Charity Commission Warns of Rising Fraud and AI Enabled Threats as Sector Risks Increase

A charity worker at a desk reviewing documents, representing charity governance, fraud risk, and the Charity Commission's 2026 sector risk assessment

AI Use: AI tools were used to support source discovery and to structure the article for clarity. All research, verification, drafting, and final editorial decisions are fully human led. Learn about our AI policy.

Every year the Charity Commission publishes a snapshot of the threats facing the sector. This year's picture is sharper, and more concerning. The Commission's second annual Charity Sector Risk Assessment, published on 18 August 2026, documents a sustained rise in abuse of charitable status, growing complexity in casework, a new technological dimension to fraud, and a financial picture that remains uneven despite some modest signs of recovery.

The report draws on charity accounts, trustee annual reports, serious incident submissions, and intelligence referrals from other government agencies. Its purpose is partly analytical, tracking where the risks are moving and partly practical, giving trustees a framework to sense check their own risk registers against.

At a Glance

  • Abuse of charitable status: 374 cases in 2025-26, a 29% increase, following a 38% rise the year before
  • Regulatory referrals: The Commission passed information to HMRC, the police, and local authorities 500 times in the last year, up 8%
  • Registration scrutiny: Fewer than 45% of charity applications now result in registration, down from 72% in 2016-17
  • Financial strain: Two in five charities spent more than they received, one in four small charities reported only breaking even in 2024
  • Cyber incident: A breach at Beacon CRM in August 2026 exposed data held by a significant number of charities

A Two Year Acceleration in Abuse Cases

The headline figure is a 29% increase in concerns raised about charitable status being exploited for private benefit, with 374 cases recorded in 2025-26. That follows a 38% increase the previous year, when cases rose from 211 to 291. Taken together, the data describes not a spike but a trajectory and the Commission's language reflects that. It speaks of a "sustained increase" and "particularly complex case work", the latter often involving charities operating in sectors where two or more regulators share an interest, or where the lines between their respective remits are not cleanly drawn.

The practical consequence of that complexity is visible in the referral figures. The Commission passed information to other agencies including HMRC, the police, and local authorities, 500 times in the last year, up 8% on the previous twelve months. Some of that reflects better intelligence sharing, some of it reflects the growing difficulty of cases that do not sit neatly within any single regulator's domain.

The report also raises a concern that gets less attention than outright fraud, charities providing sensitive services to vulnerable people in areas where there is no subject expert regulator at all. Out of school settings and certain housing services are specifically cited. In those cases, the Commission notes, beneficiaries may have limited avenues for redress if service quality falls short. The Commission's own remit covers governance and charity law compliance, it has no powers to set or enforce service standards, and it has raised this gap directly with government.

AI Is Adding a New Dimension to Fraud

The report names artificial intelligence explicitly as a tool being used to submit fraudulent applications both to register charities and to apply for grants. The impact is visible in the Commission's own data. Fewer than half of all registration applications, 45% are now approved and result in a new charity being registered. In 2016-17, the approval rate was 72%. That shift partly reflects tighter scrutiny in response to rising fraud, but it also signals how much the threat landscape has changed in less than a decade.

Separately, in early August 2026 the Commission responded to a cyber security incident at Beacon CRM, a Customer Relationship Management system used by a significant number of charities. The breach exposed donor and beneficiary data held by affected organisations. The Commission encouraged trustees to report the incident through its serious incident process, to notify the Information Commissioner's Office where required under data protection law, and to communicate clearly with their supporters. Given the volume of reports it expected to receive, it warned that responses to individual submissions might take longer than usual.

Safeguarding remained a persistent thread running through the Commission's caseload. Around a quarter of concerns raised with the regulator over recent years have related to safeguarding matters, and this year's report draws particular attention to cases involving individuals in positions of power or spiritual influence, a category the Commission says requires trustees to handle allegations with special care.

A Financial Picture That Remains Fragile

On the financial side, the Commission describes some early signs of recovery, sector income has risen slightly, and aggregate data suggests income growth now narrowly outpaces growth in total spending. But the Commission is careful not to overstate this. Two in five charities recorded spending that exceeded income in 2024. One in four charities with total income below £10,000 reported only breaking even that year. For smaller organisations, the financial margin remains very thin.

The Commission encourages trustees to treat financial planning as a continuous process, making sure income projections are grounded in operating realities, reviewing forecasts regularly, and acting early if the numbers start to diverge. Given how many charities are already operating at the edge, the report implies that waiting to see how things develop is not a safe default.

What the Commission Is Asking Trustees to Do

Paul Latham, the Commission's Director of Communication and Policy, acknowledged the complexity of the picture directly. "The vast majority of charities are well run, making a positive difference to lives and communities every day. However, our assessment highlights the growing scale and complexity of risks they face, including from those seeking to exploit charity status for personal benefit, and from a lack of regulatory clarity which potentially leaves service users exposed to poor services or harm."

The Commission's practical asks for trustees are focused on two areas, due diligence before entering new service delivery arrangements, and early engagement with risks rather than waiting for problems to surface. The report is explicitly not a verdict on the sector. Most charities are not directly affected by the specific threats it documents. But the environment is getting more complicated and the data on fraud, technology risks, and financial fragility suggests the pressures are not temporary.

Key Takeaways

  • Cases of alleged abuse of charitable status rose 29% to 374 in 2025-26, continuing a two year acceleration from 211 cases in 2023-24
  • AI is enabling fraudulent charity registration and grant applications, fewer than 45% of registration applications are now approved, down from 72% in 2016-17
  • A Beacon CRM cyber security incident in August 2026 exposed donor and beneficiary data held by a significant number of charities
  • Two in five charities spent more than they received in income, small charities with income below £10,000 are particularly squeezed
  • The Commission has raised gaps in service quality regulation with government, particularly for charities operating without a subject expert regulator