National Museums Scotland
https://www.nms.ac.uk · 49/92 checks passed · archives
Compliance report (framework 0.8)
Gate passed (every Core check must pass) · not counted towards the gate: paused 35, draft 48, ready for review 54.
Site level: 0 (no scored checks yet).
By level
| Level | Result |
|---|---|
| Level 1 — Basic | 27/37 (10 failed) |
| Level 2 — Enhanced | 13/27 (14 failed) |
| Level 3 — Advanced | 0/10 (9 failed) |
By category
| Category | Result |
|---|---|
| Accessibility | 9/13 |
| Accountability | 0/5 |
| AI & Automation | 3/8 |
| Interoperability | 2/3 |
| Privacy | 11/16 |
| Provenance | 2/2 |
| Security | 6/11 |
| Transparency | 7/13 |
| Responsibility to the Future | 0/3 |
Level 1 — Basic
Accessibility
- 2 WCAG 2.1 Level A violations reported by axe-core: list, listitem.
- 2 WCAG 2.1 Level A violations reported by axe-core: list, listitem.
AI & Automation
-
policy_exists: The About page lists policies and reports but shows no AI use policy or statement anywhere on the page.
Fix: Publish a dedicated AI use policy or statement and link to it from the Policies and reports section of the About page.
-
scope_clear: With no AI policy present, there is no explanation of what AI is used for on the site.
Fix: Clearly describe in the AI policy which site functions or operations (e.g., search, translation, collections metadata) use AI.
- Not found at any of: /ai-policy, /ai.
Privacy
- 1 inline script matched a tracker/ad pattern; first match: ' window.dataLayer = window.dataLayer || []; function gtag() { dataLayer.…'.
- 1 hidden iframe found: https://consentcdn.cookiebot.com/sdk/bc-v4.min.html.
- Detected 2 data-leaking services across 1 category: cookie consent saas (consent.cookiebot.com, consentcdn.cookiebot.com).
PASS
Session cookies only
PASS
No tracking pixels
Security
- Redirect chain (1 hops): https://www.nms.ac.uk
- content-security-policy: header not set on the response.
PASS
HTTPS enforced
PASS
No mixed content
Transparency
PASS
Contact form present
Level 2 — Enhanced
Accessibility
Accountability
-
named_person: The page lists generic departments (e.g., 'Executive Team', 'Media enquiries') but does not name a specific person or role responsible for handling contact enquiries.
Fix: Identify at least one named individual or specific role (e.g., 'Head of Visitor Services, Jane Smith') accountable for responding to enquiries.
-
response_timeframe: The contact page lists phone, email, and postal options but does not state any timeframe for when enquiries will be answered.
Fix: Add a clear statement on the contact page indicating how long visitors should expect to wait for a response (e.g. 'We aim to respond to emails within 5 working days').
-
specific: Since no timeframe is published at all, there is no specific duration (in days or hours) provided.
Fix: Publish a specific, measurable response target such as '3 working days' rather than vague language like 'soon' or 'promptly'.
-
process_exists: The page provides contact channels but does not reference or link to a documented complaints or feedback process.
Fix: Add a dedicated complaints/feedback section or link to a complaints policy outlining how feedback and complaints are handled.
-
steps_clear: With no complaints process documented on the page, there are no clear steps for making a complaint.
Fix: Provide a step-by-step guide (e.g. Step 1: contact the department, Step 2: escalate to X, Step 3: external review) so users can follow a transparent complaints path.
-
appeals_exists: The contact page only lists general contact methods and no documented appeals process is mentioned.
Fix: Add a dedicated appeals or complaints procedure section describing how users can formally challenge decisions.
-
independent: No escalation path or independent review body is referenced on the page.
Fix: Document an escalation route to an independent reviewer or external ombudsman for unresolved appeals.
AI & Automation
-
detailed_scope: No AI policy is visible on the page, so no detailed scope of AI use is provided.
Fix: Add an AI policy section detailing specific AI systems, use cases, and data involved across museum operations and digital services.
-
limitations: The page contains no acknowledgement of AI system limitations because no AI policy is present.
Fix: Include a section in the AI policy that discusses known limitations such as inaccuracies, bias, and contexts where AI should not be relied upon.
-
safeguards: No safeguards or quality controls related to AI are described on this page.
Fix: Document safeguards such as human review, accuracy checks, data protection measures, and governance oversight within the AI policy.
-
marking_policy: The About page contains no reference to any policy for marking or labelling AI-assisted content.
Fix: Publish a clear policy (e.g., in Policies and reports) stating how AI-assisted content is identified and labelled on the site.
-
consistent: With no visible marking policy or labels, there is no evidence that AI content marking is applied consistently across the page.
Fix: Implement a standard AI-content label and apply it consistently to any AI-assisted text, images, or interpretation on the site.
-
oversight_exists: The page does not document any human oversight arrangements for AI outputs.
Fix: Add a statement in Policies and reports describing human oversight procedures for any AI-generated outputs.
-
review_process: No review or approval process for AI content is described anywhere on the page.
Fix: Describe the editorial review and approval workflow used before publishing AI-assisted content.
-
accountability: No individual, role, or team is identified as accountable for AI-generated content.
Fix: Name a responsible role or team (e.g., within the Executive Team) as the accountable owner for AI-generated content.
Interoperability
Privacy
-
specific: Retention is described vaguely as 'only as long as necessary for the purpose it was collected' without specific time periods.
Fix: Add concrete retention durations (e.g., 'membership data retained for 7 years after lapsing', 'CCTV footage retained for 30 days') for each data category.
-
partner_count_specific: The banner references partners in general categories but provides no specific numeric count of partners.
Fix: Add an explicit partner count (e.g., 'We share data with X partners') to the banner or link to a full vendor list with the number disclosed.
Provenance
Security
- security.txt not published.
Transparency
-
named_person: No named individual or specific team is identified for enquiries—emails to info@nms.ac.uk are simply 'passed to the relevant person' without disclosing who that is.
Fix: Add the name or title of the team/person (e.g., 'Visitor Information Team') that receives and triages enquiries sent to the general address.
-
role_clear: While category links like 'Media enquiries' and 'Executive Team' are present, the page does not clearly state the role or authority of who handles general enquiries or responds on behalf of NMS.
Fix: Clarify each contact route with a brief description of the team's remit and decision-making authority (e.g., 'Our Enquiries Team handles general public questions and routes specialist requests to curators').
-
detail: The page names categories but provides no amounts, percentages, or breakdown of how much each funding stream contributes, only referring users to an Annual Review.
Fix: Include summary figures or percentages for each funding stream (e.g., % of income from donations, memberships, corporate partners) directly on the support page or a linked funding transparency page.
-
complete: The disclosure omits major public funding streams such as Scottish Government grant-in-aid and other grants, which are typically primary income sources for National Museums Scotland.
Fix: Add a section disclosing government grant-in-aid, trust/foundation grants, and trading/commercial income alongside the philanthropic categories already listed.
-
algorithm_explained: The About page describes the museum's mission and governance but does not mention or explain any algorithms used on the site or in operations.
Fix: Add a section (or link to one) describing any algorithmic systems used—such as search, recommendations, or ticketing—and their purpose.
-
impact_clear: There is no description of how algorithmic decisions affect users visiting or interacting with the site.
Fix: Include a clear statement of how any automated decision-making impacts users (e.g., content ranking, personalisation, access) and their rights in response.
-
annual_statement: The page links to a Privacy policy but provides no evidence on this page of a regular or annual review of data practices.
Fix: Add a note on the Privacy page (and reference it here) stating when data practices were last reviewed and the cadence of future reviews.
-
dated: No date or version information for a data practices statement is visible on this About page, only a copyright year.
Fix: Include a 'last updated' date or version number on the linked Privacy/data practices statement and surface it where users can easily see it.
Level 3 — Advanced
Accessibility
-
known_issues: The visible page content only links to an accessibility page but shows no acknowledgment of known accessibility issues or limitations.
Fix: Include a section on the accessibility statement page that lists any known non-conformances or limitations of the site.
-
remediation_timeline: No timeline or commitment for fixing accessibility issues appears anywhere in the visible content.
Fix: Add a stated timeline or commitment on the accessibility page describing when known issues will be addressed.
-
feedback_channel: While a 'Contact us' link exists, there is no accessibility-specific feedback mechanism with a stated response commitment shown on the page.
Fix: Provide a dedicated accessibility feedback channel on the accessibility page along with a commitment to respond within a specified timeframe.
Accountability
-
policy_exists: The terms page covers external links, accessibility, copyright, and takedown, but does not publish any moderation policy for user-contributed content.
Fix: Publish a dedicated moderation policy section (or linked page) describing how user-generated content and interactions are moderated.
-
criteria_clear: No moderation criteria (e.g., prohibited content types, acceptable behaviour standards) are stated anywhere on the page.
Fix: Add clear criteria listing what content/behaviour is permitted or prohibited and the standards moderators apply.
-
enforcement: Only a copyright takedown process is described; there is no explanation of how moderation decisions are enforced, appealed, or escalated.
Fix: Document the enforcement workflow, including review timelines, actions taken (removal, warnings, bans), and an appeals mechanism.
Interoperability
- Not found at: /status
Security
-
plan_exists: The About us page and its listed policies/links contain no published incident response plan or security incident policy.
Fix: Publish an incident response plan or security incident policy and link it from the Policies and reports or Small Print sections.
-
notification_commitment: Nothing on the page commits to publicly notifying users of significant security or data incidents.
Fix: Add a clear statement committing to notify affected users and the public in the event of a significant security or data breach.
-
timeframe: The page states no timeframe for disclosing incidents to affected users.
Fix: Specify a concrete disclosure timeframe (e.g., notification within 72 hours of discovering a significant incident) in the incident response policy.
Skipped: Target page not found in captured content
Transparency
-
criteria_published: The page contains no information about criteria used in any algorithmic decision-making.
Fix: Publish a dedicated page listing the specific input criteria used by any algorithmic systems on the site.
-
weighting: No weighting or prioritisation of decision criteria is disclosed anywhere on this page.
Fix: Document the relative weight or priority given to each criterion used in automated decisions and link to it from the About or Policies section.
-
auditable: The page provides no technical or procedural detail sufficient for an external party to audit algorithmic processes.
Fix: Provide an algorithmic transparency record (e.g., following the UK Algorithmic Transparency Recording Standard) with enough detail to enable independent review.
-
open_source: There is no link to a source code repository; the footer only credits 'Website by Supercool' with no open-source reference.
Fix: Add a link to a public code repository (e.g., GitHub) for any reusable components, or publish a statement clarifying the site's open-source status.
-
tech_docs: No technical documentation, API reference, or developer resources are linked from the About page.
Fix: Publish and link to technical documentation such as an API, open data portal, or developer pages for the collections and digital services.
Responsibility to the Future
-
specific_metrics: The page references net zero targets, carbon reduction and biodiversity goals but provides no specific figures for carbon emissions, energy use, or measurable targets on the page itself.
Fix: Publish concrete metrics on the page, such as baseline and current carbon emissions in tonnes CO2e, energy consumption figures, and dated net zero targets.
-
hosting_disclosure: While the page shows a 'Measuring CO2…Website Carbon' widget, it does not disclose the carbon or energy profile of the hosting infrastructure or whether green hosting is used.
Fix: Add a statement disclosing the website's per-page carbon footprint and confirm whether the hosting provider uses renewable/green energy.
-
plan_exists: The About page describes governance, strategy, and commercial activities but contains no published plan for what happens if the organisation fails or exits.
Fix: Publish a succession or continuity plan describing what would happen to the museum's digital presence and collections in the event of organisational failure or closure.
-
data_and_content_fate: The page makes no mention of what would happen to user data or published content should the organisation cease to exist.
Fix: Add a section addressing the fate of user data and published content, including retention, transfer, or deletion arrangements in a wind-down scenario.
-
custodians_or_mirrors: No custodians, mirrors, or archive partners are identified anywhere on the page for preserving content if the organisation exits.
Fix: Identify and name archive partners, custodians, or mirroring arrangements (e.g., a national digital archive) responsible for preserving collections and content.
-
policy_exists: The page mentions jobs, volunteering, and a Board of Trustees but publishes no dedicated policy on worker wellbeing or working conditions.
Fix: Publish a clearly labelled worker wellbeing or working conditions policy and link it from the 'Policies and reports' or 'Jobs and volunteering' section.
-
specific_commitments: There are no specific commitments regarding pay, hours, mental health, or benefits anywhere on the page.
Fix: Add concrete, measurable commitments covering fair pay, working hours, mental health support, and employee benefits to the policy content.
-
accountability: While the Board of Trustees and Executive Team are named for strategy and operations, no accountability or oversight is specifically assigned for worker conditions.
Fix: State which role, committee, or team is responsible for overseeing and reporting on worker wellbeing and working conditions.