Think Tank QA

Accessibility Audit

Independent, Fixed-Scope WCAG and ADA Conformance Audit

Trusted by product teams at leading enterprises and startups

An accessibility audit is an independent, fixed-scope evaluation of a website or application against the accessibility standards that apply to it.

Think Tank QA delivers an accessibility audit that combines AI-accelerated automated scanning with manual and assistive-technology testing led by experienced accessibility engineers, maps every finding to WCAG 2.1 and 2.2 success criteria, and flags the barriers that create legal exposure under the ADA and Section 508.

The engagement runs four weeks at a fixed bid of $15,000 to $20,000 and produces four documents:

  • an audit report,
  • an Accessibility Conformance Report (ACR or VPAT),
  • a prioritized remediation roadmap,
  • and an executive summary.

The result is a documented, defensible picture of where a product stands and a clear plan for closing the gaps.

When an Accessibility Audit Makes Sense

Most audits are triggered by a specific event rather than a general intention.

In each case the need is the same: a clear, documented answer to where the product stands today and a prioritized plan for what to fix. The audit is built to produce exactly that, on a fixed timeline and a fixed budget.

What the Accessibility Audit Covers

The audit examines the in-scope pages and flows across three layers of evaluation. Most engagements combine all three.

01

Automated Testing

An AI-accelerated automated scan runs across all in-scope pages to surface the WCAG violations that tools can detect from code structure, among them missing alternative text, contrast below threshold, and incorrect ARIA usage. Findings are deduplicated and grouped by success criterion, so the report reflects distinct issues rather than repeated instances of the same problem.

This is where AI fits the audit: it speeds the mechanical first pass and covers every in-scope page consistently, which makes the manual evaluation that follows more focused. It does not decide conformance, and it does not replace the manual work.

Automated scanning catches a portion of conformance issues quickly and leaves the rest, the larger part, to manual evaluation.

02

Manual Testing

Manual evaluation covers what automated tools cannot reliably detect. Experienced accessibility engineers work through keyboard navigation, focus management, and interactive components by hand, and run screen reader testing with NVDA and JAWS on Windows and VoiceOver on macOS and iOS across representative pages.

The pass also assesses color contrast in context, text alternatives, form labels, and ARIA usage where automated detection falls short. Because so much of accessibility depends on interaction rather than markup, this is the part of the audit that most distinguishes a real evaluation from an automated scan exported as a report.

Manual testing of this kind, with human judgment and rigor, is where most of the barriers that affect real users are found.

03

Conformance Mapping

Every finding is mapped to its WCAG 2.1 and 2.2 success criterion and conformance level (A, AA, or AAA), so the report ties directly to the standard the obligations reference.

Findings that create legal exposure under the ADA or Section 508 are identified separately, which lets legal and compliance stakeholders see the risk-bearing issues without reading the full technical report.

Tying each finding to a specific criterion and level also makes the conformance report defensible, since every claim in it traces back to a tested success criterion. This assessment-first approach reflects a Shift Left view of quality: surfacing barriers early, where they are cheaper to address.

What the Audit Surfaces

Across the automated and manual passes, an audit surfaces the barrier types that keep people with disabilities from completing core tasks. Common categories include

Each finding is documented with the criterion it violates, its severity, and a recommended fix, so the report reads as an actionable list rather than a single pass-or-fail score.

What You Receive

The audit produces four documents, each written for a different audience inside the organization, from the people implementing the fixes to the leadership and legal stakeholders who review the results.

01

Accessibility Audit Report

A written report of all findings, organized by WCAG success criterion and severity, with a clear description of each issue, supporting screenshots, and a recommended fix. It is the working reference for the remediation that follows.

02

Conformance Report (ACR or VPAT)

An Accessibility Conformance Report, delivered as a VPAT or equivalent, documenting the current conformance status of the product. This is the document procurement teams and vendors ask for when accessibility is a contract requirement.

03

Remediation Roadmap

A prioritized plan that separates launch-blocking barriers from enhancement-level issues, so the team can sequence the work against its own timeline and capacity.

04

Executive Summary

A one to two page summary of compliance posture, risk, and recommended next steps, written for leadership and legal stakeholders rather than the implementation team.

Why an Independent, Fixed-Scope Audit

An audit carries more weight when it comes from outside the team that built the product. An independent assessment is not working inside the same assumptions, deadlines, and familiarity that create blind spots for an internal team, which is part of why procurement and legal stakeholders ask for third-party conformance reports rather than self-declarations.

The fixed-scope structure adds a second kind of confidence: the in-scope pages, the timeline, and the price are agreed before the work begins, so the engagement produces a defined set of documents on a defined date.

For an organization facing a deadline or a complaint, that predictability matters as much as the findings: the result is a documented conformance status the organization can stand behind, not an open-ended project.

How the Engagement Runs

Who This Is For

Case Study

Accessibility Conformance Audit for Big Timber Media

Think Tank QA ran a WCAG 2.2 AA accessibility audit for Big Timber Media (BTM) covering four websites and two online ebook readers operated for their client, ABDO Publishing, including the abdodigital.com site and the abdozoom.com database.

The two-week audit combined automated tools (Axe DevTools and Google Lighthouse) with manual testing across JAWS, NVDA, and VoiceOver, and included evaluation of the embedded iframe ebook readers.

Think Tank QA also delivered Voluntary Product Accessibility Templates (VPATs) using the latest ITI templates for transparent reporting to BTM’s vendors. The audit established the baseline that BTM’s development team worked from during the subsequent rebuild, supported through accessibility consulting.

The Result

The audit findings reports identified Critical and High severity issues, among them keyboard traps in modals, reflow and text-resize failures that left pages unnavigable at 200% zoom, missing accessible names on controls, and color-contrast failures.

Frequently Asked Questions

An accessibility audit is a point-in-time evaluation of a website or application against the accessibility standards that apply to it, most often WCAG 2.1 and 2.2 at Level AA. The audit combines automated scanning with manual and assistive technology testing, documents each barrier with its severity and a recommended fix, and maps findings to the relevant success criteria. The output is a record of where the product stands and what needs to change to conform. An audit is the assessment step; the remediation that follows is a separate effort, often handled through ongoing accessibility consulting.

Most audits center on the Web Content Accessibility Guidelines (WCAG), currently version 2.2 at Level AA, with 2.1 AA still referenced across procurement and regulation. In the United States, an audit also addresses the Americans with Disabilities Act (ADA) and, for federal-facing and many publicly funded organizations, Section 508 of the Rehabilitation Act. WCAG is the technical standard the legal frameworks point to: ADA and Section 508 obligations are generally met by conforming to WCAG 2.1 or 2.2 AA. An audit maps each finding to the specific success criterion and level it relates to.

Automated tools scan code and catch the issues detectable from structure: missing alternative text, contrast ratios below threshold, and some incorrect ARIA usage. The scan is AI-accelerated and fast, but it detects only a portion of WCAG issues. Manual testing covers what automation cannot reach: keyboard operability, focus order, screen reader output, and whether an interactive component actually works for someone not using a mouse. A credible audit combines both, because automated coverage alone leaves most of the barriers that affect real users undetected. The manual and assistive technology evaluation is where those issues surface, and where the conformance judgment is made by a person, not a tool.

An Accessibility Conformance Report (ACR) documents how a product measures against accessibility standards, criterion by criterion. A Voluntary Product Accessibility Template (VPAT) is the common format for an ACR. Procurement teams, especially in higher education, government, and large enterprises, request a current ACR or VPAT before buying or renewing software, because it shows the product’s conformance status in a standard form they can evaluate. An audit produces the underlying findings; the ACR or VPAT presents them in the format buyers expect. A current, accurate report is increasingly a precondition for winning and keeping public-sector and education contracts.

Title II of the ADA applies to state and local government entities, including public colleges and universities. A 2024 Department of Justice rule set WCAG 2.1 Level AA as the technical standard for their websites and mobile apps. The compliance deadlines are tiered by population size and have been revised: as of a 2026 DOJ interim final rule, larger entities have until 2027 and smaller entities until 2028, with rulemaking still in progress. Because the dates can move, the durable takeaway is the standard itself, WCAG 2.1 AA, and the obligation to document conformance. This is general information, not legal advice; confirm current obligations with counsel.

An accessibility audit is the point-in-time assessment: it documents where a product stands against WCAG and the applicable laws, with findings, severity, and recommended fixes. Accessibility consulting is the broader, ongoing engagement that follows: prioritizing the work, supporting the development team through the fixes, training, and re-checking as the product changes. Most organizations start with an audit to establish a baseline, then move into consulting to turn the findings into a conformant product and a team that can maintain accessibility. The audit answers where you stand; consulting is how you close the gap and keep it closed.

Four things separate audit providers. Method: does the audit combine automated scanning with manual and assistive technology testing, or lean on automated scans alone? Standards depth: does the provider work across WCAG 2.1 and 2.2, ADA, and Section 508, and map findings to specific criteria? Documentation: does the engagement produce a conformance report (ACR or VPAT) that procurement and legal teams can actually use? Scope clarity: is the engagement fixed in scope and price, or open-ended? A provider that runs a tool and exports the result is selling something far narrower than an audit that includes manual and screen reader testing.

A standard audit report documents each finding against the WCAG criterion it relates to, with a severity rating, the page or component where it occurs, a clear description, supporting evidence such as a screenshot, and a recommended fix. Reports usually also include an executive summary for leadership and legal stakeholders, a conformance report (ACR or VPAT) when procurement needs one, and a prioritized view that separates launch-blocking barriers from enhancement-level issues. The report is the basis for the remediation work, written to be actioned by the team doing the fixes rather than filed for the record.

No audit can guarantee legal immunity. What an audit provides is a documented, defensible record of conformance status at a point in time and a prioritized plan to address the gaps. That documentation matters: it demonstrates good-faith effort, supports responses to complaints or demand letters, and gives procurement teams the conformance report they require. But conformance shifts as a product changes, and legal exposure depends on facts an audit does not control. Treat an audit as evidence and a roadmap, not a certificate of compliance, and confirm legal questions with counsel.

Manual testing in the audit covers the major screen readers across platforms: NVDA and JAWS on Windows, and VoiceOver on macOS and iOS. Beyond screen readers, the audit evaluates keyboard-only navigation, which is the baseline for users who cannot use a mouse and a foundation for many other assistive technologies. Coverage of additional tools and of mobile-specific assistive technology depends on the product’s surface and is set during scoping. Testing across more than one screen reader matters because behavior differs between them: an issue one reader handles can break another.

A fixed-scope audit fits when the need is a clear, documented answer to where a product stands: ahead of a procurement deadline, in response to a complaint, before or after a rebuild, or when a contract requires a current conformance report. It is bounded, predictable, and produces the documentation. Ongoing accessibility consulting fits when the work is continuous: remediating across releases, building accessibility into the development process, and re-checking as the product evolves. Many organizations begin with the audit to set a baseline and move into consulting once they know the scope of the work ahead.

The audit is a four-week, fixed-bid engagement. It begins once the in-scope pages and flows are agreed and access is provided, runs automated scanning alongside manual and assistive technology testing, maps findings to WCAG criteria, and delivers the four documents: audit report, conformance report (ACR or VPAT), remediation roadmap, and executive summary. A mid-point check-in keeps findings visible before the final review. Where the product surface is large, scope is set to what the four-week window can responsibly cover, with additional surfaces handled as separate scope.

Get Started

An accessibility audit gives you a documented conformance status, a prioritized roadmap, and the conformance report your procurement or legal stakeholders need. Whether you are preparing for a deadline, responding to a complaint, or validating a rebuild, the engagement is scoped and priced before it begins. Reach out to define the scope and timing.

What Are You Working On?

We’d love to show you how Think Tank QA can help you achieve better quality outcomes for your business.​