Trustee Meetings
← All guides

Duties & compliance

Charity Risk Management Policy & Risk Register: Free Template

By the Trustee Meetings editorial team, led by Brad Askew — founder, non-practising solicitor.

Last reviewed: 20 July 2026

If the phrase "risk register" makes you picture a colour-coded corporate spreadsheet that nobody reads, you are not alone — and you are probably closer to good practice than you think. Most small charity boards already manage risk every time they ask "what happens if the grant doesn't come through?" or "who checks the minibus insurance?". A risk management policy and register simply write that instinct down, so it survives trustee changes and gets discussed before the crisis rather than during it.

A charity risk management policy is the document that sets out how your trustees identify, assess and manage the major risks to the charity's beneficiaries, money, people, operations and reputation — and the risk register is the working table where those risks are recorded, scored and tracked. The policy is short; the register does the daily work. Most people searching for a "risk management policy" actually need both, which is why our free template includes the two together.

Is it legally required? For most small charities, no statute demands a risk management policy — but the Charity Commission expects every charity to manage its risks, the charity annual return asks directly whether you have one, and larger charities must make a formal risk statement in their trustees' annual report. The detail matters, so let's take it precisely.

Is a charity risk management policy legally required?

There are three distinct layers, and it helps to keep them separate.

Statutory audit charities: a legal reporting requirement. Charities that are required by law to have their accounts audited — broadly, income over £1 million, or gross assets over £3.26 million combined with income over £250,000 — must make a risk management statement in their trustees' annual report (thresholds are due to rise for accounting periods ending on or after 30 September 2026). Under the Charities (Accounts and Reports) Regulations 2008, as set out in CC26, the trustees confirm that they have given consideration to the major risks to which the charity is exposed and satisfied themselves that systems or procedures are established to manage those risks. The Charities SORP (FRS 102) separately requires larger auditable charities to describe the principal risks and uncertainties facing the charity, together with a summary of their plans and strategies for managing those risks. You cannot honestly sign that statement without something resembling a register. Charities below the audit threshold are encouraged to make the same statement as good practice.

Every charity: a Charity Commission expectation. The Commission's guidance Charities and risk management (CC26) applies to charities of all sizes in England and Wales. It sets out a five-stage model — establish a risk policy, identify risks, assess them, decide what action to take, and monitor periodically — and describes risk management as a key part of effective governance for charities of all sizes and complexity, applied proportionately to the scale of the charity's activities.

The annual return prompt. The charity annual return for 2023 onwards asks charities completing the policy question whether they have an internal risk management policy — one of thirteen named policies the Commission asks about. Answering "no" is not an offence, but it is a signal to the regulator, and to you, that a gap exists.

So the honest summary for a small charity: not legally compulsory, firmly expected, asked about annually, and legally reportable once you reach audit size. It is also, of the thirteen annual-return policies, the one that makes all the others work — your safeguarding, reserves and financial-controls policies are all mitigations that belong on the register.

If you are working out which policies your charity needs overall, start with our pillar guide to what policies a charity needs.

Policy or risk register — which do you actually need?

Both, but they do different jobs. The policy is one or two pages, adopted by the board, that says how your charity approaches risk: what you will and won't accept, who does what, how often the register is reviewed. It changes rarely. The register is the living document — a table, usually one page for a small charity, listing your top eight to fifteen risks with scores, mitigations and owners. It changes whenever reality does.

A register without a policy drifts, because nobody has agreed who maintains it or what the scores mean. A policy without a register is a promise with no evidence behind it. The NCVO's free sample documents include a sample risk register you can look at; our template pairs the register with the policy wrapper so you adopt them as one.

What your risk management policy must include

A good small-charity policy has five sections. Here is what each should say.

1. Purpose and risk appetite

State why the policy exists — to help trustees protect the charity's beneficiaries, assets and reputation while still taking the sensible risks that charitable work requires. Then include a plain-English risk appetite statement. It does not need jargon. Something like: "We accept measured risk in pursuit of our charitable purposes — new projects, new funders, new partnerships. We have no appetite for risks to the safety of beneficiaries, to legal compliance, or to the charity's solvency, and we will always mitigate these as a priority." Two sentences that tell future trustees where the lines are.

2. Roles and responsibilities

The board owns risk; it cannot delegate that ownership away. But maintenance is delegable: name who keeps the register up to date between meetings — typically the coordinator, manager or a finance/risk subcommittee in a slightly larger charity — and confirm that every individual risk has a named owner (a person, not "the board"). Say explicitly that the board reviews the full register annually and the top risks at every meeting.

3. The risk register — how it works

Commit the charity to maintaining a register, define its columns and scoring system (covered fully in the next section), and adopt CC26's risk categories so risks are identified systematically rather than only when they are already on fire.

4. Escalation triggers

Define what jumps the queue. Sensible triggers for a small charity: any risk scoring 15 or more goes to the chair immediately and to the next board meeting as a standing item; any new risk with an impact of 5 is reported to the chair within a week regardless of likelihood; and anything that meets the Commission's threshold for a serious incident triggers the serious incident reporting process as well as a register update.

5. Links to your other policies and review cadence

Say how the register connects to the rest of your governance. Your reserves policy is the mitigation for financial shocks — the register should reference the reserves target set under CC19. Your financial controls (CC8), safeguarding procedures and insurance are mitigations for other rows. Finish with the review cycle: full annual review by the board, top-risks summary at each meeting, early review on defined triggers.

The charity risk register: columns, categories and scoring

This is the part people actually want, so here it is in full.

The columns

A small-charity register needs eight columns and no more:

ColumnWhat goes in it
Risk descriptionOne specific sentence: cause and consequence ("Loss of main grant funder leaves a £30k hole in next year's budget")
CategoryOne of the CC26 categories below
Likelihood (1–5)1 = remote, 3 = possible, 5 = highly probable
Impact (1–5)1 = insignificant, 3 = moderate disruption, 5 = extreme (major service interruption, existential)
ScoreLikelihood × impact, out of 25
MitigationsWhat you already do, and what you plan to do, to reduce likelihood or impact
OwnerA named person responsible for the mitigations
Review dateWhen this row is next checked

Some registers record a "gross" score (before mitigations) and a "net" score (after) — CC26 illustrates this. For a small charity, one score reflecting your current mitigated position is usually enough; add the gross/net split only if the board finds it useful.

The categories (from CC26)

CC26 groups charity risks into five categories: governance (skills gaps on the board, unmanaged conflicts of interest, poor structure), operational (service delivery failures, loss of key staff or volunteers, premises, safeguarding incidents), financial (loss of funding, weak budgetary control, inadequate reserves, fraud), external (changes in government policy, demographic shifts, public perception, economic conditions) and compliance with law and regulation (breach of trust, employment law, data protection). Many charities add reputational as a sixth heading; CC26 treats reputational damage as a consequence that can arise from any category, and either approach is fine as long as reputation gets discussed. Walking through the categories once a year is the single best way to find the risks you have been quietly not thinking about — safeguarding risks in particular belong on every register, not just those of children's charities.

Scoring honestly

Multiply likelihood by impact and you get a number out of 25. Broadly the same bands CC26 uses on its weighted heat map work for the simple product too: 15 and above is a red risk needing urgent board attention, 8–14 is amber and needs active management, 7 and below is monitored. CC26 also offers a weighted formula that gives extra emphasis to impact, which some boards prefer so that low-likelihood catastrophes don't slip down the ranking.

Be honest about what the numbers are: a conversation-forcing device, not science. Nobody can tell the difference between a likelihood of 3 and a likelihood of 4 with any rigour, and that is fine. The value of scoring is that it makes trustees argue — "why have we scored losing the lease as a 6 when we have no alternative premises?" — and the argument is the risk management. If your register's scores never change and never provoke discussion, the register has stopped working, whatever the numbers say.

A worked example row

Here is what a good row looks like for one of the most common small-charity risks:

Risk descriptionCategoryLikelihoodImpactScoreMitigationsOwnerReview
Loss of main grant funder (60% of income) at renewal in MarchFinancial3515Funder diversification target (no funder >40% by 2028); 4 months' running costs held as free reserves per reserves policy; early renewal conversation diarised for SeptemberTreasurerEach board meeting

Notice what makes it useful: the description is specific enough to act on, the mitigations are real things with dates and targets rather than "monitor closely", and the owner is a person. A score of 15 puts it in the red band — which is exactly right for a charity with one dominant funder, and exactly the conversation the board should be having.

The top-risks summary at every board meeting

Don't table the full register at every meeting; boards glaze over. Instead, put the top five risks — highest scores plus anything that moved — on every agenda as a standing item, with one line each on what changed. Ten minutes, every meeting. This is where a tool earns its keep: Trustee Meetings keeps risk as a standing agenda item and mirrors each risk's agreed actions into the trustee action log, so "treasurer to open renewal conversation with funder by September" is chased automatically rather than rediscovered at the year-end review.

Download our free charity risk management policy template (Word) — openly licensed, written for small charities in England and Wales, and yours to adapt with no sign-up. It includes the policy wrapper and a ready-to-use charity risk register template with the columns, categories and scoring bands above.

Adopting it properly

A policy and register only count once the board has adopted them. Tailor the template first — delete categories of risk you genuinely don't face, set your own appetite statement and escalation thresholds, and draft your first register as a board exercise rather than a solo job (thirty minutes of a meeting spent brainstorming risks against the five CC26 categories will produce a better register than any template alone). Then take a board decision to adopt, record it in the minutes, and give the policy itself an owner and a review date. If your board uses Trustee Meetings, the policy sits alongside your agendas and minutes with its owner and review date attached, and resurfaces automatically when the review falls due — free to try, no card needed.

Common mistakes

Twenty-five risks, none owned. A long register feels thorough and achieves nothing. Eight to fifteen risks with named owners beats an encyclopaedia every time.

Generic risks copied from a template. "Cyber attack — likelihood 2, impact 3" tells you nothing. "Treasurer's laptop holds the only copy of the accounts and has no backup" is a risk you can fix this week.

Mitigations that are hopes. "Monitor the situation" and "maintain good relationships" are not mitigations. A mitigation reduces likelihood or impact and can be checked: a reserves target, a second signatory, a backup, a diarised conversation.

Scoring by one person. If the treasurer fills in all the scores alone, the register records one person's anxieties. Score the top risks together as a board at least once a year — disagreement about a score is information.

The register and the reserves policy never meeting. Your free reserves exist to absorb the financial risks on your register; the two documents should quote each other. If your register says losing a funder is a 15 and your reserves policy holds two weeks' costs, one of them is wrong.

Filed and forgotten. The commonest failure of all. A register last updated three years ago is worse than none, because it gives false comfort — and it undermines the SORP risk statement if you are audited.

When to review your policy and register

Formally review the full register once a year as a board — ideally alongside the budget, so financial risks and reserves are set together — and re-adopt the policy itself every two to three years or when the review falls due. Between annual reviews, the top-risks summary at each meeting keeps the register alive; if your board meets four to six times a year (see our guide on how often trustees should meet), that rhythm is enough for most small charities.

Trigger an early review whenever the risk landscape actually shifts: a major funder gives notice or a renewal looks shaky, a serious incident occurs or is reported to the Commission, you take on staff, premises or a new activity for the first time, a key trustee or staff member leaves, or an external shock (policy change, cost inflation, a safeguarding issue in your sector) changes the odds. The test is simple: would a new trustee reading your register today recognise the charity it describes? If not, review it now — the free template gives you a clean structure to rebuild from in an afternoon.

Risk management sits at the centre of a web of policies, so it pairs naturally with the rest of this series: start with the pillar guide to what policies your charity needs, then make sure your reserves policy actually matches the financial risks on your register, check your safeguarding policy covers the operational risks that matter most, and use a trustee action log to make sure the mitigations you agree at board meetings actually happen.

Related guides

TrusteeMeetings.co.uk is a governance tool, not a law firm — this is information, not legal advice.