FISCAL NXG Forensics P2P Risk Management - Supplier Risk Intelligence
Continuous supplier risk intelligence enabling finance teams to prevent payment errors at source, maintain audit-ready data, and support ECCTA compliance. Identifies duplicates and dormant suppliers, tracks critical field changes, and screens against credit, sanctions, and employee-link risks - delivering proactive risk protection, increased efficiency and oversight
Features
- Comprehensive duplicate supplier detection which manual review may miss
- Dormant supplier identification based on transaction history and inactivity
- Change tracking highlighting modifications to bank details and key fields
- Credit score monitoring through integration with external data providers
- Global sanctions and adverse media screening with regular updates
- Employee-supplier relationship detection identifying potential conflicts of interest
- Transaction pattern analysis including spend concentration and anomalies
- Bulk action workflows for efficient supplier file cleansing
- Configurable thresholds and rules matching organisational risk appetite
- Complete audit trail providing evidence for compliance requirements
Benefits
- Prevent payments to duplicate, dormant, or fraudulent suppliers
- Reduce manual supplier file maintenance effort significantly
- Pass audits with evidence of proactive supplier controls
- Support ECCTA Failure to Prevent Fraud compliance requirements
- Protect working capital from supplier data errors
- Early warning of supplier financial distress and sanctions exposure
- Detect potential fraud and conflicts of interest proactively
- Scale supplier oversight with existing team resource
- Continuous monitoring replacing periodic manual supplier reviews
- Free AP staff from reactive supplier data queries
Pricing
- Free trial available
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
3 8 1 9 7 1 3 3 2 0 7 0 4 8 4
Contact
FISCAL TECHNOLOGIES LTD
Stewart Hayward
Telephone: 08456801905
Email: smarter@fiscaltec.com
About your service
- Service categories
-
Applications
Enterprise resource management
Financial
- Financial and Accounting Applications
- Accounts Payable Applications
- Treasury and Risk Management Applications
- Multi cloud support
- No
Service scope
- Software add-on or extension
- No
- Cloud deployment model
- Public cloud
- Service constraints
- None
- System requirements
- Modern Web Browser (Chrome, Edge, Firefox)
User support
- Email or online ticketing support
- Yes
- Support response times
-
FISCAL's support teams initial response time service level objectives are:
Severity 1 - 1 business hour
Severity 2 - 2 business hours
Severity 3 - 4 business hours
Severity 4 - 1 business day - User can manage status and priority of support tickets
- Yes
- Online ticketing support accessibility
- WCAG 2.2 AA
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- No
- Onsite support
- No
- Support levels
-
We provide a single comprehensive support tier included with all subscriptions. Support is delivered by qualified engineers familiar with the platform.
Support Channels:
- Telephone and email during standard support hours (Monday-Friday, 08:30-17:30 UK time, excluding English bank holidays)
- 24/7/365 access to our online knowledge base for self-service guidance
- Interactive remote support for incident resolution
Incident Response Times:
Incidents are prioritised by business impact with defined response and resolution targets:
- Severity 1 (Service unavailable, no workaround): 1 business hour response, 4 business hour resolution target. Must be reported via telephone.
- Severity 2 (Major functionality affected or Severity 1 with workaround): 2 business hour response, 1 business day resolution target.
- Severity 3 (Minor functionality affected): 4 business hour response, 3 business day resolution target.
- Severity 4 (Questions, minor issues, documentation): 1 business day response, reasonable endeavours for resolution.
Dedicated customer success managers are aligned to customers as standard to provide basic support and guidance on using the product. - Support available to third parties
- Yes
Onboarding and offboarding
- Getting started
-
All customers have a dedicated implementation manager who will work with the customer on configuration and set-up, including generation of automated ERP extracts required by the platform and initial user-level configuration and hierarchy.
At the same time, the nominated Customer Success Manager aligned to the account will manage training, either onsite or online for all nominated users - training is recorded and available on demand and supported with detailed user documentation. Typically an overview session takes place prior to customer data being added, then follow-up user sessions on a regular basis during initial usage, at a cadence defined with the customer success manager.
Follow-up sessions are scheduled regularly to cover new features or to onboard new users - Service documentation
- Yes
- Documentation formats
- HTML
- End-of-contract data extraction
- The customer can export their data in a common format prior to contract termination via the reporting module and product export functions.
- End-of-contract process
- Upon termination, all of the customer data and backups are securely removed from the platform and associated Azure services within 30 days using custom scripts and Microsoft Azure security processes.
- Documentation accessibility standard
- WCAG 2.2 AA
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Opera
- Application to install
- No
- Designed for use on mobile devices
- No
- Service interface
- Yes
- User support accessibility
- WCAG 2.2 AA
- Description of service interface
- The platform is accessed via a web portal.
- Accessibility standards
- WCAG 2.2 AA
- Accessibility testing
-
Our interface testing with assistive technology users follows a structured, iterative approach through our Special Interest Groups (SIGs). These customer-led testing groups provide real-world validation of accessibility features before general release.
Our standard process involves three key stages:
Pre-Release Testing: SIG members representing diverse accessibility needs test beta releases using their own assistive technologies, including screen readers (JAWS, NVDA), voice recognition software, and alternative input devices. This provides authentic user experience feedback in actual operating environments.
Structured Feedback Collection: Participants complete standardised testing protocols covering keyboard navigation, screen reader compatibility, colour contrast effectiveness, and form interaction. We collect both quantitative metrics (task completion rates, error frequencies) and qualitative feedback on user experience barriers.
Iterative Refinement: Issues identified during SIG testing are categorised by severity and addressed prior to production release. Critical accessibility barriers trigger immediate remediation, whilst enhancement opportunities inform our development roadmap.
This approach has proven effective in identifying issues automated testing alone cannot detect, such as illogical tab order, unclear ARIA labels, or confusing screen reader output. Our SIG members provide ongoing validation that our WCAG 2.2 AA compliance translates into genuine usability for assistive technology users. - API
- Yes
- What users can and can't do using the API
-
FISCAL's platform supports automated uploading of data via an API.
Users setup an access token via the admin portal to connect to the API and can configure automated uploads following the attached guide: https://onboarding.apfnxg.com/uploads/why - API documentation
- Yes
- API documentation formats
- HTML
- API sandbox or test environment
- No
- Customisation available
- Yes
- Description of customisation
-
At organisation level, customers select which modules to enable: Suppliers, Transactions, Statement Reconciliation, Reporting, Sanctions Screening, ESG, and Credit Monitoring.
Site-wide settings include transaction workflows, invoice statuses, transaction categories, automated user assignment rules, supplier duplicate identification rules, credit monitoring thresholds, and supplier dormancy thresholds.
Individual users can personalise their date format preferences and default landing page.
How and who:
Module selection is configured during onboarding in consultation with FISCAL. Site-wide settings are managed through the application by customer administrators with appropriate permissions.
Scaling
- Independence of resources
-
FISCAL Technologies' platform leverages Microsoft Azure's elastic scalability. Traffic is distributed by Azure Load Balancers and filtered at the edge by Cloudflare WAF, providing DDoS protection before reaching the platform.
The architecture enforces logical tenant segmentation through separate SQL Server databases, separate Azure storage containers, and per-customer Solr collections, ensuring one customer's operations do not affect another.
Compute resources are managed through Azure Kubernetes Service with configured resource limits per service. Azure SQL Elastic Pools provide automatic database scaling. Continuous monitoring via Azure Application Insights enables proactive scaling before service degradation occurs.
Analytics
- Service usage metrics
- Yes
- Metrics types
-
FISCAL provides an inbuilt reporting module with analytics on service usage and value delivered. Examples of these would be:
Business Value Metrics:
- Values prevented, recovered, corrected, and dismissed
- Transaction and supplier volume and value
Usage Metrics:
- User activity including system logons
- User workflow reports
These reports enable customers to track the effectiveness of the solution, identify risks, monitor user adoption, and demonstrate return on investment. Reports can be accessed on-demand through the platform by users with appropriate permissions. - Reporting types
-
- Real-time dashboards
- Regular reports
- Reports on request
- Resource tagging
- No
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Other security clearance
- Government security clearance
- Security Clearance (SC)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
-
- United Kingdom
- European Economic Area (EEA)
- User control over data storage and processing locations
- Yes
- Datacentre security standards
- Complies with a recognised standard (for example CSA CCM version 4.0)
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- ‘IT Health Check’ performed by a CREST-approved service provider
- Protecting data at rest
-
- Physical access control, complying with CSA CCM v4.0
- Physical access control, complying with SSAE-18 / ISAE 3402
- Physical access control, complying with another standard
- Encryption of all physical media
- Other
- Other data at rest protection approach
-
Hosting on Microsoft Azure; Azure region(s) are agreed per customer.
All customer data at rest is encrypted using AES‑256 (databases, storage, logs, credentials, configuration data). SQL Servers and cloud assets are encrypted by default. - Data sanitisation process
- Yes
- Equipment disposal approach
- Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
- Data sanitisation type
-
- Deleted data can’t be directly accessed / Cryptographic Erasure
- Data Erasure
- Explicit overwriting of storage before reallocation / Secure Erase
- Physical Destruction / Hardware containing data is completely destroyed
Data importing and exporting
- Data export approach
-
The customer can export their data in a common formats via the reporting module and product export functions.
For more advanced requirements FISCAL offers advanced reporting module options to enable reporting and data extraction options. - Data export formats
-
- CSV
- Other
- Other data export formats
-
- Excel
- Images (PNG)
- Data import formats
-
- CSV
- Other
- Other data import formats
-
- JSON via the API
- XML via the API
- TSV
- TXT
- XLSX
Data-in-transit protection
- Data protection between buyer and supplier networks
- TLS (version 1.2 or above)
- Data protection within supplier network
-
- TLS (version 1.2 or above)
- IPsec or TLS VPN gateway
- Other
- Other protection within supplier network
- All data transmitted to or from the service is encrypted in transit using TLS 1.2 or higher. Internal service-to-service communications and external API integrations use TLS 1.2+. HTTPS is enforced for all web traffic and legacy/weak SSL/TLS versions are disabled. Certificate management is automated with regular renewals and HSTS is enabled to help prevent downgrade attacks. Services are hosted on Microsoft Azure and leverage Azure network and encryption controls. FISCAL Technologies operates under an ISO 27001-certified ISMS and holds Cyber Essentials accreditation.
Availability and resilience
- Guaranteed availability
- FISCAL aims for 99.5% availability, with historic performance figures available to support and updates communicated quarterly through the contract duration
- Approach to resilience
-
FISCAL leverages the resilience of Microsoft 's Azure platform using availability (Availability Zones/Regions) and site-level redundancy (see Microsoft Trust Center for detailed facility controls).
The application and data are deployed with logical redundancy and multi-region redundancies for customer data. Customer data stays within their selection geographic region, but can span several datacentres.
Backups are automated and encrypted with defined RTO/RPO and stored multi-regionally for resilience.
Edge protections include Cloudflare WAF and Microsoft load balancing to allow connectivity redundancies and reduce risk of service degradation. - Outage reporting
-
Status dashboard: Our support portal (Minerva) displays real-time service status using RAG indicators:
- Red: Full outage preventing multiple or all customers from accessing the product
- Amber: Issues impacting some elements or specific customers
- Green: No issues impacting customers
The support page provides detailed outage information including current investigation actions, resolution timelines, and confirmation when resolved.
Email alerts: Customers are notified via email of any critical outages or issues affecting their service, with regular updates throughout the incident until resolution.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Public key authentication (including by TLS client certificate)
- Identity federation with existing provider (for example Google Apps)
- Username or password
- Other
- Other user authentication
-
Users authenticate via Auth0 using username/password or Single Sign-On (SSO) integration with the customer's identity provider (Microsoft Entra ID, ADFS, Google, Okta, and others).
Password authentication enforces minimum 14 characters with complexity requirements. Auth0 provides brute force protection, breached password detection, and suspicious IP throttling.
SSO customers retain full control over their authentication policies including MFA requirements.
Sessions timeout after configurable inactivity periods (15 minutes to 1 hour) or maximum 12 hours.
Customer administrators manage user access through role-based access control (RBAC) within the platform. - Access restrictions in management interfaces and support channels
-
Management interfaces: FISCAL staff access backend infrastructure via Microsoft Entra ID with mandatory MFA and conditional access policies requiring device compliance. Privileged access uses Azure Privileged Identity Management (PIM) requiring peer review authorisation, MFA re-verification, and time-limited elevation. All privileged actions are audit logged.
Support channels: Support staff have no default access to customer environments. Access requires an open Zendesk ticket with customer authorisation, subject to the same Entra ID, MFA, conditional access, and device compliance controls. - Access restriction testing frequency
- At least once a year
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Public key authentication (including by TLS client certificate)
- Username or password
- Other
- Description of management access authentication
-
Management interfaces: FISCAL staff access backend infrastructure via Microsoft Entra ID with mandatory MFA and conditional access policies requiring device compliance. Privileged access uses Azure
Privileged Identity Management (PIM) requiring peer review authorisation, MFA re-verification, and time-limited elevation. All privileged actions are audit logged.
Support channels: Support staff have no default access to customer environments. Access requires an open Zendesk ticket with customer authorisation, subject to the same Entra ID, MFA, conditional access, and device compliance controls.
Audit information for users
- Access to user activity audit information
- Users receive audit information on a regular basis
- How long user audit data is stored for
- At least 12 months
- Access to supplier activity audit information
- Users have access to real-time audit information
- How long supplier audit data is stored for
- User-defined
- How long system logs are stored for
- At least 12 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
-
- ISO/IEC 27001
- Other
- Other security governance standards
- Cyber Essentials
- Information security policies and processes
-
FISCAL maintains a comprehensive ISMS and is ISO 27001 accredited and Cyber Essentials certified.
Policies & processes
Core Information Security Policy supported by topic-specific policies (access control, cryptography, acceptable use, data protection, incident management, etc.).
Policies are version-controlled, published in the ISMS platform and follow the Policy Governance process.
Policies are reviewed annually by the Director of IT & Security and approved by the Senior Leadership Team.
Changes are communicated via mandatory read, awareness training, onboarding, and email notifications.
Security is embedded in delivery through a DevSecOps approach and secure development responsibilities are assigned to development leads and architects.
Reporting & governance
Information Security Forum (ISF) meets quarterly to review risks, incidents, policies and ISMS improvements.
CISO / Director of IT & Security and TISO are responsible for the information security programme.
Reporting structure:
- Director of IT & Security (CISO) reports to executive leadership
- Chief Technology & Product Officer (CTPO) works closely with CISO on product security
- IT Team reports to the Director of IT
- Development Leads report to the CTPO
- Chief Software Architect responsible for secure design - Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Configuration and change management approach
-
All infrastructure and application configurations are defined as code and stored in version control, providing a complete audit trail of every change throughout the service lifecycle.
Every change follows a formal review process: changes must be linked to a tracked work item, pass automated, performance, code quality, SAST and DAST, and be approved by a peer reviewer. Reviewers assess potential security impact including customer impact, data protection, secure communications, stability, and risks from third-party components.
Production releases require sign-off from senior engineers at release readiness meetings. Automated pipelines deploy changes, with Terraform plans reviewed before applying to production. - Vulnerability management type
- Supplier-defined controls
- Vulnerability management approach
-
We assess threats through continuous automated scanning:
Dependency vulnerability scanning identifies risks in third-party components.
Code quality, SAST, and DAST scanning detects weaknesses in our code, secure configuration and running environment.
Web application scanning detects security weaknesses in our live services.
Vulnerabilities are scored using industry-standard CVSS ratings.
Patch deployment targets are based on severity: critical and high vulnerabilities within 2 weeks, medium within 4-8 weeks, and low within 3-6 months. Critical security fixes are deployed via emergency release processes.
Threat information is gathered from vulnerability databases integrated with our scanning tools, UK-NCSC, US-CISA, and vendor security advisories and recommendations. - Protective monitoring type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Protective monitoring approach
-
Potential compromises are identified through real-time monitoring of our platform using Azure Defender, Application Insights and Prometheus, with automated alerts configured for anomalous behaviour, security events, and system faults. Staff report suspected incidents immediately via our helpdesk.
When a potential compromise is detected, incidents are classified by security impact (confidentiality, integrity, availability) and assigned priority levels. Critical incidents trigger immediate response with dedicated resources and a live incident channel. High-priority incidents are addressed before all others.
For incidents affecting customer data, we notify affected customers within 24 hours with details of scope, impact, and remediation measures. - Incident management type
- Complies with a recognised standard, for example, CSA CCM v4.0 or ISO/IEC 27035:2011 or SSAE-18 / ISAE 3402
- Incident management approach
-
We maintain documented incident management procedures with pre-defined processes for common security events including service disruption, access violations, system faults, and data breaches. Incidents are classified by impact (confidentiality, integrity, availability) and prioritised as Critical, High, Medium, or Low.
Users report incidents via our helpdesk, with product-related incidents tracked in our development management system. Critical and high-priority incidents trigger immediate escalation to senior management.
For incidents affecting customer data, we notify affected customers within 24 hours with details of scope, impact, and remediation measures. Post-incident reports document root cause analysis and corrective actions. - Post-quantum cryptography secure
- Yes
Secure development
- Approach to secure software development best practice
- Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- No
- Free trial available
- Yes
- Description of free trial
- We offer a free 'proof of value' - the customer provides AP data and we create a snapshot of current/historical AP risk exposure using the same preventative risk management approach that underpins the FISCAL software. We can show the results produced by the software without integration or obligation
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 25%
- Between £500,001 and £1,000,000
- 40%
- Between £1,000,001 and £2,500,000
- 60%
- Between £2,500,001 and £5,000,000
- 70%
- Over £5,000,001
- 80%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- Yes
- Who accredited the ISO/IEC 27001
- British Assessment Bureau
- ISO/IEC 27001 accreditation date
- Monday 2 February 2015
- What the ISO/IEC 27001 doesn’t cover
- There are not any exempt areas of the standard. All controls are in scope.
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- No
- Quality management systems (QMS)
- No
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- Ae2ef55a-c845-4abb-a957-06e911aa4c7c
- Cyber essentials plus
- No
- Cyber Essentials Alternative
- You do not have a current and valid Cyber Essentials Plus certificate, or will not have in place within 12 months of the date of award but have an IASME certified equivalent.
- Other security certifications
- No
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.
- Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
-
Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero
Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.
- Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
- Delivery of additional environmental benefits through the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
-