University of Manchester

https://www.manchester.ac.uk · 54/92 checks passed · higher_education

Compliance report (framework 0.8)

Gate passed (every Core check must pass) · not counted towards the gate: paused 35, draft 48, ready for review 54.

Site level: 0 (no scored checks yet).

By level

LevelResult
Level 1 — Basic 33/37 (4 failed)
Level 2 — Enhanced 8/27 (19 failed)
Level 3 — Advanced 0/10 (9 failed)

By category

CategoryResult
Accessibility 12/13
Accountability 0/5
AI & Automation 4/8
Interoperability 1/3
Privacy 10/16
Provenance 1/2
Security 7/11
Transparency 6/13
Responsibility to the Future 0/3

Level 1 — Basic

Accessibility

AI & Automation

  • policy_exists: The page describes AI research activities but contains no AI use policy or governance statement.
    Fix: Publish a clear AI use policy or statement on this page (or link to one) outlining principles governing AI use at the institution.
  • scope_clear: The page mentions 'responsibly and ethically' applied AI but does not explain specifically what AI is used for in a policy sense.
    Fix: Add a dedicated section explaining the concrete scope of AI use cases covered by the policy (e.g., research, teaching, administration).

Privacy

Security

Transparency

Level 2 — Enhanced

Accessibility

Accountability

  • named_person: The page lists generic categories (e.g., 'Media enquiries', 'Campus security') but does not name any specific individual or role responsible for handling contact.
    Fix: Add named individuals or specific role titles (e.g., 'Head of Communications — Jane Smith') accountable for each enquiry category.
  • response_timeframe: The contact page lists phone numbers and contact categories but does not publish any expected response timeframes for enquiries.
    Fix: Add a clear statement of expected response times (e.g., 'We aim to respond within 5 working days') on the contact page.
  • specific: Since no timeframes are published at all, there are no specific day-based timeframes provided.
    Fix: Specify concrete response windows in days or working days for each enquiry channel rather than vague language.
  • process_exists: The page references 'Enquiries or concerns about students' and general contact routes but does not document a formal complaints or feedback process.
    Fix: Add a dedicated complaints/feedback procedure page (or link) explaining how to submit, escalate, and track a complaint.
  • steps_clear: No step-by-step instructions for lodging a complaint are visible on the page content provided.
    Fix: Publish clear numbered steps (e.g., Step 1: submit form, Step 2: acknowledgement, Step 3: investigation, Step 4: outcome) for the complaints process.
  • appeals_exists: The contact page lists enquiry channels and an FAQ but does not document any appeals process.
    Fix: Add a dedicated section or linked page describing how users can formally appeal decisions, including steps and timelines.
  • independent: No appeals process is described, so there is no indication of independent review or escalation path.
    Fix: Document an escalation route to an independent body or ombudsperson (e.g., OIA) for unresolved complaints and appeals.

AI & Automation

  • detailed_scope: No detailed scope of AI use is provided; the content is promotional about research capacity rather than policy detail.
    Fix: Include a detailed scope section in the AI policy covering domains, user groups, and types of AI systems in use.
  • limitations: The page does not acknowledge any limitations of AI systems, only promoting capabilities and partnerships.
    Fix: Add an explicit subsection acknowledging AI limitations such as bias, hallucination, data quality, and contexts where AI should not be used.
  • safeguards: Beyond a brief mention of 'responsibly and ethically', no specific safeguards or quality controls are described.
    Fix: Describe concrete safeguards such as human oversight, ethical review processes, auditing, and quality assurance measures governing AI use.
  • marking_policy: The page contains no policy or statement about how AI-assisted content is marked or labelled.
    Fix: Publish a clear policy describing how AI-assisted content on the site is identified and labelled.
  • consistent: Without a marking policy, there is no evidence that AI content marking is applied consistently across the page.
    Fix: Adopt a standard AI-content label and apply it uniformly to any AI-generated or AI-assisted text, images or media.
  • oversight_exists: The page mentions 'responsibly and ethically' in passing but does not document any human oversight process for AI outputs.
    Fix: Add a statement describing how humans review and oversee AI-generated outputs before publication or use.
  • review_process: No review or approval workflow for AI-generated content is described anywhere on the page.
    Fix: Document the specific review/approval steps AI-generated content must pass through before going live.
  • accountability: No named role, team or contact is identified as accountable for AI-generated content on this page.
    Fix: Name a responsible owner (e.g. an editorial lead or AI governance contact) accountable for AI-generated content and provide their contact details.

Interoperability

Privacy

  • comprehensive: This landing page only summarises and links out; it does not itself detail specific data categories collected or the full purposes of processing.
    Fix: Include a concise summary on this page listing the key categories of data collected and the specific purposes, or surface that content directly rather than only linking to sub-pages.
  • understandable: A non-expert cannot tell from this page exactly what data is collected or why, as specifics are deferred to linked privacy notices.
    Fix: Add a short plain-English summary on this page describing the main types of data collected and the reasons, before directing users to detailed notices.
  • retention_stated: The page mentions retaining data securely but does not state any retention periods on this page.
    Fix: Add a retention section (or clear link to a retention schedule) stating how long different categories of personal data are kept.
  • specific: No specific retention durations or timeframes are provided anywhere in the visible content.
    Fix: Publish specific retention periods (e.g., "student records kept for X years after graduation") either on this page or in a clearly linked retention schedule.
  • banner_present: The page content shows no visible cookie or consent banner text.
    Fix: Implement a visible cookie consent banner on page load that complies with UK GDPR/PECR requirements.
  • partner_sharing_mentioned: There is no on-page copy disclosing data sharing with third-party partners.
    Fix: Add explicit disclosure in the consent banner listing categories of third-party partners with whom data is shared.
  • partner_count_specific: No partner sharing is disclosed, so no specific numeric count of partners is stated.
    Fix: Include an exact number of third-party partners (e.g., 'We share data with X partners') within the consent banner or a linked preferences panel.

Provenance

Security

Transparency

  • named_person: No named individual or specific team is identified for enquiries—only generic categories and a central switchboard number are shown.
    Fix: Identify the team or office (e.g., 'Student Services Team' or 'Communications Office') and, where possible, a named contact for each enquiry type.
  • role_clear: While enquiry topics are listed, the role, authority, or remit of the people/teams behind them is not described.
    Fix: Add a short description beside each contact option explaining the team's role and the scope of issues they are authorised to handle.
  • detail: The disclosure only lists broad categories and vaguely states the University 'invests substantially' without providing any amounts, percentages, or specific figures.
    Fix: Add concrete figures such as annual doctoral funding totals, number of studentships funded, or percentage breakdowns by source (e.g., research councils vs. industry).
  • complete: While major external categories are mentioned, the page does not comprehensively cover all funding streams such as government loans, specific scholarship schemes, or self-funded proportions in the disclosure itself.
    Fix: Expand the disclosure to enumerate all major funding streams, including postgraduate loans, the President's Doctoral Scholar Award, CDT funding, and self-funded routes with their relative scale.
  • roles_clear: The page itself does not identify key roles or responsibilities of leadership or editorial staff, only linking generically to 'People' and 'Structure'.
    Fix: Add a summary on the About page naming key roles (e.g., President, Vice-Chancellor, Board of Governors) with their responsibilities or link directly to role descriptions.
  • algorithm_explained: The About page describes the university's mission and achievements but makes no mention of any algorithms or their purpose.
    Fix: Add a section (or link to a dedicated page) explaining any algorithms used by the university in decision-making, such as admissions or student services, and their intended purpose.
  • impact_clear: There is no description of how algorithmic decisions might affect users such as applicants, students, or staff.
    Fix: Publish a clear statement outlining how algorithmic decisions impact users and what recourse or review options are available.
  • annual_statement: The page links to 'Privacy and information governance' but provides no evidence on this page of an annual or periodic review of data practices.
    Fix: Add a statement (or visible note on the linked privacy page) indicating that data practices are reviewed annually, including the date of the last review.
  • dated: There is no visible date or version number associated with any data practices or privacy statement on this page.
    Fix: Include a 'Last updated' date or version number next to the privacy/information governance link or statement.

Level 3 — Advanced

Accessibility

  • remediation_timeline: The statement says it is 'working to fix these issues' and has an 'ongoing programme of work' but provides no specific dates or timeline for resolving the known issues.
    Fix: Add target dates or a scheduled review timeline for resolving each listed non-compliant issue so users know when fixes are expected.

Accountability

  • policy_exists: The About page contains no published moderation policy or link to one.
    Fix: Publish a clearly linked moderation policy covering user-generated content and community interactions on the site.
  • criteria_clear: No moderation criteria (what is allowed or prohibited) are stated anywhere on the page.
    Fix: Document explicit moderation criteria outlining acceptable and prohibited content with examples.
  • enforcement: The page does not describe any enforcement process, appeals, or responsible party for moderation.
    Fix: Add an enforcement section detailing how violations are reviewed, actions taken, and how users can appeal decisions.

Interoperability

Security

  • plan_exists: The About page contains only institutional overview and links to governance/privacy but shows no published incident response plan or policy.
    Fix: Publish a dedicated incident response plan or policy page and link to it from the site's governance or privacy sections.
  • notification_commitment: The page makes no commitment to publicly notify users of significant security or data incidents.
    Fix: Add an explicit statement committing to notify affected users and the public in the event of a significant incident.
  • timeframe: No timeframe for disclosing incidents to affected users is stated anywhere on the page.
    Fix: Specify a concrete disclosure timeframe (e.g., notification within 72 hours of discovering a breach) in the incident response policy.

Transparency

  • criteria_published: No criteria for any algorithmic decisions are published anywhere on the About page.
    Fix: Create and link to a transparency page that lists the specific criteria used in any automated or algorithmic decision-making processes.
  • weighting: The page provides no information about weightings or prioritisation of criteria in algorithmic decisions.
    Fix: Document and publish the relative weighting or priority assigned to each criterion used in algorithmic decisions.
  • auditable: The page offers no technical or procedural detail that would enable external audit or independent review of any algorithms.
    Fix: Provide sufficient methodological detail, data sources, and contact routes for independent auditors to review the university's algorithmic systems.
  • open_source: The page contains no links to source code repositories for the website or the university's digital infrastructure.
    Fix: Add a link to a public code repository (e.g., GitHub/GitLab) for the university's open-source projects or website codebase.
  • tech_docs: No technical documentation about the site, APIs, or data formats is linked from the about page.
    Fix: Publish and link to technical documentation such as API references, developer docs, or a technology/data transparency page.

Responsibility to the Future

  • specific_metrics: The page states a target of 'zero direct carbon emissions by 2038' but provides no specific current figures for carbon, energy use, or emissions on the page itself.
    Fix: Add concrete quantitative data (e.g., current annual carbon emissions, energy consumption figures, and year-on-year progress) directly on the page or in a clearly linked performance report.
  • hosting_disclosure: The page makes no mention of the carbon or energy profile of the website's hosting infrastructure.
    Fix: Add a statement disclosing the hosting provider's energy sourcing or carbon footprint, ideally confirming use of renewable-powered or green-certified hosting.
  • plan_exists: The governance page describes committees and decision-making but contains no published plan for what happens if the organisation fails or exits.
    Fix: Publish a continuity or wind-down plan describing the steps and responsibilities that apply if the University ceases operations or exits key services.
  • data_and_content_fate: The page makes no reference to what would happen to user data or published content in the event of failure or exit.
    Fix: Add a section specifying how user data and published content would be preserved, transferred, or deleted if the organisation fails or exits.
  • custodians_or_mirrors: No custodians, mirrors, or archive partners are named anywhere in the governance content.
    Fix: Identify and publish named custodians, mirror hosts, or archive partners responsible for safeguarding data and content after an exit.
  • policy_exists: The page is a university Careers Service homepage offering student career support and contains no published policy on worker wellbeing or working conditions.
    Fix: Publish a dedicated worker wellbeing or working conditions policy and link to it from the site.
  • specific_commitments: There are no specific commitments on pay, hours, mental health, or benefits anywhere in the content.
    Fix: Add concrete, measurable commitments covering pay, working hours, mental health support, and employee benefits.
  • accountability: The page names no individual, role, or body responsible for overseeing worker conditions.
    Fix: Designate and publicly name an owner or oversight body accountable for worker wellbeing and conditions.