OPRaaS LSCA; Labour Supply Chain Assurance Compliance & Audit Platform
OPRaaS Labour Supply Chain Assurance (LSCA) is a SaaS platform that standardises labour supply chain self‑certification, embedded training and evidence‑based audit across end-hiring organisations, agencies and intermediaries, giving public sector buyers real‑time visibility of workforce, compliance and supply chain risk through configurable workflows, dashboards and exportable reports.
Features
- Single, structured evidential audit trail across an endhirer's intermediaries
- Cuts through labour‑supply compliance complexity, giving end‑hirers visibility
- Automated compliance supplier scoring with pass, partial, fail thresholds.
- Automated red‑flag detection for disguised remuneration, phoenixism, mini‑umbrellas
- Secure AWS data repository holding all LSCA audits and evidence
- Time‑stamped audit trails showing checks, findings, and remediation actions.
- Unlimited audits across agencies, umbrellas, payroll and SOW arrangements
- Automated escalation and case management for non‑compliant suppliers
- Onboarding portal enforcing LSCA completion for PSL entry
- Virtual Compliance Director overlays LSCA governance expertise across your organisation
Benefits
- Gives boards one defensible file for HMRC and internal audits
- Simplifies fragmented data into a single, understandable risk picture
- Prioritises remediation effort and PSL decisions using objective risk ratings
- Spots hidden scams early, before they become seven‑figure liabilities
- Protects sensitive data while keeping every defence document instantly accessible
- Proves continuous monitoring, not one‑off box‑ticking exercises
- Enables ongoing assurance as suppliers, models and risks change
- Ensures issues translate into tracked actions and accountable owners
- Blocks high‑risk suppliers from joining without evidencing compliance first
- Delivers a premium compliance ecosystem without capex or extra headcount
Pricing
- Education pricing available
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
2 2 3 4 7 2 2 7 9 4 7 1 1 7 5
Contact
OPRAAS LTD
Chris Dunn
Telephone: 07703036821
Email: chris@opraas.co.uk
About your service
- Service categories
-
Applications
Enterprise resource management
- Procurement
Human capital management
- Core Human Resources Applications
- Multi cloud support
- No
Service scope
- Software add-on or extension
- Yes, but can also be used as a standalone service
- What software services is the service an extension to
- Typically integrated via secure data feeds or custom interfaces into VMS, MSP and HR/ERP platforms to share supplier, audit and risk data. Where required, API‑based integration can be scoped and delivered as a project-specific enhancement.
- Cloud deployment model
- Public cloud
- Service constraints
- Service delivered as UK‑hosted public‑cloud SaaS with planned maintenance windows, dependent on customer internet connectivity and browser support. Data extraction via standard reports / APIs; bespoke integrations or major customisations are subject to separate scoping and may require additional fees
- System requirements
-
- Modern web browser (Chrome, Edge, Safari, Firefox) with JavaScript enabled
- Reliable internet connection to access the cloud‑hosted LSCA platform
User support
- Email or online ticketing support
- Yes
- Support response times
- Email and online ticketing support available 09:00–17:30 UK time, Monday–Friday (excluding public holidays). We aim to respond to all tickets within 4 working hours and resolve priority issues within 1 working day. Limited monitoring at weekends for critical availability incidents only.
- User can manage status and priority of support tickets
- Yes
- Online ticketing support accessibility
- None or don’t know
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- No
- Onsite support
- Yes, at extra cost
- Support levels
- Standard support is included in the subscription price and covers email and online ticketing during UK business hours (09:00–17:30, Monday–Friday, excluding public holidays). A named LSCA lead provides account management and coordinates technical support, onboarding and periodic service reviews. Enhanced support options (e.g. extended hours or on‑site consultancy) can be scoped and priced separately on request.
- Support available to third parties
- Yes
Onboarding and offboarding
- Getting started
- OPRaaS provides a fully managed onboarding process. End‑hirer stakeholders complete LSCA online training and then use the platform to perform their own self‑audit, which OPRaaS reviews and quality‑assures before agreeing improvement actions. Supplying agencies and any approved umbrella companies complete the same training and self‑audit process, with OPRaaS reviewing outcomes and advising on remediation where required. A vetted panel of umbrella companies is available, or agencies’ preferred umbrellas can be onboarded subject to successful LSCA self‑audit and review. OPRaaS also undertakes quarterly business‑continuity and risk checks, with optional additional auditing on payslips and payment data. Ongoing LSCA audits and enhanced monitoring provided by OPRaaS beyond the core platform access are delivered as chargeable services, with scope, frequency and pricing agreed with each buyer at call‑off and reviewed periodically alongside performance.
- Service documentation
- Yes
- Documentation formats
- End-of-contract data extraction
- Contracts are typically let on an annual basis. At the end of the contract, buyers can request a full export of LSCA data (for example supplier records, audit responses, findings and recommendations) in commonly used formats such as CSV or PDF, provided securely via encrypted file transfer. A basic, one‑off data export to support offboarding is included in the service price, with any additional, bespoke extraction or transformation requirements scoped and charged separately by agreement.
- End-of-contract process
- At the end of the contract the buyer can request a full export of LSCA data (for example supplier details, audit responses, findings and recommendations) in agreed open formats, and user access to the platform is then removed on the agreed termination date. A standard one‑off data export and secure transfer is included in the contract price. Any further activity – such as extended access, additional or repeated data extracts, complex data transformation, or follow‑on advisory work on historic data – is scoped separately and charged as an additional cost.
- Documentation accessibility standard
- None or don’t know
- How the documentation is accessible
- Onboarding and offboarding guides are provided as clear, structured PDF documents using plain language, logical headings and labelled screenshots, which work with standard screen‑reader and magnification tools. Documents can be enlarged without loss of clarity, printed in high contrast, and alternative formats or reasonable adjustments can be provided on request for users with specific accessibility needs.
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Application to install
- No
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
- The service is accessible on modern mobile browsers, but the interface is optimised for desktop and laptop use. Review, reporting and document upload tasks are more practical on larger screens.
- Service interface
- Yes
- User support accessibility
- None or don’t know
- Description of service interface
- The service is delivered through a secure, browser-based web interface with role-based access for end‑hirers, agencies and umbrella companies. Users access dashboards to complete LSCA self‑assessments, upload evidence, review risk scores and generate reports. Navigation is via a top menu and sectioned forms, designed to be usable on standard desktop browsers and responsive on tablets and mobiles. No client software needs to be installed; all access is over HTTPS with authenticated log‑in
- Accessibility standards
- None or don’t know
- Description of accessibility
- The LSCA interface is delivered through a responsive web application that works with keyboard navigation and supports browser zoom, high‑contrast modes and screen‑reader friendly headings and labels for key forms and buttons. Users can complete assessments, upload evidence and view reports using standard desktop browsers and tablets. Some tables and dashboards are easier to interpret on larger screens, and there may be limitations for users relying solely on screen readers for long narrative content or large data grids.
- Accessibility testing
- No formal testing with users of assistive technologies has been completed yet. Accessibility has been considered during design through use of semantic HTML, clear labels and heading structures, and checking pages with browser-based accessibility tools. The roadmap includes structured testing with screen‑reader users and keyboard-only users, and addressing any issues identified as part of ongoing service improvements.
- API
- No
- Customisation available
- Yes
- Description of customisation
- Buyers can commission tailored audit templates, question sets, reporting views and optional white‑labelling (logos, colours and terminology). Customisation is scoped separately and may attract additional setup and configuration charges agreed at call‑off.
Scaling
- Independence of resources
- Our multi‑tenant SaaS is deployed on auto‑scaling cloud infrastructure with separate application containers and logically isolated databases per customer. Resource limits, connection pooling and query optimisation prevent a single tenant from monopolising CPU, memory or database capacity. Background jobs are rate‑limited and queued so large audits or data imports cannot degrade other customers’ performance. Continuous performance monitoring alerts our operations team to unusual load so additional capacity can be provisioned before service levels are affected. This combination of logical isolation, capacity management and monitoring ensures one customer’s demand does not impact others’ availability or response times.
Analytics
- Service usage metrics
- Yes
- Metrics types
-
Yes – the platform provides rich service usage metrics as standard.
We track audit volumes, completion rates, compliance scores, red‑flag counts, and evidence gaps at supplier, group and portfolio level, alongside user logins, activity by section, and export/download events.
Metrics are available through on‑screen dashboards and downloadable reports, with instance IDs, timestamps and version history recorded so buyers can evidence how LSCA due diligence activity has changed over time and which suppliers have improved or deteriorated - Reporting types
-
- Real-time dashboards
- Regular reports
- Reports on request
- Resource tagging
- No
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Conforms to BS7858:2019
- Government security clearance
- Baseline Personnel Security Standard (BPSS)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- United Kingdom
- User control over data storage and processing locations
- No
- Datacentre security standards
- Complies with a recognised standard (for example CSA CCM version 4.0)
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- Another external penetration testing organisation
- Protecting data at rest
- Encryption of all physical media
- Data sanitisation process
- Yes
- Equipment disposal approach
- Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
- Data sanitisation type
-
- Deleted data can’t be directly accessed / Cryptographic Erasure
- Physical Destruction / Hardware containing data is completely destroyed
Data importing and exporting
- Data export approach
- Users can export all LSCA data directly from the secure SaaS interface, using role‑based permissions to run on‑demand or scheduled exports at engagement, supplier, or audit level into open formats such as PDF for downstream reporting, with full audit trails retained in the platform for verification of what was extracted, when and by whom.
- Data export formats
-
- CSV
- ODF
- Other
- Other data export formats
- Data import formats
-
- CSV
- ODF
- Other
- Other data import formats
-
- Word
- Excel
Data-in-transit protection
- Data protection between buyer and supplier networks
- TLS (version 1.2 or above)
- Data protection within supplier network
- TLS (version 1.2 or above)
Availability and resilience
- Guaranteed availability
-
We guarantee 99.9% monthly uptime for the LSCA production service, excluding scheduled maintenance windows notified in advance.
Availability is measured using continuous monitoring of application and API endpoints from multiple locations, with incidents logged and time‑stamped to calculate actual uptime against the SLA.
If monthly availability drops below 99.9% for reasons within our control, affected customers become eligible for service credits (typically a percentage of the monthly subscription fee, tiered by severity of the breach) which are applied against future invoices rather than cash refunds. - Approach to resilience
-
Our service is hosted on AWS across multiple availability zones within a single UK region, using auto‑scaling application instances, managed database services and redundant load balancers to remove single points of failure.
All components are deployed as code so infrastructure can be rebuilt quickly, with automated backups, point‑in‑time database recovery and cross‑AZ data replication to protect against hardware or zone failure.
We operate continuous monitoring, alerting and incident response runbooks, and can provide more detailed diagrams of our resilience architecture to buyers on request under appropriate confidentiality. - Outage reporting
-
Outages, planned maintenance and degraded performance are communicated through email alerts to nominated buyer contacts and administrators, plus status updates on our online service status page.
For major incidents we also provide follow‑up incident reports summarising impact, root cause and remediation, and can enable webhook or API notifications for integrated buyers on request so they can feed LSCA status into their own dashboards.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Username or password
- Access restrictions in management interfaces and support channels
-
Management interfaces are restricted to named operational and support staff using unique accounts, role‑based access control and mandatory MFA, with least‑privilege roles for routine activities.
Administrative consoles are not exposed to the public internet; access is via hardened endpoints and secure VPN, with all actions logged and regularly reviewed.
Support channels never require full credentials; staff use secure tooling to view only the customer data needed to resolve an issue, and any temporary elevated access is time‑limited and recorded in the ticketing system. - Access restriction testing frequency
- At least once a year
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Dedicated link (for example VPN)
- Username or password
Audit information for users
- Access to user activity audit information
- Users have access to real-time audit information
- How long user audit data is stored for
- At least 12 months
- Access to supplier activity audit information
- Users contact the support team to get audit information
- How long supplier audit data is stored for
- At least 12 months
- How long system logs are stored for
- At least 12 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- No
- Security governance approach
-
Security governance for LSCA is led by a designated senior security owner who is accountable for risk management, policy approval and alignment with the UK Software Security Code of Practice.
We maintain documented information security policies, a risk register, and defined roles for development, operations and data protection, with regular review by management.
Secure development is built into our SDLC through change control, code review, dependency scanning and penetration testing, supported by incident management, access control, logging and supplier assurance processes that are reviewed at least annually or after any major incident. - Information security policies and processes
- We operate a formal Information Security Policy approved and reviewed annually by the Managing Director, covering asset management, access control, physical and operational security, cryptography, incident management and business continuity. All information assets are classified and protected, access is restricted to authorised staff using strong authentication, and critical systems are patched and backed up regularly. Staff are made aware of their responsibilities through induction and ongoing training, and any breaches or incidents must be reported immediately for investigation and remediation in line with our documented incident management process
- Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
-
We use documented configuration and change management processes with all infrastructure and application components defined as code and tracked in version control, including full history and rollback capability.
Changes follow a standard workflow covering request, impact assessment, peer review, testing in non‑production, and approval before deployment via automated pipelines, with security‑relevant changes reviewed by a designated security lead.
Configuration baselines are monitored using environment manifests and audit logs so we can detect unauthorised changes, and all releases are recorded in a change register with links to tickets, test evidence and deployment timestamps. - Vulnerability management type
- Supplier-defined controls
- Vulnerability management approach
-
We run regular automated vulnerability scans of our infrastructure, application code and dependencies, and subscribe to vendor and NCSC threat advisories to identify new risks.
Findings are triaged by severity; critical vulnerabilities are assessed immediately and typically remediated or mitigated within 24–72 hours, with high‑severity issues addressed in the next available maintenance window.
Patches are deployed through our change management pipeline, with regression testing in non‑production before release, and we repeat scans to confirm remediation and track outstanding items on a central risk register. - Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
-
We collect and correlate application, database, infrastructure and access logs to detect suspicious activity such as unusual login patterns, privilege changes, failed access attempts or anomalous data exports.
Alerts from our monitoring tools are triaged by severity; potential compromises trigger our incident response process which includes containment (for example account lockout, key rotation, traffic blocking), investigation, and remediation.
High‑severity security alerts are typically responded to within minutes and formally acknowledged within one hour, with incident timelines, actions and lessons learned recorded and, where appropriate, communicated to affected customers. - Incident management type
- Supplier-defined controls
- Incident management approach
-
We operate a documented incident management process with predefined runbooks for common events such as suspected account compromise, data loss, denial‑of‑service and service degradation.
Users can report incidents via the support portal or email to our service desk, which logs and triages each case, escalating security events to the incident response team.
For significant incidents we provide customers with written incident reports summarising impact, timeline, root cause, remediation and lessons learned, and we update internal procedures where needed to prevent recurrence. - Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Supplier-defined process
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- Yes
- Free trial available
- No
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 2%
- Between £500,001 and £1,000,000
- 3%
- Between £1,000,001 and £2,500,000
- 4%
- Between £2,500,001 and £5,000,000
- 5%
- Over £5,000,001
- 7%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- No
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- No
- Quality management systems (QMS)
- No
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- 2d7d1040-c1ef-478c-9f99-c495a9cc47c3
- Cyber essentials plus
- No
- Cyber Essentials Alternative
- In relation to the services you do not have a current and valid Cyber Essentials Plus certificate which has been awarded by one of the government approved Cyber Essentials accreditation bodies but you are working towards gaining it, and will be in a position to confirm that you have been awarded a current and valid Cyber Essentials Plus certificate by one of the government approved accreditation bodies within 12 months of the date of award.
- Other security certifications
- No
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- New or retained jobs on the contract workforce in the relevant area that meet the criteria set out in MAC 1b, 1c and 1d
- New apprenticeships on the contract workforce in the relevant area that meet the criteria set out in MAC 1b
- Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
- Plans to engage the contract workforce in deciding the most important workplace issues to address
- Ensuring new workers are informed of their right to join a trade union
- Monitoring of employee engagement rates (by protected characteristic) and, where necessary, the development of actions to ensure all voices are heard across the diversity of the workforce
- Employment contracts that reflect actual hours worked; steps taken to ensure employees understand their contracts and have the ability to review and adjust them if actual hours regularly exceed contracted hours
- Activities that support an environment where staff are educated about, and feel empowered to, address their physical wellbeing
- Activities that support an environment where staff are educated about and feel empowered to report and address bullying and harassment
- Activities to cascade good practice on fair working conditions throughout the supply chain
- Offer a pay and leave entitlement to all eligible staff who become kinship carers, ideally equivalent to statutory adoption pay and leave
- Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
- Monitoring and reporting of gender and ethnicity pay gaps and plans to address them where necessary
- Entitlement to sick pay for the contract workforce, with provision in place for any staff who do not meet the earnings threshold for statutory sick pay, payment of sick pay from day one of absence and payment of staff on the contract workforce who are off sick a replacement income of 100% of their usual earnings for as long as possible
- Plans for an appropriate income replacement policy for staff who are required to spend time away from work to care for a sick dependent or close relative
- Understanding of in-work progression issues affecting the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors
- Measures to support in-work progression to help people in the contract workforce, to move into higher paid work by developing new skills relevant to the contract
- Support for the contract workforce by providing career advice, and providing opportunities for staff working on the contract with in-work progression career development into known skills shortages or high growth areas
- Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
- Volunteering opportunities for staff
- Understanding of the modern slavery risks and issues affecting the market, industry, sector or country (of origin or of source) relevant to the contract, and the workforce in the supplier’s own organisation and those of its key subcontractors
- Measures to identify, mitigate and manage modern slavery risks relating to the contract and how these will be implemented
- Outline policies and practices to be applied to or put in place for the contract to mitigate and manage modern slavery risks, including: Pre-employment checks, recruitment practices. Workplace conditions, safeguarding plans and processes in place and regular monitoring with relevant groups considered, which may include sampling
- How these flow down the supply chain and are monitored Illustrative examples include reporting, site visits, audits, etc.
- How to ensure business decisions re: price/cost, short lead times, payment timescales do not create modern slavery risks in the supply chain
- How the supplier will work with NGOs, trade unions or other businesses to address modern slavery risk
- Means of influencing staff, suppliers, customers, communities and/or any other appropriate stakeholders with respect to modern slavery risks relating to the contract
-