Skip to main content

Help us improve the Digital Marketplace - send your feedback

MERCUR SOLUTIONS (UK) LIMITED

Mercur Business Control

Mercur Business Control is a public sector xP&A and FP&A solution integrating data from any source. It streamlines budget setting, rigorous monitoring, forecasting, and analysis. By automating workflows and providing real-time insights, Mercur empowers finance functions to exercise control and enables better-informed decision-making through accurate, consolidated data.

Features

  • Comprehensive xP&A solution for budgeting, forecasting, reporting, and analysis
  • Rigorous public sector budget setting and continuous financial monitoring
  • Integrates data from any source for informed decision-making
  • Automated workflows streamline distributed input and approval processes
  • Advanced scenario planning with driver-based modelling and payroll forecasting
  • Interactive, BI & real-time dashboards with drill-down to transaction details
  • Self-service analysis empowering budget holders and non-finance users
  • Flexible dimensionality for complex cost centre and project reporting
  • Standardised API connectors for seamless ERP and HR integration
  • Unlimited data sources captures data at transaction level

Benefits

  • Enable informed decision-making with consolidated, real-time data insights
  • utomate budget setting to eliminate manual spreadsheet errors and delays
  • Monitor budgets rigorously with automated variance analysis and alerts
  • Integrate any data source for a single version of truth
  • Empower budget holders to manage finances via intuitive self-service tools
  • Rapidly re-forecast and model scenarios to adapt to changing needs
  • Create and distribute comprehensive reports instantly without manual consolidation
  • Free finance teams to focus on value-added analysis, not processing
  • ccess critical financial data securely from any location or device
  • nsure compliance with full audit trails for all data changes

Pricing

  • Education pricing available
  • Free trial available

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at derek.morrison@mercur.com. Tell them what format you need. It will help if you say what assistive technology you use.

Framework

G-Cloud 15

Service ID

1 5 8 6 2 0 7 6 7 7 4 1 2 8 8

Contact

MERCUR SOLUTIONS (UK) LIMITED Derek Morrison
Telephone: 07388906833
Email: derek.morrison@mercur.com

About your service

Service categories

Applications

Enterprise resource management

  • Enterprise performance management

Financial

  • Financial and Accounting Applications
Multi cloud support
Yes

Service scope

Software add-on or extension
Yes, but can also be used as a standalone service
What software services is the service an extension to
Mercur can be configured as an extensiuon to any ERP, General ledger or data source. Examples would include, Unit4, SAP, Oracle, Integra, Workday. The solution has no limitations in terms of leveraging Ledger Financial or Non Financial Data
Cloud deployment model
  • Public cloud
  • Private cloud
  • Hybrid cloud
Service constraints
There are no known constraints that we are aware of that would 'frustrate' or 'limit' the use or delivery of Mercur
System requirements
Any Modern Browser i.e. Microsoft Edge, Safari, Chrome,

User support

Email or online ticketing support
Yes
Support response times
Priority Primary response Forecast Resolution Time Target Resolution time
1 1 working hour Within 3 working hours 6 working hours
2 4 working hours Within 8 working hours 16 working hours
3 8 working hours Within 5 working days 10 working days
4 TBA TBA TBA

Weekend support by arrangement
User can manage status and priority of support tickets
Yes
Online ticketing support accessibility
None or don’t know
Phone support
Yes
Phone support availability
9 to 5 (UK time), Monday to Friday
Web chat support
Yes
Web chat support availability
9 to 5 (UK time), Monday to Friday
Web chat support accessibility standard
None or don’t know
How the web chat support is accessible
Via our website we have chat enabled. Though ticketing can only be provided through phone and email
Web chat accessibility testing
The development team continue to work in all areas including assistive technology users
Onsite support
Yes, at extra cost
Support levels
Mercur Business Control provides four support levels based on error severity, with strict SLAs for issues reported via telephone, email, or online.

Critical (Priority 1): Fatal errors preventing system use.

Response: 1 working hour.

Target Resolution: 6 working hours.

Major (Priority 2): Errors significantly inhibiting system effectiveness but not preventing use.

Response: 4 working hours.

Target Resolution: 16 working hours.

Minor (Priority 3): Less serious errors that do not inhibit effective use.

Response: 8 working hours.

Target Resolution: 10 working days.

Trivial (Priority 4): Cosmetic issues (e.g., labels, help text) with little impact.

Resolution: Handled as time permits or as agreed.

Roles and Costs
Standard Support covers all the levels above and is included in the service price.

For specialized needs, Mercur does not use generic cloud support engineers. Instead, we provide Integration Support and Named Consultants. These experts know your specific configuration and can be called upon for technical account management and complex problem-solving.
Support available to third parties
Yes
AI chatbot
No

Onboarding and offboarding

Getting started
At Mercur, we understand that software value is only realized through successful user adoption. Therefore, our "Getting Started" methodology is designed to ensure a seamless transition from the Proof of Concept phase to full-scale production. We provide a comprehensive, supportive onboarding experience tailored to your organization’s specific configuration.

Training & Empowerment We offer a flexible, blended training approach to suit different learning styles and geographical needs:

Onsite Training: We provide intensive, hands-on workshops at your location. These are ideal for administrators and super-users who require deep technical proficiency and understanding of the system's architecture.

Online Training: For distributed teams or broader user groups, we conduct live, interactive web sessions. These ensure consistent knowledge transfer and minimize business disruption.

Documentation & Resources To support continuous, self-paced learning, all users gain access to our extensive Knowledge Base. This includes detailed user documentation, searchable help files, and step-by-step video tutorials that guide users through common workflows and best practices.

Commitment to Success Our goal is client self-sufficiency. By combining direct expert coaching with robust documentation, we ensure your team is confident and capable from day one, maximizing the return on your investment.
Service documentation
Yes
Documentation formats
  • HTML
  • ODF
  • PDF
End-of-contract data extraction
Mercur adheres to strict principles of data sovereignty; our clients retain full ownership of their data throughout the engagement and upon contract termination. We ensure the exit process is transparent, secure, and free of vendor lock-in.

Self-Service Extraction Throughout the contract term and during the offboarding phase, authorized users can utilize built-in system tools to export data independently. All reports, input forms, and master data tables can be exported directly into universal formats—such as Microsoft Excel (.xlsx), CSV, and PDF—without requiring technical intervention.

Comprehensive Database Archive For a complete audit trail and archival purposes, Mercur facilitates a bulk data extraction. We can provide a structured export of the underlying database (e.g., SQL dump or flat files), comprising all historical records, transaction logs, metadata, and audit trails. This ensures the organization possesses a complete, machine-readable copy of their environment for migration to a new system.

Retention and Deletion Upon contract expiration, a "Grace Period" (typically 30 days) is activated to allow for final data retrieval. Once the client confirms receipt of their data, Mercur securely purges all records from our servers in compliance with GDPR and ISO security standards.
End-of-contract process
Mercur executes a transparent, secure decommissioning process upon contract termination, designed to ensure you retain full control over your data without penalty.

The Transition Process Upon the contract end date, your environment enters a defined Grace Period (typically 30 days). During this window, the system remains accessible to administrators in a "Read-Only" state. This ensures sufficient time for your team to perform final data extractions and audit checks. Once you confirm successful retrieval, or the grace period expires, Mercur performs a permanent, secure deletion of all active data and backups in strict accordance with GDPR and ISO 27001 standards.

Commercial Terms Mercur adheres to a "No Vendor Lock-in" policy.

Included: All costs associated with data extraction are fully covered by your SaaS subscription. We do not charge exit fees. You are free to export your complete database and reports using our built-in tools at no additional cost.

Additional Costs: Extra charges apply only if you request Mercur Professional Services for bespoke transition support—such as complex data mapping or custom migration consultancy—outside the scope of the standard self-service export tools.
Documentation accessibility standard
None or don’t know
How the documentation is accessible
Mercur ensures that all documentation regarding the customer lifecycle—from initial implementation to contract conclusion—is transparent, secure, and easily accessible.

Onboarding Documentation Upon project initiation, authorized stakeholders gain access to a dedicated Secure Client Portal. This repository serves as the single source of truth, hosting critical governance documents including the Statement of Work (SOW), Implementation Plan, and technical integration guides. This ensures your team has immediate visibility into the deployment roadmap and technical requirements from day one.

Offboarding & Data Portability We recognize the importance of data sovereignty and reject vendor lock-in. Detailed offboarding documentation is available throughout the contract term, outlining clear protocols for:

Data Export: Step-by-step guides on extracting all proprietary data in standard, open formats (e.g., CSV, SQL).

Service Termination: Clear definitions of the "End of Service" timeline and handover procedures.

Data Destruction: Compliance documentation detailing how and when data is permanently purged from our servers to meet GDPR and security standards.

All documentation is searchable, version-controlled, and available for download (PDF) to ensure you maintain a complete audit trail of the partnership at all times.

Using the service

Web browser interface
Yes
Supported browsers
  • Microsoft Edge
  • Firefox
  • Chrome
  • Safari
  • Opera
Application to install
No
Designed for use on mobile devices
Yes
Differences between the mobile and desktop service
There are no functional differences between the desktop and mobile services. The mobile service offers the following characteristics:

Browser-Based Access: Users access the full system via any modern web browser on their mobile or tablet device, with no need to install a separate application.

Touch-Enabled Interface: The application interface adapts to provide a touch-enabled experience suitable for mobile and tablet use.

Full Functionality: Users have access to the same features as the desktop version, including accessing all reports and data entry workflows.
Service interface
No
User support accessibility
None or don’t know
API
Yes
What users can and can't do using the API
Set up the service

Automated Data Management (ETL): Users can configure API connections to manage the "Extract, Transform, Load" (ETL) process, ensuring seamless data movement from external sources (such as ERPs, HR systems, or Data Warehouses) into Mercur Business Control.

Scheduled Data Synchronization: Users can set up automated jobs to trigger data imports, allowing for the periodic movement of large datasets (actuals, dimensions, and hierarchies) without manual intervention.

User Provisioning (SCIM): Users can utilize the SCIM API to automate identity management, setting up user accounts and access rights directly from their central Identity Provider (e.g., Azure AD).

Make changes

API Extraction from Mercur: Users can utilize the API and ODBC/JDBC interfaces to extract calculated data, budgets, and forecasts out of Mercur for use in third-party systems, BI tools (like Power BI), or data lakes.

Dynamic Data Updates: The API allows for the dynamic updating of dimension members (e.g., adding a new cost centre or project) and hierarchy structures to ensure the planning model matches the source system in real-time.
API documentation
Yes
API documentation formats
  • HTML
  • ODF
  • PDF
API sandbox or test environment
Yes
Customisation available
Yes
Description of customisation
What can be customised Users can fully customise the application to match their specific organisational requirements. This includes the underlying data model (dimensions, hierarchies, and attributes) and business logic. Users can also design and tailor their own content, creating bespoke financial reports, interactive dashboards, and budget input forms. Additionally, workflow processes and approval chains can be configured to align with internal governance structures.

How users can customise All customisation is performed directly via the standard web interface using intuitive, no-code tools. Users utilise drag-and-drop functionality to build reports or input screens and use simple configuration menus to manage the data model. This ensures that changes can be made quickly without the need for technical coding, scripting, or database expertise.

Who can customise Mercur Business Control is designed to be owned and managed by the Finance function. Administrators and authorised Power Users have full autonomy to configure the system. They can independently manage the data model, create new reports, and update dashboards as business needs evolve. This ensures self-sufficiency and agility, eliminating the need to rely on IT specialists or external consultants for routine changes.

Scaling

Independence of resources
Mercur Business Control ensures performance independence primarily through Multiversion Concurrency Control (MVCC) within its proprietary Veloxic database. This technology guarantees that users reading reports never have to wait for users entering data, effectively eliminating read/write queues.

To manage high demand, the system processes updates asynchronously: user inputs are quickly queued as "diffs" and integrated into the database in the background, ensuring low latency. The system also adapts to load spikes by integrating data "loosely" to maintain throughput. Additionally, distributing calculations to clients reduces central server strain

Analytics

Service usage metrics
Yes
Metrics types
The system includes logging and statistical tools to monitor user activity and system events:

Usage Statistics: A dedicated statistics database allows administrators to analyze system usage, such as tracking which reports are opened by specific users.
Reporting types
  • Real-time dashboards
  • Regular reports
  • Reports on request
Resource tagging
Yes
FOCUS resource tagging
Yes

Resellers

Supplier type
Not a reseller

Staff security

Staff security clearance
Other security clearance
Government security clearance
Developed Vetting (DV)

Asset protection

Knowledge of data storage and processing locations
Yes
Data storage and processing locations
  • United Kingdom
  • European Economic Area (EEA)
User control over data storage and processing locations
Yes
Datacentre security standards
Complies with a recognised standard (for example CSA CCM version 4.0)
Penetration testing frequency
At least once a year
Penetration testing approach
‘IT Health Check’ performed by a CHECK service provider
Protecting data at rest
  • Physical access control, complying with CSA CCM v4.0
  • Physical access control, complying with SSAE-18 / ISAE 3402
  • Encryption of all physical media
Data sanitisation process
Yes
Equipment disposal approach
Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
Data sanitisation type
  • Deleted data can’t be directly accessed / Cryptographic Erasure
  • Data Erasure
  • Explicit overwriting of storage before reallocation / Secure Erase

Data importing and exporting

Data export approach
Mercur empowers users with flexible export capabilities designed for both daily analysis and technical requirements.

Business Users: Can instantly export any report, input form, or dashboard directly to Microsoft Excel (.xlsx), PDF, or CSV. Uniquely, Excel exports retain formatting and formulas, allowing for immediate offline analysis.

Technical Administration: For comprehensive data retrieval, administrators can perform bulk extractions of master data and transaction logs using standard flat-file formats. Additionally, our REST API allows for programmatic, automated data retrieval in JSON or XML, facilitating seamless integration with third-party BI tools or data warehouses.
Data export formats
  • CSV
  • Other
Other data export formats
  • JDBC and ODBC drivers authorized
  • RESTful web service API
  • Reports can be exported to PDF, text files
  • Image files
  • Thirdparty tools read data directly from database using SQL
  • MS Office formats; Excel, PowerPoint, Word
Data import formats
CSV

Data-in-transit protection

Data protection between buyer and supplier networks
  • TLS (version 1.2 or above)
  • Other
Other protection between networks
AES Encryption: All session traffic is encrypted using AES (128, 192, or 256-bit).

RSA Key Exchange: The session keys are secured using RSA (recommended 2048-bit).

Protection: This custom handshake protects against "spoofing" and "man-in-the-middle" attacks.
Data protection within supplier network
  • TLS (version 1.2 or above)
  • IPsec or TLS VPN gateway

Availability and resilience

Guaranteed availability
Mercur shall ensure that the Services shall have an overall availability of no less than 99.5% in each calendar month (the “Availability Percentage”), this can be viewed at https://status.mercur.com. Where Mercur fails to meet the Availability Percentage for a month, it shall provide the Customer with service credits in accordance with the following table.

Availability Percentage Service Credit
99.5% + No credit
99% 5%
98.5% 7.5%
98% 10%
97.5% 20%
97% or less 25%
Approach to resilience
The service utilizes a 'Hotcopy' mechanism for 24/7 availability, ensuring backups do not interrupt operations. Data resilience is guaranteed via 'Recovery Points' and sequential transaction logging, allowing the system to replay inputs and recover data to the point of failure. The architecture uses adaptive load handling to maintain stability during demand spikes. Datacentre hosting provides physical resilience compliant with ISO 27001 and SSAE-18 standards.
Outage reporting
Yes, the service has a public dashboard, email alerts, and feed capabilities.

Public Dashboard: You can view the real-time status of the cloud service, including availability percentages, updates, incidents, and maintenance, at https://status.mercur.com.

Email Alerts: Yes, users can subscribe via the status website to receive automatic email alerts regarding service incidents and updates.

Identity and authentication

User authentication needed
Yes
User authentication
  • Multi-Factor Authentication (MFA)
  • Identity federation with existing provider (for example Google Apps)
  • Username or password
Access restrictions in management interfaces and support channels
Mercur restricts access to management interfaces and support channels based on the principle of least privilege. Permissions are defined by job function using Role-Based Access Controls (RBAC) and must be formally approved via our Jira ticketing system.

We secure access with strong password policies and mandatory Two-Factor Authentication (2FA) for critical systems. Support staff are restricted to specific client environments only when required.

To ensure compliance, all access is continuously monitored and logged , and user accounts undergo periodic reviews to revoke unnecessary privileges immediately.
Access restriction testing frequency
At least once a year
Management access authentication
  • Multi-Factor Authentication (MFA)
  • Username or password

Audit information for users

Access to user activity audit information
Users have access to real-time audit information
How long user audit data is stored for
At least 12 months
Access to supplier activity audit information
Users have access to real-time audit information
How long supplier audit data is stored for
User-defined
How long system logs are stored for
User-defined

Security governance

Named board-level person responsible for service security
Yes
Security governance certified
Yes
Security governance standards
Other
Other security governance standards
The company holds Cyber Essentials Plus certification. Our datacentre maintains independent ISO/IEC 27001, SSAE 18 / ISAE 3402 (SOC 1 & 2), and CSA STAR certifications. While the company itself is not ISO 27001 certified, it aligns its internal governance policies with ISO 27001 principles
Information security policies and processes
Mercur Solutions maintains a comprehensive Information Security Management System (ISMS) to safeguard customer data, anchored by an IT Security Policy that requires regular risk assessments and adherence to the principle of "least privilege".

Key operational policies include:

User Access: Access is granted strictly by job function, authorized via the ticketing system, and fully logged for audit purposes.

Data Protection: Mandates encryption for critical systems, regular vulnerability assessments, and secure data disposal methods like crypto-shredding.

Incident Response & Resilience: Incidents are categorized by severity, with "High" impact events triggering the Enterprise Incident Management Team (EIMT). Business continuity is ensured through daily backups and annual full-scale disaster recovery drills.

Reporting & Compliance Security governance is centralized under the Chief Information Security Officer (CISO), who oversees strategy and incident response. Compliance is ensured through mandatory annual privacy and security training for all staff , continuous automated monitoring of user activity , and annual policy reviews by the IT team. Violations result in disciplinary action, ensuring strict policy enforcement.
Software Security Code of Practice
Yes

Operational security

Configuration and change management standard
Supplier-defined controls
Configuration and change management approach
Mercur Business Control tracks service components using a layered architecture that strictly separates the core "System Layer" from the "Customer Adaptation Layer". This ensures that core updates do not disrupt customer-specific configurations. All configuration changes are recorded in a central, searchable event log, creating a full audit trail of system modifications.

Changes are assessed for security impact through the company’s Information Security Management System (ISMS). The IT Security Policy mandates regular risk assessments to evaluate potential threats , while strict Functional Access rights limit configuration capabilities to authorized administrators
Vulnerability management type
Supplier-defined controls
Vulnerability management approach
Mercur Solutions manages vulnerabilities through a rigorous Information Security Management System (ISMS). We assess potential threats using regular risk assessments , penetration testing, and vulnerability scans.

Information on threats is gathered via continuous system monitoring, log analysis , and third-party provider due diligence.

Remediation is prioritized based on severity. Critical patches are deployed immediately to the server environment, while client applications automatically detect and download updates upon startup. Unpatched vulnerabilities are classified as security incidents, triggering immediate response protocols led by the CISO.
Protective monitoring type
Supplier-defined controls
Protective monitoring approach
Mercur Solutions identifies potential compromises through continuous monitoring of centralized event logs and user access records, compliant with Cyber Essentials Plus standards. Anomalies, such as unauthorized access or malware, trigger our formal Incident Response Policy.

Upon detection, the CISO appoints an Incident Manager to coordinate containment and evidence preservation. For severe breaches, the Enterprise Incident Management Team is activated. Response times are strictly defined by severity: "High" impact incidents require an immediate response, "Medium" incidents within 4 hours, and "Low" severity issues by the next business day.
Incident management type
Supplier-defined controls
Incident management approach
Mercur Solutions follows a formal IT Security Incident Response Policy, classifying incidents by severity (Low, Medium, High) with strict response SLAs ranging from immediate action to next-business-day resolution. We maintain pre-defined protocols for common threats like malware, unauthorized access, and DDoS attacks.

Reporting Users must report suspected incidents immediately to the IT Operations Team via cybersecurity@mercur.com.

Incident Reports The Incident Manager maintains detailed logs of all actions. Formal incident reports are mandatory for high-severity events. For critical breaches, the Enterprise Incident Management Team oversees external notifications to affected customers and regulators.
Post-quantum cryptography secure
No

Secure development

Approach to secure software development best practice
Supplier-defined process

Public sector networks

Connection to public sector networks
No

Pricing

Discount for educational organisations
Yes
Free trial available
Yes
Description of free trial
Mercur does not offer a permanently free version. Instead, a free trial is available as a "live Proof of Concept". This includes configuring your live data to validate specific business requirements. The trial excludes permanent production access and is limited to the duration of the evaluation engagement.

Discount percentage by annual call-off contract value (excluding VAT)

Less than £250,000
5%
Between £250,000 and £500,000
10%
Between £500,001 and £1,000,000
25%
Between £1,000,001 and £2,500,000
25%
Between £2,500,001 and £5,000,000
25%
Over £5,000,001
25%

Non-mandatory Standards and certifications

ISO/IEC 27001 certification
No
ISO 28000:2022 certification
No
ISO 9001 certification
No
Quality management systems (QMS)
Yes
CSA STAR certification
No
PCI certification
No
Cyber essentials
Yes
Please provide your Cyber Essentials Certificate Number
431ff343-c7d0-4149-a40f-dfa83d81297a
Cyber essentials plus
Yes
Please provide your Cyber Essentials Plus Certificate Number
Bbda97a5-0025-4e12-81db-deb6837d20b5
Other security certifications
No

Social value

Section B - Commitment for Future: Delivery
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority

    • Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
    • Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
    • Plans for an appropriate income replacement policy for staff who are required to spend time away from work to care for a sick dependent or close relative
    • Understanding of in-work progression issues affecting the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors
    • Measures to support in-work progression to help people in the contract workforce, to move into higher paid work by developing new skills relevant to the contract
    • Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
    • Volunteering opportunities for staff
    • Understanding of the modern slavery risks and issues affecting the market, industry, sector or country (of origin or of source) relevant to the contract, and the workforce in the supplier’s own organisation and those of its key subcontractors
    • Measures to identify, mitigate and manage modern slavery risks relating to the contract and how these will be implemented
    • Outline policies and practices to be applied to or put in place for the contract to mitigate and manage modern slavery risks, including: Pre-employment checks, recruitment practices. Workplace conditions, safeguarding plans and processes in place and regular monitoring with relevant groups considered, which may include sampling
    • How these flow down the supply chain and are monitored Illustrative examples include reporting, site visits, audits, etc.
    • How to ensure business decisions re: price/cost, short lead times, payment timescales do not create modern slavery risks in the supply chain
    • How the supplier will work with NGOs, trade unions or other businesses to address modern slavery risk
    • Means of influencing staff, suppliers, customers, communities and/or any other appropriate stakeholders with respect to modern slavery risks relating to the contract

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at derek.morrison@mercur.com. Tell them what format you need. It will help if you say what assistive technology you use.