Fraud in the charity sector – what trustees and directors need to know
Fraud remains a significant and evolving threat, potentially affecting financial stability, public trust, and the institutional resilience of any organisation. Given their nature, that threat is often acutely felt in charities.
Surveys of UK charities show that over a third reported incidents of fraud or attempted fraud in the past year, with 73% suffering financial loss and only 32% recovering those losses. According to the Charity Commission and the Fraud Advisory Panel, the true figure is likely even higher because fraud in charities, as in other sectors, remains substantially underreported, often due to reputational concerns or a lack of awareness that fraud has occurred.
Within the charity sector, fraud risk comes from multiple internal and external sources. Insider fraud is the most prevalent threat to charities, with misappropriation of cash or assets accounting for a substantial proportion of reported incidents. However, cyber‑enabled fraud is increasing rapidly, with charities reporting more frequent phishing attempts, payment diversion attacks, and system compromises.
Insider fraud
Charities are driven by altruism and, given their nature, rely on trust (both legally and practically) to succeed. Despite this, they are sadly far from immune to fraud from within. Recent reports show that 38–50% of fraud cases affecting charities are committed by insiders such as employees, volunteers or trustees.
Trust and goodwill are often central to the smooth functioning and overall success of many charitable organisations. These organisations typically rely on a culture of openness, shared purpose, and mutual confidence between employees, volunteers, and trustees. However, this same culture may inadvertently create conditions that are vulnerable to abuse. When oversight mechanisms are informal or under‑resourced, the trust placed in individuals can be exploited by insiders who have access to the charity’s finances, systems, or physical assets.
Dishonest employees, volunteers, or trustees may take advantage of their position to misuse funds or divert resources for personal gain. This typically arises because internal controls are weaker than in larger, more commercial, and/or better-funded organisations, or because financial duties are concentrated in the hands of a small number of people, resulting in reduced oversight, limited segregation of duties, and insufficient auditing mechanisms, which collectively increase the likelihood that wrongdoing will go unnoticed.
Small charities in particular often rely on a single administrator or treasurer, increasing the risk of unchecked authority and reducing opportunities for independent review. Common insider fraud schemes include payroll manipulation, expense fraud, procurement fraud, and the misuse of charity credit cards or grant funds.
Trustee duties
Charity trustees are under a legal duty to safeguard their charity’s assets and apply its resources responsibly under the Charities Act 2011 and general principles of trustee law. They are also expected, under the Charity Commission’s guidance (notably CC3 ‘The essential trustee’ and CC8 ‘Internal financial controls for charities’) to implement proportionate risk management and internal control frameworks.
However, many charities find it challenging to ensure that anti-fraud policies and procedures operate effectively. This is often due to limited resources, competing operational demands, and the absence of specialist financial or compliance expertise. Strengthening governance, improving segregation of duties, and maintaining a healthy degree of scrutiny can help ensure that trust supports the charity’s mission, rather than becoming a point of vulnerability.
Cyber fraud
Although insider fraud remains the most prevalent threat within the charitable sector, cyber-enabled fraud is also a very real (and ever-increasing) risk. Internal or external actors leverage technology to access sensitive information or disrupt operations. While charities face the same cyber threats as businesses and public bodies, several structural and cultural factors make them more exposed and less resilient to attacks.
Many charities operate on tight budgets and prioritise frontline service delivery over the acquisition, effective implementation, and consistent maintenance of sophisticated IT systems. Underinvestment in cyber infrastructure and the prohibitive cost of cybersecurity tools, monitoring systems and specialist staff often mean that basic vulnerabilities tend to go unaddressed. The National Cyber Security Centre (NCSC) notes that many charities lack multi‑factor authentication (MFA), adequate password policies, regular system patching, and secure data backup processes.
This situation is compounded by a lack of incident response plans, cyber risk assessments, governance around cyber risk, contingency planning, and internal training. As such, charities are frequently underprepared for, and would struggle to recover from, any potential cyberattack.
Charities are attractive targets because they hold data that is often extremely valuable to bad actors such as donor contact and payment details, employee and volunteer information, and beneficiary records (often including sensitive or special-category data). Bad actors may also target charities for direct financial theft or to exploit public generosity by impersonating charitable organisations. Cybercriminals are increasingly using social engineering techniques, such as phishing (the most common cyber threat to charities, according to the Charity Commission), impersonation, and business email compromise. All of these exploit the trust‑based culture, and the need for external funding, often by individuals, that charities rely on.
Despite being less frequent than insider fraud, cyber‑enabled fraud can cause severe damage, including major data breaches, payment diversion, and long‑term reputational harm. Recent UK cyberattacks on major retailers (including M&S, Jaguar Land Rover, and Co-op) illustrate the scale of disruption possible, even where organisations have significant security budgets, highlighting the challenges charities may face in mounting an effective response.
Preventing fraud
Strong internal controls remain one of the most effective methods of fraud detection and prevention. Such measures include robust segregation of financial duties, dual authorisation for payments, regular internal audits, and fraud awareness training for staff, trustees and volunteers. Whistleblowing mechanisms are also essential; employees and volunteers must feel safe raising concerns.
The new ‘failure to prevent fraud’ offence, introduced under the Economic Crime and Corporate Transparency Act 2023 (ECCTA), came into force on 1 September 2025. This marks the UK’s third corporate ‘failure to prevent’ offence, sitting alongside the Bribery Act 2010 (failure to prevent bribery) and the Criminal Finances Act 2017 (failure to prevent the facilitation of tax evasion). Together, these laws establish a framework that holds organisations, including corporate charities (eg charitable companies, CIOs, and Royal Charter bodies), accountable for unlawful activities by individuals associated with them. A charity will be in scope only if it meets the statutory definition of a ‘large organisation’, namely satisfying at least two of the following: more than 250 employees, a turnover of greater than £36 million, and/or total assets exceeding £18 million.
While the Bribery Act targets bribery offences and the Criminal Finances Act focuses on preventing tax‑evasion facilitation, ECCTA closes a significant gap by requiring large organisations to implement ‘reasonable procedures’ to prevent fraud carried out by employees, agents, subsidiaries, or other associated persons for the organisation’s benefit.
Under ECCTA, charities meeting the ‘large organisation’ threshold must implement ‘reasonable procedures’ to prevent fraud for their benefit. However, even charities below the threshold are strongly encouraged to adopt similar measures as a matter of good governance and risk management.
Reasonable procedures may include:
- updating anti‑fraud policies;
- conducting fraud and cyber‑risk assessments;
- strengthening financial and cyber controls;
- enhanced due diligence of trustees, senior managers, and third‑party partners;
- targeted training for staff and volunteers; and
- documenting governance improvements.
Charities should also ensure they have appropriate fidelity insurance and/or cyber‑insurance in place. Where a fraud is perpetrated by an insider, the charity may bring a civil claim for breach of fiduciary duty. In certain cases, charities must also report fraud to Action Fraud, the Charity Commission, insurers, and, in the case of personal data breaches, potentially the ICO.
The current economic climate presents significant challenges for the charity sector, with charitable donations down by £1.4 billion last year and millions of people saying they can no longer afford to give to charity amid rising living cost pressures. When charitable income is constrained but demand for charitable services remains high, the financial and reputational impact of fraud can be particularly damaging.
In such an environment, fraud prevention is not simply a matter of regulatory compliance or good governance. It is a critical component of organisational resilience. Charities that take proactive steps to identify and assess fraud risks, strengthen internal controls, improve cyber security, and foster a culture of vigilance will be better placed to protect their funds, maintain public trust, and continue delivering their charitable objectives. As resources become increasingly stretched, prevention is likely to prove far less costly than responding to fraud after the event.

