Website Builder Studio
Learn

One checklist, split by who can actually check it

Website compliance is four different jobs with four different owners. Most checklists mix what a scanner finds in a second with what only a lawyer can answer, which is why nobody finishes them.

Short answer

A practical website compliance checklist covers four areas: accessibility, honest claims, privacy, and web standards. The useful split is by who can check each item. A machine handles structure and contrast. You handle truthfulness and retention. A professional handles whether a rule applies to you.

What a machine checks

Images have text alternatives. Form fields have connected labels. Headings run in order with one main heading per page. Contrast passes.

Links have real words. The page has a title and a description. Structured data parses. Nothing traps the keyboard.

Every page written by Website Builder Studio passes a check that runs before anything publishes, validated against Google Search Essentials and modern web standards, so this part is continuous rather than annual.

This half runs continuously rather than annually, which matters because the pages that fail are almost always the ones added after the last review.

  • Images carry text alternatives
  • Form fields have connected labels
  • Headings run in order with one main heading per page
  • Text contrast passes the published minimum
  • Links carry real words rather than click here
  • Every page has a unique title and description
  • Structured data parses, and nothing traps the keyboard

What only you can check

Whether your alt text describes the actual picture. Whether your headings describe their sections. Whether the tab order makes sense on your layout.

Whether every claim on the site is true and you could show it. Whether prices shown are the prices charged.

No scanner will ever report these. They are the half of the list that decides whether the page is genuinely useful.

It is worth being blunt about this row: it contains everything that could actually mislead somebody. A false claim passes every scanner ever written.

What needs somebody qualified

Whether an accessibility obligation reaches your business. Whether a state privacy law applies. What your terms need to say once you take money.

Anything involving a licensed profession, where your own regulator has rules about advertising that sit above anything general.

Nothing here is legal advice, and this row of the list is exactly why.

Accessibility, the short version

Run a scan and fix what it reports. Walk the site with the tab key. Listen to two pages with the screen reader you already own.

Read your own alt text against the images. Check contrast in both light and dark themes if you offer both.

Publish an honest accessibility statement with a working way to report a barrier.

The full version, in the order that finds the most for the least effort, is in the accessibility checklist.

Claims, the short version

Every number on the site traceable to something real. Every testimonial genuine and attributed with permission.

Before and after photos showing the same job, not a stock pair. Licences and credentials current and stated accurately.

Prices honest, including what is not included. Anything that renews said plainly where the decision is made.

Privacy, the short version

An inventory of what the site collects and what it loads. A privacy policy that matches that inventory rather than a template.

A retention period you actually keep to. No email address printed on any page. A cookie banner only if something genuinely needs consent.

Third parties named. A route for somebody to ask what you hold and to ask you to delete it.

Web standards, the short version

Valid markup that parses. One main heading per page. A title and a description on every page, both unique across the site.

Links that work, a real page returned for a missing address rather than a blank one, and a sitemap that lists what exists.

Structured data that describes what is actually on the page. Markup claiming a rating or an event the visitor cannot see is the fastest way to lose the feature entirely.

How to run the list

The machine half runs itself on every publish. The half only you can check deserves an hour twice a year and an hour after any redesign.

The professional half gets looked at when something changes: a new service line, a new state, a new way of taking money.

Keep the findings in one place with dates. That record is most of an accessibility statement and most of any report a buyer asks for.

Keep the findings in one place with dates beside them. That record is most of an accessibility statement and most of any report a buyer asks for.

Questions people ask

How often should I run this?

The automated part continuously, the self check twice a year and after any redesign, and the professional part whenever your business materially changes.

Where should I start if I have done none of it?

Run a scan and fix what it reports, then read your own claims for anything you could not prove. Those two passes remove most of the real risk.

Is there a certificate at the end?

No, and be wary of anybody selling one. What you can honestly publish is a description of what you check and what you found.

Does passing every automated check mean I am compliant?

No. It means the checks you ran passed. That is a useful, narrower statement, and it is the one to make.

See your website built from a conversation

15-day free trial. Card required. Cancel before day 15 and you pay nothing.

Build my website
Every plan starts with a 15-day free trial. Card required.See plans and pricing