HIF / Documentation / Delivery

HIF Web Audit Report Template

Status: controlled template, version 0.1

Use this template with the Web Audit Playbook and HIF Test Design. Remove guidance text in brackets before delivery. Do not remove scope, limitations or statement boundaries.


[Client / product] Web Interface Audit

Report ID: [AUDIT-ID]
Report version: [x.y]
Report status: [Draft | Client review | Final | Retest]
Audit period: [UTC start — UTC end]
Report date: [YYYY-MM-DD]
Prepared by: [organisation and named reviewers]
Approved recipient: [name/role]
Confidentiality: [classification and handling]

1. Executive decision brief

Purpose

[What decision was this audit commissioned to support?]

Scope in one sentence

[Properties, journeys, environments, sample and explicitly excluded areas.]

Evidence level

[HIF E1 | E2 | E3 | E4 | E5, with explanation]

Overall conclusion

[Three to six bounded sentences: what was evaluated, what works, the most material risks, and what cannot be concluded.]

Priority decisions

DecisionReasonOwnerTarget dateEvidence needed
[decision][risk/outcome][role][date][closure evidence]

Finding summary

SeverityOpenResolvedAccepted riskHypothesis
S0 Blocker0000
S1 Critical0000
S2 Major0000
S3 Moderate0000
S4 Minor0000

[Do not present a single score as proof of quality or conformance.]

2. Engagement and authority

Commissioning organisation: [name]
Authorised contact: [name/role]
Purpose: [purpose]
Authorised methods: [methods]
Prohibited actions: [actions]
Test accounts/data: [synthetic source and roles]
Test window/rate limits: [conditions]
Incident contact: [route]
Evidence retention/deletion date: [date]
Scope changes approved: [IDs or none]

Commercial disclosure

[State whether the auditor, its affiliates or tool suppliers may benefit from remediation work. State that the client may implement with another supplier.]

3. Scope

Included

Scope IDProperty / journeyRoleEnvironmentReason
SC-001[item][role][environment][reason]

Excluded

ItemReasonConsequence for conclusions
[item][reason][limit]

Standards and profiles

  • HIF version: [version]
  • HIF Product Profile: [profile]
  • WCAG target requested: [for example, WCAG 2.2 Level AA | not commissioned]
  • Accessibility assurance record: [ID/link | not commissioned]
  • Applicable accessibility law mapping: [record/date | legal review required]
  • Browser/device support policy: [policy/version/date]
  • Other approved criteria: [criterion]

4. Limitations and statement boundary

[Record access gaps, unavailable states, sample limits, environment differences, release changes, third-party boundaries, missing field data, participant limitations and tool limitations.]

This report:

  • describes the tested sample, tasks, dates and environments only;
  • does not guarantee absence of defects or future performance;
  • is not legal advice or security certification;
  • does not establish whole-site WCAG conformance unless an explicitly defined, complete conformance evaluation supports that statement;
  • does not treat a technical failure as proof of statutory breach, liability, enforcement outcome or damages;
  • does not convert a laboratory performance result into a field result;
  • separates verified evidence from expert judgement and hypotheses.

5. Product, audience and task model

Priority audiences and contexts

Audience/contextNeedRelevant constraintsEvidence source
[audience][need][constraint][source]

Priority tasks

Task IDGoalStarting state / roleSuccessCritical errorEvidence level
TASK-001[goal][state][outcome][error][E-level]

6. Inventory and sample

Inventory date: [UTC timestamp]
Known release/build: [identifier]

Unit IDURL / state / templateTypeInclusion reasonTestedEvidence
UNIT-001[safe reference][type][structured/random/risk][yes/no][ID]

Sampling method: [complete | structured + random, with method]
Population known: [yes/no and size]
Sample size: [n]
Generalisation limits: [statement]

7. Environments

Env IDBrowser/versionOSDevice/viewport/DPRInputAT/preferencesNetwork/cache
ENV-001[value][value][value][value][value][value]

Unsupported or blocked combinations: [list and consequence]

8. Methods and coverage

MethodCoverage targetExecutedEvidence / limitation
model review[target][yes/no][ID/limit]
functional test design[target][yes/no][ID/limit]
heuristic evaluation[target/evaluators][yes/no][ID/limit]
usability research[participants/tasks][yes/no][ID/limit]
accessibility[criteria/AT/sample][yes/no][ID/limit]
performance[field/lab][yes/no][ID/limit]
responsive/browser[matrix][yes/no][ID/limit]
UI security/privacy[boundary][yes/no][ID/limit]

Coverage detail: [link to test register]

9. Cross-cutting conclusions

Task effectiveness and recovery

[Evidence-led conclusion.]

Comprehension, content and information architecture

[Evidence-led conclusion.]

Accessibility and input independence

[Criteria tested, complete processes, AT matrix, barriers, assurance-record reference and exact technical/legal statement boundary.]

Performance and resilience

[Separate field data, laboratory diagnostics and observed task behaviour.]

Responsive and cross-browser behaviour

[Matrix and material differences.]

Privacy, security and trust at the UI boundary

[Visible/observable issues only; identify referrals for specialist testing.]

10. Prioritised finding register

IDFindingStateSeverityReachFrequencyConfidenceTaskRecommendationOwner
HIF-WEB-001[title][state][S0–S4/Obs][R1–R4][F1–F4][C1–C3][ID][short outcome][role]

If a planning score is used, publish the formula and keep the component ratings. Do not let the score override S0 escalation or professional judgement.

11. Detailed finding

[Repeat this section.]

HIF-WEB-[NNN] — [Outcome-focused title]

State: [Verified | Intermittent | Systemic | Hypothesis | Not reproduced | Resolved | Accepted risk]
Severity: [S0–S4 | Observation]
Reach: [R1–R4, measured/inferred/unknown]
Frequency: [F1–F4, occurrence/sample]
Confidence: [C1–C3]
Affected tasks: [TASK-IDs]
Affected units: [UNIT-IDs]
Environment: [ENV-IDs]

What happens

[One factual paragraph.]

Why it matters

[Person, task, exclusion/harm, recovery and business consequence. Do not invent prevalence or quote unverified legal exposure.]

Reproduction

Preconditions: [state, role, synthetic data]

  1. [Step]
  2. [Step]
  3. [Step]

Expected: [semantic outcome, authority and feedback]
Observed: [outcome]
Occurrence: [x/y attempts and conditions]

Evidence

Evidence IDTypeUTC timestampDescriptionRedaction
EV-001[image/video/DOM/trace/note][time][description][none/what]

Criteria

  • HIF: [requirement IDs]
  • External normative criterion: [exact criterion/version or none]
  • Supporting guidance: [source and section]

Root-cause hypothesis

[Clearly marked hypothesis; omit if unsupported.]

Recommended outcome

[Outcome to achieve, options and trade-offs. Separate requirement from one possible implementation.]

Acceptance criteria

  • Given [state], when [action], then [observable outcome].
  • [Keyboard/AT/input alternative where applicable.]
  • [Error, interruption and recovery behaviour.]
  • [Persistence and feedback.]

Estimate

Range: [range or not estimated]
Includes: [discovery/design/content/build/test/release]
Assumptions: [list]
Dependencies: [list]
Estimate confidence: [low/medium/high]

Regression surface

[Components, tasks, roles, locales, browsers and analytics affected.]

Client decision

[Accept remediation | Investigate | Accept risk until date | Reject with reason]
Owner: [role]
Decision date: [date]
Review/expiry: [date]

12. Remediation roadmap

Work packageFindingsIntended outcomeDependenciesEstimate rangeOwnerAcceptance gate
WP-01[IDs][outcome][items][range][role][gate]

[Identify shared root-cause work, prerequisites, quick risk reductions and items requiring discovery. “Quick win” must not mean “low human importance”.]

13. Retest and regression plan

Finding / packageOriginal casesAdded negative/recovery casesEnvironmentsEvidence required
[ID][TEST-IDs][TEST-IDs][ENV-IDs][evidence]

Closure authority: [role]
Retest window: [date/conditions]

14. Retest record

Build/date: [identifier / UTC date]

FindingResultCasesEvidenceRemaining limitationRegression
[ID][resolved/partial/open/not tested][IDs][IDs][limit][result]

15. Evidence index and handling

Evidence repository: [controlled location]
Access: [roles]
Retention/deletion date: [date]
Redaction log: [reference]
Integrity hashes: [reference/not used]

Never include credentials, tokens or unnecessary personal data in this report.

16. Open questions and accepted risk

IDQuestion/riskEvidence missingOwnerDecision/review date
Q-001[item][evidence][role][date]

17. Source register

Source/versionStatusApplied scope
HIF [version]product standard[scope]
WCAG 2.2 [level if commissioned]W3C Recommendation[scope]
WCAG-EM 1.0W3C Working Group Note methodology[scope]
WAI-ARIA 1.2 / APGstandard / supporting guidance[patterns]
ISTQB CTFL 4.0.1test-design syllabus[techniques]
Google Web Vitals [retrieval date]performance definition/guidance[page groups]
OWASP WSTG [version]security-testing guidance[UI boundary/referral]

18. Sign-off

Prepared by: [name/date]
Quality-reviewed by: [name/date]
Client acknowledgement: [name/date]

Client acknowledgement confirms receipt and recorded decisions; it does not change the evidence, remove limitations or create a guarantee.