Requirements - Decision Making & Governance - DM02 - External Controls

Spend control (GaTS) and associated Government Digital Services & Service Design related guidance should be followed whilst developing the solution and be evidenced for service design & spend control reviews.

Requirement description

This requirement is concerned with demonstrating that the appropriate spend control, governance and service design processes have been followed during solution development.

The focus is not simply on obtaining approval. Teams should be able to show that relevant guidance, assessments, reviews and artefacts have been produced and used to inform decisions throughout the lifecycle of the service.

Evidence should support any service design, spend control, assurance or governance reviews that apply to the service.

In simple terms:
The team should be able to demonstrate that required spend control and service design processes have been followed and that evidence exists to support review and assurance activity.

Scoring rubric table – DM02 Spend Control and Service Design Governance

Score What it looks like Typical evidence Key gaps / risks
0 No evidence that spend control, GaTS, service design or related governance requirements have been considered. No assurance artefacts.
No review evidence.
No governance records.
No documented compliance activities.
Significant risk of non-compliance, failed assurance reviews, duplicated effort, delayed approvals and poor governance.
1 Limited awareness of spend control or service design requirements. Activities are informal and largely undocumented. Ad hoc meeting notes.
Informal discussions.
Unstructured evidence held by individuals.
High-risk gaps. Insufficient evidence to support formal reviews. Significant risk of governance challenge.
2 Some required activities have been completed, but evidence is incomplete, inconsistent or difficult to trace. Partial service design outputs.
Incomplete review packs.
Some governance records.
Limited evidence of compliance activities.
Significant notable gaps. Required activities may have been missed and there is limited confidence that reviews could be successfully supported.
3 Much of the required spend control and service design process has been followed. Evidence exists for most key activities and reviews. Documented service design artefacts.
Governance papers.
Review submissions.
Decision records.
Evidence of engagement with relevant assurance processes.
Notable gaps remain. Some artefacts are missing, outdated or lack approval records. Traceability between requirements and evidence may be incomplete.
4 Most required governance, spend control and service design activities have been completed and are supported by clear, maintained evidence. Complete review packs.
Service design outputs.
Governance approvals.
Assurance feedback records.
Traceable evidence repository.
Evidence of actions being tracked and completed.
Minor gaps only. Any missing evidence is low risk and unlikely to affect assurance outcomes.
5 Comprehensive and exemplar evidence of adherence to spend control and service design guidance. Compliance is embedded within delivery governance and planning. Comprehensive and maintained assurance artefacts.
Clear audit trail of reviews and approvals.
Evidence repository linked to governance processes.
Lessons learned incorporated into delivery practices.
Early and proactive engagement with assurance stakeholders.
Regular review of compliance obligations.
Minimal or no significant gaps. Governance and assurance activities are well controlled and continually improved.

What assessors should look for

  1. Process compliance – Has the team followed the relevant spend control, assurance and service design processes?
  2. Evidence quality – Is there clear, accessible evidence supporting review activities and decisions?
  3. Governance engagement – Has the service engaged with the appropriate governance and assurance groups where required?
  4. Traceability – Can decisions, reviews and approvals be traced back to supporting artefacts and activities?
  5. Maintenance – Is evidence current and maintained throughout the service lifecycle rather than produced retrospectively?

What separates a 3 from a 4 or 5

A score of 3 generally indicates that the team has completed most required activities and can provide evidence for many of them, but gaps remain in completeness, traceability, maintenance or approval records.

A score of 4 requires evidence to be structured, maintained and routinely available to support governance reviews, with only minor gaps remaining.

A score of 5 requires governance and assurance activities to be embedded within normal delivery processes. Evidence is comprehensive, maintained over time, easily traceable and demonstrates continuous improvement rather than simple compliance.

Suggested evidence examples (not SAF-mandated artefacts)

  • GaTS submissions and supporting artefacts
  • Service design review packs
  • Governance and Design Authority papers
  • TRG, PDG or programme review outputs
  • Assurance review feedback and actions
  • Architecture Decision Records
  • Delivery approval records
  • Requirements traceability evidence
  • Risk, issue and dependency logs related to assurance activities
  • Evidence repositories or compliance trackers

Updated: 04 September 2026 (SAF Version 1.1)