Safeguarding, Governance & Standards

Trust has to be earned.

Working with young people carries responsibility. Youth Futures Partnership is committed to building safeguarding, governance, data protection, information security and operational standards into our programmes from the beginning — not adding them later as a procurement exercise.

Our assurance framework

Eight areas we believe partners should expect us to take seriously.

The exact requirements vary by programme, but these principles should underpin Youth Futures delivery.

🛡️

Safeguarding

Clear responsibilities, reporting routes, escalation procedures and programme-specific safeguarding arrangements.

👥

Safer Recruitment

Appropriate vetting, references, role assessment, training and DBS checks where the role is eligible.

🔐

Data Protection

Privacy by design, appropriate lawful bases, retention controls and proportionate handling of personal information.

💻

Cyber Security

Secure devices, identities, platforms, access controls and incident-management arrangements.

⚠️

Health & Safety

Risk assessment appropriate to vehicles, venues, equipment, practical activities and public-facing delivery.

⚖️

Equality & Inclusion

Accessible, fair provision that considers barriers to participation and treats young people with dignity.

📋

Quality & Governance

Clear ownership, documented processes, complaints routes, learning and proportionate oversight.

☂️

Insurance & Assurance

Appropriate organisational and activity-specific insurance, evidence and partner due diligence.

Safeguarding young people

Safeguarding is a system, not a certificate.

Youth Futures intends to design safeguarding into recruitment, partnerships, programme design, physical environments, digital services and day-to-day delivery.

Core safeguarding controls

  • named safeguarding leadership and accountability;
  • clear safeguarding and child-protection procedures;
  • safer recruitment and role-appropriate DBS checking;
  • staff and volunteer safeguarding training;
  • codes of conduct and professional boundaries;
  • concern, disclosure and escalation procedures;
  • appropriate recording and information sharing; and
  • programme and venue-specific safeguarding risk assessment.

Working with partners

Where delivery involves schools, councils, charities, employers or training providers, responsibilities should be agreed before delivery begins.

That includes who is supervising young people, who responds to safeguarding concerns, which organisation holds particular records and how concerns are escalated.

Youth Futures should never assume that another organisation's safeguarding arrangements automatically cover our responsibilities.

Data, privacy & cyber

Especially important when technology becomes part of the service.

Ideas such as the Career Passport and Harm Intelligence Platform create opportunities, but they also increase our responsibility to minimise data and protect it properly.

🔏

Privacy by Design

Consider data protection before systems and programmes launch, including DPIAs where processing is likely to create higher risks.

🪪

Identity & Access

Only authorised people should have access to information, with access appropriate to their role and reviewed over time.

🗂️

Data Minimisation

Collect what is genuinely required rather than building a database simply because information might become useful later.

Retention

Define how long information is required, why it is retained and how it is securely disposed of when no longer needed.

🚨

Incident Response

Have clear routes for identifying, containing, investigating and appropriately reporting security or personal-data incidents.

🔗

Supplier Assurance

Understand where third parties process data and ensure appropriate contractual, security and data-processing arrangements exist.

Standards roadmap

Build assurance in sensible stages.

Youth Futures should only claim certifications it actually holds. The following is a sensible direction of travel, not a statement of current certification.

Foundation

Procurement Ready

Get the fundamentals right before chasing badges.

  • safeguarding framework;
  • DBS / safer recruitment process;
  • insurance;
  • ICO/data-protection position confirmed;
  • H&S and risk management;
  • privacy and information governance;
  • EDI, complaints and whistleblowing policies.
Early certification target

Cyber Essentials

A practical early external cyber-security standard, particularly relevant as Youth Futures develops digital services and works with larger organisations.

  • secure configuration;
  • access control;
  • malware protection;
  • security updates;
  • firewall controls.
Scale stage

Formal Management Standards

As the organisation and data footprint mature, independently certified management systems may provide stronger assurance.

  • Cyber Essentials Plus;
  • ISO 9001 quality management;
  • ISO/IEC 27001 information security;
  • other standards where a real commissioner or operational need exists.
Certification & assurance register

A place for verified credentials — when we have them.

This section is deliberately transparent. Planned credentials should not be presented as certifications already achieved.

🛡️

Cyber Essentials

Baseline externally recognised cyber-security assurance.

Future target
🔒

Cyber Essentials Plus

Technical verification of Cyber Essentials controls.

Future target

ISO 9001

Quality-management certification to consider as delivery scales.

Future consideration
🔐

ISO/IEC 27001

Information-security management certification potentially relevant to mature digital services.

Future consideration
Supplier assurance

Make due diligence easy for partners.

The Youth Futures Assurance Pack

As the organisation becomes operational, we intend to maintain a controlled set of due-diligence information that can be shared appropriately with commissioners, schools, funders and delivery partners.

Depending on the relationship and programme, that pack could include:

  • company details;
  • insurance evidence;
  • safeguarding policy;
  • safer recruitment approach;
  • health & safety policy;
  • risk-management framework;
  • privacy notices;
  • data-protection policy;
  • cyber-security policy;
  • incident response;
  • EDI policy;
  • complaints procedure;
  • whistleblowing;
  • modern slavery position;
  • certification evidence; and
  • relevant programme documentation.
A note on our current status

Youth Futures Partnership is developing its operational assurance framework. This page describes the standards and controls we intend to build into the organisation and should not be interpreted as claiming certifications, registrations, insurance arrangements or accreditations that have not yet been formally confirmed. As these are achieved, this page can be updated with verified evidence.

Due diligence

Need assurance information for a potential partnership?

If you are considering commissioning, funding or partnering with Youth Futures, talk to us about the assurance requirements relevant to your organisation and proposed programme.