Skip to content
Digital Trust Audit

The Digital Trust Audit Standard

Version 1.0. Published 20 September 2026. This standard is public, dated and versioned. Any assessment states the version it was carried out under.This standard sets out what a Digital Trust Audit checks, how each finding is flagged, how the score is calculated, what the scheme refuses to do, and how a finding or a withdrawn accreditation is appealed. It is published so that anyone can check whether we applied our own rules.

What is assessed

The assessment is outside-in. It examines what a customer, a procurement team or an AI answer engine can establish about a business without being given access to anything — the public website, the domain records, the mail configuration, the public registers and the public presence.

It does not examine trading conduct, financial standing, complaint history or the quality of the work a business does. Those are assessed by other bodies, several of them with public authority this scheme does not have, and this standard makes no claim about them.

The eleven areas checked in a Digital Trust AuditEleven small hexagons in a row, one for each of the eleven areas the audit checks.
  1. Company record — the registered name, number, registered office and filing status, and whether the address itself tells a checker anything.

  2. One business or several — whether the trading names, brands and legal entities a visitor encounters resolve to the company they think they are dealing with.

  3. Machine-readability — whether the site states, in a form a machine can extract, what the business is, where it is and what it sells.

  4. Navigability — whether a visitor and a crawler can reach everything the business claims to publish.

  5. Email authentication — SPF, DKIM and DMARC, and whether the domain can be impersonated.

  6. Contactability and identification — whether the published contact routes reach the business, and whether the business is identifiable from them.

  7. Proof — whether case studies, figures and claimed accreditations reconcile against the registers that issue them.

  8. Presence away from the site — what independent sources say, and whether they agree with the site.

  9. Domain ownership — who holds the domain, how it renews, and how close it is to expiry.

  10. Legal pages and company particulars — whether the statutory disclosures are present and name the correct entity.

  11. Accessibility — conformance against the published standard, checked rather than fixed.

The four flags, and the fifth state

Every finding in a report carries one of these. Colour is never the only carrier of meaning — each one is labelled as well.

  • Passed — Checked against a live source and found to meet the criterion

  • Needs a decision — Correct as it stands, but a choice the business has not made is visible from outside

  • Weak — Present but below the criterion

  • Failed — Checked against a live source and found not to meet the criterion

Could not be confirmed — Not establishable from outside. Excluded from the score

How the score is calculated

The overall score is out of 100, built from the eleven area scores. Three rules govern it and all three are printed in every report.

Unconfirmed items are excluded, not penalised. An assessment carried out from outside cannot see a good reason that has not been published. A business with a legitimate explanation it has never put on its website looks, from outside, identical to a business with something to conceal. Scoring the second as though it were the first would make the number dishonest. Every unconfirmed item is listed in the report’s closing table, with the question that would settle it and who in the business is likely to hold the answer.

The score is allowed to fall. A later assessment may score lower than an earlier one, because more evidence was supplied and more could be checked. A scheme whose scores only ever rise is not measuring anything.

The area headings are published; the individual checks are not. The eleven areas above are the whole of what is disclosed. The specific tests inside each area are not published, because an assessment whose checklist is public measures preparation for the checklist rather than the thing itself.

Bands

The four score bands and the score range each one covers
BandScore
Strong80–100
Workable65–79
Weak45–64
Exposed0–44

What this scheme will not do

It does not sell remediation. Digital Trust Audit does not fix what it finds, does not recommend a supplier to fix it, and takes no commission from any firm that does. Where a business is introduced by a partner agency that also carries out remediation, the assessment is run and scored before any remediation relationship exists, and nobody with an interest in that work touches the score.

It does not issue a work plan. The report states the finding and the criterion — this is what we found, this is what the standard requires. It does not state what to buy, in what order, from whom, or at what cost. Publishing the requirement and selling nobody the implementation is the ordinary posture of a standards body, and it removes the incentive to find more.

The free check is not tuned to alarm. The automated website health check must be capable of returning nothing significant found, and it must sometimes do so. An automated check whose commercial purpose is to worry a business into paying is the oldest trick in this market, and this scheme is held to the opposite by this sentence.

It does not assess a business it has a hand in. No assessor may assess a business whose website, mail or infrastructure they built or maintain. Where the issuer has any connection to the assessed business, or to the supplier who built or maintains what is being assessed, the connection is stated on the report and on the verification page. There is no discretion about what counts as material.

Foreign incorporation is not a failure. Undisclosed incorporation is.

A business incorporated outside the United Kingdom passes this standard provided the site names the actual legal entity, its number and its jurisdiction, that this is consistent with what the site implies about where the business operates, and that the register it points to is publicly checkable.

What fails is a mismatch: a site that implies one jurisdiction while the entity sits in another, or that names no entity at all. The criterion is disclosure, not geography — and it has to be, because this scheme is itself owned from Hong Kong and would otherwise fail its own test.

How AI visibility readings are taken

Readings are taken with personalisation disabled and no account history in play, on each platform’s standard consumer product, from a UK location, on a single stated date.

Google’s AI Overview and AI Mode and Microsoft Copilot are read signed out. ChatGPT and Gemini are read in temporary chats with personalisation switched off, because signed-out access on those platforms returns a reduced model rather than a neutral one. Claude requires an account and is read in a fresh conversation with no prior context. Every capture is run from one dedicated capture identity used for nothing else, so that readings taken months apart are comparable.

Every question is run twice on the same day, because answers move between consecutive runs and a single reading is not evidence. Results are directional: AI answers vary by location, account, prompt, browsing mode and time, and no assessment guarantees placement.

The question themes are published in the report. The standard’s own question set is not published, for the same reason the individual checks are not.

Accreditation, and how it is lost

Accreditation is earned from an assessment under this standard, expires twelve months from the date of the assessment, and is withdrawn or stepped down when a later assessment shows the level is no longer met. Withdrawals appear on the register. A register that only ever grows is a rubber stamp.

The levels, the hard floor and the mechanics are on the accreditation page.

Disputing a finding

Any business assessed under this standard may dispute a finding or a withdrawn accreditation. The route, the timescales and the outcomes are published on the complaints and appeals page.

Insurance

This scheme does not require an accredited business to hold any particular insurance, and does not check insurance. It is stated here because knowing what a scheme does and does not require is the point, and a scheme silent on the question is harder to judge than one that answers it.

What this scheme is not

Digital Trust Audit is a private certification scheme. It is not a statutory scheme, it carries no government endorsement, and it is not connected to UK CertifID or the UK digital identity and attributes trust framework.

It does not assess trading conduct. A business that trades fairly and a business that does not will score identically under this standard if their websites, domains and records read the same from outside. Assessments of trading conduct are made elsewhere. The body behind this standard is described on the about page.

The standard is the product.

Read it, check it against what we publish, then ask for an assessment.

Request an audit