Arbor Finance for Schools and Local Authorities
Arbor Finance is a cloud-based, cashbook finance and accounting system for schools and Local Authorities, integrated with Arbor MIS. It streamlines budgeting, invoicing, reconciliation and statutory reporting and provides secure access, supports compliance, transparency and efficient financial management across schools and authorities.
Features
- Accounts payable transactions with comprehensive reporting
- Online invoicing and paperless approvals
- Budget planning, monitoring and import tools
- Automated bank reconciliation matching transactions
- Built-in statutory reporting (e.g., CFR returns)
- Configurable user roles and secure access controls
- Custom and statutory report generation
- Real-time dashboards and financial visibility
- Integration with Arbor MIS and APIs
- 24/7 cloud access with automatic backups
Benefits
- Provides scalable finance management for authorities and schools
- Reduces burden of manual finance administration
- Improves financial transparency and audit readiness
- Supports compliance with statutory requirements
- Enables remote access for leaders and finance teams
- Enhances reporting for governors, auditors and authorities
- Shortens month-end processes and reconciliation times
- Works without specialist accounting expertise
- Unifies school finance data across multi-school groups
- Reduces reliance on paper and legacy systems
Pricing
- Free trial available
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
1 2 6 9 7 0 6 6 0 3 7 9 7 3 9
Contact
ARBOR EDUCATION PARTNERS GROUP LTD
Phillippa De'Ath
Email: bids@arbor-education.com
About your service
- Service categories
-
Applications
Enterprise resource management
- Payroll management
- Asset life-cycle management
Financial
- Financial and Accounting Applications
- Accounts Payable Applications
- Accounts Receivable Applications
- Multi cloud support
- No
Service scope
- Software add-on or extension
- No
- Cloud deployment model
- Public cloud
- Service constraints
- Requires an internet connection
- System requirements
-
- Recommended browser: Chrome, Microsoft Edge, Firefox
- Recommended internet bandwidth: 2MB
User support
- Email or online ticketing support
- Yes
- Support response times
- Our email and phone lines are staffed 8-5, Monday-Friday by a team of experienced analysts. We aim to respond to users as quickly as possible when queries come in, within a day during working hours. There is no weekend service.
- User can manage status and priority of support tickets
- No
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- No
- Onsite support
- Yes, at extra cost
- Support levels
- We have 1st, 2nd, 3rd and 4th line support from our customer and engineering teams. Support costs, including both front line and technical support, are included in the price of the software. Schools will also have access to an Online Help Centre and the Arbor Training Hub, and we prepare specific resources to get you ready for important dates, like the end of the financial year.
- Support available to third parties
- Yes
Onboarding and offboarding
- Getting started
-
We’ve designed a hassle-free journey for schools to move to Arbor Finance. You’ll have clear, supportive guidance every step of the way, helping you set up and use Arbor Finance in your school. We take care when moving your data to Arbor Finance, giving you the opportunity to check everything’s in order with a clear view of your data migration.
Onboarding takes just six weeks - we get you set-up fast so you can complete all your essential accounting tasks from day one. Meanwhile, our expert trainers will give your staff the training they need to use Arbor Finance confidently. Training and onboarding support can be completed entirely remotely, saving you time and giving you more flexibility for when to move.
You will have access to our online learning as soon as you sign. All help documentation can be accessed online, and is also searchable without logging in. Documentation includes videos, product gifs and written instructions. - Service documentation
- Yes
- Documentation formats
-
- HTML
- Other
- Other documentation formats
-
- Searchable Help Centre website
- Video introductions & guides
- Live webinars with a library of prior webinars
- In-app walkthroughs and information
- End-of-contract data extraction
- The data can be exported to csv which is a standard file transfer format for finance data, or it can be exported as reports.
- End-of-contract process
-
We send the customer a reminder at least 1 month before the end of the service to let them know it will end and how to renew.
There are no additional costs to decommission the service.
At the end of the contract, access to the service is lost and the data is deleted 60 days later. The end of contract process is managed to let the customer know what is happening at each stage of the process. - Documentation accessibility standard
- None or don’t know
- How the documentation is accessible
- You will have access to our online learning as soon as you sign. All help documentation can be accessed online, and is also searchable without logging in. Documentation includes videos, product gifs and written instructions.
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Application to install
- No
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
- The service will work on internet connected tablets that support modern browsers. It does not have a user interface suitable for mobile phones as this would reduce the screen size too much to show financial reports.
- Service interface
- Yes
- User support accessibility
- WCAG 2.2 AA
- Description of service interface
-
Arbor Finance is a web based application that has been structured intuitively to enable users to complete tasks within the application. It is designed to be easy to navigate, understand and use.
Our user interface is clear and accessible, with colour coding and all displays carefully considered to ensure a consistent user experience across the site. - Accessibility standards
- None or don’t know
- Description of accessibility
-
We design new features to meet WCAG 2.2 Level AA standards and are progressively improving accessibility across our existing products.
Arbor Finance works with browser zoom to enable users to navigate the full page when in zoom. Users can also use the keyboard to complete actions.
Our interface is also customisable through browser-based accessibility controls. We recommend Google Chrome for the best range of accessibility controls and plugins, such as their high contrast, colourblind, and greyscale modes. - Accessibility testing
- We have not conducted specific testing at this time.
- API
- Yes
- What users can and can't do using the API
- Arbor Finance has an API available that links to your Arbor MIS. In this way then data drawn from other systems into your Arbor MIS can also be drawn into Arbor Finance.
- API documentation
- Yes
- API documentation formats
- Other
- API sandbox or test environment
- Yes
- Customisation available
- Yes
- Description of customisation
- Arbor Finance can be set up to match school priorities, as well as individually the needs of each user. This includes, cheque printing layouts, transactional options, levels of access to different areas and the Chart of Accounts. There are also Local Authority reports that can be tailored for your LA.
Scaling
- Independence of resources
-
The product is hosted in Microsoft Azure and is able to auto-scale according to service utilisation. The monitors are able to react within 30 minutes.
We monitor and report on user APDEX scores to ensure that the service is fast and responsive for customers.
Analytics
- Service usage metrics
- Yes
- Metrics types
-
We monitor the service using Azure monitoring tools.
For end users there is a full audit log of activities carried out in the program. - Reporting types
-
- Regular reports
- Reports on request
- Resource tagging
- Yes
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Conforms to BS7858:2019
- Government security clearance
- None
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- United Kingdom
- User control over data storage and processing locations
- No
- Datacentre security standards
- Managed by a third party
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- Another external penetration testing organisation
- Protecting data at rest
- Encryption of all physical media
- Data sanitisation process
- Yes
- Equipment disposal approach
- In-house destruction process
- Data sanitisation type
-
- Deleted data can’t be directly accessed / Cryptographic Erasure
- Data Erasure
- Explicit overwriting of storage before reallocation / Secure Erase
Data importing and exporting
- Data export approach
- Users can print, export to CSV/Excel or PDF.
- Data export formats
-
- CSV
- Other
- Other data export formats
-
- Excel
- CSV
- Read from the API
- Data import formats
-
- CSV
- Other
- Other data import formats
-
- CSV
- Xlsx
- API
Data-in-transit protection
- Data protection between buyer and supplier networks
- TLS (version 1.2 or above)
- Data protection within supplier network
- TLS (version 1.2 or above)
Availability and resilience
- Guaranteed availability
- There is no fixed Service Level Agreement however we will use our reasonable endeavours to maximise uptime, and ensure that the System is available least 99.5% of the time during each year, excluding (i) any of our or our subcontractors' maintenance downtime, (ii) a failure between the Institution's computer(s) and the internet; (iii) factors outside of our reasonable control; (iv) the Institution's action or inaction, or any action or inaction of the Users or the Institution's other suppliers.
- Approach to resilience
-
Our data centre supplier is Microsoft Azure, which has the following benefits:
• Network reliability through intelligent software
• Safe Deployment with AIOps
• Resiliency threat modelling for large distributed systems
• Low and no impact maintenance
Further information is available on request. - Outage reporting
- Internal monitoring, email alerts and a public Status dashboard.
Identity and authentication
- User authentication needed
- Yes
- User authentication
- Username or password
- Access restrictions in management interfaces and support channels
- Arbor Finance uses a custom Roles based permissions system for management and support teams. Access is granted to various business systems based on defined Access Control Policy. We conduct regular Access Control reviews. We maintain a test/demo system that minimises the need for support access to production systems.
- Access restriction testing frequency
- At least once a year
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Username or password
Audit information for users
- Access to user activity audit information
- Users have access to real-time audit information
- How long user audit data is stored for
- At least 12 months
- Access to supplier activity audit information
- Users contact the support team to get audit information
- How long supplier audit data is stored for
- At least 12 months
- How long system logs are stored for
- At least 12 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
- ISO/IEC 27001
- Information security policies and processes
- We adhere to a robust Information Security Management System (ISMS) and are certified to ISO 27001:2013 and Cyber Essentials. Our infrastructure provider, Amazon Web Services, is also ISO 27001 certified. Security is integral to our design, employing bank grade 256-bit SSL for data in transit and AES-256 for data at rest. Physical access is restricted with 24/7 security and CCTV, while digital access utilizes two-factor authentication and strict need-to-know permissions. We continuously monitor for vulnerabilities, patch servers nightly, and conduct annual penetration testing. For data breaches, our policy is to report to customers within 24 hours. All staff are DBS checked and receive continuous data protection training. Our supply chain partners are contractually bound to uphold these security standards.
- Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
- All systems are configured using SaltStack. No changes are ever made to live server configurations (we operate with immutable servers). Salt allows us to define the end state of the system declaratively in salt state files which are version controlled. This means that any changes to the configuration of servers leave an audit trail. It also means that all configuration can be tested in our staging environment and repeated deterministically. All changes are assessed by the Head of Technical Security Operations before being approved.
- Vulnerability management type
- Supplier-defined controls
- Vulnerability management approach
-
Assessing: We run a monthly Security Committee to assess potential threats to our services. In addition, there is a quarterly Management Information Security Review to ensure effectiveness of the information security management system. A dedicated DevOps team subscribes to relevant security briefings and assesses the risk on a daily basis. We commission external penetration tests at least once per year.
Patching: All systems are configured to download and install security updates nightly, and the installed updates are checked via a centralized log. - Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
-
Monitoring: All changes to any data records are kept in an Audit Log. All errors are logged to a centralized error reporting system and investigated by relevant engineering teams. All user activity, page requests, system and server logs are aggregated in a centralized log. All services are continually monitored into a centralized system.
Identification: Automatic alerts are sent to DevOps/engineers whenever breaches/errors are identified.
Response: Incidents are assessed and classified. Serious incidents are reported to the CTO and our Incident Response Policy is followed to completion (48 hours). Minor incidents are resolved by individual teams (14 days). - Incident management type
- Supplier-defined controls
- Incident management approach
-
The security incident response plan aligns with the SANS Identification step and is about making use of a robust detection and reporting capability. Early visibility of incidents facilitates quick decision making and rapid action. Potential security incidents can be detected and reported from a number of different sources, such as:
Arbor employees.
Arbor customers.
Arbor business partners.
Other external sources such as Law Enforcement Agencies.
System logs.
For non-system reporting our support line can be contacted to report a perceived security event or security weakness.
Security related incidents are centrally recorded using an Incident Log. - Post-quantum cryptography secure
- Yes
Secure development
- Approach to secure software development best practice
- Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- No
- Free trial available
- Yes
- Description of free trial
- We can provide full access to the system to try it out for up to 3 months.
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 10%
- Between £500,001 and £1,000,000
- 10%
- Between £1,000,001 and £2,500,000
- 10%
- Between £2,500,001 and £5,000,000
- 10%
- Over £5,000,001
- 10%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- Yes
- Who accredited the ISO/IEC 27001
- Citation ISO Certification Limited
- ISO/IEC 27001 accreditation date
- Tuesday 24 March 2020
- What the ISO/IEC 27001 doesn’t cover
- Our ISO 27001:2013 certification is comprehensive, covering the entirety of our information security management system across all offices and systems. We do not exclude any internal business systems or geographic locations from this scope, ensuring that every aspect of our operations meets this international benchmark for data security. While our certification specifically validates our internal management processes and the security of platforms, it is important to note that it does not extend to the independent internal infrastructure of the schools we serve or third-party hardware managed locally by clients.
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- Yes
- Who accredited the ISO 9001 certification
- Citation ISO Certification Limited
- ISO 9001 accreditation date
- Tuesday 10 January 2023
- What the ISO 9001 doesn’t cover
- Our ISO 9001:2015 certification is an internationally recognised gold standard that ensures our quality management systems are measurably effective and subject to independent annual audits. We added this certification specifically to provide assurance for our customer services, ensuring that our internal processes for supporting schools and trusts meet rigorous quality benchmarks.
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- Eaa86dd2-b784-4b53-bee1-76f80b5f6903
- Cyber essentials plus
- No
- Cyber Essentials Alternative
- None of the criteria
- Other security certifications
- No
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain
Policy Outcome 7: Creating a pipeline of opportunities: For the contract workforce, reducing barriers to entry for under-represented groups.
- Understanding of issues relating to entering the contract workforce
-