National Trust

https://www.nationaltrust.org.uk · 33/92 checks passed · not_for_profit

Compliance report (framework 0.8)

Gate passed (every Core check must pass) · not counted towards the gate: paused 35, draft 48, ready for review 54.

Site level: 0 (no scored checks yet).

By level

LevelResult
Level 1 — Basic 24/37 (13 failed)
Level 2 — Enhanced 3/27 (24 failed)
Level 3 — Advanced 1/10 (8 failed)

By category

CategoryResult
Accessibility 10/13
Accountability 0/5
AI & Automation 3/8
Interoperability 1/3
Privacy 8/16
Provenance 0/2
Security 4/11
Transparency 2/13
Responsibility to the Future 0/3

Level 1 — Basic

Accessibility

AI & Automation

  • human_or_disclosed: The page only displays a browser verification interstitial with no substantive content, so authorship (human or AI) cannot be determined or disclosed.
    Fix: Ensure the actual page content loads for reviewers/crawlers and include a clear statement of authorship or AI-use disclosure on the about page.
  • policy_exists: The page only displays a browser verification message with no AI policy content visible.
    Fix: Publish an accessible AI use policy at /ai-policy that loads without requiring browser verification gating or ensure the policy content is reachable to users and crawlers.
  • scope_clear: No AI usage scope is described because the page content is blocked behind a verification screen.
    Fix: Provide clear text on the page explaining what AI tools are used for across the organisation's services.

Privacy

Security

  • strict-transport-security: header not set on the response.

Transparency

  • contact_exists: The page only shows a browser verification message with an incident ID, so no contact page content is visible.
    Fix: Ensure the /contact page renders actual contact information rather than being blocked by a browser verification interstitial.
  • findable: No contact details are rendered on the page; only a verification screen is displayed.
    Fix: Allow the contact page to load for all legitimate visitors and surface phone, email, and address details prominently.
  • actionable: There is no phone number, email, form, or address provided—only a verification message.
    Fix: Provide actionable contact methods (such as a phone number, email address, or contact form) directly on the contact page.
  • about_exists: The /about URL returns only a browser verification screen, not an actual about page.
    Fix: Resolve the bot-check blocking issue so the about page content is reachable to users and reviewers.
  • purpose_clear: No statement of purpose is present because only the verification message is shown.
    Fix: Display a clear statement of the National Trust's purpose at the top of the about page once accessible.
  • disclosure_exists: The page only shows a browser verification screen with no funding or sponsorship disclosure content visible.
    Fix: Ensure the /funding page loads actual content with a clear funding/sponsorship disclosure section accessible to reviewers and users.
  • transparent: No funding sources are identified because only a browser verification message is present.
    Fix: Publish a transparent list of funding sources (grants, donors, government support, commercial income) on the funding page.

Level 2 — Enhanced

Accessibility

Accountability

  • named_person: The page only shows a browser verification message with no named person or role identified as responsible.
    Fix: Once past the verification screen, ensure the contact page lists a named individual, team, or role responsible for handling enquiries.
  • contactable: No contact details (email, phone, form, or address) are visible; the page only displays a browser verification notice.
    Fix: Provide accessible contact information such as an email address, phone number, or contact form directly on the page.
  • response_timeframe: The page only shows a browser verification message with no content about response timeframes.
    Fix: Publish explicit acknowledgement and resolution timeframes for complaints once the page loads its actual content.
  • specific: No timeframes are visible at all, so specificity cannot be demonstrated.
    Fix: State specific day-based targets (e.g. acknowledge within 3 working days, respond within 20) on the complaints page.
  • process_exists: The page displays only a browser verification screen with an incident ID and no complaints process content.
    Fix: Ensure the /complaints page is accessible to users and publish a documented complaints or feedback process.
  • steps_clear: No complaint steps are visible because the page content is blocked by a verification screen.
    Fix: Provide clearly numbered steps (how to submit, what happens next, escalation routes) on the accessible complaints page.
  • appeals_exists: The page only shows a browser verification challenge with an incident ID and no documented appeals process content is visible.
    Fix: Publish a dedicated appeals page describing the steps, timelines, and contact methods for submitting an appeal.
  • independent: No information about independent review or escalation pathways is present on the page, which displays only a browser verification notice.
    Fix: Document an independent reviewer or external escalation route (e.g., ombudsman or independent panel) within the appeals process.

AI & Automation

  • detailed_scope: The page shows only a verification notice and contains no detailed scope of AI use.
    Fix: Add a detailed section listing specific AI applications, use cases, and business areas where AI is deployed.
  • limitations: No acknowledgement of AI limitations is present on the accessible page content.
    Fix: Include a section that openly describes known limitations, risks, and failure modes of the AI systems used.
  • safeguards: No safeguards or quality controls are described because the policy content is not visible.
    Fix: Document the human oversight, review processes, and quality assurance measures applied to AI outputs on the policy page.
  • marking_policy: The page only shows a browser verification message with no AI content marking policy visible.
    Fix: Publish the AI policy content on the page describing how AI-assisted content is labeled and disclosed.
  • consistent: No AI content marking is visible because the page content is blocked by a browser verification screen.
    Fix: Ensure the AI policy page is accessible and demonstrates consistent labeling conventions across AI-assisted content.
  • oversight_exists: Human oversight of AI outputs is not documented on the accessible page content.
    Fix: Add a section explicitly describing how humans oversee and validate AI outputs before publication.
  • review_process: No review or approval process is described on the visible page.
    Fix: Document the step-by-step review/approval workflow for AI-generated content on the policy page.
  • accountability: No accountable party or role is named for AI-generated content on the visible page.
    Fix: Name a specific role, team, or contact accountable for AI-generated content within the policy.

Interoperability

  • open_formats: The page only shows a browser verification challenge with no actual HTML content delivered.
    Fix: Ensure the about page content is served as accessible HTML rather than being blocked behind an unresolved bot-check interstitial.
  • no_proprietary_lock: Access requires passing a proprietary browser verification script before any content is shown.
    Fix: Provide a fallback or progressive enhancement so content is reachable without executing proprietary verification scripts.

Privacy

  • exists: The page only shows a browser verification/challenge screen with no privacy policy content visible.
    Fix: Ensure the /privacy URL serves the actual privacy policy content to reviewers and bots, or allow-list compliance crawlers past the bot challenge.
  • plain_language: No policy text is accessible to evaluate language clarity due to the verification interstitial.
    Fix: Publish the privacy policy in plain English and make it reachable without a browser challenge blocking access.
  • comprehensive: No content about data collection or purposes is present on the page.
    Fix: Provide a full policy covering categories of data collected, purposes, legal bases, sharing, and rights on this URL.
  • plain_language: No data-practice descriptions are visible because the page is stuck on a verification screen.
    Fix: Make the privacy page content render for all visitors and write data practices in jargon-free language.
  • understandable: A non-expert cannot understand data practices when no text is shown.
    Fix: Include clear, user-friendly explanations of what is collected and why, accessible without passing a bot challenge.
  • necessity: The page contains no statement about limiting data collection to what is necessary.
    Fix: Add an explicit data minimisation statement confirming only necessary data is collected.
  • proportionate: No information is available to assess proportionality of data collection.
    Fix: Describe each data collection purpose and justify that the data gathered is proportionate to the service.
  • retention_stated: No retention information appears on the verification page.
    Fix: Publish a retention schedule within the privacy policy explaining how long each data type is kept.
  • specific: With no retention content visible, specific periods cannot be confirmed.
    Fix: State concrete retention durations (e.g., '24 months after last activity') rather than vague terms like 'as long as necessary'.
  • no_dark_patterns: The page displays only a browser verification challenge with no visible consent interface, so dark-pattern-free consent cannot be confirmed.
    Fix: Ensure the privacy page is accessible to reviewers and presents consent choices in neutral, non-manipulative language.
  • equal_choices: No accept or reject options are visible on the page, as it only shows a browser verification screen.
    Fix: Provide accessible accept and reject buttons of equal visual prominence on the privacy/consent interface.
  • no_forced_consent: The page is blocked by a verification challenge and shows no consent interface, preventing confirmation that consent is not bundled or forced.
    Fix: Make the privacy page reachable and ensure consent is granular and not a precondition for accessing the site.
  • ads_labelled: The page only shows a browser verification challenge, so no advertising or sponsored content labelling is visible.
    Fix: Ensure the actual content loads for reviewers and clearly label any advertising or sponsored content with visible tags such as 'Ad' or 'Sponsored'.
  • disclosure: The page displays a verification interstitial with no disclosure of any advertiser relationships.
    Fix: Publish an accessible disclosure statement describing any commercial or advertiser relationships on the site.
  • partner_sharing_mentioned: The banner only mentions 'embedded third party tools (such as video and audio players)' but does not disclose data sharing with third-party partners for marketing or analytics purposes.
    Fix: Update the banner copy to explicitly disclose that cookies may share data with third-party advertising, analytics, and marketing partners.
  • partner_count_specific: No specific numeric count of third-party partners is stated anywhere in the banner copy.
    Fix: Add a specific partner count (e.g., 'We share data with X partners') in the banner or link to a vendor list that states the exact number.

Provenance

  • authorship_clear: The verification interstitial contains no information about who creates or curates the content.
    Fix: Once the page loads, clearly identify the National Trust team or department responsible for the about content.
  • credentials: No author credentials or organisational background are visible on the verification page.
    Fix: Include organisational background and credentials of contributors on the about page itself.

Security

Transparency

  • named_person: The page content does not identify any named individual or team responsible for enquiries, only a browser verification message.
    Fix: Publish the name of the responsible individual or team (e.g., Customer Service Team) on the contact page.
  • role_clear: No role or authority is stated because the page displays only a verification challenge.
    Fix: Clearly describe the role, remit, or authority of the contact person or team (e.g., scope of enquiries they handle).
  • substantive: There is no substantive content visible—only a verification interstitial.
    Fix: Publish a detailed purpose statement on the about page beyond a tagline, covering scope and activities.
  • mission_clear: No mission or editorial approach is articulated on the served page.
    Fix: Add a clearly written mission statement describing the National Trust's conservation and editorial approach.
  • detail: No details such as amounts, percentages, or categories of funding appear on the page.
    Fix: Include specific figures or percentage breakdowns by funding category (e.g., memberships, legacies, grants, commercial).
  • complete: Without any disclosure content loaded, coverage of major funding streams cannot be demonstrated.
    Fix: Provide a comprehensive disclosure covering all major funding streams, ideally linking to the latest annual report.
  • governance_exists: The page only displays a browser verification challenge with no governance or editorial structure content visible.
    Fix: Ensure the /about page renders actual content describing the organisation's governance structure rather than a bot-check interstitial.
  • roles_clear: No roles or responsibilities are identified because the page content is blocked by a browser verification screen.
    Fix: Publish accessible content identifying key leadership roles and responsibilities, and ensure crawlers/reviewers can reach it without being blocked.
  • algorithm_explained: The page only displays a browser verification challenge with no content explaining any algorithms in use.
    Fix: Ensure the actual About page content loads and include a section describing any algorithms used and their purposes.
  • impact_clear: No information about algorithmic decisions or their impact on users is visible on the page.
    Fix: Publish a description of how algorithmic decisions affect users on the accessible About page.
  • annual_statement: The content shown is only a browser-verification message with no evidence of a periodic data practices review.
    Fix: Publish a privacy/data practices page that references an annual or periodic review cycle and ensure it is reachable by crawlers.
  • dated: No data practices statement or version/date information is present on the verification page.
    Fix: Include a 'Last updated' date or version number at the top of the data practices/privacy statement.

Level 3 — Advanced

Accessibility

  • statement_exists: The page only displays a browser verification interstitial ('Verifying your browser before proceeding...') with no accessibility statement content.
    Fix: Ensure the actual /about content loads for reviewers and provide a dedicated, linkable accessibility statement page.
  • known_issues: No accessibility content is present because the page is blocked by a browser-verification screen, so no known issues are acknowledged.
    Fix: Publish an accessibility statement that lists known accessibility limitations and non-conformances of the site.
  • remediation_timeline: The interstitial page contains no timeline or commitment to fix any accessibility issues.
    Fix: Include target dates or a commitment schedule for remediating identified accessibility issues in the statement.
  • feedback_channel: No feedback mechanism or response commitment is shown on the verification-only page.
    Fix: Add a feedback channel (email or form) for accessibility problems along with a stated response timeframe.

Accountability

  • policy_exists: The page only displays a browser verification message and incident ID, with no moderation policies published.
    Fix: Publish a clear moderation policy document accessible at this URL or link to one from the moderation page.
  • criteria_clear: No moderation criteria are stated on the page; it only shows a browser verification interstitial.
    Fix: Add a section that clearly lists the criteria used to moderate content, such as prohibited behaviors and content types.
  • enforcement: There is no explanation of the enforcement process, only a verification notice and incident ID.
    Fix: Document the enforcement workflow, including actions taken, appeal rights, and response timelines, directly on the moderation page.

Interoperability

Security

  • plan_exists: The page only shows a browser verification/security interstitial with an incident ID and contains no published incident response plan or policy.
    Fix: Publish an accessible incident response plan or security policy page outlining how incidents are detected, managed, and resolved.
  • notification_commitment: The interstitial content includes no commitment to publicly notify users of significant security incidents.
    Fix: Add a clear statement committing to public notification of affected users when significant incidents occur.
  • timeframe: No disclosure timeframe is mentioned anywhere on the browser-verification page.
    Fix: Specify a concrete timeframe (e.g., within 72 hours of discovery) for disclosing incidents to affected users.

Transparency

  • criteria_published: The page shows only a verification screen and does not publish any decision criteria.
    Fix: Make the About page accessible and list the specific criteria used in any algorithmic decisions.
  • weighting: No weighting or prioritisation of criteria is provided on the visible content.
    Fix: Add an explanation of how criteria are weighted or prioritised in algorithmic decisions.
  • auditable: The verification placeholder provides no detail that would support external audit or review.
    Fix: Publish sufficiently detailed algorithm documentation (inputs, logic, outcomes) to enable independent review.
  • open_source: No links to source code repositories appear on the verification page.
    Fix: Link to any publicly available source code repositories from the about or developer section of the site.
  • tech_docs: No technical documentation is referenced or linked from the displayed content.
    Fix: Publish and link to technical documentation (e.g., API docs, platform info) from the about page.

Responsibility to the Future

  • disclosure_exists: The page only shows a browser verification/security interstitial ('Verifying your browser before proceeding...') with no accessible content or sustainability disclosure.
    Fix: Ensure the actual /about page content loads for reviewers and publish an environmental impact or sustainability disclosure on an accessible page.
  • specific_metrics: No specific figures on carbon, energy use, or emissions are present because only a browser verification message is displayed.
    Fix: Include concrete quantified metrics such as annual carbon emissions, energy consumption, and reduction targets in the disclosure.
  • hosting_disclosure: There is no information about the carbon or energy profile of hosting infrastructure, as the page content is inaccessible behind a verification screen.
    Fix: Disclose your hosting provider's carbon/energy profile, such as use of renewable-powered or green-certified data centers, on the accessible site content.
  • plan_exists: The governance page describes organisational structure, constitution, and the Governance Handbook, but contains no published plan for what happens if the organisation fails or exits.
    Fix: Publish a continuity or wind-down plan that describes what would happen to the organisation's activities and assets in the event of failure or dissolution.
  • data_and_content_fate: The page makes no mention of what would happen to user data or published content should the Trust cease operating.
    Fix: Add a section specifying how user data and published content would be preserved, transferred, or deleted in a wind-down scenario.
  • custodians_or_mirrors: No custodians, mirrors, or archive partners are identified anywhere on the governance page.
    Fix: Name specific custodians, mirror sites, or archive partners (e.g., a national archive) responsible for safeguarding content and data if the organisation exits.
  • policy_exists: The page is an 'About us' overview that references a Modern slavery statement and a Gender and Diversity Pay Gap Report but contains no published policy dedicated to worker wellbeing or working conditions.
    Fix: Publish a dedicated worker wellbeing/working conditions policy and link to it from this page or the careers/jobs section.
  • specific_commitments: The content mentions inclusion, diversity and safeguarding generally but states no specific commitments on pay, hours, mental health, or benefits for workers.
    Fix: Add concrete, measurable commitments on fair pay, working hours, mental health support, and employee benefits.
  • accountability: While the page lists governance bodies like the Executive Team and Board of Trustees, none are identified as accountable specifically for worker conditions or wellbeing.
    Fix: Name a specific role or body (e.g., an HR/People Director or committee) responsible for overseeing worker wellbeing and working conditions.