Skip to main content

Help us improve the Digital Marketplace - send your feedback

DEEPER THAN BLUE LTD

Microsoft Copilot Implementation and Integration Services and Support

DeeperThanBlue delivers end-to-end Microsoft Copilot for Microsoft 365 services, from readiness assessments and “Art of the Possible” workshops to governance frameworks and technical integration. We help organisations unlock productivity, elevate skills, enhance collaboration, and adopt AI responsibly, ensuring secure, compliant, and impactful deployment across the enterprise.

Features

  • Evaluates infrastructure, licences, and AI readiness to mitigate adoption risks.
  • Interactive sessions to uncover high-value AI scenarios.
  • Establish policies for ethical AI use, data protection, and compliance.
  • Tailor Copilot deployment to departmental needs and workflows.
  • Ensure context-aware, data-driven AI assistance across all Microsoft 365 apps.
  • Structured testing phases to validate scenarios and refine deployment strategy.
  • Design bespoke company-specific AI solutions and workflow automations.
  • Upskill employees with on-demand guidance and best-practice adoption support.
  • Level 1–3 support with SLAs, monitoring, and performance optimisation.
  • Provide dashboards and reports to measure usage, productivity gains, ROI.

Benefits

  • Automate routine tasks, freeing staff to focus on strategic work.
  • Support creative processes in Word, Excel, PowerPoint, and Teams.
  • Provide guidance and upskilling for smarter, faster decision-making.
  • Reduce administrative effort with intelligent document generation and workflow automation.
  • Ensure data residency and adherence to UK/EEA regulations.
  • Enhance real-time team collaboration and information sharing.
  • Identify and manages AI adoption risks proactively through structured governance.
  • Use analytics to monitor AI adoption and inform continuous improvement.
  • Unleash creative potential with scenario-driven AI applications.
  • Deliver measurable, ongoing improvements across processes and workflows.

Pricing

  • Free trial available

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at chris.booker@deeperthanblue.co.uk. Tell them what format you need. It will help if you say what assistive technology you use.

Framework

G-Cloud 15

Service ID

8 7 2 6 9 4 8 1 9 1 5 3 1 6 0

Contact

DEEPER THAN BLUE LTD Chris Booker
Telephone: 0114 3992820
Email: chris.booker@deeperthanblue.co.uk

About your service

Service categories

Application Development and Deployment

AI platforms

  • Search and knowledge discovery

AI life cycle

  • AI Build Software

AI software services

  • Conversational AI Software Services
  • Generative AI Software Services
  • Document AI Software Services
  • Personalize AI Software Services
Multi cloud support
Yes

Service scope

Software add-on or extension
Yes, but can also be used as a standalone service
What software services is the service an extension to
Microsoft 365 E3/E5 Office 365 E3/E5
Cloud deployment model
  • Public cloud
  • Private cloud
  • Hybrid cloud
Service constraints
Specific constraints would need to be further understood as part of service scoping and project take-on.
System requirements
  • Microsoft 365: Fully hosted, managed SaaS; no on-premises infrastructure needed.
  • Use on any web-enabled device with modern internet browsers.
  • Supports Internet Explorer, Edge, Chrome, Safari.
  • Deployed on AWS, Microsoft Azure, Google Cloud or IBM Cloud
  • Can be deployed on premise

User support

Email or online ticketing support
Yes
Support response times
DeeperThanBlue provides flexible, enterprise‑grade Managed Services with defined service levels tailored to customer needs. Support is available across Standard and Premium tiers, with coverage options ranging from business hours to full 24×7 service.

We prioritise incidents by severity, ensuring fast and effective response times, from critical Level 1 issues, where systems are unavailable, through to general enquiries. Our SLAs guarantee rapid response, with Premium support offering enhanced targets for high‑impact incidents.

This structured approach ensures consistent, reliable service management that keeps essential systems stable, secure, and fully supported.
User can manage status and priority of support tickets
No
Phone support
Yes
Phone support availability
24 hours, 7 days a week
Web chat support
Yes
Web chat support availability
9 to 5 (UK time), Monday to Friday
Web chat support accessibility standard
WCAG 2.2 AA
Web chat accessibility testing
None
Onsite support
Yes, at extra cost
Support levels
DeeperThanBlue provides comprehensive Support and Managed Services to ensure stability, performance, and security of critical business systems, priced from £850 to £3,575 monthly including incident hours.

Our support model offers a choice of coverage levels, allowing customers to select the service window that best fits operational needs, from standard business hours, extended business hours, and full 24×5 availability through to 24×7 support for always‑on environments. These options ensure organisations can depend on consistent access to skilled support specialists whenever incidents arise.

Two service tiers are available: Standard and Premium. Both provide structured incident categorisation with defined response times, while Premium delivers faster responses for high-severity issues. Incidents are prioritised by impact and urgency: Level 1 (production system outages) through Level 4 (general enquiries). Response commitments range from one-hour for critical Premium incidents to 24-hour for low-severity queries across both tiers.

Our Managed Services are delivered by experienced engineers who monitor, diagnose, and support system operations proactively. By combining flexible coverage options with clear and measurable SLAs, DeeperThanBlue ensures customers benefit from reliable technical support, reduced downtime, and consistently high service quality. This approach enables organisations to maintain optimal performance while focusing on strategic objectives.
Support available to third parties
No
AI chatbot
No

Onboarding and offboarding

Getting started
Microsoft provides all Modern Work customers with 24/7 self-help resources, including Microsoft Learn, training documentation, templates, and community support. For more information, visit:
- https://learn.microsoft.com/en-us/microsoft-365/
- https://support.microsoft.com/en-us/training
- https://adoption.microsoft.com/en-us/customer-hub/
- https://support.microsoft.com/en-us/modernworkplace
Service documentation
Yes
Documentation formats
  • HTML
  • PDF
End-of-contract data extraction
When the contract ends, your access to Modern Work services, applications, and customer data go through multiple stages before the subscription is fully turned off, or deleted:
1. Expired Stage (30 days): Users have normal access to Modern Work applications and files.
2. Disabled Stage (90 days): Data is accessible to admins only. Users can’t access applications. Admins can access the admin centre to buy and manage other subscriptions.
3. Deleted Stage: After the 90-day retention period ends, Microsoft disables the account and deletes the customer data.
During the term of an active subscription, a subscriber can access, extract, or delete customer data stored in Modern Work apps. For more information, visit https://learn.microsoft.com/en-us/microsoft-365/commerce/subscriptions/what-if-my-subscription-expires
End-of-contract process
Microsoft is governed by strict standards and follows specific processes for removing cloud customer data from systems under our control, overwriting storage resources before reuse, and purging or destroying decommissioned hardware. In our Online Service Terms, Microsoft contractually commits to specific processes when a customer leaves a cloud service or the subscription expires. This includes deleting customer data from systems under our control.

Please see Data Protection Addendum for full and up to date details about how Microsoft manages your data. https://www.microsoft.com/licensing/docs/view/Microsoft-Products-and-Services-Data-Protection-Addendum-DPA?lang=1

https://learn.microsoft.com/en-us/microsoft-365/commerce/subscriptions/what-if-my-subscription-expires?view=o365-worldwide
Documentation accessibility standard
WCAG 2.2 AA

Using the service

Web browser interface
Yes
Supported browsers
  • Microsoft Edge
  • Firefox
  • Chrome
  • Safari
  • Opera
Application to install
Yes
Compatible operating systems
  • Android
  • IOS
  • Linux or Unix
  • MacOS
  • Windows
  • ChromeOS
Designed for use on mobile devices
Yes
Differences between the mobile and desktop service
The desktop service may integrate with other enterprise applications. This may be more limited on the mobile device.
Service interface
No
User support accessibility
WCAG 2.2 AA
API
Yes
What users can and can't do using the API
The Microsoft Graph API enables you to access data, intelligence, and insights from Microsoft applications. By integrating Modern Work with Graph API, developers can tap into user data and organizational information to enhance context-aware assistance from applications like Word, Excel, Teams, etc. Starting with users and groups at the core, Microsoft Graph forms a network of Modern Work services and features that manage, protect, and extract data to support a wide range of scenarios. Microsoft Graph lets you access this wealth of user data while always respecting proper authorization. For more information on Microsoft Graph's capabilities, services, and features, visit:
- https://learn.microsoft.com/en-us/graph/overview
- https://learn.microsoft.com/en-us/graph/overview-major-services
For information on Microsoft Graph limitations (throttling limits, service-specific limits, connection limits, schema limits, and availability), visit:
- https://learn.microsoft.com/en-us/graph/throttling-limits
- https://learn.microsoft.com/en-us/graph/connecting-external-content-api-limits
- https://learn.microsoft.com/en-us/graph/metered-api-overview
Microsoft Azure OpenAI also offers a suite of artificial intelligence (AI) services that can be seamlessly integrated with Modern Work to enhance its functionality. By leveraging services such as Azure Cognitive Services and Azure Machine Learning, developers can extend capabilities in areas such as code summarization, sentiment analysis of code reviews, and even predictive coding assistance based on historical patterns.
API documentation
Yes
API documentation formats
  • HTML
  • PDF
API sandbox or test environment
Yes
Customisation available
Yes
Description of customisation
Modern Work customers can customize their services in various ways:
- The Microsoft 365 Admin Centre is a web-based portal where administrators can manage user accounts and settings for their organization. They can add or remove users, manage billing, reset passwords, and more.
- The Office Customization Tool allows administrators to customize the installation of Office by choosing which applications and languages are installed, how those applications should be updated, and application preferences.
- Users can personalize their Microsoft 365 experience by changing the theme, notifications, and other settings.
- The Microsoft 365 Developer Program provides a sandbox environment where developers can learn and experiment with Modern Work technologies.
- Developers can use the Microsoft Graph API to interact with data in Modern Work and build apps that integrate with Microsoft 365.
For more information, visit:
- https://learn.microsoft.com/en-us/deployoffice/admincenter/overview-office-customization-tool
- https://learn.microsoft.com/en-us/microsoft-365/admin/setup/customize-your-organization-theme
- https://support.microsoft.com/en-us/office/personalize-your-microsoft-365-experience-eb34a21b-52fa-4fbf-a8d5-146132242985

Scaling

Independence of resources
Microsoft employs a combination of proactive monitoring and efficient management practices to mitigate the impact of demand fluctuations on Modern Work services. Microsoft focuses on several areas of service management to minimise the affect on Modern Work users by demands placed on the service:
- Monitoring and Major Incident Management:
- Service Desk and Normal Incident Management:
- Administration and Feature Management:
- Business Consumption and Productivity:
For more information, visit:
- https://learn.microsoft.com/en-us/microsoft-365/community/maturity-model-microsoft365-servicing-microsoft365-service-change-management
- https://techcommunity.microsoft.com/t5/microsoft-365-blog/modern-service-management-for-office-365/ba-p/52793

Analytics

Service usage metrics
Yes
Metrics types
Billing & Usage metrics, Application logs & performance metrics, User login & API events.
Reporting types
  • API access
  • Real-time dashboards
  • Reports on request
Resource tagging
No
FOCUS resource tagging
No

Resellers

Supplier type
Reseller providing extra support
Organisation whose services are being resold
Microsoft

Staff security

Staff security clearance
Staff screening not performed
Government security clearance
Security Clearance (SC)

Asset protection

Knowledge of data storage and processing locations
Yes
Data storage and processing locations
  • United Kingdom
  • European Economic Area (EEA)
User control over data storage and processing locations
Yes
Datacentre security standards
Complies with a recognised standard (for example CSA CCM version 4.0)
Penetration testing frequency
At least once a year
Penetration testing approach
Another external penetration testing organisation
Protecting data at rest
  • Physical access control, complying with CSA CCM v4.0
  • Physical access control, complying with SSAE-18 / ISAE 3402
  • Physical access control, complying with another standard
  • Encryption of all physical media
  • Scale, obfuscating techniques, or data storage sharding
  • Other
Other data at rest protection approach
Security for both data-in-use and data-at-rest is the customers responsibility as the applications are developed.
Data sanitisation process
Yes
Equipment disposal approach
Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
Data sanitisation type
Explicit overwriting of storage before reallocation / Secure Erase

Data importing and exporting

Data export approach
Modern Work applications enable users to export their data in numerous ways.
For information on how Outlook users can export their data, visit https://support.microsoft.com/en-us/office/export-emails-contacts-and-calendar-items-to-outlook-using-a-pst-file-14252b52-3075-4e9b-be4e-ff9ef1068f91
For information on how Teams users can export their data, visit https://answers.microsoft.com/en-us/msteams/forum/all/how-to-download-data-and-activities-carried-out-on/0e21a9e5-71c8-4cdd-b817-a019dcd54592
Data export formats
  • CSV
  • Other
Other data export formats
  • Microsoft Excel
  • Text only
  • CSV
  • XML
Data import formats
  • CSV
  • ODF

Data-in-transit protection

Data protection between buyer and supplier networks
  • TLS (version 1.2 or above)
  • IPsec or TLS VPN gateway
Data protection within supplier network
  • TLS (version 1.2 or above)
  • IPsec or TLS VPN gateway

Availability and resilience

Guaranteed availability
Please note that the following links are collectively a high-level overview, and the actual terms can be found in the specific SLA and refund policy documents.
• https://www.microsoft.com/licensing/docs/view/Service-Level-Agreements-SLA-for-Online-Services?lang=1&year=2023
• https://www.microsoft.com/licensing/docs/view/Service-Level-Agreements-SLA-for-Online-Services
• https://support.microsoft.com/en-us/account-billing/how-to-get-a-refund-on-a-microsoft-subscription-67dca30b-b323-44d5-acc2-e02f9902c472
• https://www.microsoft.com/en-us/store/b/returns
• https://learn.microsoft.com/en-us/answers/questions/1275102/ms-365-business-premium-service-level-agreement?page=1
• https://learn.microsoft.com/en-us/dynamics365/customer-service/use/overview-service-level-agreements
• https://learn.microsoft.com/en-us/training/modules/service-level-agreements/
• https://www.microsoft.com/licensing/servicelevelagreements%29
Approach to resilience
Microsoft's datacentre is designed to be resilient/align with the UK Government's 2nd Cloud Security Principle "Asset Protection and Resilience".
* Redundant Architecture: Microsoft online services achieve service resilience through redundant architecture, which involves deploying multiple instances of a service on geographically and physically separate hardware. This provides increased fault-tolerance for Microsoft online services.
* Data Replication and Automated Integrity Checking: Data replication and automated integrity checking are also part of Microsoft's strategy to ensure service resilience.
* Compliance with UK G-Cloud: Every year, Microsoft prepares documentation and submits evidence to attest that its in-scope enterprise cloud services comply with the 14 Cloud Security Principles of G-Cloud. This gives potential G-Cloud customers an overview of its risk environment.
* ISO/IEC 27001 Certification: The compliance process relies on the ISO/IEC 27001 certification. A Government Digital Service (GDS) accreditor then performs several random checks on the Microsoft assertion statement, samples the evidence, and makes a determination of compliance.
* UK OFFICIAL Data: The appointment of Microsoft services to the Digital Marketplace means that UK government agencies and partners can use in-scope services to store and process UK OFFICIAL government data.
Please also see:
• https://learn.microsoft.com/en-us/compliance/assurance/assurance-resiliency-and-continuity
• https://learn.microsoft.com/en-us/compliance/regulatory/offering-g-cloud-uk
• https://learn.microsoft.com/en-us/azure/compliance/offerings/offering-uk-g-cloud
• https://azure.microsoft.com/en-us/blog/trusted-cloud-security-privacy-compliance-resiliency-and-ip/
• https://azure.microsoft.com/en-us/blog/easing-compliance-for-uk-public-and-health-sectors-with-new-azure-blueprints/
Outage reporting
Microsoft provides several ways to report service outages for BizApps and Azure Cloud:
*Public Dashboard:
*API: Microsoft offers the Service Communications API in Microsoft Graph
*Email Alerts:
In addition to the public dashboard, API, and email alerts, Microsoft provides a few more methods for service outage notifications:
*Mobile Push Notifications: For urgent issues, Microsoft recommends configuring Service Health alerts to send mobile push notifications through the Azure mobile app.
*IT Service Management Tools: Many customers already have ticketing systems and IT service management (ITSM) tools in place.
*Power BI Notifications: Power BI provides incident notification so you can optionally receive emails if there's a service disruption or degradation.
Please also see:
•https://learn.microsoft.com/en-us/microsoft-365/enterprise/view-service-health?view=o365-worldwide
•https://azure.microsoft.com/en-us/get-started/azure-portal/service-health/
•https://learn.microsoft.com/en-us/graph/service-communications-concept-overview
•https://learn.microsoft.com/en-us/azure/service-health/impacted-resources-outage
•https://learn.microsoft.com/en-us/azure/azure-monitor/app/sla-report
•https://azure.microsoft.com/en-us/blog/how-to-stay-informed-about-azure-service-issues/
•portal.microsoft.com. https://portal.microsoft.com/servicestatus
•https://learn.microsoft.com/en-us/power-platform/admin/check-online-service-health
•https://learn.microsoft.com/en-us/power-bi/support/service-interruption-notifications
•https://techcommunity.microsoft.com/t5/microsoft-defender-xdr-blog/get-email-notifications-on-new-incidents-from-microsoft-365/ba-p/2012518
•https://azure.microsoft.com/en-us/blog/three-ways-to-get-notified-about-azure-service-issues/
•https://learn.microsoft.com/en-us/power-bi/support/service-interruption-notifications
•https://answers.microsoft.com/en-us/msoffice/forum/all/notifications-regarding-outages/0f8eb1e3-5caf-4e66-bbd9-e94415dba089

Identity and authentication

User authentication needed
Yes
User authentication
  • Multi-Factor Authentication (MFA)
  • Identity federation with existing provider (for example Google Apps)
  • Username or password
Access restrictions in management interfaces and support channels
Role based access restricts access to management interfaces and support channels. Roles include developer, manager, auditor and billing manager. Different roles see different interfaces.
Access restriction testing frequency
At least once a year
Management access authentication
  • Multi-Factor Authentication (MFA)
  • Public key authentication (including by TLS client certificate)
  • Identity federation with existing provider (for example Google Apps)

Audit information for users

Access to user activity audit information
Users have access to real-time audit information
How long user audit data is stored for
User-defined
Access to supplier activity audit information
Users contact the support team to get audit information
How long supplier audit data is stored for
At least 12 months
How long system logs are stored for
Between 1 month and 6 months

Security governance

Named board-level person responsible for service security
Yes
Security governance certified
No
Security governance approach
Microsoft adheres to numerous, rigorous security and compliance standards, including CSA CCM version 3.0, ISO 27001, ISO 27018, SOC 1, SOC 2, SOC 3, FedRAMP, and HITRUST, among others. For more on specific compliance, visit:
- https://learn.microsoft.com/en-us/compliance/assurance/assurance-governance
- https://learn.microsoft.com/en-us/microsoft-365/community/microsoft365-maturity-model--governance-and-compliance
- https://servicetrust.microsoft.com/
Information security policies and processes
Microsoft's approach to security governance is multi-faceted and includes several key components:
*Microsoft Power Platform: Microsoft Power Platform plays a crucial role in security and governance. It helps secure and govern apps like Power Automate and Power Apps. The platform allows administrators to create simple environment and tenant-wide Data Loss Prevention (DLP) policies. It also provides tools like the Microsoft Power Platform Centre of Excellence (COE) toolkit.
*Data Loss Prevention Policies: These policies are used to prevent data leakage and ensure data security.
*Security Design Considerations: Microsoft provides best practices for security design considerations.
*Governance Model: Microsoft provides guidance on defining the governance model between citizen developers and managed IT services, as well as between central IT and the business unit admins.
*Monitoring: Microsoft provides tools for capturing compliance/auditing data and measuring adoption and usage within an organization.
*App Governance in Microsoft Defender for Cloud Apps: This provides visibility, remediation, and governance into how apps and their users access, use, and share sensitive data in Microsoft 365 and other cloud platforms.
For more detailed information, you may want to explore these resources on the following resources:
•https://learn.microsoft.com/en-us/training/modules/security-governance-intro/
•https://learn.microsoft.com/en-us/power-platform/admin/governance-considerations
•https://learn.microsoft.com/en-gb/defender-cloud-apps/app-governance-manage-app-governance?view=o365-worldwide
•https://learn.microsoft.com/en-us/defender-cloud-apps/app-governance-app-policies-overview
•https://learn.microsoft.com/en-us/microsoft-365/business-premium/m365bp-security-privacy-compliance?view=o365-worldwide
Software Security Code of Practice
Yes

Operational security

Configuration and change management standard
Supplier-defined controls
Configuration and change management approach
Modern Work enforces change management procedures for both code and non-code changes to maintain its security posture. Detailed change management processes are enforced to maintain system integrity.
Service teams utilize ticketing or source control tools to document evidence of approval and track all changes. Changes are deployed through Microsoft’s Secure Development Lifecycle (SDL), which includes specific security considerations related to code reviews, tests, and approvals before systematically releasing code into the Modern Work environment. Critical security review and approval checkpoints are part of the SDL.
For more information, visit https://learn.microsoft.com/en-us/compliance/assurance/assurance-microsoft-365-change-management
Vulnerability management type
Supplier-defined controls
Vulnerability management approach
Microsoft uses a variety of methods to assess potential threats. The Microsoft Detection and Response Team actively looks for cyberthreats that have penetrated an environment, looking beyond known alerts or malicious threats to discover new potential threats and vulnerabilities.
Deploying Patches
The pace at which Microsoft deploys patches is dependent on specific requirements.
Sources of Information About Potential Threats
Microsoft aggregates data from various sources to gather information about potential threats.
Please also see:
•https://www.microsoft.com/en-us/security/blog/2022/09/08/part-1-the-art-and-science-of-threat-hunting/
•https://learn.microsoft.com/en-us/microsoft-365/security/defender/criteria?view=o365-worldwide
•https://learn.microsoft.com/en-us/windows/deployment/windows-autopatch/overview/windows-autopatch-deployment-guide
Protective monitoring type
Supplier-defined controls
Protective monitoring approach
Azure security has defined requirements for active monitoring. Service teams configure active monitoring tools in accordance with these requirements. Active monitoring tools include the Microsoft Monitoring Agent (MMA) and System Centre Operations Manager. These tools are configured to provide time alerts to Azure security personnel in situations that require immediate action.
Azure continuously monitors and detects risk in your organization, even when devices aren’t connected to the corporate network. Azure security has defined requirements for active monitoring.
For a breakdown of initial response times by several level and business impact, please visit https://azure.microsoft.com/en-us/support/plans/response/
Incident management type
Supplier-defined controls
Incident management approach
Microsoft employs a federated security incident response model. Each major online service team adheres to a shared incident management process, shared definitions, shared training to provide consistency. The Microsoft365 Security Response team provides service teams with centralized security expertise and incident response guidance as part of our federated security response model.
Responsibilities for security incident response are shared between the Microsoft365 Security Response team and each Modern Work service team. Our incident response strategy, based on the NIST 800-61 response management phases, through phases of interconnected activity:
-Preparation
-Containment, eradication, recovery
-Post-incident activity
For more information, visit https://learn.microsoft.com/en-us/compliance/assurance/assurance-incident-management
Post-quantum cryptography secure
No

Secure development

Approach to secure software development best practice
Supplier-defined process

Public sector networks

Connection to public sector networks
No

Pricing

Discount for educational organisations
No
Free trial available
Yes
Description of free trial
Self service trials for: Teams Exploratory, Viva Goals, Visio Plan 1 & 2, Project Plan 1 & 3. Any other trial customer will need to contact MS.
Link to free trial
Customers can view self-service subscriptions. In the Microsoft 365 admin center, go to the Billing > Your products page. On the Products tab, select the filter icon, then select Self-service. To view more details about a subscription, select one from the list.

Discount percentage by annual call-off contract value (excluding VAT)

Less than £250,000
0%
Between £250,000 and £500,000
0%
Between £500,001 and £1,000,000
0%
Between £1,000,001 and £2,500,000
0%
Between £2,500,001 and £5,000,000
0%
Over £5,000,001
0%

Non-mandatory Standards and certifications

ISO/IEC 27001 certification
No
ISO 28000:2022 certification
No
ISO 9001 certification
No
Quality management systems (QMS)
No
CSA STAR certification
No
PCI certification
No
Cyber essentials
Yes
Please provide your Cyber Essentials Certificate Number
172fc5f8-b27f-4d3b-8e17-7491b529e4be
Cyber essentials plus
Yes
Please provide your Cyber Essentials Plus Certificate Number
A62e3614-9846-4de9-90f3-0c032387c640
Other security certifications
No

Social value

Section B - Commitment for Future: Delivery
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority

    • New or retained jobs on the contract workforce in the relevant area that meet the criteria set out in MAC 1b, 1c and 1d
    • Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
    • Plans to engage the contract workforce in deciding the most important workplace issues to address
    • Employment contracts that reflect actual hours worked; steps taken to ensure employees understand their contracts and have the ability to review and adjust them if actual hours regularly exceed contracted hours
    • Activities that support an environment where staff are educated about and feel empowered to report and address bullying and harassment
    • Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
    • Monitoring and reporting of gender and ethnicity pay gaps and plans to address them where necessary
    • Entitlement to sick pay for the contract workforce, with provision in place for any staff who do not meet the earnings threshold for statutory sick pay, payment of sick pay from day one of absence and payment of staff on the contract workforce who are off sick a replacement income of 100% of their usual earnings for as long as possible
    • Understanding of in-work progression issues affecting the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors
    • Measures to support in-work progression to help people in the contract workforce, to move into higher paid work by developing new skills relevant to the contract
    • Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
    • Volunteering opportunities for staff
    • Outline policies and practices to be applied to or put in place for the contract to mitigate and manage modern slavery risks, including: Pre-employment checks, recruitment practices. Workplace conditions, safeguarding plans and processes in place and regular monitoring with relevant groups considered, which may include sampling
    • How to ensure business decisions re: price/cost, short lead times, payment timescales do not create modern slavery risks in the supply chain
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.

    • Understanding of employment and relevant skills issues, and of the education and training issues relating to the contract. Illustrative examples: demographics, skills shortages, new opportunities in high growth sectors, geographic/local community and skills/employment challenges
    • Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
  • Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.

    Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.

    • Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce
    • Understanding barriers to access to health and social care services or employment opportunities e.g. digital inclusion

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at chris.booker@deeperthanblue.co.uk. Tell them what format you need. It will help if you say what assistive technology you use.