Natural History Museum
https://www.nhm.ac.uk · 54/92 checks passed · archives
Compliance report (framework 0.8)
Gate passed (every Core check must pass) · not counted towards the gate: paused 35, draft 48, ready for review 54.
Site level: 0 (no scored checks yet).
By level
| Level | Result |
|---|---|
| Level 1 — Basic | 29/37 (8 failed) |
| Level 2 — Enhanced | 12/27 (15 failed) |
| Level 3 — Advanced | 0/10 (9 failed) |
By category
| Category | Result |
|---|---|
| Accessibility | 11/13 |
| Accountability | 2/5 |
| AI & Automation | 3/8 |
| Interoperability | 1/3 |
| Privacy | 11/16 |
| Provenance | 1/2 |
| Security | 5/11 |
| Transparency | 7/13 |
| Responsibility to the Future | 0/3 |
Level 1 — Basic
Accessibility
AI & Automation
-
policy_exists: The page contains no AI use policy or statement anywhere in its content or footer links.
Fix: Publish a dedicated AI use policy page and link to it from the site footer alongside the Privacy notice and Terms and conditions.
-
scope_clear: With no AI policy present, there is no explanation of what AI is used for on the site.
Fix: Within the new AI policy, clearly describe the specific use cases (e.g., search, content generation, collections analysis) where AI is employed.
- Not found at any of: /ai-policy, /ai.
Privacy
- No hidden iframes detected.
PASS
Session cookies only
PASS
No tracking pixels
Security
- Redirect chain (1 hops): https://www.nhm.ac.uk
- x-frame-options: header not set on the response.
- content-security-policy: header not set on the response.
- referrer-policy: header not set on the response.
PASS
HTTPS enforced
PASS
No mixed content
Transparency
PASS
Contact form present
Level 2 — Enhanced
Accessibility
Accountability
-
process_exists: The page provides general contact and feedback email options but no documented complaints or feedback process is described.
Fix: Add a dedicated complaints/feedback section outlining how concerns are received, handled, escalated, and resolved.
-
steps_clear: Because no complaints process is documented, no step-by-step instructions for making a complaint are provided.
Fix: Publish clear numbered steps (e.g., how to submit, what information to include, acknowledgement timeline, escalation path) for making a complaint.
-
appeals_exists: The contact page lists various enquiry channels but does not document any appeals process for challenging decisions.
Fix: Add a clearly labeled appeals section describing how users can formally challenge decisions, including steps, timelines, and contact details.
-
independent: No escalation path or independent review mechanism is mentioned anywhere on the page.
Fix: Specify an independent or higher-level escalation route (e.g., an ombudsman, trustee board, or ICO referral) for unresolved appeals.
AI & Automation
-
detailed_scope: No AI policy exists on the page, so detailed scope of AI use is absent.
Fix: Add a detailed AI policy section enumerating each AI system, its purpose, data inputs, and affected user interactions.
-
limitations: The page does not acknowledge any limitations of AI systems since no AI policy is present.
Fix: Include a 'Limitations' subsection in the AI policy noting known issues such as inaccuracy, bias, or gaps in training data.
-
safeguards: No safeguards or quality controls related to AI are described on the page.
Fix: Document safeguards such as human review, accuracy checks, bias mitigation, and escalation paths within the AI policy.
-
marking_policy: The About/Careers page contains no policy or statement about marking AI-assisted content.
Fix: Publish a clear policy stating how AI-assisted content is labeled and link to it from the About or Legal section.
-
consistent: Without any visible AI-content marking policy or labels on the page, consistency of application cannot be demonstrated.
Fix: Apply consistent AI-content labels across articles and staff profiles and document the labeling convention publicly.
-
oversight_exists: The page does not mention any human oversight framework for AI outputs.
Fix: Add a statement describing how humans review and supervise any AI-generated or AI-assisted outputs used by the Museum.
-
review_process: No review or approval workflow for AI content is described anywhere on the page.
Fix: Document the editorial review and approval steps AI content must pass through before publication.
-
accountability: No role, team, or individual is identified as accountable for AI-generated content.
Fix: Name an accountable role (e.g., Head of Digital or Editorial Lead) responsible for AI-generated content and provide contact details.
Interoperability
- No RSS/Atom feeds discovered.
Privacy
-
necessity: The visible content does not include any statement that data collection is limited to what is necessary.
Fix: Add an explicit data minimisation statement confirming the Museum only collects personal information necessary for stated purposes.
-
proportionate: There is no visible language describing proportionality between data collected and the services provided.
Fix: Include a sentence explaining that data collected is proportionate to each service (e.g., membership, ticketing, newsletters) with examples.
-
retention_stated: Although a 'How long we keep your information' section is listed, no retention details are visible in the provided content.
Fix: Publish retention details inline (or expand the section) specifying how long each category of personal data is kept.
-
specific: No specific retention periods (e.g., in months or years) are visible on the page.
Fix: State concrete retention periods per data type, such as 'newsletter subscriber data retained for 24 months after last engagement'.
-
equal_choices: The page references a 'Cookie preferences' link but does not demonstrate that accept and reject options are presented with equal prominence on the consent interface.
Fix: Ensure the cookie banner presents a 'Reject all' button with the same visual weight, size, and placement as the 'Accept all' button.
-
partner_count_specific: The banner references 'third-party platforms' generically but does not state a specific numeric count of partners.
Fix: Add a specific number of third-party partners (e.g., 'we share data with X partners') in the banner or link to a list of named partners.
Provenance
- No author or date metadata found on the page.
Security
Transparency
-
detail: The page only lists funding categories generically (e.g., 'From £5 a month', '£150 million' fundraising target) without breakdowns of amounts or percentages per funding stream.
Fix: Add a breakdown showing the proportion or amount of income from each funding stream (e.g., government grants, memberships, corporate partners, donations) or link to the annual report.
-
complete: The disclosure omits major funding streams such as government/public grants, trust and foundation grants, and commercial/trading income (shop, venue hire, consulting) that are referenced elsewhere on the site.
Fix: Expand the disclosure to cover all significant funding streams, including public funding, grants, and trading/commercial revenue, to give a complete picture of the Museum's income.
-
governance_exists: The page focuses on careers and working at the Museum but does not describe the governance or editorial structure, though a 'Governance' link exists elsewhere in the footer.
Fix: Add a summary of the Museum's governance structure (e.g., Trustees, Board) on the About page or link prominently to the Governance page from this content.
-
roles_clear: The page mentions employing 900 staff and references some individual researchers but does not identify key leadership roles or responsibilities.
Fix: Include a section outlining key roles such as Director, Trustees, and senior leadership with their responsibilities, or link directly to a leadership/roles page.
-
algorithm_explained: The page is about careers and the museum's mission and does not mention or explain any algorithms in use.
Fix: Add a section or link disclosing any algorithms used (e.g., in recruitment or visitor services) and their purpose.
-
impact_clear: There is no description of how algorithmic decisions might affect users, applicants, or visitors.
Fix: Publish a statement describing the impact of any algorithmic decision-making on users, such as job applicants or website visitors.
-
annual_statement: The page links to a privacy notice in the footer but shows no evidence of a regular or annual review of data practices.
Fix: Add a statement to the privacy notice indicating when data practices were last reviewed and the cadence of periodic reviews.
-
dated: The visible content and footer link to the privacy notice do not display a date or version indicator for the data practices statement.
Fix: Include a 'last updated' date or version number prominently on the privacy notice and reference it from the footer.
Level 3 — Advanced
Accessibility
-
known_issues: The visible page content is an About/Careers page and shows no acknowledgment of any known accessibility issues or limitations.
Fix: Add a section in the accessibility statement that lists specific non-compliant elements or known barriers users may encounter.
-
remediation_timeline: No timeline or commitment for fixing accessibility issues appears anywhere on the visible page.
Fix: Include target dates or a stated commitment for when identified accessibility issues will be remediated.
-
feedback_channel: The page provides only a generic 'Contact us' link and no accessibility-specific feedback mechanism with a response commitment.
Fix: Provide a dedicated accessibility feedback contact (email/form) along with a stated response timeframe within the accessibility statement.
Accountability
-
enforcement: While the NHM reserves the right to remove material or revoke access without notice, there is no explanation of the enforcement process, review steps, or appeals mechanism.
Fix: Add a section describing how moderation decisions are made, who reviews content, timelines, and how users can appeal a removal or access decision.
Interoperability
- Not found at: /status
Security
-
plan_exists: The page is a Careers/About page with no published incident response plan or security policy anywhere in its content or footer links.
Fix: Publish an incident response plan or security policy and link to it from the site footer alongside the privacy notice.
-
notification_commitment: There is no statement anywhere on the page committing to public notification of significant security incidents.
Fix: Add explicit language committing to notify the public and affected users when significant incidents occur.
-
timeframe: The page provides no timeframe for disclosing incidents to affected users.
Fix: Specify a concrete disclosure timeframe (e.g., notification within 72 hours of discovery) in the incident response policy.
Skipped: Target page not found in captured content
Transparency
-
criteria_published: No criteria for any algorithmic decisions are published anywhere on the page.
Fix: Publish the specific criteria used in any algorithmic decisions, for example in a dedicated transparency or governance page.
-
weighting: The page contains no information about how criteria are weighted or prioritised in any decision-making process.
Fix: Document and publish the relative weighting or priority of each criterion used by any algorithm the museum employs.
-
auditable: The page provides no technical or procedural detail that would allow external audit or review of algorithmic systems.
Fix: Provide sufficient documentation (methodology, data sources, decision logic) to enable independent audit, or link to an algorithmic transparency register entry.
-
open_source: No links to source code repositories (e.g., GitHub) are provided on the page.
Fix: Add a link in the footer or About section to any public code repositories or state the site's open-source policy.
-
tech_docs: The page does not link to technical documentation about the website or its systems, only to datasets and a website accessibility statement.
Fix: Publish and link to technical documentation covering site architecture, APIs, or data access methods from the About or footer area.
Responsibility to the Future
-
disclosure_exists: The page is a careers/about page describing the Museum's mission and jobs, with no published environmental impact or sustainability disclosure.
Fix: Publish a dedicated sustainability or environmental impact statement and link to it from the About us section.
-
specific_metrics: The page contains no specific environmental figures such as carbon emissions, energy use, or waste metrics.
Fix: Include concrete measured figures such as annual carbon emissions and energy consumption in a sustainability report.
-
hosting_disclosure: There is no mention of the carbon or energy profile of the website's hosting infrastructure anywhere on the page.
Fix: Disclose whether the site uses renewable-powered or low-carbon hosting and provide associated energy figures.
-
plan_exists: The governance page covers management structure, policies and reporting but contains no published plan for what happens if the organisation fails or exits.
Fix: Publish a continuity/exit plan describing what would happen to the Museum's operations, collections and digital services in the event of organisational failure or wind-down.
-
data_and_content_fate: The page references a privacy notice and data protection policy but does not address the fate of user data or published content if the organisation ceases to exist.
Fix: Add a section specifying how user data and published web content would be preserved, transferred, or deleted should the Museum cease operations.
-
custodians_or_mirrors: While the page names sponsors and regulators like DCMS, it identifies no custodians, mirrors, or archive partners responsible for preserving content or data on exit.
Fix: Name a designated custodian or archive partner (e.g. The National Archives or a successor body) that would take responsibility for the Museum's data and published content.
-
policy_exists: The page references 'inclusive policies' and 'the way we work' framework but does not publish an actual worker wellbeing or working conditions policy on this page.
Fix: Publish or link to a clear worker wellbeing/working conditions policy document rather than only referencing benefits and framework pages.
-
specific_commitments: The page vaguely mentions 'generous benefits' and 'inclusive policies' but provides no specific commitments on pay, hours, mental health, or benefits.
Fix: Add concrete commitments such as pay standards, working hour policies, and mental health support details directly on the careers/wellbeing page.
-
accountability: The page names no individual, team, or governance body responsible for overseeing worker conditions or wellbeing.
Fix: Identify the specific role, department, or oversight body accountable for worker wellbeing and provide contact or reporting mechanisms.