1. Policy Statement
Al-Waris Foundation is committed to identifying, managing, recording and reporting serious incidents appropriately.
The Board of Trustees has ultimate responsibility for ensuring that significant incidents affecting the charity are:
- recognised;
- escalated appropriately;
- managed promptly;
- documented;
- reported to the appropriate authorities where required;
- reviewed so that lessons can be learned.
The charity will follow applicable Charity Commission guidance when determining whether an incident should be reported.
Potential reputational consequences must not prevent appropriate reporting.
2. Purpose
This policy establishes the charity's framework for:
- identifying potential serious incidents;
- escalating concerns internally;
- protecting beneficiaries and charitable assets;
- determining whether external reporting is required;
- making Charity Commission reports where appropriate;
- coordinating reports to other authorities;
- documenting decisions;
- implementing corrective action;
- learning from incidents.
3. Scope
This policy applies to incidents connected with:
- trustees;
- staff where applicable;
- volunteers;
- beneficiaries;
- donors;
- contractors;
- suppliers;
- delivery partners;
- overseas partners;
- charitable projects;
- fundraising;
- finances;
- premises;
- information systems;
- personal data;
- governance;
- other activities undertaken on behalf of Al-Waris Foundation.
It applies to incidents occurring in the United Kingdom, overseas or online.
4. What Is a Serious Incident?
A serious incident is an adverse event, whether actual or alleged, that results in or creates a significant risk of:
- harm to people who come into contact with the charity through its work;
- loss of the charity's money or assets;
- damage to the charity's property;
- damage to the charity's work;
- significant harm to the charity's reputation.
Whether an incident is sufficiently serious to require reporting depends on its circumstances.
Not every mistake, complaint, financial discrepancy or operational problem will constitute a reportable serious incident.
5. Categories of Serious Incident
Potential serious incidents may include matters relating to:
- safeguarding;
- fraud;
- theft;
- financial loss;
- misuse of charitable assets;
- money laundering;
- bribery or corruption;
- terrorist financing;
- sanctions;
- criminal allegations;
- significant governance failures;
- serious conflicts of interest;
- significant data protection breaches;
- major cybersecurity incidents;
- significant fundraising misconduct;
- major operational disruption;
- overseas partners;
- significant reputational events.
This list is not exhaustive.
6. Safeguarding Incidents
A safeguarding matter may constitute a serious incident where it significantly affects:
- beneficiaries;
- volunteers;
- staff;
- others who come into contact with the charity through its work.
Safeguarding action must take priority over administrative reporting.
Where immediate safeguarding action is required, the charity should act first to protect the person concerned and then complete appropriate regulatory reporting.
See:
- Safeguarding Children Policy;
- Safeguarding Adults at Risk Policy.
7. Financial Loss
Significant actual or suspected financial loss may require serious incident consideration.
Examples may involve:
- theft;
- fraud;
- misappropriation;
- significant unauthorised payments;
- loss of charitable assets;
- material banking fraud;
- significant diversion of project funds.
The significance of a loss should be assessed in the context of Al-Waris Foundation's:
- income;
- assets;
- financial position;
- ability to continue its work.
A relatively small monetary loss may still be significant where it indicates serious dishonesty, systemic weakness or wider risk.
8. Fraud
Suspected or confirmed significant fraud should be escalated promptly.
The charity should consider:
- securing accounts and systems;
- preserving records;
- preventing further loss;
- suspending affected payment authority where appropriate;
- obtaining professional advice;
- reporting to relevant authorities;
- recovering charitable funds.
See the Anti-Fraud, Bribery and Corruption Policy.
9. Misuse of Charitable Funds
Potential serious incidents may arise where charitable resources are deliberately used for purposes inconsistent with:
- the charity's objects;
- donor restrictions;
- grant conditions;
- lawful trustee decisions.
Particular attention should be given to suspected deliberate diversion of restricted funds.
10. Bribery and Corruption
Significant suspected:
- bribery;
- corruption;
- kickbacks;
- improper payments;
must be escalated appropriately.
This applies equally to activities undertaken:
- in the UK;
- overseas;
- through contractors;
- through partner organisations.
11. Money Laundering
Potential money laundering concerns should be escalated promptly.
The charity must not knowingly permit its:
- bank accounts;
- fundraising systems;
- payment systems;
- projects;
- partners;
to be used to disguise or facilitate unlawful financial activity.
Professional or regulatory advice should be obtained where necessary.
12. Terrorist Financing
Any credible concern that charitable resources may have been diverted to terrorist purposes must be treated seriously.
The charity should consider:
- stopping relevant payments where lawful and appropriate;
- preserving evidence;
- sanctions implications;
- professional advice;
- reporting obligations.
See the Sanctions and Terrorist Financing Policy.
13. Sanctions
A suspected material breach of applicable UK financial sanctions must be escalated.
Relevant transactions should not proceed where the charity has identified an unresolved sanctions concern.
The appropriate government or regulatory reporting requirements should be considered.
14. Governance Failures
A significant governance failure may constitute a serious incident.
Examples may include:
- trustees becoming unable to govern effectively;
- serious unmanaged conflicts;
- significant unauthorised trustee benefit;
- deliberate regulatory deception;
- sustained failure of important financial controls;
- serious misconduct by trustees;
- significant constitutional breaches.
Minor procedural errors will not automatically constitute serious incidents.
15. Conflicts of Interest
A conflict of interest may become a serious incident where it results in or creates significant risk of:
- financial loss;
- unauthorised benefit;
- improper decision-making;
- serious governance failure.
See the Conflict of Interest Policy.
16. Criminal Allegations
Significant criminal allegations connected with the charity should be assessed for serious incident reporting.
An allegation does not automatically establish that an offence occurred.
The charity should distinguish appropriately between:
- allegations;
- evidence;
- established facts.
Police or another competent authority may need to be contacted independently of Charity Commission reporting.
17. Data Protection Incidents
A significant personal-data breach may also constitute a serious incident.
The charity should separately assess:
- whether the Information Commissioner's Office must be notified;
- whether affected individuals must be informed;
- whether Charity Commission reporting is appropriate.
See the Data Protection and UK GDPR Policy.
18. Cybersecurity Incidents
A significant cybersecurity incident may require serious incident consideration where it materially affects:
- charitable funds;
- personal information;
- donor information;
- operational systems;
- website availability;
- payment systems;
- confidential information;
- the charity's ability to operate.
Examples may include significant compromise of:
- administrator accounts;
- email accounts;
- hosting;
- databases;
- payment infrastructure.
See the Information Security and Cybersecurity Policy.
19. Fundraising Incidents
Significant fundraising misconduct may require serious incident consideration.
This may include substantial concerns involving:
- misleading fundraising;
- unauthorised fundraising;
- misuse of collections;
- significant donor deception;
- serious misconduct by fundraisers;
- material loss of fundraising income.
Ordinary fundraising complaints should normally be handled under the Complaints Policy unless their seriousness requires escalation.
20. Overseas Operations
Incidents involving overseas operations must be assessed under the same principles as UK incidents.
Relevant matters may involve:
- project partners;
- contractors;
- financial transfers;
- project delivery;
- safeguarding;
- fraud;
- sanctions;
- security;
- diversion of charitable resources.
Distance from the UK does not reduce the trustees' responsibility for appropriate oversight.
21. Overseas Partner Incidents
Where an incident occurs within a partner organisation, Al-Waris Foundation should determine whether the incident materially affects:
- Al-Waris Foundation funds;
- Al-Waris Foundation beneficiaries;
- projects funded by the charity;
- the charity's reputation;
- the charity's regulatory responsibilities.
The fact that the incident occurred within a separate organisation does not automatically remove Al-Waris Foundation's reporting responsibilities.
22. Project Evidence
Suspected deliberate falsification of significant project evidence should be escalated.
This may include false:
- invoices;
- receipts;
- project completion records;
- beneficiary records;
- photographs;
- videos;
- distribution records;
- location information.
The seriousness should be assessed according to:
- scale;
- intent;
- financial value;
- effect on donors;
- whether the issue appears systemic.
23. AI-Generated Evidence
AI-generated or manipulated material must not be knowingly represented as genuine documentary evidence of completed charitable work.
A significant incident involving deliberate use of fabricated material to mislead:
- donors;
- trustees;
- regulators;
- auditors;
should be considered under this policy.
Legitimate illustrative content that is clearly presented as illustrative is distinct from false project evidence.
24. Significant Reputational Events
Reputational damage alone does not automatically make something a serious incident.
However, a matter may require reporting where it significantly affects:
- public trust;
- donor confidence;
- relationships with beneficiaries;
- ability to operate;
- regulatory confidence.
The underlying conduct should be assessed rather than relying solely on media attention.
25. Operational Disruption
A major operational event may require serious incident consideration where the charity becomes significantly unable to:
- provide important charitable services;
- access essential funds;
- operate critical systems;
- meet major obligations.
Minor or temporary technical problems would not normally meet this threshold.
26. Reporting Concerns Internally
Anyone involved with Al-Waris Foundation who becomes aware of a potential serious incident should report it promptly to an appropriate authorised person.
Depending on the matter, this may include:
- the Chair;
- another trustee;
- Designated Safeguarding Lead;
- another authorised officer.
A person should not wait until every fact has been established before raising a credible significant concern.
27. Concerns Involving the Chair
Where the potential serious incident concerns:
- the Chair;
- a conflict involving the Chair;
- actions authorised personally by the Chair;
the matter should be escalated directly to another unconflicted trustee.
The Chair must not control the assessment of whether their own alleged conduct constitutes a reportable serious incident.
28. Concerns Involving Another Trustee
Where an incident involves another trustee, the matter should be considered by unconflicted trustees.
The trustee concerned should not determine:
- whether the incident is reportable;
- the content of the report;
- the final response;
where this would create an inappropriate conflict.
29. Board-Wide Governance Concerns
Where the incident concerns most or all trustees, independent advice should be considered.
Direct regulatory reporting may be appropriate where effective internal escalation is not possible.
30. Immediate Priorities
When an incident occurs, the first priorities should be proportionate to the circumstances.
These may include:
- protecting people;
- preventing further loss;
- securing charitable assets;
- securing systems;
- preserving relevant records;
- notifying appropriate authorities;
- establishing essential facts;
- managing ongoing risk.
Regulatory reporting should follow without unnecessary delay where required.
31. Incident Record
Potential serious incidents should be appropriately documented.
The record may include:
- date identified;
- description;
- people or organisations involved;
- financial value where applicable;
- immediate action;
- current risk;
- external authorities contacted;
- reporting decision;
- reasons for that decision;
- corrective actions.
32. Serious Incident Register
Al-Waris Foundation should maintain a restricted serious incident register.
The register may record:
- internal reference;
- date;
- incident category;
- status;
- responsible person;
- Charity Commission reporting status;
- other regulatory reporting;
- closure date.
Access should be restricted appropriately.
33. Initial Assessment
A potential incident should be assessed promptly.
The assessment should consider:
- seriousness;
- scale;
- people affected;
- financial impact;
- safeguarding implications;
- legal obligations;
- regulatory implications;
- reputational impact;
- ongoing risk;
- likelihood of recurrence.
34. Do Not Wait for Complete Certainty
The charity should not automatically wait until an internal investigation is complete before considering regulatory reporting.
Where a report is required, it may be appropriate to:
- report known information;
- explain that investigation is ongoing;
- provide further information later if necessary.
35. Reporting to the Charity Commission
Where an incident meets the relevant reporting threshold, Al-Waris Foundation should make a serious incident report to the Charity Commission.
The charity should use the Commission's current reporting process and guidance.
The report should be:
- accurate;
- factual;
- proportionate;
- sufficiently detailed;
- clear about what remains under investigation.
36. Who Makes the Report?
Responsibility for submitting a report may be delegated to an appropriate person.
However, the trustees remain responsible for ensuring the report is made.
Where appropriate, the report should make clear that the trustees are aware of the incident and are managing it.
37. Information in a Report
Depending on the incident, a report may explain:
- what happened;
- when it happened;
- how the charity became aware;
- people or assets affected;
- financial value;
- immediate action taken;
- external authorities involved;
- current risks;
- investigation status;
- corrective measures;
- trustee oversight.
Only information necessary for the regulatory purpose should be included.
38. Accuracy
Reports must distinguish between:
- confirmed facts;
- allegations;
- estimates;
- matters still under investigation.
Al-Waris Foundation must not knowingly provide misleading information to a regulator.
39. Updates
Where a material development occurs after the original report, the charity should consider whether the Charity Commission should receive an update.
This may include:
- materially increased loss;
- significant investigation findings;
- additional regulatory action;
- resolution;
- significant corrective action.
40. Other Authorities
A Charity Commission report does not replace reports that may need to be made to another authority.
Depending on the incident, relevant bodies may include:
- police;
- Action Fraud;
- Information Commissioner's Office;
- local authority safeguarding services;
- HMRC;
- financial institutions;
- insurers;
- other competent authorities.
41. Police
Where appropriate, suspected criminal activity should be reported to the police or another appropriate law-enforcement route.
Immediate emergencies should be handled through the appropriate emergency services.
42. Action Fraud
Fraud and cybercrime matters may require reporting through the appropriate UK fraud-reporting arrangements.
Current official reporting routes should be checked at the time of the incident.
43. Information Commissioner's Office
Where an incident constitutes a reportable personal-data breach, the charity should follow the applicable ICO reporting requirements.
The decision should be documented.
44. Safeguarding Authorities
Where appropriate, safeguarding incidents may need to be referred to:
- local authorities;
- police;
- other safeguarding bodies.
Charity Commission reporting does not replace safeguarding referrals.
45. Professional Advice
The charity should seek professional advice where reasonably necessary.
This may include:
- legal advice;
- accounting advice;
- safeguarding advice;
- cybersecurity advice;
- insurance advice;
- regulatory advice.
Seeking advice must not create unnecessary delay where immediate protective action is required.
46. Confidentiality
Serious incident information must be handled confidentially.
Access should be limited according to legitimate need.
The charity should avoid unnecessary disclosure of:
- beneficiary identities;
- safeguarding information;
- whistleblower identities;
- personal data;
- legally privileged material.
47. Data Protection
Personal information processed during serious incident management must be handled in accordance with:
- UK GDPR;
- Data Protection Act 2018;
- Data Protection and UK GDPR Policy.
Regulatory reporting does not justify unnecessary disclosure of personal information.
48. Communications
Where an incident may become public, communications should be:
- factual;
- accurate;
- authorised;
- respectful;
- consistent with confidentiality and safeguarding requirements.
The charity should not:
- speculate;
- conceal established facts dishonestly;
- identify protected beneficiaries unnecessarily;
- make unsupported claims.
49. Donor Communications
Where an incident materially affects a particular appeal or restricted fund, the charity should consider whether donors require appropriate information.
Any communication should distinguish between:
- confirmed information;
- investigation;
- corrective action.
50. Corrective Action
Following an incident, corrective action may include:
- strengthening financial controls;
- recovering funds;
- changing access permissions;
- changing contractors;
- suspending a partner;
- improving due diligence;
- improving safeguarding;
- improving cybersecurity;
- providing training;
- revising policies;
- changing operational procedures;
- correcting inaccurate public information.
51. Recovery of Funds
Where charitable funds have been improperly lost or diverted, the trustees should consider reasonable recovery action.
Factors may include:
- amount;
- likelihood of recovery;
- legal position;
- cost;
- evidence;
- charity's best interests.
52. Partner Suspension
Where a serious incident concerns a delivery partner or contractor, Al-Waris Foundation may:
- suspend payments;
- suspend new work;
- request additional evidence;
- conduct further due diligence;
- require corrective action;
- terminate the relationship.
Decisions should be proportionate to the identified risk.
53. Lessons Learned
After a significant incident has been stabilised, the charity should consider:
- what happened;
- why it happened;
- whether controls failed;
- whether warning signs were missed;
- whether policies were followed;
- what should change;
- whether similar risks exist elsewhere.
Lessons should lead to practical improvements where appropriate.
54. Post-Incident Review
A formal post-incident review should be considered for significant incidents.
The review may examine:
- governance;
- systems;
- safeguarding;
- financial controls;
- access controls;
- partner management;
- communications;
- regulatory response.
55. Board Oversight
The Board should receive sufficient information to oversee significant incidents.
Where confidentiality requires it, information may be:
- anonymised;
- summarised;
- restricted to unconflicted trustees.
The Board should monitor significant corrective actions until appropriately completed.
56. Serious Incident Reporting in Annual Reporting
Where applicable, trustees should ensure statutory reporting accurately reflects relevant matters and regulatory disclosures.
The charity should not knowingly make statements inconsistent with serious incident information already reported to regulators.
57. Whistleblowing
A serious incident may first become known through whistleblowing.
Whistleblowers should be protected in accordance with the Whistleblowing Policy.
A whistleblowing concern must not be ignored merely because the person reporting it wishes to remain anonymous.
58. Complaints
A complaint may reveal a serious incident.
Where this occurs:
- immediate risk should be addressed;
- serious incident assessment should begin;
- the complaint should continue to be managed appropriately.
The existence of a complaints process must not delay necessary regulatory action.
59. Record Retention
Serious incident records should be retained in accordance with the Records Retention and Disposal Policy.
Retention should reflect:
- legal obligations;
- safeguarding considerations;
- financial requirements;
- regulatory requirements;
- continuing risk.
Records should be securely destroyed when their justified retention period expires.
60. Training and Awareness
Trustees and relevant operational personnel should understand:
- what may constitute a serious incident;
- how to escalate concerns;
- safeguarding escalation;
- financial incident escalation;
- that reporting should not be delayed merely to avoid reputational consequences.
61. No Retaliation
A person must not be subjected to inappropriate retaliation for genuinely reporting a potential serious incident.
Concerns about retaliation should be handled under the Whistleblowing Policy where appropriate.
62. Failure to Report Internally
Deliberately concealing a significant incident may result in appropriate:
- governance action;
- disciplinary action where applicable;
- removal of delegated authority;
- regulatory consideration.
This does not apply to a person who reasonably uses an appropriate external whistleblowing or regulatory route instead.
63. Policy Ownership
The Board of Trustees owns this policy.
Operational responsibilities may be delegated, but the Board remains responsible for ensuring that appropriate serious incident arrangements are maintained.
64. Related Al-Waris Foundation Policies
This policy should be read alongside:
- Constitution;
- Trustee Terms of Reference;
- Trustee Code of Conduct;
- Safeguarding Children Policy;
- Safeguarding Adults at Risk Policy;
- Whistleblowing Policy;
- Complaints Policy;
- Anti-Fraud, Bribery and Corruption Policy;
- Sanctions and Terrorist Financing Policy;
- Financial Controls and Reserves Policy;
- Conflict of Interest Policy;
- Risk Management Policy;
- Data Protection and UK GDPR Policy;
- Information Security and Cybersecurity Policy;
- Confidentiality Policy;
- Overseas Operations and Partner Due Diligence Policy;
- Grant Making Policy;
- Fundraising Policy;
- Records Retention and Disposal Policy.
65. Review
This policy will be reviewed:
- at least annually;
- following a serious incident;
- following significant regulatory feedback;
- where an incident identifies weaknesses in the policy;
- following material changes to Al-Waris Foundation's activities;
- following relevant changes to Charity Commission guidance or applicable law.
66. Approval
Version: 2.0 Status: Approved Approved by: Board of Trustees Approval date: 25/08/2026 Next scheduled review: 24/08/2027
