Library of Birmingham
https://www.birmingham.gov.uk/libraryofbirmingham · 41/92 checks passed · libraries
Compliance report (framework 0.8)
Gate passed (every Core check must pass) · not counted towards the gate: paused 35, draft 48, ready for review 54.
Site level: 0 (no scored checks yet).
By level
| Level | Result |
|---|---|
| Level 1 — Basic | 23/37 (14 failed) |
| Level 2 — Enhanced | 7/27 (20 failed) |
| Level 3 — Advanced | 0/10 (4 failed) |
By category
| Category | Result |
|---|---|
| Accessibility | 9/13 |
| Accountability | 1/5 |
| AI & Automation | 3/8 |
| Interoperability | 2/3 |
| Privacy | 6/16 |
| Provenance | 1/2 |
| Security | 5/11 |
| Transparency | 3/13 |
| Responsibility to the Future | 0/3 |
Level 1 — Basic
Accessibility
- 1 WCAG 2.1 Level A violation reported by axe-core: aria-command-name.
- 1 WCAG 2.1 Level A violation reported by axe-core: aria-command-name.
AI & Automation
-
policy_exists: The page mentions 'Brum Bot, our AI-powered virtual assistant' but provides no AI use policy or statement on this About page.
Fix: Add a dedicated AI use policy or statement (or link to one) from the About page explaining how AI tools like Brum Bot are used.
-
scope_clear: Beyond naming Brum Bot as an AI assistant, the page does not explain what AI is used for or in what contexts.
Fix: Include a clear description of the scope of AI use (e.g., customer support chat, search, content moderation) on the About page.
- Not found at any of: /ai-policy, /ai.
Privacy
- 3 third-party cookie domains set cookies: bcccontactcenter.my.connect.aws, hitcounter.govmetric.com, websurveys2.govmetric.com.
- 2 hidden iframes found: https://platform.twitter.com/widgets/follow_button.2f70fb173b9000da126c79afe2098f02.en.html#dnt=false&id=twitter-widget-0&lang=en&screen_name=LibraryofBham&show_count=false&show_screen_name=true&size=m&time=1776548803258, https://platform.twitter.com/widgets/widget_iframe.2f70fb173b9000da126c79afe2098f02.html?origin=https%3A%2F%2Fwww.birmingham.gov.uk.
FAIL
No tracking pixels
- 1 1×1 third-party tracking pixel: https://maps.gstatic.com/mapfiles/transparent.png.
- Detected 6 data-leaking services across 3 categories: google fonts (fonts.googleapis.com, fonts.gstatic.com); google maps (maps.googleapis.com, maps.gstatic.com); twitter x (platform.twitter.com, syndication.twitter.com).
PASS
Session cookies only
Security
- Redirect chain (1 hops): https://www.birmingham.gov.uk/libraryofbirmingham
- content-security-policy: header not set on the response.
- referrer-policy: header not set on the response.
PASS
HTTPS enforced
PASS
No mixed content
Transparency
-
purpose_clear: The page only lists navigation links (privacy, accessibility, cookies) without stating what the site or organisation does.
Fix: Add an introductory paragraph explaining the purpose of the website and the services Birmingham City Council provides through it.
-
disclosure_exists: The page contains no funding or sponsorship disclosure of any kind.
Fix: Add a funding disclosure section identifying how the council website and services are funded (e.g., council tax, government grants).
-
transparent: No funding sources are identified anywhere on the page.
Fix: Clearly list funding sources such as public revenue, grants, or sponsorships in an accessible disclosure.
PASS
Contact form present
Level 2 — Enhanced
Accessibility
Accountability
-
named_person: The page lists generic contact categories but does not name any individual or specific role responsible for the content or services.
Fix: Add a named officer or specific role (e.g., 'Head of Customer Services') as the accountable contact on the page.
-
steps_clear: While the page mentions contacting the service first and using a map/form, it does not present clearly enumerated steps for making and tracking a complaint from start to finish.
Fix: Add a numbered step-by-step guide (e.g. 1. Contact the service, 2. Submit the complaint form, 3. Receive acknowledgement, 4. Receive response) so users can easily follow the process.
-
appeals_exists: The page describes how to make a complaint and response timeframes but does not document any appeals process for dissatisfied complainants.
Fix: Add a clearly labeled section explaining how complainants can appeal or escalate if they are unhappy with the initial response, including steps and timeframes.
-
independent: No independent or escalation route (e.g., Local Government and Social Care Ombudsman) is mentioned on the page.
Fix: Include a reference and link to an independent escalation body such as the Local Government and Social Care Ombudsman for unresolved complaints.
AI & Automation
-
detailed_scope: No detailed scope of AI use is provided; only a brief reference to an AI-powered chat assistant appears.
Fix: Publish a detailed AI scope section describing each AI feature, its purpose, data sources, and user-facing functions.
-
limitations: The page does not acknowledge any limitations of the AI system such as accuracy, bias, or hallucination risks.
Fix: Add a limitations notice describing that the AI assistant may produce inaccurate responses and directing users to authoritative council resources.
-
safeguards: No safeguards, human oversight, or quality controls for the AI assistant are described on the page.
Fix: Describe safeguards such as human review, content filtering, escalation paths, and monitoring used to ensure AI output quality.
-
marking_policy: The page references an AI-powered virtual assistant (Brum Bot) but contains no policy for marking or disclosing AI-assisted content.
Fix: Publish a clear policy on the 'About our website' page describing when and how AI-assisted content is labelled for users.
-
consistent: Without a marking policy, there is no evidence AI content marking is applied consistently across the site or to Brum Bot outputs.
Fix: Introduce a standard AI disclosure label (e.g., 'Generated by Brum Bot AI') and apply it consistently wherever AI-generated responses or content appear.
-
oversight_exists: The page mentions Brum Bot but provides no documentation of human oversight over its AI outputs.
Fix: Add a section to the About page describing how Birmingham City Council staff monitor and oversee Brum Bot's AI outputs.
-
review_process: No review or approval process for AI-generated content is described on the page.
Fix: Document the review/approval workflow for AI outputs, including how errors are identified, corrected, and escalated.
-
accountability: The page does not identify any individual, team, or role accountable for AI-generated content from Brum Bot.
Fix: Name a responsible owner (e.g., a digital services team or named officer) accountable for Brum Bot's AI content and provide contact details.
Interoperability
Privacy
-
plain_language: The page only lists links (e.g., 'Privacy statement', 'Individuals Rights Request') without any actual policy text to evaluate for plain language.
Fix: Include a plain-language summary of the privacy statement directly on this landing page rather than only linking to sub-pages.
-
comprehensive: No content on this page describes what data is collected or why; it is only a navigation index.
Fix: Add a clear summary covering categories of data collected, purposes, and lawful basis directly on this page or surface key points from the linked privacy statement.
-
plain_language: The page contains no descriptive text about data practices, only link titles, so plain language cannot be demonstrated.
Fix: Provide jargon-free descriptions of data practices on the privacy landing page itself.
-
understandable: Without any explanatory content, a non-expert cannot understand what data is collected or why from this page.
Fix: Add concise explanations of what personal data the council collects and the reasons for collection, written for a general audience.
-
necessity: The page does not state that data collection is limited to what is necessary.
Fix: Include an explicit statement that data collection is limited to what is necessary for the stated purposes.
-
proportionate: There is no content addressing proportionality of data collected to the service provided.
Fix: Add a statement explaining how collected data is proportionate to each council service provided.
-
retention_stated: No data retention periods are mentioned anywhere on the page.
Fix: Publish data retention periods on the privacy page or link prominently to a retention schedule.
-
specific: Since no retention periods are stated, none are specific.
Fix: Specify concrete retention periods (e.g., '7 years for Council Tax records') for each category of personal data.
-
no_dark_patterns: The page content shows no visible cookie consent interface or language, so it cannot be confirmed that consent is gathered without dark patterns.
Fix: Display a clear, neutral cookie consent banner with plain language and no pre-ticked boxes or manipulative framing.
-
equal_choices: No consent banner with accept/reject controls is visible on the page, so equal prominence of choices cannot be verified.
Fix: Provide an explicit 'Reject all' button with equal visual weight and prominence alongside the 'Accept all' option in the cookie banner.
-
no_forced_consent: The page lacks a visible consent mechanism, making it impossible to confirm that consent is granular and not bundled or forced.
Fix: Offer granular, unbundled consent toggles for each cookie category and ensure users can access the site without being forced to accept non-essential cookies.
-
banner_present: No cookie or consent banner is visible in the page content; only a footer 'Cookies' link appears.
Fix: Implement a visible cookie consent banner on page load that allows users to accept, reject, or manage cookie preferences.
-
partner_sharing_mentioned: The page contains no on-page consent copy disclosing data sharing with third-party partners.
Fix: Add consent banner text that explicitly discloses any third-party partners receiving user data and link to a detailed cookie/privacy policy.
-
partner_count_specific: No partner sharing is disclosed and therefore no numeric count of partners is stated on the page.
Fix: If third-party partners are used, state the specific number of partners (e.g., 'We share data with X partners') in the consent banner.
Provenance
-
credentials: No organisational background, remit, or credentials for Birmingham City Council are provided on this about page.
Fix: Add a brief description of Birmingham City Council's role, statutory responsibilities, and governance to establish organisational credentials.
Security
- security.txt not published.
Transparency
-
named_person: No named individual or specific team is identified for enquiries—only generic 'Contact us' links and categories are shown.
Fix: Identify a specific team or named contact (e.g., 'Customer Services Team') with direct contact details for enquiries.
-
role_clear: Because no person or team is named, their role or authority is not stated on the page.
Fix: State the role and remit of the responsible team (e.g., 'responsible for handling public enquiries and complaints') alongside their contact details.
-
substantive: The page contains no substantive statement of purpose, only a menu of sub-links and a maintenance notice.
Fix: Write a detailed purpose statement describing the website's aims, audiences, and scope of content.
-
mission_clear: No mission or editorial approach is articulated anywhere on the page.
Fix: Include a clear mission statement explaining the council's editorial principles and commitments to residents.
-
detail: There are no funding details, amounts, percentages, or categories provided.
Fix: Include specific figures or percentage breakdowns of revenue sources (e.g., council tax %, business rates %, grants %).
-
complete: No funding streams are disclosed, so coverage cannot be considered complete.
Fix: Publish a comprehensive breakdown of all major funding streams supporting the council and its web services.
-
governance_exists: The page lists links about the website (privacy, accessibility, cookies) but does not describe any governance or editorial structure.
Fix: Add a section outlining the editorial/governance framework that oversees website content, including decision-making processes and oversight bodies.
-
roles_clear: No key roles or responsibilities for managing or editing the website are identified on the page.
Fix: Identify and list the specific roles (e.g., editor, content owner, accessibility lead) and their responsibilities for website governance.
-
algorithm_explained: The page mentions 'Brum Bot, our AI-powered virtual assistant' but provides no explanation of its purpose or how it works.
Fix: Add a dedicated section or link explaining what Brum Bot does, its purpose, and how the AI operates.
-
impact_clear: There is no description of how the AI assistant's decisions or responses affect users seeking council services.
Fix: Include a clear statement describing the impact of Brum Bot's responses on users and what to do if the AI provides incorrect information.
-
annual_statement: The page lists a Privacy statement link but provides no evidence of a regular or annual review of data practices.
Fix: Add a visible note on the Privacy statement indicating when it was last reviewed and commit to a periodic (e.g., annual) review cycle.
-
dated: No date or version information is shown for the privacy/data practices statement on this page.
Fix: Display a 'last updated' date or version number alongside the Privacy statement link or at the top of the privacy policy page.
Level 3 — Advanced
Accessibility
Skipped: Target page not found in captured content
Accountability
-
enforcement: The page says events will be 'checked by our team' and may be rejected, but does not explain how enforcement decisions are made, communicated, or appealed.
Fix: Add a section describing the review workflow, notification of rejection, reasons given, and an appeals or contact process for moderation decisions.
Interoperability
- Not found at: /status
Security
SKIPPED
Incident response plan published
Skipped: Target page not found in captured content
Skipped: Target page not found in captured content
Transparency
-
criteria_published: No criteria used by the Brum Bot AI assistant are published anywhere on this page.
Fix: Publish the specific criteria and data sources used by Brum Bot to generate its responses.
-
weighting: There is no information about how the AI assistant weights or prioritises different inputs or criteria.
Fix: Document and publish the weighting or prioritisation logic used by the algorithm in an accessible transparency notice.
-
auditable: The page provides no technical or procedural detail that would allow an external party to audit the AI assistant.
Fix: Publish an algorithmic transparency record (e.g., following the UK ATRS standard) with enough detail to support external audit.
-
open_source: There is no link to source code; the site notes only that it is 'Designed and Powered by Jadu', a proprietary CMS.
Fix: Publish any in-house code repositories and link to them, or clearly state the open-source components used by the site.
-
tech_docs: No technical documentation about the website's architecture, APIs, or data is linked from the about page.
Fix: Add a link to technical documentation, developer resources, or an open data/API page describing how the site is built.
Responsibility to the Future
Skipped: Target page not found in captured content
SKIPPED
Succession and continuity plan
Skipped: Target page not found in captured content
SKIPPED
Worker wellbeing policy
Skipped: Target page not found in captured content