source, or one you have concerns about;
- links to terrorism or extremism;
- other significant events, such as the loss of key premises or of a major delivery partner.
As a current benchmark, confirm the figures on gov.uk, the Commission treats a financial loss of £25,000 or more, or more than 20% of the charity's income, and an unverified donation of £25,000 or more, as serious.1 Use judgement below those figures: report if the impact on your charity is significant. A reportable personal data breach also counts as a serious incident; judge it against this same test, and follow our Data Protection Policy to contain the breach and decide whether to tell the ICO.
3. Who decides and who reports
The trustees are responsible for making sure serious incidents are reported. In practice, from your register assesses whether an incident meets the threshold and makes the report. The trustees remain responsible even where the task is delegated.
Anyone at your charity who becomes aware of a possible serious incident must tell from your register without delay, so that a reporting decision can be made.
If the incident involves from your register, or they are otherwise conflicted, the concern goes instead to the chair. If it involves the chair, it goes to from your register. Nobody assesses or decides on a report about themselves, and the rest of the board is told. The point is that the person who would normally control whether a report is filed must step aside when the incident is about them, so the decision is never theirs to bury.
4. When to report
Keep people safe first, then report promptly. Deal with any immediate risk first: get medical help, make people safe, secure money or property. Then report.
Report promptly, as soon as reasonably possible after the incident happens, or after your charity becomes aware of it. Do not wait until an internal investigation is finished. If you are unsure whether something crosses the threshold, the safer course is to report it and explain your reasoning.
5. How to report to the Charity Commission
Report to the Charity Commission using its online "Report a serious incident" form (linked in the sources below). Give a prompt, full and frank account: what happened, when, the harm or loss involved, who has been affected, and what your charity is doing in response. Keep a copy of everything you submit.
6. Reporting to other authorities
Reporting to the Charity Commission does not replace reports you must make elsewhere. Depending on the incident, also contact:
- Safeguarding: the local authority (and its designated officer for concerns about someone working with children) and, where a crime may have happened, the police, for any concern about a child or adult at risk. Assess and act on this under our Safeguarding Policy.
- Police or Action Fraud: for theft, fraud, cyber-crime or other crime.
- The Information Commissioner's Office (ICO): for a personal data breach that is reportable, within 72 hours of becoming aware of it.3 See our Data Protection Policy for how to contain a breach and make the reporting decision.
- The Disclosure and Barring Service (DBS): a barring referral can be a legal duty where the charity removes, or would have removed, someone from regulated activity because they caused harm or posed a risk.4 Assess and make this referral under our Safeguarding Policy.
- The Health and Safety Executive (HSE): for a death, a serious work-related injury or a dangerous occurrence that is reportable under RIDDOR.5 A RIDDOR-reportable event may also be a Charity Commission serious incident, so consider both.
- Other bodies relevant to your charity: for example a funder, your insurer, or another regulator.
Make these reports in parallel. Do not treat a report to the police or another regulator as a substitute for reporting to the Charity Commission.
7. Records and the annual return
Keep a simple record of every serious incident: what happened, the decision on whether to report and why, the reports made and their dates, and the action taken. your charity must state on its annual return whether there were any serious incidents that were not reported during the year, so an accurate record protects the trustees.
8. Reviewing this policy
The trustees review this policy at least every two years and after any serious incident, and update it in line with current Charity Commission guidance. This policy was last approved on your review date by from your register.
More about this policy
When you need it
Reporting serious incidents to the Charity Commission is a regulatory requirement for every registered charity in England and Wales, whatever its income. There is no "too small to report", and it is not optional good practice.
Every charity that files an annual return has to declare whether any serious incident went unreported during the year, so trustees need a reliable way to spot, decide on and record incidents. Some reports are also legal duties in their own right. For example, notifying the Information Commissioner's Office of a reportable personal data breach within 72 hours[3], and safeguarding referrals to the local authority or police.
All trustees share responsibility. The task can be delegated to a named lead, but the trustees remain accountable for making sure reports are made.
This template is a starting point to adapt for your charity, not legal advice. For a real incident, take proper advice before you act.
What it protects against5 examples
A safeguarding incident happens (a volunteer is accused of harming a child, or a beneficiary is seriously hurt) and the trustees deal with it quietly in-house because they hope it will settle down or they do not want the embarrassment. The Charity Commission is never told, or is told months late once it has become a bigger problem.
The reader knows a serious incident must be reported to the Commission promptly, usually within days, and that hoping it goes away is not a decision. The policy makes late or non-reporting the thing the charity is scared of, not the report itself.
The serious incident is about the person who would normally handle reporting. The chief officer takes money, or a trustee is the subject of the safeguarding concern, and that same person controls whether it gets reported. It never reaches the rest of the board.
When the usual decision-maker is involved in the incident, it automatically goes to another named trustee (the chair, or the vice-chair if the chair is involved). Nobody decides on a report about themselves.
A bookkeeper or fundraiser is found to have taken money. The treasurer wants to quietly recover it, avoid police and avoid telling the Commission, so it does not look bad to funders. Theft, fraud and significant loss go unreported.
The reader treats fraud, theft and significant financial loss as reportable serious incidents, and knows that reporting to the Commission, and where relevant the police and the bank, is separate from recovering the money.
A staff member emails a spreadsheet of beneficiaries or donors to the wrong person, or a laptop is lost. It gets tidied up locally and nobody checks whether it is a serious incident, whether the ICO needs telling within 72 hours, or whether trustees should know.
The policy links data breaches to serious incident thinking: someone assesses each breach, the 72-hour ICO clock is understood, and a breach that risks real harm reaches the trustees rather than being closed off by one person.
An incident is reported to the Commission but everyone forgets the other people who need to know: the funder whose grant conditions require disclosure, the insurer, the police, the DBS, or the local authority safeguarding team. The charity later loses the grant or the cover for not telling them.
The reader has a short checklist of who else may need telling for a given incident, so reporting to the Commission is not treated as the whole job.
Swipe or scroll for more
How to enforce it
Practical steps to make it live, not just filed:
- Name one person as the point of contact for incidents, usually the chair or a designated trustee, and put their name and how to reach them on a single page everyone has seen. If the incident involves that person, it goes to a named backup instead.
- Make 'any incidents since last time?' a standing item at every trustee meeting. Keep a simple incident log with the date, what happened, what was decided, and whether it was reported and to whom.
- For each incident that might be serious, one person writes down the decision to report or not report and the reason. 'We decided not to report because...' is a recorded decision, not a silence.
- Put it in induction. New trustees, staff and volunteers are told in plain words what counts as a serious incident, who to tell, and that raising a worry early is always fine.
- Once a year, read back through the incident log and ask two questions: did we spot the serious ones, and did we report them in time? Fix the gap before the next real one.
What larger charities add5
Pull one in only when it matches something you actually do:
- Named lead and internal escalation Mid-size (£1m to £10m)+
- Learning from incidents Mid-size (£1m to £10m)+
- Board oversight Mid-size (£1m to £10m)+
- Subsidiaries, partners and overseas activity Large (£10m+)+
- Major-incident response and communications Large (£10m+)+
What people get wrong
- Copying a large charity's serious-incident procedure, a multi-page crisis-management manual with a standing response team, media protocol and overseas-partner clauses, into a small charity that will never run it.. For a charity under £1m, keep it to the essentials: what counts, who decides, when to report, how to report to the Commission, the other bodies to tell, and a simple record. Add a response team and communications plan only if your size and risk actually need them.
- Under-covering the duty by treating this as a 'tell the Charity Commission' policy and leaving out the parallel reports.. Spell out the other mandatory routes in the same policy: safeguarding referrals to the local authority and police, Action Fraud for financial crime, a RIDDOR report to the HSE for a death or serious work injury, a DBS barring referral (assessed under your safeguarding policy) where you remove someone from regulated activity for causing harm, and the ICO within 72 hours for a reportable data breach. The Commission report does not discharge those.
- Assuming there is an income threshold, that 'we're too small to have to report'.. Serious incident reporting applies to every registered charity whatever its income. The £25,000 figures are benchmarks for what counts as 'significant', not a size exemption for the charity.
- Reporting to the police or another regulator and thinking that covers it, or waiting until an internal investigation is complete.. Report to the Charity Commission in parallel and promptly, as soon as you reasonably can after becoming aware, even if the police or another body are already involved and even before you have all the facts.
- Deciding as a board to keep a reportable incident in-house, handling it quietly to avoid embarrassment or to protect the charity's reputation, so no report is ever filed.. The decision not to report is itself a serious governance failure, and the annual return asks whether any serious incident went unreported. Report promptly and record the reasoning. Protecting reputation is never a reason to withhold a report.
- Keeping no record of incidents or of decisions not to report, then facing the annual return declaration.. Log every serious incident and every judgement call, including why you decided something did not meet the threshold, so the annual return answer is accurate and the trustees are protected.
Terms used here5
- serious incident
- An event the Charity Commission expects trustees to report, such as significant harm, fraud or a major loss.
- ICO
- The Information Commissioner's Office, the UK regulator for data protection. Serious data breaches are reported to it within 72 hours.
- DBS
- Disclosure and Barring Service, the UK criminal-record check for people working with children or adults at risk.
- regulated activity
- Work with children or adults at risk that is close or frequent enough to require an enhanced DBS check.
- RIDDOR
- The rules requiring certain workplace injuries and dangerous events to be reported to the Health and Safety Executive.
Sources8
Numbered to match the [n] citations in the template.
- How to report a serious incident in your charity (Charity Commission) legal duty
- Safeguarding and protecting people for charities and trustees (Charity Commission) Commission guidance
- Report a personal data breach under the UK GDPR 72-hour duty (ICO) legal duty
- Make a barring referral to the Disclosure and Barring Service (DBS) legal duty
- Reporting accidents and incidents at work under RIDDOR (HSE) legal duty
- The essential trustee: what you need to know, what you need to do (CC3) Commission guidance
- Report fraud and cyber crime (Action Fraud) Commission guidance
- Charity Governance Code good practice