Here is the uncomfortable truth about website sign-off: legal approves a snapshot, and then marketing keeps publishing. The wording you reviewed in March is not the wording that is live in July. Somebody strengthened a claim, deleted a "boring" disclaimer, launched a landing page that never crossed your desk, or let an old promotion keep running long after its terms changed.
This is not a people problem, it is a process problem: legal review is periodic, websites change continuously. This guide covers what actually drifts, why the regulatory stakes have gone up, and how legal and compliance teams are using automated monitoring to close the gap without becoming the website police.
The approval gap
Most organisations have decent controls at launch: legal reviews the site, the claims, the terms, the privacy policy. The gap opens afterwards, because the website is edited by people optimising for conversion, not compliance, and every edit is a chance for approved wording to quietly disappear:
- Claims get stronger over time. "Helps improve" becomes "improves" becomes "guaranteed". Each edit looked harmless to the person making it.
- Disclaimers and footnotes get deleted. They are the first casualty of every redesign, because to a designer they are clutter.
- Pages nobody remembers stay live. Old campaign landing pages with expired offers, superseded terms, or pricing that no longer exists.
- Legal pages get edited without legal. A well-meaning colleague "tidies up" the terms or pastes a template privacy policy over the bespoke one.
- Sustainability claims creep in. "Eco-friendly", "carbon neutral", "100% recyclable", added by marketing in good faith, each one a green claim that needs substantiation.
Why the stakes have risen
Two shifts make website wording a live legal risk rather than a housekeeping issue. First, UK regulators have moved from guidance to enforcement on marketing claims: the CMA's Green Claims Code set clear expectations on environmental claims, and the Digital Markets, Competition and Consumers Act gave the CMA the power to fine businesses directly, up to 10 percent of global turnover, for unfair commercial practices, no court case required. Misleading claims on a website sit squarely in scope.
Second, the ASA has become systematic: it actively monitors online advertising at scale, and a website page is advertising. Add sector regimes on top, health claims, financial promotions (which we cover in a separate guide for finance teams), and the website is often the largest unreviewed surface the business publishes.
What "monitoring" means for a legal team
The fix is not more sign-off meetings. It is making the website report its own changes, so legal reviews what changed instead of re-reading everything, or worse, finding out from a regulator's letter. In practice that is four layers:
1. Change alerts on the pages that matter to you
Terms, privacy policy, cookie policy, pricing pages, key product claims pages. Any edit triggers a notification showing exactly what changed. Ten seconds to read, and nothing on those pages moves without you knowing. This is standard content monitoring.
2. Must-contain rules
The approved disclaimer, the mandatory wording, the required footnote: encode each as a rule that says "this page must always contain this text". The day a redesign drops it, you get an alert, not a complaint.
3. Policy-based checks on everything else
The newer layer, and the one that changes the game for legal teams: give the system your actual policies, the claims you never make, the wording standards, the tone rules, the sustainability position, and AI-powered checks read every page against them, flagging content that contradicts what you have stated. TLDTrack's compliance checks work exactly this way: upload the policy documents, and each scan judges the site's real content against your rules, so "marketing added a guarantee we do not offer" surfaces as a finding, not a surprise.
4. An evidence trail
Every check, change and resolution is logged. When a regulator, insurer or acquirer asks "what controls do you have over published claims?", you have a running record of oversight rather than a shrug. Demonstrable monitoring is itself a mitigating factor in most enforcement regimes.
A workflow that does not make legal the bottleneck
- Write down the rules you actually enforce. Most teams have them scattered across email threads and memory. A one-page claims policy is enough to start.
- Put the crown jewels on change alerts: legal pages, pricing, top product pages.
- Encode the must-never and must-always wording as rules.
- Run policy checks on a schedule and treat findings like a review queue: confirm, fix, or update the policy.
- Keep the log. It is your audit trail and your renewal-conversation evidence in one.
None of this replaces legal judgement, the point is that judgement gets applied to a short list of real changes instead of an unreadable whole. For the broader foundation, cookie consent, company information, accessibility, see our plain-English website compliance guide. And as ever: this is practical guidance, not legal advice.
