Skip to main content

Operations and risk

Risk Management Policy

Al-Waris Foundation recognises that effective risk management is an essential part of good charity governance.

Current version 2.0

1. Policy Statement

Al-Waris Foundation recognises that effective risk management is an essential part of good charity governance.

The charity cannot and should not attempt to eliminate every risk.

Instead, Al-Waris Foundation will seek to:

  • identify significant risks;
  • understand their potential impact;
  • assess their likelihood;
  • implement proportionate controls;
  • monitor changing risks;
  • respond appropriately when incidents occur;
  • make informed decisions about acceptable risk.

Risk management should support, rather than unnecessarily prevent, the charity's ability to pursue its charitable purposes.

2. Purpose

This policy establishes the framework used by Al-Waris Foundation to manage risks affecting:

  • beneficiaries;
  • charitable funds;
  • trustees;
  • volunteers;
  • projects;
  • fundraising;
  • overseas operations;
  • information;
  • systems;
  • reputation;
  • regulatory compliance;
  • continued operation of the charity.

3. Scope

This policy applies across all Al-Waris Foundation activities, including:

  • governance;
  • fundraising;
  • donations;
  • financial management;
  • grant making;
  • charitable projects;
  • overseas operations;
  • contractors;
  • suppliers;
  • partner organisations;
  • volunteers;
  • safeguarding;
  • data protection;
  • cybersecurity;
  • communications;
  • website and digital services;
  • premises;
  • events;
  • public collections.

Risk management should be proportionate to the nature, scale and complexity of each activity.

4. Trustee Responsibility

The Board of Trustees retains ultimate responsibility for risk management.

Trustees are responsible for ensuring that:

  • significant risks are identified;
  • appropriate controls exist;
  • significant risks are reviewed;
  • major incidents are appropriately managed;
  • risk is considered when making important decisions.

Operational risk-management responsibilities may be delegated.

Delegation does not remove the Board's governance responsibility.

5. Operational Responsibility

The Board may delegate day-to-day risk management to:

  • the Chair;
  • authorised officers;
  • project leads;
  • safeguarding leads;
  • volunteers;
  • contractors;
  • other appropriately appointed persons.

People responsible for operational activities should escalate significant risks rather than attempting to manage matters beyond their authority.

6. Risk Management Principles

Al-Waris Foundation will apply the following principles:

Proportionality

Controls should reflect the seriousness and likelihood of the risk.

Accountability

Responsibility for significant controls should be clear.

Evidence

Important risk decisions should be based on available evidence rather than assumption alone.

Prevention

Where reasonably practicable, risks should be reduced before an incident occurs.

Escalation

Significant risks should be brought to an appropriate decision-maker promptly.

Review

Risks change and should therefore be periodically reassessed.

7. Risk Appetite

Risk appetite is the level and type of risk that Al-Waris Foundation is prepared to accept while pursuing its charitable purposes.

The charity may accept reasonable operational risks where:

  • the charitable benefit justifies them;
  • they are understood;
  • appropriate controls exist;
  • the remaining risk is considered acceptable.

The charity has a very low tolerance for risks involving:

  • serious safeguarding failures;
  • deliberate fraud;
  • bribery or corruption;
  • unlawful diversion of charitable funds;
  • sanctions breaches;
  • terrorist financing;
  • deliberate regulatory deception;
  • deliberate misuse of beneficiary information.

8. Risk Categories

Significant risks may fall into categories including:

  • governance;
  • strategic;
  • financial;
  • fraud;
  • safeguarding;
  • operational;
  • overseas;
  • partner and contractor;
  • fundraising;
  • regulatory;
  • legal;
  • data protection;
  • cybersecurity;
  • health and safety;
  • reputational;
  • financial sustainability;
  • project delivery.

Risks may fall into more than one category.

9. Governance Risk

Governance risks may include:

  • insufficient trustee oversight;
  • ineffective decision-making;
  • unmanaged conflicts of interest;
  • unclear delegation;
  • failure to comply with the Constitution;
  • inadequate records;
  • excessive dependence on one person;
  • trustee vacancies;
  • lack of appropriate skills;
  • failure to submit regulatory filings.

Controls may include:

  • clear trustee responsibilities;
  • documented decisions;
  • conflicts procedures;
  • delegated authority;
  • governance reviews;
  • succession planning;
  • appropriate trustee recruitment.

10. Strategic Risk

Strategic risks may arise where:

  • activities do not sufficiently further charitable purposes;
  • resources are spread too widely;
  • projects become financially unsustainable;
  • priorities no longer reflect beneficiary needs;
  • the charity undertakes activity beyond its capacity.

Significant new programmes should therefore be assessed before substantial resources are committed.

11. Financial Risk

Financial risks may include:

  • insufficient income;
  • excessive expenditure;
  • cash-flow problems;
  • inappropriate use of restricted funds;
  • inaccurate financial records;
  • unauthorised payments;
  • financial dependency on one source;
  • unplanned liabilities;
  • loss of banking or payment services.

Controls should be maintained under the Financial Controls and Reserves Policy.

12. Financial Sustainability

The Board should monitor whether Al-Waris Foundation has sufficient financial resources to:

  • meet liabilities;
  • continue planned activities;
  • honour restricted-fund obligations;
  • respond to unexpected costs.

The charity should avoid committing to expenditure that it cannot reasonably expect to fund.

13. Reserves Risk

Insufficient reserves may leave the charity unable to respond to:

  • income reductions;
  • unexpected expenditure;
  • operational disruption;
  • emergency liabilities.

Excessive unrestricted reserves may also create governance concerns where charitable funds are accumulated without sufficient justification.

The Board should therefore maintain an appropriate reserves approach.

14. Fraud Risk

Fraud risks may include:

  • false invoices;
  • unauthorised payments;
  • fabricated beneficiaries;
  • duplicate claims;
  • false project evidence;
  • payment-account compromise;
  • fundraising theft;
  • contractor fraud.

Controls should include appropriate:

  • approvals;
  • records;
  • verification;
  • payment controls;
  • due diligence;
  • monitoring.

See the Anti-Fraud, Bribery and Corruption Policy.

15. Bribery and Corruption Risk

The charity may encounter bribery or corruption risks particularly through:

  • procurement;
  • overseas operations;
  • contractor selection;
  • beneficiary selection;
  • customs or local administration;
  • grant making.

Improper payments must not be made merely because they are described as normal local practice.

16. Safeguarding Risk

Safeguarding is a major risk area for any activity involving children, adults at risk or vulnerable communities.

Controls may include:

  • safeguarding policies;
  • designated responsibility;
  • safer recruitment;
  • appropriate supervision;
  • reporting routes;
  • training;
  • partner due diligence;
  • beneficiary consent procedures.

See the relevant safeguarding policies.

17. Volunteer Risk

Volunteer-related risks may include:

  • inadequate training;
  • unclear responsibilities;
  • inappropriate access;
  • safeguarding concerns;
  • unsafe activities;
  • reputational misconduct;
  • misuse of charity resources.

Volunteer access and responsibilities should be proportionate to their role.

18. Overseas Risk

Overseas work may create additional risks including:

  • weaker infrastructure;
  • limited banking;
  • fraud;
  • corruption;
  • safeguarding;
  • sanctions;
  • political instability;
  • unreliable suppliers;
  • security conditions;
  • difficulty verifying project delivery.

Risk assessments should reflect the specific country, location, activity and partner rather than treating all overseas work as equally risky.

19. Partner Risk

Al-Waris Foundation may rely on local organisations or partners to deliver charitable work.

Risks may include:

  • weak governance;
  • poor financial controls;
  • inadequate safeguarding;
  • inaccurate reporting;
  • misuse of funds;
  • sanctions exposure;
  • reputational concerns.

Appropriate due diligence should be completed before material relationships begin.

See the Overseas Operations and Partner Due Diligence Policy.

20. Contractor Risk

Contractors may be used for:

  • construction;
  • water projects;
  • transport;
  • food procurement;
  • photography;
  • project delivery;
  • professional services.

Before material work begins, Al-Waris Foundation should consider:

  • identity;
  • registration where applicable;
  • quotation;
  • experience;
  • reputation;
  • price;
  • safeguarding implications;
  • payment terms;
  • evidence requirements;
  • warranty or maintenance arrangements where relevant.

21. New Contractor Pilot Approach

Where practicable, new contractors undertaking repeatable charitable project work should initially be tested through a limited pilot before receiving substantial batches of work.

A pilot may help assess:

  • quality;
  • reliability;
  • evidence standards;
  • communication;
  • pricing;
  • project completion;
  • compliance with agreed specifications.

Successful completion of a pilot does not remove the need for continuing monitoring.

22. Procurement Risk

Procurement risks include:

  • overpayment;
  • conflicts;
  • poor-quality goods;
  • unreliable suppliers;
  • false quotations;
  • kickbacks;
  • inappropriate related-party transactions.

Material procurement should follow the Procurement and Purchasing Policy.

23. Project Delivery Risk

Projects may fail because of:

  • poor planning;
  • inaccurate cost estimates;
  • contractor failure;
  • insufficient monitoring;
  • environmental conditions;
  • delays;
  • changes in local circumstances;
  • unrealistic targets.

Project planning should identify significant delivery risks before substantial commitments are made.

24. Water Project Risk

Water installations may involve specific risks including:

  • unsuitable sites;
  • inadequate water assessment;
  • unsuccessful drilling or boring;
  • unsuitable water quality;
  • contractor failure;
  • inaccurate depth information;
  • maintenance failures;
  • unsafe installation.

Before material water-project work, the charity should obtain proportionate information concerning:

  • site conditions;
  • proposed installation type;
  • expected specification;
  • contractor pricing;
  • water/site assessment where appropriate.

25. Water Project Evidence

Completed water installations should normally have an appropriate evidence record containing:

  • Al-Waris Foundation project number;
  • location;
  • GPS/location information where safe and appropriate;
  • installation type;
  • depth/specification where applicable;
  • completion date;
  • photographs/video;
  • cost/invoice;
  • contractor information;
  • maintenance or warranty information;
  • Al-Waris Foundation project identification or plaque where appropriate.

This supports both accountability and future maintenance.

26. Food Distribution Risk

Food and essential-aid distributions may involve:

  • supplier quality;
  • food safety;
  • crowd management;
  • beneficiary dignity;
  • unfair selection;
  • duplication;
  • inaccurate quantities;
  • safeguarding;
  • financial control.

Distribution planning should be proportionate to the scale and environment.

27. Fundraising Risk

Fundraising risks may include:

  • misleading claims;
  • inappropriate pressure;
  • unauthorised collectors;
  • theft;
  • inaccurate donation allocation;
  • misuse of restricted funds;
  • data protection failures;
  • poor donor communications.

Fundraising activities should comply with the Fundraising Policy.

28. Public Collection Risk

Street and public collections may involve:

  • collector safety;
  • cash security;
  • licensing;
  • identification;
  • supervision;
  • reconciliation;
  • public conduct.

Appropriate permissions and controls should be established before collections take place.

29. Donation Processing Risk

Online donation systems may create risks involving:

  • payment failure;
  • fraud;
  • incorrect allocation;
  • duplicate payments;
  • account compromise;
  • refund errors;
  • inaccurate receipts.

Access to payment systems should be restricted to authorised persons.

30. Restricted Fund Risk

Restricted donations must be used according to their applicable restrictions.

Risks may arise from:

  • incorrect coding;
  • unclear fundraising wording;
  • transfers between funds;
  • operational misunderstanding;
  • insufficient records.

Donation-routing and accounting systems should preserve the intended designation.

31. Data Protection Risk

The charity processes personal information relating to people including:

  • donors;
  • volunteers;
  • beneficiaries;
  • complainants;
  • trustees;
  • supporters.

Risks include:

  • unauthorised access;
  • excessive collection;
  • inappropriate disclosure;
  • loss;
  • retention beyond necessity;
  • insecure transfers.

See the Data Protection and UK GDPR Policy.

32. Cybersecurity Risk

Digital systems may be exposed to:

  • phishing;
  • account compromise;
  • malware;
  • credential theft;
  • software vulnerabilities;
  • unauthorised administrator access;
  • data loss;
  • service disruption.

Appropriate controls should include, where relevant:

  • strong authentication;
  • MFA;
  • least-privilege access;
  • software updates;
  • backups;
  • secret management;
  • access reviews;
  • incident response.

33. Website Risk

The charity website is an important fundraising, communication and transparency platform.

Website risks may include:

  • downtime;
  • security vulnerabilities;
  • inaccurate content;
  • compromised administrator accounts;
  • broken donation journeys;
  • privacy failures;
  • misleading project information.

Material website functionality should be appropriately tested and monitored.

34. Artificial Intelligence Risk

Al-Waris Foundation may use artificial intelligence to support:

  • drafting;
  • design;
  • administration;
  • software development;
  • analysis.

AI outputs must not automatically be treated as verified facts.

Particular care is required where AI is used for:

  • public claims;
  • legal or regulatory information;
  • financial decisions;
  • beneficiary information;
  • project evidence.

AI-generated illustrative material must not be presented as genuine documentary evidence of charitable activity.

35. Email Risk

Email systems may be exposed to:

  • phishing;
  • impersonation;
  • misdirected information;
  • account compromise;
  • fraudulent payment instructions.

Unexpected payment or bank-detail changes should be independently verified where practicable.

36. Access-Control Risk

Access to charity systems should follow the principle of least privilege.

People should receive only the access reasonably necessary for their authorised role.

Trustee status alone does not require operational access to:

  • payment processors;
  • donor databases;
  • CMS administration;
  • hosting;
  • email administration;
  • beneficiary records.

Trustees must nevertheless receive sufficient information to exercise proper governance oversight.

37. Social Media Risk

Social-media risks may include:

  • unauthorised posts;
  • inaccurate information;
  • compromised accounts;
  • disclosure of confidential information;
  • inappropriate beneficiary content;
  • reputational damage.

Account access should be limited and appropriately secured.

38. Communications Risk

Public communications should not knowingly contain fabricated:

  • donation totals;
  • beneficiary numbers;
  • project outcomes;
  • impact statistics;
  • endorsements;
  • evidence.

Material factual claims should be capable of reasonable substantiation.

39. Reputational Risk

Reputational risk may arise from:

  • poor governance;
  • safeguarding failures;
  • misleading fundraising;
  • project failures;
  • fraud;
  • inappropriate conduct;
  • inaccurate public communications.

Reputation should be protected through good governance and appropriate conduct rather than by concealing genuine problems.

40. Regulatory Risk

The charity must consider risks arising from failure to comply with requirements relating to:

  • Charity Commission;
  • HMRC;
  • fundraising;
  • data protection;
  • safeguarding;
  • financial reporting;
  • employment where applicable;
  • health and safety;
  • sanctions;
  • other applicable obligations.

Regulatory deadlines should be tracked appropriately.

41. Legal Risk

Professional advice should be considered where a matter presents significant:

  • contractual;
  • property;
  • employment;
  • regulatory;
  • tax;
  • charity-law;
  • data-protection;

risk.

Trustees should recognise when specialist expertise is required.

42. Premises Risk

Where the charity occupies premises, risks may include:

  • health and safety;
  • utilities;
  • insurance;
  • lease obligations;
  • fire safety;
  • security;
  • property damage;
  • unauthorised access.

Responsibilities should be clearly understood.

43. Business Continuity

Al-Waris Foundation should maintain proportionate arrangements for continuing critical activities following disruption.

Critical functions may include:

  • access to charity funds;
  • donor administration;
  • website availability;
  • essential communications;
  • safeguarding reporting;
  • access to governance records.

44. Dependency Risk

The charity should identify important dependencies on:

  • individual people;
  • suppliers;
  • contractors;
  • platforms;
  • payment processors;
  • banks;
  • hosting providers;
  • software systems.

Where dependency is significant, reasonable contingency arrangements should be considered.

45. Key-Person Risk

Al-Waris Foundation should recognise where substantial organisational knowledge or operational control depends on one individual.

Controls may include:

  • documented procedures;
  • appropriate backups;
  • secure recovery arrangements;
  • succession planning;
  • governance oversight.

Controls should not require unnecessary sharing of sensitive credentials.

46. Risk Identification

Risks may be identified through:

  • trustee meetings;
  • project planning;
  • complaints;
  • incidents;
  • audits;
  • financial monitoring;
  • safeguarding concerns;
  • contractor reviews;
  • volunteer feedback;
  • regulatory changes;
  • system monitoring.

Risk identification is an ongoing process.

47. Risk Register

Al-Waris Foundation should maintain a proportionate risk register for significant organisational risks.

The register may include:

  • risk reference;
  • category;
  • description;
  • likelihood;
  • impact;
  • existing controls;
  • residual risk;
  • responsible person;
  • further action;
  • review date.

Routine low-level operational issues do not necessarily require individual entries.

48. Likelihood

Likelihood may be assessed using the following scale:

1 – Rare: Highly unlikely to occur.

2 – Unlikely: Could occur but is not expected.

3 – Possible: Could reasonably occur.

4 – Likely: Expected to occur in some circumstances.

5 – Almost Certain: Expected to occur frequently or imminently.

49. Impact

Impact may be assessed using the following scale:

1 – Insignificant: Minimal disruption or loss.

2 – Minor: Limited impact that can be managed routinely.

3 – Moderate: Noticeable operational, financial or reputational effect.

4 – Major: Significant harm, loss or disruption requiring senior intervention.

5 – Severe: Threatens beneficiaries, significant assets, regulatory standing or continued operation.

50. Risk Score

Where the charity uses numerical scoring:

Risk Score = Likelihood × Impact

This creates a score between 1 and 25.

The score is a decision-support tool.

It does not replace judgement.

A safeguarding or regulatory risk may require immediate action even where its calculated likelihood is relatively low.

51. Suggested Risk Bands

Risk scores may normally be interpreted as:

  • 1–4: Low
  • 5–9: Moderate
  • 10–15: High
  • 16–25: Very High

The Board may adjust treatment based on the nature of the risk.

52. Inherent Risk

Inherent risk is the level of risk before controls are taken into account.

Assessing inherent risk helps determine how important the control environment is.

53. Residual Risk

Residual risk is the level remaining after controls are considered.

The charity should focus primarily on whether residual risk is acceptable.

A control should not be assumed effective merely because it exists on paper.

54. Risk Treatment

A risk may be addressed by:

Avoiding

Stopping or not undertaking an activity where risk cannot reasonably be controlled.

Reducing

Introducing controls that reduce likelihood or impact.

Transferring

Using appropriate insurance or contractual arrangements.

Accepting

Proceeding where remaining risk is understood and considered proportionate.

55. Control Effectiveness

Controls should periodically be assessed to determine whether they actually operate as intended.

Evidence may include:

  • testing;
  • reconciliations;
  • audit logs;
  • project evidence;
  • incident history;
  • access reviews;
  • monitoring reports.

56. Escalation

Very high or otherwise significant risks should be escalated promptly to the Board or appropriate authorised decision-maker.

Urgent matters should not wait for the next scheduled trustee meeting.

57. New Activities

Before undertaking a significant new activity, the charity should consider:

  • charitable purpose;
  • financial exposure;
  • safeguarding;
  • regulatory requirements;
  • delivery capacity;
  • partner risk;
  • reputation;
  • operational sustainability.

A proportionate documented assessment should be used for materially higher-risk activities.

58. Major Projects

Material projects should consider risk during:

  • planning;
  • contractor selection;
  • implementation;
  • monitoring;
  • completion.

Risk management should continue throughout the project rather than being completed only at the beginning.

59. Decision Records

Significant risk decisions should be documented.

Records may explain:

  • risk identified;
  • options considered;
  • controls;
  • remaining risk;
  • decision;
  • person or Board approving it.

This helps demonstrate responsible trustee decision-making.

60. Incidents

Where a risk materialises, the charity should:

  1. protect people;
  1. contain the issue;
  1. protect charitable assets;
  1. preserve appropriate evidence;
  1. notify responsible persons;
  1. consider external reporting;
  1. investigate proportionately;
  1. implement corrective action;
  1. update the risk assessment.

61. Serious Incidents

Where an event may meet the threshold for Charity Commission serious incident reporting, it should be handled under the Serious Incident Reporting Policy.

Risk-management procedures must not delay required regulatory reporting.

62. Insurance

The charity should consider appropriate insurance according to its activities and risks.

Insurance does not replace appropriate controls.

The Board should periodically consider whether cover remains suitable.

63. Fraud Response

Where fraud is suspected:

  • further loss should be prevented where practicable;
  • records should be preserved;
  • relevant access may be restricted;
  • appropriate authorities should be considered;
  • recovery should be considered.

See the Anti-Fraud, Bribery and Corruption Policy.

64. Risk Reporting to Trustees

The Board should receive proportionate information concerning:

  • significant risks;
  • material changes;
  • control weaknesses;
  • incidents;
  • overdue actions.

Trustees do not need to manage every operational risk directly.

65. Review Frequency

The risk register should be reviewed:

  • periodically according to organisational need;
  • when a major new risk emerges;
  • following a significant incident;
  • before major new activities where appropriate.

Very high risks may require more frequent monitoring.

66. Confidentiality

Risk records may contain sensitive information.

Access should be appropriately restricted where records contain:

  • safeguarding information;
  • security weaknesses;
  • financial access information;
  • confidential partner information;
  • personal data.

Public transparency does not require publication of information that would itself create additional risk.

67. Records

Risk-management records should be retained in accordance with the Records Retention and Disposal Policy.

Records may include:

  • risk registers;
  • risk assessments;
  • Board decisions;
  • incident records;
  • mitigation plans;
  • review records.

68. Training

Relevant trustees and operational personnel should receive proportionate guidance on:

  • recognising risks;
  • escalation;
  • safeguarding;
  • financial controls;
  • fraud;
  • cybersecurity;
  • incident reporting.

69. Continuous Improvement

Risk management should develop as Al-Waris Foundation grows.

The charity should use:

  • incidents;
  • near misses;
  • complaints;
  • project outcomes;
  • audit findings;
  • regulatory guidance;

to improve its controls.

70. Related Al-Waris Foundation Policies

This policy should be read alongside:

  • Constitution;
  • Trustee Terms of Reference;
  • Serious Incident Reporting Policy;
  • Financial Controls and Reserves Policy;
  • Anti-Fraud, Bribery and Corruption Policy;
  • Sanctions and Terrorist Financing Policy;
  • Conflict of Interest Policy;
  • Safeguarding Children Policy;
  • Safeguarding Adults at Risk Policy;
  • Overseas Operations and Partner Due Diligence Policy;
  • Grant Making Policy;
  • Procurement and Purchasing Policy;
  • Fundraising Policy;
  • Data Protection and UK GDPR Policy;
  • Information Security and Cybersecurity Policy;
  • Records Retention and Disposal Policy;
  • Volunteer Policy;
  • Photography, Video and Beneficiary Consent Policy;
  • Social Media and Digital Communications Policy.

71. Review

This policy will be reviewed:

  • at least annually;
  • following a serious incident;
  • following a material change in the charity's activities;
  • following significant expansion of overseas operations;
  • where major control weaknesses are identified;
  • following significant regulatory or legal developments.

72. Approval

Version: 2.0 Status: Approved Approved by: Board of Trustees Approval date: 25/08/2026 Next scheduled review: 24/08/2027

Essential cookies keep secure account and donation features working. With your permission, Google Analytics helps us understand how public pages are used. It is not loaded unless you accept.

Read our cookie information