British Red Cross

https://www.redcross.org.uk · 48/92 checks passed · not_for_profit

Compliance report (framework 0.8)

Gate passed (every Core check must pass) · not counted towards the gate: paused 35, draft 48, ready for review 54.

Site level: 0 (no scored checks yet).

By level

LevelResult
Level 1 — Basic 29/37 (8 failed)
Level 2 — Enhanced 9/27 (18 failed)
Level 3 — Advanced 0/10 (9 failed)

By category

CategoryResult
Accessibility 12/13
Accountability 0/5
AI & Automation 3/8
Interoperability 1/3
Privacy 9/16
Provenance 1/2
Security 7/11
Transparency 5/13
Responsibility to the Future 0/3

Level 1 — Basic

Accessibility

AI & Automation

  • policy_exists: The About page contains no mention of an AI use policy or statement.
    Fix: Publish an AI use policy or statement (e.g., linked from the footer or About section) describing how the British Red Cross uses AI.
  • scope_clear: There is no content on the page explaining what AI is used for.
    Fix: Add a clear description of the scope of AI use (e.g., chatbots, data analysis, fundraising) within an AI policy page.

Privacy

Security

Transparency

  • disclosure_exists: The page is a donation appeal and contains no disclosure of the organization's funding or sponsorship sources.
    Fix: Add a funding disclosure section that identifies where the British Red Cross's income comes from (e.g., public donations, grants, government contracts).
  • transparent: No funding sources are identified on this page; it only solicits donations without explaining the broader funding mix.
    Fix: Clearly list and link to a page identifying all major funding sources, such as individual donations, corporate partners, trusts, and government grants.

Level 2 — Enhanced

Accessibility

Accountability

  • named_person: The page does not identify any named person or specific role responsible for handling enquiries, only the generic 'British Red Cross' organisation.
    Fix: Add the name or title of a responsible individual or team (e.g., 'Head of Supporter Care' or 'Supporter Care Team Lead') accountable for enquiries and complaints.
  • response_timeframe: The page only states complaints will be addressed 'as soon as possible' without publishing any response timeframe.
    Fix: Publish a specific response timeframe (e.g., 'We respond within 10 working days') on the contact page.
  • specific: The phrase 'as soon as possible' is vague and not specific in days or hours.
    Fix: Replace 'as soon as possible' with a concrete duration such as a specified number of working days.
  • steps_clear: The page mentions feedback but does not lay out clear step-by-step instructions for how to make a complaint on this page.
    Fix: Add a numbered list of steps describing how to submit a complaint, what information to include, and what happens next.
  • appeals_exists: The contact page mentions feedback and complaints generally but does not document a formal appeals process.
    Fix: Add a clearly labeled appeals procedure describing how users can formally challenge decisions, including required steps and timelines.
  • independent: There is no mention of an independent reviewer or escalation path for appeals on this page.
    Fix: Specify an independent body or escalation route (e.g., an ombudsman or senior review panel) that handles appeals separately from the original decision-maker.

AI & Automation

  • detailed_scope: The page does not detail any scope of AI use across operations or services.
    Fix: Create a dedicated AI policy page that enumerates each AI application area and its purpose.
  • limitations: No acknowledgement of AI system limitations appears on the page.
    Fix: Include a section in the AI policy that candidly describes the limitations and risks of the AI systems used.
  • safeguards: The page describes no safeguards or quality controls for AI.
    Fix: Document safeguards such as human oversight, accuracy checks, and bias mitigation in a published AI policy.
  • marking_policy: The About page contains no policy or statement about how AI-assisted content is marked or disclosed.
    Fix: Publish an AI content policy (linked from the About or Transparency section) describing how AI-assisted material is labelled on the site.
  • consistent: Without any visible marking policy or labels, consistent application of AI content marking cannot be demonstrated on this page.
    Fix: Adopt a standard label (e.g., 'AI-assisted') and apply it consistently to any AI-generated text, images, or summaries across the site.
  • oversight_exists: The page makes no mention of human oversight of AI outputs anywhere in its governance or 'How we are run' content.
    Fix: Add a statement to the governance pages confirming that all AI outputs are subject to human review before publication.
  • review_process: No review or approval workflow for AI-generated content is described on the page.
    Fix: Document the editorial review steps (e.g., staff review, sign-off, fact-checking) that AI-assisted content must pass before going live.
  • accountability: No individual, team, or role is named as accountable for AI-generated content on this page.
    Fix: Identify an accountable owner (such as a named team or the Executive Team) responsible for AI content and publish their remit.

Interoperability

Privacy

  • plain_language: Portions discussing the Misconduct Disclosure Scheme and legitimate interests use legalistic phrasing like 'necessary for reasons of substantial public interest' and cite GDPR/DPA/DUAA statutes without plain-language explanation.
    Fix: Add short plain-language summaries or a glossary alongside the legal terminology so non-experts can understand lawful bases and schemes referenced.
  • retention_stated: Only one retention period is mentioned (up to 12 months for unsuccessful applicants); retention for donors, service users, volunteers, and employees is not stated on the visible content.
    Fix: Add a dedicated retention section listing how long each category of personal data (donors, service users, volunteers, employees, enquirers) is kept.
  • specific: Apart from the 12-month applicant retention, other retention references are vague (e.g., 'in accordance with your employment contract') rather than specifying durations.
    Fix: Provide specific time periods (e.g., '7 years after last donation', '6 years after employment ends') for each data category rather than referring generally to policies or contracts.
  • equal_choices: The privacy notice references a cookies policy but does not show the actual consent interface on this page, so equal prominence of accept/reject cannot be verified here.
    Fix: Ensure the cookie banner displays 'Accept' and 'Reject' buttons with equal visual prominence (same size, color, and placement) and link to it from the privacy notice for transparency.
  • partner_count_specific: The banner references 'trusted partners' generically but does not state a specific numeric count of partners.
    Fix: Update the cookie banner to disclose the exact number of third-party partners (e.g., 'including from our X trusted partners') with a link to the full list.

Provenance

Security

Transparency

  • named_person: No named individual or specific team (e.g., 'Supporter Care Team') is identified as responsible for enquiries—only the general organisation is referenced.
    Fix: Explicitly name the team handling enquiries (such as 'Supporter Care Team' or 'Customer Service Team') on the contact page.
  • role_clear: Because no person or team is named, their role and authority to handle enquiries, complaints, or feedback is not stated.
    Fix: After naming the responsible team, describe their role and authority, e.g., 'Our Supporter Care Team is authorised to respond to all general enquiries, complaints, and feedback within X working days.'
  • detail: The page provides no amounts, percentages, or categories describing funding streams—only example uses of donation amounts.
    Fix: Include a breakdown (e.g., percentages or figures) of income by source, such as donations, legacies, grants, and trading activities.
  • complete: No funding disclosure is present, so major funding streams are not covered at all.
    Fix: Publish a complete funding breakdown covering all major income streams and link to the annual report or financial statements from this page.
  • roles_clear: While Trustees and the Executive Team are mentioned, the page does not identify specific roles, individuals, or their responsibilities in any detail.
    Fix: Add a summary or link on this page naming key leadership roles (e.g., Chair, CEO, Trustees) with brief descriptions of their responsibilities.
  • algorithm_explained: The About page does not mention any algorithms or explain their purpose.
    Fix: Add a section or link describing any algorithms used (e.g., for case prioritisation or donor targeting) and their purpose.
  • impact_clear: There is no description of how algorithmic decisions affect users or beneficiaries.
    Fix: Publish a clear statement describing how any automated decisions impact service users, donors, or volunteers.
  • annual_statement: The page links to a Privacy policy but provides no evidence of a regular or annual review of data practices.
    Fix: Add a statement on the Privacy page indicating that data practices are reviewed on a regular (e.g., annual) basis, with the date of the most recent review.
  • dated: There is no visible date or version indicator for the Privacy/data practices statement on this page.
    Fix: Include a 'last updated' date or version number adjacent to the Privacy link or at the top of the Privacy policy itself.

Level 3 — Advanced

Accessibility

  • known_issues: The statement only lists aspirational improvement goals and never acknowledges any specific known accessibility issues or limitations of the current site.
    Fix: Add a section listing specific non-compliant elements or known barriers (e.g., 'some older PDFs are not accessible') to be transparent about current limitations.
  • remediation_timeline: The statement describes what they 'aim to' do but provides no dates, deadlines, or commitments for when known issues will be fixed.
    Fix: Include target dates or a schedule for addressing identified accessibility issues so users know when to expect improvements.
  • feedback_channel: A feedback email (digitalsupport@redcross.org.uk) and Contact Us link are provided, but there is no stated commitment on response time.
    Fix: State a response commitment, such as replying to accessibility feedback within a specific number of working days.

Accountability

  • policy_exists: The page is about text-to-donate terms and does not publish any moderation policies for user content.
    Fix: Publish a dedicated moderation policy page covering user-generated content and community interactions, and link to it from the site footer.
  • criteria_clear: No moderation criteria (e.g., prohibited content, acceptable behaviour) are stated anywhere on this page.
    Fix: Clearly enumerate the criteria used to moderate content, such as prohibited categories and standards of conduct, within the moderation policy.
  • enforcement: The page does not describe any enforcement process for moderation decisions, appeals, or escalation.
    Fix: Document the enforcement workflow including who reviews content, actions taken (removal, warnings, bans), and how users can appeal decisions.

Interoperability

Security

  • plan_exists: The page is a contact/about page with no published incident response plan or policy.
    Fix: Publish an incident response plan or policy and link to it from the site.
  • notification_commitment: There is no commitment anywhere on the page to publicly notify users of significant incidents.
    Fix: Add a clear commitment to notify affected users and the public of significant security or data incidents.
  • timeframe: No timeframe for disclosing incidents to affected users is stated on the page.
    Fix: Specify a concrete disclosure timeframe (e.g., within 72 hours of confirming an incident) in the incident response policy.

Transparency

  • criteria_published: No specific criteria for any algorithmic decision-making are published on this page.
    Fix: Publish the specific criteria used in any algorithmic decisions, either on this page or via a linked transparency notice.
  • weighting: There is no information about weighting or priority of any decision criteria.
    Fix: Document and publish how different criteria are weighted or prioritised in any automated decision process.
  • auditable: The page provides no technical or procedural detail that would support external audit of algorithms.
    Fix: Provide an algorithmic transparency report with sufficient detail (data sources, logic, governance) to enable independent audit.
  • open_source: There is no link to any public source code repository for the website on the About page.
    Fix: Add a link in the footer or About page to a public code repository (e.g., GitHub) for any open-source components used on the site.
  • tech_docs: No technical documentation about the site's technology, APIs, or data is published or linked from the page.
    Fix: Publish and link to technical documentation (e.g., a developer/API page or tech stack description) from the About or footer area.

Responsibility to the Future

  • disclosure_exists: The page is a contact/about page and contains no published environmental impact or sustainability disclosure.
    Fix: Publish an environmental or sustainability statement and link it from the footer or About us section.
  • specific_metrics: No specific figures on carbon, energy use, or emissions appear anywhere on the page.
    Fix: Include concrete metrics such as annual carbon footprint or energy consumption in a dedicated sustainability disclosure.
  • hosting_disclosure: The page provides no information about the carbon or energy profile of its hosting infrastructure.
    Fix: Disclose the hosting provider's energy sourcing or carbon profile, ideally referencing green/renewable hosting credentials.
  • plan_exists: The page is a contact/about page with no published plan describing what would happen if the organisation fails or exits.
    Fix: Publish a succession or wind-down plan describing continuity, transfer of activities, or dissolution procedures if the organisation ceases to operate.
  • data_and_content_fate: The page contains no information about the fate of user data or published content in the event of organisational failure.
    Fix: Add a section (or link from the privacy policy) explaining what happens to user data and site content if the organisation shuts down.
  • custodians_or_mirrors: No custodians, mirrors, or archive partners are identified anywhere on the page.
    Fix: Name a custodian, archival partner, or mirror arrangement responsible for preserving data and content if the organisation ceases operations.
  • policy_exists: The page is a donation appeal for the British Red Cross and contains no published policy on worker wellbeing or working conditions.
    Fix: Publish a worker wellbeing or working conditions policy and link to it from the site.
  • specific_commitments: The page contains no specific commitments on pay, hours, mental health, or benefits, focusing solely on soliciting donations.
    Fix: Add concrete commitments covering pay, working hours, mental health support, and benefits for workers.
  • accountability: The page identifies no person, role, or body responsible for overseeing worker conditions.
    Fix: Name a role or oversight body accountable for worker conditions and describe their responsibilities.