Eight questions that every trustee of a charity handling money from donations and fundraising activities needs to ask and the nine operational activities that they should review.
Last year, we looked at how anti-money laundering rules affect UK charities. Trustees need to understand who their charity is receiving money from, where those funds have come from, and where they ultimately go.
It clearly struck a chord. The article became one of our most-read pieces. Perhaps because financial crime can feel like something that happens to banks and multinational businesses rather than charities.
The warning signs haven’t disappeared. Unusually large donations, unexplained overseas funds, donors unwilling to provide information, unusual conditions attached to gifts or requests to move money quickly should still prompt further questions. Charities also need to think carefully about what they do with the information those checks uncover.
But identifying a potential problem is now only part of the challenge. Charities are attractive precisely because they are trusted.
And a year on, the picture has become more complicated.
The rules around fraud have become tougher, with organisations facing greater responsibility for the actions of their senior people. Many charities are also carrying out increasingly sophisticated checks on donors, funders, partners and other organisations.
That is sensible. But there is another question that is much easier to overlook.
What happens to all the information charities collect while carrying out financial and regulatory checks?
Because the moment your charity searches a donor against a sanctions list, investigates adverse media, records concerns about the source of a donation or assesses whether an individual poses a financial crime risk. You have moved into another important area of compliance – data protection.
Financial crime prevention and data protection can no longer be treated as two separate issues.
Fraud prevention is becoming a governance issue in charities
On 1 September 2025, the new corporate offence of failure to prevent fraud came into force under the Economic Crime and Corporate Transparency Act 2023.
It applies to large organisations, including incorporated charities, where they meet at least two of three tests. These are:
- More than 250 employees
- Turnover above £36 million
- More than £18 million in total assets.
An organisation could be held criminally responsible if someone acting for it commits fraud and it did not have proper measures in place to prevent it. Management does not have to have known about the fraud.
While many charities fall below those thresholds, it does not mean smaller organisations can simply disregard the wider direction of travel.
Since June 2026, the law has gone further, making it easier to hold an organisation responsible for crimes committed by senior managers acting on its behalf. This replaces the narrower rules that previously focused mainly on economic crime.
What that means is that for every charity, irrespective of size, the Charity Commission has long expected trustees to understand their donors, beneficiaries and partners and to carry out appropriate, proportionate due diligence.
The message is therefore not that every small charity suddenly needs a substantial compliance department. It’s more about good financial crime controls being increasingly part of good governance.
Charity financial crime and data protection example: When “Know Your Donor” becomes “Know Your Data”
Suppose a donor offers your charity £25,000.
Before accepting it, somebody carries out an internet search, checks sanctions information and looks for adverse media. They discover an old article suggesting that somebody with the same name was investigated for fraud.
The donation is declined, and someone writes a note in the CRM – “Possible proceeds of crime concerns, donation declined.”
From a financial crime perspective, your charity may believe it has behaved responsibly.
From a data protection perspective, however, you have just created something potentially much more sensitive.
The ICO makes clear that criminal offence data does not only mean convictions. It can include information about suspected offenders, allegations, investigations and even unproven allegations.
That means your charity needs to consider not merely whether carrying out the check was sensible. Here are the 8 questions that you should ask:
- Why are we processing this information?
What is our Article 6 lawful basis? Under the Data (Use and Access) Act 2025, the new Recognised Legitimate Interest basis may apply where processing is genuinely necessary to prevent, detect or investigate crime, including fraud or money laundering.
Where criminal offence data is involved, you will still need an appropriate condition under Schedule 1 of the Data Protection Act 2018.
- Do we need an Appropriate Policy Document? For several conditions particularly relevant to fraud, unlawful acts and money laundering, the Data Protection Act (DPA) 2018 requires one. It records the condition being relied upon, how the data protection principles will be met and the charity’s approach to retention and deletion.
- Is the information accurate? An adverse media result is not proof. Common names, outdated reports and incorrect matches can turn sensible due diligence into an unfair decision about the wrong person.
- How much information do we really need to keep? There is rarely a good reason to retain an entire investigation indefinitely when what the charity may need is an appropriate record of the decision and why it was made.
- What have we told people? Your donor privacy information should reflect the checks you genuinely carry out and the purposes for which personal information is used.
- Could the individual ask to see it? Yes. A donor can make a Subject Access Request for the personal information you hold about them. Organisations only need to carry out reasonable and proportionate searches. There are exemptions where disclosure would be likely to prejudice the prevention or detection of crime, but these are not blanket exemptions and must be considered case by case.
- Is technology or AI involved? Automated screening tools can save considerable time but can also magnify false matches, bias and poor-quality information. High-risk processing may require a Data Protection Impact Assessment. If a system is making significant decisions without meaningful human involvement, additional safeguards apply, including giving people the ability to challenge the decision and obtain human intervention.
- What happens if someone complains about the way their information has been used? Organisations must now have a process for handling data protection complaints and respond to them appropriately.
The important point is that doing more due diligence is not automatically the same as doing better due diligence. It needs to be targeted, proportionate and properly governed. Financial crime is not just a finance-team problem.
One of the easiest mistakes is to give this problem to the finance director, compliance officer or fundraising manager and assume it has been dealt with.
In reality, it cuts across almost every part of a charity.
So how does financial management and data protection impact a charity?
Governance matters because trustees need oversight of the risks the charity is prepared to accept, the controls in place and the circumstances in which donations or partnerships should be refused. An independent governance review can help test whether written policies translate into effective board oversight.
Eastside People, for example, can benchmark governance practice and help boards turn findings into practical improvement plans.
Strategy and risk cannot be separated from the direction in which an organisation wants to grow. Moving into a new country, building a corporate fundraising programme, creating commercial income or substantially increasing grant funding can all alter the organisation’s financial crime and information risks.
Strategy should therefore consider risk at the beginning rather than attaching compliance after decisions have already been made.
Income generation and fundraising are particularly important. Growth requires charities to find new donors, funders, contracts and sources of earned income. But diversification also changes the people and organisations with whom the charity does business.
Reviewing and risk-assessing current and future income sources should be part of a sustainable fundraising strategy rather than a barrier to one.
Digital and data protection increasingly underpin the whole process. CRMs, donor platforms, screening services and cloud applications all hold information that can become highly sensitive.
Eastside People’s digital consultancy includes data protection and GDPR audits, training, Data Protection Office (DPO) support, supplier agreements and ongoing advice. Exactly the kind of joined-up approach needed when financial due diligence creates personal data.
Artificial intelligence adds another dimension. AI can help analyse information, identify anomalies, and improve efficiency, but charities need appropriate policies, governance, and human oversight before using it to inform decisions about donors, beneficiaries, or partners.
Eastside People’s AI consultancy specifically approaches adoption through organisational objectives, risk, governance and responsible implementation rather than technology for technology’s sake.
Workforce and culture matter because controls ultimately depend on people. Staff and volunteers need to recognise warning signs, know when to escalate concerns and feel comfortable challenging a transaction. Even when the prospective donation is financially attractive.
Clear responsibilities, training and an open culture are often more effective than another policy sitting unread on the shared drive.
An issue that extends beyond donors
When considering a merger or strategic partnership, due diligence needs to examine financial, governance, management and organisational risks before boards make major commitments. Eastside People already provides formal due diligence and feasibility support for charities considering mergers and partnerships.
Similarly, charities seeking social investment or property finance may themselves go through extensive due diligence and need to demonstrate strong governance, financial planning and reliable information. Eastside People supports charities with investment readiness, financial modelling, investor relationships and due diligence.
Even impact measurement and ESG belong in the conversation. Increasing scrutiny from funders, commissioners and stakeholders means charities need to demonstrate not only what difference their money has achieved but how responsibly the organisation is governed. Good evidence, good data and good governance increasingly work together.
What would happen if somebody asked, “show me your protection processes”?
That may be the most useful test of all.
Imagine a trustee, major funder, auditor, the Charity Commission or the ICO asked your organisation tomorrow:
“Show us how you decide which donors and partners you check, what information you collect, who makes the decision, where you record it and when you delete it.”
Could you answer these five questions on where the money came from and how it was managed once you received it?
- Could you explain why one £10,000 donation was accepted, and another was rejected?
- Could you show that the person carrying out the check understood the difference between suspicion and fact?
- Could you demonstrate that somebody reviewed a potential false match?
- Could you show that your privacy notice, retention schedule and internal procedures reflect what happens in practice?
- And could your trustees explain how they know the system is working?
If the answer to several of those questions is “not really”, the solution is not necessarily more paperwork. It is better-connected governance. Start with the risk, not the policy
Nine areas of operation to review for financial risk in your charity or not-for-profit. A practical starting point is to look at the organisation’s operations:
- Where does money come from?
- Where does it go?
- Which countries do you operate in?
- Who can approve transactions?
- Which donors or partners are screened?
- What technology is being used?
- What personal information is being created?
- Who can see it?
- And how long does it remain on your systems?
Only once those questions are understood should the organisation decide what policies, processes, technology, training and controls it needs.
That is where the connection between Eastside People’s different areas of expertise becomes particularly valuable. Financial crime risk rarely arrives neatly labelled as a “compliance project”. It may emerge through a new fundraising strategy, a merger, an AI project, a change in leadership, new social investment, a digital transformation or a governance review.
Looking at those issues together can produce something far more valuable than compliance for compliance’s sake. An organisation that understands its risks, protects its reputation and can pursue opportunities with greater assurance.
Know who and what you’re dealing with
Charities depend on trust.
- The public needs to trust that funds will be used for the right purposes.
- Donors need to trust charities with their information.
- Funders need to trust the organisation’s governance.
- Trustees need to trust the systems and people managing the charity’s resources.
Effective due diligence protects all four audiences.
So “Know Your Donor” should no longer be the end of the conversation. It should be the beginning.
Identify your risk, protect your charity
If your organisation would benefit from an independent look at its governance, strategy, fundraising, digital and data protection arrangements or wider organisational risks. Eastside People can bring together the specialist expertise needed to turn those risks into practical, proportionate action.
If you have one of these challenges, we can help. Get in touch today to have a chat.
Blog written by data protection specialist Simon Hinks.