A board-level checklist for charity trustees

What trustees should be asking about technology

Seven sections, twenty-nine questions. No technical knowledge required. Take one section per board cycle, record the answers in the minutes, and note where the answer was vague.

Why this exists

Most technology advice written for charities assumes one of two things. Either that there is no money at all, or that a charity is basically a small business with worse funding.

Neither is right, and I say that as a director and a serving trustee rather than as somebody looking in from outside.

Charities carry obligations that commercial organisations of the same size simply do not. Trustees are personally accountable. Restricted funding cannot be moved across to rescue a project that has gone over. And there is often data about vulnerable people sitting in a system that was chosen years ago for reasons nobody can now remember.

The difficulty at board level is rarely a lack of interest. It is that trustees are unsure whether they are allowed to ask, because there is a widespread assumption that you need to understand the technology before you can scrutinise it.

You do not. Every question in this document can be asked and answered in plain language, and none of them requires anybody in the room to know how anything works.

How to use it

Not all at once. Thirty-odd questions in a single meeting will produce defensiveness and no useful answers.

Take one section per board cycle. Ask the questions, record the answers in the minutes, and note where the answer was vague. The vague answers are the finding. That is true even when everything else looks fine.

A quick note: this is general guidance rather than legal advice, and where the law applies to your charity you should take proper advice on it.

Section 1

Ownership and oversight

Who owns technology in this organisation?

A good answer

Names a person, and that person is senior enough to make decisions and will still be here next year.

What should concern you

A committee, a job title nobody currently holds, or the finance director having inherited it because the invoices land on their desk.

When did the board last discuss technology as an agenda item rather than under any other business?

A good answer

Within the last two board cycles, with something recorded in the minutes.

What should concern you

That it only appears when something has gone wrong or when a large invoice needs approving.

Is technology on the risk register, and who reviews it?

A good answer

Identifies specific risks with named owners and review dates.

What should concern you

A single line saying “IT systems” with no detail, or nothing at all.

If a technology decision went badly wrong tomorrow, who would answer for it?

A good answer

Uncomfortable but clear.

What should concern you

A pause, or the assumption that the supplier would carry it. Suppliers carry contractual liability. Trustees carry accountability, and those are not the same thing.

Section 2

What you spend, and what it does

Can anyone produce a single list of everything we spend on technology and what each item is for?

A good answer

Yes, and it is produced within a week.

What should concern you

That the spend is spread across departments, budgets and personal cards, and nobody has ever looked at it together.

This is the most revealing question in the document. In my experience most organisations cannot answer it, and the reason is never carelessness. The spend accumulated over years, each decision sensible on its own, and nobody was ever made responsible for the whole picture.

For each recurring cost, who uses it and when did we last check?

A good answer

Identifies an owner and a purpose for every line.

What should concern you

Any subscription nobody can account for. There is usually at least one, and the total is usually higher than the finance lead expected.

What did we spend on technology last year, and what changed as a result?

A good answer

Connects money to an outcome, even a modest one.

What should concern you

A figure with no answer to the second half of the question.

Is any of this funded from restricted funds, and are we certain that is permitted?

A good answer

Documented.

What should concern you

An assumption. This one has consequences beyond the technology.

Section 3

Data and the people you serve

What personal data do we hold, where does it live, and who can see it?

A good answer

Covers every system, including the spreadsheets and the shared drives, not only the main database.

What should concern you

An answer that only describes the official system. The unofficial ones are where the risk usually sits.

Do we hold data about people who are vulnerable, and is it treated differently?

A good answer

Describes specific controls.

What should concern you

That it is held in the same way as everything else because nobody has separated it out.

If we had a data breach on Monday, what would happen?

A good answer

Describes who is called, in what order, and who decides what gets reported.

What should concern you

That the plan exists in one person’s head, or does not exist.

Who has access to systems who should no longer have it?

A good answer

Describes a leavers process that includes system access, and evidence it has been followed.

What should concern you

Nobody having checked. Former staff, former volunteers and former trustees frequently retain access for years.

Section 4

Suppliers and dependency

Who are our technology suppliers, what do they do, and when were the contracts last reviewed?

A good answer

A short list with dates.

What should concern you

A long-standing relationship nobody has examined because examining it feels like a criticism.

If our main supplier doubled their price, what would we do?

A good answer

Describes realistic alternatives.

What should concern you

That the honest answer is that the charity would pay. That is a supplier relationship you do not control.

Can we get our data out, in a usable form, and has anybody tested it?

A good answer

Somebody has actually tried and the export worked.

What should concern you

Confidence based on the contract rather than on a test. I have seen more than one export function that technically existed and produced something nobody could use.

Who is checking that we get what we pay for?

A good answer

Names somebody internal with the standing to challenge.

What should concern you

That the only person evaluating the supplier’s work is the supplier.

Section 5

Artificial intelligence

Most charities have adopted at least one AI tool in the past two years. Far fewer approved it at board level, and the advice arriving from outside is currently the worst in this whole document. It tends to come as enthusiasm about efficiency, usually from somebody with something to sell.

None of that argues for avoidance. It argues for asking.

What AI tools are being used in this organisation, and who approved them?

A good answer

A list, with names against it.

What should concern you

That nobody knows, because tools were adopted by teams rather than procured centrally. This is extremely common and it is not a disciplinary matter. It is a governance gap.

What organisational data goes into these tools?

A good answer

Specific about what goes in, from which systems, and who decided that.

What should concern you

Vagueness. For a charity holding data about vulnerable people, vagueness here is itself the finding.

What decision would we never let an AI tool make on its own?

A good answer

Has been written down. Eligibility, safeguarding, hiring, anything affecting an individual’s access to a service.

What should concern you

That everybody agrees in principle and nothing is recorded. A boundary in people’s heads is not a control.

If the supplier changed the price or withdrew the tool, what would we lose?

A good answer

Treats this as a dependency question, because that is what it is.

What should concern you

That a tool has quietly become the way a team works, with no plan for its absence.

Can anybody here explain, in plain terms, how it reaches its answers?

A good answer

Describes the shape of it. What it was built on, what it is good at, where it is known to be unreliable.

What should concern you

That nobody can, because that means the charity cannot defend a decision the tool influenced.

Section 6

Accessibility

For a charity this is not a design preference. It is a legal duty in most cases, and it is also a mission question. If you exist to serve people including disabled people, and your main digital service excludes some of them, that is worth a board conversation regardless of what the law requires.

Which accessibility standard do we work to, and who confirmed we meet it?

A good answer

Names a standard, commonly WCAG 2.2 at level AA, and a person who assessed it.

What should concern you

The second half being unanswerable. Somebody’s name should be attached.

When was our website last tested, and how?

A good answer

Includes testing beyond automated tools. Somebody has tried to complete the main task using a keyboard alone, or with a screen reader.

What should concern you

A report from an automated checker. Those catch roughly a third of issues and will not tell you whether a form is usable.

What did we find, and what have we not fixed?

A good answer

A list with a plan, which is a defensible position.

What should concern you

No list, which means the charity cannot demonstrate it ever looked.

Is accessibility in the specification for the next thing we build?

A good answer

Yes, in writing, in the brief.

What should concern you

The assumption that the supplier will handle it. Specified up front it costs very little. Retrofitted it is a project.

Section 7

If the key person left tomorrow

Every charity I have worked with has one. Somebody who understands how the systems fit together, usually alongside their actual job, often without it appearing anywhere in their role description.

Who is that person here, and what would we lose?

A good answer

Names them and has thought about it.

What should concern you

That the question produces recognition and laughter but no plan.

Are passwords and system access held anywhere other than in one person’s head?

A good answer

Describes a shared, secure arrangement that more than one person can reach.

What should concern you

A personal password manager, a spreadsheet, or a memory.

Who else could keep things running for a month?

A good answer

Names a second person, even a partial one.

What should concern you

Nobody, and no plan to change that.

Are we building internal capability or increasing our dependence on outsiders?

A good answer

Shows staff learning to do more over time.

What should concern you

A pattern where every new need becomes a new supplier. That is how small charities end up with technology costs they cannot reduce.

What to do with the answers

You will finish this with a mix of confident answers, partial ones and blanks.

The blanks are the useful part. Not because they represent failure, but because they are the things nobody had been made responsible for, which is a different and more fixable problem.

Three things worth doing next.

Record where the answer was vague

Vagueness in the minutes is a finding. It gives the next board the starting point this one did not have.

Pick one thing

Not seven. The list of technology spend is usually the best first move, because it is dull, it takes an afternoon, and it produces something concrete that every other question then becomes easier to answer.

Put one section on each board agenda

Seven sections, quarterly meetings, and inside two years the board has genuine oversight built up gradually rather than a policy nobody reads.

Take it into the meeting

Print this page and the checkboxes work on paper. Or have the formatted version sent over, which is the same twenty-nine questions laid out for a board pack.

Share this freely with other boards. It is more useful passed on than kept.

Brian Schur

About the author

Brian Schur is an independent Digital, AI and Business Transformation Advisor. Drawing on more than forty years of commercial, government and charity experience, he helps organisations avoid expensive technology mistakes, improve performance and make confident decisions without vendor bias or the complexity of a large consultancy.

He is a company director and a serving trustee with risk and audit responsibilities, so the questions in this document come from having sat on both sides of them.

He has no software to sell, no reseller agreements and no platform commissions.

If a section produced more blanks than answers

I advise trustee boards independently, and the honest answer is frequently that things are in better shape than the board feared.

Thirty minutes will usually establish which situation you are in.

Book a free 30-minute call

We handle your details in line with our privacy policy.