The Charity Commission's Charity Sector Risk Assessment 2026 offers more than an overview of the risks facing the charity sector. It provides a useful indication of the regulator's priorities and a clear signal of the governance standards that charities are increasingly expected to meet.
While fraud has always presented challenges for charities, the nature of that threat is evolving. Emerging technologies, increasingly sophisticated cybercrime, complex organisational structures and heightened regulatory expectations are creating new risks for trustees and charity leaders. The most significant message emerging from the Risk Assessment is not that fraud risks are increasing. It is that regulators now expect trustees to demonstrate active oversight of those risks. Fraud prevention is increasingly being treated as a governance obligation rather than an operational function delegated to finance or IT teams.
For charities, social housing providers and other not-for-profit organisations, this presents a challenge that goes beyond preventing financial loss. Organisations must be able to demonstrate that they have identified relevant risks, implemented appropriate controls and responded effectively when concerns arise.
A Changing Fraud Landscape
One of the most notable findings in the report is the continued increase in cases involving concerns that charitable status is being used for private benefit. The Charity Commission recorded a 38% increase in such cases during 2024-25, followed by a further 29% increase during 2025-26. Whilst such cases remain relatively limited in number, the potential consequences for charitable assets, beneficiaries and public confidence can be significant.
The report also highlights concerns regarding the use of voucher schemes, money service businesses and other less transparent financial arrangements that can reduce visibility of transactions and create opportunities for abuse.
Although these risks manifest in different ways, they point towards a common challenge: ensuring governance frameworks are capable of identifying and responding to increasingly sophisticated threats.
At Trowers & Hamlins, we are increasingly advising charities and not-for-profit organisations on governance structures, internal controls and risk management frameworks designed to identify vulnerabilities before they become regulatory issues. In our experience, fraud rarely results from a single failure. More commonly, it emerges where governance weaknesses, inadequate oversight and poor internal challenge combine to create an environment in which misconduct can occur undetected.
The Commission's findings are therefore a reminder that trustees should be looking beyond traditional financial controls and considering whether current governance arrangements remain fit for purpose.
AI-Enabled Fraud: A Growing Governance Challenge
The Charity Commission's reference to artificial intelligence is particularly noteworthy. Whilst AI presents clear opportunities for charities, including administrative efficiencies and improved accessibility, the Commission has specifically identified the use of AI in charity registration applications as a developing area of concern – the potential for bad actors to use emerging technologies when seeking charitable status or legitimacy.
However, the significance of this warning extends far beyond charity registration processes.
AI is making it easier to generate convincing communications, replicate authentic documentation and conduct sophisticated impersonation attempts. The result is that many of the traditional indicators of fraud are becoming increasingly difficult to identify. Fraudsters can now generate highly convincing invoices, supplier communications and payment requests, while developments in voice and image technology create new opportunities for impersonation and social engineering attacks.
The governance implications are significant. Trustees have traditionally been able to rely on verification processes that were designed for a very different risk environment. As AI-enabled fraud becomes more sophisticated, organisations may need to revisit existing approval procedures, due diligence requirements and financial authorisation processes to ensure they remain effective.
Many of the questions we are now seeing from boards are not about the technology itself, but about governance. How should information be verified? What controls should apply to high-risk transactions? Are existing approval processes sufficiently robust in circumstances where AI-generated content may be involved?
For many organisations, the answer will not be to introduce entirely new governance structures. Rather, it will be to ensure that existing frameworks are tested against emerging risks and adapted where necessary. The introduction of the "failure to prevent fraud" offence in September 2025 (addressed further below) emphasises the importance of tailored fraud risk assessment, both to be undertaken and kept under regular review to take account of emerging threats.
Cybercrime Is No Longer Just an IT Issue
The report highlights that 30% of charities had reported experiencing a cyber-attack during the previous year , with phishing identified as the most common and disruptive threat. The Charity Commission also notes an increase in ransomware attacks across the sector.
The immediate consequences of a cyber incident can be severe. Financial losses, compromised data, operational disruption and reputational damage are all well-established risks. However, the wider governance implications are equally important.
Following a cyber incident, regulators and stakeholders are increasingly concerned not only with what happened, but whether reasonable steps were taken to prevent it. Questions around board oversight, risk management and organisational preparedness are often just as important as the technical details of the attack itself, particularly when looking forward and considering lessons learned.
This reflects a broader shift in expectations. Cybersecurity is no longer viewed solely as an operational or IT issue. It is increasingly regarded as a core governance matter.
We are seeing trustees place greater emphasis on cyber resilience as part of wider governance and risk management discussions. In practice, this means ensuring that cyber risks are understood at board level, regularly reviewed and incorporated into organisational risk assessments alongside financial, operational and safeguarding risks.
Complex Fraud Investigations and Regulatory Scrutiny
The assessment also highlights a growing willingness by regulators and law enforcement agencies to scrutinise suspected fraud and misconduct within the sector.
The Charity Commission reports an increase in particularly complex casework involving allegations of significant fraud and made almost 500 disclosures to external agencies, including HMRC, local authorities and law enforcement bodies during 2025-26.
The report's discussion of supported housing is particularly significant. The Commission refers to ongoing inquiries involving extensive property portfolios, relationships between charities and commercial entities, and concerns that criminal activity may be involved. It has also engaged with both the Serious Fraud Office and local police forces in relation to these matters.
For organisations operating in regulated sectors, including housing and care, these findings reinforce an important lesson: governance issues rarely exist in isolation.
Concerns relating to conflicts of interest, related-party transactions, procurement processes or financial management can quickly become the subject of wider regulatory scrutiny. Even where no wrongdoing is ultimately established, investigations can be costly, time-consuming and highly disruptive.
The supported housing sector presents particular governance challenges because of the often-complex relationships between charities, registered providers, managing agents, property owners and public funding streams. Where organisations operate across multiple entities or rely on extensive outsourcing arrangements, transparency, oversight and the management of conflicts of interest become increasingly important. The Commission's focus on governance within such arrangements serves as a reminder that robust accountability and oversight remain essential, even where organisational structures have been developed for legitimate commercial or operational reasons.
As a firm with extensive experience advising both charities and registered providers, we frequently see the overlap between governance, regulation and disputes. Addressing concerns early, conducting appropriate internal investigations and understanding the Commission's approach to reporting can often make a significant difference to how matters unfold.
The Wider Regulatory Direction of Travel
The Charity Commission's assessment should also be viewed against the backdrop of wider developments in economic crime regulation.
The report specifically references measures introduced through the Economic Crime and Corporate Transparency Act 2023, and in particular, the introduction of the new "failure to prevent fraud" corporate criminal offence, highlighting additional responsibilities on larger charities to address fraud risks. For further information, please see our previous article: The Countdown is on: Failure to Prevent Fraud Offence will come into force on 1 September 2025.
Taken together with broader regulatory reforms, the direction of travel appears clear. Regulators increasingly expect organisations not only to react to fraud when it occurs but to demonstrate that they have actively considered relevant risks and implemented proportionate safeguards.
The focus is shifting from response to prevention.
This represents a significant challenge for trustees. It is no longer enough simply to have policies in place. Organisations should be able to show that those policies are understood, implemented, reviewed and tested against emerging risks.
These governance expectations are grounded in trustees' existing legal duties. Trustees are responsible for safeguarding charitable assets, acting in the charity's best interests and ensuring that risks are properly identified and managed. The Charity Commission's guidance has long emphasised the importance of protecting charities from financial crime and abuse. The 2026 Risk Assessment does not create new obligations, but it reinforces the expectation that trustees will take active and informed steps to address emerging fraud risks.
What Does This Mean for Trustees?
Perhaps the most important lesson from the Charity Commission's assessment is that fraud should not be viewed as a standalone compliance issue.
Instead, the risks identified throughout the report point towards a broader governance challenge. Trustees should consider the following, in fulfilling their duties in relation to protecting charitable assets and managing risk:
- whether governance arrangements have kept pace with technological change;
- whether internal controls remain proportionate to current risks;
- whether whistleblowing and reporting procedures are operating effectively;
- whether investigation and escalation protocols are clearly understood; and
- whether risk assessments adequately address cybercrime, AI-enabled fraud and other emerging threats.
The organisations best placed to prevent and respond to fraud are often those that embed fraud prevention within their wider governance framework rather than treating it as a separate compliance exercise.
Looking Ahead
The Charity Commission's 2026 Risk Assessment is ultimately about more than fraud statistics. It provides a clear insight into the regulator's evolving expectations and reinforces the importance of proactive governance in an increasingly complex risk environment.
As financial crime risks continue to evolve, organisations must ensure that their governance arrangements evolve with them. The challenge is no longer simply preventing fraud. It is demonstrating that governance frameworks are sufficiently robust to withstand increasing scrutiny while protecting charitable assets, maintaining public trust and enabling organisations to continue delivering their charitable objectives. If you or your organisation would like advice on strengthening governance arrangements and mitigating the risks discussed in this article, please contact Emily Sharples.