Scope
https://www.scope.org.uk · 52/92 checks passed · not_for_profit
Compliance report (framework 0.8)
Gate passed (every Core check must pass) · not counted towards the gate: paused 35, draft 48, ready for review 54.
Site level: 0 (no scored checks yet).
By level
| Level | Result |
|---|---|
| Level 1 — Basic | 24/37 (13 failed) |
| Level 2 — Enhanced | 15/27 (12 failed) |
| Level 3 — Advanced | 1/10 (8 failed) |
By category
| Category | Result |
|---|---|
| Accessibility | 7/13 |
| Accountability | 5/5 |
| AI & Automation | 3/8 |
| Interoperability | 1/3 |
| Privacy | 12/16 |
| Provenance | 1/2 |
| Security | 4/11 |
| Transparency | 7/13 |
| Responsibility to the Future | 0/3 |
Level 1 — Basic
Accessibility
- 1 WCAG 2.1 Level A violation reported by axe-core: image-alt.
- 1 WCAG 2.1 Level A violation reported by axe-core: image-alt.
- 2 images missing alt attribute: https://assets-eu-01.kc-usercontent.com/73ea709e-f9f8-0168-3842-ebd7ad1e23ac/6f0a1386-b78b-4417-a99f-fa71f8ad65cc/home%20icon.svg, https://assets-eu-01.kc-usercontent.com/73ea709e-f9f8-0168-3842-ebd7ad1e23ac/538e31c6-0ee5-49e3-8eca-a79a7fea2350/live-chat.svg.
- 2 images missing alt attribute: https://assets-eu-01.kc-usercontent.com/73ea709e-f9f8-0168-3842-ebd7ad1e23ac/6f0a1386-b78b-4417-a99f-fa71f8ad65cc/home%20icon.svg, https://assets-eu-01.kc-usercontent.com/73ea709e-f9f8-0168-3842-ebd7ad1e23ac/538e31c6-0ee5-49e3-8eca-a79a7fea2350/live-chat.svg.
- Heading hierarchy issues: h1 -> h3 (skipped h2); h1 -> h3 (skipped h2).
AI & Automation
-
policy_exists: The About page contains no mention of an AI use policy or statement.
Fix: Publish an AI use policy or statement and link to it from the About page or site footer.
-
scope_clear: There is no explanation of what AI is used for since no AI policy is present on the page.
Fix: In the AI policy, clearly describe the specific uses of AI across Scope's services and website.
- Not found at any of: /ai-policy, /ai.
Privacy
- 1 inline script matched a tracker/ad pattern; first match: 'function ga4(e,t){"undefined"!=typeof gtag&>ag("event",e,t)}function trackShar…'.
PASS
Session cookies only
PASS
No tracking pixels
Security
- Redirect chain (1 hops): https://www.scope.org.uk
- x-frame-options: header not set on the response.
- content-security-policy: header not set on the response.
- referrer-policy: header not set on the response.
PASS
HTTPS enforced
PASS
No mixed content
Transparency
-
transparent: The About page itself does not clearly identify funding sources; it only links to an annual report without summarizing funders or income streams on-page.
Fix: Add a brief 'How we are funded' section on the About page summarizing major income sources (donations, shops, grants, government contracts) with links to detailed reports.
PASS
Contact form present
Level 2 — Enhanced
Accessibility
Accountability
AI & Automation
-
detailed_scope: No AI policy is present, so the scope of AI use is not detailed.
Fix: Add an AI policy section that enumerates each area and system where AI is deployed.
-
limitations: No acknowledgement of AI system limitations appears on the page.
Fix: Include a limitations section in the AI policy explaining known risks, biases, and constraints of the AI systems used.
-
safeguards: No safeguards or quality controls for AI are described on the page.
Fix: Document the human oversight, review processes, and quality controls applied to AI outputs in the AI policy.
-
marking_policy: The About page contains no policy or statement regarding the marking or labelling of AI-assisted content.
Fix: Publish a clear policy describing how AI-assisted content is identified and labelled, and link to it from the About or editorial standards section.
-
consistent: Without any visible AI marking policy or labels on the page, consistent application cannot be demonstrated.
Fix: Apply consistent AI-content labels across all pages and reference the labelling convention in a published editorial standards document.
-
oversight_exists: The page does not document any human oversight process for AI-generated outputs.
Fix: Add a statement (e.g. in About us or Editorial policy) describing how humans review and oversee any AI-generated content used by Scope.
-
review_process: No review or approval workflow for AI outputs is described anywhere on the page.
Fix: Document the review/approval steps AI-assisted content must pass through before publication and publish this on the website.
-
accountability: No individual, role, or team is identified as accountable for AI-generated content on the page.
Fix: Name a responsible role (e.g. Head of Digital or Editorial Lead) accountable for AI content and include their remit in the governance or leadership section.
Interoperability
- No RSS/Atom feeds discovered.
Privacy
-
specific: While many retention periods are specific, some are vague such as 'indefinitely' for Online Community posts and legacy data 'kept on file long-term' or 'indefinitely'.
Fix: Replace vague terms like 'indefinitely' and 'long-term' with defined maximum retention periods or clear review criteria for Online Community posts and legacy administration data.
-
equal_choices: The page describes opt-in for email but legitimate interest for post/telephone, and does not show an actual consent interface where accept and reject are equally prominent.
Fix: Provide a clear, symmetric consent mechanism (e.g., equally styled 'Accept' and 'Reject' buttons) for all marketing channels rather than relying on legitimate interest with opt-out.
-
no_forced_consent: Scope uses legitimate interest as the basis for post and telephone marketing, effectively bundling these communications without requiring affirmative consent.
Fix: Require affirmative, granular opt-in consent for each communication channel (email, post, telephone) instead of defaulting postal and phone contact to legitimate interest.
-
banner_present: The page content shows no visible cookie or consent banner, only a 'Manage cookies' footer link and a 'Cookies' policy link.
Fix: Implement a visible cookie consent banner on first visit that allows users to accept, reject, or manage cookie preferences before non-essential cookies are set.
-
partner_sharing_mentioned: There is no on-page consent copy or banner disclosing data sharing with third-party partners.
Fix: Add explicit banner or consent copy stating whether personal data or cookie data is shared with third-party advertising or analytics partners, with a link to the full cookie policy.
-
partner_count_specific: No specific numeric count of third-party partners is stated anywhere in the visible page content.
Fix: Include a specific number of third-party partners (e.g., 'We share data with X partners') in the consent banner and link to a full list.
Provenance
- No author or date metadata found on the page.
Security
- security.txt not published.
Transparency
-
detail: No amounts, percentages, or funding categories are provided on this page—only a link to the annual report.
Fix: Include a summary breakdown of income (e.g., % from public donations, retail, grants, statutory funding) directly on the About page or a dedicated funding page.
-
complete: The page does not enumerate funding streams at all, so completeness across major sources cannot be established from the content shown.
Fix: Publish a comprehensive funding disclosure covering all major streams (individual giving, corporate partnerships, retail, legacies, grants, government contracts) on-page or via a clearly labeled funding section.
-
algorithm_explained: The About page describes Scope's mission and structure but does not mention any algorithms or explain their purpose.
Fix: Add a section or link disclosing any algorithmic or automated decision-making systems used by Scope and explaining their purpose in plain language.
-
impact_clear: There is no description of how algorithmic decisions might affect users, service recipients, or supporters.
Fix: Publish a clear statement describing the impact of any automated decisions on users, including what outcomes they influence and how users are affected.
-
annual_statement: The page links to a Privacy policy but provides no evidence on this page of a regular or annual review of data practices.
Fix: Add a note on the About/Privacy page stating when the privacy policy was last reviewed and commit to a periodic (e.g., annual) review cycle.
-
dated: No date or version information is shown for the privacy/data practices statement referenced in the footer.
Fix: Display a 'Last updated' date or version number on the Privacy policy and reference it from the About page.
Level 3 — Advanced
Accessibility
-
remediation_timeline: The statement only says issues will be fixed 'as soon as we can' without any concrete dates or target timelines.
Fix: Add specific target dates or estimated timeframes for resolving each listed accessibility issue.
Accountability
Interoperability
- Not found at: /status
Security
-
plan_exists: The page lists policies like safeguarding and modern slavery but no published incident response plan or policy is present.
Fix: Publish a dedicated incident response plan or security policy and link it from the About or footer section.
-
notification_commitment: The page contains no commitment to publicly notify users of significant security or data incidents.
Fix: Add an explicit statement committing to notify affected users and the public when significant incidents occur.
-
timeframe: No timeframe for disclosing incidents to affected users is stated anywhere on the page.
Fix: Specify a concrete disclosure timeframe (e.g., within 72 hours of discovery) in the incident response policy.
Skipped: Target page not found in captured content
Transparency
-
criteria_published: The page does not publish any specific criteria used in algorithmic decision-making.
Fix: Publish the specific input criteria used by any algorithms (e.g., eligibility factors, data points) on a dedicated transparency page.
-
weighting: No information about the weighting or prioritisation of decision criteria is provided.
Fix: Document and publish how each criterion is weighted or prioritised within any algorithmic processes used by the charity.
-
auditable: The page lacks technical or methodological detail that would enable external audit or independent review of any algorithm.
Fix: Provide an audit-ready disclosure (e.g., model description, data sources, testing methodology, contact for auditors) to support external review.
-
open_source: The about page contains no links to source code repositories or any indication that the site's code is publicly available.
Fix: Add a link in the footer or about page to a public code repository (e.g., GitHub) if any Scope-developed tools or site components are open source.
-
tech_docs: No technical documentation is linked from the about page; only brand guidelines and policy documents are referenced.
Fix: Publish and link to technical documentation (e.g., API docs, accessibility implementation notes, or developer resources) from the about or footer section.
Responsibility to the Future
-
disclosure_exists: The About us page covers governance, strategy, and impact but contains no published environmental impact or sustainability disclosure.
Fix: Publish a dedicated sustainability or environmental impact statement and link to it from the About us page.
-
specific_metrics: The page provides no specific figures for carbon emissions, energy use, or other environmental metrics.
Fix: Include quantified environmental data such as annual carbon footprint or energy consumption in a sustainability report.
-
hosting_disclosure: There is no mention of the carbon or energy profile of the site's hosting infrastructure anywhere on the page.
Fix: Add a statement disclosing the hosting provider's energy source or carbon profile, ideally noting use of green/renewable-powered hosting.
-
plan_exists: The About page describes Scope's mission, governance, and strategy but contains no published plan for what happens if the organisation fails or exits.
Fix: Publish a succession or wind-down plan describing what would happen to the organisation and its services in the event of failure or closure.
-
data_and_content_fate: The page addresses safeguarding, privacy, and cookies but says nothing about the fate of user data or published content should the organisation cease operating.
Fix: Add a statement clarifying how user data and published content would be preserved, transferred, or deleted if the organisation shuts down.
-
custodians_or_mirrors: The page names trustees, consortium membership, and leadership but does not identify any custodians, mirrors, or archive partners for its content or data.
Fix: Identify a named custodian, archive partner, or mirror arrangement responsible for maintaining the site's content and data after any exit.
-
policy_exists: The page lists policies like safeguarding and modern slavery but contains no published policy on worker wellbeing or working conditions.
Fix: Publish a dedicated worker wellbeing or working conditions policy and link to it from the About us page.
-
specific_commitments: The page includes no specific commitments regarding pay, hours, mental health, or benefits for workers.
Fix: Add explicit commitments covering fair pay, working hours, mental health support, and staff benefits to the site.
-
accountability: While a Leadership team and Trustees are named, the page does not identify any accountability or oversight specifically for worker conditions.
Fix: Clearly designate a role, committee, or trustee responsible for overseeing worker wellbeing and working conditions.