What Trustees Are on the Hook for in Safeguarding

Three answers, and they pull in different directions. Trustees are collectively responsible for making sure measures exist to protect anyone who comes into contact with the charity. The Charity Commission’s safeguarding guidance is non-statutory, so departing from it does not by itself make a trustee personally liable in negligence. And the sharpest edge in the whole subject is not the safeguarding at all – it is the box on the annual return.

Boards tend to sit at one of two extremes. Either everything feels like personal risk, which makes the subject too frightening to look at properly. Or the charity is incorporated and insured, so nothing does. Neither position survives contact with what the Commission can and cannot do.

If this is a live question for your board rather than an abstract one, governance support is where the practical work sits. What follows is where the exposure is real and where it is not.

What ultimately responsible means when you have delegated everything

A charity can have a safeguarding lead, a trained staff team, a written policy and a reporting route, and the board still answers for whether the arrangements work. Delegation moves the task. It does not move the responsibility.

What that means in practice is narrower than it sounds. The board is not expected to run safeguarding. It is expected to know whether safeguarding is running – which is a different question, answered by different evidence, and it is the question a regulator asks after something has gone wrong.

The distinction matters most in charities where a trustee is also the safeguarding lead. It is common in small charities and it removes the escalation step, because the person the concern goes to is the person the board would ask about it. That arrangement needs a written alternative route, and it belongs in the policy rather than in somebody’s head. What a safeguarding policy must cover sets out the rest of what the document has to do.

The declaration on your annual return

Charities with income over £25,000 have to declare, as part of the annual return, that there are no serious incidents they should have reported to the Commission and did not. The Commission’s instruction is plain: report first, then submit the return.

Section 60 of the Charities Act 2011 makes it an offence to knowingly or recklessly give the Commission information that is false or misleading in a material particular. The annual return is not exempt from that. So a board that looked at an incident, decided it was not serious enough, and then ticked the box has made a judgement that sits closer to a criminal provision than most trustees realise.

The word doing the work there is recklessly. A board that genuinely did not know about an incident is in a different position from one that discussed it, could not agree, and let the deadline decide. The second is the situation to worry about, and it is the reason the reasoning belongs in the minutes at the time rather than in a reconstruction afterwards. Where the threshold sits is covered in serious incident reporting.

The same return also asks whether the charity has obtained standard, enhanced or enhanced with barred list DBS checks on all trustees, employees and volunteers in roles eligible for them. From 1 September 2026 the answer changes for a lot of charities, because the supervision exemption disappears – who in your charity needs a DBS check covers what moved.

Where personal liability sits, and where it does not

Departing from non-statutory guidance is not, on its own, a source of personal financial liability. What creates exposure is something else: acting outside the charity’s powers, failing to act on a risk the board knew about, or breaching the duties trustees owe the charity.

Legal structure changes the picture underneath that. In an unincorporated charity – a trust or an association – the trustees contract personally and can be personally liable to third parties, with a right to be indemnified from the charity’s assets where the liability was properly incurred. That right is only worth what the assets are worth. In a company or a CIO, the charity is a separate legal person, and the trustees’ exposure is different in kind.

Trustee indemnity insurance is where boards over-assume. It is permitted, most policies exclude deliberate wrongdoing, and cover for regulatory investigations and defence costs varies considerably between products. The useful step is not reading the article. It is asking your broker three questions: whether the policy responds to a Commission inquiry, whether it covers defence costs as well as awards, and what it excludes on safeguarding claims specifically.

None of that is advice on any particular charity’s position. Where a board has a real concern about its own exposure, that is a question for a charity solicitor, not for a website.

The exposure that actually turns up

For most small charities the realistic consequence is regulatory rather than financial. The Commission can open a statutory inquiry, issue an official warning, make orders and directions about how the charity operates, and in serious cases disqualify or remove trustees.

Then there is the consequence that appears in no legislation and hurts small charities most. Regulatory action is public. Funders read the register, and a charity with an official warning against its name spends the next three years explaining it. That is a reputational risk with a direct route to income, which is why it belongs on the risk register rather than in the category of things that only happen to other people.

Partners, subsidiaries and the charities you fund

There is a separate reporting duty for incidents involving someone else’s organisation. It covers delivery partners and sub-contractors, trading subsidiaries, organisations that receive funding from the charity, and other bodies linked to it – a federated structure, for example.

The test is whether the incident materially affects the charity, its staff, operations or finances, or damages its reputation enough to be serious. A grant-maker that funds a delivery organisation and never asks what happened there has taken on the risk without the information needed to judge it.

Two things follow. Due diligence covers the partner’s safeguarding arrangements, not only their accounts. And the obligation to tell you about incidents goes into the grant or partnership agreement in writing, because without it you are relying on them volunteering bad news.

Almost everything in this section comes down to what the minutes say. The Trustees Meeting Minutes Template is a structured Word template built around CC48, with blocks for resolutions, voting outcomes, conflict declarations and the reasoning behind each decision, plus guidance notes on what to record and what to leave out.

The fundraising duty almost nobody knows about

Where a charity uses a professional fundraiser, the agreement between them has to include specific things. The voluntary regulatory scheme or fundraising standards the fundraiser will follow. How the fundraiser will protect people at risk, and other members of the public, from unreasonably intrusive or persistent approaches and undue pressure to donate. And how the charity will monitor whether that is happening.

This comes from section 59 of the Charities Act 1992, as amended by the Charities (Protection and Social Investment) Act 2016. It is statutory rather than guidance, it is rarely mentioned in safeguarding discussions, and it applies to any charity that has signed an agreement with a professional fundraiser without reading what the agreement has to contain.

What reduces the exposure

Records that show the board considered something, rather than records that show a decision appeared. The reasoning is the protection, which is the same discipline that applies to any trustee decision that might be examined later.

A reporting route that still works when the concern involves a trustee or the chief executive. If every path leads to the same person, there is no route.

Reporting early rather than deciding it away. The Commission has said repeatedly that what matters is what trustees did about an incident and how quickly. Reporting something that turns out not to need reporting costs an hour. The reverse costs considerably more.

Reviewing the policy after every incident, not only once a year, and checking the insurance covers what the board assumes it covers.

The question to put to your board

Not whether the trustees would be blamed if something went wrong. Whether they could show, from what was written down at the time, what they knew and what they did about it.

A board that can answer that is in a defensible position even when something goes badly. A board that cannot is relying on nothing going wrong. Book a call if you want to work out which one describes yours.

Ghamdan Al-Areeky

Ghamdan Al-Areeky

Founder & Charity Mentor

I'm Ghamdan Al-Areeky, founder of Evolve Catalyst and a charity mentor. I work with small UK charities to build organisations that work, so they can focus on the people and causes they exist to serve. I spent more than 15 years working inside UK charities - close to the day-to-day, across operations, systems, fundraising and strategy.

What I saw again and again is that the problems a charity struggles with on the surface usually trace back to something underneath: the foundations that were never quite put right. Governance that doesn't hold. A strategy that stopped guiding decisions. Systems the team can't rely on. Income resting on a single funder. That's the work.

I help charities at every stage - people turning an idea into a charity, registered charities that never quite got going, and established organisations pulled in too many directions - get those four foundations right, in the order that matters for them. I don't hand over a report and leave. I work alongside trustees, chief executives and their teams: helping them reach the decision, then helping them act on it, so what changes stays changed. No cause should be held back by the organisation built to serve it.

Leave a Reply