National Library of Scotland

https://www.nls.uk · 57/92 checks passed · libraries

Compliance report (framework 0.8)

Gate passed (every Core check must pass) · not counted towards the gate: paused 35, draft 48, ready for review 54.

Site level: 0 (no scored checks yet).

By level

LevelResult
Level 1 — Basic 34/37 (3 failed)
Level 2 — Enhanced 7/27 (20 failed)
Level 3 — Advanced 0/10 (9 failed)

By category

CategoryResult
Accessibility 12/13
Accountability 0/5
AI & Automation 3/8
Interoperability 1/3
Privacy 12/16
Provenance 0/2
Security 8/11
Transparency 5/13
Responsibility to the Future 0/3

Level 1 — Basic

Accessibility

AI & Automation

  • policy_exists: The About page contains no AI use policy or statement of any kind.
    Fix: Publish an AI use policy or statement on the About page (or link to one) describing the organisation's position on AI.
  • scope_clear: No AI usage is described anywhere on the page, so scope is not explained.
    Fix: Add a clear description of what AI tools or systems the Library uses and for which purposes (e.g., cataloguing, transcription, search).

Privacy

Security

Transparency

Level 2 — Enhanced

Accessibility

Accountability

  • named_person: The page refers only to generic 'our team' and departmental phone lines without naming any individual or specific role responsible for enquiries.
    Fix: Identify a named person or specific role (e.g., Head of Enquiry Services) as the accountable contact on the page.
  • response_timeframe: The page only states enquiries will be responded to 'as quickly as we can' and 'shortly' without publishing an actual timeframe.
    Fix: Publish a specific response timeframe (e.g. 'we respond within 5 working days') directly on the contact page.
  • specific: Language such as 'shortly' and 'as quickly as we can' is vague and contains no concrete number of days or hours.
    Fix: Replace vague terms with specific time commitments such as 'within 10 working days' for enquiries and complaints.
  • steps_clear: The contact page itself does not outline the steps of the complaints process; it only links out to a separate procedure without summarising what to expect.
    Fix: Summarise the key steps of the complaints process (how to submit, acknowledgement, investigation, response, escalation) directly on the contact page alongside the link.
  • independent: The page does not indicate any independent review or escalation path (e.g., to an ombudsman or external body) for unresolved complaints.
    Fix: Add information on the contact page about escalating unresolved complaints to an independent body such as the Scottish Public Services Ombudsman.

AI & Automation

  • detailed_scope: There is no AI policy on the page, so no detailed scope is provided.
    Fix: Include a detailed scope section in the AI policy listing specific systems, use cases, and data involved.
  • limitations: The page does not acknowledge any AI limitations since no AI policy is present.
    Fix: Add a section acknowledging known limitations of AI (e.g., accuracy, bias, hallucination) within a published AI policy.
  • safeguards: No safeguards or quality controls for AI are described on the page.
    Fix: Document safeguards such as human review, bias testing, and data governance controls in a published AI policy.
  • marking_policy: The About page contains no policy or statement regarding the marking of AI-assisted content.
    Fix: Publish a clear policy under Plans and policies that describes how AI-assisted content is labelled on the site.
  • consistent: No AI content markings are visible on the page, so consistency of application cannot be demonstrated.
    Fix: Introduce a standard visual label or disclosure for AI-assisted content and apply it consistently across all pages.
  • oversight_exists: The page does not mention any human oversight of AI outputs.
    Fix: Add a statement to the About or policies section describing how humans oversee any AI-generated outputs used by the Library.
  • review_process: No review or approval workflow for AI content is described anywhere on this page.
    Fix: Document the editorial review and approval steps for AI-assisted content within a published AI governance policy.
  • accountability: No individual, role, or team is identified as accountable for AI-generated content.
    Fix: Name a responsible role (e.g., a Head of Digital or AI governance lead) accountable for AI outputs in the published policy.

Interoperability

Privacy

  • necessity: The visible overview page does not explicitly state that data collection is limited to what is necessary.
    Fix: Add a statement on the privacy overview page affirming that data collection is limited to what is strictly necessary for the stated purpose.
  • proportionate: There is no explicit statement on this overview page that data collected is proportionate to the service provided.
    Fix: Include a clear proportionality statement on the overview page indicating that data collected is proportionate to the activity/service.
  • retention_stated: The overview page does not mention data retention periods at all.
    Fix: Add a retention section (or link to one) on the privacy overview summarising how long each category of personal data is kept.
  • specific: Since retention is not addressed, no specific time periods are provided on this page.
    Fix: State concrete retention periods (e.g. 'CCTV footage retained for 30 days', 'enquiry records kept for 2 years') rather than vague language.
  • equal_choices: The page content shown contains no visible consent interface with accept/reject options, so equal prominence cannot be confirmed (only a 'Cookies' footer link is present).
    Fix: Provide a consent banner with 'Accept' and 'Reject' buttons rendered with equal visual weight (same size, color, and placement) on first visit.
  • banner_present: The page content shows no visible cookie or consent banner; only a 'Cookies' footer link is present.
    Fix: Implement a visible cookie consent banner that appears on first visit to inform users and capture their preferences.
  • partner_sharing_mentioned: No on-page consent copy or banner discloses any data sharing with third-party partners.
    Fix: Add clear language in the cookie banner disclosing whether data is shared with third-party partners and link to the full cookie policy.
  • partner_count_specific: Because partner sharing is not disclosed at all, no specific numeric count of partners is stated.
    Fix: If third-party partners are used, state the exact number of partners (e.g., 'We share data with X partners') in the consent banner.

Provenance

  • credentials: While the organisation is named, no detail is given on its credentials, governance, or background on this page itself.
    Fix: Add a brief summary of the Library's statutory role, governance, and history (or link directly to such a page) from the About us landing.

Security

Transparency

  • named_person: No named individual or specific team (beyond a vague 'our team') is identified as responsible for handling enquiries.
    Fix: Name the responsible team (e.g., 'Enquiries Team' or 'Reader Services') and, ideally, a lead contact person for enquiries.
  • role_clear: The page does not state the role or authority of whoever responds to enquiries, complaints, or feedback.
    Fix: Add a brief description of the responsible team's role and authority, such as who handles enquiries, complaints, and media requests.
  • substantive: The description is a short tagline-like sentence with navigational links rather than a substantive explanation of the Library's work.
    Fix: Expand the About us page with detailed content describing the Library's activities, collections, and impact directly on the page rather than only linking out.
  • mission_clear: The page references a strategy and mission but does not articulate the mission or editorial approach on the page itself.
    Fix: Include the Library's mission and vision statements directly on the About us page instead of requiring users to click through to the strategy page.
  • detail: The page describes funding categories (donations, patrons, legacies, organisations) but provides no amounts, percentages, or breakdown of how funds are used.
    Fix: Add figures or percentages showing how much is raised from each stream and how funds are allocated (e.g., digitisation, exhibitions, preservation).
  • complete: The page omits major funding streams typical for a national library such as Scottish Government grant-in-aid, trusts, and commercial income, focusing only on philanthropic giving.
    Fix: Include or link to a complete funding overview covering government grant-in-aid, trusts and foundations, commercial/trading income, and philanthropy.
  • governance_exists: The About page mentions 'Plans and policies' and 'Who we are and what we do' as links but does not describe the governance or editorial structure on this page.
    Fix: Add a dedicated governance section on the About page summarising the board/trustees and editorial oversight, with links to detailed governance documents.
  • roles_clear: No key roles or responsibilities (e.g., trustees, executive leadership, editorial leads) are identified in the visible page content.
    Fix: List key leadership roles and their responsibilities (e.g., Chair, National Librarian, Board members) directly on the About page or link prominently to a leadership/team page.
  • algorithm_explained: The About page makes no mention of any algorithms or automated decision-making systems used by the Library.
    Fix: Add a section disclosing any algorithms used (e.g., in search, recommendations, or collection curation) and explain their purpose.
  • impact_clear: There is no description of how algorithmic decisions might affect users of the Library's services.
    Fix: Include a clear statement describing the impact of any algorithmic decisions on users, such as search ranking or access decisions.
  • annual_statement: The page links to a Privacy page but shows no evidence of an annual or periodic review of data practices.
    Fix: Publish a note on the Privacy page indicating when data practices were last reviewed and commit to a regular review cadence.
  • dated: There is no visible date or version on the privacy/data practices reference from this page.
    Fix: Add a 'Last updated' date or version number to the Privacy statement linked from the footer.

Level 3 — Advanced

Accessibility

  • known_issues: The provided page content is the About page and shows no acknowledgment of any known accessibility issues or limitations.
    Fix: Ensure the linked accessibility statement page explicitly lists known non-compliant elements or accessibility limitations of the site.
  • remediation_timeline: There is no visible timeline or commitment for fixing accessibility issues anywhere on the provided page.
    Fix: Add a stated timeline or target dates in the accessibility statement for remediating identified accessibility issues.
  • feedback_channel: The page offers a 'Contact us' link but no feedback mechanism specific to accessibility with a stated response commitment.
    Fix: Provide a dedicated accessibility feedback contact in the statement along with a commitment to respond within a defined timeframe.

Accountability

  • policy_exists: The About page does not publish or link to any moderation policies for user-generated content.
    Fix: Publish a dedicated moderation policy page and link to it from the About or Plans and policies section.
  • criteria_clear: No moderation criteria (e.g., prohibited content, acceptable use) are stated on the page.
    Fix: Add a clearly written list of moderation criteria detailing what content is allowed or removed.
  • enforcement: The page does not describe any enforcement process, appeals, or moderator responsibilities.
    Fix: Document the enforcement workflow, including how violations are handled, who reviews them, and how users can appeal.

Interoperability

Security

  • plan_exists: The page only lists general policies and Freedom of Information links but shows no published incident response plan or policy.
    Fix: Publish a dedicated incident response plan or policy and link to it from the plans and policies section.
  • notification_commitment: There is no statement committing to public notification of significant security or data incidents anywhere on the page.
    Fix: Add a clear commitment to notify the public and affected users when a significant incident occurs.
  • timeframe: The page provides no timeframe for disclosing incidents to affected users.
    Fix: Specify a concrete disclosure timeframe (e.g., notification within 72 hours of discovering a significant incident).

Transparency

  • criteria_published: No criteria for any algorithmic decisions are published on this page.
    Fix: Publish the specific criteria used in any algorithmic decision-making processes on a dedicated transparency page.
  • weighting: The page does not explain the weighting or prioritisation of any decision criteria.
    Fix: Document the relative weighting or priority assigned to each criterion used by algorithms on the site.
  • auditable: The page provides no technical or procedural detail that would support external audit of algorithmic systems.
    Fix: Provide auditable documentation such as model cards, data sources, and review processes to enable external scrutiny.
  • open_source: No link to source code or a public code repository is present on the page.
    Fix: Add a link to any public code repositories (e.g., GitHub) or a statement about open-source projects maintained by the Library.
  • tech_docs: No technical documentation or developer resources are referenced on the page.
    Fix: Provide a link to technical documentation, APIs, or open data resources from the About us page.

Responsibility to the Future

  • disclosure_exists: The About page lists plans, policies, and annual reviews but contains no published environmental impact or sustainability disclosure.
    Fix: Publish a dedicated sustainability or environmental impact statement and link it prominently from the About and Plans and policies sections.
  • specific_metrics: The page provides no specific figures on carbon emissions, energy use, or other environmental metrics.
    Fix: Include measurable environmental data such as annual carbon footprint, energy consumption, and emissions figures in a sustainability report.
  • hosting_disclosure: There is no mention of the carbon or energy profile of the website's hosting infrastructure.
    Fix: Disclose the hosting provider's energy sourcing or carbon profile, e.g. whether servers run on renewable energy, in the site's environmental or technical documentation.
  • plan_exists: The page lists organisational policies and annual reviews generically but shows no published plan for what happens if the Library fails or exits its operations.
    Fix: Publish a succession or continuity plan under 'Plans and policies' describing what would happen to the organisation and its collections in the event of closure or transfer.
  • data_and_content_fate: The page references digital resources and collections but does not address what would happen to user data or published content should the organisation cease to exist.
    Fix: Add explicit statements about the fate of user data and published/digitised content, including retention, transfer, or deletion arrangements in a wind-down scenario.
  • custodians_or_mirrors: No custodians, mirrors, or archive partners are identified anywhere on the page for preserving collections if the Library exits.
    Fix: Name designated custodians, archive partners, or mirror institutions that would take over stewardship of the collections and digital assets.
  • policy_exists: The page mentions 'Plans and policies' and 'organisational policies' but contains no specific published policy on worker wellbeing or working conditions.
    Fix: Publish a dedicated worker wellbeing or working conditions policy and link to it clearly from the About or Jobs sections.
  • specific_commitments: The page includes no specific commitments regarding pay, hours, mental health, or benefits for workers.
    Fix: Add explicit commitments on fair pay, working hours, mental health support, and benefits within a wellbeing policy accessible from this page.
  • accountability: The page does not identify any person, team, or governance body responsible for overseeing worker conditions.
    Fix: Name a responsible role or committee (e.g., HR director or a wellbeing oversight board) accountable for monitoring and improving worker conditions.