<?xml version='1.0' encoding='UTF-8'?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Tracked Changes</title>
    <link>https://www.trackedchanges.co.uk/feed.xml</link>
    <description>Tracked Changes reads UK government legislation, guidance and playbooks line by line and checks what they claim against the evidence they cite. Every document we scan lands in a public register; the ones that earn it get a full teardown. When a document does what it says, we say that too.</description>
    <atom:link href="https://www.trackedchanges.co.uk/feed.xml" rel="self"/>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en-gb</language>
    <lastBuildDate>Sun, 13 Sep 2026 05:52:06 +0000</lastBuildDate>
    <item>
      <title>The Corrections Log. Every Error This Site Publishes, and What Was Done About It.</title>
      <link>https://www.trackedchanges.co.uk/2026-updates/corrections-log.html</link>
      <description>The public corrections log for Tracked Changes. Substantive errors are corrected in the article and recorded here permanently with the date, the original wording, the correction, and how the error occurred. Registry corrections are logged here too, since the Daily Register regenerates from the data.</description>
      <content:encoded><![CDATA[<figure class="article-hero">
<img alt="A printed manuscript page marked up by hand during copy editing." height="630" loading="eager" src="https://www.trackedchanges.co.uk/assets/images/articles/corrections-log/hero.webp" width="1200"/>
<figcaption>A manuscript page marked up in copy editing, 2014. Photo: <a href="https://commons.wikimedia.org/wiki/File:Example_of_copyedited_manuscript.jpg">Phoebe / Wikimedia Commons</a>, <a href="https://creativecommons.org/licenses/by-sa/3.0/">CC BY-SA 3.0</a>.</figcaption>
</figure>

<blockquote class="govuk-inset-text">
<p><strong>In short.</strong> This page records every substantive error the site publishes: the date, what was wrong, the corrected wording, and how it happened. Corrections to the registry itself are logged here too, because the Daily Register regenerates from that data and a silent data fix would silently rewrite the record. Entries are never removed.</p>
</blockquote>
<p><strong>The policy.</strong> When an error is found, the article or registry entry is corrected with a dated note and an entry is added here. If the error was material to a piece's verdict, the correction is also flagged at the top of the article. To report an error, use the route on the <a href="https://www.trackedchanges.co.uk/contact.html">contact page</a>, naming the claim and the document that contradicts it; reports are acknowledged and the outcome recorded whichever way it goes.</p>
<p>A site whose business is holding government documents to their own words has no room to be precious about its own. The teardown format makes claims that are checkable by design; when a check goes against us, this is where it shows.</p>
<h2>The log</h2>
<p>No corrections yet. The site launched on 11 September 2026; the first substantive error, when it comes, will be recorded here with the date, the original wording, the correction, and an honest account of how it got through.</p>]]></content:encoded>
      <guid isPermaLink="false">https://www.trackedchanges.co.uk/2026-updates/corrections-log.html</guid>
      <pubDate>Fri, 11 Sep 2026 22:45:00 +0000</pubDate>
    </item>
    <item>
      <title>The government's AI Playbook tells civil servants to check everything. A line-by-line reading suggests nobody checked the playbook.</title>
      <link>https://www.trackedchanges.co.uk/2026-updates/ai-playbook-plausible-but-wrong.html</link>
      <description>A close reading of the UK Government's Artificial Intelligence Playbook finds verifiable factual errors, a security anecdote describing an event that did not happen, a misstatement of UK data protection law, and direct contradictions between its agentic AI enthusiasm and its own security analysis.</description>
      <content:encoded><![CDATA[<p>Estimated reading time: 8 minutes</p>
<figure class="article-hero">
<img alt="The Cabinet Office building at 70 Whitehall, London, seen from the street." height="630" loading="eager" src="https://www.trackedchanges.co.uk/assets/images/articles/ai-playbook-plausible-but-wrong/hero.webp" width="1200"/>
<figcaption>The Cabinet Office, 70 Whitehall, London, 2017. Photo: <a href="https://commons.wikimedia.org/wiki/File:Cabinet_Office,_70_Whitehall,_London.jpg">Paul the Archivist / Wikimedia Commons</a>, <a href="https://creativecommons.org/licenses/by-sa/4.0/">CC BY-SA 4.0</a>.</figcaption>
</figure>

<blockquote class="govuk-inset-text">
<p><strong>In short.</strong> The Artificial Intelligence Playbook for the UK Government instructs every civil servant to treat AI output as plausible but not necessarily correct, and to check everything. Read against the evidence it cites, the playbook itself fails that test: it misnames its own sponsoring department three times, presents a security incident in a form that did not happen, invents a data-retention policy, overstates the single most important legal constraint on government AI, and contradicts its own security analysis on the question departments most need answered. Much of it is sensible. None of it has been revised in the nineteen months since publication.</p>
</blockquote>
<p>In February 2025 the Government Digital Service published the Artificial Intelligence Playbook for the UK Government <a href="https://www.gov.uk/government/publications/ai-playbook-for-the-uk-government">[1]</a>, a 118-page guide meant to help departments and public bodies "harness the power of a wider range of AI technologies safely, effectively, and responsibly" <a href="https://assets.publishing.service.gov.uk/media/67aca2f7e400ae62338324bd/AI_Playbook_for_the_UK_Government__12_02_.pdf">[2]</a>. It carries a ministerial foreword, credits from more than twenty departments, four tech giants and five academic institutions, and a central message it repeats relentlessly: AI output is plausible but not necessarily correct, so check everything <a href="https://gds.blog.gov.uk/2025/02/10/launching-the-artificial-intelligence-playbook-for-the-uk-government/">[3]</a>.</p>
<p>It is advice the playbook's own authors could have taken. A line-by-line reading of the document, which at the time of writing remains unrevised on GOV.UK nineteen months after publication <a href="https://www.gov.uk/government/publications/ai-playbook-for-the-uk-government">[1]</a>, turns up verifiable factual errors, a security anecdote describing an event that did not happen that way, a misstatement of UK data protection law, and direct contradictions between the playbook's enthusiasm for autonomous AI and its own security analysis.</p>
<p>None of this makes the playbook worthless. Much of it is sensible, and parts of its security guidance are better than most vendor documentation. But a government document whose first principle is "you know what AI is and what its limitations are" should be held to the standard it sets for the machines.</p>
<h2>A department that cannot spell its own name</h2>
<p>Start with the smallest error, because it is the most telling. On pages 31, 44 and 69, the playbook names its own sponsoring department as the "Department for Science, Information and Technology" <a href="https://assets.publishing.service.gov.uk/media/67aca2f7e400ae62338324bd/AI_Playbook_for_the_UK_Government__12_02_.pdf">[2]</a>. It is the Department for Science, Innovation and Technology: the department whose minister, Feryal Clark, signed the foreword, and which is named correctly elsewhere in the same document. Three occurrences is not a typo; it is a proofreading process that did not happen.</p>
<p>It is not alone. The acknowledgements (page 5) thank the "Department for Levelling Up, Housing and Communities", a department that had been renamed the Ministry of Housing, Communities and Local Government seven months before publication, and file BCS, a professional body, under "Academic institutes". Page 34 refers to the "UK Statistic Authority" (it is the UK Statistics Authority). Pages 41 and 43 cite the "Public Contract Regulations 2015" (Public Contracts Regulations). Page 101 tells departments to comply with standards defined by the "International Standards Organisation", and ISO's actual name is the International Organization for Standardization. Individually trivial; collectively, a signal about how carefully the rest was checked.</p>
<h2>The security story that did not happen that way</h2>
<p>The security chapter is the playbook's strongest section, which makes its factual stumbles more unfortunate.</p>
<p>On page 79, illustrating supply-chain risk, it states that "when software libraries are hacked, all downstream systems that depend on those libraries are affected", and offers as its notable example "the Faker NPM hack". The faker.js incident of January 2022 was not a hack. The package's own maintainer, Marak Squires, deliberately sabotaged faker.js and its sibling colors.js in protest at large companies using his free work <a href="https://www.bleepingcomputer.com/news/security/dev-corrupts-npm-libs-colors-and-faker-breaking-thousands-of-apps/">[4]</a> <a href="https://www.sonatype.com/blog/npm-libraries-colors-and-faker-sabotaged-in-protest-by-their-maintainer-what-to-do-now">[5]</a>. The distinction matters because the lessons differ: an external compromise argues for supply-chain integrity checks, while maintainer sabotage argues for dependency vetting and caution about single-maintainer open-source projects. The playbook draws the wrong lesson from a mislabelled event.</p>
<p>Page 94 is worse. A scenario describes a developer who "receives advice to install a specific software package, ArangoDB... When the LLM was trained, the package did not exist. A hacker has previously interrogated the LLM... They then created a malicious package with the fictitious name." ArangoDB is a real database from a real company. In the Vulcan Cyber research the playbook itself cites, ChatGPT hallucinated a non-existent npm package called arangodb, while the legitimate JavaScript client is arangojs, and no hacker planted malware; a researcher registered an empty proof-of-concept package to demonstrate the risk <a href="https://www.securityweek.com/chatgpt-hallucinations-can-be-exploited-to-distribute-malicious-code-packages/">[6]</a> <a href="https://www.infosecurity-magazine.com/news/chatgpt-spreads-malicious-packages/">[7]</a>. As written, the playbook implies a real vendor's product is fictitious and presents a hypothetical as a completed attack. The underlying risk, now widely called slopsquatting, is real and worth warning about <a href="https://www.lasso.security/blog/ai-package-hallucinations">[8]</a>. The example, as told, is not.</p>
<p>Then there is page 77, where the playbook says Microsoft's Azure OpenAI service offers models "running in a private instance with zero-day retention policies". There is no such thing as "zero-day retention": the phrase collides "zero-day", a class of security vulnerability, with "zero data retention", a data-handling posture. And the substance is wrong too. Azure OpenAI's default is to retain prompts and completions for up to 30 days for abuse monitoring; genuine zero-data-retention requires an application to Microsoft and approval <a href="https://learn.microsoft.com/en-us/answers/questions/4372674/how-to-opt-in-for-zero-data-retention-with-azure-o">[9]</a>. A procurement team relying on this sentence would misdescribe its own data-handling position, in a document that exists to prevent exactly that.</p>
<h2>The law, overstated</h2>
<p>Page 73 tells civil servants that UK GDPR "Article 22 currently prohibits decision(s) based solely on automated processing that have legal or similarly significant consequences", and that services affecting a person's legal rights "must only use AI to support decisions that must be made by a human decision maker" <a href="https://assets.publishing.service.gov.uk/media/67aca2f7e400ae62338324bd/AI_Playbook_for_the_UK_Government__12_02_.pdf">[2]</a>. That is not what the law said. Article 22 was never a blanket prohibition: it expressly permitted solely automated decisions where necessary for a contract, authorised by law, or based on explicit consent, subject to safeguards. The playbook's flat "must be made by a human" is stricter than the statute, and gives no help on the safeguards required where the lawful routes are used.</p>
<p>The passage has since been overtaken entirely. The Data (Use and Access) Act 2025, which received Royal Assent in June 2025, replaces the old Article 22 regime with a more permissive framework for automated decision-making (except where special category data is involved), with provisions commencing in phases <a href="https://www.legislation.gov.uk/ukpga/2025/18/part/5">[10]</a> <a href="https://privacymatters.dlapiper.com/2025/06/uk-data-use-and-access-bill-passes-through-parliament/">[11]</a>. Nineteen months on, the playbook's account of the single most operationally important legal constraint on government AI is both overstated and out of date.</p>
<p>Smaller legal slips compound the impression. Page 66 attributes three separate DPIA triggers to "Article 35(3)(a)" of the UK GDPR; they are Articles 35(3)(a), (b) and (c). Page 67 says international transfers "are restricted under Article 46"; Article 46 is the provision that permits transfers subject to safeguards, and the restriction is Article 44. And page 83's claim that "a legal case in Canada found an organisation... with a hallucinating chatbot financially responsible" stretches Moffatt v Air Canada, a small-claims tribunal decision awarding roughly CA$800, in which it was never established that the chatbot was a hallucinating large language model rather than a badly scripted conventional one <a href="https://www.canlii.org/en/bc/bccrt/doc/2024/2024bccrt149/2024bccrt149.html">[15]</a>. The liability principle is real; the framing is not established fact.</p>
<h2>A document that disagrees with itself</h2>
<p>The deeper problem is internal consistency.</p>
<p>On page 22, generative AI "learns from large amounts of specially curated training data". On page 52, the same technology is "trained on vast amounts of unfiltered data scraped from the internet". Both cannot be true as stated; the second is closer to reality, and the first reads like vendor copy.</p>
<p>Principle 1 (page 10) asserts that "AI systems currently lack reasoning", a contested blanket claim even in February 2025, months after dedicated reasoning models had shipped. Thirteen pages later, the playbook's own Agentic AI section describes systems that "figure out the best way to achieve the system's objectives", and page 83 describes the ReAct pattern in which "the LLM is prompted to reason about how to perform a task". The document holds both positions and reconciles neither.</p>
<p>Most consequentially: the Agentic AI section (page 23) is pure enthusiasm. Autonomous agents operating "with minimal human intervention" make it "easier to create more efficient and effective systems", with not one sentence of risk discussion, in a document otherwise saturated with caution. Sixty pages later, the security chapter concludes that because prompt injection cannot be reliably prevented, "there must be a human present to review the action before carrying it out", which "significantly limits the utility of generative AI in fully automated solutions". That is a direct contradiction of the agentic pitch, and the two sections never acknowledge each other, on precisely the question where departments most need joined-up guidance.</p>
<p>The same pattern recurs in miniature. The security recommendations (page 96) advise: "Avoid putting LLM chatbots on public-facing government websites unless the risk of direct prompt injection is acceptable", having rated that attack's likelihood HIGH. The appendix's flagship case study is GOV.UK Chat, an LLM chatbot for the public, and the document never explains how its own showcase satisfies its own criterion. That case study, meanwhile, reports an answer "accuracy threshold of 80%" under the heading "Value delivered": a public information service wrong one time in five, presented as an achievement, pages after the playbook warns that hallucination "could lead to someone being misled about a government service, policy or point of law."</p>
<h2>What 118 pages do not contain</h2>
<p>The single most important question such a playbook could answer, where government should not use AI, receives two bullet points (page 37): "be cautious" about fully automated significant decisions, and do not use AI "on its own" in high-risk areas. No definition of high-risk, no examples, no red lines; this from a state whose recent history includes the withdrawn visa-streaming algorithm and the A-level grading fiasco. The EU AI Act's prohibited-practice and high-risk categories are never mentioned, even as a reference point.</p>
<p>Nor is there a single measurable requirement anywhere in the main text. Departments are told to "ensure a net positive impact on society," to make "specific and robust measurements," and to "select low carbon emission energy grids", with no threshold, benchmark, methodology or worked example. In place of specifics, the playbook signposts: a count of its cross-references finds it defers to more than forty other frameworks, standards and guides, without resolving priorities or conflicts between them. And unlike its sibling, the Digital, Data and Technology Playbook, which departments must follow on a "comply or explain" basis, the AI Playbook has no compliance status at all. "Should" appears hundreds of times; a consequence for ignoring it, never.</p>
<h2>Already history</h2>
<p>Some of the playbook was stale on arrival. Page 22 cites "Google Duet AI" as a current example of embedded generative AI; Google had renamed Duet AI to Gemini a full year before publication <a href="https://workspaceupdates.googleblog.com/2024/02/gemini-for-google-workspace.html">[12]</a>. Page 75's "Slack GPT" had long since become Slack AI. Page 22's "AWS ChatOps Chatbot" appears to confuse AWS Chatbot, a notification-routing tool, with a generative AI product. The playbook, published in the same month DSIT was announcing its own "Humphrey" AI suite for civil servants and folding CDDO into a reconstituted GDS, mentions neither <a href="https://www.civilserviceworld.com/professions/article/dsit-humphrey-ai-package-civil-servants-45bn-productivity-drive">[13]</a> <a href="https://www.publictechnology.net/2025/01/21/education-and-skills/cddo-brought-back-into-gds-in-digital-government-shake-up/">[14]</a>.</p>
<p>Other passages have aged badly since: the Procurement Act 2023 went live a fortnight after publication, superseding the playbook's framing; the Data (Use and Access) Act rewrote the automated-decision-making rules <a href="https://www.legislation.gov.uk/ukpga/2025/18/part/5">[10]</a>; and the reassurance on page 86 that Microsoft and OpenAI had "yet to observe any particularly novel or unique attacks resulting from the use of AI" describes the threat landscape of early 2024, not today's. The foreword promised "a launchpad that we will continuously revise and improve" <a href="https://gds.blog.gov.uk/2025/02/10/launching-the-artificial-intelligence-playbook-for-the-uk-government/">[3]</a>. As of this week, GOV.UK records no revision <a href="https://www.gov.uk/government/publications/ai-playbook-for-the-uk-government">[1]</a>.</p>
<h2>Credit where due</h2>
<p>Fairness requires saying what the playbook gets right, because it is not nothing. Its statement that "an LLM cannot distinguish between user input and system instructions... there is no way to prevent a user prompt affecting the behaviour of the LLM" (page 92) is more honest than most vendor documentation. Its email-attachment prompt-injection scenario anticipated attacks that later became mainstream. "Treat all LLM-generated code as inherently insecure" and "never use private data that needs different levels of user access permissions to train or fine-tune a model" are correct, crisp and actionable. The GOV.UK Chat case study is candid about hallucinations and about manual quality assurance failing to scale. And the cultural instincts, engage lawyers early, keep humans over consequential decisions, assume the model is wrong, are the right ones.</p>
<h2>Verdict</h2>
<p>The AI Playbook's problem is not its values but its craftsmanship. A document that instructs every civil servant to verify AI output misnames its own department three times, mislabels a famous security incident, garbles the research behind its showcase attack scenario, invents a data-retention policy, and overstates the very article of data protection law most likely to govern its readers' projects. Its promotional sections contradict its security analysis without acknowledgement, and on the hardest question, where government should refuse to deploy AI, it offers two sentences of caution in 118 pages.</p>
<p>The irony writes itself: the playbook is a competent first draft that needed exactly what it prescribes for AI systems, rigorous review by someone accountable for accuracy, and a maintenance plan that survived contact with publication. Until it gets one, departments should treat it the way it tells them to treat a large language model: useful, fluent, and not to be relied upon without checking.</p>
<div class="warning-box">
<p>This analysis is based on the February 2025 PDF edition (ISBN 9781036688745), published 10 February 2025 and unrevised on GOV.UK at the time of writing. Page references are to that PDF. If the playbook is revised, this piece will be updated with a diff of what changed; the document is tracked in our <a href="https://www.trackedchanges.co.uk/daily-register.html">Daily Register</a>.</p>
<p>The star score counts thirteen documented mistakes: six naming and proofreading errors (the DSIT misnaming, DLUHC, BCS, the UK Statistic Authority, the Public Contract Regulations, the ISO name), three security-chapter errors (the faker mislabel, the garbled ArangoDB scenario, the invented zero-day retention policy) and four legal misstatements (Article 22, the DPIA triggers, Articles 46 and 44, the Moffatt framing). The internal contradictions and stale product references are documented above but not counted as mistakes. Thirteen falls in the 10 to 19 band: two stars. The bands are on the <a href="https://www.trackedchanges.co.uk/ratings.html">ratings page</a>.</p>
</div>
<h2>Sources</h2>
<ol>
<li>GOV.UK publication page, "AI Playbook for the UK Government" (checked unrevised, 11 September 2026). <a href="https://www.gov.uk/government/publications/ai-playbook-for-the-uk-government">https://www.gov.uk/government/publications/ai-playbook-for-the-uk-government</a></li>
<li>"Artificial Intelligence Playbook for the UK Government" (PDF, February 2025 edition; all page references). <a href="https://assets.publishing.service.gov.uk/media/67aca2f7e400ae62338324bd/AI_Playbook_for_the_UK_Government__12_02_.pdf">https://assets.publishing.service.gov.uk/media/67aca2f7e400ae62338324bd/AI_Playbook_for_the_UK_Government__12_02_.pdf</a></li>
<li>GDS blog, "Launching the Artificial Intelligence Playbook for the UK Government" (10 February 2025; the foreword's revision promise). <a href="https://gds.blog.gov.uk/2025/02/10/launching-the-artificial-intelligence-playbook-for-the-uk-government/">https://gds.blog.gov.uk/2025/02/10/launching-the-artificial-intelligence-playbook-for-the-uk-government/</a></li>
<li>BleepingComputer, "Dev corrupts NPM libs 'colors' and 'faker' breaking thousands of apps" (January 2022; the sabotage, not a hack). <a href="https://www.bleepingcomputer.com/news/security/dev-corrupts-npm-libs-colors-and-faker-breaking-thousands-of-apps/">https://www.bleepingcomputer.com/news/security/dev-corrupts-npm-libs-colors-and-faker-breaking-thousands-of-apps/</a></li>
<li>Sonatype, "Maintainer Sabotages npm Libraries 'colors' and 'faker'" (corroborates the maintainer-sabotage account). <a href="https://www.sonatype.com/blog/npm-libraries-colors-and-faker-sabotaged-in-protest-by-their-maintainer-what-to-do-now">https://www.sonatype.com/blog/npm-libraries-colors-and-faker-sabotaged-in-protest-by-their-maintainer-what-to-do-now</a></li>
<li>SecurityWeek, "ChatGPT Hallucinations Can Be Exploited to Distribute Malicious Code Packages" (the Vulcan Cyber research; arangodb vs arangojs). <a href="https://www.securityweek.com/chatgpt-hallucinations-can-be-exploited-to-distribute-malicious-code-packages/">https://www.securityweek.com/chatgpt-hallucinations-can-be-exploited-to-distribute-malicious-code-packages/</a></li>
<li>Infosecurity Magazine, "New ChatGPT Attack Technique Spreads Malicious Packages" (proof-of-concept package, no planted malware). <a href="https://www.infosecurity-magazine.com/news/chatgpt-spreads-malicious-packages/">https://www.infosecurity-magazine.com/news/chatgpt-spreads-malicious-packages/</a></li>
<li>Lasso Security, "Lasso Research: AI Package Hallucinations" (the wider package-hallucination risk). <a href="https://www.lasso.security/blog/ai-package-hallucinations">https://www.lasso.security/blog/ai-package-hallucinations</a></li>
<li>Microsoft Q&amp;A, "How to opt-in for zero data retention with Azure OpenAI service?" (default 30-day retention; approval needed for zero data retention). <a href="https://learn.microsoft.com/en-us/answers/questions/4372674/how-to-opt-in-for-zero-data-retention-with-azure-o">https://learn.microsoft.com/en-us/answers/questions/4372674/how-to-opt-in-for-zero-data-retention-with-azure-o</a></li>
<li>Data (Use and Access) Act 2025, Part 5 (the replacement automated-decision-making regime). <a href="https://www.legislation.gov.uk/ukpga/2025/18/part/5">https://www.legislation.gov.uk/ukpga/2025/18/part/5</a></li>
<li>DLA Piper Privacy Matters, "UK: Data (Use and Access) Bill passes through Parliament" (June 2025; commencement phasing). <a href="https://privacymatters.dlapiper.com/2025/06/uk-data-use-and-access-bill-passes-through-parliament/">https://privacymatters.dlapiper.com/2025/06/uk-data-use-and-access-bill-passes-through-parliament/</a></li>
<li>Google Workspace Updates, "Introducing Gemini for Google Workspace" (February 2024; Duet AI renamed a year before the playbook cited it). <a href="https://workspaceupdates.googleblog.com/2024/02/gemini-for-google-workspace.html">https://workspaceupdates.googleblog.com/2024/02/gemini-for-google-workspace.html</a></li>
<li>Civil Service World, "DSIT previews 'Humphrey' AI package for civil servants in £45bn productivity drive" (January 2025). <a href="https://www.civilserviceworld.com/professions/article/dsit-humphrey-ai-package-civil-servants-45bn-productivity-drive">https://www.civilserviceworld.com/professions/article/dsit-humphrey-ai-package-civil-servants-45bn-productivity-drive</a></li>
<li>PublicTechnology, "CDDO brought back into GDS in digital government shake-up" (January 2025). <a href="https://www.publictechnology.net/2025/01/21/education-and-skills/cddo-brought-back-into-gds-in-digital-government-shake-up/">https://www.publictechnology.net/2025/01/21/education-and-skills/cddo-brought-back-into-gds-in-digital-government-shake-up/</a></li>
<li>Moffatt v Air Canada, 2024 BCCRT 149 (British Columbia Civil Resolution Tribunal, February 2024). <a href="https://www.canlii.org/en/bc/bccrt/doc/2024/2024bccrt149/2024bccrt149.html">https://www.canlii.org/en/bc/bccrt/doc/2024/2024bccrt149/2024bccrt149.html</a></li>
</ol>]]></content:encoded>
      <guid isPermaLink="false">https://www.trackedchanges.co.uk/2026-updates/ai-playbook-plausible-but-wrong.html</guid>
      <pubDate>Fri, 11 Sep 2026 22:45:00 +0000</pubDate>
    </item>
    <item>
      <title>The department on this code's cover stopped existing in 2023. The nine pages underneath needed the attention to detail they ask of software vendors.</title>
      <link>https://www.trackedchanges.co.uk/2026-updates/software-security-code-nine-pages.html</link>
      <description>A structured teardown of the UK's voluntary Software Security Code of Practice (May 2025, updated January 2026): the claims tested against the sources, eight documented mistakes counted, and a three-star verdict on a code that asks vendors for more care than its own pages received.</description>
      <content:encoded><![CDATA[<p>Estimated reading time: 6 minutes</p>
<figure class="article-hero">
<img alt="The Nova building development at Victoria, London, seen from street level." height="630" loading="eager" src="https://www.trackedchanges.co.uk/assets/images/articles/software-security-code-nine-pages/hero.webp" width="1200"/>
<figcaption>The Nova development, Victoria, London, 2023. The National Cyber Security Centre, co-author of the code, is headquartered in Nova South. Photo: <a href="https://commons.wikimedia.org/wiki/File:The_Nova_Building_79a_Buckingham_Palace_Rd,_London_SW1W_0AJ.jpg">Spudgun67 / Wikimedia Commons</a>, <a href="https://creativecommons.org/licenses/by-sa/4.0/">CC BY-SA 4.0</a>.</figcaption>
</figure>

<blockquote class="govuk-inset-text">
<p><strong>In short.</strong> The Software Security Code of Practice (May 2025) is a voluntary code asking software vendors to meet 14 security principles, co-designed with the NCSC and genuinely maintained since launch. It is also a document whose cover names a department that ceased to exist in February 2023, whose scope table numbers its principles in a way the code itself does not use, and which cites the EU's Cyber Resilience Act through a commercial training website rather than the law. Eight documented mistakes in nine pages: three stars. The doctrine is better than the drafting.</p>
</blockquote>
<p>Escalated from the <a href="https://www.trackedchanges.co.uk/daily-register.html">Daily Register</a> under the site's criteria: a first-of-kind framework with no enforcement clause, in a sector measured in billions. This is a Tier 2 structured teardown: claims tested against the sources they rest on, mistakes counted, arithmetic shown.</p>
<p>The code itself is short. Published 7 May 2025, it sets out 14 principles across four themes (secure design and development, build environment security, secure deployment and maintenance, communication with customers) that vendors selling software to businesses are "expected to implement" <a href="https://www.gov.uk/government/publications/software-security-code-of-practice/software-security-code-of-practice">[2]</a>. It was co-designed with the NCSC, refined through a 2024 call for views, and has been updated twice since launch: a monitoring survey in November 2025 and, in January 2026, a Software Security Ambassadors Scheme with firms including Cisco, Palo Alto Networks, Sage, Santander and NCC Group championing the code across industry <a href="https://www.gov.uk/government/publications/software-security-code-of-practice">[1]</a> <a href="https://www.gov.uk/government/news/cyber-sector-is-target-for-growth-as-government-supports-businesses-against-serious-organised-cyber-crime">[11]</a>.</p>
<h2>The claims, tested</h2>
<table>
<thead>
<tr>
<th>The code's claim</th>
<th>What we found</th>
<th>Verdict</th>
</tr>
</thead>
<tbody>
<tr>
<td>Co-designed with NCSC; supported by implementation guidance and an assurance framework</td>
<td>The implementation guidance <a href="https://www.ncsc.gov.uk/collection/software-security-code-of-practice-implementation-guidance">[7]</a> and the Assurance Principles and Claims <a href="https://www.ncsc.gov.uk/guidance/software-security-code-of-practice-assurance-principles-claims">[8]</a> are live on the NCSC site, with a downloadable self-assessment template</td>
<td>Holds</td>
</tr>
<tr>
<td>"14 principles split across 4 themes"</td>
<td>Confirmed: 1.1 to 1.4, 2.1 to 2.2, 3.1 to 3.5, 4.1 to 4.3 <a href="https://www.gov.uk/government/publications/software-security-code-of-practice/software-security-code-of-practice">[2]</a></td>
<td>Holds</td>
</tr>
<tr>
<td>'"shall" represents a requirement of the Code of Practice'</td>
<td>True as written, and the code is voluntary: the glossary borrows the grammar of a standard while the document carries no mechanism to oblige anyone</td>
<td>Holds, and proves the critics' point</td>
</tr>
<tr>
<td>Complementary to international approaches "including the US SSDF and the EU's Cyber Resilience Act"</td>
<td>The SSDF link goes to NIST. The Cyber Resilience Act link goes to european-cyber-resilience-act.com, a commercial site selling CRA training and certificates <a href="https://www.european-cyber-resilience-act.com/">[5]</a>, not to the regulation itself <a href="https://eur-lex.europa.eu/eli/reg/2024/2847/oj">[6]</a></td>
<td>Fails on sourcing</td>
</tr>
<tr>
<td>Resellers are covered by "principles 3 to 4"; in-house developers by "principles 1 and 2... as well as principle 3"</td>
<td>The code contains no principles numbered 1 to 4; those are theme numbers. Whether a reseller owes two principles or eight is not decidable from the text</td>
<td>Fails as written</td>
</tr>
<tr>
<td>A certification scheme is in development, "shared in due course"</td>
<td>Sixteen months and two page updates later: a survey and an ambassadors scheme, no certification scheme <a href="https://www.gov.uk/government/publications/software-security-code-of-practice">[1]</a></td>
<td>Still a promise</td>
</tr>
</tbody>
</table>
<h2>The mistakes, counted</h2>
<p><strong>The cover (1).</strong> The code is attributed to the Department for Science, Innovation and Technology and the Department for Digital, Culture, Media and Sport <a href="https://www.gov.uk/government/publications/software-security-code-of-practice/software-security-code-of-practice">[2]</a>. The second of those stopped existing in February 2023, when the machinery of government changes that created DSIT stripped Digital from DCMS <a href="https://www.gov.uk/government/news/making-government-deliver-for-the-british-people">[3]</a> <a href="https://insidegovuk.blog.gov.uk/2023/06/15/updating-gov-uk-when-there-is-a-machinery-of-government-change/">[4]</a>. This document was first published in May 2025, twenty-seven months after that name went away, and the badge has survived two subsequent updates.</p>
<p><strong>The scope table (2).</strong> As above: the sentences that tell each audience which parts of the code apply to them use a numbering scheme ("principles 3 to 4") that does not exist in the code. In the one place where precision decides who does what, the text is ambiguous.</p>
<p><strong>The citation (3).</strong> A government code of practice pointing readers at EU law routes them to a commercial training vendor's website rather than the Official Journal. The site sells CRA certificates <a href="https://www.european-cyber-resilience-act.com/">[5]</a>; the regulation lives at EUR-Lex <a href="https://eur-lex.europa.eu/eli/reg/2024/2847/oj">[6]</a>.</p>
<p><strong>The glossary definition that disagrees with itself (4).</strong> An incident is defined as "unauthorised access (or attempted access) to an organisation's IT systems", and the same entry then includes "accidental incidents (such as incidents where disruption is caused by vulnerabilities in software or updates)". An accidental disruption involves no access, attempted or otherwise. One of the two halves is wrong.</p>
<p><strong>The stale sentence (5).</strong> The skills section still reads "In 2025 the NCSC plans to launch a revised undergraduate degree certification standard". The page was updated on 15 January 2026, by which point 2025 had ended; the future tense survived anyway <a href="https://www.gov.uk/government/publications/software-security-code-of-practice/software-security-code-of-practice">[2]</a>.</p>
<p><strong>The proofreading (6, 7, 8).</strong> "Measures that should be reasonably be expected" (a doubled "be", in the sentence defining the code's whole scope). "A software producers practices" (a missing apostrophe, in the glossary entry explaining the assurance method). And principle 4.2 begins "Provides at least 1 year's notice" where every one of the other thirteen principles is an imperative: Follow, Protect, Have, Make. Small, individually; but this is a nine-page document that had a public consultation, two named departments, the NCSC, and two maintenance updates to catch them.</p>
<h2>What the code gets right</h2>
<p>The count above is not the whole picture, and fairness requires the other column. The 14 principles are concrete and sensible: publish a vulnerability disclosure process, log changes to the build environment, give customers a year's notice before support ends. Every one of the thirteen outbound links we checked resolves, which is more than can be said for most guidance this site reads. The assurance layer is real, not decorative: the NCSC's principles-based assurance approach is wired to a usable self-assessment template <a href="https://www.ncsc.gov.uk/guidance/software-security-code-of-practice-assurance-principles-claims">[8]</a>. And the document is visibly maintained, with two substantive updates in eight months and named firms publicly attached to it <a href="https://www.gov.uk/government/news/cyber-sector-is-target-for-growth-as-government-supports-businesses-against-serious-organised-cyber-crime">[11]</a>. By the standards of the genre, this is a living document. That is exactly why the surviving errors are worth counting: the maintenance passes happened, and rolled past them.</p>
<h2>Verdict</h2>
<p>Three stars, from eight documented mistakes in nine pages. The doctrine is largely sound and the follow-through is unusually real; the drafting and sourcing let it down in ways a single careful proofread would have caught. The deeper question is structural and is not scored: a code whose glossary defines "shall" as a requirement, inside a document nothing requires anyone to read, is a standard on the honour system, while the EU it politely gestures at made the same demands law <a href="https://eur-lex.europa.eu/eli/reg/2024/2847/oj">[6]</a>. And the code now has an ownership problem through no fault of its drafters: DSIT, its surviving sponsor, was broken up in the July 2026 reshuffle, with digital functions moving to a reformed DCMS <a href="https://www.gov.uk/government/organisations/department-for-science-innovation-and-technology">[9]</a> <a href="https://www.theregister.com/public-sector/2026/07/21/ukgovs-tech-department-gets-the-chop-after-two-years/5275573">[10]</a>. A document that asks vendors to name a Senior Responsible Owner currently cannot name its own.</p>
<div class="warning-box">
<p>The star score counts eight documented mistakes: the defunct department attribution, the principles-versus-themes scope numbering, the commercial-site citation for EU law, the self-contradicting incident definition, the stale 2025 future tense, and three proofreading errors (the doubled "be", the missing apostrophe, the 4.2 verb form). Eight falls in the 4 to 9 band: three stars; the bands are on the <a href="https://www.trackedchanges.co.uk/ratings.html">ratings page</a>. The July 2026 abolition of DSIT is noted but NOT counted: rebadging after a machinery of government change takes time, and the February 2023 DCMS attribution is counted once, not twice. Analysis is of the HTML edition as fetched on 12 September 2026, reflecting the 15 January 2026 update. The document is tracked in the Daily Register; a revision will get a diff entry.</p>
</div>
<h2>Sources</h2>
<ol>
<li>GOV.UK publication page, "Software Security Code of Practice" (update history: 7 May 2025, 28 November 2025, 15 January 2026). <a href="https://www.gov.uk/government/publications/software-security-code-of-practice">https://www.gov.uk/government/publications/software-security-code-of-practice</a></li>
<li>"Software Security Code of Practice", HTML edition, updated 15 January 2026 (all quoted text). <a href="https://www.gov.uk/government/publications/software-security-code-of-practice/software-security-code-of-practice">https://www.gov.uk/government/publications/software-security-code-of-practice/software-security-code-of-practice</a></li>
<li>GOV.UK, "PM: Making government deliver for the British people" (February 2023 machinery of government changes creating DSIT). <a href="https://www.gov.uk/government/news/making-government-deliver-for-the-british-people">https://www.gov.uk/government/news/making-government-deliver-for-the-british-people</a></li>
<li>Inside GOV.UK, "Updating GOV.UK when there is a machinery of government change" (confirms the February 2023 department changes). <a href="https://insidegovuk.blog.gov.uk/2023/06/15/updating-gov-uk-when-there-is-a-machinery-of-government-change/">https://insidegovuk.blog.gov.uk/2023/06/15/updating-gov-uk-when-there-is-a-machinery-of-government-change/</a></li>
<li>european-cyber-resilience-act.com, "Cyber Resilience Act (CRA) | Updates, Compliance, Training" (the commercial site the code links for the CRA). <a href="https://www.european-cyber-resilience-act.com/">https://www.european-cyber-resilience-act.com/</a></li>
<li>EUR-Lex, Regulation (EU) 2024/2847 (the Cyber Resilience Act itself). <a href="https://eur-lex.europa.eu/eli/reg/2024/2847/oj">https://eur-lex.europa.eu/eli/reg/2024/2847/oj</a></li>
<li>NCSC, "Software Security Code of Practice implementation guidance". <a href="https://www.ncsc.gov.uk/collection/software-security-code-of-practice-implementation-guidance">https://www.ncsc.gov.uk/collection/software-security-code-of-practice-implementation-guidance</a></li>
<li>NCSC, "Software Security Code of Practice: Assurance Principles and Claims". <a href="https://www.ncsc.gov.uk/guidance/software-security-code-of-practice-assurance-principles-claims">https://www.ncsc.gov.uk/guidance/software-security-code-of-practice-assurance-principles-claims</a></li>
<li>GOV.UK organisation page for DSIT (carries the notice that the organisation is being replaced). <a href="https://www.gov.uk/government/organisations/department-for-science-innovation-and-technology">https://www.gov.uk/government/organisations/department-for-science-innovation-and-technology</a></li>
<li>The Register, "UK.gov's tech department gets the chop after two years" (21 July 2026). <a href="https://www.theregister.com/public-sector/2026/07/21/ukgovs-tech-department-gets-the-chop-after-two-years/5275573">https://www.theregister.com/public-sector/2026/07/21/ukgovs-tech-department-gets-the-chop-after-two-years/5275573</a></li>
<li>GOV.UK, "Cyber sector is target for growth as Government supports businesses against serious organised cyber crime" (January 2026; the Ambassadors Scheme and named firms). <a href="https://www.gov.uk/government/news/cyber-sector-is-target-for-growth-as-government-supports-businesses-against-serious-organised-cyber-crime">https://www.gov.uk/government/news/cyber-sector-is-target-for-growth-as-government-supports-businesses-against-serious-organised-cyber-crime</a></li>
</ol>]]></content:encoded>
      <guid isPermaLink="false">https://www.trackedchanges.co.uk/2026-updates/software-security-code-nine-pages.html</guid>
      <pubDate>Sat, 12 Sep 2026 11:51:00 +0000</pubDate>
    </item>
    <item>
      <title>The government's Data and AI Ethics Framework tells every team building AI to record, audit and explain their decisions. Nobody outside the team ever has to check the record.</title>
      <link>https://www.trackedchanges.co.uk/2026-updates/data-ai-ethics-framework-self-assessed.html</link>
      <description>A structured teardown of the UK government's Data and AI Ethics Framework (December 2025 edition): the claims tested against the sources they cite, five documented mistakes counted, and a three-star verdict on a framework that asks for more oversight than it submits to.</description>
      <content:encoded><![CDATA[<p>Estimated reading time: 6 minutes</p>
<figure class="article-hero">
<img alt="The White Chapel Building, a glass-fronted office block on Whitechapel High Street, London." height="630" loading="eager" src="https://www.trackedchanges.co.uk/assets/images/articles/data-ai-ethics-framework-self-assessed/hero.webp" width="1200"/>
<figcaption>The White Chapel Building, Whitechapel High Street, London, 2025. The Government Digital Service, which owns the Data and AI Ethics Framework, is based here. Photo: <a href="https://commons.wikimedia.org/wiki/File:The_White_Chapel_Building_in_2025.01.jpg">CAPTAIN RAJU / Wikimedia Commons</a>, <a href="https://creativecommons.org/publicdomain/zero/1.0/">CC0 1.0</a>.</figcaption>
</figure>

<blockquote class="govuk-inset-text">
<p><strong>In short.</strong> The Data and AI Ethics Framework, first published in 2018 and retitled in December 2025 to cover artificial intelligence, tells every public sector team building an AI or data project to name a senior owner, log every decision, complete an equality and privacy impact assessment, and use a self-assessment tool. Nobody outside the team ever reviews the self-assessment. The transparency standard the framework leans on for accountability, the Algorithmic Transparency Recording Standard, has been mandatory for central government since 2022 and has 152 published records to show for it. Five documented mistakes in an otherwise thorough document: three stars.</p>
</blockquote>
<p>Escalated from the <a href="https://www.trackedchanges.co.uk/daily-register.html">Daily Register</a> under the site's criteria: a framework covering AI and data spending across the whole public sector, with high search salience following this site's teardown of <a href="https://www.trackedchanges.co.uk/2026-updates/ai-playbook-plausible-but-wrong.html">the AI Playbook</a>. This is a Tier 2 structured teardown: claims tested against the sources they cite, mistakes counted, arithmetic shown.</p>
<p>The framework began life in 2018 as the Data Ethics Framework, three principles long. It was rewritten in 2020, and rewritten again on 18 December 2025, when it was retitled the Data and AI Ethics Framework "to reflect the expanded scope covering AI and algorithmic technologies", gained four new principles and a companion self-assessment tool <a href="https://www.gov.uk/government/publications/data-ethics-framework">[1]</a>. Seven principles now stand: transparency, accountability, fairness, privacy, safety, societal impact and environmental sustainability <a href="https://www.gov.uk/government/publications/data-ethics-framework/data-and-ai-ethics-framework">[2]</a>. It is thorough. It is also, by its own account, unpoliced.</p>
<h2>The claims, tested</h2>
<table>
<thead>
<tr>
<th>The framework's claim</th>
<th>What we found</th>
<th>Verdict</th>
</tr>
</thead>
<tbody>
<tr>
<td>Teams "should use the Data and AI Ethics Self-Assessment Tool" <a href="https://www.gov.uk/government/publications/data-ethics-framework/data-and-ai-ethics-framework">[2]</a></td>
<td>The hyperlink on that exact sentence points to the framework's own landing page, not to the tool</td>
<td>Fails as written</td>
</tr>
<tr>
<td>Central government departments and qualifying arm's length bodies "must use the ATRS" <a href="https://www.gov.uk/government/publications/data-ethics-framework/data-and-ai-ethics-framework">[2]</a></td>
<td>Confirmed on the ATRS hub <a href="https://www.gov.uk/government/collections/algorithmic-transparency-recording-standard-hub">[3]</a>; the public repository lists 152 records total across the whole scheme <a href="https://www.gov.uk/algorithmic-transparency-records">[4]</a></td>
<td>Holds on paper, thin in practice</td>
</tr>
<tr>
<td>LLMs "may hallucinate ... for unexpected reasons" <a href="https://www.gov.uk/government/publications/data-ethics-framework/data-and-ai-ethics-framework">[2]</a></td>
<td>The word "hallucinate" is hyperlinked to the AI Playbook's landing page, which does not define or explain hallucination <a href="https://www.gov.uk/government/publications/ai-playbook-for-the-uk-government">[9]</a></td>
<td>Fails on sourcing</td>
</tr>
<tr>
<td>Run workshops using "the Model for Responsible Innovation", created by "the Department for Science, Innovation and Technology (DSIT)" <a href="https://www.gov.uk/government/publications/data-ethics-framework/data-and-ai-ethics-framework">[2]</a></td>
<td>DSIT's own GOV.UK page confirms it is "being replaced" by three successor departments, a change dated 15 July 2026 <a href="https://www.gov.uk/government/organisations/department-for-science-innovation-and-technology">[5]</a> <a href="https://www.theregister.com/public-sector/2026/07/21/ukgovs-tech-department-gets-the-chop-after-two-years/5275573">[6]</a></td>
<td>Stale since the document's last edit</td>
</tr>
<tr>
<td>Check "the Responsible Handover Framework" for supplier handovers <a href="https://www.gov.uk/government/publications/data-ethics-framework/data-and-ai-ethics-framework">[2]</a></td>
<td>The actual document is titled "Responsible Handover of AI", published by the charity Sense about Science with the IET and Wellcome, not a government framework <a href="https://senseaboutscience.org/responsible-handover-of-ai/">[7]</a></td>
<td>Fails on attribution</td>
</tr>
<tr>
<td>Consult "the AI Testing and Assurance Framework for Public Sector" <a href="https://www.gov.uk/government/publications/data-ethics-framework/data-and-ai-ethics-framework">[2]</a> for post-deployment testing</td>
<td>Hosted on GitHub Pages, credited only to an informal "Cross Government Testing Community" with no named accountable owner on the page <a href="https://testing-ai-standards.github.io/cross-gov-ai-testing-framework/">[8]</a></td>
<td>Weak sourcing for a document about accountability</td>
</tr>
</tbody>
</table>
<h2>The mistakes, counted</h2>
<p><strong>The self-assessment link (1).</strong> The framework's own instruction to use the Data and AI Ethics Self-Assessment Tool is a hyperlink. It goes to gov.uk/government/publications/data-ethics-framework, the page the reader is already on. The tool itself, an ODT file, sits one click further down that same landing page as a document attachment; the in-text link never reaches it <a href="https://www.gov.uk/government/publications/data-ethics-framework/data-and-ai-ethics-framework">[2]</a>.</p>
<p><strong>The hallucination citation (2).</strong> In a paragraph explaining why large language models produce confident, false answers, the technical term carrying that claim is linked not to a definition, a research paper or an ICO explainer, but to the landing page of the AI Playbook for the UK Government <a href="https://www.gov.uk/government/publications/data-ethics-framework/data-and-ai-ethics-framework">[2]</a> <a href="https://www.gov.uk/government/publications/ai-playbook-for-the-uk-government">[9]</a>, a document this site has already found to be, in its own words, plausible but wrong.</p>
<p><strong>The Responsible Handover misnomer (3).</strong> The framework tells teams buying AI from suppliers to check "the Responsible Handover Framework" for what information a handover needs <a href="https://www.gov.uk/government/publications/data-ethics-framework/data-and-ai-ethics-framework">[2]</a>. No government publication carries that name. The linked document, from the charity Sense about Science, is called "Responsible Handover of AI" <a href="https://senseaboutscience.org/responsible-handover-of-ai/">[7]</a>. A framework whose first principle is transparency gets the name of its own source wrong.</p>
<p><strong>The stale department (4).</strong> The framework directs teams towards "the Model for Responsible Innovation ... created by the Department for Science, Innovation and Technology (DSIT)" <a href="https://www.gov.uk/government/publications/data-ethics-framework/data-and-ai-ethics-framework">[2]</a>. DSIT's GOV.UK organisation page now opens with a notice that it is changing and "being replaced by the Department for Business, Innovation, Science and Trade, the Department for Digital, Culture, Media and Sport and the Cabinet Office", dated 15 July 2026 <a href="https://www.gov.uk/government/organisations/department-for-science-innovation-and-technology">[5]</a>. The framework was last updated 18 December 2025, seven months earlier, and has not been touched since.</p>
<p><strong>The unaccountable testing standard (5).</strong> For post-deployment monitoring, the framework recommends "the AI Testing and Assurance Framework for Public Sector" <a href="https://www.gov.uk/government/publications/data-ethics-framework/data-and-ai-ethics-framework">[2]</a>, hosted not on GOV.UK, NCSC or any department domain but on GitHub Pages, credited to a "Cross Government Testing Community" that names no lead department, no senior owner and no contact route on the page itself <a href="https://testing-ai-standards.github.io/cross-gov-ai-testing-framework/">[8]</a>. The Accountability section of this same framework requires exactly that of every project it governs.</p>
<h2>What the framework gets right</h2>
<p>The count above is not the whole document. The privacy section correctly threads UK GDPR, the Data Protection Act 2018 and the newer Data (Use and Access) Act 2025 together, linking the Data Protection Act to its actual enacted text on legislation.gov.uk rather than a summary <a href="https://www.legislation.gov.uk/ukpga/2018/12/contents/enacted">[10]</a>. The fairness section names the Equality Act 2010 and the Public Sector Equality Duty correctly and links to live EHRC guidance rather than paraphrasing it. The environmental sustainability principle, new in this edition, is unusually specific for a government ethics document: it names real measurement tools, CodeCarbon, ML CO2 Impact, the Hugging Face open LLM leaderboard, rather than gesturing at green AI in the abstract. And the framework has now been substantively rewritten three times in seven years, 2018, 2020 and 2025, each time in response to how the technology actually changed, which is more revision discipline than most guidance in this genre gets.</p>
<h2>Verdict</h2>
<p>Three stars, from five documented mistakes across a genuinely detailed document. The structural finding is not one of the five and is not scored: every principle in this framework, transparency, accountability, fairness, comes with a list of things a team "must" do, and every one of those obligations is discharged by the team marking its own homework. The Algorithmic Transparency Recording Standard is the framework's one external-facing accountability mechanism, and it is real, but 152 published records is a thin count for a requirement that has applied across central government since 2022 <a href="https://www.gov.uk/algorithmic-transparency-records">[4]</a>. A framework that tells teams to "establish mechanisms for independent reviews of your project" <a href="https://www.gov.uk/government/publications/data-ethics-framework/data-and-ai-ethics-framework">[2]</a> has no independent review of its own.</p>
<div class="warning-box">
<p>The star score counts five documented mistakes: the self-referential self-assessment link, the hallucination citation pointing to an unrelated landing page, the Responsible Handover Framework misnomer, the stale DSIT attribution, and the unaccountable GitHub-hosted testing standard. Five falls in the 4 to 9 band: three stars; the bands are on the <a href="https://www.trackedchanges.co.uk/ratings.html">ratings page</a>. The low ATRS record count is a system-wide accountability finding, not a drafting error in this framework, and is not counted. Analysis is of the HTML edition as fetched on 12 September 2026, reflecting the 18 December 2025 update. The document is tracked in the Daily Register; a revision will get a diff entry.</p>
</div>
<h2>Sources</h2>
<ol>
<li>GOV.UK publication page, "Data and AI Ethics Framework" (update history: 13 June 2018, 30 August 2018, 16 September 2020, 18 December 2025). <a href="https://www.gov.uk/government/publications/data-ethics-framework">https://www.gov.uk/government/publications/data-ethics-framework</a></li>
<li>"Data and AI Ethics Framework", HTML edition, updated 18 December 2025 (all quoted framework text unless noted). <a href="https://www.gov.uk/government/publications/data-ethics-framework/data-and-ai-ethics-framework">https://www.gov.uk/government/publications/data-ethics-framework/data-and-ai-ethics-framework</a></li>
<li>GOV.UK, "Algorithmic Transparency Recording Standard Hub" (confirms mandatory scope for central government departments and qualifying arm's length bodies). <a href="https://www.gov.uk/government/collections/algorithmic-transparency-recording-standard-hub">https://www.gov.uk/government/collections/algorithmic-transparency-recording-standard-hub</a></li>
<li>GOV.UK, "Algorithmic transparency records" repository (152 records, checked 12 September 2026). <a href="https://www.gov.uk/algorithmic-transparency-records">https://www.gov.uk/algorithmic-transparency-records</a></li>
<li>GOV.UK organisation page for DSIT (carries the notice that the department is being replaced, dated 15 July 2026). <a href="https://www.gov.uk/government/organisations/department-for-science-innovation-and-technology">https://www.gov.uk/government/organisations/department-for-science-innovation-and-technology</a></li>
<li>The Register, "UK.gov's tech department gets the chop after two years" (21 July 2026). <a href="https://www.theregister.com/public-sector/2026/07/21/ukgovs-tech-department-gets-the-chop-after-two-years/5275573">https://www.theregister.com/public-sector/2026/07/21/ukgovs-tech-department-gets-the-chop-after-two-years/5275573</a></li>
<li>Sense about Science, Institution of Engineering and Technology and Wellcome, "Responsible Handover of AI". <a href="https://senseaboutscience.org/responsible-handover-of-ai/">https://senseaboutscience.org/responsible-handover-of-ai/</a></li>
<li>Cross Government Testing Community, "AI Testing and Assurance Framework for Public Sector". <a href="https://testing-ai-standards.github.io/cross-gov-ai-testing-framework/">https://testing-ai-standards.github.io/cross-gov-ai-testing-framework/</a></li>
<li>GOV.UK, "AI Playbook for the UK Government" publication page (the page hyperlinked from the word "hallucinate"). <a href="https://www.gov.uk/government/publications/ai-playbook-for-the-uk-government">https://www.gov.uk/government/publications/ai-playbook-for-the-uk-government</a></li>
<li>legislation.gov.uk, Data Protection Act 2018, enacted text. <a href="https://www.legislation.gov.uk/ukpga/2018/12/contents/enacted">https://www.legislation.gov.uk/ukpga/2018/12/contents/enacted</a></li>
</ol>]]></content:encoded>
      <guid isPermaLink="false">https://www.trackedchanges.co.uk/2026-updates/data-ai-ethics-framework-self-assessed.html</guid>
      <pubDate>Sat, 12 Sep 2026 17:48:00 +0000</pubDate>
    </item>
    <item>
      <title>The Cabinet Office guide to hiring consultants tells civil servants to contact a Whitehall unit for help. That unit closed down in January 2023, and the guide has not been rewritten since.</title>
      <link>https://www.trackedchanges.co.uk/2026-updates/consultancy-playbook-cites-defunct-hub.html</link>
      <description>A structured teardown of the UK government's Consultancy Playbook: the claims tested against the sources they cite, five documented mistakes counted, and a three-star verdict on a guide still pointing staff towards an office that no longer exists.</description>
      <content:encoded><![CDATA[<p>Estimated reading time: 6 minutes</p>
<figure class="article-hero">
<img alt="The Cabinet Office building at 70 Whitehall, London, a stone-fronted government office with columns." height="630" loading="eager" src="https://www.trackedchanges.co.uk/assets/images/articles/consultancy-playbook-cites-defunct-hub/hero.webp" width="1200"/>
<figcaption>The Cabinet Office, 70 Whitehall, London, 2017. The Cabinet Office publishes and owns the Consultancy Playbook. Photo: <a href="https://commons.wikimedia.org/wiki/File:Cabinet_Office,_70_Whitehall,_London.jpg">Paul the Archivist / Wikimedia Commons</a>, <a href="https://creativecommons.org/licenses/by-sa/4.0/">CC BY-SA 4.0</a>.</figcaption>
</figure>

<blockquote class="govuk-inset-text">
<p><strong>In short.</strong> The Consultancy Playbook tells every central government department how to hire and manage consultants, and it repeatedly directs staff to the Government Consulting Hub for triage, training and a knowledge-sharing platform. The Hub closed on 31 January 2023. The Playbook has not been revised since September 2022 and still carries an email address on the Hub's own defunct domain. The National Audit Office said in November 2025 that the document needs refreshing; the Cabinet Office says a refresh is under way. Neither has happened yet. Five documented mistakes: three stars.</p>
</blockquote>
<p>Picked from the registry's queued Tier 2 entries: a live, current Cabinet Office publication with a specific, checkable claims-versus-evidence angle, and no diff or withdrawal pending. This is a Tier 2 structured teardown: claims tested against the sources they cite, mistakes counted, arithmetic shown.</p>
<p>The Consultancy Playbook launched in May 2021, built jointly by the Government Commercial Function and a new internal unit called the Government Consulting Hub (GCH) <a href="https://assets.publishing.service.gov.uk/media/631f2237e90e077db807dd00/The_Consultancy_Playbook_Version_1.1_September_2022.pdf">[1]</a>. Version 1.1, the one still live on GOV.UK today, was published in September 2022 <a href="https://assets.publishing.service.gov.uk/media/631f2237e90e077db807dd00/The_Consultancy_Playbook_Version_1.1_September_2022.pdf">[1]</a>. GOV.UK's own update log for the page records exactly one event, "Published 5 September 2022", and nothing since <a href="https://www.gov.uk/government/publications/the-consultancy-playbook">[2]</a>. Four months after that publication date, the Hub the Playbook was built around stopped existing.</p>
<h2>The claims, tested</h2>
<table>
<thead>
<tr>
<th>The Playbook's claim</th>
<th>What we found</th>
<th>Verdict</th>
</tr>
</thead>
<tbody>
<tr>
<td>"Teams considering going to market for consultancy services should contact the GCH or their commercial teams to access the Triage service" <a href="https://assets.publishing.service.gov.uk/media/631f2237e90e077db807dd00/The_Consultancy_Playbook_Version_1.1_September_2022.pdf">[1]</a></td>
<td>Cabinet Office closed the GCH on 31 January 2023; the triage function moved to a Crown Commercial Service initiative called Prosper, named nowhere in the Playbook <a href="https://www.nao.org.uk/wp-content/uploads/2025/11/governments-use-of-external-consultants.pdf">[4]</a></td>
<td>Fails as written</td>
</tr>
<tr>
<td>"We have launched the GCH Knowledge Exchange to capture and share across the Civil Service the types of tools, methodologies and thinking that we typically buy" <a href="https://assets.publishing.service.gov.uk/media/631f2237e90e077db807dd00/The_Consultancy_Playbook_Version_1.1_September_2022.pdf">[1]</a></td>
<td>The NAO confirms the in-house consulting service and its knowledge-sharing platform "were discontinued" when the Hub closed <a href="https://www.nao.org.uk/wp-content/uploads/2025/11/governments-use-of-external-consultants.pdf">[4]</a></td>
<td>Fails as written</td>
</tr>
<tr>
<td>The companion guidance note tells staff with questions to contact "the Government Consulting Hub's Knowledge and Skills Team" at an address on the Hub's own domain <a href="https://assets.publishing.service.gov.uk/media/632dc02ad3bf7f567479bd05/Knowledge_and_Skills_Guidance_Note_September_2022__1_.pdf">[3]</a></td>
<td>That domain belonged to a unit closed since January 2023; the note itself has never been updated to remove it</td>
<td>Fails as written</td>
</tr>
<tr>
<td>The Playbook is implemented "on a comply or explain basis" <a href="https://assets.publishing.service.gov.uk/media/631f2237e90e077db807dd00/The_Consultancy_Playbook_Version_1.1_September_2022.pdf">[1]</a>, with departments answerable for their own consultancy spend</td>
<td>The central spending controls Cabinet Office ran over consultancy from 2010 to 2022 were withdrawn in 2023; departments now police their own thresholds, which the Public Accounts Committee found produces uneven scrutiny <a href="https://www.nao.org.uk/wp-content/uploads/2025/11/governments-use-of-external-consultants.pdf">[4]</a></td>
<td>Explain to whom, exactly</td>
</tr>
<tr>
<td>Cabinet Office's own live Sourcing Playbook page says "the new Consultancy Playbook provides specific guidance on sourcing consultancy services" <a href="https://www.gov.uk/government/publications/the-sourcing-and-consultancy-playbooks">[5]</a></td>
<td>That page, last updated 15 June 2026, carries no attachment, link or cross-reference to any such document; the NAO confirms the promised refresh is still only "in the process" of happening <a href="https://www.nao.org.uk/wp-content/uploads/2025/11/governments-use-of-external-consultants.pdf">[4]</a></td>
<td>Promised, not delivered</td>
</tr>
</tbody>
</table>
<h2>The mistakes, counted</h2>
<p><strong>The dead triage route (1).</strong> Chapter one tells any team weighing up whether to hire a consultant to contact the GCH "at the earliest possible stage" for triage <a href="https://assets.publishing.service.gov.uk/media/631f2237e90e077db807dd00/The_Consultancy_Playbook_Version_1.1_September_2022.pdf">[1]</a>. The GCH closed on 31 January 2023, as part of a civil service headcount reduction <a href="https://www.nao.org.uk/wp-content/uploads/2025/11/governments-use-of-external-consultants.pdf">[4]</a>. Its triage function was rebuilt at the Crown Commercial Service under a different name, Prosper. A reader following this Playbook today has no way of knowing that.</p>
<p><strong>The vanished Knowledge Exchange (2).</strong> The Playbook's foreword calls the GCH Knowledge Exchange "the supporting infrastructure for new elements of the Playbook" <a href="https://assets.publishing.service.gov.uk/media/631f2237e90e077db807dd00/The_Consultancy_Playbook_Version_1.1_September_2022.pdf">[1]</a>, and the body text sends teams there repeatedly to check for existing toolkits and case studies before commissioning new work. The NAO's November 2025 review states plainly that when the Hub closed, "the in-house consulting services and knowledge sharing platform were discontinued" <a href="https://www.nao.org.uk/wp-content/uploads/2025/11/governments-use-of-external-consultants.pdf">[4]</a>. The infrastructure the Playbook is built on is gone.</p>
<p><strong>The dead-domain email address (3).</strong> The companion Knowledge and Skills Guidance Note, still attached to the Playbook's live GOV.UK page, tells staff with questions to email the Hub's Knowledge and Skills Team at an address on the Hub's own domain <a href="https://assets.publishing.service.gov.uk/media/632dc02ad3bf7f567479bd05/Knowledge_and_Skills_Guidance_Note_September_2022__1_.pdf">[3]</a>. That domain has belonged to a closed government unit for almost four years.</p>
<p><strong>The unwatched comply-or-explain (4).</strong> The Playbook asks departments to apply its principles "on a comply or explain basis" <a href="https://assets.publishing.service.gov.uk/media/631f2237e90e077db807dd00/The_Consultancy_Playbook_Version_1.1_September_2022.pdf">[1]</a>, proportionate to the value of the work. From 2010 to 2022, Cabinet Office ran central spending controls that gave that phrase teeth. Those controls were withdrawn in 2023 to cut departments' administrative burden, and Cabinet Office now relies on departments' own internal thresholds, which the NAO found vary from department to department <a href="https://www.nao.org.uk/wp-content/uploads/2025/11/governments-use-of-external-consultants.pdf">[4]</a>. Comply or explain needs someone on the other end of "explain".</p>
<p><strong>The uncounted spend (5).</strong> The Playbook asks contracting authorities to capture "accurate data about our use of consultancy... the suppliers used and their size, the type of consultancy, the cost and the reasons" specifically so government can "build a picture of the government's consultancy ecosystem" <a href="https://assets.publishing.service.gov.uk/media/631f2237e90e077db807dd00/The_Consultancy_Playbook_Version_1.1_September_2022.pdf">[1]</a>. The NAO found the opposite: departmental definitions of consultancy spend are inconsistent enough that two commercial data platforms tracking the same government varied by an average of £270 million a year between 2017-18 and 2022-23 <a href="https://www.nao.org.uk/wp-content/uploads/2025/11/governments-use-of-external-consultants.pdf">[4]</a>. The picture the Playbook asks for has not been built.</p>
<h2>Credit where due</h2>
<p>Not every part of this document has aged badly. The distinction it draws between consultancy and contingent labour, set out in a plain comparison table on page 12, is exactly the kind of clear, practical guidance a commissioning officer can use without a training course <a href="https://assets.publishing.service.gov.uk/media/631f2237e90e077db807dd00/The_Consultancy_Playbook_Version_1.1_September_2022.pdf">[1]</a>. The instruction to exhaust internal options and reuse existing knowledge before going to market is sound policy design, whatever became of the office meant to support it. The National Audit Office's own November 2025 review, drawing on interviews with departments and consultancy firms, reports that "the playbook was useful and contained sensible advice, but that it could be used more consistently" <a href="https://www.nao.org.uk/wp-content/uploads/2025/11/governments-use-of-external-consultants.pdf">[4]</a>. That is a fair account of a document whose ideas have outlasted the institution built to run them.</p>
<h2>Verdict</h2>
<p>Three stars, from five documented mistakes in a document that is, at its core, still sound guidance. None of the five are typos or dead hyperlinks of the kind that creep into any four-year-old PDF. Each is the same fault repeated in a different place: a Playbook built around a single institution, the Government Consulting Hub, that Cabinet Office closed for its own headcount reasons four months after this version was published, and never went back to fix. The Cabinet Office knows this. Its own commissioned auditor said so in public in November 2025 and reported that a refresh was "in the process" of happening <a href="https://www.nao.org.uk/wp-content/uploads/2025/11/governments-use-of-external-consultants.pdf">[4]</a>. Meanwhile, the Cabinet Office's own live 2026 Sourcing Playbook page tells readers a new, specific Consultancy Playbook already exists <a href="https://www.gov.uk/government/publications/the-sourcing-and-consultancy-playbooks">[5]</a>. It does not, not on GOV.UK, not anywhere a civil servant following the rules would find it.</p>
<div class="warning-box">
<p>The star score counts five documented mistakes: the dead GCH triage route, the discontinued Knowledge Exchange the Playbook's own foreword calls essential infrastructure, the guidance note's email address on a defunct domain, the withdrawal of the central spending controls that gave "comply or explain" its force, and the inconsistent spend data that leaves the Playbook's own data-capture goal unmet. Five falls in the 4 to 9 band: three stars; the bands are on the <a href="https://www.trackedchanges.co.uk/ratings.html">ratings page</a>. The broader question of whether government consultancy spend has actually fallen is a policy outcome, not a drafting fault in this document, and is not counted. Analysis is of the PDF edition (Version 1.1, September 2022) as served from the live GOV.UK publication page on 12 September 2026. The document is tracked in the Daily Register; a revision will get a diff entry.</p>
</div>
<h2>Sources</h2>
<ol>
<li>Cabinet Office, "The Consultancy Playbook", Version 1.1, September 2022 (PDF; all quoted Playbook text unless noted). <a href="https://assets.publishing.service.gov.uk/media/631f2237e90e077db807dd00/The_Consultancy_Playbook_Version_1.1_September_2022.pdf">https://assets.publishing.service.gov.uk/media/631f2237e90e077db807dd00/The_Consultancy_Playbook_Version_1.1_September_2022.pdf</a></li>
<li>GOV.UK, "The Consultancy Playbook" publication page (update history: Published 5 September 2022, no entries since; checked 12 September 2026). <a href="https://www.gov.uk/government/publications/the-consultancy-playbook">https://www.gov.uk/government/publications/the-consultancy-playbook</a></li>
<li>Cabinet Office, "Knowledge and Skills: Generation, Transfer and Sharing", Guidance Note, September 2022 (PDF). <a href="https://assets.publishing.service.gov.uk/media/632dc02ad3bf7f567479bd05/Knowledge_and_Skills_Guidance_Note_September_2022__1_.pdf">https://assets.publishing.service.gov.uk/media/632dc02ad3bf7f567479bd05/Knowledge_and_Skills_Guidance_Note_September_2022__1_.pdf</a></li>
<li>National Audit Office, "Lessons learned: the government's use of external consultants" (full report PDF, 21 November 2025; summarised at the NAO's "Government's use of external consultants" insight page). <a href="https://www.nao.org.uk/wp-content/uploads/2025/11/governments-use-of-external-consultants.pdf">https://www.nao.org.uk/wp-content/uploads/2025/11/governments-use-of-external-consultants.pdf</a></li>
<li>GOV.UK, "The Sourcing and Consultancy Playbooks" publication page (last updated 15 June 2026). <a href="https://www.gov.uk/government/publications/the-sourcing-and-consultancy-playbooks">https://www.gov.uk/government/publications/the-sourcing-and-consultancy-playbooks</a></li>
</ol>]]></content:encoded>
      <guid isPermaLink="false">https://www.trackedchanges.co.uk/2026-updates/consultancy-playbook-cites-defunct-hub.html</guid>
      <pubDate>Sat, 12 Sep 2026 18:11:00 +0000</pubDate>
    </item>
    <item>
      <title>The Service Standard tells every government team to publish proof their service works. The replacement for the tool that did this lists two dozen services, one of which no longer exists.</title>
      <link>https://www.trackedchanges.co.uk/2026-updates/service-standard-requires-data-nobody-publishes.html</link>
      <description>A structured teardown of GOV.UK's Service Standard: the performance-data promise checked against data.gov.uk, the assessment gate checked against a major programme that failed it twice, and the standard's own author admitting, in July 2026, that it needs rebuilding.</description>
      <content:encoded><![CDATA[<p>Estimated reading time: 6 minutes</p>
<figure class="article-hero">
<img alt="Aviation House on Kingsway, London, a converted Edwardian former church building that once housed the Government Digital Service." height="630" loading="eager" src="https://www.trackedchanges.co.uk/assets/images/articles/service-standard-requires-data-nobody-publishes/hero.webp" width="1200"/>
<figcaption>Aviation House, Kingsway, London, 2021: a former home of the Government Digital Service, the unit behind the Service Standard. Photo: <a href="https://commons.wikimedia.org/wiki/File:Aviation_House_on_Kingsway_-_geograph.org.uk_-_7018444.jpg">Philip Halling / Wikimedia Commons</a>, <a href="https://creativecommons.org/licenses/by-sa/2.0/">CC BY-SA 2.0</a>.</figcaption>
</figure>

<blockquote class="govuk-inset-text">
<p><strong>In short.</strong> The Service Standard is the fourteen-point checklist every central government digital service is meant to meet, and point ten tells teams to publish performance data so the public can judge whether a service works. The tool built for that, the Performance Platform, closed in March 2021; its promised successor on data.gov.uk lists 23 datasets today, several years stale, one of them for a service that shut down in 2023. The assessment built on this Standard let the Pensions Dashboards Programme through despite failing most of its points, twice. And in July 2026, the Government Digital Service published its own account of why the Standard no longer works. Three documented mistakes: four stars.</p>
</blockquote>
<p>Picked from the registry's queued Tier 2 entries: a document that applies, by GDS's own account, to every central government digital service, still live and unrevised in its current form since June 2019, with a specific and checkable claims-versus-evidence angle. This is a Tier 2 structured teardown: claims tested against the sources they cite, mistakes counted, arithmetic shown.</p>
<p>The Service Standard traces back to the Digital by Default Standard of 2014 and has sat, in its current fourteen-point form, on GOV.UK's Service Manual since 2016 <a href="https://www.gov.uk/service-manual/service-standard">[1]</a>. Its own page metadata records one substantive update since: 7 June 2019 <a href="https://www.gov.uk/service-manual/service-standard">[1]</a>. It applies to every central government service, gates progress through discovery, alpha, beta and live via a formal assessment, and its fourteenth point promises to "operate a reliable service" <a href="https://www.gov.uk/service-manual/service-standard">[1]</a>. Since January 2025, responsibility for it sits with the Government Digital Service inside the Department for Science, Innovation and Technology, after the Central Digital and Data Office (which ran assessments through 2022 and 2023) was folded back into GDS.</p>
<h2>The claims, tested</h2>
<table>
<thead>
<tr>
<th>The Standard's claim</th>
<th>What we found</th>
<th>Verdict</th>
</tr>
</thead>
<tbody>
<tr>
<td>"Publishing performance data means that you're being transparent about the success of services funded by public money," and central government services "must also publish data on the mandatory key performance indicators" <a href="https://www.gov.uk/service-manual/service-standard/point-10-define-success-publish-performance-data">[2]</a></td>
<td>The Performance Platform, GDS's tool for exactly this, closed 15 March 2021. GDS promised the data would move to data.gov.uk "in the coming weeks and months" <a href="https://dataingovernment.blog.gov.uk/2021/02/18/new-guidance-for-publishing-data/">[4]</a>. Its designated topic there holds 23 datasets today, several untouched since 2021-2022 <a href="https://www.data.gov.uk/search?topic=Digital+services+performance">[5]</a></td>
<td>Migration incomplete</td>
</tr>
<tr>
<td>A service standard assessment "is designed to ensure that government services are built to a good standard" <a href="https://www.nao.org.uk/wp-content/uploads/2024/05/investigation-into-the-pensions-dashboards-programme.pdf">[7]</a> before a service can progress</td>
<td>The Pensions Dashboards Programme's mock assessment (July 2022) found it did not meet 12 of the 14 standards; the formal assessment that followed (November 2022) still found it did not meet 7 of the 14 <a href="https://www.nao.org.uk/wp-content/uploads/2024/05/investigation-into-the-pensions-dashboards-programme.pdf">[7]</a></td>
<td>Failed the gate, twice</td>
</tr>
<tr>
<td>The Standard "helps teams to create and run great public services" <a href="https://www.gov.uk/service-manual/service-standard">[1]</a>, defining "what good looks like" across government</td>
<td>GDS's own July 2026 post says the Standard is "designed for a different era," is "harder to apply consistently across complex, end-to-end services," and "doesn't yet reflect a shared, cross-government view of good" <a href="https://gds.blog.gov.uk/2026/07/02/evolving-the-service-standard-for-the-future-of-public-services/">[8]</a></td>
<td>Contradicted by its own author</td>
</tr>
</tbody>
</table>
<h2>The mistakes, counted</h2>
<p><strong>The performance-data promise, unmet (1).</strong> Point 10 tells teams to "collect and use performance data from all channels, online and offline" and states plainly that "publishing performance data means that you're being transparent about the success of services funded by public money" <a href="https://www.gov.uk/service-manual/service-standard/point-10-define-success-publish-performance-data">[2]</a>. The linked guidance is more specific: "you must publish data on the 4 mandatory key performance indicators", cost per transaction, user satisfaction, completion rate and digital take-up, "and add it to data.gov.uk" <a href="https://www.gov.uk/service-manual/measuring-success/data-you-must-publish">[3]</a>. That guidance page itself carries a notice explaining why: "you can no longer share your service's performance data with the Performance Platform. The Performance Platform was closed in March 2021" <a href="https://www.gov.uk/service-manual/measuring-success/data-you-must-publish">[3]</a>. GDS's own announcement of that closure promised continuity: "in the coming weeks and months, you will see more performance and reference data available via data.gov.uk" <a href="https://dataingovernment.blog.gov.uk/2021/02/18/new-guidance-for-publishing-data/">[4]</a>. Five years on, the "Digital services performance" topic on data.gov.uk, the designated home for this mandatory data, returns 23 results <a href="https://www.data.gov.uk/search?topic=Digital+services+performance">[5]</a>. Several have not been touched since 2021 or 2022, including GOV.UK Pay's own performance page (last updated 23 April 2021) and the Verify Performance Statistics dataset, last updated 10 March 2021 for a service, GOV.UK Verify, that itself stopped operating on 30 March 2023 <a href="https://www.data.gov.uk/dataset/739a8fea-e559-4e3c-a1e4-9b7bf3f518b2/verify-performance-statistics">[6]</a> <a href="https://www.theyworkforyou.com/wms/?id=2023-05-02.hcws755.h">[9]</a>. A reader following the Standard's own link to "the data you must publish" finds the mandatory home for it thinly populated and, in places, two years out of date for a service that no longer exists.</p>
<p><strong>The assessment gate, failed twice (2).</strong> The Standard's central enforcement mechanism is the service standard assessment, described by the National Audit Office as a process "designed to ensure that government services are built to a good standard" by requiring services "to meet 14 standards" <a href="https://www.nao.org.uk/wp-content/uploads/2024/05/investigation-into-the-pensions-dashboards-programme.pdf">[7]</a>. The NAO's May 2024 investigation into the Pensions Dashboards Programme, the public service meant to let people see all their pensions in one place, found that "the pensions dashboards service initially underwent a mock service standard assessment in July 2022, carried out by DWP's digital team. This assessment found that the service did not meet 12 of the 14 standards" <a href="https://www.nao.org.uk/wp-content/uploads/2024/05/investigation-into-the-pensions-dashboards-programme.pdf">[7]</a>. The Infrastructure and Projects Authority downgraded the programme to a "red" delivery confidence rating on the strength of that result. A formal assessment by the Central Digital and Data Office in November 2022 found the programme "still did not meet seven of the 14 standards" <a href="https://www.nao.org.uk/wp-content/uploads/2024/05/investigation-into-the-pensions-dashboards-programme.pdf">[7]</a>. The following month, the Money and Pensions Service told the Department for Work and Pensions its delivery timetable was "no longer viable", and the connection deadline set in regulations was pushed back by at least six months <a href="https://www.nao.org.uk/wp-content/uploads/2024/05/investigation-into-the-pensions-dashboards-programme.pdf">[7]</a>. The gate the Standard relies on to catch problems early caught this one only after the core architecture was already built.</p>
<p><strong>The standard, marked down by its own author (3).</strong> The Service Standard's own page still opens with "the Service Standard helps teams to create and run great public services" <a href="https://www.gov.uk/service-manual/service-standard">[1]</a>, unrevised in substance since June 2019. On 2 July 2026, the Government Digital Service published a blog post titled "Evolving the Service Standard for the future of public services", explaining why it is being rebuilt. It states that the current Standard has become "closely associated with assessment of central government services at important delivery stages, rather than embedded in continuous improvement of service operations", is "harder to apply consistently across complex, end-to-end services that span organisations and channels", and was "designed for a different era", so that it "doesn't yet reflect a shared, cross-government view of good" <a href="https://gds.blog.gov.uk/2026/07/02/evolving-the-service-standard-for-the-future-of-public-services/">[8]</a>. GDS also concedes "inconsistent interpretations of 'what good looks like'" across departments <a href="https://gds.blog.gov.uk/2026/07/02/evolving-the-service-standard-for-the-future-of-public-services/">[8]</a>. Every one of these admissions describes the exact document still live on GOV.UK, unchanged, telling teams today that it defines what good looks like.</p>
<h2>Credit where due</h2>
<p>GDS's own account of the Standard's history is not spin. It has been, in its words, "lauded at home and abroad" and has genuinely "improved usability, accessibility, sustainability, interoperability and value for money" across a decade of public services <a href="https://gds.blog.gov.uk/2026/07/02/evolving-the-service-standard-for-the-future-of-public-services/">[8]</a>, and the fourteen points themselves, understand users, make services simple, operate reliably, remain sound advice that few would argue against. The Pensions Dashboards Programme's story cuts both ways: the assessment did exactly its job, catching a programme that was not ready before it reached the public, even if the underlying resourcing problems it flagged took another two years to resolve. And publishing an unflattering account of your own flagship product's limits, in public, before a fix exists, is not the easy option. Most departments do not do this. GDS did.</p>
<h2>Verdict</h2>
<p>Four stars, from three documented mistakes in a Standard whose fourteen points remain sound even where its machinery has not kept up. None of the three is a typo or a dead link of the kind any seven-year-old web page accumulates. Each traces the same shape: a promise the Standard makes about transparency, assessment or currency, tested against what actually happened, and found short. The performance-data promise leads to a data.gov.uk topic with 23 entries and a stale record for a decommissioned identity service. The assessment gate let a major programme through only after it had already failed most of its points, twice. And the Standard's own authors now say, in public, that the document does not reflect "a shared, cross-government view of good" <a href="https://gds.blog.gov.uk/2026/07/02/evolving-the-service-standard-for-the-future-of-public-services/">[8]</a>. GDS is rebuilding it. Until that lands, the page every assessor and every service team is pointed to is the one this piece tested.</p>
<div class="warning-box">
<p>The star score counts three documented mistakes: the performance-data requirement whose designated publishing home is thinly populated and, in one case, stale for a service that has since closed; the service standard assessment that let the Pensions Dashboards Programme proceed to build despite failing most of its points on two separate checks; and the Standard's own July 2026 admission from GDS that it no longer reflects a shared view of what good looks like. Three falls in the 1 to 3 band: four stars; the bands are on the <a href="https://www.trackedchanges.co.uk/ratings.html">ratings page</a>. Whether GDS's planned rebuild fixes these gaps is a future outcome, not counted here. Analysis is of the Service Standard and its linked guidance pages as served from GOV.UK on 12 September 2026. The document is tracked in the Daily Register; a revision will get a diff entry.</p>
</div>
<h2>Sources</h2>
<ol>
<li>GOV.UK, "Service Standard" (Service Manual; page metadata records last substantive update 7 June 2019, checked 12 September 2026). <a href="https://www.gov.uk/service-manual/service-standard">https://www.gov.uk/service-manual/service-standard</a></li>
<li>GOV.UK, "10. Define what success looks like and publish performance data". <a href="https://www.gov.uk/service-manual/service-standard/point-10-define-success-publish-performance-data">https://www.gov.uk/service-manual/service-standard/point-10-define-success-publish-performance-data</a></li>
<li>GOV.UK, "Data you must publish" (Service Manual). <a href="https://www.gov.uk/service-manual/measuring-success/data-you-must-publish">https://www.gov.uk/service-manual/measuring-success/data-you-must-publish</a></li>
<li>Government Digital Service, "New guidance for publishing data", 18 February 2021. <a href="https://dataingovernment.blog.gov.uk/2021/02/18/new-guidance-for-publishing-data/">https://dataingovernment.blog.gov.uk/2021/02/18/new-guidance-for-publishing-data/</a></li>
<li>data.gov.uk, search results filtered to topic "Digital services performance" (23 results, checked 12 September 2026). <a href="https://www.data.gov.uk/search?topic=Digital+services+performance">https://www.data.gov.uk/search?topic=Digital+services+performance</a></li>
<li>data.gov.uk, "Verify Performance Statistics" dataset (Publisher: GOV.UK Verify, updated 10 March 2021). <a href="https://www.data.gov.uk/dataset/739a8fea-e559-4e3c-a1e4-9b7bf3f518b2/verify-performance-statistics">https://www.data.gov.uk/dataset/739a8fea-e559-4e3c-a1e4-9b7bf3f518b2/verify-performance-statistics</a></li>
<li>National Audit Office, "Investigation into the Pensions Dashboards Programme", May 2024 (PDF, Summary p.11 and Part Two pp.29-30). <a href="https://www.nao.org.uk/wp-content/uploads/2024/05/investigation-into-the-pensions-dashboards-programme.pdf">https://www.nao.org.uk/wp-content/uploads/2024/05/investigation-into-the-pensions-dashboards-programme.pdf</a></li>
<li>Government Digital Service, "Evolving the Service Standard for the future of public services", 2 July 2026. <a href="https://gds.blog.gov.uk/2026/07/02/evolving-the-service-standard-for-the-future-of-public-services/">https://gds.blog.gov.uk/2026/07/02/evolving-the-service-standard-for-the-future-of-public-services/</a></li>
<li>Hansard via TheyWorkForYou, "Closure of GOV.UK Verify", Written Statement, 2 May 2023 (HC Deb, 2 May 2023, cWS; hansard.parliament.uk returns a bot-block 403, mirror used per HOUSE-RULES.md rule 6; confirms "the final government service stopped using the platform on 30 March 2023"). <a href="https://www.theyworkforyou.com/wms/?id=2023-05-02.hcws755.h">https://www.theyworkforyou.com/wms/?id=2023-05-02.hcws755.h</a></li>
</ol>]]></content:encoded>
      <guid isPermaLink="false">https://www.trackedchanges.co.uk/2026-updates/service-standard-requires-data-nobody-publishes.html</guid>
      <pubDate>Sat, 12 Sep 2026 18:27:00 +0000</pubDate>
    </item>
    <item>
      <title>The Construction Playbook has a chapter for exactly this moment: a big contractor going bust mid-project. When the Ministry of Justice's prison builder did, prisons lost up to eighteen months anyway.</title>
      <link>https://www.trackedchanges.co.uk/2026-updates/construction-playbook-resolution-planning-tested.html</link>
      <description>A structured teardown of the Construction Playbook: its resolution-planning promise checked against the ISG collapse, its Should Cost Model promise checked against a 259 percent cost overrun, and its pledge of a profitable industry checked against Insolvency Service data.</description>
      <content:encoded><![CDATA[<p>Estimated reading time: 7 minutes</p>
<figure class="article-hero">
<img alt="A construction crane over the site of a new school building in Cambridge, England." height="630" loading="eager" src="https://www.trackedchanges.co.uk/assets/images/articles/construction-playbook-resolution-planning-tested/hero.webp" width="1200"/>
<figcaption>A crane marks a new school under construction, Cambridge, December 2014. Photo: <a href="https://commons.wikimedia.org/wiki/File:Crane_marks_a_new_school_-_geograph.org.uk_-_4483524.jpg">Fernweh / Wikimedia Commons</a>, <a href="https://creativecommons.org/licenses/by-sa/2.0/">CC BY-SA 2.0</a>.</figcaption>
</figure>

<blockquote class="govuk-inset-text">
<p><strong>In short.</strong> The Construction Playbook is the Cabinet Office's mandatory rulebook for how central government buys public works, and one of its fourteen key policies exists specifically for a supplier going bust mid-contract: resolution planning. In September 2024 ISG, the Ministry of Justice's main prison-building contractor, did exactly that. The National Audit Office found the collapse still cost some individual prison projects up to eighteen months, inside a portfolio already running 4.2 billion pounds over budget, partly because a flagship modular programme's own costs were never properly scoped, the precise failure the Playbook's Should Cost Models are meant to prevent. Three documented mistakes: four stars.</p>
</blockquote>
<p>Picked from the registry's queued Tier 2 entries: a document mandatory for every central government department buying public works, still live in its September 2022 edition, with a specific, checkable claim about what happens when a contractor fails. This is a Tier 2 structured teardown: the document's own words, tested against the evidence the record actually shows.</p>
<p>The Construction Playbook sets out fourteen "key policies" that departments must follow on a "comply or explain" basis when procuring "building, civil engineering, construction or infrastructure" work <a href="https://assets.publishing.service.gov.uk/media/6312222de90e075880923330/14.116_CO_Construction_Playbook_Web.pdf">[1]</a>. It was co-developed with the Construction Leadership Council and signed as a "Compact with Industry" by dozens of the sector's largest firms, including the chief executives of Kier, Balfour Beatty, Skanska UK and Mace <a href="https://assets.publishing.service.gov.uk/media/6312222de90e075880923330/14.116_CO_Construction_Playbook_Web.pdf">[1]</a>. Its stated purpose, in the words of its introduction: "it is in all of our interests to create a profitable, sustainable and resilient industry with a well-trained workforce for the future" <a href="https://assets.publishing.service.gov.uk/media/6312222de90e075880923330/14.116_CO_Construction_Playbook_Web.pdf">[1]</a>. The version current today, 1.1, dates from September 2022 and remains the live guidance on GOV.UK, with no withdrawal notice <a href="https://www.gov.uk/government/publications/the-construction-playbook">[2]</a>.</p>
<h2>The claims, tested</h2>
<table>
<thead>
<tr>
<th>The Playbook's claim</th>
<th>What we found</th>
<th>Verdict</th>
</tr>
</thead>
<tbody>
<tr>
<td>"Resolution planning can help to mitigate the impacts of insolvency, ensuring that projects can continue following an orderly transfer to a new supplier" <a href="https://assets.publishing.service.gov.uk/media/6312222de90e075880923330/14.116_CO_Construction_Playbook_Web.pdf">[1]</a></td>
<td>ISG, the Ministry of Justice's main contractor for 17% of the prison expansion portfolio, went into administration in September 2024. The NAO found this will still delay some individual projects by three to eighteen months <a href="https://www.nao.org.uk/wp-content/uploads/2024/12/increasing-the-capacity-of-the-prison-estate-to-meet-demand.pdf">[3]</a></td>
<td>Contingency modelled, delay not avoided</td>
</tr>
<tr>
<td>"Inaccurate estimates may lead to unrealistic expectations, which can derail a project's chances of success," the reason every project "should produce a" Should Cost Model before build <a href="https://assets.publishing.service.gov.uk/media/6312222de90e075880923330/14.116_CO_Construction_Playbook_Web.pdf">[1]</a></td>
<td>The NAO found HMPPS's Rapid Deployment Cells, its flagship modular build, saw costs rise 247-259% "due to HMPPS underestimating the scope of what was required" <a href="https://www.nao.org.uk/wp-content/uploads/2024/12/increasing-the-capacity-of-the-prison-estate-to-meet-demand.pdf">[3]</a></td>
<td>The exact failure the Playbook warns against</td>
</tr>
<tr>
<td>The Playbook exists to build "a profitable, sustainable and resilient industry" <a href="https://assets.publishing.service.gov.uk/media/6312222de90e075880923330/14.116_CO_Construction_Playbook_Web.pdf">[1]</a></td>
<td>Construction remains the UK's most insolvency-prone sector by number of firms, every year the Playbook has been in force <a href="https://www.gov.uk/government/statistics/company-insolvencies-september-2025/commentary-company-insolvency-statistics-september-2025">[4]</a></td>
<td>Unchanged since the Compact was signed</td>
</tr>
</tbody>
</table>
<h2>The mistakes, counted</h2>
<p><strong>Resolution planning modelled the risk, and the risk happened anyway (1).</strong> Chapter 10 of the Playbook states that "although major insolvencies are infrequent, we need to be prepared for the risk to continuity of critical projects posed by the insolvency of key suppliers," and that "all new critical construction contracts will now require resolution planning information to be provided by suppliers" <a href="https://assets.publishing.service.gov.uk/media/6312222de90e075880923330/14.116_CO_Construction_Playbook_Web.pdf">[1]</a>. Its key points promise this "helps ensure continuity of critical projects and their orderly transfer to a new supplier in the event of supplier insolvency" <a href="https://assets.publishing.service.gov.uk/media/6312222de90e075880923330/14.116_CO_Construction_Playbook_Web.pdf">[1]</a>. On 20 September 2024, eight companies in the ISG group entered administration <a href="https://www.gov.uk/government/news/isg-group-of-companies-in-administration-information-for-employees-and-creditors">[5]</a>. ISG was "MoJ's main construction contractor on 3,634 places (17% of the prison expansion portfolio)" <a href="https://www.nao.org.uk/wp-content/uploads/2024/12/increasing-the-capacity-of-the-prison-estate-to-meet-demand.pdf">[3]</a>. The NAO recorded that "prior to the insolvency, HMPPS modelled the estimated impact as a worst-case scenario when resetting timelines and estimated this will cause delays of three to 18 months for some individual projects" <a href="https://www.nao.org.uk/wp-content/uploads/2024/12/increasing-the-capacity-of-the-prison-estate-to-meet-demand.pdf">[3]</a>. The modelling itself is evidence the Playbook's discipline was followed: MoJ was watching and had a worst-case number ready. But the number is still a delay of up to a year and a half, on a prison-building programme already the subject of a national capacity crisis. "Ensuring that projects can continue" is not the same promise as "some individual projects lose up to eighteen months," and the Playbook's own chapter draws no such distinction.</p>
<p><strong>The Should Cost Model promise, undone by its own case study (2).</strong> Chapter 5 tells departments that "having a clear understanding of the whole life costs and risks of delivering a project or programme is best achieved by producing a Should Cost Model," that "all projects and programmes should produce" one during "the planning and preparation stage," and that skipping this step matters because "inaccurate estimates may lead to unrealistic expectations, which can derail a project's chances of success" <a href="https://assets.publishing.service.gov.uk/media/6312222de90e075880923330/14.116_CO_Construction_Playbook_Web.pdf">[1]</a>. HMPPS's Rapid Deployment Cells, prefabricated modular units built to add prison capacity quickly, are exactly the kind of fast-track, standardised build the Playbook's Modern Methods of Construction chapter champions two sections earlier <a href="https://assets.publishing.service.gov.uk/media/6312222de90e075880923330/14.116_CO_Construction_Playbook_Web.pdf">[1]</a>. The NAO found the first two tranches of RDCs had "the highest percentage cost increase (247-259%), with significant additional cost due to HMPPS underestimating the scope of what was required" <a href="https://www.nao.org.uk/wp-content/uploads/2024/12/increasing-the-capacity-of-the-prison-estate-to-meet-demand.pdf">[3]</a>. Across the whole prison expansion portfolio, the NAO put the total damage at "between 80% and 93%" above budget, an extra £4.2 billion to £4.9 billion against approved 2021 funding of £5.2 billion <a href="https://www.nao.org.uk/wp-content/uploads/2024/12/increasing-the-capacity-of-the-prison-estate-to-meet-demand.pdf">[3]</a>. This is not a case of a Should Cost Model producing an honest estimate that then met bad luck. It is the specific failure mode, requirements not scoped before build, that the Playbook's own chapter exists to rule out.</p>
<p><strong>The "profitable, sustainable and resilient industry" is not the industry that exists (3).</strong> The Playbook's introduction commits government to help "create a profitable, sustainable and resilient industry" <a href="https://assets.publishing.service.gov.uk/media/6312222de90e075880923330/14.116_CO_Construction_Playbook_Web.pdf">[1]</a>, and its Compact with Industry chapter, signed by the sector's own trade bodies and largest contractors, frames the document as the mechanism for delivering that <a href="https://assets.publishing.service.gov.uk/media/6312222de90e075880923330/14.116_CO_Construction_Playbook_Web.pdf">[1]</a>. The Insolvency Service's own official statistics record construction as the UK industry with the highest number of company insolvencies of any sector in the twelve months to August 2025, 3,934 firms, 17% of all cases with an industry recorded, ahead of every other sector including wholesale and retail and accommodation and food service <a href="https://www.gov.uk/government/statistics/company-insolvencies-september-2025/commentary-company-insolvency-statistics-september-2025">[4]</a>. This has been true throughout the Playbook's life; ISG was simply the name large enough, in September 2024, to make the pattern a national news story rather than a trade-press one. A Playbook cannot be blamed for macroeconomic conditions, but a document that names industry resilience as one of its founding aims, and is co-signed by the industry it names, should not leave that claim standing four years on with no acknowledgement that the sector it describes remains the most insolvency-prone in the country.</p>
<h2>Credit where due</h2>
<p>The Playbook's resolution-planning chapter is not decorative. MoJ had a worst-case delay estimate ready before ISG's administration was even announced, which is precisely what the chapter's contingency planning requirement is meant to produce, and the NAO's account reads as a system that noticed the risk early rather than one caught by surprise. The Should Cost Model failure sits inside a wider portfolio where two new prisons, Five Wells and Fosse Way, were delivered and opened broadly on their original schedule, showing the underlying model can work when scoping is done properly at the outset. And a government document that asks industry's own chief executives to co-sign a pledge on productivity, safety and fair payment terms, then measures itself against the results in public NAO reports rather than burying them, is not the easy path. Most policy documents do not invite that scrutiny. This one does.</p>
<h2>Verdict</h2>
<p>Four stars, from three documented mistakes in a Playbook whose central mechanisms, resolution planning and Should Cost Models, are sound in principle and were both put to a real test within two years of this edition's publication. Each mistake traces the same shape: a promise about what the machinery prevents, checked against what the National Audit Office found actually happened. Resolution planning produced an accurate worst-case forecast, not a project that carried on unaffected. The Should Cost Model chapter warns against exactly the scoping failure that then hit the government's own showcase modular programme. And the pledge to build a resilient industry has not moved the industry off the top of the Insolvency Service's own league table. None of this means the policies are wrong. It means the document oversells what they deliver.</p>
<div class="warning-box">
<p>The star score counts three documented mistakes: the resolution-planning chapter's promise of continuity, tested against the NAO's finding that ISG's collapse will still delay some prison projects by up to eighteen months; the Should Cost Model chapter's warning against unscoped estimates, tested against the NAO's finding that HMPPS's own Rapid Deployment Cells rose 247-259% for exactly that reason; and the Playbook's stated aim of a profitable, resilient industry, tested against Insolvency Service data showing construction remains the UK's most insolvency-prone sector. Three falls in the 1 to 3 band: four stars; the bands are on the <a href="https://www.trackedchanges.co.uk/ratings.html">ratings page</a>. Analysis is of the Construction Playbook version 1.1 (September 2022) as served from GOV.UK on 12 September 2026. The document is tracked in the Daily Register; a revision will get a diff entry.</p>
</div>
<h2>Sources</h2>
<ol>
<li>HM Government, "The Construction Playbook: Government Guidance on sourcing and contracting public works projects and programmes", version 1.1, September 2022 (pp.2, 8, 42, 66, 69, 78). <a href="https://assets.publishing.service.gov.uk/media/6312222de90e075880923330/14.116_CO_Construction_Playbook_Web.pdf">https://assets.publishing.service.gov.uk/media/6312222de90e075880923330/14.116_CO_Construction_Playbook_Web.pdf</a></li>
<li>GOV.UK, "The Construction Playbook" (publication page; first published 8 December 2020, checked live 12 September 2026, no withdrawal notice). <a href="https://www.gov.uk/government/publications/the-construction-playbook">https://www.gov.uk/government/publications/the-construction-playbook</a></li>
<li>National Audit Office, "Increasing the capacity of the prison estate to meet demand", Ministry of Justice / HM Prison and Probation Service, HC 376, Session 2024-25, 4 December 2024 (Summary paras 9-10, p.7; Part One paras 1.10-1.13, pp.17 and 19). <a href="https://www.nao.org.uk/wp-content/uploads/2024/12/increasing-the-capacity-of-the-prison-estate-to-meet-demand.pdf">https://www.nao.org.uk/wp-content/uploads/2024/12/increasing-the-capacity-of-the-prison-estate-to-meet-demand.pdf</a></li>
<li>GOV.UK / Insolvency Service, "Commentary - Company Insolvency Statistics September 2025", published 17 October 2025. <a href="https://www.gov.uk/government/statistics/company-insolvencies-september-2025/commentary-company-insolvency-statistics-september-2025">https://www.gov.uk/government/statistics/company-insolvencies-september-2025/commentary-company-insolvency-statistics-september-2025</a></li>
<li>GOV.UK / The Insolvency Service, "ISG group of companies in administration: information for employees and creditors", 24 September 2024. <a href="https://www.gov.uk/government/news/isg-group-of-companies-in-administration-information-for-employees-and-creditors">https://www.gov.uk/government/news/isg-group-of-companies-in-administration-information-for-employees-and-creditors</a></li>
</ol>]]></content:encoded>
      <guid isPermaLink="false">https://www.trackedchanges.co.uk/2026-updates/construction-playbook-resolution-planning-tested.html</guid>
      <pubDate>Sat, 12 Sep 2026 18:43:00 +0000</pubDate>
    </item>
    <item>
      <title>Capita helped the Cabinet Office write the government's rulebook for what happens when an outsourcer collapses. Its own pension contract shows what happens when one does not.</title>
      <link>https://www.trackedchanges.co.uk/2026-updates/sourcing-playbook-capita-pension-transition.html</link>
      <description>A structured teardown of the Sourcing Playbook: its data quality, risk screening, financial monitoring and savings verification promises tested against the Cabinet Office's own Capita pension contract.</description>
      <content:encoded><![CDATA[<p>Estimated reading time: 12 minutes</p>
<figure class="article-hero">
<img alt="The Art Deco clock tower of the National Audit Office building on Buckingham Palace Road, London, against a clear sky." height="630" loading="eager" src="https://www.trackedchanges.co.uk/assets/images/articles/sourcing-playbook-capita-pension-transition/hero.webp" width="1200"/>
<figcaption>The National Audit Office headquarters, Buckingham Palace Road, London, July 2014. Photo: <a href="https://commons.wikimedia.org/wiki/File:National_Audit_Office_building,_Buckingham_Palace_Road.JPG">Danrok / Wikimedia Commons</a>, <a href="https://creativecommons.org/licenses/by-sa/4.0/">CC BY-SA 4.0</a>.</figcaption>
</figure>

<blockquote class="govuk-inset-text">
<p><strong>In short.</strong> The Sourcing Playbook is the Cabinet Office's rulebook for how every central government department buys outside help, and most of its eleven key policies exist to manage one risk: a supplier collapsing mid-contract. Capita was one of the firms that helped shape the rulebook's first edition in 2019. In December 2025 Capita took over the Cabinet Office's own Civil Service Pension Scheme, 1.7 million members, 189 billion pounds in liabilities, without coming anywhere near insolvency, and the transition still went wrong in almost every way the Playbook says good data, real monitoring and enforceable targets are meant to prevent. Six documented mistakes: three stars.</p>
</blockquote>
<p>Picked from the registry's queued Tier 3 entries: a document that scores highest on every criterion CLAUDE.md sets for deep editorial treatment, sector spend above a billion pounds, first-of-kind framework claims, and a live, checkable contradiction against real award data. This is a Tier 3 deep teardown: the document's own words, tested against the fullest evidence the record allows.</p>
<h2>The rulebook Capita helped write</h2>
<p>On 20 February 2019, thirteen months after Carillion's compulsory liquidation on 15 January 2018 <a href="https://www.nao.org.uk/reports/investigation-into-the-governments-handling-of-the-collapse-of-carillion/">[1]</a> left hundreds of public contracts without a working supplier overnight, Cabinet Office minister Oliver Dowden launched the Outsourcing Playbook <a href="https://www.gov.uk/government/news/outsourcing-playbook-published">[2]</a>. Jon Lewis, then chief executive of Capita, one of the suppliers government "worked with to develop the new measures", welcomed it: "This is fundamental to the successful procurement and delivery of public-sector contracts," he said <a href="https://www.gov.uk/government/news/outsourcing-playbook-published">[2]</a>. A second edition in June 2020 rebranded the document as the Sourcing Playbook, and the version live today, updated 15 June 2026, describes itself as the "fourth update", still built around the same eleven policies: pipelines, market health checks, project validation, delivery model assessments, should cost modelling, pilots, KPIs, risk allocation, pricing, supplier financial standing, and resolution planning <a href="https://www.gov.uk/government/publications/the-sourcing-and-consultancy-playbooks/the-sourcing-playbook-html">[3]</a>. It remains live guidance, checked on GOV.UK on 13 September 2026 with no withdrawal notice <a href="https://www.gov.uk/government/publications/the-sourcing-and-consultancy-playbooks">[4]</a>.</p>
<p>Six years after Lewis's endorsement, Capita is the company whose own government contract has become the Playbook's most visible live test. In November 2023 the Cabinet Office awarded Capita a seven-year, 239 million pound contract, extendable to ten years, to administer the Civil Service Pension Scheme, taking over from MyCSP, which had run it since 2012 <a href="https://www.theregister.com/2025/12/03/capita_civil_service_pension_portal/">[5]</a>. The award came months after Capita disclosed a data breach in which bank details, addresses and passport photos belonging to staff and members of its schemes were reportedly put up for sale <a href="https://www.theregister.com/2025/12/03/capita_civil_service_pension_portal/">[5]</a>. Capita is also one of the Cabinet Office's roster of Strategic Suppliers, each assigned a named Crown Representative inside the department for closer oversight, Capita's own listing last updated 1 July 2026 <a href="https://www.gov.uk/government/publications/crown-representatives-and-strategic-suppliers">[6]</a>. The scheme transferred to Capita on 1 December 2025.</p>
<h2>The claims, tested</h2>
<table>
<thead>
<tr>
<th>The Playbook's claim</th>
<th>What we found</th>
<th>Verdict</th>
</tr>
</thead>
<tbody>
<tr>
<td>"We are committed to providing accurate data... particularly with first generation contracts", and for later procurements "we rely on data provided by the incumbent" <a href="https://www.gov.uk/government/publications/the-sourcing-and-consultancy-playbooks/the-sourcing-playbook-html">[3]</a></td>
<td>Capita's own chief executive told MPs "the sheer scale of the data that was missing upon transfer is huge. We're talking about 20 million records" <a href="https://www.theregister.com/public-sector/2026/07/09/ukgov-withholds-10m-payment-from-capita-over-pensions-project-fiasco-as-dispute-continues/5269227">[7]</a></td>
<td>The handover the chapter describes did not happen</td>
</tr>
<tr>
<td>Outsourcing is "more challenging" for services that "have experienced many operational difficulties in the past" or carry "disproportionate effort and cost to bring services back in-house in future" <a href="https://www.gov.uk/government/publications/the-sourcing-and-consultancy-playbooks/the-sourcing-playbook-html">[3]</a></td>
<td>Cabinet Office's own 2021 Delivery Model Assessment found "outsourcing provided the best opportunity to realize defined benefits with the least risk" for exactly this scheme <a href="https://www.theregister.com/2026/04/17/capita_csps/">[8]</a></td>
<td>The Playbook's own checklist, waved through by the Playbook's own process</td>
</tr>
<tr>
<td>"In future, the financial thresholds we require suppliers to meet... will include some of the financial tests conducted on procurement" <a href="https://www.gov.uk/government/publications/the-sourcing-and-consultancy-playbooks/the-sourcing-playbook-html">[3]</a></td>
<td>Identical wording, "in future", appears on page 65 of the original May 2021 edition <a href="https://assets.publishing.service.gov.uk/government/uploads/system/uploads/attachment_data/file/987353/The_Sourcing_Playbook.pdf">[9]</a></td>
<td>Five years and four updates, still unfulfilled</td>
</tr>
<tr>
<td>KPIs "should be relevant and proportionate"; more than "10 to 15 per service" risks "overcomplicated contracts" <a href="https://www.gov.uk/government/publications/the-sourcing-and-consultancy-playbooks/the-sourcing-playbook-html">[3]</a></td>
<td>Capita was "on track to fail 16 of its 21 headline KPIs" seven months after go-live, with the backlog "getting higher and higher" <a href="https://www.theregister.com/public-sector/2026/07/09/ukgov-withholds-10m-payment-from-capita-over-pensions-project-fiasco-as-dispute-continues/5269227">[7]</a></td>
<td>Twenty-one is already over the Playbook's own ceiling</td>
</tr>
<tr>
<td>Ongoing monitoring should use "alert systems... to monitor company announcements and other information sources", independent of day-to-day contract management <a href="https://www.gov.uk/government/publications/the-sourcing-and-consultancy-playbooks/the-sourcing-playbook-html">[3]</a></td>
<td>The NAO found Cabinet Office "largely reliant on self-reported data from MyCSP" for oversight of the predecessor contract <a href="https://www.nao.org.uk/reports/investigation-into-the-administration-of-the-civil-service-pension-scheme/">[10]</a></td>
<td>The independent check the chapter describes was not the practice</td>
</tr>
<tr>
<td>Benefits realised through the contract should have milestones "to align with the intended benefits" <a href="https://www.gov.uk/government/publications/the-sourcing-and-consultancy-playbooks/the-sourcing-playbook-html">[3]</a></td>
<td>The NAO found Cabinet Office's claimed 83 million pound saving had "no fixed innovation or digitalisation milestones for Capita to deliver against" <a href="https://www.nao.org.uk/reports/investigation-into-the-administration-of-the-civil-service-pension-scheme/">[10]</a></td>
<td>A headline number nobody can check</td>
</tr>
</tbody>
</table>
<h2>Twenty million records, and a chapter about exactly that</h2>
<p>Chapter 5 of the Sourcing Playbook, "Preparing to go to market", has a section called "Quality data and asset registers". It states plainly: "Suppliers are dependent on us having good data. The only way they can assess whether the delivery model and pricing structure that we take to market is deliverable and sustainable is if it is based on quality data." For a second or subsequent procurement, it continues, "we rely on data provided by the incumbent", and "good contract management throughout the life of the contract is essential to ensure that the incumbent consistently provides and updates this information" <a href="https://www.gov.uk/government/publications/the-sourcing-and-consultancy-playbooks/the-sourcing-playbook-html">[3]</a>.</p>
<p>The Civil Service Pension Scheme was exactly this kind of procurement. MyCSP had run it since 2012, meaning thirteen years of records to hand over cleanly. Capita initially expected to inherit around 37,300 cases; by July 2025, months before go-live, the Cabinet Office was instructing Capita to prepare for volumes of up to 100,000 <a href="https://www.theregister.com/2026/04/17/capita_csps/">[8]</a>. By April 2026 the actual backlog stood at 86,000 cases, a significant proportion already overdue <a href="https://www.theregister.com/2026/04/17/capita_csps/">[8]</a>. Richard Holroyd, chief executive of Capita Public Services, told the Public Accounts Committee that although the company had been warned about rising case numbers, "it had little understanding of their complexity or how long they had been outstanding" <a href="https://www.theregister.com/2026/04/17/capita_csps/">[8]</a>. By July, Capita group chief executive Adolfo Hernandez put a number on the underlying problem: cases up to four years old, some relating to government departments that no longer exist, and "the sheer scale of the data that was missing upon transfer is huge. We're talking about 20 million records" <a href="https://www.theregister.com/public-sector/2026/07/09/ukgov-withholds-10m-payment-from-capita-over-pensions-project-fiasco-as-dispute-continues/5269227">[7]</a>.</p>
<p>The Playbook does not say quality data is desirable. It says the incumbent, MyCSP, and the department's own contract management were responsible for making sure it existed. Twenty million missing records is not a supplier failing to read the handbook. It is the handbook's own precondition for a safe transition not being met, on the one document that wrote the precondition down.</p>
<h2>The risk checklist the department's own assessment waved through</h2>
<p>Chapter 3, "Delivery model assessments", tells departments that some services are harder to justify outsourcing than others. It lists them: services that "are core to your organisation's purpose and objectives", that "have experienced many operational difficulties in the past", that are "poorly understood and/or not well defined", or where "there will be disproportionate effort and cost to bring services back in-house in future" <a href="https://www.gov.uk/government/publications/the-sourcing-and-consultancy-playbooks/the-sourcing-playbook-html">[3]</a>. A defined-benefit pension scheme for 1.7 million people, with 189 billion pounds of future liability <a href="https://www.nao.org.uk/reports/investigation-into-the-administration-of-the-civil-service-pension-scheme/">[10]</a>, administered by an incumbent whose call centre had missed its answer-time target for at least two years running <a href="https://www.nao.org.uk/reports/investigation-into-the-administration-of-the-civil-service-pension-scheme/">[10]</a>, is a reasonable match for at least three of those descriptions.</p>
<p>Cabinet Office ran the process the Playbook requires. Catherine Little, the Cabinet Office's permanent secretary, told the Public Administration and Constitutional Affairs Committee that the 2021 decision to outsource followed an "Outline Business Case" and a "Delivery Model Assessment" weighing insourcing against outsourcing. "The assessment provided a data-driven indication that outsourcing provided the best opportunity to realize defined benefits with the least risk," she wrote <a href="https://www.theregister.com/2026/04/17/capita_csps/">[8]</a>. The competition launched in February 2022; two independent teams ran a technical and a commercial evaluation; Capita passed a past-performance check at pre-selection and won on price and value for money <a href="https://www.theregister.com/2026/04/17/capita_csps/">[8]</a>. Every visible step matches the chapter.</p>
<p>What the chapter does not do is explain how "least risk" survived contact with its own checklist two paragraphs earlier. The process was followed. The conclusion it produced has not held up.</p>
<h2>A promise still written in the future tense</h2>
<p>Chapter 11's "Compliance confirmation" section reads: "In future, the financial thresholds we require suppliers to meet during the lifetime of new critical contracts will include some of the financial tests conducted on procurement. We will also require the boards of suppliers of new critical contracts to confirm annually that they continue to meet these thresholds" <a href="https://www.gov.uk/government/publications/the-sourcing-and-consultancy-playbooks/the-sourcing-playbook-html">[3]</a>. That sentence is not new. It appears, word for word, on page 65 of the original Sourcing Playbook, published in May 2021 <a href="https://assets.publishing.service.gov.uk/government/uploads/system/uploads/attachment_data/file/987353/The_Sourcing_Playbook.pdf">[9]</a>. Five years and, by the document's own count, four further updates later, including the one that covers the Capita transition described in this piece, the promised mechanism is still described as something that will happen, not something that does.</p>
<h2>Monitoring built on the numbers the supplier hands over</h2>
<p>The Playbook's "Ongoing financial monitoring" section is explicit about how it should work: monitoring should be run by "a function or team that is independent of the day-to-day contract management role", and "ongoing 'alert' systems should be established to monitor company announcements and other information sources" <a href="https://www.gov.uk/government/publications/the-sourcing-and-consultancy-playbooks/the-sourcing-playbook-html">[3]</a>. The National Audit Office's investigation into the predecessor contract found something narrower in practice: Cabinet Office "has an established governance structure... although it is largely reliant on self-reported data from MyCSP for its oversight of the Scheme's performance" <a href="https://www.nao.org.uk/reports/investigation-into-the-administration-of-the-civil-service-pension-scheme/">[10]</a>.</p>
<p>The same report shows what that reliance cost. MyCSP's contact centre missed its 80 per cent, 30-second call-answer target for at least two years, at one point averaging 24 minutes to answer, yet this was "not a key service level" and "does not attract a financial penalty" <a href="https://www.nao.org.uk/reports/investigation-into-the-administration-of-the-civil-service-pension-scheme/">[10]</a>. Complaints rose 43 per cent between 2016-17 and 2024-25, to 4,780 <a href="https://www.nao.org.uk/reports/investigation-into-the-administration-of-the-civil-service-pension-scheme/">[10]</a>. Across that entire period, Cabinet Office applied precisely two financial penalties, 19,355 pounds in June 2022 and 228,538 pounds in 2024, and penalties of this kind can be waived by MyCSP itself citing "extenuating circumstances" <a href="https://www.nao.org.uk/reports/investigation-into-the-administration-of-the-civil-service-pension-scheme/">[10]</a>. The new Capita contract redesigns this: a five-point severity scale replaced the old met-or-not-met test, and call response was upgraded to a key service level that can attract a penalty <a href="https://www.nao.org.uk/reports/investigation-into-the-administration-of-the-civil-service-pension-scheme/">[10]</a>. That redesign is real progress. It is also an admission that the "independent" monitoring the Playbook describes was not what Cabinet Office was actually doing on the contract it is now citing as the reason to trust the process.</p>
<h2>Sixteen of twenty-one, and getting worse</h2>
<p>The Playbook's KPI chapter warns departments against setting too many: "having too many KPIs (i.e. more than 10 to 15 per service) will lead to overcomplicated contracts and ambiguity with suppliers" <a href="https://www.gov.uk/government/publications/the-sourcing-and-consultancy-playbooks/the-sourcing-playbook-html">[3]</a>. It also commits that "four KPIs from each of the government's most important contracts shall be made publicly available", in line with "the government's transparency agenda" <a href="https://www.gov.uk/government/publications/the-sourcing-and-consultancy-playbooks/the-sourcing-playbook-html">[3]</a>. The Capita contract carries 21 headline KPIs, already above the chapter's own ceiling before a single one is measured <a href="https://www.theregister.com/public-sector/2026/07/09/ukgov-withholds-10m-payment-from-capita-over-pensions-project-fiasco-as-dispute-continues/5269227">[7]</a>.</p>
<p>Speaking to a joint session of the Public Accounts Committee and the Public Administration and Constitutional Affairs Committee on 8 July 2026, seven months after go-live, Cat Little, chief operating officer of the Civil Service, said Capita was "on track to fail 16 of its 21 headline KPIs" that month. "They are not at the pace they need to move through the processing of the work, the backlog is just getting higher and higher, so my expectation is that this trend worsens and worsens, unless something radically shifts in their ability to tackle the most important, urgent, high-priority work" <a href="https://www.theregister.com/public-sector/2026/07/09/ukgov-withholds-10m-payment-from-capita-over-pensions-project-fiasco-as-dispute-continues/5269227">[7]</a>. Little had already told the same committee in April that "Capita had provided inadequate management information to date," meaning the government's own picture of its "most important contracts" transparency commitment could not be verified even from the inside <a href="https://www.theregister.com/2026/04/17/capita_csps/">[8]</a>. This was not confined to CSPS: across Capita's other 16 government contracts, 90 per cent of KPI data was rated "good" in the same quarter <a href="https://www.theregister.com/2026/04/17/capita_csps/">[8]</a>, which argues against "Capita is simply a bad supplier" and for a specific, document-shaped failure on this one.</p>
<h2>Eighty-three million pounds, no way to check it</h2>
<p>Cabinet Office's central financial argument for the switch is that the new contract saves money: 83 million pounds over its lifetime, through "innovation and automation", compared with the MyCSP contract it replaces <a href="https://www.nao.org.uk/reports/investigation-into-the-administration-of-the-civil-service-pension-scheme/">[10]</a>. The National Audit Office's June 2025 report, published five months before go-live, recorded that Cabinet Office "does not have agreed milestones against which to manage performance" for that figure, and that "with a plan yet to be provided, there are no fixed innovation or digitalisation milestones for Capita to deliver against" <a href="https://www.nao.org.uk/reports/investigation-into-the-administration-of-the-civil-service-pension-scheme/">[10]</a>. The same report notes Cabinet Office had previously hoped MyCSP would cut costs through digitalisation and made "limited progress", for the same reason: no contractual incentive to do so <a href="https://www.nao.org.uk/reports/investigation-into-the-administration-of-the-civil-service-pension-scheme/">[10]</a>.</p>
<p>The Playbook's own logic is that KPIs "should be set to align with the intended benefits to be realised during contract delivery" <a href="https://www.gov.uk/government/publications/the-sourcing-and-consultancy-playbooks/the-sourcing-playbook-html">[3]</a>. An 83 million pound headline saving with no milestone attached to it is not a benefit that can be checked against delivery. It is a number in a business case, repeated in public, that nobody outside Cabinet Office and Capita has the means to audit while the contract runs.</p>
<h2>Credit where due</h2>
<p>The migration itself landed on schedule. A defined-benefit scheme covering 1.7 million people, with 189 billion pounds of liability and thirteen years of MyCSP records behind it, went live on 1 December 2025 as planned <a href="https://www.theregister.com/2025/12/03/capita_civil_service_pension_portal/">[5]</a>, which is a genuinely hard technical and data cutover to land on time even before anything else about it is judged. When it went wrong, the response was not silence: the government withheld 9.9 million pounds in transition payments, brought in an independent auditor to settle a dispute over further deductions, and put named officials in front of two select committees on the record within months rather than years <a href="https://www.theregister.com/public-sector/2026/07/09/ukgov-withholds-10m-payment-from-capita-over-pensions-project-fiasco-as-dispute-continues/5269227">[7]</a>. Capita group chief executive Adolfo Hernandez apologised in the same hearing to members "who have been receiving a very poor service at a very difficult and challenging time in their lives" <a href="https://www.theregister.com/public-sector/2026/07/09/ukgov-withholds-10m-payment-from-capita-over-pensions-project-fiasco-as-dispute-continues/5269227">[7]</a>, rather than deflecting the question. And the National Audit Office's own June 2025 report flagged the unmeasurable savings claim five months before it became a live problem: the machinery the post-Carillion reforms built to surface exactly this kind of risk did its job. Nobody acted on the warning in time, but the warning was there, on the record, before go-live.</p>
<h2>Verdict</h2>
<p>Three stars, from six documented mistakes in a rulebook whose central chapters, on data quality, risk screening, financial monitoring and benefits tracking, are sound in principle and were tested in public within five years of this edition's currency, on the department's own contract, involving a supplier that helped write the rulebook's first edition. None of the six is a case of Capita or Cabinet Office breaking a rule. Every one is a case of the Playbook's own promise not surviving contact with a procurement its own department ran. The Playbook was built to survive a supplier going bankrupt. Capita never came close to bankruptcy. The pension scheme still broke.</p>
<div class="warning-box">
<p>The star score counts six documented mistakes against the Sourcing Playbook's own text: the "Quality data and asset registers" chapter's promise tested against 20 million missing records; the "Delivery model assessments" risk checklist tested against the 2021 assessment that still recommended outsourcing; the "Compliance confirmation" section's threshold promise, written "in future" and unchanged since the 2021 edition; the KPI chapter's stated ceiling of 10 to 15 indicators tested against a 21-KPI contract failing 16 of them; the "Ongoing financial monitoring" chapter's independent-alert-system promise tested against the NAO's finding of reliance on supplier self-reported data; and the KPI-to-benefits alignment principle tested against an 83 million pound savings claim with no agreed milestones. Six falls in the 4 to 9 band: three stars; the bands are on the <a href="https://www.trackedchanges.co.uk/ratings.html">ratings page</a>. Capita's own marketing language on go-live, describing "the largest ever on time transition of a public sector pension scheme in the UK", is quoted for colour and not counted as a mistake against the Playbook, since the rating tracks the document's claims, not a supplier's press line. Analysis is of the Sourcing Playbook as served from GOV.UK on 13 September 2026, updated 15 June 2026. The document is tracked in the Daily Register; a revision will get a diff entry.</p>
</div>
<h2>Sources</h2>
<ol>
<li>National Audit Office, "Investigation into the government's handling of the collapse of Carillion", HC 1002, Session 2017-2019, 7 June 2018. <a href="https://www.nao.org.uk/reports/investigation-into-the-governments-handling-of-the-collapse-of-carillion/">https://www.nao.org.uk/reports/investigation-into-the-governments-handling-of-the-collapse-of-carillion/</a></li>
<li>GOV.UK / Cabinet Office, "'Outsourcing Playbook' published", 20 February 2019. <a href="https://www.gov.uk/government/news/outsourcing-playbook-published">https://www.gov.uk/government/news/outsourcing-playbook-published</a></li>
<li>HM Government / Cabinet Office, "The Sourcing Playbook" (HTML edition, updated 15 June 2026). <a href="https://www.gov.uk/government/publications/the-sourcing-and-consultancy-playbooks/the-sourcing-playbook-html">https://www.gov.uk/government/publications/the-sourcing-and-consultancy-playbooks/the-sourcing-playbook-html</a></li>
<li>GOV.UK, "The Sourcing Playbook" (publication page, checked live 13 September 2026, no withdrawal notice). <a href="https://www.gov.uk/government/publications/the-sourcing-and-consultancy-playbooks">https://www.gov.uk/government/publications/the-sourcing-and-consultancy-playbooks</a></li>
<li>The Register, "New Capita-run civil service pension portal full of errors", 3 December 2025. <a href="https://www.theregister.com/2025/12/03/capita_civil_service_pension_portal/">https://www.theregister.com/2025/12/03/capita_civil_service_pension_portal/</a></li>
<li>GOV.UK / Cabinet Office, "Crown Representatives and strategic suppliers" (last updated 1 July 2026). <a href="https://www.gov.uk/government/publications/crown-representatives-and-strategic-suppliers">https://www.gov.uk/government/publications/crown-representatives-and-strategic-suppliers</a></li>
<li>The Register, "UK.gov withholds £10M payment from Capita over pensions project fiasco, as dispute continues", 9 July 2026. <a href="https://www.theregister.com/public-sector/2026/07/09/ukgov-withholds-10m-payment-from-capita-over-pensions-project-fiasco-as-dispute-continues/5269227">https://www.theregister.com/public-sector/2026/07/09/ukgov-withholds-10m-payment-from-capita-over-pensions-project-fiasco-as-dispute-continues/5269227</a></li>
<li>The Register, "Capita won troubled UK pensions gig after performance checks", 17 April 2026. <a href="https://www.theregister.com/2026/04/17/capita_csps/">https://www.theregister.com/2026/04/17/capita_csps/</a></li>
<li>Cabinet Office, "The Sourcing Playbook" (PDF, first edition, May 2021, p.65). <a href="https://assets.publishing.service.gov.uk/government/uploads/system/uploads/attachment_data/file/987353/The_Sourcing_Playbook.pdf">https://assets.publishing.service.gov.uk/government/uploads/system/uploads/attachment_data/file/987353/The_Sourcing_Playbook.pdf</a></li>
<li>National Audit Office, "Investigation into the administration of the Civil Service Pension Scheme", HC 951, Session 2024-25, 16 June 2025. <a href="https://www.nao.org.uk/reports/investigation-into-the-administration-of-the-civil-service-pension-scheme/">https://www.nao.org.uk/reports/investigation-into-the-administration-of-the-civil-service-pension-scheme/</a></li>
</ol>]]></content:encoded>
      <guid isPermaLink="false">https://www.trackedchanges.co.uk/2026-updates/sourcing-playbook-capita-pension-transition.html</guid>
      <pubDate>Sun, 13 Sep 2026 06:44:00 +0000</pubDate>
    </item>
  </channel>
</rss>
