The rule: a governance priority, and the trustees’ own duty
The Charity Commission’s guidance Safeguarding and protecting people for charities and trustees opens with the principle: “Protecting people and safeguarding responsibilities should be a governance priority for all charities. It is a fundamental part of operating as a charity for the public benefit. As part of fulfilling your trustee duties, whether working online or in person, you must take reasonable steps to protect from harm people who come into contact with your charity.” That includes “people who benefit from your charity’s work, staff, volunteers, [and] other people who come into contact with your charity through its work”. It applies to every charity, not only those working with children or adults at risk.
The accountability is the trustees’. “The Charity Commission can hold trustees to account if things go wrong and can check that trustees followed this guidance and the law.” The Commission “is not a safeguarding authority. We do not investigate individual allegations of abuse, decide whether any allegations are true or bring prosecutions”, but it can refer concerns to the agencies that do, and it assesses how the trustees acted. For charities working with children, Working Together to Safeguard Children 2026 adds the statutory frame: “Every VCSE, faith-based organisation and private sector organisation or agency should have policies in place to safeguard and protect children from harm. These should be followed, and systems should be in place to ensure compliance in this” (paragraph 358); charity trustees “are responsible for ensuring that those benefiting from, or working with, their charity, are not harmed in any way through contact with it” (paragraph 355); and “all practitioners … are subject to the same safeguarding responsibilities, whether paid or a volunteer” (paragraph 357). Charities and “any person involved in the provision, supervision or oversight of sport or leisure” are within the Relevant Agency Regulations, so a local safeguarding partnership can name them and they must then co-operate (paragraph 359).
For charities working with adults, the Care Act 2014 and chapter 14 of the Care and Support Statutory Guidance define an adult at risk and the local authority’s section 42 duty, and the charity’s policy has to connect to the local safeguarding adults board’s procedures in the same way a children’s charity connects to the local safeguarding partnership.
What the Commission expects every charity to have
The Commission’s list is the checklist the policy is written against. “We expect all trustees to make sure their charity:”
- “has appropriate policies and procedures in place, which are followed by all trustees, volunteers and beneficiaries”
- “checks that people are suitable to act in their roles”
- “knows how to spot and handle concerns in a full and open manner”
- “has a clear system of referring or reporting to relevant agencies as soon as concerns are suspected or identified”
- “sets out identified risks and how they will be managed in a risk register which is regularly reviewed”
- “follows safeguarding statutory guidance, good practice guidance and legislation relevant to their charity”
- “is quick to respond to concerns and carry out appropriate investigations”
- “does not ignore harm or downplays failures”
- “has a balanced trustee board and does not let one trustee dominate its work”
- “makes sure protecting people from harm is central to its culture”
- “has enough resources, including trained staff/volunteers/trustees for safeguarding and protecting people”
- “conducts periodic reviews of safeguarding policies, procedures and practice”
Then the standard for the documents themselves. Policies and procedures “should be: put into practice; responsive to change; reviewed as necessary, always following a serious incident and at least once a year; available to the public; compliant with all relevant legislation”. Every trustee, member of staff, volunteer, partner and beneficiary must be made aware of them. And “in your policies make clear how you will: protect people from undue harm; make sure people can raise safeguarding concerns; handle allegations or incidents; respond, including reporting to the relevant authorities”. The Commission adds that “the amount of detail in your policies depends on what your charity does, where it works, whether it operates in person or online and the level of risk”, which is the sentence that lets a small charity write a short policy rather than a long one.
Around the policy sit the other documents the Commission names: “a clear code of conduct which sets out your charity’s culture and values [and] how people in your charity should behave” if there are staff or volunteers; “welfare, discipline and whistleblowing policies for staff if you have them”; “a complaints process for users and others with concerns”; and “first aid, fire safety and digital safety policies that everyone understands”. Trustees “must be assured that all policies, procedures and practice are checked and challenged to ensure they are fit for purpose”, and must make sure the charity “complies with relevant legislation and statutory guidance, keeps accurate records, [and] complies with its own policies and procedures”.
Writing it: the sections a small charity actually needs
A policy that satisfies the list above without becoming a council’s procedures manual has these parts:
- Statement and scope. Who the charity is, who it serves, and the commitment: the charity will take reasonable steps to protect from harm everyone who comes into contact with it, and no trustee, member of staff or volunteer may harm a child or an adult at risk. Name the legislation and guidance the charity follows for the people it works with.
- Who is responsible. The trustee board collectively; a named trustee lead for safeguarding (Working Together 2026 asks for “a senior board level lead” and “a designated practitioner” – in a small charity these may be one person, and the policy says so); and the day-to-day safeguarding lead, with contact details, and a deputy for when they are away.
- Recognising harm. The types of abuse and neglect for the people the charity serves, in a page, with the signs; the Commission’s guidance links to the sources.
- Raising a concern. What anyone – a beneficiary, a parent, a volunteer, a member of the public – does when worried, in three steps, with the lead’s name and number and the out-of-hours alternative (the local authority’s children’s or adults’ team, the police, the NSPCC helpline). Working Together asks for “a culture of listening to children” and “clear escalation policies for staff to follow when their child safeguarding concerns are not being addressed”.
- Responding. What the lead does: makes the person safe, records the concern, decides whether to refer to the local authority (the local safeguarding partnership’s or board’s thresholds and referral route, named), tells the police if a crime may have been committed, and does not investigate a disclosure themselves.
- Concerns about trustees, staff and volunteers. The allegations route: to the local authority designated officer for children, to the adults’ safeguarding team for adults, and who handles a concern about the safeguarding lead or a trustee (the chair, or the vice-chair where it is the chair).
- Reporting. The serious incident report to the Commission, the DBS referral where the charity provides regulated activity and has removed someone, and the funder or the governing body of the sport where the charity is affiliated.
- Safer recruitment. Application, references, interview, the DBS check where the role is eligible and at the level legally permitted for that role; a risk assessment cannot make an ineligible role eligible for an enhanced or barred-list check, and the policy on ex-offenders the DBS Code of Practice requires of any charity using DBS information.
- Training and code of conduct. Who is trained, to what level, how often; the code of conduct or the safer working practice rules the charity adopts; the rules on working alone with children, transport, images and contact with beneficiaries outside sessions.
- Records, information sharing and review. What is written down, where it is kept, who may see it, how long it is kept, when it may be shared; the annual review and the review after any incident, with the date and the trustees’ approval.
The policy applies to everyone: trustees, staff, volunteers, contractors and anyone acting for the charity, whether they work with children, with adults at risk or with neither. A charity that does not work with children still has beneficiaries, volunteers and staff to keep safe, and the Commission’s expectations apply to it; a charity that does work with children or adults at risk writes safeguarding procedures that fit “the policies and procedures of your local authority safeguarding partnership or safeguarding children or adults board”, and its safeguarding policies and procedures are checked against that partnership’s thresholds. Policy templates from NCVO, the NSPCC or a national governing body are a starting point, and the Commission’s advice on them is one sentence: “Only use templates that are appropriate for your charity.”
Two paragraphs the templates leave out. First, the online one: the Commission says “operating online carries specific safeguarding risks connected to protecting people from abuse and protecting sensitive information. You must make sure these are managed and reflected in your policies and practices” – so the policy covers messaging, social media and video sessions, not only the church hall. Second, working with others: “carry out proper due diligence when you work with, or make grants to, any other bodies”, so a charity that funds or partners with a youth group asks for the partner’s policy and checks it.
Handling and reporting: what the policy commits the charity to do
The Commission’s guidance on an incident or allegation is a sequence the policy can adopt verbatim. “If you have an incident or allegation of abuse you should: handle and record it in a secure and responsible way; follow your protecting people and safeguarding policies and procedures; act quickly, ensuring you stop or minimise any further harm or damage; report it to all relevant agencies and regulators when required; plan what to say to those involved with your charity and the media if appropriate; be as open and transparent as possible … while protecting confidentiality appropriately; [and] review what happened to understand how to stop it from happening again.” It adds: “consider whether the incident or concern involves criminal behaviour and whether you therefore need to report it to the police.”
Use the correct external route. Concerns about a child’s welfare go to children’s social care; allegations about an adult working with children go through the LADO route, with police involvement where a crime may have been committed. Adult safeguarding concerns go to the local authority’s adult safeguarding team. Trustees should assess serious incidents against the Commission’s reporting guidance and report promptly where required, rather than waiting for an investigation to finish. Separately, a regulated activity provider must refer to the DBS when the statutory removal and harm conditions are met, including where the person left before they could be removed. A report to one body does not replace another required report.
A safeguarding incident that is also a whistleblowing matter – a volunteer reporting a trustee, a member of staff reporting the safeguarding lead – goes through the whistleblowing policy as well, and the Commission’s own whistleblowing route is open to anyone who works or volunteers for a charity. The policy should say who makes each report and by when, because in a small charity the answer is usually the same person and the reports are usually late. A trustee lead who has the Commission’s serious incident form, the local authority’s referral form and the DBS referral guidance bookmarked before anything happens is most of the difference between a charity that reports and one that meant to.

The records the policy depends on
The Commission requires trustees to make sure the charity “keeps accurate records”, and the policy is only as good as the records that show it was followed. For a small charity they are few, and each has a home:
- The safeguarding log: every concern, what was done, the reason for the decision, who was told and when, and the outcome – the DfE’s guidance for out-of-school settings puts it in three lines: the lead “should record any concerns about abuse and neglect, what they have done about them, [and] the reason for their decisions”. Kept securely, seen only by the lead and the trustees who need to, and retained under the charity’s retention schedule.
- Recruitment and checks: the application, references, interview notes, the DBS certificate number and date (not a copy of the certificate), and the risk assessment for any role or any disclosure.
- Training: who was trained in what and when, and the refresher schedule.
- Consents and registers: parental consents, emergency contacts, medical information, attendance and the adult-to-child ratio for each session.
- The risk register, with the safeguarding risks the Commission expects trustees to set out and review.
- Board records: the minute that approved the policy and the date, the annual review, the minute that received the safeguarding lead’s report, and the record of any serious incident report made.
The Commission’s test for oversight is qualitative as well as numerical: “every trustee should have clear oversight of how safeguarding and protecting people from harm are managed within their charity. This means you need to monitor your performance, not just using statistics, but with supporting information, such as qualitative reports.” A standing item at each board meeting, a written report from the lead, and a minute that shows the trustees asked questions is what that looks like in a charity of three trustees.
The concern raised in a message to a trustee
Every safeguarding policy describes a concern arriving at the lead. In a small charity it arrives on someone’s phone. A volunteer at the Saturday session messages the coordinator that evening: “bit worried about J, he flinched when I moved past him, and he said his dad had been shouting.” The coordinator forwards it to the safeguarding lead, who is at work on Monday and replies at lunchtime. A parent messages a trustee she knows from the school gate about another volunteer. The chair and the lead agree in a two-person chat that the session leader should be stood down while they think. The Commission asks the trustees to “act quickly” and to “record it in a secure and responsible way”; the record, at this point, is three personal phones.
None of it reaches the safeguarding log until the lead types a summary, and the summary is what the charity can show the local authority, the Commission or a later review when they ask when the concern was first raised, what exactly the volunteer saw, and what the chair decided on Sunday night. The charity cannot produce the messages; they are in apps it does not run, on handsets it does not own, and it needs a lawful, proportionate process for obtaining relevant work messages while protecting unrelated personal information. The “culture of listening” Working Together asks for exists – people did speak up – and the charity has no way to prove it.
Use a restricted reporting route, with access limited to the people who need the information. A recorded message is not proof that someone has read or acted on a concern: follow the safeguarding procedure, contact the responsible person directly when action is urgent, and use the local authority or emergency route when required. Add the relevant information and decisions promptly to the formal safeguarding record.
The policy cannot stop people using their phones; that is how volunteers talk. It can say that concerns are raised on a channel the charity runs, where the safeguarding lead is in the conversation from the first message, where everyone in it has been told it is on the record, and where the volunteer’s words, the lead’s reply and the chair’s decision are the record rather than a reconstruction of it. The question for the trustees is whether the policy names such a channel, or whether it assumes the lead is at a desk.
Official guidance and your next step
The primary sources are the Charity Commission’s Safeguarding and protecting people for charities and trustees and its guidance on reporting a serious incident; Working Together to Safeguard Children 2026 (paragraphs 259 and 354 to 359) and the DfE’s guidance on keeping children safe in out-of-school settings; chapter 14 of the Care and Support Statutory Guidance for adults at risk; the Safeguarding Vulnerable Groups Act 2006 and the DBS’s referral guidance; and the Charity Governance Code. NCVO and the NSPCC publish template policies and procedure-writing guidance; the Commission’s advice is to “only use templates that are appropriate for your charity”.
The Charity Commission guidance covers England and Wales. Working Together and the Care Act discussion here apply to England; charities in Wales should use the Welsh safeguarding legislation and Wales Safeguarding Procedures. This is a summary, not legal advice. Charities affiliated to a national governing body of sport, a denomination or an umbrella body usually have to adopt that body’s policy as well.
Then do one thing: put the Commission’s twelve expectations beside the charity’s policy and, for each, write the name of the document or record that proves it. The blanks are the work.
We build ComplyChat for the work conversations organisations need to keep. The organisational archive described here is available on paid plans, with a connected Microsoft 365 tenant and retention configured by the organisation. A charity whose safeguarding lead is a volunteer with a day job needs a route that works from a personal phone on a Saturday evening, and that is what ComplyChat is: a channel the charity owns, on a compatible phone, on the record from the first message with everyone in it told so, filing into the charity’s own Microsoft 365 once the tenant is connected and kept under the charity’s own retention rules, with volunteers, trustees and parents who have no account on any of the charity’s systems joining by verified mobile number. It is not a safeguarding log or a case system; it is where a concern and the response can be recorded. A volunteer’s own messages stay in their own apps. There is no WhatsApp, Signal or Meta anything in the path.
How it works · Why us · Pricing · FAQ



