Help & resources
Get guidance on things such as HR, Marketing and Legal.
Charities can face a range of risks that may affect their finances, reputation, employees, volunteers, or ability to deliver their objectives.
The Charity Commission’s Charity Sector Risk Assessment recommends that charity trustees regularly review and assess the risks facing their organisations and plan for how to manage them. The Commission also states that charities which are legally required to have their accounts audited must include a risk management statement in their trustees’ annual report.
Our guide below, created in collaboration with Markel Law, explains key charity risk management principles, including governance, risk assessments, practical controls, and insurance considerations.
Risk management involves identifying potential events or circumstances that could prevent a charity from achieving its objectives and taking steps to reduce their potential impact.
The risks a charity may face can depend on its activities, size, funding model, and beneficiaries, and could include the loss of a primary funding source, a cyber incident, an employment dispute, or damage to the charity’s reputation.
Understanding the risks that could affect your charity can help you prepare for them and reduce their potential impact. Effective risk management can also help build donor confidence by demonstrating that funds are being managed responsibly.
Starting with a risk register can provide a central record of relevant risks and the measures in place to manage them. For each risk, consider recording:
Risk registers often use a risk score based on the likelihood of an event occurring and the potential impact on the charity. This can help trustees focus their attention on the risks that may have the greatest consequences.
Trustees have overall responsibility for the management and control of a charity, even when they delegate specific aspects of risk management to employees, volunteers, or professional advisers.
Establishing strong governance is key as it can provide the framework for effective risk management. Trustees may consider including regular reviews of the risk register in board meetings and tracking the progress of agreed measures, as this can help to identify changes that may need to be made before significant problems develop.
Staff and volunteers can also contribute to the process as they may see operational risks in their day-to-day work that are less visible to trustees. For example, teams may be aware of weaknesses in fundraising processes or issues with how sensitive information is handled.
Financial risks can directly affect a charity’s ability to achieve its objectives. Reliance on a small number of donors or funding sources, unexpected cost increases, fraud, and poor cash flow management can all place financial pressure on an organisation.
Charities can aim to reduce their exposure to risk by monitoring income and expenditure and maintaining appropriate financial controls. Trustees may also consider how the charity would operate if an important grant or regular source of donations ended unexpectedly. Scenario planning can help trustees to understand the potential consequences and identify actions that could strengthen the charity’s financial resilience.
Internal controls, including appropriate authorisation procedures, separation of financial responsibilities, and regular reviews of account transactions, can also help to reduce the risk of fraud and financial loss.
Data protection is an important part of risk management as charities often hold personal information about donors, beneficiaries, employees, and volunteers.
The UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018 set requirements around how organisations should collect, store, use, and share personal data. Charities can reduce risks related to the data they hold by establishing clear data protection procedures, limiting access to information, and ensuring employees and volunteers understand their responsibilities.
Cyber security can also form an important part of a charity’s risk assessment as cyber threats continue to increase. Around 28% of charities reported experiencing a cyber security breach or attack in the previous 12 months, equivalent to around 57,000 UK charities, according to the Cyber Security Breaches Survey 2025/2026 commissioned by the UK government.
Charities may be at particular risk of a cyber-attack if they lack formal IT and technology oversight, hold large amounts of personal data, have a high turnover of volunteers, or lack the resources to implement security processes. Staff and volunteers may also use personally-owned devices when carrying out their roles, which may introduce a further range of risks. Phishing, ransomware, account compromise, and other forms of data breaches can disrupt fundraising and services as well as having financial consequences.
If your charity uses third-party platforms, such as fundraising, payment, customer relationship management (CRM), or cloud services, consider assessing the security and data protection arrangements those providers offer as part of your charity risk assessment.
For further guidance, you can check your organisation’s cyber risk score with Markel Direct’s risk assessment and read our guide to cyber security for charities. A separate cyber risk assessment may also be appropriate for your charity.
The Charity Commission expects safeguarding to be a governance priority for all charities. It can be particularly important for charities working with children, adults at risk, volunteers, members of the public, or people who may be at increased risk of harm.
In addition, all charities should have appropriate safeguarding policies in place, take reasonable steps to prevent harm, and promptly report serious incidents to the Charity Commission where required. A safeguarding assessment may consider the risks associated with the charity’s services, premises, activities, and beneficiaries.
Potential risks may include abuse or exploitation, inappropriate behaviour by staff or volunteers, unsafe events, and inadequate recruitment checks.
Charities can manage these risks by maintaining clear and appropriate safeguarding policies, carrying out relevant checks and staff training, assessing activities, and working environments, and ensuring employees and volunteers know how to report concerns.
Employees and volunteers can be essential to delivering charitable objectives; however, they may also create legal and operational risks if appropriate procedures are not in place.
Charities can reduce these risks by maintaining clear employment contracts, policies, and procedures, providing effective training, and ensuring that managers understand their responsibilities.
Organisations may also need to consider health and safety risks, particularly where employees or volunteers work in charity shops, community venues, fundraising events, or other public-facing environments.
For charities employing staff, Markel Direct’s guide to the legal implications of employing staff provides further information.
Reputational risks can have consequences beyond negative publicity, as public perception can affect donations, grants, partnerships, and confidence in the organisation.
Fundraising activities may create risks around communications, donor expectations, data protection, and compliance with fundraising requirements – similar risks may also arise when merging with another charity. Charities can manage these risks by ensuring campaigns are carefully planned and authorised, communications are accurate, and fundraising strategies comply with relevant requirements.
Social media may also create additional reputational risks where employees, volunteers, or trustees publish content on behalf of the organisation. A clear social media policy can help establish expectations and provide a framework for responding if problems arise.
Trustees may also wish to monitor complaints, concerns raised by beneficiaries, and stakeholder feedback as indicators of emerging risks.
Charities can benefit from planning how they would respond if a significant incident affected their operations.
Creating a business continuity plan may also be appropriate for a charity as it can help prepare for events such as the loss of premises, IT disruption, a cyber incident, extreme weather, the loss of a key supplier, or the sudden unavailability of critical staff.
The plan can identify essential services, alternative arrangements, key contacts, and responsibilities, as well as how the charity would communicate with beneficiaries, employees, donors, and other stakeholders during an incident.
Testing the plan can also reveal gaps that may be easier to address before an actual disruption occurs. Business continuity plans should be reviewed and tested periodically, particularly following significant organisational or technology changes.
Legal and regulatory requirements can change as a charity grows or introduces new activities.
Depending on its activities, a charity may need to consider areas such as charity law, fundraising regulation, employment law, health and safety, data protection, safeguarding, and financial reporting.
Larger charities may have additional reporting requirements relating to risk management. In England and Wales, a statutory audit is generally required where a charity’s gross annual income exceeds the audit threshold set by the Charities Act 2011 (as recently amended by the Charities Acts 1992 and 2011 (Substitution of Sums) Order 2026), or where its gross annual income exceeds the accounts threshold and its gross assets exceed the relevant assets threshold. Separately, Charities SORP 2026 uses income-based reporting tiers that determine the disclosures a charity must provide in its trustees’ annual report and accounts.
In situations where the legal position is unclear, or the charity is facing a significant dispute or regulatory issue, professional legal advice can help trustees understand their obligations and available options.
Insurance can form part of a broader risk management strategy by helping charities manage financial consequences that cannot be avoided through other controls. Insurance should complement, rather than replace, effective governance, internal controls and risk management processes.
The Charity Commission recognises insurance is one possible way for trustees to manage risks; the appropriate cover will depend on the charity’s activities and risk profile.
Depending on its circumstances, a charity may consider public liability, professional indemnity, employers’ liability, or cyber insurance. Trustees can use their risk assessment to identify where insurance may provide an additional layer of financial protection. Trustee indemnity insurance can help to protect trustees’ personal finances by covering the costs of defending trustees against certain legal claims arising from their role, subject to the terms of the policy. Section 189 of the Charities Act 2011 permits charities to purchase this insurance, although it cannot cover liability for acts which the trustee knew, or ought to have known, were not in the interests of the charity, or in respect of which the trustee was unconcerned whether they were in the interests of the charity.
A charity’s risk profile can change as its activities, funding, emerging technologies, staffing, and regulatory environment change, requiring ongoing risk management.
Trustees can review the risk register regularly and consider whether existing controls remain effective, whether new risks have emerged, and whether previously identified risks have changed in likelihood or potential impact.
A structured approach to risk management can help charities prepare for uncertainty while giving trustees a clearer basis for making informed decisions.
Discover more about charity insurance and visit our knowledge centre for more help and guidance.
Please note: This article provides guidance for information purposes only and is accurate at the time of production. It should not be relied upon wholly when making or taking important business decisions – always seek the services of an appropriately qualified professional. The views expressed by websites referred to are limited to those of the websites, and do not necessarily reflect the views of Markel Direct. Markel Direct is not affiliated with any of the brands, companies or websites mentioned in this article.