Lifebit Platform Trusted Operations
Lifebit Trusted Research Environment is infrastructure software that enables organisations to securely provision, govern, and orchestrate cloud compute and data resources. The platform provides role-based access control, resource allocation, workload orchestration, and policy enforcement within customer-owned cloud environments, supporting scalable, compliant research and analytics without moving data.
Features
- Secure cloud-based trusted research environment for sensitive biomedical data
- Federated data access across multiple data repositories without data movement
- Scalable genomics and multi-omics analysis using containerised workflows
- Integrated workflow orchestration using Nextflow
- Fine-grained access controls and audit logging for compliance
- Secure collaboration tools for multi-organisation research teams
- Support for AI and machine learning model development
- Automated reproducibility and provenance tracking for analyses
- Interoperability with public and private cloud infrastructures
- Compliance with UK GDPR and ISO-aligned security standards
Benefits
- Enable secure research on sensitive data without data duplication
- Accelerate scientific discovery through scalable cloud analytics
- Reduce infrastructure management overhead for research teams
- Ensure compliance with regulatory and ethical data requirements
- Increase reproducibility and transparency of research outputs
- Support rapid deployment of advanced analytics and AI models
- Lower costs through elastic compute and shared infrastructure
- Simplify access to diverse datasets across trusted environments
- Empower researchers to focus on insights rather than infrastructure
Pricing
- Education pricing available
- Free trial available
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
1 6 4 9 9 9 4 0 6 2 8 0 8 1 3
Contact
LIFEBIT BIOTECH LIMITED
Thorben Seeger
Telephone: + 44 7857149052
Email: procurement@lifebit.ai
About your service
- Service categories
-
Systems Infrastructure Software
System and service management
IT automation and configuration management
- Workload management
- Multi cloud support
- Yes
Service scope
- Software add-on or extension
- No
- Cloud deployment model
-
- Public cloud
- Private cloud
- Community cloud
- Hybrid cloud
- Service constraints
- The service must be deployed within a customer-approved cloud environment that meets security and data governance requirements. Availability of specific compute resources, such as GPUs, depends on the underlying cloud provider and regional capacity. Planned maintenance is notified in advance and may result in brief service interruptions. Access to sensitive datasets is subject to data owner approvals and onboarding processes. Performance can vary based on workload complexity, data volumes, and customer-selected infrastructure. Network access may be restricted in secure environments to maintain compliance.
- System requirements
-
- Modern web browser supporting HTTPS and JavaScript
- Secure internet connection to approved cloud environments
- Buyer-approved cloud account or hosted trusted research environment
- User authentication via organisation-approved identity provider
- Network configuration allowing secure access to cloud services
- Role-based access permissions configured by administrators
- Sufficient compute and storage quotas provisioned in cloud
- Support for container execution environments
- Access to datasets approved by relevant data controllers
- Compliance with organisational security and data governance policies
User support
- Email or online ticketing support
- Yes
- Support response times
- Core business hours are 09:00 to 18:00. Support is included within the service licence. Standard support is provided during business hours. Incidents are prioritised by severity. Major incidents involving total service loss are responded to within two business hours. High-priority incidents affecting specific features or a limited subset of users, and medium-priority incidents covering other issues or malfunctions, are responded to within four business days. Support requests are managed through email or ticketing channels. Lifebit provides access to a technical account manager and a cloud support engineer to support service operation and escalation where required.
- User can manage status and priority of support tickets
- Yes
- Online ticketing support accessibility
- WCAG 2.2 AA
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- No
- Onsite support
- Yes, at extra cost
- Support levels
- Support is included within the service licence. Standard support is provided during business hours. Incidents are prioritised by severity. Major incidents involving total service loss are responded to within two business hours. High-priority incidents affecting specific features or a limited subset of users, and medium-priority incidents covering other issues or malfunctions, are responded to within four business days. Support requests are managed through email or ticketing channels. Lifebit provides access to a technical account manager and a cloud support engineer to support service operation and escalation where required.
- Support available to third parties
- Yes
Onboarding and offboarding
- Getting started
-
Users are supported through a structured onboarding process tailored to their environment and governance requirements. This includes guided setup, access configuration, and initial service orientation. Users have access to online documentation, user guides, and example workflows to help them get started quickly.
Optional remote training sessions and workshops are available to introduce core features, workflows, and best practices. Ongoing support is provided through helpdesk channels and scheduled check-ins where required. For buyers with specific requirements, additional onboarding and training services can be agreed as part of the contract. - Service documentation
- Yes
- Documentation formats
-
- HTML
- End-of-contract data extraction
- No data extraction is required at contract end because all customer data remains within the buyer’s own cloud account at all times. The service uses Lifebit's patented federation technology to enable analysis without moving or copying data outside the customer-controlled environment. This approach avoids vendor lock-in by ensuring customers retain full ownership, control, and direct access to their data, infrastructure, and outputs. When the contract ends, access to Lifebit services can simply be disabled with no dependency on proprietary storage, data formats, or migration processes.
- End-of-contract process
-
At the end of the contract, access to the Lifebit service is disabled in line with the agreed off-boarding process. All customer data remains within the buyer’s own cloud account throughout the contract and after termination, as the service uses federated technology and does not store or transfer customer data. This ensures there is no vendor lock-in, no data migration requirement, and no dependency on proprietary storage or formats.
Contract pricing includes standard service off-boarding, access removal, and confirmation of contract closure. No data extraction, migration, or deletion activities are required as part of the standard process. Optional additional support, such as extended exit planning, documentation, or assistance with transitioning to alternative services, can be provided at additional cost if requested by the buyer. - Documentation accessibility standard
- WCAG 2.2 AA
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Opera
- Application to install
- No
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
- The service is accessible via modern mobile web browsers for viewing, monitoring, and basic administration. Due to screen size and security considerations, complex tasks such as large dataset management, and interactive analysis are optimised for desktop use. Full functionality, including data analysis and pipeline configuration, is best experienced on desktop or laptop devices within approved secure environments.
- Service interface
- Yes
- User support accessibility
- WCAG 2.2 A
- Description of service interface
- The service is accessed through a secure, browser-based web interface providing user, project, and data management capabilities. The interface supports workflow configuration, job monitoring, access control, and collaboration within approved trusted research environments. Users can launch and manage analyses using visual tools and integrated workflow engines. In addition, the service provides APIs for automation and integration with external systems, subject to security and governance controls.
- Accessibility standards
- WCAG 2.2 AA
- Accessibility testing
- Formal testing with users of assistive technology has not yet been completed. Accessibility considerations are addressed during interface design using recognised best practices, including semantic markup, keyboard navigation, and contrast checks. The service is evolving, and structured accessibility testing and improvements are planned as part of ongoing development to align with WCAG 2.2 guidance and buyer requirements.
- API
- Yes
- What users can and can't do using the API
-
Yes, our service provides a comprehensive Command Line Interface (CLI) and Python API: https://github.com/lifebit-ai/cloudos-cli/, Python library and Command Line Interface for interacting with Lifebit Applications.
Users can install the CLI via PyPI, Docker, or directly from GitHub. Through the CLI, users can configure profiles, create and manage projects, submit and monitor Nextflow and Bash jobs, manage datasets and files, import workflows, and access job logs, results, and costs. The CLI also supports Cromwell and WDL pipeline management, procurement image management, and integration with custom scripts.
Some advanced or administrative settings may require the web interface. All actions are subject to user permissions and rate limits. Full documentation and usage examples are available https://github.com/lifebit-ai/cloudos-cli/ : Python library and Command Line Interface for interacting with Lifebit Applications. - API documentation
- Yes
- API documentation formats
-
- Open API (also known as Swagger)
- HTML
- API sandbox or test environment
- Yes
- Customisation available
- Yes
- Description of customisation
-
Buyers can customise the service through configuration, extensions, and optional add-ons. Authorised users can enable or integrate approved plugins, workflow tools, and external services to extend functionality, subject to security and governance controls. Customisation includes configuring projects, workflows, compute resources, integrations, and access policies.
Administrative users manage available add-ons, plugins, and integrations, and control who can use them. End users can customise analysis workflows and execution settings within those constraints. Platform-level functionality, core security controls, and unapproved extensions cannot be modified to ensure compliance, stability, and data protection.
Scaling
- Independence of resources
- Users are isolated because workloads run within the customer’s own cloud environment rather than shared platform infrastructure. Service performance is not affected by other users, as compute, storage, and networking scale elastically with the underlying cloud. Resources can increase on demand in line with buyer-defined policies and approvals. Where multiple teams operate within the same environment, role-based controls and cloud-native resource management ensure fair usage without contention. This approach avoids noisy-neighbour effects while enabling scaling as required, subject to the customer’s governance and cost controls.
Analytics
- Service usage metrics
- Yes
- Metrics types
- We provide comprehensive service usage metrics, including job and workflow status, resource consumption (CPU, memory, storage), job duration, queue times, and cost breakdowns. Users can access metrics via the CLI in table, CSV, or JSON formats, and detailed logs and results are available for each job. Metrics can be filtered by project, user, or time period, supporting monitoring, reporting, and cost management. Additional usage analytics are available through the platform dashboard and downloadable reports.
- Reporting types
-
- API access
- Real-time dashboards
- Regular reports
- Reports on request
- Resource tagging
- Yes
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Other security clearance
- Government security clearance
- Security Clearance (SC)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- United Kingdom
- User control over data storage and processing locations
- Yes
- Datacentre security standards
- Managed by a third party
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- Another external penetration testing organisation
- Protecting data at rest
-
- Encryption of all physical media
- Other
- Other data at rest protection approach
- In addition to encrypting all physical media, data at rest is protected using cloud-native encryption services within the buyer’s cloud environment. All storage, disks, snapshots, and backups are encrypted by default using managed key services backed by hardware security modules, with equivalent controls on Azure and AWS. Encryption keys are centrally managed, access-controlled, and auditable, with no direct access by Lifebit personnel. Role-based access controls and continuous monitoring ensure data remains protected throughout its lifecycle under buyer governance.
- Data sanitisation process
- Yes
- Equipment disposal approach
- A third-party destruction service
- Data sanitisation type
-
- Deleted data can’t be directly accessed / Cryptographic Erasure
- Data Erasure
Data importing and exporting
- Data export approach
-
Research outputs are managed within the customer’s own cloud environment using configurable governance controls.
Data and output exports can be fully restricted, released post review, or openly accessible depending on regulatory, ethical, and organisational requirements.Reviews can be manual, using automated policy checks, or both before release.
Different teams and projects can operate under distinct governance rules simultaneously. Once outputs are approved, users can export them from the customer’s cloud environment for their permitted downstream use. - Data export formats
-
- CSV
- ODF
- Other
- Other data export formats
-
- Html5
- Png
- Txt
- Json
- .config
- Data import formats
-
- CSV
- ODF
- Other
- Other data import formats
-
- Json
- Csv
- Txt
- Png
- Html
Data-in-transit protection
- Data protection between buyer and supplier networks
-
- TLS (version 1.2 or above)
- Other
- Other protection between networks
- In addition to TLS encryption, the service uses a federated cloud architecture where workloads execute within the buyer’s own cloud environment. Data is protected using cloud-native encryption, key management, and hardware security modules, with equivalent controls supported across cloud providers (AWS, Azure). Comprehensive monitoring and auditing are provided through platform-level logging and cloud-native services, including authentication, network activity, data access, and operational events. This approach ensures secure data-in-transit protection while enabling continuous monitoring, auditing, and compliance under the buyer’s security governance.
- Data protection within supplier network
- Other
- Other protection within supplier network
- Within the platform, data is protected using cloud-native security controls operating inside the buyer’s cloud environment. All service-to-service communication uses encrypted channels, and data is encrypted at rest and during processing using managed key services and hardware security modules, with equivalent implementations on Azure and AWS. Access is controlled through cloud-native identity, role-based permissions, and policy enforcement. Continuous monitoring, logging, and audit trails track authentication, network activity, data access, and operational changes to maintain security and compliance.
Availability and resilience
- Guaranteed availability
-
Service availability is delivered through a cloud-native, highly available architecture designed to operate within the buyer’s chosen cloud environment. The service leverages managed cloud services, regional redundancy, automated scaling, and resilient deployment patterns to support reliable operation when implemented in line with recommended configurations.
Availability is supported through continuous monitoring, proactive alerting, and defined incident management processes. Lifebit provides operational support to diagnose and resolve service issues within agreed response and resolution targets, working collaboratively with the buyer where access to the underlying cloud environment is required.
Where availability commitments are agreed, these are defined in the call-off contract and aligned to both the Lifebit service scope and the availability guarantees of the underlying cloud provider (for example, AWS or Azure). Availability measurement, reporting, and review mechanisms are also defined in the call-off agreement to ensure transparency.
If agreed availability levels are not met due to issues attributable to the Lifebit service, service credits or other contractual remedies may apply in accordance with the call-off contract. Availability issues arising from the buyer’s cloud configuration, third-party services, or cloud provider outages are excluded. - Approach to resilience
-
The service is designed to meet the UK Government Cloud Security Principle 2: Asset protection and resilience. It is deployed within the buyer’s own, owned, and controlled cloud environment, meaning baseline physical, environmental, and infrastructure resilience is provided by the chosen hyperscale cloud provider, such as AWS, Azure, or GCP. This includes resilient data centre design, redundant power and networking, and protection against physical disruption.
On top of this foundation, the service is architected to support availability, resilience, and recovery using cloud-native design patterns. The service supports deployment across multiple availability zones within a region, reducing the impact of component, hardware, or network failures. Application components are fault tolerant, with automated scaling, health checks, and self-healing mechanisms to maintain service continuity.
Data assets are protected using cloud-native storage services that provide built-in redundancy and durability. Backup and recovery capabilities are supported and can be configured in line with the buyer’s business continuity and disaster recovery requirements.
Operational resilience is maintained through continuous monitoring, logging, and alerting, enabling timely detection and remediation of incidents. Roles and responsibilities for resilience are clearly defined between the cloud provider, the buyer, and the service provider.
Further details can be provided upon request - Outage reporting
-
The service includes clear and timely outage reporting mechanisms appropriate to its deployment within a buyer-owned cloud environment.
Operational monitoring is performed continuously, with automated detection of service degradation or outages affecting availability, performance, or critical functionality. When an incident is identified that materially impacts users, Lifebit notifies nominated buyer contacts in line with the agreed support and incident management process.
Outage notifications are primarily delivered via email alerts to agreed distribution lists, providing information on incident status, impact, mitigation actions, and expected resolution times. Updates are issued at appropriate intervals until the incident is resolved.
Where required, outage and service health information can also be surfaced through buyer-accessible dashboards within the deployed environment, using standard cloud-native monitoring and logging tools. These dashboards provide visibility into service status, key components, and historical incident data.
An external public status dashboard or public API is not provided by default, as deployments are customer-specific and operate within buyer-controlled cloud environments. However, API-based integration with monitoring or incident management tooling can be supported where agreed.
Post-incident reporting, including root cause analysis and corrective actions, is provided to buyers for significant outages in accordance with the call-off contract.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Identity federation with existing provider (for example Google Apps)
- Dedicated link (for example VPN)
- Username or password
- Other
- Other user authentication
- All authentication occurs over encrypted channels (TLS), and IP allow listing can be configured for additional access control
- Access restrictions in management interfaces and support channels
-
Access to management interfaces and support channels is restricted using role-based access control and least-privilege principles. Administrative access is limited to authorised personnel and protected by strong authentication. Access is granted based on defined job roles and reviewed regularly.
Support channels are restricted to verified customer contacts, and sensitive actions require identity verification and appropriate authorisation. All administrative and support access is logged and monitored to provide auditability and support security monitoring and incident investigation.
Access rights are revoked promptly when no longer required, including when roles change or personnel leave the organisation. - Access restriction testing frequency
- At least once a year
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Identity federation with existing provider (for example Google Apps)
- Dedicated link (for example VPN)
- Username or password
- Other
- Description of management access authentication
- All authentication occurs over encrypted channels (TLS), and IP allow listing can be configured for additional access control
Audit information for users
- Access to user activity audit information
- Users have access to real-time audit information
- How long user audit data is stored for
- User-defined
- Access to supplier activity audit information
- Users have access to real-time audit information
- How long supplier audit data is stored for
- User-defined
- How long system logs are stored for
- User-defined
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
- ISO/IEC 27001
- Information security policies and processes
-
Lifebit operates a comprehensive set of information security policies and processes designed to protect the confidentiality, integrity, and availability of information. These policies are aligned with recognised good practice and are reviewed regularly to ensure continued effectiveness.
Core policies include information security, access control, risk management, incident management, secure development, supplier security, data protection, and business continuity. Supporting procedures define how these policies are implemented in day-to-day operations, including user access management, vulnerability management, logging and monitoring, change control, and secure configuration.
Security governance is overseen by senior management, with clear accountability for information security assigned to designated security and compliance roles. Security risks, incidents, and compliance matters are reported through defined escalation and reporting structures, ensuring appropriate visibility and decision-making at management level.
Policy compliance is enforced through mandatory staff training, role-based access controls, and documented operational processes. All staff are required to complete security awareness training and to comply with relevant policies as part of their employment conditions. Compliance is further supported through regular reviews, audits, and monitoring activities, with corrective actions tracked to closure.
These measures ensure information security policies are consistently applied and effectively embedded across the organisation. - Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
-
Configuration and change management are governed through defined internal processes aligned with recognised good practice. Service components, including application code, infrastructure configuration, and dependencies, are tracked throughout their lifecycle using version control, configuration repositories, and documented release records.
All changes follow a controlled change process that includes impact assessment, approval, testing, and rollback planning. Changes are assessed for potential security impact, including effects on confidentiality, integrity, availability, and compliance requirements. Security-relevant changes require additional review and validation before deployment.
Changes are deployed in a controlled manner, with monitoring in place to detect issues and enable rapid remediation if required. - Vulnerability management type
- Supplier-defined controls
- Vulnerability management approach
- Potential threats are identified through automated code scanning prior to deployment, dependency analysis, and monitoring of cloud provider security advisories and recognised vulnerability databases. Vulnerabilities are assessed based on severity and potential impact. Critical and High vulnerabilities must be remediated before deployment to staging, and a clean scan is required prior to release. Security patches and fixes are deployed as part of controlled release processes, prioritised by risk. Information on emerging threats is sourced from security tooling, AWS and Azure security notifications, and industry vulnerability disclosures.
- Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
- We identify potential compromises through continuous platform and cloud-native monitoring, including audit logs, security events, access patterns, and anomaly detection across compute, storage, and network layers. Alerts are generated automatically for suspicious or non-compliant activity. Incidents are triaged immediately by the security team, with containment actions such as access restriction, workload isolation, or policy enforcement applied as required. High-severity incidents are responded to in near real time, with defined escalation and forensic review processes. All events and responses are fully logged to support audit and regulatory requirements.
- Incident management type
- Complies with a recognised standard, for example, CSA CCM v4.0 or ISO/IEC 27035:2011 or SSAE-18 / ISAE 3402
- Incident management approach
- The organisation operates a formal incident management process aligned with ISO/IEC 27001 and ISO/IEC 27035 requirements and assessed through SOC 2 controls. Pre-defined procedures exist for common security and service incidents, including access issues, suspected compromise, and service disruption. Incidents can be reported by users through designated support channels and service contacts. All incidents are logged, triaged, and managed based on severity, with escalation where required. Incident reports are provided to affected customers following resolution, including impact assessment, actions taken, and any required remediation.
- Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- Yes
- Free trial available
- Yes
- Description of free trial
- We offer a free START tier that provides access to core platform functionality, including a single workspace, unlimited users, and essential data science and workflow tools. Advanced features, enterprise governance, automation, and premium support are not included. The free version is not time-limited but is functionally restricted.
- Link to free trial
- https://lifebit.ai/lifebit-start-first-hand-try/
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 0%
- Between £500,001 and £1,000,000
- 0%
- Between £1,000,001 and £2,500,000
- 5%
- Between £2,500,001 and £5,000,000
- 10%
- Over £5,000,001
- 15%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- Yes
- Who accredited the ISO/IEC 27001
- SOCOTEC Certification UK Ltd
- ISO/IEC 27001 accreditation date
- Tuesday 31 January 2023
- What the ISO/IEC 27001 doesn’t cover
- The organisation does not have any outsourced development and therefore the control about supervising and monitoring the activity of outsourced system development from our statement of applicability does not apply.
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- Yes
- Who accredited the ISO 9001 certification
- SOCOTEC Certification UK
- ISO 9001 accreditation date
- Friday 12 September 2025
- What the ISO 9001 doesn’t cover
- The organisation does not have any outsourced development and therefore the control about supervising and monitoring the activity of outsourced system development from our statement of applicability does not apply.
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- 961b9f29-c097-4162-98ac-13baf466300d
- Cyber essentials plus
- Yes
- Please provide your Cyber Essentials Plus Certificate Number
- D98208db-38d6-4cd7-b77b-6ccd32dc2fbc
- Other security certifications
- Yes
- Any other security certifications
- FedRamp Marketplace Ready Certification
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- New or retained jobs on the contract workforce in the relevant area that meet the criteria set out in MAC 1b, 1c and 1d
- Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
- Plans to engage the contract workforce in deciding the most important workplace issues to address
- Monitoring of employee engagement rates (by protected characteristic) and, where necessary, the development of actions to ensure all voices are heard across the diversity of the workforce
- Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
- Entitlement to sick pay for the contract workforce, with provision in place for any staff who do not meet the earnings threshold for statutory sick pay, payment of sick pay from day one of absence and payment of staff on the contract workforce who are off sick a replacement income of 100% of their usual earnings for as long as possible
- Measures to support in-work progression to help people in the contract workforce, to move into higher paid work by developing new skills relevant to the contract
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.
- Delivery of apprenticeships, supported internships and T Level industry placement opportunities (Level 2, 3 and 4+) in relation to the contract
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 3: Resilient, innovative and flexible supply chains: Support economic growth through enabling resilient businesses, opportunities for small businesses and voluntary, community and social enterprises
- Understanding of the types of businesses in the market and the level of participation by new businesses, entrepreneurs, start-ups, SMEs, VCSEs and mutuals
- Plans for engaging a diverse range of businesses in engagement activities prior to appointing subcontractors (including activities prior to award of the main contract and during the contract term)
- Plans to respond flexibly and adapt approaches to community engagement and initiatives
-
Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero
Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.
- Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
- Understanding of how to influence staff, suppliers, customers, communities and/or any other appropriate stakeholders through the delivery of the contract to support climate and nature protection and improvement
- Activities to reconnect people with the environment and increase awareness of ways to protect and enhance it
-
Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain
Policy Outcome 6: Employment and training: For those who face barriers to employment
- Understanding of employment and skills issues, and of the skills and employment shortages of high growth sectors relating to the contract
- Understanding of the issues affecting the representation of disabled people in the workforce in the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors
- Understanding of the issues affecting inequality in employment, skills and pay in the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors. Measures to tackle inequality in employment, skills and pay in the contract workforce
-
Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain
Policy Outcome 7: Creating a pipeline of opportunities: For the contract workforce, reducing barriers to entry for under-represented groups.
- Understanding of issues relating to entering the contract workforce
-
Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.
Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.
- Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce
- Inclusive and accessible recruitment practices, development practices and retention policies that support-focused activities including those provided in the Guide for line managers on recruiting, managing and developing which support people with a disability or health condition
-