Citizens Advice

https://www.citizensadvice.org.uk · 56/92 checks passed · not_for_profit

Compliance report (framework 0.8)

Gate passed (every Core check must pass) · not counted towards the gate: paused 35, draft 48, ready for review 54.

Site level: 0 (no scored checks yet).

By level

LevelResult
Level 1 — Basic 32/37 (5 failed)
Level 2 — Enhanced 8/27 (19 failed)
Level 3 — Advanced 0/10 (9 failed)

By category

CategoryResult
Accessibility 11/13
Accountability 1/5
AI & Automation 3/8
Interoperability 1/3
Privacy 13/16
Provenance 0/2
Security 7/11
Transparency 4/13
Responsibility to the Future 0/3

Level 1 — Basic

Accessibility

AI & Automation

  • policy_exists: The page contains no AI use policy or statement anywhere in its content or navigation.
    Fix: Publish a clear AI use policy page and link to it from the site footer or About section.
  • scope_clear: With no AI policy present, there is no explanation of what AI is used for on the site.
    Fix: Include a scope section in the AI policy describing specific use cases (e.g., content generation, chat support, analytics).

Privacy

Security

Transparency

  • about_exists: This page is an 'Adviser resources' page rather than an About page, though an 'About us' link appears in the footer.
    Fix: Ensure the About page at /about-us is directly accessible and consider making /about route to it, rather than to adviser resources.

Level 2 — Enhanced

Accessibility

Accountability

  • named_person: The page lists generic services (Adviceline, online chat) but does not identify any named person or specific role responsible for the contact function.
    Fix: Add the name or job title of the person or team (e.g., Head of Customer Service) accountable for contact and complaints handling.
  • response_timeframe: The page does not state any response timeframe for complaints; it only provides contact hours (Mon–Fri, 9am–5pm).
    Fix: Publish a clear expected response timeframe (e.g., 'we will acknowledge complaints within 5 working days and respond within 20 working days').
  • specific: No specific timeframes in days or weeks are given for handling complaints on this page.
    Fix: Add concrete timeframes such as number of working days for acknowledgement and final response to the complaints page.
  • independent: The page does not describe any independent review or escalation path beyond the internal Client Services team or the local office being complained about.
    Fix: Add a clear escalation route to an independent body (e.g., an ombudsman or external reviewer) for complainants dissatisfied with the initial response.

AI & Automation

  • detailed_scope: No AI policy is present, so no detailed scope of AI use is provided.
    Fix: Create an AI policy that enumerates each AI system in use, its purpose, data inputs, and affected user journeys.
  • limitations: The page does not acknowledge any limitations of AI systems because no AI policy exists.
    Fix: Add a limitations section describing known risks such as inaccuracy, bias, and situations where AI should not be relied upon.
  • safeguards: No safeguards or quality controls for AI are described on the page.
    Fix: Document safeguards such as human review, accuracy checks, escalation paths, and governance oversight in the AI policy.
  • marking_policy: The page contains no policy or statement about how AI-assisted content is marked or labelled.
    Fix: Publish a clear policy stating whether and how AI-assisted content is labelled on the site, linked from the About or About this site section.
  • consistent: With no marking policy present, there is no evidence of consistent labelling of AI content across the page.
    Fix: Implement a site-wide convention (e.g., a visible 'AI-assisted' tag) and document it so it can be applied consistently to any AI-generated material.
  • oversight_exists: The page does not document any human oversight process for AI outputs.
    Fix: Add a statement describing how humans review AI-generated content before it is published, e.g. within the About us or Accessibility/Editorial pages.
  • review_process: No review or approval workflow for AI content is described on the page.
    Fix: Describe the review and approval steps (who reviews, against what criteria, and at what stage) in a published editorial or AI governance policy.
  • accountability: The page does not identify any individual, role, or team accountable for AI-generated content.
    Fix: Name a responsible role or team (e.g., Head of Digital Content) accountable for AI outputs and provide contact details for queries or corrections.

Interoperability

Privacy

  • necessity: The visible page content does not include any statement that data collection is limited to what is necessary.
    Fix: Add an explicit statement on the privacy landing page confirming that Citizens Advice only collects personal data that is necessary for the stated purposes.
  • proportionate: There is no visible text describing proportionality of data collection relative to the service provided.
    Fix: Include a short proportionality statement explaining that data collected is limited and proportionate to each service context (advice, donations, volunteering, etc.).
  • specific: The visible content only references retention as a section heading without showing any specific time periods on this page view.
    Fix: Surface concrete retention durations (e.g. 'advice records kept for 6 years') directly within the 'How long we keep your data for' section rather than only linking to it.
  • partner_sharing_mentioned: The banner describes cookie purposes (site improvement, campaigning, videos) but does not disclose data sharing with third-party partners.
    Fix: Update the cookie banner to explicitly state whether data is shared with third-party partners (e.g., video providers, analytics vendors) and link to a list of them.
  • partner_count_specific: No numeric count of partners is stated anywhere in the banner or on-page consent copy.
    Fix: Include a specific count of third-party partners in the consent copy (e.g., 'We share data with X partners') alongside a link to the full list.

Provenance

  • credentials: Beyond describing itself as 'the UK's largest advice giving charity' and listing a charity number, the page provides no detail on the credentials, expertise, or editorial processes behind the advice.
    Fix: Add a section describing the qualifications of advisers, editorial review processes, and the organisation's history or expertise in providing trusted advice.

Security

Transparency

  • named_person: No named individual or specific team (such as a 'Customer Contact Team') is identified as responsible for handling enquiries on this page.
    Fix: Name the responsible team (e.g., 'Our Adviceline team' or a specific complaints officer) handling enquiries and complaints.
  • role_clear: While channels and opening hours are described, the role or authority of whoever answers enquiries (trained adviser aside) and handles complaints is not clearly stated.
    Fix: Clarify the role and authority of the contact team, e.g., who reviews complaints and what decisions they can make.
  • substantive: The statement of purpose is limited to a two-sentence summary focused on adviser resources, not a substantive description of the organisation.
    Fix: Expand the page with detailed information on the organisation's history, scope of services, impact, and values rather than a brief tagline.
  • mission_clear: The page does not articulate an editorial approach or mission statement beyond a generic description of providing advice.
    Fix: Add a clear mission statement and describe the editorial/quality-assurance approach used when producing advice content.
  • detail: The page mentions categories of support but provides no amounts, percentages, or breakdown of funding streams.
    Fix: Add specific figures or percentages showing how much funding comes from donations, corporate partners, legacies, and government grants, or link directly to the relevant annual report section.
  • complete: The disclosure omits major funding streams such as government grants and contracts, which are typically significant for Citizens Advice.
    Fix: Expand the disclosure to include all major funding streams including government/public sector funding, grants, and trust income alongside the existing donation and partnership categories.
  • governance_exists: The page describes adviser resources but does not outline any governance or editorial structure for the organisation or site content.
    Fix: Add a section (or link to one) describing the governance structure, such as the board of trustees, editorial oversight, and decision-making processes.
  • roles_clear: No key roles or responsibilities (e.g., trustees, editors, executives) are identified on the page.
    Fix: Identify leadership and editorial roles with names and responsibilities, or link to an 'Our people/leadership' page detailing them.
  • algorithm_explained: The page describes adviser resources and organizational info but makes no mention of any algorithms or their purpose.
    Fix: Add a section explaining any algorithms used on the site (e.g., for personalisation, search, or advice matching) and their purpose.
  • impact_clear: There is no description of how algorithmic decisions affect users on this page.
    Fix: Include a clear statement describing how any algorithmic decisions impact users and what outcomes they influence.
  • annual_statement: The page links to a 'Privacy and cookies' page but shows no evidence of a regular or annual review of data practices.
    Fix: Add a statement to the privacy notice indicating when it was last reviewed and the cadence of periodic reviews (e.g., annually).
  • dated: No date or version indicator is visible for the privacy/data practices statement on this page.
    Fix: Display a 'last updated' date or version number on the privacy and cookies statement and reference it where linked.

Level 3 — Advanced

Accessibility

  • known_issues: The provided page content does not display any acknowledged accessibility issues or limitations, only a link to a statement.
    Fix: Ensure the linked accessibility statement explicitly lists known non-compliant elements and inaccessible content areas.
  • remediation_timeline: There is no visible timeline or commitment for fixing accessibility issues on this page.
    Fix: Add a section to the accessibility statement stating target dates or a schedule for resolving identified accessibility barriers.
  • feedback_channel: The only feedback prompt shown ('Is there anything wrong with this page? Let us know') is generic and lacks any stated response commitment or timeframe.
    Fix: Provide a dedicated accessibility feedback contact with an explicit commitment to respond within a defined number of days.

Accountability

  • policy_exists: The terms page covers site use, liability, and copyright but does not publish any moderation policy for user content or interactions.
    Fix: Publish a dedicated moderation policy section (or linked page) describing how user-submitted content and community interactions are moderated.
  • criteria_clear: Beyond a general prohibition on unlawful acts and malware, the page does not state specific moderation criteria for what content or behaviour is acceptable.
    Fix: Add clear, itemised moderation criteria (e.g., prohibited content categories like harassment, hate speech, spam) so users know what standards apply.
  • enforcement: The page does not describe how moderation decisions are made, who enforces them, appeals, or consequences such as removal or bans.
    Fix: Document the enforcement process, including reporting channels, review steps, possible actions (warnings, removal, bans), and an appeals mechanism.

Interoperability

Security

  • plan_exists: The page contains only an 'about us' description of the charity's advice services with no published incident response plan or security policy.
    Fix: Publish an incident response plan or security policy and link to it from the site footer or a dedicated security page.
  • notification_commitment: There is no statement anywhere on the page committing to public notification of significant security incidents.
    Fix: Add an explicit commitment to notify affected users and the public of significant incidents within your incident response documentation.
  • timeframe: The page states no timeframe for disclosing incidents to affected users.
    Fix: Specify a concrete disclosure timeframe (e.g., within 72 hours of discovery) in a published incident response policy.

Transparency

  • criteria_published: No criteria for any algorithmic decision-making are published on this page.
    Fix: Publish the specific criteria used in any algorithmic decisions, ideally in a dedicated transparency or algorithms page.
  • weighting: The page does not explain weighting or priority of any decision criteria.
    Fix: Document how each criterion is weighted or prioritised when algorithms make or support decisions.
  • auditable: The page contains no technical or procedural detail that would enable external audit of algorithmic processes.
    Fix: Provide sufficient documentation (data sources, logic, evaluation metrics) to allow independent external audit or review of any algorithms used.
  • open_source: The page contains no links to source code repositories or any mention of open-source availability.
    Fix: If applicable, add links to public code repositories (e.g. GitHub) and clearly state the project's open-source licensing.
  • tech_docs: No technical documentation is linked or referenced from this page.
    Fix: Publish and link to technical documentation covering APIs, data sources, or site architecture from the About or resources section.

Responsibility to the Future

  • disclosure_exists: The page contains no published environmental impact or sustainability disclosure, only charity advice and footer links covering privacy, accessibility, and modern slavery.
    Fix: Publish a dedicated sustainability or environmental impact statement and link it from the footer alongside the other policy statements.
  • specific_metrics: There are no specific figures for carbon, energy use, or emissions anywhere on the page.
    Fix: Include quantified metrics such as annual carbon footprint (tCO2e) and energy consumption in a published environmental report.
  • hosting_disclosure: The page provides no information about the carbon or energy profile of the hosting infrastructure.
    Fix: Disclose the website's hosting provider and whether it runs on renewable or low-carbon energy in the sustainability statement.
  • plan_exists: The page describes the charity's advice services and adviser resources but contains no published plan for organisational failure or exit.
    Fix: Publish a succession or wind-down plan describing what happens to the service if the organisation ceases operations, and link to it from the About and footer sections.
  • data_and_content_fate: There is no mention of what would happen to user data or published advice content in the event of the organisation failing or exiting.
    Fix: Add a section (or link to a policy) stating how user data would be handled and whether advice content would be preserved, transferred, or deleted upon closure.
  • custodians_or_mirrors: The page names no custodians, mirrors, or archive partners who would preserve the content or services if the organisation shut down.
    Fix: Identify and publicly name a custodian, mirror host, or archive partner (e.g., a national web archive) responsible for preserving content and data after any exit.
  • policy_exists: The page is an 'About' page describing adviser resources and charity registration details, with no published policy on worker wellbeing or working conditions.
    Fix: Publish a worker wellbeing or working conditions policy and link to it from the About or governance sections of the site.
  • specific_commitments: The page contains no specific commitments regarding pay, hours, mental health, or benefits for workers.
    Fix: Add explicit commitments covering fair pay, working hours, mental health support, and staff benefits to a dedicated wellbeing policy.
  • accountability: The page does not identify any individual, role, or body responsible for overseeing worker conditions.
    Fix: Name a responsible role or oversight body (e.g., an HR director or board committee) accountable for monitoring worker conditions.