Charity Policy Management: What Trustees Need to Know
Published 15 July 2026
By Brian Crocker
A trustee at a small housing charity in the North West raised the same question at every board meeting for two years: "Have we reviewed the safeguarding policy?" The answer was always a variant of "yes, we looked at it recently" — but when the Charity Commission opened a regulatory compliance case following a complaint, the board could not produce a review record. The policy existed. The evidence of governance did not.
Charity trustees have a duty to ensure their organisation is well-governed. For most charities, that includes maintaining policies that are fit for purpose and evidence of regular review. The Charity Commission does not prescribe exactly which policies a charity must have — but it does assess whether trustees have discharged their governance duties, and the absence of documented policy governance is a recurring finding in regulatory cases.
This guide covers what the Charity Governance Code expects, which policies matter most for Charity Commission compliance, and how small charities can build a review system that is both manageable and evidenced.
What the Charity Governance Code Says About Policies
The Charity Governance Code is the primary best-practice framework for UK charities. Compliance is not a legal requirement — the Code operates on an "apply or explain" basis — but the Charity Commission uses it as a reference point when assessing governance quality. A board that cannot explain how it has applied the Code's principles is at risk.
The Code emphasises that trustees are collectively responsible for governing the charity and managing its resources. On policies specifically, it expects that policies, processes and practices are tailored to the charity, and for trustees to review these as part of regular governance oversight.
In practice, the Commission's concerns about policy governance centre on three things:
That policies exist at all. Small charities often operate without written policies in areas where they are clearly needed — data protection, safeguarding, financial controls. This is not a governance technicality; it creates real legal and operational risk.
That policies are owned and reviewed. A policy written in 2019 and not touched since does not demonstrate active governance. The Commission expects trustees to be able to show that policies are kept current against the charity's evolving activities and the regulatory environment.
That trustees can evidence their oversight. Board meeting minutes that record "safeguarding policy reviewed and approved" provide evidence. A verbal assertion that "we looked at it" does not.
Which Policies Matter Most for Charity Compliance
There is no statutory list of required charity policies comparable to what maintained schools must have. But the areas where policy gaps create the most compliance risk for registered charities are well-established:
Safeguarding. Any charity working with children, young people, or adults at risk needs a safeguarding policy. The Charity Commission expects this to be current, to reflect the relevant statutory guidance (Working Together to Safeguard Children for charities working with children), and to be reviewed at least annually. Safeguarding failings are among the most common subjects of Charity Commission regulatory action.
Data protection. Charities hold personal data and must comply with UK GDPR and the Data Protection Act 2018. A data protection policy, privacy notice, and a record of processing activities (ROPA) are the minimum documentation the ICO expects.
Financial controls. Charities must be able to demonstrate to their auditors and the Commission that they have adequate financial controls. An expenses policy, a financial controls policy, and a reserves policy are standard. For charities above the audit threshold, the independent examiner or auditor will expect these.
Conflicts of interest. The Commission considers conflicts of interest a high-risk governance area. A documented conflicts of interest policy — and evidence that it is applied at board meetings — is a basic governance requirement.
Equal opportunities and diversity. Public-benefit charities increasingly need to demonstrate that their governance reflects equalities obligations. An equal opportunities policy that covers both beneficiaries and staff is expected.
Complaints and whistleblowing. Charities need a clear process for handling complaints from beneficiaries or the public, and a route for staff and volunteers to raise concerns safely. Both should be documented and reviewed.
The Trustee Board's Role in Policy Governance
Trustees are not expected to write policies — that is typically the staff team's job. But trustees are responsible for ensuring that the charity has the policies it needs, that they are fit for purpose, and that there is a system for keeping them current.
In a small charity, the governance structure is often informal enough that these responsibilities can drift. The CEO assumes the trustees have approved the safeguarding policy. The trustees assume the CEO has reviewed the data protection policy. Neither has happened.
A clear allocation of responsibility resolves this:
Trustees own: approval of all policies; ensuring policies exist in high-risk areas (safeguarding, finance, data protection); receiving a regular report on policy currency.
Staff own: drafting policy updates; scheduling reviews; flagging when policies need to change in response to regulatory changes; managing the day-to-day review process.
The chair or a nominated trustee coordinates the governance oversight — receives the policy status report before each board meeting and confirms that the board's policy obligations are being met.
Policy reviews should be minuted at board level for statutory or high-risk policies. "Safeguarding policy reviewed, no material changes required, approved by the board on [date]" is sufficient. An undocumented verbal discussion is not.
Building a Manageable Review Cycle
Small charities often have twenty to forty policies. At an annual review cycle, that is one or two policies per month. The approach that works is:
-
List every policy you have — including those you know are out of date. A gap-analysis approach: what policies do we have, what policies do we need, are there areas where we are operating without written procedures?
-
Categorise by risk. Safeguarding and data protection: annual minimum review. Financial controls: annual. Other operational policies: every two years. The Policy Review Schedule Generator helps you build this calendar from your policy list.
-
Assign a lead trustee or staff member to each high-risk policy. Not the whole board — one person who is responsible for flagging when a review is needed and presenting the updated policy for board approval.
-
Build the review into the board calendar. Before the AGM is a natural moment: review all governance and financial policies, ensure everything is current for the annual report. Tie safeguarding reviews to September or October, aligned to the DfE's KCSIE annual update cycle.
-
Record it. A brief note in the board minutes, plus a policy register showing the current version, the review date, and the approving trustee meeting, creates the paper trail the Commission expects to see.
Our Policy Register Template is a free browser-based tool for building a charity policy register — all policies in one place, with owner, version, last-reviewed date, and review frequency. Export to CSV and share with your board.
Managing Policy Governance Across a Multi-Branch Charity
Charities with multiple branches, sites, or subsidiary organisations face a version of the MAT problem: some policies are owned at organisational level, others at branch level. Clarity about which applies at each level — and who reviews and approves each — is essential.
The most common issue is safeguarding. A charity with twelve local branches may have a central safeguarding policy but branch-level designated safeguarding leads who each maintain their own local procedures. Without a clear relationship between the central policy and the branch procedures, inconsistency accumulates and the central governance oversight becomes nominal.
PolicyBoard is designed for exactly this: managing the relationship between central and branch-level policies, with clear ownership, version tracking, and an audit trail that holds up at a Charity Commission inspection. Join the waitlist to be notified when it launches.
Sources
- Charity Governance Code
- Charity Commission: Guidance for charity trustees
This guide is written for charity trustees, chief executives, and governance leads at small to medium UK registered charities. It covers general principles of good governance based on Charity Commission guidance and the Charity Governance Code. Requirements and expectations evolve — always verify obligations against current Charity Commission guidance and the charity's own governing document. This is not legal advice.
Stop tracking policy reviews in spreadsheets
PolicyBoard automates review reminders, approval workflows, and compliance dashboards for UK regulated organisations.
Related articles
Housing Association Policy Management: RSH Standards
How registered social landlords manage their policy obligations under the RSH Consumer Standards — what the governance framework requires, which policies drive regulatory compliance, and how to build a review system that holds up to IDA scrutiny.
Parish Council Policies: What Clerks Need to Know
Which policies parish and town councils must have, what the governance framework requires, and how clerks can build a review system that holds up to internal audit and principal authority scrutiny.
School Policy Management: Guide for Business Managers
How schools and multi-academy trusts manage their statutory and operational policy obligations — what must be reviewed, what must be published, and how to keep track without it consuming a working week.