Imperial War Museums
https://www.iwm.org.uk · 53/92 checks passed · archives
Compliance report (framework 0.8)
Gate passed (every Core check must pass) · not counted towards the gate: paused 35, draft 48, ready for review 54.
Site level: 0 (no scored checks yet).
By level
| Level | Result |
|---|---|
| Level 1 — Basic | 30/37 (6 failed) |
| Level 2 — Enhanced | 9/27 (18 failed) |
| Level 3 — Advanced | 0/10 (9 failed) |
By category
| Category | Result |
|---|---|
| Accessibility | 12/13 |
| Accountability | 0/5 |
| AI & Automation | 3/8 |
| Interoperability | 1/3 |
| Privacy | 12/16 |
| Provenance | 1/2 |
| Security | 4/11 |
| Transparency | 6/13 |
| Responsibility to the Future | 0/3 |
Level 1 — Basic
Accessibility
AI & Automation
-
policy_exists: The About page contains no mention of an AI use policy or statement.
Fix: Publish a dedicated AI use policy or statement and link to it from the About and Policies & procedures sections.
-
scope_clear: No content on the page describes what AI is or isn't used for at IWM.
Fix: Add a clear scope section to the AI policy describing the specific contexts in which IWM uses AI (e.g., collections cataloguing, research, visitor services).
- Not found at any of: /ai-policy, /ai.
Privacy
PASS
Session cookies only
PASS
No tracking pixels
Security
FAIL
HTTPS enforced
- strict-transport-security: header not set on the response.
- Redirect chain (1 hops): https://www.iwm.org.uk
- content-security-policy: header not set on the response.
- referrer-policy: header not set on the response.
- TLS certificate expires in 3 days.
PASS
No mixed content
Transparency
PASS
Contact form present
Level 2 — Enhanced
Accessibility
Accountability
-
named_person: The page references generic groups like 'Customer Services', 'Reception', and 'one of our team' but does not name a specific person or defined role owner responsible for enquiries.
Fix: Identify a specific named person or clearly defined role (e.g., Head of Visitor Services) as the accountable contact for enquiries and complaints.
-
response_timeframe: The page only states 'we will get back to you as quickly as we can' without publishing a defined response timeframe.
Fix: Publish a specific expected response window (e.g., 'We respond to enquiries within 5 working days') on the contact page.
-
specific: No specific number of days or hours is given for responding to enquiries—only vague language like 'as quickly as we can'.
Fix: Replace vague phrasing with concrete timeframes such as '10 working days for general enquiries' and similar for complaints.
-
steps_clear: The page lists complaint categories and links to policies but does not lay out the actual steps a user should follow to make a complaint.
Fix: Add a brief numbered list of steps (e.g., 1. Complete form, 2. Receive acknowledgement, 3. Investigation, 4. Response/escalation) directly on the contact page.
-
independent: The page does not indicate whether complaints are escalated to an independent body or reviewer beyond IWM's internal team.
Fix: Add information on the contact page describing escalation to an independent reviewer or ombudsman if complainants are dissatisfied with the internal outcome.
AI & Automation
-
detailed_scope: The page does not provide any detailed scope of AI use across IWM's activities.
Fix: Document each AI use case with purpose, systems involved, and data sources in a published policy.
-
limitations: No acknowledgement of AI system limitations appears anywhere on the page.
Fix: Include a section in the AI policy acknowledging known limitations such as bias, inaccuracy, and contextual gaps in AI outputs.
-
safeguards: No safeguards, human oversight, or quality controls relating to AI are described.
Fix: Describe safeguards such as human review, accuracy checks, data protection measures, and escalation procedures in the AI policy.
-
marking_policy: The About page contains no policy or statement regarding the marking or labeling of AI-assisted content.
Fix: Publish a clear policy describing how AI-assisted content will be labeled or disclosed, and link to it from the About or Policies section.
-
consistent: Without a stated marking policy, there is no evidence that AI content marking is applied consistently across the site.
Fix: Adopt a standard AI-content label (e.g., an 'AI-assisted' tag) and apply it uniformly to all qualifying content across the museum's digital outputs.
-
oversight_exists: The page makes no mention of human oversight of AI outputs within IWM's governance or editorial processes.
Fix: Add a statement to the Governance or Policies section confirming that AI outputs receive human oversight before publication.
-
review_process: No review or approval workflow for AI-generated content is described on the About page or linked governance materials shown.
Fix: Document and publish a clear review/approval workflow (editorial sign-off, curatorial validation) for any AI-generated content.
-
accountability: No individual, role, or team is identified as accountable for AI-generated content on the page.
Fix: Name a responsible role (e.g., Head of Digital or Editorial Lead) accountable for AI-generated outputs and publish contact details in the governance section.
Interoperability
- No RSS/Atom feeds discovered.
Privacy
-
necessity: The policy does not explicitly state that data collection is limited to what is necessary, only that essential cookies are required.
Fix: Add an explicit statement that IWM limits data collection to what is necessary for the stated purposes and avoids collecting extraneous data.
-
specific: The retention period is given as a broad range ('duration of your visit... or up to two years') rather than specific periods per cookie or data type.
Fix: Provide a table or list specifying the exact retention period for each cookie and category of personal data collected.
-
equal_choices: The page describes a consent banner but does not confirm that accept and reject options are presented with equal prominence.
Fix: Explicitly state in the policy (and ensure in the banner UI) that 'Accept' and 'Reject' buttons are equally visible, styled, and accessible at the same level.
-
banner_present: The page content shows no visible cookie or consent banner, only a 'Cookies' link in the footer legal section.
Fix: Implement a visible cookie consent banner on page load that allows users to accept, reject, or manage cookie preferences.
-
partner_sharing_mentioned: There is no banner or on-page consent copy disclosing data sharing with third-party partners.
Fix: Add clear disclosure within a consent banner explaining that data may be shared with third-party partners, with a link to details.
-
partner_count_specific: No partner sharing is disclosed and no specific numeric count of partners is stated anywhere on the page.
Fix: Include a specific numeric count of third-party partners (e.g., 'We share data with X partners') within the consent interface.
Provenance
- No author or date metadata found on the page.
Security
Transparency
-
role_clear: While team names are given, the page does not clarify the scope, authority, or remit of Customer Services versus Reception or who handles which enquiry type.
Fix: Add a short description next to each team explaining their role and which types of enquiries they handle.
-
detail: The disclosure lists categories of funding but provides no amounts, percentages, or proportional breakdown of how much comes from each source.
Fix: Add specific figures or percentages (e.g., a pie chart or summary showing the share of income from government grant-in-aid, commercial activities, donations, and memberships) or link to the annual report.
-
roles_clear: While 'Trustees' is mentioned as a link, the page does not describe key roles, responsibilities, or who holds them within the governance structure.
Fix: Add a brief description of key governance roles (e.g., Board of Trustees, Director-General, executive leadership) and their responsibilities directly on the About page.
-
algorithm_explained: The About page does not mention any algorithms or automated systems used by IWM, so their purpose is not explained.
Fix: Add a section or link describing any algorithmic or automated systems used (e.g., for collections search, recommendations, or visitor analytics) and their purpose.
-
impact_clear: There is no description of how algorithmic decisions affect users on this page.
Fix: Include a clear statement of how any automated decisions impact visitors, researchers, or members, and link to a fuller explanation.
-
annual_statement: The page links to a Privacy page in the footer but provides no evidence on this page of an annual or periodic review of data practices.
Fix: Publish a statement (e.g., on the Privacy page or governance section) indicating that data practices are reviewed on a regular, defined cadence such as annually.
-
dated: No date or version information is shown for any data practices statement on this page.
Fix: Add a 'Last updated' date or version number to the privacy/data practices statement and surface it where referenced.
Level 3 — Advanced
Accessibility
-
remediation_timeline: The statement commits to fixing issues ('we are currently working to address these issues') but provides no dates or target timeline for remediation.
Fix: Add specific target dates or milestones for when the listed non-compliant issues are expected to be resolved.
Accountability
-
policy_exists: The page only covers ticket terms and conditions with no published moderation policy for user content or community interactions.
Fix: Publish a dedicated moderation policy covering user-generated content, comments, and community guidelines.
-
criteria_clear: No moderation criteria are stated; the page only outlines ticket rules and admission conditions.
Fix: Clearly list the criteria used to assess and moderate content, such as prohibited behaviours and content types.
-
enforcement: There is no explanation of any moderation enforcement process, only a general right to refuse admission on-site.
Fix: Document the enforcement process, including how violations are reviewed, actions taken, and how users can appeal decisions.
Interoperability
- Not found at: /status
Security
-
plan_exists: The page lists governance policies and procedures but shows no published incident response plan or security incident policy.
Fix: Publish an incident response plan or policy and link it from the governance or legal section of the site.
-
notification_commitment: There is no statement committing to public notification of significant security or data incidents anywhere on the page.
Fix: Add an explicit commitment to notify affected users and the public when a significant incident occurs.
-
timeframe: No timeframe for disclosing incidents to affected users is stated on the page.
Fix: Specify a concrete disclosure timeframe (e.g., within 72 hours of discovery) in the incident response policy.
Skipped: Target page not found in captured content
Transparency
-
criteria_published: No specific criteria for any algorithmic decisions are published on the page.
Fix: Publish the criteria used by any algorithmic systems (e.g., in a dedicated transparency or policies page) and link to them from About.
-
weighting: The page provides no information about weighting or prioritisation of decision criteria.
Fix: Document and publish how criteria are weighted or prioritised in any automated decision processes.
-
auditable: The page offers no technical or procedural detail sufficient for external audit or review of algorithms.
Fix: Provide an algorithmic transparency record (such as the UK ATRS) with enough methodological detail to support independent audit.
-
open_source: There is no link or reference to publicly available source code for the website on the about page.
Fix: Add a link to a public code repository (e.g., GitHub) or a statement about the site's technology stack if any components are open source.
-
tech_docs: No technical documentation about the site's platform, APIs, or data access is published or linked from the about page.
Fix: Publish technical documentation such as an API reference, data schema, or developer page and link it from the About or Footer section.
Responsibility to the Future
-
disclosure_exists: The About page describes museums, collections, research, and governance but contains no published environmental impact or sustainability disclosure.
Fix: Publish a dedicated sustainability or environmental impact statement and link to it from the About and governance sections.
-
specific_metrics: The page provides no specific figures on carbon emissions, energy use, or other environmental metrics.
Fix: Include measurable environmental data such as annual carbon footprint, energy consumption, and emissions reduction targets in the disclosure.
-
hosting_disclosure: There is no mention of the carbon or energy profile of the website's hosting infrastructure anywhere on the page.
Fix: Add a statement disclosing the hosting provider's energy sourcing or the site's estimated carbon footprint, ideally with green hosting details.
-
plan_exists: The page describes IWM's mission, museums, and governance documents but contains no published plan for what happens if the organisation fails or exits.
Fix: Publish a succession or continuity plan within the governance section outlining what happens to the museum's operations and collections should the organisation cease to function.
-
data_and_content_fate: There is no mention of what would happen to user data or published content in the event of organisational failure or closure.
Fix: Add an explicit statement describing the intended fate of user data and published content (e.g., transfer, archiving, or deletion) if the organisation exits.
-
custodians_or_mirrors: The page names trustees and partnerships generally but does not identify any custodians, mirrors, or archive partners who would preserve content or collections on exit.
Fix: Identify and name specific custodians, archive partners, or mirror arrangements responsible for preserving collections and content in a wind-down scenario.
-
policy_exists: The page is an editorial feature about the 'Culture Under Attack' exhibition season and contains no published policy on worker wellbeing or working conditions.
Fix: Publish a worker wellbeing or working conditions policy and link to it from a discoverable location such as the footer or 'About IWM' section.
-
specific_commitments: The content covers exhibitions and stories with no mention of pay, hours, mental health, or benefits commitments.
Fix: Add specific, measurable commitments on pay, working hours, mental health support, and benefits to a dedicated policy document.
-
accountability: No individual, role, or oversight body is identified as responsible for worker conditions anywhere on the page.
Fix: Name a responsible owner or oversight body (e.g., HR lead or board committee) accountable for monitoring and reporting on worker conditions.