How is Zeffy free?
How is Zeffy free?
Zeffy relies entirely on optional contributions from donors. At the payment confirmation step - we ask donors to leave an optional contribution to Zeffy.
Learn more >
Nonprofit guides

Charity Risk Assessment: A Practical Guide for UK Trustees (2026)

July 6, 2026

If your treasurer is a volunteer with a full-time job, your first risk assessment should fit on one page and take one board meeting. For most small charities, "risk assessment" is not an enterprise project. It is the two-hour exercise where your trustees and chief executive name the three to five risks that could actually shut you down, score each one, and assign one owner and one deadline per row.

This guide walks through what a risk assessment is, why it matters, who runs it, the five steps to do it, and how to build your own scoring matrix in a free spreadsheet. It is written for the organisation where the same person opens the post, runs the fundraiser, and emails the board agenda.

In this article:

What is a charity risk assessment?

A charity risk assessment is the process of identifying, evaluating, and prioritising the risks that could harm your organisation, before you decide what to do about them. It is the diagnostic step. Risk management is the ongoing treatment that follows.

Put simply: a risk assessment helps you identify, assess, and control risks to protect your organisation and guard its mission. The output of an assessment is a short list of named risks, each scored on how likely it is to happen and how badly it would hurt, with one person and one deadline against each row.

That distinction matters. A lot of small organisations say "we do risk management" when what they mean is "we bought public liability insurance once." Risk management is the year-round work. Risk assessment is the moment, ideally annual, where you stop and ask which risks are actually on the table this year.

For a small charity: the assessment is the artefact that justifies every other governance task on your list. Without it, you are guessing which risks to spend volunteer time on.

Why every charity needs a risk assessment

A short, honest risk assessment does four things for a small organisation:

  • Supports trustee duty of care. Under the Charities Act 2011, trustees have a statutory duty of care to act in the best interests of the charity. A documented risk review is one of the clearest ways trustees demonstrate they are meeting that duty. The Charity Commission for England and Wales and NCVO both treat periodic risk review as basic governance hygiene. The same principle applies in Scotland under OSCR and in Northern Ireland under CCNI.
  • Strengthens your Trustees' Annual Report. Trustees must summarise the principal risks the charity faces and how they are managed in the Trustees' Annual Report and Accounts (TAR). The risk register you build this quarter is what you will summarise in next year's TAR. A documented review signals to your regulator that governance is active, not passive.
  • Builds donor and funder trust. Donors increasingly ask how their data is handled and how funds are controlled. Funders want assurance that grants will be managed responsibly. A risk assessment gives you real answers instead of generalities.
  • Prevents mission disruption. Most small organisations that pause their programmes do so because of a known, ignored risk: an uninsured event, a treasurer who stopped reviewing the books, a single grant ending. Naming the risk early is the cheapest way to keep the lights on. The Code of Fundraising Practice (new version effective 1 November 2025) is itself a live risk area: if your charity fundraises online, the new Section 9 on online platforms applies to you and belongs on your list.

For a small charity: the value is not a polished document. It is the two-hour conversation that surfaces what nobody has been paying attention to.

Who should be involved

For a small or all-volunteer organisation, the answer is short: your trustees and your chief executive or founder-trustee run the assessment. That is it. You do not need a committee, a risk officer, or outside counsel to start.

Add specialists only if you already have them:

  • If you have a treasurer (a trustee role in most UK charities), they own the financial-risk inputs, revenue concentration, cash on hand, who reviews the books.
  • If you have programme leads, each one owns the risks tied to their programme, volunteer safety, participant data, vendor reliability.
  • If you have a solicitor or accountant on call, share the draft with them after the meeting, not during.

The common failure mode in a volunteer-led organisation is not bad people. It is that no one is paid to look. Months go by, nobody pulls a financial report, nobody checks who still has access to the supporter list, and a small issue compounds. The risk assessment is the forcing function that puts someone's name next to "look at this by [date]."

One specific area to walk through together: who has access to your supporter data, and how do you remove access when a volunteer rolls off? On a five- or six-person team, login privileges sprawl fast, and most small charities have no audit trail of who can see what. If supporter data lives in one place with real access controls, that question takes a minute. If it lives in three spreadsheets on three personal phones, it takes a weekend. Zeffy's built-in supporter management is one way small charities replace spreadsheet sprawl with a single system.

For a small charity: if you are waiting until you have a "real" risk committee to start, you will never start. Your trustees plus your chief executive, around a table for two hours, is the assessment team.

Run a charity risk assessment in five steps

This is the core of the work. The whole process is designed to fit in one board meeting.

Step 1: Identify the risks

Walk through your operations and list every risk you can think of. Do not filter yet. Cover finances, programmes, fundraising, technology, people, compliance, and reputation. Ask each trustee to bring three risks they worry about. Look at what has gone wrong before, and what almost did.

For a small organisation, the boring-but-fatal risks tend to come up first:

  • No public liability insurance in place before your first in-person event.
  • One donor or one grant funds more than a third of your budget.
  • Your treasurer has not reviewed bank statements in three months.
  • Your supporter list lives in a personal Gmail or a phone contacts app.
  • You are running a raffle without registering it as a small society lottery with your local licensing authority.
  • You have never confirmed your charity is HMRC-recognised for Gift Aid, and you are missing 25p on every £1.
  • Your charity is trading in Scotland (or has a Scottish trustee, employee, or fundraiser) but has not registered with OSCR.

One quick note on infrastructure: using a PCI-compliant payment processor like Zeffy's free, PCI-compliant payment processing means your charity is not storing card data itself, which removes one infrastructure-risk category from the list before you start scoring. Plain guidance, not a fix-all.

Step 2: Score the likelihood

For each risk, ask: how likely is this to happen in the next 12 months? Score it 1 to 5.

  • 1 = rare
  • 2 = unlikely
  • 3 = possible
  • 4 = likely
  • 5 = almost certain

Use the room. If three trustees say "this happens to small organisations like ours all the time," that is a 4 or 5. Do not overthink it.

Step 3: Score the impact

For each risk, ask: how much harm would this cause if it happened? Score it 1 to 5.

  • 1 = minor inconvenience
  • 2 = recoverable in a week
  • 3 = a hard quarter
  • 4 = a hard year, programmes paused
  • 5 = the organisation might not survive it

Two simple questions help you prioritise: how likely is the risk to happen, and how much harm could it cause? Steps 2 and 3 are just those two questions, written down.

Step 4: Calculate the risk score and prioritise

Multiply likelihood by impact. That is your risk score, from 1 to 25.

  • 15 to 25: act now. These are the risks that could end the organisation.
  • 8 to 14: plan this quarter. Real risks, manageable with attention.
  • 1 to 7: monitor. Note them, revisit next year.

You will almost always find three to five risks in the top tier. That is your list. Resist the urge to act on everything. A small organisation can credibly work on the top tier this year, not all 25 things.

Step 5: Document findings and assign owners

For every risk in the top two tiers, write down four things in one row:

  • 1. The risk, in one sentence.
  • 2. One owner. A real person, not "the trustees."
  • 3. One deadline. A real date.
  • 4. One next action. The smallest thing that moves the risk down.

Example: "We have no public liability insurance before our June fete. Owner: Maria. Deadline: 1 April. Next action: get two quotes from brokers familiar with UK charities." That is a complete row.

Put the document in a shared folder the whole board of trustees can see. Revisit it at every meeting for five minutes. That is the difference between a risk assessment that works and one that lives in a drawer.

For a small charity: if you finish the five steps with a one-page list, three to five top-tier rows, and an owner and date on each, you have done a real risk assessment. That is the bar.

Build your own risk assessment matrix

You can build the matrix in any free spreadsheet (Google Sheets, Excel Online, Numbers). Here is the structure.

Set up the grid. Use a 5x5 grid. Likelihood runs across the top (1 to 5). Impact runs down the side (1 to 5). Each cell holds the score, which is likelihood times impact. Colour the top-right corner red (scores 15 to 25), the middle yellow (8 to 14), and the bottom-left green (1 to 7).

The grid looks like this:

Impact / Likelihood1 (Rare)2 (Unlikely)3 (Possible)4 (Likely)5 (Almost certain)
5 (Org-ending)510152025
4 (Hard year)48121620
3 (Hard quarter)3691215
2 (Recoverable week)246810
1 (Minor)12345

Build the risk register. On a second tab, make one row per risk with these columns: Risk, Category, Likelihood (1-5), Impact (1-5), Score (formula: =likelihood*impact), Owner, Deadline, Next action, Notes.

Pre-populate it with the boring-but-fatal risks small organisations flag. Use these as your starter rows; cut what does not apply.

RiskCategoryLikelihoodImpactScore
No general liability insurance before first eventInsurance3515
One donor or grant funds more than 33% of budgetFinancial4416
Treasurer has not reviewed books in 90+ daysOversight4416
Donor data lives on personal phones / shared spreadsheetsData5315
Online raffle status under state law is unclearCompliance3412

Worked example. Take the first row, "No public liability cover before summer fete." Likelihood: 3 (you have an event coming and no broker contacted, so it is possible nothing is in place by the date). Impact: 5 (one injury at an uninsured event can end a small organisation). Score: 15. That puts it in the top tier. Owner: chair of trustees. Deadline: 30 days before the event. Next action: get two broker quotes. Done.

That is the whole tool. A grid, a register, and discipline about owners and dates.

7 types of risks every charity should assess

1. Data breaches and cybersecurity

Small charities hold donor names, emails, giving history, and sometimes payment information. That data is valuable to attackers and easy to leak when it lives across personal phones, shared Google Drives, and an old spreadsheet a volunteer downloaded once.

UK charities must have a lawful basis (consent or legitimate interest) to process supporter data under UK GDPR and the Data Protection Act 2018. Direct e-marketing is governed by the Privacy and Electronic Communications Regulations (PECR). The Code of Fundraising Practice 2.1.5 requires explicit consent or appropriate legitimate-interest basis before sharing supporter data. GDPR compliance is a gate for many supporters: in our UK interviews, trustees asked "Are you GDPR compliant?" before adopting any new platform.

What to look for: supporter data on personal devices, shared logins, no record of who has access to what.

Warning signs: nobody can name everyone with access to your supporter list. A volunteer left and you do not know what they still have.

Ask: if our most active volunteer's laptop was stolen tonight, what supporter data would be exposed? Replacing scattered spreadsheets with a single supporter management system that has real access controls is one of the highest-leverage moves a small organisation can make.

2. Financial instability and revenue concentration

If one donor, one grant, or one event funds most of your budget, you have concentration risk, full stop. Diversifying revenue is the long-term fix.

What to look for: any single source above 33% of revenue. Months of cash reserve below 3.

Ask: which one donor or grant ending tomorrow would force us to cut programmes? Diversifying your revenue streams across donations, recurring giving, events, and memberships shrinks this risk over time.

3. Legal and compliance risks

UK charity filings, Gift Aid compliance, Fundraising Regulator obligations, and gambling law are all live wires for a small organisation.

What to look for: a missed annual return to CCEW, OSCR, or CCNI; an overdue Trustees' Annual Report and Accounts (TAR); lapsed HMRC Gift Aid claim compliance (4-year claim window, 6-year record-keeping requirement); a small society lottery return not submitted to the local licensing authority within 3 months of the draw.

Ask: which compliance filings do we owe in the next 90 days, and who is doing them? See our charity compliance overview for the common items to track, and check with your charity regulator (the Charity Commission, OSCR, or CCNI) on anything specific.

The Code of Fundraising Practice was updated with a new Section 9 on online platforms, effective 1 November 2025. If your charity uses any online fundraising platform, that section applies to you and belongs on your risk list.

4. Insurance and liability gaps

Public liability insurance is standard for any in-person event. Employers' liability insurance is legally required if your charity has any paid staff and may be required in other circumstances too. Trustee Indemnity Insurance (TII) protects your trustees personally against claims arising from their decisions in that role, and is increasingly required by funders and venues. Treat these as pre-first-event line items, not someday line items. Many venues require proof of public liability before they will let you set up.

Ask: do we have proof of public liability we can hand a venue tomorrow? Do our trustees have Trustee Indemnity Insurance? NCVO publishes guidance on the insurance types most UK charities need. Frame this as general practice; specific requirements vary by funder and venue.

5. Human resource and volunteer risks

Burnout, key-person dependency (the one volunteer who knows the supporter database), and turnover are real and quiet risks.

Ask: if our most stretched volunteer left this month, what would break? Write it down. That is your succession plan.

6. Reputational risk

Donor trust is the asset. A botched receipt season, a tone-deaf social post, or unclear messaging on fees can dent it.

Ask: what would a current donor see if they searched our name today? Do our receipts go out automatically and accurately?

7. Strategic and technology risk

Buying tools you cannot staff, or staying on tools nobody trained on, both create real cost. Map your tools, name an owner per tool, and do not add a tool without a plan to use it.

Ask: are we paying for software nobody opens? Is there a tool a volunteer set up that only that volunteer knows how to use?

Financial risk assessment for charities

Financial risk deserves its own pass. For a small organisation, the categories that matter are concrete:

  • Revenue concentration. Track the percentage of total revenue from your largest donor, your largest grant, and your top three sources combined. If any single source is above 33%, that is an evergreen concentration risk worth a row on your matrix, regardless of who the funder is.
  • Cash flow and reserves. Track months of operating reserve (cash on hand divided by average monthly expenses). Three months is a common floor; six is more comfortable.
  • Grant compliance. For each active grant, name the reporting dates and the person responsible. Missed reports cost future funding. UK funders such as the National Lottery Community Fund and the Big Give Christmas Challenge treat overdue reports as a barrier to future applications.
  • Gift Aid claim discipline. Every eligible donation you fail to claim within 4 years is money left with HMRC permanently. The Gift Aid Small Donations Scheme (GASDS) lets you claim 25% on cash and contactless gifts of £30 or less without a written declaration, capped at £8,000 in eligible small donations per tax year. Both require the charity to be HMRC-recognised, a separate registration from your Charity Commission entry.
  • Treasury risk-aversion. Keeping everything in a plain current account out of complexity-fear is its own risk. A money-market or short-term account at the same bank usually takes an afternoon to set up.
  • Payment fraud and chargebacks. Online giving brings card-not-present fraud risk. A reputable payment processor handles the heavy lifting on dispute response, but somebody at your organisation still needs to read the alerts.
  • Segregation of duties. The person who deposits money should not be the only person who reconciles the bank statement. If you are a three-person team, get a second trustee to spot-check monthly.

For a small charity: if you track concentration percentage, months of reserve, and the next three grant report dates, you have covered 80% of the financial risk a small organisation actually faces.

Risk assessment tools for charities

Most small charities should start with a spreadsheet. The 5x5 matrix and the risk register above fit in any free spreadsheet, cost nothing, and require no training. If a tool is not getting opened, it is not reducing risk.

For organisations that have outgrown a spreadsheet, dedicated governance, risk, and compliance (GRC) platforms exist. They are built for organisations with paid compliance staff, multiple programmes across regulated areas, or complex vendor risk. Enterprise GRC platforms are available for charities that have outgrown a spreadsheet; most small UK charities will not need them.

Two free authority resources are worth a bookmark either way:

  • NCVO maintains governance and risk guidance, free to read, aimed at UK charities of all sizes.
  • The Fundraising Regulator publishes the Code of Fundraising Practice and supporting guidance on compliance and good practice.

A note on adjacent infrastructure: the fundraising platform a small organisation already uses can quietly remove a few risk-register rows. Automated donation receipts, for instance, take a chunk of compliance and recordkeeping admin off the treasurer's plate. That is not GRC software. It is just one less thing to forget. Zeffy is used by 100,000+ charities and nonprofits and has processed over £2 billion raised, all free for the organisation.

For a small charity: a free spreadsheet, the NCVO framework as a reference, and disciplined trustee follow-through beats any tool you cannot staff. Adopt GRC software only when you have outgrown the spreadsheet, not before.

Frequently asked questions

How often should we conduct a risk assessment?

Once a year is the standard for most small charities, reviewed briefly at every trustees' meeting. If your organisation undergoes a significant change (a new programme, a new funder, a change in key staff or volunteers, a new event type), do a targeted review at that point rather than waiting for the annual cycle. The Charity Commission expects trustees to keep risk oversight current, not just annual.

What is the difference between risk assessment and risk management?

risk assessment is the diagnostic step: you identify, score, and prioritise the risks your organisation faces. Risk management is the ongoing treatment that follows: the insurance you buy, the controls you put in place, the contingency plans you document, and the regular check-ins that keep the list current. Most small organisations that say "we do risk management" mean they bought public liability insurance once. A risk assessment is the moment you ask which risks are actually on the table this year.

How do we prioritise risks with limited resources?

Use the likelihood-times-impact score. Anything scoring 15 or above is in the top tier: act on it this quarter. Scores of 8 to 14 are real risks you can plan for across the next few months. Scores of 1 to 7 go on the watch list for next year. A small organisation can credibly work on three to five top-tier risks in a year. Resist the urge to act on everything at once: partial action on the top risks is worth more than spreading thin attention across 25.

Who should run the risk assessment in a small charity?

Your trustees and chief executive (or founder-trustee) run it together. You do not need a risk officer, a committee, or outside counsel to start. The chair typically facilitates; the treasurer leads the financial inputs; programme leads bring the operational risks. If you have a solicitor or accountant you already work with, share the draft after the meeting for a sense-check. The assessment belongs in the room with the people who make decisions, not in a consultant's report that arrives six weeks later.

Can we run a raffle without breaching UK gambling law?

Yes, if you follow the rules. Most charity raffles are small society lotteries under the Gambling Act 2005. You must register with your local licensing authority (not the Gambling Commission directly) before selling tickets. The registration fee is £40 initially and £20 for annual renewal. Key limits: £20,000 in ticket sales per single draw, £250,000 aggregate across all your lotteries in a year, at least 20% of proceeds must go to your cause, and the maximum single prize is £25,000. Submit a return to the local authority within 3 months of the draw. If the draw takes place entirely at an event (an incidental non-commercial lottery, such as a fete raffle), no registration is required. Note: Gift Aid does not apply to raffle ticket purchases. Full details are on the Gambling Commission small society lotteries page.

Do we need insurance before our first event?

Yes. Public liability insurance is standard practice before any in-person event and many venues will not let you set up without proof of it. If your charity employs anyone (even part-time), employers' liability insurance is a legal requirement. Trustee Indemnity Insurance (TII) protects your trustees personally against claims arising from decisions they make in their trustee role; it is increasingly required by funders and a sensible precaution for any board. Get at least two quotes from a broker familiar with UK charities. NCVO publishes guidance on the insurance types relevant to small charities. Treat insurance as a pre-event line item, not a someday line item.

Written by
Camille Duboz
Share this article

https://home.simplyk.io/blog/nonprofit-risk-management

Keep reading :

Nonprofit software
Best Charity Management Software for UK Charities in 2026

UK charities juggle fundraising, event ticketing, donor records, volunteers, grants, and finances across multiple tools. This guide cuts through the US-centric noise to compare the best charity management software genuinely suited to the UK sector in 2026, from free all-in-one platforms to specialist CRMs and ticketing tools.

Read more
Nonprofit software
Best Donor Management Software for Small UK Charities in 2026

Choosing the right supporter management software is one of the most impactful decisions a small UK charity can make. This guide compares the 8 best tools for 2026, covering Gift Aid handling, UK GDPR compliance, fees in £, and the features that matter most to time-poor fundraising teams.

Read more
Nonprofit software
Best Grant Management Software for UK Charities (2026 Guide)

Grant management software is two products in one label. On one side are workflow platforms foundations use to run their grantmaking: application intake, review scoring, disbursement, compliance reporting. On the other are trackers that charities use to manage the grants they are chasing and the ones they have won: pipeline, deadlines, restricted-fund reporting. Different buyers, different jobs, different shortlists. This guide splits the audience first, then recommends tools per job.

Read more

Raise funds with Zeffy. 100% free, forever.

Sign up for free
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.

More fundraising tips, straight to your inbox!

Join 250K+ fundraising leaders receiving exclusive tips

Get weekly fundraising tips from nonprofits experts

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.

Zeffy is the only 100% free fundraising platform for nonprofits.

Get tailored fundraising ideas—free AI tool!

Find your ideal grant among thousands—free AI tool!

Start your nonprofit in 3 days—for free.

Start fundraising
Zeffy is 100% free and always will be. (We even cover transactions fees.)
Sign up and start fundraising for free today
With Zeffy, 100% of the money you raise goes to your cause. <br>No credit card fees. No platform fees. No fees period.
Did you know
Sign up for free
With Zeffy, 100% of the money you raise goes to your cause. <br>No credit card fees. No platform fees. No fees period.
Did you know
Sign up for free
Question
Cost :
$
$$
Effort :
1
23
Fun :
★★

Insights from over $100M in monthly transactions

Quick wins for you:

  • Look for people who attend related events, follow relevant Facebook groups, or subscribe to aligned newsletters.These aren’t just potential donors—they’re your future advocates.
  • Look for people who attend related events, follow relevant Facebook groups, or subscribe to aligned newsletters.These aren’t just potential donors—they’re your future advocates.

See our Guide for Mission Statements

How Loose Ends turned fee savings into mission impact
$1,715
saved
1
new hire
2500+
finished textile projects
This is some text inside of a div block.
This is some text inside of a div block.
  • This is some text inside of a div block.
  • This is some text inside of a div block.
  • This is some text inside of a div block.
This is some text inside of a div block.
This is some text inside of a div block.
This is some text inside of a div block.
This is some text inside of a div block.
  • This is some text inside of a div block.
  • This is some text inside of a div block.
  • This is some text inside of a div block.

Heading

Heading

Heading

Heading

Heading

Always Say Thanks
Every donor gets an automatic, branded thank-you email the moment they give. It’s fast, personal, and completely hands-off.