What a Charity Safeguarding Policy Must Cover

The Charity Commission’s requirement for what a safeguarding policy says amounts to four things. The policy has to make clear how you protect people from undue harm, how someone raises a concern, how you handle an allegation or incident, and how you respond, including reporting to the relevant authorities. Four. Templates run to twenty pages, and nothing in them tells a trustee which parts are the requirement and which are the author’s preference.

This is about the document and what the board is answerable for. If you have a live concern about a child or an adult at risk, stop reading. Contact your local authority’s safeguarding children team or the designated officer, or the adult safeguarding team, and call the police if a crime may have been committed. Nothing on this page helps with that, and delay does harm.

For a board that has realised its safeguarding policy was downloaded once and never opened again, governance support is where the wider fix sits. What follows is what the policy has to do.

What the policy has to say

Protecting people from undue harm means describing the harm your charity could cause or fail to prevent, given what it does. A befriending service reaching older people at home carries different risk from a youth football club, and both differ from a grant-maker that never meets a beneficiary. A policy that describes harm in the abstract has skipped the only part specific to you.

Making it possible to raise a concern means naming who, how, and what happens next, including the route that works when the concern is about the chief executive or a trustee. A policy that routes everything through one person has no answer when that person is the subject.

Handling an allegation means saying what happens in the first hours: who is told, what is recorded, what is preserved, and who decides what. Responding means naming the external agencies and when they are contacted, not describing the internal process and mentioning the authorities in passing.

Then the sentence in the Commission’s guidance that undoes the template approach: the amount of detail depends on what the charity does, where it works, whether it operates in person or online, and the level of risk. Depth is proportionate. A generic policy is not accidentally right for anyone.

The conditions that have nothing to do with the wording

Five requirements attach to the policy’s status rather than its contents, and a document can satisfy every content requirement while failing all five.

It has to be put into practice. This is the one the Commission examines most closely after something goes wrong, and it is the difference between a policy and a file.

It has to be responsive to change and reviewed as necessary, always after a serious incident, and at least once a year. That is a two-part rule. Most policies state an annual review and say nothing about incidents, which means the review that matters most is the one nobody scheduled. If you are unsure what counts, the threshold sits alongside the Commission’s reporting duty, which we cover in serious incident reporting.

It has to be available to the public. Not shared internally, not stored in a folder the trustees can reach. Published. This is the quiet failure in small charities, and it is the first thing a funder or a complainant checks.

It has to comply with the legislation covering the people you work with, which varies by who they are.

One policy is not enough

The Commission’s guidance names a set of documents alongside the safeguarding policy, and a board that has adopted one policy has usually not adopted the rest.

A code of conduct setting out the charity’s values and how people are expected to behave. Health and safety arrangements. First aid, fire safety and digital safety policies that everyone understands. Welfare, discipline and whistleblowing policies where there are staff. A complaints process for beneficiaries and anyone else with a concern. Clear procedures on bullying and harassment.

Two more attach to the act of running a criminal records check rather than to safeguarding as a subject, which is why they get missed. If you ask applicants about criminal records, you need a policy setting out your lawful basis for processing that information under data protection law. If you use DBS information, you need a policy on the recruitment of ex-offenders to comply with the DBS Code of Practice. Charities run DBS checks without either, and the omission is invisible until someone asks.

Our overview of charity policies covers the wider set and what each is for.

Safeguarding risks belong on the risk register, in the Commission’s own words – identified risks and how they will be managed, recorded and regularly reviewed. The Charity Risk Register Template is an Excel workbook built around CC26, with a five-by-five scoring guide, a board summary that pulls the top risks automatically, and worked example risks across every category the Commission expects to see, safeguarding among them.

Whether the extra duties apply to you

Two triggers, and charities misjudge both.

The children trigger is wide and simple. Safeguarding duties for children apply to any charity working with, or coming into contact with, anyone under 18. Not only charities whose purpose involves children.

The adults at risk trigger is a three-part test, and all three parts have to be met. The person has needs for care and support, whether or not the local authority is meeting them. They are experiencing, or at risk of, abuse or neglect. And as a result of those care and support needs, they are unable to protect themselves. A charity working with people who are frail, unwell, or living with a learning disability or addiction may or may not be in scope, and the answer turns on that third limb.

Where either applies, the Commission expects policies that fit with your local authority safeguarding partnership’s own procedures, regular training for staff and volunteers, a safeguarding lead who works with the partnership, and clear rules on when DBS checks are needed and at what level. Those are stated as expectations rather than legal duties, which is worth knowing when you are deciding what your charity can sustain – but a board departing from any of them should be able to say why.

One thing to watch when you follow the Commission’s own links. Its safeguarding guidance was last substantively updated on 1 June 2022 and cites Working Together to Safeguard Children 2023. The Department for Education published a new edition in March 2026, which replaced it and applies to voluntary and community organisations including charities. Check the current version rather than the one the regulator’s page points to.

What the board is answerable for

Safeguarding risks go on the risk register, with how each is managed, reviewed regularly. That is the guidance’s wording, and it connects safeguarding to the document your board already reviews rather than leaving it in a policy nobody opens. If your register does not carry a safeguarding entry, what the Commission expects on a risk register sets out the rest of what should be there.

Oversight has to run on more than numbers. The Commission asks for supporting information alongside statistics – qualitative reports, themes, the things a count of incidents cannot show. Two concerns in a year tell you nothing about whether people feel able to raise a third.

The assurance measures the Commission suggests are ordinary and mostly free. A standing agenda item at board meetings. Training plans for trustees, staff and volunteers, which the Commission expects to cover the board as well as the people delivering the work – trustee duties include this one. Asking beneficiaries whether they know how to raise a concern, and listening to what comes back. Reviewing past cases for what was learned. Recording conflicts of interest at every level, which matters more here than almost anywhere – a concern involving someone connected to a trustee is exactly where conflicts of interest stop being procedural.

And a trigger most boards do not have written down: if you change how or where you work, review the policies before you start, consider whether new ones are needed, and record the discussion. New premises, a new service, moving something online. Recording the reasoning is the same discipline that applies to any trustee decision that might be examined later.

Where it comes apart

A policy adopted and never applied. The Commission does not treat having a document as compliance, and after an incident the question is what people did, not what the policy said they would do.

A named safeguarding lead who left eighteen months ago. Anything in a policy that names a person needs a review trigger attached to it.

DBS assumptions in both directions. Not every role working with children or adults at risk is eligible for a standard or enhanced check, and not every role that feels low-risk is ineligible. Eligibility is risk-assessed per role against the DBS criteria, and where a role does not qualify but still involves contact, the assessment is the record that you thought about it.

Grants and partners, which is the section small charities skip because it does not feel like safeguarding. If you fund another organisation, deliver through a partner, or run a trading subsidiary, due diligence covers their safeguarding arrangements too, and a written agreement should set out who is responsible for what. A charity that funds a delivery partner and never asks about their safeguarding has taken on the risk without the oversight.

The question underneath the document

The useful test is not whether the policy exists. It is whether a trustee could describe, without opening it, what happens when a volunteer reports something on a Friday evening. If the answer is a shrug and a link to a shared drive, the policy is not the thing that needs work.

Book a call if you want to look at where the gaps are before a funder or an incident finds them for you.

Ghamdan Al-Areeky

Ghamdan Al-Areeky

Founder & Charity Mentor

I'm Ghamdan Al-Areeky, founder of Evolve Catalyst and a charity mentor. I work with small UK charities to build organisations that work, so they can focus on the people and causes they exist to serve. I spent more than 15 years working inside UK charities - close to the day-to-day, across operations, systems, fundraising and strategy.

What I saw again and again is that the problems a charity struggles with on the surface usually trace back to something underneath: the foundations that were never quite put right. Governance that doesn't hold. A strategy that stopped guiding decisions. Systems the team can't rely on. Income resting on a single funder. That's the work.

I help charities at every stage - people turning an idea into a charity, registered charities that never quite got going, and established organisations pulled in too many directions - get those four foundations right, in the order that matters for them. I don't hand over a report and leave. I work alongside trustees, chief executives and their teams: helping them reach the decision, then helping them act on it, so what changes stays changed. No cause should be held back by the organisation built to serve it.

Leave a Reply