Internal Controls Manager
CoreStream Controls Manager is a flexible platform for creating and managing an effective control environment across your organisation. Automation & driving efficiency are the heart of the platform with
simple and intuitive interface to aid adoption in your business. Link controls to related content such as policies, processes and risks.
Features
- Platform maps all internal controls onto defined process flows.
- Platform automates control assessments with reminders and reviews.
- Centralised/decentralised controls framework with mapped risks, processes, and governance.
- Automated control testing with deficiency & remediation.
- AI pinpoints control gaps & guides improvement for assertions.
- Track & manage control gaps, automate tasks, escalate, review closure.
- AI co-pilot suggests content, boosting productivity and quality
- Control dashboards track status & user engagement with timers
- Platform automates control tasks & reviews for real-time performance
Benefits
- Internal controls lessen risks through error, fraud, and efficiency safeguards.
- Internal controls: Secret weapon for efficiency, streamlining processes.
- Controls ensure accurate financial data for decisions, trust, and compliance.
- Internal controls ensure legal compliance & prevent deviations.
- Internal controls stop fraud & theft through checks and reviews.
- Strong controls deliver reliable data for informed decisions.
- Internal controls safeguard assets, enabling smooth operations and accurate financials.
- Internal controls clarify roles & build a responsible culture
- Regular checks improve controls by identifying and fixing weaknesses.
- Strong controls build stakeholder trust in governance.
Pricing
- Education pricing available
- Free trial available
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
1 0 0 9 2 1 6 5 1 7 1 9 9 1 5
Contact
CORE STREAM LTD
Matthew Eddolls
Telephone: 0207 100 4378
Email: tenders@corestream.co.uk
About your service
- Service categories
-
Applications
Enterprise resource management
- Enterprise performance management
- Multi cloud support
- Yes
Service scope
- Software add-on or extension
- Yes, but can also be used as a standalone service
- What software services is the service an extension to
- The CoreStream Platform is a fully integrated set of components for solving common, Governance, Risk and Compliance Challenges. Please refer to the G-Cloud Catalogue. Whilst each module can operate independently, additional modules can be provided for lower incremental cost, allowing to to advance your GRC practice with ease.
- Cloud deployment model
- Private cloud
- Service constraints
- None
- System requirements
- All modern browsers are supported (including Mobile operating systems)
User support
- Email or online ticketing support
- Yes
- Support response times
- 30 minutes, within UK business hours (8am to 6pm)
- User can manage status and priority of support tickets
- Yes
- Online ticketing support accessibility
- WCAG 2.2 AA
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- No
- Onsite support
- Yes, at extra cost
- Support levels
-
Our standard model is for 2nd and 3rd line support to be included in our license fee.
First line support is typically best provided by our clients, but can be provided by CoreStream if necessary. This would be by separate negotiation as it will depend on system complexity and number of users - Support available to third parties
- Yes
Onboarding and offboarding
- Getting started
- Training can be arranged as required, however our system is designed with intuitiveness and user-friendliness in mind, and formal training is rarely required. Full documentation of client specific configuration will be provided in online guides, contextual help, and on-screen prompts
- Service documentation
- Yes
- Documentation formats
- HTML
- End-of-contract data extraction
- Data repatriation and purging / destruction of data from all servers including backups is included. Additional requirements for delivery of the data in non-standard file formats or with transformations applied will be chargeable per the standard rate card.
- End-of-contract process
- Data repatriation will be provided free of charge (in raw text and PDF formats)
- Documentation accessibility standard
- WCAG 2.2 AA
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Opera
- Application to install
- No
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
-
Our user interface is a mobile-first design and fully responsive for all screen sizes from smartphone mobile devices, up to full desktop machines.
Some advanced features such as process mapping are not suitable for small screen sizes - Service interface
- No
- User support accessibility
- WCAG 2.2 AA
- API
- Yes
- What users can and can't do using the API
- Our application is built upon formal architectural layers, with APIs enabling communication between them. As such, all features are available via API (both read and write operations), subject to permissions.
- API documentation
- Yes
- API documentation formats
- Open API (also known as Swagger)
- API sandbox or test environment
- Yes
- Customisation available
- Yes
- Description of customisation
- Admin users can be trained to configure any part of the system
Scaling
- Independence of resources
- All clients are on a dedicated web application with protected compute and storage resources.
Analytics
- Service usage metrics
- Yes
- Metrics types
- Logins, session length
- Reporting types
- Reports on request
- Resource tagging
- Yes
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Conforms to BS7858:2019
- Government security clearance
- Security Clearance (SC)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- United Kingdom
- User control over data storage and processing locations
- Yes
- Datacentre security standards
- Managed by a third party
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- ‘IT Health Check’ performed by a CHECK service provider
- Protecting data at rest
-
- Physical access control, complying with CSA CCM v4.0
- Physical access control, complying with SSAE-18 / ISAE 3402
- Encryption of all physical media
- Data sanitisation process
- Yes
- Equipment disposal approach
- Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
- Data sanitisation type
-
- Deleted data can’t be directly accessed / Cryptographic Erasure
- Data Erasure
- Explicit overwriting of storage before reallocation / Secure Erase
Data importing and exporting
- Data export approach
- Excel, PDF and fully formatted / branded Word extracts can be provided as required. And export wizard can be made available on any grid across the platform.
- Data export formats
-
- CSV
- Other
- Other data export formats
-
- XLS
- .DOCX
- Data import formats
-
- CSV
- Other
- Other data import formats
-
- Excel
- JSON (Via REST API)
Data-in-transit protection
- Data protection between buyer and supplier networks
- TLS (version 1.2 or above)
- Data protection within supplier network
-
- TLS (version 1.2 or above)
- IPsec or TLS VPN gateway
Availability and resilience
- Guaranteed availability
- 99.9% guaranteed, with service credits should this level not be achieved (10% refund of the monthly licence fee per 2% below 99.9%)
- Approach to resilience
- We utilise multiple resilience arrangements and regularly practice disaster recovery scenarios. For security reasons, full details are available on request.
- Outage reporting
- Email alerts will be generated upon a service being unavailable for a period of 5 minutes.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Identity federation with existing provider (for example Google Apps)
- Dedicated link (for example VPN)
- Username or password
- Other
- Other user authentication
- Single Sign On via OAuth or SAML 2.0
- Access restrictions in management interfaces and support channels
- Hidden webpages with additional security group requirements.
- Access restriction testing frequency
- At least every 6 months
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Public key authentication (including by TLS client certificate)
- Identity federation with existing provider (for example Google Apps)
- Dedicated link (for example VPN)
- Username or password
- Other
- Description of management access authentication
- Single Sign on via oAuth or SAML 2.0
Audit information for users
- Access to user activity audit information
- Users contact the support team to get audit information
- How long user audit data is stored for
- User-defined
- Access to supplier activity audit information
- Users have access to real-time audit information
- How long supplier audit data is stored for
- User-defined
- How long system logs are stored for
- User-defined
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
-
- ISO/IEC 27001
- Other
- Other security governance standards
- SOC2 Type 2 (Security and Availability)
- Information security policies and processes
- Production information never replicated and stored in non production environments. Administrator access to production environments is limited to a handful of senior, named individuals who can only access via secure VPN, and named server accounts. CoreStream has a documented ISMS policy which is continually reviewed and redistributed to employees on an annual basis. Information Security events are recorded in a central database and reviewed by board-level management with actions and follow-ups implemented as required.
- Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
-
Software changes are subject to a standard requirements definition template and reviewed by senior functional and security design resource before being approved for development.
Once developed, changes are assigned to a specific release, with this release passing through a defined 'path to live' - escalating from development to test environment before being placed in a stage environment for final checks.
New changes, once developed are reviewed by a security test specialist and also subject to ongoing vulnerability scanning and penetration testing. - Vulnerability management type
- Supplier-defined controls
- Vulnerability management approach
-
We employ an ongoing external third party fully managed service to continually review our servers for known vulnerabilities. (Daily scans)
Once a vulnerability is discovered, a user story is raised for a new software or configuration change, which will be then pass through our standard development process outlined above, however for serious vulnerabilities a specific patch release will be created to speed up the release process.
The most serious vulnerabilities will be resolved within 6 hours.
In addition we run monthly sweeps for internal vulnerabilities, with the same resolution process described above being applied. - Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
-
We employ multiple third party services to continually review our servers for known vulnerabilities and this forms the same process for protective monitoring.
Once a compromise is discovered, a user story is raised for a new software or configuration change, which will be then pass through our standard development process outlined above, however for serious vulnerabilities a specific patch release will be created to speed up the release process.
The most serious compromises will be resolved within 6 hours. - Incident management type
- Supplier-defined controls
- Incident management approach
-
We make use of our own software platform for incident reporting using an online form. Incidents are then automatically escalated to a fortnightly director meeting for review.
Incidents impacting clients will be communicated on an ad-hoc basis if and when they occur. - Post-quantum cryptography secure
- Yes
Secure development
- Approach to secure software development best practice
- Conforms to a recognised standard, but self-assessed
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- Yes
- Free trial available
- Yes
- Description of free trial
- A fully functioning trial system can be arranged by negotiation
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 0%
- Between £500,001 and £1,000,000
- 0%
- Between £1,000,001 and £2,500,000
- 0%
- Between £2,500,001 and £5,000,000
- 0%
- Over £5,000,001
- 0%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- Yes
- Who accredited the ISO/IEC 27001
- British Assessment Bureau
- ISO/IEC 27001 accreditation date
- Monday 15 September 2025
- What the ISO/IEC 27001 doesn’t cover
- The certification covers the entirety of our company and the software platform we provide.
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- No
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- 7ffc5d0b-0193-4c41-b3d0-d13d31d872f1
- Cyber essentials plus
- No
- Cyber Essentials Alternative
- You do not have a current and valid Cyber Essentials Plus certificate, or will not have in place within 12 months of the date of award but have an IASME certified equivalent.
- Other security certifications
- Yes
- Any other security certifications
-
- SOC2 Type 2 (Security and Availability)
- TX Ramp
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- New or retained jobs on the contract workforce in the relevant area that meet the criteria set out in MAC 1b, 1c and 1d
- Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.
- Activities to support relevant sector related skills growth and sustainability in the contract workforce. Illustrative examples: careers talks, curriculum support, literacy support, safety talks and volunteering
-