Financial Conduct Authority
https://www.fca.org.uk · 62/92 checks passed · government
Compliance report (framework 0.8)
Gate passed (every Core check must pass) · not counted towards the gate: paused 35, draft 48, ready for review 54.
Site level: 0 (no scored checks yet).
By level
| Level | Result |
|---|---|
| Level 1 — Basic | 35/37 (2 failed) |
| Level 2 — Enhanced | 11/27 (16 failed) |
| Level 3 — Advanced | 0/10 (9 failed) |
By category
| Category | Result |
|---|---|
| Accessibility | 12/13 |
| Accountability | 1/5 |
| AI & Automation | 5/8 |
| Interoperability | 1/3 |
| Privacy | 12/16 |
| Provenance | 2/2 |
| Security | 7/11 |
| Transparency | 6/13 |
| Responsibility to the Future | 0/3 |
Level 1 — Basic
Accessibility
AI & Automation
Privacy
PASS
Session cookies only
PASS
No tracking pixels
Security
- Redirect chain (1 hops): https://www.fca.org.uk
PASS
HTTPS enforced
PASS
No mixed content
Transparency
-
disclosure_exists: The About page contains no funding or sponsorship disclosure, only general descriptions of the FCA's regulatory role.
Fix: Add a dedicated funding disclosure section (or link to one) on the About page explaining how the FCA is financed, e.g., through industry fees and levies.
-
transparent: No funding sources are identified anywhere on the page, so transparency cannot be assessed.
Fix: Clearly name the FCA's funding sources (such as regulated firm fees, levies, and penalties) in a visible section on the About page.
PASS
Contact form present
Level 2 — Enhanced
Accessibility
Accountability
-
named_person: The page lists generic teams (press office, whistleblowing team, FCA Head Office) but does not name a specific person or titled role accountable for contact handling.
Fix: Identify a named individual or specific role (e.g., Head of Consumer Contact Centre) responsible for the contact function on this page.
-
response_timeframe: The page states users will receive an email response with guidance but does not publish a specific timeframe for when replies will arrive.
Fix: Add a concrete response-time commitment (e.g., 'We will reply within 5 working days') near the 'Report a concern' section.
-
specific: No numeric timeframe in days or hours is given for responses; the page only says a reply will come after reporting a concern.
Fix: Specify an exact timeframe in days (e.g., 'within 10 business days') rather than leaving it open-ended.
-
steps_clear: The contact page lists what the FCA can't do and links to 'How to complain' but does not lay out clear sequential steps for making a complaint on this page.
Fix: Include a short numbered list of complaint steps (e.g., 1. Contact the firm, 2. Escalate to Ombudsman, 3. Report to FCA) directly on the contact page.
AI & Automation
-
detailed_scope: The page only references AI use at a high level (AI Lab, Live Testing, smarter regulator) without detailing specific internal AI use cases or systems.
Fix: Publish a detailed scope section enumerating specific AI applications, systems, and use cases within the FCA and for regulated firms.
-
limitations: The page mentions cybersecurity as a perceived risk but does not explicitly acknowledge limitations of AI systems used by or regulated by the FCA.
Fix: Add a clearly labelled section describing known limitations of the AI systems in scope, such as accuracy, bias, and explainability constraints.
-
safeguards: While oversight and testing environments are referenced, the page does not describe specific safeguards or quality controls (e.g. human review, validation, monitoring) for AI use.
Fix: Document concrete safeguards and quality-control measures—such as human oversight, model validation, auditing, and incident response—on the AI page.
-
marking_policy: The page discusses AI in financial services but does not state any policy for marking AI-assisted content on the site itself.
Fix: Publish a clear policy indicating whether and how any AI-assisted content on the site is labeled or disclosed to readers.
-
consistent: No AI content markings are visible on the page, so consistent application cannot be demonstrated.
Fix: Apply a consistent visible label (e.g., 'AI-assisted') to any content produced with AI across all pages and publications.
-
oversight_exists: The page describes AI regulation of firms but does not document human oversight of the FCA's own AI-generated content.
Fix: Add a statement describing how humans review AI outputs used in FCA content before publication.
-
review_process: There is no description of a review or approval workflow for AI outputs appearing on the site.
Fix: Document the editorial review/approval steps applied to any AI-assisted content, including who signs off before publication.
Interoperability
- No RSS/Atom feeds discovered.
Privacy
-
plain_language: While much is accessible, the notice relies on legal jargon such as 'Article 6(1)(e) of the UK GDPR', 'section 166 of FSMA', 'joint controller', and 'legitimate interest lawful basis' without plain-language explanation.
Fix: Add brief plain-language explanations alongside legal references (e.g., explain what 'Article 6(1)(e)' means in everyday terms).
-
necessity: The policy does not explicitly state a principle of data minimisation or that collection is limited to what is necessary, though it implies purpose limitation.
Fix: Add an explicit statement that data collection is limited to what is necessary for the stated purposes, referencing the data minimisation principle.
-
specific: Retention is described only by reference to an unspecified 'retention policy' and 'retention schedule' without any concrete time periods on this page.
Fix: Include specific retention periods (e.g., 'call recordings are kept for X years') or a direct link to the retention schedule with timeframes.
-
partner_sharing_mentioned: The banner only mentions necessary and optional analytics cookies with anonymised data, and does not disclose any data sharing with third-party partners.
Fix: Update the cookie banner copy to explicitly state whether any data is shared with third-party partners and link to a detailed list of those partners.
-
partner_count_specific: No specific numeric count of partners is stated because partner sharing itself is not disclosed on the banner.
Fix: If third-party partners receive data, state the exact number of partners in the banner (e.g., 'We share data with X partners').
Provenance
Security
- security.txt not published.
Transparency
-
named_person: Only generic team references such as 'press office' and 'whistleblowing team' are provided, with no named individual or clearly designated enquiry team lead.
Fix: Add the name or title of the individual/team lead responsible for handling each category of enquiry (consumer, firm, press, whistleblowing).
-
detail: The page provides no amounts, percentages, or categories relating to funding.
Fix: Include meaningful detail such as annual funding figures, percentage breakdowns by fee block, or categorised funding streams, ideally with a link to the annual funding requirement report.
-
complete: Because no funding information is disclosed, the disclosure cannot cover major funding streams.
Fix: Publish a complete breakdown covering all major revenue sources (periodic fees, application fees, levies, fines allocation, etc.) and link to it from the About page.
-
algorithm_explained: The About page describes the FCA's regulatory role but makes no mention of any algorithms or automated decision-making systems or their purpose.
Fix: Add a dedicated section explaining any algorithms or automated tools the FCA uses in supervision or decision-making and describe their purpose.
-
impact_clear: There is no description on the page of how algorithmic decisions affect consumers, firms, or markets.
Fix: Publish a clear statement outlining the impact of any algorithmic decisions on users, including affected groups and potential outcomes.
-
annual_statement: The page links to a Privacy notice but shows no evidence of a regular or annual review of data practices.
Fix: Add a statement on the privacy page indicating when the data practices were last reviewed and the cadence of future reviews.
-
dated: No date or version is visible for a data practices statement on this page; only a generic Privacy link is offered.
Fix: Display a 'last updated' date or version number on the Privacy notice and reference it from the About page.
Level 3 — Advanced
Accessibility
-
remediation_timeline: The statement commits to fixing issues and updating the page but provides no specific dates or timeline for when the known issues will be resolved.
Fix: Add target dates or estimated completion timeframes for each listed non-compliant issue so users know when fixes are expected.
-
feedback_channel: The statement offers a 'contact us' feedback mechanism and enforcement escalation path but states no commitment to a response time.
Fix: State a specific response commitment (for example, acknowledging feedback within a set number of working days) alongside the contact link.
Accountability
-
policy_exists: The About page contains no published moderation policy for user-generated content or community interactions.
Fix: Publish a moderation policy page and link it from the About section or footer.
-
criteria_clear: No moderation criteria are stated anywhere on the visible page content.
Fix: Define and publish specific criteria (e.g., prohibited content types, acceptable use rules) in an accessible moderation policy.
-
enforcement: There is no explanation of how moderation decisions are made or enforced on the page.
Fix: Document the enforcement workflow including review steps, actions taken, and appeals process within the moderation policy.
Interoperability
- Not found at: /status
Security
-
plan_exists: The About page describes the FCA's regulatory role and organizational structure but contains no published incident response plan or policy.
Fix: Publish an incident response plan or policy and link to it from the site, for example under the 'How we operate' or 'Transparency' section.
-
notification_commitment: The page makes no commitment to publicly notify affected parties of significant security or data incidents.
Fix: Add an explicit statement committing to public notification of significant incidents affecting users or their data.
-
timeframe: No timeframe for disclosing incidents to affected users is stated anywhere on the page.
Fix: Specify a concrete disclosure timeframe (e.g., notification within 72 hours of confirming a significant incident) in the incident response policy.
Skipped: Target page not found in captured content
Transparency
-
criteria_published: The page does not publish any specific criteria used in algorithmic decisions; it only gives high-level regulatory objectives.
Fix: Publish the specific input criteria used by any algorithmic systems, ideally in a transparency or accountability section.
-
weighting: No information is provided about how criteria are weighted or prioritised in any algorithmic process.
Fix: Document and disclose the weighting or prioritisation logic applied to each criterion within algorithmic decision-making.
-
auditable: The page offers no technical or procedural detail that would allow external audit or review of algorithms.
Fix: Provide an algorithmic transparency record with sufficient technical detail (model, data, governance) to enable independent audit.
-
open_source: There is no link to source code or any open-source repository on the about page.
Fix: Add a link in the footer or transparency section to any publicly available source code repositories (e.g., GitHub) used by the FCA.
-
tech_docs: The page does not link to technical documentation about the website's systems or APIs (the Handbook is regulatory, not technical).
Fix: Publish and link to technical documentation for FCA digital services/APIs (e.g., RegData, Connect) from the about or transparency pages.
Responsibility to the Future
-
specific_metrics: The page describes focus areas and targets in narrative terms but provides no specific figures for carbon, energy use, or emissions on the page itself.
Fix: Add concrete quantitative data (e.g., annual tonnes of CO2e, energy consumption in kWh, and baseline vs. current emissions) directly on this page or link prominently to a page containing those figures.
-
hosting_disclosure: The page mentions ICT and digital services as a focus area but discloses no carbon or energy profile of its hosting or IT infrastructure.
Fix: Publish the carbon or energy footprint of the site's hosting and data-centre infrastructure, including whether providers use renewable energy.
-
plan_exists: The About page describes the FCA's regulatory role and structure but contains no published plan for what happens if the organisation fails or exits.
Fix: Publish a succession or continuity plan describing how the organisation's functions would be transferred or wound down in the event of failure or exit.
-
data_and_content_fate: The page does not address what would happen to user data or published content if the organisation ceased operations.
Fix: Add a section explaining how user data and published content would be preserved, migrated, or handled if the organisation stops operating.
-
custodians_or_mirrors: No custodians, mirrors, or archive partners are identified anywhere on the page.
Fix: Name any custodians, mirrors, or archive partners (e.g. a national web archive) that would maintain the site's data and content after an exit.
-
policy_exists: The page is a regulatory overview of culture and governance in financial services firms, not a published worker wellbeing or working conditions policy for the FCA's own staff.
Fix: Publish a dedicated worker wellbeing or working conditions policy covering the organisation's own employees and link to it from this or a relevant HR/careers page.
-
specific_commitments: The content discusses 'rewarding and managing people' as a regulatory driver but provides no specific commitments on pay, hours, mental health, or benefits.
Fix: Add concrete, measurable commitments on pay, working hours, mental health support, and employee benefits.
-
accountability: The page references the Senior Managers and Certification Regime for regulated firms but names no internal owner or oversight body accountable for worker conditions at the FCA.
Fix: Name a specific role, team, or governance body responsible for overseeing worker wellbeing and describe how it is monitored and reported.