A board-level checklist for charity trustees
What trustees should be asking about technology
Seven sections, twenty-nine questions. No technical knowledge required. Take one section per board cycle, record the answers in the minutes, and note where the answer was vague.
Why this exists
Most technology advice written for charities assumes one of two things. Either that there is no money at all, or that a charity is basically a small business with worse funding.
Neither is right, and I say that as a director and a serving trustee rather than as somebody looking in from outside.
Charities carry obligations that commercial organisations of the same size simply do not. Trustees are personally accountable. Restricted funding cannot be moved across to rescue a project that has gone over. And there is often data about vulnerable people sitting in a system that was chosen years ago for reasons nobody can now remember.
The difficulty at board level is rarely a lack of interest. It is that trustees are unsure whether they are allowed to ask, because there is a widespread assumption that you need to understand the technology before you can scrutinise it.
You do not. Every question in this document can be asked and answered in plain language, and none of them requires anybody in the room to know how anything works.
How to use it
Not all at once. Thirty-odd questions in a single meeting will produce defensiveness and no useful answers.
Take one section per board cycle. Ask the questions, record the answers in the minutes, and note where the answer was vague. The vague answers are the finding. That is true even when everything else looks fine.
A quick note: this is general guidance rather than legal advice, and where the law applies to your charity you should take proper advice on it.
Section 1
Ownership and oversight
Who owns technology in this organisation?
A good answer
Names a person, and that person is senior enough to make decisions and will still be here next year.
What should concern you
A committee, a job title nobody currently holds, or the finance director having inherited it because the invoices land on their desk.
When did the board last discuss technology as an agenda item rather than under any other business?
A good answer
Within the last two board cycles, with something recorded in the minutes.
What should concern you
That it only appears when something has gone wrong or when a large invoice needs approving.
Is technology on the risk register, and who reviews it?
A good answer
Identifies specific risks with named owners and review dates.
What should concern you
A single line saying “IT systems” with no detail, or nothing at all.
If a technology decision went badly wrong tomorrow, who would answer for it?
A good answer
Uncomfortable but clear.
What should concern you
A pause, or the assumption that the supplier would carry it. Suppliers carry contractual liability. Trustees carry accountability, and those are not the same thing.
Section 2
What you spend, and what it does
Can anyone produce a single list of everything we spend on technology and what each item is for?
A good answer
Yes, and it is produced within a week.
What should concern you
That the spend is spread across departments, budgets and personal cards, and nobody has ever looked at it together.
This is the most revealing question in the document. In my experience most organisations cannot answer it, and the reason is never carelessness. The spend accumulated over years, each decision sensible on its own, and nobody was ever made responsible for the whole picture.
For each recurring cost, who uses it and when did we last check?
A good answer
Identifies an owner and a purpose for every line.
What should concern you
Any subscription nobody can account for. There is usually at least one, and the total is usually higher than the finance lead expected.
What did we spend on technology last year, and what changed as a result?
A good answer
Connects money to an outcome, even a modest one.
What should concern you
A figure with no answer to the second half of the question.
Is any of this funded from restricted funds, and are we certain that is permitted?
A good answer
Documented.
What should concern you
An assumption. This one has consequences beyond the technology.
Section 3
Data and the people you serve
What personal data do we hold, where does it live, and who can see it?
A good answer
Covers every system, including the spreadsheets and the shared drives, not only the main database.
What should concern you
An answer that only describes the official system. The unofficial ones are where the risk usually sits.
Do we hold data about people who are vulnerable, and is it treated differently?
A good answer
Describes specific controls.
What should concern you
That it is held in the same way as everything else because nobody has separated it out.
If we had a data breach on Monday, what would happen?
A good answer
Describes who is called, in what order, and who decides what gets reported.
What should concern you
That the plan exists in one person’s head, or does not exist.
Who has access to systems who should no longer have it?
A good answer
Describes a leavers process that includes system access, and evidence it has been followed.
What should concern you
Nobody having checked. Former staff, former volunteers and former trustees frequently retain access for years.
Section 4
Suppliers and dependency
Who are our technology suppliers, what do they do, and when were the contracts last reviewed?
A good answer
A short list with dates.
What should concern you
A long-standing relationship nobody has examined because examining it feels like a criticism.
If our main supplier doubled their price, what would we do?
A good answer
Describes realistic alternatives.
What should concern you
That the honest answer is that the charity would pay. That is a supplier relationship you do not control.
Can we get our data out, in a usable form, and has anybody tested it?
A good answer
Somebody has actually tried and the export worked.
What should concern you
Confidence based on the contract rather than on a test. I have seen more than one export function that technically existed and produced something nobody could use.
Who is checking that we get what we pay for?
A good answer
Names somebody internal with the standing to challenge.
What should concern you
That the only person evaluating the supplier’s work is the supplier.
Section 5
Artificial intelligence
Most charities have adopted at least one AI tool in the past two years. Far fewer approved it at board level, and the advice arriving from outside is currently the worst in this whole document. It tends to come as enthusiasm about efficiency, usually from somebody with something to sell.
None of that argues for avoidance. It argues for asking.
What AI tools are being used in this organisation, and who approved them?
A good answer
A list, with names against it.
What should concern you
That nobody knows, because tools were adopted by teams rather than procured centrally. This is extremely common and it is not a disciplinary matter. It is a governance gap.
What organisational data goes into these tools?
A good answer
Specific about what goes in, from which systems, and who decided that.
What should concern you
Vagueness. For a charity holding data about vulnerable people, vagueness here is itself the finding.
What decision would we never let an AI tool make on its own?
A good answer
Has been written down. Eligibility, safeguarding, hiring, anything affecting an individual’s access to a service.
What should concern you
That everybody agrees in principle and nothing is recorded. A boundary in people’s heads is not a control.
If the supplier changed the price or withdrew the tool, what would we lose?
A good answer
Treats this as a dependency question, because that is what it is.
What should concern you
That a tool has quietly become the way a team works, with no plan for its absence.
Can anybody here explain, in plain terms, how it reaches its answers?
A good answer
Describes the shape of it. What it was built on, what it is good at, where it is known to be unreliable.
What should concern you
That nobody can, because that means the charity cannot defend a decision the tool influenced.
Section 6
Accessibility
For a charity this is not a design preference. It is a legal duty in most cases, and it is also a mission question. If you exist to serve people including disabled people, and your main digital service excludes some of them, that is worth a board conversation regardless of what the law requires.
Which accessibility standard do we work to, and who confirmed we meet it?
A good answer
Names a standard, commonly WCAG 2.2 at level AA, and a person who assessed it.
What should concern you
The second half being unanswerable. Somebody’s name should be attached.
When was our website last tested, and how?
A good answer
Includes testing beyond automated tools. Somebody has tried to complete the main task using a keyboard alone, or with a screen reader.
What should concern you
A report from an automated checker. Those catch roughly a third of issues and will not tell you whether a form is usable.
What did we find, and what have we not fixed?
A good answer
A list with a plan, which is a defensible position.
What should concern you
No list, which means the charity cannot demonstrate it ever looked.
Is accessibility in the specification for the next thing we build?
A good answer
Yes, in writing, in the brief.
What should concern you
The assumption that the supplier will handle it. Specified up front it costs very little. Retrofitted it is a project.
Section 7
If the key person left tomorrow
Every charity I have worked with has one. Somebody who understands how the systems fit together, usually alongside their actual job, often without it appearing anywhere in their role description.
Who is that person here, and what would we lose?
A good answer
Names them and has thought about it.
What should concern you
That the question produces recognition and laughter but no plan.
Are passwords and system access held anywhere other than in one person’s head?
A good answer
Describes a shared, secure arrangement that more than one person can reach.
What should concern you
A personal password manager, a spreadsheet, or a memory.
Who else could keep things running for a month?
A good answer
Names a second person, even a partial one.
What should concern you
Nobody, and no plan to change that.
Are we building internal capability or increasing our dependence on outsiders?
A good answer
Shows staff learning to do more over time.
What should concern you
A pattern where every new need becomes a new supplier. That is how small charities end up with technology costs they cannot reduce.
What to do with the answers
You will finish this with a mix of confident answers, partial ones and blanks.
The blanks are the useful part. Not because they represent failure, but because they are the things nobody had been made responsible for, which is a different and more fixable problem.
Three things worth doing next.
Record where the answer was vague
Vagueness in the minutes is a finding. It gives the next board the starting point this one did not have.
Pick one thing
Not seven. The list of technology spend is usually the best first move, because it is dull, it takes an afternoon, and it produces something concrete that every other question then becomes easier to answer.
Put one section on each board agenda
Seven sections, quarterly meetings, and inside two years the board has genuine oversight built up gradually rather than a policy nobody reads.
Take it into the meeting
Print this page and the checkboxes work on paper. Or have the formatted version sent over, which is the same twenty-nine questions laid out for a board pack.
Share this freely with other boards. It is more useful passed on than kept.
If a section produced more blanks than answers
I advise trustee boards independently, and the honest answer is frequently that things are in better shape than the board feared.
Thirty minutes will usually establish which situation you are in.
Book a free 30-minute call