Welsh Government

https://www.gov.wales · 61/92 checks passed · government

Compliance report (framework 0.8)

Gate passed (every Core check must pass) · not counted towards the gate: paused 35, draft 48, ready for review 54.

Site level: 0 (no scored checks yet).

By level

LevelResult
Level 1 — Basic 31/37 (6 failed)
Level 2 — Enhanced 14/27 (13 failed)
Level 3 — Advanced 0/10 (9 failed)

By category

CategoryResult
Accessibility 11/13
Accountability 3/5
AI & Automation 3/8
Interoperability 1/3
Privacy 14/16
Provenance 1/2
Security 5/11
Transparency 7/13
Responsibility to the Future 0/3

Level 1 — Basic

Accessibility

AI & Automation

  • policy_exists: The About page contains no AI use policy or statement among its listed corporate information.
    Fix: Publish an AI use policy or statement and link it from the About/Corporate Information section.
  • scope_clear: No mention of AI is present, so the scope of any AI use is not explained.
    Fix: Include a clear description of what AI systems are used for (e.g., translation, chatbots, analytics) within the AI policy.

Privacy

Security

Transparency

Level 2 — Enhanced

Accessibility

Accountability

  • named_person: The page lists service areas (e.g., Welsh Government, RPW, WRA) but names no individual or specific role as responsible for enquiries.
    Fix: Identify a named contact or specific role (e.g., Head of Customer Contact) responsible for each service area listed.

AI & Automation

  • detailed_scope: No AI policy appears on the page, so detailed scope is absent.
    Fix: Add a detailed AI policy outlining specific systems, use cases, and departments deploying AI.
  • limitations: The page does not acknowledge any limitations of AI systems.
    Fix: Include a section in the AI policy that transparently acknowledges known limitations and risks of AI tools used.
  • safeguards: No safeguards or quality controls for AI are described on the page.
    Fix: Document safeguards such as human review, bias testing, and oversight mechanisms within the published AI policy.
  • marking_policy: The About page contains no policy or mention of marking AI-assisted content.
    Fix: Publish a clear policy stating how AI-assisted content is labelled and link to it from the About or Corporate information section.
  • consistent: Without any marking policy visible on the page, consistent application cannot be demonstrated.
    Fix: Adopt a standard AI-content label and apply it consistently across all pages, with examples shown in the published policy.
  • oversight_exists: The page does not document any human oversight process for AI outputs.
    Fix: Add a statement under Corporate information describing how humans oversee any AI use in Welsh Government content.
  • review_process: No review or approval workflow for AI-generated content is described on the page.
    Fix: Document the review/approval steps (e.g., editorial sign-off) for AI outputs and publish them in the About section.
  • accountability: No individual, role, or team is identified as accountable for AI-generated content.
    Fix: Name an accountable role or team (e.g., Chief Digital Officer) responsible for AI-generated content and publish their remit.

Interoperability

Privacy

  • equal_choices: The banner offers 'Accept all cookies' and 'Change cookie settings' but no equally prominent 'Reject all' option at the same level.
    Fix: Add a 'Reject all' button with equal visual prominence alongside the 'Accept all cookies' button so users can decline non-essential cookies in one click.
  • partner_sharing_mentioned: The cookie banner only mentions essential cookies and cookies to improve the website and tailor communications, with no disclosure of data sharing with third-party partners.
    Fix: Update the cookie banner to explicitly disclose any third-party partners with whom data is shared and link to a detailed partner list.
  • partner_count_specific: No numeric count of partners is stated anywhere in the cookie banner or on-page consent copy.
    Fix: Include a specific number of third-party partners (e.g., 'We share data with X partners') in the cookie banner or linked consent settings.

Provenance

Security

Transparency

  • substantive: The statement of purpose is limited to brief taglines like 'We are the devolved government for Wales' and 'Making policies and laws for our country' rather than a detailed statement.
    Fix: Expand the About page with a substantive narrative describing the Welsh Government's functions, scope, values, and how it operates, rather than relying on short link labels.
  • mission_clear: While priorities are linked, the page itself does not articulate a clear mission or editorial approach beyond navigation headings.
    Fix: Add an explicit mission statement on the About page that articulates the Welsh Government's guiding principles and strategic approach.
  • detail: The page names funding categories (block grant, devolved taxes, borrowing) but provides no amounts, percentages, or meaningful breakdown on this page.
    Fix: Add summary figures or percentages for each funding stream (e.g., block grant value, tax revenue, borrowing cap) directly on the collection page or in a visible summary.
  • algorithm_explained: The About page makes no mention of any algorithms or automated decision-making systems used by the Welsh Government.
    Fix: Add a section describing any algorithmic or automated decision-making tools in use and explain their purpose.
  • impact_clear: There is no description of how algorithmic decisions might affect users or citizens on this page.
    Fix: Include a clear explanation of the impact algorithmic decisions have on users, including any rights to appeal or human review.
  • annual_statement: The page links to a Privacy notice but shows no evidence of an annual or periodic review of data practices.
    Fix: Publish a clearly visible statement indicating when the privacy/data practices were last reviewed and commit to a regular (e.g., annual) review cycle.
  • dated: The visible content does not show any date or version for the data practices or privacy statement.
    Fix: Add a 'last updated' date or version number to the privacy statement and surface it from the About page.

Level 3 — Advanced

Accessibility

  • remediation_timeline: The statement notes issues have been 'resolved where possible' and that historic documents will not be made accessible, but provides no dates or timeline for fixing the remaining listed non-compliances.
    Fix: Add target dates or a committed timeframe for remediating each listed WCAG non-compliance (e.g., 'we aim to fix contrast issues by Q2 2026').

Accountability

  • policy_exists: The terms page only references 'Welsh Government social media house rules' by link but does not publish any moderation policy for the site itself.
    Fix: Publish a dedicated moderation policy covering user-generated content and comments on gov.wales, linked from the Terms and Conditions.
  • criteria_clear: No moderation criteria (e.g., what content is disallowed, standards for removal) are stated on the page.
    Fix: Add a clearly enumerated list of moderation criteria (prohibited content types, behavior standards) within the moderation policy.
  • enforcement: The page does not explain any enforcement process, appeals, or actions taken against violations.
    Fix: Document the enforcement workflow—how violations are reported, reviewed, actioned, and appealed—on the moderation policy page.

Interoperability

Security

  • plan_exists: The About page lists corporate information links like the publication scheme and information management, but no published incident response plan or policy is present.
    Fix: Publish an incident response plan or security incident policy and link to it from the corporate information section.
  • notification_commitment: The page contains no statement committing to public notification of significant security or data incidents.
    Fix: Add an explicit commitment to notify the public and affected users of significant incidents within the incident response documentation.
  • timeframe: No timeframe for disclosing incidents to affected users appears anywhere on the page.
    Fix: State a specific disclosure timeframe (e.g., notification within 72 hours of discovery) in the incident response policy.

Transparency

  • criteria_published: No specific criteria for any algorithmic decisions are published or linked from this About page.
    Fix: Publish the specific decision criteria used by any algorithms, or link to a dedicated transparency register.
  • weighting: The page contains no information about weighting or prioritisation of criteria in algorithmic decisions.
    Fix: Document and publish how criteria are weighted or prioritised in any algorithmic systems used.
  • auditable: The page provides no technical or procedural detail that would enable external audit or independent review of algorithms.
    Fix: Provide auditable documentation such as model cards, data sources, and review processes to support external scrutiny.
  • open_source: The page contains no link to source code or any open-source repository for the website.
    Fix: Publish the website's source code in a public repository (e.g., GitHub) and link to it from the About or a developer/technical page.
  • tech_docs: No technical documentation is linked from the About page.
    Fix: Provide and link to technical documentation (e.g., APIs, platform architecture, data standards) from the About or a dedicated developer section.

Responsibility to the Future

  • disclosure_exists: The About page lists corporate and open government reports but contains no published environmental impact or sustainability disclosure.
    Fix: Publish a dedicated environmental or sustainability disclosure and link to it from the corporate information section of this page.
  • specific_metrics: No specific figures for carbon, energy use, or emissions appear anywhere in the page content.
    Fix: Include quantified metrics such as annual carbon emissions and energy consumption in a published sustainability report.
  • hosting_disclosure: The page provides no information about the carbon or energy profile of its hosting infrastructure.
    Fix: Disclose the hosting provider's energy source or carbon profile (e.g., renewable-powered data centres) in an environmental statement.
  • plan_exists: The page contains general 'About us' and corporate information links but no published plan describing what happens if the organisation fails or exits.
    Fix: Publish a succession or continuity plan outlining what happens to the organisation's functions and services in the event of failure or exit, and link to it from the corporate information section.
  • data_and_content_fate: The page addresses privacy and information management generally but does not state what would happen to user data and published content if the organisation ceased to operate.
    Fix: Add explicit guidance on the fate of user data and published content in a wind-down scenario, including retention, transfer, or deletion arrangements.
  • custodians_or_mirrors: The page mentions 'Find archived information' but does not identify any custodians, mirrors, or archive partners responsible for preserving content if the organisation exits.
    Fix: Name the custodians, mirror sites, or archive partners (e.g., a national web archive) that would preserve the site's content and link to their arrangements.
  • policy_exists: The page is a recruitment landing page describing job opportunities, not a published policy on worker wellbeing or working conditions.
    Fix: Publish a dedicated worker wellbeing or working conditions policy and link to it from this careers page.
  • specific_commitments: The page only vaguely mentions 'flexible working hours and comprehensive benefits' without any specific commitments on pay, hours, mental health, or benefits.
    Fix: Add concrete details or links specifying pay ranges, working hour policies, mental health support, and the full benefits package.
  • accountability: The page names no individual, team, or body responsible for overseeing worker conditions or wellbeing.
    Fix: Identify a responsible department or role (e.g., HR or a wellbeing lead) with contact details and oversight responsibilities for worker conditions.