| Legal entity | Current | The Hwb Collective CIC, company number 16467677. | Verify Companies House details during due diligence. |
| Governance manual | Current | Version 1 approved unanimously by the board on 14 February 2026; review scheduled for February 2027. | Record any amendment through the board process. |
| Safeguarding roles | Current | Grant Parry is Safeguarding Lead; Claudia Niamh Evan-Jones is Deputy; dedicated mailbox in place. | Confirm delivery-specific escalation and partner responsibilities. |
| Data Protection Lead | Current | Grant Parry is named Data Protection Lead under the approved manual. | Maintain request, breach and processing records. |
| Website privacy information | Published; service checks in progress | Published notices distinguish service communication from optional updates, and the website uses email routes instead of unconnected forms. | Complete the CV Builder data-flow, retention and supplier-role verification before organised institutional rollout. |
| CV Builder DPIA | In progress | A structured assessment process has been prepared but is not presented as complete. | Complete, approve and review before organised school or council rollout. |
| Processing record | In progress | Processing, lawful-basis, supplier and retention records are being verified against the real service. | Complete and maintain the records from verified system information. |
| Accessibility | In progress | Keyboard structure, scalable text, colour themes and reduced-motion support are built into the website. | Complete automated and manual WCAG 2.2 AA testing and publish verified results. |
| Cyber Essentials | Not certified | No certification is claimed. Readiness work covers devices, accounts, cloud services and the scheme's core control areas. | Complete the readiness review, remediate gaps and decide when to certify. |
| Independent security testing | Not completed | No penetration-test or independent security-audit claim is made. | Commission proportionate testing before higher-risk scale-up. |
| Insurance and DBS evidence | Verify before delivery | No blanket public claim is made. Currency, scope and suitability requirements depend on the activity and roles. | Verify and supply relevant evidence through a controlled due-diligence route. |
| Risk and health and safety | Delivery-specific | The governance framework assigns health-and-safety implementation responsibility. Each practical activity still requires proportionate risk controls. | Approve venue, equipment, supervision and emergency arrangements before delivery. |
| Complaints | Published route; procedure review in progress | A dedicated complaints address and conflict-aware escalation principle exist. | Approve and record acknowledgement, response and review times. |
| Business continuity | Not publicly evidenced | No completed continuity-plan claim is made on this website. | Document essential services, backups, recovery, communications and responsible roles. |
| Welsh-language provision | Developing | A complete bilingual service is not currently claimed. | Agree language requirements and resource status for each partnership. |