Most child-serving organizations have a safeguarding policy. Considerably fewer can tell you when it was last verified at a specific site, by someone who does not report to that site's manager.
Why written policy is not protection
Policies fail quietly in predictable places: staff who signed a document they never read, volunteers who were never screened because they were "only helping," reporting channels that run through the person most likely to be implicated, and field sites where the policy was translated into a language nobody uses.
The governing principle: safeguarding is a system, not a document. If any part of it depends on an individual remembering to do the right thing under pressure, it will eventually fail — which is the same structural argument that runs through everything else in this library.
The seven components
- A written policy in every working language, not just the headquarters language.
- Screening for everyone with access — staff, volunteers, visitors, board members, contractors, and short-term teams. The exceptions people make for volunteers and visitors are where risk concentrates.
- Training at induction and annually, with attendance recorded. Untracked training did not happen.
- A reporting channel that bypasses line management, reaching a named person and, ultimately, the board. If the only route runs through the manager, serious concerns will not travel.
- A documented response protocol — who is informed, in what order, within what timeframe, and what happens to the accused person during investigation.
- Board-level oversight, reviewed at least annually as a standing agenda item, not delegated entirely to staff.
- Field verification — someone independent visiting sites and checking whether the policy is actually operating.
The verification visit
This is the component almost everyone skips, and the only one that tells you the truth. A verification visit asks straightforward questions of people at the site:
- Can staff describe what they would do if a child disclosed abuse — without looking anything up?
- Do children know who they can tell, and is that person accessible without a gatekeeper?
- Are screening records complete for everyone currently on site, including volunteers?
- Is the reporting number posted somewhere visible, in the local language?
- When was training last delivered here, and who attended?
Any site that cannot answer these is not protected by your policy, regardless of what headquarters believes.
Governance implications
Safeguarding oversight belongs explicitly in your board charter and cannot be fully delegated to the executive. Boards should receive, at minimum, an annual safeguarding report covering training completion, screening compliance, verification visits conducted, and any incidents and their resolution — with the understanding that a report of zero incidents may indicate a functioning system or a broken reporting channel, and the board should ask which.
Your first 90 days
- Confirm the policy exists in every working language and that current staff have actually read it.
- Audit screening records for everyone with current site access, volunteers included.
- Establish a reporting channel that does not pass through line management.
- Conduct one unannounced verification visit and document what you find.
- Put safeguarding on the board agenda as a standing annual item.
Where this sits. Risk & Safeguarding work only holds when the layer beneath it is solid. The free Flourishing Index shows you which layer is actually constraining you — in six minutes. Take the Index →
Sources
- National Council of Nonprofits — Governance & Leadership, on board oversight responsibilities.
- Component structure reflects common practice across international child-focused organizations; verify against your own jurisdictions' legal requirements, which vary significantly by country.