Is your board getting accessibility governance right?
Posted on by Léonie Watson in Strategy
Tags: Corporate governance
When it comes to digital matters, most boards consider privacy, security, and, increasingly, AI risk. But all too often, accessibility risk is not managed with the same level of discipline. Whereas accessibility delivery can be delegated, accountability for accessibility risk oversight cannot.
According to the G20/OECD Principles of Corporate Governance, the board is responsible for ensuring there are systems in place for finding, monitoring, managing, and disclosing financial and non-financial risks. National frameworks like the UK Corporate Governance Code echo this expectation, as do US legal and regulatory expectations around board oversight.
Why is accessibility risk so often overlooked?
One reason accessibility does not get executive attention is that it's often discussed in technical terms, like conformance with the Web Content Accessibility Guidelines (WCAG) or compatibility with assistive technologies. Another is that accessibility is regarded as an operational matter where responsibility is delegated to the teams on the production frontline of product and service delivery and thus is taken care of.
Yet, the consequences of inaccessible products and services can have an impact on revenue, profitability, reputation, procurement, operational efficiency, and even mergers and acquisitions.
Accessibility risk manifests when:
- A customer cannot complete a transaction without calling customer support
- An employee cannot use an internal system without a workaround that everyone pretends is OK
- A product launch is delayed because regulatory compliance was considered too late
- A procurement response requires evidence of product accessibility, but the organization has nothing to show
- Accessibility complaints are managed in isolation instead of being recognized as a systemic problem
- A customer or an employee exercises their legal rights to use accessible products and services
- An acquisition fails because of an ongoing legal case against the organization
These are all business risks. What goes onto the risk register will depend on the organization and its risk appetite, but there are some common patterns.
As with all risks, the board needs to be clear about which types of accessibility risk it is prepared to tolerate, which require mitigation, and which are unacceptable because of their legal, commercial, operational, or reputational impact.
Legal and regulatory exposure
This is the accessibility risk that most people recognize, but even so, it's often misunderstood. The board doesn't need to know about every accessibility regulation in every jurisdiction, but it does need to know:
- What are the organization's obligations?
- Who in the organization is accountable?
- Is there evidence that the organization is meeting its obligations?
Accessibility legislation continues to evolve around the world, so you need to be confident that the proper ownership and controls are in place for keeping pace with changes and meeting legal and regulatory requirements.
Customer exclusion
If disabled customers are unable to use your organization's products and services, they're prevented from doing business with you. This can mean lost revenue, more operational cost due to increased calls to customer support, and reputational damage as customers abandon their journey and take their frustration to social media.
Even organizations that extensively measure and analyse customer experience know little about the experiences of their disabled customers, and that gap is a risk.
It's also worth noting that customers and employees are not the only relevant stakeholders. Regulators, enterprise buyers, public-sector procurement teams, investors, advocacy groups, and the media may all influence how accessibility risk materializes.
Operational inefficiency
Inaccessible products and services create work. Sometimes that work is clear - teams spend time responding to avoidable complaints, product roadmaps are disrupted by urgent accessibility remediations, or product releases are delayed. At other times the work is hidden - inaccessible internal systems reduce employee productivity, teams must put in place exceptions to processes, or customers have to rely on workarounds because repeatedly raising the issue with customer support is exhausting.
Either way, your organization is liable for the cost of that work, but unless the proper ownership and controls are in place, the true extent of the risk may not be realized.
Digital transformation
Eventually, most organizations will rebrand, change platforms, replace legacy systems, redesign products and services, or introduce new modern technologies, sometimes several of these things at once.
These activities are often closely associated with the organization's strategic direction, so it's important for the board to assess the true cost, risk, and feasibility of major transformation activities by considering accessibility during strategic analysis, option appraisal, investment approval, procurement, delivery planning, and post-implementation review.
If accessibility isn't considered from the first proposal onwards, and if it isn't factored into the budget before it's approved, the risk is that accessibility debt will begin accumulating almost at once. Like technical debt, accessibility debt is expensive and inconvenient, but with the added risk of becoming publicly damaging or legally actionable if not managed effectively.
Risk register
An effective risk register drives meaningful discussion and enables the board to ask critical questions. For example:
- Who is accountable for managing accessibility risk across the organization?
- Which business critical customer journeys are not accessible?
- How is accessibility risk assessed for strategic transformation activities?
- What accessibility requirements exist within our procurement processes?
- How are we measuring the experiences of disabled customers and employees?
- What trends are appearing from accessibility-related complaints and support requests?
- Where do we have the greatest concentration of accessibility debt?
- How is accessibility assessed before major technology decisions are made?
A risk register should show where the organization is exposed to accessibility risk, what the likely impact is, who owns the risk, what controls exist, and whether those controls are working.
Typical controls might include clear executive ownership, accessibility requirements for procurement, product accessibility standards, needed accessibility testing before launch, evidence of conformance for critical products and services, analysis of complaints and support channels, and remediation plans for known accessibility debt.
Conclusion
Accessibility risk needs ordinary, disciplined, and mature risk oversight. Without this, you put revenue, profitability, reputation, procurement, operational efficiency, and potential mergers and acquisitions at risk.
A useful way to gauge if this has been achieved is to ask whether the board would feel confident explaining the organization's position on accessibility risk to customers, employees, regulators, investors, or the media?
If the answer is "no", then it's a clear signal that it's time for the board to start managing its accessibility risk.
Next steps
If you'd like to talk about how your organisation approaches accessibility risk and governance, you'll find me as Léonie Watson on LinkedIn.
We like to listen
Wherever you are in your accessibility journey, get in touch if you have a project or idea.