Most organisations that commission a child safeguarding audit already have a safeguarding policy. What they want to know is whether the policy is real: whether the people they hire are properly checked, whether a concern raised on a Friday evening reaches someone who acts on it, and whether the board would learn about a serious problem before a funder, regulator or journalist does. An audit is how an organisation finds that out.

What does a child safeguarding audit cover?

A child safeguarding audit tests an organisation's arrangements for keeping children safe against a recognised standard, using evidence rather than assurances. It covers policy, leadership, safer recruitment, training, reporting and case handling, partners, online and digital contact, activity risk assessment, children's participation and record keeping, and ends with rated findings and a prioritised action plan.

What an audit is, and what it is not

  • An audit is not an inspection. An inspection is carried out by a regulator with statutory powers, such as a schools inspectorate, and its judgement can carry formal consequences. An audit is commissioned by the organisation itself, or sometimes by a funder, and its purpose is improvement.
  • An audit is not a child rights impact assessment. A child rights impact assessment looks at a specific decision, policy, product or AI system and asks how it will affect children's rights, usually before it launches. A safeguarding audit looks at the organisation as a whole and asks whether its systems prevent and respond to harm caused by its own staff, volunteers, activities, partners and services.

The frameworks an audit is measured against

A credible audit states its benchmark at the outset. The right one depends on sector and jurisdiction, and many organisations are measured against more than one.

  • UK Charity Commission expectations. The Commission's guidance, Safeguarding and protecting people for charities and trustees, makes trustees responsible for protecting people who come into contact with the charity. It expects safeguarding policies to be reviewed at least once a year and always after a serious incident, proper due diligence on partners, eligible roles to be checked with the Disclosure and Barring Service, and online risks to be identified and managed.
  • Standards for safeguarding children in sport. In the UK, the NSPCC Child Protection in Sport Unit's framework sets ten standards, from policy and procedures for responding to concerns through to implementation and monitoring, with an online self-assessment tool for sports bodies.
  • Keeping children safe in education. Schools and colleges in England work to the Department for Education's statutory guidance. The 2026 edition came into force on 1 September 2026. Many local safeguarding partnerships ask schools to complete an annual self-assessment of how they meet their duties under section 175 or section 157 of the Education Act 2002, and an external audit often uses the same structure.

Faith groups, corporates and technology companies rarely have a single sector code. For them, the UN Convention on the Rights of the Child provides the backbone, supplemented by local law and, for digital services, online safety regulation.

The areas a safeguarding audit examines

Whatever the framework, a thorough audit works through the same core areas. Each is tested against documents, conversations and records.

  1. Policy and code of conduct. Is there a child safeguarding policy that people can find, understand and act on? Does a code of conduct set clear behavioural boundaries, including for digital contact, and do staff and volunteers sign it?
  2. Leadership and accountability. Is there a named board-level owner and a designated safeguarding lead with the time, authority and deputy cover to do the role? Does safeguarding appear on the board agenda routinely, not only after an incident?
  3. Safer recruitment and vetting. Do recruitment files show criminal record checks proportionate to the role, references genuinely taken up, gaps in work history explored and safeguarding questions asked at interview? Are volunteers and short-term contractors covered?
  4. Training and induction. Does everyone receive induction and refresher training matched to their role, with more depth for leads, managers and trustees? Can staff describe what they would do with a disclosure?
  5. Reporting and case management. Are there routes that children, parents, staff and partners can actually use, including one that bypasses line management? Are concerns logged, escalated, referred to statutory authorities where required, and closed with a documented outcome?
  6. Partners, contractors and due diligence. Are safeguarding requirements built into grant agreements, contracts and memoranda of understanding? Is partner capacity assessed before funding and monitored afterwards?
  7. Online and digital safeguarding. Which platforms may staff use to communicate with children, and is one-to-one contact visible to a third party? How are images and videos of children consented to, stored and published? Which AI tools are used with or about children, and has anyone assessed them? Where a service verifies ages, is its approach to age assurance proportionate?
  8. Programme and activity risk assessment. Are risks to children assessed before activities, trips, events, research or new programmes begin, and are the controls actually applied?
  9. Children's participation and feedback. Are children told, in language they understand, what they can expect and how to raise a worry? Is their feedback sought and used?
  10. Record keeping and data protection. Are safeguarding records secure, accurate, access-controlled and retained for the right period?
  11. Whistleblowing. Can staff raise concerns about colleagues or senior leaders without fear of retaliation, and is there evidence that they have?
  12. Monitoring and review. Does the organisation collect safeguarding data, learn from incidents and review its arrangements on a fixed cycle?

The digital area is often where the gap between policy and practice is widest. Many policies were written for a building and a face-to-face relationship, and have not been extended to messaging apps, video calls, social media or the AI tools now placed in front of young people. Bringing a safeguarding policy and framework up to date for digital and AI-era risk is often the first action an audit recommends.

How the audit is carried out

A well-run audit combines several sources so that no single one can mislead.

  • Document review. Policies, procedures, codes of conduct, training records, board minutes, risk registers, partner agreements and previous reviews.
  • Interviews. With trustees or board members, senior leaders, the designated safeguarding lead, managers, frontline staff and volunteers.
  • Focus groups. With staff, and where it is safe, ethical and appropriately consented, with children, young people and parents.
  • Site visits. Observing physical environments, supervision ratios, signage and how activities run in practice.
  • Sampling. Checking a sample of recruitment files and, under strict confidentiality, a sample of past safeguarding cases, to see whether the procedure was followed from first concern to closure.

What you should receive at the end

The output should be decision-ready, not a narrative that sits in a drawer. Expect:

  • Findings rated by area, commonly using a red, amber and green (RAG) scale, with the evidence behind each rating.
  • Good practice identified, so that what works is protected rather than accidentally dismantled.
  • A prioritised action plan separating urgent risks to children from medium-term improvements, with owners and realistic timescales.
  • A board or leadership briefing that sets out the organisation's risk position in plain terms.

If a live risk to a child is identified during fieldwork, it should be escalated immediately through the organisation's procedure, not held for the final report. Agree that protocol before the audit starts.

How often should an organisation be audited?

There is no single legal rule across sectors. The Charity Commission expects charities to review safeguarding policies at least once a year and after any serious incident. In practice, a sensible cycle is an annual internal self-assessment with an independent audit every two to three years, and an additional review after a serious incident, a merger, a major expansion into new countries, or the launch of a new digital service or AI tool that reaches children.

How to prepare: a checklist

Before the auditor arrives:

  • Agree the scope, the benchmark standard and which sites or programmes are included.
  • Name an internal coordinator with authority to open doors and records.
  • Gather current policies, codes of conduct, procedures and the date each was last reviewed.
  • Pull recent board minutes that discuss safeguarding.
  • Prepare an anonymised log of safeguarding concerns for the past two to three years.
  • Make recruitment files and training records available for sampling.
  • List partners, contractors and grantees who have contact with children.
  • Inventory the digital platforms and AI tools used with or about children.
  • Confirm consent and support arrangements for any consultation with children.
  • Agree the escalation protocol for any live concern found during the audit.

The most useful thing an organisation can do is resist the urge to tidy up before the audit. A finding that something is not working is the point of the exercise. What matters is what happens afterwards: an action plan owned at board level, and training that reaches the people who have to act on it. The broader case for taking this seriously outside the charity sector is set out in five reasons corporates should consider child safeguarding.

Frequently asked questions

Is a child safeguarding audit a legal requirement? Not usually in itself. But many legal and regulatory duties, including trustees' duties to UK charities and schools' statutory safeguarding duties, are difficult to demonstrate without one, and funders increasingly require independent evidence of safeguarding arrangements.

How long does a safeguarding audit take? It depends on size and spread. A single-site organisation may need a few weeks from document request to final report. A multi-country organisation with partners and digital services will need longer, particularly if fieldwork includes visits and consultation with children.

Should the audit be internal or external? Both have a place. Internal self-assessment builds ownership and is well suited to annual checks. An independent external audit is better at testing seniority, culture and whether reporting routes really work, because staff can speak more freely to someone outside the line management chain.

Does a safeguarding audit cover online safety and AI? It should. Any organisation that contacts children through messaging, video, social media or online learning, or uses AI tools with or about children, needs those channels tested to the same standard as face-to-face work.

What is the difference between a safeguarding audit and a child rights impact assessment? An audit examines an organisation's safeguarding system as a whole. A child rights impact assessment examines the effect of one specific decision, product, policy or AI system on children's rights, ideally before it is introduced.

References to standards and guidance are accurate as of September 2026 and should be checked against the Charity Commission and the Department for Education before being relied on in a compliance decision.

Work with Maryam

Looking for expert guidance on child safeguarding, online safety, or AI governance? Maryam and the Child Safe ME team are here to help.

Get in Touch