Your board approves budgets for insurance, audits, and legal counsel without hesitation. But when the website comes up, it's treated as a communications expense — discretionary, deferrable, someone else's problem. That framing is wrong, and it's costing organisations far more than a rebuild ever would.

What Governance Actually Means for a Website

Governance isn't just about board meetings and policy documents. It encompasses every system through which an organisation makes, implements, and accounts for decisions — including how it communicates with the public. Your website is the most visible output of that communication system. If it's inaccessible, non-compliant, or misrepresents your programmes, the board is ultimately accountable.

In the UK, the Charity Commission expects trustees to ensure their organisation maintains accurate public information. A website that shows outdated annual reports, missing safeguarding policies, or incorrect trustee listings isn't a design problem — it's a compliance failure.

The Four Governance Risks Hiding in Plain Sight

1. Outdated Information Creates Legal Exposure

Outdated programme descriptions, expired policies, or incorrect contact details create legal exposure if a beneficiary, donor, or regulator relies on that information and is misled. Most boards have no process for ensuring website content reflects current organisational reality.

2. Accessibility Failures Are Discrimination

WCAG 2.2 AA compliance is not aspirational — for organisations receiving public funding or serving vulnerable populations, failure to meet basic accessibility standards can constitute discrimination under the Equality Act 2010. The board is responsible for ensuring the organisation meets its legal obligations. An inaccessible website is a breach of that responsibility.

3. Data Handling on the Website Is a Trustee Matter

Every contact form, newsletter signup, and donation flow on your website processes personal data under GDPR. The trustees are the data controller. If your website uses third-party scripts, outdated consent mechanisms, or inadequate privacy notices, the exposure falls to the board — not the developer who built the site three years ago.

4. Platform Dependency Is Key Person Risk

If your website requires a specific developer, plugin combination, or institutional knowledge to maintain, the board has approved an operational dependency they may not even be aware of. When that developer leaves — or the plugin breaks — the organisation loses its most public-facing asset with no contingency plan.

What the Board Should Be Asking

Governance AreaWhat to AskRed Flag Answer
ComplianceWhen was the website last audited for regulatory compliance?"We haven't" or "The agency handles it"
AccessibilityWhat is our current Lighthouse accessibility score?Below 85, or "I don't know what that is"
DataDo we have a current privacy policy and cookie consent mechanism?"I think so" or pointing to a 2019 policy
ContinuityIf our web developer left tomorrow, what would happen?"We'd be in trouble"
ContentWho is responsible for keeping website content accurate?No clear owner, or "whoever has time"
PerformanceWhat does our website cost in lost donor trust annually?Silence — this has never been calculated

How to Raise This With Your Board

The most effective framing is not "we need a new website." That sounds like a spend request. The effective framing is: "We have identified governance risks in our current web infrastructure that require trustee awareness and a remediation plan."

Present it the same way you would present findings from a safeguarding audit or a financial controls review — with specific risks identified, likelihood and impact assessed, and options for resolution costed. Boards respond to structured risk framing. They disengage from design conversations.

A Blueprint Audit produces exactly this output: a board-ready diagnostic that maps technical debt, compliance gaps, and content governance failures in plain language — with a prioritised remediation roadmap your trustees can approve and track.

The Cost of Inaction Is Not Zero

Deferring website investment feels like saving money. In practice, it accumulates compounding costs: missed grant opportunities because funders couldn't verify your governance on your site, donor attrition because the donation journey was broken on mobile, staff time spent manually fielding enquiries that a functional website would have resolved, and regulatory risk that grows with every year of non-compliance.

None of these costs appear on a budget line. All of them are real.

Further Reading

What Changes When You Treat the Website as Governance

Organisations that make this shift stop having the same conversation every 18 months. Instead of another reactive rebuild triggered by a crisis — a broken donation form during a campaign, a Charity Commission query about outdated trustee information, a funder who couldn't verify financials — the website becomes something that gets reviewed, maintained, and invested in as part of normal governance cycles.

The ED stops apologising for the site in funder meetings. The board has a clear picture of what the organisation's most public asset says about it. The comms team has the infrastructure to do their job. None of this is aspirational — it's what well-governed website infrastructure actually produces.