QEPA Educational Psychology Advice Quality Assurance Module
The QEPA Module Quality Educational Psychology Advice is a cloud-hosted QA tool built specifically for Educational Psychology Services to deliver high-quality statutory advice that is consistent, evidence-based and aligned with professional expectations.
Features
- Comprehensive EHCP audit criteria aligned with national standards
- Structured grading (e.g., Gold, Silver, Bronze, Significant Gap)
- Instant dashboards and real-time quality oversight
- Exportable, customisable quality reports
- Secure UK data residency and no identifiable child data stored
- Peer moderation of EP Advice audits
Benefits
- Improves EP Advice quality and compliance consistently
- Provides clear evidence for governance and inspection
- Reduces manual workload and supports trend-led planning
- Enables meaningful service performance insight
- Promotes consistent standards across EP teams
- Reduces subjectivity and enhances audit transparency
- Strengthens collaborative working across agencies
- Provides bespoke reporting for leaders and stakeholders
- Supports professional development and supervisory insight
Pricing
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
3 7 0 9 2 0 7 7 5 7 9 8 8 3 6
Contact
INVISION SERVICES LIMITED
Philip Stock
Telephone: 07739573596
Email: p.stock@invision360.com
About your service
- Service categories
-
Applications
Enterprise resource management
- Enterprise performance management
- Multi cloud support
- No
Service scope
- Software add-on or extension
- Yes, but can also be used as a standalone service
- What software services is the service an extension to
- Each Invision360 QA module can operate standalone or integrate with other modules, providing flexible, scalable quality assurance across EHCPs, Annual Reviews, and Educational Psychology services. Standalone use targets specific QA needs, while combined deployment delivers end-to-end oversight, aligned reporting, and insight-driven improvement, supporting compliance, governance, and continuous service enhancement.
- Cloud deployment model
- Private cloud
- Service constraints
-
The service is cloud-hosted on AWS and may occasionally require scheduled maintenance to ensure security, reliability, and performance.
While designed for high availability, rare infrastructure outages or connectivity issues may temporarily affect access.
Notifications of scheduled maintenance are provided in advance to minimise disruption. The service is designed to maintain data integrity and continuity, with contingency measures for planned or unplanned interruptions. - System requirements
- Modern, up-to-date web browser; no additional software needed.
User support
- Email or online ticketing support
- Yes
- Support response times
- Within 2 working days
- User can manage status and priority of support tickets
- No
- Phone support
- No
- Web chat support
- No
- Onsite support
- No
- Support levels
-
We offer dedicated customer success for all clients, with all customers receiving the same package of customer support (there is no variation on cost).
Support is offered via a dedicated customer success email inbox, 121 support calls, team workshops for on-boarding, moderation sessions, and troubleshooting, and regular usage and impact reports where required.
Our Customer Success team can assist with most customer queries, but access to the engineering team can be supported if required. - Support available to third parties
- No
Onboarding and offboarding
- Getting started
- Users will be onboarded via an initial meeting and given a user manual to help them get started. After the initial onboarding the team will be at hand to offer support via email and on Teams. The CS team will schedule regular touchpoint and check in meetings. These meetings, and ongoing communication via email can be used to arrange further training, co-production sessions, or support as required, at no additional cost.
- Service documentation
- Yes
- Documentation formats
-
- HTML
- End-of-contract data extraction
- At the end of a contract, or if a customer does not upgrade or migrate to a new system version, all customer data is made available in an open, machine-readable format. Following extraction, data is permanently deleted from our AWS-hosted environment. This process ensures customers retain control of their information, supports secure transition or archiving, and maintains compliance with data protection obligations. Customers are notified in advance and provided with instructions for accessing their data, ensuring a smooth and transparent data handover at contract conclusion.
- End-of-contract process
-
At the end of the contract period, client and user access to the system ceases, and billing ends. We work closely with clients to ensure a smooth closure of services, including data handover in an open, machine-readable format. Following data extraction, all information is permanently removed from our AWS-hosted environment.
The contract price includes standard access to the system, maintenance, support, updates, and data export at contract end. Additional costs may apply for bespoke configurations, extended support beyond the contract period, or migration to upgraded modules or new versions. - Documentation accessibility standard
- WCAG 2.2 AA
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Application to install
- No
- Designed for use on mobile devices
- No
- Service interface
- Yes
- User support accessibility
- WCAG 2.2 AA
- Description of service interface
- Our modules provide a user interface via a web dashboard, allowing staff to submit and review audits, and generate reports for quality insight analysis. The interface is designed to be intuitive, supporting efficient QA workflows. We continually enhance accessibility, aligning with WCAG 2.2 AA standards, to ensure equitable access for all users. The service interface supports secure, role-based access and presents data in clear, actionable formats. Regular updates improve usability, navigation, and reporting features, ensuring that staff can effectively monitor, evaluate, and drive continuous improvement across EHCP, Annual Review, and Educational Psychology quality assurance processes.
- Accessibility standards
- WCAG 2.2 AA
- Accessibility testing
- Our modules are designed to align with WCAG 2.2 AA standards, and we continually aim to improve accessibility. However, we have not yet conducted formal interface testing with users of assistive technology. We plan to incorporate such testing in future development cycles to validate and enhance usability for all users.
- API
- No
- Customisation available
- No
Scaling
- Independence of resources
- This system auto-scales through the cloud.
Analytics
- Service usage metrics
- Yes
- Metrics types
- Our modules provide clients with real-time dashboards displaying service usage, including user activity, audit submissions, and review progress. Clients can also request custom reports to gain deeper insights into engagement, performance trends, and quality assurance outcomes. These metrics support monitoring, governance, and continuous improvement, helping organisations identify areas for development, plan interventions, and demonstrate compliance. All usage data is accessible securely via the web interface, with role-based permissions ensuring only authorised users can view or extract metrics. This approach provides transparent, actionable insights into service adoption and effectiveness across EHCP, Annual Review, and EP QA processes.
- Reporting types
-
- Real-time dashboards
- Reports on request
- Resource tagging
- No
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Conforms to BS7858:2019
- Government security clearance
- None
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- United Kingdom
- User control over data storage and processing locations
- No
- Datacentre security standards
- Complies with a recognised standard (for example CSA CCM version 4.0)
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- ‘IT Health Check’ performed by a CREST-approved service provider
- Protecting data at rest
- Encryption of all physical media
- Data sanitisation process
- No
- Equipment disposal approach
- A third-party destruction service
Data importing and exporting
- Data export approach
- Users can download their data in an open format (csv) or in pdf format
- Data export formats
- CSV
- Data import formats
- CSV
Data-in-transit protection
- Data protection between buyer and supplier networks
- TLS (version 1.2 or above)
- Data protection within supplier network
- TLS (version 1.2 or above)
Availability and resilience
- Guaranteed availability
- We target 99% uptime. Availability SLAs available upon request.
- Approach to resilience
-
Databases are automatically backed up via cloud and recovery is verified manually.
Backups are held across multiple AWS availability zones.
Issues are raised by the client with customer success. A ticket is created on our ticketing system and shared with the engineering team. The team update the ticket when the issue is solved and tested. Customer Success then goes back to the client. - Outage reporting
- In the event of a service outage or disruption, we notify clients promptly via email alerts to designated contacts. Alerts include relevant details such as affected modules, estimated resolution time, and any interim workarounds. This ensures clients remain informed, can take appropriate action, and maintain continuity of operations.
Identity and authentication
- User authentication needed
- Yes
- User authentication
- Multi-Factor Authentication (MFA)
- Access restrictions in management interfaces and support channels
-
Access to Invision360 management interfaces and support channels is restricted using role-based access controls (RBAC). Each user is assigned a role that determines the modules, features, and data they can access. Administrative or sensitive functions are limited to authorised personnel only.
Support channels, including the support portal and email, are secured via authentication mechanisms and monitored to ensure only verified users can report incidents or request actions. Access rights are reviewed regularly, and inactive accounts are disabled promptly. These measures ensure that only authorised users can access systems, data, and support functions. - Access restriction testing frequency
- At least every 6 months
- Management access authentication
- Multi-Factor Authentication (MFA)
Audit information for users
- Access to user activity audit information
- No audit information available
- Access to supplier activity audit information
- No audit information available
- How long system logs are stored for
- Between 6 months and 12 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
- ISO/IEC 27001
- Information security policies and processes
-
Invision360 maintains a comprehensive suite of information security policies and processes aligned with ISO 27001, ensuring the confidentiality, integrity, and availability of client data across all QA modules. Policies cover areas including access control, data classification, incident management, change management, secure development, and cloud security practices.
To ensure policies are followed, we implement:
Mandatory staff training and awareness programmes
Role-based access controls and regular permission reviews
Routine audits and internal checks against ISO 27001 standards
Incident reporting procedures to detect and respond to potential breaches - Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
- Invision360 follows structured configuration and change management processes to ensure system stability and integrity. All changes to software, infrastructure, or configurations are planned, reviewed, and approved before implementation. Changes are logged, version-controlled, and tested in a staging environment prior to release. Critical updates follow a formal approval workflow with stakeholder sign-off. Emergency changes are documented and reviewed retrospectively. Regular audits and monitoring ensure adherence to processes, enabling consistent, reliable service delivery across all modules while minimising risk and maintaining compliance with ISO 27001 and internal security standards.
- Vulnerability management type
- Supplier-defined controls
- Vulnerability management approach
-
Invision360’s vulnerability management combines automated and manual assessments to provide comprehensive oversight of infrastructure, applications, and network perimeters. This is supplemented by periodic penetration tests and Cyber Essentials Plus assessments to validate system resilience.
Identified vulnerabilities are prioritised based on risk and impact, and patches are deployed according to a structured schedule, with critical updates applied promptly in line with Cyber Essentials Plus guidance.
Continuous monitoring, reporting, and review ensure vulnerabilities are addressed proactively, maintaining the security, integrity, and compliance of Invision360’s QA services while supporting ISO 27001-aligned practices. - Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
-
Invision360 implements a proactive protective monitoring strategy as part of our ISO 27001-aligned ISMS. Monitoring includes automated cloud-based alerts, logging, and intrusion detection, covering infrastructure, applications, and service activity. Thresholds and alerts are configured to detect anomalous or potentially malicious behaviour.
Upon identification of an incident, our structured incident response process is initiated promptly, following agreed procedures. Clients are informed and updated via email.
Protective monitoring complements our vulnerability management, Cyber Essentials Plus assessments, and periodic penetration testing, enabling timely detection, escalation, and mitigation of potential security threats while maintaining service availability and integrity. - Incident management type
- Supplier-defined controls
- Incident management approach
-
Invision360 maintains a structured incident management process to ensure timely resolution and communication. Pre-defined procedures exist for common events, including system outages, service disruptions, and performance issues.
Users report incidents via email which creates a ticket in our system. Tickets are assigned to the appropriate technical team for investigation, resolution, and testing. Once resolved, the ticket is updated with details of the actions taken.
Clients are informed of incident status throughout the process and receive formal incident reports via email summarising the issue, impact, resolution steps, and any follow-up actions. - Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Supplier-defined process
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- No
- Free trial available
- No
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 0%
- Between £500,001 and £1,000,000
- 0%
- Between £1,000,001 and £2,500,000
- 0%
- Between £2,500,001 and £5,000,000
- 0%
- Over £5,000,001
- 0%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- Yes
- Who accredited the ISO/IEC 27001
- Citation ISO
- ISO/IEC 27001 accreditation date
- Friday 28 March 2025
- What the ISO/IEC 27001 doesn’t cover
- Protection of secure areas, and physical security of office space is not applicable to Invision360 as a fully remote company and controls addressing these risks have been excluded from the measures taken. In addition, the company does not use outsourced developers to build its systems, so this is excluded from the controls taken.
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- No
- Quality management systems (QMS)
- No
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- 30297826-62ad-4b3b-a34f-f05a98c416d9
- Cyber essentials plus
- Yes
- Please provide your Cyber Essentials Plus Certificate Number
- 9d4db082-cc94-4d48-a829-bbd8a485a4fa
- Other security certifications
- No
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
- Plans to engage the contract workforce in deciding the most important workplace issues to address
- Ensuring new workers are informed of their right to join a trade union
- Monitoring of employee engagement rates (by protected characteristic) and, where necessary, the development of actions to ensure all voices are heard across the diversity of the workforce
- Employment contracts that reflect actual hours worked; steps taken to ensure employees understand their contracts and have the ability to review and adjust them if actual hours regularly exceed contracted hours
- Activities that support an environment where staff are educated about, and feel empowered to, address their physical wellbeing
- Activities that support an environment where staff are educated about and feel empowered to report and address bullying and harassment
- Activities to cascade good practice on fair working conditions throughout the supply chain
- Offer a pay and leave entitlement to all eligible staff who become kinship carers, ideally equivalent to statutory adoption pay and leave
- Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
- Monitoring and reporting of gender and ethnicity pay gaps and plans to address them where necessary
- Entitlement to sick pay for the contract workforce, with provision in place for any staff who do not meet the earnings threshold for statutory sick pay, payment of sick pay from day one of absence and payment of staff on the contract workforce who are off sick a replacement income of 100% of their usual earnings for as long as possible
- Plans for an appropriate income replacement policy for staff who are required to spend time away from work to care for a sick dependent or close relative
- Understanding of in-work progression issues affecting the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors
- Measures to support in-work progression to help people in the contract workforce, to move into higher paid work by developing new skills relevant to the contract
- Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
- Volunteering opportunities for staff
- Understanding of the modern slavery risks and issues affecting the market, industry, sector or country (of origin or of source) relevant to the contract, and the workforce in the supplier’s own organisation and those of its key subcontractors
- Measures to identify, mitigate and manage modern slavery risks relating to the contract and how these will be implemented
- Outline policies and practices to be applied to or put in place for the contract to mitigate and manage modern slavery risks, including: Pre-employment checks, recruitment practices. Workplace conditions, safeguarding plans and processes in place and regular monitoring with relevant groups considered, which may include sampling
- How to ensure business decisions re: price/cost, short lead times, payment timescales do not create modern slavery risks in the supply chain
- How the supplier will work with NGOs, trade unions or other businesses to address modern slavery risk
- Means of influencing staff, suppliers, customers, communities and/or any other appropriate stakeholders with respect to modern slavery risks relating to the contract
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.
- Understanding of employment and relevant skills issues, and of the education and training issues relating to the contract. Illustrative examples: demographics, skills shortages, new opportunities in high growth sectors, geographic/local community and skills/employment challenges
- Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
- Activities to support relevant sector related skills growth and sustainability in the contract workforce. Illustrative examples: careers talks, curriculum support, literacy support, safety talks and volunteering
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 3: Resilient, innovative and flexible supply chains: Support economic growth through enabling resilient businesses, opportunities for small businesses and voluntary, community and social enterprises
- Understanding of the types of businesses in the market and the level of participation by new businesses, entrepreneurs, start-ups, SMEs, VCSEs and mutuals
- Activities to identify opportunities to open up sub-contracts under the prime contract to a diverse range of businesses, including new businesses, entrepreneurs, start-ups, SMEs, VCSEs and mutuals
- Plans for engaging a diverse range of businesses in engagement activities prior to appointing subcontractors (including activities prior to award of the main contract and during the contract term)
- Activities that demonstrate a collaborative way to work with a diverse range of businesses as part of the supply chain
- Advertising of supply chain opportunities openly and to ensure they are accessible to a diverse range of businesses, including advertising all subcontracting opportunities on Contracts Finder
- Ensuring accessibility to contracting and subcontracting opportunities for disabled business owners and employees
- Structuring of the supply chain selection process to ensure fairness (e.g. anti-corruption) and encourages participation by a diverse range of businesses, including with regard to new businesses, entrepreneurs, start-ups, SMEs, VCSEs and mutual
- Understanding of local demographics, needs and opportunities for the co-design of the goods, services and works to be delivered under the contract
- Methods for engaging with different parts of the community (including the education system and charities representing the community) and how communities come together to inform decisions, strategy and projects to leave a positive legacy for future generations
- Measures to involve local stakeholders and/or users in design (e.g. in the design of services, systems, products or buildings)
- Plans for positive actions with community groups.
- Measures for making facilities used in the delivery of the contract available for community groups, education or training
- Measures to engage users and communities and build relationships to increase community integration build trust and influence how the contract is delivered
- Plans to respond flexibly and adapt approaches to community engagement and initiatives
- Support for community-led initiatives relevant to the contract. Illustrative examples: improving transport links; reducing loneliness; helping with English language proficiency; and facilitating social mixing among people with different backgrounds
- Collaborating with anchor institutions and community groups to make facilities available for education, training or community events
-
Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero
Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.
- Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
- Collaborative ways of working with the supply chain to deliver additional environmental benefits in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
- Understanding of how to influence staff, suppliers, customers, communities and/or any other appropriate stakeholders through the delivery of the contract to support climate and nature protection and improvement
-
Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain
Policy Outcome 6: Employment and training: For those who face barriers to employment
- Understanding of employment and skills issues, and of the skills and employment shortages of high growth sectors relating to the contract
- Creation of employment opportunities particularly for those who face barriers to employment, such as prison leavers, care leavers and/or who are located in deprived areas, and for people in industries with known skills shortages or in high growth sectors
- Understanding of the issues affecting the representation of disabled people in the workforce in the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors
- Collection of the views and expertise of disabled people and their representative organisations on successfully supporting disabled employees or applicants
- Inclusive and accessible recruitment practices, and retention-focused activities, including those provided in the Guide for line managers on recruiting, managing and developing people with a disability or health condition
- Introducing transparency to pay and reward processes
- Offering a range of quality opportunities with routes of progression if appropriate, e.g. T Level industry placements, students supported into higher level apprenticeships.
- Working conditions which promote an inclusive working environment and promote retention and progression
- Other measures to provide equality of opportunity for disabled people and those with health conditions into employment, including becoming a Disability Confident employer and inclusion of supported businesses in the contract supply chain
- Understanding of the issues affecting inequality in employment, skills and pay in the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors. Measures to tackle inequality in employment, skills and pay in the contract workforce
- Inclusive and accessible development practices, including guidance for line managers on recruiting, managing and developing people with a disability or health condition
-
Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain
Policy Outcome 7: Creating a pipeline of opportunities: For the contract workforce, reducing barriers to entry for under-represented groups.
- Understanding of the issues affecting the development of new skills by target cohort
- Understanding of the underlying factors affecting improvements to reduce barriers to entry and training schemes for the target cohort(s) related to the contract workforce
- Understanding of issues relating to entering the contract workforce
- Creation of outreach activities to create a pipeline of employees for the future contract delivery
- Content of the outreach activity is designed to suit the target cohort
- Advertising, promotional and outreach activities designed to raise awareness of the offer to reach the target cohort
-
Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.
Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.
- Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce
- Understanding barriers to access to health and social care services or employment opportunities e.g. digital inclusion
- Inclusive and accessible recruitment practices, development practices and retention policies that support-focused activities including those provided in the Guide for line managers on recruiting, managing and developing which support people with a disability or health condition
- Actions to invest in the physical and mental health and wellbeing of the contract workforce
-