54th Report - Afghanistan Response Route
Select Committee
Public Accounts Committee
HC 1391
14 November 2025
No response data available yet.
Government response
Treasury minutes: Government response to the Committee of Public Accounts on the Fifty-fourth report from Session 2024-26 · published 19 Jan 2026
Recommendations & Conclusions
26 results
2
Conclusion
Require assurance that new casework system prevents recurrence of Afghan resettlement data breaches
Conclusion
The Department did not have appropriate systems and controls in place at the time of the February 2022 breach to manage personal data in a high-risk environment. The Department did not use a caseworking system designed to hold and process …
Read more
HM Treasury
View Details
3
Conclusion
Require Department to detail data protection policies, assurance, and changes made after breaches
Conclusion
The Department did not do enough to learn the lessons from previous data breaches. Before the February 2022 data breach, the Department had policies in place to protect against the loss of personal information. After three separate data breaches in …
Read more
HM Treasury
View Details
4
Conclusion
Establish agreement on information sharing for scrutiny and issue new super-injunction guidance
Conclusion
The Department failed in its responsibility to enable effective scrutiny by the Public Accounts Committee and the National Audit Office. Ministers decided who should be informed about, or ‘read in to’, the super- injunction, balancing the need to know against …
Read more
HM Treasury
View Details
5
Conclusion
Require Department to explain how Afghanistan Response Route resettlement costs are separately captured
Conclusion
The Department did not put in place a mechanism to accurately identify and account for the costs of resettling individuals who were at high risk due to the data breach. The Department accounted for the costs of the ARR within …
Read more
HM Treasury
View Details
1
Conclusion
Committee took evidence on February 2022 data breach and Afghanistan Response Route
Conclusion
On the basis of a report by the Comptroller and Auditor General (C&AG), we took evidence from the Ministry of Defence (the Department) on the circumstances surrounding the February 2022 data breach and the Department’s subsequent response, including setting up …
Read more
HM Treasury
View Details
6
Conclusion
Treasury clarified reporting rules and guidance for spending following Afghan data breach.
Conclusion
We received a written submission from the Treasury Officer of Accounts at HM Treasury (the Treasury). This letter, which is published on the Committee’s inquiry page, set out:10 • the Treasury’s understanding of the reporting rules and expectations related to …
Read more
HM Treasury
View Details
7
Conclusion
Department estimates resettling up to 27,278 individuals due to Afghan data breach.
Conclusion
At the end of July 2025, the Department estimated that it would resettle 7,355 people through the ARR scheme as a direct result of the February 2022 data breach. This included 1,531 ‘principals’ (initial applicants) 6 C&AG’s Report, para 8 …
Read more
HM Treasury
View Details
8
Conclusion
Identifying and contacting all high-risk individuals after data breach remains difficult.
Conclusion
We asked the Department how it obtained assurance that those put at the highest risk from the data breach were identified and contacted.14 The Department told us that it undertook a risk assessment almost immediately after the breach was discovered, …
Read more
HM Treasury
View Details
9
Conclusion
Full resettlement of eligible individuals accepting offers will take several years.
Conclusion
We asked the Department how confident it was that it would be able to resettle all those individuals, and how long it would take. The Department said that the estimate of 7,355 was a “maximalist projection” because it expected that …
Read more
HM Treasury
View Details
10
Conclusion
ICO unable to conduct full data breach investigation due to classified information.
Conclusion
In August 2023, after it discovered the data breach, the Department reported the incident to the Metropolitan Police and the Information Commissioner’s Office (ICO). The police decided that no criminal investigation was necessary. The ICO decided that it was not …
Read more
HM Treasury
View Details
11
Conclusion
February 2022 data breach caused by inappropriate systems and hidden data.
Conclusion
We asked the Department to outline how the February 2022 data breach had occurred. The Department told us that the systems it used to manage case work for the ARAP scheme—a Sharepoint site and Excel spreadsheets—were not appropriate for handling …
Read more
HM Treasury
View Details
12
Conclusion
New casework system DACS implemented with enhanced controls to protect information.
Conclusion
The Department told us that it has since implemented a new system which has embedded controls to allow the Department to protect information more effectively, and that this meant that it is no longer using embedded or hidden data in …
Read more
HM Treasury
View Details
13
Conclusion
Department had data protection policies but improved systems since February 2022 breach.
Conclusion
As part of its investigation into the February 2022 data breach, the Department provided to the ICO details of its data protection policies, as well as training and guidance for staff on the risks of sharing information by email, that …
Read more
HM Treasury
View Details
14
Conclusion
Afghan relocation unit reported 49 data breaches between 2021 and 2025.
Conclusion
In August 2025, the Department reported that there had been 49 separate data breaches between 2021 and 2025 at the unit handling applications from Afghan citizens to relocate to the UK. Of these, the Department assessed that seven met the …
Read more
HM Treasury
View Details
15
Conclusion
Department implemented significant data protection improvements following multiple previous breaches.
Conclusion
We asked the Department about its response to a data breach which occurred in September 2021 relating to the ARAP scheme.31 The Department told us that it had engaged with the ICO in the autumn of 2021 follow multiple data …
Read more
HM Treasury
View Details
16
Conclusion
Department identified 49 data breaches, attributing many to common email errors.
Conclusion
We asked the Department about the reported 49 data breaches, which included seven which met the threshold for reporting to the ICO, and whether there were ongoing investigations relating to these. The Department said that five incidents related to the …
Read more
HM Treasury
View Details
17
Conclusion
MoD failed to notify PAC about data breach after 18-month delay and obtaining super-injunction.
Conclusion
The Department first became aware of the data breach on 14 August 2023, 18 months after it occurred, when personal details of 10 individuals from the dataset were posted online on Facebook.40 Following its discovery of the data breach, on …
Read more
HM Treasury
View Details
18
Conclusion
Super-injunction upheld, limiting ministerial briefing on data breach to a select few.
Conclusion
The High Court and the Court of Appeal upheld the super-injunction in several subsequent private hearings and judgments between 2023 and 2025.43 The Department said that in September 2023, it expected that an injunction might be in place for at …
Read more
HM Treasury
View Details
19
Conclusion
Permanent Secretary chose not to inform C&AG or report data breach in MoD's annual accounts.
Conclusion
The data breach was also not reported in the MoD’s Annual Report and Accounts for 2023–24. The Comptroller & Auditor General, who is an officer of the House of Commons, is responsible for the audit of these accounts, which is …
Read more
HM Treasury
View Details
20
Conclusion
C&AG discovered data breach publicly in 2025, while audit director was secretly briefed but silenced.
Conclusion
The C&AG told us that the first he knew about the data breach was when it became publicly known in July 2025. His audit director had been briefed at the time of auditing the 2023–24 accounts, that there was a …
Read more
HM Treasury
View Details
21
Conclusion
C&AG requires full cost assessment; Permanent Secretary acknowledges "deeply uncomfortable" relationship handling.
Conclusion
The C&AG highlighted to us the crucial importance to the audit opinion of being able to assess whether there was adequate provision in the accounts to cover the full costs of resettlement schemes.54 We challenged the Permanent Secretary about the …
Read more
HM Treasury
View Details
22
Conclusion
Department and C&AG discuss future protocol, but parliamentary oversight committee progress is too slow.
Conclusion
The Department and the C&AG have discussed whether they might develop a protocol for use in similar circumstances in future. The Department told us that a super-injunction was so unprecedented it was hard to think of circumstances in which it …
Read more
HM Treasury
View Details
23
Conclusion
Department unable to determine precise ARR scheme costs due to commingled accounts and super-injunction.
Conclusion
The Department is not able to determine exactly what it has spent on resettling people through the ARR scheme, because it did not separately identify the costs in its accounting system. The Department told us that it did this because …
Read more
HM Treasury
View Details
24
Conclusion
Department's £850 million ARR cost estimate lacks sufficient evidence for NAO audit assurance.
Conclusion
At the time of publication of the NAO’s report, the Department had not provided the NAO with enough evidence to have confidence in the completeness and accuracy of the Department’s cost estimates.62 The Department estimates the total cost of the …
Read more
HM Treasury
View Details
25
Conclusion
Data breach cost estimate of £850 million excludes substantial legal fees and potential compensation claims.
Conclusion
The Department’s estimate of £850 million for the total costs related to the February 2022 data breach does not include legal costs, which the Department estimates will be at least £2.5 million, or compensation claims from people affected. In July …
Read more
HM Treasury
View Details
26
Conclusion
Qualified departmental accounts resulted from Afghan resettlement provision adjustments and expenditure breach.
Conclusion
Since our evidence session the C&AG has qualified his regularity opinion on the departmental Annual Report and Accounts for the year ended 31 March 2025. The Department made a prior period adjustment to ensure that the legal and other provisions …
Read more
HM Treasury
View Details