ON THE RECORD · NO. 17 · THE CRAFT

How to pass a website review before it starts

Legal, IT, procurement, and the rating services all review your website, mostly without telling you. What they look at, and what to have standing before they arrive.

How to pass a website review before it starts
“He skipped the punch list,” 1893
EDVARD MUNCH · THE SCREAM · NATIONAL GALLERY OF NORWAY

If you market in healthcare or financial services, your website gets reviewed more often by legal, IT, procurement, and rating services than by any single prospect. Most of those reviews happen without an email, and the site passes or fails them alone. Here is what those reviews look at, and what to have standing before they arrive. The laws behind them are in The pixel, the plaintiff, and your website, and this is the punch list.

A cookie banner a developer hand-rolled three years ago is a liability with a user interface. Consent belongs to a dedicated consent management platform, installed and updated as its own product. It should be geo-aware so each visitor gets the rights their jurisdiction requires, honor Global Privacy Control, serve the Do Not Sell or Share link where law names one, and keep the records of consent it will one day need to produce. Wire Google Consent Mode on day one. Retrofitting consent costs twice what installing it does.

Keep every pixel in one tag manager

An auditor should be able to read your entire tracking surface on one screen. Every tag goes in one tag manager, and none go in the theme or the pages. Tags your campaign partners add should gate on consent and load after the page paints. We watched a pair of campaign tags drag a mobile speed score from the 90s to the 60s with no code change anywhere. One container meant the culprit turned up in minutes.

Send form fills to the CRM, never the CMS

Every review eventually asks the same question about your contact form, which is where the person’s information goes. The answer should be the CRM, with the website storing nothing. Then deleting a person is one system’s job, the consent context rides with the record, and nobody discovers a decade of submissions sitting in a plugin table. One dedicated form per intent, so routing and attribution are native instead of rebuilt.

Keep the records reviews will ask for

Keep revisions on for every page and post, so who changed what and when is always answerable. Keep publish dates honest. Put required disclosures in synced blocks, so legal edits the language once and every placement updates. Map every published claim that carries a number to its source in one file, so a compliance pull is a lookup. Firms under books-and-records duties should archive the live site on a schedule, with a service built for that job.

Put publish rights in permissions

The review chain belongs in the CMS’s permissions, never in a policy memo. Writers and AI tools draft. A person with review authority holds the publish button. When the capability enforces the rule, nobody has to remember it, and the audit trail writes itself.

Set the accessibility target in writing

Target WCAG 2.1 AA and say so. Automated checkers catch the easy half, so run one manual pass per launch, a screen reader walk of the paths that make you money and a keyboard walk of every form. Where the brand knowingly trades a criterion, record the exception as the owner’s dated decision. A recorded exception reads as governance in any review.

Govern the AI and publish the policy

If the site runs AI features, each one needs rate limits, input validation, checks on what comes back, and a plain admission on the surface that it is AI. Then publish the house AI policy as a page on the site itself. One document becomes the positioning and the compliance answer at once, and your sales team will link to it more than you expect.

Set the security headers and close the quiet doors

Every response the site sends either carries its security headers or doesn’t, and scanners file each missing one. Frame protection with X-Frame-Options, content-type protection with nosniff, a referrer policy, and strict transport where the host serves it, all set once at the theme or the host and never touched again. Then the quiet doors. Generator tags and version banners off, so the site stops announcing its software to anyone who asks. A login that answers every wrong guess the same way, so it never confirms which usernames exist. Author lists closed at the API, the file editor disabled, and a security.txt at the standard address, because it is the first file a scanner looks for and it costs half an hour. Read your own report card at securityheaders.com.

Read your security grade before procurement does

Rating services score your domain the way bureaus score borrowers, and procurement teams buy the reports. The inputs are public, so check them yourself first. The headers and doors above are half of what feeds it. Set DMARC to enforcement, because a policy of none reads as spoofable in every report. Inventory your subdomains and retire DNS records when campaigns end, since a forgotten record can hand a subdomain to a stranger. Lock the domain at the registrar. Then scan yourself at launch with the free tools the raters draw from, SSL Labs for the certificate, so the grade procurement pulls is one you have already seen.

Write the IT answer sheet once

The questions never change. Where is it hosted, who patches it, where are the backups, when was a restore last tested, who has admin access, and who gets called at 2am. Answer them on one page, review the access list when people leave, and keep an uptime monitor that lives outside the building it watches. The review that drags a quarter is usually the one where these answers got assembled from memory.

None of this is marketing’s favorite work, and all of it is deal velocity. A review that closes in a week keeps a deal’s momentum, and a review that drags a quarter kills more of them than any headline ever will.

The fastest security review is the one you finished first.

Katie Clark signature
SIGNED & DATED · SEP 22, 2026 · WORK NO. 17
EXHIBITED SINCE SEP 2026
EVERY POST IS A SIGNED WORK
Get the next signed work first.
One piece a month. No filler, no reheated takes.
MORE FROM THE GALLERY
VIEW THE COLLECTION →
THANKS FOR VISITING. TIME FOR FIKA. THE SWEETSHOP IS OPEN

Discover more from JXT Collective

Subscribe now to keep reading and get access to the full archive.

Continue reading