University of Manchester
https://www.manchester.ac.uk · 54/92 checks passed · higher_education
Compliance report (framework 0.8)
Gate passed (every Core check must pass) · not counted towards the gate: paused 35, draft 48, ready for review 54.
Site level: 0 (no scored checks yet).
By level
| Level | Result |
|---|---|
| Level 1 — Basic | 33/37 (4 failed) |
| Level 2 — Enhanced | 8/27 (19 failed) |
| Level 3 — Advanced | 0/10 (9 failed) |
By category
| Category | Result |
|---|---|
| Accessibility | 12/13 |
| Accountability | 0/5 |
| AI & Automation | 4/8 |
| Interoperability | 1/3 |
| Privacy | 10/16 |
| Provenance | 1/2 |
| Security | 7/11 |
| Transparency | 6/13 |
| Responsibility to the Future | 0/3 |
Level 1 — Basic
Accessibility
AI & Automation
-
policy_exists: The page describes AI research activities but contains no AI use policy or governance statement.
Fix: Publish a clear AI use policy or statement on this page (or link to one) outlining principles governing AI use at the institution.
-
scope_clear: The page mentions 'responsibly and ethically' applied AI but does not explain specifically what AI is used for in a policy sense.
Fix: Add a dedicated section explaining the concrete scope of AI use cases covered by the policy (e.g., research, teaching, administration).
Privacy
- 5 hidden iframes found: https://www.youtube-nocookie.com/embed/lrF1RLGpgak?enablejsapi=1, https://www.youtube-nocookie.com/embed/9IVMuB-BCAg?enablejsapi=1, https://www.youtube-nocookie.com/embed/8tuctFFG88g?enablejsapi=1, https://www.youtube-nocookie.com/embed/xVtOxrSdaNE?enablejsapi=1, https://www.youtube-nocookie.com/embed/3gutk0X0k4Y?enablejsapi=1.
- Detected 5 data-leaking services across 2 categories: google fonts (fonts.googleapis.com, fonts.gstatic.com); youtube embed (i.ytimg.com, www.youtube-nocookie.com, www.youtube.com).
PASS
Session cookies only
PASS
No tracking pixels
Security
- Redirect chain (1 hops): https://www.manchester.ac.uk
PASS
HTTPS enforced
PASS
No mixed content
Transparency
PASS
Contact form present
Level 2 — Enhanced
Accessibility
Accountability
-
named_person: The page lists generic categories (e.g., 'Media enquiries', 'Campus security') but does not name any specific individual or role responsible for handling contact.
Fix: Add named individuals or specific role titles (e.g., 'Head of Communications — Jane Smith') accountable for each enquiry category.
-
response_timeframe: The contact page lists phone numbers and contact categories but does not publish any expected response timeframes for enquiries.
Fix: Add a clear statement of expected response times (e.g., 'We aim to respond within 5 working days') on the contact page.
-
specific: Since no timeframes are published at all, there are no specific day-based timeframes provided.
Fix: Specify concrete response windows in days or working days for each enquiry channel rather than vague language.
-
process_exists: The page references 'Enquiries or concerns about students' and general contact routes but does not document a formal complaints or feedback process.
Fix: Add a dedicated complaints/feedback procedure page (or link) explaining how to submit, escalate, and track a complaint.
-
steps_clear: No step-by-step instructions for lodging a complaint are visible on the page content provided.
Fix: Publish clear numbered steps (e.g., Step 1: submit form, Step 2: acknowledgement, Step 3: investigation, Step 4: outcome) for the complaints process.
-
appeals_exists: The contact page lists enquiry channels and an FAQ but does not document any appeals process.
Fix: Add a dedicated section or linked page describing how users can formally appeal decisions, including steps and timelines.
-
independent: No appeals process is described, so there is no indication of independent review or escalation path.
Fix: Document an escalation route to an independent body or ombudsperson (e.g., OIA) for unresolved complaints and appeals.
AI & Automation
-
detailed_scope: No detailed scope of AI use is provided; the content is promotional about research capacity rather than policy detail.
Fix: Include a detailed scope section in the AI policy covering domains, user groups, and types of AI systems in use.
-
limitations: The page does not acknowledge any limitations of AI systems, only promoting capabilities and partnerships.
Fix: Add an explicit subsection acknowledging AI limitations such as bias, hallucination, data quality, and contexts where AI should not be used.
-
safeguards: Beyond a brief mention of 'responsibly and ethically', no specific safeguards or quality controls are described.
Fix: Describe concrete safeguards such as human oversight, ethical review processes, auditing, and quality assurance measures governing AI use.
-
marking_policy: The page contains no policy or statement about how AI-assisted content is marked or labelled.
Fix: Publish a clear policy describing how AI-assisted content on the site is identified and labelled.
-
consistent: Without a marking policy, there is no evidence that AI content marking is applied consistently across the page.
Fix: Adopt a standard AI-content label and apply it uniformly to any AI-generated or AI-assisted text, images or media.
-
oversight_exists: The page mentions 'responsibly and ethically' in passing but does not document any human oversight process for AI outputs.
Fix: Add a statement describing how humans review and oversee AI-generated outputs before publication or use.
-
review_process: No review or approval workflow for AI-generated content is described anywhere on the page.
Fix: Document the specific review/approval steps AI-generated content must pass through before going live.
-
accountability: No named role, team or contact is identified as accountable for AI-generated content on this page.
Fix: Name a responsible owner (e.g. an editorial lead or AI governance contact) accountable for AI-generated content and provide their contact details.
Interoperability
- No RSS/Atom feeds discovered.
Privacy
-
comprehensive: This landing page only summarises and links out; it does not itself detail specific data categories collected or the full purposes of processing.
Fix: Include a concise summary on this page listing the key categories of data collected and the specific purposes, or surface that content directly rather than only linking to sub-pages.
-
understandable: A non-expert cannot tell from this page exactly what data is collected or why, as specifics are deferred to linked privacy notices.
Fix: Add a short plain-English summary on this page describing the main types of data collected and the reasons, before directing users to detailed notices.
-
retention_stated: The page mentions retaining data securely but does not state any retention periods on this page.
Fix: Add a retention section (or clear link to a retention schedule) stating how long different categories of personal data are kept.
-
specific: No specific retention durations or timeframes are provided anywhere in the visible content.
Fix: Publish specific retention periods (e.g., "student records kept for X years after graduation") either on this page or in a clearly linked retention schedule.
-
banner_present: The page content shows no visible cookie or consent banner text.
Fix: Implement a visible cookie consent banner on page load that complies with UK GDPR/PECR requirements.
-
partner_sharing_mentioned: There is no on-page copy disclosing data sharing with third-party partners.
Fix: Add explicit disclosure in the consent banner listing categories of third-party partners with whom data is shared.
-
partner_count_specific: No partner sharing is disclosed, so no specific numeric count of partners is stated.
Fix: Include an exact number of third-party partners (e.g., 'We share data with X partners') within the consent banner or a linked preferences panel.
Provenance
- No author or date metadata found on the page.
Security
- security.txt not published.
Transparency
-
named_person: No named individual or specific team is identified for enquiries—only generic categories and a central switchboard number are shown.
Fix: Identify the team or office (e.g., 'Student Services Team' or 'Communications Office') and, where possible, a named contact for each enquiry type.
-
role_clear: While enquiry topics are listed, the role, authority, or remit of the people/teams behind them is not described.
Fix: Add a short description beside each contact option explaining the team's role and the scope of issues they are authorised to handle.
-
detail: The disclosure only lists broad categories and vaguely states the University 'invests substantially' without providing any amounts, percentages, or specific figures.
Fix: Add concrete figures such as annual doctoral funding totals, number of studentships funded, or percentage breakdowns by source (e.g., research councils vs. industry).
-
complete: While major external categories are mentioned, the page does not comprehensively cover all funding streams such as government loans, specific scholarship schemes, or self-funded proportions in the disclosure itself.
Fix: Expand the disclosure to enumerate all major funding streams, including postgraduate loans, the President's Doctoral Scholar Award, CDT funding, and self-funded routes with their relative scale.
-
roles_clear: The page itself does not identify key roles or responsibilities of leadership or editorial staff, only linking generically to 'People' and 'Structure'.
Fix: Add a summary on the About page naming key roles (e.g., President, Vice-Chancellor, Board of Governors) with their responsibilities or link directly to role descriptions.
-
algorithm_explained: The About page describes the university's mission and achievements but makes no mention of any algorithms or their purpose.
Fix: Add a section (or link to a dedicated page) explaining any algorithms used by the university in decision-making, such as admissions or student services, and their intended purpose.
-
impact_clear: There is no description of how algorithmic decisions might affect users such as applicants, students, or staff.
Fix: Publish a clear statement outlining how algorithmic decisions impact users and what recourse or review options are available.
-
annual_statement: The page links to 'Privacy and information governance' but provides no evidence on this page of an annual or periodic review of data practices.
Fix: Add a statement (or visible note on the linked privacy page) indicating that data practices are reviewed annually, including the date of the last review.
-
dated: There is no visible date or version number associated with any data practices or privacy statement on this page.
Fix: Include a 'Last updated' date or version number next to the privacy/information governance link or statement.
Level 3 — Advanced
Accessibility
-
remediation_timeline: The statement says it is 'working to fix these issues' and has an 'ongoing programme of work' but provides no specific dates or timeline for resolving the known issues.
Fix: Add target dates or a scheduled review timeline for resolving each listed non-compliant issue so users know when fixes are expected.
Accountability
-
policy_exists: The About page contains no published moderation policy or link to one.
Fix: Publish a clearly linked moderation policy covering user-generated content and community interactions on the site.
-
criteria_clear: No moderation criteria (what is allowed or prohibited) are stated anywhere on the page.
Fix: Document explicit moderation criteria outlining acceptable and prohibited content with examples.
-
enforcement: The page does not describe any enforcement process, appeals, or responsible party for moderation.
Fix: Add an enforcement section detailing how violations are reviewed, actions taken, and how users can appeal decisions.
Interoperability
- Not found at: /status
Security
-
plan_exists: The About page contains only institutional overview and links to governance/privacy but shows no published incident response plan or policy.
Fix: Publish a dedicated incident response plan or policy page and link to it from the site's governance or privacy sections.
-
notification_commitment: The page makes no commitment to publicly notify users of significant security or data incidents.
Fix: Add an explicit statement committing to notify affected users and the public in the event of a significant incident.
-
timeframe: No timeframe for disclosing incidents to affected users is stated anywhere on the page.
Fix: Specify a concrete disclosure timeframe (e.g., notification within 72 hours of discovering a breach) in the incident response policy.
Skipped: Target page not found in captured content
Transparency
-
criteria_published: No criteria for any algorithmic decisions are published anywhere on the About page.
Fix: Create and link to a transparency page that lists the specific criteria used in any automated or algorithmic decision-making processes.
-
weighting: The page provides no information about weightings or prioritisation of criteria in algorithmic decisions.
Fix: Document and publish the relative weighting or priority assigned to each criterion used in algorithmic decisions.
-
auditable: The page offers no technical or procedural detail that would enable external audit or independent review of any algorithms.
Fix: Provide sufficient methodological detail, data sources, and contact routes for independent auditors to review the university's algorithmic systems.
-
open_source: The page contains no links to source code repositories for the website or the university's digital infrastructure.
Fix: Add a link to a public code repository (e.g., GitHub/GitLab) for the university's open-source projects or website codebase.
-
tech_docs: No technical documentation about the site, APIs, or data formats is linked from the about page.
Fix: Publish and link to technical documentation such as API references, developer docs, or a technology/data transparency page.
Responsibility to the Future
-
specific_metrics: The page states a target of 'zero direct carbon emissions by 2038' but provides no specific current figures for carbon, energy use, or emissions on the page itself.
Fix: Add concrete quantitative data (e.g., current annual carbon emissions, energy consumption figures, and year-on-year progress) directly on the page or in a clearly linked performance report.
-
hosting_disclosure: The page makes no mention of the carbon or energy profile of the website's hosting infrastructure.
Fix: Add a statement disclosing the hosting provider's energy sourcing or carbon footprint, ideally confirming use of renewable-powered or green-certified hosting.
-
plan_exists: The governance page describes committees and decision-making but contains no published plan for what happens if the organisation fails or exits.
Fix: Publish a continuity or wind-down plan describing the steps and responsibilities that apply if the University ceases operations or exits key services.
-
data_and_content_fate: The page makes no reference to what would happen to user data or published content in the event of failure or exit.
Fix: Add a section specifying how user data and published content would be preserved, transferred, or deleted if the organisation fails or exits.
-
custodians_or_mirrors: No custodians, mirrors, or archive partners are named anywhere in the governance content.
Fix: Identify and publish named custodians, mirror hosts, or archive partners responsible for safeguarding data and content after an exit.
-
policy_exists: The page is a university Careers Service homepage offering student career support and contains no published policy on worker wellbeing or working conditions.
Fix: Publish a dedicated worker wellbeing or working conditions policy and link to it from the site.
-
specific_commitments: There are no specific commitments on pay, hours, mental health, or benefits anywhere in the content.
Fix: Add concrete, measurable commitments covering pay, working hours, mental health support, and employee benefits.
-
accountability: The page names no individual, role, or body responsible for overseeing worker conditions.
Fix: Designate and publicly name an owner or oversight body accountable for worker wellbeing and conditions.