A report the people who fix things can act on: scope, method, a findings register with severity by user impact, a result for every WCAG criterion, and retests.Build it in the workbench on this page, or download the blank files.
Fill in the scope, list the pages you tested, log each finding, mark each criterion, then export the report as Markdown, HTML or CSV.Your work stays in this browser: nothing is sent to us.
Saved in this browserNot saved: this browser blocks storage. Download the workbench file to keep your work.
The audit at a glance
0Findings
0Still open
0Critical and open
0 / 55Criteria checked
Three to six sentences for someone who reads nothing else. Write it last, or start from a draft made from your findings.
The draft replaced the summary. Undo with Ctrl+Z.
Before you share the report
Nothing to check: the report says who tested what, when and how.
1 / 5
Choose the most used pages, one of each kind of page, the essential functions and every step of each process.Then add a random sample: WCAG-EM 2.0 asks for 10% as many pages as you chose.
0chosen0picked at randomStill to pick at random:1The random sample is big enough.
Pages, screens and processes in the sample
ID
What
URL or path
Kind
Why it is in the sample
Remove
No pages yet. Add the first one.
2 / 5
0shown
No findings yet.
Add one, import a findings register on the Export tab, or load the sample audit to see a finished one.
No finding matches these filters.
Finding deleted.
3 / 5
WCAG 2.2Level ALevels A and AALevels A, AA and AAA55criteria
Fail0
Pass0
Not present0
Not checked55
A criterion fails while any finding on it is not closed. Mark the others Pass, or Not present when nothing on the pages is covered by it, such as video on a site without any.
Some findings cite criteria outside this standard and level:
4 / 5
.md
The report
Markdown, the template's eight sections filled in. For a repository, a wiki or an email.
.html
A report to print
One file that opens in any browser and prints to PDF, with the findings and the results laid out.
.csv
Findings register
The template's 17 columns, one row for each finding. For a spreadsheet or an issue tracker.
.csv
Results by criterion
Every criterion in the scope with its result and its findings, in the columns of the criteria sheet.
.json
Workbench file
Everything on this workbench, to open here again later or to hand to a colleague.
The files are written in English, like the template, whatever language this page is shown in. What you typed is kept as you typed it.
Open a file
A workbench file (.json) replaces everything here. A findings register (.csv), from this template or a spreadsheet with the same headings, adds its rows to the findings.
Opened the workbench file.
Findings added from the register:0
That file is not a workbench file from this page.
That file has no Title column, so it is not a findings register.
Choose a .json or a .csv file.
Preview the Markdown report
Start again
Clearing empties the workbench in this browser. Download the workbench file first if you want to keep it.
5 / 5
Download
Three plain files
A report you fill in, in Markdown; the findings register as CSV for a spreadsheet or an issue tracker; and a sheet of every WCAG 2.2 criterion to record a result for each.All three are plain ASCII text in English, so they open the same everywhere.
# Accessibility audit report: [name of the site or product]
> Template version 1.1, 2026-10-07, from https://auricartisan.com/templates/accessibility-audit/
> The workbench on that page fills this report in for you, in your browser.
> Licence: CC0 1.0 (https://creativecommons.org/publicdomain/zero/1.0/). Copy it, change it and use it for anything; no credit needed.
> Replace everything in [square brackets], then delete this note.
| Report | |
|---|---|
| Report version | [1.0] |
| Date of report | [YYYY-MM-DD] |
| Audited by | [Name, role, organisation] |
| Reviewed by | [Name, or "Not reviewed"] |
| Prepared for | [Team or client] |
ID,Title,Location,WCAG criterion,Level,Severity,User impact,Description,Steps to reproduce,Expected,Actual,Recommendation,Owner,Status,Found on,Retest date,Retest result
AUD-001,Card errors shown only by a red border,/checkout/payment/ - payment form,3.3.1 Error Identification,A,Critical,"Screen reader users and people who cannot see red are not told that the card was rejected or which field is wrong, so they cannot pay.","When the card number, expiry date or security code is wrong, the field's border turns red. No text explains the error and focus does not move.",1) Go to /checkout/payment/ with an item in the basket. 2) Enter 1234 in Card number. 3) Press Pay now.,"A message in text beside the field says what is wrong and how to fix it, the field is marked aria-invalid=""true"", and an error summary takes focus.",Only the border colour changes. Nothing is announced and focus stays on Pay now.,"Describe each error in text beside its field and in a summary that takes focus, for example ""Enter the 16-digit number on the front of your card"". Pattern: https://auricartisan.com/accessibility-patterns/forms/",Checkout team,Closed,2026-09-21,2026-10-02,Pass - retested with the keyboard and a screen reader
Criterion,Name,Level,Since,Guideline,Result,Findings,Notes
1.1.1,Non-text Content,A,2.0,1.1 Text Alternatives,,,
1.2.1,Audio-only and Video-only (Prerecorded),A,2.0,1.2 Time-based Media,,,
1.2.2,Captions (Prerecorded),A,2.0,1.2 Time-based Media,,,
1.2.3,Audio Description or Media Alternative (Prerecorded),A,2.0,1.2 Time-based Media,,,
Each row is a criterion of WCAG 2.2 at Level A, AA or AAA, with the version that added it, so a 2.1 audit can leave out the newer ones.4.1.1 Parsing is not listed: WCAG 2.2 removed it.
Licence: CC0 1.0 Universal, a public domain dedication.You can copy, change and use all three files for any purpose, including paid work, without asking or giving credit.Delete the sample rows before you start, or keep them as a guide.
Structure
What goes in a good report
Seven parts, in the order a reader needs them.
A report is good when someone who was not there can see each problem, fix it and check the fix.
Summary.For people who read nothing else: what was tested, the overall picture, the worst problems and what to do next, with a count of findings by severity.
Scope.The pages, screens and processes in the sample and why each was chosen, the standard (WCAG 2.2, Level A and AA), the dates and the version tested.Test a process such as checkout from start to finish, every step.
Method.The automated tools and their versions; the checks by hand with a keyboard, at 200% text and at 320 CSS pixels wide, and with screen readers; the browsers and devices; and what was not tested.
Findings register.One row per problem, with its place, criterion, severity, effect on people, steps to see it, expected and actual results, a fix, an owner and a status.
Severity scale.Ratings based on what happens to people, defined once and applied the same way to every finding.
Results by criterion.Pass, Fail, Not present or Not checked for every success criterion in the scope, so the gaps in the testing show as clearly as the failures.
Retests.When each fix was checked again, by whom, with what, and the result. A finding closes only when its retest passes.
Findings register
Column by column
The CSV has these columns, in this order.They work as the fields of an issue template too.
Column
What to write
ID
A short, stable reference, such as AUD-001. Never reuse one.
Title
The problem in a few words, written so the person fixing it can find it in a list.
Location
The page or component, its URL or path, and where on the page.
WCAG criterion
The success criterion it fails, by number and name, such as 3.3.1 Error Identification.
Level
A, AA or AAA: the criterion's level, which is not the same as the severity.
Severity
Critical, High, Medium or Low, from the scale below: the effect on people.
User impact
Who is affected and what happens to them, in one or two sentences.
Description
What is wrong, in plain words, without assuming the reader knows the code.
Steps to reproduce
Numbered steps from a known starting point, so anyone can see the problem.
Expected
What should happen.
Actual
What happens instead.
Recommendation
How to fix it, with a technique or pattern where one helps.
Owner
The team or person who will fix it.
Status
Open, In progress, Fixed - awaiting retest, Closed, or Won't fix (with the reason).
Found on
The date of the test that found it, as YYYY-MM-DD.
Retest date
When the fix was, or will be, tested again.
Retest result
Pass, Fail or Partly fixed, and who retested it with what.
Severity
Rate the effect on people
Severity is about what happens to the people using the page, not about the level of the criterion.A Level AA failure can be critical, and a Level A failure can be low.
Severity
What it means
Sample finding
Suggested response
Critical
Blocks a task: some people cannot complete it on their own, or are put at risk.
The suggested responses are a starting point: agree your own with the people who plan the work, and write them in the report.
Not sure which? Answer three questions
Ask them in order, about the people the problem affects. The first yes is the severity; three noes make it Low.
Answer in order: the first yes is the severity.That makes it
Examples
Four sample findings
From a made-up shop, one at each severity: the same four rows as in the CSV, laid out to read.The paths are invented for the example: these are not findings about this site.
Screen reader users and people who cannot see red are not told that the card was rejected or which field is wrong, so they cannot pay.
Description
When the card number, expiry date or security code is wrong, the field's border turns red. No text explains the error and focus does not move.
Steps to reproduce
Go to /checkout/payment/ with an item in the basket.
Enter 1234 in Card number.
Press Pay now.
Expected
A message in text beside the field says what is wrong and how to fix it, the field is marked aria-invalid="true", and an error summary takes focus.
Actual
Only the border colour changes. Nothing is announced and focus stays on Pay now.
Recommendation
Describe each error in text beside its field and in a summary that takes focus, for example "Enter the 16-digit number on the front of your card".Pattern: accessible form errors
Owner
Checkout team
Found on
2026-09-21
Retest
2026-10-02Pass - retested with the keyboard and a screen reader
People who rely on a password manager, or cannot remember and retype a long password, must type it character by character; some cannot sign in at all.
Description
A script cancels paste in the Password field, and autocomplete="off" stops the browser's password manager from filling it.
Steps to reproduce
Go to /account/sign-in/.
Copy a password and paste it into Password with Ctrl+V.
Try to fill the form from the browser's password manager.
Expected
Pasting and password manager filling both work, so signing in does not depend on remembering or transcribing the password.
Actual
Paste does nothing and the password manager offers no fill.
Recommendation
Remove the paste blocker. Set autocomplete="current-password" on Password and autocomplete="username" on Email. See failure F109 in the WCAG techniques.
Owner
Accounts team
Found on
2026-09-21
Retest
Not yet
AUD-003MediumOpen
No visible focus on the sort and filter buttons
Location
/products/Sort and Filter buttons above the product grid
A sample of pages, screens and processes that you choose and list.
Every page it names, each one whole, and every step of each process on them.
What it says
The problems found, how serious they are and how to fix them.
That those pages meet every success criterion at the stated level.
What it must include
The scope, the method and the findings.
Its date, the standard and version, the level, the pages it covers, and the technologies they rely on.
What it is for
Finding and fixing problems, and tracking progress.
An accessibility statement, or a procurement or legal document.
A scan alone proves nothing legal
Automated tools find some failures quickly, but many criteria need a person to judge them.The W3C puts it plainly:Web accessibility evaluation tools can not determine accessibility, they can only assist in doing so.
Whether a law applies to a site, and which standard it names, depends on the country and the organisation.A clean scan does not show that a site meets any law, and neither does this report on its own.