Community Resilience Hub App (CRHA)
Community Resilience Hub is an offline-capable coordination platform enabling local communities to self-organise during emergencies. It maintains registers of skills, equipment, and vulnerable residents, coordinates volunteer response, and feeds situational awareness to Category 1 and 2 responders. Designed for councils and parishes, it strengthens local resilience while complementing statutory response.
Features
- Full offline functionality when power and networks fail
- Register community skills, equipment and vulnerable residents
- iOS and Android apps with offline data synchronisation
- Assign volunteer roles and track task completion
- Welfare check tracking with traffic light status
- Offline maps showing critical locations and infrastructure
- Mutual aid networking between neighbouring communities
- Complete audit trail of all incidents and actions
- Structured debrief facility captures lessons learned
- Situation reports feed to Category 1 and 2 responders
Benefits
- Communities coordinate effectively when infrastructure fails
- Vulnerable residents identified and checked systematically
- Volunteers deployed with clear roles and responsibilities
- Reduce pressure on emergency services during incidents
- Single version of truth for community situational awareness
- Standardised framework enables scaling across councils
- Local ownership with consistent operating model
- Annual registration reviews maintain data accuracy
- Exercise mode enables realistic training without live data
- Bottom-up intelligence complements formal response arrangements
Pricing
- Education pricing available
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
3 7 5 3 4 6 8 7 7 7 3 7 1 5 4
Contact
FullyCoded
Mark Grice
Telephone: 01326 536077
Email: mark@fullycoded.com
About your service
- Service categories
-
Applications
Collaborative
- Team collaboration
- Multi cloud support
- No
Service scope
- Software add-on or extension
- No
- Cloud deployment model
- Public cloud
- Service constraints
- Community Resilience Hub is designed for offline operation during emergencies. However, an internet connection is required to download the offline data pack and synchronise updates when connectivity returns. Mobile applications require iOS 14 or later, or Android 10 or later. The web portal is optimised for modern browsers including Google Chrome, Microsoft Edge, Apple Safari, and Mozilla Firefox; latest versions are recommended. Scheduled maintenance occurs monthly during off-peak hours with 48 hours advance notification. Offline maps require sufficient device storage for local area data. Administrative functions including user management and configuration are available through the web portal only.
- System requirements
-
- Mobile devices iOS 13+ or Android 10+ for mobile app.
- Internet connectivity, Active internet connection required for real-time synchronisation
- Chrome, Edge, Safari, or Firefox for web dashboard
- Email accesss
- Device notification permissions required for real-time alerts
- PDF reader required for exported compliance reports
- Camera access – Device camera permission for asset barcode scanning.
User support
- Email or online ticketing support
- Yes
- Support response times
- Tickets are responded to within 12 hours, including weekends and public holidays.
- User can manage status and priority of support tickets
- Yes
- Online ticketing support accessibility
- WCAG 2.2 A
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- No
- Onsite support
- Yes, at extra cost
- Support levels
-
Standard Support (included)
Standard support is included with all Community Resilience Hub subscriptions at no additional cost. This provides email and web-based support seven days a week, including bank holidays. Response times are within 24 hours for general enquiries and within 4 hours for critical issues affecting service availability. Standard support includes access to our online knowledge base, user documentation, and video tutorials.
Enhanced Support (additional)
Enhanced support is available for councils and communities requiring telephone assistance. This tier includes telephone support during UK business hours (Monday to Friday, 9am to 5pm) in addition to standard email and web-based support. Enhanced support also includes priority handling for critical issues, onboarding assistance for new communities, configuration guidance during initial setup, and annual review sessions. Enhanced support is priced at 15% of the annual subscription value.
Emergency Support (additional)
Emergency support is available for organisations requiring 24/7 assistance during declared emergencies. This tier provides telephone support for critical platform issues when communities are responding to live incidents.
Emergency support is priced at 25% of the annual subscription value and includes Enhanced Support benefits.
A dedicated account manager is assigned to all Enhanced and Emergency support customers to provide continuity and strategic guidance. - Support available to third parties
- Yes
Onboarding and offboarding
- Getting started
-
Onboarding process
We provide a structured onboarding process to ensure communities are operational quickly. Upon subscription, customers receive a dedicated onboarding session via video call to configure their tenant, establish community boundaries, define skill and equipment categories, and set up volunteer roles. This guided setup typically takes one to two hours. We then support the community registration drive with template communications. Onsite setup is available upon request.
Training
Online training is provided for coordinators and volunteers. Coordinator training covers registration management, incident logging, volunteer coordination, welfare check procedures, offline operations, and reporting. Volunteer training focuses on the mobile app, understanding assigned roles, and completing tasks. Training is delivered via live video sessions and recorded tutorials accessible on demand. Onsite training is available at additional cost.
Documentation
Comprehensive user documentation is available through our online knowledge base. This includes step-by-step setup guides, video tutorials, frequently asked questions, and best practice recommendations. Quick-start guides are available as downloadable PDFs for distribution to volunteers. Documentation is maintained and updated with each release.
Ongoing support
Following onboarding, customers have continued access to our support team. We provide regular updates on new features and offer refresher training as required. - Service documentation
- Yes
- Documentation formats
-
- HTML
- End-of-contract data extraction
-
Data export options
At contract end, customers can extract all their data through multiple methods. The web dashboard provides built-in export functionality allowing administrators to download complete datasets including resident registers, incident histories, debrief records, and audit trails. Data is exported in standard formats including CSV, Excel, and JSON for easy migration or archival purposes.
API extraction
Customers with API access can programmatically extract all data during the contract notice period. The API provides endpoints for retrieving complete records across all data types, enabling automated migration to replacement systems.
Assisted extraction
Upon request, our team can provide a complete data export package containing all community data in structured formats. This service is provided at no additional cost during the contract termination period.
Data retention
Following contract termination, customer data is retained for 60 days to allow for any additional extraction requirements. After this period, all data is securely deleted from our systems in accordance with our data protection policies. Customers receive written confirmation of data deletion upon request.
Formats provided
Exported data is provided in non-proprietary formats to ensure accessibility regardless of future system choices. - End-of-contract process
-
End-of-contract process
Prior to contract end, we provide written notification and offer the opportunity to renew. During the notice period, administrators retain full access to export all community data through the web dashboard or API. Our support team is available to assist with data extraction requirements at no additional cost.
Upon contract termination, user access to the mobile app and web portal is disabled. Data is retained securely for 60 days following termination to allow for any final extraction requests. After this retention period, all customer data is permanently and securely deleted from our systems. Written confirmation of data deletion is provided upon request.
Included in contract price
The contract price includes full platform access with unlimited resident registrations, up to 10 coordinator accounts, unlimited volunteer accounts, iOS and Android applications, offline data pack functionality, standard support with 24-hour response times, access to all features and updates released during the contract period, online training materials, initial onboarding session, and data export at contract end.
Additional costs
Additional costs may apply for enhanced telephone support, emergency 24/7 support, onsite setup or training, additional coordinator accounts, bespoke development requests, local authority multi-community dashboards, and custom API integrations. - Documentation accessibility standard
- WCAG 2.2 AA
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Opera
- Other
- Application to install
- Yes
- Compatible operating systems
-
- Android
- IOS
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
-
Community Resilience Hub provides native iOS and Android applications with full offline functionality. Volunteers and coordinators can view registers, log incidents, assign tasks, complete welfare checks, and access offline maps without internet connectivity. Push notifications alert coordinators to hub activation requests and mutual aid enquiries when online.
The web portal provides additional administrative functionality not available on mobile, including user management, community configuration, multi-hub oversight, compliance reporting, and bulk data exports. The web portal is suited to desktop use for preparedness activities, while mobile apps are optimised for rapid response during live incidents.
Both platforms synchronise automatically when connectivity returns. - Service interface
- Yes
- User support accessibility
- WCAG 2.2 AA
- Description of service interface
- Community Resilience Hub provides three service interfaces. The mobile applications for iOS and Android enable volunteers and coordinators to view registers, log incidents, assign tasks, complete welfare checks, and access offline maps with full offline functionality. The web-based administration portal allows community administrators to configure settings, manage users, define volunteer roles, generate reports, and conduct debriefs. The public registration portal enables residents to self-register their skills, equipment, and support needs without downloading an application. All interfaces feature intuitive navigation, high-contrast options for accessibility, and large clear buttons designed for use during stressful situations. The interfaces synchronise automatically when connectivity returns.
- Accessibility standards
- WCAG 2.2 AA
- Accessibility testing
- We have conducted accessibility testing throughout the development lifecycle to ensure Community Resilience Hub is usable by people with assistive technology. Testing has included keyboard-only navigation to verify all functions are accessible without a mouse, and screen reader compatibility testing using JAWS, NVDA, and VoiceOver on both web and mobile platforms. We have verified that all interactive elements have appropriate ARIA labels, colour contrast meets WCAG 2.1 AA standards, and focus states are clearly visible. A high-contrast mode with enlarged text is available for users with visual impairments. User testing sessions have been conducted with participants using screen magnification software. We continue to gather feedback and address accessibility improvements in each release cycle.
- API
- Yes
- What users can and can't do using the API
-
The Community Resilience Hub API enables councils and communities to integrate emergency coordination data into existing systems and workflows. Users can retrieve register data, incident logs, welfare check status, and situation reports programmatically. The API supports creating and updating resident records, managing volunteer assignments, and exporting debrief data. Organisations can use the API to synchronise data with local authority systems, automate reporting to Local Resilience Forums, and export compliance reports for external tools.
Certain administrative functions are restricted to the web dashboard for security purposes. These include tenant configuration, role-based access control setup, user management, and API key management. Users cannot delete audit trail records via the API to maintain data integrity for governance requirements. Access to vulnerable resident data requires elevated permissions and is logged for safeguarding compliance.
API access is available on request and subject to rate limiting of 500 requests per hour per token. Initial community setup and configuration must be completed via the web dashboard before API integration. Webhook endpoints enable real-time notifications of hub activations and mutual aid requests. API documentation and sandbox environments are provided for development and testing purposes. - API documentation
- Yes
- API documentation formats
- Open API (also known as Swagger)
- API sandbox or test environment
- Yes
- Customisation available
- Yes
- Description of customisation
-
Community Resilience Hub offers extensive customisation to meet local requirements. Communities can define their own skill and equipment categories, create custom vulnerability types, and configure volunteer roles with specific responsibilities. Standard operating procedures can be tailored to local geography, risks, and infrastructure. Custom fields allow communities to capture additional data specific to their needs, such as grid references, access codes, or medical equipment details. Hub activation triggers, welfare check schedules, debrief templates, and reporting parameters can all be tailored. Branding elements including community logo and name are displayed throughout the interface.
All customisation is performed through the web-based administration portal. Administrators use intuitive forms and configuration screens to define categories, set procedures, and adjust settings. Changes take effect immediately and synchronise to all users when connectivity is available. Pre-configured templates are available for different community types including rural parishes, coastal communities, and urban neighbourhoods, providing appropriate defaults while remaining fully customisable.
Customisation access is controlled through role-based permissions. Community administrators have full access to all configuration options. Hub coordinators can be granted limited customisation rights, such as updating key contacts or incident procedures. Volunteers cannot access configuration settings, ensuring system integrity and governance controls are maintained.
Scaling
- Independence of resources
-
Multi-tenant architecture
Community Resilience Hub uses a multi-tenant architecture with logical data separation between communities. Each tenant's data is isolated, ensuring no organisation can access another's information.
Resource management
Our infrastructure scales automatically based on demand. Load balancing distributes traffic across multiple servers, preventing any single community's usage from impacting others.
Rate limiting
API rate limits are applied per organisation to prevent any single tenant from consuming excessive resources, ensuring fair access for all customers.
Performance monitoring
Continuously monitoring system performance and resources. Automatic scaling provisions additional capacity during peak demand. Performance thresholds trigger alerts, enabling proactive intervention before degradation.
Analytics
- Service usage metrics
- Yes
- Metrics types
- Community Resilience Hub provides comprehensive service metrics including registered volunteer counts, vulnerable resident numbers, and registration completion rates. Incident metrics show response times, welfare check completion rates, checkpoint completions, and volunteer deployment statistics. Coordinators can view task assignment statistics, issue resolution times, and resource utilisation. Platform metrics track sync frequency, offline usage patterns, and mobile application adoption. Debrief completion rates and lessons learned are tracked to support continuous improvement. All metrics can be filtered by date range, community, incident type, and volunteer groups.
- Reporting types
-
- Real-time dashboards
- Reports on request
- Resource tagging
- No
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Other security clearance
- Government security clearance
- Security Clearance (SC)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- United Kingdom
- User control over data storage and processing locations
- Yes
- Datacentre security standards
- Complies with a recognised standard (for example CSA CCM version 4.0)
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- ‘IT Health Check’ performed by a CREST-approved service provider
- Protecting data at rest
-
- Physical access control, complying with SSAE-18 / ISAE 3402
- Encryption of all physical media
- Data sanitisation process
- Yes
- Equipment disposal approach
- Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
- Data sanitisation type
-
- Deleted data can’t be directly accessed / Cryptographic Erasure
- Data Erasure
Data importing and exporting
- Data export approach
- Administrators can export data directly through the web dashboard at any time during the contract. Built-in export functionality allows download of users, equipment, assignments, compliance histories, and audit trails in CSV and PDF formats. Customers with API access can extract data programmatically using standard endpoints. At contract end, our support team can provide a complete data package upon request at no additional cost. All exports use non-proprietary formats ensuring data remains accessible regardless of future system choices.
- Data export formats
- CSV
- Data import formats
- CSV
Data-in-transit protection
- Data protection between buyer and supplier networks
- TLS (version 1.2 or above)
- Data protection within supplier network
- TLS (version 1.2 or above)
Availability and resilience
- Guaranteed availability
-
Availability guarantee
Community Resilience Hub guarantees 99.9% service availability, measured monthly excluding scheduled maintenance windows. Scheduled maintenance is performed during low-usage periods with a minimum of 48 hours advance notification. The offline capability ensures communities can continue operations even during platform unavailability.
Service level agreement
Our SLA defines availability as the ability for authenticated users to access core platform functionality including the mobile app and web portal. Availability is monitored continuously and measured as a percentage of total minutes in each calendar month. Offline functionality is excluded as it operates independently.
Service credits
If availability falls below guaranteed levels, customers are entitled to service credits applied to future invoices. For availability between 99.0% and 99.9%, a credit of 10% of the monthly fee applies. For availability between 95.0% and 99.0%, a credit of 25% applies. For availability below 95.0%, a credit of 50% applies.
Claiming credits
Customers must submit credit requests within 30 days of the affected month. Credits are capped at 50% of the monthly subscription fee and do not apply where unavailability results from factors outside our control, scheduled maintenance, or customer-side issues. - Approach to resilience
-
Infrastructure resilience
Community Resilience Hub is hosted on UK cloud infrastructure, leveraging multiple availability zones. This ensures continued service operation if an individual datacentre experiences failure. Data is automatically replicated across availability zones, providing redundancy and rapid failover capability.
Database resilience
Databases are configured with automated backups and point-in-time recovery. Backups are stored in geographically separate UK locations from primary data. Database replication ensures data durability and enables quick restoration in the event of failure.
Application resilience
The application layer uses load balancing to distribute traffic across multiple servers. Auto-scaling provisions additional capacity during demand spikes. Health monitoring automatically removes unhealthy instances and replaces them without manual intervention.
Offline resilience
The offline-first architecture ensures communities can operate independently of cloud infrastructure. Complete data packs on local devices enable full functionality during connectivity outages.
Disaster recovery
A documented disaster recovery plan is maintained and tested annually. Recovery time objective is 4 hours and recovery point objective is 1 hour. Full details are available on request.
Monitoring
Continuous monitoring tracks system health, performance, and availability. Automated alerts enable proactive response before service impact occurs. - Outage reporting
-
Email alerts
Customers are notified of any service outages via email. Alerts are sent to designated administrators when incidents are identified, with follow-up notifications providing status updates and resolution confirmation.
Scheduled maintenance
Planned maintenance windows are communicated via email a minimum of 48 hours in advance, including expected duration and any anticipated impact.
Incident communication
During outages, we provide regular updates until the issue is resolved. Following resolution, customers receive a summary of the incident including root cause and preventative measures implemented.
Status page
A public status page is planned for a future release, providing real-time visibility of service availability and historical uptime data.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Identity federation with existing provider (for example Google Apps)
- Username or password
- Access restrictions in management interfaces and support channels
-
Management interfaces
Access to management interfaces is restricted through role-based access controls. Only authorised administrators can access system configuration and user management. Administrative access requires MFA. All actions are logged for audit purposes.
Support channels
Support staff access customer data only when required to resolve issues. Access is logged and granted on a least-privilege basis. Customer identity is verified before discussing account matters.
Internal systems
Access to infrastructure is restricted to authorised personnel. Credentials are managed securely with regular rotation. Access reviews ensure appropriate permissions. - Access restriction testing frequency
- At least once a year
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Identity federation with existing provider (for example Google Apps)
- Username or password
Audit information for users
- Access to user activity audit information
- Users have access to real-time audit information
- How long user audit data is stored for
- User-defined
- Access to supplier activity audit information
- Users contact the support team to get audit information
- How long supplier audit data is stored for
- User-defined
- How long system logs are stored for
- User-defined
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- No
- Security governance approach
- Security governance is embedded throughout our organisation. We maintain documented security policies covering access control, data protection, incident response, and secure development practices. Regular risk assessments identify and address potential vulnerabilities. All staff complete security awareness training annually. Code reviews and security testing are integrated into our development lifecycle. Third-party penetration testing is conducted annually by a CREST-approved provider. We monitor emerging threats and update our practices accordingly. Our approach aligns with industry frameworks including ISO 27001, NCSC guidance, and Cyber Essentials principles, with formal certification planned.
- Information security policies and processes
-
Security policies
We maintain comprehensive information security policies covering data classification, access control, acceptable use, incident response, business continuity, and secure development. Policies are reviewed annually and updated in response to emerging threats or organisational changes. All policies align with ISO 27001 framework principles and NCSC guidance.
Reporting structure
Security responsibility sits at senior management level, with clear accountability for information security decisions. Security matters are reported to leadership regularly, ensuring visibility and appropriate resource allocation for security initiatives.
Staff responsibilities
All staff receive security awareness training during onboarding and annually thereafter. Staff are required to acknowledge and comply with security policies as a condition of employment. Role-specific training is provided for those handling sensitive data or system administration.
Compliance monitoring
Policy compliance is monitored through regular internal reviews and audits. Access logs are reviewed to identify unusual activity. Non-compliance is addressed through documented procedures and escalated where necessary.
Incident management
A documented incident response process ensures security events are identified, contained, and resolved promptly. Incidents are logged, investigated, and reviewed to identify improvements. Significant incidents are reported to senior management and affected customers where appropriate. - Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
-
Configuration management
All system components are tracked through centralised configuration management. Infrastructure is defined as code, ensuring consistent deployments. Version control maintains complete history of changes.
Change management process
Changes follow a documented process, categorised by risk level. Standard changes follow pre-approved procedures, while significant changes require approval.
Security impact assessment
Changes are assessed for security impact before approval, including access control implications. Security-relevant changes undergo additional review.
Testing and deployment
Changes are tested in staging environments before production. Deployments use controlled release processes with rollback capability.
Audit trail
All changes are logged with timestamps and approval records. - Vulnerability management type
- Supplier-defined controls
- Vulnerability management approach
-
Threat assessment
We conduct regular vulnerability assessments using automated scanning tools. Annual penetration testing by a CREST-approved provider identifies potential weaknesses. Risk assessments evaluate severity and impact of identified vulnerabilities.
Patch management
Critical security patches are deployed within 24 hours. High-severity patches are deployed within 7 days. All patches are tested before production deployment.
Threat intelligence
We monitor NCSC advisories, AWS security bulletins, CVE databases, and vendor security notifications for emerging threats.
Remediation tracking
Vulnerabilities are logged and tracked through to resolution, prioritised by severity and exploitability. - Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
-
Identifying compromises
Continuous monitoring tracks system activity, access patterns, and security events. Automated alerts flag anomalous behaviour including unusual login attempts, privilege escalation, and unexpected data access. Log aggregation enables correlation of events across systems.
Incident response
Potential compromises trigger our documented incident response process. Events are triaged, contained, and investigated promptly. Affected systems are isolated to prevent further impact.
Response times
Critical security incidents are responded to within one hour. Investigation findings and remediation actions are documented. Affected customers are notified where appropriate. Post-incident reviews identify preventative improvements. - Incident management type
- Supplier-defined controls
- Incident management approach
-
Pre-defined processes
We maintain documented incident management procedures for common events including service outages, security breaches, and data incidents. Runbooks provide step-by-step guidance. Incidents are categorised by severity to determine response priority and escalation.
Reporting incidents
Users report incidents via email. Reports are acknowledged within 12 hours and logged in our tracking system. Critical issues can be escalated through enhanced support telephone lines.
Incident reports
Customers receive incident reports detailing timeline, root cause, impact, and corrective actions. Reports are provided within 5 working days of resolution. - Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Conforms to a recognised standard, but self-assessed
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- Yes
- Free trial available
- No
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 5%
- Between £500,001 and £1,000,000
- 6%
- Between £1,000,001 and £2,500,000
- 10%
- Between £2,500,001 and £5,000,000
- 12%
- Over £5,000,001
- 15%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- No
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- No
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- 434ca00e-da12-4a61-8cac-a93339528c02
- Cyber essentials plus
- No
- Cyber Essentials Alternative
- You do not have a current and valid Cyber Essentials Plus certificate, or will not have in place within 12 months of the date of award but have an IASME certified equivalent.
- Other security certifications
- No
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- New or retained jobs on the contract workforce in the relevant area that meet the criteria set out in MAC 1b, 1c and 1d
- Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
- Plans to engage the contract workforce in deciding the most important workplace issues to address
- Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
- Monitoring and reporting of gender and ethnicity pay gaps and plans to address them where necessary
- Entitlement to sick pay for the contract workforce, with provision in place for any staff who do not meet the earnings threshold for statutory sick pay, payment of sick pay from day one of absence and payment of staff on the contract workforce who are off sick a replacement income of 100% of their usual earnings for as long as possible
- Plans for an appropriate income replacement policy for staff who are required to spend time away from work to care for a sick dependent or close relative
- Understanding of in-work progression issues affecting the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors
- Measures to support in-work progression to help people in the contract workforce, to move into higher paid work by developing new skills relevant to the contract
- Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
- Volunteering opportunities for staff
- Understanding of the modern slavery risks and issues affecting the market, industry, sector or country (of origin or of source) relevant to the contract, and the workforce in the supplier’s own organisation and those of its key subcontractors
- Measures to identify, mitigate and manage modern slavery risks relating to the contract and how these will be implemented
- Outline policies and practices to be applied to or put in place for the contract to mitigate and manage modern slavery risks, including: Pre-employment checks, recruitment practices. Workplace conditions, safeguarding plans and processes in place and regular monitoring with relevant groups considered, which may include sampling
- How these flow down the supply chain and are monitored Illustrative examples include reporting, site visits, audits, etc.
- How to ensure business decisions re: price/cost, short lead times, payment timescales do not create modern slavery risks in the supply chain
- How the supplier will work with NGOs, trade unions or other businesses to address modern slavery risk
- Means of influencing staff, suppliers, customers, communities and/or any other appropriate stakeholders with respect to modern slavery risks relating to the contract
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.
- Understanding of employment and relevant skills issues, and of the education and training issues relating to the contract. Illustrative examples: demographics, skills shortages, new opportunities in high growth sectors, geographic/local community and skills/employment challenges
- Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
- Activities to support relevant sector related skills growth and sustainability in the contract workforce. Illustrative examples: careers talks, curriculum support, literacy support, safety talks and volunteering
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 3: Resilient, innovative and flexible supply chains: Support economic growth through enabling resilient businesses, opportunities for small businesses and voluntary, community and social enterprises
- Understanding of the types of businesses in the market and the level of participation by new businesses, entrepreneurs, start-ups, SMEs, VCSEs and mutuals
- Activities to identify opportunities to open up sub-contracts under the prime contract to a diverse range of businesses, including new businesses, entrepreneurs, start-ups, SMEs, VCSEs and mutuals
- Plans for engaging a diverse range of businesses in engagement activities prior to appointing subcontractors (including activities prior to award of the main contract and during the contract term)
- Activities that demonstrate a collaborative way to work with a diverse range of businesses as part of the supply chain
- Advertising of supply chain opportunities openly and to ensure they are accessible to a diverse range of businesses, including advertising all subcontracting opportunities on Contracts Finder
- Ensuring accessibility to contracting and subcontracting opportunities for disabled business owners and employees
- Understanding of local demographics, needs and opportunities for the co-design of the goods, services and works to be delivered under the contract
- Methods for engaging with different parts of the community (including the education system and charities representing the community) and how communities come together to inform decisions, strategy and projects to leave a positive legacy for future generations
- Measures to involve local stakeholders and/or users in design (e.g. in the design of services, systems, products or buildings)
- Plans for positive actions with community groups.
- Measures for making facilities used in the delivery of the contract available for community groups, education or training
- Measures to engage users and communities and build relationships to increase community integration build trust and influence how the contract is delivered
- Plans to respond flexibly and adapt approaches to community engagement and initiatives
- Support for community-led initiatives relevant to the contract. Illustrative examples: improving transport links; reducing loneliness; helping with English language proficiency; and facilitating social mixing among people with different backgrounds
- Collaborating with anchor institutions and community groups to make facilities available for education, training or community events
-
Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero
Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.
- Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
- Collaborative ways of working with the supply chain to deliver additional environmental benefits in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
- Delivery of additional environmental benefits through the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
- Understanding of how to influence staff, suppliers, customers, communities and/or any other appropriate stakeholders through the delivery of the contract to support climate and nature protection and improvement
- Activities to reconnect people with the environment and increase awareness of ways to protect and enhance it
-
Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain
Policy Outcome 7: Creating a pipeline of opportunities: For the contract workforce, reducing barriers to entry for under-represented groups.
- Understanding of the issues affecting the development of new skills by target cohort
- Understanding of the underlying factors affecting improvements to reduce barriers to entry and training schemes for the target cohort(s) related to the contract workforce
- Other measures to offer development opportunities for the target cohort(s) in the contract workforce
- Advertising, promotional and outreach activities designed to raise awareness of the offer to reach the target cohort
- Understanding of issues relating to entering the contract workforce
- Creation of outreach activities to create a pipeline of employees for the future contract delivery
- Content of the outreach activity is designed to suit the target cohort
- Advertising, promotional and outreach activities designed to raise awareness of the offer to reach the target cohort
-
Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.
Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.
- Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce
- Understanding barriers to access to health and social care services or employment opportunities e.g. digital inclusion
- Inclusive and accessible recruitment practices, development practices and retention policies that support-focused activities including those provided in the Guide for line managers on recruiting, managing and developing which support people with a disability or health condition
- Actions to invest in the physical and mental health and wellbeing of the contract workforce
-