Tendable - Quality and Regulatory Compliance Manager
A comprehensive digital quality assurance and improvement solution providing real time ward-to-board quality oversight for NHS acute, community and local authority social care providers. Modules: Audits, Checklists, Clinical Audits, Patient Staff Feedback, Accreditation, Incidents, Regulatory Compliance, Actions. All modules underpinned by sophisticated Analytics engine, AI capabilities and inbuilt risk stratification.
Features
- Practical mobile and web apps designed for the end users
- System prompts and personalised notifications to make prioritising work easier
- Tailor audits to specific areas making data entry more efficient
- Tag questions to customised themes CQC domains organisation priorities etc
- Real-time automated reporting data exports in PDF CSV other formats
- Integrated action tracking highlights actions addressing issues raised during inspections
- Issue resolution reporting highlights problems and speed being addressed
- Remote access via Android iOS devices and web browser
- Interoperable with other software (e.g. PowerBI, InPhase, Ideagen, Radar)
- Live dashboards for every level of your organisation
Benefits
- Demonstrable return on investment through reduced audit administration and duplication
- Faster rollout of Trust-wide quality improvement at scale
- Improved inspection readiness and accreditation outcomes
- Real-time executive visibility of organisational quality performance
- Reduced operational risk through early issue detection and escalation
- Lower compliance management costs through automation and standardisation
- Increased staff productivity and more time for patient care
- Consistent quality assurance across all services and care settings
- Evidence-based governance supporting confident regulatory and board reporting
- Long-term value through continuous optimisation and platform innovation
Pricing
- Free trial available
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
2 0 1 5 7 1 2 4 8 4 6 2 9 8 0
Contact
TENDABLE LIMITED
Robert Thornton
Telephone: 020 7435 7349
Email: finance@tendable.com
About your service
- Service categories
-
Applications
Production and operations
- Other operations
Service industry and public sector operations
- Healthcare
- Adult Social Care
- Children's Social Care
- Multi cloud support
- No
Service scope
- Software add-on or extension
- No
- Cloud deployment model
- Public cloud
- Service constraints
- Tendable is available on Android, iOS and Huawei smartphones and tablets. It aims to be backwards compatible providing support to devices on the two previous OS versions. The app requires internet access (though can work offline during inspections). Inspections can also be carried out on computer desktops, via a web browser.
- System requirements
-
- Compatible Android and iOS devices
- Internet access
- Ability to upgrade to the latest version of the app
- Licences require for usage
- Compatible operating systems Android , iOS, PC (Windows, MacOS)
- Compatible with any device supporting Chrome, Firefox web browsers
- Compatible with any device supporting Edge or Safari web browsers
User support
- Email or online ticketing support
- Yes
- Support response times
- Our response times are typically within 24 hours between Monday to Friday 09:00 to 17:30 GMT excluding English bank holidays. We may take longer to respond outside office hours.
- User can manage status and priority of support tickets
- Yes
- Online ticketing support accessibility
- None or don’t know
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- No
- Onsite support
- Yes, at extra cost
- Support levels
-
All customers will have access to help desk support provided in office hours via phone and email.
All customers have access to a self-service platform to manage their system configuration. Depending on the contracted service package, support may also include ongoing system configuration carried out by the Tendable team. - Support available to third parties
- Yes
Onboarding and offboarding
- Getting started
- Onboarding is delivered using Tendable’s structured implementation methodology, The Tendable Touch, which combines clinical leadership, technical configuration and change management to ensure successful adoption and long-term value. All customers receive access to the Tendable virtual training suite, covering mobile and desktop data capture, dashboards and analytics, action planning and administration tools. For Advanced and Custom service packages, onboarding is led by a dedicated Implementation Lead and supported by a Clinical Lead with NHS experience. Together they work with the organisation to confirm audit scope and quality objectives; review and optimise existing audit programmes; configure templates, scoring models and dashboards; support user setup and role configuration; deliver structured User Acceptance Testing;provide role-based training and rollout support. Change management is embedded throughout onboarding, including guidance materials and engagement support to drive consistent use across clinical and non-clinical teams. Offboarding is supported through secure user deactivation and structured data export in standard formats, ensuring customers retain full access to audit records, reports and action plans in line with contractual and data protection requirements.
- Service documentation
- Yes
- Documentation formats
-
- HTML
- End-of-contract data extraction
-
Customers can extract their own data through the API and reporting modules. Full data sets can also be provided as pdf, csv or a combination of both.
Precise details of data extraction formats will be agreed as part of the exit plan
We will agree with users how they want to obtain their data. We can make the data available to them as pdf reports or work with them to enable a data feed so they can extract the raw data. - End-of-contract process
- Included in the price of the contract: Offboarding is supported through secure user deactivation and structured data export in standard formats, ensuring customers retain full access to audit records, reports and action plans in line with contractual and data protection requirements.. Not included in the price of the contract: Any additional requirements such as tailored data or reports will be subject to additional costs.
- Documentation accessibility standard
- None or don’t know
- How the documentation is accessible
-
Onboarding documentation is tailored to each customer from the standard Tendable Touch implementation methodology. This is prepare with you by your Tendable implementation manager. Further technical "how to" documentation is available via the Knowledge Base accesses through the Tendable app and portal.
Offboarding documentation will be provided by your customer success manager at the time as part of the exit plan and offboarding process
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Application to install
- Yes
- Compatible operating systems
-
- Android
- IOS
- MacOS
- Windows
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
- Both mobile and desktop services enable users to conduct inspections, manage actions, review results, and personalise settings and notifications. The mobile application provides enhanced push notification settings and is optimised for on-the-go data capture at the point of care. The desktop service offers extended functionality including a comprehensive analytics dashboard for reviewing quality programme data, advanced reporting capabilities, and access to the administration portal where authorised users can manage organisational settings, user permissions, and overall quality programme configuration.
- Service interface
- Yes
- User support accessibility
- WCAG 2.2 AA
- Description of service interface
- Tendable's service interfaces are designed with a focus on ease of use, accessibility, and robust functionality. The intuitive user interface follows familiar mobile and web design patterns, ensuring rapid adoption across diverse user groups. Integrated real-time monitoring provides instant visibility of system performance and inspection data. Embedded support resources, including contextual help and a comprehensive knowledge base, enhance user experience and operational efficiency. The interface meets WCAG accessibility guidelines and satisfies the stringent usability and security requirements of NHS and public sector clients.
- Accessibility standards
- None or don’t know
- Description of accessibility
- Tendable's external API provides authorised users with secure, programmatic access to their organisational data. Access is controlled through individual authentication tokens issued via our dedicated developer portal, ensuring only approved integrations can connect to the service. The developer portal provides comprehensive API documentation, examples, guides to support implementation. Users can leverage the API to retrieve inspections, action tracking data, compliance and analytics information for integration with third-party BI tools, data warehouses, or dashboards. The API supports standard RESTful conventions and returns data in JSON format.
- Accessibility testing
- Accessibility is assessed throughout Tendable’s product development lifecycle using a combination of automated and manual testing. Automated accessibility testing tools are used to identify common issues such as colour contrast, missing labels, heading structure, focus order and keyboard navigation barriers. These checks are run regularly as part of release testing and regression testing cycles. Manual testing is also undertaken by developers and QA engineers to assess real-world usability, including navigation using keyboard-only input, screen scaling, readability and interaction with core workflows such as audit completion, action management and reporting. Accessibility issues are logged, prioritised and resolved within Tendable’s product backlog alongside functional enhancements and security updates. Improvements are validated before release to ensure compliance is maintained over time. Feedback from customers and users is actively encouraged and used to inform further accessibility enhancements. This approach ensures accessibility is treated as an ongoing quality requirement rather than a one-off activity.
- API
- Yes
- What users can and can't do using the API
- Tendable's external API provides authorised users with secure, programmatic access to their organisational data. Access is controlled through individual authentication tokens issued via our dedicated developer portal, ensuring only approved integrations can connect to the service. The developer portal provides comprehensive API documentation, code examples, and integration guides to support seamless implementation. Users can leverage the API to retrieve detailed inspection results, action tracking data, compliance metrics, and analytics information for integration with third-party business intelligence tools, data warehouses, or organisational dashboards. The API supports standard RESTful conventions and returns data in JSON format.
- API documentation
- Yes
- API documentation formats
-
- HTML
- API sandbox or test environment
- Yes
- Customisation available
- Yes
- Description of customisation
-
Tendable is designed to be highly configurable without requiring bespoke software development. Organisations can customise the platform through the administration interface or with support from Tendable’s Customer Success team, including:
1. Creation of multiple audit templates with customised question text, guidance, images, links and answer options
2. Structuring and grouping of questions into categories with defined ordering
3. Configuration of which questions apply to specific areas or services
4. Definition of inspection areas, locations and responsible leads
5. Configuration of organisational structures including divisions, sites and services
6. Scheduling rules and inspection frequencies
7. Use of tags for data aggregation and reporting
8. Enabling or disabling peer and expert audit classifications
End users can also personalise their experience, including:
1. Managing user profiles, team membership and contact details
2. Configuring alerts and inspection reminders
3. Customising dashboards by saving filters and selecting chart types
Customisation is supported during onboarding as part of The Tendable Touch and maintained through system upgrades, ensuring customers retain full access to future product enhancements while operating a configuration aligned to local quality objectives.
Scaling
- Independence of resources
- Tendable's service utilises Google Cloud Platform (GCP) infrastructure with intelligent autoscaling to ensure complete resource independence and consistent performance for all customers. Google Cloud Run services provide automatic scaling capabilities distributed across multiple availability zones within the region. Each customer's data is logically segregated within our secure multi-tenant architecture, ensuring no cross-contamination between organisations. A dedicated Virtual Private Cloud provides network isolation with private service access for secure database connectivity. This automatic scaling capability, combined with GCP's enterprise-grade security measures and UK-based data centres, guarantees high availability, reliability, and compliance with NHS and public sector data handling standards.
Analytics
- Service usage metrics
- Yes
- Metrics types
- Tendable provides reporting on system usage and operational performance, including user activity levels, audit completion rates, deadline adherence, inspection results, compliance scores, recurring issues and the progress and status of actions generated within the platform. Metrics can be viewed in real time via dashboards or exported for governance reporting and performance monitoring.
- Reporting types
-
- API access
- Real-time dashboards
- Regular reports
- Resource tagging
- No
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Conforms to BS7858:2019
- Government security clearance
- Baseline Personnel Security Standard (BPSS)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- United Kingdom
- User control over data storage and processing locations
- No
- Datacentre security standards
- Supplier-defined controls
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- ‘IT Health Check’ performed by a CREST-approved service provider
- Protecting data at rest
- Other
- Other data at rest protection approach
- Tendable implements comprehensive security measures for data at rest utilising industry-standard encryption across all storage layers. Data at rest within GCP data centres is protected through encryption protocols. Limited operational data cached on devices during use is secured with AES-256+SHA2 encryption utilising a 64-byte encryption key, with keys stored securely within the device's operating system encrypted storage. Google Cloud Secret Manager provides centralised management of application secrets with regional replication. Access to data is controlled through fine-grained, role-based access controls aligned to the principle of least privilege. Regular security audits ensure ongoing compliance with GDPR and NHS Data Security standards.
- Data sanitisation process
- No
- Equipment disposal approach
- Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
Data importing and exporting
- Data export approach
-
Users are able to email historical inspection reports as a pdf document directly from the app, or download from the web portal.
Full raw inspection data can be extracted via the API.
An analytics tool is provided to users as standard which facilitates export of different views of the data submitted in CSV, PDF or PNG format
Further export scenarios may be possible, subject to additional costs. - Data export formats
-
- CSV
- Other
- Other data export formats
- Data import formats
-
- CSV
- Other
- Other data import formats
-
- EXCEL
- PAPER INSPECTIONS
- Via API
Data-in-transit protection
- Data protection between buyer and supplier networks
- TLS (version 1.2 or above)
- Data protection within supplier network
- TLS (version 1.2 or above)
Availability and resilience
- Guaranteed availability
- Tendable guarantees 99% service availability, underpinned by our enterprise-grade Google Cloud Platform infrastructure and continuous monitoring systems. Our PostgreSQL database infrastructure is configured with highly available regional deployment across multiple availability zones. The database features point-in-time recovery capabilities with automated daily backups and maintains a 30-day backup retention policy with cross-zone replication. The application layer utilises Google Cloud Run services with intelligent auto-scaling capabilities. Traffic distribution is managed through a Global HTTP(S) Load Balancer with 99.99% SLA that routes requests across multiple backend services. Service availability is measured monthly, excluding planned maintenance windows scheduled outside core business hours and communicated to customers in advance. Our monitoring systems provide real-time alerting for any service degradation.
- Approach to resilience
- Tendable's resilience strategy leverages Google Cloud Platform's enterprise-grade infrastructure capabilities to ensure service continuity and data protection. Our architecture spans multiple availability zones within the UK region, providing automatic failover capability should any single zone experience disruption. Database systems utilise Cloud SQL for PostgreSQL with automated daily backups retained for 45 days within GCP, plus additional daily backup copies stored with an external cloud provider and retained indefinitely for long-term protection. Application servers operate on Cloud Run with automatic scaling and load balancing. A dedicated Virtual Private Cloud provides regional subnet distribution with private service access for secure database connectivity, ensuring data never traverses public networks. NAT Gateway configuration enables secure outbound connectivity whilst maintaining network isolation. Google Cloud Storage buckets are configured with regional replication for document storage. Secret management utilises Google Cloud Secret Manager with regional storage and automatic replication. Our disaster recovery procedures are documented and tested regularly.
- Outage reporting
- Tendable maintains proactive communication protocols for any service disruptions. In the event of an outage or significant service degradation, affected customers are promptly notified via email to designated technical contacts and, for critical incidents, via telephone to nominated escalation points. Initial notification is provided as soon as an incident is confirmed, with regular status updates throughout the resolution process. Following incident resolution, a post-incident report is provided detailing the root cause, timeline of events, customer impact assessment, and preventive measures implemented to avoid recurrence. For planned maintenance activities, customers receive advance notification at least 5 working days prior, detailing the maintenance window, expected impact, and any actions required. Our comprehensive monitoring infrastructure using Coralogix, Rollbar, and Google Cloud Monitoring ensures rapid detection and response to any service issues.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Username or password
- Other
- Other user authentication
- Users authenticate via username and password with enforced complexity requirements. Nominated administrators from each customer organisation are responsible for approving user access requests, managing role-based permissions, and offboarding user accounts when staff leave. Tendable fully supports Azure Active Directory (Entra ID) integration, enabling centralised identity management, automated user provisioning and deprovisioning, and Single Sign-On (SSO) capabilities. This integration allows organisations to leverage their existing identity infrastructure, enforce corporate authentication policies, and maintain consistent access governance across their technology estate.
- Access restrictions in management interfaces and support channels
- End users have no access to management interfaces and can only interact with support channels to view tickets they have personally submitted. Nominated organisational leads can be granted elevated access to manage Tendable system configuration and user permissions for their organisation, with optional visibility of all support tickets raised by their users. Within Tendable's internal operations, access follows strict 'need to know' and 'need to use' principles, ensuring only staff members with legitimate operational requirements receive access to management interfaces and support systems. Access grants are reviewed periodically and revoked promptly when no longer required.
- Access restriction testing frequency
- At least once a year
- Management access authentication
-
- Username or password
- Other
- Description of management access authentication
- All Tendable internal management systems are protected by Single Sign-On (SSO) with mandatory Multi-Factor Authentication (MFA) enabled wherever technically supported. Administrative access to production systems requires additional authentication steps and is restricted to authorised personnel only. Access to sensitive management functions is logged and monitored. Privileged access credentials are managed through secure password management systems with regular rotation schedules. Remote administrative access is secured via encrypted VPN connections with certificate-based authentication. These controls ensure robust protection of management interfaces against unauthorised access attempts.
Audit information for users
- Access to user activity audit information
- Users contact the support team to get audit information
- How long user audit data is stored for
- Between 1 month and 6 months
- Access to supplier activity audit information
- Users contact the support team to get audit information
- How long supplier audit data is stored for
- Between 1 month and 6 months
- How long system logs are stored for
- At least 12 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
- ISO/IEC 27001
- Information security policies and processes
- ISO/IEC 27001
- Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Configuration and change management approach
- Tendable's change management process employs structured workflow systems to record and track change requests through planning, development, testing, and deployment phases. Every change maintains a complete audit trail within our process management systems. All changes undergo mandatory risk assessment evaluating potential functional and security impacts. Infrastructure change control is managed by the DevOps Lead with Management oversight, including Google Cloud Platform monitoring and change coordination procedures. A Development → Staging → Production workflow ensures security testing at each stage. Automated vulnerability scanning and dependency management validate system updates. Emergency change procedures are defined for incident response with approval pathways.
- Vulnerability management type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Vulnerability management approach
- Tendable maintains a comprehensive vulnerability management programme aligned to industry best practices. Automated vulnerability scanning is conducted across all externally-facing systems and internal infrastructure. Vulnerability scanning tools continuously monitor code repositories and dependencies to identify potential security threats. Static code scanning processes analyse application code during development to detect vulnerabilities before deployment. Annual penetration testing validates security standards compliance. Critical and high-severity vulnerabilities are prioritised for immediate remediation, with patches deployed within 48 hours. Medium and low-severity items are incorporated into the development pipeline for resolution.
- Protective monitoring type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Protective monitoring approach
- Tendable maintains comprehensive logging of all user activity, system access events, and administrative actions. Coralogix serves as our comprehensive logging and monitoring platform with dedicated service accounts per environment. Rollbar provides application-level error tracking for immediate issue identification. Google Cloud Monitoring delivers native infrastructure metrics and alerting. The system implements OpenTelemetry standards for standardised observability. Any potential security compromise triggers our internal security incident management policy for immediate investigation. Confirmed data breaches are assessed for severity and reported to the Information Commissioner's Office within the statutory 72-hour timeframe where personal data is involved, with affected customers notified promptly.
- Incident management type
- Complies with a recognised standard, for example, CSA CCM v4.0 or ISO/IEC 27035:2011 or SSAE-18 / ISAE 3402
- Incident management approach
- We employ a security incident management policy as defined by our Information Security Management System which defines a common approach to the logging, assessment, reporting and resolution to each potential breach. All users are trained on this policy upon induction then at minimum once per year for a knowledge refresh or after a change ensuring they have the knowledge on reporting. The process is in place for any data or systems classified as private and/or confidential and includes personal data
- Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- No
- Free trial available
- Yes
- Description of free trial
- Tendable offers a time-limited trial of the platform to allow organisations to evaluate core functionality, usability and reporting capabilities using their own audit content. Trials can be supported by onboarding guidance to demonstrate operational value and inform the business case for wider deployment.
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 2%
- Between £500,001 and £1,000,000
- 5%
- Between £1,000,001 and £2,500,000
- 10%
- Between £2,500,001 and £5,000,000
- 10%
- Over £5,000,001
- 10%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- Yes
- Who accredited the ISO/IEC 27001
- BSI
- ISO/IEC 27001 accreditation date
- Wednesday 21 May 2025
- What the ISO/IEC 27001 doesn’t cover
- All development and business processes covered
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- No
- Quality management systems (QMS)
- No
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- 6330856b-85e9-456f-b314-737501d21498
- Cyber essentials plus
- No
- Cyber Essentials Alternative
- In relation to the services you do not have a current and valid Cyber Essentials Plus certificate which has been awarded by one of the government approved Cyber Essentials accreditation bodies but you are working towards gaining it, and will be in a position to confirm that you have been awarded a current and valid Cyber Essentials Plus certificate by one of the government approved accreditation bodies within 12 months of the date of award.
- Other security certifications
- No
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
- Outline policies and practices to be applied to or put in place for the contract to mitigate and manage modern slavery risks, including: Pre-employment checks, recruitment practices. Workplace conditions, safeguarding plans and processes in place and regular monitoring with relevant groups considered, which may include sampling
-