Lessons from published reports on governance and risk in UK schools and trusts
Academy trusts operate in a demanding regulatory environment. The Academies Trust Handbook sets clear expectations for governance, internal control, and risk management. When these systems fail, the consequences can be severe—for pupils, staff, and the trust's reputation.
Understanding where things have gone wrong elsewhere helps trustees and executives recognise vulnerabilities in their own arrangements.
Safeguarding failures remain one of the most serious risk categories for schools. Published ESFA (formerly EFA) investigation reports have repeatedly identified patterns where compliance controls deteriorated over time without adequate board oversight.
The Cuckoo Hall Academies Trust investigation (published 2016) identified significant failings including: incomplete Single Central Record (SCR) checks, inadequate DBS verification processes, fire safety compliance gaps, and insufficient risk assessment procedures. Critically, the investigation found that these risks had not been adequately escalated to trustees, and risk registers were not being maintained as live documents.
The trust was subsequently rebrokered, with schools transferred to new sponsors.
In August 2023, the Department for Education issued urgent guidance requiring schools to identify and mitigate risks from Reinforced Autoclaved Aerated Concrete (RAAC). This lightweight concrete, used widely in school buildings from the 1950s to 1990s, had been found to pose structural risks including sudden collapse.
The resulting disruption affected over 200 schools and colleges at its peak, with some institutions requiring partial or full closures, emergency decanting of pupils, and significant business continuity challenges. Analysis from the Education Policy Institute highlighted that many trusts had limited visibility of their estates risk profile, with condition surveys incomplete or outdated.
Key lessons included: the need for systematic estates risk identification, integration of building condition data into board-level risk registers, and robust business continuity planning for premises-related disruption.
When a significant incident occurs—such as a school fire—the aftermath often reveals weaknesses in risk management, insurance arrangements, and board oversight that had previously gone unnoticed.
The Vantage CE Academies Trust received a Financial Notice to Improve (FNtI) following a school fire in 2019. The subsequent ESFA investigation identified that the trust had inadequate insurance arrangements, with cover insufficient for the actual reinstatement costs. The investigation also found breaches of the Academies Trust Handbook relating to financial management, internal control, and governance oversight of residual risk.
This case illustrates how risks that appear theoretical can crystallise rapidly, and how gaps in board-level risk oversight only become apparent when incidents occur.
Ransomware and cyber attacks on UK schools and trusts have increased significantly in recent years. The National Cyber Security Centre (NCSC) and Department for Education have issued specific guidance for the education sector, recognising schools as attractive targets due to the sensitive data they hold and often limited IT resources.
While many incidents go unreported, several high-profile cases have been widely covered. Large multi-academy trusts have reported recovery costs running to six figures following ransomware attacks, with disruption lasting weeks. In some cases, exam data, safeguarding records, and financial information have been compromised or encrypted.
The common theme in post-incident reviews is that cyber risk was not being treated as a board-level concern. Risk registers either omitted cyber entirely, or recorded it without clear ownership, controls, or residual risk assessment. When attacks occurred, there was no documented business continuity plan for IT systems failure.
Many trusts still manage risk using spreadsheets shared via email or stored on network drives. While this approach may work initially, it creates systemic vulnerabilities that become apparent under scrutiny or during incidents.
Common failure patterns include:
These weaknesses feature repeatedly in ESFA investigation reports and audit findings. A Financial Notice to Improve often requires trusts to demonstrate improved internal control—including risk management—and spreadsheet-based systems rarely provide the evidence required.
How EduRisk addresses each category of risk management challenge
| Risk Category | Common Failure Pattern | EduRisk Solution |
|---|---|---|
| Safeguarding & Compliance | Drift without board visibility; static registers; no escalation | Live register, owners, reminders, board summaries |
| Estates & Building Safety | Incomplete condition data; no link to continuity planning | Estates category, trust-wide view, BCP integration |
| Insurance & Business Continuity | Gaps only visible after incidents; inadequate cover | Residual risk scoring, audit trail for scrutiny |
| Cyber & IT Security | Not treated as board-level; no ownership or controls | Cyber category, clear ownership, linked controls |
| Governance & Internal Control | Spreadsheets; no audit trail; weak board packs | Automated reports, full history, FNtI readiness |
Understanding the expectations placed on academy trusts
The ATH (formerly Academies Financial Handbook) sets out the requirements for governance, financial management, and internal control. It explicitly requires trusts to manage risks and have a system of internal control.
The Education and Skills Funding Agency monitors trust compliance. Financial Notices to Improve are issued when significant weaknesses are identified, requiring trusts to demonstrate remediation of control failures.
Annual external audits assess whether trusts have adequate systems of internal control. Auditors increasingly expect to see documented risk management processes with clear evidence of board oversight.
EduRisk is designed specifically for UK academy trusts—helping you meet regulatory expectations while making risk management genuinely useful.
Contact us at hello@edurisk.uk