Safeguarding is the policy trustees worry about most, and with reason: it is the one where the Charity Commission's expectations are highest, and the one where a gap can hurt a person rather than a spreadsheet. It is also the policy most often borrowed from a bigger organisation and never made to fit — full of job titles the charity does not have and procedures nobody could follow on a bad afternoon.
Here is the position, plainly. A charity safeguarding policy is the document that sets out how your charity protects everyone who comes into contact with it from harm, and exactly what every trustee, staff member and volunteer must do when they have a concern. The Commission expects every charity in England and Wales to have safeguarding policies and procedures — whatever its size, whatever it does, and whether or not it works with children or adults at risk. Where it does, the expectation rises sharply: a fuller policy, a designated safeguarding lead, safer recruitment with DBS checks at the right level, and clear routes to the local authority and police.
The good news: a genuinely strong safeguarding policy for a small charity is short, specific and buildable in an afternoon. This guide covers the legal position, every section your policy needs, the reporting routes that must work under pressure, and the mistakes that turn a policy into a liability — with a free template to adapt.
Does every charity need a safeguarding policy?
Yes. The Commission's guidance, Safeguarding and protecting people for charities and trustees, is unambiguous: trustees must take reasonable steps to protect from harm the people who come into contact with their charity, and every charity should have policies and procedures covering how people are protected, how concerns are raised, and how allegations and incidents are handled and reported to the authorities. The guidance expects those policies to be put into practice — not filed — reviewed regularly, and made available so people know how to raise a concern.
The same guidance opens with ten actions every trustee board should take, from establishing an adequate policy and code of conduct through identifying risks, making reporting pathways clear, and reviewing which posts need DBS checks. And the charity annual return asks charities completing it, directly, whether they had "safeguarding policy and procedures" in place at the end of the financial period — one of thirteen named policies, and — although the guide itself notes that appropriate policies vary with a charity's size, nature and activities — the one hardest to justify ticking "no" to, because unlike most of the others it applies whatever your charity does. For where safeguarding sits among the rest, see our pillar guide to what policies a charity needs.
Retire one misconception here: "we don't work with children, so safeguarding doesn't apply to us." It does. Safeguarding in the Commission's sense covers everyone the charity touches — volunteers, staff, beneficiaries, event attendees, donors. A village hall charity, a grant-maker, a heritage society: all are expected to have thought about how they protect people and what happens when a concern is raised. The policy for a charity with no contact with children or adults at risk can be two pages. It cannot be zero.
Is a safeguarding policy a legal requirement?
Be precise about the legal ladder — it matters when the board asks.
No single statute requires every charity to hold a written safeguarding policy. The universal expectation comes from the Charity Commission, grounded in trustees' legal duties to act with reasonable care and skill and to protect the charity's beneficiaries and reputation. A regulator's expectation is not optional in any practical sense — safeguarding is consistently among the most common subjects of serious incident reports and Commission compliance cases — but it is an expectation, not an Act of Parliament.
The criminal law bites on specific conduct. Under section 9 of the Safeguarding Vulnerable Groups Act 2006 it is a criminal offence — punishable by up to five years' imprisonment — to permit a person to engage in regulated activity with children or vulnerable adults (the Act's term) while knowing, or having reason to believe, that they are barred from it. That is why safer recruitment and barred-list checks are not paperwork: they are how a charity avoids committing an offence.
Statutory guidance applies when you work with children or adults at risk. Charities working with children in England are expected to work within Working Together to Safeguard Children, the statutory inter-agency guidance, which expressly extends to voluntary, charity and faith-based organisations; in Wales, the Wales Safeguarding Procedures apply. For adults, the Care Act 2014 frames the local authority duties your procedures must connect with.
Safeguarding incidents are reportable to the Commission. Actual or alleged incidents that cause, or risk, significant harm to people connected with your charity are serious incidents, reportable through the Commission's serious incident procedure as soon as reasonably possible. A policy that never mentions this leaves trustees to discover the duty mid-crisis.
One policy, two levels
Every charity needs the baseline: a statement of commitment, named responsibility, a code of behaviour, and clear routes for raising and reporting concerns. A charity working with children or adults at risk — an adult at risk being, in the Care Act 2014 sense, an adult with care and support needs who is experiencing or at risk of abuse or neglect and unable to protect themselves because of those needs — needs the substantially enhanced version set out below. The anatomy covers the full version; a charity with no such contact can slim several sections, but should still be able to point to each heading and say what its answer is.
What your safeguarding policy must include
Section by section, this is what a complete safeguarding policy for a small charity in England and Wales contains, and what good looks like in each.
- Purpose and scope. One paragraph: the charity is committed to protecting everyone who comes into contact with it from harm, and this policy applies to all trustees, staff, volunteers and contractors, in person and online. Name the charity, not "the organisation" — borrowed scope statements are where cut-and-paste policies give themselves away.
- Definitions. Define child (anyone under 18 — including a 17-year-old volunteer, which surprises many boards), adult at risk (the Care Act 2014 formulation above), and the recognised types of abuse: physical, emotional, sexual, neglect, financial, discriminatory, domestic and organisational, plus exploitation and radicalisation where relevant. Two clear sentences per term beat a page of legalese nobody reads.
- Designated safeguarding lead and deputy. Name a lead — a real person, with contact details — responsible for receiving concerns, deciding referrals, keeping records and liaising with the local authority safeguarding partnership, and a deputy for when they are away or the concern is about them. In a small charity the lead is often a trustee or the senior staff member; what matters is authority to act and availability to be reached.
- Safer recruitment. How every role — paid or voluntary — is risk-assessed, advertised with the charity's safeguarding commitment, interviewed with gaps in history explored, referenced, and DBS-checked at the level the role is eligible for: standard, enhanced, or enhanced with barred-list check for regulated activity, never higher than the role qualifies for. State that no one barred from regulated activity will ever be engaged in it — the section 9 offence — and that checks are renewed on a stated cycle.
- Code of behaviour. The practical do's and don'ts for everyone acting in the charity's name: never alone and unobserved with a child as a matter of design, no personal social-media contact with young beneficiaries, no gifts or favouritism, appropriate physical contact and language, what to do if you find yourself in a situation the code did not anticipate. This is the section volunteers actually use — write it for them.
- Recognising and responding to concerns. The signs of abuse and neglect in brief, and the golden rules for the moment someone discloses: listen, don't promise secrecy, don't investigate or interview, record what was said in the person's own words, and pass it to the safeguarding lead the same day. Make explicit that a concern does not need to be proven to be raised.
- Reporting routes. The heart of the policy — see the next section. Internally: concern → safeguarding lead (or deputy, or chair if the concern involves the lead) → decision within a stated time. Externally: the local authority, LADO, police, DBS and Charity Commission routes set out below. A one-page flowchart with real phone numbers turns this section from prose into a procedure.
- Online and digital safeguarding. How the charity keeps contact with beneficiaries safe online: which platforms and accounts may be used, group rather than one-to-one messaging with young people, parental consent for online sessions, moderation of the charity's social channels, and how online concerns are reported through exactly the same routes as offline ones.
- Photography, film and consent. Written consent before images of children or adults at risk are taken or published, no full names alongside photographs, secure storage, and an easy way for consent to be withdrawn. Small charities are caught out here more often than anywhere else — usually by a newsletter.
- Training. Who is trained, to what level, how often. At minimum: safeguarding induction for everyone, refreshed on a stated cycle, with the designated lead trained to a higher level. The Commission expects charities working with children or adults at risk to provide regular training and to evaluate whether it works.
- Record-keeping and confidentiality. Concerns recorded on a standard form, factually, promptly and in the speaker's own words; stored securely and separately from general files, with access restricted; retained for the period your retention policy sets — for safeguarding records, decades rather than years. Confidentiality means need-to-know sharing; it never means secrecy from statutory agencies.
- Review. A named owner, a review at least annually and immediately after any incident, near-miss or change in the law or your activities, and the date and version on the front page. An undated safeguarding policy reads as an unowned one.
Download our free charity safeguarding policy template (Word) — openly licensed, written for small charities in England and Wales, and yours to adapt with no sign-up.
The Charity Commission itself publishes no safeguarding policy template — its guidance points to sector bodies instead. NCVO publishes free governance samples (though no safeguarding policy); for safeguarding itself, NSPCC Learning's example safeguarding policy statement is the sector reference — free to download and tailor for charities working with children, though the NSPCC retains its copyright, so treat it as a base for your own document rather than something to republish.
Reporting routes: who you tell, and when
When a concern lands, nobody should be composing a decision tree from scratch. The routes, in the order a real incident meets them:
- Immediate danger — 999. Safety first, policy second. The police, then the safeguarding lead.
- Concern about a child or adult at risk — the local authority. The Commission's guidance is direct: refer safeguarding concerns about children or adults at risk to your local authority's children's or adult safeguarding team. Your policy should carry the actual numbers for the areas where you operate.
- Allegation against your own people — the LADO. Where the allegation is that someone who works or volunteers for your charity has harmed, or may pose a risk to, a child, it goes to the local authority designated officer as well — not into an internal HR process first. Adult equivalents run through the adult safeguarding team.
- Someone removed from regulated activity — the DBS. If your charity stops someone working in regulated activity because they harmed or posed a risk of harm to a child or adult at risk, referral to the Disclosure and Barring Service is a legal duty, not a discretion.
- The Charity Commission — a serious incident report. Actual or alleged abuse or mistreatment of people connected with your charity, or a serious breach of your own safeguarding procedures, is a reportable serious incident. Report via the Commission's online form as soon as reasonably possible, saying what the charity has done about it; trustees may delegate the filing but remain responsible for it happening.
Reporting to the Commission is not an admission of failure — charities that report promptly and show they acted are treated very differently from those the Commission hears about from a newspaper.
Adopting it properly
A safeguarding policy becomes real through the same sequence as any policy, applied with more care. Tailor the template until every named role exists and every phone number is right. Take it to the board, discuss it — this one deserves more than "taken as read" — and adopt it by a recorded decision so the minutes show what was adopted and when. Then give it an owner, a review date, and a place where both resurface: Trustee Meetings keeps policies, owners and review dates alongside your agendas and minutes and brings each back when due.
Induction is the other half of adoption. A safeguarding policy nobody has read protects nobody: build it into every trustee, staff and volunteer induction, and put it in your trustee welcome pack so new board members meet it in week one.
Common mistakes
- The borrowed giant. A 30-page policy from a national charity, complete with a head of safeguarding the charity does not employ. If your people cannot find the "what do I do right now" page in thirty seconds, the policy fails at the only moment it exists for.
- A lead with no deputy. One name, one phone, one fortnight in Portugal. Every concern route needs a second person — and a route that bypasses the lead when the concern is about the lead.
- DBS as the whole answer. A clean certificate is a snapshot, not a character reference. Treating the check as the end of safer recruitment skips the references, gap-probing interviews and supervision that actually catch problems.
- No online provisions. Sessions, mentoring and messaging moved online years ago; a policy that assumes every risk happens in a hall has a hole where much of the contact now is.
- Silence on the Commission. Policies that end at "tell the local authority" leave trustees unaware that the same incident is usually a reportable serious incident too.
- The unminuted adoption. If the minutes cannot show when the policy was adopted and last reviewed, then to the Commission, an insurer or a tribunal, it barely exists.
Review: annually, and after anything
Safeguarding sits on the shortest review cycle of any charity policy: at least once a year, and immediately after any incident or near-miss, any change in activities (a new youth project, a move online, work in a new area), any change in key personnel, or a change in the law or Commission guidance. Each review, however brief, goes in the minutes with a next-review date attached. If review dates in your charity have a habit of dissolving, Trustee Meetings resurfaces each policy when its date comes round, so safeguarding never silently goes stale — free to try, no card needed. And when the review lands, our free safeguarding policy template gives you a current baseline to check your document against.
Safeguarding does not stand alone: it leans on your volunteer policy for recruitment and supervision, your complaints policy for the concerns that arrive as grievances, and your data protection policy for the confidential records it generates — and a trustee action log is the simplest way to keep the actions each review produces visible until they are done.