Skip to main content

Help us improve the Digital Marketplace - send your feedback

Clew

Clew Software

Clew provides a cloud-based software platform which enables management of risk and assurance in a way that is resolutely focused on decisions and outcomes. It provides a golden thread connecting objectives to actions, allowing organisations to act with confidence. Users span public, private and third-sector organisations in 70+ countries.

Features

  • Active management of objectives, linking to performance indicators/other records.
  • Risk management at enterprise, operational and project/programme levels.
  • Capability across audit, compliance and safety management domains.
  • Quantitative performance analysis through automated indicators, scenario and Monte-Carlo modelling.
  • Reporting suite including dashboards, custom csv and PowerBI API.
  • Use 'in-the-field' through CGRF Mobile (iOS/Android) including offline mode.
  • AI-leveraged capabilities including generative, search/linking, and user guidance.
  • Fully auditable history of changes in all modules.
  • Supports API integrations.
  • Extensive in-house self-configuration capability.

Benefits

  • Decision-support with clear objectives-focused picture informed by business intelligence.
  • Integrated risk picture across different business areas in single application.
  • Wide capability across governance domains enables staged and incremental benefit.
  • Array of insights enhances decision-making to improve performance outcomes.
  • Flexible approach to tailored in-application and external reporting.
  • Supports array of operational use-cases through field-use via mobile app.
  • AI features accelerate insights and discovery while keeping human in-the-loop.
  • Full confidence in data and enhanced accountability through audit histories.
  • Efficiencies through reduction in overheads associated with standard office tools.
  • Enhanced flexibility for evolving requirements and reduced vendor dependency.

Pricing

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at pat.parker@clew.io. Tell them what format you need. It will help if you say what assistive technology you use.

Framework

G-Cloud 15

Service ID

1 2 6 5 3 0 9 5 2 3 7 1 3 7 9

Contact

Clew Patrick Parker
Telephone: 0118 2059378
Email: pat.parker@clew.io

About the service

Service categories

Applications

Enterprise resource management

  • Enterprise performance management
Multi cloud support
No

Service scope

Software add-on or extension
No
Cloud deployment model
Public cloud
Service constraints
The only constraint we wish to highlight is that we deploy our Clew software on our AWS infrastructure only - we do not deploy on-premise or to bespoke customer cloud environments.
System requirements
  • Our web application requires access through standard supported browsers.
  • Our mobile app requires supported iOS/Android operating systems.

User support

Email or online ticketing support
Yes
Support response times
Tickets highlighting technical errors will be triaged based on severity level and handled in accordance with our SLA (which is embedded within our Terms and Conditions document). Response times range from one hour to one business day, and target resolution times range from six hours to three business days. Tickets raising general queries (eg enquiries about additional capability, or configuration change requests where Clew support is requested) will be responded to within standard business norms, typically 1-2 business days.
User can manage status and priority of support tickets
No
Phone support
Yes
Phone support availability
9 to 5 (UK time), Monday to Friday
Web chat support
No
Onsite support
Yes, at extra cost
Support levels
Clew's SLA identifies three support levels for enquiries. The first two are with the customer - helpdesk and system champion. This reflects that the majority of requests relate to user accounts and access permissions which are within the customer's responsibility to determine. Our training and online support portal make this straightforward. Other queries, eg relating to configuration changes, can also be addressed by customer champions through system admin privileges. Any queries relating to a suspected technical fault or to requests for configuration change support can be raised by designated customer users for Level 3 support with Clew. Clew will triage these as: Platform Error (with response times as indicated above and in accordance with our SLA); Platform Use (where support will guide the customer to the relevant online support article); Configuration Requests (eg where a customer requests that Clew manage a configuration change as part of a paid-for support package).
Support available to third parties
Yes

Onboarding and offboarding

Getting started
During initial deployment, Clew builds a Configuration Scoping Document (CSD) which captures in detail the customer's exact requirements down to individual fields, forms, workflows, email notifications etc. Typically this level of detail has not been available during pre-contract negotiation/tender process etc. This process is collaborative - including provision of access to a drawing tool where example process flow diagrams are provided and either accepted or adjusted as required. The CSD is then signed-off by the customer, and initial configuration built. This will be modified through workshops and UAT until approved. Initial configuration will include Single Sign On, user account set-up and organisational structure prior to detailed module-specific configuration. Training will be provided, focused on standard users (through train-the-trainer approach) and system admin users, focused on enabling self-help following transition to BaU. The production environment will be deployed, data imported through a managed cut-over plan, and formal Go Live approved. Clew offers a Post Go Live Onboarding Support service, designed to account for change requests arising in the early months (which can still occur despite a customer's best efforts to pre-empt through workshops and UAT) and for hand-holding of customer system admin users in the early stages of live use.
Service documentation
Yes
Documentation formats
  • PDF
  • Other
Other documentation formats
Online portal.
End-of-contract data extraction
Customers can extract all data through csv export options. This can be done for records en-masse by module.
End-of-contract process
Clew will provide customer data in a csv flat file, and will make available all attachments in file formats that contain mapping to parent records based on unique system ID. Clew will return or destroy all copies of Customer Data in its possession within 40 days of termination - including permanent destruction of all customer instances.
Documentation accessibility standard
WCAG 2.2 AA

Using the service

Web browser interface
Yes
Supported browsers
  • Microsoft Edge
  • Firefox
  • Chrome
  • Safari
  • Opera
  • Other
Application to install
No
Designed for use on mobile devices
Yes
Differences between the mobile and desktop service
Clew has a mobile app available in the app store, which can also be controlled across an organisation's mobile device fleet through MS Intune. The mobile app is designed as a fieldwork and reporting tool - as such, it only makes available records that are created by or assigned to a user, and not all records to which their system permissions would give them wider access in the web app.
Service interface
Yes
User support accessibility
WCAG 2.2 A
Description of service interface
Log-in via standard supported browsers through manual log-in approach or Single Sign On.
Accessibility standards
WCAG 2.2 A
Accessibility testing
Our Accessibility Conformance Report, based on the Voluntary Product Accessibility Template (VPAT) and available on request, identifies that our testing includes macOS and Windows screen readers (VoiceOver and NVDA), AXE DevTools, Lighthouse, and AXE Developer Hub.
API
Yes
What users can and can't do using the API
Clew has a standard API connector and can make available end-points for customers to build and map to. Users can create, read, update and delete records via the API. To ensure platform stability, performance, and fair usage, Clew reserves the right to apply rate limiting where customer configurations or usage patterns are suboptimal or exceed reasonable thresholds.
API documentation
Yes
API documentation formats
PDF
API sandbox or test environment
Yes
Customisation available
Yes
Description of customisation
Configuration can be tailored on a no-code basis by system admin users. This means that in addition to managing user accounts (adding/de-activating and setting permissions) system admin users can also create and amend forms, fields, workflows, email notifications, risk matrices, system triggers, hint text, and a range of other areas. System admin users can also use an importer tool for bulk import of data from csv files - the tool maps columns to system fields, highlights mismatches, and enables in-line adjustment of data to correct mismatches within the importer tool. This is fully supported through a navigation-sensitive in-application manual and online Knowledge Base with clear content supported with images and videos. In addition to dashboard self-build (explored below) system admin users can also create custom csv reports and make available to standard users. Standard users can build, amend and share their own dashboards. Clew Professional Services staff have higher access levels to customise configuration settings - such as re-labelling core out-of-the-box field labels to customer specific requirements, and customising pdf exports with customer logos and disclaimers. They can also create (or select from a Clew library) more enhanced dashboard widgets for customers to use and re-use in their own dashboards.

Scaling

Independence of resources
We prevent “noisy neighbour” impact by combining tenant isolation with elastic scaling and active monitoring. We run the platform on AWS using Elastic Kubernetes Service (EKS) with strict logical separation per customer and controls that ensure one customer’s load does not degrade another’s experience.

Analytics

Service usage metrics
Yes
Metrics types
System admin users can interrogate user accounts for date of last login and the history of account details such as access permissions over time.

On request, Clew can provide metrics including active and inactive users in the previous month, user activity (based on log-in) month by month on a rolling 12-month history, and module usage (showing number of records created and updated month by month on a rolling 12 month basis).
Reporting types
Reports on request
Resource tagging
Yes
FOCUS resource tagging
Yes

Supplier type

Supplier type
Not a reseller

Staff security

Staff security clearance
Conforms to BS7858:2019
Government security clearance
Security Clearance (SC)

Asset protection

Knowledge of data storage and processing locations
Yes
Data storage and processing locations
United Kingdom
User control over data storage and processing locations
Yes
Datacentre security standards
Complies with a recognised standard (for example CSA CCM version 4.0)
Penetration testing frequency
At least every 6 months
Penetration testing approach
Another external penetration testing organisation
Protecting data at rest
  • Physical access control, complying with SSAE-18 / ISAE 3402
  • Physical access control, complying with another standard
  • Encryption of all physical media
Data sanitisation process
Yes
Equipment disposal approach
A third-party destruction service
Data sanitisation type
Physical Destruction / Hardware containing data is completely destroyed

Data importing and exporting

Data export approach
Users can export individual records, multiple records and dashboards in pdf format; the generic pdf template can be customised by CGR during implementation for customer logo and disclaimer.

Users can export individual or multiple records in csv, and can also export dashboard tables in csv format.

System admin users can use the custom csv report builder to create specific reports that standard users can access. These custom reports can include relational data, such that a risk report can include columns showing the titles and other details of linked controls and actions.

Clew also offers an API connector to PowerBI.
Data export formats
  • CSV
  • Other
Other data export formats
PDF
Data import formats
CSV

Data-in-transit protection

Data protection between buyer and supplier networks
TLS (version 1.2 or above)
Data protection within supplier network
TLS (version 1.2 or above)

Availability and resilience

Guaranteed availability
99.9% uptime.
Approach to resilience
Our service is designed to stay available during failures and demand spikes through resilient cloud architecture and tested recovery processes. We host on AWS, benefiting from physically secure, highly resilient data centres and region-based high-availability design. Data is protected with encrypted storage and AWS-native redundancy, and backups (including DR data) are retained within the customer’s designated AWS region/Data Zone. We operate documented Disaster Recovery and Business Continuity plans with defined RTO/RPO, reviewed at least annually and validated through tabletop and simulated recovery exercises. The platform is monitored 24/7/365 with alerting and escalation. We also use autoscaling (e.g., Kubernetes HPA and cluster autoscaling) to add capacity automatically during peak usage, helping maintain performance and availability.
Outage reporting
We report outages via proactive monitoring and direct customer communications (including email alerts to nominated contacts). Our Business Continuity Plan includes a client communication protocol, and our systems are monitored 24/7/365 with real-time alerting and escalation to support rapid incident response and timely updates.

We notify clients via email/client communication channels, including advance notifications for major changes that may affect availability or integrations, and communications during incidents/outages under our client comms protocol.

Identity and authentication

User authentication needed
Yes
User authentication
  • Multi-Factor Authentication (MFA)
  • Identity federation with existing provider (for example Google Apps)
  • Username or password
Access restrictions in management interfaces and support channels
Yes, we tightly restrict access to management interfaces and support channels using least-privilege RBAC, strong authentication (SSO/MFA), segregated admin access paths, and comprehensive audit logging. Our controls include role-based access and formal joiner–mover–leaver processes, periodic access reviews, and MFA for internal/administrative access.
Access restriction testing frequency
At least every 6 months
Management access authentication
Identity federation with existing provider (for example Google Apps)

Audit information for users

Access to user activity audit information
Users have access to real-time audit information
How long user audit data is stored for
At least 12 months
Access to supplier activity audit information
Users have access to real-time audit information
How long supplier audit data is stored for
At least 12 months
How long system logs are stored for
At least 12 months

Security governance

Named board-level person responsible for service security
Yes
Security governance certified
Yes
Security governance standards
ISO/IEC 27001
Information security policies and processes
We ensure policies are followed through external certification, regular checks, strong operational controls, and continuous monitoring. We maintain independent assurance through ISO 27001 alongside Cyber Essentials/Cyber Essentials Plus (and ISO 9001), all renewed and independently verified. We track obligations in a compliance register and run periodic internal reviews and audits, bringing in legal support when major regulatory changes arise. Access is controlled through role-based access and least privilege, supported by regular access reviews and a formal joiner–mover–leaver process. We log and retain key activity for audit purposes and monitor security events to detect and respond to threats. Finally, we operate controlled change management with risk assessment, approvals, testing, and post-change monitoring, backed by secure development training and vulnerability scanning before releases. Security oversight brings together leadership, DevSecOps, development teams, and our AI function to review design decisions, assess security/compliance considerations, and manage risk across the lifecycle.
Software Security Code of Practice
Yes

Operational security

Configuration and change management standard
Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
Configuration and change management approach
We operate a documented configuration and change management process that provides end-to-end traceability and security impact control.
In terms of through-life component tracking, we manage infrastructure and server configuration using Infrastructure as Code to enforce consistent, repeatable configurations and reduce drift, with automated patching updates. Endpoints are managed via MDM. All changes follow a documented Change Management Process and are risk/impact assessed, logged, reviewed/approved, and tested in non-production. Major changes that could affect security posture, availability, or integrations are notified in advance via agreed client channels. Emergency changes are logged immediately, approved by authorised personnel, and undergo approval via CAB.
Vulnerability management type
Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
Vulnerability management approach
Proactive, risk-based vulnerability management program with continuous monitoring, regular testing, and controlled remediation. We use SIEM monitoring and IDS/IPS-style detection, supported by AWS-native threat detection and endpoint protection, to identify suspicious activity and emerging threats. We prioritise vulnerabilities on severity, exploitability, and system criticality, deploying patches in line with internal SLAs and industry guidance. If immediate patching isn’t possible, we apply temporary mitigations until the full fix is released. We perform vulnerability scanning before each release and use automated patching and image-scanning to reduce exposure to known issues. Threat intelligence is informed by AWS threat intelligence feeds and security telemetry.
Protective monitoring type
Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
Protective monitoring approach
We operate continuous protective monitoring to detect suspicious activity quickly and respond using a defined, severity-based incident process. We identify potential compromises by collecting and analysing security logs and telemetry in real time using SIEM-backed monitoring, IDS/IPS-style detection, and cloud-native threat detection, supported by endpoint protection. When a potential compromise is detected, alerts are triaged immediately and escalated to the security/operations team for investigation, containment, eradication/remediation, and recovery, with full logging and root-cause follow-up. We respond based on severity, with acknowledgement and initiation of remedial action from 1 hour for highest-severity incidents, and within defined targets for lower-severity events.
Incident management type
Complies with a recognised standard, for example, CSA CCM v4.0 or ISO/IEC 27035:2011 or SSAE-18 / ISAE 3402
Incident management approach
We have a structured incident management process with predefined triage and escalation, clear reporting routes, and documented customer communications.
We use pre-defined processes for common events. Incidents (including outages and security-related events) follow a severity-based triage process with defined response targets, and are handled through our structured support and operations model.
Post-quantum cryptography secure
Yes

Secure development

Approach to secure software development best practice
Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)

Public sector networks

Connection to public sector networks
No

Pricing

Discount for educational organisations
No
Free trial available
No

Discount percentage by annual call-off contract value (excluding VAT)

Less than £250,000
0%
Between £250,000 and £500,000
5%
Between £500,001 and £1,000,000
10%
Between £1,000,001 and £2,500,000
10%
Between £2,500,001 and £5,000,000
10%
Over £5,000,001
10%

Standards and certifications

ISO/IEC 27001 certification
Yes
ISO/IEC 27001 accredited by
Compass Assurance Services
ISO/IEC 27001 accreditation date
Monday 23 January 2023
What the ISO/IEC 27001 doesn’t cover
Our certification does not certify AWS (or any other third-party suppliers). It covers our ISMS for delivering our SaaS product within the scoped activities and boundaries described on the certificate.
ISO 28000:2022 certification
No
ISO 9001 certification
Yes
ISO 9001 certification accredited by
British Assessment Bureau
ISO 9001 accreditation date
Wednesday 26 February 2025
What the ISO 9001 doesn’t cover
The scope of our Quality Management System is the development, provision, maintenance and service delivery of the Clew product in both its web and mobile forms. It does not extend to the cloud hosting environment we outsource through AWS – although we recognise its criticality to the provision of our product for our customers, and our Business Continuity Processes ensure that we identify and test fallback options in the event of AWS service interruption or unavailability.
Quality management systems (QMS)
Yes
CSA STAR certification
No
PCI certification
No
Cyber essentials
Yes
Cyber Essentials Certificate Number
637dfeb7-233a-46d7-89fd-27b729378073
Cyber essentials plus
Yes
Cyber Essentials Plus Certificate Number
D6de8e00-c348-4a78-83e3-2a12a36b58bf
Other security certifications
No

Social value

Mission: Kick start economic growth

To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority

  • New or retained jobs on the contract workforce in the relevant area that meet the criteria set out in MAC 1b, 1c and 1d
  • Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
  • Plans to engage the contract workforce in deciding the most important workplace issues to address
  • Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
  • Volunteering opportunities for staff
Mission: Make Britain a clean energy superpower

To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero

Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.

  • Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
  • Delivery of additional environmental benefits through the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
Mission: Build an NHS fit for the future

That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.

Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.

  • Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at pat.parker@clew.io. Tell them what format you need. It will help if you say what assistive technology you use.