University of St Andrews

https://www.st-andrews.ac.uk · 44/92 checks passed · higher_education

Compliance report (framework 0.8)

Gate passed (every Core check must pass) · not counted towards the gate: paused 35, draft 48, ready for review 54.

Site level: 0 (no scored checks yet).

By level

LevelResult
Level 1 — Basic 26/37 (11 failed)
Level 2 — Enhanced 8/27 (15 failed)
Level 3 — Advanced 0/10 (9 failed)

By category

CategoryResult
Accessibility 9/13
Accountability 0/5
AI & Automation 3/8
Interoperability 2/3
Privacy 9/16
Provenance 1/2
Security 6/11
Transparency 4/13
Responsibility to the Future 0/3

Level 1 — Basic

Accessibility

AI & Automation

  • policy_exists: The About page contains no AI use policy or statement anywhere in its content or footer links.
    Fix: Publish a dedicated AI use policy page and link to it from the About section and site footer.
  • scope_clear: With no AI policy present, there is no explanation of what AI is used for on the page.
    Fix: Include a clear scope section describing where and how AI is used across University services and communications.

Privacy

Security

Transparency

  • disclosure_exists: The page contains no funding or sponsorship disclosure; it only mentions financial statements as a link without detailing funding sources.
    Fix: Add a clear funding/sponsorship disclosure section on the About page summarizing the University's main funding sources.
  • transparent: No funding sources are identified anywhere in the visible page content.
    Fix: Explicitly list key funding streams (e.g., tuition, government grants, research councils, donations) with links to supporting documentation.

Level 2 — Enhanced

Accessibility

Accountability

  • named_person: The page lists generic teams (Student Services, Estates, IT service desk) but does not identify any named individual or specific role accountable for the contact function.
    Fix: Add the name or at least the specific job title of the person or office head responsible for handling general enquiries and University contact.
  • response_timeframe: The page states hours of operation and mentions a call-back for out-of-hours calls but does not publish any response timeframe for enquiries or complaints.
    Fix: Publish an explicit expected response timeframe (e.g., 'we respond to enquiries within 5 working days') on the contact page.
  • specific: No specific timeframe in days or hours is given; the page only vaguely says a staff member 'will then call you back'.
    Fix: Replace vague phrasing with a concrete timeframe such as '24 hours' or '5 business days' for each contact channel.
  • process_exists: The contact page lists phone numbers and a 'Report and support' tool for wellbeing/harassment but does not link to or document a general complaints or feedback process.
    Fix: Add a clearly labelled link to a formal complaints and feedback procedure (e.g., 'How to make a complaint') from the contact page.
  • steps_clear: Because no complaints process is presented on the page, the steps for submitting a complaint are not articulated.
    Fix: Include a numbered list of steps (e.g., submit form, acknowledgement, investigation, response) so users know exactly how to file and track a complaint.
  • appeals_exists: The contact page lists general contacts and reporting tools but does not document any appeals process.
    Fix: Add a clearly labeled section or link describing how individuals can formally appeal decisions, including steps, timelines, and contact points.
  • independent: No appeals process is described, so there is no indication of independent review or escalation pathways.
    Fix: Document an escalation route to an independent reviewer or ombudsperson for appeals, distinct from the original decision-maker.

AI & Automation

  • detailed_scope: The page does not mention AI at all, so no detailed scope of AI use is provided.
    Fix: Add an AI policy detailing specific use cases, systems, and contexts where AI is deployed by the University.
  • limitations: No AI limitations are acknowledged because the page contains no AI-related content.
    Fix: Include a section in the AI policy that transparently acknowledges known limitations and risks of the AI systems used.
  • safeguards: There is no description of AI safeguards or quality controls since no AI policy is present.
    Fix: Document the governance, human oversight, and quality-control safeguards applied to AI use in a published policy.
  • marking_policy: The About page contains no policy or statement regarding the marking of AI-assisted content.
    Fix: Publish a clear policy on the site (linked from About or Policies) that defines how AI-assisted content is labelled and disclosed.
  • consistent: Without any AI marking policy visible, there is no evidence that AI content marking is applied consistently across the page.
    Fix: Adopt a standard AI-content label and apply it consistently to any AI-generated or AI-assisted text, images, or media on the site.
  • oversight_exists: The page makes no mention of human oversight of AI outputs.
    Fix: Add a statement (e.g., in governance or policies) documenting that AI outputs used by the University are subject to human oversight.
  • review_process: No review or approval process for AI-generated content is described on the page.
    Fix: Document and publish the review/approval workflow used before AI-generated content is published.
  • accountability: No individual, role, or office is named as accountable for AI-generated content.
    Fix: Identify and publish a named role or office (e.g., within Professional Services or Governance) accountable for AI-generated content.

Interoperability

Privacy

  • banner_present: No cookie or consent banner is visible on the page content; only a 'Cookie preferences' link appears in the footer.
    Fix: Implement a visible cookie consent banner that appears on first visit to allow users to accept or reject cookies before tracking begins.
  • partner_sharing_mentioned: There is no on-page consent copy or banner disclosing any data sharing with third-party partners.
    Fix: Add explicit disclosure within the cookie banner listing categories of third parties (e.g., analytics, social media) with whom data is shared.
  • partner_count_specific: No banner or consent copy is present, so no specific numeric count of partners is stated.
    Fix: Include a specific number of third-party partners (e.g., 'We share data with X partners') in the cookie banner and link to a full list.

Provenance

Security

Transparency

  • named_person: No named individual or specific team is identified for enquiries; only a general University phone number and address are provided.
    Fix: Identify the specific team (e.g., 'Communications Office' or 'Main Reception') or named contact responsible for handling general enquiries.
  • role_clear: Because no specific person or team is named for general enquiries, their role and authority are not stated.
    Fix: Clearly state the role and remit of the contact team (e.g., 'The Reception team handles general enquiries and directs callers to the appropriate department').
  • mission_clear: While the page references a strategy and annual review, it does not explicitly articulate the University's mission or educational/research purpose on the page itself.
    Fix: Add a concise mission statement summarising the University's educational and research purpose directly on the about page, or link prominently to the strategy document.
  • detail: The page provides no amounts, percentages, or categories describing funding.
    Fix: Include a breakdown of funding by category with amounts or percentages, or link prominently to a summary drawn from the financial statements.
  • complete: Since no funding streams are disclosed, coverage of major streams cannot be established.
    Fix: Publish a comprehensive disclosure covering all major funding streams such as tuition fees, research grants, endowments, donations, and public funding.
  • roles_clear: While the page references professional services and governing bodies, it does not identify specific key roles or responsibilities on this page itself.
    Fix: Add a brief summary or list on the About page naming the key governing bodies (e.g., Court, Senate, Principal) and their responsibilities, or link directly to a roles/responsibilities page.
  • algorithm_explained: The About page contains no mention of any algorithms or automated decision-making systems used by the University.
    Fix: Add a dedicated section or link disclosing any algorithmic systems in use (e.g., admissions, search, recommendations) and explaining their purpose.
  • impact_clear: There is no description of how algorithmic decisions affect users such as applicants, students, or staff.
    Fix: Publish a clear statement describing who is affected by algorithmic decisions and what outcomes those decisions influence.
  • annual_statement: The page shows no evidence of a regular or annual review of data practices, only a generic cookie/accessibility footer link.
    Fix: Publish a periodic (e.g., annual) data practices review statement and link to it from the footer alongside the privacy and cookie links.
  • dated: No data practices statement with a visible date or version number is present on the page.
    Fix: Add a clearly dated or versioned privacy/data practices statement (e.g., 'Last updated: [date]') accessible from the footer.

Level 3 — Advanced

Accessibility

  • known_issues: The provided page content only shows a link to an accessibility statement and does not include any acknowledgment of known accessibility issues or limitations.
    Fix: Ensure the linked accessibility statement lists specific known issues or non-compliant areas of the site.
  • remediation_timeline: There is no timeline or commitment to fixing accessibility issues visible on this page.
    Fix: Add a clear timeline or commitment for remediating known accessibility issues within the accessibility statement.
  • feedback_channel: The page provides only a general phone number and address but no dedicated accessibility feedback mechanism with a response commitment.
    Fix: Include a specific accessibility feedback channel (e.g., dedicated email or form) and a stated response time in the accessibility statement.

Accountability

  • policy_exists: The terms page lists general terms but does not publish a moderation policy for user-generated or community content.
    Fix: Publish a dedicated moderation policy covering user-generated content such as personal pages, comments, and forums.
  • criteria_clear: No moderation criteria (e.g., what content is prohibited or reviewed) are stated on this page.
    Fix: Add explicit criteria listing prohibited content types and the standards used to evaluate submissions.
  • enforcement: The page does not explain how moderation decisions are enforced, appealed, or actioned against violators.
    Fix: Describe the enforcement workflow, including who reviews content, possible sanctions, and how users can appeal decisions.

Interoperability

Security

  • plan_exists: The About page contains only institutional overview, governance, and visitor information with no published incident response plan or security policy.
    Fix: Publish a security incident response plan or policy and link to it from the site, for example under Governance or Policies, procedures and guidance.
  • notification_commitment: The page makes no commitment to publicly notify users about significant security or data incidents.
    Fix: Add an explicit commitment to notify affected users and the public when a significant incident occurs, within the incident response documentation.
  • timeframe: No timeframe for disclosing incidents to affected users is stated anywhere on the page.
    Fix: State a specific disclosure timeframe (e.g., notification within 72 hours of detecting a breach) in the published incident response policy.

Transparency

  • criteria_published: The page does not publish any criteria used in algorithmic decision-making.
    Fix: Publish the specific input criteria and data fields used by any algorithmic decision systems on a transparency or governance page.
  • weighting: No information is given about how criteria are weighted or prioritised in any decision process.
    Fix: Include documentation describing the relative weighting, priority, or scoring logic applied to each criterion.
  • auditable: The page provides no technical or procedural detail that would allow external audit or review of algorithmic systems.
    Fix: Publish an algorithmic transparency record (e.g., following the UK ATRS standard) with sufficient detail for independent audit.
  • open_source: There is no link to source code or any open-source repository for the website on the page.
    Fix: Add a link in the footer or website help section to a public code repository (e.g., GitHub) if any site components are open source.
  • tech_docs: No technical documentation about the website's platform, APIs, or data is referenced on the page.
    Fix: Publish and link to technical documentation such as API references, data schemas, or a developer portal from the about or website help section.

Responsibility to the Future

  • specific_metrics: The page states a net zero target and qualitative goals but contains no specific figures for carbon, energy use, or emissions.
    Fix: Add quantified metrics such as current annual carbon emissions, energy consumption, and progress-to-target figures directly on the page or clearly linked from it.
  • hosting_disclosure: There is no mention of the carbon or energy profile of the website's hosting infrastructure anywhere on the page.
    Fix: Publish a statement on the site's hosting carbon/energy profile, e.g. green hosting provider details or measured page/site emissions.
  • plan_exists: The About page describes governance, strategy, and history but contains no published plan for what happens if the organisation fails or exits.
    Fix: Publish a succession or continuity plan section outlining what would happen to the institution's services and assets in the event of closure or major disruption.
  • data_and_content_fate: The page makes no mention of what would happen to user data or published content should the University cease operations.
    Fix: Add explicit statements describing how user data and published content would be preserved, transferred, or deleted in a wind-down scenario.
  • custodians_or_mirrors: No custodians, mirrors, or archive partners are identified anywhere on the page.
    Fix: Name specific archive partners, custodians, or mirror arrangements (e.g., a national archive) that would take responsibility for content upon exit.
  • policy_exists: The page is a Careers Centre landing page for students and employers with no published policy on worker wellbeing or working conditions.
    Fix: Publish a dedicated worker wellbeing or working conditions policy and link to it from the page.
  • specific_commitments: The content contains no specific commitments regarding pay, hours, mental health, or benefits for workers.
    Fix: Add explicit commitments covering pay standards, working hours, mental health support, and staff benefits.
  • accountability: The page names only general contact details and identifies no accountable owner or oversight body for worker conditions.
    Fix: Name a responsible role or oversight committee accountable for monitoring and reporting on worker conditions.