The pattern repeats across public-sector and regulated delivery. An audit date appears, an agency is engaged, a list of defects comes back, a team spends six weeks fixing them, and the report passes.
Eighteen months later the same site fails a similar audit on similar findings, because nothing about how the work is produced changed. Only the output was corrected.
Most findings originate in design, not code
Colour contrast, focus order, target size, error messaging and the meaning conveyed by colour alone are all settled before an engineer opens an editor. By the time they appear in an audit they are expensive, because fixing them means revisiting decisions rather than adjusting markup.
Moving the decision earlier is most of the work. A design system whose tokens cannot express a failing contrast pair removes an entire category of finding permanently, and it does so without anyone having to remember a rule.
Automation catches a minority, and that is fine
Automated checks reliably find a real but limited share of issues: missing alternatives, unlabelled controls, contrast failures, structural problems. They cannot tell you whether alternative text is meaningful or whether a flow can be completed with a keyboard.
The correct response is to automate the mechanical part in the pipeline so it never regresses, and spend human review on the part that requires judgement. Treating an automated pass as compliance is how sites fail audits they technically passed.
- Run automated checks on every pull request, not before releases
- Keyboard-test the primary journeys by hand
- Test with a screen reader on the journeys that matter most
- Include people with disabilities in research, not only in testing
Write it into the definition of done
Accessibility survives when it is a property of finished work rather than a phase. That means the acceptance criteria for a component mention keyboard behaviour and announced state, and a component that lacks them is not finished.
This is less onerous than it sounds, because it applies to new work only. The existing estate is remediated on its own schedule, while the flow of new defects stops.
The report is not the goal
An audit measures a moment. The thing worth optimising is the rate at which new inaccessible work enters the system, because that is what determines the result of every future audit.
Teams that make this shift tend to find the next audit uneventful, which is the only outcome worth wanting from an audit.



