Skip to main content

Help us improve the Digital Marketplace - send your feedback

THE INSTITUTE OF CLINICAL SCIENCE AND TECHNOLOGY LTD

SIMPSi® Assurance

SIMPSi® Assurance is a robust governance platform that manages processes and assets, such as that within SIMPSi® health, SIMPSi® EHR and SIMPSi® QI, and implementation processes with commissioners, clinicians, NHS managers, commercial partners, and government. Its governance model ensures safety, security, and assurance across clinical, data, operational, and change management.

Features

  • Trusted digital infrastructure for robust intervention design and delivery.
  • Centrally coordinated with role-based access and multi-level authorisation.
  • Automated reminders prompting timely actions, reviews, and reporting.
  • E-signature approvals for changes, decisions, and releases.
  • Mobile-friendly interface managing tasks, approvals, and updates on-the-go.
  • Email notifications keeping stakeholders informed and actions on schedule.
  • Rule-based workflows enforcing controls and automating agreed decisions.
  • Aligned to CE and ISO standards for compliance and security.
  • Secure version control with complete change tracking and audit archive.
  • Proven at scale, used by hundreds of managers and clinicians.

Benefits

  • Robust governance improving assurance, accountability, and safe decision-making.
  • Fully auditable records strengthening transparency, traceability, and compliance.
  • Clear accountability lines reducing ambiguity, speeding decisions, supporting safe delivery.
  • Escalation management surfacing issues early, routing owners, preventing delays.
  • Portfolio oversight tracking delivery, performance, and risk end-to-end.
  • Secure-by-design access control reducing information and data risks.
  • Embeds standards, controls, evidence trails into everyday workflows.
  • Consistent processes and transparent records build control and trust.
  • Adapts rapidly to new legislation and emerging evidence.
  • Defensible audit trail supporting evaluation, compliance, and legal assurance.

Pricing

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at support@icst.org.uk. Tell them what format you need. It will help if you say what assistive technology you use.

Framework

G-Cloud 15

Service ID

1 4 9 0 4 7 1 5 6 4 9 3 5 5 8

Contact

THE INSTITUTE OF CLINICAL SCIENCE AND TECHNOLOGY LTD Grace Moore
Telephone: 02920092828
Email: support@icst.org.uk

About your service

Service categories

Applications

Production and operations

Service industry and public sector operations

  • Healthcare
Multi cloud support
No

Service scope

Software add-on or extension
No
Cloud deployment model
Public cloud
Service constraints
The service requires internet connectivity and access via a modern web browser or supported mobile device. Planned maintenance may occur outside core working hours, with advance notification provided. Service availability is dependent on third-party hosting infrastructure. Local configuration may be required to enable integration with organisation-specific systems. Mobile app functionality may vary slightly between operating systems. Offline functionality is limited. Customer IT policies, firewalls or device restrictions may affect access and require local support. Data exchange with external systems is subject to agreed interoperability arrangements.
System requirements
  • Internet connectivity
  • Modern web browser (Chrome, Edge, Safari, Firefox)
  • Organisation firewall allowing HTTPS traffic
  • Email account for notifications and onboarding
  • Mobile app requires iOS or Android Device

User support

Email or online ticketing support
Yes
Support response times
We reply within 3 working days, but often within 24 hours on weekdays.
User can manage status and priority of support tickets
No
Phone support
Yes
Phone support availability
9 to 5 (UK time), Monday to Friday
Web chat support
No
Onsite support
No
Support levels
We provide a single, comprehensive support package included within the annual licence cost. This includes weekday email and online ticket support, with response within three working days, and priority escalation for service availability issues. Customers also have access to an implementation lead and ongoing contact with our support team.

Each organisation is assigned an account manager who acts as the primary point of contact for operational queries, reporting requests and user onboarding. A technical contact is available for integration and access configuration support when required.

We provide implementation support during rollout, including virtual onboarding sessions for staff, configuration of organisational structures, and access to training materials. Regular progress review meetings are included in the service and can involve clinical or commissioning leads.

System monitoring, maintenance and updates are included at no additional cost. Updates are deployed centrally, ensuring all users benefit from the latest features and security improvements without local installation work.

We do not charge extra for standard support. Optional extended support arrangements can be discussed based on local requirements. A cloud infrastructure engineer is available for service continuity and incident resolution.
Support available to third parties
Yes

Onboarding and offboarding

Getting started
We provide a structured onboarding process to ensure users can start using the service quickly and confidently. New organisations receive an initial setup session with a named implementation lead to configure the organisational structure, add local resources and agree rollout plans. Online training is available, including live virtual sessions, recorded tutorials and written guidance. Users also have access to step-by-step documentation and short instructional videos within the platform.

We provide launch resources for organisations, including communication templates, local guidance integration and support. Progress review meetings are included to monitor uptake and address any early questions.

No technical installation is required. All updates and improvements are delivered centrally, ensuring users always access the latest version without local IT involvement.

Optional onsite training can be arranged if required by the buyer.
Service documentation
Yes
Documentation formats
  • HTML
  • PDF
End-of-contract data extraction
At the end of the contract, users can request the extraction of their data in a structured, machine-readable format. Full data extracts can be provided securely on request in agreed formats such as CSV or JSON, subject to appropriate information governance and security checks.

Where integrations are in place, data can also be transferred via existing agreed interoperability mechanisms. Patient-entered data remains accessible to individual users through their account during the notice period, allowing them to view or download their own information.

Once extraction is complete and confirmed by the customer, data will be securely deleted in line with contractual, legal and regulatory requirements, unless retention is required for lawful purposes. No additional software is required for data extraction.
End-of-contract process
At the end of the contract, the organisation will be notified in advance and provided with the opportunity to extract their data. Standard end-of-contract activities are included in the annual licence cost, including data extraction in an agreed structured format, continuation of access during the notice period, and coordinated service closure. Individual users can continue to access their own information during this time.

We will support the customer through the offboarding process, including confirming data extraction requirements, providing guidance on accessing reporting data and agreeing timelines for system access removal. Once extraction is complete and confirmed by the customer, data will be securely deleted in line with contractual, legal and regulatory requirements.

No additional cost is charged for standard end-of-contract processes, data export or secure deletion. Optional services, such as bespoke data transformation, migration into third-party systems or extended access beyond the contract end date, can be agreed separately if required by the buyer.
Documentation accessibility standard
WCAG 2.2 AA

Using the service

Web browser interface
Yes
Supported browsers
  • Microsoft Edge
  • Firefox
  • Chrome
  • Safari
  • Opera
Application to install
Yes
Compatible operating systems
  • Android
  • IOS
Designed for use on mobile devices
Yes
Differences between the mobile and desktop service
The mobile app is designed for reviewers only. Admin functionality is managed through a web browser.
Service interface
Yes
User support accessibility
WCAG 2.2 AA
Description of service interface
SIMPSi® Assurance is accessed through a secure, cloud-based web interface. The interface supports role-based workflows for managing governance processes, approvals, and assets. Users can view status, audit trails, and version history through clear dashboards, with all changes safely tracked and archived. The system is centrally managed and designed to support safe, transparent governance across clinical, data, operational, and change management activities.
Accessibility standards
WCAG 2.2 AA
Accessibility testing
NA
API
No
Customisation available
Yes
Description of customisation
Users can customise elements of the service according to their role.

Educational content can be tailored to include locally recorded videos featuring local clinicians or service representatives where available, supporting engagement and recognition.

Scaling

Independence of resources
The service is delivered on a scalable cloud infrastructure with load balancing and automatic resource allocation, ensuring that demand from one organisation does not impact others. Capacity is monitored continuously and additional resources are provisioned as required. Application and database environments are optimised for multi-tenant use, with logical separation of data and performance safeguards. Traffic management and prioritisation ensure consistent response times. Regular performance testing and system monitoring allow us to maintain service levels and respond proactively to increased demand.

Analytics

Service usage metrics
Yes
Metrics types
We can provide detailed service usage metrics through commissioner and organisational dashboards. Metrics include number of users, registrations over time, engagement levels, and feature utilisation. Commissioners can monitor population uptake and engagement trends to support service planning and quality improvement. Exportable reports and summaries are available on request, or any metrics required specificaly by the organisation.
Reporting types
  • API access
  • Real-time dashboards
  • Regular reports
  • Reports on request
Resource tagging
No
FOCUS resource tagging
No

Resellers

Supplier type
Not a reseller

Staff security

Staff security clearance
Other security clearance
Government security clearance
Baseline Personnel Security Standard (BPSS)

Asset protection

Knowledge of data storage and processing locations
Yes
Data storage and processing locations
United Kingdom
User control over data storage and processing locations
No
Datacentre security standards
Complies with a recognised standard (for example CSA CCM version 4.0)
Penetration testing frequency
At least once a year
Penetration testing approach
‘IT Health Check’ performed by a CREST-approved service provider
Protecting data at rest
  • Physical access control, complying with CSA CCM v4.0
  • Physical access control, complying with SSAE-18 / ISAE 3402
  • Encryption of all physical media
Data sanitisation process
Yes
Equipment disposal approach
Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
Data sanitisation type
  • Deleted data can’t be directly accessed / Cryptographic Erasure
  • Data Erasure
  • Physical Destruction / Hardware containing data is completely destroyed

Data importing and exporting

Data export approach
Users can export their data through several methods. Organisational administrators can request that data extracts be provided securely in agreed-upon formats upon request.
Individual users can view and request to download their own information through the support channels. Where integrations exist, data can also be transferred via agreed interoperability mechanisms.
Data export formats
Other
Other data export formats
Pdf
Data import formats
Other
Other data import formats
Manual upload

Data-in-transit protection

Data protection between buyer and supplier networks
TLS (version 1.2 or above)
Data protection within supplier network
TLS (version 1.2 or above)

Availability and resilience

Guaranteed availability
We guarantee a minimum service availability of 99.9% uptime per calendar month for the SIMPSI platform, excluding planned maintenance windows which are notified in advance. The service is hosted on highly available cloud infrastructure with automatic scaling and redundancy to minimise downtime.

Availability covers access to patient and clinician applications, authentication services, and core data storage. Planned maintenance is typically performed outside peak usage periods and is designed to have minimal impact on users.

Response procedures ensure rapid mitigation and communication. We aim to restore full service as quickly as possible and provide post-incident reporting where required.
Approach to resilience
The SIMPSI service is designed to be resilient through the use of highly available cloud infrastructure. Patient and clinical data is hosted within AWS, which provides built-in redundancy, load balancing and automatic scaling across multiple availability zones. This ensures continued service operation in the event of underlying hardware or node failure.

Core systems are monitored continuously, with automated failover and rapid recovery mechanisms in place. Regular backups are maintained and replicated to support service restoration. Our deployment approach allows components to be restarted or replaced without user impact.

Limited clinician account information hosted within Kinsta’s Google Cloud Platform environment benefits from similar underlying resilience and global infrastructure capabilities, with no patient data stored or processed in this environment.

We maintain documented incident response and disaster recovery procedures, enabling timely restoration of service following disruption. In the event of a major outage, we work with affected customers to provide updates and ensure continuity of access.
Outage reporting
We continuously monitor the availability and performance of the SIMPSI service using automated monitoring tools. In the event of a service outage or significant degradation, we notify affected customers directly by email and, where appropriate, through agreed communication channels with commissioning organisations.

Incidents are logged and triaged by our technical team, with updates provided throughout the resolution process. Organisations may also request service status information at any time.

For high-impact outages affecting multiple customers, we issue proactive notifications and follow-up summaries once service is restored. Planned maintenance windows are communicated in advance to minimise disruption.

Identity and authentication

User authentication needed
Yes
User authentication
  • Multi-Factor Authentication (MFA)
  • Identity federation with existing provider (for example Google Apps)
  • Username or password
Access restrictions in management interfaces and support channels
Access to management interfaces is restricted using role-based access controls and the principle of least privilege. Only authorised ICST staff with a valid business need can access administrative systems, and all access requires strong authentication, including MFA. Management interfaces are not publicly exposed and can only be accessed via secure channels, such as approved IP ranges. Support channels are controlled, with requests authenticated and verified before any account or configuration changes are made. There are regular reviews of access rights and audit trails to ensure inappropriate access is prevented and detected.
Access restriction testing frequency
At least once a year
Management access authentication
  • Multi-Factor Authentication (MFA)
  • Identity federation with existing provider (for example Google Apps)
  • Dedicated link (for example VPN)
  • Username or password

Audit information for users

Access to user activity audit information
Users contact the support team to get audit information
How long user audit data is stored for
At least 12 months
Access to supplier activity audit information
Users contact the support team to get audit information
How long supplier audit data is stored for
At least 12 months
How long system logs are stored for
At least 12 months

Security governance

Named board-level person responsible for service security
Yes
Security governance certified
Yes
Security governance standards
ISO/IEC 27001
Information security policies and processes
We operate a formal Information Security Management System aligned with ISO 27001. Policies cover access control, data protection, secure development, incident management, business continuity, asset management and supplier management. Policies apply to all staff and contractors and are reviewed at least annually or following significant change.

The Chief Executive Officer holds board level responsibility for information security. Operational responsibility is delegated to the Information Security Lead, who oversees policy implementation, risk assessments and compliance activities. All staff receive onboarding and annual training on information security and data protection, with mandatory acknowledgement of key policies.

Access to systems and data is controlled through role-based permissions and least privilege principles. Changes to systems follow a documented change control process that includes testing and approval.

Compliance with policies is monitored through internal audits, access reviews, incident reporting and regular management review meetings. Any non compliance or security incidents are investigated and corrective actions are tracked to completion.
Software Security Code of Practice
Yes

Operational security

Configuration and change management standard
Supplier-defined controls
Configuration and change management approach
We follow a formal configuration and change management process. All components and configuration items are documented and tracked through their lifecycle, with a maintained baseline and inventory. Changes are requested in writing, reviewed and approved before implementation, and include testing and a rollback strategy. Each change is assessed for potential security and operational impact as part of the approval process. Implementation is coordinated and documented, with post-implementation reviews to identify improvements. Compliance is monitored through audits and reporting.
Vulnerability management type
Supplier-defined controls
Vulnerability management approach
We operate a formal vulnerability management process. Potential threats are identified through regular vulnerability scanning, vendor security advisories, alerts and industry threat intelligence. Vulnerabilities are assessed for risk and potential security impact, with high-risk issues prioritised and remediated as soon as practical and within the NCSC guidance of 14 days. Systems and applications are patched in line with vendor recommendations, with additional controls applied where patching is not possible. Public-facing systems are monitored continuously. Anti-malware controls, email filtering and secure web gateway technologies provide additional protection. Compliance is monitored through audits and reporting.
Protective monitoring type
Supplier-defined controls
Protective monitoring approach
We use continuous monitoring tools, logs and alerting to identify potential compromises, including unusual access patterns, failed logins and suspicious activity on public-facing systems. Alerts are investigated immediately by the technical team and escalated through our incident response process where required. High-risk incidents are assessed and acted upon as a priority, with containment measures implemented quickly to protect data and service availability. We aim to respond to potential compromises within hours, with rapid communication to affected customers if needed. All incidents are documented, reviewed and used to improve controls and monitoring.
Incident management type
Supplier-defined controls
Incident management approach
We operate a defined incident management process based on ISO 27001 and NHS DSP requirements. All incidents are logged through our internal ticketing system by staff or automated monitoring alerts. Incidents are triaged and assessed for severity, with predefined procedures for common events such as data access issues, service outages, or security alerts. High-severity incidents are escalated to the Security Lead. Users are informed through email updates, and incident reports are provided to commissioners on request, including root cause, actions taken, and prevention measures
Post-quantum cryptography secure
Yes

Secure development

Approach to secure software development best practice
Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)

Public sector networks

Connection to public sector networks
No

Pricing

Discount for educational organisations
No
Free trial available
No

Discount percentage by annual call-off contract value (excluding VAT)

Less than £250,000
2%
Between £250,000 and £500,000
3%
Between £500,001 and £1,000,000
4%
Between £1,000,001 and £2,500,000
6%
Between £2,500,001 and £5,000,000
8%
Over £5,000,001
10%

Non-mandatory Standards and certifications

ISO/IEC 27001 certification
Yes
Who accredited the ISO/IEC 27001
Citation ISO Certification
ISO/IEC 27001 accreditation date
Friday 20 August 2021
What the ISO/IEC 27001 doesn’t cover
NA
ISO 28000:2022 certification
No
ISO 9001 certification
No
Quality management systems (QMS)
No
CSA STAR certification
No
PCI certification
No
Cyber essentials
Yes
Please provide your Cyber Essentials Certificate Number
Fa1ea9f6-afe9-45b5-8df6-f25eac23e4f3
Cyber essentials plus
Yes
Please provide your Cyber Essentials Plus Certificate Number
4c5bb7b6-410c-40c7-8268-5200c335f8f5
Other security certifications
No

Social value

Section B - Commitment for Future: Delivery
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority

    • Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
    • Plans to engage the contract workforce in deciding the most important workplace issues to address
    • Activities that support an environment where staff are educated about, and feel empowered to, address their physical wellbeing
    • Activities that support an environment where staff are educated about and feel empowered to report and address bullying and harassment
    • Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
    • Monitoring and reporting of gender and ethnicity pay gaps and plans to address them where necessary
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.

    • Understanding of employment and relevant skills issues, and of the education and training issues relating to the contract. Illustrative examples: demographics, skills shortages, new opportunities in high growth sectors, geographic/local community and skills/employment challenges
    • Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
    • Activities to support relevant sector related skills growth and sustainability in the contract workforce. Illustrative examples: careers talks, curriculum support, literacy support, safety talks and volunteering
  • Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero

    Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.

    • Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
    • Collaborative ways of working with the supply chain to deliver additional environmental benefits in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
    • Delivery of additional environmental benefits through the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
  • Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.

    Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.

    • Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce
    • Understanding barriers to access to health and social care services or employment opportunities e.g. digital inclusion

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at support@icst.org.uk. Tell them what format you need. It will help if you say what assistive technology you use.