Most organisations that work with children have a safeguarding policy. Far fewer have a safeguarding framework: the connected set of documents, roles and routines that turns a statement of commitment into decisions people actually make. The gap between the two is where most safeguarding failures happen. A funder or regulator who asks to see "your safeguarding" is rarely satisfied by a single PDF, and nobody can act on one during a live disclosure.
What is the difference between a safeguarding policy and a safeguarding framework?
A safeguarding policy states what an organisation commits to and why. A safeguarding framework is the system that delivers it: the policy plus a code of conduct, reporting and response procedures, safer recruitment, partner due diligence, digital safety rules, risk assessment, governance roles and a review cycle, all consistent with each other.
The documents a framework contains
The exact set depends on the organisation's size, sector and exposure to children, but a complete framework usually includes the following.
- Safeguarding policy. A short, public statement of commitment, scope (who it applies to, including staff, volunteers, trustees, consultants and partners), definitions of harm, and the principles the organisation works to.
- Code of conduct. Concrete expected and prohibited behaviours for anyone representing the organisation, written so it can be signed, taught and enforced.
- Reporting and response procedure. What to do when a concern arises: who to tell, in what timeframe, how to record it, when to refer to police or statutory services, how to support the child, and how allegations against staff are managed. It should include at least one route that does not run through a person's own line manager.
- Safer recruitment and people management. Role-based vetting, references that are actually taken up, criminal record checks where available and their equivalents where not, safeguarding in interviews and induction, and supervision after appointment.
- Partner and contractor due diligence. How partners, grantees, suppliers and venues are assessed before engagement, what safeguarding clauses go into agreements, and how compliance is monitored during the relationship.
- Online and digital safety. Which platforms staff may use with children, rules on one-to-one digital contact, consent and use of children's images and stories, storage of photographs, and the use of AI tools, including whether children's data or images may be entered into them and how AI-generated content about children is handled.
- Risk assessment for activities and programmes. A standard method for assessing safeguarding risk before a programme, event, product feature or country entry begins, with named mitigations and an owner.
- Whistleblowing. Protection for people who raise concerns, including concerns about senior leaders, with an external route where internal routes are compromised.
- Data and records. What is recorded about concerns and cases, who can see it, how long it is kept, and how the organisation meets data protection law while preserving records that may be needed years later.
Many frameworks were written for face-to-face work and have not caught up with messaging apps or generative AI. For organisations deploying AI tools that children use directly, a child rights impact assessment is the natural companion to the framework's risk assessment step.
Governance: who owns the framework
Documents without owners decay. Every framework needs three layers of responsibility, written down and visible on an organisational chart.
- A board or trustee lead. A named person at governance level who receives safeguarding reports on a set schedule, not only after incidents, and who can challenge the executive. In England and Wales, the Charity Commission's guidance is explicit that trustees are responsible for protecting people who come into contact with their charity.
- A designated safeguarding lead. A senior member of staff with the authority, time and training to manage concerns, make referrals and advise leadership.
- Focal points. In larger or multi-site organisations, trained people in each country office, programme or department who are the first point of contact and escalate to the designated lead.
Reporting lines should ensure that a concern about anyone, including the chief executive, has somewhere to go.
Anchoring the framework to recognised standards
A framework built from first principles is harder to defend than one mapped against standards that funders, regulators and partners already recognise. The most relevant are:
- The UN Convention on the Rights of the Child. The UNCRC is the foundation. Article 19 establishes children's right to protection from all forms of violence, abuse and neglect; Article 12 their right to be heard in matters affecting them, which is why child participation belongs in the framework itself. For digital risk, the Committee's General Comment No. 25 applies those rights to the digital environment.
- The Core Humanitarian Standard and PSEAH commitments. For humanitarian and development organisations, the 2024 edition of the Core Humanitarian Standard on Quality and Accountability requires a coherent organisational approach to preventing sexual exploitation, abuse and harassment, and the CHS Alliance's PSEAH Index is aligned to it.
- National regulator guidance. For charities in England and Wales, the Charity Commission's safeguarding guidance for trustees expects policies to be put into practice, made available to the public, and reviewed as necessary, always after a serious incident and at least once a year. Other jurisdictions and sectors have their own equivalents, and the framework should name the ones that apply.
Tailoring for multi-country operations and local law
An international framework has to do two things at once: set a single minimum standard everywhere, and comply with local law wherever the organisation operates. The usual approach is a global framework that defines the non-negotiable minimum, with country annexes that record local requirements.
Mandatory reporting is the clearest example of why annexes matter. Obligations differ in who must report, what must be reported, the threshold for reporting and to whom. In Australia, every state and territory has its own mandatory reporting law, and they are not the same: in the Northern Territory any person must report, while elsewhere the duty falls on specified professions. In England, the Crime and Policing Act 2026, which received Royal Assent on 29 April 2026, creates a duty for people undertaking relevant activity with children to report child sexual abuse, although the duty was not yet in force at the time of writing.
The framework should therefore state that the organisation's internal reporting standard applies everywhere, that local legal duties are always met in addition, and that where referring to local authorities could put a child at greater risk, the decision is escalated and documented rather than made alone in the field.
How to build a child safeguarding policy framework, step by step
- Map exposure. List every way the organisation comes into contact with children, directly, through partners, and through digital products or channels, in every country.
- Assess what already exists. Test current policies and practice against evidence rather than intent. A structured safeguarding audit is the most reliable way to do this.
- Choose the standards to map against. Typically the UNCRC, plus CHS and PSEAH for humanitarian work and the relevant national regulator guidance.
- Agree governance first. Name the board lead, the designated safeguarding lead and focal points, and set reporting lines and schedules before drafting procedures that depend on them.
- Draft the core documents. Policy, code of conduct and reporting procedure first, then recruitment, partners, digital safety, risk assessment, whistleblowing and records.
- Add country annexes. Record mandatory reporting duties, vetting options, data protection law and referral services for each operating country.
- Consult staff, partners and children. Test drafts with the people who will use them, including children and young people in age-appropriate ways.
- Approve at board level. Formal adoption makes ownership explicit and gives the designated lead the authority to act.
- Implement and train. Roll out with training, communication and partner onboarding.
- Monitor, review and update. Set indicators, a reporting schedule and a fixed review date.
Child Safe ME supports organisations through this process, from gap analysis to an implementation roadmap, as part of its child safeguarding policy and framework development work.
Implementation: making it real
An approved but unimplemented framework is a liability: it documents a standard the organisation is not meeting. Implementation has three strands.
- Training. Differentiated by role: induction for everyone, deeper training for focal points and managers, and briefings for the board. For organisations scaling across many sites, train-the-trainer programmes keep standards consistent.
- Communication to children. Children cannot use a reporting route they do not know exists. Child-friendly versions of the policy and reporting procedure, in local languages and suitable formats for different ages and abilities, are part of the framework, not an optional extra.
- Partners. Safeguarding clauses in agreements, onboarding that explains expectations and support to meet the minimum standard, not just a signature.
Monitoring and the review cycle
Monitoring should answer a small number of questions on a regular schedule: how many concerns were raised and through which routes, how quickly they were handled, what proportion of staff and partners are trained and vetted, and what changed as a result of cases. A year with no reported concerns usually means reporting routes are not trusted, not that nothing happened.
The full framework should be reviewed at least annually and always after a serious incident, a significant change in operations such as entering a new country or launching a digital service, or a change in the law.
Common failure points
- Written for an audit, not for use. Long documents nobody has read, which cannot be followed under pressure.
- Inconsistency between documents. A code of conduct that permits what the digital safety rules prohibit, or a reporting procedure that names a role the organisation no longer has.
- Partners outside the perimeter. Delivery partners and contractors who touch children on the organisation's behalf but never saw the framework.
- Digital and AI risk left out. Frameworks that cover the building but not the messaging app, the photo library or the AI tool.
- No review. Adopted once and never revisited as the organisation changed.
Frequently asked questions
How often should a safeguarding framework be reviewed? At least once a year, and always after a serious incident or significant change. The Charity Commission sets this expectation for charities in England and Wales, and it is sound practice everywhere.
Should a child safeguarding framework be separate from PSEAH? The two should be consistent and cross-referenced. Many organisations maintain an overarching safeguarding framework that covers children, adults at risk and PSEAH, with child-specific procedures where children's needs differ.
What if local law conflicts with the organisation's standard? Local legal duties must always be met. Where local law sets a lower standard, the organisation's own higher standard still applies internally. Where a statutory referral could put a child at greater risk, the decision should be escalated and documented.
Does the framework need to cover AI tools? Yes, if staff, partners or children use them in the course of the organisation's work. At a minimum it should set rules on entering children's personal data and images into AI tools and on the use of AI-generated content involving children.
Regulatory and standards details cited here are accurate as of September 2026 and should be checked against the relevant regulator, legislation and standard-setting body before being relied on in a compliance decision.