Blog

What's In an Accessibility Audit Report? A Section-by-Section Sample

TestParty
TestParty
September 25, 2026

Last updated: September 25, 2026

A professional accessibility audit report has eight sections: cover and scope, executive summary, methodology, findings register, severity model, fix specifications, retest plan, and conformance statement. Anything less is a scan export with a logo on it. This page walks each one with a sample excerpt from a composite report for an anonymized mid-size Shopify apparel brand, plus the buyer's quality check; the end-to-end audit process covers the testing that produces them.

Key numbers: WCAG 2.2 defines 86 success criteria, 55 at Levels A and AA β€” the full set a Level AA report must account for, passes included (W3C). In 2026, 95.9% of the top million home pages had detectable WCAG failures, averaging 56.1 errors per page (WebAIM Million 2026). Automated tooling detects roughly 60–70% of issues in TestParty's audit work; the other 30% is manual, and that is where blockers sit.

1. Cover and scope: what must it pin down?

The cover fixes four variables: the property tested, the standard and version, the evaluation window, and the sample. Without all four, every later claim is uncheckable.

Property: shop.example.com β€” storefront and checkout, mid-size Shopify apparel brand Standard: WCAG 2.2 Level AA; EN 301 549 mapping in Appendix B Evaluation window: August 3–14, 2026 Sample: 14 structured templates (home, collection, product, cart, checkout steps 1–3, account, search, blog, 404, size guide, store locator) plus 2 random pages Environments: Chrome and Firefox on Windows; Safari on macOS and iOS Version: 1.0, issued August 19, 2026

-

Quality check: the dates and sample list are what an opposing expert reads first. "The website" is not a scope statement.

2. Executive summary: what does a non-technical reader need?

One verdict, three counts, and the top three risks, on one page. It is the only section most stakeholders read, so it states conformance plainly, not as a grade.

Conformance status: Does not conform to WCAG 2.2 Level AA. Criteria: of 55 Level A and AA criteria evaluated, 38 passed, 12 failed, 5 not applicable. Findings: 47 total β€” 3 blocker, 9 critical, 21 major, 14 minor. Top three risks: a newsletter modal trapping keyboard focus site-wide (2.1.2, Level A); cart-drawer controls with no accessible name (4.1.2, Level A); checkout fields labeled only by placeholder text (3.3.2, Level A), which scanners report as a pass. All three sit on the path to order confirmation.

-

Quality check: conformance is binary per criterion, so a summary leading with a 78% "accessibility score" and no pass/fail counts is marketing.

3. Methodology: how was the site actually tested?

The methodology names the sampling method, tools, assistive-technology matrix, and evaluators. It makes the verdict repeatable β€” and it is the first section padded when an audit was mostly automated.

Testing followed W3C's WCAG-EM methodology, the 14-template structured sample supplemented by a random sample equal to 10% of it. Each page got an automated pass β€” axe-core, WAVE, Lighthouse β€” then manual evaluation: keyboard traversal, NVDA and JAWS with Chrome, VoiceOver with Safari, 200% and 400% zoom, reflow at 320 CSS pixels. Complete processes were tested end to end, cart through confirmation.

-

Quality check: a scanner-only methodology leaves roughly 30% of the issue surface unevaluated. In TestParty's monthly expert audits across 100+ brands, the findings that stop a purchase β€” focus traps, unnamed controls, unannounced errors β€” come from that manual layer.

4. Findings register: what does one finding record contain?

Every finding is a self-contained record with eleven fields, so it moves into a ticket without translation. Four worked findings β€” contrast, keyboard trap, unnamed buttons, placeholder labels β€” appear in our WCAG audit reference. Here is a fifth.

+-----------------------+----------------------------------------------------+
|         Field         |                   Sample: F-052                    |
+-----------------------+----------------------------------------------------+
|           ID          |                       F-052                        |
+-----------------------+----------------------------------------------------+
|   Success criterion   |          1.1.1 Non-text Content (Level A)          |
+-----------------------+----------------------------------------------------+
|        Severity       |                      Critical                      |
+-----------------------+----------------------------------------------------+
|        Location       | Collection template, `.card__media img`, 240 instances |
+-----------------------+----------------------------------------------------+
|      Description      | Alt attributes output the CDN filename β€” `alt="ss26_crew_04_navy_1200x.jpg"` β€” on every product card |
+-----------------------+----------------------------------------------------+
|      User impact      | Screen-reader users hear filenames and cannot tell products apart in a collection |
+-----------------------+----------------------------------------------------+
|    Evidence method    | NVDA + Chrome, confirmed in the accessibility tree; unflagged by axe-core, which sees a non-empty alt attribute |
+-----------------------+----------------------------------------------------+
|   Fix specification   | Bind alt to the product title in the card snippet; `alt=""` on decorative badges |
+-----------------------+----------------------------------------------------+
|         Effort        |       S β€” one Liquid snippet, template-wide        |
+-----------------------+----------------------------------------------------+
|         Owner         |               Storefront engineering               |
+-----------------------+----------------------------------------------------+
|         Status        |           Open; retest due September 12            |
+-----------------------+----------------------------------------------------+

Quality check: each missing field costs a round trip. F-052 also shows why scanners cannot close an audit: filename alt text passes every automated rule and fails 1.1.1 for every user.

5. Severity model: how are findings prioritized?

Severity is defined before testing and applied consistently, scoring three inputs: user impact, legal exposure, and fix effort. Labels without published definitions are sorting, not prioritization.

+--------------+--------------------------------------------------+--------------------------------------------+--------------------------+
|   Severity   |                   User impact                    |               Legal exposure               |        Fix window        |
+--------------+--------------------------------------------------+--------------------------------------------+--------------------------+
|   Blocker    |       Task impossible with assistive tech        |   Highest β€” what demand letters describe   |   Before next release    |
+--------------+--------------------------------------------------+--------------------------------------------+--------------------------+
|   Critical   |          Completable only by workaround          |      High β€” Level A on a revenue path      |         14 days          |
+--------------+--------------------------------------------------+--------------------------------------------+--------------------------+
|    Major     |   Real friction; Level AA on a common template   |       Moderate β€” cited cumulatively        |         30 days          |
+--------------+--------------------------------------------------+--------------------------------------------+--------------------------+
|    Minor     |            Localized, no task blocked            |                    Low                     |   Next quarterly cycle   |
+--------------+--------------------------------------------------+--------------------------------------------+--------------------------+

Quality check: effort breaks ties inside a band, never downgrades one β€” a blocker that takes two days is still a blocker.

6. Fix specifications: what separates a spec from advice?

A fix specification names the file, supplies corrected code, cites the criterion it satisfies, and states the acceptance test. Advice restates the problem in nicer words and bills for it.

Advice (not actionable): "Images are missing meaningful alternative text. Add descriptive alt text to all images."

-

Specification (actionable): In `snippets/card-product.liquid`, replace `alt="{{ product.featuredimage.src }}"` with `alt="{{ product.featuredimage.alt | default: product.title | escape }}"`, and set `alt=""` on the decorative sale badge in the same snippet. Satisfies 1.1.1 Non-text Content (Level A). Acceptance test: NVDA announces the product title on each card; axe-core reports zero `image-alt` violations on the collection template.

-

Quality check: ask for one redacted fix spec before signing. No file path, no code, no acceptance test means paying an engineer to re-diagnose all 47 findings.

7. Retest and verification: what counts as closed?

A finding is closed when the same evaluator retests the same location by the same method and records a date. "Ticket marked done" is not verification, and neither is a clean scan.

Retest window: 30 days from fix delivery, on the original 14-template sample plus a regression pass on any template the fixes touched. Automated thresholds, per template: Lighthouse accessibility 90+, WAVE errors ≀5, axe violations ≀3. Manual verification: every blocker and critical finding retested with the AT pairing that surfaced it. Evidence retained: dated before-and-after exports, screen-reader notes, a Closed date per finding.

-

Quality check: those thresholds are TestParty's post-remediation reference standard β€” a regression floor, not a conformance result. A page can hit all three and still fail 1.1.1, as F-052 does. Pressure-test the scope with a 30-point checklist.

8. Conformance statement and the compliance file

The closing section states what can honestly be claimed β€” standard, level, scope, date, method β€” and what is excluded. There is no ADA certification and no W3C certification of websites, so "certified accessible" has no referent.

As of August 19, 2026, shop.example.com partially conforms to WCAG 2.2 Level AA β€” "partially conforms" meaning some content does not fully conform. The claim covers the 16 sampled URLs in Appendix A, with the technologies in Section 3. Third-party review and chat widgets are recorded in the register and excluded.

-

Quality check: the Department of Justice has not adopted a technical web standard for private businesses and points to WCAG as guidance (ADA.gov), so the dated record β€” not a badge β€” is what counsel or procurement weighs. Filed with your scans and remediation logs, it anchors the compliance file worth keeping.

What are the red flags in a weak audit report?

Five. Screenshots without criteria: annotated images with no success-criterion numbers cannot be mapped, tracked, or defended. Failures only: a conformance answer covers all 55 criteria, so no record of passes means no claim. No methodology: no sample, tools, AT matrix, or credentials. Advice instead of specs. No severity definitions or retest plan. Quick test: if one rule description repeats across 200 pages of appendix, you bought a CSV export with a cover.

What happens after the report lands?

The audit-only trap is the common outcome: the report arrives, findings become a backlog, sprints fill with revenue work, and the next release ships new violations on top of the old ones. An audit measures; it does not fix.

The way out is treating the register as a work queue with owners and dates, then verifying against the same sample. TestParty runs both halves: a 14-day initial remediation cycle turning findings into source-code pull requests, then daily AI scans plus monthly expert manual audits with date-stamped reports. In the history of the company, fewer than 1% of TestParty customers have been named in accessibility lawsuits while on the platform; in one public matter, documented remediation helped Dorai Home settle a $74,999 demand for $2,000. See how findings become merged source-code fixes.

Frequently Asked Questions

Is an accessibility audit report the same as a VPAT? No. The audit report is an internal working document: every finding located and specified so engineers can fix it. A VPAT and the resulting Accessibility Conformance Report summarize conformance per criterion for procurement. The audit is the evidence; the ACR is the statement drawn from it.

How long should an accessibility audit report be? Length is a poor proxy for quality. Judge density instead: does every finding carry a criterion number, a template and selector, a user-impact line, and a code-level fix? A 30-page report meeting that bar beats 200 pages of rule descriptions.

Who should receive it inside the company? Three readers, three sections. Engineering works from the register and fix specifications. The executive sponsor needs the summary and severity counts. Counsel needs the scope statement, methodology, and dates β€” what was tested, and when.

Should we publish our audit report? Most companies publish an accessibility statement and conformance claim rather than the full register β€” an open list of unfixed Level A failures on your checkout is a roadmap for anyone looking. Publish the statement, standard, and date.

How can I tell a real audit report from a scan export? Look for findings no scanner produces: focus traps, illogical focus order, filename alt text, unannounced form errors, meaningless link names. If every finding maps to an automated rule name, it is a scan with formatting.

Humans + AI = this article. TestParty uses a cyborg approach to content β€” combining human accessibility expertise with AI capabilities to produce accurate, comprehensive guides. This content is for educational purposes and reflects our analysis of publicly available information as of the publication date. TestParty competes in the digital accessibility market, and we encourage readers to evaluate all solutions independently based on their specific needs.

Stay informed

Accessibility insights delivered
straight to your inbox.

Contact Us

Automate the software work for accessibility compliance, end-to-end.

Empowering businesses with seamless digital accessibility solutionsβ€”simple, inclusive, effective.

Book a Demo