What the Charity Commission Wants on Your Risk Register

The Charity Commission published its second annual sector risk assessment on 18 August 2026, and it says plainly what it is for: to help trustees review their own risk registers. It covers ten risk areas. For a charity under £1m, four of them matter and the rest are noise. This is which four, and what each one changes about what you write down.

Take a charity with £180,000 of income, five trustees, one grant covering most of the work and a part-time coordinator. Its risk register, if it has one, probably lists fire safety, data protection, loss of key funding, and safeguarding. All reasonable. None of them are what the Commission spent this year worrying about.

If your register hasn’t been looked at since the last annual report, governance support is the wider fix. The four entries below are the immediate ones.

The money risk on your register is the wrong money risk

Most registers carry “loss of funding” as a single line. The report’s financial data suggests something more specific and more likely.

Looking at annual returns for years ending in 2024, sector income reached £102 billion against £100 billion of spend. That reads like recovery. Underneath it, 41% of charities spent more than they brought in, and among charities with income of £10,000 or less, one in four reported only breaking even – against under 1% in every other income band. Casework followed the same shape: insolvency and financial difficulty cases rose 27.7% between October 2024 and September 2025, and voluntary removals from the register climbed 36%, to 938 charities telling the Commission they had stopped functioning.

A charity on £180,000 with one main grant does not lose it overnight. What happens is that the grant renews at the same figure it was three years ago, staff costs rise, and the deficit runs for four quarters before anyone names it. The Commission’s own advice is about early warning indicators – reviewing forecasts often enough to spot variation while options still exist.

So the register entry is not “loss of funding”. It is closer to: costs rise faster than income across the year, and the board sees it too late to act on. The control is a quarterly forecast the trustees actually read, not an annual budget. If your reserves policy has a number in it that nobody has tested against current running costs, that belongs in the same entry.

Private benefit is now the Commission’s fastest-growing complaint

Cases about charitable status being abused for private benefit went from 211 in 2023-24, to 291 in 2024-25, to 374 in 2025-26. Two consecutive rises of 38% and 29%. The Commission links part of this to AI making fraudulent registration applications easier, and notes that fewer than half of applications – 45% – now result in a registered charity, down from 72% in 2016-17.

The instinct is to read that as a problem for other charities. Somebody else’s bad actors. The useful reading is different, because the mitigations the Commission lists are all things a five-trustee board either does or doesn’t do: no single person able to move charity funds without a second pair of eyes, regular review of payments out of the bank account, and any payment to a trustee checked against the governing document before it happens rather than after.

At £180,000 with a part-time coordinator, that second pair of eyes is a real constraint. The coordinator raises the payment, one trustee approves it, and the treasurer reconciles monthly. That is the control, and it is worth writing down that you have it – or that you don’t. This overlaps with what we covered in financial controls when you don’t have enough people, which goes further into how to separate duties across three or four people.

The register entry here is not “fraud”. It is: one person can initiate and complete a payment without independent review. Score it honestly. For a lot of small charities, the gross score is high, and the net score depends entirely on whether the treasurer looks at the statements.

Rebuilding a register from scratch is the part boards avoid. The Charity Risk Register Template is an Excel workbook built around CC26, with a five-by-five scoring guide, a board summary that pulls the top risks automatically, and fifteen worked example risks across every category the Commission expects to see. It comes with guidance notes covering how to score, who owns what, and how often to review.

The risk almost nobody has written down

This is the finding worth the read. Cases involving a dispute inside a charity rose from 579 to 909 – up 57%. Over the same period, cases about trustee decision-making or breaches of Commission guidance fell 32%, from 458 to 313.

Read those two together. Boards are not making worse decisions. They are falling out over harder ones. The Commission attributes the rise partly to the difficult choices charities are having to make under financial pressure, and partly to wider social tensions reaching into boardrooms. Disputes are showing up around trustee elections, financial transparency, and land or property.

Almost no small charity has “the board cannot reach agreement” on its risk register. It sits in the category of things that feel personal rather than structural, and registers are for structural things. That distinction is wrong. A five-person board where two trustees stop speaking is an operational risk with a direct route to the charity stopping work, and it is more likely than the fire you have listed.

What goes in the mitigation column is unglamorous. A conflicts process that runs at every meeting rather than annually. Minutes that record reasoning, not just outcomes, so a disputed decision can be explained six months later. A written route for a trustee who disagrees to have that recorded. We covered the reasoning point in how trustees should make decisions that hold up, and the declarations point in conflicts of interest in practice.

Cyber, with the number checked

The Commission’s report states that 30% of charities reported a cyber attack in the past year and describes a notable rise in ransomware. It gives no source for either.

The government’s Cyber Security Breaches Survey for 2025/2026, published on 30 April 2026, puts it at 28% of charities identifying a breach or attack in the previous twelve months. Phishing is the dominant form, affecting 25% of charities, and among charities that experienced anything at all, the proportion hit by phishing and nothing else rose from 46% to 57%. Ransomware among charities moved from under 0.5% to 1%.

That changes what you write down. Ransomware is not your risk. A phishing email that looks like it came from your chair, asking the coordinator to move money, is your risk – and it connects straight back to the payment control in the section above. One entry can cover both.

Above £500,000 of income, this stops being optional. SORP 2026 requires charities over that threshold to describe their principal risks, cyber and environmental among them, in the trustees’ annual report. At £180,000 the disclosure doesn’t apply, but the register that would produce it is the same register.

What to leave off

The report also covers hostile foreign states, charities operating overseas, geopolitical turbulence and casework arising from international conflict. Those are real risks to the charities they apply to. If you deliver services in one English town with five trustees, none of them belongs on your register.

A register padded with risks that will never materialise is worse than a short one, because it buries the four entries that would have told you something. The guidance notes we supply with the template put the working range for a small charity at ten to fifteen material risks. Under five suggests the work hasn’t been done. Thirty suggests somebody copied a list.

Two questions decide it. Could this plausibly happen to a charity of our size doing our work? And if it did, would we be able to point to a control? Anything that fails both is not a risk you are managing. It is a paragraph.

Where this leaves your next board meeting

Four entries to add or rewrite: the slow deficit rather than the sudden funding loss, single-person payment authority, board breakdown, and phishing aimed at whoever handles the money. Each one needs a named owner, a control you can describe, and a review date.

If the honest answer is that your register is a document produced once for a funder and never opened since, the register is not really the problem. Book a call, and we’ll look at what the board is and isn’t seeing.

Ghamdan Al-Areeky

Ghamdan Al-Areeky

Founder & Charity Mentor

I'm Ghamdan Al-Areeky, founder of Evolve Catalyst and a charity mentor. I work with small UK charities to build organisations that work, so they can focus on the people and causes they exist to serve. I spent more than 15 years working inside UK charities - close to the day-to-day, across operations, systems, fundraising and strategy.

What I saw again and again is that the problems a charity struggles with on the surface usually trace back to something underneath: the foundations that were never quite put right. Governance that doesn't hold. A strategy that stopped guiding decisions. Systems the team can't rely on. Income resting on a single funder. That's the work.

I help charities at every stage - people turning an idea into a charity, registered charities that never quite got going, and established organisations pulled in too many directions - get those four foundations right, in the order that matters for them. I don't hand over a report and leave. I work alongside trustees, chief executives and their teams: helping them reach the decision, then helping them act on it, so what changes stays changed. No cause should be held back by the organisation built to serve it.

Leave a Reply