- The core records are your audit reports, ACRs (completed VPATs), remediation logs, accessibility policy, and public accessibility statement.
- Records are only useful if they’re dated, versioned, and updated after every meaningful change to your site.
- Good documentation supports procurement, legal defense, and your own retesting over time.
Every organization should maintain a small, current set of accessibility records: an audit report, an ACR, a remediation log, an internal accessibility policy, and a public accessibility statement. These five documents show what you tested, what you found, what you fixed, and how you plan to keep things conformant. Together they answer the questions a buyer, a regulator, or a plaintiff’s attorney is most likely to ask.
Why keep them at all? Because memory isn’t evidence. When a demand letter arrives or a procurement team requests proof, you need dated documents, not recollections.
The records that matter most
Here are the accessibility records every organization should maintain, and what each one proves:
- Audit report: the technical findings from a (manual) audit, mapped to WCAG success criteria. This is your baseline of record.
- ACR: a completed VPAT that summarizes conformance for buyers and procurement teams.
- Remediation log: which issues were fixed, when, and by whom. This is where tracking these documents over time pays off.
- Accessibility policy: your internal commitment and process for design, development, and content.
- Accessibility statement: the public-facing page describing your target conformance level and how users can report problems.
Note: default to WCAG 2.1 AA or 2.2 AA as your target. It’s the level most laws and contracts reference.
How the records compare
The table below breaks down each record by who reads it and how often it should be refreshed:
| Record | Primary audience | Update cadence |
|---|---|---|
| Audit report | Developers, internal teams | After major releases or annually |
| ACR (completed VPAT) | Buyers, procurement | After significant product changes |
| Remediation log | Internal, legal | Continuously |
| Accessibility policy | Staff, leadership | Annually |
| Accessibility statement | Public, end users | When conformance status changes |
Keeping the records current
A record from three years ago describes a website that no longer exists. New code, new design, and new content all change your conformance picture, so your documentation has to keep pace.
Setting up a records routine takes a few steps:
- Store every audit report and ACR in one place with clear version dates.
- Log each remediation as it ships, and note the WCAG criterion it addresses.
- Re-test after major releases, then update the ACR and statement to match.
- Review your policy annually so it reflects how your team actually works.
- Keep the accessibility statement honest about your current status, not an aspirational one.
Software helps here. A tracker keeps issues, fixes, and retests connected so your remediation log doesn’t drift from reality.
What these records are not
An ACR isn’t certification, and neither is an audit report. They’re accurate snapshots, not seals of approval. Their value comes entirely from accuracy, so a scan-only report with empty remarks columns is near worthless as a record.
Keep the set small, keep it dated, and keep it true. That’s the whole discipline.
Need an audit report or an ACR to anchor your records? Send us a message and we’ll get you a fast quote at a competitive price, usually within a few hours.
For a closer look at this, see our overview of accessibility statement.