University of St Andrews
https://www.st-andrews.ac.uk · 44/92 checks passed · higher_education
Compliance report (framework 0.8)
Gate passed (every Core check must pass) · not counted towards the gate: paused 35, draft 48, ready for review 54.
Site level: 0 (no scored checks yet).
By level
| Level | Result |
|---|---|
| Level 1 — Basic | 26/37 (11 failed) |
| Level 2 — Enhanced | 8/27 (15 failed) |
| Level 3 — Advanced | 0/10 (9 failed) |
By category
| Category | Result |
|---|---|
| Accessibility | 9/13 |
| Accountability | 0/5 |
| AI & Automation | 3/8 |
| Interoperability | 2/3 |
| Privacy | 9/16 |
| Provenance | 1/2 |
| Security | 6/11 |
| Transparency | 4/13 |
| Responsibility to the Future | 0/3 |
Level 1 — Basic
Accessibility
- 1 WCAG 2.1 Level A violation reported by axe-core: aria-valid-attr-value.
- 1 WCAG 2.1 Level A violation reported by axe-core: aria-valid-attr-value.
- Heading hierarchy issues: h2 -> h4 (skipped h3).
AI & Automation
-
policy_exists: The About page contains no AI use policy or statement anywhere in its content or footer links.
Fix: Publish a dedicated AI use policy page and link to it from the About section and site footer.
-
scope_clear: With no AI policy present, there is no explanation of what AI is used for on the page.
Fix: Include a clear scope section describing where and how AI is used across University services and communications.
- Not found at any of: /ai-policy, /ai.
Privacy
- 1 hidden iframe found: https://www.youtube-nocookie.com/embed/FHdjbkLaVAU?rel=0.
- Detected 4 data-leaking services across 2 categories: google fonts (fonts.gstatic.com); youtube embed (i.ytimg.com, www.youtube-nocookie.com, www.youtube.com).
PASS
Session cookies only
PASS
No tracking pixels
Security
- Redirect chain (1 hops): https://www.st-andrews.ac.uk
- x-frame-options: header not set on the response.
- referrer-policy: header not set on the response.
PASS
HTTPS enforced
PASS
No mixed content
Transparency
-
disclosure_exists: The page contains no funding or sponsorship disclosure; it only mentions financial statements as a link without detailing funding sources.
Fix: Add a clear funding/sponsorship disclosure section on the About page summarizing the University's main funding sources.
-
transparent: No funding sources are identified anywhere in the visible page content.
Fix: Explicitly list key funding streams (e.g., tuition, government grants, research councils, donations) with links to supporting documentation.
PASS
Contact form present
Level 2 — Enhanced
Accessibility
Accountability
-
named_person: The page lists generic teams (Student Services, Estates, IT service desk) but does not identify any named individual or specific role accountable for the contact function.
Fix: Add the name or at least the specific job title of the person or office head responsible for handling general enquiries and University contact.
-
response_timeframe: The page states hours of operation and mentions a call-back for out-of-hours calls but does not publish any response timeframe for enquiries or complaints.
Fix: Publish an explicit expected response timeframe (e.g., 'we respond to enquiries within 5 working days') on the contact page.
-
specific: No specific timeframe in days or hours is given; the page only vaguely says a staff member 'will then call you back'.
Fix: Replace vague phrasing with a concrete timeframe such as '24 hours' or '5 business days' for each contact channel.
-
process_exists: The contact page lists phone numbers and a 'Report and support' tool for wellbeing/harassment but does not link to or document a general complaints or feedback process.
Fix: Add a clearly labelled link to a formal complaints and feedback procedure (e.g., 'How to make a complaint') from the contact page.
-
steps_clear: Because no complaints process is presented on the page, the steps for submitting a complaint are not articulated.
Fix: Include a numbered list of steps (e.g., submit form, acknowledgement, investigation, response) so users know exactly how to file and track a complaint.
-
appeals_exists: The contact page lists general contacts and reporting tools but does not document any appeals process.
Fix: Add a clearly labeled section or link describing how individuals can formally appeal decisions, including steps, timelines, and contact points.
-
independent: No appeals process is described, so there is no indication of independent review or escalation pathways.
Fix: Document an escalation route to an independent reviewer or ombudsperson for appeals, distinct from the original decision-maker.
AI & Automation
-
detailed_scope: The page does not mention AI at all, so no detailed scope of AI use is provided.
Fix: Add an AI policy detailing specific use cases, systems, and contexts where AI is deployed by the University.
-
limitations: No AI limitations are acknowledged because the page contains no AI-related content.
Fix: Include a section in the AI policy that transparently acknowledges known limitations and risks of the AI systems used.
-
safeguards: There is no description of AI safeguards or quality controls since no AI policy is present.
Fix: Document the governance, human oversight, and quality-control safeguards applied to AI use in a published policy.
-
marking_policy: The About page contains no policy or statement regarding the marking of AI-assisted content.
Fix: Publish a clear policy on the site (linked from About or Policies) that defines how AI-assisted content is labelled and disclosed.
-
consistent: Without any AI marking policy visible, there is no evidence that AI content marking is applied consistently across the page.
Fix: Adopt a standard AI-content label and apply it consistently to any AI-generated or AI-assisted text, images, or media on the site.
-
oversight_exists: The page makes no mention of human oversight of AI outputs.
Fix: Add a statement (e.g., in governance or policies) documenting that AI outputs used by the University are subject to human oversight.
-
review_process: No review or approval process for AI-generated content is described on the page.
Fix: Document and publish the review/approval workflow used before AI-generated content is published.
-
accountability: No individual, role, or office is named as accountable for AI-generated content.
Fix: Identify and publish a named role or office (e.g., within Professional Services or Governance) accountable for AI-generated content.
Interoperability
Privacy
-
banner_present: No cookie or consent banner is visible on the page content; only a 'Cookie preferences' link appears in the footer.
Fix: Implement a visible cookie consent banner that appears on first visit to allow users to accept or reject cookies before tracking begins.
-
partner_sharing_mentioned: There is no on-page consent copy or banner disclosing any data sharing with third-party partners.
Fix: Add explicit disclosure within the cookie banner listing categories of third parties (e.g., analytics, social media) with whom data is shared.
-
partner_count_specific: No banner or consent copy is present, so no specific numeric count of partners is stated.
Fix: Include a specific number of third-party partners (e.g., 'We share data with X partners') in the cookie banner and link to a full list.
SKIPPED
Human-readable privacy policy
Skipped: Target page not found in captured content
SKIPPED
Plain language data practices
Skipped: Target page not found in captured content
Skipped: Target page not found in captured content
SKIPPED
Published data retention periods
Skipped: Target page not found in captured content
Provenance
- No author or date metadata found on the page.
Security
Transparency
-
named_person: No named individual or specific team is identified for enquiries; only a general University phone number and address are provided.
Fix: Identify the specific team (e.g., 'Communications Office' or 'Main Reception') or named contact responsible for handling general enquiries.
-
role_clear: Because no specific person or team is named for general enquiries, their role and authority are not stated.
Fix: Clearly state the role and remit of the contact team (e.g., 'The Reception team handles general enquiries and directs callers to the appropriate department').
-
mission_clear: While the page references a strategy and annual review, it does not explicitly articulate the University's mission or educational/research purpose on the page itself.
Fix: Add a concise mission statement summarising the University's educational and research purpose directly on the about page, or link prominently to the strategy document.
-
detail: The page provides no amounts, percentages, or categories describing funding.
Fix: Include a breakdown of funding by category with amounts or percentages, or link prominently to a summary drawn from the financial statements.
-
complete: Since no funding streams are disclosed, coverage of major streams cannot be established.
Fix: Publish a comprehensive disclosure covering all major funding streams such as tuition fees, research grants, endowments, donations, and public funding.
-
roles_clear: While the page references professional services and governing bodies, it does not identify specific key roles or responsibilities on this page itself.
Fix: Add a brief summary or list on the About page naming the key governing bodies (e.g., Court, Senate, Principal) and their responsibilities, or link directly to a roles/responsibilities page.
-
algorithm_explained: The About page contains no mention of any algorithms or automated decision-making systems used by the University.
Fix: Add a dedicated section or link disclosing any algorithmic systems in use (e.g., admissions, search, recommendations) and explaining their purpose.
-
impact_clear: There is no description of how algorithmic decisions affect users such as applicants, students, or staff.
Fix: Publish a clear statement describing who is affected by algorithmic decisions and what outcomes those decisions influence.
-
annual_statement: The page shows no evidence of a regular or annual review of data practices, only a generic cookie/accessibility footer link.
Fix: Publish a periodic (e.g., annual) data practices review statement and link to it from the footer alongside the privacy and cookie links.
-
dated: No data practices statement with a visible date or version number is present on the page.
Fix: Add a clearly dated or versioned privacy/data practices statement (e.g., 'Last updated: [date]') accessible from the footer.
Level 3 — Advanced
Accessibility
-
known_issues: The provided page content only shows a link to an accessibility statement and does not include any acknowledgment of known accessibility issues or limitations.
Fix: Ensure the linked accessibility statement lists specific known issues or non-compliant areas of the site.
-
remediation_timeline: There is no timeline or commitment to fixing accessibility issues visible on this page.
Fix: Add a clear timeline or commitment for remediating known accessibility issues within the accessibility statement.
-
feedback_channel: The page provides only a general phone number and address but no dedicated accessibility feedback mechanism with a response commitment.
Fix: Include a specific accessibility feedback channel (e.g., dedicated email or form) and a stated response time in the accessibility statement.
Accountability
-
policy_exists: The terms page lists general terms but does not publish a moderation policy for user-generated or community content.
Fix: Publish a dedicated moderation policy covering user-generated content such as personal pages, comments, and forums.
-
criteria_clear: No moderation criteria (e.g., what content is prohibited or reviewed) are stated on this page.
Fix: Add explicit criteria listing prohibited content types and the standards used to evaluate submissions.
-
enforcement: The page does not explain how moderation decisions are enforced, appealed, or actioned against violators.
Fix: Describe the enforcement workflow, including who reviews content, possible sanctions, and how users can appeal decisions.
Interoperability
- Not found at: /status
Security
-
plan_exists: The About page contains only institutional overview, governance, and visitor information with no published incident response plan or security policy.
Fix: Publish a security incident response plan or policy and link to it from the site, for example under Governance or Policies, procedures and guidance.
-
notification_commitment: The page makes no commitment to publicly notify users about significant security or data incidents.
Fix: Add an explicit commitment to notify affected users and the public when a significant incident occurs, within the incident response documentation.
-
timeframe: No timeframe for disclosing incidents to affected users is stated anywhere on the page.
Fix: State a specific disclosure timeframe (e.g., notification within 72 hours of detecting a breach) in the published incident response policy.
Skipped: Target page not found in captured content
Transparency
-
criteria_published: The page does not publish any criteria used in algorithmic decision-making.
Fix: Publish the specific input criteria and data fields used by any algorithmic decision systems on a transparency or governance page.
-
weighting: No information is given about how criteria are weighted or prioritised in any decision process.
Fix: Include documentation describing the relative weighting, priority, or scoring logic applied to each criterion.
-
auditable: The page provides no technical or procedural detail that would allow external audit or review of algorithmic systems.
Fix: Publish an algorithmic transparency record (e.g., following the UK ATRS standard) with sufficient detail for independent audit.
-
open_source: There is no link to source code or any open-source repository for the website on the page.
Fix: Add a link in the footer or website help section to a public code repository (e.g., GitHub) if any site components are open source.
-
tech_docs: No technical documentation about the website's platform, APIs, or data is referenced on the page.
Fix: Publish and link to technical documentation such as API references, data schemas, or a developer portal from the about or website help section.
Responsibility to the Future
-
specific_metrics: The page states a net zero target and qualitative goals but contains no specific figures for carbon, energy use, or emissions.
Fix: Add quantified metrics such as current annual carbon emissions, energy consumption, and progress-to-target figures directly on the page or clearly linked from it.
-
hosting_disclosure: There is no mention of the carbon or energy profile of the website's hosting infrastructure anywhere on the page.
Fix: Publish a statement on the site's hosting carbon/energy profile, e.g. green hosting provider details or measured page/site emissions.
-
plan_exists: The About page describes governance, strategy, and history but contains no published plan for what happens if the organisation fails or exits.
Fix: Publish a succession or continuity plan section outlining what would happen to the institution's services and assets in the event of closure or major disruption.
-
data_and_content_fate: The page makes no mention of what would happen to user data or published content should the University cease operations.
Fix: Add explicit statements describing how user data and published content would be preserved, transferred, or deleted in a wind-down scenario.
-
custodians_or_mirrors: No custodians, mirrors, or archive partners are identified anywhere on the page.
Fix: Name specific archive partners, custodians, or mirror arrangements (e.g., a national archive) that would take responsibility for content upon exit.
-
policy_exists: The page is a Careers Centre landing page for students and employers with no published policy on worker wellbeing or working conditions.
Fix: Publish a dedicated worker wellbeing or working conditions policy and link to it from the page.
-
specific_commitments: The content contains no specific commitments regarding pay, hours, mental health, or benefits for workers.
Fix: Add explicit commitments covering pay standards, working hours, mental health support, and staff benefits.
-
accountability: The page names only general contact details and identifies no accountable owner or oversight body for worker conditions.
Fix: Name a responsible role or oversight committee accountable for monitoring and reporting on worker conditions.