The UK Charity Compliance Handbook
What this covers
This handbook is a plain-English map of charity compliance for a small UK charity: who regulates you, what you must register, file and report, how your accounts and the Charities SORP work, and your duties on fundraising, safeguarding and data protection. It focuses on England and Wales, flags where Scotland and Northern Ireland differ, and marks the rules changing in 2026.
Compliance has a poor reputation among busy trustees — it sounds like red tape that gets in the way of the real work. In practice, for a small charity it is a fairly short, predictable list, and most of it exists to protect the very things you care about: your beneficiaries, your money, and the public’s trust in you. A charity that files on time, keeps clean records and deals openly with problems is not just avoiding trouble; it is more fundable, more resilient, and easier to run. The aim of this handbook is to make the list clear, so you can meet it without anxiety and without paying for advice you do not need. Where a duty is genuinely complex or the stakes are high — a serious incident, an audit, a safeguarding concern — it also points you to the right specialist help. Everything here reflects the rules as they stand in July 2026, and flags what is due to change.
What compliance means for a small charity
Compliance means meeting the legal duties that come with being a charity: doing what your governing document says, following charity law, keeping proper records, filing on time, and being accountable to the public and the regulator. For a small charity it is mostly a handful of predictable, once-a-year tasks, provided you stay organised and know what is coming.
As of 9 July 2026, the Charity Commission’s register listed 185,360 charities in England and Wales — 171,572 main charities plus 13,788 linked — supported by around 922,000 trustees and 6.5 million volunteers. (Source: Charity Commission, register sector overview, 9 July 2026.) The great majority are small, run by volunteers, and the rules are designed to scale with size: the smallest charities do the least, and duties step up as income grows.
It helps to see compliance as three overlapping jobs. First, being set up correctly and staying that way: the right structure, an accurate register entry, and a governing document you actually follow. Second, reporting: telling the regulator and the public what you did and how the money was spent, on time. Third, protecting people and assets: safeguarding, sound finances, data protection, and reporting when something goes wrong. Almost every duty in this handbook falls into one of those three, which is why staying compliant is less about memorising rules and more about a few good habits — keeping records, meeting deadlines, and asking for help when a situation is unfamiliar. Get those habits in place and the specific rules become manageable rather than daunting.
Know who regulates you. In England and Wales that is the Charity Commission by default; in Scotland it is OSCR, and in Northern Ireland the Charity Commission for Northern Ireland. Separately, HMRC handles charity tax and Gift Aid, the Fundraising Regulator oversees fundraising, and the Information Commissioner’s Office (ICO) covers data protection. This handbook walks through each duty in turn; if you are unsure where a term fits, the register of charities and the Trustee & Governance Handbook are good companions.
Registration and keeping your register entry correct
In England and Wales, a charity that is not a CIO must register with the Charity Commission once its gross income passes £5,000; a charitable incorporated organisation must register whatever its income. Registration is only the start — keeping your entry accurate afterwards is a continuing duty, and an out-of-date entry is a red flag to funders and donors.
Some charities sit outside this route. Excepted charities — certain churches, scout and guide groups, and armed forces funds — need not register unless income exceeds £100,000, and exempt charities are overseen by another principal regulator instead of the Commission. If you are unsure of your status, check before assuming you do or do not need to register, because getting it wrong affects everything downstream.
Registering is worth doing properly, because your registered number is what funders, banks and donors use to check you are genuine. When you apply, the Commission looks at your purposes and public benefit, your trustees, and evidence that your income is over the threshold. Charitable status for tax is separate: HMRC recognises charities for Gift Aid and other reliefs on its own criteria, so you may be recognised by HMRC even where Commission registration is not required. If you are a very small unincorporated group under £5,000 and not a CIO, you cannot usually register yet, but you can still operate as a charity in law and register once you grow. Whatever your position, keep evidence of your income, your governing document and your trustee decisions from the very start.
Once registered, keep your details current: trustees, contact details, activities, governing document and financial year. You update most of this through the annual return, but material changes — new trustees, a change of name, or a change to your purposes — should be recorded promptly. Changes to your purposes or other regulated alterations usually need the Commission’s prior consent, so read your governing document’s amendment clause first. Accurate registration is the foundation the rest of compliance is built on.
The annual return
The annual return is a yearly online update to the Charity Commission that keeps the public register accurate. All CIOs and any registered charity with gross income over £10,000 must file it within 10 months of their financial year-end; charities with income of £10,000 or less do not complete the full return but must still keep their registered details up to date.
The return is separate from your accounts, though most charities deal with both together. If your gross income is over £25,000, you must also file your Trustees’ Annual Report and accounts with the Commission, usually by the same 10-month deadline. Below £25,000 you still prepare accounts, but you do not have to file them. Work your deadline back from your accounting reference date: a 31 March year-end means a 31 January deadline.
The questions in the return change from year to year, and the Commission has been asking for more detail — for example about income from outside the UK and about how the charity operates. You do not need to reinvent anything: pull the figures from your accounts, confirm your trustees and contact details, and answer honestly. It usually takes an organised small charity an hour or two once the accounts are done. Give yourself a login to the Commission’s online service well before the deadline rather than on the day, and make sure at least two trustees or staff can access it, so a single person being away never puts your filing at risk.
Filing late is not a small matter. Your register entry is publicly marked as having overdue documents, which funders check, and persistent default can prompt regulatory action. The fix is simple: diarise the deadline the moment your year ends, prepare early, and file as soon as you can if you do slip. Keeping every recurring date in one place — see the compliance calendar below — is the single most effective habit for staying compliant.
Annual accounts: receipts and payments versus accruals
Every charity must prepare accounts, but the form depends on size and structure. A non-company charity in England and Wales with gross income of £250,000 or less can currently prepare simple, cash-based receipts and payments accounts; above that, and for all charitable companies whatever their income, accounts must be prepared on the accruals basis under the Charities SORP.
How much external scrutiny your accounts need also steps up with income. Income of £25,000 or less usually needs none. Above £25,000 you must have at least an independent examination; a full audit is compulsory only where income exceeds £1 million, or where gross assets exceed £3.26 million and income exceeds £250,000. A qualified examiner is required above £250,000. Your governing document or a funder can require an audit even when the law does not.
Whichever basis you use, the underlying discipline is the same: keep clear, complete financial records throughout the year, not just at the end. Record income and spending as it happens, keep receipts and bank statements, and reconcile to your bank regularly. Track any restricted funds separately, so you can always show a funder exactly how their money was spent. Good records make preparing accounts quick, make an independent examination or audit cheaper, and protect the trustees if a question is ever raised. They are also the foundation of the reserves policy and financial oversight the Commission expects — work out a sensible level with the reserves calculator.
These thresholds are changing. For England and Wales, a package confirmed in secondary legislation raises the receipts-and-payments and qualified-examiner thresholds to £500,000, the audit-by-income threshold to £1.5 million, and the audit-by-assets threshold to £5 million, and raises the threshold below which no external scrutiny is needed at all from £25,000 to £40,000 — under the Charities Acts 1992 and 2011 (Substitution of Sums) Order 2026 (SI 2026/427), applying to financial years ending on or after 30 September 2026. Until then, the current figures apply. Check which regime fits your year with the audit-threshold checker. In Scotland and Northern Ireland, accruals accounts are required at £250,000 income or more.
The Charities SORP 2026 in one page
The Charities SORP is the rulebook for how charities preparing accruals accounts present their finances and Trustees’ Annual Report. The current version, Charities SORP 2026, applies to accounting periods beginning on or after 1 January 2026. If you use receipts and payments accounts, the SORP does not apply to you at all.
SORP 2026 introduces three tiers by income — Tier 1 up to £500,000, Tier 2 from £500,000 to £15 million, and Tier 3 above £15 million — with more disclosure required from larger charities. Most small charities that prepare accruals accounts sit comfortably in Tier 1. A full statement of cash flows is only required above £15 million unless the underlying standard (FRS 102) requires it anyway, which keeps the burden proportionate for smaller organisations.
For a small charity, the practical question is simply whether the SORP applies to you at all. If you prepare receipts and payments accounts, it does not — you follow the simpler Commission template instead. If you prepare accruals accounts, either because you are a charitable company or because your income is over the receipts-and-payments threshold, then the SORP governs how you present them, and you will almost certainly work with an accountant or independent examiner who knows it. You do not need to master the SORP yourself, but you should know which basis you are on, which tier you fall into, and that SORP 2026 is the version in force for periods beginning on or after 1 January 2026.
The update also refreshes the Trustees’ Annual Report, adding dedicated sections on reserves, future plans, impact, and environmental, social and governance matters. It was issued on 31 October 2025 by the joint SORP-making body — the Charity Commission, OSCR and the Charity Commission for Northern Ireland. If you are close to a tier boundary or unsure whether the SORP applies to you, the SORP tier checker will place you, and your independent examiner or accountant can confirm the detail.
Serious incident reporting
Trustees must report a serious incident to the Charity Commission promptly — as soon as is reasonably possible. A serious incident is an adverse event, actual or alleged, that results in or risks significant harm to people connected with your charity, significant loss of its money or assets, or serious damage to its reputation. You report even if you have also told the police or another regulator.
The most common serious incidents for small charities involve safeguarding, fraud or theft, a significant cyber-attack or data breach, and links to terrorism or extremism. The Commission publishes an examples table to help trustees judge borderline cases; where you are unsure, the safer course is to report. What matters is prompt, full and frank disclosure, along with an account of what the trustees are doing to deal with it.
Reporting a serious incident is not an admission that the charity has failed — it is evidence that the trustees are managing a problem responsibly, which is exactly what the Commission wants to see. Charities that report promptly and explain what they are doing are treated very differently from those where the regulator, a funder or the press finds out first. Alongside reporting, deal with the incident itself: make people safe, take advice, preserve evidence, tell your insurer, and, where relevant, the police, your bank or the ICO. Keep a written record of what happened and what you decided. A calm, documented response protects both the people affected and the charity.
Responsibility rests with the trustees. In practice they can delegate the actual filing to a staff member or adviser, but all trustees remain accountable for making sure a report is made in good time. Reports go through the Commission’s online serious incident service. Having a short internal process, so any trustee, staff member or volunteer knows how to escalate a concern, turns a stressful event into a manageable one. Detailed step-by-step responses will sit in the CharityIQ crisis playbooks.
Fundraising regulation
If your charity asks the public for money, you must follow the Code of Fundraising Practice, the standards maintained by the Fundraising Regulator for England, Wales and Northern Ireland. The Code covers how you and anyone fundraising for you should behave — honesty, respecting donors’ wishes, and protecting people in vulnerable circumstances — across every method, from collections and events to email and social media. A revised edition of the Code — the first major review since 2019 — took effect on 1 November 2025, restructuring and updating the standards, so check your fundraising against the current version rather than an older copy.
The Code is not an Act of Parliament, but parts of it reflect legal requirements, and the Fundraising Regulator investigates complaints and can require changes. Charities whose fundraising spend passes a set threshold are required to pay the Fundraising Levy, and any charity can register voluntarily to display the regulator’s badge, which reassures donors. Scotland has its own fundraising standards arrangements, so check the position if you fundraise there.
Watch a few specific duties that catch small charities out. If you work with a professional fundraiser or a commercial partner, there are legal rules about written agreements and about telling donors how much of their money the charity receives. If you run public collections, you may need a licence from the local authority. And you must respect people’s data and marketing preferences — the data protection rules in the next section apply directly to fundraising, including the new charity soft opt-in for electronic marketing. None of this should stop a small charity fundraising; it just means being honest, keeping simple records, and checking the Code before you try a new method.
In practice, good fundraising compliance means being honest in your asks, handling donor data lawfully, keeping clear records of what you raised and how, and dealing with complaints openly. If a fundraising problem causes significant harm or loss, it may also be a reportable serious incident. Grant fundraising has its own good practice — covered in the Complete Guide to Grant Funding — but the same principles of honesty and record-keeping apply.
Safeguarding duties
Safeguarding is your charity’s responsibility to protect the people who come into contact with it — beneficiaries, staff, volunteers and others — from harm, abuse and neglect. The Charity Commission expects every charity to have arrangements proportionate to its work, not only those working with children or adults at risk. Trustees hold ultimate responsibility for it.
Proportionate arrangements mean, at a minimum: a written safeguarding policy, safe recruitment (including DBS checks where a role is eligible), a named person to lead on safeguarding, clear ways for people to raise concerns, and a process for responding to and recording them. Even a two-person charity should know how it would handle a disclosure. Trustees should review the arrangements regularly and make sure everyone involved knows how to use them.
Safe recruitment deserves particular care because it is where problems are most often prevented. Depending on the role and who it involves, a person may be eligible — or in some cases required — for a Disclosure and Barring Service (DBS) check, and eligibility is specific, so check each role rather than assuming. Beyond checks, take up references, be clear about boundaries and expectations, and induct new people into your safeguarding policy. Volunteers matter as much as paid staff here. Getting recruitment right, and reviewing it as your activities change, is far easier than dealing with the consequences of getting it wrong.
When something goes seriously wrong — actual or alleged abuse, or a significant failure to protect someone — it is a serious incident to report to the Commission promptly, alongside any reports to the police or social services. Reporting shows the trustees are dealing with the issue responsibly. Safeguarding governance, including policies and safe recruitment, is covered further in the Trustee & Governance Handbook.
Data protection at a glance
Every charity holds personal data — supporter lists, beneficiary records, staff and volunteer files — so every charity has data protection duties. The UK GDPR, with the Data Protection Act 2018 and the marketing rules (PECR), governs how you collect, use, store and share that information. Most charities that process personal data must also pay the ICO’s data protection fee, generally at the lowest tier.
The rules were updated by the Data (Use and Access) Act 2025, which amends rather than replaces the UK GDPR. A change that matters for charities is a new ‘soft opt-in’, in force from 5 February 2026, letting you send electronic marketing to people who have expressed interest in or supported your cause without prior consent, if strict conditions are met. Separately, all organisations must have a data protection complaints process in place by 19 June 2026.
The basics protect you more than any single rule. Only collect the personal data you actually need, keep it accurate and secure, do not keep it longer than necessary, and be clear with people — through a short privacy notice — about what you hold and why. Give people a straightforward way to ask what data you hold or to have it corrected or deleted. For a small charity these duties are manageable: a simple data protection policy, a locked cabinet or a password-protected system, and a habit of not sharing personal information carelessly will meet most of what the law expects.
Handle personal data lawfully and securely, tell people what you do with their information, and respect their rights over it. If you suffer a notifiable personal data breach, report it to the ICO without undue delay and within 72 hours of becoming aware — and remember a serious breach can also be a reportable serious incident to the Commission. Using AI safely with charity data is covered in the AI for UK Charities handbook.
Trustees’ legal duties
Compliance ultimately rests with your trustees. The Charity Commission’s guidance The essential trustee (CC3) sets out six core duties: further the charity’s purposes for the public benefit; comply with the governing document and the law; act in the charity’s best interests; manage its resources responsibly; act with reasonable care and skill; and ensure the charity is accountable. These duties are collective — the whole board shares them.
Two duties do most of the day-to-day work. Acting in the charity’s best interests means managing conflicts of interest openly, usually by declaring them and stepping out of the affected decision. Managing resources responsibly means safeguarding funds, keeping adequate reserves, and putting basic financial controls in place. Trustees are normally unpaid volunteers, and payment is only allowed where the governing document or the Commission specifically permits it.
Good boards turn these duties into simple routines: meeting regularly with a clear agenda, keeping accurate minutes of decisions, reviewing the finances at every meeting, and maintaining a register of interests. They recruit trustees for a mix of skills, induct new trustees properly, and are not afraid to take advice on anything unfamiliar. Compliance is very often a by-product of good governance rather than a separate task — a board that meets, records its decisions and watches its money tends to file on time and spot problems early. The reverse is also true: most serious compliance failures start with a board that stopped paying attention.
Trustees who act honestly, reasonably and within their powers are generally protected from personal liability, which is rare in practice. Choosing an incorporated structure such as a CIO or a charitable company limits it further. The point of trustee duties is not to catch people out but to keep the charity well run and trusted. The charity trustee entry and the Trustee & Governance Handbook go deeper on the board’s role.
Your compliance calendar
The simplest way to stay compliant is to turn the duties in this handbook into a dated calendar you review at every board meeting. Most of charity compliance is predictable and annual, so once the recurring dates are written down, the year runs itself and nothing sneaks up on you. Build it around your financial year-end, from which most deadlines flow.
A typical small-charity year includes: your year-end and the run of preparing accounts; the annual return and, if income is over £25,000, accounts and Trustees’ Annual Report filing within 10 months; any Gift Aid claims; your AGM and trustee recruitment; insurance renewal; and a yearly review of key policies (safeguarding, reserves, conflicts of interest, data protection). Add sector moments such as Trustees’ Week, and any recurring funder deadlines from your funding pipeline.
It helps to think of the year in seasons. Soon after your year-end, the focus is on preparing accounts and getting them examined or audited if needed. In the middle of the ten-month window come the annual return and, where required, filing your accounts and report. Around this sit the recurring rhythms: your AGM and any trustee elections, Gift Aid claims, insurance renewal, and the annual review of your main policies. Add your funders’ reporting and application deadlines from your grant pipeline, and any national dates you take part in, such as Trustees’ Week. Written down together, these turn a year of potential surprises into a short, repeating list.
Keep it all in one place rather than in several people’s heads, and set reminders a month ahead of each deadline so there is time to act. The CharityIQ tools can tell you which accounting and scrutiny rules apply to your year, and a downloadable charity deadlines calendar brings the whole UK charity year onto one page. Good record-keeping and a shared calendar are what turn compliance from a worry into a routine.
None of this has to be done alone or all at once. If you are new to a charity, work through this handbook one chapter at a time, fix the basics first — an accurate register entry, a filing calendar, and clear financial records — and bring in an independent examiner, accountant or safeguarding adviser for the parts that genuinely need a specialist. Compliance is not a test you pass once; it is a steady rhythm of small, sensible actions that keep your charity legal, funded and trusted. Do the predictable things well, deal openly with the occasional problem when it arises, keep a record of your decisions, and you will spend far less time worrying about the regulator and far more on the work that matters. When a rule changes — as several are in 2026 — you will hear about it in good time and be able to adjust, because you already have the habits and the records in place.
Last reviewed: July 2026 · Reviewed by Ivan Siyanko.
Changelog: July 2026 — first published; reflects Charities SORP 2026, the accounting-threshold changes confirmed for financial years ending on or after 30 September 2026 (SI 2026/427), and the Data (Use and Access) Act 2025.
Download the full handbook (PDF). Get this guide as a printable PDF to share with your trustees — email optional. [NOTE FOR IVAN: attach the generated PDF; keep the download ungated, email optional.]
CharityIQ is the grounded AI built for UK charities: it can help you keep on top of deadlines and draft compliance documents grounded in your own verified data, citing its sources and logging every decision so there is always an audit trail — with a person checking before anything is filed. Everything in this handbook stands on its own as free help whether or not you ever use the product.
More handbooks: Trustee & Governance Handbook · Complete Guide to Grant Funding · Gift Aid Handbook · Impact Measurement Handbook.