Data quality in compliance: a guide for regulated transport teams

A compliance-grade data quality programme must combine continuous automated validation, clear data ownership, and immutable audit evidence to be defensible to regulators. Without all three, even well-intentioned teams produce records that fail at inspection.

Three steps to begin today:

  • Assign a named data owner to each feed or register your organisation submits to a regulator, with a documented escalation contact.
  • Run a schema validation check against your current SIRI-VM or TransXChange feeds and record the baseline pass rate before making any changes.
  • Confirm your case management process produces a timestamped, exportable audit trail for every compliance decision. A platform such as Velocerta automates this across DVLA and DVSA-connected checks.

Key takeaways

Effective data quality in compliance requires continuous automated validation, named data ownership, and immutable audit evidence working together. No single control is sufficient without the other two.

Point Details
Assign ownership first Name a data owner and escalation contact for every feed before running any other improvement.
Validate continuously BODS samples 250 packets per day; feeds below 70% field completeness are non-compliant on a seven-day rolling average.
Human review before enforcement Requiring a named reviewer to confirm every finding before action produces a defensible record and reduces enforcement risk.
Retain evidence structurally Store feed logs for 12 months, incident records for three years, and register decisions for the licence period plus two years.
Velocerta for continuous monitoring Velocerta automates DVLA/DVSA checks, human-reviewed alerts, and structured audit trails for regulated transport organisations.

Table of Contents

What does data quality in compliance actually require?

Good compliance data rests on five principles: ownership, provenance, validation, accountability, and auditability. Each one is necessary; none is sufficient alone. Ownership means a named individual or role is responsible for each data source. Provenance means the origin and transformation history of every record is traceable. Validation means automated checks run continuously, not just at submission. Accountability means decisions are logged against named users. Auditability means evidence can be exported in an immutable form that a regulator can inspect without your assistance.

The UKSA Quality Assurance Toolkit, which the Department for Transport applied to DVSA administrative data, uses a risk-versus-public-interest matrix to set the appropriate assurance level for each data source.

Data risk Public interest Assurance level
Low Low Basic
Low High Enhanced
High High Comprehensive

Pro Tip: Assign data ownership at the point of system configuration, not after an audit finding. When the physical fleet state and the recorded compliance data diverge, the most common cause is that no single person owned both. Inconsistent standards and absent ownership are a leading root cause of audit failure across transport organisations.

Which standards and profiles must transport teams enforce?

The DfT transport data strategy commits to promoting open standards and improving interoperability to reduce integration and cleaning costs. For transport teams, that commitment translates into three mandatory standards to check first.

TransXChange PTI profile. The Bus Open Data Service (BODS) mandates TransXChange 2.4 with the PTI profile for all timetable data. Feeds that do not conform to this profile are flagged as non-compliant in the BODS catalogue.

SIRI-VM. Vehicle location feeds submitted to BODS must conform to the SIRI-VM schema. Mandatory fields include vehicle reference, line reference, direction, and timestamped location. Missing or malformed values in these fields directly affect your compliance score.

Metadata standards. Every feed should carry machine-readable metadata describing its coverage period, geographic scope, operator, and known limitations. The DfT Data Action Plan explicitly recommends transparent quality assessments and user feedback loops, which metadata enables.

Mandatory field checks to run on every submission:

  • Vehicle reference present and matched to a licensed vehicle record
  • Operator National Operator Code (NOC) valid and active
  • Timestamp within an acceptable offset from real time (typically under 60 seconds)
  • Line reference matched to a published timetable in the same BODS dataset
  • Bounding coordinates within the declared service area

PTI profile documentation and validator rules are available directly from the BODS guidance pages.

How to validate data automatically and the KPIs that prove compliance

BODS runs a two-part automated validator on SIRI-VM feeds: a schema check first, then a mandatory field population check. It samples 250 packets per day and calculates compliance using a seven-day rolling average.

Separating schema validation from business-rule validation matters operationally. Schema errors are fast to detect and fix; field population rates require monitoring over time. Sampling strategies must be documented so that an auditor can reproduce the same checks independently.

Telematics logging strategy also affects these metrics. Curve-based logging reduces redundant data points while preserving critical events, improving the reliability of location and driving-behaviour records that feed into compliance KPIs.

Example calculation. Over seven days, your SIRI-VM feed produces 1,750 sampled packets (250 per day). Of these, 1,330 contain all mandatory fields. Field completeness = 1,330 / 1,750 = 76%. Status: compliant. If the count dropped to 770, completeness = 44%, triggering immediate non-compliance.

From basic to comprehensive assurance: what to do at each level

The UKSA Quality Assurance Toolkit defines three assurance levels. Each requires progressively more rigorous controls, and the risk-versus-public-interest matrix from Section 2 determines which level applies to each of your data sources.

Basic assurance

  1. Document the data source, its owner, and its update frequency.
  2. Run automated schema validation on every submission.
  3. Record validation outcomes and store them for a minimum of 12 months.
  4. Review error logs monthly and assign remediation tasks to the named data owner.

Enhanced assurance

  1. Complete all basic controls.
  2. Add a seven-day rolling compliance score tracked against the 70% threshold.
  3. Introduce a peer review step: a second named reviewer signs off any data correction before resubmission.
  4. Conduct a quarterly internal audit comparing physical fleet records to registered data.
  5. Document all known data limitations in metadata and share them with downstream users.

Comprehensive assurance

  1. Complete all enhanced controls.
  2. Commission an independent review of validation logic and sampling methodology annually.
  3. Maintain an immutable audit log of every data change, reviewer action, and enforcement decision.
  4. Produce a formal quality report for each regulatory submission period.
  5. Trigger a full assurance review whenever a new data source, feed format, or legislative requirement is introduced.

Escalation triggers. Move a source from basic to enhanced when it feeds a public-facing service or a national register. Move from enhanced to comprehensive when enforcement actions are possible, when the source is cited in regulatory returns, or when 2025 amendments to ERRU and CTUD exchange requirements add new mandatory data fields to your register.

Practical workflows: detection, human review, remediation and evidence retention

Automated detection is the starting point, not the endpoint. The workflow below covers the full cycle from alert to case closure.

Stage Action Owner Evidence to retain
Detection Validator flags schema error or field drop System Validator log with timestamp
Alert Notification sent to data owner and escalation contact System Alert record with recipient and time
Human review Reviewer assesses root cause; decides remediation or dispute Named reviewer Review note, decision, reviewer ID
Remediation Feed corrected and resubmitted; or formal exception raised Data owner Corrected submission, exception record
Case closure Case closed with outcome recorded; evidence package assembled Compliance lead Closed case record, evidence export

Human review before enforcement is the control that reduces enforcement risk most directly. Automatic enforcement without review creates liability when the underlying data error was caused by a system fault rather than an operator failure. Requiring a named reviewer to confirm the finding before any enforcement action is taken produces a defensible record and catches false positives.

For evidence retention and chain of custody, store short-term feed logs for a minimum of 12 months, incident records for three years, and register-level compliance decisions for the full licence period plus two years.

Preparing regulator-ready reports and evidence packages

Regulators typically request the following when reviewing transport compliance data:

  • A list of all data sources submitted during the review period, with named owners and submission dates
  • Validation reports showing compliance scores and any threshold breaches
  • Incident records for every non-compliant period, including root cause and remediation action
  • Evidence that human review occurred before any enforcement decision
  • Metadata describing known data limitations and the period they applied

Retention guidance aligned with current practice: feed-level logs, 12 months minimum; incident and case records, three years; register entries and enforcement decisions, licence period plus two years. The 2025 Road Transport Regulations introduce additional mandatory fields for ERRU-connected national registers, so review your register dataset against the updated minimum data elements before your next submission.

The DfT Data Action Plan recommends machine-readable sharing and transparent quality assessments. Producing exports in structured formats (JSON or XML with schema references) rather than PDF summaries makes your evidence reusable and auditor-friendly.

Pro Tip: Generate an immutable, timestamped export of your compliance dataset at the close of each reporting period and store it separately from your live system. A signed snapshot that cannot be altered after the fact is the strongest single piece of evidence you can present at a regulatory inspection. Guidance on compliance document management covers the practical steps for structured evidence retention.

Operational checklist for the next 30, 90 and 180 days

Days 1–30

  • Assign a named data owner and escalation contact to every feed and register entry (owner: compliance lead).
  • Run baseline schema validation on all SIRI-VM and TransXChange submissions; record pass rates (owner: data owner).
  • Confirm your case management process produces a timestamped, exportable audit trail (owner: IT or platform administrator).

Days 31–90

  • Implement seven-day rolling compliance scoring against the 70% field completeness threshold (owner: data owner).
  • Conduct a gap analysis against the UKSA assurance level appropriate to each data source (owner: compliance lead).
  • Review retention policies and confirm evidence storage meets the minimum periods above (owner: compliance lead).
  • Begin quarterly internal audits comparing physical fleet records to registered data (owner: fleet manager).

Days 91–180

  • Commission an independent review of validation logic for any source at comprehensive assurance level (owner: compliance lead).
  • Produce a formal quality report for the most recent regulatory submission period (owner: compliance lead).
  • Review your dataset against the 2025 ERRU/CTUD minimum data element changes and update fields accordingly (owner: data owner).
  • Introduce regulatory change management procedures so future legislative updates trigger a structured review of affected data sources.

Pro Tip: Prioritise quick wins that directly reduce enforcement risk: assign data owners, fix schema errors, and confirm human review gates are in place before any other improvement work. These three controls are the ones regulators look for first.

A practitioner’s perspective on what actually matters

The gap between a technically valid feed and a defensible compliance record is wider than most teams expect. Passing a schema check is not the same as demonstrating that your data accurately reflects the physical state of your fleet. The teams that perform best at inspection are those that treat data quality as an operational discipline, not a submission task. One common pitfall: a team corrects a non-compliant feed, resubmits, and closes the ticket, but never records why the error occurred or who approved the correction. Six months later, the same error recurs and there is no evidence that the previous incident was ever properly resolved. The remedy is straightforward: close every case with a root cause note and a named reviewer, and store that record alongside the corrected submission.

How Velocerta supports continuous compliance

Velocerta maps directly to the controls described throughout this article. Its continuous monitoring integrates with DVLA and DVSA to check vehicle identity, tax, and MOT status without manual intervention. Every alert passes through a human review step before any enforcement action is triggered, producing the defensible record that regulators expect.

Audit trails are version-controlled and exportable in structured formats, supporting the immutable evidence packages described in the reporting section. Case management workflows record root cause, reviewer identity, and remediation outcome against every incident. Configurable validation rules and notification routing mean compliance leads can set thresholds appropriate to their assurance level and receive escalations through the right channels. For fleet operators and taxi and private-hire organisations, the platform provides role-based access so data ownership is enforced at the system level, not just on paper.

To see how Velocerta fits your organisation’s compliance workflow, request a demonstration.

Sources

The following authoritative sources are referenced throughout this article and contain the validator thresholds, schema profiles, toolkit matrices, and legislative requirements described above.

This article is general information, not a substitute for advice from a qualified lawyer. Consult a qualified legal professional about your own circumstances before acting on anything here.

Recommended