Computer Usage Policy
Computers and digital systems are now part of everyday life in most members’ clubs. Even small clubs that operate largely in cash will usually rely on computers for banking, payroll, emails, stock control, and dealing with HM Revenue & Customs.
Used sensibly, these systems can make administration easier and improve compliance. Used without thought or control, they can expose the club to financial loss, disruption, and unnecessary risk.
Most clubs use a number of computer-based systems as part of day-to-day administration. These typically include:
Online banking
Many clubs now manage their bank accounts online rather than using cheques. This allows quicker payments and easier access to statements, but it represents a significant change from traditional controls.
Email
Email is the main method of communication with suppliers, advisers, banks, HMRC, and members. It is often used to receive invoices, bank messages and official correspondence.
Accounting and bookkeeping records
Some clubs use simple spreadsheets, while others use small-business accounting software packages. These accounting software packages are usually designed for commercial businesses and can be more complex than a club actually needs, but where used they still hold important financial records.
Payroll systems
Because of PAYE reporting requirements and pension auto-enrolment, most clubs now use payroll software or an outsourced payroll provider. These systems contain sensitive personal and financial information.
Membership and bar systems
Some clubs also hold membership records electronically or use basic till or card payment systems at the bar. Even simple bar systems can store financial data and connect to the internet.
HMRC online access
Clubs are issued with digital credentials that allow access to HMRC online services for payroll, VAT and other filings. Without these access details, statutory returns cannot be submitted.
In many clubs, these systems are operated by volunteers and are often accessed using home laptops, tablets or mobile phones. This is common and understandable, but it needs to be recognised and managed.
The move towards digital systems has changed the nature of risk faced by clubs. While internal error or misuse remains a concern, external threats are now increasingly common.
Online banking and fraud
Online banking removes the physical safeguards that existed with cheques. In some cases, a single individual can initiate payments without a second person being involved.
Clubs are also regularly targeted by external fraudsters. Common examples include:
These communications can be convincing and have resulted in substantial losses for clubs.
Email misuse and loss of control
Where a club relies on a personal email account, problems can arise when an officer is unavailable or leaves office. Important correspondence can be missed, access lost, or emails intercepted without the committee realising.
Loss of access on change of officers
A recurring difficulty arises when a Secretary or Treasurer leaves and passwords, HMRC access codes or banking details cannot be found. Regaining access can take time and may lead to missed deadlines, penalties, or disruption to the club’s affairs.
Cyber risk and data loss
Clubs now hold sensitive information electronically, including payroll details and bank information. Risks include:
Devices used for club business should have up-to-date anti-virus and security software. Even a small club can be seriously affected if systems fail or data is lost.
These risks do not require complex or expensive solutions. What matters most is clarity, oversight and common sense.
Online banking controls
Good practice is to require dual authorisation, so that no payment can be completed without approval by at least two authorised officers. Any request to change bank details or payment instructions should always be independently verified.
Passwords and access details
Passwords should be strong, kept secure, and not shared unnecessarily. Critical access details (such as HMRC credentials) should be recorded securely so that they can be accessed if an officer leaves unexpectedly.
Clear responsibility and oversight
Committees should agree who is responsible for operating key systems: –
Club email account
Clubs should operate a dedicated club email address rather than relying on personal accounts. Access should be controlled, but more than one officer should be able to view the inbox to ensure continuity and oversight.
Use of personal devices
Where officers use their own phones or laptops for club business, basic safeguards should apply. Devices should be protected by a PIN or password, and club information should be deleted when the officer leaves office.
Back-ups
Important data should be backed up regularly. At least one copy should be kept separately from the main device, whether securely stored or cloud-based, to protect against loss or failure.
Succession planning
Before introducing new systems, committees should ask a simple question: what happens if the person running this leaves tomorrow? Systems should be chosen with simplicity and continuity in mind, particularly given that officers are often volunteers.
Final observations
Computer systems can greatly improve efficiency and help clubs meet their obligations, but they also introduce new risks if poorly controlled or overly reliant on individuals. With clear oversight, simple controls and an awareness of the risks, committees can ensure that technology supports the club rather than becoming a source of difficulty.