Reference: Alignment with UK Government Guidance
This framework is designed to be consistent with current UK Government guidance on AI. It does not replace that guidance but provides a practical mechanism for delivery teams to apply it in their day-to-day work.
Key publications this framework aligns with
-
AI Playbook for the UK Government (February 2025). The primary government guidance on AI use, setting out 10 principles for responsible AI including knowing AI's limitations, using AI lawfully and ethically, and maintaining meaningful human control. This framework applies those principles as an assessment process. Its accompanying AI Knowledge Hub guidance on security sets the rule that public or unassured generative AI must not process OFFICIAL information carrying additional markings such as ‑SENSITIVE or ‑PERSONAL.
-
Data and AI Ethics Framework (updated December 2025). Provides ethical principles covering privacy, fairness, accountability, and transparency, along with a self-assessment tool. The risk categories in Step 3: Assess the Risks map directly to these principles.
-
Algorithmic Transparency Recording Standard (ATRS). Mandatory for central government departments since 2024. If you are building a product feature or using AI in user-facing support in a way that involves algorithmic decision-making affecting how requests are handled, you may need to complete an ATRS record. This is addressed in Step 4: Approve, Record and Do the Work and the relevant checklists.
-
Code of Practice for the Cyber Security of AI (January 2025). Establishes baseline security requirements for AI systems across five lifecycle phases. The facts recorded in a tool profile and the security considerations in the risk catalogue reflect these requirements.
-
NCSC guidance on prompt injection (December 2025). The National Cyber Security Centre's position that prompt injection "may never be totally mitigated" and that LLMs should be treated as "inherently confusable deputies." This informs the prompt injection risk category and the emphasis on deterministic safeguards and least privilege throughout the checklists.
-
Government Security Classifications Policy (June 2023; quick read). The classification framework (OFFICIAL, SECRET, TOP SECRET, with ‑SENSITIVE as a handling caveat on OFFICIAL) is one of the key inputs to the data assessment in Step 1: Scope Your Use. Its requirement that SECRET and above be handled on dedicated accredited systems is the basis for the hard stop at those tiers.
-
ICO AI and Data Protection Risk Toolkit. The Information Commissioner's Office's practical toolkit for assessing AI systems against UK GDPR requirements, covering accountability, transparency, lawfulness, accuracy, fairness, security, individual rights, and automated decision-making. The risk assessment and the DPIA requirements align with this toolkit.
-
ICO Toolkit for Data Analytics. The ICO's introductory assessment for organisations considering data analytics, covering lawfulness, accountability, data protection principles, and data subject rights. Useful for teams new to AI-assisted data processing.
-
Understanding AI Ethics and Safety (Office for AI / GDS / Alan Turing Institute). Establishes the SUM values framework (respect dignity, connect sincerely, care for wellbeing, protect social values) and the FAST Track principles (Fairness, Accountability, Sustainability, Transparency) for public sector AI. The ethical considerations throughout this framework reflect these principles.
-
UNESCO Recommendation on the Ethics of AI (2021). Adopted by all 193 UNESCO member states, establishing principles including proportionality, safety, privacy, accountability, transparency, and human oversight. Provides the broader ethical context for responsible AI use.
-
AI Action Plan for Justice (2025). For teams working on justice sector projects, this sets out the Ministry of Justice's approach to AI adoption, including the role of the Justice AI Unit, the SAFE-D ethical principles (Sustainability, Accountability, Fairness, Explainability, Data Responsibility), and approved tools. Justice sector teams should follow this plan alongside this framework.
Mapping to the AI Playbook's 10 principles
| AI Playbook principle | Where addressed in this framework |
|---|---|
| 1. Know AI's limitations | Step 3 (Accuracy and hallucination), checklists (all require human review) |
| 2. Use AI lawfully and ethically | Step 1 (data and consent assessment), Step 3 (bias and fairness, IP), risk assessment template |
| 3. Ensure meaningful human control | Step 3 (per-risk mitigations, plus those that scale with autonomy), Step 4 (approvals), checklists (human review in all) |
| 4. Be transparent about AI use | Step 4 (record and share), checklists (ATRS, methodology documentation) |
| 5. Use the right tool for the job | Step 1 (define the use), Step 2 (tool profiles) |
| 6. Work collaboratively | Step 4 (share and document learnings, periodic review) |
| 7. Manage AI throughout its lifecycle | checklists (ongoing monitoring), Step 4 (periodic review) |
| 8. Secure AI systems | Step 3 (supply chain and security, prompt injection), Step 2 (security certifications), checklists (all include prompt injection considerations). Aligned with the NCSC's guidance that prompt injection is a design-time concern requiring deterministic safeguards and least privilege. |
| 9. Use AI proportionately | Step 3 (risk rating and proportionate mitigations), Step 4 (approval scaled to the level) |
| 10. Learn, iterate, and improve | Step 4 (share and document learnings, periodic review) |
Mapping to other referenced frameworks
| Framework | Key principles | Where addressed in this framework |
|---|---|---|
| ICO AI and Data Protection Risk Toolkit | Accountability, transparency, lawfulness, accuracy, fairness, security, individual rights, Article 22 compliance | Step 1 (data assessment, GDPR), Step 3 (all risk categories), Step 4 (DPIA), risk assessment template |
| ICO Data Analytics Toolkit | Lawfulness, accountability, data protection principles, data subject rights | Step 1 (data classification, consent), Step 2 (tool profiles) |
| UNESCO Recommendation on the Ethics of AI | Proportionality, safety, privacy, governance, accountability, transparency, human oversight, sustainability, awareness, fairness | Proportionality: Step 3. Human oversight: checklists. Fairness: Step 3 (bias). Transparency: Step 4. Awareness: ground rules in the overview. |
| Understanding AI Ethics and Safety (SUM/FAST) | Fairness, Accountability, Sustainability, Transparency | Fairness: Step 3 (bias and fairness). Accountability: Step 3 (accountability gaps), Step 4. Sustainability: checklists (ongoing monitoring). Transparency: Step 4 (ATRS). |
| AI Action Plan for Justice (SAFE-D) | Sustainability, Accountability, Fairness, Explainability, Data Responsibility | Sustainability: checklists (ongoing monitoring), Step 4 (periodic review). Accountability: Step 3, Step 4. Fairness: Step 3 (bias). Explainability: checklists (ATRS, model card). Data Responsibility: Step 1, Step 2. |