This site found a government digital standard's risk rules were mandatory for suppliers who could not reach the guidance behind them. Thirteen days later the standard was rewritten for artificial intelligence, and the sentence naming suppliers disappeared.
Estimated reading time: 6 minutes
In short. On 18 September this site found that GovS 005: Digital makes the Orange Book's risk rules mandatory for civil servants and third-party suppliers alike, while the only detailed guidance on meeting them had sat behind a civil service login since July. Thirteen days later, on 1 October, GOV.UK published Version 2.2 of GovS 005, a rewrite its own change note describes as adding artificial intelligence references "throughout the entirety of the Functional Standard." The login gate behind the Orange Book mandate is unchanged. The sentence that named third-party suppliers as part of who the standard directs is no longer in it. Five documented mistakes: three stars.
Rule 3 of this site's constitution is that updates produce diffs, never a silent overwrite. GovS 005: Digital is exactly the kind of document that rule exists for: this site tore it down on 18 September, and the scanner that watches its GOV.UK page flagged it changed again on 2 October, confirmed twice [2]. The cause is a genuine rewrite, not page furniture: the standard's own PDF has moved from Version 2.1 (December 2023) to Version 2.2 (September 2026), and GOV.UK's own update history dates it precisely: "1 October 2026, This version updates terminology to 'government digital and data' where appropriate. It also adds proportionate references to Artificial Intelligence (AI), as well as Knowledge and Information Management throughout the entirety of the Functional Standard" [2].
What the rewrite actually changed
The new PDF's own cover page calls this a "Minor update," then describes it as updating "the standard from a digital, data and technology focus to a broader government digital and data standard," simplifying and modernising "much of the language," strengthening "lifecycle management, governance and accountability throughout," and introducing "extensive new content on the safe, secure, transparent and responsible use of artificial intelligence (AI), embedding AI considerations across governance, strategy, assurance, service management, technology, data and risk management" [1] (page 2). That is not a small claim for a document to make about itself. AI now appears on more than twenty of the standard's thirty-five content pages, woven into sections on technology, governance, data, assurance and risk in turn.
Buried inside that rewrite is a change the document does not flag in its own summary. This site's 18 September teardown quoted Version 2.1's Purpose and Scope section stating the standard "provides direction and guidance for permanent secretaries, directors general, chief executive officers of arm's length bodies and third-party suppliers" [3], naming suppliers as part of who it binds directly. That sentence is gone. Version 2.2's equivalent section, "This standard is for," lists senior accountable leaders, senior leaders accountable for digital and data, senior leaders for strategy, policy or service delivery, and practitioners who plan, deliver, operate or manage digital and data activity [1] (page 6). Third-party suppliers are not on it. The word still appears three times elsewhere, describing suppliers as a delivery option alongside in-house teams and naming them among people who must follow records-management rules, but never again as part of who the standard itself addresses [1] (pages 13, 21, 31).
The old PDF cannot be checked against this directly: fetched again for this piece, its GOV.UK asset has been taken down entirely, superseded in place rather than kept available for comparison. The only surviving record of its exact wording is this site's own 18 September teardown, quoted above.
The claims, tested
| The document's own words | What we found | Verdict |
|---|---|---|
| Version 2.2 calls itself a "Minor update" while adding AI references "throughout the entirety of the Functional Standard" [1] (page 2) | AI terminology now appears across more than twenty of the standard's thirty-five content pages, spanning governance, strategy, assurance, technology, data and risk | A rewrite of this scale labelled "minor" |
| Version 2.1 named "third-party suppliers" directly in its list of who the standard is for [3] | Version 2.2's equivalent list, "This standard is for," omits third-party suppliers entirely [1] (page 6) | The sentence naming who is bound changed; the mandatory rule it introduced did not |
| "The requirements of the Orange Book: management of risk, principles and concepts, shall be met" [1] (page 13) | The Orange Book's own GOV.UK page is unchanged since 29 July 2026, and the Government Finance Function's Risk Management Centre of Excellence, its only detailed public guidance, still requires a civil service sign-in [4] [5] | Same mandatory rule, same locked door, unaddressed by a rewrite that touched almost everything else |
| Version 2.1 pointed readers to GovS 001, Government Functions, for what happens if a "shall" is not met [3] | GovS 001 is not mentioned anywhere in Version 2.2's text or its 25-item reference list [1] (page 35) | The only pointer toward consequences was removed, not answered |
The mistakes, counted
A rewrite that touched most of the document is labelled "minor" (1). The standard's own cover page calls Version 2.2 a "Minor update" in the same sentence that describes new content spanning governance, strategy, assurance, service management, technology, data and risk management [1] (page 2).
The sentence naming suppliers as bound by the standard did not survive the rewrite (2). Version 2.1 named third-party suppliers directly among who the standard is for [3]; Version 2.2's replacement list does not [1] (page 6).
The mandatory Orange Book clause survived unchanged (3). The requirement that Orange Book risk rules "shall be met" still appears, now on page 13 rather than pages 7 and 25, with no change to its force [1] (page 13).
The guidance gap behind that clause is exactly as it was (4). The Orange Book's GOV.UK page has not moved since 29 July 2026, and the Risk Management Centre of Excellence it points to still returns a sign-in form, not guidance [4] [5].
The self-assessment framework was not touched, and still measures against an expired plan (5). The Digital and Data Continuous Improvement Assessment Framework remains Version 1.2 of 23 April 2026, unchanged alongside the standard's rewrite, and its top performance tier still measures against "the cross-government 2022 to 2025 Roadmap for Digital and Data," whose own GOV.UK page has not moved since 29 November 2023 [6] (page 7) [7].
Credit where due
Government Digital Service did not let this teardown sit unanswered: within two weeks of publication, the document it concerns was reissued, not quietly amended behind the scenes. The AI content itself, so far as the standard's own text goes, reads as substantive rather than decorative, with specific lifecycle, assurance and human-control expectations attached to AI systems rather than the word used as a label. And the standard still names a specific accountable role for digital risk, carried over unchanged from the version this site reviewed, rather than leaving accountability diffuse.
Verdict
Three stars, from five documented mistakes. A government standard spent its first rewrite in three years adding artificial intelligence to nearly every page, while the two problems a published teardown had already identified, a mandatory rule with no public guidance reachable by the people it names, and a scorecard measuring against a plan that expired in 2023, were left exactly where they stood. The one textual change that touches this site's findings removed the sentence naming who the mandate binds, rather than fixing what it binds them to.
The star score counts five documented mistakes against GovS 005's own text and its own GOV.UK record: the cover page's "Minor update" label against the scale of its own described changes; the removal of the sentence naming third-party suppliers as part of who the standard is for; the unchanged mandatory Orange Book clause; the unchanged login gate behind the only detailed guidance on meeting it; and the unreissued self-assessment framework still scored against an expired roadmap. Five falls in the 4 to 9 band: three stars; the bands are on the ratings page. This is a diff entry against this site's 18 September teardown of GovS 005: Digital, not a retraction of it; the earlier piece's four findings about the Orange Book access gap and the stale self-assessment framework stand. Analysis is of GovS 005: Digital Version 2.2, issued September 2026 and live on GOV.UK as of 2 October 2026.
Sources
- GovS 005: Digital (PDF, Version 2.2, September 2026), Government Digital and Data function
- Government Functional Standard GovS 005: Digital, GOV.UK, last updated 1 October 2026
- "Government's own digital standard tells civil servants and their suppliers that Treasury's risk rules are mandatory, not advisory", Tracked Changes, 18 September 2026
- The Orange Book, HM Treasury, last updated 29 July 2026
- Risk Management Centre of Excellence, Government Finance Function (OneFinance)
- Digital and Data Continuous Improvement Assessment Framework (PDF, Version 1.2, 23 April 2026), Government Digital Service
- Transforming for a digital future: government's 2022 to 25 roadmap for digital and data, Cabinet Office, last updated 29 November 2023