Most banks face mounting EAA enforcement heat

As banks face growing pressure to demonstrate accessible digital services, QA Financial and Level Access will host a hands-on workshop AI for Accessibility and Cutting-Edge UX on Tuesday, September 15, from 12:00 pm to 3:00 pm BST. Led by Dana Randall, Head of Accessible UI Design at Level Access, the session will show delegates how AI can help embed accessibility into design, development and testing while retaining essential human validation.


European regulators are scaling up accessibility monitoring, sharing complaints across borders and increasingly looking for documented proof that banks and other digital service providers are making measurable progress towards compliance.

One year after the European Accessibility Act became enforceable, financial institutions face a more coordinated and consequential enforcement environment in which automated scans, consumer complaints and weak accessibility reporting can all trigger regulatory scrutiny.

A new report from digital accessibility specialist Deque found that European monitoring bodies are expanding their audit programmes, recruiting specialist staff and exchanging information about enforcement approaches.

At the same time, disability organisations are increasingly using the EAA’s litigation mechanisms, creating a second enforcement channel that can operate alongside formal regulatory investigations.

For banks, payment providers and other financial services firms, the emerging regime turns accessibility into a continuous software quality, compliance and digital resilience requirement. Institutions may need to demonstrate not only that their customer journeys are accessible, but that they have tested against the correct standard, logged known failures, assigned remediation responsibilities and prevented fixed defects from returning.

Deque warned that most organisations remain operationally unprepared. Drawing on its strategic consulting work, the company estimated that approximately 95% of organisations are still at either the “not started” or “informal” stage of accessibility programme maturity.

Only around 1% have reached what it calls a “repeatable” stage, while less than 1% operate at a “managed” or “leader” level.

That gap is particularly significant for banking because consumer financial services are explicitly covered by the EAA. Online account opening, authentication, payments, transfers, customer support and other transactional journeys must be usable by customers with disabilities, including those relying on screen readers, keyboard navigation, magnification and other assistive technologies.

Accessibility meets AI assurance

The EAA challenge is becoming more complicated as banks embed artificial intelligence into most of its platforms and services.

AI assistants, automated support systems and personalised interfaces remain subject to the accessibility requirements applying to the wider service. They may also introduce dynamic and non-deterministic behaviour that is harder to evaluate using conventional scripted tests.

Chris Munroe, VP of Delivery, Strategic Practices at Applause, recently argued in the context of the EU AI Act that the growth of AI will make quality engineering increasingly central to regulatory compliance.

Chris Munroe

“The AI Act will have far-reaching effects on software testing, making QA a vital component in compliance,” Munroe said.

The AI Act and the EAA impose different obligations, but both push QA teams beyond narrowly defined functional checks.

An AI chatbot may function technically but still fail if it does not identify itself as AI, produces discriminatory output, cannot be controlled by a human operator or is inaccessible to a screen-reader user.

“Testing for basic technical functionality is no longer enough because the EAA explicitly targets algorithmic bias and safety flaws,” Munroe said.

For banks, the overlap means testing may need to cover accessibility, accuracy, bias, security, explainability, human oversight and regulatory traceability within the same customer journey.

“Preparing for this new reality requires a sophisticated, multi-layered approach to quality assurance,” Munroe added. “No single testing method can handle the complexity and unpredictability of a probabilistic model on its own.”

Munroe called for a blend of human and automated validation.

“Instead, QA teams must deploy a blended strategy: manual, human-in-the-loop testing to evaluate real-world contextual nuance, traditional test automation to maintain speed, and AI-powered testing techniques, such as multi-model evaluation, to score outputs at enterprise scale.”

That blended model is equally relevant to accessibility assurance. Automated scanning provides coverage and speed, while people using assistive technologies can expose barriers that rules-based tools cannot interpret.

Continuous testing is then needed to ensure that frequent releases, third-party components and AI-generated interface changes do not undermine previous remediation.

Enforcement moves beyond warnings

The EAA became applicable across the European Union on June 28, 2025. It covers specified consumer products and services, including consumer banking, payment services, e-commerce, electronic communications and transport-related digital services.

Although the legislation establishes an EU-wide framework, enforcement is carried out through national laws, regulators and penalty regimes. This creates country-level differences, but Deque said the authorities responsible for enforcement are now moving towards greater coordination.

Monitoring bodies in Poland, Sweden, Ireland and the Netherlands have indicated plans to expand their monitoring activity during 2026, according to the report.

Germany has reportedly recruited approximately 70 auditors, while the Netherlands has added accessibility specialists. Deque said those investments point towards systematic, large-scale monitoring rather than enforcement being limited to individual complaints or occasional investigations.

The targeting of organisations is also becoming more sophisticated.


“Preparing for this new reality requires a sophisticated, multi-layered approach to quality assurance.”

– Chris Munroe

According to Deque, authorities in some countries are prioritising companies already under scrutiny for other compliance problems. Failure to submit required non-conformance reports, inadequate reporting and repeated complaints can move an organisation towards the front of the audit queue.

That potentially connects accessibility with a financial institution’s wider regulatory posture. Weaknesses in operational resilience, consumer protection, governance or regulatory reporting could become signals prompting an authority to examine the accessibility of its digital services.

A validated consumer complaint may also result in a broader audit rather than an investigation limited to the barrier originally reported. Fixing a single inaccessible button or form field may therefore be insufficient if the institution cannot show that it has assessed the wider customer journey.

The process often begins with automated scanning. When issues are detected, regulators may contact the organisation and request a response. Continued inaction can lead to more frequent communication, on-site intervention, formal sanctions and potentially litigation.

In the Netherlands, the Authority for Consumers and Markets has developed an on-site model under which it visits organisations with a blind user, examines their digital services and demonstrates which elements are inaccessible.

Deque characterised this as an educational and collaborative intervention, but also as a formal stage in an escalation process. Organisations that acknowledge known defects, report them and engage openly on remediation are placed in a substantially stronger position than companies that remain silent.

Cross-border complaints

The enforcement risk is no longer confined to the country in which a complaint originates.

Deque said complaints submitted to monitoring bodies in EU member states are entered into a central database maintained by the European Commission. A complaint filed in Ireland about a bank or digital platform that also operates in Sweden can therefore become visible to the Swedish authority.

The company said it is aware of customers contacted by monitoring bodies about complaints originally submitted by consumers in other countries.

National regulators are also exchanging information outside the Commission’s formal infrastructure. Authorities from the Netherlands, Sweden, Germany, Austria, Ireland and other countries met in Norway in May to compare approaches, share data and discuss their experience.

That informal network is operating alongside a European Commission working group launched earlier this year. The group brings together monitoring bodies, government-appointed disability organisations and representatives from the private sector.

For multinational banks, this makes fragmented national testing programmes increasingly difficult to defend. A defect in a shared component, authentication service or digital design system could be exposed in one market and subsequently examined across several European operations.

It also raises the importance of centralised defect intelligence. Accessibility findings identified by one subsidiary may need to be assessed across every digital property using the same code, supplier platform or interface pattern.

Banks show testing gaps

One of the most striking findings in the report concerns the financial sector.

Deque cited a study of 43 European financial institutions in which 33 scored below 70% in automated accessibility testing. The assessment was conducted against WCAG 2.2 rather than the broader EN 301 549 standard, meaning it did not necessarily capture all the requirements institutions may ultimately need to demonstrate.

The results do not by themselves prove that those institutions breached the EAA. Automated testing can only identify part of the accessibility failure landscape, and a percentage score is not equivalent to a legal conformance determination.

Nevertheless, the findings indicate widespread weaknesses in the digital interfaces of a sector in which inaccessible services can prevent customers from managing money, making payments or accessing essential financial products.

They also highlight the danger of testing against an incomplete or outdated benchmark.

The current EN 301 549 v3.2.1 standard incorporates WCAG 2.1 Level AA requirements for web content while extending beyond websites to areas including software, documentation and support services. Deque expects a future v4.1.1 version, currently anticipated in October 2026, to reference WCAG 2.2 AA.

Banks testing only selected WCAG requirements may therefore overlook accessibility obligations elsewhere in the service, including mobile applications, customer documentation, identification processes and support channels.

They may also produce assurance reports that overstate their position. A green automated dashboard cannot establish that a screen-reader user can successfully open an account, complete a transfer or recover access after an authentication failure.

Automated tools are effective at detecting issues such as missing accessible names, certain colour-contrast failures, invalid document structures and misuse of ARIA attributes. They are less able to determine whether information is announced in a sensible order, whether instructions are understandable or whether an error message enables a disabled customer to recover.

A defensible testing strategy consequently requires automation to be combined with manual keyboard testing, assistive-technology testing and end-to-end validation of critical customer journeys.

Regulators demand progress

Full conformance remains the objective, but Deque’s findings indicate that regulators are also examining how organisations respond when deficiencies exist.

Signals likely to concern monitoring bodies include missing or implausible accessibility plans, poor reporting of known defects, repeated complaints, unclear routes to compliance and limited evidence that remediation is progressing. This makes the underlying evidence trail almost as important as the test result itself.

An accessibility defect should be connected to the relevant requirement, affected customer journey, severity, responsible owner, remediation deadline and re-test result. Where a defect can be detected automatically, the repaired behaviour should be incorporated into regression testing so that a subsequent release does not reintroduce it.

The accessibility statement must also remain aligned with the institution’s actual defect and risk records. A statement claiming broad conformance while internal testing shows unresolved barriers could create an additional credibility problem during an investigation.

Deque outlined three steps based on its discussions with European monitoring bodies. Organisations should first establish their current risk by testing representative customer journeys against EN 301 549, rather than relying only on a WCAG scan. They should then establish a documented accessibility programme with a published roadmap and a plan for evidencing conformance.


“Ultimately, testing AI-enabled products is about much more than dodging non-compliance penalties.”

–Chris Munroe

Finally, banks need internal structures connecting product, engineering, QA, legal, compliance and customer support. Those structures must include a process for receiving complaints, escalating them quickly and engaging constructively with regulators.

The report found that these functions frequently operate in silos. Legal teams may lack the technical expertise to evaluate accessibility exposure, while product teams may fix an isolated defect without understanding whether the remediation meets the applicable standard.

Customer support is another potential point of failure. If frontline teams cannot recognise an accessibility complaint or have no route for escalating it, a manageable software defect may develop into a regulatory matter.

Litigation

Regulatory monitoring is only one part of the risk. The EAA allows consumers to complain directly to companies, monitoring bodies and disability advocacy organisations.

Legal action is also possible, while disability associations can bring cases on behalf of the groups they represent without relying on individual claimants.

France has provided one of the clearest examples of this civil-society enforcement route.

In 2025, disability organisations ApiDV and Droit Pluriel, together with legal collective Intérêt à Agir, issued non-conformance notices against four major French grocery groups.

After the stated remediation period passed, the organisations sought emergency legal action. On June 4, 2026, a French court ordered Carrefour to make its online commerce services fully accessible within six months, with daily fines for continued delay, according to Deque.

A separate action against Auchan was dismissed but appealed. Meanwhile, associations belonging to the French Collective for Visual Impairment announced a class action against the country’s public finance directorate over the accessibility of its online tax portal.

Although these actions did not target banks, they establish a litigation model that could be applied to other essential consumer services. A digital banking journey that prevents a customer from accessing funds or completing a payment could provide a particularly powerful basis for a complaint.

An institution could also face simultaneous scrutiny from a national regulator and a disability organisation. Deque warned that most companies are not structured to manage either process effectively, let alone both at the same time.

From compliance exercise to resilience programme

The emerging EAA regime challenges the idea that accessibility can be handled through an annual audit shortly before publication of a compliance statement.

Banks operate large, interconnected digital estates in which a change to a design system, identity platform or third-party payment component can affect numerous products and markets. Accessibility therefore needs to be integrated into release controls, regression suites, supplier assurance and operational risk reporting.

Critical journeys should be inventoried by customer outcome rather than by webpage. Opening an account, logging in, transferring money, authorising a payment, downloading a statement and contacting support each contain multiple states that a simple URL scan may never reach.

Error handling deserves particular attention. A payment flow might appear accessible until a transaction is rejected, a one-time password expires or identity verification fails.

These exceptional states are also where operational resilience and accessibility intersect most clearly: a service is not resilient for a disabled customer if the recovery journey is inaccessible.

The same principle applies to third parties. Banks may depend on external identity-verification services, payment gateways, chat platforms and software development kits. Contractual assurances cannot replace testing of how those components behave inside the finished customer journey.

Ultimately, the strongest defence is not a perfect score captured at a single moment. It is a documented system showing that the institution understands its risk, tests the right services against the right standards, responds to complaints and continuously reduces known barriers.

As Munroe put it: “Ultimately, testing AI-enabled products is about much more than dodging non-compliance penalties. It is about protecting a company’s hard-earned brand reputation and providing users with digital experiences that are safe, reliable and enjoyable.”

The first year of EAA enforcement suggests European authorities increasingly expect the same principle to apply to accessibility. For financial institutions, accessibility is no longer a peripheral usability consideration. It is becoming a test of software quality, customer protection, regulatory readiness and digital resilience.


The EAA enforcement challenges explored in this article will be addressed in practical terms during AI for Accessibility and Cutting-Edge UX, a three-hour workshop led by Dana Randall of Level Access on September 15, from 12:00 pm BST. Delegates will learn how to use AI to identify accessibility risks earlier, build more inclusive customer experiences and integrate accessibility into the software lifecycle. View the workshop and register here.

NEXT MONTH

REGISTER TODAY – SIMPLY CLICK HERE


Why not become a QA Financial subscriber?

It’s entirely FREE

* Receive our weekly newsletter every Wednesday * Get priority invitations to our Forum events *

SIGN UP HERE TODAY


REGULATION & COMPLIANCE

Looking for more news on regulations and compliance requirements driving developments in software quality engineering at financial firms? Visit our dedicated Regulation & Compliance page here.


READ MORE


WATCH NOW


QA FINANCIAL PODCASTS

CLICK HERE TO LISTEN TO OUR EXCLUSIVE CONVERSATIONS