Top 25 GIGW Audit Findings for STQC Compliance (2026)

Many Government Websites Don't Fail GIGW Audits Because of Complex Technology They Fail Because of Small Compliance Gaps.

Government organizations invest significant time and resources in designing websites that serve citizens, businesses, and stakeholders. Yet, when it comes to GIGW (Guidelines for Indian Government Websites) or STQC compliance assessments, many websites fall short—not because of major security flaws, but because of overlooked accessibility, usability, governance, and content management issues.

A missing accessibility feature, an outdated privacy policy, broken links, inaccessible PDF documents, or weak security headers can all contribute to non-compliance. The good news is that most of these issues are preventable.

Understanding the common findings observed during GIGW audits allows organizations to proactively address gaps before formal assessments, reducing project delays, improving citizen experience, and strengthening digital governance.

Who Should Read This Guide?

If your organization is planning for GIGW 3.0 or STQC certification, this checklist can help you prepare effectively. This guide is specifically useful for:

Government Departments
Public Sector Undertakings (PSUs)
Municipal Corporations
Smart City Projects
Government Universities
Government Agencies & NIC Teams
Website Development Agencies
Digital Transformation Teams
Compliance Officers

Why Government Websites Commonly Fail GIGW Audits

Many organizations assume that website compliance is only about design or security. In reality, GIGW evaluates multiple aspects including accessibility, performance, security, content governance, citizen experience, technical standards, and information architecture.

Common reasons for audit findings include:

  • Websites developed without GIGW requirements in mind.
  • Accessibility testing performed late in the project.
  • Outdated content.
  • Lack of periodic website reviews.
  • Missing governance documentation.
  • Security configurations overlooked during deployment.
From the Field – Lumiverse Insight:

During compliance assessments, one recurring observation is that organizations often focus heavily on website functionality while underestimating accessibility and governance requirements. A technically functional website may still fail a GIGW audit if citizen accessibility and content management practices are not aligned with the guidelines.

A Practical Scenario

Consider a government department that launches a redesigned citizen service portal. The website is responsive, visually appealing, and integrated with online services.

However, during the GIGW assessment, auditors identify missing ALT text for images, broken PDF accessibility, weak keyboard navigation, missing security headers, outdated contact information, and poor heading hierarchy.

Although the portal functions correctly, these issues delay compliance and require additional remediation before certification. This highlights why GIGW readiness should begin during website planning—not after development is complete.

Top 25 GIGW Audit Findings

Below are the top 25 GIGW audit findings commonly identified by assessors. Addressing these checklist items is crucial to achieving formal STQC compliance:

1. Missing Alternative Text (ALT Text) for Images

Images without descriptive ALT text create accessibility barriers for visually impaired users relying on screen readers.

2. Improper Heading Structure

Incorrect or skipped headings (H1, H2, H3 hierarchy) affect readability and search engine structure validation.

3. Poor Keyboard Navigation

Interactive elements must be fully navigable using only keyboard inputs (Tab key support, focus indicators).

4. Low Color Contrast

Insufficient contrast between background color and text elements makes content illegible for visually challenged users.

5. Non-Accessible PDF Documents

Circulars and documents published in PDF formats frequently lack OCR parsing, preventing reading by assistive systems.

6. Broken Internal Links

Dead links throughout the website negatively impact usability and break citizen search paths.

7. Missing Sitemap

Missing XML or HTML sitemaps decreases search engine discoverability and manual site-mapping transparency.

8. Inconsistent Navigation

Changing menu hierarchies and sidebars across different sections confuses users and degrades usability.

9. Missing Breadcrumb Navigation

Failing to display location paths makes it difficult for users to track their current position within nested sub-pages.

10. Outdated Content

Allowing expired notifications, circulars, or old office addresses to remain online decreases information trustworthiness.

11. Missing Privacy Policy

Every public portal must disclose user data logging, cookie settings, and tracking disclosures clearly.

12. Missing Terms & Conditions

Explicit terms of usage, liability exclusions, and copyright guidelines must be easily accessible in the footer.

13. Weak Search Functionality

Inability to search, filter, or index documents and citizen services efficiently leads to navigation frustration.

14. Missing Contact Information

Failing to supply updated support channels, directory offices, or grievance officer contacts violates content mandates.

15. Inaccessible Online Forms

Feedback or request forms lacking proper labeling, input guidelines, and error announcements fail accessibility rules.

16. Missing SSL or Mixed Content Issues

Not enforcing HTTPS universally or running insecure assets over HTTP degrades connection trustworthiness.

17. Missing Security Headers

Lacking crucial headers (CSP, HSTS, X-Frame-Options) exposes portals to clickjacking, XSS, and transport attacks.

18. Poor Mobile Responsiveness

Portals with rigid container scales break layouts on mobile browsers, restricting citizen-centric accessibility.

19. Slow Website Performance

Bloated scripts, missing server-side caching, and uncompressed assets cause long load delays.

20. Missing Accessibility Declaration

Failing to host a visible accessibility statement listing compliance standards and accessibility point-of-contact.

21. No Content Review Process

Lacking defined schedules, governance parameters, and ownership guidelines to review and archive content.

22. Improper Metadata

Missing structural page title tags or descriptive meta tags makes search indexing and cataloging difficult.

23. No Disaster Recovery Information

Lacking documented backup schedules, server redundancies, and disaster recovery procedures for critical sites.

24. CAPTCHA Accessibility Issues

Enforcing visual verification forms without providing audio options locks out disabled users from sending submissions.

25. Lack of Periodic Security Assessment

Failing to run regular vulnerability scans, penetration tests, and security reviews to validate application defenses.

What Most Organizations Overlook

One of the biggest misconceptions is that passing a functional acceptance test means the website is ready for GIGW certification. It doesn't.

GIGW evaluates how well the website serves all citizens, including people with disabilities, users accessing the site from different devices, and those relying on assistive technologies. Similarly, technical security alone cannot compensate for poor accessibility or weak governance practices. Compliance requires a balanced approach that combines usability, accessibility, security, and content governance.

A 5-Step GIGW Readiness Framework

To systematically resolve common findings and prepare for formal audits, organizations should implement this structured readiness roadmap:

01

Perform a GIGW Gap Assessment

Initiating a comprehensive audit of the website against GIGW 3.0 guidelines reveals existing accessibility, usability, and technical shortcomings.

02

Validate Accessibility Controls

Systematically verify keyboard navigation focus, screen reader compatibility, forms markup, color ratios, and the readability of downloadable PDF attachments.

03

Review Technical Security

Expose logical bugs and software configuration gaps by conducting standard website Vulnerability Assessments and implementing security headers.

04

Strengthen Content Governance

Verify that updated privacy declarations, contact directories, terms of service, metadata, and scheduled content archiving procedures are documented.

05

Conduct a Pre-STQC Assessment

Perform an internal audit simulation utilizing professional STQC readiness assessment methodologies to confirm GIGW readiness.

GIGW Self-Assessment Checklist

Verify that your portal satisfies these compliance baselines before submitting an application for official STQC certification:

Follows GIGW 3.0 Guidelines
WCAG Requirements Satisfied
Image ALT Text Added
Accessible PDF Documents
Keyboard Navigable Forms
SSL Enforced Globally
Security Headers Configured
Mobile Responsiveness Verified
Updated Content Audited
VAPT Completed
Policy and Terms Available
XML Sitemap Generated

Achieve Seamless STQC Compliance for Your Portal

Preparing for a GIGW or STQC assessment is far more effective when accessibility, security, and governance are built directly into your website's lifecycle. Partnering with certified compliance professionals ensures that gaps are identified early and corrected prior to official audits.

If your department is preparing for certification, you can learn more about our structured GIGW compliance services or contact Lumiverse Solutions today for a comprehensive readiness review.

Frequently Asked Questions

What are GIGW Audit Findings?

GIGW audit findings are observations identifying gaps between a government website and the Guidelines for Indian Government Websites (GIGW), covering accessibility, usability, security, content governance, and technical compliance.

What is the purpose of a GIGW audit?

A GIGW audit ensures government websites are accessible, secure, user-friendly, and compliant with national digital governance standards.

Is GIGW different from STQC certification?

Yes. GIGW provides the compliance framework, while STQC conducts assessments and certification based on applicable requirements.

How often should government websites undergo compliance reviews?

Organizations should conduct periodic internal reviews and security assessments, particularly after significant website updates or new feature deployments.

Does GIGW include cybersecurity requirements?

Yes. While accessibility and usability are key focus areas, GIGW also expects secure website configurations, HTTPS implementation, and ongoing security assessments to support citizen trust.

Disclaimer

This article is designed as a general information guide only and does not constitute formal, professional compliance, cybersecurity, or legal advice. Every government department and public portal operates within distinct IT architectures and guidelines. Organizations must conduct independent research and consult with certified compliance experts and information security professionals prior to scheduling formal STQC certification audits. Lumiverse Solutions Pvt. Ltd. holds no liability for actions taken or security outcomes arising from the information compiled in this guide.