Independent audit of a high-traffic transactional website
Real data from our reference project, as of 2026-07-13. The client's name is intentionally omitted from this document — a concrete example is available on request, subject to a confidentiality agreement.
Scale of the audit
Coverage achieved by our automated approach
On this project, 121 of the 162 regulatory criteria (75%) were covered by our automated approach — the rest (41 criteria, 25%) required human judgment we don't yet integrate into our approach.
| Metric | RGAA | WCAG |
|---|---|---|
| Criteria covered by our automated approach | 82 / 106 (77%) | 39 / 56 (70%) |
| Resolved (with or without quick manual confirmation) | 100% | 100% |
| Human judgment required, not yet covered | 24 / 106 (23%) | 17 / 56 (30%) |
The 2 remaining RGAA criteria require human judgment our approach doesn't yet integrate. The RGAA framework is due to evolve into a version 5, currently being drafted.
The criteria unlocked by our real-evidence protocols — NVDA bridge (real captured speech), forced-colors mode, focus-visibility diffing, a real 30-minute session-timeout wait, vision-assisted icon triage, automatic audio/video transcription, multimodal model judgment, cross-screen coherence — are all automated (some with a quick manual confirmation), never a classic manual audit.
Systemic defects identified
The analysis surfaced patterns rooted in the site's design system (components shared across every page of the interface framework) — a single component-level fix resolves several findings at once:
- Design-system icon buttons without an accessible name
- Progress bars without a label
- Accordion panels without an accessible name
- Multiple
H1tags per page on single-page applications aria-modal="true"misapplied to plain buttons
This analysis changes the remediation-effort estimate presented to the client: one component fix can resolve dozens of defects at once, rather than being addressed page by page.
What this case study demonstrates
We don't leave you with a manual checklist
Every criterion that can't be automated gets a concrete test protocol, not just a "check manually" tag.
We test what a real user experiences
A real screen reader's actual voice output, a real elapsed session-timeout wait — not heuristics that approximate behavior.
We separate rigor from speed
Vision-model-assisted triage speeds up detection but is not presented as a final verdict.
We document systemic defects
Not just page-by-page symptoms — one component fix can resolve dozens of defects at once.
A site of this scale to have audited?
This reference project is a very large-scale site, not a simple brochure site — let's talk about your scope.