Skip to main content

Help us improve the Digital Marketplace - send your feedback

CORE STREAM LTD

Internal Controls Manager

CoreStream Controls Manager is a flexible platform for creating and managing an effective control environment across your organisation. Automation & driving efficiency are the heart of the platform with
simple and intuitive interface to aid adoption in your business. Link controls to related content such as policies, processes and risks.

Features

  • Platform maps all internal controls onto defined process flows.
  • Platform automates control assessments with reminders and reviews.
  • Centralised/decentralised controls framework with mapped risks, processes, and governance.
  • Automated control testing with deficiency & remediation.
  • AI pinpoints control gaps & guides improvement for assertions.
  • Track & manage control gaps, automate tasks, escalate, review closure.
  • AI co-pilot suggests content, boosting productivity and quality
  • Control dashboards track status & user engagement with timers
  • Platform automates control tasks & reviews for real-time performance

Benefits

  • Internal controls lessen risks through error, fraud, and efficiency safeguards.
  • Internal controls: Secret weapon for efficiency, streamlining processes.
  • Controls ensure accurate financial data for decisions, trust, and compliance.
  • Internal controls ensure legal compliance & prevent deviations.
  • Internal controls stop fraud & theft through checks and reviews.
  • Strong controls deliver reliable data for informed decisions.
  • Internal controls safeguard assets, enabling smooth operations and accurate financials.
  • Internal controls clarify roles & build a responsible culture
  • Regular checks improve controls by identifying and fixing weaknesses.
  • Strong controls build stakeholder trust in governance.

Pricing

  • Education pricing available
  • Free trial available

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at tenders@corestream.co.uk. Tell them what format you need. It will help if you say what assistive technology you use.

Framework

G-Cloud 15

Service ID

1 0 0 9 2 1 6 5 1 7 1 9 9 1 5

Contact

CORE STREAM LTD Matthew Eddolls
Telephone: 0207 100 4378
Email: tenders@corestream.co.uk

About your service

Service categories

Applications

Enterprise resource management

  • Enterprise performance management
Multi cloud support
Yes

Service scope

Software add-on or extension
Yes, but can also be used as a standalone service
What software services is the service an extension to
The CoreStream Platform is a fully integrated set of components for solving common, Governance, Risk and Compliance Challenges. Please refer to the G-Cloud Catalogue. Whilst each module can operate independently, additional modules can be provided for lower incremental cost, allowing to to advance your GRC practice with ease.
Cloud deployment model
Private cloud
Service constraints
None
System requirements
All modern browsers are supported (including Mobile operating systems)

User support

Email or online ticketing support
Yes
Support response times
30 minutes, within UK business hours (8am to 6pm)
User can manage status and priority of support tickets
Yes
Online ticketing support accessibility
WCAG 2.2 AA
Phone support
Yes
Phone support availability
9 to 5 (UK time), Monday to Friday
Web chat support
No
Onsite support
Yes, at extra cost
Support levels
Our standard model is for 2nd and 3rd line support to be included in our license fee.
First line support is typically best provided by our clients, but can be provided by CoreStream if necessary. This would be by separate negotiation as it will depend on system complexity and number of users
Support available to third parties
Yes

Onboarding and offboarding

Getting started
Training can be arranged as required, however our system is designed with intuitiveness and user-friendliness in mind, and formal training is rarely required. Full documentation of client specific configuration will be provided in online guides, contextual help, and on-screen prompts
Service documentation
Yes
Documentation formats
HTML
End-of-contract data extraction
Data repatriation and purging / destruction of data from all servers including backups is included. Additional requirements for delivery of the data in non-standard file formats or with transformations applied will be chargeable per the standard rate card.
End-of-contract process
Data repatriation will be provided free of charge (in raw text and PDF formats)
Documentation accessibility standard
WCAG 2.2 AA

Using the service

Web browser interface
Yes
Supported browsers
  • Microsoft Edge
  • Firefox
  • Chrome
  • Safari
  • Opera
Application to install
No
Designed for use on mobile devices
Yes
Differences between the mobile and desktop service
Our user interface is a mobile-first design and fully responsive for all screen sizes from smartphone mobile devices, up to full desktop machines.

Some advanced features such as process mapping are not suitable for small screen sizes
Service interface
No
User support accessibility
WCAG 2.2 AA
API
Yes
What users can and can't do using the API
Our application is built upon formal architectural layers, with APIs enabling communication between them. As such, all features are available via API (both read and write operations), subject to permissions.
API documentation
Yes
API documentation formats
Open API (also known as Swagger)
API sandbox or test environment
Yes
Customisation available
Yes
Description of customisation
Admin users can be trained to configure any part of the system

Scaling

Independence of resources
All clients are on a dedicated web application with protected compute and storage resources.

Analytics

Service usage metrics
Yes
Metrics types
Logins, session length
Reporting types
Reports on request
Resource tagging
Yes
FOCUS resource tagging
No

Resellers

Supplier type
Not a reseller

Staff security

Staff security clearance
Conforms to BS7858:2019
Government security clearance
Security Clearance (SC)

Asset protection

Knowledge of data storage and processing locations
Yes
Data storage and processing locations
United Kingdom
User control over data storage and processing locations
Yes
Datacentre security standards
Managed by a third party
Penetration testing frequency
At least once a year
Penetration testing approach
‘IT Health Check’ performed by a CHECK service provider
Protecting data at rest
  • Physical access control, complying with CSA CCM v4.0
  • Physical access control, complying with SSAE-18 / ISAE 3402
  • Encryption of all physical media
Data sanitisation process
Yes
Equipment disposal approach
Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
Data sanitisation type
  • Deleted data can’t be directly accessed / Cryptographic Erasure
  • Data Erasure
  • Explicit overwriting of storage before reallocation / Secure Erase

Data importing and exporting

Data export approach
Excel, PDF and fully formatted / branded Word extracts can be provided as required. And export wizard can be made available on any grid across the platform.
Data export formats
  • CSV
  • Other
Other data export formats
  • XLS
  • .DOCX
Data import formats
  • CSV
  • Other
Other data import formats
  • Excel
  • JSON (Via REST API)

Data-in-transit protection

Data protection between buyer and supplier networks
TLS (version 1.2 or above)
Data protection within supplier network
  • TLS (version 1.2 or above)
  • IPsec or TLS VPN gateway

Availability and resilience

Guaranteed availability
99.9% guaranteed, with service credits should this level not be achieved (10% refund of the monthly licence fee per 2% below 99.9%)
Approach to resilience
We utilise multiple resilience arrangements and regularly practice disaster recovery scenarios. For security reasons, full details are available on request.
Outage reporting
Email alerts will be generated upon a service being unavailable for a period of 5 minutes.

Identity and authentication

User authentication needed
Yes
User authentication
  • Multi-Factor Authentication (MFA)
  • Identity federation with existing provider (for example Google Apps)
  • Dedicated link (for example VPN)
  • Username or password
  • Other
Other user authentication
Single Sign On via OAuth or SAML 2.0
Access restrictions in management interfaces and support channels
Hidden webpages with additional security group requirements.
Access restriction testing frequency
At least every 6 months
Management access authentication
  • Multi-Factor Authentication (MFA)
  • Public key authentication (including by TLS client certificate)
  • Identity federation with existing provider (for example Google Apps)
  • Dedicated link (for example VPN)
  • Username or password
  • Other
Description of management access authentication
Single Sign on via oAuth or SAML 2.0

Audit information for users

Access to user activity audit information
Users contact the support team to get audit information
How long user audit data is stored for
User-defined
Access to supplier activity audit information
Users have access to real-time audit information
How long supplier audit data is stored for
User-defined
How long system logs are stored for
User-defined

Security governance

Named board-level person responsible for service security
Yes
Security governance certified
Yes
Security governance standards
  • ISO/IEC 27001
  • Other
Other security governance standards
SOC2 Type 2 (Security and Availability)
Information security policies and processes
Production information never replicated and stored in non production environments. Administrator access to production environments is limited to a handful of senior, named individuals who can only access via secure VPN, and named server accounts. CoreStream has a documented ISMS policy which is continually reviewed and redistributed to employees on an annual basis. Information Security events are recorded in a central database and reviewed by board-level management with actions and follow-ups implemented as required.
Software Security Code of Practice
Yes

Operational security

Configuration and change management standard
Supplier-defined controls
Configuration and change management approach
Software changes are subject to a standard requirements definition template and reviewed by senior functional and security design resource before being approved for development.

Once developed, changes are assigned to a specific release, with this release passing through a defined 'path to live' - escalating from development to test environment before being placed in a stage environment for final checks.

New changes, once developed are reviewed by a security test specialist and also subject to ongoing vulnerability scanning and penetration testing.
Vulnerability management type
Supplier-defined controls
Vulnerability management approach
We employ an ongoing external third party fully managed service to continually review our servers for known vulnerabilities. (Daily scans)

Once a vulnerability is discovered, a user story is raised for a new software or configuration change, which will be then pass through our standard development process outlined above, however for serious vulnerabilities a specific patch release will be created to speed up the release process.

The most serious vulnerabilities will be resolved within 6 hours.

In addition we run monthly sweeps for internal vulnerabilities, with the same resolution process described above being applied.
Protective monitoring type
Supplier-defined controls
Protective monitoring approach
We employ multiple third party services to continually review our servers for known vulnerabilities and this forms the same process for protective monitoring.

Once a compromise is discovered, a user story is raised for a new software or configuration change, which will be then pass through our standard development process outlined above, however for serious vulnerabilities a specific patch release will be created to speed up the release process.

The most serious compromises will be resolved within 6 hours.
Incident management type
Supplier-defined controls
Incident management approach
We make use of our own software platform for incident reporting using an online form. Incidents are then automatically escalated to a fortnightly director meeting for review.

Incidents impacting clients will be communicated on an ad-hoc basis if and when they occur.
Post-quantum cryptography secure
Yes

Secure development

Approach to secure software development best practice
Conforms to a recognised standard, but self-assessed

Public sector networks

Connection to public sector networks
No

Pricing

Discount for educational organisations
Yes
Free trial available
Yes
Description of free trial
A fully functioning trial system can be arranged by negotiation

Discount percentage by annual call-off contract value (excluding VAT)

Less than £250,000
0%
Between £250,000 and £500,000
0%
Between £500,001 and £1,000,000
0%
Between £1,000,001 and £2,500,000
0%
Between £2,500,001 and £5,000,000
0%
Over £5,000,001
0%

Non-mandatory Standards and certifications

ISO/IEC 27001 certification
Yes
Who accredited the ISO/IEC 27001
British Assessment Bureau
ISO/IEC 27001 accreditation date
Monday 15 September 2025
What the ISO/IEC 27001 doesn’t cover
The certification covers the entirety of our company and the software platform we provide.
ISO 28000:2022 certification
No
ISO 9001 certification
No
Quality management systems (QMS)
Yes
CSA STAR certification
No
PCI certification
No
Cyber essentials
Yes
Please provide your Cyber Essentials Certificate Number
7ffc5d0b-0193-4c41-b3d0-d13d31d872f1
Cyber essentials plus
No
Cyber Essentials Alternative
You do not have a current and valid Cyber Essentials Plus certificate, or will not have in place within 12 months of the date of award but have an IASME certified equivalent.
Other security certifications
Yes
Any other security certifications
  • SOC2 Type 2 (Security and Availability)
  • TX Ramp

Social value

Section B - Commitment for Future: Delivery
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority

    • New or retained jobs on the contract workforce in the relevant area that meet the criteria set out in MAC 1b, 1c and 1d
    • Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.

    • Activities to support relevant sector related skills growth and sustainability in the contract workforce. Illustrative examples: careers talks, curriculum support, literacy support, safety talks and volunteering

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at tenders@corestream.co.uk. Tell them what format you need. It will help if you say what assistive technology you use.