Records, Reporting and Compliance
This section covers the records a charity has to keep, the forms it has to file and the policies and checks that keep it on the right side of the law between one annual return and the next. It is aimed at trustees, secretaries and administrators who look after the paperwork rather than at the decisions themselves, which are in the Meetings and Decisions section.
What does the law expect of each type of charity?
A charitable company limited by guarantee must keep statutory registers and file forms at Companies House as well as reporting to the Charity Commission. A charitable incorporated organisation (CIO) must keep registers of its trustees and members but deals only with the Charity Commission. An unincorporated charity has the fewest formal registers but still needs to comply with the general obligations that apply to every charity, from the information on its letterhead to data protection.
How are the sections organised?
The first three sections are structure-specific: the statutory registers and related letters for a charitable company, the registers and lists for a CIO and the Companies House forms a charitable company files for routine changes.
The last three apply to charities generally. General Administration and Ongoing Compliance contains guidance and checklists on the formalities every charity has to observe. Financial Controls, Data Protection and Electronic Marketing contains internal financial controls policies, a privacy notice and guidance on marketing by email and text. Complaints and Safeguarding contains complaints procedures and safeguarding policies, which the Charity Commission treats as a governance priority for every charity.
Records, Reporting and Compliance is part of Charity. Just £38.50 + VAT provides unlimited downloads from Charity for 1 year.
Frequently Asked Questions
Only within the electronic marketing rules: direct marketing by email or text generally needs the person's explicit consent (unless the "soft opt in" exception applies), and fundraising appeals count as direct marketing for these purposes. Relying on old mailing lists without consent records is the classic breach. Keep evidence of consent, offer an opt-out in every message and check your privacy notice covers marketing. The Charity Electronic Marketing guidance note here explains the rules (including "soft opt in") as they apply to a charity.
Yes. UK GDPR requires anyone processing personal data, and every charity holds supporter, beneficiary or volunteer data, to tell people what is collected, why, on what lawful basis, who it is shared with and their rights. A privacy notice is how you meet that duty. Publish it on your website and reference it at data collection points. The GDPR compliant charity privacy notice template here is written to suit a small scale organisation.
There is no single statutory list. What exists is a web of Charity Commission expectations: some policies are effectively required for charities with particular activities, safeguarding where you work with children or vulnerable people, internal financial controls for everyone, and the annual return asks trustees to confirm which policies they hold. Treat safeguarding, financial controls, conflicts of interest and expenses as the core set. This section provides the safeguarding and financial controls templates, scaled for smaller charities; the conflict of interest policies are in the Conflicts of Interest and Trustee Conduct section and the expenses policies in the Expenses for Trustees, Employees and Volunteers section.
No, it is a voluntary code. It reflects the legal duties in the Commission's essential trustee guidance and adds practical standards boards adopt on an apply or explain basis. Funders and larger partners increasingly ask whether you follow it, so adopting it signals credibility even though no law requires it. A sensible route for a small charity is to adopt the core policies in this group first, then benchmark against the Code as you grow.