A nonprofit organization may have a noble mission, a dedicated team, and programs with a clear impact, yet still remain exposed to one of the most serious types of institutional risk: someone being harmed while engaging with the organization, because of one of its activities, or as a result of weaknesses in its systems and procedures.

That is why safeguarding beneficiaries, staff, and volunteers is no longer a peripheral operational matter. It has become an integral part of governance, risk management, and institutional responsibility.

The question the board should ask is not merely: Do we have a safeguarding policy?

It is: Can our institutional system prevent harm, detect it early, and deal with it clearly and responsibly if it occurs?

Safeguarding Starts with the Board

Guidance from the Charity Commission for England and Wales confirms that safeguarding people should be a governance priority for charities, and that trustees must take reasonable steps to protect everyone who engages with the organization from harm, whether the work is conducted in person or through digital means.

This is not limited to beneficiaries.

The scope of safeguarding includes employees, volunteers, beneficiaries, and others who communicate with the organization or participate in its programs and activities.

This is where the difference emerges between an organization that views safeguarding as an administrative document and one that treats it as part of its institutional culture.

Having a policy is important, but its real value begins when everyone knows how to apply it, whom to approach when a problem arises, and what happens after it is reported.

Risks Are Broader Than We Imagine

When the word “safeguarding” is mentioned, people may immediately think of physical abuse or child protection, while the reality is much broader.

Risks may include harassment or exploitation, bullying, abuse of power and trust, neglect, discrimination, health and safety risks, personal data breaches, violence, sexual exploitation, human trafficking, extremism, and other forms of harm.

Sometimes the source of the risk may be the organization’s own culture.

When accountability is absent, one person dominates decision-making, or employees and volunteers feel that reporting mistakes could harm them, silence itself becomes a risk factor.

Building a safe environment therefore does not mean simply adding another form to the administrative files. It means creating a culture in which people can discuss concerns without fear and trust that what they raise will be taken seriously.

A Policy That Is Not Implemented Protects No One

Effective safeguarding policies should be living documents that evolve as the organization changes.

They need to be reviewed regularly and reassessed after serious incidents, as well as whenever the organization’s way of working, the groups it serves, or the areas in which it operates changes.

A good policy should clearly answer several fundamental questions:

How does the organization prevent harm before it occurs?

How can a person express their concerns?

How are reports received and documented?

Who is responsible for making decisions?

When should a case be escalated to a specialist authority?

How does the organization maintain confidentiality without allowing it to become a pretext for concealing problems?

The clearer these answers are, the less room there is for arbitrary judgment when a crisis occurs.

A Code of Conduct Is Part of the Safeguarding System

Having a clear code of conduct for staff and volunteers is not a merely formal measure.

The code defines the type of culture the organization wants to build, the behavior expected of its people, and the boundaries that must not be crossed.

It is important for this code to be linked to other policies, such as those addressing bullying and harassment, whistleblowing, complaints, health and safety, disciplinary procedures, data protection, and digital safety.

When these policies operate as an interconnected system, safeguarding shifts from incident response to a comprehensive preventive system.

Selecting People Is Part of Risk Management

A common mistake is to treat recruitment and safeguarding as separate matters.

The truth is that selecting the right person for a role represents one of the first lines of defense against risk.

British guidance highlights the importance of verifying the suitability of trustees, employees, and volunteers for the roles they undertake, using legally available methods such as reference checks, examination of gaps in employment history, interviews, and appropriate statutory checks based on the nature of the role.

In the United Kingdom, for example, criminal record checks are conducted through the Disclosure and Barring Service, commonly abbreviated as DBS, for certain jobs and roles.

This does not mean applying this procedure literally in every country, but rather drawing on the same principle: the more sensitive the role, or the greater its contact with groups most exposed to risk, the greater the need for verification procedures proportionate to the level of risk and compliant with applicable local regulations.

Children and Adults at Greater Risk Need Additional Protection

The responsibility increases when an organization works with children or people who may have care or support needs that make them more vulnerable to exploitation or neglect.

In these cases, a general policy is not enough.

The organization needs specialized procedures, regular training for staff and volunteers, a clearly designated safeguarding lead, and specific mechanisms for receiving, managing, and handling reports with the relevant authorities.

The most important principle here is that a person’s protection should not depend solely on the goodwill of staff, but on a clear system that reduces the likelihood of error and defines responsibilities in advance.

The Digital Environment Is No Less Risky

As an increasing proportion of organizational activities moves to websites, social media platforms, and virtual meetings, digital safeguarding has become a direct extension of institutional safeguarding.

Digital risks revolve around three main areas: content, communication, and behavior.

Who can post on the organization’s accounts?

How do beneficiaries and staff communicate through digital platforms?

Who can access meetings or online services?

How is personal information protected?

Is there a clear mechanism for reporting abuse or inappropriate behavior online?

These questions are no longer merely technical; they are part of governance.

A weak password, poorly controlled access to a social media account, or sharing a photo without the consent of those depicted can become a problem that goes beyond the technical aspect and affects people’s safety, the organization’s reputation, and their trust in it.

Working with Partners Does Not Transfer Responsibility

An organization may deliver its programs through partners or entities that receive grants and funding from it, but the involvement of a third party does not eliminate the need to verify the level of safeguarding in place.

Before entering into a partnership or providing funding, due diligence proportionate to the level of risk should be conducted, and it should be confirmed that the partner has suitable procedures for protecting people.

It is also important for agreements and contracts to define roles clearly: Who is responsible for what? How are reports made? Who handles follow-up? What mechanism is used to deal with incidents?

The less clearly responsibilities are defined, the greater the likelihood that a problem will fall between multiple organizations.

What Does the Organization Do When an Incident Occurs?

The strength of a safeguarding system is revealed not only by its ability to prevent incidents, but also by how it acts when they occur.

When a report or incident emerges, it should be handled quickly and responsibly, information should be documented securely, efforts should be made to stop or minimize the harm, internal procedures should be followed, and the relevant authorities should be contacted when necessary.

Then comes an equally important stage: learning.

What happened?

Why was the problem able to occur?

Was there an earlier warning that was not taken seriously?

Was the policy unclear?

Do staff need additional training?

Is there a gap in supervision or authority?

A mature organization does not treat an incident as a file it wants to close, but as an opportunity to identify a weakness that should not recur.

Measurement Is Not Just About Numbers

Monitoring safeguarding requires indicators, but the number of reports alone is not enough.

A decline in reports does not necessarily mean that the environment has become safer; it may sometimes mean that people do not know how to report or do not feel safe doing so.

Boards therefore need to combine quantitative data with qualitative information.

They can review reporting patterns, study previous cases, listen to the experiences of beneficiaries and staff, measure their awareness of safeguarding procedures, review the level of training, and test how well teams comply with procedures.

In this way, safeguarding becomes an area that can be overseen and improved, rather than an assumption that is difficult to verify.

Ten Questions the Board Should Ask

The board can test the maturity of its safeguarding system through ten practical questions:

  1. Do we have a clear and up-to-date safeguarding policy, code of conduct, and procedures?
  2. Do we know the potential risks to beneficiaries, staff, and volunteers?
  3. Does the organization’s culture encourage people to talk about concerns and mistakes?
  4. Do all staff know how to recognize a problem and report it?
  5. Is there a clear and safe channel for receiving reports?
  6. Is the training provided to staff and volunteers current and appropriate to the nature of the risks?
  7. Are sensitive roles subject to an appropriate level of checking in accordance with local regulations?
  8. Do we assess the risks associated with jobs and roles that involve direct contact with groups most vulnerable to harm?
  9. Do we review policies after incidents and near misses?
  10. If we work with partners or in different regions, are our safeguarding procedures appropriate to the varying risks and environments?

The purpose of these questions is not to prove that the organization possesses a collection of documents, but to determine whether its safeguarding system is actually working.

Safeguarding Is an Indicator of Governance Quality

A nonprofit organization is fundamentally built on trust.

Beneficiaries trust it, donors trust it, volunteers trust it, and employees expect it to provide a responsible working environment.

That is why ignoring safeguarding risks threatens not only individuals, but can also destroy a reservoir of trust that took years to build.

An organization that makes protecting people part of its culture, decisions, and regular reviews not only reduces risks, but also builds a more responsible and sustainable institution.

The real test is not whether the organization has a safeguarding policy.

The real test is whether a person engaging with it knows that if they are harmed or feel at risk, there is a system that sees it, a voice that hears them, and a responsibility that is activated to protect them.