Government's own digital standard tells civil servants and their suppliers that Treasury's risk rules are mandatory, not advisory. Since July, the only practical guide to following them has needed a civil service login that no supplier can use.
Estimated reading time: 6 minutes
In short. GovS 005: Digital is the functional standard that sets the rules for every digital, data and technology project run by a UK government department or arm's length body, and it names third-party suppliers as part of its audience directly. Twice in its own text, it states that the Orange Book's risk-management requirements "shall be met", the strongest form of obligation the standard uses. Since 29 July 2026, the only practical guidance on how to meet those requirements has sat behind a civil service login that a third-party supplier cannot obtain. The standard's own self-assessment tool, reissued as recently as 23 April 2026, still measures top performance against a cross-government roadmap that expired in 2025, with no public record anywhere of how any department has actually scored. Four documented mistakes: three stars.
GovS 005: Digital is not a suggestion document. Issued by the Government Digital Service and approved as one of the government's functional standards, its own purpose statement says it exists "to set expectations for the management of digital, data and technology in government" [1] (page 2). Its stated audience is not limited to civil servants: the standard "provides direction and guidance for permanent secretaries, directors general, chief executive officers of arm's length bodies and third-party suppliers" [1] (page 2), naming the companies that build and run government digital services as part of who the standard binds, not just who it describes.
The standard uses "shall" to mark a mandatory element and "should" for an advisory one, a distinction it defines for itself [1] (page 2). Under section 4.3, Assurance, it states plainly: "The requirements of the Orange Book: management of risk - principles and concepts, shall be met" [1] (page 7). The same sentence appears again under section 8.12, Risk management [1] (page 25), the section that defines the duties of the senior officer accountable for an organisation's digital portfolio, a role the standard notes "is often known as Chief Digital Officer" [1] (page 9), and whose responsibilities include "managing digital, data and technology related risk within the organisation's risk appetite and tolerance" [1] (page 9).
What the mandate actually points to
This site's own reporting this morning established what "the Orange Book" now contains. On 29 July 2026, HM Treasury deleted four of the Orange Book's practical supporting documents, including its only guidance on setting risk appetite, saying they "no longer fully reflect the current Risk Centre of Excellence thinking and practice" [2]. In their place, the page added a link to the Government Finance Function's internal site, describing it as available to "most public sector employees" [2]. Fetched again directly for this piece, that page still returns a form headed "Sign-in" with fields for "Email" and "Password" and a "Need to register?" link beneath them [3], not the guidance itself.
A civil service login is not a plausible route for a third-party supplier. GovS 005 names those suppliers as bound by its own direction on page 2; the Orange Book requirement it makes mandatory, on pages 7 and 25, now has no publicly reachable practical guidance behind it at all. A supplier told to meet Treasury's risk-management requirements has, since July, had nowhere public to read what that actually involves beyond the Orange Book's own core principles document, unchanged since May 2023.
The standard's own scorecard
GovS 005 is not just a set of rules; it comes with a self-assessment tool, the Digital and Data Continuous Improvement Assessment Framework, which organisations use to score their own performance against the standard. The version current at the time of writing is dated "Version 1.2 - 23 April 2026" [4] (page 2), reissued the same week the underlying GovS 005 page itself was last touched. Its top performance tier for governance and strategy, labelled "Best", requires that "the organisation's digital strategy exceeds targets set by GDS and/or is delivering to the commitments ahead of schedule" against "the cross-government 2022 to 2025 Roadmap for Digital and Data" [4] (page 7). That roadmap's own GOV.UK page has not been updated since 29 November 2023 and carries no progress report, no completion notice and no account of which of its commitments were actually delivered by the time its own window closed [5]. A framework reissued in April 2026 is still asking departments to measure themselves against a plan whose own stated end date is more than a year in the past, with nothing published to say whether it succeeded.
Nor is there any public record of the scores that result. A search of GOV.UK for the assessment framework's own results turns up nothing resembling a departmental scorecard, aggregate or otherwise, despite the framework's own top-tier criterion for digital strategy urging that it be "published publicly, where possible" [4] (page 6). The standard asks departments to publish their ambition. It does not appear to publish how they did against it.
The claims, tested
| The document's own words | What the record actually shows | Verdict |
|---|---|---|
| GovS 005 "provides direction and guidance for... third-party suppliers" [1] (page 2) and "the requirements of the Orange Book... shall be met" [1] (pages 7, 25) | The only practical guidance on meeting the Orange Book's requirements sits behind a civil service login [3], unreachable by the suppliers page 2 names | A mandatory duty with no public route for part of its own named audience to fulfil it |
| The self-assessment framework's top tier rewards exceeding "targets set by GDS" under "the cross-government 2022 to 2025 Roadmap" [4] (page 7), in a version reissued 23 April 2026 | The roadmap's own page has not been updated since 29 November 2023 and reports no outcome for the period it covered [5] | The current scorecard measures against a plan nobody has confirmed succeeded or failed |
| Digital strategy performance should be "published publicly, where possible" [4] (page 6) | No aggregate or departmental assessment results against GovS 005 or the CIAF are published anywhere on GOV.UK | The framework asks for public reporting it does not itself appear to produce |
The mistakes, counted
A mandatory duty extended by name to third-party suppliers has no public guidance behind it (1). GovS 005 names third-party suppliers on page 2 as part of who it directs, then makes Orange Book compliance mandatory twice, on pages 7 and 25. Since 29 July 2026 the only detailed guidance on that compliance has required a civil service login [3].
The standard's own scorecard measures against an expired plan (2). The Continuous Improvement Assessment Framework, reissued 23 April 2026, still sets its top performance tier against the "2022 to 2025 Roadmap for Digital and Data" [4] (page 7), a plan whose own page has not been updated since November 2023 and reports no final outcome [5].
No public data shows how any department actually scores (3). Despite the framework's own preference for public reporting "where possible" [4] (page 6), no departmental or aggregate results against GovS 005 appear anywhere on GOV.UK.
The standard does not say what happens if its own "shall" is ignored (4). GovS 005 points readers to a different document, GovS 001, Government Functions, for "expectations relating to management of a function across government, and management of functional standards" [1] (page 3), rather than describing any consequence within its own text for a department, officer or supplier that does not meet a mandatory requirement.
Credit where due
GovS 005's internal structure is not vague where it matters most: the standard names a specific accountable role, the senior officer accountable for an organisation's digital portfolio, usually a Chief Digital Officer, and ties that role directly to risk management duties rather than leaving accountability diffuse [1] (page 9). The self-assessment framework itself is detailed and specific, with graded criteria rather than a single pass or fail, which is a genuine attempt at measurable maturity rather than a box-ticking exercise. And the standard is current in the sense that matters for a rulebook: its GOV.UK page has been checked and touched as recently as April 2026, not abandoned since issue.
Verdict
Three stars, from four documented mistakes. GovS 005 does what a functional standard is supposed to do on paper: it names who is bound, states what is mandatory, and points to the detailed doctrine, the Orange Book, that mandatory duty rests on. What it does not do is ensure that doctrine stays reachable by the people it names. A supplier told a requirement is not optional, and then finds the only practical guide to meeting it needs a password it cannot hold, is being asked to comply with something it cannot read.
Sources
- Government Functional Standard GovS 005: Digital (PDF, Version 2.1, December 2023), Government Digital Service
- The Orange Book, HM Treasury, last updated 29 July 2026
- Risk Management Centre of Excellence, Government Finance Function (OneFinance)
- Digital and Data Continuous Improvement Assessment Framework (PDF, Version 1.2, 23 April 2026), Government Digital Service
- Transforming for a digital future: government's 2022 to 25 roadmap for digital and data, Cabinet Office, last updated 29 November 2023
- Government Functional Standard GovS 005: Digital, GOV.UK, last updated 22 April 2026