ib1.org

https://ib1.org · 43/89 checks passed

Compliance report (framework 0.8)

Gate passed (every Core check must pass) · not counted towards the gate: paused 35, draft 48, ready for review 54.

Site level: 0 (no scored checks yet).

By level

LevelResult
Level 1 — Basic 24/37 (12 failed)
Level 2 — Enhanced 11/27 (16 failed)
Level 3 — Advanced 0/10 (9 failed)

By category

CategoryResult
Accessibility 9/13
Accountability 1/5
AI & Automation 5/8
Interoperability 1/3
Privacy 8/16
Provenance 1/2
Security 5/11
Transparency 5/13
Responsibility to the Future 0/3

Level 1 — Basic

Accessibility

AI & Automation

Privacy

  • 1 inline script matched a tracker/ad pattern; first match: ' var _paq = window._paq = window._paq || []; /* tracker methods like "setCustomD…'.

Security

  • strict-transport-security: header not set on the response.

Transparency

Level 2 — Enhanced

Accessibility

Accountability

  • independent: The page only names a dispute resolution procedure link but provides no visible detail confirming the appeals process is independent or escalated to a neutral third party.
    Fix: Add explicit text (or content on the linked DRP page) describing an independent or escalated appeals stage, such as review by an impartial party or external arbitrator.
  • response_timeframe: The page provides contact emails (partners@ib1.org) but publishes no timeframe for responding to inquiries.
    Fix: Add a stated response timeframe near the contact details, such as 'We respond to inquiries within 5 business days.'
  • specific: No timeframes appear at all, so none are specific in days or hours.
    Fix: Specify concrete response times in defined units (e.g. '3 working days') rather than vague terms.
  • process_exists: The page offers only generic contact emails and no documented complaints or feedback process.
    Fix: Publish a dedicated complaints/feedback procedure page and link it from the About and footer sections.
  • steps_clear: Because no complaints process is documented, there are no clear steps for submitting one.
    Fix: Outline explicit steps (how to submit, where it goes, escalation path, and expected acknowledgment) for raising a complaint.

AI & Automation

  • marking_policy: The page describes AI data governance and provenance infrastructure but contains no policy for marking or labelling AI-assisted content.
    Fix: Publish a clear policy stating how AI-assisted or AI-generated content on the site is identified and labelled to users.
  • consistent: Because no AI content marking policy exists on the page, there is no evidence of consistent application of such marking.
    Fix: Define and apply a consistent labelling convention (e.g. a visible tag or disclaimer) across all AI-assisted content on the site.
  • oversight_exists: The page details automated agent governance and 'no human in the loop' data flows but does not document human oversight of AI outputs.
    Fix: Document the human oversight arrangements that govern AI outputs, specifying where and how humans review or intervene.
  • review_process: The page describes technical audit trails and provenance records but does not describe any review or approval process for AI-generated content.
    Fix: Describe a concrete review or approval workflow for AI outputs, including who reviews and the criteria applied before publication or use.
  • accountability: While IB1 is named as operator of the governance infrastructure, no individual or role is identified as accountable for AI-generated content.
    Fix: Name a responsible role or function accountable for AI-generated content and its compliance with governance standards.

Interoperability

Privacy

  • no_dark_patterns: The page only shows a privacy notice header with no visible consent mechanism, so it cannot be confirmed that consent is gathered without dark patterns or manipulative language.
    Fix: Include the actual consent request text on the page so reviewers can verify it uses neutral, non-manipulative language.
  • equal_choices: No accept or reject consent controls are present in the page content, so their relative prominence cannot be verified.
    Fix: Display clearly visible accept and reject buttons of equal size, color, and prominence within the consent interface.
  • no_forced_consent: The page provides no consent flow, so it cannot be confirmed that consent is unbundled and not forced as a condition of access.
    Fix: Provide a granular consent interface that lets users decline optional processing without losing access to the core service.
  • banner_present: The page content shows no cookie or consent banner anywhere on the page, only a footer with a 'Privacy' link.
    Fix: Implement a visible cookie/consent banner that appears on page load to inform users about cookie usage and obtain consent.
  • partner_sharing_mentioned: There is no banner or on-page consent copy, and no disclosure of data sharing with third-party partners appears anywhere on the page.
    Fix: Add consent copy to the cookie banner that clearly discloses whether and how user data is shared with third-party partners.
  • partner_count_specific: No partner sharing is disclosed and consequently no specific numeric count of partners is stated anywhere on the page.
    Fix: If partner data sharing occurs, disclose the exact number of third-party partners in the consent banner or linked privacy notice.
  • plain_language: The page content shows only a title, version, and reading time with no actual policy body text to assess for plain language.
    Fix: Publish the full privacy notice body text so its language can be reviewed and ensure it is written in plain, non-legal terms.
  • comprehensive: No substantive content is present describing what data is collected or why, only metadata like version and reading time.
    Fix: Add sections detailing what personal data is collected, the purposes for collection, and the legal basis for processing.
  • plain_language: There is no visible description of data practices on the page, so plain-language writing cannot be confirmed.
    Fix: Include a clearly written, jargon-free description of the organisation's data handling practices on the page.
  • understandable: Without any content explaining what data is collected and why, a non-expert cannot understand the data practices.
    Fix: Explain in simple terms what data is collected, how it is used, and who it is shared with so non-experts can understand.
  • necessity: The page contains no statement that data collection is limited to what is necessary.
    Fix: Add an explicit statement that data collection is limited to what is necessary for providing the service.
  • proportionate: No information about the data collected or the service is provided, so proportionality cannot be assessed.
    Fix: Describe the data collected relative to the services offered and confirm collection is proportionate to those services.
  • retention_stated: The page does not mention any data retention periods.
    Fix: State how long each category of personal data is retained within the privacy notice.
  • specific: As no retention periods are stated at all, none are specific.
    Fix: Provide specific retention durations (e.g. '12 months after account closure') rather than vague or absent timeframes.

Provenance

Security

Transparency

  • annual_statement: The page shows no evidence of a regular or periodic review of data practices, only linking to a generic 'Privacy' page without any review cadence.
    Fix: Add a statement to the Privacy page indicating the date of the last review and a commitment to review data practices at least annually.
  • dated: Neither the page nor its 'Privacy' link displays any date or version number for the data practices statement.
    Fix: Include a 'last updated' date or version number on the privacy/data practices statement so users can verify its currency.
  • detail: Funding is described only in broad categories (industry, public sector, philanthropy) with no amounts, percentages, or breakdown of actual funding received.
    Fix: Add specific figures or percentages showing how much funding comes from each source, such as industry contributions, public grants, and philanthropic capital.
  • complete: The page argues for future philanthropic funding but does not confirm whether it covers all current funding streams or provide a comprehensive accounting of them.
    Fix: Provide a complete list of all major funding streams and their relative contributions to demonstrate the disclosure is exhaustive rather than aspirational.
  • algorithm_explained: The About page describes IB1's mission, services, and team but does not mention or explain any algorithms in use.
    Fix: If algorithms are used in any IB1 services, add a section explaining their purpose in plain language.
  • impact_clear: The page contains no description of algorithmic decisions or how they affect users.
    Fix: Describe how any automated or algorithmic decisions impact users and their data-sharing outcomes.

Level 3 — Advanced

Accessibility

  • statement_exists: The page contains only footer links to Privacy, Credits, IP & Copyright, and Join, with no dedicated accessibility statement anywhere.
    Fix: Create a dedicated accessibility statement page and link to it from the site footer.
  • known_issues: No accessibility statement exists, so no known accessibility issues or limitations are acknowledged.
    Fix: In the accessibility statement, list any known accessibility limitations such as non-conforming components or content.
  • remediation_timeline: There is no accessibility statement and therefore no timeline or commitment to fix known issues.
    Fix: Include a target date or commitment schedule for addressing identified accessibility issues in the statement.
  • feedback_channel: The page provides only a general partners@ib1.org contact and no accessibility-specific feedback channel with a response commitment.
    Fix: Add a dedicated accessibility feedback contact and state a specific response time commitment in the statement.

Accountability

  • policy_exists: The page lists governance, antitrust, and dispute resolution documents but no content moderation policy is published.
    Fix: Publish a dedicated content moderation policy and link it from this terms and SOPs index page.
  • criteria_clear: No moderation criteria (e.g., what content is permitted or removed) are stated anywhere on the page.
    Fix: Add a clearly written section defining what content is prohibited and the criteria used to assess it for moderation.
  • enforcement: The page describes dispute resolution and governance but does not explain any moderation enforcement process such as review, removal, or appeals.
    Fix: Document the enforcement workflow, including how content is reviewed, what actions are taken, and how users can appeal moderation decisions.

Interoperability

Security

  • plan_exists: The About page describes IB1's mission, services, and team but contains no published incident response plan or policy.
    Fix: Publish a dedicated incident response plan or security policy page and link to it from the site.
  • notification_commitment: The page makes no commitment to publicly notify users of significant security incidents.
    Fix: Add an explicit statement committing to public notification of affected users when significant incidents occur.
  • timeframe: No disclosure timeframe for reporting incidents to affected users is stated anywhere on the page.
    Fix: Specify a concrete disclosure window (e.g., notify affected users within 72 hours of confirming an incident).

Transparency

  • open_source: The page mentions MIT licensing of outputs but provides no link or reference to a public source code repository.
    Fix: Add a visible link to a public code repository (e.g., GitHub/GitLab) where IB1's software and standards are hosted.
  • tech_docs: The page references trust frameworks and services but does not link to any published technical documentation.
    Fix: Add links to technical documentation for the trust frameworks, standards, and services from the About page.
  • criteria_published: No specific decision criteria for any algorithm are published anywhere on the page.
    Fix: Publish the specific criteria used in any algorithmic decisions, or link to a page that does.
  • weighting: The page provides no information about the weighting or priority of any decision criteria.
    Fix: Document the relative weighting or priority of each criterion used in algorithmic decisions.
  • auditable: The page offers no technical or methodological detail sufficient for external audit of any algorithm.
    Fix: Provide detailed algorithm documentation or an audit trail enabling independent external review.

Responsibility to the Future

  • disclosure_exists: The page is a conceptual article about sustainability data flows and decision-making, not a published environmental impact or sustainability disclosure for the organisation itself.
    Fix: Publish a dedicated sustainability/environmental disclosure page reporting the organisation's own environmental impact rather than only discussing data governance concepts.
  • specific_metrics: The content contains no specific figures for carbon, energy use, or emissions, describing only abstract data layers and processes.
    Fix: Add quantified environmental metrics such as annual carbon emissions, energy consumption, and reduction targets with baseline years.
  • hosting_disclosure: There is no mention of the carbon or energy profile of the website's or organisation's hosting infrastructure anywhere on the page.
    Fix: Disclose the hosting provider's energy source (e.g., renewable-powered data centres) and the estimated carbon or energy footprint of the site's infrastructure.
  • policy_exists: The page describes IB1's mission, services, advisory board, and team but contains no published policy on worker wellbeing or working conditions.
    Fix: Publish a worker wellbeing or working conditions policy and link to it from the About or a dedicated policies page.
  • specific_commitments: There are no specific commitments regarding pay, hours, mental health, or benefits anywhere on the page.
    Fix: Add explicit commitments covering fair pay, working hours, mental health support, and employee benefits.
  • accountability: The page references the IoD Code of Conduct for Directors but does not identify any accountability or oversight specifically for worker conditions.
    Fix: Name a responsible role or oversight body accountable for monitoring and upholding worker wellbeing standards.
  • plan_exists: The governance page describes Steering, Advisory, and Working Group structures but contains no published plan for what happens if the organisation fails or exits.
    Fix: Publish a succession or wind-down plan describing the steps and responsible parties should the organisation cease operations.
  • data_and_content_fate: The page addresses governance meetings and minutes but says nothing about what would happen to user data or published content in a failure or exit scenario.
    Fix: Add a section specifying how user data and published content (e.g., minutes, standards) would be preserved, transferred, or deleted if the organisation exits.
  • custodians_or_mirrors: No custodians, mirrors, or archive partners are identified anywhere on the page to safeguard content beyond the organisation's lifetime.
    Fix: Name specific custodians, mirror hosts, or archive partners (such as a national archive or web archive) committed to preserving the content.