TEARDOWN Published 21 September 2026 at 06:25. Evidence-based. Source-cited. No sponsored content.

Every department is told to publish a yearly list of its highest-risk analytical models, against a threshold it sets itself. Search GOV.UK for the biggest departments and most do not appear to have published one at all.

4 out of 5 stars4/52 documented mistakes in this teardownHow ratings work

Estimated reading time: 7 minutes

The Ministry of Defence's Main Building on Whitehall, London.
The Ministry of Defence Main Building, Whitehall, London, photographed November 2005. Photo: Chris Nyborg / Wikimedia Commons, CC BY-SA 3.0.

In short. The AQuA Book, government's guidance on quality analysis, says departments and arm's-length bodies "should publish a list of business critical models (BCM)... at least annually" [1], but leaves each organisation to set its own definition and threshold for "business critical" [1]. A search of GOV.UK finds no such list published by HM Treasury, HMRC, the Home Office, the Ministry of Justice or the Department for Environment, Food and Rural Affairs [7] [8] [9] [10] [11]. The Cabinet Office publishes one under this exact requirement's name, and has not updated it since 31 October 2024 [3]. Two documented mistakes: four stars.

A model that estimates the cost of civil service pensions, or calculates compensation for victims of the infected blood scandal, or decides how border checkpoints get built, is exactly the kind of thing the government's own guidance calls a "business critical model": one whose error could carry serious financial, legal or reputational consequences. The guidance that names that category, the AQuA Book, revised 30 July 2025 and produced jointly by the Government Operational Research Service, the Government Analysis Function, the Government Actuary's Department and the Office for National Statistics, tells every department and arm's-length body to publish a list of theirs "at least annually" [1]. Checking who actually does turns up a government website with almost none of its biggest departments on it.

The rule, and who gets to write its own test

Section 9.7.1 of the AQuA Book is unambiguous about the obligation and vague about everything that defines it. Departments and ALBs "should publish a list of business critical models (BCM) in use within their organisations at least annually," and the list "should meet accessibility guidelines" [1]. But "should" is not "shall": the AQuA Book's own glossary states that "should" denotes "a recommendation, an advisory element, to be met on a 'comply or explain' basis," while "shall" denotes "a requirement, a mandatory element, which applies in all circumstances" [1]. Publishing the list is advisory. So is deciding what belongs on it: "Each Department and ALB should decide what is defined as business critical based on the extent to which they influence significant financial and funding decisions... The definitions and thresholds of business criticality should be aligned with their organisation's own risk framework. The thresholds should be agreed by the director of analysis or equivalent" [1]. No external body sets the bar, checks it, or publishes what any department's bar actually is; the agreement that sets it happens inside the department, with the department's own analysis director. The list can also be trimmed by exemptions the AQuA Book itself supplies: FOI Act exclusions, national security, "policy under development," "commercial interests," and, catch-all, "further reasons where the risk of a negative consequence is deemed to outweigh the potential benefits" [1]. GovS 010, the Government Functional Standard covering all analysis carried out "in departments and arm's length bodies," does not add a firmer test of its own. Its one substantive mention of business-critical models simply defers: "further guidance on business-critical models is provided in the Aqua Book" [2].

What the government's own website shows

An advisory rule with a self-set threshold is still checkable at the most basic level: does the list exist at all. Searching GOV.UK's own search engine for "business critical models" filtered to each department in turn finds no dedicated publication for HM Treasury, the department that literally issues the AQuA Book's parent guidance [7]; none for HM Revenue and Customs, which runs the tax system on models whose errors would carry obvious financial stakes [8]; none for the Home Office [9]; none for the Ministry of Justice [10]; and none for the Department for Environment, Food and Rural Affairs [11]. This does not prove these departments hold no business-critical models by their own definition, or that none exists behind an internal document never put on GOV.UK. It does show that whatever list the AQuA Book asks for is not visible to the public those models ultimately affect, for five of the government's largest departments by spend and reach.

The department that quotes the rule hasn't followed it

The Cabinet Office is one of the few organisations that does publish a list, and it names the exact requirement it is meeting: "Cabinet Office list of Business Critical Models published in line with the Addendum to the Aqua Book (5th October 2023), which recommends annual publication" [3]. That list, nine named models covering the Civil Service Pension Costs Model, the National Security Risk Assessment and the Infected Blood Compensation Model among others, was published once, on 31 October 2024, "as of October 2024" [4]. Almost two years on, GOV.UK's own "Updates to this page" field, the mechanism the site uses to show when a document has been revised, records nothing beyond that original publication date [3]. A rule the Cabinet Office cites by name, and describes as recommending annual publication, has been met by the Cabinet Office exactly once.

The claims, tested

The document's own words What the evidence actually shows Verdict
Departments and ALBs "should publish a list of business critical models (BCM)... at least annually" [1] GOV.UK carries no dedicated business-critical-models publication for HM Treasury, HMRC, the Home Office, the Ministry of Justice or DEFRA [7] [8] [9] [10] [11] An advisory rule with no visible compliance among five of government's largest departments
The Cabinet Office's own list is "published in line with the Addendum to the Aqua Book... which recommends annual publication" [3] That list has one edition, dated October 2024, with no recorded update since [3] [4] The department citing the annual-publication recommendation by name has not itself met it since the first edition
"The definitions and thresholds of business criticality should be aligned with their organisation's own risk framework. The thresholds should be agreed by the director of analysis or equivalent" [1] No published document sets an external test, and GovS 010 defers entirely back to the AQuA Book rather than adding one [2] A department could set its own bar low and there is no external check to catch it

The mistakes, counted

No department's list is checkable against an external threshold, because none exists (1). The AQuA Book leaves the definition of "business critical" to each organisation's own risk framework, agreed internally with its director of analysis, and GovS 010 does not add a firmer test [1] [2].

The annual-publication expectation is not visibly met, including by the department that names it (2). Five of the largest departments checked directly have no dedicated list on GOV.UK at all, and the Cabinet Office, which does publish one under the AQuA Book Addendum's "recommends annual publication" wording, has not updated its own list since October 2024 [3] [4].

Credit where due

Two organisations show the requirement can be met properly. The Department for Transport's register of business critical models was first published in September 2014 and was last updated 11 May 2026, a genuine twelve-year track record rather than a one-off [5]. The Ministry of Defence has published a fresh edition of its own list almost every year since 2014, most recently in November 2025 covering its position as of that April [6]. And the AQuA Book itself, in its 2025 revision, is a more serious document than the version it replaced: it adds real guidance on assuring AI and "black box" models, multi-use models and third-party analysis that the 2015 edition never addressed. The gap is not that the guidance is thin. It is that the one part of it built for public accountability, the published list, has no working mechanism to make sure it happens.

Verdict

Four stars, from two documented mistakes. The AQuA Book asks every department and arm's-length body to tell the public which of its models are too risky to get wrong, on a cadence and a definition the department sets for itself. Two organisations, the Department for Transport and the Ministry of Defence, have shown that this works when someone actually keeps it up. Search for most of the rest of Whitehall, including the department that writes the tax rules, the department that runs the border, and the department that wrote the requirement itself, and the record on GOV.UK is either silent or nearly two years out of date.

Sources

  1. The AQuA Book, GOV.UK, Government Operational Research Service, Government Analysis Function, Government Actuary's Department and Office for National Statistics, published 30 July 2025
  2. GovS 010: Analysis, version 2.2, Government Functional Standard, issued 26 August 2025
  3. Cabinet Office list of business critical models, GOV.UK, Cabinet Office, published 31 October 2024
  4. Business Critical Models in the Cabinet Office, GOV.UK, Cabinet Office, published 31 October 2024
  5. DfT register of business critical models, GOV.UK, Department for Transport, published 4 September 2014, updated 11 May 2026
  6. Business critical models: Ministry of Defence 2025, GOV.UK, Ministry of Defence, published 17 November 2025
  7. GOV.UK Search API: "business critical models", filtered to HM Treasury
  8. GOV.UK Search API: "business critical models", filtered to HM Revenue and Customs
  9. GOV.UK Search API: "business critical models", filtered to the Home Office
  10. GOV.UK Search API: "business critical models", filtered to the Ministry of Justice
  11. GOV.UK Search API: "business critical models", filtered to the Department for Environment, Food and Rural Affairs
SHARE THIS ARTICLEXBlueskyMastodonLinkedInRedditEmail