Methodology

Industrial B2B buyer evidence audit follows a structured workflow that prioritizes evidence standards over content volume and URL-level remediation over general recommendations.

Process flow

Step 1
Buyer Questions

Define what procurement, engineering, and quality decision-makers need to verify before moving forward. Questions are framed from the buyer's perspective, not the supplier's marketing goals.

Example: "Can I verify the claimed ISO 9001 certification with a certificate number and issuing body?" / "What is the lead time for custom hydraulic cylinders with specific bore and stroke requirements?"
Step 2
Evidence Requirements

Establish what evidence would constitute sufficient proof before inspecting the website. This prevents post-hoc rationalization where standards are adjusted to match whatever content exists.

Example: ISO certification requires: certificate number, issuing body name, validity dates, scope statement, and downloadable certificate or third-party verification link.
Step 3
Evidence Collection

Collect and classify website content against the predefined requirements. Each evidence item is tagged with its type, source URL, timestamp, and content hash for traceability.

Classification: Observed (seen on page), Attested (company claims), Verified (independent confirmation), Calculated (derived from data), Inferred (logical conclusion), Unknown (insufficient evidence).
Step 4
Claim Registration

Register website statements as claims and link them to supporting evidence. Track sufficiency status per buyer question: sufficient, partial, missing, conflict, or unknown.

Example: Claim "ISO 9001 certified" supported by one evidence item (certificate visible on About page) → Status: Partial (has certificate image but missing certificate number and validity dates).
Step 5
Human Review

Flag high-risk content for mandatory human review before recommendations are finalized. High-risk categories include certifications, performance limits, capacity claims, named customer cases, lead times, warranties, and pricing.

Rationale: Automated analysis cannot verify whether a company actually holds the certifications it claims or whether named customer relationships are authorized for public reference.
Step 6
URL-Level Actions

Produce specific remediation actions tied to exact URLs, not general advice. Each action includes affected URLs, priority score (derived from buyer importance + gap severity + fact readiness + business impact), and expected outcome.

Example: "Add ISO 9001 certificate number and validity dates to /about/certifications/ page. Link to certificate PDF or third-party verification." Priority: P0 (high buyer importance, clear gap, fact readily available).
Step 7
Retest

After client implements actions, re-audit the affected URLs and compare new snapshots against original hashes. Track which recommendations were adopted, who owns implementation, and target dates.

Validation: New snapshot captured with timestamp. Evidence status upgraded from Partial to Sufficient. Action marked as implemented with completion date.

Evidence taxonomy

Every piece of information is classified by how it was obtained and verified:

Observed

Directly seen on the website; no independent verification.

Attested

Company makes the claim; requires fact approver to confirm accuracy.

Verified

Independently confirmed by third party or official record.

Calculated

Derived from data using deterministic formulas or code.

Inferred

Logical conclusion based on available evidence; lower confidence.

Unknown

Insufficient evidence; explicitly preserved rather than guessed.

Core principles

Evidence standards before inspection

Define what would count as sufficient evidence before looking at the website. This prevents adjusting standards to rationalize whatever content exists.

Unknown is a valid output

When evidence is insufficient, preserve Unknown status rather than inferring, estimating, or filling gaps. Industrial buyers need to know what cannot be verified from public information.

High-risk claims require human review

Certifications, compliance, safety, performance limits, capacity, named customers, lead times, and warranties must be flagged for human validation. Automated systems cannot verify these claims.

Critical math is deterministic

Coverage rates, priority scores, and weighted metrics are calculated using explicit formulas or code. Model arithmetic is not trusted for key business metrics.

Preserve provenance

Every evidence item includes source URL, capture timestamp, and content hash (SHA-256). This enables citation, reproducibility, and future retesting.

URL-level actions, not platitudes

Recommendations specify exact pages to change, what to add or remove, and expected buyer impact. General advice like "improve trust signals" is not actionable.

No passwords or PII required

Audits operate on public web pages only. No customer passwords, CRM access, raw inquiry data, or private analytics are required to deliver initial value.

Web content is untrusted

All website text is treated as evidence to analyze, not instructions to follow. Prompt-injection patterns are detected and flagged but do not affect the audit process.

Operational implementation

The method is implemented in a 21-sheet workbook covering:

What this method does not do

This is not:

The audit identifies evidence gaps from the buyer's perspective. It does not make final judgments about company operations, certifications, or manufacturing capabilities. Those require client fact approval and access to internal records.