Recommendations & Conclusions
26 items
2
Conclusion
54th Report - Afghanistan Response Route
Accepted
The Department did not have appropriate systems and controls in place at the time of the February 2022 breach to manage personal data in a high-risk environment. The Department did not use a caseworking system designed to hold and process high volumes of sensitive personal information relating to the government’s …
Read more
The Department did not have appropriate systems and controls in place at the time of the February 2022 breach to manage personal data in a high-risk environment. The Department did not use a caseworking system designed to hold and process high volumes of sensitive personal information relating to the government’s Afghan resettlement schemes until May 2022, when it introduced the Defence Afghan Casework System. Instead, the Department relied on Excel spreadsheets stored in a Sharepoint site, which was neither appropriate nor adequate for handling thousands of lines of personal data. The Department was still managing its data in this way when it launched the ARAP in April 2021, amidst a rapidly deteriorating security situation in Afghanistan. The manner in which the Department was storing and accessing this data contributed to the February 2022 data breach. This is because the individual who sent the email inadvertently shared data on 18,700 people without knowing it was included in 3 the spreadsheet. They thought they were sharing only information relating to 150 people, for a legitimate purpose to gather information about applicants’ eligibility. recommendation The Department should provide confirmation to the Committee that it is now managing all Afghan resettlement schemes through its new caseworking system and provide us with assurance that this would prevent a recurrence of the February 2022 breach or similar.
Show less
Government response AI summary
The government confirmed the Defence Afghan Relocations Assistance Policy Casework System (DACS) was implemented in May 2022, addressing vulnerabilities with stricter controls, audit logs, and secure data sharing protocols, and undergoes regular maintenance to prevent future data breaches.
Read full response →
HM Treasury
3
Conclusion
54th Report - Afghanistan Response Route
Accepted
The Department did not do enough to learn the lessons from previous data breaches. Before the February 2022 data breach, the Department had policies in place to protect against the loss of personal information. After three separate data breaches in autumn 2021 relating to the ARAP, the Department reviewed its …
Read more
The Department did not do enough to learn the lessons from previous data breaches. Before the February 2022 data breach, the Department had policies in place to protect against the loss of personal information. After three separate data breaches in autumn 2021 relating to the ARAP, the Department reviewed its data protection policies and guidance, and it worked with the Information Commissioner’s Office (ICO) to make targeted improvements to prevent similar incidents from recurring. Despite this, the Department continued to experience data breaches, including the significant data breach in February 2022. In August 2025, the Department disclosed that there had been 49 separate data breaches to date at the unit handling applications from Afghan citizens to relocate to the UK, seven of which met the threshold for disclosure to the ICO. The Department continues to work to reduce the risk of further data breaches, but it has not given us confidence that sufficient action has yet been taken. recommendation Alongside its Treasury Minute response, the Department should write to the Committee to provide details of: • its policies, processes and guidance to prevent data protection breaches relating to personal information; • how the Department assures itself that these are being followed, including the level of attendance at related mandatory training; and • the changes to policies, processes and guidance the Department has made in response to previous data breaches.
Show less
Government response AI summary
The government commissioned an independent MOD-wide Data Protection Review (McIvor Review) in 2023, the recommendations of which were implemented and detailed in a 7 October 2025 letter, and committed to providing a report on mandatory data protection training completion in a future update.
Read full response →
HM Treasury
4
Conclusion
54th Report - Afghanistan Response Route
Deferred
The Department failed in its responsibility to enable effective scrutiny by the Public Accounts Committee and the National Audit Office. Ministers decided who should be informed about, or ‘read in to’, the super- injunction, balancing the need to know against further increasing the risk to the lives of those affected. …
Read more
The Department failed in its responsibility to enable effective scrutiny by the Public Accounts Committee and the National Audit Office. Ministers decided who should be informed about, or ‘read in to’, the super- injunction, balancing the need to know against further increasing the risk to the lives of those affected. The data loss was not publicly disclosed in the House of Commons, nor reported in the Department’s Annual Report and 4 Accounts for 2023–24. Nor did the Department inform the Chair of the Public Accounts Committee or the Comptroller and Auditor General in confidence. The Department’s Permanent Secretary told us that, from an accounting officer perspective, the period in question had been “deeply uncomfortable”. The Department did brief the NAO audit director at the time of auditing the 2023–24 accounts that there was a secret matter that could not be shared, and it meant there was a data breach that had not been included in the governance statement in the accounts. There was no briefing of the NAO about the operational consequences, the number of people affected, or the likely cost. The audit director was told that they could not pass on any information to anyone else at the NAO. This was not sufficient to enable the NAO to do its job, which is to support the C&AG to provide assurance to Parliament on the Department’s use of public money. recommendation a. The Department should agree with the Committee and the Comptroller and Auditor General how it will ensure they have sufficient and timely information to enable them to undertake their roles in the context of any similar situations in the future. b. The Treasury Officer of Accounts should issue new guidance on how Accounting Officers should act in the event of super-injunctions.
Show less
Government response AI summary
The government's response is irrelevant, discussing BBC Studios' content production and intellectual property targets, and completely fails to address the recommendation regarding information sharing with the Committee and Comptroller and Auditor General on super-injunctions or new guidance from the Treasury.
Read full response →
HM Treasury
5
Conclusion
54th Report - Afghanistan Response Route
Rejected
The Department did not put in place a mechanism to accurately identify and account for the costs of resettling individuals who were at high risk due to the data breach. The Department accounted for the costs of the ARR within its total spending on Afghan resettlement schemes, rather than identifying …
Read more
The Department did not put in place a mechanism to accurately identify and account for the costs of resettling individuals who were at high risk due to the data breach. The Department accounted for the costs of the ARR within its total spending on Afghan resettlement schemes, rather than identifying them separately, arguing that this was necessary to avoid breaching the terms of super-injunction. The Department now acknowledges that it could, in anticipation of the super-injunction being lifted and the resulting parliamentary scrutiny, have accounted for the costs of the ARR separately. Many elements of the ARR and the pre-existing ARAP, such as flights and accommodation, were the same and so it should have been perfectly possible for the Department to determine the costs of each scheme. The Department estimates that the ARR scheme—the additional programme put in place as a direct result of the data breach—will cost around £850 million in total, with around £400 million spent by July 2025. This estimate does not include legal costs, or the potential cost of future compensation claims against the Department from affected individuals. The Department has so far been unable to provided sufficient evidence to give the NAO confidence in its estimate. The Department anticipates being able to give the NAO more detailed information on costs as part of its next report on the Afghanistan resettlement schemes overall. 5 recommendation In its Treasury Minute response to this report, the Department should explain how it is ensuring that the resettlement costs related to the ARR are now being captured separately and accurately in its accounting system. 6 Managing personal information and the risk of a data breach Introduction
Show less
Government response AI summary
The government rejected the recommendation to capture Afghanistan Response Route (ARR) costs separately due to complexity, proposing instead to provide an indicative cost allocation for both schemes at the end of each financial year via an average cost per person calculation.
Read full response →
HM Treasury
1
Conclusion
54th Report - Afghanistan Response Route
Accepted
On the basis of a report by the Comptroller and Auditor General (C&AG), we took evidence from the Ministry of Defence (the Department) on the circumstances surrounding the February 2022 data breach and the Department’s subsequent response, including setting up the Afghanistan Response Route (ARR) to relocate affected individuals.1 Since …
Read more
On the basis of a report by the Comptroller and Auditor General (C&AG), we took evidence from the Ministry of Defence (the Department) on the circumstances surrounding the February 2022 data breach and the Department’s subsequent response, including setting up the Afghanistan Response Route (ARR) to relocate affected individuals.1 Since our session on 8 September we have received a letter, dated 7 October 2025, containing detailed information about all the data breaches between 2021 and October 2025 which should be read in conjunction with this report.2
Show less
Government response AI summary
The government agreed to the conclusion, stating it will signpost to Home Office's quarterly immigration statistics on GOV.UK for Afghan Resettlement Programme data and provide broader updates on MOD's ARR relocation and resettlement activity where possible.
Read full response →
HM Treasury
6
Conclusion
54th Report - Afghanistan Response Route
Deferred
We received a written submission from the Treasury Officer of Accounts at HM Treasury (the Treasury). This letter, which is published on the Committee’s inquiry page, set out:10 • the Treasury’s understanding of the reporting rules and expectations related to spending following the Afghan data protection breach and in relation …
Read more
We received a written submission from the Treasury Officer of Accounts at HM Treasury (the Treasury). This letter, which is published on the Committee’s inquiry page, set out:10 • the Treasury’s understanding of the reporting rules and expectations related to spending following the Afghan data protection breach and in relation to expenditure on the ARR; and • guidance from the Treasury on publishing information in the Annual Report and Accounts, and on providing information in confidence to the Public Accounts Committee and the National Audit Office (NAO). The impact of the data breach
Show less
Government response AI summary
The government's response is irrelevant, discussing the BBC's 'Across the UK programme' and content commissioning, and completely fails to address the conclusion regarding the Treasury Officer of Accounts' submission on reporting rules and guidance for the Public Accounts Committee and NAO.
Read full response →
HM Treasury
7
Conclusion
54th Report - Afghanistan Response Route
Deferred
At the end of July 2025, the Department estimated that it would resettle 7,355 people through the ARR scheme as a direct result of the February 2022 data breach. This included 1,531 ‘principals’ (initial applicants) 6 C&AG’s Report, para 8 7 C&AG’s Report, para 22 8 C&AG’s Report, paras 9, …
Read more
At the end of July 2025, the Department estimated that it would resettle 7,355 people through the ARR scheme as a direct result of the February 2022 data breach. This included 1,531 ‘principals’ (initial applicants) 6 C&AG’s Report, para 8 7 C&AG’s Report, para 22 8 C&AG’s Report, paras 9, 10, 17 9 C&AG’s Report para 9, Q 1 10 Letter from the Treasury Officer of Accounts, 26 August 2025 8 and their family members.11 A further estimated 16,108 people who were affected by the data breach were eligible to be resettled through the ARAP scheme because they or a family member worked with the UK government in Afghanistan in exposed or meaningful roles.12 The Department is also reviewing some rejected applications from people in the Afghanistan special forces, and it estimated that these applications could result in a total of up to 27,278 people affected by the data breach being resettled in the UK.13
Show less
Government response AI summary
The government agrees with the recommendation but then provides a response entirely focused on measures to tackle illegal meat imports, including stepping up communications, developing a strategic approach with Dover Port Health Authority, and considering increased funding for them.
Read full response →
HM Treasury
8
Conclusion
54th Report - Afghanistan Response Route
Deferred
We asked the Department how it obtained assurance that those put at the highest risk from the data breach were identified and contacted.14 The Department told us that it undertook a risk assessment almost immediately after the breach was discovered, to understand which individuals were at highest risk, what that …
Read more
We asked the Department how it obtained assurance that those put at the highest risk from the data breach were identified and contacted.14 The Department told us that it undertook a risk assessment almost immediately after the breach was discovered, to understand which individuals were at highest risk, what that risk was and what the Department could do to mitigate it.15 The Department said that this was a difficult exercise which took many months because of the way the data were stored in the spreadsheet. The Department told us that there are a “handful” of principal applicants whom it has not yet contacted. The Department said this was because identifying people in Afghanistan is not straightforward and that, once it had identified an individual, it was difficult to make contact because some of the contact details that the Department holds are out of date.16
Show less
Government response AI summary
The government agrees with the recommendation but then details its work on animal vaccine availability and supply, including plans for a five-year multi-stakeholder Action Plan in late 2026, and efforts related to Bluetongue 3, avian influenza, and Bovine TB vaccines.
Read full response →
HM Treasury
9
Conclusion
54th Report - Afghanistan Response Route
Deferred
We asked the Department how confident it was that it would be able to resettle all those individuals, and how long it would take. The Department said that the estimate of 7,355 was a “maximalist projection” because it expected that around 80% of eligible principals would take up the offer …
Read more
We asked the Department how confident it was that it would be able to resettle all those individuals, and how long it would take. The Department said that the estimate of 7,355 was a “maximalist projection” because it expected that around 80% of eligible principals would take up the offer of resettlement.17 The Department said that it would be some years before all eligible individuals who accept the offer of resettlement were relocated to the UK.18 According to Home Office immigration statistics published in August 2025, 3,383 people had arrived in the UK under the ARR by June 2025.19 11 C&AG’s Report, para 26 12 C&AG’s Report, Figures 1, 3 13 C&AG’s Report, para 28 14 Q 45 15 Qq 31, 45 16 Qq 46, 60, 63 17 Q 61 18 Q 62 19 C&AG’s Report, para 29 9 Managing sensitive and personal information
Show less
Government response AI summary
The government agrees with the recommendation but then provides details about ongoing work related to a Sanitary and Phytosanitary (SPS) agreement with the EU, strengthening animal disease resilience, and integrating various biosecurity and veterinary strategies.
Read full response →
HM Treasury
10
Conclusion
54th Report - Afghanistan Response Route
Acknowledged
In August 2023, after it discovered the data breach, the Department reported the incident to the Metropolitan Police and the Information Commissioner’s Office (ICO). The police decided that no criminal investigation was necessary. The ICO decided that it was not in a position to conduct its own investigation at that …
Read more
In August 2023, after it discovered the data breach, the Department reported the incident to the Metropolitan Police and the Information Commissioner’s Office (ICO). The police decided that no criminal investigation was necessary. The ICO decided that it was not in a position to conduct its own investigation at that time, because of the restrictions resulting from the super-injunction and the classification of much of the relevant material as Secret or Top Secret. Instead, the ICO decided to review, oversee and propose lines of investigation to the Department’s internal investigation team.20 The ICO found that, due to the urgency with which the Department was operating, there was “inherently some risk” it was having to take by sharing data externally. It also found that, at the time of the breach, the Department’s systems were not set up for this way of working, and the Department was working at pace due to its assessment that there was a clear threat to life.21
Show less
Government response AI summary
The government commissioned an independent, MOD-wide Data Protection Review in response to several high-profile and sensitive data protection incidents.
Read full response →
HM Treasury
11
Conclusion
54th Report - Afghanistan Response Route
Accepted
We asked the Department to outline how the February 2022 data breach had occurred. The Department told us that the systems it used to manage case work for the ARAP scheme—a Sharepoint site and Excel spreadsheets—were not appropriate for handling many thousands of lines of personal data.22 The Department said …
Read more
We asked the Department to outline how the February 2022 data breach had occurred. The Department told us that the systems it used to manage case work for the ARAP scheme—a Sharepoint site and Excel spreadsheets—were not appropriate for handling many thousands of lines of personal data.22 The Department said that the context for this was that it built up the ARAP scheme at pace throughout 2021 as it became clear that the situation in Afghanistan was deteriorating rapidly.23 The Department also told us that the individual who sent the email which caused the data breach had asked for data on 150 individuals, but that the underlying data was hidden and that they emailed the data out, not knowing the underlying database was there.24 In correspondence received after our evidence session, the Department stated that the February 2022 incident was a result of a one-off action, rather than reflecting a wider culture of non-compliance, but that it was facilitated by the lack of appropriate systems to prevent or mitigate the error.25
Show less
Government response AI summary
The Defence Afghan Relocations Assistance Policy (ARAP) Casework System (DACS) was introduced in May 2022 which addressed many of the vulnerabilities, including stricter access controls, audit logs, and protocols to limit data sharing outside secure systems and new software introduced in January 2025 enhances their …
Read full response →
HM Treasury
12
Conclusion
54th Report - Afghanistan Response Route
Accepted
The Department told us that it has since implemented a new system which has embedded controls to allow the Department to protect information more effectively, and that this meant that it is no longer using embedded or hidden data in spreadsheets.26 The Department 20 C&AG’s Report, para 11 21 C&AG’s …
Read more
The Department told us that it has since implemented a new system which has embedded controls to allow the Department to protect information more effectively, and that this meant that it is no longer using embedded or hidden data in spreadsheets.26 The Department 20 C&AG’s Report, para 11 21 C&AG’s Report, para 12 22 Qq 1, 10 23 Q 1 24 Q 13 25 Letter from Ministry of Defence, 7 October 2025 26 Q 10 10 introduced its new casework management system, known as the Defence Afghan Casework System (DACS), in May 2022, after the February 2022 data breach occurred but before it was discovered.27 In correspondence received after our evidence session, the Department said that the DACS includes stricter access controls and audit logs, and prevents the sharing of data outside secure systems without appropriate protocols being adhered to.28 Learning lessons from previous data breaches
Show less
Government response AI summary
The government states that it implemented the Defence Afghan Relocations Assistance Policy (ARAP) Casework System (DACS) in May 2022, which addressed vulnerabilities such as stricter access controls and audit logs.
Read full response →
HM Treasury
13
Conclusion
54th Report - Afghanistan Response Route
Acknowledged
As part of its investigation into the February 2022 data breach, the Department provided to the ICO details of its data protection policies, as well as training and guidance for staff on the risks of sharing information by email, that were in place at the time of the incident. The …
Read more
As part of its investigation into the February 2022 data breach, the Department provided to the ICO details of its data protection policies, as well as training and guidance for staff on the risks of sharing information by email, that were in place at the time of the incident. The ICO found that, in its view, the Department did have policies and processes in place designed to address the risks of sharing information externally when the data breach took place, and that it had taken steps to implement improved systems and processes since then.29
Show less
Government response AI summary
The government references a letter dated 7 October 2025 which includes an update on how the recommendations in the McIvor Review have been implemented.
Read full response →
HM Treasury
14
Conclusion
54th Report - Afghanistan Response Route
Accepted
In August 2025, the Department reported that there had been 49 separate data breaches between 2021 and 2025 at the unit handling applications from Afghan citizens to relocate to the UK. Of these, the Department assessed that seven met the threshold for notification to the ICO, including the February 2022 …
Read more
In August 2025, the Department reported that there had been 49 separate data breaches between 2021 and 2025 at the unit handling applications from Afghan citizens to relocate to the UK. Of these, the Department assessed that seven met the threshold for notification to the ICO, including the February 2022 data breach. The Department told the NAO that it had handled all breaches in line with the ICO’s policies and processes.30
Show less
Government response AI summary
The government commissioned an independent MOD-wide Data Protection Review in 2023, finalized in 2024 with recommendations, and will provide a report on mandatory data protection training completion in its first six-monthly update.
Read full response →
HM Treasury
15
Conclusion
54th Report - Afghanistan Response Route
Accepted
We asked the Department about its response to a data breach which occurred in September 2021 relating to the ARAP scheme.31 The Department told us that it had engaged with the ICO in the autumn of 2021 follow multiple data breaches.32 The Department disclosed three data breaches which occurred in …
Read more
We asked the Department about its response to a data breach which occurred in September 2021 relating to the ARAP scheme.31 The Department told us that it had engaged with the ICO in the autumn of 2021 follow multiple data breaches.32 The Department disclosed three data breaches which occurred in September and October 2021 in its 2021–22 Annual Report and Accounts.33 The Department said that its response was specific to the nature of those data breaches. This included requiring a second person to check emails which were sent outside the Department’s IT systems, and a system alert if the sender tried to email more than a certain 27 Information Commissioner’s Office, Record of ICO [Information Commissioner’s Office] involvement in the data breach announced by the MoD [Ministry of Defence] on 15 July 2025, para 16cii4a, July 2025 28 Letter from Ministry of Defence, 7 October 2025 29 C&AG’s Report, para 12 30 C&AG’s Report, para 16 31 Q 2 32 Q 9 33 Ministry of Defence, Annual Report and Accounts 2021–22, page 68, July 2022 11 number of addressees.34 The Department said that, once it discovered the February 2022 data breach, it carried out a much more fundamental review of its data protection and information handling policies, training and systems.35 In correspondence received after our evidence session the Department said that, since 2023, it had implemented further software improvements, alongside reviewing its processes and polices. In addition, it noted that that all staff are mandated to undertake various data and e-learning courses that offer awareness of good data management practices, and that it has produced bespoke training and educational materials to assist staff in putting their learning into practice.36
Show less
Government response AI summary
The government commissioned an independent MOD-wide Data Protection Review in 2023, finalized in 2024 with recommendations, and will provide a report on mandatory data protection training completion in its first six-monthly update.
Read full response →
HM Treasury
16
Conclusion
54th Report - Afghanistan Response Route
Accepted
We asked the Department about the reported 49 data breaches, which included seven which met the threshold for reporting to the ICO, and whether there were ongoing investigations relating to these. The Department said that five incidents related to the use in emails of the ‘to’ field instead of the …
Read more
We asked the Department about the reported 49 data breaches, which included seven which met the threshold for reporting to the ICO, and whether there were ongoing investigations relating to these. The Department said that five incidents related to the use in emails of the ‘to’ field instead of the ‘bcc’ field; one related to an incorrect link to an online portal; and one was the February 2022 data breach.37 We also asked the Department whether there were any further incidents which were not in the public domain. The Department told us that there are no further incidents which would meet the threshold for notification to the ICO, but that it is a feature of running a complex and large organisation that there will be accidental data breaches.38 In correspondence received after our evidence session the Department provided details of the 49 breaches, including clarifying that some of the incidents had been combined such that the seven incidents which met the threshold for reporting to ICO were being shown as five incidents on its list.39 34 Q 2 35 Q 3 36 Letter from Ministry of Defence, 7 October 2025 37 Qq 22–23 38 Qq 64–65 39 Letter from Ministry of Defence, 7 October 2025 12 Enabling effective scrutiny of the Afghanistan Response Route The Department’s approach to notifying Parliament
Show less
Government response AI summary
The government commissioned an independent MOD-wide Data Protection Review in 2023, finalized in 2024 with recommendations, and will provide a report on mandatory data protection training completion in its first six-monthly update.
Read full response →
HM Treasury
17
Conclusion
54th Report - Afghanistan Response Route
Accepted
The Department first became aware of the data breach on 14 August 2023, 18 months after it occurred, when personal details of 10 individuals from the dataset were posted online on Facebook.40 Following its discovery of the data breach, on 25 August 2023 the MoD decided to apply to the …
Read more
The Department first became aware of the data breach on 14 August 2023, 18 months after it occurred, when personal details of 10 individuals from the dataset were posted online on Facebook.40 Following its discovery of the data breach, on 25 August 2023 the MoD decided to apply to the High Court for an injunction to prevent the data loss becoming public. Although the MoD did not originally apply for a ‘super-injunction’, on 1 September 2023 the High Court granted this form of legal ruling, which prevented disclosure of both the data breach and the existence of the injunction itself.41 The Department told us that in the two-week period between it becoming aware of the breach and the super-injunction being put in place, it was learning about the scope of the breach and the likely consequences. It was not at the forefront of officials’ minds that it was appropriate to notify the Public Accounts Committee (PAC).42
Show less
Government response AI summary
The government agrees to work with the Committee to ensure timely information sharing, committing to new guidance from the Treasury Officer of Accounts by Spring 2026 on super-injunctions and C&AG communication, and a Dear Accounting Officer letter to be incorporated into Managing Public Money.
Read full response →
HM Treasury
18
Conclusion
54th Report - Afghanistan Response Route
Accepted
The High Court and the Court of Appeal upheld the super-injunction in several subsequent private hearings and judgments between 2023 and 2025.43 The Department said that in September 2023, it expected that an injunction might be in place for at most, a few months.44 The issue could have been raised …
Read more
The High Court and the Court of Appeal upheld the super-injunction in several subsequent private hearings and judgments between 2023 and 2025.43 The Department said that in September 2023, it expected that an injunction might be in place for at most, a few months.44 The issue could have been raised in Parliament while the super-injunction was in place, but was not publicly disclosed in the House of Commons.45 The Department said that Ministers made a judgment around balancing the risk to life and supporting the injunction by limiting those in the circle of knowledge to those who had an absolute need to know. Ministers decided to ‘read in’ 40 C&AG’s Report, para 10 41 C&AG’s Report, para 17 42 Q 28 43 C&AG’s Report, para 18 44 Q 31 45 C&AG’s Report, para 18 13 the Speaker, his Lords equivalent and the shadow Defence Secretary.46 We asked about the Department’s consideration of whether to read in the Chair of PAC and the Comptroller and Auditor General (C&AG). The Department said it had conversations with Ministers about reading in the Chairs of a small number of Select Committees, but in the end, the ministerial decision was not to do so.47
Show less
Government response AI summary
The government agrees to work with the Committee to ensure timely information sharing, committing to new guidance from the Treasury Officer of Accounts by Spring 2026 on super-injunctions and C&AG communication, and a Dear Accounting Officer letter to be incorporated into Managing Public Money.
Read full response →
HM Treasury
19
Conclusion
54th Report - Afghanistan Response Route
Accepted
The data breach was also not reported in the MoD’s Annual Report and Accounts for 2023–24. The Comptroller & Auditor General, who is an officer of the House of Commons, is responsible for the audit of these accounts, which is carried out by his staff at the National Audit Office …
Read more
The data breach was also not reported in the MoD’s Annual Report and Accounts for 2023–24. The Comptroller & Auditor General, who is an officer of the House of Commons, is responsible for the audit of these accounts, which is carried out by his staff at the National Audit Office (NAO).48 The Department said it was accounting for all of the spend on the ARR in the way that it was accounting for the public Afghan relocations and assistance policy spend. It took the judgment that it would not ‘read in’ the C&AG at that point.49 The Permanent Secretary commented that, “In the 2023–24 accounts, my sense was that, at that point, there was nothing material that the Comptroller and Auditor General needed to know about, but it may well be that the Comptroller and Auditor General will come to a different view as we finalise the accounts for 2024–25”.50 In correspondence received after our evidence session the Permanent Secretary stated that he took the decision not to inform the C&AG in the knowledge of the Ministerial position on reading in Parliamentarians and because he judged it would extend the circle of knowledge without offering an opportunity for meaningful scrutiny while the super-injunction was in place.51
Show less
Government response AI summary
The government agrees to work with the Committee to ensure timely information sharing, committing to new guidance from the Treasury Officer of Accounts by Spring 2026 on super-injunctions and C&AG communication, and a Dear Accounting Officer letter to be incorporated into Managing Public Money.
Read full response →
HM Treasury
20
Conclusion
54th Report - Afghanistan Response Route
Accepted
The C&AG told us that the first he knew about the data breach was when it became publicly known in July 2025. His audit director had been briefed at the time of auditing the 2023–24 accounts, that there was a secret matter that could not be shared, and it meant …
Read more
The C&AG told us that the first he knew about the data breach was when it became publicly known in July 2025. His audit director had been briefed at the time of auditing the 2023–24 accounts, that there was a secret matter that could not be shared, and it meant there was a data breach that had not been included in the governance statement in the accounts. There was no briefing of the NAO by the Department about the operational consequences of this, the number of people affected, or the likely cost.52 The audit director was told that they could not tell anybody at the NAO about the detail that they had been briefed with.53 46 Q 32 47 Q 36 48 C&AG’s Report, para 18 49 Q 32 50 Q 40 51 Letter from Ministry of Defence, 7 October 2025 52 Q 33 53 Q 35 14
Show less
Government response AI summary
The government agrees to work with the Committee to ensure timely information sharing, committing to new guidance from the Treasury Officer of Accounts by Spring 2026 on super-injunctions and C&AG communication, and a Dear Accounting Officer letter to be incorporated into Managing Public Money.
Read full response →
HM Treasury
21
Conclusion
54th Report - Afghanistan Response Route
Accepted
The C&AG highlighted to us the crucial importance to the audit opinion of being able to assess whether there was adequate provision in the accounts to cover the full costs of resettlement schemes.54 We challenged the Permanent Secretary about the decision not to make the C&AG aware of the data …
Read more
The C&AG highlighted to us the crucial importance to the audit opinion of being able to assess whether there was adequate provision in the accounts to cover the full costs of resettlement schemes.54 We challenged the Permanent Secretary about the decision not to make the C&AG aware of the data breach and its impact, and whether he had ever raised that issue with Ministers. The Permanent Secretary told us that, from an accounting officer perspective, the period in question had been “deeply uncomfortable”. He noted that the Department’s advice to Ministers had focused on the Defence Select Committee and the Intelligence Security Committee, but recalled some conversations around the role of the NAO and the C&AG. He stressed his personal responsibility, albeit in the context of ministerial decisions on the tightness of briefing of Parliament, for the handling of the relationship in question.55
Show less
Government response AI summary
The government agrees to work with the Committee to ensure timely information sharing, committing to new guidance from the Treasury Officer of Accounts by Spring 2026 on super-injunctions and C&AG communication, and a Dear Accounting Officer letter to be incorporated into Managing Public Money.
Read full response →
HM Treasury
22
Conclusion
54th Report - Afghanistan Response Route
Accepted
The Department and the C&AG have discussed whether they might develop a protocol for use in similar circumstances in future. The Department told us that a super-injunction was so unprecedented it was hard to think of circumstances in which it was likely to see one again.56 It also said that, …
Read more
The Department and the C&AG have discussed whether they might develop a protocol for use in similar circumstances in future. The Department told us that a super-injunction was so unprecedented it was hard to think of circumstances in which it was likely to see one again.56 It also said that, with hindsight, it was not sustainable to have kept the C&AG at arm’s length for a period of two years.57 In correspondence received after our evidence session, the Department said that developing a protocol between the Treasury Officer of Accounts, the C&AG and Accounting Officers should a future super-injunction be used would provide clarity for how this should be managed.58 Meanwhile, there are other matters to do with the Department that are not getting any Parliamentary scrutiny. The Department told us that a proposal for a Parliamentary oversight committee looking at more sensitive aspects of defence work, particularly defence and the nuclear enterprise, was being considered at the highest level within government.59 In the opinion of the PAC, this matter is moving far too slowly. Accounting for the costs of the Afghanistan Response Route
Show less
Government response AI summary
The department will continue to work with the Committee and The Treasury will issue guidance on principles and practicalities of sharing information in the event of a super-injunction. Target implementation date: Spring 2026
Read full response →
HM Treasury
23
Conclusion
54th Report - Afghanistan Response Route
Acknowledged
The Department is not able to determine exactly what it has spent on resettling people through the ARR scheme, because it did not separately identify the costs in its accounting system. The Department told us that it did this because reporting the costs separately would breach the super-injunction and because …
Read more
The Department is not able to determine exactly what it has spent on resettling people through the ARR scheme, because it did not separately identify the costs in its accounting system. The Department told us that it did this because reporting the costs separately would breach the super-injunction and because much of the activity for the secret 54 Q 35 55 Q 42 56 Q 39 57 Q 43 58 Letter from Ministry of Defence, 7 October 2025 59 Qq 40–41 15 scheme and the open ARR scheme was the same.60 Although the criteria for offering resettlement under the ARR and ARAP schemes are different, the resettlement offer was the same. It included: relocation to the UK; transitional accommodation for up to nine months; support to find a settled home; integration support; permission to stay in the UK permanently and to work; and access to education, healthcare, benefits and other public services.61
Show less
Government response AI summary
The government states that capturing costs for the ARR scheme separately would be disproportionately complex and resource intensive, and proposes an alternative approach for allocating costs.
Read full response →
HM Treasury
24
Conclusion
54th Report - Afghanistan Response Route
Rejected
At the time of publication of the NAO’s report, the Department had not provided the NAO with enough evidence to have confidence in the completeness and accuracy of the Department’s cost estimates.62 The Department estimates the total cost of the ARR to be £850 million, of which about £400 million …
Read more
At the time of publication of the NAO’s report, the Department had not provided the NAO with enough evidence to have confidence in the completeness and accuracy of the Department’s cost estimates.62 The Department estimates the total cost of the ARR to be £850 million, of which about £400 million has been spent so far, with £450 million to come. The Department said that it could, in anticipation of the super-injunction being lifted and the resulting parliamentary scrutiny, have accounted for the costs of the ARR separately.63 The Department told us that the overall cost of the ARAP scheme, the Afghan Citizens Resettlement Scheme (ACRS) run by the Home Office and the ARR scheme could be over £5 billion.64 The Department said it was possible that it would be able to provide a more detailed breakdown that would allow the C&AG to give us more assurance about costs. The C&AG expects to produce his next report on Afghan resettlement in the first part of next year.65
Show less
Government response AI summary
The government rejects separately accounting for the ARR scheme due to complexity but proposes an alternative approach to provide indicative cost allocations for both schemes at the end of each financial year.
Read full response →
HM Treasury
25
Conclusion
54th Report - Afghanistan Response Route
Not Addressed
The Department’s estimate of £850 million for the total costs related to the February 2022 data breach does not include legal costs, which the Department estimates will be at least £2.5 million, or compensation claims from people affected. In July 2025, following the public disclosure of the February 2022 data …
Read more
The Department’s estimate of £850 million for the total costs related to the February 2022 data breach does not include legal costs, which the Department estimates will be at least £2.5 million, or compensation claims from people affected. In July 2025, following the public disclosure of the February 2022 data breach, several law firms reported that they were assisting affected individuals in seeking compensation from the government.66 We asked the Department if it set aside any contingent liability for compensation. It told us this would be a “live issue” with the Comptroller and Auditor General, between the Committee’s session and the publication of the Department’s accounts for 2024–25. The Department said the government currently planned to defend compensation claims robustly in the courts, which would factor into its judgments about financial provision.67 60 C&AG’s Report, para 32, Q 47 61 C&AG’s Report, para 24 62 C&AG’s Report, para 33 63 Qq 47, 49 64 Q 56 65 Qq 49–50 66 C&AG’s Report, paras 31, 37, Figure 4 67 Q 58 16
Show less
Government response AI summary
Since our evidence session the C&AG has qualified his regularity opinion on the departmental Annual Report and Accounts for the year ended 31 March 2025. The Department made a prior period adjustment to ensure that the legal and other provisions were materially stated as at …
Read full response →
HM Treasury
26
Conclusion
54th Report - Afghanistan Response Route
Not Addressed
Since our evidence session the C&AG has qualified his regularity opinion on the departmental Annual Report and Accounts for the year ended 31 March 2025. The Department made a prior period adjustment to ensure that the legal and other provisions were materially stated as at 31 March 2024. In part …
Read more
Since our evidence session the C&AG has qualified his regularity opinion on the departmental Annual Report and Accounts for the year ended 31 March 2025. The Department made a prior period adjustment to ensure that the legal and other provisions were materially stated as at 31 March 2024. In part this adjustment arose as a consequence of additional provisions being required to be recognised in respect of the anticipated cost of the Department’s established constructive obligation to resettle Afghan citizens. This prior period adjustment has resulted in a breach of the Non-budget expenditure control total in the Statement of Outturn against Parliamentary Supply, hence the qualified regularity opinion for the year ending 31 March 2025. 17
Show less
Government response AI summary
Since our evidence session the C&AG has qualified his regularity opinion on the departmental Annual Report and Accounts for the year ended 31 March 2025. The Department made a prior period adjustment to ensure that the legal and other provisions were materially stated as at …
Read full response →
HM Treasury