- A defensible record is dated documentation of audits, fixes, monitoring, and training over time, not a single certificate.
- Fix scan-detectable issues first, then user flows, and preserve a dated before-state before you remediate.
- This is general information for preparedness, not legal advice.
Building a defensible accessibility compliance record means keeping dated, organized documentation of your ongoing program, because good faith and mootness are only as strong as the evidence behind them. The record is the defense. Everything below frames documentation and preparedness, and none of it is legal advice.
Why the record matters more than any single fix
Large companies have mostly remediated, so small and medium businesses are now the primary targets. The vulnerability is the awareness gap: sites with high automated error counts that nobody is watching.
Plaintiff firms use free scanning tools as a triage layer to find targets. Scan-detectable errors are what get you discovered in the first place, so reducing them lowers your visibility to that first pass.
An organized program record is what separates a defensible company from one that looks like it did nothing. Think of the record as a mirror: it shows exactly what you knew, what you fixed, and when.
Prioritize remediation in the right order
There is a two-step sequence that keeps your effort aligned with how risk actually forms:
- Eliminate scan-detectable issues first, since the scan layer is how you get found.
- Fix user flows second, because that layer is what a real claim gets built on.
Handling scan output well starts with knowing what an audit and a scan each cover. A scan flags roughly a quarter of issues; the rest come from a (manual) audit conducted against WCAG. Keeping records of both, and tracking these documents over time, is part of the posture.
What a defensible record contains
A program record worth having documents your work at every layer. Here is what a defensible accessibility record should hold:
- Dated (manual) audit reports tied to specific WCAG success criteria.
- Scan results captured on dated intervals to show error counts trending down.
- A remediation log linking each fix to the issue it resolved and the date.
- A monitoring cadence, since developers and content managers reintroduce problems.
- Training records showing your team knows how to keep new content accessible.
If a demand letter or claim arrives
Don’t act rashly. The first obligation is to preserve the evidence, not the website.
Capture a dated record of the site’s state at the time of the claim, then remediate quickly. The sequence matters: preserve first, then fix.
Fixing the live site is not destroying evidence as long as you documented the before-state first. Remediating without that preserved state can look like scrubbing evidence and leaves you unable to prove what the issues were.
| Step | Preserve first, then fix | Fix without preserving |
|---|---|---|
| Before-state | Dated screenshots, crawls, archived copies, scan results | None captured |
| Mootness argument | Supported by dated evidence | Hard to prove what was fixed |
| Spoliation risk | Low | High |
Fast remediation before a suit is filed supports a mootness argument, since the relief sought may already be provided. But mootness only works with dated evidence: the preserved before-state plus remediation records tied to specific issues prove what you fixed and exactly when.
Settlement terms and the window after
The non-monetary terms are the hidden cost. Forced audits, quarterly user testing, and ongoing monitoring obligations can exceed the settlement figure.
Plaintiffs re-check after settlement, so the 12 to 24 month compliance window carries breach risk. Meeting those terms is a deadline-and-evidence problem: track progress against the agreed scope and hold proof you met it before the window closes.
Where a statement fits
An accessibility statement and a contact method help in negotiation and as good-faith evidence, but they are not a defense, and phone support alone doesn’t cure inaccessibility. Treat them as part of the record, not a substitute for real remediation.
Keep the program ongoing
Accessibility is never one-and-done. Good faith is a documentation posture built from audits, monitoring, training, and fixes logged over time.
If you want help conducting an audit or setting up a program record you can maintain, reach out and we’ll respond quickly with a clear quote and timeline.
For a closer look at this, see our overview of website compliance accessibility consultant.