SIMPSi® Assurance
SIMPSi® Assurance is a robust governance platform that manages processes and assets, such as that within SIMPSi® health, SIMPSi® EHR and SIMPSi® QI, and implementation processes with commissioners, clinicians, NHS managers, commercial partners, and government. Its governance model ensures safety, security, and assurance across clinical, data, operational, and change management.
Features
- Trusted digital infrastructure for robust intervention design and delivery.
- Centrally coordinated with role-based access and multi-level authorisation.
- Automated reminders prompting timely actions, reviews, and reporting.
- E-signature approvals for changes, decisions, and releases.
- Mobile-friendly interface managing tasks, approvals, and updates on-the-go.
- Email notifications keeping stakeholders informed and actions on schedule.
- Rule-based workflows enforcing controls and automating agreed decisions.
- Aligned to CE and ISO standards for compliance and security.
- Secure version control with complete change tracking and audit archive.
- Proven at scale, used by hundreds of managers and clinicians.
Benefits
- Robust governance improving assurance, accountability, and safe decision-making.
- Fully auditable records strengthening transparency, traceability, and compliance.
- Clear accountability lines reducing ambiguity, speeding decisions, supporting safe delivery.
- Escalation management surfacing issues early, routing owners, preventing delays.
- Portfolio oversight tracking delivery, performance, and risk end-to-end.
- Secure-by-design access control reducing information and data risks.
- Embeds standards, controls, evidence trails into everyday workflows.
- Consistent processes and transparent records build control and trust.
- Adapts rapidly to new legislation and emerging evidence.
- Defensible audit trail supporting evaluation, compliance, and legal assurance.
Pricing
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
1 4 9 0 4 7 1 5 6 4 9 3 5 5 8
Contact
THE INSTITUTE OF CLINICAL SCIENCE AND TECHNOLOGY LTD
Grace Moore
Telephone: 02920092828
Email: support@icst.org.uk
About your service
- Service categories
-
Applications
Production and operations
Service industry and public sector operations
- Healthcare
- Multi cloud support
- No
Service scope
- Software add-on or extension
- No
- Cloud deployment model
- Public cloud
- Service constraints
- The service requires internet connectivity and access via a modern web browser or supported mobile device. Planned maintenance may occur outside core working hours, with advance notification provided. Service availability is dependent on third-party hosting infrastructure. Local configuration may be required to enable integration with organisation-specific systems. Mobile app functionality may vary slightly between operating systems. Offline functionality is limited. Customer IT policies, firewalls or device restrictions may affect access and require local support. Data exchange with external systems is subject to agreed interoperability arrangements.
- System requirements
-
- Internet connectivity
- Modern web browser (Chrome, Edge, Safari, Firefox)
- Organisation firewall allowing HTTPS traffic
- Email account for notifications and onboarding
- Mobile app requires iOS or Android Device
User support
- Email or online ticketing support
- Yes
- Support response times
- We reply within 3 working days, but often within 24 hours on weekdays.
- User can manage status and priority of support tickets
- No
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- No
- Onsite support
- No
- Support levels
-
We provide a single, comprehensive support package included within the annual licence cost. This includes weekday email and online ticket support, with response within three working days, and priority escalation for service availability issues. Customers also have access to an implementation lead and ongoing contact with our support team.
Each organisation is assigned an account manager who acts as the primary point of contact for operational queries, reporting requests and user onboarding. A technical contact is available for integration and access configuration support when required.
We provide implementation support during rollout, including virtual onboarding sessions for staff, configuration of organisational structures, and access to training materials. Regular progress review meetings are included in the service and can involve clinical or commissioning leads.
System monitoring, maintenance and updates are included at no additional cost. Updates are deployed centrally, ensuring all users benefit from the latest features and security improvements without local installation work.
We do not charge extra for standard support. Optional extended support arrangements can be discussed based on local requirements. A cloud infrastructure engineer is available for service continuity and incident resolution. - Support available to third parties
- Yes
Onboarding and offboarding
- Getting started
-
We provide a structured onboarding process to ensure users can start using the service quickly and confidently. New organisations receive an initial setup session with a named implementation lead to configure the organisational structure, add local resources and agree rollout plans. Online training is available, including live virtual sessions, recorded tutorials and written guidance. Users also have access to step-by-step documentation and short instructional videos within the platform.
We provide launch resources for organisations, including communication templates, local guidance integration and support. Progress review meetings are included to monitor uptake and address any early questions.
No technical installation is required. All updates and improvements are delivered centrally, ensuring users always access the latest version without local IT involvement.
Optional onsite training can be arranged if required by the buyer. - Service documentation
- Yes
- Documentation formats
-
- HTML
- End-of-contract data extraction
-
At the end of the contract, users can request the extraction of their data in a structured, machine-readable format. Full data extracts can be provided securely on request in agreed formats such as CSV or JSON, subject to appropriate information governance and security checks.
Where integrations are in place, data can also be transferred via existing agreed interoperability mechanisms. Patient-entered data remains accessible to individual users through their account during the notice period, allowing them to view or download their own information.
Once extraction is complete and confirmed by the customer, data will be securely deleted in line with contractual, legal and regulatory requirements, unless retention is required for lawful purposes. No additional software is required for data extraction. - End-of-contract process
-
At the end of the contract, the organisation will be notified in advance and provided with the opportunity to extract their data. Standard end-of-contract activities are included in the annual licence cost, including data extraction in an agreed structured format, continuation of access during the notice period, and coordinated service closure. Individual users can continue to access their own information during this time.
We will support the customer through the offboarding process, including confirming data extraction requirements, providing guidance on accessing reporting data and agreeing timelines for system access removal. Once extraction is complete and confirmed by the customer, data will be securely deleted in line with contractual, legal and regulatory requirements.
No additional cost is charged for standard end-of-contract processes, data export or secure deletion. Optional services, such as bespoke data transformation, migration into third-party systems or extended access beyond the contract end date, can be agreed separately if required by the buyer. - Documentation accessibility standard
- WCAG 2.2 AA
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Opera
- Application to install
- Yes
- Compatible operating systems
-
- Android
- IOS
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
- The mobile app is designed for reviewers only. Admin functionality is managed through a web browser.
- Service interface
- Yes
- User support accessibility
- WCAG 2.2 AA
- Description of service interface
- SIMPSi® Assurance is accessed through a secure, cloud-based web interface. The interface supports role-based workflows for managing governance processes, approvals, and assets. Users can view status, audit trails, and version history through clear dashboards, with all changes safely tracked and archived. The system is centrally managed and designed to support safe, transparent governance across clinical, data, operational, and change management activities.
- Accessibility standards
- WCAG 2.2 AA
- Accessibility testing
- NA
- API
- No
- Customisation available
- Yes
- Description of customisation
-
Users can customise elements of the service according to their role.
Educational content can be tailored to include locally recorded videos featuring local clinicians or service representatives where available, supporting engagement and recognition.
Scaling
- Independence of resources
- The service is delivered on a scalable cloud infrastructure with load balancing and automatic resource allocation, ensuring that demand from one organisation does not impact others. Capacity is monitored continuously and additional resources are provisioned as required. Application and database environments are optimised for multi-tenant use, with logical separation of data and performance safeguards. Traffic management and prioritisation ensure consistent response times. Regular performance testing and system monitoring allow us to maintain service levels and respond proactively to increased demand.
Analytics
- Service usage metrics
- Yes
- Metrics types
- We can provide detailed service usage metrics through commissioner and organisational dashboards. Metrics include number of users, registrations over time, engagement levels, and feature utilisation. Commissioners can monitor population uptake and engagement trends to support service planning and quality improvement. Exportable reports and summaries are available on request, or any metrics required specificaly by the organisation.
- Reporting types
-
- API access
- Real-time dashboards
- Regular reports
- Reports on request
- Resource tagging
- No
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Other security clearance
- Government security clearance
- Baseline Personnel Security Standard (BPSS)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- United Kingdom
- User control over data storage and processing locations
- No
- Datacentre security standards
- Complies with a recognised standard (for example CSA CCM version 4.0)
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- ‘IT Health Check’ performed by a CREST-approved service provider
- Protecting data at rest
-
- Physical access control, complying with CSA CCM v4.0
- Physical access control, complying with SSAE-18 / ISAE 3402
- Encryption of all physical media
- Data sanitisation process
- Yes
- Equipment disposal approach
- Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
- Data sanitisation type
-
- Deleted data can’t be directly accessed / Cryptographic Erasure
- Data Erasure
- Physical Destruction / Hardware containing data is completely destroyed
Data importing and exporting
- Data export approach
-
Users can export their data through several methods. Organisational administrators can request that data extracts be provided securely in agreed-upon formats upon request.
Individual users can view and request to download their own information through the support channels. Where integrations exist, data can also be transferred via agreed interoperability mechanisms. - Data export formats
- Other
- Other data export formats
- Data import formats
- Other
- Other data import formats
- Manual upload
Data-in-transit protection
- Data protection between buyer and supplier networks
- TLS (version 1.2 or above)
- Data protection within supplier network
- TLS (version 1.2 or above)
Availability and resilience
- Guaranteed availability
-
We guarantee a minimum service availability of 99.9% uptime per calendar month for the SIMPSI platform, excluding planned maintenance windows which are notified in advance. The service is hosted on highly available cloud infrastructure with automatic scaling and redundancy to minimise downtime.
Availability covers access to patient and clinician applications, authentication services, and core data storage. Planned maintenance is typically performed outside peak usage periods and is designed to have minimal impact on users.
Response procedures ensure rapid mitigation and communication. We aim to restore full service as quickly as possible and provide post-incident reporting where required. - Approach to resilience
-
The SIMPSI service is designed to be resilient through the use of highly available cloud infrastructure. Patient and clinical data is hosted within AWS, which provides built-in redundancy, load balancing and automatic scaling across multiple availability zones. This ensures continued service operation in the event of underlying hardware or node failure.
Core systems are monitored continuously, with automated failover and rapid recovery mechanisms in place. Regular backups are maintained and replicated to support service restoration. Our deployment approach allows components to be restarted or replaced without user impact.
Limited clinician account information hosted within Kinsta’s Google Cloud Platform environment benefits from similar underlying resilience and global infrastructure capabilities, with no patient data stored or processed in this environment.
We maintain documented incident response and disaster recovery procedures, enabling timely restoration of service following disruption. In the event of a major outage, we work with affected customers to provide updates and ensure continuity of access. - Outage reporting
-
We continuously monitor the availability and performance of the SIMPSI service using automated monitoring tools. In the event of a service outage or significant degradation, we notify affected customers directly by email and, where appropriate, through agreed communication channels with commissioning organisations.
Incidents are logged and triaged by our technical team, with updates provided throughout the resolution process. Organisations may also request service status information at any time.
For high-impact outages affecting multiple customers, we issue proactive notifications and follow-up summaries once service is restored. Planned maintenance windows are communicated in advance to minimise disruption.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Identity federation with existing provider (for example Google Apps)
- Username or password
- Access restrictions in management interfaces and support channels
- Access to management interfaces is restricted using role-based access controls and the principle of least privilege. Only authorised ICST staff with a valid business need can access administrative systems, and all access requires strong authentication, including MFA. Management interfaces are not publicly exposed and can only be accessed via secure channels, such as approved IP ranges. Support channels are controlled, with requests authenticated and verified before any account or configuration changes are made. There are regular reviews of access rights and audit trails to ensure inappropriate access is prevented and detected.
- Access restriction testing frequency
- At least once a year
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Identity federation with existing provider (for example Google Apps)
- Dedicated link (for example VPN)
- Username or password
Audit information for users
- Access to user activity audit information
- Users contact the support team to get audit information
- How long user audit data is stored for
- At least 12 months
- Access to supplier activity audit information
- Users contact the support team to get audit information
- How long supplier audit data is stored for
- At least 12 months
- How long system logs are stored for
- At least 12 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
- ISO/IEC 27001
- Information security policies and processes
-
We operate a formal Information Security Management System aligned with ISO 27001. Policies cover access control, data protection, secure development, incident management, business continuity, asset management and supplier management. Policies apply to all staff and contractors and are reviewed at least annually or following significant change.
The Chief Executive Officer holds board level responsibility for information security. Operational responsibility is delegated to the Information Security Lead, who oversees policy implementation, risk assessments and compliance activities. All staff receive onboarding and annual training on information security and data protection, with mandatory acknowledgement of key policies.
Access to systems and data is controlled through role-based permissions and least privilege principles. Changes to systems follow a documented change control process that includes testing and approval.
Compliance with policies is monitored through internal audits, access reviews, incident reporting and regular management review meetings. Any non compliance or security incidents are investigated and corrective actions are tracked to completion. - Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
- We follow a formal configuration and change management process. All components and configuration items are documented and tracked through their lifecycle, with a maintained baseline and inventory. Changes are requested in writing, reviewed and approved before implementation, and include testing and a rollback strategy. Each change is assessed for potential security and operational impact as part of the approval process. Implementation is coordinated and documented, with post-implementation reviews to identify improvements. Compliance is monitored through audits and reporting.
- Vulnerability management type
- Supplier-defined controls
- Vulnerability management approach
- We operate a formal vulnerability management process. Potential threats are identified through regular vulnerability scanning, vendor security advisories, alerts and industry threat intelligence. Vulnerabilities are assessed for risk and potential security impact, with high-risk issues prioritised and remediated as soon as practical and within the NCSC guidance of 14 days. Systems and applications are patched in line with vendor recommendations, with additional controls applied where patching is not possible. Public-facing systems are monitored continuously. Anti-malware controls, email filtering and secure web gateway technologies provide additional protection. Compliance is monitored through audits and reporting.
- Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
- We use continuous monitoring tools, logs and alerting to identify potential compromises, including unusual access patterns, failed logins and suspicious activity on public-facing systems. Alerts are investigated immediately by the technical team and escalated through our incident response process where required. High-risk incidents are assessed and acted upon as a priority, with containment measures implemented quickly to protect data and service availability. We aim to respond to potential compromises within hours, with rapid communication to affected customers if needed. All incidents are documented, reviewed and used to improve controls and monitoring.
- Incident management type
- Supplier-defined controls
- Incident management approach
- We operate a defined incident management process based on ISO 27001 and NHS DSP requirements. All incidents are logged through our internal ticketing system by staff or automated monitoring alerts. Incidents are triaged and assessed for severity, with predefined procedures for common events such as data access issues, service outages, or security alerts. High-severity incidents are escalated to the Security Lead. Users are informed through email updates, and incident reports are provided to commissioners on request, including root cause, actions taken, and prevention measures
- Post-quantum cryptography secure
- Yes
Secure development
- Approach to secure software development best practice
- Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- No
- Free trial available
- No
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 2%
- Between £250,000 and £500,000
- 3%
- Between £500,001 and £1,000,000
- 4%
- Between £1,000,001 and £2,500,000
- 6%
- Between £2,500,001 and £5,000,000
- 8%
- Over £5,000,001
- 10%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- Yes
- Who accredited the ISO/IEC 27001
- Citation ISO Certification
- ISO/IEC 27001 accreditation date
- Friday 20 August 2021
- What the ISO/IEC 27001 doesn’t cover
- NA
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- No
- Quality management systems (QMS)
- No
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- Fa1ea9f6-afe9-45b5-8df6-f25eac23e4f3
- Cyber essentials plus
- Yes
- Please provide your Cyber Essentials Plus Certificate Number
- 4c5bb7b6-410c-40c7-8268-5200c335f8f5
- Other security certifications
- No
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
- Plans to engage the contract workforce in deciding the most important workplace issues to address
- Activities that support an environment where staff are educated about, and feel empowered to, address their physical wellbeing
- Activities that support an environment where staff are educated about and feel empowered to report and address bullying and harassment
- Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
- Monitoring and reporting of gender and ethnicity pay gaps and plans to address them where necessary
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.
- Understanding of employment and relevant skills issues, and of the education and training issues relating to the contract. Illustrative examples: demographics, skills shortages, new opportunities in high growth sectors, geographic/local community and skills/employment challenges
- Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
- Activities to support relevant sector related skills growth and sustainability in the contract workforce. Illustrative examples: careers talks, curriculum support, literacy support, safety talks and volunteering
-
Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero
Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.
- Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
- Collaborative ways of working with the supply chain to deliver additional environmental benefits in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
- Delivery of additional environmental benefits through the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
-
Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.
Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.
- Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce
- Understanding barriers to access to health and social care services or employment opportunities e.g. digital inclusion
-