Briefing · SDWH Board Briefing #2
Regulating in an AI-Native Society
An API maturity survey of the UK's economic and social regulators, and what the Care Quality Commission's own data reveals.
The Question
This briefing provides an overview of how regulators support AI-native stakeholders, based on review of 12 regulators selected because they typically authorise, regulate and examine businesses and organisations across the economy.
SDWH's first board briefing, Governance in an AI-Native Society, set out a governing principle for boards: analytical capability that was once concentrated in institutions is now widely distributed to citizens, journalists, campaigners, investors and SMEs, most of it mediated by AI. That briefing asked how organisations should govern themselves as their stakeholders become AI-native.
What this briefing is about
This briefing is not about frontier AI models, or debates about whether an advanced model could act autonomously beyond its intended boundaries, or “escape” the controlled environments in which it is developed and tested. That is a real and serious question, but it is a different one, and conflating the two would misread what follows.
This briefing is about the legitimate, everyday use of openly available AI tools, often nothing more than the free tier of a mainstream consumer AI assistant, to do more with public data than a web search alone would ever allow. That capability is no longer speculative or specialist; it is routine enough to be a fixture of professional discussion on platforms like LinkedIn, and it is the starting assumption this briefing makes about what an AI-native stakeholder can already do.
The AI-native stakeholder may be curious about much more than the regulator's own performance (history, costs, efficiency, outcomes). Increasingly they want to understand how well the regulator understands the sector that it oversees, and how active it is in improving outcomes for society.
The AI-native stakeholder is not incapable of reading a PDF. The more precise problem is that the presentational layer of these websites still defaults to the PDF as the finished product for much of what they publish. Checking each of the twelve regulators' most recent annual report and accounts directly, four of them, the Office of Rail and Road, the Competition and Markets Authority, the Regulator of Social Housing and CQC, publish a genuine, navigable HTML edition. The other eight (FCA, ICO, FSA, Ofgem, TPR, Ofcom, CAA and Ofwat) present the PDF as the only version. Several of the PDF-only listings carry gov.uk's standard accessibility warning outright: CQC's own government-mirror listing states “this file may not be suitable for users of assistive technology,” as does Ofcom's, each inviting readers to request an accessible format by email rather than providing one by default, which is notable given that CQC's own website separately publishes an HTML edition of the same report, so the document exists in two different accessibility postures depending on where a reader finds it.
That is not only an AI-native problem. A document built as a print artefact is a well-documented obstacle for screen readers, and the “PDF as final product” habit has drawn sustained criticism in disability and accessibility literature for years, independent of anything to do with AI. The Government Digital Service made the same case internally in 2018, noting that PDFs are “bad for accessibility” and pushing for an HTML-first publishing culture across government. That a third of this sample already manage it shows the barrier is a choice, not a technical constraint. What connects the two audiences is the same underlying failure: information packaged for one visual, printable presentation, rather than in a form any reader, human or machine, sighted or not, can navigate, extract from, or have read aloud on their own terms. This briefing's real question, then, is broader than API access alone: it is about the accessibility, usability and efficiency of the entire visual language regulators use to present their own performance data, of which a documented API is simply the most demanding test.
To test the question empirically rather than rhetorically, this briefing surveys a defensible cross-section of UK statutory regulators for one specific thing: what a developer, researcher or AI agent can actually query from the outside, today, using only what each regulator has published.
It then examines one regulator in further detail, the Care Quality Commission, because it provides one example of a regulator seeking to be genuinely open in one respect and acknowledged by its own leadership to be failing in another, at the same time.
The Open Data Backdrop
Government has run a formal process for mandating open technical standards since November 2012, when the Cabinet Office's Open Standards Principles came into force. An Open Standards Board has since endorsed close to twenty specific standards for how government bodies exchange, format and publish data: grant data, beneficial ownership, emergency-service handovers, contract data, and more.
None of them addresses how a regulator should publish its own register: the organisations it oversees, their status, and the outcome of its last review. Where a mandated standard exists, publication tends to be consistent, because it isn't optional; where none exists, openness depends entirely on individual regulator initiative. That gap is the practical backdrop to this survey, and is examined in full later in this briefing.
Sample Selection Principles
This survey starts from the membership of the UK Regulators Network (UKRN), the body bringing together statutory regulators across the UK's utility, financial, transport and housing sectors, and looks for regulators with a large and diverse population of regulated organisations. The Competition and Markets Authority is added beyond UKRN's own membership for the same reason taken to its logical extreme: its remit is competition, consumer protection and mergers across every sector of the UK economy at once.
The result is a deliberate sample, not a random or exhaustive one: twelve regulators chosen to cover a genuinely wide cross-section of how the UK regulates its economy and society, from a single small utility market to the whole of financial services to competition policy with no sector boundary at all.
Between them, the twelve employ around 20,600 staff, spend roughly £2.4 billion a year, and hold some form of regulatory relationship with well over 1.5 million organisations, professionals, schemes and licensed entities: from the FCA's ~35,500 authorised firms, to the FSA's ~600,000 registered food premises, to CQC's 56,616 registered locations. Full regulator-by-regulator detail, including the basis for these figures, follows later in this briefing.
Measuring Openness
“Open data” is used loosely across government. This briefing distinguishes four tiers, defined by what a developer or an AI agent can actually do, not by what a regulator's website claims. This assessment is desktop analysis: a systematic review of each regulator's own published website, developer documentation and technical portals, rather than direct engagement with each regulator. Where a live technical test was possible, as with CQC's Syndication API, this is noted explicitly rather than left implicit.
The four tiers
- Tier 1: open by default. A documented API serving the regulator's own core dataset, with no registration, authentication or key required beyond a lightweight identifier; free, machine-readable, updated on a defined cycle. This is the benchmark for AI-native readiness: it removes the last human-mediated step between a question and an answer.
- Tier 2: open, but gated. A functioning API exists, or is funded and under active development, but access requires registration and an issued key, or is scoped to a narrow transactional purpose rather than full dataset access.
- Tier 3: open data, not open API. The underlying dataset is published and freely reusable, typically under the Open Government Licence, but access is via web search, dashboard or bulk file download rather than a queryable interface. This is transparency in the traditional FOI sense, not interoperability in the API sense.
- Tier 4: neither open data nor open API. No evidence of a published API or a structured open dataset covering the regulator's core population. Any external use depends on someone manually reading documents and re-keying facts.
Summary Results
At a glance, the twelve regulators sort into a simple 2×2: whether a developer-facing API exists at all (top row vs bottom row), and whether access is open without registration, or gated or absent (right column vs left column).
Figure 1: Regulators sorted by API existence and openness
Detailed Survey Results
Figure 2: Tier and evidence by regulator
| Tier | Regulator | Evidence |
|---|---|---|
| 1 | FSA | Food Hygiene Rating Scheme API: no authentication, no registration, JSON/XML, free |
| 1 | CQC | Bulk care directory and ratings downloads: no registration at all, updated weekly/monthly, dated snapshot (see case study below) |
| 1 | TPR | Live developer portal and API endpoints (e.g. auto-enrolment staging-date lookups), though narrower and more transactional in scope than FSA or CQC |
| 2 | FCA | Financial Services Register API: documented and free, but requires registration and a key |
| 2 | Ofcom | Azure-based developer portal (api.ofcom.org.uk), registration required |
| 2 | ORR | Public data portal is dashboards and downloads, not an API; but ORR's own 2024/25 accounts record capital spend on “the public consumption API,” i.e. one is funded and being built |
| 3 | ICO | Register of 1m+ fee-payers, searchable and downloadable daily under OGL, but no API |
| 3 | Ofgem | A data portal that reads as a dashboard; the genuine APIs in its ecosystem (NESO, LCCC) belong to adjacent bodies, not Ofgem itself |
| 3 | CAA | Datasets and reports published under “data and analysis”; the Aurora portal is for authorised data submission, not public consumption |
| 3 | RSH | Register is machine-readable, but via MHCLG's shared Open Data Communities platform, not RSH's own infrastructure |
| 4 | CMA | No API and no structured open dataset found, despite the widest remit of any regulator surveyed |
| 4 | Ofwat | No API of its own; instead funds Stream, a platform that requires the water companies it regulates to publish open data, rather than opening its own regulatory data |
Regulator Profiles
The table below sets out each regulator's sector, the segments of the economy or society it covers, an estimate of its regulated population, headcount and running costs, drawn from each regulator's most recently published annual report and accounts as at July 2026.
Figure 3: Regulator profiles: remit, population, headcount and cost
| Regulator | Sector / remit | Segments | Est. organisations regulated | Headcount, 2024–25 (note 1) | Annual running cost, 2024–25, £m (note 1) |
|---|---|---|---|---|---|
| FCA | Financial services conduct & prudential regulation | Banking, insurance, investment management, payments, consumer credit, mortgages, crypto-assets | ~35,500 authorised firms | 5,379 | £797.5m |
| ICO | Data protection, every UK sector | Universal: any organisation processing personal data | 1,000,000+ registered fee-payers | 1,029 | £104.4m |
| FSA | Food hygiene & safety, England/Wales/NI | One segment, but every food premises | ~600,000 registered food premises | 2,184 | £193.0m |
| Ofgem | Energy: supply, networks, generation | Electricity & gas supply, transmission/distribution, generation | 800+ licensed entities | 2,247 | £259.8m |
| TPR | Occupational pensions | DB schemes, DC schemes, master trusts, public sector schemes, micro schemes | Tens of thousands of schemes (~5,000 private DB, ~790 DC, 200 public DB, ~24,700 micro), ~22m savers | 974 | £105.3m |
| CQC | Health & social care, England | ~13 categories: care homes, hospitals, GPs, dentists, ambulances, hospices, mental health, community, home care, local authorities, plus children's/defence medical/secure settings/urgent care | 56,616 registered locations | 3,301 | £292.7m |
| Ofcom | Communications: broadcast, telecoms, post, spectrum | TV/radio, fixed & mobile telecoms, broadband, post, spectrum licensing | ~10,000 organisations | 1,608 | £209.2m |
| CAA | Aviation safety & economic regulation | Airlines, airports, air traffic, personnel licensing, drones | Low hundreds of licensed airlines/aerodromes | 1,602 | £195.7m |
| ORR | Rail safety/economic regulation + strategic roads | Rail infrastructure (Network Rail), train/freight operators, National Highways | ~23 passenger operators + freight operators + Network Rail + National Highways | 378 | £40.7m |
| RSH | Social housing, England | For-profit and not-for-profit landlords, local authorities | 1,624 registered providers, 4.4m homes | 299 | £29.7m |
| Ofwat | Water & wastewater, England/Wales | One segment | ~17 companies | 447 | £62.4m |
| CMA | Competition, consumer protection, mergers, subsidy control | All UK markets | No registered/licensed population | 1,126 | £125.0m |
| Total (12 combined) | 20,574 | £2,415.4m | |||
Note 1: this is the annual account disclosure for headcount, including contractors and temporary staff where disclosed. 5 of 12 regulators have not yet published 2025–26 accounts.
Open Data Policy
The Cabinet Office's Open Standards Principles came into force on 1 November 2012, establishing an Open Standards Board to identify, select and mandate open technical standards for government IT, software interoperability and data formats across central government departments, agencies and non-departmental public bodies.
The current endorsed list was last refreshed on 29 January 2026 (a page on critical data assets was added in April 2026). It runs to around twenty standards in three bands: exchanging information (calendar events, contact information, cyber threat intelligence, emergency-service handovers, beneficial ownership data, local authority service records); formatting information (character encoding, date formats, persistent identifiers, language and country codes); and publishing information (property and street identifiers, the Open Contracting Data Standard, grant data, job vacancy data). A recommended tier adds OpenAPI 3 and metadata standards.
None of these standards covers how a regulator should publish its own register: the organisations it authorises, inspects or rates, what it found, and when. Where a mandated standard exists, publication is consistent; where none exists, it depends on individual regulator initiative, which is why the FSA's and CQC's bulk downloads read as good practice rather than compliance.
A light “regulator register” standard, specifying a minimum schema (identifier, status, category, rating, last review date, geography) and access method (a documented API or bulk download, no registration required), would close this gap.
CQC case study
CQC was selected as the case study because it is a genuine Tier 1 result on the public data it publishes outward, while still working to resolve a finding first raised over two years ago and still open today. Dr Penny Dash's interim review of CQC's operational effectiveness, published 26 July 2024, recorded as its second numbered conclusion: “Conclusion 2: significant challenges with the provider portal and the regulatory platform.” New IT systems began rolling out across CQC from 2021 onwards; the provider portal itself launched in July 2023 and was not used in significant numbers until April 2024. CQC's November 2025 update on improvement plans for 2026 describes “improving the provider portal” and “reflecting on lessons learned” as live, ongoing work.
The open side. CQC publishes its full care directory and its ratings as free bulk downloads: no registration, no key, no relationship to establish. Anyone can take a dated snapshot of the entire register of locations and providers it regulates and start working with it immediately; this briefing's companion explorer was built entirely from that channel. Alongside it, CQC also runs a live Syndication API (api.cqc.org.uk/public/v1) for current, queryable access, but that channel requires a partner code issued by CQC on registration, confirmed directly while building the explorer (an unregistered request returns a 403). So CQC is genuinely open, but via the plainer of its two channels: the public gets a free, no-questions-asked download of the last available data; registered partners get live access. This is also why CQC appears as Tier 1 in the survey results earlier in this briefing: that placement reflects the public bulk-download channel specifically, not the gated live API, which would sit at Tier 2 on its own.
The closed side. The Provider Portal, the system CQC's own regulated providers use to submit evidence, register services and interact with their regulator, has been the subject of sustained, public criticism. Dr Penny Dash's full review, published in March 2025 as the follow-up to her July 2024 interim conclusions, found providers waiting hours for password resets and struggling to submit evidence at all. CQC has since run a public “Rebuilding CQC” improvement programme through 2025 and into 2026, with the portal rebuild, a data platform upgrade and reform of the Single Assessment Framework named as explicit, dated 2026 priorities in CQC's own progress updates.
Figure 4: locations by year of latest inspection, by category
2016–2026 · 42,283 categorised locations with a recorded inspection date · 2026 is a partial year (to the 22 July 2026 snapshot); 2010–2015 excluded as too sparse to be reliable
Nationwide count of locations by calendar year (1 January–31 December) of their most recent CQC inspection, broken down by category. The earliest inspection date included is 5 January 2016 and the latest is 22 July 2026, the date of the underlying care-directory snapshot, so 2026 is a partial year of just under seven months. CQC's bulk download records only the latest inspection date per location, not a full inspection history, so this is a proxy for inspection activity rather than a literal count of every inspection carried out. The 2020 dip across Care homes and Home care coincides with reduced on-site CQC inspection during the pandemic. Locations can carry more than one category, so category counts sum to slightly more than the number of distinct locations inspected each year. Explore this data further in the CQC Constituency Explorer.
Two datasets, one cross-check. The chart above, and the two further rating charts in the companion explorer, are built entirely from SDWH's examination of CQC's bulk data downloads, after cleansing the data to categorise it cleanly: the full care directory and ratings extract, independently parsed and joined by SDWH, with no reliance on any summary statistic CQC itself publishes. As a check on that reconstruction, SDWH separately recorded a count CQC does publish directly on its own website: a running total of ratings issued in the past month, based on a review on 23 July 2026. The two datasets cover different populations over different time windows, set out below.
Figure 5: Two CQC ratings datasets compared
| Dataset | Source and method | Observations | Time period covered |
|---|---|---|---|
| SDWH's national ratings stock | CQC's public bulk downloads (care directory and ratings extract, ~1GB uncompressed as XML), independently parsed, joined by name and postcode, and resolved to constituency by SDWH; no CQC-published summary statistics used as an input | 56,616 locations; 31,770 with a published Overall rating | Snapshot as at 1 July 2026 (ratings) / 22 July 2026 (care directory) |
| CQC's own published count | Read directly from the ratings count CQC displays on its own website (cqc.org.uk), viewed 23 July 2026 | 628 ratings | Ratings published in the preceding month |
Figure 6: Rating bands, both datasets
| Dataset | Outstanding | Good | Requires improvement | Inadequate |
|---|---|---|---|---|
| SDWH's national ratings stock (rated locations only) | 4.9% | 82.0% | 12.5% | 0.6% |
| CQC's own published count (past month) | 4.3% | 73.4% | 19.6% | 2.7% |
The two rows are not directly comparable line-for-line — one is a full national stock of currently-held ratings, the other a rolling monthly count of newly-published ratings — but both are read off the same four-band CQC rating scale. That an entirely independent reconstruction from raw public bulk data, with no privileged access and no use of CQC's own summary statistics, lands in a broadly similar range to what CQC itself publishes is a useful corroboration of the analysis in this case study.
Inside the Data
What, specifically, is available, and through which of CQC's two channels?
The bulk downloads (open to anyone, no registration) give the core of what's needed: for each location, name, type, full postal address and postcode, service type, provider name, local authority, region, and the date of latest inspection; a separate ratings extract adds CQC's Overall five-domain rating and publication date where one has been published.
The live Syndication API's published schema goes further: providers and locations carry the same core fields plus geographic coordinates.
What This Follows From, and What Comes Next
Governance in an AI-Native Society argued that AI-native stakeholders, with richer evidence, faster analysis and more sophisticated challenge, are already changing what boards need to ask themselves. This briefing extends that argument outward: regulators are themselves stakeholders' first point of contact with public accountability, and an AI-native stakeholder can only engage a regulator as directly as that regulator's own published infrastructure allows. A Tier 1 API is not a technical nicety. It is the precondition for the kind of engagement the first briefing describes.
Part Two of this briefing is a working data explorer, built entirely from CQC's open bulk downloads plus one small independent join (postcode to parliamentary constituency, via free open sources), in the same format as SDWH's existing Community Lenders Data Explorer: a searchable map and table, sourced from public data throughout, with no scraping, no registered partner access and no privileged relationship with CQC. It exists to demonstrate the argument rather than merely state it, including the argument's own limits: even the most open channel didn't give us the one field that mattered most, and getting it required going elsewhere.
Explore the CQC Constituency Explorer →
Thank you for reading this far. Please use the ‘get in touch’ button if you would like to comment on the briefing or get in touch for a discussion about it.
Approach and Methodology
This note draws on each regulator's own published website, developer documentation and annual report and accounts, supplemented by independent reporting on CQC's Provider Portal and the Dash review. Population and cost figures are drawn from the most recent primary source located for each regulator. API access was assessed by locating and, where possible, directly testing each regulator's published developer documentation; where a live call could not be independently verified, this is noted. The four-tier framework is the author's own analytical construction, designed to be checkable against each regulator's published material rather than reliant on self-description. This note does not constitute legal, regulatory or investment advice.
Appendix: Open Data and Data Protection
It is worth being precise about what “open” was ever meant to include, because the apparent tension between openness and privacy is mostly a category error rather than a real conflict.
The Open Knowledge Foundation's Open Definition, the standard reference used across the open data movement, defines open data as “data that can be freely used, re-used and redistributed by anyone.” Its own scope section is explicit about what that excludes: “the focus is on non-personal data, that is, data which does not contain information about specific individuals,” and it notes separately that national security restrictions may apply to some government data. Personal data was never within the definition of open data to begin with. A regulator that withholds individual-level records is not falling short of an open data standard; it is applying one correctly.
That distinction matters for how this briefing's central recommendation, a light, common “regulator register” standard set out earlier, should be read. It was never a proposal to publish everything a regulator holds. It was a proposal to publish the register: the organisation-level facts (identifier, status, category, rating, last review date, geography) that sit above the individual level and were always the intended subject of open data policy.
Personal data. Regulators hold personal data about the people who work in, use, or complain about the services they regulate: care home residents, patients, named staff, whistleblowers. UK GDPR and the Data Protection Act 2018 require that this data be used fairly, lawfully and transparently, for specified purposes, and kept secure; some categories (health, ethnicity, criminal record) carry stronger protection again. None of the twelve regulators surveyed here could lawfully run an “open by default” API over individual-level records of this kind, and none does; every one of them necessarily withholds far more personal data than it publishes.
Privacy by design, not privacy as an afterthought. The more useful framing than “open versus closed” is what UK GDPR calls data protection by design and by default (Article 25). Applied to regulator data, this is a design discipline that is entirely compatible with Tier 1 openness, not opposed to it: a bulk download or API that exposes organisation-level register data by default, while never collecting or exposing individual-level personal data in the first place, is simultaneously open by default and private by design. CQC's own bulk downloads are a working example of exactly this: they operate at the level of the regulated location and provider, not the individual resident or member of staff, which is a material part of why they can be published with no registration at all.
Statistical confidentiality. Even where a public body actively wants to publish, it applies disclosure control to protect individuals and businesses from being identifiable in aggregate data, suppressing or rounding results based on small counts and treating data from dominant firms in a sector as sensitive even where the underlying activity is otherwise public. The same logic would apply to any regulator publishing granular, geographically disaggregated data about a small number of regulated firms in a local market: Ofwat's 17 water companies, for instance, or ORR's handful of passenger operators.
Commercial interests. Section 43 of the Freedom of Information Act allows a public authority, including a regulator, to withhold information that is a trade secret, or whose disclosure would, or would be likely to, prejudice a legal person's commercial interests. This is not a blanket exemption; it requires a demonstrated causal link between disclosure and harm, and even where harm is shown, the exemption is still subject to a public interest test weighing accountability and value-for-money against commercial damage.
National security classification. A small proportion of regulatory information, for example aspects of CAA's work on critical aviation infrastructure or ORR's oversight of rail security, may properly fall under the Government Security Classifications Policy. This, too, sits within the Open Definition's own carve-out for national security, not outside the logic this briefing has been applying throughout.
None of this weakens the case made earlier in this briefing. A regulator can be open by default at Tier 1 and fully compliant with data protection law at the same time, because the two apply to different layers of the same dataset: the register is open (who is regulated, what their status is, when they were last reviewed); the individual is protected (the people behind that register are not exposed). A “regulator register” standard, designed properly, would specify both the open schema and the boundary around it in the same document.
Sources
- Governance in an AI-Native Society (SDWH Board Briefing #1), SDWH Limited, Jul 2026. sdwh.co.uk
- Community Lenders Data Explorer, SDWH Limited, Jul 2026. sdwh.co.uk
- UK Regulators Network: membership, UKRN, 2026. ukrn.org.uk
- Using CQC data, CQC, May 2024. cqc.org.uk
- Services we regulate, CQC, Apr 2026. cqc.org.uk
- CQC Syndication API documentation, Open Answers (community-maintained), current. openans.github.io
- CQC responds to reviews by Dr Penny Dash and Professor Sir Mike Richards, CQC, 2025. cqc.org.uk
- Dash review of the CQC: what you need to know, NHS Confederation, 2025. nhsconfed.org
- Rebuilding CQC: progress during 2025, CQC, Dec 2025. cqc.org.uk
- Food Hygiene Rating Scheme API guidance, Food Standards Agency, current. ratings.food.gov.uk
- ORR Annual Report and Accounts 2024–25 (financial statements), Office of Rail and Road, Jul 2025. orr.gov.uk
- Financial Services and Markets Bill 2026 (Payment Systems Regulator abolition), HM Treasury, 2026. gov.uk
- Using CQC data: bulk directory and ratings downloads, CQC, 22 Jul / 1 Jul 2026. cqc.org.uk
- Postcode to constituency resolution (built on ONS NSPL), postcodes.io, current. postcodes.io
- Westminster Parliamentary Constituencies (July 2024) Boundaries UK BUC, ONS Open Geography Portal, 2024. geoportal.statistics.gov.uk
- Open standards for government, Cabinet Office / CDDO / GDS, est. Nov 2012, updated Jan 2026. gov.uk
- Open Standards Principles (foreword: Rt Hon Francis Maude MP), Cabinet Office, in force 1 Nov 2012. assets.publishing.service.gov.uk
- Open standards for government data and technology (full endorsed-standards index), Government Digital Service, published Jul 2017, updated Apr 2026. gov.uk
- Data protection: the UK's data protection legislation, GOV.UK / Government Digital Service, updated Jun 2026. gov.uk
- Confidentiality policy (Standards for official statistics published by DESNZ), Department for Energy Security and Net Zero, updated Apr 2026. gov.uk
- Section 43: Commercial interests, Information Commissioner's Office, updated Aug 2023. ico.org.uk
- Government Security Classifications Policy (HTML), Cabinet Office, published Jun 2023, updated Aug 2024. gov.uk
- Review into the operational effectiveness of the Care Quality Commission: interim report (source of “Conclusion 2”), Department of Health and Social Care, 26 Jul 2024. gov.uk
- Our improvement plans for 2026, CQC, Nov 2025. cqc.org.uk
- What is Open Data? (Open Definition), Open Knowledge Foundation / Open Data Handbook, current. opendatahandbook.org
- Data protection by design and by default, Information Commissioner's Office, updated Feb 2026. ico.org.uk
- Why GOV.UK content should be published in HTML and not PDF, Government Digital Service, Jul 2018. gds.blog.gov.uk
- ORR annual report and accounts 2024/25 (HTML publication), Office of Rail and Road, Jul 2025. orr.gov.uk
- CMA Annual Report and Accounts 2024 to 2025 (HTML publication), Competition and Markets Authority, 2025. gov.uk
- CQC annual report and accounts 2024 to 2025 (gov.uk mirror: PDF only, assistive technology notice), Department of Health and Social Care, 21 May 2026. gov.uk
- CQC annual report and accounts (own-site HTML edition), CQC, current. cqc.org.uk
- Regulator of Social Housing: Annual Report and Accounts 2024-25 (HTML and PDF both published), Regulator of Social Housing, 4 Dec 2025. gov.uk
- Ofgem annual report and accounts 2024 to 2025 (PDF only), Ofgem, 17 Jul 2025. gov.uk
- The Pensions Regulator annual report and accounts 2025 to 2026 (PDF only), The Pensions Regulator, 30 Jun 2026. gov.uk
- Ofcom annual report and accounts 2025 to 2026 (PDF only, assistive technology notice), Ofcom, 9 Jul 2026. gov.uk
- About us (regulated firms count), Financial Conduct Authority, current. fca.org.uk
- Written evidence (food business registrations), submission to Parliamentary committee, current. committees.parliament.uk
Sources and scope. This page presents SDWH Board Briefing #2 (23 July 2026, v1.0). SDWH Limited provides independent analysis and policy insight. Nothing in this document constitutes financial advice, investment advice, transaction advisory, audit, assurance or valuation services, and it should not be relied upon as such. SDWH Limited is not authorised or regulated by the Financial Conduct Authority. The analysis is based on publicly available information and the author's independent judgement; no representation is made as to its completeness or accuracy. Contains public sector information licensed under the Open Government Licence v3.0. © SDWH Limited 2026. All rights reserved.