Senior leaders and SROs must stop treating appraisal, contract design and delivery assurance as discrete phases. The Treasury’s Green Book (2026) re‑frames what counts as value in public investments; at the same time SI 2026/425 forces the ICO to produce a statutory AI/ADM code that will change how personal data and automated decisions are treated in procurement and in live services. This article gives a practical operating‑model playbook and 90‑day priorities for converting compliant appraisal into executable, low‑risk delivery. ([gov.uk](https://www.gov.uk/government/publications/the-green-book-appraisal-and-evaluation-in-central-government/the-green-book-2026?utm_source=openai))
What has changed — the new constraints you cannot ignore
Green Book (2026) broadens appraisal beyond single metrics and requires clearer evidence of distributional, social and digital/data benefits. Investment cases will be judged on wider impact and on how benefits are realised across systems, not only on a headline cost‑benefit ratio. That affects business case structure, options weighting and the evidence you must bring to a Treasury gateway. ([gov.uk](https://www.gov.uk/government/publications/the-green-book-appraisal-and-evaluation-in-central-government/the-green-book-2026?utm_source=openai))
SI 2026/425 (Data Protection Act 2018 regulations) places a statutory duty on the Information Commissioner to produce a code of practice for AI and automated decision‑making; the code is explicitly required to cover processing of children’s personal data and will raise expectations on documentation, testing, human review and records of training/validation data. This is not optional guidance — it is an enabling statutory instrument already in force (May 2026). ([legislation.gov.uk](https://www.legislation.gov.uk/uksi/2026/425/pdfs/uksi_20260425_en.pdf?utm_source=openai))
Procurement and commercial controls are already changing. The Procurement Act 2023 introduced new exclusion, debarment and KPI‑reporting expectations for contracting authorities; commercial teams must treat supplier governance, performance KPIs and exclusion risk as part of the operating‑model decisions that shape options and procurement route. ([gov.uk](https://www.gov.uk/government/publications/procurement-act-2023-guidance-documents-procure-phase/guidance-exclusions-html?utm_source=openai))
How this affects transformation operating models (three immediate design consequences)
1) Appraisal must include delivery‑grade supplier and data risk evidence. When you choose options, evidence packs should include high‑level supplier risk heatmaps, a data‑use impact summary and a short ‘AI/ADM control’ strategy so that Treasury reviewers see delivery feasibility, not just theoretical benefit.
2) Contracting and governance must be designed for regulated AI/ADM. Procurement teams must bake in obligations for audit trails, algorithmic impact assessments and human‑in‑loop design where automatic decisions materially affect citizens. This must be costed and scoped in the business case.
3) Operating models must explicitly allocate data‑product and run‑book responsibilities. Where services create derived data assets or automated decisions, your operating model must identify owners, SRO escalation paths, regulatory evidence owners, and a mapped supplier ecosystem (primary supplier, integrators, sub‑contractors and data processors).
90‑day SRO checklist: convert appraisal into executable delivery
Week 1–2: Rapid evidence triage — mandate a 5‑page evidence pack for each high‑value option that includes: (a) benefits map against Green Book distributional and digital/data framework, (b) supplier risk heatmap (top 10 risks), (c) data classification and ADM touchpoints, and (d) a cyber/resilience risk summary referencing CAF v4.0 where relevant. Use this pack at your next Programme Board. ([gov.uk](https://www.gov.uk/government/publications/the-green-book-appraisal-and-evaluation-in-central-government/the-green-book-2026?utm_source=openai))
Week 3–6: Procurement and contract templates — instruct procurement to produce a short list of procurement routes and a contract starter pack that embeds: ICO code compliance obligations (audit & data handling), KPIs required by the Procurement Act, mandatory supplier reporting on near‑misses and breach playbooks, and clear subcontractor flow‑down clauses. Include options for incentives tied to benefits realisation.
Week 7–12: Delivery‑grade controls and acceptance criteria — define Minimum Viable Controls (MVCs) that a supplier must demonstrate before live handover: evidence of training/test data lineage, ADM impact assessment, human review procedures, a CAF v4.0 mapping for security controls (where essential services are involved), and a live‑cutover rollback and recovery test.
Commercial design patterns that work (practical templates)
Hybrid commercial model: small capex + staged benefits milestones. Use an initial capability contract (6–12 months) with a clearly priced option for scale‑up pending delivery of MVCs and independent assurance findings.
Data escrow + access guarantees: for services dependent on third‑party platforms or models, require data‑in‑escrow arrangements and run‑time access guarantees so the authority retains the ability to observe, audit and extract outputs for continuity or re‑procurement.
Regulatory pass‑throughs: where the statutory ICO code requires specific mitigations, contractually require suppliers to maintain compliance and to notify the authority of any change in practices, third‑party model suppliers, or material changes to training data composition.

Assurance: what auditors and Treasury will expect
Auditors and Treasury will want to see an auditable claim that benefits are likely and an evidence chain to delivery. That means: a) a tested acceptance plan with MVCs, b) independent assurance milestones baked into the contract, c) evidence of commercial remedies (liquidated damages, step‑in rights) and d) a clear data governance register mapping processing grounds and retention policies. Failure to provide these often creates approval delays and rework. ([gov.uk](https://www.gov.uk/government/publications/the-green-book-appraisal-and-evaluation-in-central-government/the-green-book-2026?utm_source=openai))
For any automated decisions that materially affect individuals, prepare an early privacy/data protection impact assessment and a governance note showing where and how human review will be applied; the ICO’s forthcoming code will expect documented mitigation and explainability for significant ADM. ([legislation.gov.uk](https://www.legislation.gov.uk/uksi/2026/425/pdfs/uksi_20260425_en.pdf?utm_source=openai))
Practical pitfalls — five things senior leaders still get wrong
Treating model or algorithm risk as purely technical (it is a commercial and policy risk).
Assuming standard procurement templates cover AI/ADM obligations — they rarely do; you must add specific clauses.
Under‑estimating the cost and time to produce training‑data lineage and audit trails.
Failing to include independent assurance gates before benefit‑linked payments.
Not mapping cyber resilience to CAF v4.0 outcomes where essential services are involved; this tends to surface late in gateway reviews. ([ncsc.gov.uk](https://www.ncsc.gov.uk/blog-post/caf-v4-0-released-in-response-to-growing-threat?utm_source=openai))
If you design appraisal, procurement and delivery separately you will be forced back into rework. Treat regulation, data controls and supplier governance as delivery design constraints — not as checkbox compliance after the contract is signed.
Antares recommended actions
These are Antares's recommended first actions for organisations turning the issues in this article into practical governance and delivery.
- Immediate (0–30 days): Require a one‑page regulatory impact statement for every high‑value business case (Green Book appendix) that lists SI 2026/425 touchpoints and data/ADM obligations. ([gov.uk](https://www.gov.uk/government/publications/the-green-book-appraisal-and-evaluation-in-central-government/the-green-book-2026?utm_source=openai))
- Short (30–90 days): Mandate delivery‑grade MVCs and an evidence pack for procurement that includes data lineage, ADM impact assessment and independent assurance entry/exit criteria.
- Commercial: Adopt hybrid contracts (small initial deployment + milestone payments tied to independent assurance and demonstrated MVCs). Include data escrow and step‑in rights.
- Governance: Appoint a named Data & ADM SRO within each programme with budget authority for independent testing and audit evidence.
- Risk & resilience: Map CAF v4.0 IGPs to your cyber assurance workstreams where services are essential or highly connected. ([ncsc.gov.uk](https://www.ncsc.gov.uk/blog-post/caf-v4-0-released-in-response-to-growing-threat?utm_source=openai))
- Organisation design: Create a short cross‑functional panel (SRO, Head of Commercial, Data Protection Officer, CIO, SRO for security) that must sign off gateway packs prior to any major procurement.