The standard governing every part of government defines mandatory in a circle, then says the record of who complied is not meant to be published. It also repeats the Treasury risk duty this site found locked behind a login.
Estimated reading time: 7 minutes
In short. GovS 001, Government Functions, is the standard that sits above every other government functional standard, including GovS 005, Digital, torn down on this site this morning. It makes the Orange Book's risk-management requirements mandatory in almost the same words GovS 005 uses, so the login gate this site found on the Orange Book's practical guidance in July 2026 blocks compliance with the whole of government, not just digital work. Asked what a mandatory "shall" actually requires, the standard's own definition only bars claiming compliance while deviating from it; the closest it comes to a real penalty is discretionary language decided by a board that publishes no minutes on the subject. And its own text states that completed self-assessments are "not intended for publication", which is the direct explanation for a gap already found in GovS 005's scorecard. Four documented mistakes: three stars.
GovS 001 is not a standard for digital teams, or finance teams, or any one function. Issued by the Cabinet Office and now in its second version, it "sets expectations for the direction and management of functions across government and within organisations, including management of functional standards" [1] (page 1), the umbrella document the entire functional standards suite, GovS 002 through GovS 011, sits under. Under its own section on functional assurance, it states: "The requirements of The Orange Book (management of risk - principles and concepts) shall be met" [1] (page 13). This is close to a direct repeat of the sentence this site found in GovS 005, Digital this morning: "the requirements of the Orange Book: management of risk - principles and concepts, shall be met" [2] (pages 7, 25). The duty is not particular to digital work. It is the baseline for every function GovS 001 governs.
The login gate this reaches now
This site's own reporting this morning established that the Orange Book's only practical guidance has sat behind a civil service login since 29 July 2026, when HM Treasury deleted four supporting documents and replaced them with a link to the Government Finance Function's internal site [3]. Fetched again directly for this piece, that page still returns a form headed "Sign-in" with fields for "Email" and "Password" [4]. GovS 001 makes clear that this is not a digital-function problem alone. Every function operating under the functional standards suite, and every organisation subject to it, carries the same mandatory duty, and the same login gate now sits in the way of meeting it.
What "shall" actually means
GovS 001 defines its own vocabulary in a writing-style annex for anyone drafting a functional standard. It defines the word that carries the mandatory duty this way: "shall Requirements - content from which no deviation is permitted if compliance with the document is to be claimed" [1] (page 38). Read closely, that sentence does not describe a consequence for failing to meet a mandatory requirement. It describes a condition on the claim of compliance: deviate, and you may not say you complied. It says nothing about what follows if an organisation deviates and does not make that claim, or simply never checks.
The standard's own text does go further than that definition, but only in hedged terms. "Failure to comply is an indicator of heightened risk about the underlying transactions, and of potential systemic failure. It would trigger additional scrutiny and likely corrective action through management lines, and might also lead to formal independent assurance reviews and adverse findings by internal and/or external auditors" [1] (page 32). Every verb in that sentence is conditional: "would trigger", "likely", "might". None of it states a defined threshold for when scrutiny becomes mandatory, or names a body required to act.
The nearest thing to a formal escalation route sits earlier in the standard, where senior stakeholders are told to "escalate issues to Civil Service Board where necessary" [1] (page 10). The Civil Service Board itself is "chaired by the chief operating officer for the Civil Service on behalf of the cabinet secretary and head of the Civil Service" and "comprises a quorum of permanent secretaries" [1] (page 14). "Where necessary" is not defined anywhere in the standard, and a GOV.UK search for published Civil Service Board minutes or decisions on functional standard non-compliance returns nothing resembling a public record. The body that functional escalation ultimately reaches meets, and decides, without a public account of what it decided or why.
The scorecard gap, explained
GovS 005's own self-assessment tool, the Digital and Data Continuous Improvement Assessment Framework, was found this morning to have no public results anywhere on GOV.UK, despite its own top-tier criterion urging that digital strategy performance be "published publicly, where possible" [5] (page 6). GovS 001, the standard that governs how every function's self-assessment framework is meant to work, explains why. In its own annex on continuous improvement, it states plainly: "completed self-assessments by organisations are for internal government management purposes, and not intended for publication" [1] (page 35). The gap this site found in GovS 005's scorecard is not an oversight. It is what the parent standard says should happen, stated in the same document that lets individual frameworks describe publication as merely something a function "is able to" do "should it wish" [1] (page 35).
The claims, tested
| The document's own words | What the record actually shows | Verdict |
|---|---|---|
| "Shall" requirements permit "no deviation... if compliance with the document is to be claimed" [1] (page 38) | The definition bars a compliance claim on deviation; it states no penalty for the deviation itself | A word defined around the claim, not the conduct |
| Failure to comply "would trigger additional scrutiny and likely corrective action" and "might also lead to formal independent assurance reviews" [1] (page 32) | No defined threshold triggers the sequence; escalation is "where necessary" [1] (page 10) to a board with no published record on the subject | A consequence chain built entirely from discretionary language |
| "The requirements of The Orange Book... shall be met" [1] (page 13), for every function across government | The Orange Book's only practical guidance has needed a civil service login since 29 July 2026 [4] | A government-wide mandate, not just a digital one, resting on guidance most of its own audience cannot reach |
| Self-assessments "are for internal government management purposes, and not intended for publication" [1] (page 35) | GovS 005's own CIAF has no published results anywhere on GOV.UK, consistent with this instruction | The transparency gap already found is the parent standard's stated design |
The mistakes, counted
A mandatory Orange Book duty extends to every function, not just digital, and inherits the same login gate (1). GovS 001's own text makes the requirement near-identical to the one in GovS 005 [1] (page 13), so the practical guidance login-gated since 29 July 2026 blocks compliance across the whole of government [4].
The standard's own definition of "mandatory" does not describe a penalty (2). "Shall" is defined as barring a compliance claim on deviation, not as carrying a stated consequence for the deviation itself [1] (page 38).
The nearest thing to a real consequence is entirely discretionary and decided in private (3). Scrutiny "would trigger", corrective action is "likely", assurance review "might" follow [1] (page 32), and escalation reaches the Civil Service Board only "where necessary" [1] (page 10), a body with no published minutes on functional standard compliance.
The standard states self-assessment results are not meant to be published (4). "Completed self-assessments by organisations are for internal government management purposes, and not intended for publication" [1] (page 35), explaining the transparency gap already found in GovS 005's own scorecard.
Credit where due
GovS 001 is not careless about structure. It names the Civil Service Board and gives it a defined, accountable membership rather than leaving oversight vague [1] (page 14), and it sets out a genuine three-tier assurance model, from operational management up to independent bodies including the National Audit Office [1] (page 16), rather than describing assurance as a single box to tick. Its own writing-style guidance, defining "shall", "should" and "may" precisely for anyone drafting a standard [1] (page 38), is exactly the kind of internal discipline that keeps eleven separate standards consistent with each other. And the standard is current: last updated 15 April 2024, not abandoned since its 2021 launch [6].
Verdict
Three stars, from four documented mistakes. GovS 001 does the one thing an umbrella standard has to do: it makes the same mandatory duty apply everywhere, consistently, rather than leaving each function to invent its own version. What it does not do is answer the question its own subordinate standard, GovS 005, left open. Ask what happens when a "shall" is ignored, and the master standard offers a definition that only bites on the claim of compliance, a consequence chain written entirely in "would" and "might" and "where necessary", and a closed-door board whose decisions are never published, on a subject where its own rules say the underlying self-assessments were never meant to be published either.
Sources
- Government Functional Standard GovS 001: Government Functions (PDF, Version 2.0, 15 June 2022), Cabinet Office
- Government Functional Standard GovS 005: Digital (PDF, Version 2.1, December 2023), Government Digital Service
- The Orange Book, HM Treasury, last updated 29 July 2026
- Risk Management Centre of Excellence, Government Finance Function (OneFinance)
- Digital and Data Continuous Improvement Assessment Framework (PDF, Version 1.2, 23 April 2026), Government Digital Service
- Government Functional Standard GovS 001: Government Functions, GOV.UK, last updated 15 April 2024