Library of Birmingham

https://www.birmingham.gov.uk/libraryofbirmingham · 41/92 checks passed · libraries

Compliance report (framework 0.8)

Gate passed (every Core check must pass) · not counted towards the gate: paused 35, draft 48, ready for review 54.

Site level: 0 (no scored checks yet).

By level

LevelResult
Level 1 — Basic 23/37 (14 failed)
Level 2 — Enhanced 7/27 (20 failed)
Level 3 — Advanced 0/10 (4 failed)

By category

CategoryResult
Accessibility 9/13
Accountability 1/5
AI & Automation 3/8
Interoperability 2/3
Privacy 6/16
Provenance 1/2
Security 5/11
Transparency 3/13
Responsibility to the Future 0/3

Level 1 — Basic

Accessibility

AI & Automation

  • policy_exists: The page mentions 'Brum Bot, our AI-powered virtual assistant' but provides no AI use policy or statement on this About page.
    Fix: Add a dedicated AI use policy or statement (or link to one) from the About page explaining how AI tools like Brum Bot are used.
  • scope_clear: Beyond naming Brum Bot as an AI assistant, the page does not explain what AI is used for or in what contexts.
    Fix: Include a clear description of the scope of AI use (e.g., customer support chat, search, content moderation) on the About page.

Privacy

Security

Transparency

  • purpose_clear: The page only lists navigation links (privacy, accessibility, cookies) without stating what the site or organisation does.
    Fix: Add an introductory paragraph explaining the purpose of the website and the services Birmingham City Council provides through it.
  • disclosure_exists: The page contains no funding or sponsorship disclosure of any kind.
    Fix: Add a funding disclosure section identifying how the council website and services are funded (e.g., council tax, government grants).
  • transparent: No funding sources are identified anywhere on the page.
    Fix: Clearly list funding sources such as public revenue, grants, or sponsorships in an accessible disclosure.

Level 2 — Enhanced

Accessibility

Accountability

  • named_person: The page lists generic contact categories but does not name any individual or specific role responsible for the content or services.
    Fix: Add a named officer or specific role (e.g., 'Head of Customer Services') as the accountable contact on the page.
  • steps_clear: While the page mentions contacting the service first and using a map/form, it does not present clearly enumerated steps for making and tracking a complaint from start to finish.
    Fix: Add a numbered step-by-step guide (e.g. 1. Contact the service, 2. Submit the complaint form, 3. Receive acknowledgement, 4. Receive response) so users can easily follow the process.
  • appeals_exists: The page describes how to make a complaint and response timeframes but does not document any appeals process for dissatisfied complainants.
    Fix: Add a clearly labeled section explaining how complainants can appeal or escalate if they are unhappy with the initial response, including steps and timeframes.
  • independent: No independent or escalation route (e.g., Local Government and Social Care Ombudsman) is mentioned on the page.
    Fix: Include a reference and link to an independent escalation body such as the Local Government and Social Care Ombudsman for unresolved complaints.

AI & Automation

  • detailed_scope: No detailed scope of AI use is provided; only a brief reference to an AI-powered chat assistant appears.
    Fix: Publish a detailed AI scope section describing each AI feature, its purpose, data sources, and user-facing functions.
  • limitations: The page does not acknowledge any limitations of the AI system such as accuracy, bias, or hallucination risks.
    Fix: Add a limitations notice describing that the AI assistant may produce inaccurate responses and directing users to authoritative council resources.
  • safeguards: No safeguards, human oversight, or quality controls for the AI assistant are described on the page.
    Fix: Describe safeguards such as human review, content filtering, escalation paths, and monitoring used to ensure AI output quality.
  • marking_policy: The page references an AI-powered virtual assistant (Brum Bot) but contains no policy for marking or disclosing AI-assisted content.
    Fix: Publish a clear policy on the 'About our website' page describing when and how AI-assisted content is labelled for users.
  • consistent: Without a marking policy, there is no evidence AI content marking is applied consistently across the site or to Brum Bot outputs.
    Fix: Introduce a standard AI disclosure label (e.g., 'Generated by Brum Bot AI') and apply it consistently wherever AI-generated responses or content appear.
  • oversight_exists: The page mentions Brum Bot but provides no documentation of human oversight over its AI outputs.
    Fix: Add a section to the About page describing how Birmingham City Council staff monitor and oversee Brum Bot's AI outputs.
  • review_process: No review or approval process for AI-generated content is described on the page.
    Fix: Document the review/approval workflow for AI outputs, including how errors are identified, corrected, and escalated.
  • accountability: The page does not identify any individual, team, or role accountable for AI-generated content from Brum Bot.
    Fix: Name a responsible owner (e.g., a digital services team or named officer) accountable for Brum Bot's AI content and provide contact details.

Interoperability

Privacy

  • plain_language: The page only lists links (e.g., 'Privacy statement', 'Individuals Rights Request') without any actual policy text to evaluate for plain language.
    Fix: Include a plain-language summary of the privacy statement directly on this landing page rather than only linking to sub-pages.
  • comprehensive: No content on this page describes what data is collected or why; it is only a navigation index.
    Fix: Add a clear summary covering categories of data collected, purposes, and lawful basis directly on this page or surface key points from the linked privacy statement.
  • plain_language: The page contains no descriptive text about data practices, only link titles, so plain language cannot be demonstrated.
    Fix: Provide jargon-free descriptions of data practices on the privacy landing page itself.
  • understandable: Without any explanatory content, a non-expert cannot understand what data is collected or why from this page.
    Fix: Add concise explanations of what personal data the council collects and the reasons for collection, written for a general audience.
  • necessity: The page does not state that data collection is limited to what is necessary.
    Fix: Include an explicit statement that data collection is limited to what is necessary for the stated purposes.
  • proportionate: There is no content addressing proportionality of data collected to the service provided.
    Fix: Add a statement explaining how collected data is proportionate to each council service provided.
  • retention_stated: No data retention periods are mentioned anywhere on the page.
    Fix: Publish data retention periods on the privacy page or link prominently to a retention schedule.
  • specific: Since no retention periods are stated, none are specific.
    Fix: Specify concrete retention periods (e.g., '7 years for Council Tax records') for each category of personal data.
  • no_dark_patterns: The page content shows no visible cookie consent interface or language, so it cannot be confirmed that consent is gathered without dark patterns.
    Fix: Display a clear, neutral cookie consent banner with plain language and no pre-ticked boxes or manipulative framing.
  • equal_choices: No consent banner with accept/reject controls is visible on the page, so equal prominence of choices cannot be verified.
    Fix: Provide an explicit 'Reject all' button with equal visual weight and prominence alongside the 'Accept all' option in the cookie banner.
  • no_forced_consent: The page lacks a visible consent mechanism, making it impossible to confirm that consent is granular and not bundled or forced.
    Fix: Offer granular, unbundled consent toggles for each cookie category and ensure users can access the site without being forced to accept non-essential cookies.
  • banner_present: No cookie or consent banner is visible in the page content; only a footer 'Cookies' link appears.
    Fix: Implement a visible cookie consent banner on page load that allows users to accept, reject, or manage cookie preferences.
  • partner_sharing_mentioned: The page contains no on-page consent copy disclosing data sharing with third-party partners.
    Fix: Add consent banner text that explicitly discloses any third-party partners receiving user data and link to a detailed cookie/privacy policy.
  • partner_count_specific: No partner sharing is disclosed and therefore no numeric count of partners is stated on the page.
    Fix: If third-party partners are used, state the specific number of partners (e.g., 'We share data with X partners') in the consent banner.

Provenance

  • credentials: No organisational background, remit, or credentials for Birmingham City Council are provided on this about page.
    Fix: Add a brief description of Birmingham City Council's role, statutory responsibilities, and governance to establish organisational credentials.

Security

Transparency

  • named_person: No named individual or specific team is identified for enquiries—only generic 'Contact us' links and categories are shown.
    Fix: Identify a specific team or named contact (e.g., 'Customer Services Team') with direct contact details for enquiries.
  • role_clear: Because no person or team is named, their role or authority is not stated on the page.
    Fix: State the role and remit of the responsible team (e.g., 'responsible for handling public enquiries and complaints') alongside their contact details.
  • substantive: The page contains no substantive statement of purpose, only a menu of sub-links and a maintenance notice.
    Fix: Write a detailed purpose statement describing the website's aims, audiences, and scope of content.
  • mission_clear: No mission or editorial approach is articulated anywhere on the page.
    Fix: Include a clear mission statement explaining the council's editorial principles and commitments to residents.
  • detail: There are no funding details, amounts, percentages, or categories provided.
    Fix: Include specific figures or percentage breakdowns of revenue sources (e.g., council tax %, business rates %, grants %).
  • complete: No funding streams are disclosed, so coverage cannot be considered complete.
    Fix: Publish a comprehensive breakdown of all major funding streams supporting the council and its web services.
  • governance_exists: The page lists links about the website (privacy, accessibility, cookies) but does not describe any governance or editorial structure.
    Fix: Add a section outlining the editorial/governance framework that oversees website content, including decision-making processes and oversight bodies.
  • roles_clear: No key roles or responsibilities for managing or editing the website are identified on the page.
    Fix: Identify and list the specific roles (e.g., editor, content owner, accessibility lead) and their responsibilities for website governance.
  • algorithm_explained: The page mentions 'Brum Bot, our AI-powered virtual assistant' but provides no explanation of its purpose or how it works.
    Fix: Add a dedicated section or link explaining what Brum Bot does, its purpose, and how the AI operates.
  • impact_clear: There is no description of how the AI assistant's decisions or responses affect users seeking council services.
    Fix: Include a clear statement describing the impact of Brum Bot's responses on users and what to do if the AI provides incorrect information.
  • annual_statement: The page lists a Privacy statement link but provides no evidence of a regular or annual review of data practices.
    Fix: Add a visible note on the Privacy statement indicating when it was last reviewed and commit to a periodic (e.g., annual) review cycle.
  • dated: No date or version information is shown for the privacy/data practices statement on this page.
    Fix: Display a 'last updated' date or version number alongside the Privacy statement link or at the top of the privacy policy page.

Level 3 — Advanced

Accessibility

Accountability

  • enforcement: The page says events will be 'checked by our team' and may be rejected, but does not explain how enforcement decisions are made, communicated, or appealed.
    Fix: Add a section describing the review workflow, notification of rejection, reasons given, and an appeals or contact process for moderation decisions.

Interoperability

Security

Transparency

  • criteria_published: No criteria used by the Brum Bot AI assistant are published anywhere on this page.
    Fix: Publish the specific criteria and data sources used by Brum Bot to generate its responses.
  • weighting: There is no information about how the AI assistant weights or prioritises different inputs or criteria.
    Fix: Document and publish the weighting or prioritisation logic used by the algorithm in an accessible transparency notice.
  • auditable: The page provides no technical or procedural detail that would allow an external party to audit the AI assistant.
    Fix: Publish an algorithmic transparency record (e.g., following the UK ATRS standard) with enough detail to support external audit.
  • open_source: There is no link to source code; the site notes only that it is 'Designed and Powered by Jadu', a proprietary CMS.
    Fix: Publish any in-house code repositories and link to them, or clearly state the open-source components used by the site.
  • tech_docs: No technical documentation about the website's architecture, APIs, or data is linked from the about page.
    Fix: Add a link to technical documentation, developer resources, or an open data/API page describing how the site is built.

Responsibility to the Future