FUND DISTRIBUTION SCHEMES WITH FRAUD PREVENTION STRATEGIES
Opia offers a turnkey solution to administering Fund Distribution Schemes. Opia drives tax payer value by embedding AI and fraud prevention measures within a digital first solution.
Features
- Low Friction User Journeys
- AI enabled claim validation
- Fraud screening on claim
- OCR enabled and "Zero Touch" Claim Approval
- Omnichannel Fund distribution
- User Log In - OTP and MFA
- AA Accessibility and Inclusive UI Design
- Real Time Reporting and Tracking
- API Integration Capability
- Multi Currency Disbursement
Benefits
- Reduced cost to serve
- Consistent & reliable output
- Policy built into process
- Drives Tax-Payer value
- Reduced fraudulent activity
- Fast and Responsive Service to vulnerable users
- Audit Trail Capability
- Quick Launch Capability
Pricing
- Education pricing available
- Free trial available
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
5 6 1 0 7 8 1 4 5 6 3 5 6 4 9
Contact
OPIA LIMITED
Alex Catton
Telephone: 02080784290
Email: alex.catton@opia.com
About your service
- Service categories
-
Application Development and Deployment
Application platforms
- Model driven application platforms
- Multi cloud support
- Yes
Service scope
- Software add-on or extension
- No
- Cloud deployment model
- Public cloud
- Service constraints
-
Client sites maintain +99% uptime as we build redundancy into every part of our infrastructure.
We limit any backend infrastructure maintenance to a specific window of 01:00 to 04:00 UTC. None of our routine maintenance results in more than a momentary lapse in availability.
Any planned updates to the service would be run through a sandbox environment prior to update to minimise risk of disruption with a "rollback" feature enabled. Any action that would impact the service or infrastructure would be notified to the buyer prior to commencement. - System requirements
-
- Web Browser Access
- Secure Internet Connection via WiFi or Mobile Service
- Laptop, Phone or Tablet Access
- Access to 2 devices (only for MFA enabled services)
User support
- Email or online ticketing support
- Yes, at extra cost
- Support response times
-
Standard terms are two business days but we can adjust this to service requirements.
User Queries and Support Tickets are prioritied within our team once logged by the user. - User can manage status and priority of support tickets
- No
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), 7 days a week
- Web chat support
- Yes, at an extra cost
- Web chat support availability
- 9 to 5 (UK time), 7 days a week
- Web chat support accessibility standard
- WCAG 2.2 AA
- Web chat accessibility testing
- N/A
- Onsite support
- Yes, at extra cost
- Support levels
-
Opia Technical Support.
Included within all contracts is a Technical Account Manager within standard business hours of 9am - 5pm, Monday - Friday (excluding Bank and Public Holidays).
This relates to all services hosted by Opia, relating to the processing and distribution of funds. We operate a UK Based, human service to allow for accurate and fast response times.
Voucher and Pre-Paid Card Support.
The nature of disbursement schemes relies on the provision of Pre-Paid Cards and Retailer specific vouchers. Support directly related to the usage of the vouchers and prepaid cards are subject to the issuer. - Support available to third parties
- Yes
- AI chatbot
- No
Onboarding and offboarding
- Getting started
-
Yes, Opia have a dedicated onboarding journey which we outline in each of our mobilisation plans. We endeavour to complete these online via video meeting or face-to-face where possible. These will be available with sufficient time to allow for rollout and training.
Includes details such as:
Team Mobilisation to introduce key members of each team,
Briefing and Governance meetings to establish correct channels of communication and escalation processes. We will also agree meeting cadence and reporting requirements.
Scope Clarification and Confirmation; for any changes to product or service offering (if required)
By default, User guides to the platform are distributed via PDF or other preferred electronic medium. Optional Training Sessions pre-launch of service are offered to maximise a frictionless implementation.
Training Sessions cover; How to use the portal, how to raise support tickets, how to access reporting and a Q&A to ensure the users of the system are "Product Ready" when they have completed the session(s). - Service documentation
- Yes
- Documentation formats
-
- HTML
- ODF
- End-of-contract data extraction
-
During the exit and run-off period, users will benefit from practices defined under Opia's ISO27001.
Opia continues to deliver services in line with agreed service levels, security controls and data protection requirements. No material changes are made to systems, processes or resourcing without client agreement, ensuring stability until transition is complete.
Data Migration: We securely extract and transfer all service data, transaction history, and user accounts in agreed open formats (e.g., CSV, SQL) using secure protocols (SFTP/AWS S3). We ensure data integrity is validated with the client before final handover.
Knowledge Transfer and Documentation: We provide full operational asset registers, and knowledge transfer sessions to the incoming provider to ensure business continuity.This includes service handbooks, process maps, asset registers and configuration details. Structured knowledge transfer sessions are delivered to the incoming provider or internal team to ensure a smooth handover and minimise service disruption. - End-of-contract process
-
At the end of the contract, we operate a documented and tested exit process designed to ensure continuity, protect data, and minimise risk to the Client/Authority.
We maintain service access and full support until the agreed contract end date. An exit plan is agreed in advance and sets out clear timelines, responsibilities, and exit activities.
All customer data remains the property of the Client/Authority. We support secure data export in open, reusable formats, or verified deletion where required, in full compliance with UK GDPR and data protection legislation. Written confirmation of data transfer or destruction is provided.
We complete all final reporting, performance evidence, and financial reconciliation promptly. We cooperate fully with the Client/Authority or any successor supplier, providing structured knowledge transfer and reasonable assistance to enable a smooth, disruption‑free transition with no vendor lock‑in. - Documentation accessibility standard
- WCAG 2.2 AA
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Opera
- Other
- Application to install
- No
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
- Functionally identical. UI optimised for screen size and accessibility.
- Service interface
- Yes
- User support accessibility
- WCAG 2.2 AA
- Description of service interface
- The primary interface for the users would be a web portal/interface. Additional service interfaces may include reporting portals.
- Accessibility standards
- WCAG 2.2 AA
- Accessibility testing
-
Lighthouse and WAVE are used for automated baseline testing.
Manual testing addressed interaction, visual, contextual, and behavioural requirements.
Combined automated and manual testing provides broader coverage of WCAG 2.2 AA success criteria
Colour and Contrast
Semantic HTML & structure
Images & media (including alt text)
ARIA usage
Forms & inputs (Inputs have associated labels, Buttons have accessible names)
Keyboard & focus basics
Manual (keyboard, screen reader) - We have used NVDA and built in screen readers
Visual Testing
Contextual (meaning of text, instructions) - manual validation of alternative text
Behavioural (dynamic updates, errors) - API
- No
- Customisation available
- Yes
- Description of customisation
-
Our standard package includes basic customisation, however where more complex customisation is required we offer support within our most comprehensive support package.
What can be customised:
Voucher Configuration: For voucher schemes, users can customise the type and value of vouchers, set specific expiry dates, and schedule when voucher batches are issued.
User Accounts and Access: Administrators can create accounts for designated staff members and grant specific access rights.
Policy and Validity Criteria: Clients can customise what constitutes as evidence for valid claims and fund payouts.
real-time customised dashboards.
How users can customise:
Customisation are logged as support tickets and enter the approval flow with the client to be released at the next update sprint.
Opia offers included technical support and account support.
Who can customise
Designated Administrators: Specific client administrators can set up relevant departments, create user accounts, and allocate budgets. (Solution Specific)
Authorised Staff: Department staff with secure logins can issue platform alterations via Opia's ticketing system.
Scaling
- Independence of resources
-
We have in place work force planning managers and real time analysts responsible for monitoring real time and long term demands ensuring we maintain our agreed service level outlined in our contract.
Where we may see a spike in activity, we operate a shared resource centre model across our UK, in house agent base, which allows us to prioritise demand from other areas.
In extreme scenarios, we have established supply chains in place to recruit short term resource in the event temporary cover is needed.
Analytics
- Service usage metrics
- Yes
- Metrics types
-
Opia offers a comprehensive reporting suite. This ranges from call centre KPIs, such as
1) Contact handling SLA,
2) Volumes,
3) Escalations and exceptions,
4) Category of contact and categorisation of contact.
We also have the ability to report on delivery such as number of change requests or defects, categorisation of the issue or time spent on the issue by support staff. - Reporting types
-
- Real-time dashboards
- Regular reports
- Reports on request
- Resource tagging
- No
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Other security clearance
- Government security clearance
- Baseline Personnel Security Standard (BPSS)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
-
- European Economic Area (EEA)
- Other locations
- User control over data storage and processing locations
- No
- Datacentre security standards
- Supplier-defined controls
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- NCSC approved service provider
- Protecting data at rest
-
- Physical access control, complying with CSA CCM v4.0
- Physical access control, complying with SSAE-18 / ISAE 3402
- Physical access control, complying with another standard
- Encryption of all physical media
- Other
- Other data at rest protection approach
-
We implement encryption at rest at the storage/volume layer (database volume encryption), which is the ‘encryption of all physical media’ approach for protecting data from unauthorised disclosure in the event of physical media compromise.
AWS maintains CSA STAR certification against CCM v4.0 and their SOC audits are performed under SSAE 18. All key AWS elements we utilise are covered under the CSA STAR certification. - Data sanitisation process
- Yes
- Equipment disposal approach
- A third-party destruction service
- Data sanitisation type
- Deleted data can’t be directly accessed / Cryptographic Erasure
Data importing and exporting
- Data export approach
- By default there is no ability to export, however we offer the ability to make SARs accessible and will comply with all relevant GDPR regulation.
- Data export formats
- CSV
- Data import formats
- CSV
Data-in-transit protection
- Data protection between buyer and supplier networks
- TLS (version 1.2 or above)
- Data protection within supplier network
- Other
- Other protection within supplier network
- Data in transit is protected via HTTPS/TLS1.3. Additionally data is encrypted at rest with AES-256 at Database Volume level.
Availability and resilience
- Guaranteed availability
-
Platform SLAs:
Online Platform Availability
Target: 100% Availability (excluding planned maintenance)
Threshold: 99%
Credit: 0.5% of service charges for monthly charge per percentage point of non-availability
Unplanned Portal Downtime Resolution
Target: 0 instances of unscheduled downtime lasting >5 hours.
Threshold: >1 incident.
Credit: 0.5% service charges for monthly charge per incident over the target.
Where contracts are on a fixed term, a prorata monthly value will apply for calculation.
A comprehensive Service Credit Agreement would be confirmed based on client's specific SLA requirements across all deliverables of the contract. - Approach to resilience
-
We operate within Kubernetes, meaning any failure in virtual machines is rapidly remediated by spinning up images to replace and/or to increase capacity to cope with extra demands.
Additionally we operate in multiple AWS availability zones to account for data centre outages. - Outage reporting
-
Email notifications: When an incident meets our notification threshold (e.g., service unavailability, material degradation, or a security-related availability impact), we send an email update to nominated customer contacts and/or defined distribution lists.
Incident updates: During an active incident we provide periodic updates (including impact summary, affected components, workarounds if available, and current status).
Closure and RCA: Once resolved, we issue a closure notification and provide a post-incident summary. For significant incidents, this includes a root cause summary and corrective/preventative actions.
How customers subscribe / are included
Customers provide one or more nominated contacts during onboarding (or via account management). We maintain and regularly validate the distribution list as part of our customer and access management processes. Customers can request additions/removals at any time via support email / service desk.
Internal governance (supporting reliability)
Incidents are logged and managed through our incident management process, with severity levels and escalation paths to ensure timely communication and resolution. Notifications are initiated by the incident lead and reviewed by the responsible operational owner to ensure clarity and consistency.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Identity federation with existing provider (for example Google Apps)
- Other
- Other user authentication
-
Users access data via our secure Business Intelligence platform, hosted by Microsoft BI.
We enable external accounts with strict restrictions on a case by case basis as defined by the client.
We primarily utilise Microsoft 365 to enforce MFA linked directly to client accounts. If this option is not available, One-Time Passwords (OTPs) are used, ensuring we retain full access control. Public-facing solutions, such as claims portals, typically function without login requirements; however, specific authentication requirements can be defined on a case-by-case basis to align with Buyer security needs. - Access restrictions in management interfaces and support channels
-
Role-Based Access Control (RBAC) is used along with mandatory Multi-Factor Authentication (MFA).
We maintain separation for named accounts away from standard traffic. - Access restriction testing frequency
- At least once a year
- Management access authentication
- Multi-Factor Authentication (MFA)
Audit information for users
- Access to user activity audit information
- You control when users can access audit information
- How long user audit data is stored for
- At least 12 months
- Access to supplier activity audit information
- No audit information available
- How long system logs are stored for
- Between 1 month and 6 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
- ISO/IEC 27001
- Information security policies and processes
- Cyber Essentials Plus
- Software Security Code of Practice
- No
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
-
ITIL 4 Service Configuration Management and Change Enablement to control service components and introduce change safely.
Maintain a CMDB/service configuration records for configuration items (CIs) and their relationships (apps, infra, environments, integrations, data stores and third parties). CIs are version-controlled and linked to releases for full traceability from request → build → deployment.
All changes follow a standard flow (request → assess → authorise → implement → review) with risk-based approvals and controlled emergency change. Each change includes a security impact assessment. Security is embedded via CI/CD automated checks and peer review, with security sign-off for high-risk changes. - Vulnerability management type
- Supplier-defined controls
- Vulnerability management approach
-
Vulnerability management platform which operates across our staff devices and infrastructure.
Categorised by severity and/or category and indicates where patches may have a low rating but are actively known exploits in the wild.
Security patches on staff devices are applied within 14 days of release but normally sooner.
Patches on other systems fall in line with regular maintenance window updates.
Information on potential threats come from partnerships with multiple vendors with regular updates including daily roundups, ad-hoc alerts via email of emerging threats, and quarterly calls with our AV supplier to talk about threats, our platforms and best practices. - Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
- We identify potential compromises via centralised logging, endpoint and network monitoring, and automated alerting. IT personnel have 24/7 coverage via defined software, with oversight/escalation if not acknowledged, quarterly proactive log reviews to validate detection effectiveness. On detection, we follow a defined incident process: triage and scope using logs/telemetry, contain, coordinate escalation via specific named role and a cross-functional security group, remediate root cause, and document outcomes for audit and continuous improvement. Alerts are acknowledged within 1 business hour, and containment is initiated as soon as compromise is confirmed, typically the same business day, prioritised by risk.
- Incident management type
- Supplier-defined controls
- Incident management approach
-
We utilise an ITIL 4 Incident Management process to rapidly restore service, following a standard lifecycle from logging to closure.
High-impact events trigger our Major Incident path with defined escalation and communication protocols. We apply runbooks / SOPs for consistent triage of common issues.
Our Self-Serve portal allows users to raise issues via email, or Phone/Teams for urgency; monitoring alerts also trigger proactive tickets. We provide regular status updates and detailed post-incident reviews for Major Incidents, covering impact, root cause, resolution, and preventative actions. - Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- Yes
- Free trial available
- Yes
- Description of free trial
-
Included:
Access to the base platform without customisation for illustrative purposes.
Not included:
Basic levels included Fraud Prevention and Customer Support
Limited to set users to trial software, with limited transact volumes.
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 3%
- Between £250,000 and £500,000
- 6%
- Between £500,001 and £1,000,000
- 9%
- Between £1,000,001 and £2,500,000
- 12%
- Between £2,500,001 and £5,000,000
- 15%
- Over £5,000,001
- 18%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- Yes
- Who accredited the ISO/IEC 27001
- Approachable Certification Ltd
- ISO/IEC 27001 accreditation date
- Tuesday 25 March 2025
- What the ISO/IEC 27001 doesn’t cover
- N/A
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- Yes
- Who accredited the ISO 9001 certification
- Approachable Certification Ltd
- ISO 9001 accreditation date
- Tuesday 4 April 2023
- What the ISO 9001 doesn’t cover
- N/A
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- D76d0b21-864e-4d95-8229-90fda3a84af3
- Cyber essentials plus
- Yes
- Please provide your Cyber Essentials Plus Certificate Number
- 13a20449-714d-4140-86eb-763de7350648
- Other security certifications
- No
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain
Policy Outcome 6: Employment and training: For those who face barriers to employment
- Creation of employment opportunities particularly for those who face barriers to employment, such as prison leavers, care leavers and/or who are located in deprived areas, and for people in industries with known skills shortages or in high growth sectors
- Inclusive and accessible development practices, including guidance for line managers on recruiting, managing and developing people with a disability or health condition
-