Governance, risk and compliance matters as much for charities and non-profit organisations as for commercial ones. The perception that GRC is primarily a financial services or corporate governance concern, less relevant to organisations whose purpose is charitable or social rather than commercial, is both wrong and increasingly costly for the sector organisations that hold it.
Charities manage public funds, employ people, work with vulnerable populations, and operate within legal and regulatory frameworks that impose specific and enforceable obligations. Trustees have personal legal duties. The Charity Commission has enforcement powers it is increasingly willing to use. Donors, funders, and beneficiaries expect transparent, well-governed organisations. And the reputational consequences of governance failures in the charity sector, where public trust is the fundamental operating currency, can be disproportionately severe.
This article sets out what GRC means for charities and non-profits, with practical guidance on making it proportionate, credible, and genuinely embedded in how the organisation is governed.
In England and Wales, charity trustees have specific legal duties under the Charities Act 2011 and related legislation, overseen by the Charity Commission. These duties are not advisory guidance. They are legal obligations that individual trustees are personally accountable for meeting.
The duties most directly relevant to GRC include the duty to act in the charity's best interests, which requires trustees to exercise genuine judgement rather than simply deferring to management; the duty to manage resources responsibly, which includes managing the risks that could threaten those resources; the duty to act with reasonable care and skill, which requires trustees to apply the knowledge and experience they have, and to seek advice when they do not have what is needed; and the duty to ensure the charity is accountable, both to the Charity Commission and to the public.
Trustees in Scotland operate under similar duties established by the Charities and Trustee Investment (Scotland) Act 2005 and overseen by OSCR, the Office of the Scottish Charity Regulator. Charities registered in Ireland are regulated by the Charities Regulator, whose governance expectations for registered charities are increasingly detailed.
The Charity Commission's guidance on risk management makes clear that managing risk is a fundamental part of trustees' responsibility, not an optional add-on for larger or more complex charities. Trustees must identify the major risks the charity faces, assess how likely they are and how serious their consequences would be, and decide what to do about them.
Every registered charity in England and Wales with annual income over £25,000 must include a statement in its annual report confirming that the trustees have given consideration to the major risks the charity faces and have satisfied themselves that adequate controls are in place. This is not a perfunctory statement. It is a trustee attestation that should reflect genuine, documented risk assessment activity rather than formulaic reassurance.
Financial sustainability risk is the single most common and most acute risk for most charities. Dependence on a small number of funders, the risk of a major grant not being renewed, the vulnerability of earned income streams to demand changes, and the challenge of managing cash flow through grant cycles, are risks that affect organisations of all sizes in the sector.
Concentration of funding in a single source is particularly significant. A charity where 70% of its income comes from one statutory funder or one major donor is carrying a material existential risk if that relationship ends unexpectedly. Trustees should understand this concentration explicitly, not assume that because the relationship is currently positive it will remain so.
Reputational risk is structurally more significant for charities than for most commercial organisations. A charity's ability to fundraise, attract staff and volunteers, maintain relationships with partners, and deliver its mission depends on public trust in a way that a commercial business's ability to sell a product or service does not.
Reputational risk arises from safeguarding failures, financial mismanagement, conflicts of interest, association with problematic individuals or organisations, and conduct issues affecting staff, volunteers, or trustees. The interconnected nature of reputational damage in the charity sector, where a single high-profile failure can affect donor confidence across the sector, means that reputational risk management is a governance priority even for organisations that consider themselves lower profile.
For charities working with children, vulnerable adults, or people in difficult circumstances, safeguarding is both a legal obligation and a moral imperative. The risk of harm to beneficiaries, and the governance, reputational, and legal consequences of safeguarding failures, makes this one of the highest-priority risk categories for relevant organisations.
Trustees must ensure the charity has adequate safeguarding policies, that those policies are implemented in practice rather than existing only on paper, and that serious incidents are reported to the appropriate authorities including the Charity Commission under its serious incident reporting requirements.
Charities are subject to a broader range of regulatory obligations than many trustees realise. Data protection under UK GDPR applies fully to charities regardless of their non-commercial status. Employment law, health and safety legislation, and equality and diversity requirements apply. Charities with restricted funds must manage and report on those funds in accordance with the donor's restrictions. And depending on their activities, charities may face sector-specific regulatory requirements around financial services, healthcare, education, or other regulated activities.
Key person dependency is a significant risk in the charity sector, where expertise and relationships are often concentrated in a small number of staff or volunteers. When a CEO who has built key funder relationships leaves unexpectedly, or when a specialist role critical to programme delivery cannot be filled, the operational consequences can be severe and disproportionate to the size of the loss.
Proportionality is often cited as a reason for charities to do less governance work than they need. A small charity with five members of staff does not need the same GRC infrastructure as a major financial institution, and nobody is suggesting otherwise. But proportionality does not mean doing governance work only when it is convenient or comfortable. It means doing governance work that is appropriate to the actual scale and complexity of the risks the organisation faces.
A charity with £2 million of annual income working with vulnerable children faces significant safeguarding risk, significant reputational risk, and significant compliance risk regardless of its size. The proportionate response to these risks is serious governance attention, not a simplified process that prioritises administrative efficiency over substantive risk management.
A practical starting point for most charities is a simple risk register that captures the organisation's most significant risks, who is responsible for managing each one, what controls are in place, and what the assessed likelihood and consequence would be if the risk materialised.
This does not need to be complex. A well-maintained, genuinely current risk register with 10 to 20 significant risks is more valuable than an elaborate framework covering 100 risks that is updated once a year and never discussed outside the formal trustee meeting where it appears. The quality test is whether the risk register is actually used in trustee discussions and influences how the charity allocates its management attention.
Trustees should not simply receive risk management reports and note them. They should actively engage with the risk picture, ask questions that test whether management responses are adequate, and satisfy themselves that the controls described are genuinely in place and working. Where the trustees do not have the expertise to assess a particular type of risk, they should seek external advice rather than accepting management assurances that they cannot independently evaluate.
Charities often underestimate the range of compliance obligations they carry. Data protection under UK GDPR is the most commonly underestimated. The Information Commissioner's Office applies GDPR to charities with the same expectations it applies to commercial organisations. Charities that collect personal data about donors, beneficiaries, service users, or volunteers, which is effectively all charities, must meet the full range of GDPR obligations including lawful basis, data subject rights, data security, and breach notification.
Employment law, health and safety requirements, and equality legislation apply fully regardless of charitable status. For charities with trading subsidiaries, the tax and company law obligations associated with trading activities require separate compliance attention. And for charities operating internationally, the regulatory environments of each country in which they operate add further layers of compliance obligation.
The most practical way for smaller charities to approach compliance is within the risk management framework rather than as a separate compliance programme. Each significant compliance obligation represents a regulatory risk if not met. Recording those obligations in the risk register, alongside operational and reputational risks, ensures they receive appropriate trustee attention rather than being managed informally by staff without governance visibility.