Lifebit Trusted Research Environment & Lifebit Airlock
Lifebit Federated Trusted Research Environment/Secure Data Environment, Data Lakehouse & Lifebit Airlock (Output Checking System) enables secure, federated access to sensitive biomedical/genomic data, allowing organisations to ingest, harmonise, govern and analyse data in place, without moving it, so researchers can generate insights, collaborate safely, and accelerate research at population scale.
Features
- Federated in-place data access without movement across secure environments trusted.
- AI-automated data ingestion, harmonisation and metadata cataloguing at scale population.
- Role-based access control with full audit logging and governance compliance.
- Secure cloud-native trusted research environment and trusted data lakehouse
- Scalable analytics using elastic compute for large population datasets globally.
- Interoperable standards-based integration with genomics clinical imaging and omics data.
- Self-service workflow execution via notebooks containers and automated pipelines securely.
- Built-in cost management monitoring and controls for storage and compute.
- Real-time collaboration sharing results cohorts and analyses across organisations securely.
- Regulatory-grade security compliance, Airlock/Output Checking System
Benefits
- Access sensitive data securely without copying, delays and compliance risk.
- Onboard datasets rapidly, shortening time from data arrival to analysis.
- Harmonise data automatically, reducing manual effort and operational burden.
- Enable researchers to analyse data using familiar tools and workflows.
- Scale compute to match demand, accelerating large and complex analyses.
- Support collaboration across organisations while maintaining strict data governance controls.
- Reduce administrative overhead through self-service access, workflows, and approvals.
- Improve reproducibility with standardised pipelines, metadata, and audit trails.
- Control costs proactively with transparent usage monitoring and spending limits.
- Increase research productivity by simplifying secure access to multi-modal datasets.
Pricing
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
1 9 7 5 4 1 2 7 9 7 6 1 1 1 9
Contact
LIFEBIT BIOTECH LIMITED
Thorben Seeger
Telephone: + 44 7857149052
Email: procurement@lifebit.ai
About your service
- Service categories
-
Application Development and Deployment
Data management
Database management systems
- Relational Database Management Systems
- Data Lake Management Systems
Data integration and intelligence
- Data Ingestion and Transformation Software
- Metadata Management Software
- Multi cloud support
- Yes
Service scope
- Software add-on or extension
- Yes
- What software services is the service an extension to
- Additional federated data sites and Additional federated data & compute sites are available as extensions to the Trusted Research Environment.
- Cloud deployment model
-
- Public cloud
- Private cloud
- Community cloud
- Hybrid cloud
- Service constraints
-
• Cloud-based service; on-premise-only deployments not supported.
• Data must remain within buyer-controlled cloud accounts and regions.
• Scheduled maintenance may cause short, pre-notified service interruptions.
• Requires modern web browsers and buyer identity provider integration.
• Performance depends on buyer-provisioned cloud compute and storage. - System requirements
-
- No required software licenses.
- Customer-owned public cloud account (for example AWS or Azure)
- Secure internet connectivity and HTTPS access
- Modern web browser supporting JavaScript
- Cloud identity and access management configured
- Network access to required cloud services
- Permissions to deploy resources within customer cloud account
- Optional GPU-enabled instances where required
User support
- Email or online ticketing support
- Yes
- Support response times
- Core business hours are 09:00 to 18:00. Lifebit will categorise the severity of an issue based on the impact statement provided by the client in the Help Desk ticket. Lifebit engineering operates over two week sprints. For high and medium priority tickets it is expected that the majority of issues will follow the sprint process and further, will be subject to the Client release process. Timing is therefore variable and subject to change.
- User can manage status and priority of support tickets
- Yes
- Online ticketing support accessibility
- WCAG 2.2 AA
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- No
- Onsite support
- Yes, at extra cost
- Support levels
- The cost of support is included in the license. Support levels: Major Incidents entailing total loss of service the response is 2 business hours. High priority incidents impacting one of more features for a small % of the overall users of the system the response time is 4 business days. Medium Priority Incidents cover any other issues and malfunctions the response time is 4 business days. Lifebit provides provides a technical account manager and cloud support engineer.
- Support available to third parties
- Yes
Onboarding and offboarding
- Getting started
- Lifebit supports users through a structured onboarding process tailored to customer requirements. This includes initial service setup, configuration guidance, and user enablement. Users are provided with online documentation, user guides, and platform walkthroughs to support self-service adoption. Remote training sessions and user-requestable high-touch support sessions are available to address specific use cases or questions. Ongoing support is provided through email or ticketing channels as users become familiar with the service.
- Service documentation
- Yes
- Documentation formats
-
- HTML
- Other
- Other documentation formats
- Docx
- End-of-contract data extraction
- Users do not need to extract their data when the contract ends because all data is stored in the buyer’s own cloud infrastructure at all times. Data remains fully accessible to the buyer before, during, and after the contract, independent of the Lifebit service. At contract end Platform access is disabled, but all datasets, results, metadata, and files remain in the buyer’s cloud accounts and storage locations under their control. No data is removed, transferred, or locked by Lifebit. Optional support If required, Lifebit can provide offboarding support, including documentation and assistance to identify data locations, validate outputs, export derived results, or transition workflows. Support is delivered through agreed, secure processes and does not require proprietary tools. Security and closure Once offboarding is complete, Lifebit access credentials are revoked and service components are decommissioned in line with contract terms. Any service-managed metadata or logs are handled according to agreed data retention and deletion policies. Limitations Third-party licensed datasets remain subject to their original licence terms.
- End-of-contract process
-
At contract end, Lifebit access to the platform is formally decommissioned, including user accounts, service credentials, and managed platform components. All customer data remains in the buyer’s own cloud infrastructure, under their full control, and is not removed, locked, or transferred by Lifebit. Where agreed, a defined offboarding period allows validation, knowledge transfer, and orderly transition. Any Lifebit-managed service metadata or logs are handled in line with contractual retention and deletion obligations, with confirmation provided.
What’s included in the contract price
• Use of the Lifebit platform software during the contract term.
• Secure operation within the buyer’s cloud environment.
• Standard onboarding, documentation, and remote training.
• Ongoing platform updates, maintenance, and security patches.
• Standard support and incident management during service hours.
• Governance, audit, and access controls as configured.
Additional costs (if required)
• Buyer cloud infrastructure costs (compute, storage, network) paid directly to the cloud provider.
• Optional enhanced support, bespoke training, or onsite services.
• Custom integrations, configuration, or development beyond standard capabilities.
• Extended offboarding or transition support beyond the contracted scope.
• Third-party tools or licensed datasets subject to separate licence terms. - Documentation accessibility standard
- WCAG 2.2 AA
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Application to install
- No
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
- The service is accessible through a modern web browser and adapts to different screen sizes. Core functionality is available on mobile devices; however, the desktop interface is optimised for complex workflows such as managing compute environments, configuring resources, and running large-scale analyses. Mobile access is best suited for viewing information, monitoring activity, and performing basic administrative tasks rather than full operational use.
- Service interface
- Yes
- User support accessibility
- WCAG 2.2 AA
- Description of service interface
- The service is accessed through a secure web-based interface and APIs. The web interface provides role-based access to manage organisations, users, workspaces, compute environments, and workflows. It includes an airlock capability that supports controlled data import and export, with configurable manual or automated review workflows. Users can submit and monitor jobs, manage resources, and view audit and usage information. APIs support automation and integration with external systems. All access is secured using authentication, role-based permissions, and comprehensive logging.
- Accessibility standards
- WCAG 2.2 AA
- Accessibility testing
- Formal usability testing with users of assistive technology has not yet been completed. Accessibility considerations are incorporated into interface design and development, including use of standard web technologies and semantic components. The service is designed to be compatible with common assistive technologies supported by modern browsers. Accessibility testing and improvements are planned as part of ongoing product development, informed by user feedback and recognised accessibility standards.
- API
- Yes
- What users can and can't do using the API
-
What users can do through the API
Service setup
• Programmatically create and manage organisations, projects/workspaces, and user groups.
• Provision users and assign roles/permissions (RBAC) to projects and datasets.
• Register datasets and metadata in the catalogue; tag, version, and describe assets.
• Configure approved connectors and data registrations (within allowed policies).
• Submit workflows/jobs (e.g., WDL/Nextflow/container), and create analysis runs.
Making changes
• Update user access, rotate credentials/tokens, and manage service accounts.
• Update metadata, dataset visibility, retention tags, and governance attributes.
• Start/stop jobs, change job parameters, monitor run status, and retrieve logs.
• Query usage/cost telemetry (where enabled) and generate operational reports.
• Automate approvals/requests (e.g., export/egress requests) where configured.
Limitations
• Cannot change underlying cloud infrastructure, regions, tenant boundaries, or core security controls via API.
• Actions are constrained by buyer governance (approval workflows, policies, least-privilege roles).
• Connector types and external integrations may require admin enablement and/or provider support.
• Some UI-only administrative functions (e.g., certain dashboard configurations) may not be exposed. - API documentation
- Yes
- API documentation formats
-
- Open API (also known as Swagger)
- HTML
- API sandbox or test environment
- No
- Customisation available
- Yes
- Description of customisation
- Users can customise the service to meet their organisational and project needs. Customisable elements include user roles and permissions, workspace structures, compute environments, resource quotas, workflow configurations, data access rules, and export controls. Customisation is performed through the web-based interface and APIs, using role-based configuration settings rather than code changes. Administrative users within the customer organisation can manage configuration for their teams, while individual users can customise their own workspaces within permitted policies. Lifebit may provide additional configuration or integration support where agreed, but customers retain control over all customisable settings within their cloud environment.
Scaling
- Independence of resources
- User workloads are isolated to guarantee independence of resources and prevent contention. Each project operates in separate, logically isolated environments within the buyer’s cloud, with dedicated compute, storage, and quotas. Resource limits are enforced per project and user, preventing any single workload from consuming shared capacity. Elastic scaling provisions resources on demand, avoiding competition during peak usage. Scheduling and queuing controls ensure fair allocation for batch workloads. Continuous monitoring and throttling detect and contain abnormal usage. Because data and compute run in the buyer’s cloud tenancy, there is no cross-tenant resource sharing, ensuring user’s demand cannot impact performance or availability.
Analytics
- Service usage metrics
- Yes
- Metrics types
-
CPU
Disk
Memory
Network
Number of active instances - Reporting types
-
- API access
- Real-time dashboards
- Resource tagging
- Yes
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Staff screening not performed
- Government security clearance
- Baseline Personnel Security Standard (BPSS)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- United Kingdom
- User control over data storage and processing locations
- No
- Datacentre security standards
- Complies with a recognised standard (for example CSA CCM version 4.0)
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- Another external penetration testing organisation
- Protecting data at rest
-
- Encryption of all physical media
- Scale, obfuscating techniques, or data storage sharding
- Data sanitisation process
- Yes
- Equipment disposal approach
- Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
- Data sanitisation type
- Deleted data can’t be directly accessed / Cryptographic Erasure
Data importing and exporting
- Data export approach
- Data export is managed through Lifebit Airlock services. Export permissions can be enabled, restricted, or fully disabled for different user groups or projects based on organisational policy. Where permitted, users submit export requests for off-platform data access through the Airlock, supporting manual review, automated checks, or pre-approved export for verified analyses. Automated rules can assess outputs before release. Lifebit Airlock is responsible for managing all data export controls and auditing. Airlock is an add-on to the Lifebit Trusted Research Environment and can also be procured separately.
- Data export formats
-
- CSV
- ODF
- Other
- Other data export formats
- Any formats of choice. Lifebit platform is data-agnostic
- Data import formats
-
- CSV
- ODF
- Other
- Other data import formats
- Any format of choice. Lifebit Platform is data agnostic
Data-in-transit protection
- Data protection between buyer and supplier networks
- TLS (version 1.2 or above)
- Data protection within supplier network
- TLS (version 1.2 or above)
Availability and resilience
- Guaranteed availability
- The service is designed to be resilient in line with the UK Government’s Cloud Security Principle 2: Asset protection and resilience, combining cloud-native resilience with application-level safeguards. Data centre resilience The service runs entirely within the buyer’s chosen hyperscale cloud provider. Data centre resilience, including physical security, power, cooling, and environmental controls, is provided by the cloud provider and designed for high availability using geographically separated, highly available facilities. These controls are independently audited and certified (e.g. ISO 27001, SOC/ISAE), and detailed evidence is available on request. Platform resilience The platform is deployed using cloud-native, fault-tolerant architectures. Services are distributed across multiple availability zones, avoiding single points of failure. Stateless components, managed services, and automated recovery mechanisms enable rapid restart and failover in the event of component failure. Data resilience Customer data remains in the buyer’s cloud environment and benefits from cloud-native durability features such as multi-zone storage, replication, and snapshotting, configured to client requirements and best practices. Operational resilience Continuous monitoring, alerting, and logging detect issues early. Planned maintenance is performed with minimal disruption, and incident response processes are in place to restore service quickly. Detailed architectural and resilience documentation can be provided on request.
- Approach to resilience
-
The service is designed for resilience by operating within the buyer’s own cloud environment and leveraging cloud-native availability and recovery capabilities. Workloads are deployed using managed services, redundant components, and automated scaling features provided by the underlying cloud platform. This allows services to recover from component failure and scale in response to demand, subject to buyer configuration and policies.
Datacentre resilience is provided by the underlying cloud providers, which operate geographically distributed regions, availability zones, and resilient physical infrastructure. The service can be configured to use multi-zone or regional deployment patterns where required by the buyer.
Operational resilience is further supported through controlled release processes, monitoring, and automated health checks. The platform avoids single points of failure by design and relies on stateless services and externally managed storage where appropriate. Backup, restore, and disaster recovery options are available using cloud-native mechanisms and can be configured to meet buyer recovery objectives.
Detailed architecture and resilience configurations can be provided on request, as they may vary depending on buyer requirements and cloud environment. - Outage reporting
- Service outages and incidents are communicated to users through agreed support and communication channels. Where an issue relates to the underlying cloud infrastructure, users can reference the relevant cloud provider’s public service status dashboards. For issues attributable to Lifebit's Platform services, affected customers are notified directly via email or agreed incident notification channels, with updates provided as the incident progresses. Operational status and incident information can also be shared through support tickets and service communications. Where required, buyers can integrate their own monitoring and alerting using cloud-native tools and APIs within their environment alongside Lifebit's own monitoring and telemetry tools.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Identity federation with existing provider (for example Google Apps)
- Username or password
- Access restrictions in management interfaces and support channels
- Access to management interfaces and support channels is restricted using role-based access control and least-privilege principles. Administrative access is limited to authorised personnel and protected by strong authentication. Access is granted based on defined job roles and reviewed regularly. Support channels are restricted to verified customer contacts, and sensitive actions require identity verification and appropriate authorisation. All administrative and support access is logged and monitored to provide auditability and support security monitoring and incident investigation. Access rights are revoked promptly when no longer required, including when roles change or personnel leave the organisation.
- Access restriction testing frequency
- At least once a year
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Public key authentication (including by TLS client certificate)
- Identity federation with existing provider (for example Google Apps)
- Dedicated link (for example VPN)
- Username or password
- Other
- Description of management access authentication
- All authentication occurs over encrypted channels (TLS), and IP allow listing can be configured for additional access control
Audit information for users
- Access to user activity audit information
- Users receive audit information on a regular basis
- How long user audit data is stored for
- User-defined
- Access to supplier activity audit information
- Users have access to real-time audit information
- How long supplier audit data is stored for
- User-defined
- How long system logs are stored for
- User-defined
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
- ISO/IEC 27001
- Information security policies and processes
-
We follow a comprehensive information security management framework aligned to recognised standards and client requirements, with clear accountability and enforcement.
Policies and standards
Lifebit maintains formal, documented policies covering information security, data protection, access control, incident management, risk management, supplier security, business continuity, and secure development. Policies align with ISO/IEC 27001 principles, UK GDPR, NHS expectations where applicable, and cloud security best practices.
Reporting structure
Overall accountability sits with senior management, with day-to-day responsibility held by a designated security leadership function. Security risks, incidents, and compliance status are reported through defined internal governance forums and escalated to executive level where required.
Processes and enforcement
Policies are embedded into operational processes, including onboarding/offboarding, change management, access approvals, and incident response. Role-based access control, least-privilege principles, audit logging, and monitoring ensure compliance in practice.
Assurance
All staff receive mandatory security and data protection training. Compliance is reinforced through regular reviews, risk assessments, vulnerability management, and independent audits where required. Deviations are tracked, remediated, and reviewed to ensure continuous improvement.
This approach ensures security policies are consistently applied, monitored, and enforced across the service lifecycle. - Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Configuration and change management approach
- Configuration and change management are governed through controlled, auditable processes aligned with ISO/IEC 27001. Service components are tracked throughout their lifecycle using version control, configuration records, and change histories. Infrastructure and application changes are managed through defined release and approval workflows. All changes are assessed for potential security, stability, and compliance impact, including dependency and vulnerability checks, prior to deployment. Changes are tested in non-production environments before release, and all deployments and configuration changes are logged to provide traceability and support audit and incident investigation.
- Vulnerability management type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Vulnerability management approach
- Lifebit operates a formal vulnerability management programme governed by our Operational Security Policy. We use Rapid7 InsightVM and related tooling to perform regular vulnerability scanning across production, staging and corporate environments. Scan results are assessed using CVSS, asset criticality and exposure, and vulnerabilities are prioritised as Critical, High, Medium, Low or Informational with defined remediation SLAs. Patches are tested in non‑production before production rollout, with an emergency change path for critical fixes. Threat intelligence is sourced from Rapid7 feeds, vendor advisories (e.g. AWS, OS, middleware) and public vulnerability databases such as NVD/CVE to drive timely remediation.
- Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
-
Lifebit operates 24×7 protective monitoring using centralised logging and a managed SOC service. Logs from AWS (CloudTrail, GuardDuty, VPC Flow Logs, host logs), Google Workspace and managed endpoints are streamed into our SIEM for correlation and alerting Operational Security Policy,
Security Monitoring. Integrity360’s SOCaaS triages alerts, raises tickets and escalates to Lifebit’s Security Operations team under our Security Monitoring and Incident Response Process and Incident Response Plan. High‑severity incidents are responded to immediately, with defined SLAs for investigation, containment and remediation - Incident management type
- Complies with a recognised standard, for example, CSA CCM v4.0 or ISO/IEC 27035:2011 or SSAE-18 / ISAE 3402
- Incident management approach
- Lifebit operates a formal incident management process defined in our Incident Response Plan and supporting procedures. We maintain pre‑defined playbooks for common events (e.g. malware, account compromise, service outage, data breach), covering detection, triage, containment, eradication and recovery. Incidents can be reported by users via our service desk, email, and direct escalation to the Security Operations team. Security events from logging, SIEM and our managed SOC are also raised as incidents. For significant incidents, we provide customers with incident reports that include timeline, impact assessment, root cause, remediation actions and preventive measures, in line with contractual and regulatory obligations.
- Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- No
- Free trial available
- Yes
- Description of free trial
- We offer a free START tier that provides access to core platform functionality, including a single workspace, unlimited users, and essential data science and workflow tools. Advanced features, enterprise governance, automation, and premium support are not included. The free version is not time-limited but is functionally restricted.
- Link to free trial
- https://lifebit.ai/lifebit-start-first-hand-try/
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 0%
- Between £500,001 and £1,000,000
- 0%
- Between £1,000,001 and £2,500,000
- 5%
- Between £2,500,001 and £5,000,000
- 10%
- Over £5,000,001
- 15%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- Yes
- Who accredited the ISO/IEC 27001
- SOCOTEC Certification UK Ltd
- ISO/IEC 27001 accreditation date
- Tuesday 31 January 2023
- What the ISO/IEC 27001 doesn’t cover
- The organisation does not have any outsourced development and therefore the control about supervising and monitoring the activity of outsourced system development from our statement of applicability does not apply.
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- Yes
- Who accredited the ISO 9001 certification
- SOCOTEC Certification UK
- ISO 9001 accreditation date
- Friday 12 September 2025
- What the ISO 9001 doesn’t cover
- The organisation does not have any outsourced development and therefore the control about supervising and monitoring the activity of outsourced system development from our statement of applicability does not apply.
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- 961b9f29-c097-4162-98ac-13baf466300d
- Cyber essentials plus
- Yes
- Please provide your Cyber Essentials Plus Certificate Number
- D98208db-38d6-4cd7-b77b-6ccd32dc2fbc
- Other security certifications
- Yes
- Any other security certifications
- FedRamp Marketplace Ready Certification
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- New or retained jobs on the contract workforce in the relevant area that meet the criteria set out in MAC 1b, 1c and 1d
- Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
- Plans to engage the contract workforce in deciding the most important workplace issues to address
- Monitoring of employee engagement rates (by protected characteristic) and, where necessary, the development of actions to ensure all voices are heard across the diversity of the workforce
- Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
- Entitlement to sick pay for the contract workforce, with provision in place for any staff who do not meet the earnings threshold for statutory sick pay, payment of sick pay from day one of absence and payment of staff on the contract workforce who are off sick a replacement income of 100% of their usual earnings for as long as possible
- Measures to support in-work progression to help people in the contract workforce, to move into higher paid work by developing new skills relevant to the contract
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.
- Delivery of apprenticeships, supported internships and T Level industry placement opportunities (Level 2, 3 and 4+) in relation to the contract
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 3: Resilient, innovative and flexible supply chains: Support economic growth through enabling resilient businesses, opportunities for small businesses and voluntary, community and social enterprises
- Understanding of the types of businesses in the market and the level of participation by new businesses, entrepreneurs, start-ups, SMEs, VCSEs and mutuals
- Plans for engaging a diverse range of businesses in engagement activities prior to appointing subcontractors (including activities prior to award of the main contract and during the contract term)
- Plans to respond flexibly and adapt approaches to community engagement and initiatives
-
Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero
Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.
- Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
- Understanding of how to influence staff, suppliers, customers, communities and/or any other appropriate stakeholders through the delivery of the contract to support climate and nature protection and improvement
- Activities to reconnect people with the environment and increase awareness of ways to protect and enhance it
-
Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain
Policy Outcome 6: Employment and training: For those who face barriers to employment
- Understanding of employment and skills issues, and of the skills and employment shortages of high growth sectors relating to the contract
- Understanding of the issues affecting the representation of disabled people in the workforce in the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors
- Understanding of the issues affecting inequality in employment, skills and pay in the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors. Measures to tackle inequality in employment, skills and pay in the contract workforce
-
Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain
Policy Outcome 7: Creating a pipeline of opportunities: For the contract workforce, reducing barriers to entry for under-represented groups.
- Understanding of issues relating to entering the contract workforce
-
Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.
Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.
- Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce
- Inclusive and accessible recruitment practices, development practices and retention policies that support-focused activities including those provided in the Guide for line managers on recruiting, managing and developing which support people with a disability or health condition
-