Where the money changes hands
It is a remarkably consistent pattern: a clean, considered marketing site with a published accessibility statement — and a booking engine, ticket checkout or customer portal behind it that has not been touched in a decade. One of those two surfaces takes payment.
These are patterns found repeatedly on transactional surfaces across hospitality, tourism, arts and industrial customer portals. No organization is named here — findings belong to the client who paid for them.
A published accessibility policy committing to WCAG 2.0 AA, authored
by a named compliance staffer, reviewed on a schedule — describing
the public website. The login-gated scheduling tool customers
actually book through is a separate, much older application: no
lang attribute, an unlabelled logo image, and username
and password fields with no associated <label> at
all. Table-based markup, a jQuery version from 2011, and a current
copyright date — actively maintained, never audited.
Check-in and check-out fields on an availability widget, with the words "Check in" and "Check out" sitting right above them in the design. Sighted users see a labelled form. A screen reader announces two unlabelled edit fields, because nothing ties the text to the input. This is among the most common findings on booking widgets and among the cheapest to fix.
An accessibility overlay installed site-wide, running correctly on the homepage and the information pages — and absent from the ticketing checkout, because the checkout is hosted on a different domain by the ticketing vendor. The subscription covers the pages that were already in reasonable shape.
A viewport meta tag with user-scalable=no
or a capped maximum-scale, applied to a ticket purchase
page. That is a WCAG 1.4.4 failure, it takes one line to fix, and it
specifically affects the low-vision customers most likely to be
buying a seat where they can see.
Offer tiles on a resort homepage that look like links, announce like links, and resolve to hidden tracking pixels or empty targets. Every visitor loses here, but a keyboard user loses worse: they tab into a control that reports itself as actionable and does nothing.
No tooling, no purchase, no consultant. Open your own booking or checkout flow and put the mouse away entirely.
If you get stuck, that is the finding. You have just reproduced the experience of a customer who was going to give you money and could not. Most people who run this test on their own site do not finish it.
This is the usual case, not the exception — and it is where most audits quietly stop.
Tasting reservations, restaurant bookings, ticketing and hotel availability are typically hosted by a vendor, on the vendor's domain, in the vendor's markup. You cannot remediate it, and any consultant who implies otherwise either has not looked or is planning to bill you for something they cannot deliver.
It still gets audited, for one reason: your customer has no idea where the domain boundary is. They know your winery took their money or didn't.
The regulation draws the line in the same place you would. Section 14 reaches web content an organization controls directly or through a contractual relationship that allows for modification — so where a booking engine is genuinely outside your control, the obligation sits differently, and the contract is what decides it. That cuts both ways: it is a real answer if someone claims you are in breach over markup you cannot touch, and it is the reason renewal is the moment to ask for conformance in writing.
What comes out of it is a findings list written for the vendor — each issue named against the success criterion it breaches, in the form their development team can act on. That turns an awkward "your thing is broken" email into a specification. Contract renewal is the moment it carries real weight, and knowing what to ask for before that conversation is worth more than the audit costs.
Audits are priced by page template rather than by page count. Transactional interfaces carry an application complexity multiplier — date pickers, availability calendars and multi-step flows hold state, and state is where accessibility failures hide.
A booking or checkout path plus the page that feeds it usually fits a focused audit, from $2,200. A full path with several distinct steps, or a portal with account management behind a login, generally lands in the $2,500 – $4,500 range.
Remediation is quoted separately once the audit is done, and where the failing system belongs to a vendor there may be nothing to quote at all — the deliverable is the leverage, not the labour.
Yes, and this is the common case. Restaurant and tasting reservations, ticketing and hotel availability are usually hosted by a vendor on their own domain, and their markup is not yours to change. The audit still covers it, because your customer does not know or care where the domain boundary is. The deliverable is a findings list written for the vendor, with the success criteria named, so the request arrives as a specification rather than a complaint. The regulation draws the line in the same place: section 14 reaches content an organization controls directly or through a contractual relationship that allows for modification. So the contract is what decides where the obligation sits, and renewal is the moment to ask for conformance in writing.
Almost certainly not. An overlay is JavaScript installed on the pages you control. When the checkout or booking engine is hosted on a different domain, the script does not load there at all — so the one surface where money changes hands is the one surface the subscription does not reach. This is worth checking before renewing, because the gap is invisible from the dashboard.
Both, in different proportions depending on size. Ontario organizations with 50 or more employees have owed WCAG 2.0 Level AA conformance since January 1, 2021 under section 14 of O. Reg. 191/11 — on content published after January 1, 2012, that they control directly or can change under contract, and except where meeting the requirement is not practicable. Below 50 employees there is no website obligation at all, and the argument is purely commercial: a booking flow that cannot be completed by keyboard is a booking that does not happen — in a region whose visitors skew older, and therefore skew toward vision and motor needs. For most operators the commercial case is the larger number anyway.
A focused audit covering up to three page templates starts at $2,200, which is typically enough for a booking or checkout path plus the page that feeds it. Transactional interfaces carry an application complexity multiplier because date pickers, availability calendars and multi-step flows hold state, so a full path with several distinct steps usually lands in the $2,500 – $4,500 range.
Twenty minutes. Bring the URL of the flow you are least sure about — that is usually enough to know whether there is a real problem underneath it.
Book a 20-minute call