University of Cambridge

https://www.cam.ac.uk · 53/92 checks passed · higher_education

Compliance report (framework 0.8)

Gate passed (every Core check must pass) · not counted towards the gate: paused 35, draft 48, ready for review 54.

Site level: 0 (no scored checks yet).

By level

LevelResult
Level 1 — Basic 30/37 (7 failed)
Level 2 — Enhanced 10/27 (15 failed)
Level 3 — Advanced 1/10 (8 failed)

By category

CategoryResult
Accessibility 11/13
Accountability 0/5
AI & Automation 4/8
Interoperability 1/3
Privacy 12/16
Provenance 1/2
Security 5/11
Transparency 7/13
Responsibility to the Future 0/3

Level 1 — Basic

Accessibility

AI & Automation

  • policy_exists: The page showcases Cambridge's AI research mission and projects but does not present an AI use policy or governance statement.
    Fix: Publish a dedicated AI use policy or statement (e.g., linked from this page) outlining principles and governance for AI use at the institution.

Privacy

Security

Transparency

Level 2 — Enhanced

Accessibility

Accountability

  • named_person: The page lists generic teams like 'Student Admissions' and 'External Affairs and Communications' but no named individual or specific role holder is identified as responsible.
    Fix: Add the name or job title of a specific responsible person (e.g., Head of Admissions or Director of Communications) alongside each contact route.
  • appeals_exists: The contact page only lists general and admissions contact details with no documented appeals process.
    Fix: Add a clearly labeled appeals section or link describing how to formally appeal decisions (e.g., admissions or complaints appeals).
  • independent: No escalation path or independent review mechanism is described anywhere on the page.
    Fix: Document an independent or escalated review route (such as an ombudsperson or external adjudicator) with contact details.

AI & Automation

  • detailed_scope: While application areas are listed at a high level, the page lacks a detailed policy-level scope describing how and where AI is deployed.
    Fix: Add a policy section detailing specific AI use cases, data sources, user groups, and boundaries of acceptable use.
  • limitations: The page does not acknowledge limitations, risks, or failure modes of AI systems beyond a passing mention of 'balancing risks and benefits.'
    Fix: Include an explicit section acknowledging AI limitations such as bias, inaccuracy, and contexts where AI should not be relied upon.
  • safeguards: No safeguards, quality controls, review mechanisms, or oversight processes are described on the page.
    Fix: Describe concrete safeguards such as human oversight, ethical review boards, testing procedures, and accountability mechanisms for AI projects.
  • marking_policy: The page describes AI research initiatives but contains no policy statement about marking or labeling AI-assisted content.
    Fix: Publish a clear policy explaining how AI-assisted content on the site will be labeled or disclosed to readers.
  • consistent: No AI content markings or disclosures are visible on any of the features, news items, or case studies listed on the page.
    Fix: Apply consistent visual labels or metadata tags to any content produced with AI assistance across all articles, films, and case studies.
  • oversight_exists: The page promotes AI research but does not document any human oversight process for AI outputs used on the site.
    Fix: Add a statement describing how human reviewers oversee AI-generated outputs before publication.
  • review_process: There is no description of a review or approval workflow for AI-generated material anywhere on the page.
    Fix: Document the editorial review or approval steps that AI-assisted content must pass through before being published.
  • accountability: While experts are named for research topics, no individual or role is identified as accountable for AI-generated content on the site.
    Fix: Name a specific role or team (e.g., an editorial lead or ai@cam contact) responsible for AI-generated content and provide their contact information.

Interoperability

Privacy

  • necessity: The policy does not explicitly state that data collection is limited to what is necessary, only referencing 'legitimate interests' and consent.
    Fix: Add an explicit statement that data collection is limited to the minimum necessary to provide and secure the service (data minimisation principle).
  • retention_stated: Only security/performance logs have a stated retention period; retention for analytics, Qualtrics, and marketing cookie data is not specified.
    Fix: Add explicit retention periods for all data categories including Google Analytics, Qualtrics survey responses, and marketing cookie data.
  • specific: Only one specific period is given ('maximum of 3 months' for security logs) while other categories lack specific timeframes.
    Fix: Provide concrete time periods (e.g., number of months or years) for each data category rather than leaving retention unstated.
  • banner_present: No cookie or consent banner is visible in the page content; only a footer link to 'Privacy policy and cookies' is present.
    Fix: Implement a visible cookie consent banner on first visit that allows users to accept, reject, or configure cookies.
  • partner_sharing_mentioned: The page content does not disclose any data sharing with third-party partners in banner or on-page consent copy.
    Fix: Include explicit disclosure in the consent banner that identifies third-party partners with whom data may be shared.
  • partner_count_specific: No numeric count of partners is stated anywhere in the visible page content.
    Fix: State a specific number of third-party partners (e.g., 'We share data with X partners') in the consent banner and link to the full list.

Provenance

Security

Transparency

  • detail: The About page itself provides no amounts, percentages, or categories for funding, only links to annual reports where such details might reside.
    Fix: Add a brief summary on the About page itemising major funding categories (e.g., tuition, research grants, endowment income) with approximate amounts or percentages.
  • complete: No major funding streams (research grants, tuition, donations, endowment returns, government funding) are enumerated on this page.
    Fix: Include a concise breakdown of all principal funding streams on the About page, or link directly to a dedicated funding transparency summary.
  • roles_clear: The page lists navigation labels like 'People', 'Governance', and 'Processes' but does not identify specific key roles or responsibilities on this page.
    Fix: Add a brief summary on the About page naming key roles (e.g., Vice-Chancellor, Council, Regent House) and their responsibilities, or surface this content directly rather than behind nav links.
  • algorithm_explained: The About page contains no mention of any algorithms used by the University or their purpose.
    Fix: Add a section or link describing any algorithmic systems used (e.g., in admissions or services) and their intended purpose.
  • impact_clear: There is no description of how algorithmic decisions affect users such as applicants, students, or staff.
    Fix: Publish a clear statement explaining how algorithmic outputs influence decisions affecting users and what recourse they have.
  • annual_statement: The page links to a 'Privacy policy and cookies' but shows no evidence of a regular or annual review of data practices.
    Fix: Add a statement to the privacy policy indicating when it was last reviewed and commit to a periodic (e.g., annual) review cycle.
  • dated: No date or version information is visible for the privacy/data practices statement from this page.
    Fix: Display a 'last updated' date or version number alongside the privacy policy link and on the policy page itself.

Level 3 — Advanced

Accessibility

Accountability

  • enforcement: While the page states the University may review, edit or remove contributions at its discretion, it does not explain the enforcement process such as how reviews occur, notification, or appeals.
    Fix: Add a section describing the moderation enforcement workflow, including how violations are reported, reviewed, communicated to contributors, and any appeal or escalation process.

Interoperability

Security

  • plan_exists: The About page contains only institutional overview content and links, with no published incident response plan or security policy.
    Fix: Publish an incident response plan or security policy and link to it from the site footer or a dedicated security page.
  • notification_commitment: The page makes no commitment to publicly notify users of significant security or data incidents.
    Fix: Add an explicit statement committing to public notification of significant incidents affecting users.
  • timeframe: No timeframe for disclosing incidents to affected users appears anywhere on the page.
    Fix: Specify a concrete disclosure timeframe (e.g., notification within 72 hours of discovery) in the incident response policy.

Transparency

  • criteria_published: The page does not publish any criteria used in algorithmic decision-making.
    Fix: Publish the specific input criteria and decision factors used by any algorithms in a dedicated transparency page.
  • weighting: No information is given about how criteria are weighted or prioritised in any algorithmic process.
    Fix: Document and disclose the relative weighting or priority assigned to each criterion in algorithmic decisions.
  • auditable: The page provides no technical detail, documentation, or contact pathway enabling external audit of algorithmic systems.
    Fix: Provide auditable documentation (model cards, data sources, methodology) and a contact route for independent reviewers.
  • open_source: There is no link to source code or any open source repository for the website on this page.
    Fix: Add a link to a public code repository (e.g., GitHub) if any site components are open source, or publish a statement about the technology stack used.
  • tech_docs: No technical documentation about the website platform, APIs, or data formats is published or linked from this page.
    Fix: Publish technical documentation or a developer page describing site architecture, APIs, or data feeds available to the public.

Responsibility to the Future

  • disclosure_exists: The About page lists sections like history, mission, and annual reports but contains no published environmental impact or sustainability disclosure.
    Fix: Publish a dedicated sustainability or environmental impact statement and link to it from the About the University section.
  • specific_metrics: The page provides no specific figures for carbon emissions, energy use, or other environmental metrics.
    Fix: Include quantified environmental data such as annual carbon emissions and energy consumption in a sustainability report.
  • hosting_disclosure: There is no mention of the carbon or energy profile of the website's hosting infrastructure anywhere on the page.
    Fix: Add a statement disclosing the hosting provider's energy source or carbon footprint, ideally in the accessibility or privacy/footer area.
  • plan_exists: The About page describes the University's mission, structure, and history but contains no published plan for organisational failure or exit.
    Fix: Publish a continuity or succession plan describing what would happen to the institution's digital services in the event of failure or wind-down.
  • data_and_content_fate: The page does not address what would happen to user data or published content if the organisation ceased operations.
    Fix: Add a section explaining how user data and published content would be preserved, transferred, or deleted upon closure, linked from the privacy policy.
  • custodians_or_mirrors: No custodians, mirrors, or archive partners are identified anywhere on the page.
    Fix: Name specific archive partners or custodians (e.g., a national web archive or repository) that would maintain access to content if the organisation exited.
  • policy_exists: The page is a business and enterprise landing page with no published policy on worker wellbeing or working conditions.
    Fix: Publish a dedicated worker wellbeing or working conditions policy and link to it from this page.
  • specific_commitments: The page contains no specific commitments regarding pay, hours, mental health, or benefits.
    Fix: Add concrete commitments covering fair pay, working hours, mental health support, and employee benefits.
  • accountability: The page identifies no accountability or oversight body responsible for worker conditions.
    Fix: Name a responsible team or officer and describe the oversight process for monitoring worker conditions.