Victoria and Albert Museum
https://www.vam.ac.uk · 56/92 checks passed · archives
Compliance report (framework 0.8)
Gate passed (every Core check must pass) · not counted towards the gate: paused 35, draft 48, ready for review 54.
Site level: 0 (no scored checks yet).
By level
| Level | Result |
|---|---|
| Level 1 — Basic | 32/37 (5 failed) |
| Level 2 — Enhanced | 10/27 (17 failed) |
| Level 3 — Advanced | 0/10 (9 failed) |
By category
| Category | Result |
|---|---|
| Accessibility | 12/13 |
| Accountability | 0/5 |
| AI & Automation | 3/8 |
| Interoperability | 1/3 |
| Privacy | 13/16 |
| Provenance | 1/2 |
| Security | 6/11 |
| Transparency | 6/13 |
| Responsibility to the Future | 0/3 |
Level 1 — Basic
Accessibility
AI & Automation
-
policy_exists: The About page contains no AI use policy or statement of any kind.
Fix: Publish an AI use policy or statement on the website (e.g., linked from the About or Policies section) describing how the V&A uses AI.
-
scope_clear: Because no AI policy is present, the scope of AI use is not explained anywhere on the page.
Fix: Include a clear description of what AI is used for (e.g., collections search, content generation, visitor services) within the AI policy.
- Not found at any of: /ai-policy, /ai.
Privacy
PASS
Session cookies only
PASS
No tracking pixels
Security
- Redirect chain (1 hops): https://www.vam.ac.uk
- content-security-policy: header not set on the response.
PASS
HTTPS enforced
PASS
No mixed content
Transparency
-
transparent: While government sponsorship is named, other funding sources (private, commercial, membership, donations) are only alluded to without clear identification on this page.
Fix: Add a dedicated funding section on the About page that clearly identifies all funding sources (government grant-in-aid, private donors, corporate partners, commercial revenue, memberships).
PASS
Contact form present
Level 2 — Enhanced
Accessibility
Accountability
-
named_person: The page lists generic categories (Press office, Marketing, Collection departments) but no named person or specific role is identified as responsible.
Fix: Add the name or specific job title of the person/team lead responsible for each contact category (e.g., 'Head of Press Office: [Name]').
-
response_timeframe: The page references 'Getting a response' as a link but does not display any response timeframe on this contact page itself.
Fix: Publish an explicit response timeframe directly on the contact page (e.g., 'We aim to respond within 10 working days').
-
specific: No specific timeframe in days or weeks is given on the visible contact page content.
Fix: State a concrete number of days (e.g., '5 working days for visiting queries, 20 working days for collection queries') rather than vague language.
-
steps_clear: The feedback section lists categories ('In person', 'Write to us', 'Getting a response') but does not clearly lay out the steps for submitting a complaint on this page.
Fix: Add a clear, numbered step-by-step complaints procedure on the contact page describing how to submit, what information to include, and what to expect next.
-
appeals_exists: The page shows a 'no results found' message and only displays a donation appeal, with no documented appeals process present.
Fix: Publish a dedicated appeals page describing how users can formally challenge decisions, including steps, contacts, and timelines.
-
independent: Because no appeals process is documented, there is no indication of independent review or escalation paths.
Fix: Define and publish an independent or escalated review mechanism (e.g., an ombudsperson or external reviewer) as part of the appeals procedure.
AI & Automation
-
detailed_scope: No AI policy exists on the page, so detailed scope of AI use is not provided.
Fix: Add a dedicated AI policy page detailing specific AI applications, systems used, and contexts of deployment across V&A operations.
-
limitations: There is no acknowledgement of AI system limitations anywhere in the content.
Fix: Within the AI policy, explicitly acknowledge limitations such as potential inaccuracies, bias, and areas where AI outputs should not be solely relied upon.
-
safeguards: No safeguards or quality controls related to AI are described on the page.
Fix: Describe safeguards such as human review, data governance, bias mitigation, and quality assurance processes used with AI systems.
-
marking_policy: The About page contains no policy or statement about how AI-assisted content is marked or labeled.
Fix: Publish a clear policy within the reports, plans & policies section describing how AI-assisted content will be identified and labeled for visitors.
-
consistent: Without any marking policy visible on the page, there is no evidence of consistent AI content labeling practices.
Fix: Adopt a standardized labeling convention (e.g., an 'AI-assisted' tag) and apply it uniformly across digital experiences, exhibitions content, and research outputs.
-
oversight_exists: The page does not document any human oversight mechanism for AI outputs anywhere in the About content.
Fix: Add a section to the policies page outlining human-in-the-loop oversight procedures for any AI-generated or AI-assisted outputs.
-
review_process: No review or approval workflow for AI-generated content is described on the page.
Fix: Document a staged review and approval process (e.g., curator or editorial sign-off) for AI outputs and publish it alongside other governance policies.
-
accountability: Although an Executive Board and Director are named for general governance, no individual or role is identified as accountable for AI-generated content.
Fix: Designate a named role (such as a Head of Digital or Chief Data Officer) responsible for AI content governance and publish that accountability on the About or policies page.
Interoperability
- No RSS/Atom feeds discovered.
Privacy
-
retention_stated: Only Wi-Fi MAC/location retention is mentioned; the page lacks a general retention section covering other data categories within the visible content.
Fix: Add a dedicated 'Data security and retention' section that states retention periods for each major data category (e.g., memberships, donations, marketing contacts, CCTV).
-
specific: Beyond the 90-day Wi-Fi diagnostic retention, no specific time periods are provided for other data types in the visible content.
Fix: Specify concrete retention durations (e.g., 'CCTV retained for 31 days', 'marketing data retained for 3 years after last interaction') rather than general statements.
-
equal_choices: The page content shown does not display a visible consent banner with equally prominent accept and reject options, so equal prominence cannot be confirmed.
Fix: Ensure the cookie consent banner presents 'Accept' and 'Reject' buttons with equal visual weight (same size, color, and placement) on the first layer.
-
banner_present: The page content shows no visible cookie or consent banner; only a footer link to 'Privacy notice and cookies' is present.
Fix: Implement a visible cookie consent banner on page load that allows users to accept, reject, or customize cookie preferences.
-
partner_sharing_mentioned: No banner or on-page consent copy is shown, so third-party partner data sharing is not disclosed at the point of consent.
Fix: Include clear language in the consent banner disclosing that data may be shared with third-party advertising and analytics partners, with a link to the full list.
-
partner_count_specific: No partner sharing disclosure exists on the page, so no specific numeric count of partners is stated.
Fix: State the exact number of third-party partners (e.g., 'We share data with X partners') within the consent banner and link to their identities.
Provenance
- No author or date metadata found on the page.
Security
- security.txt not published.
Transparency
-
named_person: No named individual or specific team is identified for enquiries; only broad functional categories like 'Press office' and 'Marketing' are listed.
Fix: Identify the specific team or individual handling each enquiry type, e.g., 'Visitor Experience Team' or a named contact for press.
-
detail: No amounts, percentages, or detailed categories of funding are provided on the page; it only references a strategic objective to diversify funding.
Fix: Include a summary table or paragraph with funding amounts or percentages by category (e.g., grant-in-aid, self-generated income, philanthropy) directly on or linked from the About page.
-
complete: The page does not comprehensively cover all major funding streams such as sponsorships, endowments, trading income, or specific corporate partners.
Fix: Publish a complete breakdown of all major funding streams (public grant, trading, philanthropy, sponsorships, membership) with links to the full annual report for verification.
-
algorithm_explained: The About page makes no mention of any algorithms used by the V&A, so their purpose is not explained.
Fix: Add a section (or link to a dedicated page) describing any algorithms used on the site, such as search ranking or recommendations, and their purpose.
-
impact_clear: The page does not describe how algorithmic decisions affect users in any way.
Fix: Publish a clear statement of how algorithmic systems impact visitors (e.g., personalisation, content ordering) and what decisions they influence.
-
annual_statement: The About page references a privacy notice but provides no evidence of a regular or annual review of data practices.
Fix: Add a statement to the privacy notice indicating the cadence of review (e.g., 'Reviewed annually') and link it from the About page.
-
dated: The page links to a 'Privacy notice and cookies' but shows no visible date or version for the data practices statement.
Fix: Include a 'Last updated' date or version number on the privacy notice and surface it where the notice is referenced.
Level 3 — Advanced
Accessibility
-
known_issues: The visible page content is the 'About' page and provides no acknowledgment of any known accessibility issues or limitations.
Fix: Add a section to the linked accessibility statement that explicitly lists known accessibility issues and non-conformances with WCAG.
-
remediation_timeline: There is no visible timeline or commitment for fixing accessibility issues anywhere on the page.
Fix: Include target dates or a remediation schedule for resolving each identified accessibility issue in the accessibility statement.
-
feedback_channel: While general contact details are provided, the page offers no accessibility-specific feedback mechanism or a commitment to respond within a stated timeframe.
Fix: Provide a dedicated accessibility feedback contact and state a specific response time commitment (e.g., within 5 working days) in the accessibility statement.
Accountability
-
policy_exists: The page lists terms for websites, membership, shop, orders, and suppliers but does not publish any moderation policy for user-generated content.
Fix: Publish a dedicated moderation or community guidelines policy linked from the terms page covering user comments, submissions, and social interactions.
-
criteria_clear: No moderation criteria (e.g., prohibited content, acceptable use rules) are stated anywhere on this terms index page.
Fix: Add a clearly worded section specifying what content or behaviour is disallowed and the standards used to evaluate submissions.
-
enforcement: The page does not describe any enforcement process, such as how violations are reported, reviewed, or acted upon.
Fix: Document the enforcement workflow, including how to report issues, review timelines, possible sanctions, and appeal rights.
Interoperability
- Not found at: /status
Security
-
plan_exists: The About page describes the museum's mission, history and reports but contains no published incident response plan or security incident policy.
Fix: Publish an incident response plan or security policy and link to it from the site, for example under 'Reports, strategic plans and policies'.
-
notification_commitment: The page makes no commitment to publicly notify users about significant security or data incidents.
Fix: Add an explicit commitment to notify affected users and the public when a significant incident occurs, ideally within the published incident response policy.
-
timeframe: No disclosure timeframe for notifying affected users of incidents is stated anywhere on the page.
Fix: Specify a concrete disclosure timeframe (e.g., notify affected users within 72 hours of confirming an incident) in the incident response policy.
Skipped: Target page not found in captured content
Transparency
-
criteria_published: No criteria used by any algorithmic decision-making system are published on this page.
Fix: Publish the specific input criteria and data sources that drive any algorithmic decisions on the site.
-
weighting: The page provides no information about how criteria are weighted or prioritised in any algorithm.
Fix: Document the relative weighting or prioritisation of each criterion used in algorithmic decisions.
-
auditable: There is insufficient detail on the page to allow any external audit or review of algorithmic systems.
Fix: Provide technical documentation, model cards, or audit reports enabling external reviewers to assess the algorithms.
-
open_source: The about page contains no link to source code or any public code repository for the website or related tools.
Fix: Add a link (e.g., to a GitHub/GitLab organisation) disclosing any open-source components of the V&A's digital platforms or state the site's source policy.
-
tech_docs: No technical documentation about the website, APIs, or digital infrastructure is linked from the about page.
Fix: Publish and link to technical documentation (e.g., a developers page or API docs for the collections) from the About section.
Responsibility to the Future
-
disclosure_exists: The page contains no published environmental impact or sustainability disclosure, only mentions of mission, history, and reports without sustainability content.
Fix: Publish a dedicated sustainability or environmental impact statement and link it from the About or Reports section.
-
specific_metrics: No specific figures on carbon emissions, energy use, or emissions appear anywhere on the page.
Fix: Include quantified environmental metrics such as annual carbon footprint, energy consumption, and emissions in a published disclosure.
-
hosting_disclosure: There is no information about the carbon or energy profile of the website's hosting infrastructure.
Fix: Add a statement disclosing the hosting provider's energy source or carbon profile, ideally noting use of renewable-powered or green hosting.
-
plan_exists: The page describes the V&A's mission, history, and strategic objectives but contains no published plan addressing what happens if the organisation fails or exits.
Fix: Publish a succession or contingency plan (or link to one in the reports and policies section) describing what would happen to the organisation and its digital assets in the event of closure or exit.
-
data_and_content_fate: There is no mention of what would happen to user data or published content should the organisation cease operations, only a general reference to the privacy notice.
Fix: Add a clear statement or policy explaining how user data and published collections/content would be preserved, transferred, or deleted if the organisation shuts down.
-
custodians_or_mirrors: The page names no custodians, mirrors, or archive partners who would take over stewardship of the museum's digital content or collection records.
Fix: Identify and publish designated custodians, archive partners, or mirror arrangements (for example a national archive or heritage body) responsible for maintaining content if the organisation ceases to exist.
-
policy_exists: The page is a careers/recruitment page describing benefits and vacancies but does not publish a formal policy on worker wellbeing or working conditions.
Fix: Publish or link to a formal worker wellbeing and working conditions policy document from the careers page.
-
accountability: The page names 'People teams' and an Executive board in passing but does not identify any specific body or role accountable for overseeing worker conditions or wellbeing.
Fix: State which team, role, or governance body is responsible for monitoring and upholding worker wellbeing and working conditions.