When I saw the headlines surrounding the Oxfam scandal over the weekend – claims of sexual exploitation and abuse by staff members in Haiti and within its volunteering circuit – it made me question if the Third Sector had the same structures around Risk and Compliance that Banking & Finance do, might this have helped prevent, manage or at least put in place controls to prevent or adequately manage these situations?

It has been reported that in 2017, there were 125 cases of sexual abuse across the Third Sector with 87 from within Oxfam, 31 from Save the Children and a small number from British Red Cross.

Since the unprecedented exposure, Oxfam have now stated they will be putting in better governance controls and whistleblowing procedures. I’m sure it isn’t just me that recognises these as the typical responsibilities of Risk and Compliance professionals? It also raises the question what processes and contingencies do the Top 100 charities currently have in place to mitigate, control and manage risk?

Save the Children have recently appointed a new Chief Risk Officer and currently, they appear to be the only large charity who have an individual at Director level, responsible for risk and compliance. Sometimes it is easy to overlook the size of charitable organisations, a number of whom, if they were commercial businesses, would sit in the FTSE 250 with responsibility for managing and distributing huge sums of cash whilst ensuring the money is being spent responsibly in line with their charters or commitments to transparency.

It is useful to start by looking at what the role of the Chief Risk Officer (CRO) is as this goes some way to aiding in the understanding of what benefits they can bring. The CRO and his or her team are responsible for identifying, analysing and mitigating internal and external events that could threaten a company, establishing policies, governance, reporting structures, owning business continuity, IT security, Cyber, and in 2018, being an active business partner. Protecting a company is much more complex and demanding than it was twenty years ago with a broader range of threats, in particular surrounding technology or data privacy. Charities have a history of poor customer data management which in 2017 resulted in 13 fines to large charities from the Information Commissioners office (ICO).

In the case of large charities with substantial cash donations, government funding, international operations, high volumes of customer data, regulation (GDPR), global threats from Cyber Crime, invaluable brand and customer reputations, and in the case of Oxfam, existing abuse of the system, what is stopping these organisations taking control? The Oxfam case outlines the need for improved governance and controls, better processes around employment checks for new and current staff, complaints and whistleblowing policies and procedures. This isn’t to say that charities don’t take this seriously, I’m just not sure if they take the potential threats to their organisations seriously enough.

It wasn’t that long ago that the banks had a much lighter version of Risk and Compliance. Significant events over the last ten years were cause for change – the Mexican drug cartel money laundering, LIBOR, PPI, TCF, KYC, Sanctions, AML. The rogue traders, The London Whale, Bruno Iksil, Kweku Adoboli and Jerome Kerviel who collectively lost $15.6 bn – In the past Kweku, Jerome and Bruno wouldn’t have been called rogue traders, they would have just ‘disappeared’ off the scene and suddenly stopped coming to work. It’s here where the best parallels with Oxfam. Mistakes have been made, you can’t turn back the clock, sometimes it’s the shock that creates the calls to action. The learnings will hopefully be to be bold and brave; take action, beef up your Risk and Compliance functions, don’t be afraid and try and get in front of it. It takes time, but it creates better and more stable organisations in the long term. A lesson that all sectors can learn from.

 

To follow Kirsten’s articles on LinkedIn, click here.

Related News

News

22 May, 2026

The Sunday Times Best Places to Work 2026

The official The Sunday Times Best Places to Work, powered by WorkL, has been published today (22nd May 2026), showcasin...

News

15 May, 2026

The Asymmetric Workforce: A New Lens on Senior Appointments

For twenty years, Green Park has helped organisations think differently about leadership - not simply identifying senior...

News

13 April, 2026

C-Suite Report 2026 Released

As Green Park enters its twentieth year, we are increasingly clear about the questions that matter most to senior leader...

News

27 February, 2026

Workforce Asymmetry: The Talent Challenge Defining Modern Leadership

As Green Park enters its 20th year, we’ve become clear on the defining talent challenges we want to help leaders s...

News

25 June, 2025

Global Talent Conference 2025

We are delighted to announce the third annual virtual Green Park Global Talent Conference on 1st - 2nd October. Join us...

News

19 March, 2025

How to Be an Indispensable CMO

The proportion of CMOs with a seat at the top table is gaining traction as the business focus on customer experience ram...

News

6 March, 2025

It’s Time to Stop Hoping for More Female CEOs - And Start Acting

This International Women's Day, Green Park's Managing Director, Jo Sweetland, highlights the lack of progress in appoint...

News

18 February, 2025

Unlocking Your Potential: The Power of Transformational Leadership

Did you know that 70% of employees don't feel engaged at work? This staggering statistic highlights a critical issue th...