ComplyChat Start free

Guide · Charity governance

What policies does a charity need?

Search for the policies a charity needs and you will find lists of sixty or more, most of them templates. The honest answer is shorter and more useful: there is no single list in charity law, a handful of policies are required by other legislation once you employ people or handle personal data, the Charity Commission expects a further set of every charity, and the rest depend on what your charity actually does. This guide sorts them into those groups, explains what a small charity with no staff genuinely needs, sets out what every policy has to say to be worth having, and ends on the question the Commission itself asks after something goes wrong: was the policy followed, and can you show it?

By ComplyChatPublished 13 minute read

Two charity trustees walk and talk along the corridor of a community centre in late afternoon light, one carrying a ring binder under his arm, noticeboards blurred behind them
01

The rule: no single list, but three sources of obligation

Charity law in England and Wales does not contain a list of policies every charity must adopt. The Charities Act 2011 sets the rules on accounts, annual reports and the Commission's powers, and the Commission does not publish a single list of policies required of charities of any size. What the law does contain is the trustees' duty, set out in the Charity Commission's guidance The essential trustee (CC3), to comply with the charity's governing document and with the law, to manage the charity's resources responsibly and to be able to show that the charity is well run. Policies are how most charity trustees meet that duty in practice, so the useful question is less which policies are required by law than which obligations your organisation has taken on. Those come from three places.

  • Other legislation that applies to the charity as an employer, a controller of personal data or a provider of a regulated service. The Health and Safety Executive is plain about the first one: "If you have five or more employees, you must write your policy down." The Employment Rights Act 1996 requires the written statement every worker receives to cover disciplinary rules and procedures and who to go to with a grievance. UK GDPR, which sits alongside the Data Protection Act 2018, requires a controller, "where proportionate", to implement "appropriate data protection policies".
  • The Charity Commission's guidance. The Commission does not have power to write policies into law, but its guidance tells trustees what it expects, and it uses "should" deliberately. Its safeguarding guidance expects safeguarding policies and procedures, a code of conduct where there are staff or volunteers, and other policies besides; its reserves guidance (CC19) says "It is important for charities to have a policy explaining their approach to reserves"; its social media guidance says "If your charity uses social media, you should have a social media policy."
  • The codes and regulators that apply to what the charity does. The Code of Fundraising Practice, set by the Fundraising Regulator, for any charity that fundraises, alongside the Commission's own guide to trustees' fundraising duties (CC20). The Care Quality Commission, for a charity providing regulated care. Ofsted and the Department for Education, for a charity running a school, nursery or childcare. Each brings its own required policies.

The practical difference between "must" and "should" is smaller than it looks. When something goes wrong, the Commission's serious incident report asks the trustees to set out "which of the charity's policies or procedures relate to the incident and whether they were followed". A charity that did not have the policy the Commission expects is answering the first half of that question badly before it reaches the second.

This guide follows the Commission's guidance for England and Wales. Scottish charities are regulated by OSCR and Northern Ireland charities by the Charity Commission for Northern Ireland; the employment, health and safety and data protection points apply across the UK in broadly the same way, but check the regulator's own guidance for the charity-law points.

02

The policies, sorted by what triggers them

Sorting by trigger is more useful than a single list, because it tells a board which policies it can leave out and why. Start with the ones that apply to every charity, then add each group that applies to yours.

Every charity, whatever its size:

  • Safeguarding. The Commission treats protecting people as a governance priority for all charities, not only those whose beneficiaries are children or vulnerable adults. Every charity needs a named safeguarding lead (schools call the role the designated safeguarding lead) and a route for safeguarding concerns. Our guide to a safeguarding policy for a small charity sets out what it has to say.
  • Conflicts of interest. How trustees declare an interest and how the board goes about managing conflicts, and the register of interests behind it. The Commission's CC29 is the authority; see our guide to a conflict of interest policy.
  • Reserves. How much the charity aims to hold and why, including a reasoned decision to hold none. The trustees' annual report reports against it.
  • Financial controls. Who can authorise spending, who signs, how cash and online banking are handled and how the books are checked. The Commission's CC8 covers the controls it expects.
  • Data protection. Almost every charity holds personal data about donors, members, volunteers or beneficiaries, and a short data protection policy is the proportionate minimum. The Data (Use and Access) Act 2025 has amended UK GDPR and the Data Protection Act 2018, and its last data protection provisions came into force on 19 June 2026, so check the date on any ICO page you rely on.
  • Serious incident reporting. Who decides whether something must be reported to the Commission, and who reports it. The duty rests with the trustees whatever the policy says.

If the charity employs staff, add:

  • Health and safety, written down once there are five or more employees, and a risk assessment in every case.
  • Disciplinary and grievance procedures, which the written statement of particulars must refer to. The Acas Code of Practice is the standard an employment tribunal takes into account.
  • Whistleblowing, which the Commission lists among the policies it expects for staff. See our whistleblowing policy guide.
  • A code of conduct, equality and dignity at work, absence and leave, and expenses. These are good employment practice rather than charity law, and small employers can often combine them in one handbook.

If the charity has volunteers, add:

  • A code of conduct: the Commission's safeguarding guidance says "If you have staff or volunteers you should have a clear code of conduct".
  • A volunteering policy covering recruitment, role descriptions, induction, expenses and how problems are raised, written so that it does not accidentally create an employment relationship.
  • Health and safety arrangements that include volunteers, even where no employee is involved.

Depending on what the charity does, add:

  • Fundraising: a fundraising policy setting out how the charity raises money and protects donors in vulnerable circumstances, a fundraising complaints procedure, which the Code of Fundraising Practice makes a "must" ("You must have a clear and publicly available fundraising complaints procedure"), and a published route for staff and volunteers to report concerns about fundraising practice.
  • Complaints more generally: the Commission's safeguarding guidance expects "a complaints process for users and others with concerns". See our guide to a complaints procedure for a charity.
  • Social media, if the charity uses it: our social media policy guide follows the Commission's checklist.
  • Safer recruitment and DBS checks, if staff or volunteers work with children or adults at risk.
  • Risk management, usually a short policy and a risk register the board reviews, then investment, trading, lone working, campaigning and political activity, and the policies a sector regulator requires, where each applies.
03

What a small charity with no staff actually needs

A charity with five trustees, twenty volunteers and an income of a few thousand pounds a year does not need sixty policies, and adopting sixty is a risk in itself. Every policy is a promise: that someone will do what it says, in the way it says, within the time it says. A downloaded policy that nobody has read commits the charity to procedures it has never operated, and the gap between the document and the practice is exactly what the serious incident question exposes.

For most small charities without employees, the realistic set is short:

  1. Safeguarding, with a named lead and a route to report a concern that volunteers know.
  2. A code of conduct for volunteers and trustees, which can be two pages.
  3. Conflicts of interest, with an annual declaration and a register.
  4. Financial controls and reserves, which can sit in one document: two signatories, who approves what, how often the bank is reconciled, and the reserves target with its reasoning.
  5. Data protection, covering what personal data the charity holds, where, who can see it and how long it is kept.
  6. Health and safety arrangements for the activities volunteers actually carry out, and a first aid and fire plan for any premises.
  7. Complaints, and a fundraising complaints procedure if the charity fundraises from the public.

Several of these can live in one governance handbook, provided each part says who owns it and when it was last reviewed. Add a policy when something the charity starts doing triggers it: the first employee, the first activity with children, the first social media account, the first event with a bucket collection. Removing a policy the charity has outgrown is also a decision, and it should be minuted as one.

Policy templates have their place. NCVO, local voluntary and community infrastructure bodies and umbrella organisations publish downloadable templates, and they are good practice for structure and for spotting what a first draft has missed. The mistake is adopting one unchanged. A template written for a charity with an HR team will name roles your organisation does not have and promise timescales nobody will meet; strike out what does not apply and write in the names of the people who will actually do it.

The Charity Governance Code is a useful benchmark for boards that want to go further, but it is voluntary. As the Code itself puts it, "Compliance with the Code is not a regulatory requirement."

04

What every policy needs, whatever its subject

A policy is a statement of what the charity will do; a procedure is how. Small charities can keep both in one document, but each document should answer the same questions:

  • Purpose and scope: what the policy is for, and whether it covers trustees, staff, volunteers, contractors or all of them.
  • The named owner: a role, such as the safeguarding lead or the treasurer, rather than "the charity".
  • The procedure: what someone should actually do, in order, with the route to use when the named person is the problem.
  • The record: what gets written down, by whom, where it is kept and for how long.
  • Approval and review: the date the board approved it, the date of the next review, and what triggers an early one.

On review, the Commission's safeguarding guidance sets the standard most boards now apply to everything: policies and procedures should be "put into practice", "responsive to change" and "reviewed as necessary, always following a serious incident and at least once a year", and "available to the public". More generally, it says "Trustees must be assured that all policies, procedures and practice are checked and challenged to ensure they are fit for purpose."

The simplest tool for that is a policy register: one list of every policy the charity holds, its owner, the date of approval and the next review date, reviewed at a board meeting once a year. It is also the document a funder's due diligence form or a new trustee's induction asks for first.

Volunteers from a canal restoration charity in waders clear weed from an old lock on a grey morning while their coordinator watches from the towpath
05

Who asks to see them, and what they look for

Policies are read by more people than the board expects, and each of them is looking for something slightly different.

  • Funders ask for copies at application, commonly safeguarding, equality, data protection, health and safety and financial controls, and some ask when each was last reviewed.
  • The independent examiner or auditor reads the financial controls and the reserves policy against what the accounts show.
  • The Charity Commission reads them after a serious incident report, a concern raised by the public or a regulatory compliance case, and asks whether they were followed.
  • Staff, volunteers and beneficiaries read them when something has gone wrong for them, and judge the charity by whether it did what it said.
  • A court or tribunal reads the disciplinary, grievance and whistleblowing procedures against what actually happened to the individual.

Every one of those readers moves quickly from the document to the evidence. A safeguarding policy promises that concerns are recorded and passed to the lead; the question becomes where the record of the last concern is. A conflicts policy promises annual declarations; the question becomes where the declarations are. A financial controls policy promises two authorisations; the question becomes who authorised the payment, and when. The policy is the easy half. The record of the charity following it is the half that is usually missing.

06

The policy is followed in a message

Most charity policies describe a route: raise a safeguarding concern with the lead, declare an interest to the chair, pass a complaint to the complaints officer, get a second trustee to approve the payment. In a small charity, almost every one of those routes is travelled first in a message. A volunteer texts the coordinator on a Saturday afternoon about something a child said. A trustee messages the chair to say she knows one of the tenderers. The treasurer asks the trustees' WhatsApp group whether anyone objects to paying the roofer before the meeting, and three people reply with a thumbs up.

Each of those is the policy working. Each is also the only evidence that it worked, and each sits on the personal phones of the people involved, in a consumer app whose messages are end-to-end encrypted between their devices so that the charity holds no copy of its own. When the coordinator moves away or the chair steps down, the evidence leaves with them. If the Commission later asks whether the safeguarding procedure was followed, the honest answer is that it was, and that the charity cannot show it.

The fix is not a longer policy. It is giving those messages somewhere to land that the charity controls. ComplyChat provides channels for that kind of work conversation, in which everyone added is told the channel is on the record and can object or leave, and a mobile number verified by SMS is an identity, which matters in a charity where volunteers and many trustees have no work account. Messages are recorded on the server as they are sent. On paid plans, once the charity's Microsoft 365 tenant is connected, the lasting record files there under the charity's own retention rules. It is not a policy library, it does not write or review policies, and a charity whose conversations already happen in a system it controls does not need it. ComplyChat Free is personal messaging with one private group, direct messages and three calendar months of recent history, with no Microsoft 365 archive, so it is not a way to meet a retention duty.

A question for the next board meeting: pick the last three decisions or concerns that a policy covered, and ask where the evidence that the policy was followed is kept today. If the answer for any of them is somebody's phone, the policy register is describing a charity that cannot yet prove it exists.

07

Official guidance and your next step

The Charity Commission's The essential trustee (CC3) sets out the duties the policies serve, and its safeguarding and protecting people guidance contains the clearest statement of the policies it expects. The subject-specific guidance is CC19 on reserves, CC8 on internal financial controls, CC29 on conflicts of interest, charities and social media, CC20 on fundraising and how to report a serious incident. For employment policies, the HSE's guidance on a health and safety policy and NCVO's guidance on creating policies and procedures are the practical starting points, and the Code of Fundraising Practice covers fundraising. Quotations are from those pages as published on 25 September 2026; check the date on the page you read.

This guide is a practical summary for trustees of charities in England and Wales, not legal advice. Where a policy touches employment, a regulated service or a live incident, take professional advice on your own facts.

Then do one thing: make a policy register. List every policy the charity holds, its owner, when the board last approved it and when it is next due, and put the review on the agenda of a board meeting this year. Any policy nobody can name an owner for is the first one to rewrite or retire.

Why we publish this

We build ComplyChat for the work conversations organisations need to keep. A charity's policies are mostly carried out in messages between volunteers, staff and trustees, and the record that shows a policy was followed is the one most boards do not hold. Explore Free personal messaging, or compare the paid plans if your charity needs a lasting Microsoft 365 archive.

Explore Free · How it works · Compare plans

Sources

Every document this guide quotes or links to, in the order it first cites them.

  1. Acas Code of Practice acas.org.uk
  2. The essential trustee (CC3) gov.uk
  3. Safeguarding and protecting people guidance gov.uk
  4. CC19 on reserves gov.uk
  5. CC8 on internal financial controls gov.uk
  6. CC29 on conflicts of interest gov.uk
  7. Charities and social media gov.uk
  8. CC20 on fundraising gov.uk
  9. How to report a serious incident gov.uk
  10. HSE's guidance on a health and safety policy hse.gov.uk
  11. NCVO's guidance on creating policies and procedures ncvo.org.uk
  12. Code of Fundraising Practice fundraisingregulator.org.uk