Skip to content
CharityProof
By Brian Crocker, CharityProof

Charity Risk Register: Template and Guide for Trustees

A risk register is how a charity's trustees document the risks they have identified, assessed, and decided how to manage. The Charity Commission does not require charities to use a specific format, but it does expect trustees to manage risk as part of their duty to manage the charity's resources responsibly.

For many small charities, risk management is informal — discussed at board meetings but never written down in a structured way. The problem with informal risk management is that it depends on institutional memory. When trustees change, unwritten risk awareness changes too. A risk register is the institutional record that survives trustee turnover.

What the Charity Commission expects

The Commission's guidance on risk management (CC26) sets out the expectation: the responsibility for managing and controlling a charity rests with the trustee body, and trustees are required to manage risk as part of their duty to manage the charity's resources responsibly. Identifying and managing risks is how trustees protect the charity's ability to achieve its aims.

Charities with income over £500,000 must include in their trustees' annual report a statement of the principal risks identified and the systems in place to manage them. Smaller charities are encouraged to do the same as good practice.

What a risk register should include

A risk register typically captures for each risk:

  • Risk description — what could happen and why
  • Likelihood — how probable is the risk materialising (often scored 1-5)
  • Impact — how severe the consequences would be (often scored 1-5)
  • Risk score — likelihood × impact (gives a 1-25 score, or a RAG rating)
  • Current controls — what the charity already does to reduce likelihood or impact
  • Residual risk — the risk score after controls are applied
  • Owner — which trustee or staff member is responsible for monitoring this risk
  • Action — what additional action, if any, is needed

The risk score (likelihood × impact) helps prioritise. A common convention is: 15+ on a 25-point scale = high priority; 8-14 = medium; 1-7 = low. The Charity Commission does not prescribe a specific scoring system — the bands are a practical tool rather than a regulatory standard.

Common risks for small charities

The categories below cover the risks the Charity Commission most commonly identifies in small charity governance failures. Trustees should use these as a starting point and add risks specific to their charity's activities and circumstances.

Financial risks:

  • Loss of a major funder (likelihood 3, impact 5 for many charities that depend on one source of income)
  • Unexpectedly large expenditure (for example, emergency building repairs for charities with premises)
  • Fraud or misappropriation by staff, volunteers, or trustees
  • Cash flow gap between grant receipt and expenses

People risks:

  • Key person dependency (sole paid staff member leaving; only one trustee with financial skills)
  • Difficulty recruiting or retaining volunteers
  • Trustee vacancy falling below quorum

Safeguarding risks:

  • Failure to identify or respond to a safeguarding concern
  • Inadequate DBS check processes for trustees or volunteers

Operational risks:

  • Data breach or ICO notification requirement (UK GDPR)
  • Loss of key relationships (referral partners, local authority contracts)
  • Reputational damage from a public incident

External risks:

  • Regulatory change affecting the charity's activities or funding
  • Economic downturn reducing charitable giving
  • Loss of premises

A practical risk register template

The template below covers the six columns most useful for small charities. Add rows for each risk you identify. Start with 5-10 risks and review annually.


Risk Likelihood (1-5) Impact (1-5) Score Current controls Owner Action needed
Loss of primary funder 3 5 15 Reserve policy targets 3 months; funder relationship managed by chair Chair Identify secondary funding stream before end of year
Safeguarding incident 2 5 10 Policy in place; DSL designated; DBS checks up to date DSL Annual safeguarding training for all volunteers
Key staff departure 3 4 12 Trustee oversight of operations; documented procedures Chair Complete procedures manual for key roles
Data breach 2 4 8 Data protection policy; restricted access to donor database Data lead Annual review of access rights
Trustee vacancy below quorum 2 3 6 3 trustees minimum; annual recruitment review Chair Add trustee recruitment to AGM agenda

How to use the risk register

At adoption: the board should work through the risk register together at a dedicated agenda item, not receive a draft for passive approval. Discussion surfaces risks that individuals have identified but not shared, and builds shared understanding of which risks the board considers material.

Annual review: the risk register should be reviewed at least once a year, typically at the same meeting as the annual accounts. Likelihood and impact scores can shift — a risk that was theoretical last year may be live this year. The review is also when to add new risks and close risks that have been resolved.

In the trustees' annual report: for charities required to report on principal risks (income over £500,000), the risk register feeds directly into the annual report. For smaller charities, a brief statement that risks have been reviewed is good practice.

When the risk landscape changes: a major funder withdrawal, a safeguarding incident, a sudden loss of premises — these trigger an out-of-cycle risk review. The register gives the board a baseline to work from.

Linking risk to your compliance obligations

Risk management connects to several other governance obligations. A well-run compliance programme reduces operational risks; a well-run safeguarding policy reduces safeguarding risks. Our charity compliance checklist covers the obligations that feed directly into the risk register, and our reserves policy guide covers how financial reserves are the primary financial risk control.


This guide applies to charities registered with the Charity Commission for England and Wales. CC26 provides detailed guidance on risk management for charities. This is general guidance, not legal advice.

Sources

Last reviewed: 8 August 2026

Stop tracking compliance in spreadsheets

CharityProof brings annual returns, policy reviews, DBS renewals, and trustee admin into one dashboard — built for small UK charities.

No spam. Unsubscribe any time. Privacy policy