Welsh Government
https://www.gov.wales · 61/92 checks passed · government
Compliance report (framework 0.8)
Gate passed (every Core check must pass) · not counted towards the gate: paused 35, draft 48, ready for review 54.
Site level: 0 (no scored checks yet).
By level
| Level | Result |
|---|---|
| Level 1 — Basic | 31/37 (6 failed) |
| Level 2 — Enhanced | 14/27 (13 failed) |
| Level 3 — Advanced | 0/10 (9 failed) |
By category
| Category | Result |
|---|---|
| Accessibility | 11/13 |
| Accountability | 3/5 |
| AI & Automation | 3/8 |
| Interoperability | 1/3 |
| Privacy | 14/16 |
| Provenance | 1/2 |
| Security | 5/11 |
| Transparency | 7/13 |
| Responsibility to the Future | 0/3 |
Level 1 — Basic
Accessibility
AI & Automation
-
policy_exists: The About page contains no AI use policy or statement among its listed corporate information.
Fix: Publish an AI use policy or statement and link it from the About/Corporate Information section.
-
scope_clear: No mention of AI is present, so the scope of any AI use is not explained.
Fix: Include a clear description of what AI systems are used for (e.g., translation, chatbots, analytics) within the AI policy.
- Not found at any of: /ai-policy, /ai.
Privacy
PASS
Session cookies only
PASS
No tracking pixels
Security
- Redirect chain (1 hops): https://www.gov.wales
- content-security-policy: header not set on the response.
- referrer-policy: header not set on the response.
PASS
HTTPS enforced
PASS
No mixed content
Transparency
PASS
Contact form present
Level 2 — Enhanced
Accessibility
Accountability
-
named_person: The page lists service areas (e.g., Welsh Government, RPW, WRA) but names no individual or specific role as responsible for enquiries.
Fix: Identify a named contact or specific role (e.g., Head of Customer Contact) responsible for each service area listed.
AI & Automation
-
detailed_scope: No AI policy appears on the page, so detailed scope is absent.
Fix: Add a detailed AI policy outlining specific systems, use cases, and departments deploying AI.
-
limitations: The page does not acknowledge any limitations of AI systems.
Fix: Include a section in the AI policy that transparently acknowledges known limitations and risks of AI tools used.
-
safeguards: No safeguards or quality controls for AI are described on the page.
Fix: Document safeguards such as human review, bias testing, and oversight mechanisms within the published AI policy.
-
marking_policy: The About page contains no policy or mention of marking AI-assisted content.
Fix: Publish a clear policy stating how AI-assisted content is labelled and link to it from the About or Corporate information section.
-
consistent: Without any marking policy visible on the page, consistent application cannot be demonstrated.
Fix: Adopt a standard AI-content label and apply it consistently across all pages, with examples shown in the published policy.
-
oversight_exists: The page does not document any human oversight process for AI outputs.
Fix: Add a statement under Corporate information describing how humans oversee any AI use in Welsh Government content.
-
review_process: No review or approval workflow for AI-generated content is described on the page.
Fix: Document the review/approval steps (e.g., editorial sign-off) for AI outputs and publish them in the About section.
-
accountability: No individual, role, or team is identified as accountable for AI-generated content.
Fix: Name an accountable role or team (e.g., Chief Digital Officer) responsible for AI-generated content and publish their remit.
Interoperability
- No RSS/Atom feeds discovered.
Privacy
-
equal_choices: The banner offers 'Accept all cookies' and 'Change cookie settings' but no equally prominent 'Reject all' option at the same level.
Fix: Add a 'Reject all' button with equal visual prominence alongside the 'Accept all cookies' button so users can decline non-essential cookies in one click.
-
partner_sharing_mentioned: The cookie banner only mentions essential cookies and cookies to improve the website and tailor communications, with no disclosure of data sharing with third-party partners.
Fix: Update the cookie banner to explicitly disclose any third-party partners with whom data is shared and link to a detailed partner list.
-
partner_count_specific: No numeric count of partners is stated anywhere in the cookie banner or on-page consent copy.
Fix: Include a specific number of third-party partners (e.g., 'We share data with X partners') in the cookie banner or linked consent settings.
Provenance
- No author or date metadata found on the page.
Security
- security.txt not published.
Transparency
-
substantive: The statement of purpose is limited to brief taglines like 'We are the devolved government for Wales' and 'Making policies and laws for our country' rather than a detailed statement.
Fix: Expand the About page with a substantive narrative describing the Welsh Government's functions, scope, values, and how it operates, rather than relying on short link labels.
-
mission_clear: While priorities are linked, the page itself does not articulate a clear mission or editorial approach beyond navigation headings.
Fix: Add an explicit mission statement on the About page that articulates the Welsh Government's guiding principles and strategic approach.
-
detail: The page names funding categories (block grant, devolved taxes, borrowing) but provides no amounts, percentages, or meaningful breakdown on this page.
Fix: Add summary figures or percentages for each funding stream (e.g., block grant value, tax revenue, borrowing cap) directly on the collection page or in a visible summary.
-
algorithm_explained: The About page makes no mention of any algorithms or automated decision-making systems used by the Welsh Government.
Fix: Add a section describing any algorithmic or automated decision-making tools in use and explain their purpose.
-
impact_clear: There is no description of how algorithmic decisions might affect users or citizens on this page.
Fix: Include a clear explanation of the impact algorithmic decisions have on users, including any rights to appeal or human review.
-
annual_statement: The page links to a Privacy notice but shows no evidence of an annual or periodic review of data practices.
Fix: Publish a clearly visible statement indicating when the privacy/data practices were last reviewed and commit to a regular (e.g., annual) review cycle.
-
dated: The visible content does not show any date or version for the data practices or privacy statement.
Fix: Add a 'last updated' date or version number to the privacy statement and surface it from the About page.
Level 3 — Advanced
Accessibility
-
remediation_timeline: The statement notes issues have been 'resolved where possible' and that historic documents will not be made accessible, but provides no dates or timeline for fixing the remaining listed non-compliances.
Fix: Add target dates or a committed timeframe for remediating each listed WCAG non-compliance (e.g., 'we aim to fix contrast issues by Q2 2026').
Accountability
-
policy_exists: The terms page only references 'Welsh Government social media house rules' by link but does not publish any moderation policy for the site itself.
Fix: Publish a dedicated moderation policy covering user-generated content and comments on gov.wales, linked from the Terms and Conditions.
-
criteria_clear: No moderation criteria (e.g., what content is disallowed, standards for removal) are stated on the page.
Fix: Add a clearly enumerated list of moderation criteria (prohibited content types, behavior standards) within the moderation policy.
-
enforcement: The page does not explain any enforcement process, appeals, or actions taken against violations.
Fix: Document the enforcement workflow—how violations are reported, reviewed, actioned, and appealed—on the moderation policy page.
Interoperability
- Not found at: /status
Security
-
plan_exists: The About page lists corporate information links like the publication scheme and information management, but no published incident response plan or policy is present.
Fix: Publish an incident response plan or security incident policy and link to it from the corporate information section.
-
notification_commitment: The page contains no statement committing to public notification of significant security or data incidents.
Fix: Add an explicit commitment to notify the public and affected users of significant incidents within the incident response documentation.
-
timeframe: No timeframe for disclosing incidents to affected users appears anywhere on the page.
Fix: State a specific disclosure timeframe (e.g., notification within 72 hours of discovery) in the incident response policy.
Skipped: Target page not found in captured content
Transparency
-
criteria_published: No specific criteria for any algorithmic decisions are published or linked from this About page.
Fix: Publish the specific decision criteria used by any algorithms, or link to a dedicated transparency register.
-
weighting: The page contains no information about weighting or prioritisation of criteria in algorithmic decisions.
Fix: Document and publish how criteria are weighted or prioritised in any algorithmic systems used.
-
auditable: The page provides no technical or procedural detail that would enable external audit or independent review of algorithms.
Fix: Provide auditable documentation such as model cards, data sources, and review processes to support external scrutiny.
-
open_source: The page contains no link to source code or any open-source repository for the website.
Fix: Publish the website's source code in a public repository (e.g., GitHub) and link to it from the About or a developer/technical page.
-
tech_docs: No technical documentation is linked from the About page.
Fix: Provide and link to technical documentation (e.g., APIs, platform architecture, data standards) from the About or a dedicated developer section.
Responsibility to the Future
-
disclosure_exists: The About page lists corporate and open government reports but contains no published environmental impact or sustainability disclosure.
Fix: Publish a dedicated environmental or sustainability disclosure and link to it from the corporate information section of this page.
-
specific_metrics: No specific figures for carbon, energy use, or emissions appear anywhere in the page content.
Fix: Include quantified metrics such as annual carbon emissions and energy consumption in a published sustainability report.
-
hosting_disclosure: The page provides no information about the carbon or energy profile of its hosting infrastructure.
Fix: Disclose the hosting provider's energy source or carbon profile (e.g., renewable-powered data centres) in an environmental statement.
-
plan_exists: The page contains general 'About us' and corporate information links but no published plan describing what happens if the organisation fails or exits.
Fix: Publish a succession or continuity plan outlining what happens to the organisation's functions and services in the event of failure or exit, and link to it from the corporate information section.
-
data_and_content_fate: The page addresses privacy and information management generally but does not state what would happen to user data and published content if the organisation ceased to operate.
Fix: Add explicit guidance on the fate of user data and published content in a wind-down scenario, including retention, transfer, or deletion arrangements.
-
custodians_or_mirrors: The page mentions 'Find archived information' but does not identify any custodians, mirrors, or archive partners responsible for preserving content if the organisation exits.
Fix: Name the custodians, mirror sites, or archive partners (e.g., a national web archive) that would preserve the site's content and link to their arrangements.
-
policy_exists: The page is a recruitment landing page describing job opportunities, not a published policy on worker wellbeing or working conditions.
Fix: Publish a dedicated worker wellbeing or working conditions policy and link to it from this careers page.
-
specific_commitments: The page only vaguely mentions 'flexible working hours and comprehensive benefits' without any specific commitments on pay, hours, mental health, or benefits.
Fix: Add concrete details or links specifying pay ranges, working hour policies, mental health support, and the full benefits package.
-
accountability: The page names no individual, team, or body responsible for overseeing worker conditions or wellbeing.
Fix: Identify a responsible department or role (e.g., HR or a wellbeing lead) with contact details and oversight responsibilities for worker conditions.