King's College London

https://www.kcl.ac.uk · 41/92 checks passed · higher_education

Compliance report (framework 0.8)

Gate passed (every Core check must pass) · not counted towards the gate: paused 35, draft 48, ready for review 54.

Site level: 0 (no scored checks yet).

By level

LevelResult
Level 1 — Basic 24/37 (12 failed)
Level 2 — Enhanced 8/27 (19 failed)
Level 3 — Advanced 1/10 (8 failed)

By category

CategoryResult
Accessibility 10/13
Accountability 0/5
AI & Automation 4/8
Interoperability 1/3
Privacy 10/16
Provenance 1/2
Security 5/11
Transparency 2/13
Responsibility to the Future 0/3

Level 1 — Basic

Accessibility

AI & Automation

  • policy_exists: The page describes the King's Institute for AI and its programmes but contains no AI use policy or governance statement.
    Fix: Publish a clear AI use policy or statement on this page (or link prominently to one) outlining how AI is used at King's.
  • scope_clear: While the page mentions AI research programmes, it does not explain the scope of the institution's own AI use in operations, teaching, or services.
    Fix: Add a dedicated section describing specifically what AI tools/systems are used for and in what contexts across the institution.

Privacy

Security

Transparency

  • disclosure_exists: The page describes student funding options but contains no disclosure of the institution's own funding or sponsorship sources.
    Fix: Add a clear disclosure section identifying the university's funding and sponsorship sources (e.g., government grants, donors, corporate partners).
  • transparent: No funding sources for King's are identified anywhere on the page; it only references external loans, scholarships, and UKCISA.
    Fix: List the specific organisations, government bodies, or donors that fund the institution and its student support programs.

Level 2 — Enhanced

Accessibility

Accountability

  • named_person: The page references 'senior leadership' and 'Our people' generically but does not name any specific individual or role as responsible for the About page content.
    Fix: Add the name and title of a specific accountable person or office (e.g., Head of Communications) responsible for this page's content.
  • response_timeframe: The About page contains no published response timeframes for inquiries or complaints.
    Fix: Add a statement specifying how quickly the institution responds to inquiries or complaints (e.g., within 10 working days).
  • specific: No specific timeframes in days or weeks are provided anywhere on the page.
    Fix: Publish concrete response times in calendar or working days rather than vague language like 'promptly' or 'soon'.
  • process_exists: The page does not reference or link to a documented complaints or feedback process.
    Fix: Add a clearly labeled link to a complaints/feedback policy page from the About section or footer.
  • steps_clear: No steps for submitting a complaint are described or linked from this page.
    Fix: Provide a numbered, step-by-step guide on how to raise a complaint, including contact details and escalation routes.
  • appeals_exists: The page mentions a 'Complaints' section but only states complaints will be addressed as soon as possible, without describing a documented appeals process.
    Fix: Add a clearly documented appeals procedure describing how users can formally challenge decisions, including steps, timelines, and contact details.
  • independent: There is no mention of an independent reviewer or escalation path; the College reserves sole discretion over the terms without any external oversight.
    Fix: Specify an independent or escalated review body (e.g., an ombudsman or external adjudicator) that users can appeal to if dissatisfied with the initial response.

AI & Automation

  • detailed_scope: The page lacks any detailed scope definition for AI use, only describing research themes and events.
    Fix: Include a detailed scope section in the AI policy enumerating specific use cases, user groups, and boundaries of AI deployment.
  • limitations: No acknowledgement of AI system limitations (e.g., bias, hallucination, accuracy constraints) appears on the page.
    Fix: Add a section explicitly acknowledging known limitations of AI systems used, such as accuracy, bias, and appropriate-use caveats.
  • safeguards: The page references responsible research aspirations but does not describe concrete safeguards, oversight, or quality controls.
    Fix: Document specific safeguards (human oversight, review processes, data protections, audit mechanisms) applied to AI use.
  • marking_policy: The page does not describe any policy for marking or labelling AI-assisted content produced by the Institute or King's.
    Fix: Publish a clear policy statement on the AI Institute page explaining how AI-assisted content (articles, news, research outputs) is identified and labelled.
  • consistent: Since no marking policy is visible, there is no evidence that AI content labelling is applied consistently across articles, news items, or events listed.
    Fix: Apply consistent AI-content labels (e.g. an 'AI-assisted' tag) to every relevant article, news post, and event and document the convention on the site.
  • oversight_exists: The page mentions responsible research with AI in general terms but does not document any human oversight process for AI outputs on the site or within the Institute.
    Fix: Add a dedicated section describing how humans oversee AI outputs (e.g. editorial review, research governance) with links to relevant governance documents.
  • review_process: No review or approval workflow for AI-generated outputs is described anywhere on the visible page content.
    Fix: Describe the step-by-step review or approval process (who reviews, what criteria, sign-off stages) for AI-assisted outputs on a governance or 'responsible AI' page.
  • accountability: No named role, committee, or contact is identified as accountable for AI-generated content on the page.
    Fix: Name an accountable owner (e.g. Institute Director, editorial lead, or AI governance committee) with contact details for AI-generated content queries.

Interoperability

Privacy

  • necessity: The notice does not explicitly state that data collection is limited to what is necessary (no data minimisation statement is present).
    Fix: Add an explicit data minimisation statement confirming the university only collects personal information necessary for the stated purposes.
  • proportionate: There is no statement that data collected is proportionate to the service provided; the notice focuses on lawful bases rather than proportionality.
    Fix: Include language affirming that the amount and type of personal data collected is proportionate to, and not excessive for, the purposes described.
  • retention_stated: The notice refers users to an external 'Records and Data Retention Schedule' rather than stating retention periods on the page itself.
    Fix: Summarise key retention periods directly in the privacy notice (in addition to linking to the full schedule) so users can see them without leaving the page.
  • specific: Aside from the 12-month persistent cookie expiry, retention periods are vague and deferred to another document with no specific durations given.
    Fix: Provide specific example retention periods (e.g., for student records, applicant data, alumni data) with concrete timeframes in the notice.
  • equal_choices: The page itself does not display a consent banner with accept/reject options; only a 'Manage cookies' footer link is present, giving no visible indication that reject is as prominent as accept.
    Fix: Implement a cookie consent banner where 'Reject All' is displayed with equal visual prominence (same size, color, and placement) as 'Accept All' on first visit.
  • banner_present: The page content shows no visible cookie or consent banner; only a 'Cookies' link appears in the footer.
    Fix: Implement a visible cookie consent banner that appears on first visit to inform users about cookie usage and obtain consent.
  • partner_sharing_mentioned: No banner or on-page consent copy discloses data sharing with third-party partners.
    Fix: Add clear disclosure in the cookie banner stating whether and how user data is shared with third-party partners.
  • partner_count_specific: No specific numeric count of partners is stated since partner sharing is not disclosed at all.
    Fix: Include a specific number of third-party partners (e.g., 'We share data with X partners') in the consent banner with a link to the full list.

Provenance

Security

Transparency

  • named_person: No named individual or specific team is identified for handling enquiries about the About page or its content.
    Fix: Identify a specific enquiries contact (e.g., 'Press Office' or 'Communications Team') with a named lead for this page.
  • role_clear: Because no responsible person or team is identified, no role or authority is stated.
    Fix: Once a contact is named, clearly state their role and scope of authority (e.g., 'Director of Communications, responsible for institutional messaging').
  • detail: There are no amounts, percentages, or categorised breakdowns of any funding streams provided on the page.
    Fix: Include concrete figures or categorised breakdowns (e.g., £ amounts or % shares) for each major funding source.
  • complete: The page does not cover any major funding streams of the institution, only generically pointing to loans, scholarships, and hardship funds.
    Fix: Provide a comprehensive disclosure covering all major funding streams such as tuition income, research grants, government allocations, and philanthropic donations.
  • roles_clear: The page references 'senior leadership' and 'Professional Services' categories but does not identify specific roles or responsibilities on this page itself.
    Fix: Add a brief summary (or named roles like Principal, Council, Vice-Principals) with responsibilities directly on the About page, or a clear link with descriptive text to a leadership roles page.
  • algorithm_explained: The About page contains no mention of any algorithms or automated decision-making systems used by King's College London.
    Fix: Add a section or link describing any algorithms used (e.g., in admissions, research, or student services) and their purpose.
  • impact_clear: There is no description of how algorithmic decisions affect users, staff, students, or applicants on this page.
    Fix: Include clear statements about how any algorithmic decisions impact users and what recourse they have.
  • annual_statement: The page links to a privacy policy in the footer but shows no evidence on this page of a regular or annual review of data practices.
    Fix: Add a visible note on or linked from the privacy policy indicating the date of the last review and the review cadence (e.g., annually).
  • dated: No date or version information for the privacy/data practices statement is visible on this page.
    Fix: Display a 'last updated' date or version number alongside the Privacy policy link in the footer or within the policy itself.

Level 3 — Advanced

Accessibility

Accountability

  • enforcement: The page states the College may suspend or withdraw access but does not explain the moderation enforcement process, review steps, or appeal mechanism for content decisions.
    Fix: Add a section describing how violations are reported, reviewed, acted upon (e.g., content removal, account suspension), and how users can appeal moderation decisions.

Interoperability

Security

  • plan_exists: The About page contains only institutional overview content and links, with no published incident response plan or security policy visible.
    Fix: Publish an incident response plan or security policy and link to it from the site (e.g., in the footer alongside the privacy policy).
  • notification_commitment: There is no statement anywhere on the page committing to public notification of significant security or data incidents.
    Fix: Add an explicit commitment to notify affected users and the public about significant incidents within the incident response or privacy documentation.
  • timeframe: The page provides no timeframe for disclosing incidents to affected users.
    Fix: Specify a concrete disclosure timeframe (e.g., within 72 hours of discovery) in the incident response policy.

Transparency

  • criteria_published: No specific criteria for any algorithmic decision-making are published on this About page.
    Fix: Publish a transparency page listing the specific criteria used in any algorithmic decisions made by the institution.
  • weighting: The page does not explain the weighting or prioritisation of any decision criteria.
    Fix: Document and publish how criteria are weighted or prioritised in any automated or algorithmic processes.
  • auditable: The page provides no technical or procedural detail that would enable external audit or review of algorithms.
    Fix: Provide audit-ready documentation (data sources, models, evaluation metrics, governance) or a contact route for independent review.
  • open_source: There is no link to a source code repository or any indication that the site's code is publicly available.
    Fix: Add a link in the footer or About page to a public repository (e.g., GitHub) containing the site's source code or relevant open-source projects.
  • tech_docs: No technical documentation about the site's infrastructure, APIs, or data is linked from the page.
    Fix: Publish and link to technical documentation (e.g., developer docs, API references, or site architecture notes) from the About or footer area.

Responsibility to the Future

  • specific_metrics: The page provides no specific environmental figures such as carbon emissions, energy use, or emissions reduction targets, only general statements about sustainability and climate action.
    Fix: Publish concrete environmental metrics (e.g., annual carbon footprint in tonnes CO2e, energy consumption, and reduction targets) on the about or sustainability page.
  • hosting_disclosure: There is no mention of the carbon or energy profile of the website's hosting infrastructure anywhere on the page.
    Fix: Add a statement disclosing the hosting provider's energy profile or green hosting credentials, ideally with data on the site's digital carbon footprint.
  • plan_exists: The About page describes vision, history, rankings, and news but contains no published plan for what happens if the organisation fails or exits.
    Fix: Publish a continuity or succession plan describing how the institution's obligations and digital presence would be handled in the event of failure or closure.
  • data_and_content_fate: The page and its footer links (privacy policy, terms) do not address what would happen to user data and published content in a wind-down scenario.
    Fix: Add explicit statements outlining how student, staff, and public data and published content would be preserved, transferred, or deleted if the organisation ceases operations.
  • custodians_or_mirrors: No custodians, mirrors, or archive partners are identified anywhere in the page content or footer.
    Fix: Identify and document named custodians, archive partners, or mirror arrangements responsible for safeguarding content if the organisation exits.
  • policy_exists: The page only links to a 'Work at King's' job vacancies section and a modern slavery statement, but publishes no worker wellbeing or working conditions policy.
    Fix: Publish a dedicated worker wellbeing or working conditions policy and link to it from the About page or 'Work at King's' section.
  • specific_commitments: The page contains no specific commitments regarding pay, working hours, mental health support, or employee benefits.
    Fix: Add concrete, measurable commitments on fair pay, reasonable working hours, mental health provision, and staff benefits to the relevant staff or careers page.
  • accountability: While the page mentions senior leadership and Professional Services, it does not assign any named accountability or oversight for worker conditions.
    Fix: Identify a responsible role or committee (e.g., HR Director or People Committee) overseeing worker wellbeing and state this clearly on the site.