What to do if your charity discovers fraud
If you have just found fraud in your charity, act calmly and do not tip off the suspect. First, secure the evidence and stop any further loss by contacting your bank. Then report to the police, your insurer and — in almost all cases — the Charity Commission. This playbook takes you step by step, from the first 24 hours to preventing it happening again.
Discovering fraud is distressing, especially in a small charity where the person involved may be someone you know and trust. The steps below are the calm, correct order to act in. They apply to trustees, staff and volunteers in England and Wales; where Scotland (OSCR) or Northern Ireland (CCNI) differ, that is noted.
The Charity Commission expects charities to report fraud, theft and cyber-crime as a serious incident in almost all cases, with no fixed minimum loss figure — the higher the value lost, or the more senior the person involved, the more likely it must be reported (Source: gov.uk / Charity Commission, “How to report a serious incident in your charity”, updated 16 January 2026, accessed 11 July 2026).
Before you do anything: do not tip off the suspect
The single most important rule is to protect the evidence and avoid alerting whoever is responsible. Do not confront a suspect, send accusing emails, or discuss it widely before you have secured records and taken advice. A tipped-off suspect can delete evidence, move money or prepare a defence, and premature confrontation can prejudice both a police investigation and any later disciplinary process.
Tell only the people who need to know at this stage — usually the chair, the treasurer, and any trustee not connected to the matter. If a trustee or the person who would normally handle this is the suspect, route around them and take independent advice.
The first 24 hours
In the first day, your goals are simple: stop further loss, preserve evidence, and start the formal reports. Contact your bank immediately if money is still moving or accounts may be compromised, secure your financial records and systems, and note down what you know. Do not begin your own investigation in a way that contaminates evidence.
Work through these steps:
- Stop the loss. Call your bank straight away to freeze affected accounts, stop or attempt to recall payments, and change compromised online banking access. If a payment has just gone out, speed matters — banks can sometimes stop or recall a recent transfer.
- Secure the evidence. Preserve bank statements, invoices, emails, access logs and any documents, without altering them. Do not delete anything. Keep a dated written note of what you found, when, and how.
- Restrict access. Discreetly remove the suspect’s access to bank accounts, systems and cards, framed as a precaution, following your procedures. Change shared passwords.
- Convene the right people. Brief the chair and any unconflicted trustees. Agree who is co-ordinating the response and keep a decision log.
- Check for a data breach. If the fraud involved a phishing email, a hacked account or exposed personal data, you may also have a personal data breach to manage on a 72-hour clock — see the data breach playbook.
The first week
In the first week, make the formal reports, protect the charity, and begin a controlled review of what happened. This is when you report to the police and the Charity Commission, notify your insurer, take advice on any employment issues, and start to understand the scale. Keep everything documented and keep unconflicted trustees informed throughout.
Work through these steps:
- Report the crime to the police. In England, Wales and Northern Ireland, report through Report Fraud (the service that replaced Action Fraud) at reportfraud.police.uk or 0300 123 2040. In Scotland, call Police Scotland on 101. If a crime is in progress or there is an immediate risk, call 999. Keep the crime reference number.
- Report to the Charity Commission as a serious incident. Fraud, theft and cyber-crime should be reported, in almost all cases, through the Commission’s serious incident report. Do it promptly — the duty rests with the trustees. In Scotland report to OSCR; in Northern Ireland to CCNI.
- Notify your insurer. If you have crime, fidelity or trustee cover, tell your insurer promptly. Late notification can invalidate a claim, so do not wait until you have the full picture.
- Take advice on the person involved. If a staff member or volunteer is implicated, follow your disciplinary procedure and take employment-law advice before acting. Suspension is a neutral act, but get the process right.
- Assess the scale. Begin a controlled review — ideally with your accountant, examiner or auditor — of how much was lost, over what period, and how. Do not let the person involved take part in this.
- Plan your communications. Decide, with advice, what to tell funders, donors, staff and (if relevant) the public, and when. Being open about what happened and how you responded protects trust.
Your reporting duties, precisely
Fraud usually triggers more than one reporting duty, and they run in parallel. In almost all cases you must report to the Charity Commission as a serious incident and to the police; you may also have duties to the ICO (if personal data was affected), to your insurer under your policy, and to Companies House or your funders. Check each of the following against your situation.
Charity Commission (serious incident report)
The Commission expects charities to report fraud, theft and cyber-crime as a serious incident, except in exceptional cases where the amount and the impact are genuinely minor — for example a one-off theft of a very small sum. There is no fixed minimum loss figure for fraud, theft or cyber-crime specifically: the Commission judges seriousness by factors including the value lost, whether the person involved held a position of trust or seniority, and whether it is part of a pattern of incidents. Repeated low-value fraud, theft or cyber-crime should also be reported, even where no single incident is large. (A separate £25,000-or-more, or over-20%-of-income, guide figure applies to other kinds of significant financial loss, such as property damage or losing a major contract — see the funding-loss playbook.) Report promptly; the responsibility sits with the trustees. In Scotland, report to OSCR; in Northern Ireland, to CCNI.
The police (Report Fraud)
Report the crime so it is investigated and recorded. In England, Wales and Northern Ireland use Report Fraud — reportfraud.police.uk or 0300 123 2040 — which replaced Action Fraud from December 2025. If your organisation is under a live cyber attack, that line operates 24/7. In Scotland, report to Police Scotland on 101. For a crime in progress or an immediate threat, call 999. Keep the crime reference number for your insurer and the Commission.
The ICO (only if personal data was affected)
If the fraud exposed, altered or stole personal data — through a compromised email account, phishing, or a data-stealing attack — you may have a personal data breach as well. Certain breaches must be reported to the ICO without undue delay and within 72 hours of becoming aware, where the breach is likely to risk people’s rights and freedoms. Not every fraud involves a data breach, but check, and use the data breach playbook if it does.
Others to consider
If you are a charitable company, serious losses may be relevant to your accounts and directors’ duties. Grant funders whose money was affected usually expect to be told. Your independent examiner or auditor should be informed, as fraud can affect your accounts and their report. Take legal advice if you intend to pursue recovery.
Who to call
Keep this list to hand. In the first hours the order that matters most is: your bank (to stop the loss), then the police, then the Charity Commission and your insurer. The full set of contacts a charity may need is below.
- Your bank — first, to freeze accounts and stop or recall payments. Use the number on your card or statement, not one from an email.
- Report Fraud (police) — reportfraud.police.uk or 0300 123 2040 (England, Wales, Northern Ireland). Police Scotland 101 (Scotland). 999 for a crime in progress.
- The Charity Commission — serious incident report (England & Wales). OSCR (Scotland). CCNI (Northern Ireland).
- Your insurer — promptly, if you hold crime, fidelity or trustee indemnity cover.
- The ICO — only if personal data was affected, within 72 hours where required.
- Your accountant, independent examiner or auditor — to help assess the loss and the effect on your accounts.
- A solicitor — for employment issues, recovery, or if the matter is complex.
Stopping it happening again
Once the immediate crisis is handled, review how the fraud was possible and close the gap. Most small-charity fraud exploits weak financial controls — one person controlling payments, no second signatory, or no one checking bank statements. Strengthening a few basic controls prevents most repeat incidents. Record the lessons and the changes in your risk register and report the review to your trustees.
Practical steps that help: require two people to authorise payments; separate the person who makes payments from the person who reconciles the bank; have a trustee review bank statements independently; limit and review who has access to accounts; and set clear expenses and purchasing rules. Review your fraud risks in your risk register at least annually.
CharityIQ keeps a dated, auditable log of financial decisions and flags unusual patterns, so a small team has a second pair of eyes — but it never replaces the human controls above.