Skip to main content

Help us improve the Digital Marketplace - send your feedback

RiskFlag

RiskFlag ISO Accredited Safety Case, Bow Tie and Risk Software

Modular ISO accredited risk management solution managing risk and safety cases. Providing a single source of truth, offering full safety case management, with bowtie and risk register integration, and repeatable reporting functions. The safety case follows the Claim, Argument, Evidence framework creating an auditable and repeatable report.

Features

  • ISO accredited safety case management, simple structured report preparation
  • Bowtie risk management, risk register for problem identification, modular connections
  • Safety case report function with automated safety case report generation
  • Custom safety case key building information and report templates
  • Embedded word processor for collaborative safety case report creation
  • Reporting dashboard, integrated configurable management dashboard, management dashboard reporting
  • Mandatory occurrence reporting, incident reporting, occurrence reporting and incident investigation
  • Evidence database connection, evidence database connectivity, cloud evidence storage
  • Integrated activity logging tool, audit integration, integrated auditing tool
  • Collaborative case working, commenting, safety case and workflow task management

Benefits

  • Version control tracking, automated updates, real time collaboration, live working
  • Audit activity with change recording, interaction auditing and action tracking
  • Manage risk exposure, with risk tracking and complex risk visualisation
  • Safety management, safety case records, safety information and overview reports
  • Consistent reporting with compliance management, safety reporting, and compliance reporting
  • Collaborative document management, co-authoring, real-time working and document collaboration
  • Safety case improvement information, visual representation, safety case operation information.
  • Safety case replication, template cloning, document cloning, safety case templates
  • Structured arguments, structured evidence, minimise risk, compliance forecasting, forecast reporting
  • Real time data reporting, live reporting, report export, barrier effectiveness

Pricing

  • Free trial available

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at info@riskflag.com. Tell them what format you need. It will help if you say what assistive technology you use.

Framework

G-Cloud 15

Service ID

9 0 5 4 3 1 7 5 8 7 0 9 0 2 9

Contact

RiskFlag Mark Keeble
Telephone: 07979604749
Email: info@riskflag.com

About your service

Service categories

Applications

Content workflow and management

  • Capture
  • Document
  • Media Services
  • Creative
  • EDiscovery and forensics

Content services

  • Enterprise Content Management Applications
  • Content Sharing and Collaboration Applications

Persuasive content management

  • Website Software
  • Digital Asset Management Applications
  • Product Content Management Applications
  • Content Marketing Applications
  • Video Platforms
  • Digital Adoption Platform

Enterprise portals and digital workspaces

  • Multi-Audience Portals
  • Integrated Employee Workspaces
Multi cloud support
No

Service scope

Software add-on or extension
No
Cloud deployment model
Private cloud
Service constraints
Users require an internet enabled browser and internet enabled device.
Licensing is on a per-building basis. Access to the system is via a web application and is available 24/7, subject to planned maintenance and upgrades.
System requirements
  • Users need a computer with a web browser
  • Users need a reliable internet connection
  • If enabled, users need a suitable 2-factor authentication app.
  • Users need a .pdf viewer to review system reports
  • MS Office or similar is needed to review some output

User support

Email or online ticketing support
Yes
Support response times
Mon – Fri, 0900-1700.
Critical:
• Complete loss of service or a critical functionality, impacting all users.
• Acknowledgment ; 2 hours.
• Resolution or workaround ; 1 working day.

High:
• Major functionality is impacted, affecting a significant number of users.
• Acknowledgment ; 4 hours.
• Resolution or workaround ; 2 working days.

Medium:
• Noncritical functionality is impacted, affecting a limited number of users.
• Acknowledgment ; 3 days.
• Resolution or workaround; 1 working week.

Low:
• Minor issues that do not significantly impact functionality.
• Acknowledgment; 4 working days.
• Resolution or workaround; proportionate timeframe.
User can manage status and priority of support tickets
No
Phone support
Yes
Phone support availability
9 to 5 (UK time), Monday to Friday
Web chat support
No
Onsite support
Yes, at extra cost
Support levels
1.Technical Support (included in the subscription fee)
- Email support during business hours (9 AM to 5 PM, Monday to Friday).
- Access to a knowledge base.
2. Remote expert support.
Answer questions around methodology, theory and best practice
3. Additional client onboarding is available.
4. Workshops are also available.
Refer to pricing document for more detail.
Support available to third parties
Yes

Onboarding and offboarding

Getting started
Users receive two 90 minute virtual onboarding session from a member of the support team. This is backed-up with a series of videos documents describing how to use the system.
Onsite training is available on a case by case basis, at an extra cost as detailed in the pricing document
Service documentation
Yes
Documentation formats
  • HTML
  • PDF
  • Other
Other documentation formats
Documentation and support videos are also available within the system
End-of-contract data extraction
Upon termination, provided that the Customer has, at that time, paid all fees and charges outstanding RiskFlag will deliver the back-up of customer data to the Customer within 30 days of the contract ending.
Data can be extracted by the customer in the form of a Word or PDF export at any time during the contract.
End-of-contract process
Following data handover all user data is deleted from the live system and access is removed for any departing registered users.
Documentation accessibility standard
None or don’t know
How the documentation is accessible
Documentation is assessed for accessibility. We consider alt-text an essential inclusion because it assists people with visual impairments in understanding the documents. All images/diagrams should in our Service Definition have clear sentence captions/alt-text.

Using the service

Web browser interface
Yes
Supported browsers
  • Microsoft Edge
  • Firefox
  • Chrome
  • Safari
  • Opera
  • Other
Application to install
No
Designed for use on mobile devices
Yes
Differences between the mobile and desktop service
Interaction with the system is via web browsers in all cases. Whilst the system is responsive to viewing window dimensions, some functionality, such as report writing, is easier to operate using a laptop or desktop screen with a keyboard.
Service interface
Yes
User support accessibility
None or don’t know
Description of service interface
Interaction with the system is via a web application with an intuitive graphical user interface.
Accessibility standards
None or don’t know
Description of accessibility
The application has been assessed using an automated tool against WCAG 2.1 AA standards and achieved a score of 76%. The areas for improvement are largely based around colour schemes and contrast. We have a plan in place for making the suggested improvements which will mean improved accessibility for users with vision impairments.
We consider alt-text an essential inclusion because it assists people with visual impairments in understanding the documents. All images/diagrams should in our Service Definition have clear sentence captions/alt-text.
Accessibility testing
None
API
Yes
What users can and can't do using the API
The API allows organisations to remotely and automatically monitor and audit system activity and create system user logs

Users set up the API via their organisation's administrative interface within RiskFlag to retrieve client ID and secret token
API documentation
Yes
API documentation formats
Other
API sandbox or test environment
No
Customisation available
Yes
Description of customisation
Terminology - this can be changed via a simple menu, by administrators only.

Safety case scoring - the RAG scoring and word pictures are configurable, with any number of scoring levels and associated colour codes easily defined.

User roles - this can be changed via a simple menu, by administrators only.
Templates - report export templates can be changed via an options menu, by administrators only.

Safety case structures, Bowtie arrangements and metadata, and a range of other features across the system are highly configurable and adaptable to different use cases.

Scaling

Independence of resources
The software uses load balancing and autoscaling to ensure that times of high demand do not change responsiveness.

Analytics

Service usage metrics
No

Resellers

Supplier type
Not a reseller

Staff security

Staff security clearance
Other security clearance
Government security clearance
Developed Vetting (DV)

Asset protection

Knowledge of data storage and processing locations
Yes
Data storage and processing locations
United Kingdom
User control over data storage and processing locations
No
Datacentre security standards
Managed by a third party
Penetration testing frequency
At least once a year
Penetration testing approach
‘IT Health Check’ performed by a CREST-approved service provider
Protecting data at rest
  • Physical access control, complying with another standard
  • Other
Other data at rest protection approach
RiskFlag uses an IONOS VPS hosted at the VIRTUS data centre to host the SaaS platform. IONOS and VIRTUS are both ISO 27001 accredited organisations and provide:
• 24/7 on-site security team
• 3 metre high perimeter fence
• Car parks fitted with Vehicle Traps
• Internal and External IP CCTV with complete site coverage
• Full authentication and access policy control
• Security bollards at building perimeter
• Biometric entry system
Data sanitisation process
No
Equipment disposal approach
A third-party destruction service

Data importing and exporting

Data export approach
The software supports a series of customisable and exportable reports in both pdf and docx format. .csv or xlsx files are also available on request.
Data export formats
Other
Other data export formats
  • .pdf
  • .docx
Data import formats
  • CSV
  • ODF
  • Other
Other data import formats
  • PDF
  • DOCX
  • XLS

Data-in-transit protection

Data protection between buyer and supplier networks
  • TLS (version 1.2 or above)
  • Other
Other protection between networks
Traffic in transit is encrypted using SSL/TLS (PKCS #1 SHA-256 With RSA Encryption)
Industry standard salting & hashing algorithms are used to protect authentication information.
Vulnerability scanning is automated and takes place within our system. Scanning takes place during the build pipeline of the app, and on a weekly basis.
Data protection within supplier network
  • TLS (version 1.2 or above)
  • Other
Other protection within supplier network
RiskFlag hardens all network services and firewalls.
Continuous compliance monitoring for changes are run to secure configurations.
Segregation principles are used at multiple levels for security, redundancy and performance.
RiskFlag provides guidance on the safe methods of information transfer and trains users on the risks.

Availability and resilience

Guaranteed availability
RiskFlag uses commercially reasonable endeavours to make the Services available 24 hours a day, seven days a week, except for:
(a) planned maintenance carried out during the maintenance window of 10.00 pm to 2.00 am UK time; and
(b) unscheduled maintenance performed outside Normal Business Hours, provided that the Supplier has used reasonable endeavours to give the Customer at least 6 Normal Business Hours' notice in advance.
Approach to resilience
RiskFlag has a documented Business Continuity Plan and defined recovery procedures.
The Business Continuity Plan and recovery procedures are tested twice annually, at a minimum, and all learnings are incorporated into the Plan.
Redundancy is ensconced as an engineering principle, including self-healing features built-in to the platform to automatically adjust to outages wherever possible.
A cyber risk assessment has been conducted and is reviewed annually.
Outage reporting
Our service monitors for outages but does not publish the detail publicly

Identity and authentication

User authentication needed
Yes
User authentication
  • Multi-Factor Authentication (MFA)
  • Username or password
Access restrictions in management interfaces and support channels
Users can be assigned as either organisation administrators or, for RiskFlag staff, RiskFlag system administrators. These statuses give users access to various admin-only features, with more powerful configuration settings, user administration controls and other management-level functions. RiskFlag system administrators also require higher security protection, including mandatory 2FA.
Access restriction testing frequency
At least once a year
Management access authentication
  • Multi-Factor Authentication (MFA)
  • Dedicated link (for example VPN)
  • Username or password

Audit information for users

Access to user activity audit information
Users contact the support team to get audit information
How long user audit data is stored for
At least 12 months
Access to supplier activity audit information
Users contact the support team to get audit information
How long supplier audit data is stored for
At least 12 months
How long system logs are stored for
At least 12 months

Security governance

Named board-level person responsible for service security
Yes
Security governance certified
Yes
Security governance standards
  • ISO/IEC 27001
  • Other
Other security governance standards
Cyber Essentials+, ISO9001 and ISO27001
Information security policies and processes
RiskFlag maintains a formal cybersecurity programme structured around the ISO 27001 framework. This document provides an overview of the firm’s approach to information security and cybersecurity, and its practices to secure data, systems and services. While information security and cybersecurity measures will naturally change over time and may differ across the range of RiskFlag’s services, this document provides an overview of our security practices.
Software Security Code of Practice
No

Operational security

Configuration and change management standard
Supplier-defined controls
Configuration and change management approach
Changes to systems within the development lifecycle shall be controlled by the use of formal change control procedures.
Significant code changes must be reviewed and approved by at least one other Riskflag employee before being merged into any production branch.
All Riskflag software is version controlled and synced between contributors (developers). All code is written, tested, and saved in a temporary git branch before being synced to the main branch
Modifications to third-party business application packages shall be discouraged, limited to necessary changes and all changes shall be strictly controlled.
Vulnerability management type
Supplier-defined controls
Vulnerability management approach
A dedicated DevOps team monitors and manages the production platform. RiskFlag deploys malware controls to reduce the chance and impact of infections.
Audit and event logs are captured, protected and regularly reviewed.
RiskFlag regularly takes and tests backups and builds multiple layers of redundancy into the company’s platform.
The deployment process makes it impossible to install software on live production systems.
RiskFlag runs a vulnerability management program based off the CVSS
Protective monitoring type
Supplier-defined controls
Protective monitoring approach
Suspicious events (login to servers, unusual outbound activity) is detected and alerts sent to senior staff. Incident response procedure is laid out in a separate document.
Incident management type
Supplier-defined controls
Incident management approach
Suspicious events (login to servers, unusual outbound activity) is detected and alerts sent to senior staff. Incident response procedure is laid out in a separate document.
Post-quantum cryptography secure
No

Secure development

Approach to secure software development best practice
Conforms to a recognised standard, but self-assessed

Public sector networks

Connection to public sector networks
No

Pricing

Discount for educational organisations
No
Free trial available
Yes
Description of free trial
Access to the tool for 5 consecutive working days.
Ability to create one building safety case with associated bowties and risk registers for up to 10 users.

Discount percentage by annual call-off contract value (excluding VAT)

Less than £250,000
0%
Between £250,000 and £500,000
10%
Between £500,001 and £1,000,000
15%
Between £1,000,001 and £2,500,000
20%
Between £2,500,001 and £5,000,000
20%
Over £5,000,001
20%

Non-mandatory Standards and certifications

ISO/IEC 27001 certification
No
ISO 28000:2022 certification
No
ISO 9001 certification
No
Quality management systems (QMS)
Yes
CSA STAR certification
No
PCI certification
No
Cyber essentials
Yes
Please provide your Cyber Essentials Certificate Number
20c8ea7b-3b80-4ed4-904b-d4d7dd072e4f
Cyber essentials plus
Yes
Please provide your Cyber Essentials Plus Certificate Number
D5e5c2e7-e112-40f6-85b1-379188daf992
Other security certifications
No

Social value

Section B - Commitment for Future: Delivery
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority

    • Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
    • Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
    • Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.

    • Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 3: Resilient, innovative and flexible supply chains: Support economic growth through enabling resilient businesses, opportunities for small businesses and voluntary, community and social enterprises

    • Understanding of the types of businesses in the market and the level of participation by new businesses, entrepreneurs, start-ups, SMEs, VCSEs and mutuals
    • Measures to involve local stakeholders and/or users in design (e.g. in the design of services, systems, products or buildings)
  • Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain

    Policy Outcome 6: Employment and training: For those who face barriers to employment

    • Creation of employment opportunities particularly for those who face barriers to employment, such as prison leavers, care leavers and/or who are located in deprived areas, and for people in industries with known skills shortages or in high growth sectors
    • Introducing transparency to pay and reward processes
  • Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain

    Policy Outcome 7: Creating a pipeline of opportunities: For the contract workforce, reducing barriers to entry for under-represented groups.

    • Understanding of the issues affecting the development of new skills by target cohort
  • Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.

    Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.

    • Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at info@riskflag.com. Tell them what format you need. It will help if you say what assistive technology you use.