What this FAQ covers
This page answers recurring questions about reports and findings for website owners, agencies, and technical teams. The answers define practical boundaries, identify the evidence that matters, and explain when a question requires account-specific, technical, contractual, or legal review.
- What should an audit report include?
- What is the difference between severity and priority?
- Can the same finding appear on many URLs?
- What is an accepted risk?
Use the answers responsibly
Apply each answer to the actual website, scope, agreement, and evidence. Avoid publishing scores without explaining what was tested or what the score means. When the decision could affect production availability, security, accessibility, billing, privacy, or contractual commitments, document the responsible reviewer and verification plan.
Questions and answers
01What should an audit report include?
Scope, date, methodology, limitations, summaries, category results, prioritized findings, evidence, affected assets, recommendations, and verification status.
02What is the difference between severity and priority?
Severity describes technical seriousness. Priority describes the recommended order after business impact, scope, confidence, dependency, effort, and timing are considered.
03Can the same finding appear on many URLs?
Yes. The finding should preserve the full affected scope while grouping repeated symptoms into actionable work.
04What is an accepted risk?
A documented decision not to remediate now, including the reason, owner, conditions, review date, and consequences.
05How are estimates handled?
An estimate should state assumptions, affected scope, dependencies, exclusions, and the expected outcome. It is not a guarantee unless the order says so.
06What closes a finding?
The agreed verification passes, relevant side effects are reviewed, and the result is documented—or the organization records an approved exception or accepted risk.
Turn reports and findings into an accountable record.
A clear, supportable answer set for reports and findings linked to the relevant workflow or policy.