Ask a room of trustees which policies their charity is supposed to have and you will get a room of uneasy answers. Somewhere between the governing document and the last away-day, most boards have accumulated a folder of policies — some adopted, some half-drafted, some downloaded years ago and never read since — and a nagging feeling that a proper charity would have more.
Here is the reassuring truth: the law requires far fewer written policies than most trustees fear, the Charity Commission has a short, knowable list of the ones it expects, and everything beyond that is a matter of matching policies to what your charity actually does. This guide sets out the complete picture — all 52 policies a charity could reasonably be expected to have, organised by how strongly each is required — and, for each one where a good free template exists, a link to an authoritative source that has published it for charities to use and adapt at no cost.
The three tiers: required, expected, and good practice
Every charity policy sits in one of three tiers, and knowing which tier you are looking at removes most of the anxiety.
Tier one is the law. For an ordinary charity in England and Wales, remarkably little is unconditionally required in writing: a health and safety policy once you employ five or more people (Health and Safety at Work etc. Act 1974, section 2(3)); disciplinary rules and a grievance route, which must be specified in every employee's written statement of particulars (Employment Rights Act 1996, section 3); and privacy notices telling people how you use their personal data (UK GDPR, Articles 13 and 14). Two more become legal requirements in particular circumstances: a written investment policy statement if trustees delegate investment management to a discretionary manager (Trustee Act 2000, section 15), and fundraising statements in the trustees' annual report for charities whose accounts are subject to statutory audit (Charities (Protection and Social Investment) Act 2016, section 13).
Tier two is what the Charity Commission expects. The clearest expression of this is the charity annual return, which asks charities completing it whether they have thirteen named policies: internal financial controls, safeguarding, financial reserves, complaints, serious incident reporting, internal risk management, trustee expenses, trustee conflicts of interest, investing charity funds, campaigns and political activity, bullying and harassment, social media, and engaging external speakers at charity events. The question is not a trap — plenty of small charities legitimately answer no to several — but each of these has a Commission guidance document behind it, and a charity whose activities plainly call for one of them should have it.
Tier three is good practice. These are the policies that flow from what your charity does: a volunteer policy if you use volunteers, a lone working policy if people work alone, an AI use policy if your team has quietly started drafting funding bids with a chatbot. No regulator will ask for them by name, but a well-run board adopts the ones that fit and skips the ones that do not.
One rule cuts across all three tiers: a policy your board has never read is worse than no policy at all, because it documents a standard you are not actually following. Fewer, shorter, genuinely used policies beat a thick folder of borrowed ones every time.
The complete charity policies list — 52 policies
Nobody needs all 52. Read each category against what your charity actually does, and where a good free template exists, the link is given. Government sources (gov.uk, ACAS, HSE, ICO, HMRC, NCSC) publish under the Open Government Licence, which means you may copy and adapt them freely; where a sector source is linked, its terms are noted. Jump to a category:
- Governance policies
- Safeguarding and people policies
- Employment policies
- Financial policies
- Data and technology policies
- Fundraising policies
Governance policies
- Conflicts of interest policy and register — how trustees declare and manage interests that could pull against the charity's. Annual return policy; the Commission's guidance is CC29. The Commission no longer publishes its own template — the openly licensed base is the CC29 guidance itself, and NCVO's free sample declaration of interests form is a sound starting point.
- Trustee code of conduct — the behaviour trustees sign up to: duties, confidentiality, respect, declaring interests. Good practice under the Charity Governance Code; NCVO publishes a free sample code of conduct.
- Risk management policy and register — how the board identifies, scores and owns its major risks. Annual return policy; guidance is CC26, and NCVO's board basics include a free sample risk register.
- Serious incident reporting policy — when and how you report harm, loss or criminality to the Commission. Annual return policy; the Commission's guidance page includes an openly licensed examples table and checklists you can adapt.
- Complaints policy — a published route for anyone to complain and be answered fairly. Annual return policy; if you fundraise from the public, a complaints process is also required by the Code of Fundraising Practice.
- Expenses policy — what trustees, staff and volunteers can claim and how. The trustee element is an annual return policy backed by CC11; Small Charity Support publishes a free Word example, and NCVO has a free claim form.
- Campaigning and political activity policy — how the charity campaigns lawfully, always in service of its purposes and never for a party. Annual return policy; guidance is CC9.
- External speakers and events policy — vetting speakers and managing the risks of platforms and events. Annual return policy.
- Trustee recruitment, induction and training policy — how new trustees are found, checked for eligibility, and brought up to speed. Good practice; Small Charity Support has a free trustee induction example.
- Delegation of authority — what the board delegates to committees, a chief executive or staff, with limits and reporting back. Good practice for any charity with staff or committees; NCVO's free sub-committee terms of reference are a useful base.
- Whistleblowing policy — a safe internal route to raise wrongdoing. Workers are protected by law whether or not you have a policy, which is precisely why it is good practice to have one; Small Charity Support publishes a free example.
- Document retention and destruction policy — how long records are kept and how they are destroyed. UK GDPR's storage limitation principle effectively requires you to have decided retention periods; the ICO's records management resources set the standard to meet.
- Business continuity plan — how the charity keeps going through fire, flood, systems failure or the loss of a key person. Good practice, weighted by how much others depend on your services.
- Media and crisis communications policy — who speaks for the charity, and what happens in a bad week. Good practice.
- Grant-making policy — criteria, due diligence and monitoring for charities that make grants. Good practice anchored in the Commission's guidance on making grants to charities and other organisations.
- Due diligence and overseas activities policy — know your donor, know your partner, verify the end use of funds; essential where money crosses borders. A Commission expectation through its compliance toolkit.
- Environmental and sustainability policy — the charity's commitments on its own footprint. Optional good practice.
- Modern slavery statement — an annual statement of the steps taken to prevent slavery in your operations and supply chains. Only a legal duty for organisations with commercial turnover of £36 million or more (Modern Slavery Act 2015, section 54 and its regulations), which excludes almost every charity; a voluntary statement is open to any charity that wants one.
Safeguarding and people policies
- Safeguarding and protecting people policy — the Commission expects every charity to have safeguarding policies and procedures, whatever its size and whoever it serves, with a substantially stronger version wherever children or adults at risk are involved. The Commission publishes no template; NSPCC Learning offers a free example safeguarding policy statement for organisations working with children, and Small Charity Support covers the wider ground in free Word documents.
- Safer recruitment policy — references, interviews and DBS checks at the right level before anyone starts. A Commission expectation for charities working with children or adults at risk, with criminal consequences for employing a barred person in regulated activity; Small Charity Support has a free safe recruitment example.
- Staff and volunteer code of conduct — how everyone acting for the charity behaves, including contact with beneficiaries. Expected by the Commission's safeguarding guidance; Small Charity Support's code of behaviour example is free to adapt.
- Digital safeguarding, photography and imagery policy — safe online contact with beneficiaries, and consent for photographs and film. Good practice for any charity that delivers services online or publishes images of the people it helps.
- Volunteer policy — recruitment, induction, support, expenses and problem-solving for volunteers, deliberately not written as an employment contract. Good practice for every charity that uses volunteers.
- Lone working policy — keeping people safe when they work alone, in homes or in the community. Flows from the employer's duty of care wherever the risk exists.
- Equality, diversity and inclusion policy — the charity's commitment to non-discrimination across trustees, staff, volunteers and services. Good practice under the Governance Code, and useful evidence of Equality Act compliance; ACAS publishes free equality templates and Small Charity Support a free equal opportunities example.
Employment policies
- Health and safety policy — legally required in writing once you have five or more employees, and the underlying duties apply from your first employee. The HSE publishes a free policy statement template and worked example under the Open Government Licence.
- Disciplinary policy and procedure — the law requires disciplinary rules and procedure to be specified in the written statement of particulars, and the ACAS Code applies with real teeth: tribunal awards can rise by up to a quarter where it is ignored. ACAS publishes its example disciplinary procedure free in Word.
- Grievance policy and procedure — the matching requirement for how staff raise concerns; ACAS's example grievance procedure is free in Word.
- Bullying, harassment and sexual harassment policy — an annual return policy for every charity, and since October 2024 employers carry a proactive legal duty to take reasonable steps to prevent sexual harassment of their workers, for which an effective policy is a core step. Small Charity Support publishes a free bullying and harassment example.
- Sickness absence policy — reporting, sick pay, and a humane route back to work. Good practice; ACAS templates cover the letters you will need.
- Family leave policies — maternity, paternity, adoption, shared parental and carer's leave. Good practice as a written policy: the entitlements are statutory whether or not you write them down, but a policy makes them usable.
- Flexible, remote and hybrid working policy — the right to request flexible working now applies from day one, and requests must be handled within two months; ACAS publishes a free example flexible working policy.
- Pay and remuneration policy — how pay is set and benchmarked, including senior pay. Good practice under the Governance Code.
- Wellbeing and stress policy — supporting mental health at work, increasingly including menopause support. Good practice built on the HSE's management standards.
- Drugs and alcohol policy — impairment rules and support routes. Good practice, weighted heavily where your people drive or deliver care.
Financial policies
- Internal financial controls policy — segregation of duties, dual authorisation, limits, reconciliations, cash handling. The first policy named in the annual return, and the one the Commission most often finds wanting; its CC8 guidance comes with a free, openly licensed self-checklist, and Small Charity Support publishes a free financial management example.
- Reserves policy — how much the charity holds back, and why. An annual return policy under CC19, stated in the trustees' annual report by charities preparing accruals accounts; Small Charity Support has a free example.
- Investment policy — objectives, risk and the standard investment criteria for invested funds; becomes a statutory written requirement when you appoint a discretionary investment manager. Guidance is CC14.
- Anti-fraud and financial crime policy — preventing, spotting and responding to fraud against the charity, which is also a reportable serious incident. Anchored in CC8 and the Commission's compliance toolkit.
- Anti-bribery, gifts and hospitality policy — no bribes, no facilitation payments, and a register for gifts. The Bribery Act's "adequate procedures" defence makes this close to essential for charities with trading or overseas operations.
- Anti-money laundering and sanctions policy — complying with UK financial sanctions is a legal duty for every organisation; a written policy is the sensible way to show you screen for it, and matters most where donations are large, unusual or international.
- Donation acceptance and refusal policy — when to accept, refuse or return a donation, supported by the Commission's current guidance on accepting, refusing and returning donations. Good practice for every charity that receives donations. Small Charity Support covers legacies and donations free.
- Procurement policy — quotes, value for money and supplier conflicts. Good practice, flowing directly from your financial controls.
- Trading and commercial partnerships policy — the boundaries for trading, subsidiaries and commercial participator deals, with CC35 as the map. If you claim Gift Aid, HMRC's model declaration forms are free under the Open Government Licence.
Data and technology policies
- Data protection policy and privacy notices — privacy notices are a legal requirement for virtually every charity, because virtually every charity processes personal data. The ICO's free privacy notice generator has a charity and voluntary sector version, and Small Charity Support publishes free GDPR policy examples in Word.
- Individual rights and data breach procedures — subject access requests answered within a month, notifiable breaches reported to the ICO within seventy-two hours. The deadlines are law; a short written procedure is how a small team actually hits them.
- Acceptable use and cyber security policy — passwords, multi-factor authentication, phishing, backups and what happens on personal devices. The NCSC's small organisations guide is the authoritative free base, published under the Open Government Licence.
- CCTV and surveillance policy — lawful basis, signage, retention and access for any cameras you operate. Good practice as a policy; the operation itself must meet the ICO's video surveillance standards.
- Social media policy — who posts, in what tone, and how personal accounts relate to the charity's voice. An annual return policy with dedicated Commission guidance.
- AI and digital tools policy — what your people may put into AI tools, how outputs are checked, and when use is disclosed. The newest entry on this list and, for many boards, the most overdue.
Fundraising policies
- Fundraising policy — how the charity fundraises lawfully and ethically, and how trustees oversee anyone fundraising on its behalf, under CC20 and the Code of Fundraising Practice. Charities over the audit threshold must, by statute, describe their fundraising approach in the trustees' annual report.
- Vulnerable circumstances policy — protecting people in vulnerable circumstances from pressure to give, required for compliance with the Code of Fundraising Practice wherever you fundraise from the public, and most acute for face-to-face and telephone fundraising.
How to adopt a template properly
A downloaded template becomes your charity's policy through a short, deliberate sequence, and the sequence matters more than the download.
First, read the whole thing and delete what does not apply — a twelve-page policy for a charity of three volunteers is a red flag, not a reassurance. Second, fill in the specifics that make it yours: named roles rather than job titles you do not have, real financial limits, real contact routes. Third, put it to the board and adopt it by a recorded decision, so the minutes show what was adopted and when it took effect. Fourth, give it an owner and a review date, and put that date somewhere it will resurface on its own rather than relying on someone remembering.
That last step is where most policy folders quietly die. A policy adopted in 2021 with no review date is, by 2026, a liability with a logo on it. If your board keeps a rolling action log, put each policy's review on it; if your meetings run to a forward plan, give every policy a slot. This is exactly the kind of recurring, easy-to-forget governance work Trustee Meetings exists to carry — it keeps your policies, their owners and their review dates in the same place as your agendas and minutes, and resurfaces each one when its date comes round, so the folder stays alive without anyone having to remember it.
Where the free templates come from — and why that matters
Every template linked in this guide passed two tests when we verified it in July 2026: it is free to download with no payment and (except where noted) no sign-up, and its publisher permits charities to use and adapt it. Government and regulator sources — the Charity Commission, ACAS, the HSE, the ICO, HMRC and the NCSC — publish under the Open Government Licence, which grants everyone a worldwide, royalty-free licence to copy, adapt and republish. Small Charity Support publishes its Word-format examples free of charge and royalties for use by bona fide small charities and community organisations. NCVO's board basics samples are free to all and written to be adapted. NSPCC Learning's safeguarding statement is free to download and tailor, though the NSPCC keeps its copyright, so treat it as a base for your own document rather than something to republish.
Two honest gaps are worth knowing about. The Charity Commission no longer publishes its own conflicts of interest template — its CC29 guidance now points to the Chartered Governance Institute, whose version sits behind a free-subscriber sign-up — and it has never published a safeguarding policy template, preferring to point at sector bodies. Where no good free template exists for a policy, this guide leaves the entry unlinked rather than pointing you at a paywall dressed as a resource.
If you are setting up a new charity board, or tidying up an inherited one, start with the annual return thirteen, add the employment set the moment you hire, and let the rest follow what your charity actually does. And if you want the adopting, owning and reviewing handled in the same place as your meetings, Trustee Meetings is free to try — no card needed.
For more on the machinery that keeps policies alive between reviews, see our guides on keeping a charity trustee action log, how to chair a charity meeting, how often trustees should meet, and building a trustee welcome pack — a new trustee's induction is precisely the moment a well-kept policy folder earns its keep.