OnBase
OnBase is a enterprise information platform designed to manage your content, processes and cases, centralising important business content in one secure location and delivering relevant information when needed. OnBase is configurable without code and scalable across your organisation, allowing you to start in one department and expand as needed.
Features
- Captures documents and critical information at source, regardless of format.
- Automatically organises data and documents with minimal human interaction.
- Documents, data and processes managed in a single searchable system.
- Mobile access makes content available when you need it.
- Personalized, intuitive user interface for quick, efficient working.
- Enforces your access control lists and provides full audit trail.
- Powerful configurable workflow and E-signature capabilities.
- Real-time insights into your processes, records and system health.
- Variety of integration methods and low code point-and-click configuration.
- Securely stores, protects and destroys information in accordance with regulations.
Benefits
- Information flows seamlessly throughout your organisation for collaborative efficient working.
- Drastically reduces tedious and error-prone manual data entry.
- Solves problems of managing content across multiple systems/locations.
- Make better decisions, effectively serve constituents/patients/customers and keep processes flowing.
- Minimal training needs/costs and productivity benefits from day one.
- Collaborate in confidence, without compromising data security.
- Routes tasks, supports collaboration and streamlines processes.
- Enables you to take action when and where it’s needed.
- Easy access to information from preferred applications.
- Minimises risk and supports compliance.
Pricing
- Education pricing available
- Free trial available
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
2 4 0 2 2 6 1 0 5 7 3 8 7 2 2
Contact
HYLAND UK OPERATIONS LIMITED
Stacey Chapman
Telephone: +121 639 60261
Email: governmentcontracts@hyland.com
About your service
- Service categories
-
Applications
Content workflow and management
- Capture
- Document
Content services
- Enterprise Content Management Applications
- Content Sharing and Collaboration Applications
- Multi cloud support
- Yes
Service scope
- Software add-on or extension
- No
- Cloud deployment model
- Private cloud
- Service constraints
- The Hyland Cloud has no scheduled down time. CSAs (Customer Security Administrator) are notified via email of scheduled maintenance windows and alerts. Hyland will notify the customer of scheduled maintenance that is expected to impact or potentially impact system availability or functionality, typically at least one week in advance. Hyland will notify the customer of unscheduled maintenance that is expected to impact or potentially impact system availability or functionality, typically at least 24 hours in advance. Additionally, in the event of an availability incident affecting a full data center, Hyland provides ongoing updates and status via a status portal.
- System requirements
-
- Hyland owns and operates all equipment comprising Hyland Cloud Platform
- Hyland Cloud architecture is specialized, optimized for hosted Hyland products
- Hyland determines the best configuration
- Hyland engineers manage environment transparently to the Hyland Cloud customer
- Specific hardware information is maintained as proprietary to Hyland
User support
- Email or online ticketing support
- Yes
- Support response times
-
Support is provided Monday to Friday during standard business hours, and in accordance with the customer service agreement.
Hyland does not guarantee response times; however, support issues that materially impact production use of the system are addressed immediately. Hyland endeavors to identify a workaround whenever a permanent solution to a software error cannot be provided within a reasonable timeframe. The Technical Support analyst assigned to a support case is empowered to determine its impact on a customer’s implemented product per defined Severity Levels, and to obtain immediate attention to the issue as required. - User can manage status and priority of support tickets
- Yes
- Online ticketing support accessibility
- None or don’t know
- Phone support
- Yes
- Phone support availability
- 24 hours, 7 days a week
- Web chat support
- No
- Onsite support
- Yes, at extra cost
- Support levels
-
Hyland Technical Support offers multiple self-service and assisted support opportunities to assist customers in resolving issues being experienced with their implemented Hyland technology solution.
Hyland technical support is standard with subscription to OnBase solution.
Within the Hyland Cloud we offer different Service Class levels to meet the business continuity requirements of our hosted customers. With these service classes Hyland commits to high service availability\uptime (i.e. 99.5% to 99.9%). Specific financial remedies are associated with each Service Class. - Support available to third parties
- No
Onboarding and offboarding
- Getting started
-
As a part of implementation, the Hyland team trains your organisation’s designated system administrators, testers, and trainers responsible for educating their user community. The courses cover in depth all of the basic system functions plus your organisation’s specific application and procedures.
All solution training is meant to augment the training courses attended and certifications received from Hyland Education Services separate from the solution-specific engagement. Hyland offers comprehensive training courses to provide both end-users and system administrators the knowledge that they need to design, install, use and maintain the Hyland solution. Training sessions can be conducted at the customer site, at one of our training facilities, or via Hyland's online classroom; removing the need for students to travel.
Hyland also has end-user training that customers can host on their own internal network for users.
In addition, Hyland’s end users have access to web-based training courses at university.hyland.com. This website provides users with the education and knowledge they need, when they need it. Web-based courses are self-paced and provide students with an overview of Hyland solutions. They are meant to build a student’s beginning knowledge of a Hyland solution while developing their comfort with the system. - Service documentation
- Yes
- Documentation formats
-
- HTML
- Other
- Other documentation formats
-
- Documentation and training materials text-based PDFs and Microsoft HTML Help.
- Online documentation for each module single, compiled HTML file (CHM)
- Online documentation for each module locally installed Web help system
- End-of-contract data extraction
- Customer data is stored in the Hyland Cloud in the native format of the specific document. As a result, if a customer chooses to leave the Hyland Cloud, data can be exported to an encrypted hard drive with an index file included so it can be easily imported into another system, if so desired. The Hyland Cloud can provide an export of customer data as a billable service.
- End-of-contract process
- Customer data is stored in the Hyland Cloud in the native format of the specific document. As a result, if a customer chooses to leave the Hyland Cloud, data can be exported to an encrypted hard drive with an index file included so it can be easily imported into another system, if so desired. Customer data will be retained for 30 days after the contract ends. After this, the data will be deleted permanently.
- Documentation accessibility standard
- WCAG 2.2 AA
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Other
- Application to install
- No
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
-
The mobile experience is simpler than desktop. The interface is optimised for smaller screens and gesture-based navigation, and some capabilities are intentionally reduced. E.g., in OnBase Mobile, notes and annotations are managed via a list and are not rendered directly on the document, and mobile document search relies on configured custom queries with certain query types (such as Folder Type and Full Text) not available in the mobile client.
Desktop clients provide the more feature-rich experience, including broader functionality and the tooling required to configure and evolve the solution (for instance, workflow configuration in OnBase Studio and other configuration activities). - Service interface
- Yes
- User support accessibility
- WCAG 2.2 AA
- Description of service interface
-
OnBase provides an interface for point-and-click configuration of all major system components. This interface allows an administrator to accomplish the tasks of defining and administrating major system components. This limits the need for heavy IT involvement when introducing additional functionality into your OnBase solution such as the creation of new document types or capture processes.
OnBase also provides a designer called OnBase Studio that can be used to create workflows and rapid no-code/low-code applications. OnBase Studio provides a graphical layout as well as point-and-click configuration for designing these workflows and rapid no-code/low-code applications. - Accessibility standards
- WCAG 2.2 AA
- Accessibility testing
-
Third-Party Expert Testing: Hyland has historically collaborated with organizations like the Cleveland Sight Center to conduct comprehensive accessibility testing. Tests include full reports on software accessibility to identify and remediate barriers for users with visual disabilities, for example. Additionally, we have worked with Level Access experts.
Hyland employs a Software Accessibility Architect and technical roles who completed rigorous training to evaluate OnBase and other products against Voluntary Product Accessibility Template (VPAT) criteria. They are trained to translate needs of users across Hyland's portfolio and provide proper best practices to create highly accessible solutions.
Compliance Auditing: The OnBase SaaS environment is regularly audited against WCAG 2.1 Level AA standards including testing for:
Screen Reader Compatibility: Ensuring field elements, labels, and directions are properly read by assistive tools.
Keyboard-Only Navigation: Verifying all core functionalities can be executed without a mouse, including skipping repetitive navigation links.
Timed Response Management: Testing to ensure users of assistive technology are alerted when timed response is required and given options to request more time.
Ongoing Remediation: Findings used to create "remediation instructions" that guide developers in updating code, design, and content to meet latest global accessibility benchmarks for 2026.
More information found on our website: Hyland Accessibility - API
- Yes
- What users can and can't do using the API
-
OnBase provides robust API options and functionality through a variety of APIs. depending on specific integration needs.
REST API: modern option for creating integrations between OnBase and third-party applications. Enable custom solutions to work with content, including the ability to store, query, retrieve and modify documents, including keywords. Solutions can be designed to retrieve workflow lifecycles, queues and items, and execute non-interactive tasks.
Unity (SOAP) API: many elements can be obtained, including custom queries, documents, e-forms, envelopes, file cabinets, folders, keyword types, notes, print queues, workflow elements, etc.
Unity Client Automation API: allows for interaction with OnBase stored content, while making use of the Unity client as primary user interface. Allows developers to code back-end processing of data functionality and let the Unity Client present the user interface.
Automation API: offers quick easy way to extend functionality of OnBase Client using VB Scripts, which can perform actions on one or more documents, as well as access other information found within the client.
OnBase Client API: offers functionality to query for documents, save a document locally in different formats, and archive new documents into OnBase repository. Provides methods for integrating with workflow and folders and provides some configuration and application-level methods. - API documentation
- Yes
- API documentation formats
-
- HTML
- Other
- API sandbox or test environment
- No
- Customisation available
- Yes
- Description of customisation
-
Almost every facet of Hyland OnBase can be customised, with the scope of that customisation governed by your security model and agreed configuration standards. Each user’s experience is shaped by the processes and documents they are authorised to see.
Users can personalise their interface, including configuring their Personal Page so that frequently used features, forms and functions are available from a single landing page.
At an administrator level, OnBase is highly configurable:
- Security, roles and permissions: configure user groups and privileges to control which documents, folders, features and actions are available, enabling tailored experiences by role.
- Workflow automation: design and maintain custom workflows using OnBase Studio, using pre-built rules and actions to automate routing, approvals, notifications and more.
- Unity Forms: create custom form templates using the Unity Forms Designer, tailoring layout and form behaviour to your data capture and case processing requirements.
- Reporting and dashboards: Reporting Dashboards can be configured to store and present dashboards and reports.
Subject to the terms of a signed Agreement, Hyland allows customization of portions of the OnBase user interface for branding (e.g., customer name, logo, colours).
Scaling
- Independence of resources
- The Hyland Cloud is a private, managed, multi-instance cloud. Each Hyland Cloud customer is provided its own instance of OnBase so each customer has its own database and disk groups. However, the hardware and some servers are shared for the individual Hyland Cloud customers. As a result, there is no co-mingling of data in the cloud. Customers are assigned a unique encryption key that effectively renders the documents unreadable outside of the customer's dedicated instance of OnBase.
Analytics
- Service usage metrics
- Yes
- Metrics types
-
Cloud customers may also request the following reports:
Service availability report containing a list of service level availability (“SLA”) incidents that have been reported by Customer. The report will reflect each incident’s confirmation or rejection by Hyland.
Technical Support Activity report containing a list of issues that have been reported by Customer. The listing of each issue will reflect the current status (Open, Closed, etc.).
Service Consumption Report containing a detailed accounting of the measurements used to generate the most recent invoice for the Customer’s Hosted Solution. Totals are generated in multiple categories, including disk group storage and database storage. - Reporting types
- Reports on request
- Resource tagging
- Yes
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Other security clearance
- Government security clearance
- Security Clearance (SC)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
-
- United Kingdom
- European Economic Area (EEA)
- User control over data storage and processing locations
- Yes
- Datacentre security standards
- Managed by a third party
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- Another external penetration testing organisation
- Protecting data at rest
-
- Physical access control, complying with SSAE-18 / ISAE 3402
- Other
- Other data at rest protection approach
- AES 256 bit encryption. The OnBase modules Encrypted Alpha Keywords and Encrypted Disk Groups provide an additional layer of security for content stored in OnBase using AES – 256 encryption. Sensitive alphanumeric keywords can be stored in the database in an encrypted format, with access to view full or partial values granted to authorized users. Documents are automatically encrypted as they are imported into OnBase, becoming indecipherable when retrieved outside of the system. Even within OnBase, these files are accessible only to permissioned users, further decreasing risk of exposure.
- Data sanitisation process
- Yes
- Equipment disposal approach
- Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
- Data sanitisation type
-
- Deleted data can’t be directly accessed / Cryptographic Erasure
- Data Erasure
- Explicit overwriting of storage before reallocation / Secure Erase
- Physical Destruction / Hardware containing data is completely destroyed
Data importing and exporting
- Data export approach
-
For ad hoc exports, users can search for documents and save files with a list report (an index file of the supporting information). The user can select where documents and data are exported to.
Automated exports occur using workflow. Exports can be on a document-by-document basis or queued and performed as a batch process on a schedule. With automated export, documents can be in their native file format or a custom file extension can be used. You can export these files to any location the OnBase system has access to - a desktop, a server, SFTP, etc. - Data export formats
-
- CSV
- Other
- Other data export formats
-
- Documents can be exported in their native file form
- When supported- can be converted to PDF
- When supported- can be converted to an encrypted PDF
- The file format of the index file will be .TXT
- The file format of the index file will be .CSV
- Data import formats
-
- CSV
- Other
- Other data import formats
-
- All documents are stored in their native format
- Adobe XDP, AFP Document, ApproveIT Electronic Signature, CAD Document
- Classification Configuration, Configuration Package, DICOM Study, DJDE, Dynamic Document
- Electronic Form, Email Message, Emtex AFP/Metacode, Engineering Drawings
- Export Transfer Document, FormDocs Document, FormDocs Template, Geolocation Map State
- HL7 Waveform, HTML, HTML Unicode, Image File Format
- Image Rendered PDF, Internal XML, Lotus Notes Document, Media Stream
- Meditech Archive Report, MidMark Car Document, MidMark Stress Report
- Excel spreadsheet, Outlook Message, Power Point, Word, PCL, PDF
- Physical Record, Quick Time Movie, and more.
Data-in-transit protection
- Data protection between buyer and supplier networks
-
- TLS (version 1.2 or above)
- Other
- Other protection between networks
-
Hyland allows customers to white list IP addresses and/or block IP address ranges. Next gen firewalls and security groups to separate network segments are utilized. Hyland has an IDS/IPS system, anti-virus tools and protocols in place as components of its perimeter network security. IDS signatures are regularly updated based on new threats in a timely risk-prioritized manner. The IDS operates 24/7 within the Hyland Cloud platform.
The Hyland Cloud is configured to prevent DDoS attacks. Hyland partners with the upstream internet service provider to perform proactive scanning and filtering of DDoS attacks. - Data protection within supplier network
-
- TLS (version 1.2 or above)
- Other
- Other protection within supplier network
-
Hyland protects data within its network using a layered security model. Network devices are secured with encrypted management channels, strong authentication, and hardened configurations. Firewalls enforce segmentation, and IDS/IPS monitor traffic with alerts managed under documented incident response procedures. Data leakage prevention and logical network segregation further reduce risk.
Data at rest, including databases, file storage, and backups, is encrypted using AES-256. Unstructured data can be encrypted via the Encrypted Disk Groups module, and structured data via the Encrypted Alphanumeric Keywords module, both supporting AES-128 or AES-256. Data in transit uses TLS 1.2 or higher.
Availability and resilience
- Guaranteed availability
- Hyland offers multiple service classes for the Hyland Cloud that commit to uptime ranging from 99.5% to 99.9% uptime. These are the commitments upon which financial remedies will be provided. Average uptime for the Hyland Cloud is 99.99%.
- Approach to resilience
- The Hyland Cloud is highly available and N+1 redundant, and every Hyland Cloud solution is replicated to a secondary data center. All data files are replicated, and the database is log shipped to this secondary location where the logs are also applied. The disaster recovery plan is tested annually.
- Outage reporting
- Email, Public dashboard
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Identity federation with existing provider (for example Google Apps)
- Username or password
- Other
- Other user authentication
- It also supports SSO and LDAP authentication.
- Access restrictions in management interfaces and support channels
- Each Hyland employee that is granted administrative access to the Hyland Cloud is assigned a separate set of credentials from the Hyland Corporate environment that is specific to the Hyland Cloud environment. Use of this account requires a username, password, and electronic token (multi-factor authentication). This account can NOT be used to access corporate systems, nor can the corporate account be used to access Hyland Cloud systems. This “disparate” access strategy is intended to provide strong authentication as well as limit the risk associated with potential security threats from one environment to the other.
- Access restriction testing frequency
- At least once a year
- Management access authentication
-
- Identity federation with existing provider (for example Google Apps)
- Username or password
Audit information for users
- Access to user activity audit information
- You control when users can access audit information
- How long user audit data is stored for
- User-defined
- Access to supplier activity audit information
- Users have access to real-time audit information
- How long supplier audit data is stored for
- User-defined
- How long system logs are stored for
- At least 12 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
-
- ISO/IEC 27001
- Other
- Other security governance standards
- Hyland Cloud policies and procedures align with IEC/ISO 27001:2013, including Annex A controls. In addition, the Hyland Cloud aligns with guidelines found in NIST (National Institute of Standards and Technology) Special Publications including controls from standards such as SP 800-53, SP 800- 171, SP 800-88, where applicable.
- Information security policies and processes
-
Hyland Cloud policies for information security are embodied in the Hyland Cloud (HC) Information Security (IS) Policy Suite. Information Security, as defined therein, is protecting and preserving the confidentiality, integrity, availability and security of information.
The Hyland Cloud policies and procedures align with IEC/ISO 27001:2013, including Annex A controls and guidelines found in NIST (National Institute of Standards and Technology) Special Publications including controls from standards such as SP 800-53, SP 800- 171, SP 800-88, where applicable.
The Hyland Cloud is SOC 2 audited on an annual basis. The audit is performed by a qualified external agency that extensively reviews policies, measures the Hyland Cloud against those policies, and makes a determination against those policies concerning procedures and preparedness. Additionally, the Hyland Governance, Risk and Compliance (GRC) team completes internal audits quarterly.
Hyland Cloud adheres to ISO based policies governing asset management ensuring all assets managed by Hyland are clearly identified. An inventory of all critical assets are maintained to ensure effective asset protection takes place. The asset inventory includes all information necessary in order to recover from a disaster, including type of asset, format, location, backup information, license information, business value, as well as the owner of the asset. - Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Configuration and change management approach
- Hyland follows internal change management procedures when changes are initiated by Hyland, or when a customer requests to make a change on their behalf to existing systems, or when new systems are deployed to the Hyland Cloud. Generally speaking, change requests are submitted via a change management system and are then evaluated by subject matter experts. Upon approval by such subject matter experts, changes are implemented, documented, and tested. In the event an issue occurs with the approved change, rollback procedures, documented as part of the change request, are performed in order to return the system to its original state.
- Vulnerability management type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Vulnerability management approach
-
We assess potential threats to our services by:
Continuous vulnerability scanning and monitoring are integrated into our cloud environment.
External vulnerability assessments across all Hyland assets.
Risk-based evaluations occur during the SDLC and third-party penetration testing.
We deploy patches to our services by:
Vulnerabilities are prioritized and remediated within defined timelines.
Patches are applied promptly to production and non-production environments, followed by functional testing to ensure stability.
When no patch is available mitigation measures are implemented.
We get potential threat information from:
Internal monitoring and automated vulnerability detection processes.
Vendor security advisories, recognized vulnerability databases, and industry threat intelligence feeds. - Protective monitoring type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Protective monitoring approach
- Hyland employs a comprehensive protective monitoring process for the Hyland Cloud platform, which includes intrusion detection systems (IDS) to monitor network traffic and alert personnel to suspected compromises. Security Information and Event Management (SIEM) systems provide real-time collection, analysis, and correlation of log data to identify threats and trigger alerts. Endpoint Detection and Response (EDR) solutions are deployed across all workstations, servers, and infrastructure for continuous monitoring, threat detection, and automated response. Vulnerability management includes daily check-ins, weekly scans, and annual third-party penetration testing to validate defenses. Additional controls include next-generation firewalls, IPS/IDS, malware detection, server hardening, and network segmentation.
- Incident management type
- Complies with a recognised standard, for example, CSA CCM v4.0 or ISO/IEC 27035:2011 or SSAE-18 / ISAE 3402
- Incident management approach
-
Procedures are in place for escalation and notification in the event of qualified security incident. Incident response phases include:
Incident Trigger: incident logged and initial notification sent to appropriate Hyland Cloud team members
Evaluation: Each incident analyzed and information gathered to formalize specific response plan
Escalation: Scope and form of specific response required determined and coordination with any additionally needed resources completed
Response: Assigned responsibilities performed to resolve and manage incident.
Recovery: Steps to restore impacted system(s)
De-escalation: Normal processes reinstated
Post-incident Review: Secondary actions occur and review completed to improve procedures for future incident response - Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)
Public sector networks
- Connection to public sector networks
- Yes
- Connected networks
- Health and Social Care Network (HSCN)
Pricing
- Discount for educational organisations
- Yes
- Free trial available
- Yes
- Description of free trial
- Try Hyland is a unique way to experience Hyland's software through hands-on access to live software. Whether you're a customer or prospective customer, Try Hyland is your way to dive into pre-configured sample solutions and see the value that our tools can bring to your organization.
- Link to free trial
- https://try.hyland.com/
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 0%
- Between £500,001 and £1,000,000
- 0%
- Between £1,000,001 and £2,500,000
- 0%
- Between £2,500,001 and £5,000,000
- 0%
- Over £5,000,001
- 0%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- Yes
- Who accredited the ISO/IEC 27001
- EY CertifyPoint
- ISO/IEC 27001 accreditation date
- Friday 31 October 2025
- What the ISO/IEC 27001 doesn’t cover
- N/A
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- Yes
- Who accredited the ISO 9001 certification
- BSI (British Standards Institution)
- ISO 9001 accreditation date
- Tuesday 25 February 2025
- What the ISO 9001 doesn’t cover
- N/a
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- Yes
- CSA STAR accreditation date
- Friday 30 June 2023
- CSA STAR certification level
- Level 1: CSA STAR Self-Assessment
- What the CSA STAR doesn’t cover
-
Our CSA STAR Level 1 self‑assessment covers our Hyland‑managed cloud services as listed in the STAR Registry. It does not cover:
Customer‑hosted/on‑premises deployments of Hyland products
Hyland’s internal corporate IT systems
Non‑production environments (test, dev, demo)
Any Hyland offerings not delivered via the Hyland Cloud and related cloud services in the STAR listing. - PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- 0cc7ac81-8e02-4c8b-8ccb-a7e903e880bf
- Cyber essentials plus
- No
- Cyber Essentials Alternative
- None of the criteria
- Other security certifications
- Yes
- Any other security certifications
- SOC 2
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
- Plans to engage the contract workforce in deciding the most important workplace issues to address
- Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
- Understanding of in-work progression issues affecting the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors
- Measures to support in-work progression to help people in the contract workforce, to move into higher paid work by developing new skills relevant to the contract
- Support for the contract workforce by providing career advice, and providing opportunities for staff working on the contract with in-work progression career development into known skills shortages or high growth areas
- Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
- Volunteering opportunities for staff
- Understanding of the modern slavery risks and issues affecting the market, industry, sector or country (of origin or of source) relevant to the contract, and the workforce in the supplier’s own organisation and those of its key subcontractors
- Measures to identify, mitigate and manage modern slavery risks relating to the contract and how these will be implemented
- Outline policies and practices to be applied to or put in place for the contract to mitigate and manage modern slavery risks, including: Pre-employment checks, recruitment practices. Workplace conditions, safeguarding plans and processes in place and regular monitoring with relevant groups considered, which may include sampling
- How these flow down the supply chain and are monitored Illustrative examples include reporting, site visits, audits, etc.
- How to ensure business decisions re: price/cost, short lead times, payment timescales do not create modern slavery risks in the supply chain
- How the supplier will work with NGOs, trade unions or other businesses to address modern slavery risk
- Means of influencing staff, suppliers, customers, communities and/or any other appropriate stakeholders with respect to modern slavery risks relating to the contract
-
Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain
Policy Outcome 6: Employment and training: For those who face barriers to employment
- Understanding of the issues affecting the representation of disabled people in the workforce in the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors
-