Scottish Government

https://www.gov.scot · 59/92 checks passed · government

Compliance report (framework 0.8)

Gate passed (every Core check must pass) · not counted towards the gate: paused 35, draft 48, ready for review 54.

Site level: 0 (no scored checks yet).

By level

LevelResult
Level 1 — Basic 30/37 (7 failed)
Level 2 — Enhanced 13/27 (14 failed)
Level 3 — Advanced 0/10 (9 failed)

By category

CategoryResult
Accessibility 10/13
Accountability 1/5
AI & Automation 3/8
Interoperability 1/3
Privacy 13/16
Provenance 1/2
Security 8/11
Transparency 6/13
Responsibility to the Future 0/3

Level 1 — Basic

Accessibility

AI & Automation

  • policy_exists: The About page contains no AI use policy or statement.
    Fix: Publish a clear AI use policy or statement, linked from the About page, describing how and whether the Scottish Government uses AI.
  • scope_clear: There is no explanation of what AI is used for anywhere on this page.
    Fix: Add a section to the AI policy outlining the specific purposes and contexts in which AI tools are used by the organisation.

Privacy

Security

Transparency

  • disclosure_exists: The About page contains no funding or sponsorship disclosure, only describing governmental responsibilities and structure.
    Fix: Add a funding disclosure section or link on the About page indicating that the Scottish Government is funded through public sources such as the UK block grant and devolved taxation.
  • transparent: No funding sources are identified anywhere on the page.
    Fix: Clearly identify funding sources (e.g., Scottish Consolidated Fund, UK Treasury block grant, devolved tax revenues) with links to authoritative budget documents.

Level 2 — Enhanced

Accessibility

Accountability

  • response_timeframe: The contact page lists office hours and contact methods but does not publish any timeframe for responding to enquiries.
    Fix: Add a statement indicating how long users should expect to wait for a response to phone, email, or postal enquiries.
  • specific: Because no response timeframe is published at all, there are no specific durations (e.g. number of working days) provided.
    Fix: Specify a concrete response target such as 'we aim to reply to emails within 20 working days'.
  • process_exists: The page mentions welcoming feedback and an unacceptable actions policy but does not document a complaints or feedback process or link to one.
    Fix: Add a dedicated complaints/feedback section or link to a complaints procedure page explaining how to raise and escalate issues.
  • steps_clear: No step-by-step guidance is provided for how to submit a complaint or what happens after submission.
    Fix: Publish clear numbered steps covering how to submit a complaint, who handles it, expected acknowledgement, and escalation options.
  • appeals_exists: The contact page only lists general enquiry channels and an unacceptable behaviour policy, with no documented appeals process for challenging decisions.
    Fix: Add a clearly labelled appeals section or link on the contact page explaining how users can formally challenge decisions or responses.
  • independent: No escalation path or independent review body (e.g., ombudsman) is referenced anywhere on the page.
    Fix: Include a link or reference to an independent escalation route such as the Scottish Public Services Ombudsman for unresolved complaints.

AI & Automation

  • detailed_scope: No detailed scope of AI use is provided on the page.
    Fix: Include a detailed breakdown of AI systems in use, their functions, and the services or processes they support.
  • limitations: The page does not acknowledge any limitations of AI systems.
    Fix: Document known limitations of AI systems such as accuracy, bias, and appropriate-use boundaries in the AI policy.
  • safeguards: No safeguards or quality controls for AI are described on the page.
    Fix: Describe safeguards such as human oversight, quality assurance processes, data protection measures, and escalation procedures for AI use.
  • marking_policy: The About page contains no reference to a policy for marking or labelling AI-assisted content.
    Fix: Publish an AI content policy (e.g., linked from the About or Accessibility footer) that explains how AI-assisted content is identified and labelled.
  • consistent: Without a marking policy visible on the page, there is no evidence of consistent application of AI content labelling.
    Fix: Adopt a standard visual label or disclosure statement for AI-generated content and apply it uniformly across all relevant pages.
  • oversight_exists: The page does not mention any human oversight process for AI outputs.
    Fix: Document human oversight arrangements for AI use in a dedicated governance or AI policy page accessible from the About section.
  • review_process: No review or approval workflow for AI-generated content is described anywhere on the page.
    Fix: Describe the editorial review and sign-off steps AI outputs must pass before publication, and link this from the About page.
  • accountability: The page identifies no individual, role, or team accountable for AI-generated content.
    Fix: Name a responsible owner (e.g., a directorate or senior responsible officer) for AI content governance and publish the contact on the site.

Interoperability

Privacy

  • specific: While call and analytics retention are specific, retention for general enquiry correspondence, newsletter subscriptions, and other collected personal data is not specified.
    Fix: Add explicit retention periods for all categories of personal data processed, including email/postal enquiries, newsletter subscriber data, and any 'official record' correspondence.
  • partner_sharing_mentioned: The banner only mentions collecting anonymous data to improve browsing experience and does not disclose any data sharing with third-party partners.
    Fix: Update the banner copy to explicitly state whether data is shared with third-party partners and link to a list of those partners.
  • partner_count_specific: No numeric count of partners is stated because partner sharing itself is not disclosed.
    Fix: If third-party partners receive data, include the specific number of partners (e.g., 'shared with X partners') in the consent copy.

Provenance

Security

Transparency

  • mission_clear: The page describes responsibilities and structure but does not articulate a clear mission statement or editorial approach for the government's work.
    Fix: Add a concise mission statement describing the Scottish Government's guiding purpose, values, or strategic objectives in addition to its list of responsibilities.
  • detail: There are no details, amounts, percentages, or categories of funding provided on the page.
    Fix: Include meaningful detail such as budget totals, percentage breakdowns by funding stream, or categories linking to the Scottish Budget publications.
  • complete: No disclosure is present, so major funding streams are not covered.
    Fix: Provide a complete overview of all major funding streams (block grant, devolved taxes, borrowing, other receipts) or link prominently to the published Scottish Budget.
  • algorithm_explained: The About page describes the Scottish Government's responsibilities but makes no mention of any algorithms or their purpose.
    Fix: Add a section or link disclosing any algorithmic or automated decision-making systems used and explaining their purpose.
  • impact_clear: There is no discussion of how algorithmic decisions might affect users on this page.
    Fix: Include a clear description of how any automated decisions impact users, with links to detailed impact assessments.
  • annual_statement: The page shows no evidence of a regular or periodic review of data practices, only a link to a Cookies/Privacy page in the footer without review cadence information.
    Fix: Publish a dated data practices review statement (e.g., annual) on the Privacy or Cookies page indicating when practices were last reviewed and the next scheduled review.
  • dated: No date or version information is shown for any data practices statement on this page; the cookie notice and privacy link lack visible dating.
    Fix: Add a clear 'last updated' date or version number to the privacy and cookies statements linked from this page.

Level 3 — Advanced

Accessibility

  • remediation_timeline: The statement commits to fixing PDFs and reviewing its policy but provides no dates or target timeline for completing these remediations.
    Fix: Add specific target dates or milestones (e.g., a quarter or year) by which the identified PDF and menu button issues will be fixed.
  • feedback_channel: The statement provides a contact email (website@gov.scot) for reporting problems but states no commitment to a response timeframe.
    Fix: State an explicit response commitment, such as replying to accessibility feedback within a set number of working days.

Accountability

  • policy_exists: The About page does not publish or link to any moderation policy for user-generated content or interactions.
    Fix: Publish a clearly labeled moderation policy page and link to it from the About page and site footer.
  • criteria_clear: No moderation criteria (e.g., what content is allowed or removed) are stated anywhere on this page.
    Fix: Add a section specifying the criteria used to moderate comments, submissions, or social interactions, including prohibited content types.
  • enforcement: The page does not explain how moderation decisions are made, enforced, or appealed.
    Fix: Document the enforcement workflow, including who reviews content, timelines for action, and how users can appeal moderation decisions.

Interoperability

Security

  • plan_exists: The page only lists a 'Cybersecurity' navigation link but provides no published incident response plan or policy content on this page.
    Fix: Publish a dedicated incident response plan or policy document and link to it clearly from the Cybersecurity section.
  • notification_commitment: The page contains no commitment to publicly notify affected users of significant security incidents.
    Fix: Add an explicit statement committing to notify the public and affected users when significant incidents occur.
  • timeframe: There is no stated timeframe for disclosing incidents to affected users anywhere on the page.
    Fix: Specify a concrete disclosure timeframe (e.g., notification within 72 hours of confirming a significant incident).

Transparency

  • criteria_published: The page contains no published criteria for any algorithmic decision-making.
    Fix: Publish the specific criteria used by any algorithms, either on this page or via a linked transparency register.
  • weighting: No weighting or prioritisation of decision criteria is described anywhere on the page.
    Fix: Document how each criterion is weighted or prioritised in algorithmic decisions and make it accessible from the About section.
  • auditable: The page provides no technical or procedural detail sufficient to support external audit of algorithms.
    Fix: Provide or link to an algorithmic transparency record with enough methodological detail for independent audit and review.
  • open_source: No link to source code or any public code repository appears on the about page.
    Fix: Add a link to a public code repository (e.g., a GitHub organisation) or a statement describing where the site's source code can be accessed.
  • tech_docs: The page contains no technical documentation or link to developer/technical documentation about the site.
    Fix: Publish and link to technical documentation (e.g., a developer or tech docs page) covering the site's platform, APIs, or data standards.

Responsibility to the Future

  • disclosure_exists: The About page describes the Scottish Government's responsibilities and structure but contains no published environmental impact or sustainability disclosure.
    Fix: Publish a sustainability or environmental impact statement (or link to one) accessible from this page or the site footer.
  • specific_metrics: The page provides no specific figures on carbon, energy use, or emissions anywhere in its content.
    Fix: Include concrete environmental metrics such as annual carbon footprint, energy consumption, or emissions data in a dedicated sustainability disclosure.
  • hosting_disclosure: There is no mention of the carbon or energy profile of the website's hosting infrastructure on the page.
    Fix: Add a statement disclosing the hosting provider's carbon/energy profile or confirming use of renewable-powered or green hosting.
  • plan_exists: The About page describes the Scottish Government's responsibilities and structure but contains no published plan for what happens if the organisation fails or exits.
    Fix: Publish a succession or continuity plan describing what would happen to the service if the organisation ceased operating, and link to it from the About section.
  • data_and_content_fate: The page mentions the Open Government Licence and Crown Copyright but does not address what would happen to user data or published content in the event of organisational exit.
    Fix: Add a statement explaining how user data would be handled and how published content would be preserved or transferred should the organisation wind down.
  • custodians_or_mirrors: The page links to an Archive but does not identify any named custodians, mirrors, or archive partners responsible for maintaining content if the organisation ceases to exist.
    Fix: Identify and document a specific custodian or archive partner (e.g., the National Records of Scotland or UK Web Archive) responsible for preserving the site's content.
  • policy_exists: The page contains only navigation links and footer boilerplate with no published policy on worker wellbeing or working conditions.
    Fix: Publish a dedicated worker wellbeing or working conditions policy and link to it from this page.
  • specific_commitments: The page includes no content addressing pay, hours, mental health, or benefits.
    Fix: Add specific, measurable commitments on pay, working hours, mental health support, and employee benefits to the wellbeing policy.
  • accountability: No individual, role, or body is identified as responsible for overseeing worker conditions anywhere on the page.
    Fix: Name a responsible role or oversight body (e.g., HR director or wellbeing committee) accountable for worker conditions in the published policy.