Imperial College London

https://www.imperial.ac.uk · 53/92 checks passed · higher_education

Compliance report (framework 0.8)

Gate passed (every Core check must pass) · not counted towards the gate: paused 35, draft 48, ready for review 54.

Site level: 0 (no scored checks yet).

By level

LevelResult
Level 1 — Basic 32/37 (5 failed)
Level 2 — Enhanced 10/27 (17 failed)
Level 3 — Advanced 0/10 (9 failed)

By category

CategoryResult
Accessibility 12/13
Accountability 1/5
AI & Automation 4/8
Interoperability 1/3
Privacy 10/16
Provenance 1/2
Security 7/11
Transparency 6/13
Responsibility to the Future 0/3

Level 1 — Basic

Accessibility

AI & Automation

  • policy_exists: The page describes an AI research network but contains no AI use policy or statement.
    Fix: Publish an AI use policy or statement on the page outlining principles and acceptable use of AI.
  • scope_clear: The page only mentions responding to AI challenges generally and does not explain specific uses of AI.
    Fix: Add a clear description of the specific contexts and purposes for which AI is used.

Privacy

Security

Transparency

  • disclosure_exists: The About page contains no mention of funding sources, sponsorships, or financial backing for the university.
    Fix: Add a funding/sponsorship disclosure section on the About page summarising key income sources such as tuition fees, research grants, and government funding.
  • transparent: Because no disclosure is present, funding sources are not identified at all.
    Fix: Clearly name primary funders (e.g., UKRI, NIHR, industry partners, government bodies) with links to detailed financial reports.

Level 2 — Enhanced

Accessibility

Accountability

  • specific: While operating hours are given, the page does not state a specific response time (e.g. tickets answered within X hours/days) for submitted requests.
    Fix: Publish concrete response SLAs, such as 'tickets acknowledged within 1 business day and resolved within 5 business days,' alongside the contact information.
  • process_exists: The page describes how to contact the ICT Service Desk but does not document a complaints or feedback process for dissatisfied users.
    Fix: Add a dedicated section or link explaining how to submit a complaint or provide feedback about ICT services, including escalation paths.
  • steps_clear: Because no complaints process is documented, there are no clear steps outlining how to raise or escalate a complaint.
    Fix: Provide a numbered step-by-step complaints procedure (e.g. 1. Contact Service Desk, 2. Escalate to manager, 3. Formal complaint to leadership) with timeframes for each step.
  • appeals_exists: The page only lists contact methods for ICT support with no documented appeals process for decisions or complaints.
    Fix: Add a clearly labeled appeals or complaints section outlining steps users can take to challenge decisions or service outcomes.
  • independent: No appeals mechanism is described, so there is no evidence of independent review or escalation path beyond contacting the same ICT Service Desk.
    Fix: Document an escalation path to an independent party (e.g., ICT Leadership or an ombudsperson) for appeals that cannot be resolved by the Service Desk.

AI & Automation

  • detailed_scope: No detailed scope of AI use is provided; the content is a brief network description only.
    Fix: Include a detailed section specifying the domains, tasks, and systems where AI is applied.
  • limitations: The page does not acknowledge any limitations of AI systems.
    Fix: Add a section explicitly acknowledging known limitations and risks of the AI systems used.
  • safeguards: No safeguards, oversight, or quality controls are described on the page.
    Fix: Document the safeguards, human oversight, and quality assurance processes governing AI use.
  • marking_policy: The page describes an AI Network but contains no policy for marking AI-assisted content.
    Fix: Publish a clear policy describing how AI-assisted content will be labelled on the site.
  • consistent: No AI content markings appear anywhere on the page, so consistency cannot be demonstrated.
    Fix: Apply standard labels or disclosures to any AI-generated content across all pages in a uniform manner.
  • oversight_exists: The page does not document any human oversight process for AI outputs.
    Fix: Add a statement describing how humans oversee and validate AI-generated outputs on the site.
  • review_process: There is no description of any review or approval workflow for AI content.
    Fix: Publish a documented review/approval workflow outlining who reviews AI outputs before publication.
  • accountability: No individual or role is identified as accountable for AI-generated content on the page.
    Fix: Name a responsible owner or role (e.g., editorial lead) accountable for AI-generated content.

Interoperability

Privacy

  • necessity: The policy does not explicitly state that data collection is limited to what is necessary; it only says data will be retained as long as necessary.
    Fix: Add an explicit statement (e.g., a data minimisation clause) confirming that only data necessary for the stated purposes is collected.
  • specific: Retention is described only vaguely ('as long as necessary') without specific time periods on the page itself.
    Fix: Include concrete retention periods (e.g., 'newsletter subscriptions retained for 2 years after last interaction') directly in the notice or a clearly linked schedule.
  • equal_choices: The page itself does not display a consent banner with accept/reject options, so equal prominence of choices cannot be verified on this privacy notice page.
    Fix: Ensure the linked cookie consent banner presents 'Accept' and 'Reject' options with equal visual prominence (same size, color, and placement).
  • partner_sharing_mentioned: The banner mentions cookies for 'advertising purposes' but does not explicitly disclose data sharing with third-party partners.
    Fix: Update the banner copy to explicitly state that data may be shared with third-party advertising or analytics partners and link to the list of those partners.
  • partner_count_specific: No specific numeric count of partners is stated anywhere in the banner or on-page consent copy.
    Fix: Include a specific number of third-party partners (e.g., 'We share data with X partners') in the banner or linked consent details.

Provenance

Security

Transparency

  • detail: No funding amounts, percentages, or categories are described anywhere on the page.
    Fix: Include a breakdown of funding by category (e.g., % from tuition, research grants, donations) or link to the annual financial statement.
  • complete: With no disclosure present, major funding streams such as research grants, tuition, and philanthropic gifts are not covered.
    Fix: Publish a comprehensive funding overview covering all material income streams, ideally linking to the institution's published annual report.
  • roles_clear: While the leadership team is mentioned as overseeing strategy and management, the page does not identify specific roles or responsibilities of individuals or bodies on this page.
    Fix: Add a brief description of key leadership roles (e.g., President, Provost, Council) and their responsibilities, or link directly to a page listing named roles and duties.
  • algorithm_explained: The About page makes no mention of any algorithms or automated decision-making systems or their purpose.
    Fix: Add a section or link describing any algorithmic systems used (e.g., in admissions, search, or personalisation) and their intended purpose.
  • impact_clear: There is no description of how algorithmic decisions affect users such as applicants, staff, or students.
    Fix: Publish a clear statement outlining how any automated decisions impact users and what recourse they have.
  • annual_statement: The page links to a 'Privacy notice' but provides no evidence on this page of a regular or periodic review of data practices.
    Fix: Add a statement (or visible note on the linked privacy notice) indicating the date of the last review and the cadence of periodic reviews.
  • dated: The About page references a privacy notice but shows no date or version information for the data practices statement.
    Fix: Display a 'Last updated' date or version number alongside the privacy notice link or within the notice itself.

Level 3 — Advanced

Accessibility

  • known_issues: The visible page content does not acknowledge any known accessibility issues or limitations; it only links out to an accessibility page.
    Fix: Ensure the linked accessibility statement explicitly lists known non-compliant areas and surface that acknowledgement, as the current page shows no such disclosure.
  • remediation_timeline: There is no timeline or stated commitment to fix accessibility issues anywhere in the page content.
    Fix: Add a section in the accessibility statement specifying target dates or a commitment schedule for remediating identified issues.
  • feedback_channel: While a 'Report incorrect content' link and a Service Desk contact exist, there is no accessibility-specific feedback mechanism with a stated response-time commitment on this page.
    Fix: Provide a clearly labelled accessibility feedback channel (email or form) with a defined response-time commitment within the accessibility statement.

Accountability

  • policy_exists: The About page contains no published moderation policy or link to one.
    Fix: Publish a moderation policy page and link to it from the About page or site footer.
  • criteria_clear: No moderation criteria are stated anywhere on the page.
    Fix: Document clear moderation criteria (e.g., prohibited content, acceptable use) and reference them from this page.
  • enforcement: The page does not describe any enforcement process for moderation decisions.
    Fix: Add an explanation of the enforcement workflow, including reporting channels, review steps, and appeals.

Interoperability

Security

  • plan_exists: The About page contains only institutional descriptions, rankings, and navigation links with no published incident response plan or policy.
    Fix: Publish a dedicated incident response plan or security policy page and link to it from the site footer or security section.
  • notification_commitment: There is no statement committing to public notification of significant security or data incidents anywhere on the page.
    Fix: Add an explicit commitment to notify affected users and the public in the event of significant security incidents.
  • timeframe: The page provides no timeframe for disclosing incidents to affected users.
    Fix: State a specific disclosure timeframe (e.g., within 72 hours of discovery) in the incident response policy.

Transparency

  • criteria_published: No specific criteria for any algorithmic decision-making are published on this page.
    Fix: Publish the specific criteria used in any algorithmic decisions, or link to a dedicated transparency page that lists them.
  • weighting: The page provides no information about how criteria are weighted or prioritised in any algorithmic process.
    Fix: Document and publish the relative weighting or priority order of each criterion used in algorithmic decisions.
  • auditable: The page offers no technical detail, documentation, or audit mechanism that would enable external review of algorithms.
    Fix: Provide an algorithmic transparency report or audit documentation (e.g., following the UK ATRS standard) accessible from the About page.
  • open_source: The about page contains no link to source code or any open-source repository for the website.
    Fix: Add a link to a public repository (e.g., GitHub) for the site's codebase or relevant open-source projects in the footer or about page.
  • tech_docs: No technical documentation about the site's platform, APIs, or infrastructure is linked from the page.
    Fix: Publish and link to technical documentation (such as a developer portal, API docs, or platform notes) from the about page or site footer.

Responsibility to the Future

  • specific_metrics: The page mentions rankings and a fossil-fuel-free building but provides no specific figures for carbon, energy use, or emissions.
    Fix: Publish quantitative data such as annual carbon emissions (tCO2e), energy consumption, and reduction targets with baseline years directly on the sustainability page.
  • hosting_disclosure: There is no mention of the carbon or energy profile of the website's hosting infrastructure anywhere on the page.
    Fix: Add a statement disclosing the hosting provider's energy source or carbon profile, ideally confirming use of renewable-powered or green-certified hosting.
  • plan_exists: The page describes governance structures, committees, and decision delegations but contains no published plan for organisational failure, wind-down, or exit.
    Fix: Publish a documented continuity and exit plan describing what happens to the institution's services and obligations in the event of failure or closure.
  • data_and_content_fate: There is no mention of what would happen to user data or published content if the organisation ceased to operate.
    Fix: Add a section specifying how user data and published content would be preserved, transferred, or deleted in a wind-down scenario.
  • custodians_or_mirrors: The page names committees and partners but does not identify any custodians, mirrors, or archive partners responsible for preserving content upon exit.
    Fix: Designate and name specific archive partners, custodians, or mirror arrangements to safeguard data and content if the organisation exits.
  • policy_exists: The page is a college staff directory search tool and contains no published policy on worker wellbeing or working conditions.
    Fix: Publish a dedicated worker wellbeing or working conditions policy and link to it from a relevant HR or People Function section of the site.
  • specific_commitments: The page contains no specific commitments regarding pay, hours, mental health, or benefits, only directory search fields and switchboard contact information.
    Fix: Add explicit commitments covering pay, working hours, mental health support, and staff benefits within a published wellbeing policy.
  • accountability: The page does not identify any accountability, department, or oversight responsible for worker conditions beyond generic directory listings.
    Fix: Name the responsible body (e.g., the People Function) and describe its oversight role for worker conditions on the relevant policy page.