Barrier Networks Third Party Risk Management (Prevalent TPRM)
Prevalent simplifies third-party risk management, combining software, intelligence and services to cut vendor security, compliance and supply-chain exposure. Its hybrid approach delivers fast ROI via automated assessments, continuous monitoring and managed assessment services. Trusted worldwide, it provides data-driven, unified, prescriptive insights plus remediation playbooks to build scalable vendor risk programs.
Features
- Automated Vendor Onboarding & Offboarding
- Risk Assessment Library
- Continuous Monitoring
- Unified Risk Register
- Automated Risk Scoring
- Vendor Remediation Workflow
- Compliance-Specific Reporting
- Document & Evidence Management
- Inherent Risk Scoring
- Fourth-Party Mapping
Benefits
- Eliminate spreadsheets to reduce manual labor, errors and duplicate work.
- Automate collection and analysis with consistent scoring across the organization.
- Validate risks against assessment results and fill gaps between assessments.
- Simplify remediation by normalizing monitoring data
- Quickly gauge risk
- Streamline compliance with report templates
- Accelerate auditing and reporting with centralized documentation and supporting evidence.
Pricing
- Education pricing available
- Free trial available
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
7 4 4 0 6 2 5 5 5 6 5 9 9 6 3
Contact
BARRIER NETWORKS LIMITED
Iain Slater
Telephone: 0141 356 0101
Email: sales@barriernetworks.com
About the service
- Service categories
-
Systems Infrastructure Software
Security
- Governance, risk and compliance
- Multi cloud support
- No
Service scope
- Software add-on or extension
- No
- Cloud deployment model
- Public cloud
- Service constraints
- No
- System requirements
- N/A
User support
- Email or online ticketing support
- Yes
- Support response times
- Mitratech provides support 8:00 AM Monday to 2:00 AM Saturday GMT, excluding public holidays. Response targets depend on severity. Level 0 (managed hosting/SaaS) covers a hosted system that is down or unusable; response within 1 hour and work continues until fixed. Level 1 is a critical outage or data integrity issue with no workaround; response within 2 business hours, continuous remediation, and optional on-site technician after 24 hours (billable). Level 2 disruption; response within 4 business hours and efforts for a workaround. Level 3 faults; response within 1 business day. Level 4 low-impact issues or inquiries handled as time permits.
- User can manage status and priority of support tickets
- Yes
- Online ticketing support accessibility
- WCAG 2.2 AA
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- No
- Onsite support
- Yes, at extra cost
- Support levels
- Support is included with the subscription, covering hosting, security, warranty, maintenance, upgrades, and software repairs. Most clients—including large global organizations—find standard support within the annual license sufficient. 24x7 support is rarely needed but can be provided for an additional fee, and premium support packages can be customized to specific requirements. Support is delivered by tier 1, 2, and 3 engineers; new team members complete a rigorous training bootcamp and case shadowing before handling cases independently. If an issue cannot be resolved by support, engineers can escalate directly to Engineering and Professional Services. Clients can request case escalation or reprioritization by informing their Support Engineer, and may also contact the Technical Support Manager to raise concerns or request priority changes; contact details will be provided upon contract.
- Support available to third parties
- Yes
Onboarding and offboarding
- Getting started
-
"Throughout implementation, each client will have access to a dedicated consultant and Customer Success Manager (CSM) to allow for a prescriptive approach in training. Mitratech offers a structured approach to training. Training sessions are a combination of pre-recorded demonstrations and live training with our subject matter experts. During the live training, participants will engage in initial familiarization, configuration walkthroughs, and guided pilot assessments using actual vendors. Each training session is designed to be interactive, with an agenda presented at the start, followed by screen sharing to walk through the relevant functional areas. Participants are encouraged to ask questions throughout the sessions to enhance understanding and engagement.
Sessions will be recorded for review by your teams and supported by an operating manual to detail the program specifics. Additional guidance and user documentation is provided through our online support portal, accessible through the tool itself. After implementation, additional training and support is available through a dedicated CSM who is on hand to respond to ad hoc queries, guide you in the solution, and provide updates and training on new features as they are released." - Service documentation
- Yes
- Documentation formats
-
- HTML
- End-of-contract data extraction
- Upon termination and customer's request within 30 days after termination, Mitratech will make customer data available for download in a agreed upon format. Clients can extract their data through reports, CSV/XLSX exports, or API access. By default, the data will be securely deleted after (30) days of the termination of service, or as per the terms of the contract.
- End-of-contract process
-
"Mitratech's pricing model is transparent, flexible, and designed to cater to the specific needs and requirements of individual clients. The pricing model includes the cost of software licensing (including managed services in some cases), implementation services, maintenance, and support. The metrics that our pricing models are based on relate to each customer's individual requirements.
The software licensing model is an annual subscription, which includes the licensing, hosting, maintenance and support, providing ongoing technical support, software upgrades, and system maintenance to ensure that the system is functioning optimally.
The implementation project is a one-time professional services investment that includes tasks such as scoping and design of the system, configuration, testing, training and project management. Implementation is traditionally time and materials, therefore client only pays for the hours used to support your implementation." - Documentation accessibility standard
- WCAG 2.2 AA
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Application to install
- No
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
- Our solution is a next generation cloud-based SaaS, which can be run on any mobile device capable of running a latest generation browser and providing sufficient screen space for necessary content. The user interface employs responsive design, adapting to different screen sizes and resolutions to ensure optimal viewing and interaction across various mobile devices. No add-ins, apps, or special configurations are needed.
- Service interface
- Yes
- User support accessibility
- None or don’t know
- Description of service interface
- Prevalent TPRM is a unified, cloud-based platform designed for usability and a consistent interface. Built with a custom PHP front-end web UI, it provides each user a personalized dashboard highlighting their open and pending tasks. Third-party dashboards track assessment completion progress, while advanced reporting delivers overall status and progress across vendors. Heavy investment in product design and user testing ensures intuitive navigation that requires minimal training and support.
- Accessibility standards
- None or don’t know
- Description of accessibility
- We recognize the importance of providing an inclusive and accessible digital environment that empowers all users. We are continually improving the user experience and applying relevant accessibility standards to achieve this goal. We are committed to make our website accessible align with the Web Content Accessibility Guidelines (WCAG), and ensuring our digital content and platforms are accessible to individuals with various disabilities, including mobility, auditory, cognitive, and visual impairments.
- Accessibility testing
- We have dedicated resources for regular website reviews and continuous content updates to enhance accessibility and usability. Accessibility is an ongoing effort, and we are committed to making our digital platforms accessible to the widest possible audience, regardless of technology or ability. We aim to adhere to the best practices by following the principles of universal design, ensuring we provide a seamless experience for all our users.
- API
- Yes
- What users can and can't do using the API
- Integrations are enabled through Prevalent's REST API, which includes 150+ endpoints for data exchange. Custom integrations can be developed through the open API framework and Connector Marketplace with 150+ technology integrations for extending capabilities. Integrations are scoped independently of implementation, and can be facilitated through Mitratech's internal teams, or we provide the flexibility to our customers, should they wish to manage an integration themselves. Some native integrations are already included as part of our offering, including Mitratech's chosen intelligence feed partners such as CreditSafe, Acuris, Crunchbase and Sustainalytics.
- API documentation
- Yes
- API documentation formats
- Open API (also known as Swagger)
- API sandbox or test environment
- Yes
- Customisation available
- Yes
- Description of customisation
- Users have the option to customize through configuration. Every client will have a dedicated consultant who will configure the dedicated instance on behalf of client during implementation, ensuring the requirements are met. Individual user dashboards are configurable for preferences on the landing page. With additional configuration capabilities to match workflows, assessment content, risk scoring, terminology, branding, and reports. The implementation allows for a certain level of customization to ensure that system meets customer requirements.
Scaling
- Independence of resources
- The application is designed to be scalable, allowing additional computing resources to be allocated automatically or on demand as user traffic increases. This ensures consistent performance and reliability even as more users are added to the system. The number of users the application can support depends on several factors, including system configuration, available infrastructure resources, database performance, and the complexity of user operations. The architecture supports horizontal scaling, meaning additional instances or resources can be added to handle higher loads, allowing the application to support anything from a small user base to a large number of concurrent users as needed.
Analytics
- Service usage metrics
- Yes
- Metrics types
-
License utilisation and key metrics on data
contained in the platform. - Reporting types
-
- API access
- Real-time dashboards
- Regular reports
- Reports on request
- Resource tagging
- No
- FOCUS resource tagging
- No
Supplier type
- Supplier type
- Reseller (no extras)
- Organisation whose services are being resold
- Mitratech Prevalent
Staff security
- Staff security clearance
- Other security clearance
- Government security clearance
- Developed Vetting (DV)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
-
- United Kingdom
- European Economic Area (EEA)
- Other locations
- User control over data storage and processing locations
- Yes
- Datacentre security standards
- Managed by a third party
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- Another external penetration testing organisation
- Protecting data at rest
- Other
- Other data at rest protection approach
- All data at rest in databases and file storage uses AES-256 encryption, with encryption keys managed through AWS Key Management Service (KMS). The solution implements Single Sign-On and multi-factor authentication through Duo Authenticator. All encryption algorithms are FIPS 140-2 approved, and access activities are logged in CloudTrail for auditing purposes.
- Data sanitisation process
- Yes
- Equipment disposal approach
- A third-party destruction service
- Data sanitisation type
- Data Erasure
Data importing and exporting
- Data export approach
- Prevalent TPRM enables comprehensive bulk data exchange through standardized formats. The system supports bulk import and export of entity information, questionnaire submissions, risk library data, and custom attributes. Data can be imported via spreadsheet templates, intake forms, or API connections. Exports are available in Excel, CSV, and PDF formats for risk registers, controls, questionnaire responses, and entity information. Templates ensure proper field mapping and data alignment. The platform allows authorized users to manage these capabilities directly through the UI with appropriate permissions.
- Data export formats
-
- CSV
- Other
- Other data export formats
-
- XLS
- Data import formats
- CSV
Data-in-transit protection
- Data protection between buyer and supplier networks
- TLS (version 1.2 or above)
- Data protection within supplier network
- TLS (version 1.2 or above)
Availability and resilience
- Guaranteed availability
-
"Mitratech's standard contractual SLA for the TPRM platform is 99.0% uptime. Client must request, in writing, any credit due within thirty (30) days of the conclusion of the month in which it accrues.
Availability of Service & Percentage Reduction of Monthly Service:
≥ 98.0% and <99.0%, 2% reduction of monthly service fee;
≥ 97% and <98.0%, 4% reduction of monthly service fee;
< 97.0%, 7% reduction of monthly service fee" - Approach to resilience
- Prevalent TPRM is a cloud-hosted, multi-tenant solution that combines very high resilience with continuous improvements as only possible through a state-of-the-art SaaS delivery model. Our Business Continuity Policy and Business Resiliency Policy provide a framework for preparedness, response, recovery, and mitigation activities to ensure the organization's ability to deliver critical functions without significant interruption. Client data is fully backed-up daily and retained for 14 days. Backups are encrypted and stored in the same AWS region as the client tenant. In addition, all client data is replicated in real-time using Availability Zones (AZs). These are discrete data centers with redundant power, networking, and connectivity in an AWS Region. Disaster scenarios have been documented and disaster recovery is tested at least annually.
- Outage reporting
- Maintenance is performed off-hours. If downtime is required, communication will be provided by the assigned Customer Success Manager. Customers are provided a minimum of 24-hour notice before any planned outages via email and the announcements section of the platform login screen. Planned outages are only scheduled after hours or during non-peak times and typically last seconds as tests are performed.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Identity federation with existing provider (for example Google Apps)
- Username or password
- Access restrictions in management interfaces and support channels
- Our Access Control Policy mandates requirements for controlling access to information and information processing facilities. Access to data, systems, applications, networks, and infrastructure must be managed in a manner that maintains the confidentiality, integrity, and availability of customer and vendor data, and in a manner that complies with any applicable legal and regulatory requirements. It is built on the principles of least privilege and separation of duties.
- Access restriction testing frequency
- At least once a year
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Identity federation with existing provider (for example Google Apps)
- Username or password
Audit information for users
- Access to user activity audit information
- Users have access to real-time audit information
- How long user audit data is stored for
- User-defined
- Access to supplier activity audit information
- Users contact the support team to get audit information
- How long supplier audit data is stored for
- At least 12 months
- How long system logs are stored for
- At least 12 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
-
- ISO/IEC 27001
- Other
- Other security governance standards
- Mitratech maintains infrastructure, policies, procedures, and business practices which comply with numerous certifications such as SSAE SOC II Type 2 which attest to Mitratech's best-practice, best-of-breed approach to hosting and security. Mitratech has the appropriate safeguards in place to be compliant with data privacy laws/regulations of GDPR, HIPAA, and CCPA.
- Information security policies and processes
-
Mitratech follows an enterprise-wide Information Security Management Program (ISMP) to protect the availability, integrity, and confidentiality of information, information assets, and information systems.
The ISMP comprises core policies (including Access Control, Compliance, HR Security, Incident Management/Response, Information Risk Management, Information Security, and Third-Party Risk Management) that are reviewed annually.
Reporting structure / governance: Information security policy review is undertaken by Mitratech SecOps (annually or more frequently as required) using established review and approval workflows in PolicyHub.
Exceptions must be submitted to Enterprise Risk and Compliance via the IT Security Exception Request Form and follow the defined exception process.
How policies are enforced: Mitratech documents and implements acceptable-use rules; delivers role-relevant security training through joiner/leaver processes; enforces controlled, auditable access approval and timely removal/adjustment of access; maintains monitoring, logging, vulnerability scanning and independent penetration testing with prioritized remediation; manages patch advisories and malicious code controls; operates a defined incident management plan; and requires third-party access to comply with technical security standards. - Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Configuration and change management approach
- Mitratech maintains consistent, approved configurations for hosting and corporate IT infrastructure to prevent vulnerabilities and protect confidentiality, integrity and availability. Components are tracked in a configuration control system or repository, with system documentation, audit logs of updates, and retention of prior software versions plus required parameters and procedures for as long as business information is retained. Only trained administrators, with appropriate management authorization, implement changes following the Change Management Procedure. Changes are tested in non-production for usability, security, system effects and end-user experience, with a rollback strategy defined before production release. Upgrades consider business impact and release security requirements
- Vulnerability management type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Vulnerability management approach
- Mitratech’s vulnerability management is governed by its IT Security Vulnerability Management Policy to protect confidentiality, integrity and availability. Hosting and Corporate IT routinely monitor and assess newly emerging technical vulnerabilities, using operating procedures plus trusted threat-intelligence services, and staff subscriptions to the latest vulnerability information. Potential threats are assessed through logged and filtered inbound/outbound network traffic, scanning for viruses, malware and suspicious patterns, and continuously updated anti-malware controls. Patches are deployed promptly following a documented procedure with defined timelines for testing and installation; timelines are based on patch criticality and the system’s risk level, ensuring higher-risk issues are remediated sooner.
- Protective monitoring type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Protective monitoring approach
- Mitratech uses incident management plans covering logging, monitoring, detection, analysis and reporting of security incidents across IT and hosting. Staff and third parties are informed what constitutes an incident and how to report events and vulnerabilities through communicated procedures. Potential compromises are identified via monitoring and assessment steps in the Incident Response Plan, with decisions recorded and entered in the Information Security Incident Log for categorization and trend analysis. Designated responders assess evidence, escalate when needed (including external specialists and regulators), and restore normal service. Plans are reviewed and tested annually, and responses are required to be timely and effective
- Incident management type
- Complies with a recognised standard, for example, CSA CCM v4.0 or ISO/IEC 27035:2011 or SSAE-18 / ISAE 3402
- Incident management approach
- Mitratech maintains a formal incident response procedure covering scenario-based processes and real-time network traffic supervision, exercised annually. It includes security event reporting and escalation, a defined response team with clear roles, evidence collection with chain of custody, mechanisms to support reporting, required incident actions, disciplinary processes for breaches, and post-incident feedback and postmortem analysis. Reporters are informed of outcomes once incidents are resolved. If a security incident is substantially likely to be critical, Mitratech notifies affected clients within 24 hours. An overview of the procedure can be provided. Mitratech also maintains a disaster recovery plan, reviewed and executed annually.
- Post-quantum cryptography secure
- Yes
Secure development
- Approach to secure software development best practice
- Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- Yes
- Free trial available
- Yes
- Description of free trial
- We offer Proof-of-Concept (POC) trials for select solutions, enabling customers to evaluate functionality for a short period. Typical POCs last about two weeks, but duration can vary by customer, project, and evaluation needs to ensure the trial supports the intended assessment.
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 5%
- Between £250,000 and £500,000
- 5%
- Between £500,001 and £1,000,000
- 10%
- Between £1,000,001 and £2,500,000
- 10%
- Between £2,500,001 and £5,000,000
- 10%
- Over £5,000,001
- 10%
Standards and certifications
- ISO/IEC 27001 certification
- Yes
- ISO/IEC 27001 accredited by
- British Assessment Bureau
- ISO/IEC 27001 accreditation date
- Wednesday 7 June 2023
- What the ISO/IEC 27001 doesn’t cover
- Our certificate uses Statement of Applicability Version 1.3 (29 April 2025) but does not include exclusions or controls not covered.
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- Yes
- ISO 9001 certification accredited by
- British Assessment Bureau
- ISO 9001 accreditation date
- Sunday 2 June 2024
- What the ISO 9001 doesn’t cover
- N/A
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Cyber Essentials Certificate Number
- Cbaed41f-aa61-4059-8968-3775daaa83a4
- Cyber essentials plus
- Yes
- Cyber Essentials Plus Certificate Number
- Ff1c64fb-7750-4095-8fbb-45aadf87260c
- Other security certifications
- Yes
- Any other security certifications
-
- CREST – SOC (Security Operations Centre)
- CREST – Penetration Testing
- NCSC - Assured provider of Cyber Incident Exercising
- NCSC - Assured Cyber Incident Response (CIR) Standard Level
Social value
- Mission: Kick start economic growth
-
To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- New or retained jobs on the contract workforce in the relevant area that meet the criteria set out in MAC 1b, 1c and 1d
- Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
- Plans to engage the contract workforce in deciding the most important workplace issues to address
- Monitoring of employee engagement rates (by protected characteristic) and, where necessary, the development of actions to ensure all voices are heard across the diversity of the workforce
- Employment contracts that reflect actual hours worked; steps taken to ensure employees understand their contracts and have the ability to review and adjust them if actual hours regularly exceed contracted hours
- Activities that support an environment where staff are educated about and feel empowered to report and address bullying and harassment
- Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
- Entitlement to sick pay for the contract workforce, with provision in place for any staff who do not meet the earnings threshold for statutory sick pay, payment of sick pay from day one of absence and payment of staff on the contract workforce who are off sick a replacement income of 100% of their usual earnings for as long as possible
- Understanding of in-work progression issues affecting the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors
- Measures to support in-work progression to help people in the contract workforce, to move into higher paid work by developing new skills relevant to the contract
- Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
- Volunteering opportunities for staff
- Understanding of the modern slavery risks and issues affecting the market, industry, sector or country (of origin or of source) relevant to the contract, and the workforce in the supplier’s own organisation and those of its key subcontractors
- Measures to identify, mitigate and manage modern slavery risks relating to the contract and how these will be implemented
- Outline policies and practices to be applied to or put in place for the contract to mitigate and manage modern slavery risks, including: Pre-employment checks, recruitment practices. Workplace conditions, safeguarding plans and processes in place and regular monitoring with relevant groups considered, which may include sampling
- How these flow down the supply chain and are monitored Illustrative examples include reporting, site visits, audits, etc.
Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.
- Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
Policy Outcome 3: Resilient, innovative and flexible supply chains: Support economic growth through enabling resilient businesses, opportunities for small businesses and voluntary, community and social enterprises
- Understanding of the types of businesses in the market and the level of participation by new businesses, entrepreneurs, start-ups, SMEs, VCSEs and mutuals
- Understanding of local demographics, needs and opportunities for the co-design of the goods, services and works to be delivered under the contract
- Methods for engaging with different parts of the community (including the education system and charities representing the community) and how communities come together to inform decisions, strategy and projects to leave a positive legacy for future generations
- Mission: Make Britain a clean energy superpower
-
To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero
Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.
- Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
- Mission: Break down barriers to opportunity
-
By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain
Policy Outcome 6: Employment and training: For those who face barriers to employment
- Understanding of employment and skills issues, and of the skills and employment shortages of high growth sectors relating to the contract
- Understanding of the issues affecting the representation of disabled people in the workforce in the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors
- Collection of the views and expertise of disabled people and their representative organisations on successfully supporting disabled employees or applicants
- Inclusive and accessible recruitment practices, and retention-focused activities, including those provided in the Guide for line managers on recruiting, managing and developing people with a disability or health condition
- Understanding of the issues affecting inequality in employment, skills and pay in the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors. Measures to tackle inequality in employment, skills and pay in the contract workforce
- Inclusive and accessible development practices, including guidance for line managers on recruiting, managing and developing people with a disability or health condition
Policy Outcome 7: Creating a pipeline of opportunities: For the contract workforce, reducing barriers to entry for under-represented groups.
- Understanding of the issues affecting the development of new skills by target cohort
- Understanding of the underlying factors affecting improvements to reduce barriers to entry and training schemes for the target cohort(s) related to the contract workforce
- Mission: Build an NHS fit for the future
-
That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.
Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.
- Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce
- Understanding barriers to access to health and social care services or employment opportunities e.g. digital inclusion
- Inclusive and accessible recruitment practices, development practices and retention policies that support-focused activities including those provided in the Guide for line managers on recruiting, managing and developing which support people with a disability or health condition