1. Policy Statement
Al-Waris Foundation creates and receives records relating to its:
- governance;
- finances;
- donations;
- fundraising;
- beneficiaries;
- projects;
- volunteers;
- safeguarding;
- complaints;
- contractors;
- communications;
- website;
- regulatory obligations.
The charity is committed to keeping records for appropriate periods and securely disposing of information when it is no longer reasonably required.
Records must not be:
- destroyed prematurely;
- retained indefinitely without justification;
- altered to conceal activity;
- disposed of to obstruct an investigation;
- stored insecurely.
2. Purpose
This policy establishes a framework for:
- record creation;
- retention;
- storage;
- archiving;
- deletion;
- secure destruction;
- legal holds;
- digital records;
- paper records;
- project evidence;
- financial records;
- governance records;
- personal data.
3. Scope
This policy applies to records held by or on behalf of Al-Waris Foundation.
It applies to:
- trustees;
- staff where applicable;
- volunteers;
- authorised representatives;
- contractors handling charity records;
- systems operated for the charity.
It applies regardless of whether information is held:
- electronically;
- on paper;
- in email;
- in cloud storage;
- in databases;
- in messaging applications;
- in photographs or video;
- in accounting systems;
- in website systems.
4. Core Principles
Al-Waris Foundation will seek to ensure that records are:
- accurate where necessary;
- relevant;
- appropriately organised;
- accessible to authorised persons;
- protected against unauthorised access;
- retained for an appropriate period;
- securely disposed of when no longer required.
5. Responsibility
The Board of Trustees retains overall responsibility for appropriate records governance.
Operational responsibility may be delegated to authorised persons responsible for:
- administration;
- finance;
- safeguarding;
- fundraising;
- projects;
- data protection;
- technology.
6. Record Ownership
Records created or received in the course of authorised Al-Waris Foundation activity normally belong to the charity rather than the individual who created them.
This may include records stored temporarily on:
- personal devices;
- personal email accounts;
- messaging applications.
Important charity records should be transferred into appropriate charity-controlled storage where reasonably practicable.
7. Data Minimisation
The charity should not retain personal information merely because storage is available.
Records containing personal data should be limited to information reasonably required for legitimate purposes.
8. Retention Decisions
Retention periods should take account of:
- legal obligations;
- Charity Commission requirements;
- HMRC requirements;
- accounting requirements;
- safeguarding;
- contractual requirements;
- limitation periods;
- insurance;
- regulatory expectations;
- operational need;
- historical value.
9. Retention Schedule
The schedule in this policy provides Al-Waris Foundation's normal internal retention framework.
A record may be retained for longer where there is a legitimate reason.
A statutory requirement or legal obligation takes precedence over an internal period stated in this policy.
10. Permanent Governance Records
The following should normally be retained permanently:
- governing document and amendments;
- Charity Commission registration records;
- trustee appointment and resignation records;
- signed trustee resolutions of lasting significance;
- formal constitutional changes;
- records of mergers or dissolution where applicable;
- significant regulatory decisions.
11. Trustee Meeting Minutes
Approved trustee and Board meeting minutes should normally be retained permanently.
Supporting meeting papers may be retained according to their continuing governance, legal or historical significance.
12. Policies
Superseded versions of significant governance policies should normally be retained to provide an audit trail.
Records should identify where reasonably practicable:
- version;
- approval date;
- approving body;
- review date.
13. Conflict of Interest Records
Registers and declarations of trustee conflicts should normally be retained for at least 6 years after they cease to be current, unless a longer period is justified.
Records connected to a significant governance matter may be retained longer.
14. Annual Reports and Accounts
Final annual reports, annual accounts and submitted regulatory returns should normally be retained permanently as part of the charity's historical governance record.
15. Accounting Records
Accounting records should normally be retained for at least 6 years after the end of the relevant financial period, subject to applicable legal or tax requirements.
These may include:
- ledgers;
- bank statements;
- invoices;
- receipts;
- payment records;
- reconciliations;
- expense records;
- supporting financial documentation.
16. Bank Records
Bank statements, reconciliations and material supporting banking records should normally be retained for at least 6 years after the relevant financial period.
Records connected to unresolved transactions or disputes should be retained longer where necessary.
17. Donation Records
Donation transaction records should normally be retained for at least 6 years after the relevant financial period.
This may include:
- amount;
- date;
- transaction reference;
- donation designation;
- payment status;
- refund status.
Personal donor information should not be retained longer than necessary merely because transaction records must be retained.
18. Restricted Fund Records
Records demonstrating the creation, receipt, application and closure of restricted funds should normally be retained for at least 6 years after the fund has been fully applied or otherwise lawfully resolved.
Material records may be retained longer where necessary to demonstrate compliance with donor restrictions.
19. Gift Aid Records
Where Gift Aid is operated, declarations and associated records should be retained for the period required by applicable HMRC rules.
The current HMRC requirement should be checked when Gift Aid functionality is activated or administered.
20. Fundraising Appeals
Material fundraising records should normally be retained for at least 6 years after the relevant Appeal or campaign closes.
These may include:
- published fundraising wording;
- target;
- restriction;
- surplus-fund wording;
- amount raised;
- key decisions;
- closure records.
This helps demonstrate what donors were told when donations were received.
21. Cause Records
Records concerning permanent or long-term Causes may remain active for as long as the Cause operates.
Historical versions of material fundraising terms should be retained where necessary to understand earlier donations.
22. Project Records
Material project records should normally be retained for at least 6 years after project completion.
Records may include:
- project number;
- budget;
- approvals;
- supplier or contractor;
- invoices;
- completion evidence;
- monitoring;
- photographs;
- project reports.
23. Water Project Records
Al-Waris Foundation should maintain a durable record for each completed water installation.
The record should normally include:
- AWF project number;
- project location;
- GPS/location where appropriate;
- installation type;
- depth/specification where applicable;
- completion date;
- contractor;
- photographs/video;
- cost/invoice;
- maintenance information;
- warranty information;
- plaque or project-identification evidence.
Core records identifying the installation and its location may be retained for the operational life of the installation and beyond where useful for accountability and historical project records.
24. Water Maintenance Records
Maintenance, repair and warranty records should be retained for as long as they remain relevant to the installation.
Significant records may be linked permanently to the project's core record.
25. Food Distribution Records
Material food-distribution records should normally be retained for at least 6 years where required for financial or project accountability.
Records may include:
- purchase information;
- quantities;
- package composition;
- distribution date;
- location;
- evidence;
- expenditure.
Beneficiary-identifying information should only be retained where genuinely required.
26. Emergency Project Records
Emergency and disaster-response records should normally be retained for at least 6 years after completion.
Longer retention may be appropriate where the activity involves:
- significant restricted funds;
- safeguarding;
- regulatory reporting;
- litigation;
- major public interest.
27. Procurement Records
Material procurement records should normally be retained for at least 6 years after completion of the transaction or contract.
These may include:
- specifications;
- quotations;
- evaluations;
- approvals;
- contracts;
- invoices;
- contractor due diligence.
28. Contracts
Contracts should normally be retained for the duration of the agreement and for at least 6 years after termination or expiry, unless a longer period is appropriate.
Contracts executed as deeds or involving longer legal limitation periods may require longer retention.
29. Supplier Records
Routine supplier information should be retained for as long as the relationship remains active and thereafter only for as long as necessary for:
- accounting;
- tax;
- legal;
- fraud prevention;
- contractual purposes.
30. Contractor Due Diligence
Due-diligence records for significant contractors should normally be retained for at least 6 years after the relationship or relevant project ends.
High-risk or disputed relationships may justify longer retention.
31. Grant Records
Records relating to grants made by Al-Waris Foundation should normally be retained for at least 6 years after the grant is completed or closed.
This may include:
- application;
- due diligence;
- approval;
- conditions;
- payments;
- monitoring;
- completion evidence.
32. Expense Records
Expense claims and supporting evidence should normally be retained for at least 6 years after the relevant financial period.
33. Cash Collection Records
Records relating to public or street collections should normally be retained for at least 6 years where they form part of financial records.
This may include:
- permit;
- collection date;
- location;
- collector records where appropriate;
- cash count;
- reconciliation;
- banking record.
34. Payment Processor Records
Material payment-processor records should normally be retained in line with financial-record requirements.
The charity does not need to duplicate information indefinitely where reliable records remain available elsewhere and appropriate access is assured.
35. Volunteer Records
Routine volunteer records should normally be retained for the duration of the volunteer relationship and for an appropriate period afterward.
A general retention period of up to 6 years after the relationship ends may be appropriate where records remain relevant to:
- disputes;
- insurance;
- safeguarding;
- claims;
- governance.
Unnecessary personal information should be removed earlier where appropriate.
36. Volunteer Applications
Unsuccessful volunteer applications should normally be retained only for a limited period unless there is a legitimate reason for longer retention.
As a general internal period, they should normally be deleted within 6 to 12 months after the recruitment process ends.
37. Recruitment Records
Recruitment records should be retained according to:
- legal requirements;
- equality considerations;
- safeguarding;
- potential claims;
- operational need.
Unsuccessful applicant records should not be retained indefinitely.
38. DBS and Criminal Record Information
Information relating to criminal-record checks requires particular care.
The charity should not routinely retain copies of DBS certificates longer than necessary.
Where appropriate, the charity may record limited information such as:
- check completed;
- date;
- certificate reference where permitted;
- decision.
Applicable DBS handling requirements should be followed.
39. Safeguarding Records
Safeguarding records may require significantly longer retention than ordinary administrative records.
Retention should consider:
- nature of concern;
- age of person affected;
- possible future allegations;
- statutory guidance;
- insurance;
- regulatory expectations.
Safeguarding records must not be automatically deleted under a routine six-year rule.
40. Safeguarding Record Review
Where a safeguarding record reaches a proposed disposal date, an appropriately authorised person should assess whether deletion is safe and appropriate.
Professional safeguarding or legal advice should be obtained where necessary.
41. Serious Incident Records
Records concerning serious incidents should normally be retained for at least 6 years after closure, and longer where:
- safeguarding is involved;
- legal proceedings remain possible;
- the Charity Commission has been involved;
- significant governance lessons remain relevant.
42. Complaints
Routine complaint records should normally be retained for at least 3 years after closure.
A longer period may be appropriate where the complaint involves:
- safeguarding;
- litigation;
- serious misconduct;
- regulatory reporting;
- repeated complaints.
43. Whistleblowing Records
Whistleblowing records should be retained according to the seriousness and outcome of the concern.
Material substantiated matters may require retention for at least 6 years or longer.
Records should be kept confidential and access restricted.
44. Fraud and Financial Crime Records
Records relating to suspected or confirmed:
- fraud;
- bribery;
- corruption;
- money laundering concerns;
- sanctions concerns;
should normally be retained for at least 6 years after closure, unless legal, regulatory or investigative requirements justify longer retention.
45. Sanctions Screening
Material sanctions or financial-crime due-diligence records should be retained for an appropriate period demonstrating the checks undertaken.
The appropriate period should reflect the nature and risk of the relationship.
46. Health and Safety Records
Routine accident and health and safety records should normally be retained for at least 3 years from the relevant incident, subject to longer applicable requirements.
Longer retention may be required where:
- a child is involved;
- an occupational condition is involved;
- litigation remains possible;
- insurance requirements apply.
47. Insurance Records
Current insurance policies should be retained throughout their period of cover.
Historic policies and significant claims records should be retained where they may be relevant to future claims.
Some liability claims may arise many years after the relevant event, so potentially relevant historic insurance evidence should not be destroyed without appropriate consideration.
48. Premises Records
Material premises records should be retained for the duration of occupation and for an appropriate period afterward.
These may include:
- lease;
- landlord correspondence;
- utility matters;
- insurance;
- significant maintenance;
- disputes.
Legal or financial records should follow the applicable longer retention period.
49. Utility Disputes
Records connected to a disputed utility liability or enforcement matter should be retained until:
- the matter is conclusively resolved;
- relevant limitation periods have been considered;
- there is no reasonable continuing need for the evidence.
Such records must not be destroyed merely because the charity leaves the premises.
50. Legal Claims and Disputes
Records relevant to actual or reasonably anticipated legal proceedings must not be destroyed while they may remain relevant.
This applies even where their normal retention period has expired.
51. Legal Hold
Where litigation, regulatory investigation, safeguarding investigation, fraud investigation or another serious dispute is reasonably anticipated, relevant deletion should be suspended.
This is referred to in this policy as a legal hold.
52. Scope of Legal Hold
A legal hold may apply to:
- emails;
- messages;
- financial records;
- photographs;
- video;
- contracts;
- logs;
- paper documents;
- system records.
Relevant records should be preserved until the hold is formally lifted.
53. Data Subject Requests
Records relevant to an active data-protection request should not be deleted merely because a routine deletion date occurs during processing.
The charity should preserve what is reasonably necessary to respond properly.
54. Data Protection Records
Records demonstrating data-protection compliance should be retained for as long as reasonably necessary.
These may include:
- data-breach records;
- consent records;
- data-processing agreements;
- legitimate-interest assessments;
- data-subject requests;
- privacy decisions.
55. Personal Data Breach Records
Records of personal-data breaches should be retained for an appropriate period sufficient to demonstrate:
- circumstances;
- effects;
- remedial action;
- notification decisions.
Material incidents may warrant retention for at least 6 years.
56. Consent Records
Where processing or publication relies upon consent, evidence of that consent should normally be retained for as long as the relevant processing continues and for an appropriate period afterward.
A record of withdrawal should also be retained where necessary to ensure the withdrawal continues to be respected.
57. Beneficiary Records
Beneficiary information should be retained only for as long as necessary for:
- delivering assistance;
- project accountability;
- safeguarding;
- fraud prevention;
- legal obligations;
- legitimate monitoring.
Beneficiary data should not automatically be retained for six years merely because financial records relating to the same project are retained for six years.
58. Beneficiary Identity Documents
Copies of identity documents should only be retained where genuinely necessary.
Where verification can be recorded without retaining a complete identity document, this may reduce risk.
59. Photography and Video
Project photographs and videos should be retained according to:
- evidential purpose;
- consent;
- safeguarding;
- historical value;
- fundraising need;
- privacy.
Not every raw media file needs to be retained permanently.
60. Core Project Media
A limited selection of important project evidence may be retained for longer periods where it provides a legitimate historical or accountability record.
Sensitive beneficiary imagery should receive separate consideration.
61. AI-Generated Media
AI-generated illustrations that do not contain personal data may be retained according to ordinary content-management needs.
They should remain distinguishable from genuine project evidence where confusion could otherwise arise.
62. Website Content
Published website content may be retained while current.
Material historical versions should be preserved where they are relevant to:
- fundraising representations;
- governance;
- legal obligations;
- public accountability.
63. CMS Version History
The charity's CMS may retain previous content versions to support:
- rollback;
- audit;
- accountability;
- investigation.
Version history should not become an indefinite repository for personal data that should otherwise have been deleted.
64. Appeal Pages
A completed fundraising Appeal may remain publicly available as a historical record where appropriate.
The charity should consider removing or updating:
- outdated calls to donate;
- unnecessary beneficiary personal data;
- inaccurate status information.
65. Social Media Content
Social-media posts may remain publicly available where they continue to serve a legitimate purpose.
Older posts should be reviewed where they contain:
- outdated appeals;
- sensitive beneficiary information;
- incorrect information;
- expired contact details.
66. Emails
Email should not automatically be treated as permanent storage.
Important emails should be retained according to their content rather than merely because they exist in a mailbox.
Routine low-value correspondence may be deleted when no longer needed.
67. Transactional Emails
Emails forming evidence of:
- contracts;
- disputes;
- approvals;
- financial transactions;
- safeguarding;
- significant governance decisions;
should be retained according to the underlying record category.
68. Messaging Applications
Important charity decisions or evidence should not rely indefinitely on personal messaging history.
Where messages contain material records, relevant information should be transferred or preserved appropriately.
69. Social Media Direct Messages
Messages involving:
- complaints;
- safeguarding;
- donations;
- significant enquiries;
- disputes;
should be transferred into appropriate charity records where necessary.
70. Website Enquiries
Routine enquiries should be retained only as long as necessary to respond and administer the matter.
Where an enquiry develops into another record category, such as:
- complaint;
- volunteer application;
- safeguarding concern;
- donation dispute;
the applicable retention period should then apply.
71. Newsletter Records
Marketing subscription records should be retained while necessary to administer the subscription.
Where someone unsubscribes, sufficient suppression information may need to be retained to ensure they are not inadvertently resubscribed without an appropriate basis.
72. Cookie and Analytics Records
Analytics data should be retained only for a reasonable period consistent with:
- stated privacy information;
- configuration;
- legitimate analytical needs;
- applicable consent requirements.
73. Audit Logs
System audit logs should be retained for a period proportionate to:
- security risk;
- investigation needs;
- accountability;
- storage.
Critical financial or administrative audit information may require longer retention than ordinary technical logs.
74. Security Logs
Security logs should normally be retained long enough to support investigation of incidents that may not be discovered immediately.
The exact period may vary according to:
- system;
- risk;
- provider;
- cost;
- technical capability.
75. Backups
Backups are for recovery and must not be used as a means of deliberately retaining data indefinitely beyond its proper retention period.
Deletion from backups may occur through normal backup rotation where immediate selective deletion is technically impracticable, provided deleted data is not restored into active use improperly.
76. Paper Records
Paper records containing confidential information should be:
- stored securely;
- accessible only where appropriate;
- protected from avoidable loss or damage.
77. Scanning
Paper records may be digitised where appropriate.
Before destroying an original after scanning, the charity should consider whether:
- the original has legal significance;
- signatures are important;
- evidential value may be reduced;
- another requirement mandates retention.
78. Duplicate Records
Unnecessary duplicates should not be retained indefinitely.
Where a reliable master record exists, redundant copies may be securely deleted.
79. Draft Documents
Routine drafts may normally be deleted once a final version is approved.
Drafts should be retained where they have material evidential, legal or governance significance.
80. Temporary Files
Temporary exports, downloads and working copies containing confidential information should be deleted when no longer required.
Particular care should be taken with:
- CSV exports;
- spreadsheets;
- donor lists;
- beneficiary lists;
- database exports.
81. Personal Devices
Charity records stored on personal devices remain subject to this policy.
When the information is transferred to appropriate charity storage, unnecessary local copies should be deleted where reasonably practicable.
82. Former Trustees and Volunteers
When a person leaves Al-Waris Foundation, they should return or transfer charity records within their possession or control.
They should not retain confidential charity information without a legitimate reason and appropriate authority.
83. Cloud Services
Deletion from cloud systems should take account of:
- provider retention;
- recycle bins;
- version history;
- backups;
- shared copies.
The charity should use available controls proportionately.
84. Secure Disposal
Records containing confidential or personal information must be disposed of securely.
Appropriate methods may include:
- secure deletion;
- shredding;
- confidential waste disposal;
- cryptographic erasure;
- secure device wiping.
85. Ordinary Recycling
Confidential paper records must not be placed intact into ordinary recycling where unauthorised people could access them.
86. Device Disposal
Before selling, donating, recycling or disposing of devices used for charity records, information should be securely removed where reasonably practicable.
A normal file deletion may not be sufficient.
87. Storage Media
Storage devices containing highly sensitive charity information should be:
- securely erased;
- destroyed;
- otherwise rendered inaccessible;
before disposal where appropriate.
88. Disposal Register
For routine records, individual deletion records are not always necessary.
For significant bulk or sensitive destruction, the charity may maintain a disposal record identifying:
- record category;
- date;
- method;
- authorising person.
89. Automatic Deletion
Systems may use automated retention and deletion where appropriate.
Automated rules should be:
- understood;
- documented where material;
- reviewed;
- capable of suspension where a legal hold applies.
90. Destruction Authorisation
Material governance, safeguarding, legal or financial records should not be destroyed casually.
Where there is uncertainty, an appropriately authorised person should review the proposed disposal.
91. Prohibition on Concealment
No record may be destroyed, altered or hidden for the purpose of:
- concealing wrongdoing;
- preventing trustee scrutiny;
- obstructing an audit;
- avoiding regulatory disclosure;
- frustrating legal proceedings;
- hiding a safeguarding concern.
92. Investigations
Records potentially relevant to an internal or external investigation should be preserved.
This may include investigations involving:
- fraud;
- safeguarding;
- complaints;
- whistleblowing;
- data breaches;
- financial misconduct.
93. Freedom of Information
Al-Waris Foundation is not automatically subject to the Freedom of Information Act merely because it is a registered charity.
However, other disclosure obligations may apply depending on circumstances.
Records should not be destroyed merely because a person has requested information.
94. Charity Commission Requests
Records reasonably required by the Charity Commission should be preserved and supplied where the charity is lawfully required to do so.
95. HMRC and Tax Records
Applicable HMRC retention requirements take precedence over shorter internal periods.
Current requirements should be checked where necessary.
96. Insurance Requirements
Where an insurer requires records to be retained for a particular period, relevant records should be preserved accordingly.
97. Historical Archive
Al-Waris Foundation may retain selected records permanently because of legitimate historical value.
Examples may include:
- annual reports;
- major project summaries;
- significant photographs;
- founding records;
- major milestones.
Historical retention should still consider privacy and safeguarding.
98. Anonymisation
Where the informational value of a record can be preserved without identifying individuals, anonymisation may allow longer-term statistical or historical use.
Anonymisation should be sufficiently robust that individuals are no longer reasonably identifiable.
99. Pseudonymisation
Pseudonymisation may reduce risk but does not necessarily make information anonymous.
Pseudonymised personal data remains subject to data-protection requirements where re-identification remains reasonably possible.
100. Retention Reviews
The charity should periodically review significant record categories.
Reviews should identify:
- records due for deletion;
- records requiring continued retention;
- unnecessary duplicates;
- outdated personal information;
- legal holds.
101. System Design
Where reasonably practicable, new digital systems should support appropriate:
- retention;
- deletion;
- export;
- audit history;
- access control.
Records governance should be considered when systems are designed rather than only after data has accumulated.
102. Database Deletion
Deleting information from a user interface does not necessarily remove every database record.
Technical deletion procedures should reflect:
- legal requirements;
- financial-record preservation;
- audit requirements;
- data-subject rights.
103. Donor Account Deletion
Where a donor requests deletion of their account, the charity may still need to retain certain transaction records for:
- accounting;
- legal;
- fraud-prevention;
- regulatory purposes.
Unnecessary profile information should be deleted or anonymised where appropriate.
104. Financial Record Integrity
Records necessary to demonstrate genuine charitable transactions must not be deleted merely because an associated person requests account deletion.
The charity should instead minimise or separate personal information where possible while preserving required financial evidence.
105. Record Accuracy
Where records must be retained, reasonable steps should be taken to correct materially inaccurate personal information where required.
Historical records may sometimes preserve the original entry together with a correction rather than silently rewriting the historical record.
106. Access to Records
Access should be based on legitimate need.
Examples include:
- financial records for authorised finance personnel;
- safeguarding records for appropriate safeguarding personnel;
- governance records for trustees;
- project records for authorised operational personnel.
107. Trustee Access
Trustees should be provided with information reasonably necessary to discharge their governance duties.
This does not require unrestricted technical or operational access to every underlying system.
108. Confidentiality
Retention does not mean unrestricted availability.
Sensitive retained records should continue to receive appropriate confidentiality protection for their entire retention period.
109. Security
Digital and physical records should be protected according to the Information Security and Cybersecurity Policy.
Long-term archives should not become forgotten unsecured repositories.
110. Data Breaches
Improper disposal may constitute a personal-data breach.
Examples include:
- confidential records placed in public waste;
- devices sold without secure wiping;
- public links left active;
- beneficiary records discarded insecurely.
Such incidents should be assessed under the Data Protection and UK GDPR Policy.
111. Contractors
Where a contractor stores charity records, contractual arrangements should address appropriate:
- confidentiality;
- security;
- retention;
- return;
- deletion.
The charity should not assume a contractor automatically deletes information when the relationship ends.
112. Overseas Records
Records created during overseas operations remain subject to appropriate Al-Waris Foundation governance.
Practical local constraints may affect how evidence is initially collected, but material records should be transferred into suitable charity systems where reasonably practicable.
113. Cross-Border Storage
Where personal data is stored or accessed internationally, applicable data-protection requirements concerning international transfers should be considered.
114. Training and Awareness
People handling significant charity records should understand:
- what should be retained;
- where records should be stored;
- what should not be deleted;
- how to dispose of records securely;
- when to escalate uncertainty.
115. Policy Breaches
Breaches may include:
- premature destruction;
- unauthorised disclosure;
- deliberate concealment;
- insecure disposal;
- excessive unnecessary retention;
- failure to preserve evidence.
Appropriate action may include:
- access restriction;
- corrective action;
- volunteer management action;
- governance action;
- investigation;
- regulatory reporting.
116. Related Al-Waris Foundation Policies
This policy should be read alongside:
- Constitution;
- Data Protection and UK GDPR Policy;
- Confidentiality Policy;
- Information Security and Cybersecurity Policy;
- Financial Controls and Reserves Policy;
- Fundraising Policy;
- Procurement and Purchasing Policy;
- Expenses Policy;
- Safeguarding Children Policy;
- Safeguarding Adults at Risk Policy;
- Photography, Video and Beneficiary Consent Policy;
- Volunteer Policy;
- Complaints Policy;
- Whistleblowing Policy;
- Anti-Fraud, Bribery and Corruption Policy;
- Serious Incident Reporting Policy;
- Overseas Operations and Partner Due Diligence Policy.
117. Review
This policy will be reviewed:
- at least annually;
- following significant changes in applicable record-keeping requirements;
- following a significant data-protection incident;
- following material changes to the charity's digital systems;
- where retention controls are found to be inadequate;
- following significant operational expansion.
118. Approval
Version: 2.0 Status: Approved Approved by: Board of Trustees Approval date: 25/08/2026 Next scheduled review: 24/08/2027
