What happens if your key IT person disappears?
Many charities rely on one person who “knows the IT” but this presents a hidden risk of siloed knowledge.
Many charities rely on one person who “knows the IT”.
It may be a staff member, a trustee, a volunteer, a long-standing supplier or someone who has helped the charity for years. They know where the passwords are, which systems talk to each other, who hosts the website, how the email accounts are set up, where the backups are, and what to do when something stops working.
This can feel efficient. The charity has someone trusted, responsive and familiar with the organisation.
But it can also create a hidden risk.
If that person leaves, becomes unavailable, falls ill, retires, changes role or simply becomes too busy, the charity may suddenly discover how much of its IT knowledge was sitting in one person’s head.
That is when small gaps can become serious problems.
A password cannot be found. A website renewal is missed. Nobody knows who has administrator access. A key spreadsheet is stored in the wrong place. A system licence is attached to someone’s personal email. Backups exist, but nobody knows how to restore them. A supplier relationship depends on one informal contact. A trustee thinks the staff team has control, while the staff team assumes the supplier does.
None of this necessarily means the charity has bad IT. It means the charity has not yet turned informal knowledge into organisational control.
This matters because IT is no longer a background function. It underpins almost everything a charity does: email, finance, fundraising, service delivery, safeguarding records, beneficiary data, trustee papers, website updates, cloud storage, donor communications and reporting.
If access, ownership and documentation are unclear, the charity becomes vulnerable.
One warning sign is when only one person can explain how things work. They may be helpful and capable, but the organisation is exposed if nobody else can access the information or understand the set-up.
Another warning sign is personal ownership. If key accounts, documents, domain names, software subscriptions or admin rights sit with an individual rather than the charity, continuity becomes fragile. This can happen innocently, especially in small charities that grew quickly or started with volunteer support.
A third warning sign is missing documentation. The charity may have the right systems, but no simple record of what exists, who owns it, who has access, when renewals happen and what to do if something fails.
This is not just an IT inconvenience. It is a governance issue.
Trustees do not need to understand every technical detail, but they do need assurance that the charity has control over its core systems. They should know that key access is not dependent on one individual, that data is protected, that backups are in place, that suppliers are clear, and that there is a basic continuity plan if something goes wrong.
The same applies to senior leaders. A CEO should not have to become an IT specialist, but they should be able to answer basic questions: who administers our email? Who owns our domain? Where are our passwords stored? Who can access beneficiary or donor data? What happens if our main IT contact is unavailable? How quickly could we recover if a system failed?
If those questions are difficult to answer, the charity has a risk to address.
The solution is not to make IT complicated. In fact, the best starting point is often very simple: create an IT control document.
This should list the charity’s main systems, suppliers, admin accounts, renewal dates, key contacts, backup arrangements and access permissions. It should explain where passwords are stored, who can access them, and what should happen if the usual IT contact is unavailable.
The charity should also review administrator access. There should usually be more than one appropriate person with access to critical systems, but not so many that control becomes loose. When staff or volunteers leave, access should be removed promptly. When trustees change, any system access linked to their role should be reviewed.
Backups and recovery need attention too. It is not enough to assume that cloud systems are safe. The charity should know what is backed up, how often, where it is stored and how recovery would work in practice.
Supplier relationships should also be clear. If the charity uses an external IT provider, website developer, CRM consultant or software specialist, the arrangement should not depend entirely on one informal relationship. There should be clear contact details, agreed responsibilities and a record of what the supplier manages.
This kind of work may not feel urgent until something goes wrong. But that is exactly why it matters.
A charity that has documented its systems, clarified ownership and planned for continuity can respond calmly when people change or problems arise. A charity that has not may spend days trying to reconstruct basic information at the worst possible moment.
A practical first step is to ask: if our key IT person disappeared tomorrow, what would we struggle to access, explain or recover?
That question can feel uncomfortable, but it is useful. It shows where the charity is relying on memory, goodwill or informal control rather than proper organisational ownership.
At 9 Mountains, we help charities look across IT, governance, risk, finance, fundraising and service delivery so the systems behind the mission are safer, clearer and more resilient. Good IT support is not just about fixing problems when they happen – it is about making sure the charity can keep moving when circumstances change.
Get more guidance like this
If you’d like regular, practical help for the journey, our Charity Trail Cards deliver short, actionable tools straight to your inbox, one clear step to steady your organisation each week.