Citizens Advice
https://www.citizensadvice.org.uk · 56/92 checks passed · not_for_profit
Compliance report (framework 0.8)
Gate passed (every Core check must pass) · not counted towards the gate: paused 35, draft 48, ready for review 54.
Site level: 0 (no scored checks yet).
By level
| Level | Result |
|---|---|
| Level 1 — Basic | 32/37 (5 failed) |
| Level 2 — Enhanced | 8/27 (19 failed) |
| Level 3 — Advanced | 0/10 (9 failed) |
By category
| Category | Result |
|---|---|
| Accessibility | 11/13 |
| Accountability | 1/5 |
| AI & Automation | 3/8 |
| Interoperability | 1/3 |
| Privacy | 13/16 |
| Provenance | 0/2 |
| Security | 7/11 |
| Transparency | 4/13 |
| Responsibility to the Future | 0/3 |
Level 1 — Basic
Accessibility
AI & Automation
-
policy_exists: The page contains no AI use policy or statement anywhere in its content or navigation.
Fix: Publish a clear AI use policy page and link to it from the site footer or About section.
-
scope_clear: With no AI policy present, there is no explanation of what AI is used for on the site.
Fix: Include a scope section in the AI policy describing specific use cases (e.g., content generation, chat support, analytics).
- Not found at any of: /ai-policy, /ai.
Privacy
PASS
Session cookies only
PASS
No tracking pixels
Security
- Redirect chain (1 hops): https://www.citizensadvice.org.uk
PASS
HTTPS enforced
PASS
No mixed content
Transparency
-
about_exists: This page is an 'Adviser resources' page rather than an About page, though an 'About us' link appears in the footer.
Fix: Ensure the About page at /about-us is directly accessible and consider making /about route to it, rather than to adviser resources.
PASS
Contact form present
Level 2 — Enhanced
Accessibility
Accountability
-
named_person: The page lists generic services (Adviceline, online chat) but does not identify any named person or specific role responsible for the contact function.
Fix: Add the name or job title of the person or team (e.g., Head of Customer Service) accountable for contact and complaints handling.
-
response_timeframe: The page does not state any response timeframe for complaints; it only provides contact hours (Mon–Fri, 9am–5pm).
Fix: Publish a clear expected response timeframe (e.g., 'we will acknowledge complaints within 5 working days and respond within 20 working days').
-
specific: No specific timeframes in days or weeks are given for handling complaints on this page.
Fix: Add concrete timeframes such as number of working days for acknowledgement and final response to the complaints page.
-
independent: The page does not describe any independent review or escalation path beyond the internal Client Services team or the local office being complained about.
Fix: Add a clear escalation route to an independent body (e.g., an ombudsman or external reviewer) for complainants dissatisfied with the initial response.
AI & Automation
-
detailed_scope: No AI policy is present, so no detailed scope of AI use is provided.
Fix: Create an AI policy that enumerates each AI system in use, its purpose, data inputs, and affected user journeys.
-
limitations: The page does not acknowledge any limitations of AI systems because no AI policy exists.
Fix: Add a limitations section describing known risks such as inaccuracy, bias, and situations where AI should not be relied upon.
-
safeguards: No safeguards or quality controls for AI are described on the page.
Fix: Document safeguards such as human review, accuracy checks, escalation paths, and governance oversight in the AI policy.
-
marking_policy: The page contains no policy or statement about how AI-assisted content is marked or labelled.
Fix: Publish a clear policy stating whether and how AI-assisted content is labelled on the site, linked from the About or About this site section.
-
consistent: With no marking policy present, there is no evidence of consistent labelling of AI content across the page.
Fix: Implement a site-wide convention (e.g., a visible 'AI-assisted' tag) and document it so it can be applied consistently to any AI-generated material.
-
oversight_exists: The page does not document any human oversight process for AI outputs.
Fix: Add a statement describing how humans review AI-generated content before it is published, e.g. within the About us or Accessibility/Editorial pages.
-
review_process: No review or approval workflow for AI content is described on the page.
Fix: Describe the review and approval steps (who reviews, against what criteria, and at what stage) in a published editorial or AI governance policy.
-
accountability: The page does not identify any individual, role, or team accountable for AI-generated content.
Fix: Name a responsible role or team (e.g., Head of Digital Content) accountable for AI outputs and provide contact details for queries or corrections.
Interoperability
- No RSS/Atom feeds discovered.
Privacy
-
necessity: The visible page content does not include any statement that data collection is limited to what is necessary.
Fix: Add an explicit statement on the privacy landing page confirming that Citizens Advice only collects personal data that is necessary for the stated purposes.
-
proportionate: There is no visible text describing proportionality of data collection relative to the service provided.
Fix: Include a short proportionality statement explaining that data collected is limited and proportionate to each service context (advice, donations, volunteering, etc.).
-
specific: The visible content only references retention as a section heading without showing any specific time periods on this page view.
Fix: Surface concrete retention durations (e.g. 'advice records kept for 6 years') directly within the 'How long we keep your data for' section rather than only linking to it.
-
partner_sharing_mentioned: The banner describes cookie purposes (site improvement, campaigning, videos) but does not disclose data sharing with third-party partners.
Fix: Update the cookie banner to explicitly state whether data is shared with third-party partners (e.g., video providers, analytics vendors) and link to a list of them.
-
partner_count_specific: No numeric count of partners is stated anywhere in the banner or on-page consent copy.
Fix: Include a specific count of third-party partners in the consent copy (e.g., 'We share data with X partners') alongside a link to the full list.
Provenance
- No author or date metadata found on the page.
-
credentials: Beyond describing itself as 'the UK's largest advice giving charity' and listing a charity number, the page provides no detail on the credentials, expertise, or editorial processes behind the advice.
Fix: Add a section describing the qualifications of advisers, editorial review processes, and the organisation's history or expertise in providing trusted advice.
Security
- security.txt not published.
Transparency
-
named_person: No named individual or specific team (such as a 'Customer Contact Team') is identified as responsible for handling enquiries on this page.
Fix: Name the responsible team (e.g., 'Our Adviceline team' or a specific complaints officer) handling enquiries and complaints.
-
role_clear: While channels and opening hours are described, the role or authority of whoever answers enquiries (trained adviser aside) and handles complaints is not clearly stated.
Fix: Clarify the role and authority of the contact team, e.g., who reviews complaints and what decisions they can make.
-
substantive: The statement of purpose is limited to a two-sentence summary focused on adviser resources, not a substantive description of the organisation.
Fix: Expand the page with detailed information on the organisation's history, scope of services, impact, and values rather than a brief tagline.
-
mission_clear: The page does not articulate an editorial approach or mission statement beyond a generic description of providing advice.
Fix: Add a clear mission statement and describe the editorial/quality-assurance approach used when producing advice content.
-
detail: The page mentions categories of support but provides no amounts, percentages, or breakdown of funding streams.
Fix: Add specific figures or percentages showing how much funding comes from donations, corporate partners, legacies, and government grants, or link directly to the relevant annual report section.
-
complete: The disclosure omits major funding streams such as government grants and contracts, which are typically significant for Citizens Advice.
Fix: Expand the disclosure to include all major funding streams including government/public sector funding, grants, and trust income alongside the existing donation and partnership categories.
-
governance_exists: The page describes adviser resources but does not outline any governance or editorial structure for the organisation or site content.
Fix: Add a section (or link to one) describing the governance structure, such as the board of trustees, editorial oversight, and decision-making processes.
-
roles_clear: No key roles or responsibilities (e.g., trustees, editors, executives) are identified on the page.
Fix: Identify leadership and editorial roles with names and responsibilities, or link to an 'Our people/leadership' page detailing them.
-
algorithm_explained: The page describes adviser resources and organizational info but makes no mention of any algorithms or their purpose.
Fix: Add a section explaining any algorithms used on the site (e.g., for personalisation, search, or advice matching) and their purpose.
-
impact_clear: There is no description of how algorithmic decisions affect users on this page.
Fix: Include a clear statement describing how any algorithmic decisions impact users and what outcomes they influence.
-
annual_statement: The page links to a 'Privacy and cookies' page but shows no evidence of a regular or annual review of data practices.
Fix: Add a statement to the privacy notice indicating when it was last reviewed and the cadence of periodic reviews (e.g., annually).
-
dated: No date or version indicator is visible for the privacy/data practices statement on this page.
Fix: Display a 'last updated' date or version number on the privacy and cookies statement and reference it where linked.
Level 3 — Advanced
Accessibility
-
known_issues: The provided page content does not display any acknowledged accessibility issues or limitations, only a link to a statement.
Fix: Ensure the linked accessibility statement explicitly lists known non-compliant elements and inaccessible content areas.
-
remediation_timeline: There is no visible timeline or commitment for fixing accessibility issues on this page.
Fix: Add a section to the accessibility statement stating target dates or a schedule for resolving identified accessibility barriers.
-
feedback_channel: The only feedback prompt shown ('Is there anything wrong with this page? Let us know') is generic and lacks any stated response commitment or timeframe.
Fix: Provide a dedicated accessibility feedback contact with an explicit commitment to respond within a defined number of days.
Accountability
-
policy_exists: The terms page covers site use, liability, and copyright but does not publish any moderation policy for user content or interactions.
Fix: Publish a dedicated moderation policy section (or linked page) describing how user-submitted content and community interactions are moderated.
-
criteria_clear: Beyond a general prohibition on unlawful acts and malware, the page does not state specific moderation criteria for what content or behaviour is acceptable.
Fix: Add clear, itemised moderation criteria (e.g., prohibited content categories like harassment, hate speech, spam) so users know what standards apply.
-
enforcement: The page does not describe how moderation decisions are made, who enforces them, appeals, or consequences such as removal or bans.
Fix: Document the enforcement process, including reporting channels, review steps, possible actions (warnings, removal, bans), and an appeals mechanism.
Interoperability
- Not found at: /status
Security
-
plan_exists: The page contains only an 'about us' description of the charity's advice services with no published incident response plan or security policy.
Fix: Publish an incident response plan or security policy and link to it from the site footer or a dedicated security page.
-
notification_commitment: There is no statement anywhere on the page committing to public notification of significant security incidents.
Fix: Add an explicit commitment to notify affected users and the public of significant incidents within your incident response documentation.
-
timeframe: The page states no timeframe for disclosing incidents to affected users.
Fix: Specify a concrete disclosure timeframe (e.g., within 72 hours of discovery) in a published incident response policy.
Skipped: Target page not found in captured content
Transparency
-
criteria_published: No criteria for any algorithmic decision-making are published on this page.
Fix: Publish the specific criteria used in any algorithmic decisions, ideally in a dedicated transparency or algorithms page.
-
weighting: The page does not explain weighting or priority of any decision criteria.
Fix: Document how each criterion is weighted or prioritised when algorithms make or support decisions.
-
auditable: The page contains no technical or procedural detail that would enable external audit of algorithmic processes.
Fix: Provide sufficient documentation (data sources, logic, evaluation metrics) to allow independent external audit or review of any algorithms used.
-
open_source: The page contains no links to source code repositories or any mention of open-source availability.
Fix: If applicable, add links to public code repositories (e.g. GitHub) and clearly state the project's open-source licensing.
-
tech_docs: No technical documentation is linked or referenced from this page.
Fix: Publish and link to technical documentation covering APIs, data sources, or site architecture from the About or resources section.
Responsibility to the Future
-
disclosure_exists: The page contains no published environmental impact or sustainability disclosure, only charity advice and footer links covering privacy, accessibility, and modern slavery.
Fix: Publish a dedicated sustainability or environmental impact statement and link it from the footer alongside the other policy statements.
-
specific_metrics: There are no specific figures for carbon, energy use, or emissions anywhere on the page.
Fix: Include quantified metrics such as annual carbon footprint (tCO2e) and energy consumption in a published environmental report.
-
hosting_disclosure: The page provides no information about the carbon or energy profile of the hosting infrastructure.
Fix: Disclose the website's hosting provider and whether it runs on renewable or low-carbon energy in the sustainability statement.
-
plan_exists: The page describes the charity's advice services and adviser resources but contains no published plan for organisational failure or exit.
Fix: Publish a succession or wind-down plan describing what happens to the service if the organisation ceases operations, and link to it from the About and footer sections.
-
data_and_content_fate: There is no mention of what would happen to user data or published advice content in the event of the organisation failing or exiting.
Fix: Add a section (or link to a policy) stating how user data would be handled and whether advice content would be preserved, transferred, or deleted upon closure.
-
custodians_or_mirrors: The page names no custodians, mirrors, or archive partners who would preserve the content or services if the organisation shut down.
Fix: Identify and publicly name a custodian, mirror host, or archive partner (e.g., a national web archive) responsible for preserving content and data after any exit.
-
policy_exists: The page is an 'About' page describing adviser resources and charity registration details, with no published policy on worker wellbeing or working conditions.
Fix: Publish a worker wellbeing or working conditions policy and link to it from the About or governance sections of the site.
-
specific_commitments: The page contains no specific commitments regarding pay, hours, mental health, or benefits for workers.
Fix: Add explicit commitments covering fair pay, working hours, mental health support, and staff benefits to a dedicated wellbeing policy.
-
accountability: The page does not identify any individual, role, or body responsible for overseeing worker conditions.
Fix: Name a responsible role or oversight body (e.g., an HR director or board committee) accountable for monitoring worker conditions.