# Accessibility audit report: [name of the site or product]

> Template version 1.1, 2026-10-07, from https://auricartisan.com/templates/accessibility-audit/
> The workbench on that page fills this report in for you, in your browser.
> Licence: CC0 1.0 (https://creativecommons.org/publicdomain/zero/1.0/). Copy it, change it and use it for anything; no credit needed.
> Replace everything in [square brackets], then delete this note.

| Report | |
|---|---|
| Report version | [1.0] |
| Date of report | [YYYY-MM-DD] |
| Audited by | [Name, role, organisation] |
| Reviewed by | [Name, or "Not reviewed"] |
| Prepared for | [Team or client] |

## 1. Summary

[Three to six sentences for someone who reads nothing else: what was tested, against which standard, the overall picture, the most serious problems, and what should happen next.]

| Severity | Open | Fixed, awaiting retest | Closed | Total |
|---|---|---|---|---|
| Critical | [0] | [0] | [0] | [0] |
| High | [0] | [0] | [0] | [0] |
| Medium | [0] | [0] | [0] | [0] |
| Low | [0] | [0] | [0] | [0] |

Results by criterion: [0] fail, [0] pass, [0] not present and [0] not checked, of the [55] criteria in WCAG 2.2, Level A and AA.

This report records an evaluation of the pages and processes in the scope below. It is not a conformance claim: it does not state that the site, or any page, meets WCAG 2.2.

## 2. Scope

| Scope | |
|---|---|
| Site or product | [Name and address] |
| Standard | WCAG 2.2, Level A and AA |
| Dates tested | [YYYY-MM-DD to YYYY-MM-DD] |
| Version tested | [Release, build or deployment date] |
| Out of scope | [Anything left out, and why] |

### Pages, screens and processes in the sample

| ID | What | URL or path | Kind | Why it is in the sample |
|---|---|---|---|---|
| P1 | [Home page] | [/] | [Common page] | [Most visited page] |
| P2 | [Sign in] | [/account/sign-in/] | [Essential function] | [Every customer uses it] |
| P3 | [Checkout, every step] | [/checkout/] | [Process] | [A complete process: tested from start to finish] |
| P4 | [...] | [...] | [Random] | [Picked at random] |

Kind is one of Common page, Essential function, Page type, Process or Random. WCAG-EM 2.0 asks for a random sample of at least 10% as many pages as you chose.

## 3. Method

- Automated checks: [tool and version], run on every page in the sample. Each automated result was confirmed by a person before it became a finding.
- Keyboard: every page used with the keyboard alone (Tab, Shift+Tab, Enter, Space, arrow keys, Escape).
- Zoom and reflow: text at 200%, and the page at 320 CSS pixels wide (400% zoom of a 1280 pixel window).
- Screen readers: [screen reader, version, browser and operating system for each].
- Browsers and devices: [each, with versions].
- Other checks: [contrast, text spacing, reduced motion, forced colours, captions ...].
- Not tested: [what was not covered, such as speech recognition software].

## 4. Severity scale

Severity measures the effect on people, not the level of the criterion: a Level AA failure can be critical and a Level A failure can be low.

| Severity | Meaning | Suggested response |
|---|---|---|
| Critical | Blocks a task: some people cannot complete it on their own, or are put at risk. | Fix now; hold the release if it is not out yet. |
| High | The task can be done only with serious difficulty or a workaround most people will not find, or important information is missing for some people. | Fix in the next release. |
| Medium | The task takes clearly more time or effort, or is confusing, but people get through it. | Plan the fix within a few releases. |
| Low | A minor annoyance or inconsistency with little effect on getting things done. | Fix when the area is next changed. |

## 5. Findings

The full register is in accessibility-findings.csv: one row per finding. Write the most important findings here in full.

### [AUD-000] [Title of the problem]

| Finding | |
|---|---|
| Location | [Page or component, URL or path, and where on the page] |
| WCAG criterion | [Number and name, such as 3.3.1 Error Identification] |
| Level | [A / AA / AAA] |
| Severity | [Critical / High / Medium / Low] |
| User impact | [Who is affected, and how] |
| Owner | [Team or person] |
| Status | [Open / In progress / Fixed - awaiting retest / Closed / Won't fix (reason)] |
| Found on | [YYYY-MM-DD] |

**Description.** [What is wrong, in plain words.]

**Steps to reproduce.**

1. [Go to ...]
2. [...]

**Expected.** [What should happen.]

**Actual.** [What happens instead.]

**Recommendation.** [How to fix it.]

**Retest.** [YYYY-MM-DD]: [Pass / Fail / Partly fixed], [by whom, with what].

### Example: AUD-001 Card errors shown only by a red border

| Finding | |
|---|---|
| Location | /checkout/payment/ - payment form |
| WCAG criterion | 3.3.1 Error Identification |
| Level | A |
| Severity | Critical |
| User impact | Screen reader users and people who cannot see red are not told that the card was rejected or which field is wrong, so they cannot pay. |
| Owner | Checkout team |
| Status | Closed |
| Found on | 2026-09-21 |

**Description.** When the card number, expiry date or security code is wrong, the field's border turns red. No text explains the error and focus does not move.

**Steps to reproduce.**

1. Go to /checkout/payment/ with an item in the basket.
2. Enter 1234 in Card number.
3. Press Pay now.

**Expected.** A message in text beside the field says what is wrong and how to fix it, the field is marked aria-invalid="true", and an error summary takes focus.

**Actual.** Only the border colour changes. Nothing is announced and focus stays on Pay now.

**Recommendation.** Describe each error in text beside its field and in a summary that takes focus, for example "Enter the 16-digit number on the front of your card". Pattern: https://auricartisan.com/accessibility-patterns/forms/

**Retest.** 2026-10-02: Pass - retested with the keyboard and a screen reader.

## 6. Results by criterion

The result for each success criterion in the scope: Pass, Fail, Not present (nothing on the pages is covered by it) or Not checked. A criterion fails while any finding on it is not closed. Every WCAG 2.2 criterion is listed in wcag-22-criteria.csv.

| Criterion | Level | Result | Findings |
|---|---|---|---|
| [1.1.1 Non-text Content] | [A] | [Pass / Fail / Not present / Not checked] | [AUD-000] |
| [...] | [...] | [...] | [...] |

## 7. Retests

Retest each fix with the steps, browsers and assistive technology that found it. Close a finding only after its retest passes.

| ID | Fixed on | Retest date | Retested by | Result | Notes |
|---|---|---|---|---|---|
| [AUD-000] | [YYYY-MM-DD] | [YYYY-MM-DD] | [Name] | [Pass / Fail / Partly fixed] | [What was checked] |

## 8. Limits of this report

- It covers the sample in the scope, on the dates tested. Pages and processes outside the sample were not tested.
- It is not a WCAG conformance claim. A claim needs every page it names to meet every criterion at the level, with complete processes, and must state its date, standard, level, pages and the technologies relied upon (WCAG 2.2, section 5).
- It is not legal advice. Whether a law applies, and which standard it names, depends on the jurisdiction. An automated scan on its own shows some failures; it cannot show that a site meets a law.
