Home / Risk management

What should a Shopify brand put in an ADA risk register?

Published October 2, 2026

An ADA risk register turns vague website risk into a managed list: every known exposure, who owns it, and what happens next. Here is what belongs in one and what does not.

Risk you cannot see is risk you cannot manage

Most Shopify brands carry ADA website risk as a feeling: a vague worry that a demand letter might arrive someday. Feelings do not get budgeted, assigned, or fixed. A risk register converts the feeling into a list, and lists can be worked. Every known accessibility exposure gets an entry, an owner, and a next action. That is the entire concept, and it is more powerful than it sounds.

The register is not a legal document and it does not need a lawyer to start. It is an operational tool. Its audience is the founder and the team, not a court. Keep it in plain language, keep it current, and keep it short enough that someone actually reads it.

Every entry answers four questions

Each risk in the register answers the same four questions. What is the exposure, described so a non-technical founder understands it. How likely is it to be the thing a demand letter cites, ranked high, medium, or low with a one-line reason. What is the current state: unassessed, assessed, being fixed, or accepted. And who owns the next action, by name, with a date.

The likelihood ranking deserves care. A keyboard trap on the checkout is high likelihood because it blocks purchases and is trivially demonstrable. A missing alt tag on a blog image is low. Rank by what a plaintiff firm would actually put in a letter, not by technical severity scores. Those are related but not identical.

What belongs in the register

Start with the money path: every barrier on the route from product page to order confirmation, because that is where demand letters point. Add the high-traffic templates: homepage, collection pages, the search experience. Add the third-party surface: the cookie banner, the reviews widget, the chat tool, the checkout extensions, because the brand is responsible for the whole page even when it did not build every piece.

Add the process risks, not just the page risks. No named accessibility owner. No re-scan after theme updates. Evidence scattered across inboxes. These are the entries that surprise founders, because they are not findings on a page. They are the conditions that let findings accumulate unnoticed, and plaintiff firms have learned to ask about them.

What does not belong in the register

Leave out the full scan output. The register is not a second copy of the audit; it references the audit. Leave out anything the team cannot act on: platform-level limitations belong in a workaround note, not as open risks nobody can close. And leave out legal strategy. The register says what the exposure is and what the team is doing about it. What the lawyer would argue about it lives with the lawyer.

Keep the register under twenty active entries. More than that and it becomes wallpaper. If the audit found eighty issues, the register holds the themes and the highest-risk items, and points at the audit for the rest. The register is the map, not the territory.

Review it on a rhythm or do not bother

A risk register reviewed once is a document. A risk register reviewed monthly is a system. Put thirty minutes on the calendar with the owner of the store accessibility work: close what got fixed, re-rank what changed, add what the month introduced. Theme updates, new apps, and redesigns each get a register check as part of their rollout, not after.

The review is also where accepted risks get re-examined. Accepting a risk is legitimate; accepting it forever without revisiting is not. Every accepted risk carries a review date. When the date arrives, the team decides again with fresh eyes, and the decision goes in the register either way.

The register is evidence of diligence

Here is the part founders miss: a maintained risk register is itself a defense asset. It shows a pattern of attention: risks identified, ranked, assigned, and worked. No register proves perfection, and none is expected to. What it proves is that the brand took the obligation seriously and acted on it systematically.

That is the standard that matters. Courts and settlements do not punish brands for having imperfect websites; they punish indifference. A risk register is the opposite of indifference, written down, dated, and signed by the work.