Mercur Business Control
Mercur Business Control is a public sector xP&A and FP&A solution integrating data from any source. It streamlines budget setting, rigorous monitoring, forecasting, and analysis. By automating workflows and providing real-time insights, Mercur empowers finance functions to exercise control and enables better-informed decision-making through accurate, consolidated data.
Features
- Comprehensive xP&A solution for budgeting, forecasting, reporting, and analysis
- Rigorous public sector budget setting and continuous financial monitoring
- Integrates data from any source for informed decision-making
- Automated workflows streamline distributed input and approval processes
- Advanced scenario planning with driver-based modelling and payroll forecasting
- Interactive, BI & real-time dashboards with drill-down to transaction details
- Self-service analysis empowering budget holders and non-finance users
- Flexible dimensionality for complex cost centre and project reporting
- Standardised API connectors for seamless ERP and HR integration
- Unlimited data sources captures data at transaction level
Benefits
- Enable informed decision-making with consolidated, real-time data insights
- utomate budget setting to eliminate manual spreadsheet errors and delays
- Monitor budgets rigorously with automated variance analysis and alerts
- Integrate any data source for a single version of truth
- Empower budget holders to manage finances via intuitive self-service tools
- Rapidly re-forecast and model scenarios to adapt to changing needs
- Create and distribute comprehensive reports instantly without manual consolidation
- Free finance teams to focus on value-added analysis, not processing
- ccess critical financial data securely from any location or device
- nsure compliance with full audit trails for all data changes
Pricing
- Education pricing available
- Free trial available
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
1 5 8 6 2 0 7 6 7 7 4 1 2 8 8
Contact
MERCUR SOLUTIONS (UK) LIMITED
Derek Morrison
Telephone: 07388906833
Email: derek.morrison@mercur.com
About your service
- Service categories
-
Applications
Enterprise resource management
- Enterprise performance management
Financial
- Financial and Accounting Applications
- Multi cloud support
- Yes
Service scope
- Software add-on or extension
- Yes, but can also be used as a standalone service
- What software services is the service an extension to
- Mercur can be configured as an extensiuon to any ERP, General ledger or data source. Examples would include, Unit4, SAP, Oracle, Integra, Workday. The solution has no limitations in terms of leveraging Ledger Financial or Non Financial Data
- Cloud deployment model
-
- Public cloud
- Private cloud
- Hybrid cloud
- Service constraints
- There are no known constraints that we are aware of that would 'frustrate' or 'limit' the use or delivery of Mercur
- System requirements
- Any Modern Browser i.e. Microsoft Edge, Safari, Chrome,
User support
- Email or online ticketing support
- Yes
- Support response times
-
Priority Primary response Forecast Resolution Time Target Resolution time
1 1 working hour Within 3 working hours 6 working hours
2 4 working hours Within 8 working hours 16 working hours
3 8 working hours Within 5 working days 10 working days
4 TBA TBA TBA
Weekend support by arrangement - User can manage status and priority of support tickets
- Yes
- Online ticketing support accessibility
- None or don’t know
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- Yes
- Web chat support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support accessibility standard
- None or don’t know
- How the web chat support is accessible
- Via our website we have chat enabled. Though ticketing can only be provided through phone and email
- Web chat accessibility testing
- The development team continue to work in all areas including assistive technology users
- Onsite support
- Yes, at extra cost
- Support levels
-
Mercur Business Control provides four support levels based on error severity, with strict SLAs for issues reported via telephone, email, or online.
Critical (Priority 1): Fatal errors preventing system use.
Response: 1 working hour.
Target Resolution: 6 working hours.
Major (Priority 2): Errors significantly inhibiting system effectiveness but not preventing use.
Response: 4 working hours.
Target Resolution: 16 working hours.
Minor (Priority 3): Less serious errors that do not inhibit effective use.
Response: 8 working hours.
Target Resolution: 10 working days.
Trivial (Priority 4): Cosmetic issues (e.g., labels, help text) with little impact.
Resolution: Handled as time permits or as agreed.
Roles and Costs
Standard Support covers all the levels above and is included in the service price.
For specialized needs, Mercur does not use generic cloud support engineers. Instead, we provide Integration Support and Named Consultants. These experts know your specific configuration and can be called upon for technical account management and complex problem-solving. - Support available to third parties
- Yes
- AI chatbot
- No
Onboarding and offboarding
- Getting started
-
At Mercur, we understand that software value is only realized through successful user adoption. Therefore, our "Getting Started" methodology is designed to ensure a seamless transition from the Proof of Concept phase to full-scale production. We provide a comprehensive, supportive onboarding experience tailored to your organization’s specific configuration.
Training & Empowerment We offer a flexible, blended training approach to suit different learning styles and geographical needs:
Onsite Training: We provide intensive, hands-on workshops at your location. These are ideal for administrators and super-users who require deep technical proficiency and understanding of the system's architecture.
Online Training: For distributed teams or broader user groups, we conduct live, interactive web sessions. These ensure consistent knowledge transfer and minimize business disruption.
Documentation & Resources To support continuous, self-paced learning, all users gain access to our extensive Knowledge Base. This includes detailed user documentation, searchable help files, and step-by-step video tutorials that guide users through common workflows and best practices.
Commitment to Success Our goal is client self-sufficiency. By combining direct expert coaching with robust documentation, we ensure your team is confident and capable from day one, maximizing the return on your investment. - Service documentation
- Yes
- Documentation formats
-
- HTML
- ODF
- End-of-contract data extraction
-
Mercur adheres to strict principles of data sovereignty; our clients retain full ownership of their data throughout the engagement and upon contract termination. We ensure the exit process is transparent, secure, and free of vendor lock-in.
Self-Service Extraction Throughout the contract term and during the offboarding phase, authorized users can utilize built-in system tools to export data independently. All reports, input forms, and master data tables can be exported directly into universal formats—such as Microsoft Excel (.xlsx), CSV, and PDF—without requiring technical intervention.
Comprehensive Database Archive For a complete audit trail and archival purposes, Mercur facilitates a bulk data extraction. We can provide a structured export of the underlying database (e.g., SQL dump or flat files), comprising all historical records, transaction logs, metadata, and audit trails. This ensures the organization possesses a complete, machine-readable copy of their environment for migration to a new system.
Retention and Deletion Upon contract expiration, a "Grace Period" (typically 30 days) is activated to allow for final data retrieval. Once the client confirms receipt of their data, Mercur securely purges all records from our servers in compliance with GDPR and ISO security standards. - End-of-contract process
-
Mercur executes a transparent, secure decommissioning process upon contract termination, designed to ensure you retain full control over your data without penalty.
The Transition Process Upon the contract end date, your environment enters a defined Grace Period (typically 30 days). During this window, the system remains accessible to administrators in a "Read-Only" state. This ensures sufficient time for your team to perform final data extractions and audit checks. Once you confirm successful retrieval, or the grace period expires, Mercur performs a permanent, secure deletion of all active data and backups in strict accordance with GDPR and ISO 27001 standards.
Commercial Terms Mercur adheres to a "No Vendor Lock-in" policy.
Included: All costs associated with data extraction are fully covered by your SaaS subscription. We do not charge exit fees. You are free to export your complete database and reports using our built-in tools at no additional cost.
Additional Costs: Extra charges apply only if you request Mercur Professional Services for bespoke transition support—such as complex data mapping or custom migration consultancy—outside the scope of the standard self-service export tools. - Documentation accessibility standard
- None or don’t know
- How the documentation is accessible
-
Mercur ensures that all documentation regarding the customer lifecycle—from initial implementation to contract conclusion—is transparent, secure, and easily accessible.
Onboarding Documentation Upon project initiation, authorized stakeholders gain access to a dedicated Secure Client Portal. This repository serves as the single source of truth, hosting critical governance documents including the Statement of Work (SOW), Implementation Plan, and technical integration guides. This ensures your team has immediate visibility into the deployment roadmap and technical requirements from day one.
Offboarding & Data Portability We recognize the importance of data sovereignty and reject vendor lock-in. Detailed offboarding documentation is available throughout the contract term, outlining clear protocols for:
Data Export: Step-by-step guides on extracting all proprietary data in standard, open formats (e.g., CSV, SQL).
Service Termination: Clear definitions of the "End of Service" timeline and handover procedures.
Data Destruction: Compliance documentation detailing how and when data is permanently purged from our servers to meet GDPR and security standards.
All documentation is searchable, version-controlled, and available for download (PDF) to ensure you maintain a complete audit trail of the partnership at all times.
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Opera
- Application to install
- No
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
-
There are no functional differences between the desktop and mobile services. The mobile service offers the following characteristics:
Browser-Based Access: Users access the full system via any modern web browser on their mobile or tablet device, with no need to install a separate application.
Touch-Enabled Interface: The application interface adapts to provide a touch-enabled experience suitable for mobile and tablet use.
Full Functionality: Users have access to the same features as the desktop version, including accessing all reports and data entry workflows. - Service interface
- No
- User support accessibility
- None or don’t know
- API
- Yes
- What users can and can't do using the API
-
Set up the service
Automated Data Management (ETL): Users can configure API connections to manage the "Extract, Transform, Load" (ETL) process, ensuring seamless data movement from external sources (such as ERPs, HR systems, or Data Warehouses) into Mercur Business Control.
Scheduled Data Synchronization: Users can set up automated jobs to trigger data imports, allowing for the periodic movement of large datasets (actuals, dimensions, and hierarchies) without manual intervention.
User Provisioning (SCIM): Users can utilize the SCIM API to automate identity management, setting up user accounts and access rights directly from their central Identity Provider (e.g., Azure AD).
Make changes
API Extraction from Mercur: Users can utilize the API and ODBC/JDBC interfaces to extract calculated data, budgets, and forecasts out of Mercur for use in third-party systems, BI tools (like Power BI), or data lakes.
Dynamic Data Updates: The API allows for the dynamic updating of dimension members (e.g., adding a new cost centre or project) and hierarchy structures to ensure the planning model matches the source system in real-time. - API documentation
- Yes
- API documentation formats
-
- HTML
- ODF
- API sandbox or test environment
- Yes
- Customisation available
- Yes
- Description of customisation
-
What can be customised Users can fully customise the application to match their specific organisational requirements. This includes the underlying data model (dimensions, hierarchies, and attributes) and business logic. Users can also design and tailor their own content, creating bespoke financial reports, interactive dashboards, and budget input forms. Additionally, workflow processes and approval chains can be configured to align with internal governance structures.
How users can customise All customisation is performed directly via the standard web interface using intuitive, no-code tools. Users utilise drag-and-drop functionality to build reports or input screens and use simple configuration menus to manage the data model. This ensures that changes can be made quickly without the need for technical coding, scripting, or database expertise.
Who can customise Mercur Business Control is designed to be owned and managed by the Finance function. Administrators and authorised Power Users have full autonomy to configure the system. They can independently manage the data model, create new reports, and update dashboards as business needs evolve. This ensures self-sufficiency and agility, eliminating the need to rely on IT specialists or external consultants for routine changes.
Scaling
- Independence of resources
-
Mercur Business Control ensures performance independence primarily through Multiversion Concurrency Control (MVCC) within its proprietary Veloxic database. This technology guarantees that users reading reports never have to wait for users entering data, effectively eliminating read/write queues.
To manage high demand, the system processes updates asynchronously: user inputs are quickly queued as "diffs" and integrated into the database in the background, ensuring low latency. The system also adapts to load spikes by integrating data "loosely" to maintain throughput. Additionally, distributing calculations to clients reduces central server strain
Analytics
- Service usage metrics
- Yes
- Metrics types
-
The system includes logging and statistical tools to monitor user activity and system events:
Usage Statistics: A dedicated statistics database allows administrators to analyze system usage, such as tracking which reports are opened by specific users. - Reporting types
-
- Real-time dashboards
- Regular reports
- Reports on request
- Resource tagging
- Yes
- FOCUS resource tagging
- Yes
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Other security clearance
- Government security clearance
- Developed Vetting (DV)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
-
- United Kingdom
- European Economic Area (EEA)
- User control over data storage and processing locations
- Yes
- Datacentre security standards
- Complies with a recognised standard (for example CSA CCM version 4.0)
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- ‘IT Health Check’ performed by a CHECK service provider
- Protecting data at rest
-
- Physical access control, complying with CSA CCM v4.0
- Physical access control, complying with SSAE-18 / ISAE 3402
- Encryption of all physical media
- Data sanitisation process
- Yes
- Equipment disposal approach
- Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
- Data sanitisation type
-
- Deleted data can’t be directly accessed / Cryptographic Erasure
- Data Erasure
- Explicit overwriting of storage before reallocation / Secure Erase
Data importing and exporting
- Data export approach
-
Mercur empowers users with flexible export capabilities designed for both daily analysis and technical requirements.
Business Users: Can instantly export any report, input form, or dashboard directly to Microsoft Excel (.xlsx), PDF, or CSV. Uniquely, Excel exports retain formatting and formulas, allowing for immediate offline analysis.
Technical Administration: For comprehensive data retrieval, administrators can perform bulk extractions of master data and transaction logs using standard flat-file formats. Additionally, our REST API allows for programmatic, automated data retrieval in JSON or XML, facilitating seamless integration with third-party BI tools or data warehouses. - Data export formats
-
- CSV
- Other
- Other data export formats
-
- JDBC and ODBC drivers authorized
- RESTful web service API
- Reports can be exported to PDF, text files
- Image files
- Thirdparty tools read data directly from database using SQL
- MS Office formats; Excel, PowerPoint, Word
- Data import formats
- CSV
Data-in-transit protection
- Data protection between buyer and supplier networks
-
- TLS (version 1.2 or above)
- Other
- Other protection between networks
-
AES Encryption: All session traffic is encrypted using AES (128, 192, or 256-bit).
RSA Key Exchange: The session keys are secured using RSA (recommended 2048-bit).
Protection: This custom handshake protects against "spoofing" and "man-in-the-middle" attacks. - Data protection within supplier network
-
- TLS (version 1.2 or above)
- IPsec or TLS VPN gateway
Availability and resilience
- Guaranteed availability
-
Mercur shall ensure that the Services shall have an overall availability of no less than 99.5% in each calendar month (the “Availability Percentage”), this can be viewed at https://status.mercur.com. Where Mercur fails to meet the Availability Percentage for a month, it shall provide the Customer with service credits in accordance with the following table.
Availability Percentage Service Credit
99.5% + No credit
99% 5%
98.5% 7.5%
98% 10%
97.5% 20%
97% or less 25% - Approach to resilience
- The service utilizes a 'Hotcopy' mechanism for 24/7 availability, ensuring backups do not interrupt operations. Data resilience is guaranteed via 'Recovery Points' and sequential transaction logging, allowing the system to replay inputs and recover data to the point of failure. The architecture uses adaptive load handling to maintain stability during demand spikes. Datacentre hosting provides physical resilience compliant with ISO 27001 and SSAE-18 standards.
- Outage reporting
-
Yes, the service has a public dashboard, email alerts, and feed capabilities.
Public Dashboard: You can view the real-time status of the cloud service, including availability percentages, updates, incidents, and maintenance, at https://status.mercur.com.
Email Alerts: Yes, users can subscribe via the status website to receive automatic email alerts regarding service incidents and updates.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Identity federation with existing provider (for example Google Apps)
- Username or password
- Access restrictions in management interfaces and support channels
-
Mercur restricts access to management interfaces and support channels based on the principle of least privilege. Permissions are defined by job function using Role-Based Access Controls (RBAC) and must be formally approved via our Jira ticketing system.
We secure access with strong password policies and mandatory Two-Factor Authentication (2FA) for critical systems. Support staff are restricted to specific client environments only when required.
To ensure compliance, all access is continuously monitored and logged , and user accounts undergo periodic reviews to revoke unnecessary privileges immediately. - Access restriction testing frequency
- At least once a year
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Username or password
Audit information for users
- Access to user activity audit information
- Users have access to real-time audit information
- How long user audit data is stored for
- At least 12 months
- Access to supplier activity audit information
- Users have access to real-time audit information
- How long supplier audit data is stored for
- User-defined
- How long system logs are stored for
- User-defined
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
- Other
- Other security governance standards
- The company holds Cyber Essentials Plus certification. Our datacentre maintains independent ISO/IEC 27001, SSAE 18 / ISAE 3402 (SOC 1 & 2), and CSA STAR certifications. While the company itself is not ISO 27001 certified, it aligns its internal governance policies with ISO 27001 principles
- Information security policies and processes
-
Mercur Solutions maintains a comprehensive Information Security Management System (ISMS) to safeguard customer data, anchored by an IT Security Policy that requires regular risk assessments and adherence to the principle of "least privilege".
Key operational policies include:
User Access: Access is granted strictly by job function, authorized via the ticketing system, and fully logged for audit purposes.
Data Protection: Mandates encryption for critical systems, regular vulnerability assessments, and secure data disposal methods like crypto-shredding.
Incident Response & Resilience: Incidents are categorized by severity, with "High" impact events triggering the Enterprise Incident Management Team (EIMT). Business continuity is ensured through daily backups and annual full-scale disaster recovery drills.
Reporting & Compliance Security governance is centralized under the Chief Information Security Officer (CISO), who oversees strategy and incident response. Compliance is ensured through mandatory annual privacy and security training for all staff , continuous automated monitoring of user activity , and annual policy reviews by the IT team. Violations result in disciplinary action, ensuring strict policy enforcement. - Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
-
Mercur Business Control tracks service components using a layered architecture that strictly separates the core "System Layer" from the "Customer Adaptation Layer". This ensures that core updates do not disrupt customer-specific configurations. All configuration changes are recorded in a central, searchable event log, creating a full audit trail of system modifications.
Changes are assessed for security impact through the company’s Information Security Management System (ISMS). The IT Security Policy mandates regular risk assessments to evaluate potential threats , while strict Functional Access rights limit configuration capabilities to authorized administrators - Vulnerability management type
- Supplier-defined controls
- Vulnerability management approach
-
Mercur Solutions manages vulnerabilities through a rigorous Information Security Management System (ISMS). We assess potential threats using regular risk assessments , penetration testing, and vulnerability scans.
Information on threats is gathered via continuous system monitoring, log analysis , and third-party provider due diligence.
Remediation is prioritized based on severity. Critical patches are deployed immediately to the server environment, while client applications automatically detect and download updates upon startup. Unpatched vulnerabilities are classified as security incidents, triggering immediate response protocols led by the CISO. - Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
-
Mercur Solutions identifies potential compromises through continuous monitoring of centralized event logs and user access records, compliant with Cyber Essentials Plus standards. Anomalies, such as unauthorized access or malware, trigger our formal Incident Response Policy.
Upon detection, the CISO appoints an Incident Manager to coordinate containment and evidence preservation. For severe breaches, the Enterprise Incident Management Team is activated. Response times are strictly defined by severity: "High" impact incidents require an immediate response, "Medium" incidents within 4 hours, and "Low" severity issues by the next business day. - Incident management type
- Supplier-defined controls
- Incident management approach
-
Mercur Solutions follows a formal IT Security Incident Response Policy, classifying incidents by severity (Low, Medium, High) with strict response SLAs ranging from immediate action to next-business-day resolution. We maintain pre-defined protocols for common threats like malware, unauthorized access, and DDoS attacks.
Reporting Users must report suspected incidents immediately to the IT Operations Team via cybersecurity@mercur.com.
Incident Reports The Incident Manager maintains detailed logs of all actions. Formal incident reports are mandatory for high-severity events. For critical breaches, the Enterprise Incident Management Team oversees external notifications to affected customers and regulators. - Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Supplier-defined process
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- Yes
- Free trial available
- Yes
- Description of free trial
- Mercur does not offer a permanently free version. Instead, a free trial is available as a "live Proof of Concept". This includes configuring your live data to validate specific business requirements. The trial excludes permanent production access and is limited to the duration of the evaluation engagement.
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 5%
- Between £250,000 and £500,000
- 10%
- Between £500,001 and £1,000,000
- 25%
- Between £1,000,001 and £2,500,000
- 25%
- Between £2,500,001 and £5,000,000
- 25%
- Over £5,000,001
- 25%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- No
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- No
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- 431ff343-c7d0-4149-a40f-dfa83d81297a
- Cyber essentials plus
- Yes
- Please provide your Cyber Essentials Plus Certificate Number
- Bbda97a5-0025-4e12-81db-deb6837d20b5
- Other security certifications
- No
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
- Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
- Plans for an appropriate income replacement policy for staff who are required to spend time away from work to care for a sick dependent or close relative
- Understanding of in-work progression issues affecting the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors
- Measures to support in-work progression to help people in the contract workforce, to move into higher paid work by developing new skills relevant to the contract
- Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
- Volunteering opportunities for staff
- Understanding of the modern slavery risks and issues affecting the market, industry, sector or country (of origin or of source) relevant to the contract, and the workforce in the supplier’s own organisation and those of its key subcontractors
- Measures to identify, mitigate and manage modern slavery risks relating to the contract and how these will be implemented
- Outline policies and practices to be applied to or put in place for the contract to mitigate and manage modern slavery risks, including: Pre-employment checks, recruitment practices. Workplace conditions, safeguarding plans and processes in place and regular monitoring with relevant groups considered, which may include sampling
- How these flow down the supply chain and are monitored Illustrative examples include reporting, site visits, audits, etc.
- How to ensure business decisions re: price/cost, short lead times, payment timescales do not create modern slavery risks in the supply chain
- How the supplier will work with NGOs, trade unions or other businesses to address modern slavery risk
- Means of influencing staff, suppliers, customers, communities and/or any other appropriate stakeholders with respect to modern slavery risks relating to the contract
-