F0CUS Cost Assurance
F0CUS Cost Assurance is a secure, cloud-based SaaS platform for managing commercial and financial processes across construction, infrastructure and property contracts. It supports estimating, variations, compliance and payments, delivering one version of the truth, auditable workflows and real-time reporting. F0CUS Cost Assurance Improves control, transparency, efficiency and value for money.
Features
- Cloud-based, SaaS system - manage commercial transactions in construction industry
- Commercial management - variations, payments, managing value, contractual compliance
- Manage the end-to-end contract lifecycle including Procurement Act compliance
- Contractor Portal: estimates, job costings, supplier skills, accreditations, insurance
- F0CUS Variation Centre enables collaborative resolution of variations
- Compliance module ensures pre-requisites are met – documents/images/data/commercial validity
- Commercial aspects linked to service delivery and SLA/KPI performance
- Secure and compliant – ISO27001, Cyber Essential Plus, GDPR
- Real-time performance tracking, reporting, PowerBI dashboards and auditing capability
- Integrations with client systems, compatible with multiple contract mechanisms
Benefits
- Set rules to automatically approve items that meet pre-determined criteria
- Consistent, automated reporting for easier comparisons and benchmarking
- Remove manual data entry and associated scope for inputting errors
- Integrations enable F0CUS functionality, while maintaining existing datasets, workflows, sources
- Supports data-driven, holistic decision making and service delivery
- Simplify processes; increase productivity, efficiency and value for money
- Designed and built by RICS-regulated quantity surveying consultancy, TSS
- Intuitive, accessible, real-time cloud-based system with offline capability
- One version of the truth underpins collaborative relationships
- Maintain data integrity, security and compliance with statutory obligations
Pricing
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
9 7 0 6 8 9 3 3 9 9 1 5 8 0 4
Contact
T SUMNER SMITH LTD.
Sinead Maguire
Telephone: 03333 110669
Email: enquiries@f0cus.co.uk
About the service
- Service categories
-
- Applications
- Enterprise resource management
- Procurement
- Procurement
- Order management and orchestration
- Order management and orchestration
- Enterprise performance management
- Enterprise performance management
- Project and portfolio management
- Project and portfolio management
- Asset life-cycle management
- Asset life-cycle management
- Procurement
- Enterprise resource management
- Applications
- Multi cloud support
- No
Service scope
- Software add-on or extension
- No
- Cloud deployment model
- Public cloud
- Service constraints
- F0CUS is a web-based service and does not require any specific hardware nor any browser plugins and there are no service constraints.
- System requirements
-
- Runs on Chrome, Firefox, Edge, Safari and Opera.
- Mobile app runs on IOS and Android v15 and above.
User support
- Email or online ticketing support
- Yes
- Support response times
-
Support requests are assigned a priority which is agreed with the person who logged it.
Response times within support desk working hours (08:30-17:00):
Priority 1 – Critical Business Impact –1 hour
Priority 2 – Moderate Business Impact – 2 hour
Priority 3 – Minimum Business Impact 8 hours.
Weekend response (08:30-17:00):
Priority 1 – 2 hours
Priority 2 – Next working day
Priority 3 – Next working day. - User can manage status and priority of support tickets
- Yes
- Online ticketing support accessibility
- WCAG 2.2 AAA
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- No
- Onsite support
- Yes, at extra cost
- Support levels
-
We have a standard support agreement which we have provided within the Documents section.
Our subscription cost includes the support levels stated within our standard support agreement cost including:
- A named account manager who will be the primary point of contract and will hold regular service review meetings with your team to discuss our how F0CUS is working for you, our performance and any upcoming changes in requirements or functionality.
- Automated, regular reports will include performance dashboards on our contractual key performance indicators and service level agreements.
- F0CUS Service Desk provides support to users including responding queries, additional training and process requests. The Service Desk is staffed by fully trained, UK-based in-house F0CUS specialists, experienced in supporting users with a range of abilities from novice to expert and providing step-by-step support.
- Users can log support calls at any time via the Support Portal (available 24/7/365).
Our service levels are ISO27001 compliant and designed in accordance with ITIL principles.
On-site support, bespoke training and additional out of hours cover are available at additional cost, which is priced on a case by case basis. - Support available to third parties
- Yes
Onboarding and offboarding
- Getting started
-
We provide full user training to help them to start using our service, easing the transition to a new system and ensuring business continuity. Our in-house training team usually delivers F0CUS training during the mobilisation period to ensure all users are aware of the system’s capabilities and can perform their role using F0CUS from Day 1.
Our interactive training sessions are engaging, accessible and impactful and include:
-Overview / tour of system
-Training specific to role function
-Invite questions and feedback .
Training can be delivered online via Teams or onsite in person.
We also provide early training for F0CUS Champion/s which embeds ‘super users’ who can support their teams.
Intensive early-life support can be provided including physical or virtual ‘floor walkers’, support sessions via Teams and in-person support from our technical team at the client’s offices.
Reference materials are available 24/7 via our online support portal and include:
-User Guides – straightforward and written in plain English providing structured, well-presented instructions on using F0CUS
-Training PowerPoint slides and training session recording
-Operating Manuals – technical documentation with configuration details for client technical teams
Contextual help is provided on the screens available by clicking help button. - Service documentation
- Yes
- Documentation formats
- Documentation accessibility standard
- WCAG 2.2 AAA
- End-of-contract data extraction
-
At the end of the contract we would appoint a F0CUS developer to work on a full extraction of the customer’s database and associated media. We would provide:
- A backup copy of the customer’s F0CUS instance, provided as either a .bak file or a .bacpac file. This can be hosted in our cloud solution and access provided.
- Access to the customer’s document and image repository via https in line with best practice at the time of demobilisation. - End-of-contract process
-
Customer data from F0CUS can be provided to any incoming service provider on formal instruction from the customer to maintain commercial sensitivity of their data. Should the only requirement be provision of contract data, we would expect to complete a full handover of data within 10 business days of instruction – with no further charge to the customer.
At the end of the contract there are a number of activities that are required to occur. These include:
- Compiling records of open activities and orders to either migrate these to incoming provider, or close out within F0CUS.
- Reviewing security arrangements for customer staff, de-allocating users if required to reduce security footprint during final stages of contract.
- Reviewing and arranging handover of any outstanding development roadmap items requested by customer.
-Providing process charts and user manuals to new provider.
We would expect to be able to complete a full handover to an incoming provider within six weeks of instruction (subject to the incoming provider’s mobilisation plan). Any bespoke requirements of the customer or incoming service provider beyond the standard process set out above may be subject to charges at our standard rates.
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Opera
- Application to install
- No
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
- Users accessing the website via a mobile device will receive a responsive version of the application. There is also a companion mobile application designed specifically for field operatives which allows them to capture data on site using a simplified interface.
- Service interface
- Yes
- Description of service interface
-
We aim to ensure that every user who interacts with F0CUS has the best possible user experience. To do this we:
- Keep the design simple
- Design dynamic step-by-step workflows
- Consider system performance in all screens
- Interact with our users
- Intuitive navigation
- Extensively test the system.
By following these principles we aim to ensure that the user experience in F0CUS is positive, and that users are not frustrated when using the system. We take great care in our design and work with users to provide the best possible interface for their requirements. - Accessibility standards
- WCAG 2.2 AAA
- Accessibility testing
-
All modern web browsers have accessibility extensions (the most common being JAWS) – because F0CUS is web-based and WCAG compliant these extensions and technologies work well with the major components of F0CUS.
F0CUS is ‘theme-able’ which enables us to override the default theme for specific users, providing a high contrast theme where required.
For public-facing web pages we adopt the single function approach to pages, removing pop ups and dynamic HTML which improves the ability of assistive technology. We also ensure that high contrast options are available to toggle in an obvious way.
We have a screen reader plug-in which we use with F0CUS to test the user interface for blind or visually impaired users. - User support accessibility
- WCAG 2.2 AAA
- API
- Yes
- What users can and can't do using the API
-
Our API is designed to enable third party applications to access the software programmatically. As such, the API is designed around replicating user interface functionality, and not system set up. Users can work with orders and assets, and can perform the majority of tasks that a user could through the web or mobile interface such as booking commercial value, planning work to a team, calling batch processes for orders, and applying for payment. In addition, our reporting API allows users to extract data in a rationalised form for use in their own systems.
Our API methodology is based around the Azure Cloud and as such can be connected easily to systems such as SAP, SalesForce and Oracle, and additional technologies such as SQL Server, MySQL, and the Microsoft suite of automation tools like power automate and the Microsoft Graph. - API documentation
- Yes
- API documentation formats
- Open API (also known as Swagger)
- API sandbox or test environment
- Yes
- Customisation available
- Yes
- Description of customisation
-
F0CUS is a tried and tested work and asset management solution which has delivered time and cost savings for our clients. Providing a tailored solution, its modular design enables configuration to your exact needs. The key modules include, but are not limited to:
• Order management
• Document management
• Asset management
• Planning
• Reporting
• Commercial management
For each F0CUS implementation we configure the system to meet our client’s needs. Customisable elements include:
• Choice of modules
• Configure workflows to meet contract requirements
• Bespoke dashboards and reports are available in addition to our extensive bank of standard report and dashboard formats.
• Integrations with existing systems.
The theme and overall presentation of the system can be customised by importing a client’s style sheet.
F0CUS is configured by our technical team during mobilisation. Collaborating closely with stakeholders, we follow our three-stage mobilisation process:
1. Analysis and fact-finding – map existing systems and processes, define ‘to be’ configuration and processes.
2. Configuration and pre-roll out – we configure F0CUS to meet client requirements agreed during Stage 1, undertake extensive testing including User Acceptance Testing and provide full user training.
3. Active and operate.
Scaling
- Independence of resources
-
Each client has their own F0CUS database. This ensures there is no loss of performance if another client’s usage model features resource-hungry queries or import operations.
F0CUS is run on an automatically scaling App Service in Microsoft Azure. Traffic is directed between instances of the application according to the utilisation of each instance. Should resource utilisation grow, either during peak hours or due to a large new implementation – then additional instances are added by Azure automatically.
Our databases use automatic index management functionality in Azure to provide a baseline which can be adjusted by our development team if needed.
Analytics
- Service usage metrics
- Yes
- Metrics types
- The system captures user usage and access details including which contract the user is working on, and which orders they have viewed. In addition, every transaction in F0CUS is time/date and user stamped. Our reporting allows us to drill into this information and produce logs not only of user access, but also the activity completed by the user and which orders / assets / records have been viewed or modified.
- Reporting types
-
- Real-time dashboards
- Regular reports
- Reports on request
- Resource tagging
- Yes
- FOCUS resource tagging
- No
Supplier type
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Other security clearance
- Government security clearance
- Security Clearance (SC)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- United Kingdom
- User control over data storage and processing locations
- No
- Datacentre security standards
- Complies with a recognised standard (for example CSA CCM version 4.0)
- Penetration testing frequency
- At least every 6 months
- Penetration testing approach
- In-house
- Protecting data at rest
-
- Physical access control, complying with CSA CCM v4.0
- Encryption of all physical media
- Scale, obfuscating techniques, or data storage sharding
- Data sanitisation process
- Yes
- Data sanitisation type
-
- Deleted data can’t be directly accessed / Cryptographic Erasure
- Explicit overwriting of storage before reallocation / Secure Erase
- Equipment disposal approach
- Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
Data importing and exporting
- Data export approach
-
F0CUS enables data from all modules to be combined into meaningful reports to drive better informed business decisions.
All data captured via, or integrated into, F0CUS can be reported on ensuring consistency across business functions. Data is available through our reporting models and can be exported / imported to client reporting tools such as Power BI.
Generated reports can be presented as PDFs, Excel files, CSV, Crystal Reports and PowerBI. Mapping tools allow customers to import or link to GeoJSON files for map-based data.
Reporting, including real-time dashboards, can be automated and scheduled, driven by data, customer or security criteria. - Data export formats
- CSV
- Data import formats
-
- CSV
- ODF
- Other
- Other data import formats
-
- JSON
- XML
Data-in-transit protection
- Data protection between buyer and supplier networks
- TLS (version 1.2 or above)
- Data protection within supplier network
-
- TLS (version 1.2 or above)
- IPsec or TLS VPN gateway
Availability and resilience
- Guaranteed availability
-
We measure and report on F0CUS’s availability via an uptime report which is available at any time and included in monthly service review reports.
Our SLA for availability is:
System Uptime – Minimum standard 99.5% - Expected 99.99%
We operate a Service Credits mechanism whereby the client can be compensated for total system downtime for all users and non-compliance with support request Service Level Targets. Further details available on request.
In the last 2 years, we have achieved 99.99% uptime and experienced 0 instances which have affected the continuity of service. - Approach to resilience
- Our F0CUS Resiliency White Paper is available on request.
- Outage reporting
- We operate a public uptime dashboard (https://tss.f0cus.co.uk/status/index) that details outages and uptime. In addition, we receive email alerts if there are any outages plus a daily digest email of the previous day’s availability. Our backend services are continually monitored through an internal service dashboard.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Identity federation with existing provider (for example Google Apps)
- Username or password
- Access restrictions in management interfaces and support channels
- Access to management interfaces and support channels is restricted to authorised personnel within our business. Access is restricted to known IP addresses, and multi-factor authentication is in place for users accessing these channels. Users with access are regularly reviewed and reported on. Within the management interfaces we operate a granular security approach with users provided a least-access profile to complete the tasks they are required to complete. New user access to the management interfaces must be approved at board level in addition to resource owner.
- Access restriction testing frequency
- At least every 6 months
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Identity federation with existing provider (for example Google Apps)
- Username or password
Audit information for users
- Access to user activity audit information
- Users contact the support team to get audit information
- How long user audit data is stored for
- User-defined
- Access to supplier activity audit information
- Users contact the support team to get audit information
- How long supplier audit data is stored for
- User-defined
- How long system logs are stored for
- User-defined
Security governance
- Named board-level person responsible for service security
- Yes
- Software Security Code of Practice
- Yes
- Security governance certified
- Yes
- Security governance standards
- ISO/IEC 27001
- Information security policies and processes
-
Our Information Security Policy (ISP) forms the basis of our Information Security Management System (ISMS) and is assessed as part of our ISO27001 and Cyber Essentials accreditations. Its main objective is to ensure that the information processed (including storage) by T Sumner Smith Ltd (TSS) is protected against internal and external threats, both deliberate and accidental. The policy ensures that:
· Confidentiality of information will be assured.
· Integrity of information will be maintained.
· Availability of information for business processes will be maintained.
Our ISMS roles and responsibilities and reporting structure is:
• Board of Directors – ultimately responsible for ISMS.
• Information Security Manager – responsible for implementing ISP and investigating actual, potential or suspected breaches.
• Data Protection Officer – responsible for developing and implementing data security policies.
• Infrastructure Manager – responsible for providing secure tools and infrastructure to control IT security, and logging and auditing of security management.
• Information Asset Owners - responsible for determining the information security risks associated with owned assets and reporting them to the Information Security Manager for inclusion on the risk register.
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
-
All significant changes have an audit trail through requests and change logs. Changes are subject to our strict version control processes. These ensure that all changes, regardless of scope or impact are versioned and can be reverted at any time. All versions and changes are stored in our ‘Git’ repository in Microsoft Azure. We operate a strict procedure for managing versions and ‘checking in’ code changes.
Proposed changes are evaluated to assess feasibility, impact and risks. Evaluation considers factors including resource requirements, time constraints, dependencies, potential conflicts with existing functionalities and security implications. Security considerations are included within non-functional requirements. - Vulnerability management type
- Supplier-defined controls
- Vulnerability management approach
- We operate a number of vulnerability scanning solutions both provided by Microsoft through their cloud Defender platform, and also through external providers. We install all critical or high security updates as soon as we are notified of a vulnerability, and also review third party components in our code base for vulnerabilities and deprecation. As standard, we only operate software within the business that operates using automated patch management.
- Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
-
We operate a number of vulnerability scanning solutions both provided by Microsoft through their cloud Defender platform, and also through external providers. We install all critical or high security updates as soon as we are notified of a vulnerability, and also review third party components in our code base for vulnerabilities and deprecation.
We operate an incident management procedure for any incidents that arise, as part of our ISO27001 and GDPR toolkits. The procedure provides a clear route for reporting incidents and a framework of management responsibilities and actions for containment, mitigation and recovery. - Incident management type
- Supplier-defined controls
- Post-quantum cryptography secure
- No
- Incident management approach
-
We operate an incident management procedure for any incidents that are raised as part of our ISO27001 and GDPR toolkits. The procedure includes pre-defined processes for a range of potential scenarios.
Users report incidents using the Ticket Centre within the F0CUS Support Portal. Tickets categorised as security incidents will be dealt with as a high priority by the F0CUS Security Team.
The incident management procedure details a framework of management responsibilities and actions for containment, mitigation and recovery. Incident reports compiled upon resolution of the incident. Relevant stakeholders immediately notified of significant incidents and kept updated regarding resolution progress throughout.
Secure development
- Approach to secure software development best practice
- Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- No
- Free trial available
- No
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 2.5%
- Between £500,001 and £1,000,000
- 5%
- Between £1,000,001 and £2,500,000
- 7.5%
- Between £2,500,001 and £5,000,000
- 10%
- Over £5,000,001
- 12.5%
Standards and certifications
- ISO/IEC 27001 certification
- Yes
- ISO/IEC 27001 accredited by
- Citation ISO Certification
- ISO/IEC 27001 accreditation date
- Wednesday 8 September 2021
- What the ISO/IEC 27001 doesn’t cover
- No exclusions.
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- Yes
- ISO 9001 certification accredited by
- Citation ISO Certification
- ISO 9001 accreditation date
- Tuesday 30 October 2012
- What the ISO 9001 doesn’t cover
- No exclusions.
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- No
- Cyber Essentials Alternative
- None of the criteria
- Cyber essentials plus
- Yes
- Cyber Essentials Plus Certificate Number
- 487dc72c-dc6a-4f92-aaaf-34f80ec361ad
- Other security certifications
- No
Social value
- Mission: Kick start economic growth
-
To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- New or retained jobs on the contract workforce in the relevant area that meet the criteria set out in MAC 1b, 1c and 1d
- Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
- Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
- Measures to support in-work progression to help people in the contract workforce, to move into higher paid work by developing new skills relevant to the contract
- Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
- Volunteering opportunities for staff
- Understanding of the modern slavery risks and issues affecting the market, industry, sector or country (of origin or of source) relevant to the contract, and the workforce in the supplier’s own organisation and those of its key subcontractors
- Outline policies and practices to be applied to or put in place for the contract to mitigate and manage modern slavery risks, including: Pre-employment checks, recruitment practices. Workplace conditions, safeguarding plans and processes in place and regular monitoring with relevant groups considered, which may include sampling
Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.
- Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
- Delivery of apprenticeships, supported internships and T Level industry placement opportunities (Level 2, 3 and 4+) in relation to the contract
Policy Outcome 3: Resilient, innovative and flexible supply chains: Support economic growth through enabling resilient businesses, opportunities for small businesses and voluntary, community and social enterprises
- Activities that demonstrate a collaborative way to work with a diverse range of businesses as part of the supply chain
- Support for community-led initiatives relevant to the contract. Illustrative examples: improving transport links; reducing loneliness; helping with English language proficiency; and facilitating social mixing among people with different backgrounds
- Mission: Make Britain a clean energy superpower
-
To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero
Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.
- Collaborative ways of working with the supply chain to deliver additional environmental benefits in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
- Activities to reconnect people with the environment and increase awareness of ways to protect and enhance it
- Mission: Break down barriers to opportunity
-
By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain
Policy Outcome 6: Employment and training: For those who face barriers to employment
- Creation of employment opportunities particularly for those who face barriers to employment, such as prison leavers, care leavers and/or who are located in deprived areas, and for people in industries with known skills shortages or in high growth sectors
- Working conditions which promote an inclusive working environment and promote retention and progression
- Understanding of the issues affecting inequality in employment, skills and pay in the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors. Measures to tackle inequality in employment, skills and pay in the contract workforce
Policy Outcome 7: Creating a pipeline of opportunities: For the contract workforce, reducing barriers to entry for under-represented groups.
- Understanding of the underlying factors affecting improvements to reduce barriers to entry and training schemes for the target cohort(s) related to the contract workforce
- Understanding of issues relating to entering the contract workforce
- Mission: Build an NHS fit for the future
-
That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.
Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.
- Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce