Skip to main content

Digital Assurance Policy

Classification: OFFICIAL

Policy Details

Field Details
Policy Identifier JDDS-POL02
Policy Owner Head of Digital Compliance
Policy Sponsor Chief Technology Officer
Date Created 15/04/2026
Date Last Reviewed 11/06/2026
Date of Next Review 11/06/2027
Expiry When rescinded or replaced
Version 1.0

Purpose

The purpose of this policy is to define the Ministry of Justice’s (MoJ) approach to digital assurance and internal digital and technology spend approvals. It sets out how assurance activity supports informed decision-making, effective risk management and the responsible use of public money across digital and data services. This policy addresses the need for clear, proportionate and accountable assurance following the removal of central digital and technology spend controls. It ensures the MoJ maintains confidence in digital investment decisions and delivery outcomes while operating with increased departmental autonomy. The policy supports organisational objectives by enabling high-quality, sustainable digital and technology services that are aligned to MoJ strategy, deliver value for money, meet user needs and comply with relevant legislation, government standards and regulatory requirements, including the GOV.UK Service Standard, Secure by Design and GDS’ Digital Assurance Playbook.


Scope

The policy applies where; -Delivery of any digital, data and technology initiatives are being built or bought on behalf of the MoJ, this includes new services, products, programmes and contracts -Significant changes to existing live services -All delivery phases including discovery, alpha, beta, live and major change, this also applies when using non-agile phases (Scope, Pilot, Scale, Waterfall Delivery, KANBAN, Sigma Six etc)

This policy applies to; -All business areas, teams and governance forums involved in digital, data and technology delivery -All personnel, including third-party suppliers and partners, engaged in digital, data and technology delivery activity for the MoJ

This policy does not apply to; -Spend with no digital, data or technology component -Routine business as usual operational activit that does not introduce material change to scope, cost, risk or delivery approach


Policy Statements

The following mandatory principles, standards and rules must be followed to ensure compliance with MoJ governance and assurance requirements

  1. All digital and technology initiatives must undergo appropriate, proportionate assurance internally prior to proceeding to deliver or committing to spend.

  2. Initiatives above internal MoJ spend thresholds (£100k for public facing services and £1m for all other digital and technology activity), must go through the Digital Assurance Gateway for spend approval.

  3. For initiatives below internal spend thresholds, spend may be progressed through the relevant Declaration of Spend process, in place, within Justice Digital, Data and Science (JDDS), this enables the JDDS Senior Leadership Team to self-assure digital and technology spend in line with delegated authority levels.

  4. Use of the Declaration of Spend process does not remove the requirement for proportionate assurance engagement with relevant assurance forums, including Standards, Security, Demand, Commercial, Data protection and technical authorities.

  5. Services seeking approval must evidence alignment with the GOV.UK Service Standard, Secure by Design principles, accessibility regulations, data protection requirements, and applicable commercial and technical standards.

  6. The MoJ must maintain a pipeline of digital and technology initiatives in line with HM Treasury requirements. Recording an initiative on the pipeline does not constitute approval to commit spend or commence delivery.

  7. Initiatives must be added to the above pipeline where they are assessed as Novel, Contentious or Repercussive (NCR) and/or have a whole life cost above £5 million

  8. Any initiative identified as NCR and/or above the MoJ Delegated Authority Limit (DAL) of £500 million must have HM Treasury co assurance and approval before proceeding.


Principles

MoJ policies and operating procedures must provide a clear risk-based approach, providing clear, purpose driven and proportionate direction setting out how the MoJ will operate.


Roles and Responsibilities

Role/Team Responsibilities
Digital Assurance Gatewat Panel A multi-disciplinary forum accountable for reviewing and making decisions on spend approval requests above agreed internal thresholds, informed by cross-functional assurance.
Functional Assurance Assurance is provided by relevant specialist functions, each contributing within their area of expertise in line with the Digital Assurance Gateway Panel Terms of Reference. Collectively, this assurance covers areas such as commercial, security, technical design, service standards, accessibility, and compliance with government and organisational frameworks. A full list of participating functions and their roles is set out in the Digital Assurance Gateway Panel Terms of Reference.
Service Owners Accountable for service outcomes, compliance with service standards, and ownership of delivery risk. Responsible for formally accepting risk through appropriate governance routes.
Service and Delivery Teams Responsible for engaging with assurance processes, providing evidence, completing required assessments, and implementing agreed mitigations.
Budget Holder Accountable for approving the overall digital, data, or technology initiative. Provides formal approval to commit expenditure in line with delegated financial authority and confirms alignment with business priorities, funding approvals, and agreed financial envelopes. Remains accountable for the budget throughout the lifecycle of the initiative.
Finance Business Partner Provides financial and commercial challenge to support informed decision-making. Confirms affordability of proposed digital and technology spend against agreed budgets and forecasts, advises on financial risks, funding profiles, and value-for-money considerations, and supports escalation where affordability concerns or financial risks are identified.
Policy Reviewers Responsible for reviewing the content of this policy annually, and any ad hoc reviews, to ensure it remains accurate and fit for purpose.

Monitoring and Compliance

Compliance with this policy will be monitored by the Digital Assurance Team through Digital Assurance Gateways, health check reviews, pipeline oversight and governance reporting. Non‑compliance, material risks or assurance concerns will be escalated through appropriate MoJ governance forums and may result in additional assurance activity, remediation actions or withdrawal of approval.


Exceptions

Any deviations from this policy must be formally approved by the Policy Owner. Applications to deviate from the policy must be documented and subject to risk assessment.


Breach of Policy

Policy must be adhered to, and any breaches may result in steps being taken under the MoJ Performance Management Policy and may lead to escalation through governance, risk management or disciplinary processes where appropriate.


The following policies, standards, frameworks, processes, procedures and guidance support this policy:

  • Service Standard
  • Service Standards and Service Assessment Policy
  • Digital Assurance Playbook
  • Secure By Design Policy and Guidance
  • MoJ Security Policies
  • Digital Accessibility Policy
  • Data Protection Policies
  • Government Functional Standards
  • Commercial and Procurement Policies
  • Digital Assurance Gateway Terms of Reference
  • Technology Code of Practice

Review and Update

This policy must be reviewed on an annual basis. or sooner where there are material changes to government policy, assurance requirements or organisational structure.

Reviews must be conducted by the policy reviewers defined in Roles and Responsibilities, and approved by the policy owner before publication.


Questions or Feedback?

If you have any questions about this policy or the template, please contact:

Email: DigitalStandards@justice.gov.uk

Slack: [standards-team channel]

This page was last reviewed on 11 June 2026. It needs to be reviewed again on 11 June 2027 by the page owner #digital-compliance-team .