University College London

https://www.ucl.ac.uk · 50/92 checks passed · higher_education

Compliance report (framework 0.8)

Gate passed (every Core check must pass) · not counted towards the gate: paused 35, draft 48, ready for review 54.

Site level: 0 (no scored checks yet).

By level

LevelResult
Level 1 — Basic 30/37 (7 failed)
Level 2 — Enhanced 10/27 (17 failed)
Level 3 — Advanced 0/10 (10 failed)

By category

CategoryResult
Accessibility 12/13
Accountability 1/5
AI & Automation 3/8
Interoperability 1/3
Privacy 9/16
Provenance 2/2
Security 6/11
Transparency 6/13
Responsibility to the Future 0/3

Level 1 — Basic

Accessibility

AI & Automation

  • policy_exists: The About UCL page contains no AI use policy or statement anywhere in its content or footer links.
    Fix: Publish a dedicated AI use policy page and link to it from the site footer alongside Privacy and Accessibility.
  • scope_clear: There is no mention of how or where AI is used on the site or by the institution.
    Fix: Add a clear statement describing the specific purposes for which AI is used (e.g., search, content generation, analytics).

Privacy

Security

Transparency

  • disclosure_exists: The About page contains no funding or sponsorship disclosure of any kind.
    Fix: Add a funding and sponsorship disclosure section (or link to one) on the About page identifying UCL's major funding sources.
  • transparent: Because no disclosure is present, funding sources are not clearly identified on this page.
    Fix: Clearly name the key funders (e.g., UKRI, research councils, tuition, government grants, philanthropy) with links to further detail.

Level 2 — Enhanced

Accessibility

Accountability

  • response_timeframe: The contact page lists email addresses and phone numbers but does not publish any response timeframes for enquiries.
    Fix: Add a statement on the contact page indicating expected response times for each contact channel (e.g., email enquiries answered within 5 business days).
  • specific: No timeframes are provided at all, so there is nothing specific stated in days or hours.
    Fix: Publish concrete, specific response windows (e.g., '2 working days' for admissions, '24 hours' for IT) alongside each contact method.
  • process_exists: The page provides general contact routes but no documented complaints or feedback process or link to one.
    Fix: Add a clearly labelled 'Complaints and Feedback' section or link to UCL's formal complaints procedure on the contact page.
  • steps_clear: Because no complaints process is presented, there are no steps describing how to submit or escalate a complaint.
    Fix: Publish a step-by-step complaints procedure (e.g., informal resolution, formal written complaint, escalation/appeal) with contact details and timelines for each stage.
  • appeals_exists: The contact page lists departmental contacts but contains no documented appeals process for decisions or complaints.
    Fix: Add a dedicated section outlining a formal appeals/complaints procedure with clear steps, timelines, and contact points.
  • independent: No escalation path or independent review body is mentioned anywhere on the contact page.
    Fix: Document an escalation route to an independent office (e.g., Office of the Independent Adjudicator or an internal ombudsperson) for unresolved appeals.

AI & Automation

  • detailed_scope: The page provides no detail about the scope of AI use, as no AI policy is present.
    Fix: Create an AI policy that enumerates each AI system in use, its purpose, and the data it processes.
  • limitations: No limitations of AI systems are acknowledged anywhere on the page.
    Fix: Include a section in the AI policy explicitly acknowledging known limitations such as bias, inaccuracy, or hallucination risks.
  • safeguards: No safeguards, human oversight, or quality control measures are described on the page.
    Fix: Document safeguards such as human review, accuracy checks, and escalation procedures in a published AI governance statement.
  • marking_policy: The About page contains no policy or statement describing how AI-assisted content is marked or labelled.
    Fix: Publish a clear policy stating how AI-generated or AI-assisted content is identified and labelled on UCL web pages.
  • consistent: No AI content markings appear anywhere on the page, so consistent application cannot be demonstrated.
    Fix: Introduce standardised AI-content labels (e.g. a visible tag or disclosure line) and apply them uniformly across news items, highlights and other editorial content.
  • oversight_exists: The page does not mention any human oversight mechanism for AI outputs.
    Fix: Add a documented statement (linked from the footer or About section) describing how humans oversee any AI-generated content used by UCL.
  • review_process: There is no description of a review or approval workflow for AI-generated material on the page.
    Fix: Publish a short description of the editorial review/approval steps AI-assisted content must pass before publication.
  • accountability: No individual, role, or team is identified as accountable for AI-generated content on this page.
    Fix: Name an accountable role (e.g. Head of Digital or Editorial Lead) and provide contact details for AI-content governance queries.

Interoperability

Privacy

  • comprehensive: The page focuses on cookies and only links out to a privacy policy, without itself detailing the full scope of data collected and the purposes for each category.
    Fix: Include or inline a summary of what personal data UCL collects and the purposes for each, or ensure the linked privacy policy content is surfaced on this page.
  • necessity: The page distinguishes strictly necessary vs optional cookies but does not explicitly state that overall data collection is limited to what is necessary.
    Fix: Add a clear statement affirming that UCL only collects personal data that is necessary for the stated purposes (data minimisation principle).
  • proportionate: There is no explicit statement that data collection is proportionate to the service provided.
    Fix: Include language confirming that the scope of data collected is proportionate to, and no greater than required for, delivering the website's services.
  • retention_stated: The page mentions cookies can be session or persistent but does not state retention periods for personal data generally, only referring users to a separate Cookie register page.
    Fix: State data retention periods directly on this page for each category of cookie/data, rather than relying on an external register.
  • specific: Durations are described vaguely (e.g., 'until you delete them' or 'reaches its expiration date') without specific timeframes.
    Fix: Provide concrete retention periods (e.g., '13 months for analytics cookies') for each cookie and data category.
  • equal_choices: The consent banner offers 'Accept all cookies' and 'Accept necessary cookies' buttons but no clearly labeled 'Reject all' option with equal prominence, and settings are relegated to a less prominent link.
    Fix: Add a 'Reject all' button with the same visual prominence (size, color, position) as the 'Accept all cookies' button on the consent banner.
  • partner_sharing_mentioned: The banner only mentions enhancing browsing, analysing traffic, and personalised content, but does not disclose data sharing with third-party partners (though embedded YouTube content is mentioned separately).
    Fix: Update the cookie banner copy to explicitly state that data may be shared with third-party partners (e.g., YouTube, analytics, and marketing providers) for the listed purposes.
  • partner_count_specific: No numeric count of third-party partners is stated anywhere in the banner or on-page consent copy.
    Fix: Include a specific number of partners (e.g., 'We share data with X partners') in the banner, linking to a full list in the cookie settings.

Provenance

Security

Transparency

  • detail: No funding information is provided, so there are no amounts, percentages, or categories described.
    Fix: Publish a breakdown of funding by category with amounts or percentages (e.g., research grants, tuition, donations) on or linked from the About page.
  • complete: With no disclosure at all, the page cannot cover any funding streams let alone all major ones.
    Fix: Provide a comprehensive disclosure covering all major income streams such as tuition fees, research grants, government funding, donations, and commercial income.
  • roles_clear: While governance is mentioned, the page does not identify specific key roles or responsibilities (e.g., President, Provost, Council members).
    Fix: Add a summary or linked list of named leadership roles and their responsibilities directly on the About page or within the Leadership and governance preview.
  • algorithm_explained: The About page describes UCL's mission and rankings but does not mention or explain any algorithms used on the site or in decision-making.
    Fix: Add a section or link disclosing any algorithms used (e.g., for admissions, personalisation, or search) and explain their purpose.
  • impact_clear: There is no description of how algorithmic decisions might affect users such as applicants, students, or visitors.
    Fix: Publish a clear statement describing how algorithmic decisions impact users and what outcomes they influence.
  • annual_statement: The page links to a privacy policy and cookie settings but shows no evidence of a regular or annual review of data practices.
    Fix: Add a note to the privacy policy or footer stating when data practices are periodically reviewed (e.g., 'Reviewed annually, last reviewed [date]').
  • dated: The privacy/cookie statement shown on the page is not visibly dated or versioned.
    Fix: Display a 'Last updated' date or version number on the privacy policy link and cookie notice visible from this page.

Level 3 — Advanced

Accessibility

  • known_issues: This landing page only links to statements and does not itself acknowledge any specific known accessibility issues or limitations.
    Fix: Surface or summarise the known non-compliances (e.g., WCAG failures) from the underlying statements directly on this page or clearly within the linked statement.
  • remediation_timeline: The page states a commitment to improving accessibility but provides no timeline or target dates for fixing known issues.
    Fix: Add specific dates or timeframes indicating when identified accessibility issues will be resolved.
  • feedback_channel: The page references Digital Accessibility Services and a 'Contact Us' link but provides no accessibility-specific feedback mechanism with a stated response-time commitment.
    Fix: Provide a clear accessibility feedback contact (email/form) and state how quickly users can expect a response.

Accountability

  • policy_exists: The About page does not publish or link to any moderation policy for user-generated content or community interactions.
    Fix: Publish a moderation policy (e.g., community guidelines) and link it from the footer or About section.
  • criteria_clear: No moderation criteria (what content is allowed or disallowed) are stated anywhere on the page.
    Fix: Add clear criteria describing acceptable and prohibited content, tone, and behaviour within the moderation policy.
  • enforcement: The page contains no explanation of how moderation decisions are made, appealed, or enforced.
    Fix: Document the enforcement workflow, including who reviews content, response times, sanctions, and an appeals process.

Interoperability

Security

  • plan_exists: The page describes physical security services (bike security, lost property, reporting crime) and a CCTV policy but publishes no incident response plan or policy for security incidents.
    Fix: Publish a dedicated incident response plan or policy outlining how the organisation detects, responds to, and manages security incidents.
  • notification_commitment: There is no statement committing to public notification of significant security incidents anywhere on the page.
    Fix: Add an explicit commitment to notify affected users and the public when significant incidents occur.
  • timeframe: The page provides no timeframe for disclosing incidents to affected users.
    Fix: Specify a concrete disclosure timeframe (e.g., notifying affected users within 72 hours of confirming an incident).
  • policy_exists: The page is about physical campus security (ID cards, bikes, lost property, CCTV) and contains no published responsible-disclosure or bug-bounty policy for security vulnerabilities.
    Fix: Publish a security.txt file and a dedicated responsible-disclosure policy page explaining how researchers can report software or website vulnerabilities.
  • clear_contact: The only contact channels listed are physical security phone numbers and a switchboard, with no email or form for reporting digital vulnerabilities.
    Fix: Add a dedicated security contact (e.g., a security@ucl.ac.uk address or a reporting form) specifically for disclosing vulnerabilities.
  • safe_harbour_or_reward: The page makes no mention of any safe-harbour provision, legal protections, or reward structure for security researchers.
    Fix: Include explicit safe-harbour language assuring good-faith researchers of no legal action, and clarify whether any reward or recognition is offered.

Transparency

  • criteria_published: The page contains no published criteria for any algorithmic decision-making process.
    Fix: Publish the specific criteria used in any algorithmic decisions on a dedicated transparency page linked from About.
  • weighting: No weighting or prioritisation of decision criteria is disclosed anywhere on the page.
    Fix: Document and publish the relative weighting or priority assigned to each criterion used by algorithms.
  • auditable: The page provides no technical detail, documentation, or contact for external audit of any algorithmic systems.
    Fix: Provide an algorithmic transparency record with sufficient technical detail and a contact route for external auditors or reviewers.
  • open_source: There is no link to source code or any open-source repository on the about page.
    Fix: Add a link to a public repository (e.g., GitHub) if any UCL website code or digital tools are open-sourced, or link to UCL's open research/code resources.
  • tech_docs: No technical documentation about the site's platform, APIs, or data is published or linked from this page.
    Fix: Publish and link to technical documentation covering the website's platform, accessibility conformance details, or any available APIs/open data endpoints.

Responsibility to the Future

  • specific_metrics: The page contains only high-level messaging and navigation links with no concrete figures for carbon emissions, energy use, or other quantified metrics.
    Fix: Publish specific, dated environmental metrics (e.g., annual carbon emissions in tonnes CO2e, energy consumption in kWh) directly on the page or a clearly linked reporting section.
  • hosting_disclosure: There is no mention of the carbon or energy profile of the website's hosting infrastructure anywhere on the page.
    Fix: Add a statement disclosing the hosting provider's energy source or carbon profile, such as confirmation of green/renewable-powered hosting.
  • plan_exists: The About page contains institutional overview, news, rankings, and events but no published plan for what happens if the organisation fails or exits.
    Fix: Publish a continuity/succession plan describing how services and operations would be maintained or wound down if UCL ceased operating.
  • data_and_content_fate: The page addresses privacy and cookies but does not describe what would happen to user data and published content in the event of organisational failure or exit.
    Fix: Add a statement clarifying how user data and published content would be preserved, transferred, or deleted should the organisation wind down.
  • custodians_or_mirrors: No custodians, mirrors, or archive partners are identified anywhere in the page content.
    Fix: Name a designated custodian or archival partner (e.g., a national web archive or library) responsible for preserving content if the organisation ceases to exist.
  • policy_exists: The page is a UCL Museums and Collections landing page with no published policy on worker wellbeing or working conditions.
    Fix: Publish or link to a worker wellbeing/working conditions policy accessible from this page or its footer.
  • specific_commitments: There are no specific commitments regarding pay, hours, mental health, or benefits anywhere in the content.
    Fix: Add concrete commitments covering pay, working hours, mental health support, and benefits to a dedicated worker wellbeing policy.
  • accountability: No accountability structure or oversight body for worker conditions is identified on the page.
    Fix: Name the responsible team or oversight body accountable for monitoring and enforcing worker conditions.