ComplyChat Start free

Guide · Charity governance

Charity fraud policy

A charity fraud policy is the trustees’ written statement of how the charity prevents, detects and responds to fraud, and the Charity Commission’s guidance Protect your charity from fraud lists adopting one among the actions trustees can take, with a fraud response plan and a yearly review of fraud risks.

By ComplyChatPublished 15 minute read

Two volunteers at an animal rescue charity count the takings from a cash tin together at a trestle table inside a barn after an open day, straw bales and a dog crate behind them

In England and Wales the policy sits on top of duties that are not optional: trustees must manage the charity’s resources responsibly, keep accounting records and report serious incidents, including fraud, to the Commission promptly. This guide covers the policy’s contents, the response plan, serious incident reporting and the fraud register.

01

The rule: the trustees’ duty, the Commission’s guidance and the Fraud Act

The Charity Commission’s guidance Protect your charity from fraud is the starting point for a charity fraud policy in England and Wales, and it puts the duty plainly: “As trustees you have a duty to manage your charity’s resources responsibly so it’s important to: identify the risks of fraud at your charity; take actions to protect your charity; check that your actions are working.” Among the actions it lists are to “adopt an anti-fraud policy and promote it, so that everyone at the charity knows the policy”, to “review your charity’s fraud risks once a year, or after a fraud or attempted fraud”, and to “have a fraud response plan so that everyone knows what to do if they discover fraud”.

The Commission describes fraud in charities as “commonly where someone deceives a charity to get money, information or data”, and it “can come from internal and external sources. For example, from employees and volunteers, or from fake requests for funding.” The criminal definition is in the Fraud Act 2006, section 1, which creates one offence committed in three ways: fraud by false representation (section 2), fraud by failing to disclose information (section 3) and fraud by abuse of position (section 4). Abuse of position is the one most charities meet from the inside: it covers a person who “occupies a position in which he is expected to safeguard, or not to act against, the financial interests of another person” and “dishonestly abuses that position”. On conviction on indictment the maximum sentence is ten years’ imprisonment.

The Commission’s companion guidance, Internal financial controls for charities (CC8), sets out the controls the policy depends on, and reminds trustees that “You have a legal duty to keep accounting records for your charity”. So the fraud policy is not a free-standing document: it is the trustees’ account of how the controls in CC8, the reporting duty in the serious incident guidance and the whistleblowing route fit together when something goes wrong.

Large charities have a further reason to write it carefully. The offence of failure to prevent fraud in sections 199 to 206 of the Economic Crime and Corporate Transparency Act 2023 came into effect on 1 September 2025. The Home Office’s guidance on the offence of failure to prevent fraud says it applies to large incorporated bodies meeting two of three tests – more than 250 employees, more than £36 million turnover, more than £18 million in total assets – and notes that “some charities are incorporated and would therefore be in scope”. It is aimed at fraud by an employee or other associated person intended to benefit the organisation or, in certain circumstances, its clients, and the defence is having reasonable fraud prevention procedures; unincorporated organisations other than partnerships are not in scope.

02

What a charity anti-fraud policy should contain

A policy that a small charity’s volunteers will actually read is two or three pages. The outline below is for a fictional charity, Brookfield Community Larder, and follows the order in which someone who suspects fraud needs the answers:

  1. Statement and scope. The trustees will not tolerate fraud, bribery or theft, and the policy applies to trustees, staff, volunteers, contractors and partner organisations handling the charity’s money, data or name.
  2. What fraud looks like here. The Larder’s own risks in plain words: cash from collections and the café, the change of bank details request that arrives by email, false expense claims, Gift Aid declarations, grant claims, and someone using the charity’s name to collect money.
  3. Who is responsible. The trustees as a body; a named trustee (often the treasurer) who leads on fraud risk; the manager who runs the controls; everyone else, who must follow them and speak up.
  4. The controls that apply. A short list pointing to the financial procedures: two people handling and recording cash, a different person authorising a payment from the one who set it up, dual authorisation for any change to the bank mandate, monthly bank reconciliations reviewed by a second person, the register of interests and the hospitality record.
  5. How to raise a concern. To whom, by what route, what happens if the concern is about the treasurer or the chair, and the link to the whistleblowing policy and the Commission’s route for employees.
  6. The fraud response plan. Who leads, what to preserve, who reports to Report Fraud and to the Charity Commission, and who decides on suspension or disciplinary action (section three below).
  7. Records. The fraud register, what goes in it, who keeps it and how long it is kept.
  8. Training and review. How new trustees, staff and volunteers learn the policy, and the date the trustees will next review it and the fraud risks behind it.

The policy has to match what the charity actually does. CC8 says the controls “must follow any requirements in your charity’s governing document”, so a constitution that requires two signatories on cheques, or trustee approval for payments above a sum, binds the policy too. And it says that in a small charity where duties cannot be fully split “due to a lack of people or money”, the risk can be managed by “all trustees reviewing transaction reports” and “checking that internal controls are followed and sharing the results with all trustees”. Say which of those the charity does, rather than promising a segregation of duties a five-volunteer charity cannot staff.

The guidance treats culture as part of the defence, not decoration. Trustees should “understand your charity’s financial systems and what ‘normal’ looks like” and “promote a culture of fraud awareness”, and the charity “should promote an anti-fraud culture where: you promote fraud awareness messages; you encourage people to improve their knowledge about fraud. For example, cyber fraud; you encourage people to voice concerns; everyone knows how to raise concerns”. It also asks trustees to complete pre-employment checks on staff and to “discuss risks of fraud with organisations that your charity works with or funds”, so the policy should reach third parties as well as insiders.

03

The fraud response plan: the first days after fraud is found

The Commission’s fraud guidance gives the response in six steps, and they are the spine of any response plan. If you discover or suspect fraud: “do not panic. Act quickly – this will help you reduce the harm to your charity”; “report it to Report Fraud”; “make sure everyone understands what they need to do and follow your charity’s procedures”; “preserve evidence and keep a record of what happened and when”; “you may need to report it to the Charity Commission”; and “seek legal advice if you need it”. Afterwards, it adds, “review how the fraud happened and your charity’s financial controls”.

In practice the plan should say, by role, who does each of these within the first working day after fraud is suspected, and who decides whether an internal investigation is needed and who carries it out – never someone whose own work is in question:

  • Stop the loss. Contact the bank to freeze or recall a payment where that is still possible; suspend the access, card or authority involved; change passwords on the account that was used.
  • Preserve the evidence. Keep bank statements, invoices, emails, the messages in which the concern was raised and the device or account involved, without editing, forwarding round the board or deleting anything. Decide who will speak to the person suspected, and when, only after taking advice.
  • Report to the police. Fraud and cyber crime go to Report Fraud, the national reporting service run by the City of London Police, online or on 0300 123 2040. It replaced Action Fraud from 4 December 2025, according to the government’s announcement of the Report Fraud service. Report Fraud says “When you report to us you will receive a police crime reference number”, and that it does “not investigate the cases”. Theft goes to the local police on 101.
  • Decide on the serious incident report. The trustees, or whoever they have delegated to, decide whether to report to the Commission and record the reasons either way (section four).
  • Tell the people who need to know. The full board, the insurer, the auditor or independent examiner, and any funder whose grant terms require notice; and agree what will be said to staff, volunteers and the public.

The Commission’s serious incident guidance adds the step that is easiest to skip: “review what happened and prevent it from happening again – this may include reviewing internal controls and procedures, internal or external investigation and/or seeking appropriate help from professional advisers”. CC8 says to review the controls at least once a year and always after a significant financial loss, and to “keep records of your reviews and how you have responded to any issues you have found”.

04

When charity fraud is a serious incident

The Commission’s guidance How to report a serious incident in your charity names “financial crimes – fraud, theft, cyber-crime and money laundering” as one of the main categories of reportable incident, and defines fraud for that purpose as “dishonesty, involving either false representation, for example ‘identity fraud’, failing to disclose information, or abuse of position, undertaken in order to make a gain or cause loss to another”. A serious incident is one that “results in or risks significant” harm to people, loss of the charity’s money or assets, damage to its property or harm to its work or reputation, and “significant” is judged “in the context of your charity”.

There is no threshold to hide behind. For fraud and theft, the guidance says “There is no minimum loss figure that should be reported”, and lists the factors that point towards reporting: the person accused holds a senior position or “has responsibility for financial management, Treasurer on board of trustees etc”; incidents that appear connected; a fraud repeated over a long period; funds from “a public appeal, collection or grant funding”; media interest; and serious action against an individual such as disciplinary action or suspension. It warns that “‘low value’ incidents can pose serious risks – they may be a sign that individuals are trying to avoid detection”, and that the Commission “would expect you to report” repeated low-value incidents.

On timing, “You should report an actual or alleged incident promptly. This means as soon as is reasonably possible after it happens, or immediately after your charity becomes aware of it.” Charities should report “and do not wait until someone is arrested, charged or convicted before doing this”, and should report fraud to Report Fraud “ensuring you obtain a crime reference number and making clear that you’re representing a charity”. The responsibility “rests with the charity’s trustees”; it may be delegated, but “all trustees bear ultimate responsibility for ensuring their charity makes a report, and does so in a timely manner”, and decisions not to report, “particularly where incidents were ‘borderline’”, should be reported back to the trustees.

The report itself asks for the date of the incident, what happened, “date the charity found out about the incident”, “how the charity found out about the incident”, its impact, whether the trustees know, “which of the charity’s policies or procedures relate to the incident and whether they were followed”, and the steps taken. A charity with income over £25,000 must also sign a declaration in the annual return that no serious incident went unreported, and the guidance reminds trustees that it is an offence under section 60 of the Charities Act 2011 to give the Commission false or misleading information.

In the static caravan that serves as an animal rescue charity’s site office, an independent examiner goes through bank statements with the treasurer at the fold-down table, a lurcher asleep in a basket by the heater
05

The fraud register, and what to keep

CC8 is direct: “You should record any incidents of financial crime, abuse or breakdown of your charity’s financial controls.” It also says where else each kind goes: “all types of fraud to Report Fraud”, “tax fraud to HMRC”, incidents involving financial services to the Financial Conduct Authority, “data breaches to the Information Commissioner’s Office (ICO)”, and serious incidents to the Commission. A fraud register is the single place those decisions are written down, attempted frauds included. For each entry, record:

  • the date of the incident and the date the charity found out, and how it found out – the message, the bank alert, the volunteer at the till;
  • what happened, the sum lost or put at risk, and whose money it was (restricted, appeal, grant or general funds);
  • the people told, when, and the Report Fraud crime reference number, the Commission’s incident reference and any other reference;
  • the decision whether to make a serious incident report, who made it and why, including a decision not to report;
  • the policies and procedures that applied and whether they were followed;
  • the action taken – recovery, suspension, disciplinary process, insurance claim – and the controls changed afterwards, with the date of the trustees’ review.

Keep the register with the trustees’ papers, not in one officer’s inbox, and minute its review: the Commission’s fraud guidance asks trustees to “run checks to satisfy yourselves that your financial controls are being followed”, and CC8 expects records of those reviews. Records about a named individual are personal data, and the ICO’s guidance What is criminal offence data? says the extra protection “can also cover suspicion or allegations of criminal activity”, so restrict access and set a retention period with reasons, keeping anything relevant to a live investigation or claim until it is closed. The Data (Use and Access) Act 2025 is amending UK GDPR in stages, so check the date on any ICO guidance you rely on.

06

The first sign of fraud arrives as a message

Almost no fraud is first noticed in a finance meeting. It is a volunteer texting the shop manager on a Saturday that the till was short again. A trustee messaging the treasurer to ask why a supplier they have never heard of was paid twice. A finance assistant forwarding a screenshot of an email from “the chief executive” asking for an urgent transfer. A comment in the staff group chat about whose expense claims never seem to have receipts. Each of those is the moment the charity became aware, and two of the questions the Commission’s report form asks are exactly when and how that happened.

When the trustees sit down to make the report, or to explain later why they did not, the answer is on personal phones: the volunteer’s, the manager’s, the treasurer’s. Some of those people will have left by the time the Commission, an insurer or a court asks. If the person under suspicion was in the group, they saw every message about themselves. If the decision not to report was reached in a run of late-night messages between the chair and the treasurer, the board as a whole may never have seen it, though the guidance expects borderline decisions to be reported back to the trustees.

The policy can only say where a concern should go. Whether the first raising of it can be produced, intact and dated, depends on where people actually send it. The question for the next board meeting is a narrow one: if the charity discovered a fraud tomorrow, could it show the Commission the message in which someone first noticed it, and when the trustees knew?

07

Questions people ask

What counts as charity fraud?

Charity fraud is dishonesty – a false representation, a failure to disclose information or an abuse of position – to make a gain or cause a loss, whether the charity is the victim or its name is used to deceive others; that is the Charity Commission’s definition in its serious incident guidance, and it mirrors the three ways of committing fraud in the Fraud Act 2006. The Commission’s fraud guidance says it can be connected with fundraising, banking, cyber crime, tax and Gift Aid, property and investments, or a charity’s identity, and can come from employees and volunteers as well as from outside.

Do charities have to report fraud to the Charity Commission?

Trustees must report fraud to the Charity Commission as a serious incident when it is significant in the context of the charity, and the Commission says there is no minimum loss figure. It expects reports to be made promptly, without waiting for an arrest or charge, and it expects repeated low-value frauds to be reported. A charity with income over £25,000 must declare in its annual return that no serious incident went unreported.

Who do you report charity fraud to?

Report charity fraud to Report Fraud, the national service run by the City of London Police that replaced Action Fraud in December 2025, and get a crime reference number; theft goes to the local police on 101. Then make a serious incident report to the Charity Commission, giving that reference, and report tax fraud to HMRC and any data breach to the ICO.

Can you report a charity anonymously?

Yes: the Charity Commission says a charity employee who suspects serious wrongdoing, and whose employer fails to deal with it, can report it to the Commission “including anonymously if you wish to do so”. Members of the public can complain about a charity to the Commission where it is, for example, “losing lots of money” or “being used for personal profit or gain”, and should contact the police on 101 if they suspect illegal activity.

Does the failure to prevent fraud offence apply to charities?

The failure to prevent fraud offence applies to a charity only if it is incorporated (for example a charitable company or a body created by Royal Charter) and is a large organisation, meeting two of three tests: more than 250 employees, more than £36 million turnover and more than £18 million in total assets. Unincorporated charities other than partnerships are not in scope, and the offence concerns fraud intended to benefit the organisation or, in certain circumstances, its clients, not fraud against it.

08

Official guidance and your next step

The primary sources are the Charity Commission’s Protect your charity from fraud and Internal financial controls for charities (CC8), both updated 27 November 2024, its guidance How to report a serious incident in your charity, which includes a fraud and theft information checklist, and Report Fraud. The Commission also points trustees to the Preventing Charity Fraud resources for help with preventing, detecting and responding to fraud. Charities in Scotland and Northern Ireland have their own regulators and reporting routes.

This guide is a summary of published guidance for England and Wales, not legal advice. Where a fraud involves an employee or a trustee, take legal advice before interviewing anyone or taking disciplinary action.

Then do one thing: at the next trustees’ meeting, open the fraud register, or start one, and write in the last attempted fraud anyone remembers – the spoofed email, the short till – with the date the charity found out and how.

Why we publish this

ComplyChat gives a charity’s staff, volunteers and trustees a channel the charity owns, on the record from the first message, with everyone in it told so; a volunteer with no work account joins with a mobile number verified by SMS. On paid plans, once the charity’s Microsoft 365 tenant is connected, the lasting record files there under the charity’s own retention rules. It is not accounting software, a fraud case-management system or a substitute for financial controls. We publish this guide because the date a charity found out is so often a message nobody can now produce.

Explore Free · How it works · Compare plans

Sources

Every document this guide quotes or links to, in the order it first cites them.

  1. Protect your charity from fraud gov.uk
  2. Fraud Act 2006, section 1 legislation.gov.uk
  3. Internal financial controls for charities (CC8) gov.uk
  4. Guidance on the offence of failure to prevent fraud gov.uk
  5. Report Fraud reportfraud.police.uk
  6. Announcement of the Report Fraud service gov.uk
  7. How to report a serious incident in your charity gov.uk
  8. What is criminal offence data? ico.org.uk
  9. Complain about a charity gov.uk
  10. Report Fraud reportfraud.police.uk
  11. Preventing Charity Fraud resources preventcharityfraud.org.uk