The Charity Commission published its Charity Sector Risk Assessment 2026 on 18 August 2026, providing trustees and charity leaders with an updated view of the risks affecting charities across England and Wales.
The assessment does not introduce a new law or prescribe a particular risk-management framework. Its importance lies elsewhere: the regulator has used annual returns, accounts, compliance casework, serious incident reports, public concerns, intelligence and wider horizon scanning to identify where pressure is increasing across the sector.
The Commission explicitly encourages trustees to consider these findings when reviewing their own risk registers.
For charities, the practical question is therefore not simply whether a risk register exists. It is whether that register still reflects the financial, operational, safeguarding, technological and governance risks the charity faces today.
What is the Charity Sector Risk Assessment?
The Charity Sector Risk Assessment provides an evidence-led overview of current and emerging threats affecting charities regulated by the Charity Commission in England and Wales.
Not every risk identified by the Commission will apply to every organisation. A small community charity will not have the same exposure as an international humanitarian organisation, supported-housing provider or large care charity.
The assessment is intended to help trustees:
- challenge whether established risk assumptions remain valid;
- identify risks that may be missing from the charity’s register;
- consider whether existing controls remain proportionate and effective;
- understand where the Commission is seeing increasing casework or emerging harm;
- make better-informed decisions about resources, partnerships and service delivery.
This is consistent with the Commission’s wider CC26 risk-management guidance, which says risk management should be ongoing, embedded in the charity’s activities and periodically reassessed as circumstances change.
What are the principal risks identified for 2026?
1. Financial resilience
Financial pressure remains one of the most immediate risks facing the sector.
Charities collectively reported approximately £102 billion of income and £100 billion of expenditure in 2024. However, the position of individual organisations varied considerably:
- 41% of charities reported expenditure exceeding income;
- smaller charities continued to operate with the narrowest margins;
- Charity Commission casework concerning insolvency and financial difficulties increased by 27.7%, from 184 to 235 cases;
- voluntary removals from the charity register increased by 36%;
- changes in donor behaviour and pressure on unrestricted funding continued to affect financial resilience.
The Commission notes that insolvency-related cases still represent a very small proportion of more than 170,000 registered charities. Nevertheless, the direction of travel makes early identification important.
Trustees should consider whether their reporting provides timely information on:
- cash flow and available reserves;
- restricted and unrestricted income;
- reliance on individual funders, grants or contracts;
- changes in operating costs;
- fundraising performance;
- forecast-to-actual variances;
- delivery commitments where full cost recovery is not available;
- early warning indicators and agreed escalation thresholds.
A risk rating reviewed several months ago may no longer be useful if its supporting financial assumptions have changed.
2. Abuse for private benefit and fraud
Charities must operate for public benefit and protect their assets from misuse. The Commission reports a sustained increase in concerns about charities being exploited for private benefit:
- cases increased by 38% in 2024–25, from 211 to 291;
- this was followed by a further 29% increase in 2025–26, reaching 374 cases.
The assessment highlights the potential use of AI in fraudulent charity-registration applications and the use of less transparent transaction methods by bad actors. It also draws attention to conflicts of interest, unlawful payments and inadequate oversight of charitable funds.
Trustees should review whether:
- payment approvals include appropriate checks and segregation of duties;
- no single person has uncontrolled access to charitable funds or assets;
- trustee payments are lawful, properly authorised and documented;
- conflicts of interest are identified, recorded and managed;
- unusual transactions are reviewed and escalated;
- fraud concerns can be reported safely;
- the charity’s financial controls are periodically tested.
Larger incorporated charities should also consider the Failure to Prevent Fraud offence, which came into force on 1 September 2025. It applies where an organisation meets at least two of the relevant employee, turnover and asset thresholds.
3. Structural and regulatory vulnerabilities
Many charities operate across several regulatory environments.
A housing charity may be accountable under charity law while also facing housing, property and safeguarding requirements. Care charities may interact with the Care Quality Commission, local authorities and professional regulators. Educational charities may fall within Ofsted or Department for Education requirements.
The Commission identifies particular concerns involving:
- supported-housing charities;
- care and health-related services;
- out-of-school educational settings;
- situations where regulatory responsibility is unclear or fragmented;
- complex relationships between charities, companies and service providers.
This makes regulatory mapping important. Trustees should understand:
- which regulators and requirements apply to each service;
- who owns each obligation;
- which controls demonstrate compliance;
- how incidents or service failures are escalated;
- what evidence must be retained;
- whether regulatory gaps create additional risks for beneficiaries.
The Commission specifically advises charities to undertake due diligence before entering new service-delivery arrangements.
4. Governance and trustee effectiveness
Governance weaknesses can amplify financial, operational and reputational risks.
Although cases concerning trustee decision-making or breaches of Commission guidance decreased, cases involving disputes within charities increased by 57%, from 579 to 909. These disputes may concern trustee elections, financial transparency, land, property or difficult decisions arising from financial pressures.
The Commission also identifies continued difficulty recruiting enough trustees, which may affect a board’s capacity, independence and ability to provide effective challenge.
Trustees should consider whether the charity maintains:
- clear responsibilities and delegated authorities;
- accurate records of meetings and decisions;
- documented conflicts of interest;
- current policies and governing documents;
- sufficient trustee skills and succession planning;
- clear ownership of agreed actions;
- evidence showing when decisions were reviewed and why they were taken.
The Charity Governance Code 2025 provides a useful voluntary framework. It contains eight universal principles and 41 outcomes, encourages an “apply or explain” approach and places greater emphasis on evidence showing that governance works in practice.
5. Safeguarding
Safeguarding remains a persistent regulatory concern. Approximately one quarter of concerns raised with the Charity Commission in recent years have related to safeguarding.
The responsibility extends beyond beneficiaries. Charities must also consider risks affecting employees, volunteers and other people who encounter the organisation through its activities.
The 2026 assessment draws particular attention to allegations concerning people in positions of power, trust or influence.
Charities should be able to demonstrate:
- how safeguarding risks are identified;
- who is responsible for reviewing concerns;
- how incidents are reported to the appropriate agencies;
- when trustees are informed;
- which immediate protective measures were taken;
- how investigations and resulting actions are recorded;
- whether previous incidents have led to changes in controls, policies or training.
The Commission’s serious-incident guidance explains that reporting demonstrates that trustees recognise when a material risk has crystallised and are taking appropriate action.
6. Social tensions, misinformation and security threats
The assessment recognises that some charities operate in increasingly hostile environments.
Charities working with refugees, people experiencing homelessness, young people, faith communities or contested social issues may face:
- physical or online threats;
- racial or religious intolerance;
- disinformation;
- reputational attacks;
- legal uncertainty;
- increased security costs;
- disruption to services or premises.
These risks may require more than a communications response. They can affect employee safety, beneficiary access, service continuity, reputation and the charity’s ability to deliver its purposes.
Relevant scenarios should therefore be considered within risk assessments, crisis-management plans, incident procedures and business-continuity exercises.
7. International and geopolitical risks
Charities operating internationally face additional exposure to conflict, sanctions, safeguarding threats, changing government policy, financial-transfer restrictions and risks concerning local partners.
Trustees must be able to demonstrate proportionate due diligence and continued monitoring of how charitable funds are used.
The Commission’s due-diligence guidance focuses on understanding who the charity is dealing with, verifying identities where appropriate, understanding the proposed relationship and remaining alert to unusual activity.
A review completed when a partnership began may no longer be sufficient if the organisation, operating country, funding route or political environment has changed.
8. Cybersecurity and AI
The Commission reports that 30% of charities experienced a cyberattack during the preceding year, with phishing identified as the most common and disruptive form. It also notes increasing ransomware threats and the potential for AI misuse to create risks for beneficiaries and employees.
AI can improve efficiency, accessibility and impact. However, trustees remain responsible for ensuring that its use is supported by suitable governance, safeguards and oversight.
Charities should consider:
- where AI is being used, including unofficial or “shadow” use;
- which personal, confidential or beneficiary data may be processed;
- who reviews AI-generated content or decisions;
- whether suppliers are subject to appropriate due diligence;
- how cyber incidents are detected and escalated;
- whether backups and recovery arrangements have been tested;
- how staff and volunteers are trained to recognise phishing and fraud.
Cost-effective GRC Software Built for Charities
Bring risks, controls, incidents, complaints, actions and assurance together in one configurable, cost-effective platform. Start with the modules your charity needs today and expand as your governance requirements evolve.

What should trustees do now?
The assessment should not simply be circulated to trustees and filed as a governance update. It should be used to challenge the charity’s current risk position.
A structured review should ask:
1. Which risks apply to our charity?
Consider the charity’s purposes, activities, beneficiaries, funding, locations, partnerships and regulatory responsibilities.
2. Are any relevant risks missing?
Compare the Commission’s findings with the existing risk register. Avoid adding every sector risk automatically; record those that could materially affect the charity’s objectives.
3. When was each risk last challenged?
A scheduled review date does not prove that the underlying assumptions, controls and evidence remain valid.
4. What has changed?
Consider financial forecasts, service demand, regulation, technology, key personnel, suppliers, partners, geopolitical conditions and previous incidents.
5. Are controls operating as expected?
A policy’s existence does not demonstrate its effectiveness. Identify the evidence used to assess each important control and when that evidence was last reviewed.
6. Are early warning indicators defined?
Financial resilience, safeguarding, cyber risk and service delivery should not depend solely on retrospective reporting. Identify measurable indicators and escalation thresholds where possible.
7. Are incidents connected to the relevant risks?
Complaints, safeguarding concerns, fraud attempts, cyber incidents and control failures may reveal that a risk’s likelihood or impact has changed.
8. Does every action have an accountable owner?
Actions should have clear ownership, target dates, status, evidence requirements and escalation procedures.
9. Can trustees evidence their oversight?
Trustee discussions, decisions, challenges, accepted risks and required actions should be recorded clearly enough to demonstrate informed governance.
Risk reporting and the wider 2026 governance environment
Under the Commission’s CC26 guidance, charities legally required to have their accounts audited must include a risk-management statement in the trustees’ annual report. Smaller charities are encouraged to do so as good practice.
The statement should be supported by a genuine process rather than assembled retrospectively for reporting.
Other relevant developments include:
- the Charity Governance Code 2025, with its focus on outcomes and evidence of effective governance;
- Charities SORP 2026, applicable to relevant accounting periods beginning on or after 1 January 2026;
- the Code of Fundraising Practice, which has applied across UK charitable fundraising since 1 November 2025;
- the Failure to Prevent Fraud offence affecting qualifying large incorporated charities.
Together, these developments reinforce the need for charity governance information to be current, connected and supported by evidence.
Moving beyond a static charity risk register
A spreadsheet can record a risk, score and owner. It becomes less effective when trustees also need to understand:
- which objectives the risk could affect;
- which controls manage it;
- whether those controls have been tested;
- which incidents or complaints have occurred;
- which partner or supplier is involved;
- what actions remain outstanding;
- whether the risk position has changed;
- when trustees last reviewed the evidence.
Effective risk management connects these elements rather than maintaining them in separate files, emails and reports.
Supporting Charities Is Not New to Symbiant
Symbiant has worked with charities, non-profits and international NGOs for many years, supporting organisations across humanitarian aid, international development, animal welfare, health, social care, financial inclusion and community services.
These organisations often face governance and assurance demands comparable to much larger enterprises—but without the same budgets, resources or internal capacity.
That is why affordability has always been an important part of Symbiant’s approach to the charity sector.
Our modular platform allows charities to begin with the risk, audit, compliance or governance capabilities they need and expand over time. Pricing remains predictable, implementation is configurable and organisations are not forced into a large enterprise package containing functionality they may never use.
But partnership involves more than providing affordable software.
A 15-Year Partnership with Concern Worldwide
Symbiant’s relationship with international humanitarian organisation Concern Worldwide now spans over 15 years and counting.
During significant humanitarian-sector funding pressures, Symbiant provided Concern Worldwide with a full year of complimentary licensing. This helped its teams continue important audit and assurance activities across multiple countries without interruption.
The decision reflected the nature of the relationship: Concern Worldwide was not simply a software account, but a long-standing member of the Symbiant community.
It also demonstrated what dependable technology partnership can look like during difficult circumstances—protecting continuity, supporting the people responsible for oversight and giving the organisation breathing space while budgets were under pressure.
How Symbiant GRC supports charity governance and risk management
Symbiant provides configurable, cost-effective GRC and Audit software for charities, non-profits and NGOs.
Its connected modules can help charities:
- maintain organisational, service, project and programme risk registers;
- assign risks, controls and actions to accountable owners;
- manage policies and supporting evidence;
- monitor key risk indicators and review dates;
- record incidents, safeguarding concerns and complaints;
- assess delivery partners, suppliers and grant recipients;
- track audit and assurance actions;
- produce current reports for trustees and committees.
Charities can select the modules they need and develop their use of the platform as their governance requirements evolve.
The Charity Sector Risk Assessment 2026 gives trustees a current view of the wider risk environment. Symbiant helps charities translate that understanding into owned risks, operating controls, tracked actions and decision-ready oversight, without the cost and complexity associated with many enterprise GRC systems.
Strong governance should not depend on having an enterprise-sized budget.
References and further reading
Principal sources
Charity Sector Risk Assessment 2026 — Charity Commission
The principal source for the sector figures, regulatory casework trends and financial, governance, safeguarding, geopolitical, technological and cyber risks discussed in this article.Charities and Risk Management (CC26) — Charity Commission
Guidance on identifying, assessing, monitoring and reporting charity risks, including the risk-management statement required from charities whose accounts must be audited.Failure to Prevent Fraud: Guidance for Organisations — Home Office
Official guidance on the corporate Failure to Prevent Fraud offence, the organisations within scope and reasonable fraud-prevention procedures.Charity Governance Code 2025
A voluntary governance framework containing eight universal principles and 41 outcomes, supported by an “apply or explain” approach.Charities SORP 2026
Accounting and reporting requirements for relevant charities for reporting periods beginning on or after 1 January 2026.Code of Fundraising Practice — Fundraising Regulator
The fundraising standards applying to charitable institutions and third-party fundraisers across the UK from 1 November 2025.Cyber Security Breaches Survey 2025–26 — UK Government
Government research covering the prevalence, nature and impact of cyberattacks affecting UK businesses and charities.
Practical guidance for trustees
Trustee Finance Toolkit — Charity Commission
Practical resources covering financial resilience, internal controls, reserves, financial health and trustee oversight.Internal Financial Controls for Charities (CC8) — Charity Commission
Guidance on protecting charity funds, preventing fraud, managing payments and establishing appropriate financial controls.The Essential Trustee (CC3) — Charity Commission
An overview of trustees’ principal legal duties and responsibilities.Identifying and Managing Conflicts of Interest — Charity Commission
Guidance on identifying, recording and managing actual or potential conflicts of interest.Safeguarding and Protecting People — Charity Commission
Guidance on safeguarding responsibilities, risk registers, policies, reporting arrangements and trustee oversight.Reporting a Serious Incident — Charity Commission
Guidance explaining what constitutes a serious incident and when and how trustees should report one.Due Diligence, Monitoring and Verifying the End Use of Charitable Funds — Charity Commission
Guidance on partners, beneficiaries, funding arrangements, transactions and continued monitoring.Managing Risks When Working Internationally — Charity Commission
Guidance for charities operating overseas or through international partners.Protect Your Charity from Cybercrime — Charity Commission
Practical measures for preventing, responding to and reporting cyber incidents.Cyber Security Toolkit for Boards — National Cyber Security Centre
Board-level guidance for embedding cyber resilience within governance and organisational risk management.Charities and Artificial Intelligence — Charity Commission
An introduction to the opportunities, risks and trustee responsibilities associated with charity use of AI.AI and Data Protection Risk Toolkit — Information Commissioner’s Office
A practical resource for identifying and reducing data-protection risks created by AI systems.
Symbiant case study
Concern Worldwide: Audit Management and Complimentary Licensing Partnership — Symbiant
The source for information about Symbiant’s long-standing relationship with Concern Worldwide and the provision of complimentary annual licensing during funding pressures.
Strengthen Charity Governance Without Stretching Your Budget
Join charities, non-profits and NGOs using Symbiant to manage risks, controls, incidents, complaints, audit actions and assurance in one connected platform, supported by a team building charity-sector partnerships that span over 15 years and counting.
Start with the modules your organisation needs and expand as your governance requirements develop, with powerful, configurable GRC and Audit software designed to work within real charity-sector budgets.
See how Symbiant can support stronger oversight, clearer accountability and better-informed trustee decisions.


