The National Archives

https://www.nationalarchives.gov.uk · 53/92 checks passed · archives

Compliance report (framework 0.8)

Gate passed (every Core check must pass) · not counted towards the gate: paused 35, draft 48, ready for review 54.

Site level: 0 (no scored checks yet).

By level

LevelResult
Level 1 — Basic 31/37 (6 failed)
Level 2 — Enhanced 9/27 (18 failed)
Level 3 — Advanced 0/10 (9 failed)

By category

CategoryResult
Accessibility 12/13
Accountability 0/5
AI & Automation 3/8
Interoperability 1/3
Privacy 13/16
Provenance 0/2
Security 8/11
Transparency 3/13
Responsibility to the Future 0/3

Level 1 — Basic

Accessibility

AI & Automation

  • policy_exists: The About us page contains no AI use policy or statement.
    Fix: Publish an AI use policy or statement on the About us section (or link to one) describing the organisation's approach to AI.
  • scope_clear: Because no AI policy is present, the page does not explain what AI is used for.
    Fix: Include a clear description of the specific purposes and contexts in which AI is used within the published AI policy.

Privacy

Security

Transparency

  • purpose_clear: The page lists subsections but does not itself contain a clear statement of what The National Archives does beyond section labels like 'Our role'.
    Fix: Add a concise introductory paragraph on the About us page stating that The National Archives is the official archive and publisher for the UK Government and describing its core functions.
  • disclosure_exists: The About page contains no funding or sponsorship disclosure, only links to sections like 'Our role' and 'The National Archives Trust'.
    Fix: Add a funding disclosure section on the About page identifying that The National Archives is a non-ministerial government department funded by HM Government, with links to annual reports.
  • transparent: No funding sources are identified anywhere on the visible page content.
    Fix: Clearly name the funding sources (e.g., UK Government grant-in-aid, commercial income, charitable support via The National Archives Trust) directly on the About page.

Level 2 — Enhanced

Accessibility

Accountability

  • named_person: The page lists generic email aliases (e.g., webmaster@, educationenquiries@) and 'staff at The National Archives' but does not name any individual person or specific role as responsible.
    Fix: Identify a named individual or specific role (e.g., Head of Customer Services) accountable for each enquiry category.
  • response_timeframe: The page lists Live Chat operating hours but does not state how long it will take to receive a response to emails, callbacks, or written enquiries.
    Fix: Publish expected response times (e.g., 'we respond to emails within 10 working days') alongside each contact channel.
  • specific: No specific response timeframes (in days or hours) are given for any enquiry channel beyond Live Chat availability windows.
    Fix: Add concrete numeric service-level targets such as '5 working days for general enquiries' and '20 working days for FOI requests'.
  • steps_clear: The page itself only links out to the procedure without summarising the actual steps a user must take to make a complaint.
    Fix: Add a brief on-page summary of the complaint steps (e.g., how to submit, what information to include, escalation stages, and expected response time).
  • independent: The page does not indicate any independent review body or escalation path beyond contacting The National Archives itself.
    Fix: Add an explicit escalation route to an independent body (e.g., the Information Commissioner's Office or Parliamentary Ombudsman) within the complaints procedure description.

AI & Automation

  • detailed_scope: There is no AI policy on the page and therefore no detailed scope of AI use.
    Fix: Add a detailed scope section to the AI policy listing systems, use cases, and data involved.
  • limitations: No limitations of AI systems are acknowledged anywhere on the page.
    Fix: Document known limitations, risks, and uncertainties of AI tools used by The National Archives in the AI policy.
  • safeguards: The page does not describe any safeguards or quality controls related to AI.
    Fix: Describe safeguards such as human oversight, accuracy checks, and review processes for AI outputs within the AI policy.
  • marking_policy: The About page contains no policy or mention of how AI-assisted content is marked or disclosed.
    Fix: Publish a clear policy on the About or Editorial standards page explaining how AI-assisted content is labelled and disclosed.
  • consistent: Without any visible marking policy, there is no evidence that AI content marking is applied consistently across the page.
    Fix: Define and apply a consistent AI-content label (e.g., an 'AI-assisted' tag) across all pages and link to its definition.
  • oversight_exists: The page does not document any human oversight mechanism for AI outputs.
    Fix: Add a statement to the About section describing how humans oversee and validate any AI-generated outputs used on the site.
  • review_process: No review or approval workflow for AI-generated content is described on the page.
    Fix: Document the editorial review and sign-off steps AI-assisted content must pass before publication.
  • accountability: No individual, team, or role is named as accountable for AI-generated content on this page.
    Fix: Name a responsible team or role (e.g., Digital Editorial Lead) accountable for AI content and provide contact details.

Interoperability

Privacy

  • retention_stated: Although the page has a 'Retention of your personal information' heading in its table of contents, the visible content does not provide actual retention details within the excerpt.
    Fix: Include explicit retention statements under the 'Retention of your personal information' section for each processing activity on the page itself (or clearly link to a retention schedule).
  • specific: No specific retention periods (e.g., number of months or years) are stated in the visible policy content.
    Fix: Add concrete time periods for each data category (e.g., 'CCTV footage retained for 31 days', 'reader's ticket records retained for X years') rather than general statements.
  • partner_sharing_mentioned: The banner only mentions essential and analytics cookies for understanding service usage, with no disclosure of data sharing with third-party partners.
    Fix: Update the cookie banner copy to explicitly disclose whether data is shared with third-party partners (e.g., analytics providers) and link to a detailed cookie/partner list.
  • partner_count_specific: No specific numeric count of partners is stated anywhere in the banner copy.
    Fix: If partner data sharing occurs, state the exact number of partners in the banner (e.g., 'We share data with X partners') and link to their names.

Provenance

  • credentials: The about page only links to further sections (e.g. 'Our role', 'The National Archives Trust') rather than providing organisational background or credentials directly on this page.
    Fix: Include a short summary on the about page describing The National Archives' status as a non-ministerial government department and official archive, with key credentials visible without requiring a click-through.

Security

Transparency

  • named_person: Only generic team mailboxes and service names are listed; no named individual or specifically identified team is given for enquiries.
    Fix: Add the name of the responsible individual or clearly identified team (e.g., 'Education Team, led by [Name]') for each enquiry route.
  • substantive: The page shows only navigational tiles and a strategy link, lacking any substantive statement of purpose on the page itself.
    Fix: Expand the About us page with several paragraphs detailing the organisation's purpose, scope, and services rather than just linking to other sections.
  • mission_clear: Although a 'Strategy 2025–2030' link is provided, the mission or editorial approach is not articulated directly on the page.
    Fix: Summarise the mission and strategic objectives from the 2025–2030 strategy directly on the About us page so visitors can understand the mission without clicking through.
  • detail: The page provides no amounts, percentages, or categorical breakdowns of funding.
    Fix: Include a summary of funding with figures or percentages (e.g., proportion from grant-in-aid vs. self-generated income) or link prominently to the annual report's financial summary.
  • complete: No funding streams are disclosed at all, so coverage of major streams cannot be established.
    Fix: Publish a complete funding breakdown covering government grant-in-aid, commercial/trading income, and charitable contributions via the Trust and Friends organisations.
  • roles_clear: The page only lists section categories (About, Press room, FOI, Trust) without identifying specific key roles or responsibilities such as leadership, board members, or editorial ownership.
    Fix: Add a clearly labeled leadership/organizational structure section naming key officers (e.g., Chief Executive, Keeper, board) and their responsibilities, or link directly to such a page from 'About us'.
  • algorithm_explained: The About us page makes no mention of any algorithms or automated decision-making systems or their purpose.
    Fix: Add a section (or link to a dedicated page) describing any algorithms used by The National Archives and the purpose each serves.
  • impact_clear: There is no description on the page of how algorithmic decisions might affect users of the archive or its services.
    Fix: Include a clear statement outlining how any algorithmic decisions impact users, such as search ranking, recommendations, or access decisions.
  • annual_statement: The page links to a privacy policy but shows no evidence of a regular or periodic review of data practices.
    Fix: Publish a statement on the privacy policy page indicating when the data practices were last reviewed and the schedule for periodic review.
  • dated: No date or version indicator for the privacy/data practices statement is visible on or linked from this page.
    Fix: Add a 'last updated' date or version number to the privacy policy and surface it in the footer or policy landing page.

Level 3 — Advanced

Accessibility

  • feedback_channel: The statement provides feedback contact details (Webmaster email and Quality Manager phone) but states no commitment to a response timeframe for accessibility problems.
    Fix: Add an explicit response commitment, such as 'we aim to respond within 5 working days,' to the Feedback and contact information section.

Accountability

  • criteria_clear: The page only provides a brief description of the online user participation terms without exposing specific moderation criteria on this overview page.
    Fix: Add a summary of specific moderation criteria (e.g., prohibited content types, behavior standards) directly on the terms overview or ensure the linked page lists them clearly.
  • enforcement: The page does not explain how moderation decisions are enforced, appealed, or actioned against users who violate policies.
    Fix: Include or link to a clear enforcement process describing actions taken (warnings, removal, bans), appeal mechanisms, and timelines for moderation decisions.

Interoperability

Security

  • plan_exists: The page describes the archive's purpose and navigation links but contains no published incident response plan or security policy.
    Fix: Publish an incident response plan or security policy and link to it from the site, for example in the legal information or about section.
  • notification_commitment: There is no statement committing to public notification of significant security incidents anywhere on the page.
    Fix: Add an explicit commitment to notify the public and affected users when significant incidents occur.
  • timeframe: The page provides no timeframe for disclosing incidents to affected users.
    Fix: State a specific disclosure timeframe (e.g., notification within 72 hours of discovery) in the incident response documentation.

Transparency

  • criteria_published: The page does not publish any criteria used in algorithmic decision-making.
    Fix: Publish the specific input criteria used by any algorithms (e.g., on a transparency or algorithmic accountability page) linked from About us.
  • weighting: No information is provided about how any criteria are weighted or prioritised in decisions.
    Fix: Document the relative weighting or priority of each criterion used in algorithmic decisions and make it accessible from this page.
  • auditable: The page lacks the technical or procedural detail that would allow an external party to audit or review any algorithmic systems.
    Fix: Provide an algorithmic transparency record (e.g., following the UK Algorithmic Transparency Recording Standard) with sufficient detail for independent audit.
  • open_source: The page does not link to any public source code repository for the website or its services.
    Fix: Add a link to The National Archives' GitHub or equivalent public repository from the About or footer section to expose source code where available.

Responsibility to the Future

  • disclosure_exists: The page contains no published environmental impact or sustainability disclosure, only general information about the organisation's role and links to sections like 'What we do' and 'How we work'.
    Fix: Publish a dedicated environmental or sustainability disclosure page and link to it from the About us and footer navigation.
  • specific_metrics: No specific environmental figures such as carbon emissions, energy use, or emissions data appear anywhere on the page.
    Fix: Include concrete metrics such as annual carbon footprint, energy consumption, and emissions reduction targets in the sustainability disclosure.
  • hosting_disclosure: The page provides no information about the carbon or energy profile of its hosting infrastructure.
    Fix: Disclose the hosting provider's energy sourcing and the site's associated carbon or energy footprint in the sustainability content.
  • plan_exists: The About page describes the organisation's role and work but contains no published plan for what happens if the organisation fails or exits.
    Fix: Publish a succession or continuity plan describing what happens to the service and its collections if the organisation ceases operation.
  • data_and_content_fate: The page does not address what would happen to user data or published content in the event of organisational failure or exit.
    Fix: Add a statement clarifying how user data and published content would be preserved, transferred, or retired if the service ends.
  • custodians_or_mirrors: While partner sites like the UK Government Web Archive and The National Archives Trust are linked, no custodians, mirrors, or archive partners are identified as responsible for continuity should the organisation cease.
    Fix: Name specific custodians, mirror sites, or archive partners who would take over stewardship of the content and services if the organisation exits.
  • policy_exists: The page is a staff directory listing people by last name and contains no published policy on worker wellbeing or working conditions.
    Fix: Publish a dedicated worker wellbeing or working conditions policy and link to it from this or a related page.
  • specific_commitments: There are no specific commitments regarding pay, hours, mental health, or benefits anywhere on the page.
    Fix: Add concrete, measurable commitments covering pay, working hours, mental health support, and employee benefits to a published wellbeing policy.
  • accountability: While a Director of People, Inclusion & Change is listed, no accountability or oversight mechanism for worker conditions is described.
    Fix: Explicitly assign named accountability and oversight responsibilities for worker wellbeing within a published policy or governance statement.