EAA governance: what it means and why most organisations are missing it
Most EAA non-compliance is not a technical failure. It is a governance failure. The audit passes. Then the team changes, and the next release introduces a new barrier.
Three questions every organisation should be able to answer before any EAA enforcement contact arrives: who owns accessibility sign-off before a product release, what your digital systems currently protect that cannot regress without someone noticing, and what your disabled users are already signalling through their assistive technology preferences. The organisations that can answer all three have governance. The organisations that cannot are exposed — regardless of how much accessibility work they have done.
Anna E. Cook, Senior Designer at Microsoft and accessibility governance practitioner, has published a free 30-item diagnostic — the Structural Workbook for AI + Accessible Design Systems — that operationalises these questions across six governance dimensions. It is designed to be run by a small team together, because most of the items surface disagreements about what the team actually does versus what it intends to do.
Technical accessibility can be achieved. The harder problem is keeping it. A product that passes an accessibility audit today is not guaranteed to be compliant next quarter. Every new feature, every team restructure, every product release is an opportunity for accessibility to regress. Without governance, it will.
The BAF Beyond Compliance report, a two-year longitudinal study tracking organisations across banking, e-commerce and telecoms, found a clear pattern: organisations treating accessibility as a continuous process, with regular audits, design systems and dedicated accountability, sustained results above 80%. Organisations treating it as a one-off project did not.
What EAA governance actually requires
Governance is the third of the four mandatory EAA compliance requirements, alongside technical conformance, a published accessibility statement, and documentary evidence. It is also the one most commonly absent.
Named accountability
A specific person or role is accountable for accessibility. Not a team. Not "the product department." A named owner who can be identified in any enforcement investigation.
Regular testing rhythm
Accessibility is tested on a defined schedule, not only before major launches. New features are checked before release, not after. Automated and manual testing are both in place.
Process survival
The compliance process does not depend on one person. If the person responsible for accessibility left tomorrow, the organisation would know what to do next. Documentation, checklists, and onboarding for new team members.
Documentary evidence
Dated assessments, remediation records, and a paper trail that shows active management over time. This is what enforcement bodies request first. It is the difference between demonstrating due diligence and being unable to.
Why governance is what enforcement bodies look for
When an enforcement body investigates an EAA complaint, it does not only look at whether the product is currently accessible. It looks at whether the organisation was actively managing its accessibility obligations. The question is not just "is it compliant now?" but "was this organisation taking reasonable steps, over time, to achieve and maintain compliance?"
In Ireland, the due diligence defence against criminal liability requires exactly this kind of evidence. A director cannot rely on a single historic audit. They need to demonstrate an active, ongoing process. The same principle applies in the Netherlands, where the ACM assesses whether organisations have taken genuine steps toward compliance rather than simply ignoring the obligation.
The governance question to ask now: if the person responsible for accessibility in your organisation left tomorrow, what would happen to your compliance position? If the answer is unclear, that is the governance gap. It is also what enforcement bodies look for when assessing whether non-compliance was wilful or incidental.
Governance and the accessibility statement
A well-maintained accessibility statement is both evidence of governance and a governance tool. It records your current compliance position, what is not yet accessible, and your remediation plan. Keeping it up to date requires a governance process. Its existence demonstrates one.
In Ireland, the accessibility statement is among the first documents a competent authority requests in a complaint investigation, and which authority that is depends on your sector. In the Netherlands, it forms part of the mandatory reporting declaration to the ACM. An organisation without a current, accurate statement starts any enforcement interaction at a disadvantage.
What good governance looks like in practice
For most SMBs, proportionate accessibility governance does not require a dedicated accessibility team or expensive tooling. It requires three things to be in place and documented:
- A named owner with defined responsibilities and sufficient time allocated to the role
- A testing schedule tied to your release calendar, with results recorded
- A remediation process that tracks identified issues through to resolution
The Solid Foundations Method, used across Europe to assess EAA compliance, evaluates whether the core elements users need to complete essential tasks are in place. It is an expert evaluation, not a replacement for user testing with disabled people. Both matter. Governance is what ensures the findings from both are acted on and maintained.
The deviation contract: how governance survives contact with real teams
Governance sounds like process. In practice it comes down to a smaller question: what happens the moment someone steps outside the accessible pattern?
Anna E. Cook calls the answer a deviation contract. A design system, or any documented standard, cannot stop a team from diverging from the accessible default. What it can do is make the cost of diverging explicit at the point of the decision: if you step outside this pattern, here is what you now own, the annotations, the testing, the accessibility approach itself. Stated that way, the accessible path becomes the path of least resistance, and divergence stops being invisible. Without it, a team deviates for a reasonable-looking reason, nobody records the cost, and the gap surfaces months later as a complaint or a bug report. That is the regression the audit could not predict.
This is where AI has changed the shape of the problem. An AI coding assistant is deviation without a contract, at scale. It generates markup that looks right and often is not, and nobody chose to deviate or owns the cost. Peer-reviewed studies consistently find that AI coding tools produce inaccessible code by default, because they are trained on a web that is itself overwhelmingly inaccessible: WebAIM’s 2026 report found detectable WCAG failures on 95.9% of home pages. A model trained on that reproduces it, on every release, across every surface it touches.
The governance answer is the same one that holds for human teams, only it matters more. The accessible default holds only if someone owns the deviation, and when the deviation is coming from a model on every release, that owner has to be a person who can tell compliant structure from a plausible approximation of it. Automated checks catch a fraction of the issues. A person attempting the task on the real journey catches the rest. That named owner is Element 1 of governance for a reason.
What practitioners report
The pattern is not only a design-systems argument. A 2026 Master’s thesis at Tampere University, grounded in interviews with fourteen practitioners working on Finnish design systems, found that accessibility outcomes tracked most reliably with whether a named individual was accountable for them. The author is careful to describe this as a correlation rather than a proven cause, and that caution is worth preserving. But the failure mode participants described is specific: vague shared responsibility, where everyone is collectively responsible, which means nobody is.
The same research describes accessibility as something that decays rather than something an organisation arrives at. Participants reported audits conducted every few years that kept surfacing the same uncorrected issues, because nothing in between owned the problem. That is the governance gap stated from the inside: not an absence of audits, but an absence of anyone holding the standard between them.
It also points at how the work is funded. Where accessibility expertise is a cross-cutting capability rather than a per-project line item, coverage is consistent. Where it is funded per project, coverage follows budget rather than user need.
Why the EAA governance gap is a process problem
Organisations that sustain accessibility are not trying harder than those that do not. They have built a process that survives team changes, product releases, and restructures. The effort is in building the process once, correctly. After that, it runs.
Find out where your organisation stands
We’ll cover three things most organisations haven’t looked at yet: who is responsible if an accessibility complaint arrives, what in your product is protected from breaking, and whether your site already respects the settings your disabled customers are using. Most organisations we speak to haven’t had reason to check. That’s what the 20 minutes is for.
Book your free assessment today