In-Depth Guide
The Complete Guide to Accessibility Audit
Our team has written a comprehensive guide covering technical specs, best practices, and the exact approaches we use on every project.
A website accessibility audit is something most business owners assume is somebody else’s problem. A nice-to-have, maybe, but not something that touches them directly. Then a customer emails saying they couldn’t complete a purchase using a screen reader, and it’s suddenly their responsibility.
We’ve sat across the table from enough UK businesses now to know the usual starting point. Someone ran their site through a free online scanner once. They got a score that looked reasonable. They marked accessibility as done. It rarely is.
WCAG 2.2 AA Compliance
Here’s what UK businesses actually need to know before assuming they’re covered.
| Question | Answer |
|---|---|
| Is website accessibility a legal requirement in the UK? | The Equality Act 2010 already applies to websites providing services to the public |
| What standard should a UK business aim for? | WCAG 2.2 Level AA is the recognised benchmark most requirements are built around |
| Does an automated scan prove compliance? | No. It catches mechanical issues but misses how the site actually behaves for a real user |
| Does the European Accessibility Act apply to UK firms? | Yes, if you sell products or services into the EU market |
| How long does a proper audit take? | Around two weeks, combining automated scanning with manual testing |
| What’s the biggest gap we typically find? | Forms and checkout flows that cannot be completed by keyboard alone |
That last row is worth sitting with for a second. Forms are usually where a business makes its money, and they’re also where accessibility most often quietly fails.
Why an Automated Scan Told You Everything Was Fine
In our testing across dozens of client sites, automated scanners are genuinely useful for one thing. They catch missing alt text, weak colour contrast, and a handful of other mechanical issues quickly and cheaply. What they cannot do is use your site the way a real person would.
We worked with a physiotherapy clinic group in the Southeast whose online booking form looked perfectly normal on screen. Their previous scanner report had come back clean. When we tested it with an actual screen reader, the form fields were read out in an order that made no logical sense, and the submit button had no accessible label at all, just announced as button with nothing telling a screen reader user what it actually did. Nobody had ever tried booking an appointment without using their eyes. Once we did, the problem was obvious within minutes.
That’s the difference between a scan result and a genuine audit. One tells you what a machine could detect. The other tells you what actually happens when someone tries to use your site.
What a Proper Audit Actually Checks
Getting past a surface-level scan means testing the things a tool simply cannot judge on its own.
- Keyboard navigation across every interactive element, to check if a person without a mouse can reach and use everything
- Screen reader testing on key journeys, like checkout, booking, or contact forms. Listen to how the site sounds. Do not assume it reads sensibly
- Focus indicators confirming every clickable element shows a visible marker when navigated to by keyboard, not just styled for mouse hover
- Heading structure reviewed for a logical order, since screen reader users often navigate by heading rather than reading top to bottom
- Dynamic content checked for proper announcement, covering things like form validation errors or content that updates without a page reload
- Colour and contrast verified beyond the basic pass or fail a scanner gives, checking real-world readability across your actual design
Miss any of these and a site can score well on paper while remaining genuinely difficult, sometimes impossible, for someone relying on assistive technology to actually use.
Where This Sits Alongside Your Other Compliance Work
Accessibility rarely exists in isolation from the rest of a site’s compliance picture. If your privacy policy and cookie consent setup haven’t been reviewed properly either, the two often need addressing together rather than separately. Our GDPR Website Compliance service covers that area. Many businesses come to us for an accessibility audit. They often need both checked in the same chat. This is because forms collect data and affect both areas.
Security matters here too, more than people expect. A site that’s been compromised or is running on outdated software often has accessibility regressions sitting alongside the security gaps, since neither has been maintained properly. If no one has checked either recently, consider an accessibility review. It works well with our Website Security Audit. This gives you the full picture, rather than fixing one thing while another goes unnoticed.
Building Accessibility In From the Start
Businesses that struggle least with accessibility plan for it during design, not after launch. Retrofitting later is much more expensive. If you’re already planning a redesign or a fresh build, that’s genuinely the best moment to get this right from the outset.
Our UI/UX design team builds accessibility considerations directly into the research and wireframing stage, checking tab order and contrast decisions before a single line of final design gets approved. It’s considerably cheaper to design a form correctly the first time than to rebuild it eighteen months later after a customer complaint or an audit finding forces the issue.
The European Angle Most UK Businesses Are Missing
Here’s something that’s catching a growing number of UK businesses off guard. If you sell products or services to customers in the EU, even as a smaller operation, the European Accessibility Act applies to you, and enforcement has been tightening steadily through 2026.
This isn’t a distant, theoretical requirement anymore. UK firms trading across the Channel now need to consider the Equality Act at home. They also need to meet EAA duties abroad. These rules do not always align perfectly. A proper WCAG 2.2 audit gives you the strongest foundation for satisfying both, since the technical standard sits underneath each set of legal requirements even where the exact enforcement mechanisms differ.
What This Actually Comes Down To
None of this needs to feel overwhelming. Most sites we audit have a handful of recurring issues, not hundreds of scattered problems. Fixing the genuinely important ones, the form that can’t be completed by keyboard, the checkout button with no accessible label- tends to matter far more than chasing a perfect score on every minor criterion.
Getting a proper audit done means finding out where you actually stand, rather than trusting a scanner result that was never built to test the things that matter most.