National Records of Scotland
https://www.nrscotland.gov.uk · 52/92 checks passed · archives
Compliance report (framework 0.8)
Gate passed (every Core check must pass) · not counted towards the gate: paused 35, draft 48, ready for review 54.
Site level: 0 (no scored checks yet).
By level
| Level | Result |
|---|---|
| Level 1 — Basic | 30/37 (7 failed) |
| Level 2 — Enhanced | 10/27 (17 failed) |
| Level 3 — Advanced | 0/10 (9 failed) |
By category
| Category | Result |
|---|---|
| Accessibility | 11/13 |
| Accountability | 0/5 |
| AI & Automation | 3/8 |
| Interoperability | 1/3 |
| Privacy | 10/16 |
| Provenance | 1/2 |
| Security | 7/11 |
| Transparency | 7/13 |
| Responsibility to the Future | 0/3 |
Level 1 — Basic
Accessibility
AI & Automation
-
policy_exists: The About page contains no AI use policy or statement of any kind.
Fix: Publish an AI use policy or statement on the About section outlining the organisation's approach to AI.
-
scope_clear: No AI-related content appears on the page, so the scope of AI use is not explained.
Fix: Add a clear description of what AI systems are used for (e.g., records processing, statistics) within a dedicated AI policy page.
- Not found at any of: /ai-policy, /ai.
Privacy
- 1 inline script matched a tracker/ad pattern; first match: ' window.dataLayer = window.dataLayer || []; function gtag() { dataLayer.…'.
- 1 hidden iframe found: https://www.google.com/recaptcha/api2/bframe?hl=en&v=gTpTIWhbKpxADzTzkcabhXN4&k=6Lf43IwqAAAAAPWrGqpz6Cub1DuQMelBH6Xgs94L&bft=0dAFcWeA4rU8GBRev0tu6LBopu15IaERGaYp6ctTjXez--0rG9abtFRPvI8Hvx9kVVBYgA26ti2EZ_KnFMW6l8_7FIp0myM38b3w.
- Detected 1 data-leaking service across 1 category: google fonts (fonts.gstatic.com).
PASS
Session cookies only
PASS
No tracking pixels
Security
- Redirect chain (1 hops): https://www.nrscotland.gov.uk
PASS
HTTPS enforced
PASS
No mixed content
Transparency
PASS
Contact form present
Level 2 — Enhanced
Accessibility
Accountability
-
named_person: The page does not identify any named individual or specific role responsible; it only refers generically to 'the best placed team or person'.
Fix: Add the name or job title of a responsible officer (e.g., Head of Customer Services) accountable for handling enquiries.
-
response_timeframe: The contact page lists phone line hours and enquiry types but does not publish any timeframe for responding to enquiries submitted via the online form or other channels.
Fix: Add a clear statement on the contact page indicating how long users should expect to wait for a response (e.g., 'We aim to respond within 10 working days').
-
specific: Since no response timeframe is published at all, there is no specific duration in days or weeks provided.
Fix: Include a specific numeric timeframe such as 'within 5 working days' for each enquiry type rather than vague language.
-
process_exists: The page only lists 'Complaint' as a dropdown option on the contact form but does not document or link to any complaints or feedback process.
Fix: Publish a dedicated complaints procedure page (or link to one from the contact page) describing how complaints are handled, escalated, and resolved.
-
steps_clear: No step-by-step instructions for making a complaint are provided beyond selecting 'Complaint' from a dropdown menu.
Fix: Outline clear numbered steps for submitting a complaint, including what information to provide, who reviews it, expected response times, and escalation options.
-
appeals_exists: The contact page lists enquiry categories (including complaints and FOI requests) but does not describe a documented appeals process for decisions.
Fix: Add a clearly labeled appeals section or link to a dedicated appeals procedure page outlining how users can formally contest decisions.
-
independent: No mention is made of an independent reviewer or escalation path (e.g., to an ombudsman or information commissioner) for appeals.
Fix: Document an escalation route to an independent body such as the Scottish Public Services Ombudsman or Scottish Information Commissioner for unresolved appeals.
AI & Automation
-
detailed_scope: The page does not mention AI at all, let alone detail the scope of its use.
Fix: Create a detailed AI policy describing each use case, data processed, and systems employed.
-
limitations: No AI limitations are acknowledged because there is no AI content on the page.
Fix: Include an explicit section acknowledging limitations such as accuracy, bias, and model constraints in the AI policy.
-
safeguards: No safeguards or quality controls for AI are described on this page.
Fix: Document safeguards such as human review, quality assurance, and audit processes in a published AI policy.
-
marking_policy: The About page contains no mention of a policy for marking or labelling AI-assisted content.
Fix: Publish a clear policy statement on the About page (or linked from it) describing how AI-assisted content is identified and labelled.
-
consistent: Without any marking policy visible, there is no evidence AI content marking is applied consistently across the site.
Fix: Adopt and document a consistent AI-content labelling convention and apply it visibly wherever AI-assisted content appears.
-
oversight_exists: The page does not document any human oversight arrangements for AI outputs.
Fix: Add a section describing how humans oversee and validate any AI-generated outputs used by the organisation.
-
review_process: No review or approval process for AI-generated content is described on the page.
Fix: Publish the steps of the review/approval workflow (e.g., drafting, editorial check, sign-off) applied to AI outputs.
-
accountability: The page does not name any role, board or individual accountable for AI-generated content.
Fix: Identify a named role or governance board (such as one of the listed boards) as accountable owner for AI content and state this publicly.
Interoperability
- No RSS/Atom feeds discovered.
Privacy
-
necessity: The notice describes specific data uses but does not explicitly state a principle that data collection is limited to what is necessary.
Fix: Add an explicit statement that NRS only collects personal data that is necessary for the specified purposes, referencing the data minimisation principle.
-
equal_choices: The page does not display a visible consent banner with accept and reject options for evaluation of prominence.
Fix: Implement a cookie consent banner with equally prominent 'Accept' and 'Reject' buttons at the same visual weight and styling.
-
partner_sharing_mentioned: The banner only mentions collecting anonymous data to improve browsing experience and does not disclose any data sharing with third-party partners.
Fix: Update the cookie banner to explicitly disclose whether any data is shared with third-party partners and link to a list of those partners.
-
partner_count_specific: No numeric count of partners is stated because partner sharing is not disclosed at all in the banner copy.
Fix: If third-party partners receive data, state the exact number of partners in the banner (e.g., 'We share data with X partners').
Provenance
- No author or date metadata found on the page.
Security
- security.txt not published.
Transparency
-
named_person: No named individual or specific team is identified; enquiries are routed generically to an unspecified 'best placed team or person'.
Fix: List the specific teams (e.g., Certificate Services Team, FOI Team) or named contacts responsible for each enquiry category.
-
role_clear: Because no person or team is named, their role or authority for handling enquiries is not stated on the page.
Fix: Alongside each contact route, state the role or remit of the team handling it (e.g., 'FOI Officer – responsible for statutory information requests').
-
detail: The About page itself provides no amounts, percentages, or funding categories—only a link to annual reports.
Fix: Include a summary of funding figures or categories directly on the About page, or a brief excerpt with a link to the detailed annual accounts.
-
complete: The page does not enumerate all funding streams (e.g., grant-in-aid, fees from registration services, or other income sources).
Fix: Add a concise breakdown listing all major income streams (grant-in-aid, service fees, etc.) on the About page or a linked funding disclosure page.
-
algorithm_explained: The About page does not mention any algorithms or explain their purpose.
Fix: Add a section describing any algorithms or automated decision systems used by NRS and their purpose.
-
impact_clear: There is no description of how algorithmic decisions affect users on this page.
Fix: Include clear statements about how any algorithmic decisions impact users and their services.
-
annual_statement: The About page references a 2024-2029 strategy and annual reports but shows no evidence of a regular/periodic review of data practices on this page.
Fix: Add a note or link on the About page indicating when the privacy/data practices statement was last reviewed and the review cadence.
-
dated: The Privacy link is listed in the footer but the page itself provides no date or version for the data practices statement.
Fix: Display a 'last updated' date or version number alongside the Privacy link or on the privacy statement itself.
Level 3 — Advanced
Accessibility
-
remediation_timeline: The statement describes what NRS is 'working towards' and doing to improve but gives no dates or target deadlines for fixing the identified issues.
Fix: Add specific target dates or timeframes for resolving each listed non-compliance (e.g., 'we aim to fix the status message issue by Q4 2025').
-
feedback_channel: The statement invites users to 'contact us with details' and references EHRC/EASS enforcement, but includes no commitment to a response timeframe.
Fix: State an explicit response commitment for feedback, such as 'we will respond to accessibility reports within 5 working days.'
Accountability
-
policy_exists: The About page does not publish or link to any moderation policy for user-contributed content.
Fix: Publish a dedicated moderation policy page and link to it from the About or Information and processes section.
-
criteria_clear: No moderation criteria (e.g., what content is allowed or removed) are stated anywhere on the page.
Fix: Document clear moderation criteria specifying acceptable content, prohibited behaviour, and grounds for removal.
-
enforcement: The page does not describe any enforcement process for moderation decisions, appeals, or actions taken.
Fix: Add an enforcement section explaining how moderation decisions are made, who makes them, and how users can appeal.
Interoperability
- Not found at: /status
Security
-
plan_exists: The About page lists procurement, complaints, and information-request processes but contains no published incident response plan or security incident policy.
Fix: Publish a dedicated incident response plan or policy and link to it from the About or Privacy sections.
-
notification_commitment: There is no statement committing to public notification of significant security or data incidents anywhere on the page.
Fix: Add an explicit commitment to notify the public and affected individuals when a significant incident occurs.
-
timeframe: The page states no timeframe for disclosing incidents to affected users.
Fix: Specify a concrete disclosure timeframe (e.g., notification within 72 hours of confirming an incident) within the incident response policy.
Skipped: Target page not found in captured content
Transparency
-
criteria_published: No specific criteria for algorithmic decisions are published on this page.
Fix: Publish the specific decision criteria used by any algorithms in a dedicated transparency section.
-
weighting: The page does not explain weighting or priority of any algorithmic criteria.
Fix: Document and publish the weighting or relative priority given to each decision criterion.
-
auditable: The page provides no technical or procedural detail sufficient for external audit of algorithms.
Fix: Provide an algorithmic transparency record with enough detail (inputs, logic, governance) to enable external review.
-
open_source: The page contains no links to source code repositories or any mention of open-source availability of the site's code.
Fix: Add a link from the about or footer area to a public code repository (e.g., GitHub) where the site's source code or relevant components are published.
-
tech_docs: No technical documentation for the site or its data systems is linked or referenced on the about page.
Fix: Publish and link to technical documentation (e.g., API docs, data schemas, or developer notes) from the about page or a dedicated developer section.
Responsibility to the Future
-
disclosure_exists: The About us page describes purpose, governance, and processes but contains no published environmental impact or sustainability disclosure.
Fix: Publish an environmental or sustainability statement outlining the organisation's environmental impact and commitments, linked from the About us section.
-
specific_metrics: No specific figures for carbon, energy use, or emissions appear anywhere on the page.
Fix: Include quantified environmental metrics such as annual carbon emissions or energy consumption in a dedicated sustainability report.
-
hosting_disclosure: The page provides no information about the carbon or energy profile of the website's hosting infrastructure.
Fix: Disclose the hosting provider's energy sourcing or carbon footprint, ideally noting use of renewable-powered or green hosting.
-
plan_exists: The About page describes purpose, governance, strategy, and boards but contains no published plan for organisational failure or exit.
Fix: Publish a succession or continuity plan describing what happens to the organisation's functions if it ceases to operate or is dissolved.
-
data_and_content_fate: The page addresses information requests and records but does not state what would happen to user data and published content in the event of organisational failure or exit.
Fix: Add explicit provisions detailing how user data and published content would be preserved, transferred, or archived if the organisation exits.
-
custodians_or_mirrors: The page references the National Records of Scotland's archive role but does not identify any designated custodians, mirrors, or archive partners to take over content should the organisation fail.
Fix: Name specific custodians, mirror sites, or archive partners responsible for maintaining the data and content if the organisation ceases operations.
-
policy_exists: The About page contains only general departmental information and links (procurement, complaints, job vacancies) with no published worker wellbeing or working conditions policy.
Fix: Publish a dedicated worker wellbeing or working conditions policy and link to it from the About us page.
-
specific_commitments: The page includes no specific commitments regarding pay, hours, mental health, or benefits for workers.
Fix: Add concrete commitments covering fair pay, working hours, mental health support, and staff benefits to the wellbeing policy.
-
accountability: While the page references boards and groups, it does not identify any accountability or oversight specifically for worker conditions.
Fix: Name the board, committee, or role responsible for overseeing worker wellbeing and describe how it is monitored.