Compliance Frameworks

Which regulatory frameworks OpenScouter maps to, with evidence packs for DPO review.

What we do

OpenScouter maps every accessibility finding to the regulatory frameworks your compliance team needs. Not just WCAG. Consumer Duty, ISO 22458, DMCCA, and the European Accessibility Act are all covered in every report.

FCA Consumer Duty (PS22/9)

Every compliance report maps findings to the four Consumer Duty outcomes:

  • Consumer Understanding — typography, cognitive load, language clarity
  • Products and Services — friction, exclusion barriers
  • Consumer Support — error recovery, navigation, keyboard access
  • Price and Value — barriers reducing perceived value

The FCA's March 2025 review on vulnerable customers identified data-driven monitoring as a key requirement. OpenScouter's neurodivergent-stratified testing provides exactly this evidence.

WCAG 2.2 AA

  • AI agents reference specific WCAG 2.2 success criteria in every finding (e.g., 1.4.3 Contrast Minimum, 2.4.3 Focus Order).
  • WCAG 2.2 added 9 new criteria in October 2023, particularly relevant for neurodivergent users: Focus Visibility (2.4.11), Touch Targets (2.5.8), Accessible Authentication (3.3.8), and Redundant Entry (3.3.7). All are covered in testing.

ISO 22458:2022

Consumer Vulnerability standard. OpenScouter's ND-stratified testing methodology directly addresses ISO 22458's requirements around identifying and responding to consumer vulnerability. Compliance reports include ISO 22458 clause references from a built-in clause database, enabling direct submission to your GRC system.

DMCCA 2024

Digital Markets, Competition and Consumers Act (in force April 2025). Reports include a sludge and friction section mapping unnecessary obstacles encountered by neurodivergent testers to DMCCA Schedule 3 dark pattern categories. Dark patterns disproportionately affect neurodivergent users, making this mapping uniquely valuable evidence for regulators.

European Accessibility Act (EAA)

In force since June 28, 2025. OpenScouter's testing against WCAG 2.2 AA aligns directly with EAA technical requirements. Evidence packs include EAA-relevant findings clearly labelled for cross-border compliance submissions.

Evidence packs

Every study produces a downloadable evidence pack designed for direct submission to regulatory systems:

  • Branded PDF report with findings, methodology, and regulatory mappings
  • GRC-importable JSON manifest compatible with Archer, ServiceNow, and other GRC platforms
  • Token-authenticated replay link for regulators to verify what was tested
  • Screenshot pairs showing baseline and variant states for visual evidence
  • AX tree structural diff providing machine-readable evidence of what changed structurally between baseline and variant

Compliance confidence labelling. All clause mappings are labelled ‘auto’ (AI-generated) or ‘verified’ (admin-confirmed). Regulators can distinguish AI-generated evidence from human-confirmed evidence.

Study tagging by regulatory purpose. Studies can be tagged at setup: Consumer Duty evidence, IDC submission, EAA compliance, internal audit. Reports are scoped to the declared regulatory purpose.

Ready to build your compliance evidence pack?

Our team can walk you through the regulatory frameworks that apply to your sector and set up your first study with the right compliance tagging.

Talk to an Expert