Naviam Cloud and Cloud+ Service
Naviam Cloud combines, enterprise-grade cloud architecture, and exclusive Naviam-built IP to provide a complete, integrated EAM ecosystem with IBM Maximo EAM ecosystem as its core. The platform simplifies cloud operations, enhances user productivity, and ensures continuous system optimisation executed more efficiently than traditional hosting or self-managed EAM environments.
Features
- Hosted IBM Maximo Application Suite delivered as secure SaaS
- Multi-cloud deployment across AWS, Azure, or customer-hosted environments
- Dedicated or shared OpenShift platforms with logical tenant isolation
- Role-based access control integrated with enterprise identity providers
- Built-in asset lifecycle, maintenance, and reliability management
- Integrated inventory, procurement, and materials management capabilities
- REST APIs for integrations with enterprise and operational systems
- Configurable workflows and automation using Maximo business rules
- High availability architecture with defined SLAs, RTO and RPO
- Centralised monitoring, logging, backup and recovery services
Benefits
- Manage assets and maintenance processes through a single platform
- Reduce unplanned downtime through proactive maintenance and monitoring
- Improve operational visibility across assets, locations, and teams
- Standardise asset management practices across organisations and suppliers
- Access the service securely from any location with internet connectivity
- Scale environments easily as asset portfolios and users grow
- Reduce infrastructure overhead through fully managed cloud hosting
- Enable faster issue resolution with integrated workflows and alerts
- Support compliance through auditable maintenance and asset records
- Simplify upgrades and patching with managed service delivery
Pricing
- Education pricing available
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
2 3 1 1 2 2 7 4 9 6 2 1 9 3 2
Contact
Naviam Technologies Limited
Matt Deadman
Telephone: +44 (0) 77168 32204
Email: salesops.uk@naviam.io
About your service
- Service categories
-
Applications
Enterprise resource management
- Procurement
- Order management and orchestration
- Enterprise performance management
- Project and portfolio management
- Asset life-cycle management
- Multi cloud support
- Yes
Service scope
- Software add-on or extension
- Yes, but can also be used as a standalone service
- What software services is the service an extension to
- The Naviam Elevate own IP Software Suite, Offers onboarding accelerators, Mobile Solutions, enhanced Data transfers Improved Planning functionality , and GIS to complete a unified toolkit that improves efficiency, strengthens insight, and modernises how your teams operate. Every solution remains compatible with new Maximo releases and is automatically updated.
- Cloud deployment model
- Hybrid cloud
- Service constraints
- The service operates within agreed service tiers and standard maintenance arrangements. Planned maintenance may be required for upgrades and security updates, with advance notice provided where possible. Certain features or integrations may depend on the chosen deployment model and customer environment.
- System requirements
-
- Modern supported web browser with JavaScript enabled
- Internet connectivity to access the hosted service
- User device capable of running a supported browser
- Compatible identity provider for single sign-on, if required
- API access for supported system integrations
User support
- Email or online ticketing support
- Yes
- Support response times
-
P1: 30–60 minutes
P2: within 2 business hours
P3 / P4: within 8 business hours - User can manage status and priority of support tickets
- Yes
- Online ticketing support accessibility
- None or don’t know
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), 7 days a week
- Web chat support
- Yes
- Web chat support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support accessibility standard
- None or don’t know
- How the web chat support is accessible
- Our support portal provides customers with a secure, authenticated channel to raise and manage support requests. Users can submit tickets, supply detailed incident information (such as environment, severity, and supporting evidence), and track progress throughout the ticket lifecycle. Requests are automatically logged into the service desk system, prioritised according to defined severity levels, and routed to the appropriate support teams. The portal supports structured triage, SLA tracking, escalation management, and auditability, aligned with ITIL best practices. Status updates and communications are provided throughout investigation and resolution. Where required by the contract or framework, we are open to assessing and aligning the support portal to relevant accessibility standards as part of service onboarding or ongoing service improvement.
- Web chat accessibility testing
- Our support portal provides customers with a secure, authenticated channel to raise and manage support requests. Users can submit tickets, supply detailed incident information (such as environment, severity, and supporting evidence), and track progress throughout the ticket lifecycle. Requests are automatically logged into the service desk system, prioritised according to defined severity levels, and routed to the appropriate support teams. The portal supports structured triage, SLA tracking, escalation management, and auditability, aligned with ITIL best practices. Status updates and communications are provided throughout investigation and resolution. Where required by the contract or framework, we are open to assessing and aligning the support portal to relevant accessibility standards as part of service onboarding or ongoing service improvement.
- Onsite support
- Yes, at extra cost
- Support levels
-
We provide multiple, scalable support levels aligned to ITIL best practices. Standard Support is included within the core service cost and covers incident management across all priority levels (P1–P4) during UK business hours (Monday–Friday, 08:30–17:00). This includes ticket triage, prioritisation, investigation, resolution, and escalation management with defined SLA-backed response and resolution targets. Priority 1 (system down) incidents are included within standard support during service hours.
Extended or Premium Support is available at additional cost and may include 24×7 coverage for Priority 1 incidents outside normal business hours, service requests, user assistance, minor configuration changes, and small enhancement activities. Premium Support is typically priced as an uplift to the base service, with indicative uplifts in the region of 10–25%, depending on coverage hours, scope, and service complexity.
We also offer flexible Service Delivery options at additional cost, ranging from light-touch service oversight to a dedicated Service Delivery Manager or Technical Account Manager. This provides a named point of contact responsible for service governance, escalation coordination, reporting, and proactive service improvement. Service Delivery and Technical Account Management services are generally priced on a time-and-materials basis, with indicative day rates of £750–£1,200, subject to contract and engagement scope - Support available to third parties
- Yes
- AI chatbot
- No
Onboarding and offboarding
- Getting started
-
We support users in getting started through a structured onboarding and enablement approach tailored to the customer’s needs. This includes service onboarding, environment setup, user access configuration, and validation to ensure the service is ready for use. User Acceptance Testing (UAT) environments and support are provided to allow customers to validate functionality, integrations, and configurations prior to go-live.
Users are supported through a combination of user documentation, online knowledge resources, and guided walkthroughs covering core functionality and common tasks. Training options are available to suit different learning needs and may include online sessions, remote instructor-led training, and, where required, onsite training at additional cost.
Following go-live, a defined hypercare period can be provided to offer enhanced support, closer monitoring, and rapid issue resolution during early adoption. For larger or more complex deployments, onboarding and hypercare may be overseen by a Service Delivery Manager to ensure a smooth transition into business-as-usual support. - Service documentation
- Yes
- Documentation formats
-
- HTML
- End-of-contract data extraction
-
At the end of the contract, users can extract their data through a structured offboarding process. Data can be exported from the service in commonly used, non-proprietary formats, subject to security and governance controls. Where required, data extraction can be supported via system export tools or APIs, and validated to ensure completeness and integrity.
Offboarding activities, including data extraction, are planned and agreed with the customer in advance to minimise disruption. Where additional assistance is required (for example, large data volumes, complex integrations, or specific formats), this can be provided as a scoped, chargeable service. Once data extraction has been completed and confirmed by the customer, access to the service is removed in line with contractual and security requirements. - End-of-contract process
- At the end of the contract, the service enters a structured offboarding phase agreed with the customer. This includes confirmation of contract end dates, coordination of data extraction, and planning of service decommissioning. Customers are supported in exporting their data in agreed, commonly used formats using standard export tools or APIs where applicable. Once data extraction has been completed and validated by the customer, user access is removed and the service is decommissioned in line with security, data protection, and contractual requirements. Data is then securely deleted in accordance with agreed retention policies. The contract price includes standard contract close-down activities, support for data extraction using standard tools and processes, removal of user access, service decommissioning, and secure deletion of customer data. Additional costs may apply where bespoke or large-scale data extraction is required, where data transformation or migration to third-party systems is requested, where extended offboarding or transition support is needed, or where onsite support or consultancy is requested.
- Documentation accessibility standard
- WCAG 2.2 AA
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Other
- Application to install
- No
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
- The service has been designed to support mobile access. Core functionality is available via a web-based interface that can be accessed on mobile devices using a supported browser. In addition, dedicated mobile applications may be provided where included in scope to extend specific functionality for mobile and field-based users. Mobile access typically focuses on task execution, data capture, and operational activities, while the desktop interface provides the full range of configuration, administration, and reporting capabilities. Mobile and desktop services share the same underlying data and security controls, with role-based access applied consistently.
- Service interface
- Yes
- User support accessibility
- WCAG 2.2 AA
- Description of service interface
- The service provides a secure, web-based service interface that allows users to access and manage the system through a supported browser. The interface is role-based, ensuring users only see functions and data relevant to their responsibilities. It supports operational tasks, administration, reporting, and configuration activities, with consistent navigation and controls across environments. Access is authenticated and governed by organisational security policies, and the interface integrates with supporting tools such as the support portal for incident management and service requests.
- Accessibility standards
- WCAG 2.2 AA
- Accessibility testing
-
Accessibility testing for the service interface is primarily underpinned by the accessibility assurance activities carried out by IBM for the underlying platform, which include assessment against recognised accessibility standards and validation using common assistive technologies such as screen readers and keyboard-only navigation.
In addition, accessibility considerations are taken into account during implementation and configuration to ensure that customer-specific customisations do not introduce unnecessary barriers. This includes reviewing layouts, navigation structures, and form configurations to support keyboard access and screen reader usability where possible.
While we do not routinely conduct bespoke assistive-technology user testing for every deployment, we are open to supporting additional accessibility validation, user testing, or reasonable adjustments where required by contract, regulation, or specific customer needs. This can be addressed during service onboarding or as part of ongoing service improvement activities. - API
- Yes
- What users can and can't do using the API
-
Users can use the service APIs to integrate the service with other systems and to automate data exchange and operational processes. Typical API use cases include reading and updating business data, synchronising records, triggering workflows, and supporting integrations with third-party applications such as ERP, GIS, or reporting tools. APIs may also be used to support aspects of service configuration, such as user or data provisioning, where this is enabled and within scope.
Changes made via the API are subject to the same security, role-based access controls, and validation rules as changes made through the user interface. Users cannot use the API to bypass governance controls, alter core platform behaviour, or make unsupported structural changes. Certain administrative, infrastructure, or system-level configurations must be performed through the service interface or by authorised service personnel.
API capabilities and limits may vary depending on the product, deployment model, and contractual scope, and are governed by rate limits, authentication requirements, and supported operations defined in the service documentation. - API documentation
- Yes
- API documentation formats
-
- HTML
- Other
- API sandbox or test environment
- Yes
- Customisation available
- Yes
- Description of customisation
-
The service supports configuration and customisation to meet customer-specific requirements while maintaining platform stability and vendor support. Customisable elements include workflows, forms, screens, reports, dashboards, user roles, permissions, and integrations with external systems. Business rules, automation scripts, and data views can also be configured where supported by the platform.
Customisation is carried out using built-in configuration tools within the service interface, supported APIs, and approved extension mechanisms. Changes are typically implemented in non-production environments and progressed through controlled release and change management processes.
Customisation may be performed by authorised customer administrators for low-risk configuration, by approved third-party partners, or by the supplier’s specialist development and service delivery teams for more complex changes. The development team can design, build, and test enhancements or integrations where requirements go beyond standard configuration, working within supported frameworks to ensure security, performance, and upgrade compatibility.
Unsupported customisations that would compromise platform integrity or supportability are not permitted. Core platform behaviour and infrastructure remain under supplier control.
Scaling
- Independence of resources
- The service is designed to ensure customer usage is isolated and not adversely affected by the demand of other users. Resources are logically separated by customer and environment, with role-based access controls and governed workloads. The service supports named and concurrent licensing models, which are regularly audited to ensure they are appropriately sized and do not create contention. Capacity and utilisation are continuously monitored, and capacity tipping-point metrics are used to identify when growth in users or activity may impact resources or licensing limits. This provides predictability and enables proactive scaling to maintain performance
Analytics
- Service usage metrics
- Yes
- Metrics types
- The service provides usage and operational metrics, such as service usage, system activity, and support performance, which can be used for monitoring, reporting, and service management purposes (subject to role-based access and configuration).
- Reporting types
-
- Real-time dashboards
- Regular reports
- Reports on request
- Resource tagging
- Yes
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Reseller providing extra features and support
- Organisation whose services are being resold
- IBM
Staff security
- Staff security clearance
- Conforms to BS7858:2019
- Government security clearance
- Security Clearance (SC)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
-
- United Kingdom
- European Economic Area (EEA)
- Other locations
- User control over data storage and processing locations
- Yes
- Datacentre security standards
- Complies with a recognised standard (for example CSA CCM version 4.0)
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- Another external penetration testing organisation
- Protecting data at rest
-
- Physical access control, complying with CSA CCM v4.0
- Encryption of all physical media
- Other
- Other data at rest protection approach
- Data at rest is protected through layered security controls in addition to physical protections. Logical access to data is restricted using role-based access controls and least-privilege principles. Encryption keys are securely managed and access to keys is tightly controlled. Data is segregated by customer and environment to prevent unauthorised access. Regular backups are taken and stored securely, with controls in place to protect backup data and support recovery. Monitoring and audit logging are used to detect unauthorised access and support ongoing security assuran
- Data sanitisation process
- Yes
- Equipment disposal approach
- Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
- Data sanitisation type
-
- Deleted data can’t be directly accessed / Cryptographic Erasure
- Data Erasure
Data importing and exporting
- Data export approach
- Users can import and export data as part of normal service use using built-in tools, supported APIs, and Mx+ Data Studio, a proprietary data management solution developed by Naviam. Mx+ Data Studio enhances standard data handling through bulk data upload and extraction, real-time validation, error highlighting, and controlled data editing before changes are committed to the core system. All data import and export activities are governed by role-based access controls, ensuring users can only perform actions aligned to their permissions. Security, audit logging, and validation rules are enforced throughout to maintain data integrity, confidentiality, and system performance.
- Data export formats
-
- CSV
- Other
- Other data export formats
-
- CSV
- JSON
- XML
- TSV
- TXT
- Data import formats
-
- CSV
- Other
- Other data import formats
-
- JSON
- XML
- TSV
Data-in-transit protection
- Data protection between buyer and supplier networks
-
- TLS (version 1.2 or above)
- Other
- Other protection between networks
- Data transmitted between the buyer’s network and the service is protected using strong encryption in transit and secure access controls. All connections use modern TLS encryption, with managed certificates and secure protocol configurations. Access to the service is authenticated and authorised using role-based access controls to ensure only permitted users and systems can exchange data. API endpoints and data transfer interfaces are protected using the same encrypted channels and authentication mechanisms. Network traffic is monitored and logged to detect anomalous or unauthorised activity, supporting the confidentiality and integrity of data as it moves between networks
- Data protection within supplier network
-
- TLS (version 1.2 or above)
- Other
- Other protection within supplier network
- Data within the service network is protected using encrypted communications between internal components and strong access controls. Internal service-to-service traffic uses secure, authenticated connections, and network segmentation is applied to limit the exposure of sensitive components. Access to systems and data is restricted through role-based permissions and least-privilege principles. Monitoring and logging are used to detect anomalous activity and support ongoing security assurance, helping to maintain the confidentiality and integrity of data as it moves within the network.
Availability and resilience
- Guaranteed availability
-
For Naviam-hosted production services, the availability target is 99.99% availability per calendar month, as defined in the Service Level Agreement (SLA). Availability is measured monthly and excludes agreed maintenance windows and events outside the supplier’s reasonable control.
Priority 1 (Critical / System Down): Complete loss of service for all users. Target response within 30 minutes during service hours.
Priority 2 (High): Significant degradation or partial service outage. Target response within 2 business hours.
Priority 3 (Medium): Limited impact with workaround available. Target response within 8 business hours.
Priority 4 (Low): Minor issue or request. Target response within 8 business hours.
Where the 99.5% availability target is not met, customers may be eligible for service credits, calculated in accordance with the SLA and applied as a credit against future service charges. Service credits are the customer’s sole and exclusive remedy for failure to meet availability targets, unless otherwise stated in the contract. - Approach to resilience
-
The service is designed with resilience built into both the application and hosting layers. It is deployed within secure, third-party cloud datacentres that provide resilient power, cooling, physical security, and network connectivity, with redundancy across critical infrastructure components. Datacentres are operated in line with recognised security and resilience standards and are monitored continuously.
At the service level, resilience is supported through controlled deployment practices, monitoring and alerting, regular backups, and defined incident and escalation processes. Capacity and utilisation are monitored to ensure the service can scale predictably as demand changes. Licensing models and usage thresholds are reviewed to prevent contention and maintain performance.
Resilience arrangements, including detailed datacentre architecture, redundancy models, and recovery capabilities, are available to customers on request or under appropriate confidentiality arrangements. This approach aligns with the UK government’s Asset Protection and Resilience principle while balancing transparency with security. - Outage reporting
-
The service reports outages through direct communication with affected customers. Service incidents and outages are communicated via email notifications to designated customer contacts, with updates provided in line with defined incident severity and SLA commitments. Outages and service-impacting issues are also tracked and managed through the support portal, where customers can view status updates and incident progress.
The service does not currently provide a public status dashboard or API specifically for outage reporting. Where required by contract, enhanced reporting or alternative communication arrangements can be agreed as part of the service delivery model.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Identity federation with existing provider (for example Google Apps)
- Username or password
- Other
- Other user authentication
- Authentication is enforced through role-based access controls and centrally managed identity policies, ensuring users can only access functions and data appropriate to their role. Authentication events are logged and monitored to support security auditing and incident response.
- Access restrictions in management interfaces and support channels
- Access to management interfaces and support channels is restricted using role-based access controls and least-privilege principles. Administrative functions are limited to authorised users with appropriate permissions, and access is protected through authenticated user accounts, with MFA applied where configured. Support access is restricted to designated customer contacts who are authorised to raise and manage tickets. User access and permissions are reviewed regularly, and all access activity is logged and monitored to support audit, security monitoring, and incident investigation.
- Access restriction testing frequency
- At least once a year
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Identity federation with existing provider (for example Google Apps)
- Username or password
- Other
- Description of management access authentication
- Management access is further restricted using role-based access controls, least-privilege permissions, and logging of all administrative actions for audit and security monitoring.
Audit information for users
- Access to user activity audit information
- Users contact the support team to get audit information
- How long user audit data is stored for
- At least 12 months
- Access to supplier activity audit information
- Users contact the support team to get audit information
- How long supplier audit data is stored for
- At least 12 months
- How long system logs are stored for
- At least 12 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
-
- ISO/IEC 27001
- Other
- Other security governance standards
- Our security governance complies with ISO/IEC 27001 and is supported by additional recognised standards including SOC 2 Type II, ISO 9001, and Cyber Essentials, demonstrating effective information security controls, quality management processes, and baseline cyber security protections in line with UK government requirements.
- Information security policies and processes
- We operate a formal information security management framework aligned to ISO/IEC 27001, supported by documented policies covering access control, data protection, incident management, risk management, and business continuity. Security governance is overseen by senior management, with defined roles and responsibilities for information security. Compliance with policies is enforced through role-based access controls, mandatory training, regular risk assessments, internal audits, and independent assurance through certifications such as ISO 27001 and SOC 2 Type II. Security incidents are reported, managed, and reviewed through defined escalation and reporting processes to ensure continual improvement.
- Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Configuration and change management approach
- Service components are tracked throughout their lifecycle using controlled configuration and asset management processes covering environments, configurations, and software versions. Changes, patches, and planned maintenance are managed through a formal change management process that includes security and impact assessment, approval, testing, and controlled deployment. Security patches are prioritised based on risk and severity, with critical vulnerabilities addressed urgently. Planned maintenance is scheduled in advance and coordinated with customers where possible, with notice provided to support preparation and minimise disruption. Changes are tested in non-production environments before release, and all activity is logged to ensure traceability, auditability, and rollback where required.
- Vulnerability management type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Vulnerability management approach
- We operate a formal vulnerability management process aligned with recognised security standards. Potential threats are identified through vulnerability scanning, penetration testing, risk assessments, and review of system configurations. Vulnerabilities are assessed based on severity, exploitability, and potential service impact. Security patches are prioritised accordingly, with critical vulnerabilities addressed urgently and lower-risk issues remediated through scheduled patching cycles. Information about emerging threats is obtained from vendor security advisories, cloud and platform providers, industry threat intelligence feeds, and security community alerts. All remediation activity is tracked to ensure timely resolution and auditability.
- Protective monitoring type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Protective monitoring approach
- We operate protective monitoring processes aligned to recognised security standards. Potential compromises are identified through continuous monitoring of system logs, security alerts, and service activity, supported by automated alerting and periodic review. When a potential compromise is detected, incidents are investigated promptly in line with defined incident management procedures, including containment, remediation, and escalation where required. Response actions are proportionate to the severity and impact of the incident. Security incidents are prioritised based on risk, with critical incidents responded to immediately and managed through established incident response and escalation processes, including customer notification where appropriate.
- Incident management type
- Complies with a recognised standard, for example, CSA CCM v4.0 or ISO/IEC 27035:2011 or SSAE-18 / ISAE 3402
- Incident management approach
- We operate defined incident management processes aligned to recognised standards and ITIL practices. Pre-defined procedures exist for common incident types, including service outages, security incidents, and performance degradation. Users can report incidents via the support portal, email, or phone during service hours, with incidents prioritised by severity and managed against defined SLAs. Incident progress and resolution are communicated through regular status updates, and post-incident reports can be provided where appropriate, including details of cause, impact, actions taken, and preventative measures.
- Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- Yes
- Free trial available
- No
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 10%
- Between £500,001 and £1,000,000
- 20%
- Between £1,000,001 and £2,500,000
- 30%
- Between £2,500,001 and £5,000,000
- 40%
- Over £5,000,001
- 50%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- Yes
- Who accredited the ISO/IEC 27001
- British Assessment Bureau
- ISO/IEC 27001 accreditation date
- Thursday 6 March 2025
- What the ISO/IEC 27001 doesn’t cover
- Its not clear what is in scope on the certification I have . I will happily follow up with that clarity as part of the evaluation process
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- Yes
- Who accredited the ISO 9001 certification
- British Assessment Bureau
- ISO 9001 accreditation date
- Thursday 23 January 2025
- What the ISO 9001 doesn’t cover
- Its not clear what is in scope on the certification I have . I will happily follow up with that clarity as part of the evaluation process
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- No
- Cyber Essentials Alternative
- None of the criteria
- Cyber essentials plus
- No
- Cyber Essentials Alternative
- None of the criteria
- Other security certifications
- Yes
- Any other security certifications
-
- SOC 2 Type 2
- ISO27017
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
- Plans to engage the contract workforce in deciding the most important workplace issues to address
- Ensuring new workers are informed of their right to join a trade union
- Activities that support an environment where staff are educated about, and feel empowered to, address their physical wellbeing
- Activities that support an environment where staff are educated about and feel empowered to report and address bullying and harassment
- Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
- Entitlement to sick pay for the contract workforce, with provision in place for any staff who do not meet the earnings threshold for statutory sick pay, payment of sick pay from day one of absence and payment of staff on the contract workforce who are off sick a replacement income of 100% of their usual earnings for as long as possible
- Measures to support in-work progression to help people in the contract workforce, to move into higher paid work by developing new skills relevant to the contract
- Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
- Understanding of the modern slavery risks and issues affecting the market, industry, sector or country (of origin or of source) relevant to the contract, and the workforce in the supplier’s own organisation and those of its key subcontractors
- Outline policies and practices to be applied to or put in place for the contract to mitigate and manage modern slavery risks, including: Pre-employment checks, recruitment practices. Workplace conditions, safeguarding plans and processes in place and regular monitoring with relevant groups considered, which may include sampling
- How these flow down the supply chain and are monitored Illustrative examples include reporting, site visits, audits, etc.
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.
- Understanding of employment and relevant skills issues, and of the education and training issues relating to the contract. Illustrative examples: demographics, skills shortages, new opportunities in high growth sectors, geographic/local community and skills/employment challenges
- Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
- Activities to support relevant sector related skills growth and sustainability in the contract workforce. Illustrative examples: careers talks, curriculum support, literacy support, safety talks and volunteering
-