National Records of Scotland

https://www.nrscotland.gov.uk · 52/92 checks passed · archives

Compliance report (framework 0.8)

Gate passed (every Core check must pass) · not counted towards the gate: paused 35, draft 48, ready for review 54.

Site level: 0 (no scored checks yet).

By level

LevelResult
Level 1 — Basic 30/37 (7 failed)
Level 2 — Enhanced 10/27 (17 failed)
Level 3 — Advanced 0/10 (9 failed)

By category

CategoryResult
Accessibility 11/13
Accountability 0/5
AI & Automation 3/8
Interoperability 1/3
Privacy 10/16
Provenance 1/2
Security 7/11
Transparency 7/13
Responsibility to the Future 0/3

Level 1 — Basic

Accessibility

AI & Automation

  • policy_exists: The About page contains no AI use policy or statement of any kind.
    Fix: Publish an AI use policy or statement on the About section outlining the organisation's approach to AI.
  • scope_clear: No AI-related content appears on the page, so the scope of AI use is not explained.
    Fix: Add a clear description of what AI systems are used for (e.g., records processing, statistics) within a dedicated AI policy page.

Privacy

  • 1 hidden iframe found: https://www.google.com/recaptcha/api2/bframe?hl=en&v=gTpTIWhbKpxADzTzkcabhXN4&k=6Lf43IwqAAAAAPWrGqpz6Cub1DuQMelBH6Xgs94L&bft=0dAFcWeA4rU8GBRev0tu6LBopu15IaERGaYp6ctTjXez--0rG9abtFRPvI8Hvx9kVVBYgA26ti2EZ_KnFMW6l8_7FIp0myM38b3w.

Security

Transparency

Level 2 — Enhanced

Accessibility

Accountability

  • named_person: The page does not identify any named individual or specific role responsible; it only refers generically to 'the best placed team or person'.
    Fix: Add the name or job title of a responsible officer (e.g., Head of Customer Services) accountable for handling enquiries.
  • response_timeframe: The contact page lists phone line hours and enquiry types but does not publish any timeframe for responding to enquiries submitted via the online form or other channels.
    Fix: Add a clear statement on the contact page indicating how long users should expect to wait for a response (e.g., 'We aim to respond within 10 working days').
  • specific: Since no response timeframe is published at all, there is no specific duration in days or weeks provided.
    Fix: Include a specific numeric timeframe such as 'within 5 working days' for each enquiry type rather than vague language.
  • process_exists: The page only lists 'Complaint' as a dropdown option on the contact form but does not document or link to any complaints or feedback process.
    Fix: Publish a dedicated complaints procedure page (or link to one from the contact page) describing how complaints are handled, escalated, and resolved.
  • steps_clear: No step-by-step instructions for making a complaint are provided beyond selecting 'Complaint' from a dropdown menu.
    Fix: Outline clear numbered steps for submitting a complaint, including what information to provide, who reviews it, expected response times, and escalation options.
  • appeals_exists: The contact page lists enquiry categories (including complaints and FOI requests) but does not describe a documented appeals process for decisions.
    Fix: Add a clearly labeled appeals section or link to a dedicated appeals procedure page outlining how users can formally contest decisions.
  • independent: No mention is made of an independent reviewer or escalation path (e.g., to an ombudsman or information commissioner) for appeals.
    Fix: Document an escalation route to an independent body such as the Scottish Public Services Ombudsman or Scottish Information Commissioner for unresolved appeals.

AI & Automation

  • detailed_scope: The page does not mention AI at all, let alone detail the scope of its use.
    Fix: Create a detailed AI policy describing each use case, data processed, and systems employed.
  • limitations: No AI limitations are acknowledged because there is no AI content on the page.
    Fix: Include an explicit section acknowledging limitations such as accuracy, bias, and model constraints in the AI policy.
  • safeguards: No safeguards or quality controls for AI are described on this page.
    Fix: Document safeguards such as human review, quality assurance, and audit processes in a published AI policy.
  • marking_policy: The About page contains no mention of a policy for marking or labelling AI-assisted content.
    Fix: Publish a clear policy statement on the About page (or linked from it) describing how AI-assisted content is identified and labelled.
  • consistent: Without any marking policy visible, there is no evidence AI content marking is applied consistently across the site.
    Fix: Adopt and document a consistent AI-content labelling convention and apply it visibly wherever AI-assisted content appears.
  • oversight_exists: The page does not document any human oversight arrangements for AI outputs.
    Fix: Add a section describing how humans oversee and validate any AI-generated outputs used by the organisation.
  • review_process: No review or approval process for AI-generated content is described on the page.
    Fix: Publish the steps of the review/approval workflow (e.g., drafting, editorial check, sign-off) applied to AI outputs.
  • accountability: The page does not name any role, board or individual accountable for AI-generated content.
    Fix: Identify a named role or governance board (such as one of the listed boards) as accountable owner for AI content and state this publicly.

Interoperability

Privacy

  • necessity: The notice describes specific data uses but does not explicitly state a principle that data collection is limited to what is necessary.
    Fix: Add an explicit statement that NRS only collects personal data that is necessary for the specified purposes, referencing the data minimisation principle.
  • equal_choices: The page does not display a visible consent banner with accept and reject options for evaluation of prominence.
    Fix: Implement a cookie consent banner with equally prominent 'Accept' and 'Reject' buttons at the same visual weight and styling.
  • partner_sharing_mentioned: The banner only mentions collecting anonymous data to improve browsing experience and does not disclose any data sharing with third-party partners.
    Fix: Update the cookie banner to explicitly disclose whether any data is shared with third-party partners and link to a list of those partners.
  • partner_count_specific: No numeric count of partners is stated because partner sharing is not disclosed at all in the banner copy.
    Fix: If third-party partners receive data, state the exact number of partners in the banner (e.g., 'We share data with X partners').

Provenance

Security

Transparency

  • named_person: No named individual or specific team is identified; enquiries are routed generically to an unspecified 'best placed team or person'.
    Fix: List the specific teams (e.g., Certificate Services Team, FOI Team) or named contacts responsible for each enquiry category.
  • role_clear: Because no person or team is named, their role or authority for handling enquiries is not stated on the page.
    Fix: Alongside each contact route, state the role or remit of the team handling it (e.g., 'FOI Officer – responsible for statutory information requests').
  • detail: The About page itself provides no amounts, percentages, or funding categories—only a link to annual reports.
    Fix: Include a summary of funding figures or categories directly on the About page, or a brief excerpt with a link to the detailed annual accounts.
  • complete: The page does not enumerate all funding streams (e.g., grant-in-aid, fees from registration services, or other income sources).
    Fix: Add a concise breakdown listing all major income streams (grant-in-aid, service fees, etc.) on the About page or a linked funding disclosure page.
  • algorithm_explained: The About page does not mention any algorithms or explain their purpose.
    Fix: Add a section describing any algorithms or automated decision systems used by NRS and their purpose.
  • impact_clear: There is no description of how algorithmic decisions affect users on this page.
    Fix: Include clear statements about how any algorithmic decisions impact users and their services.
  • annual_statement: The About page references a 2024-2029 strategy and annual reports but shows no evidence of a regular/periodic review of data practices on this page.
    Fix: Add a note or link on the About page indicating when the privacy/data practices statement was last reviewed and the review cadence.
  • dated: The Privacy link is listed in the footer but the page itself provides no date or version for the data practices statement.
    Fix: Display a 'last updated' date or version number alongside the Privacy link or on the privacy statement itself.

Level 3 — Advanced

Accessibility

  • remediation_timeline: The statement describes what NRS is 'working towards' and doing to improve but gives no dates or target deadlines for fixing the identified issues.
    Fix: Add specific target dates or timeframes for resolving each listed non-compliance (e.g., 'we aim to fix the status message issue by Q4 2025').
  • feedback_channel: The statement invites users to 'contact us with details' and references EHRC/EASS enforcement, but includes no commitment to a response timeframe.
    Fix: State an explicit response commitment for feedback, such as 'we will respond to accessibility reports within 5 working days.'

Accountability

  • policy_exists: The About page does not publish or link to any moderation policy for user-contributed content.
    Fix: Publish a dedicated moderation policy page and link to it from the About or Information and processes section.
  • criteria_clear: No moderation criteria (e.g., what content is allowed or removed) are stated anywhere on the page.
    Fix: Document clear moderation criteria specifying acceptable content, prohibited behaviour, and grounds for removal.
  • enforcement: The page does not describe any enforcement process for moderation decisions, appeals, or actions taken.
    Fix: Add an enforcement section explaining how moderation decisions are made, who makes them, and how users can appeal.

Interoperability

Security

  • plan_exists: The About page lists procurement, complaints, and information-request processes but contains no published incident response plan or security incident policy.
    Fix: Publish a dedicated incident response plan or policy and link to it from the About or Privacy sections.
  • notification_commitment: There is no statement committing to public notification of significant security or data incidents anywhere on the page.
    Fix: Add an explicit commitment to notify the public and affected individuals when a significant incident occurs.
  • timeframe: The page states no timeframe for disclosing incidents to affected users.
    Fix: Specify a concrete disclosure timeframe (e.g., notification within 72 hours of confirming an incident) within the incident response policy.

Transparency

  • criteria_published: No specific criteria for algorithmic decisions are published on this page.
    Fix: Publish the specific decision criteria used by any algorithms in a dedicated transparency section.
  • weighting: The page does not explain weighting or priority of any algorithmic criteria.
    Fix: Document and publish the weighting or relative priority given to each decision criterion.
  • auditable: The page provides no technical or procedural detail sufficient for external audit of algorithms.
    Fix: Provide an algorithmic transparency record with enough detail (inputs, logic, governance) to enable external review.
  • open_source: The page contains no links to source code repositories or any mention of open-source availability of the site's code.
    Fix: Add a link from the about or footer area to a public code repository (e.g., GitHub) where the site's source code or relevant components are published.
  • tech_docs: No technical documentation for the site or its data systems is linked or referenced on the about page.
    Fix: Publish and link to technical documentation (e.g., API docs, data schemas, or developer notes) from the about page or a dedicated developer section.

Responsibility to the Future

  • disclosure_exists: The About us page describes purpose, governance, and processes but contains no published environmental impact or sustainability disclosure.
    Fix: Publish an environmental or sustainability statement outlining the organisation's environmental impact and commitments, linked from the About us section.
  • specific_metrics: No specific figures for carbon, energy use, or emissions appear anywhere on the page.
    Fix: Include quantified environmental metrics such as annual carbon emissions or energy consumption in a dedicated sustainability report.
  • hosting_disclosure: The page provides no information about the carbon or energy profile of the website's hosting infrastructure.
    Fix: Disclose the hosting provider's energy sourcing or carbon footprint, ideally noting use of renewable-powered or green hosting.
  • plan_exists: The About page describes purpose, governance, strategy, and boards but contains no published plan for organisational failure or exit.
    Fix: Publish a succession or continuity plan describing what happens to the organisation's functions if it ceases to operate or is dissolved.
  • data_and_content_fate: The page addresses information requests and records but does not state what would happen to user data and published content in the event of organisational failure or exit.
    Fix: Add explicit provisions detailing how user data and published content would be preserved, transferred, or archived if the organisation exits.
  • custodians_or_mirrors: The page references the National Records of Scotland's archive role but does not identify any designated custodians, mirrors, or archive partners to take over content should the organisation fail.
    Fix: Name specific custodians, mirror sites, or archive partners responsible for maintaining the data and content if the organisation ceases operations.
  • policy_exists: The About page contains only general departmental information and links (procurement, complaints, job vacancies) with no published worker wellbeing or working conditions policy.
    Fix: Publish a dedicated worker wellbeing or working conditions policy and link to it from the About us page.
  • specific_commitments: The page includes no specific commitments regarding pay, hours, mental health, or benefits for workers.
    Fix: Add concrete commitments covering fair pay, working hours, mental health support, and staff benefits to the wellbeing policy.
  • accountability: While the page references boards and groups, it does not identify any accountability or oversight specifically for worker conditions.
    Fix: Name the board, committee, or role responsible for overseeing worker wellbeing and describe how it is monitored.