Arcadia Fund

https://arcadiafund.org.uk · 50/92 checks passed · not_for_profit

Compliance report (framework 0.8)

Gate passed (every Core check must pass) · not counted towards the gate: paused 35, draft 48, ready for review 54.

Site level: 0 (no scored checks yet).

By level

LevelResult
Level 1 — Basic 26/37 (11 failed)
Level 2 — Enhanced 11/27 (16 failed)
Level 3 — Advanced 0/10 (9 failed)

By category

CategoryResult
Accessibility 9/13
Accountability 0/5
AI & Automation 3/8
Interoperability 1/3
Privacy 13/16
Provenance 2/2
Security 4/11
Transparency 5/13
Responsibility to the Future 0/3

Level 1 — Basic

Accessibility

AI & Automation

  • policy_exists: The About page contains no AI use policy or statement of any kind.
    Fix: Publish a clear AI use policy or statement on the site describing whether and how AI is used.
  • scope_clear: Since no AI policy is present, the scope of AI use is not explained.
    Fix: Add a section to the AI policy specifying the purposes and contexts in which AI tools are used.

Privacy

Security

Transparency

  • purpose_clear: The page describes Arcadia as a family philanthropy that makes grants but does not clearly state what its funding purpose or mission is on this page.
    Fix: Add a concise statement on the About page describing what Arcadia funds and why (e.g., its focus on culture, nature, and open access).

Level 2 — Enhanced

Accessibility

Accountability

  • named_person: The page lists only generic email aliases (info@, media@) and a LinkedIn handle without naming any individual or specific role as responsible.
    Fix: Add the name and/or title of a specific person or team (e.g., Head of Communications) who is accountable for responding to enquiries.
  • response_timeframe: The contact page lists email addresses but does not publish any expected response timeframe for enquiries.
    Fix: Add a stated response window (e.g., 'We aim to respond within 10 business days') next to the contact email addresses.
  • specific: Because no timeframe is published at all, there is no specific day-based commitment on the page.
    Fix: Publish a concrete number of days (e.g., '5 working days') rather than vague language when specifying response times.
  • process_exists: The page only shows a 'Report fraudulent activity' link and generic enquiry emails, with no documented complaints or feedback process.
    Fix: Create and link to a dedicated complaints/feedback policy page describing how to raise concerns and how they will be handled.
  • steps_clear: No steps for making a complaint are described on the contact page.
    Fix: Document a clear step-by-step complaints procedure (who to contact, what information to include, escalation path, and expected outcomes).
  • appeals_exists: The contact page only lists email addresses and states they don't accept applications, with no documented appeals process provided.
    Fix: Add a dedicated section or linked page outlining a formal appeals process for grant or funding-related decisions.
  • independent: No appeals mechanism is mentioned, so there is no indication of independence or escalation pathways.
    Fix: Document an escalation route to an independent reviewer or committee distinct from the original decision-makers.

AI & Automation

  • detailed_scope: The page provides no detail on the scope of AI use because no AI policy exists.
    Fix: Include a detailed description of AI use cases, systems, and data involved in an AI policy page.
  • limitations: No limitations of AI systems are acknowledged anywhere on the page.
    Fix: Add an explicit section acknowledging the limitations, risks, and known failure modes of any AI systems used.
  • safeguards: No safeguards or quality control measures for AI are described on the page.
    Fix: Document the human oversight, review processes, and quality controls applied to AI outputs in the policy.
  • marking_policy: The About page contains no policy or statement describing how AI-assisted content is marked or disclosed.
    Fix: Publish a clear policy stating whether and how AI-assisted content is labeled on the site.
  • consistent: With no marking policy present, there is no evidence that AI content labeling is applied consistently across the page.
    Fix: Adopt and consistently apply a visible AI-content label (e.g., a tag or disclosure line) wherever AI-assisted material appears.
  • oversight_exists: The page does not document any human oversight of AI outputs.
    Fix: Add a statement describing how staff review and oversee any AI-generated outputs used on the site.
  • review_process: No review or approval process for AI content is described anywhere on the page.
    Fix: Document the specific review/approval workflow (who checks, against what criteria, before publication) for AI-assisted content.
  • accountability: No individual or role is named as accountable for AI-generated content, though team roles are listed for other functions.
    Fix: Assign and publicly name a role (e.g., the Operations and Communications Manager) as accountable for AI-generated content.

Interoperability

Privacy

  • specific: While some periods are specific (six years, six months), retention for completed grant records and event/contract data is vague with no defined time period.
    Fix: Add explicit retention periods for completed grant records, event attendee data, and contract/payment records rather than keeping them indefinitely for 'learning purposes'.
  • banner_present: The page content shows no visible cookie or consent banner.
    Fix: Implement a visible cookie/consent banner on page load that informs users about cookie usage and offers accept/reject options.
  • partner_sharing_mentioned: There is no on-page consent copy disclosing data sharing with third-party partners.
    Fix: Add clear consent copy that discloses whether and how user data is shared with third-party partners.
  • partner_count_specific: No partner sharing is disclosed, so no specific numeric count of partners is stated.
    Fix: If third-party data sharing occurs, state the exact number of partners (e.g., 'We share data with X partners') within the consent disclosure.

Provenance

Security

Transparency

  • named_person: No named individual or specific team is identified for enquiries—only generic info@ and media@ email addresses are provided.
    Fix: Identify the responsible individual or team (e.g., 'Communications Team, led by [Name]') alongside the enquiry email addresses.
  • role_clear: Because no person or team is named, their role or authority for handling enquiries is not stated.
    Fix: State the role/authority of the contact (e.g., 'Media Relations Manager handles all press enquiries') next to each email address.
  • substantive: The statement of purpose is minimal, focusing on governance and structure rather than providing a substantive description of Arcadia's philanthropic aims.
    Fix: Expand the About page with a detailed description of Arcadia's funding areas, goals, and impact beyond organisational structure.
  • mission_clear: No explicit mission statement or editorial/grant-making approach is articulated on the page.
    Fix: Add a clear mission statement explaining Arcadia's philanthropic priorities and the approach it takes to grant-making.
  • detail: The disclosure references 'family trusts' generically without providing amounts, percentages, or specific named trust categories beyond the grant-making vehicle.
    Fix: Add specifics such as the names of the funding family trusts and approximate annual contribution amounts or percentages to provide meaningful detail.
  • complete: It is unclear whether 'family trusts' captures all funding streams, and no mention is made of investment income, endowments, or other potential revenue sources.
    Fix: Expand the disclosure to enumerate every major funding stream (e.g., endowment returns, individual donations, partner co-funding) so readers can confirm completeness.
  • algorithm_explained: The page describes Arcadia's governance and team but does not mention or explain any algorithms or their purpose.
    Fix: If algorithms are used in grantmaking or operations, add a dedicated section describing each algorithm and its intended purpose.
  • impact_clear: There is no description of how algorithmic decisions affect users, applicants, or grantees on this page.
    Fix: Publish a clear statement outlining how any algorithmic decision-making impacts applicants and stakeholders, including possible outcomes and recourse.
  • annual_statement: The page links to a privacy policy but shows no evidence of a regular annual or periodic review of data practices.
    Fix: Add a statement to the privacy policy indicating when it was last reviewed and commit to periodic (e.g., annual) reviews.
  • dated: The visible content references a privacy policy link but does not display any date or version for the data practices statement.
    Fix: Include a clear 'Last updated' date or version number on the privacy policy and reference it from the about page.

Level 3 — Advanced

Accessibility

  • statement_exists: The about page contains no dedicated accessibility statement, only general 'who we are', contact, and governance content.
    Fix: Create a dedicated accessibility statement page and link it in the site footer alongside the privacy policy.
  • known_issues: With no accessibility statement present, there is no acknowledgment of any known accessibility issues or limitations.
    Fix: In the accessibility statement, list known limitations (e.g., non-conforming PDFs or third-party content) and their impact on users.
  • remediation_timeline: No timeline or commitment for fixing accessibility issues appears anywhere on the page.
    Fix: Add target dates or a commitment describing when identified accessibility issues will be resolved.
  • feedback_channel: While general and media email addresses are listed, there is no accessibility-specific feedback mechanism with a response commitment.
    Fix: Provide a dedicated accessibility feedback contact and state a response time commitment (e.g., replies within 5 working days).

Accountability

  • policy_exists: The About page contains no published moderation policy for user-generated or community content.
    Fix: Publish a moderation policy page (linked from the footer or About section) describing what content is moderated and under what rules.
  • criteria_clear: No moderation criteria or content standards are stated anywhere on the page.
    Fix: Clearly list the criteria (e.g., prohibited content, acceptable use) used to moderate submissions or communications.
  • enforcement: There is no description of how moderation decisions are made, enforced, or appealed on this page.
    Fix: Add an enforcement section explaining who reviews content, what actions are taken, and how users can appeal decisions.

Interoperability

Security

  • plan_exists: The page contains only organizational information (who we are, board members, team, contact) with no published incident response plan or policy.
    Fix: Publish an incident response plan or policy document and link to it from the site (e.g., alongside the privacy policy).
  • notification_commitment: There is no statement committing to public notification of significant security or data incidents anywhere on the page.
    Fix: Add an explicit commitment to notify the public and affected users of significant incidents within the incident response policy.
  • timeframe: The page states no timeframe for disclosing incidents to affected users, as it only lists staff, boards, and contact details.
    Fix: Specify a concrete disclosure timeframe (e.g., notification within 72 hours of discovery) in the incident response policy.

Transparency

  • criteria_published: The page contains no published criteria for algorithmic decision-making, only general information about the organization and team.
    Fix: Publish the specific criteria used in any algorithmic decisions in a transparent, accessible section of the website.
  • weighting: No weighting or prioritization of decision criteria is disclosed anywhere on the page.
    Fix: Document and publish the relative weights or priorities assigned to each criterion used in algorithmic decisions.
  • auditable: The page provides no technical or methodological detail that would allow external audit or review of any algorithm.
    Fix: Release a methodology document or audit-ready technical specification enabling independent external review of algorithmic systems.
  • open_source: There is no link to source code or any indication that the site's code is publicly available.
    Fix: If applicable, publish the site's source code in a public repository (e.g., GitHub) and link to it from the About or footer.
  • tech_docs: No technical documentation is published or linked from the page.
    Fix: Publish technical documentation (e.g., about grant data, 360 Giving data standards used, or site architecture) and link it from the About page.

Responsibility to the Future

  • disclosure_exists: The About page describes Arcadia's philanthropic mission and team but contains no published environmental impact or sustainability disclosure.
    Fix: Publish a dedicated environmental impact or sustainability statement describing the organization's environmental footprint and commitments.
  • specific_metrics: The page provides no specific figures such as carbon emissions, energy use, or other quantitative environmental metrics.
    Fix: Add measurable environmental data (e.g., annual carbon emissions, energy consumption) to the sustainability disclosure.
  • hosting_disclosure: There is no mention of the carbon or energy profile of the website's hosting infrastructure anywhere on the page.
    Fix: Disclose the hosting provider's carbon or energy profile, such as whether the site is hosted on renewable-powered or green-certified infrastructure.
  • plan_exists: The about page describes the organisation's structure and funding but contains no published plan for what happens if Arcadia fails or exits.
    Fix: Publish a succession or wind-down plan describing how the organisation and its funded programmes would be handled in the event of closure or exit.
  • data_and_content_fate: The page mentions Creative Commons and open access but does not address what would happen to user data or published content if the organisation ceased operating.
    Fix: Add a statement specifying how user data and published content would be preserved, migrated, or archived if the organisation shuts down.
  • custodians_or_mirrors: No custodians, mirrors, or archive partners are identified anywhere on the page for continuity of content should the organisation exit.
    Fix: Name a designated custodian, archive partner, or mirror service that would maintain content if the organisation ceases to operate.
  • policy_exists: The about page describes the organization's structure, boards, and team but contains no published policy on worker wellbeing or working conditions.
    Fix: Publish a dedicated worker wellbeing or working conditions policy and link to it from the site.
  • specific_commitments: There are no specific commitments regarding pay, hours, mental health, or benefits anywhere on the page.
    Fix: Add concrete commitments covering pay, working hours, mental health support, and benefits to the published policy.
  • accountability: While the page lists boards and a management team, it does not assign any accountability or oversight specifically for worker conditions.
    Fix: Name a role or body (e.g., the COO or a designated committee) responsible for overseeing and reporting on worker conditions.