Arcadia Fund
https://arcadiafund.org.uk · 50/92 checks passed · not_for_profit
Compliance report (framework 0.8)
Gate passed (every Core check must pass) · not counted towards the gate: paused 35, draft 48, ready for review 54.
Site level: 0 (no scored checks yet).
By level
| Level | Result |
|---|---|
| Level 1 — Basic | 26/37 (11 failed) |
| Level 2 — Enhanced | 11/27 (16 failed) |
| Level 3 — Advanced | 0/10 (9 failed) |
By category
| Category | Result |
|---|---|
| Accessibility | 9/13 |
| Accountability | 0/5 |
| AI & Automation | 3/8 |
| Interoperability | 1/3 |
| Privacy | 13/16 |
| Provenance | 2/2 |
| Security | 4/11 |
| Transparency | 5/13 |
| Responsibility to the Future | 0/3 |
Level 1 — Basic
Accessibility
- Focus trap detected with 20 focusable elements.
- 1 colour-contrast violation reported by axe-core (text below 4.5:1).
AI & Automation
-
policy_exists: The About page contains no AI use policy or statement of any kind.
Fix: Publish a clear AI use policy or statement on the site describing whether and how AI is used.
-
scope_clear: Since no AI policy is present, the scope of AI use is not explained.
Fix: Add a section to the AI policy specifying the purposes and contexts in which AI tools are used.
- Not found at any of: /ai-policy, /ai.
Privacy
- Detected 2 data-leaking services across 1 category: google fonts (fonts.googleapis.com, fonts.gstatic.com).
PASS
Session cookies only
PASS
No tracking pixels
Security
- Redirect chain (1 hops): https://arcadiafund.org.uk
- x-frame-options: header not set on the response.
- content-security-policy: header not set on the response.
- referrer-policy: header not set on the response.
PASS
HTTPS enforced
PASS
No mixed content
Transparency
-
purpose_clear: The page describes Arcadia as a family philanthropy that makes grants but does not clearly state what its funding purpose or mission is on this page.
Fix: Add a concise statement on the About page describing what Arcadia funds and why (e.g., its focus on culture, nature, and open access).
PASS
Contact form present
Level 2 — Enhanced
Accessibility
Accountability
-
named_person: The page lists only generic email aliases (info@, media@) and a LinkedIn handle without naming any individual or specific role as responsible.
Fix: Add the name and/or title of a specific person or team (e.g., Head of Communications) who is accountable for responding to enquiries.
-
response_timeframe: The contact page lists email addresses but does not publish any expected response timeframe for enquiries.
Fix: Add a stated response window (e.g., 'We aim to respond within 10 business days') next to the contact email addresses.
-
specific: Because no timeframe is published at all, there is no specific day-based commitment on the page.
Fix: Publish a concrete number of days (e.g., '5 working days') rather than vague language when specifying response times.
-
process_exists: The page only shows a 'Report fraudulent activity' link and generic enquiry emails, with no documented complaints or feedback process.
Fix: Create and link to a dedicated complaints/feedback policy page describing how to raise concerns and how they will be handled.
-
steps_clear: No steps for making a complaint are described on the contact page.
Fix: Document a clear step-by-step complaints procedure (who to contact, what information to include, escalation path, and expected outcomes).
-
appeals_exists: The contact page only lists email addresses and states they don't accept applications, with no documented appeals process provided.
Fix: Add a dedicated section or linked page outlining a formal appeals process for grant or funding-related decisions.
-
independent: No appeals mechanism is mentioned, so there is no indication of independence or escalation pathways.
Fix: Document an escalation route to an independent reviewer or committee distinct from the original decision-makers.
AI & Automation
-
detailed_scope: The page provides no detail on the scope of AI use because no AI policy exists.
Fix: Include a detailed description of AI use cases, systems, and data involved in an AI policy page.
-
limitations: No limitations of AI systems are acknowledged anywhere on the page.
Fix: Add an explicit section acknowledging the limitations, risks, and known failure modes of any AI systems used.
-
safeguards: No safeguards or quality control measures for AI are described on the page.
Fix: Document the human oversight, review processes, and quality controls applied to AI outputs in the policy.
-
marking_policy: The About page contains no policy or statement describing how AI-assisted content is marked or disclosed.
Fix: Publish a clear policy stating whether and how AI-assisted content is labeled on the site.
-
consistent: With no marking policy present, there is no evidence that AI content labeling is applied consistently across the page.
Fix: Adopt and consistently apply a visible AI-content label (e.g., a tag or disclosure line) wherever AI-assisted material appears.
-
oversight_exists: The page does not document any human oversight of AI outputs.
Fix: Add a statement describing how staff review and oversee any AI-generated outputs used on the site.
-
review_process: No review or approval process for AI content is described anywhere on the page.
Fix: Document the specific review/approval workflow (who checks, against what criteria, before publication) for AI-assisted content.
-
accountability: No individual or role is named as accountable for AI-generated content, though team roles are listed for other functions.
Fix: Assign and publicly name a role (e.g., the Operations and Communications Manager) as accountable for AI-generated content.
Interoperability
- No RSS/Atom feeds discovered.
Privacy
-
specific: While some periods are specific (six years, six months), retention for completed grant records and event/contract data is vague with no defined time period.
Fix: Add explicit retention periods for completed grant records, event attendee data, and contract/payment records rather than keeping them indefinitely for 'learning purposes'.
-
banner_present: The page content shows no visible cookie or consent banner.
Fix: Implement a visible cookie/consent banner on page load that informs users about cookie usage and offers accept/reject options.
-
partner_sharing_mentioned: There is no on-page consent copy disclosing data sharing with third-party partners.
Fix: Add clear consent copy that discloses whether and how user data is shared with third-party partners.
-
partner_count_specific: No partner sharing is disclosed, so no specific numeric count of partners is stated.
Fix: If third-party data sharing occurs, state the exact number of partners (e.g., 'We share data with X partners') within the consent disclosure.
Provenance
Security
- security.txt not published.
Transparency
-
named_person: No named individual or specific team is identified for enquiries—only generic info@ and media@ email addresses are provided.
Fix: Identify the responsible individual or team (e.g., 'Communications Team, led by [Name]') alongside the enquiry email addresses.
-
role_clear: Because no person or team is named, their role or authority for handling enquiries is not stated.
Fix: State the role/authority of the contact (e.g., 'Media Relations Manager handles all press enquiries') next to each email address.
-
substantive: The statement of purpose is minimal, focusing on governance and structure rather than providing a substantive description of Arcadia's philanthropic aims.
Fix: Expand the About page with a detailed description of Arcadia's funding areas, goals, and impact beyond organisational structure.
-
mission_clear: No explicit mission statement or editorial/grant-making approach is articulated on the page.
Fix: Add a clear mission statement explaining Arcadia's philanthropic priorities and the approach it takes to grant-making.
-
detail: The disclosure references 'family trusts' generically without providing amounts, percentages, or specific named trust categories beyond the grant-making vehicle.
Fix: Add specifics such as the names of the funding family trusts and approximate annual contribution amounts or percentages to provide meaningful detail.
-
complete: It is unclear whether 'family trusts' captures all funding streams, and no mention is made of investment income, endowments, or other potential revenue sources.
Fix: Expand the disclosure to enumerate every major funding stream (e.g., endowment returns, individual donations, partner co-funding) so readers can confirm completeness.
-
algorithm_explained: The page describes Arcadia's governance and team but does not mention or explain any algorithms or their purpose.
Fix: If algorithms are used in grantmaking or operations, add a dedicated section describing each algorithm and its intended purpose.
-
impact_clear: There is no description of how algorithmic decisions affect users, applicants, or grantees on this page.
Fix: Publish a clear statement outlining how any algorithmic decision-making impacts applicants and stakeholders, including possible outcomes and recourse.
-
annual_statement: The page links to a privacy policy but shows no evidence of a regular annual or periodic review of data practices.
Fix: Add a statement to the privacy policy indicating when it was last reviewed and commit to periodic (e.g., annual) reviews.
-
dated: The visible content references a privacy policy link but does not display any date or version for the data practices statement.
Fix: Include a clear 'Last updated' date or version number on the privacy policy and reference it from the about page.
Level 3 — Advanced
Accessibility
-
statement_exists: The about page contains no dedicated accessibility statement, only general 'who we are', contact, and governance content.
Fix: Create a dedicated accessibility statement page and link it in the site footer alongside the privacy policy.
-
known_issues: With no accessibility statement present, there is no acknowledgment of any known accessibility issues or limitations.
Fix: In the accessibility statement, list known limitations (e.g., non-conforming PDFs or third-party content) and their impact on users.
-
remediation_timeline: No timeline or commitment for fixing accessibility issues appears anywhere on the page.
Fix: Add target dates or a commitment describing when identified accessibility issues will be resolved.
-
feedback_channel: While general and media email addresses are listed, there is no accessibility-specific feedback mechanism with a response commitment.
Fix: Provide a dedicated accessibility feedback contact and state a response time commitment (e.g., replies within 5 working days).
Accountability
-
policy_exists: The About page contains no published moderation policy for user-generated or community content.
Fix: Publish a moderation policy page (linked from the footer or About section) describing what content is moderated and under what rules.
-
criteria_clear: No moderation criteria or content standards are stated anywhere on the page.
Fix: Clearly list the criteria (e.g., prohibited content, acceptable use) used to moderate submissions or communications.
-
enforcement: There is no description of how moderation decisions are made, enforced, or appealed on this page.
Fix: Add an enforcement section explaining who reviews content, what actions are taken, and how users can appeal decisions.
Interoperability
- Not found at: /status
Security
-
plan_exists: The page contains only organizational information (who we are, board members, team, contact) with no published incident response plan or policy.
Fix: Publish an incident response plan or policy document and link to it from the site (e.g., alongside the privacy policy).
-
notification_commitment: There is no statement committing to public notification of significant security or data incidents anywhere on the page.
Fix: Add an explicit commitment to notify the public and affected users of significant incidents within the incident response policy.
-
timeframe: The page states no timeframe for disclosing incidents to affected users, as it only lists staff, boards, and contact details.
Fix: Specify a concrete disclosure timeframe (e.g., notification within 72 hours of discovery) in the incident response policy.
Skipped: Target page not found in captured content
Transparency
-
criteria_published: The page contains no published criteria for algorithmic decision-making, only general information about the organization and team.
Fix: Publish the specific criteria used in any algorithmic decisions in a transparent, accessible section of the website.
-
weighting: No weighting or prioritization of decision criteria is disclosed anywhere on the page.
Fix: Document and publish the relative weights or priorities assigned to each criterion used in algorithmic decisions.
-
auditable: The page provides no technical or methodological detail that would allow external audit or review of any algorithm.
Fix: Release a methodology document or audit-ready technical specification enabling independent external review of algorithmic systems.
-
open_source: There is no link to source code or any indication that the site's code is publicly available.
Fix: If applicable, publish the site's source code in a public repository (e.g., GitHub) and link to it from the About or footer.
-
tech_docs: No technical documentation is published or linked from the page.
Fix: Publish technical documentation (e.g., about grant data, 360 Giving data standards used, or site architecture) and link it from the About page.
Responsibility to the Future
-
disclosure_exists: The About page describes Arcadia's philanthropic mission and team but contains no published environmental impact or sustainability disclosure.
Fix: Publish a dedicated environmental impact or sustainability statement describing the organization's environmental footprint and commitments.
-
specific_metrics: The page provides no specific figures such as carbon emissions, energy use, or other quantitative environmental metrics.
Fix: Add measurable environmental data (e.g., annual carbon emissions, energy consumption) to the sustainability disclosure.
-
hosting_disclosure: There is no mention of the carbon or energy profile of the website's hosting infrastructure anywhere on the page.
Fix: Disclose the hosting provider's carbon or energy profile, such as whether the site is hosted on renewable-powered or green-certified infrastructure.
-
plan_exists: The about page describes the organisation's structure and funding but contains no published plan for what happens if Arcadia fails or exits.
Fix: Publish a succession or wind-down plan describing how the organisation and its funded programmes would be handled in the event of closure or exit.
-
data_and_content_fate: The page mentions Creative Commons and open access but does not address what would happen to user data or published content if the organisation ceased operating.
Fix: Add a statement specifying how user data and published content would be preserved, migrated, or archived if the organisation shuts down.
-
custodians_or_mirrors: No custodians, mirrors, or archive partners are identified anywhere on the page for continuity of content should the organisation exit.
Fix: Name a designated custodian, archive partner, or mirror service that would maintain content if the organisation ceases to operate.
-
policy_exists: The about page describes the organization's structure, boards, and team but contains no published policy on worker wellbeing or working conditions.
Fix: Publish a dedicated worker wellbeing or working conditions policy and link to it from the site.
-
specific_commitments: There are no specific commitments regarding pay, hours, mental health, or benefits anywhere on the page.
Fix: Add concrete commitments covering pay, working hours, mental health support, and benefits to the published policy.
-
accountability: While the page lists boards and a management team, it does not assign any accountability or oversight specifically for worker conditions.
Fix: Name a role or body (e.g., the COO or a designated committee) responsible for overseeing and reporting on worker conditions.