Charity Whistleblowing Policy: Free Template and Plain-English Guide

A whistleblowing policy sets out how staff, volunteers and trustees can raise serious concerns safely, kept separate from the normal grievance process. The Public Interest Disclosure Act 1998 protects workers who make a 'qualifying disclosure' from being dismissed or victimised for it, and charities should provide a clear escalation route: line manager, then a named trustee, then external regulators such as the Charity Commission. Some concerns raised this way will also meet the threshold for a serious incident report.

What whistleblowing means in a charity

I see a charity whistleblowing policy from both sides — as a trustee who looks after my own small charity’s policies, and as the builder of CharityIQ’s compliance tools, which meant reading more whistleblowing guidance than any one charity should. Both seats teach the same lesson: this policy exists for someone’s worst week at work, so clarity beats cleverness. Whistleblowing itself is when a worker, volunteer or trustee raises a genuine concern about serious wrongdoing, such as fraud, safeguarding failures, financial mismanagement or a danger to health and safety, rather than a personal workplace grievance. It matters in charities specifically because trust and donor confidence depend on problems being caught and fixed early, not covered up or left to fester until they become a serious incident report to the regulator; the wider framework sits in our charity compliance handbook.

A whistleblowing concern is about wrongdoing that affects others, such as the charity’s beneficiaries, finances or reputation. It’s different from a personal complaint about how you’ve been treated, which belongs in a grievance process instead.

The legal bits (PIDA) in plain English

The Public Interest Disclosure Act 1998, usually shortened to PIDA, gives legal protection to workers who make a “qualifying disclosure” in the public interest, meaning they can’t be lawfully dismissed or subjected to detriment for having raised it, provided they’ve disclosed it appropriately. Qualifying disclosures typically cover criminal offences, breaches of legal obligation, danger to health and safety, environmental damage, miscarriages of justice, or the deliberate concealment of any of these.

For the protection to apply, the worker generally needs to reasonably believe the information is true and that disclosure is in the public interest. Disclosing internally to your employer, or to a prescribed regulator such as the Charity Commission, generally gives stronger protection than going straight to the press. If you want to cite the precise legal tiers in your own policy, check the exact disclosure hierarchy on gov.uk first — the detail matters.

Free template, annotated

Below is a mirrored, on-page version of our free downloadable whistleblowing policy template, with notes on what each section is for. I drafted it myself, the way I write the policies I look after at my own charity: short numbered sections, named roles, no legalese. Use it as a starting point and adapt the named roles to your own structure.

1. Purpose and scope

States that the policy exists to let staff, volunteers and trustees raise serious concerns safely, and that it covers everyone connected to the charity, not just employees.

2. What counts as a whistleblowing concern

Lists examples: fraud, financial irregularity, safeguarding failures, danger to health and safety, breaches of law or regulation, and cover-ups of any of these.

3. What isn’t covered here

Clarifies that personal grievances belong in the grievance policy, with a link to it, so staff aren’t confused about which route to use.

4. How to raise a concern

Sets out the practical steps: who to contact first, in what format, and what information is helpful to include.

5. Escalation routes

Names the manager, the designated trustee, and the external regulator as the three tiers, explained fully in the next section.

6. Confidentiality and anonymity

Explains that identity will be protected as far as legally possible, and that anonymous concerns can still be raised, though they can be harder to investigate.

7. Protection from detriment

States plainly that no one will be penalised, demoted or dismissed for raising a genuine concern in good faith, referencing PIDA.

8. What happens next

Describes the investigation process and expected timescales, so the discloser knows roughly what to expect.

9. Review

Sets a review date, ideally annually or after any incident that tests the policy.

[Download the full free whistleblowing policy template — email capture]

Routes: staff → manager → trustee → regulator

A good whistleblowing policy gives staff a clear ladder to climb if a concern isn’t resolved at the first level: raise it with your line manager first, then a named trustee if the manager is implicated or unresponsive, and finally an external regulator such as the Charity Commission or, for certain sectors, a prescribed body. Naming a specific trustee by role (not just “the board”) removes ambiguity at the moment someone most needs clarity — in my own policies I name roles, not individuals: people change, roles don’t.

This matters most when the concern is about someone senior. If the disclosure concerns the CEO or the chair, the policy should state explicitly that staff can bypass them and go straight to another named trustee or the vice-chair, and ultimately to the Charity Commission’s serious incident reporting route if internal channels fail or are compromised.

Handling a disclosure (first 48 hours)

The first 48 hours after a disclosure sets the tone for everything that follows: acknowledge receipt quickly, keep the discloser’s identity confidential on a need-to-know basis, and make an early judgement on whether the concern also triggers a duty to report a serious incident. Acting fast and visibly protects both the discloser and the charity’s ability to investigate properly — if one line here sticks, make it this: silence in the first week does more damage than most procedural slips.

  • Acknowledge the concern in writing within a day or two, even if the investigation will take longer.
  • Assess whether it meets the threshold for a serious incident report to the Charity Commission, and if so, begin that process in parallel.
  • Protect the discloser from any risk of retaliation, and make sure line managers understand this is non-negotiable.
  • Record what was raised, when, and what action was taken, in case the process is challenged later.

One number matters here: the Charity Commission sets no minimum value for reporting fraud as a serious incident — the widely quoted £25,000 figure belongs to the separate “other significant financial loss” category — so don’t sit on a small-looking fraud concern. If the disclosure is fraud, our fraud playbook maps the parallel steps.

Culture: making it safe to speak

A policy alone doesn’t make people feel safe to speak up; culture does, which means trustees and senior leaders need to visibly welcome concerns, follow through on them, and never let a discloser be sidelined or informally punished. Charities with a genuinely open culture tend to catch problems while they’re still small and manageable.

From experience: Whistleblowing policies fail on findability, not wording. The test I apply at my own charity: could someone find the policy and name the right first contact within five minutes? Trustees over-worry about legal drafting — PIDA protection applies however imperfect the wording — and under-worry about whether anyone’s actually read the escalation route.

Practical steps: mention the policy at induction, remind staff of it annually, share (anonymised) examples of concerns that were handled well, and make sure trustees ask about whistleblowing activity as a standing item on the board agenda, not just when something’s gone wrong. This connects directly to the wider expectations in the charity governance code, and it should sit alongside your safeguarding policy template and our safeguarding incident playbook as part of a coherent set of protective policies.

What to do next

Download the free template, adapt the named roles to your own structure, and make sure every member of staff and every trustee knows the escalation route before they ever need it. Pair this policy with your serious incident and safeguarding procedures so the whole protective framework is joined up, not scattered across separate documents.

Want AI-assisted compliance drafting, from policies to serious incident reports? Join the compliance module waitlist →

Frequently asked questions

There's no single blanket legal requirement for every charity to have a written whistleblowing policy, but it's considered good practice and is expected by funders, the Charity Commission's governance expectations, and increasingly by insurers. Any charity with staff, volunteers or a safeguarding remit should have one in place and reviewed regularly.

Internally, they can raise a concern with their line manager or a named trustee; externally, prescribed regulators such as the Charity Commission can receive disclosures with legal protection under PIDA. Going straight to the media generally carries weaker legal protection unless internal and regulatory routes have genuinely failed.

Yes, the Charity Commission is a prescribed body under the Public Interest Disclosure Act for charity-related disclosures, meaning workers who raise genuine, public-interest concerns with it are generally protected from dismissal or detriment. Check the current prescribed-persons list on gov.uk before stating this as absolute in your own published policy.

A grievance is a personal complaint about how you've been treated at work, such as unfair treatment by a colleague. Whistleblowing is raising a concern about wrongdoing that affects other people or the wider organisation, such as fraud or safeguarding failures, and it follows a different process with different legal protections.

Most policies allow anonymous disclosures, but charities should be upfront that anonymous concerns can be harder to investigate fully and that disclosers who identify themselves can usually be kept informed of progress. Encouraging staff to at least confide in one named trustee, even if they want broader anonymity, often produces a better outcome.