Corrections

Our correction policy

When we get something wrong, we say so here — on this page, dated, with what was wrong, why it was wrong, how we found it, and what we changed. We do not quietly edit a page and move on. A correction notice goes on the page itself as well as in this log, so a reader who saw the original claim can find out it changed.

We would rather publish an honest log with one entry than a clean-looking site with none. If you think a page on this site is wrong, tell us what you found and where — that is exactly how the entry below was found in the first place.

The log

Three corrections are logged, covering nine blog posts. Each was found by this project’s own research and applied to the live page before it was written up here. Pages that still need a fix are not listed until the fix has actually been applied.

5 September 2026 — SORP 2026: the claim that every charity must include an impact narrative

Pages (seven): sorp-2026-impact-narrative, sorp-2026-tier-checker, sorp-2026-trustees-annual-report-template, sorp-2026-vs-sorp-2019, charity-impact-frameworks-compared, theory-of-change-template-uk-2026, chatgpt-for-uk-charities

What was wrong

Seven posts stated flatly that under SORP 2026 an impact narrative is “mandatory at all tiers”, “required of all charities” or a duty of “all UK charities (Tier 1, 2, and 3)”. Two of them also presented the doubling of the accruals-accounts threshold from £250,000 to £500,000 as a SORP change; it is a Charities Act threshold (SI 2026/427) that bites on financial years ending on or after 30 September 2026, on a different basis from the SORP tiers, which turn on periods beginning on or after 1 January 2026.

What is right

Under SORP 2026 a Tier 1 charity’s binding duty (para 1.27) is a summary of main achievements, addressing how its work changed beneficiaries’ circumstances. The explicit impact narrative in para 1.30 is formally a Tier 2 requirement, triggered above £500,000 income. The SORP-making body’s own Summary of Changes describes impact reporting as now a “must” for all charities without that tier distinction, so the position at Tier 1 is contested; a Tier 1 charity that includes a short narrative is on solid ground, and one that omits it entirely may be asked why. Future plans and volunteer contribution are mandatory at every tier.

How it was found

The project’s own blog scan against its research on 2 September 2026 (the SORP Module 1 text was read against the Summary of Changes); the same contradiction was recorded as a contested fact in the research base.

What was changed

On 5 September 2026 each of the seven posts had the flat claim replaced with the paragraph above (body text, and where present the lead, FAQ and excerpt); the tier checker’s “new for all tiers” list and the comparison tables in the SORP 2019 vs 2026 post were reworded; the two threshold passages now name SI 2026/427 and its year-ending basis. No correction notice was added to the top of these posts because the wrong sentence was a single claim inside an otherwise accurate article; this log entry is the record.

Status: corrected on all seven pages.

5 September 2026 — Cyber security for UK charities: the annual return does not ask about it

Page: /blog/compliance-regulation/cyber-security-charities-uk-2026/ (and one link on cyber-essentials-for-charities)

What was wrong

The post was built on the premise that the 2026 Charity Commission annual return added three cyber security questions, and explained “why the Commission added” them. It also quoted Cyber Essentials fee ranges (£300–£500 and £1,500–£3,000 a year) that matched no published fee schedule. The Cyber Essentials post linked to a page about “cyber security and the annual return” that did not exist.

What is right

The annual return question guide covering the 2025 and 2026 returns contains no cyber security question in any section — the same finding as the 2 September correction above. What regulators do expect is real but sits elsewhere: risk management under CC26, the UK GDPR Article 32 security duty for any charity holding personal data, the ordinary serious incident reporting duty, and NCSC guidance and Cyber Essentials as good practice rather than a mandate. Cyber Essentials self-assessment is priced by organisation size, from £320 to £600 plus VAT per certification; Cyber Essentials Plus is quoted, not fixed-price. No UK charity regulator requires a cyber security policy.

How it was found

The 2 September blog scan found the premise in the excerpt; the 3 September pass found it repeated in the body, lead, FAQ and SEO fields, and found the fee figures unsupported.

What was changed

On 5 September 2026 the post’s body, excerpt, SEO title and description, lead, FAQ and sources were rewritten around what regulators actually expect, with a dated correction notice at the top; the fee figures now come from the fact record. The broken link on the Cyber Essentials post now points to the corrected article, with the sentence around it reworded.

Still open

The post’s Open Graph and Twitter title and description still carry the old “5-step plan” and “adds cyber questions” wording as at 5 September 2026; these social fields cannot be set through the publishing route used and will be corrected by hand. The practical section still calls the NCSC’s guidance the “Small Charity Guide”, a name the NCSC no longer uses.

Status: corrected; Open Graph/Twitter fields pending.

2 September 2026 — Charity Commission annual return 2026: the AI and cyber security questions

Page: /blog/compliance-regulation/charity-commission-annual-return-2026/

What was wrong

The post claimed the 2026 Charity Commission annual return added new questions on AI use and cyber security. Specifically: a meta description reading “what’s new (AI + cyber questions)”; a fabricated “Section 7 — 2026 new questions on AI and cyber”; a ten-section form structure that does not exist; a “Section 6 — Number of safeguarding incidents… DBS checks are current” claim; and an “over £1m also requires audited accounts” line with no transitional basis stated. The same claim sat independently in the post’s meta description, Open Graph and Twitter description, JSON-LD description, and in three ACF fields — the same error repeated in six places, not one.

What is right

The GOV.UK annual return question guide, which governs both the 2025 and 2026 returns, was read end to end — the financial-period and income preamble plus all eight numbered sections — rather than keyword-searched. It contains no question on AI use, cyber security or a cyber policy, in any section.

How it was found

Our own research. An earlier draft made the same claim — a standing warning recorded in this project’s master research brief, “a real failure this project already had” — and the correction pass on 2 September 2026 re-verified the guide independently, by a full read-through rather than a keyword search, and traced the original claim to no primary source at all.

What was changed

The post’s body content, excerpt, SEO title and meta description, and its lead, FAQ and sources fields were rewritten on 2 September 2026 to describe the guide’s real eight sections, replacing the fabricated section and the ten-section structure. The accounting thresholds were reworked into a two-column table by financial-year basis (years ending before, or on or after, 30 September 2026) instead of stating one figure as current. A dated correction notice was added to the top of the post. The post’s infographic, which rendered the old four-band threshold table as an image no correction could reach, was removed; no replacement graphic has been produced yet.

Still open

The page’s Open Graph and Twitter description fields were not corrected in this pass and, as at 5 September 2026, still carry the old wording — these social fields cannot be set through the publishing route used and will be corrected by hand. The removed infographic has no replacement yet. This entry will be updated when both are resolved.

Status: corrected; Open Graph/Twitter description fields and the infographic remain pending.