NHS

https://www.nhs.uk · 57/92 checks passed · government

Compliance report (framework 0.8)

Gate passed (every Core check must pass) · not counted towards the gate: paused 35, draft 48, ready for review 54.

Site level: 0 (no scored checks yet).

By level

LevelResult
Level 1 — Basic 31/37 (6 failed)
Level 2 — Enhanced 11/27 (16 failed)
Level 3 — Advanced 0/10 (9 failed)

By category

CategoryResult
Accessibility 12/13
Accountability 1/5
AI & Automation 3/8
Interoperability 1/3
Privacy 14/16
Provenance 1/2
Security 7/11
Transparency 3/13
Responsibility to the Future 0/3

Level 1 — Basic

Accessibility

AI & Automation

  • policy_exists: The About page contains no AI use policy or statement, only links to general NHS information like NHS numbers and Friends and Family Test.
    Fix: Publish a clear AI use policy or statement on the About section outlining how the NHS website uses AI.
  • scope_clear: Without any AI policy present, the page does not explain what AI is used for.
    Fix: Add a section describing the specific purposes and contexts in which AI is used on NHS digital services.

Privacy

Security

Transparency

  • purpose_clear: The page lists links to sub-topics but does not clearly state what the NHS website or organisation does.
    Fix: Add an introductory paragraph explaining what the NHS is, what the website offers, and who it serves.
  • disclosure_exists: The page contains no funding or sponsorship disclosure; it only lists NHS service links and cookie info.
    Fix: Add a funding disclosure section on the About page stating that the NHS is publicly funded and identifying key funding sources.
  • transparent: No funding sources are identified anywhere on the visible page content.
    Fix: Clearly name the funding bodies (e.g., UK government via Department of Health and Social Care, taxpayer funding) on the About page.

Level 2 — Enhanced

Accessibility

Accountability

  • named_person: The page does not identify any named person or specific role responsible for the NHS website; it only offers a generic 'report an issue' service.
    Fix: Add the name or job title of the team lead or editorial owner (e.g. 'NHS website Editorial Manager') responsible for the site.
  • response_timeframe: The page does not mention any timeframe for when users can expect a response after submitting an issue.
    Fix: Add a clear statement indicating how long users should expect to wait for a response (e.g., 'We aim to respond within 10 working days').
  • specific: Since no timeframe is given at all, there is no specific duration expressed in days or weeks.
    Fix: Publish a specific numeric response timeframe (such as '5 working days') rather than vague language.
  • appeals_exists: The page only offers a way to report website issues and does not document any appeals process for decisions.
    Fix: Add a clearly labeled appeals process describing how users can formally challenge decisions, including steps, timelines, and contact points.
  • independent: No mention is made of an independent reviewer or escalation path for appeals on this page.
    Fix: Document an independent or escalated review route (e.g., an ombudsman or separate review team) that handles appeals beyond the initial responder.

AI & Automation

  • detailed_scope: The page provides no AI policy and therefore no detailed scope of AI use.
    Fix: Include a detailed scope section in the AI policy that lists each AI system, its purpose, and where it is deployed.
  • limitations: No AI limitations are discussed anywhere in the visible content of this page.
    Fix: Acknowledge known limitations of AI systems (e.g., accuracy, bias, clinical boundaries) in a dedicated AI policy section.
  • safeguards: The page does not describe any safeguards or quality controls for AI systems.
    Fix: Document safeguards such as human oversight, clinical validation, and monitoring processes for any AI used in NHS services.
  • marking_policy: The NHS About page shows no policy for marking or labelling AI-assisted content.
    Fix: Publish a clear policy stating how AI-assisted or AI-generated content is identified and labelled on the NHS website.
  • consistent: Without a marking policy visible on the page, there is no evidence that AI content marking is applied consistently.
    Fix: Adopt a standard AI-content label and apply it consistently across all pages, documenting the approach in the site's policies section.
  • oversight_exists: The page contains no documentation describing human oversight of AI outputs.
    Fix: Add a statement to the About or Policies section describing how humans oversee any AI systems used to produce NHS website content.
  • review_process: No review or approval process for AI-generated content is described on the page.
    Fix: Document the editorial review and approval workflow for AI-assisted content, including who checks it before publication.
  • accountability: The page does not identify any person or team accountable for AI-generated content.
    Fix: Name the role, team, or governance body responsible for AI-generated content on the NHS website in the policies or About pages.

Interoperability

Privacy

  • necessity: The policy does not contain an explicit statement that data collection is limited to what is necessary, though it implies purpose-based collection.
    Fix: Add an explicit data minimisation statement declaring that the NHS only collects personal data that is strictly necessary for the stated purposes.
  • partner_sharing_mentioned: The banner only mentions analytics cookies for improving NHS services and does not disclose data sharing with third-party partners.
    Fix: Add explicit language to the banner disclosing whether analytics data is shared with third-party partners and link to a list of those partners.
  • partner_count_specific: No numeric count of partners is stated anywhere in the banner copy.
    Fix: Include a specific partner count (e.g., 'We share data with X partners') in the banner with a link to the full list.

Provenance

  • authorship_clear: The About page lists topics (NHS number, FFT, etc.) but does not identify who creates or curates the content.
    Fix: Add a clear statement naming the NHS team or editorial body responsible for creating and curating content on the site.
  • credentials: No author credentials or organisational background are provided on this About page.
    Fix: Include a section describing the NHS website team's editorial standards, clinical review process, and organisational background.

Security

Transparency

  • named_person: No named individual or specific team (e.g. 'NHS Digital Content Team') is identified as handling enquiries on this contact page.
    Fix: State the team handling enquiries by name, such as 'NHS website content team', alongside the reporting form.
  • role_clear: Because no person or team is named, their role or authority over the website is not stated either.
    Fix: Include a short description of the responsible team's remit and authority, e.g. 'responsible for editorial content and technical operation of nhs.uk'.
  • substantive: The page contains only link summaries to other pages and no substantive statement of purpose.
    Fix: Add a detailed description of the NHS website's purpose, scope, and value to users beyond a list of sub-topic links.
  • mission_clear: No mission statement or editorial approach is articulated on the About page.
    Fix: Publish a clear mission statement and explain the editorial approach used for NHS website content.
  • detail: There is no description of funding amounts, percentages, or categories on the page.
    Fix: Include meaningful detail such as annual budget figures, percentage breakdowns, or categories of funding (e.g., general taxation, National Insurance).
  • complete: No funding streams are disclosed at all, so coverage of major streams cannot be complete.
    Fix: Provide a comprehensive breakdown covering all major funding streams (government allocation, National Insurance contributions, patient charges, etc.) with links to detailed financial reports.
  • governance_exists: The page lists topics like NHS number and FFT but does not describe any governance or editorial structure for the site or organisation.
    Fix: Add a section describing the editorial and governance structure of the NHS website, including oversight bodies and decision-making processes.
  • roles_clear: No key roles or responsibilities (e.g., editor, content owner, accountable officer) are identified on this page.
    Fix: Publish a list of key roles and responsibilities for managing the NHS website, including named teams or positions accountable for content and policy.
  • algorithm_explained: The page is a general 'About the NHS' index and does not mention or explain any algorithms used by NHS services.
    Fix: Add a dedicated section or linked page describing any algorithms used (e.g., in triage, record sharing, or service recommendations) and their purpose.
  • impact_clear: There is no description of how algorithmic decisions might affect users of NHS services on this page.
    Fix: Include plain-language explanations of how algorithmic outputs influence user care, choices, or data handling, with examples.
  • annual_statement: The page shows no evidence of a regular or periodic review of data practices, only linking generically to 'Our policies' and 'Cookies'.
    Fix: Publish a dated annual review statement of data practices and link to it from the About and policies sections.
  • dated: No date or version information is displayed for any data practices statement on this page.
    Fix: Add a 'Last reviewed' or version date to the privacy/data practices statement visible from this page.

Level 3 — Advanced

Accessibility

  • remediation_timeline: The statement commits to fixing issues but relies on vague conditions like fixing PDFs 'wherever possible' and third-party fixes with no date provided, giving no concrete timeline.
    Fix: Add target dates or expected completion periods for remediating the listed non-compliant items so users know when fixes are anticipated.

Accountability

  • policy_exists: The page lists 'Our policies' as a footer link but does not publish or reference any moderation policy for user-generated content.
    Fix: Publish a clearly labelled moderation policy (e.g., for FFT feedback or comments) and link it from the About and policies sections.
  • criteria_clear: No moderation criteria (what content is allowed, removed, or edited) are stated anywhere on the visible page content.
    Fix: Add a section listing specific moderation criteria such as prohibited content types, language standards, and grounds for removal.
  • enforcement: The page does not describe how moderation decisions are made, who enforces them, or how users can appeal.
    Fix: Document the enforcement workflow, including reviewer roles, response timeframes, and an appeals/contact process for moderation decisions.

Interoperability

Security

  • plan_exists: The page only lists general navigation and policy links with no visible published incident response plan or policy.
    Fix: Publish a dedicated incident response plan or policy page and link to it from this page.
  • notification_commitment: There is no statement committing to public notification of significant security or data incidents anywhere on the page.
    Fix: Add an explicit commitment to publicly notify affected users of significant incidents within the incident response policy.
  • timeframe: The page provides no timeframe for disclosing incidents to affected users.
    Fix: Specify a concrete disclosure timeframe (for example, notification within 72 hours of discovery) in the incident response policy.

Transparency

  • criteria_published: No specific criteria used in any algorithmic decision-making are published on this page.
    Fix: Publish the input variables and decision criteria used by any NHS algorithms, either inline or via a prominent link from the About section.
  • weighting: The page contains no information about how criteria are weighted or prioritised in any algorithmic process.
    Fix: Document the relative weighting or priority logic of criteria (e.g., in a model card or transparency note) and link to it from this page.
  • auditable: The page provides no technical or methodological detail that would allow external audit or review of any algorithm.
    Fix: Provide or link to an algorithmic transparency record (such as the UK Algorithmic Transparency Recording Standard) with sufficient detail for independent auditing.
  • open_source: No links to source code or open-source repositories are present on the About page.
    Fix: Add a link to the NHS website's public code repositories (e.g. NHS Digital's GitHub) from the About page.
  • tech_docs: No technical documentation is linked from the About page.
    Fix: Link to technical documentation, service manuals, or developer resources from the About page.

Responsibility to the Future

  • disclosure_exists: The page contains only navigation and links to NHS informational services with no published environmental impact or sustainability disclosure.
    Fix: Publish a dedicated environmental or sustainability disclosure page and link it from the About the NHS and footer sections.
  • specific_metrics: The page provides no specific figures on carbon, energy use, or emissions anywhere in its content.
    Fix: Include quantified metrics such as annual carbon emissions and energy consumption in a sustainability report accessible from this page.
  • hosting_disclosure: There is no mention of the carbon or energy profile of the website's hosting infrastructure.
    Fix: Add a statement disclosing the hosting provider's energy sources and carbon footprint, ideally referencing green hosting credentials.
  • plan_exists: The page only lists general NHS informational links (NHS number, FFT, choices, quality accounts) with no published plan describing what happens if the organisation fails or exits.
    Fix: Publish a succession/continuity plan describing what happens to the website and services if the organisation ceases to operate, and link it from this About page.
  • data_and_content_fate: Aside from an opt-out link for health records, the page does not address the fate of user data or published content in the event of organisational failure or exit.
    Fix: Add a section explaining how user data and published content would be preserved, migrated, or deleted if the organisation shuts down.
  • custodians_or_mirrors: The page names no custodians, mirrors, or archive partners who would take over content or data if the organisation exits.
    Fix: Identify and publish the custodians, mirror sites, or archive partners (e.g. UK Web Archive) responsible for preserving content and data.
  • policy_exists: The page is an NHS 'About' index linking to patient-facing topics like NHS numbers and health record sharing, with no published policy on worker wellbeing or working conditions.
    Fix: Publish a worker wellbeing or working conditions policy and link to it from this page or the 'Our policies' section.
  • specific_commitments: The content contains no specific commitments on pay, hours, mental health, or benefits for workers.
    Fix: Add explicit commitments covering staff pay, working hours, mental health support, and benefits within a dedicated wellbeing policy.
  • accountability: No individual, role, or body is identified as accountable for or overseeing worker conditions on this page.
    Fix: Name a responsible role or governance body and describe their oversight of worker wellbeing on the relevant policy page.