Charity Risk Register: Template + Real Examples
A charity risk register is a working tool for trustees to prioritise attention, not a document completed once for the Charity Commission. Risks are typically scored on likelihood multiplied by impact, both on simple 1-to-5 scales, covering financial, safeguarding, cyber, key-person and reputational categories. Small charities most often miss key-person dependency, cyber risk and reputational risk from a partner's or grantee's behaviour, and a 20-minute quarterly review is usually enough to keep a register current.
What a risk register is for (not a filing exercise)
You’ve just been asked whether your charity has a risk register — on a funder’s due-diligence form, or by a new trustee who has read the Commission’s guidance. Before you lose a weekend to a forty-row spreadsheet nobody will open again, be clear what a charity risk register is for: it exists so trustees can see, at a glance, what could stop the charity doing its work and which threats deserve attention first. I sit on a small board myself: a register is a working prioritisation tool, not a compliance document you produce once for the Charity Commission’s annual return and then leave untouched for a year.
Charities above the audit threshold must confirm in their trustees’ annual report that they have reviewed major risks, under the Charity Commission’s CC26 guidance on charities and risk management. But the real value is operational: a good register tells a small board where to spend its limited oversight time, rather than treating every risk as equally urgent. Charities that treat it as a live document, revisited every quarter, catch emerging risks (a funder pulling out, a key staff member leaving, a data breach) months before charities that only look at it once a year. Our charity governance handbook covers where this fits.
The template (15 pre-scored starter risks)
Our free starter register gives you 15 common charity risks already scored on a rough likelihood and impact basis, across five categories: financial, safeguarding, cyber, key-person, and reputational. You are not starting from a blank page; you are editing scores to match your charity’s actual circumstances. I scored these myself, as I would for my own charity — a first draft to argue with, not an answer key.
| Category | Example risk | Starting likelihood | Starting impact |
|---|---|---|---|
| Financial | Loss of a single funder providing over 30% of income | Medium | High |
| Financial | Reserves fall below policy minimum | Medium | High |
| Financial | Fraud by staff, volunteer or trustee | Low | High |
| Safeguarding | Allegation involving a beneficiary and a staff member or volunteer | Low | High |
| Safeguarding | DBS checks lapse or are incomplete for relevant roles | Medium | Medium |
| Cyber | Phishing attack leads to fraud or data loss | Medium | High |
| Cyber | Loss of access to core systems (email, finance, CRM) | Low | Medium |
| Key-person | Sole trustee/staff member with financial system access leaves suddenly | Medium | High |
| Key-person | Chair or CEO departs without a handover plan | Low | Medium |
| Reputational | Negative press or social media coverage | Low | Medium |
| Reputational | Partner organisation’s conduct reflects badly on the charity | Low | Medium |
| Governance | Trustee board falls below quorum or loses key skills | Medium | Medium |
| Operational | Loss of premises or a key venue | Low | Medium |
| Operational | Failure of a critical supplier or contractor | Low | Medium |
| Compliance | Late or missed annual return / accounts filing | Low | Medium |
Download the full editable risk register template, complete with mitigation and owner columns, using the form on this page, or rebuild the table above directly in your own spreadsheet. A filled-in example charity risk register shows how a completed version reads.
Scoring: likelihood × impact without overthinking
Score every risk on two simple 1-to-5 scales, likelihood and impact, then multiply them to get a priority number between 1 and 25. This gives you a defensible, consistent ranking without needing a statistician on the board, and it is quick enough to redo every quarter.
- Likelihood 1-5: 1 = very unlikely this year, 3 = plausible, 5 = expected to happen.
- Impact 1-5: 1 = minor inconvenience, 3 = significant disruption or cost, 5 = threatens the charity’s ability to continue operating.
- Score = likelihood × impact. Anything scoring 15 or above goes to the top of your quarterly discussion; anything under 6 can usually be reviewed annually rather than every quarter.
Resist the temptation to make the scale more complicated. A ten-point scale with colour-coded sub-categories sounds thorough on paper and dies in practice; five points, two axes, multiply is what actually survives contact with a real board. The point of scoring is to create a rough, shared priority order the whole board can agree on in minutes, not a precise mathematical model. If two trustees disagree by one point on either axis, that is fine; if they disagree by three, that disagreement itself is worth a conversation.
The risks small charities always miss
The risks small charities most consistently leave off their register are key-person dependency, cyber risk beyond “we have antivirus,” and reputational risk arising from a partner or delivery organisation’s conduct rather than their own. All three are easy to underestimate because nothing has gone wrong yet.
Key-person risk is the biggest blind spot: many small charities have exactly one person who knows the banking login, the funder relationships, or the safeguarding processes, and no written handover plan if that person leaves suddenly. The test I use on my own charity: if the one person holding the logins vanished for a month, what would stop? Cyber risk is often reduced in trustees’ minds to “we have antivirus software,” when the bigger exposure is phishing and payment fraud, which the National Cyber Security Centre flags as one of the most common ways UK organisations, including charities, lose money; see the NCSC’s guidance for charities on cyber security for the charity sector; our fraud playbook covers what to do if it lands. Reputational risk from partners, subcontractors or grantees is the third blind spot: your charity’s name can be damaged by an organisation you fund or work with, not just by your own conduct.
Reviewing it: the 20-minute quarterly agenda item
A charity risk register stays useful with a 20-minute standing agenda item each quarter, not a full away-day. In that slot, the board reviews any risks that scored 15 or above, checks whether anything new has emerged, and confirms an owner for each top risk. Twenty minutes is enough — I’ve sat through hour-long risk discussions that achieved less, because the scoring had already done the prioritising.
A simple structure that works: five minutes on any risks that have materialised or nearly materialised since the last meeting, ten minutes reviewing the top five scored risks and their mitigation status, and five minutes checking for anything new (a new funder dependency, a new system, a new safeguarding concern) that needs adding. Assign one trustee or senior staff member as the overall register owner, responsible for keeping it updated between meetings, even though the whole board remains accountable for the risks themselves.
From experience: A charity risk register that gets argued about beats one that gets formatted. The best signal of practised governance is initials in the owner column and a score that has moved since last quarter — proof the board discussed it. A beautiful register last edited a year ago tells the opposite story.
What the Commission and funders expect
The Charity Commission expects trustees of charities above the audit threshold to confirm they have reviewed major risks as part of the trustees’ annual report, per CC26, while funders increasingly ask to see a current risk register as part of due diligence on larger grants. Neither expects a perfect document, but both expect evidence that risk is genuinely discussed, not just filed. Reading funder due-diligence lists while building our grant-finder, the risk-register request kept coming up — a standard ask for larger awards now.
Funders assessing governance capacity, and the Commission when it reviews serious incident reports, both look for the same signal: was this risk foreseeable, and if so, had the trustees identified and were they managing it? A register that flags key-person and financial dependency risks, cross-referenced against your financial controls under CC8, does far more to demonstrate good governance than a document produced once and never revisited. If something does go wrong, our guide to serious incident reporting covers what must be reported and when. For charities building wider cyber resilience, our cyber security pillar is the fuller reference, and our governance health check is a good companion exercise to run alongside your first risk register review.
What to do next
Download the 15-risk starter register, adjust the scores to reflect your charity’s actual circumstances, and add any sector-specific risks unique to your work. Put a 20-minute risk review on your next board agenda and name an owner before the meeting ends.
Want your compliance and governance record kept current automatically? Join the compliance module waitlist →
Frequently asked questions
Yes, in practice every charity benefits from one regardless of size, though it is a formal requirement for the trustees' annual report only above the audit threshold. Even a one-page register with five key risks scored and reviewed quarterly is far better governance than none at all.
Cover at minimum financial, safeguarding, cyber, key-person and reputational risk, since these are the categories the Commission and most funders expect to see addressed. Add sector-specific risks relevant to your charity's activities, such as premises risk for a charity running a building, or clinical risk for a health charity.
Review the top-scored risks every quarter as a standing 20-minute agenda item, and do a full review of every risk on the register at least once a year. Any time a serious incident occurs, review the register immediately rather than waiting for the next scheduled slot.
The whole board is accountable for the risks it identifies and manages, but one trustee or senior staff member should be named as the register's day-to-day owner, responsible for keeping entries current between meetings. Ownership of individual high-scoring risks should also be assigned to specific trustees or staff.
A safeguarding policy sets out how your charity prevents and responds to safeguarding concerns; the risk register is broader and includes safeguarding as one category alongside financial, cyber, reputational and other risks. The register should reference your safeguarding policy as a mitigation for safeguarding-related entries.