Skip to main content

Help us improve the Digital Marketplace - send your feedback

FISCAL TECHNOLOGIES LTD

FISCAL NXG Forensics P2P Risk Management - Supplier Risk Intelligence

Continuous supplier risk intelligence enabling finance teams to prevent payment errors at source, maintain audit-ready data, and support ECCTA compliance. Identifies duplicates and dormant suppliers, tracks critical field changes, and screens against credit, sanctions, and employee-link risks - delivering proactive risk protection, increased efficiency and oversight

Features

  • Comprehensive duplicate supplier detection which manual review may miss
  • Dormant supplier identification based on transaction history and inactivity
  • Change tracking highlighting modifications to bank details and key fields
  • Credit score monitoring through integration with external data providers
  • Global sanctions and adverse media screening with regular updates
  • Employee-supplier relationship detection identifying potential conflicts of interest
  • Transaction pattern analysis including spend concentration and anomalies
  • Bulk action workflows for efficient supplier file cleansing
  • Configurable thresholds and rules matching organisational risk appetite
  • Complete audit trail providing evidence for compliance requirements

Benefits

  • Prevent payments to duplicate, dormant, or fraudulent suppliers
  • Reduce manual supplier file maintenance effort significantly
  • Pass audits with evidence of proactive supplier controls
  • Support ECCTA Failure to Prevent Fraud compliance requirements
  • Protect working capital from supplier data errors
  • Early warning of supplier financial distress and sanctions exposure
  • Detect potential fraud and conflicts of interest proactively
  • Scale supplier oversight with existing team resource
  • Continuous monitoring replacing periodic manual supplier reviews
  • Free AP staff from reactive supplier data queries

Pricing

  • Free trial available

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at smarter@fiscaltec.com. Tell them what format you need. It will help if you say what assistive technology you use.

Framework

G-Cloud 15

Service ID

3 8 1 9 7 1 3 3 2 0 7 0 4 8 4

Contact

FISCAL TECHNOLOGIES LTD Stewart Hayward
Telephone: 08456801905
Email: smarter@fiscaltec.com

About your service

Service categories

Applications

Enterprise resource management

Financial

  • Financial and Accounting Applications
  • Accounts Payable Applications
  • Treasury and Risk Management Applications
Multi cloud support
No

Service scope

Software add-on or extension
No
Cloud deployment model
Public cloud
Service constraints
None
System requirements
Modern Web Browser (Chrome, Edge, Firefox)

User support

Email or online ticketing support
Yes
Support response times
FISCAL's support teams initial response time service level objectives are:
Severity 1 - 1 business hour
Severity 2 - 2 business hours
Severity 3 - 4 business hours
Severity 4 - 1 business day
User can manage status and priority of support tickets
Yes
Online ticketing support accessibility
WCAG 2.2 AA
Phone support
Yes
Phone support availability
9 to 5 (UK time), Monday to Friday
Web chat support
No
Onsite support
No
Support levels
We provide a single comprehensive support tier included with all subscriptions. Support is delivered by qualified engineers familiar with the platform.

Support Channels:
- Telephone and email during standard support hours (Monday-Friday, 08:30-17:30 UK time, excluding English bank holidays)
- 24/7/365 access to our online knowledge base for self-service guidance
- Interactive remote support for incident resolution

Incident Response Times:

Incidents are prioritised by business impact with defined response and resolution targets:

- Severity 1 (Service unavailable, no workaround): 1 business hour response, 4 business hour resolution target. Must be reported via telephone.
- Severity 2 (Major functionality affected or Severity 1 with workaround): 2 business hour response, 1 business day resolution target.
- Severity 3 (Minor functionality affected): 4 business hour response, 3 business day resolution target.
- Severity 4 (Questions, minor issues, documentation): 1 business day response, reasonable endeavours for resolution.

Dedicated customer success managers are aligned to customers as standard to provide basic support and guidance on using the product.
Support available to third parties
Yes

Onboarding and offboarding

Getting started
All customers have a dedicated implementation manager who will work with the customer on configuration and set-up, including generation of automated ERP extracts required by the platform and initial user-level configuration and hierarchy.

At the same time, the nominated Customer Success Manager aligned to the account will manage training, either onsite or online for all nominated users - training is recorded and available on demand and supported with detailed user documentation. Typically an overview session takes place prior to customer data being added, then follow-up user sessions on a regular basis during initial usage, at a cadence defined with the customer success manager.

Follow-up sessions are scheduled regularly to cover new features or to onboard new users
Service documentation
Yes
Documentation formats
HTML
End-of-contract data extraction
The customer can export their data in a common format prior to contract termination via the reporting module and product export functions.
End-of-contract process
Upon termination, all of the customer data and backups are securely removed from the platform and associated Azure services within 30 days using custom scripts and Microsoft Azure security processes.
Documentation accessibility standard
WCAG 2.2 AA

Using the service

Web browser interface
Yes
Supported browsers
  • Microsoft Edge
  • Firefox
  • Chrome
  • Safari
  • Opera
Application to install
No
Designed for use on mobile devices
No
Service interface
Yes
User support accessibility
WCAG 2.2 AA
Description of service interface
The platform is accessed via a web portal.
Accessibility standards
WCAG 2.2 AA
Accessibility testing
Our interface testing with assistive technology users follows a structured, iterative approach through our Special Interest Groups (SIGs). These customer-led testing groups provide real-world validation of accessibility features before general release.

Our standard process involves three key stages:

Pre-Release Testing: SIG members representing diverse accessibility needs test beta releases using their own assistive technologies, including screen readers (JAWS, NVDA), voice recognition software, and alternative input devices. This provides authentic user experience feedback in actual operating environments.

Structured Feedback Collection: Participants complete standardised testing protocols covering keyboard navigation, screen reader compatibility, colour contrast effectiveness, and form interaction. We collect both quantitative metrics (task completion rates, error frequencies) and qualitative feedback on user experience barriers.

Iterative Refinement: Issues identified during SIG testing are categorised by severity and addressed prior to production release. Critical accessibility barriers trigger immediate remediation, whilst enhancement opportunities inform our development roadmap.
This approach has proven effective in identifying issues automated testing alone cannot detect, such as illogical tab order, unclear ARIA labels, or confusing screen reader output. Our SIG members provide ongoing validation that our WCAG 2.2 AA compliance translates into genuine usability for assistive technology users.
API
Yes
What users can and can't do using the API
FISCAL's platform supports automated uploading of data via an API.

Users setup an access token via the admin portal to connect to the API and can configure automated uploads following the attached guide: https://onboarding.apfnxg.com/uploads/why
API documentation
Yes
API documentation formats
HTML
API sandbox or test environment
No
Customisation available
Yes
Description of customisation
At organisation level, customers select which modules to enable: Suppliers, Transactions, Statement Reconciliation, Reporting, Sanctions Screening, ESG, and Credit Monitoring.

Site-wide settings include transaction workflows, invoice statuses, transaction categories, automated user assignment rules, supplier duplicate identification rules, credit monitoring thresholds, and supplier dormancy thresholds.

Individual users can personalise their date format preferences and default landing page.

How and who:
Module selection is configured during onboarding in consultation with FISCAL. Site-wide settings are managed through the application by customer administrators with appropriate permissions.

Scaling

Independence of resources
FISCAL Technologies' platform leverages Microsoft Azure's elastic scalability. Traffic is distributed by Azure Load Balancers and filtered at the edge by Cloudflare WAF, providing DDoS protection before reaching the platform.

The architecture enforces logical tenant segmentation through separate SQL Server databases, separate Azure storage containers, and per-customer Solr collections, ensuring one customer's operations do not affect another.

Compute resources are managed through Azure Kubernetes Service with configured resource limits per service. Azure SQL Elastic Pools provide automatic database scaling. Continuous monitoring via Azure Application Insights enables proactive scaling before service degradation occurs.

Analytics

Service usage metrics
Yes
Metrics types
FISCAL provides an inbuilt reporting module with analytics on service usage and value delivered. Examples of these would be:

Business Value Metrics:
- Values prevented, recovered, corrected, and dismissed
- Transaction and supplier volume and value

Usage Metrics:
- User activity including system logons
- User workflow reports

These reports enable customers to track the effectiveness of the solution, identify risks, monitor user adoption, and demonstrate return on investment. Reports can be accessed on-demand through the platform by users with appropriate permissions.
Reporting types
  • Real-time dashboards
  • Regular reports
  • Reports on request
Resource tagging
No
FOCUS resource tagging
No

Resellers

Supplier type
Not a reseller

Staff security

Staff security clearance
Other security clearance
Government security clearance
Security Clearance (SC)

Asset protection

Knowledge of data storage and processing locations
Yes
Data storage and processing locations
  • United Kingdom
  • European Economic Area (EEA)
User control over data storage and processing locations
Yes
Datacentre security standards
Complies with a recognised standard (for example CSA CCM version 4.0)
Penetration testing frequency
At least once a year
Penetration testing approach
‘IT Health Check’ performed by a CREST-approved service provider
Protecting data at rest
  • Physical access control, complying with CSA CCM v4.0
  • Physical access control, complying with SSAE-18 / ISAE 3402
  • Physical access control, complying with another standard
  • Encryption of all physical media
  • Other
Other data at rest protection approach
Hosting on Microsoft Azure; Azure region(s) are agreed per customer.
All customer data at rest is encrypted using AES‑256 (databases, storage, logs, credentials, configuration data). SQL Servers and cloud assets are encrypted by default.
Data sanitisation process
Yes
Equipment disposal approach
Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
Data sanitisation type
  • Deleted data can’t be directly accessed / Cryptographic Erasure
  • Data Erasure
  • Explicit overwriting of storage before reallocation / Secure Erase
  • Physical Destruction / Hardware containing data is completely destroyed

Data importing and exporting

Data export approach
The customer can export their data in a common formats via the reporting module and product export functions.
For more advanced requirements FISCAL offers advanced reporting module options to enable reporting and data extraction options.
Data export formats
  • CSV
  • Other
Other data export formats
  • PDF
  • Excel
  • Images (PNG)
Data import formats
  • CSV
  • Other
Other data import formats
  • JSON via the API
  • XML via the API
  • TSV
  • TXT
  • XLSX

Data-in-transit protection

Data protection between buyer and supplier networks
TLS (version 1.2 or above)
Data protection within supplier network
  • TLS (version 1.2 or above)
  • IPsec or TLS VPN gateway
  • Other
Other protection within supplier network
All data transmitted to or from the service is encrypted in transit using TLS 1.2 or higher. Internal service-to-service communications and external API integrations use TLS 1.2+. HTTPS is enforced for all web traffic and legacy/weak SSL/TLS versions are disabled. Certificate management is automated with regular renewals and HSTS is enabled to help prevent downgrade attacks. Services are hosted on Microsoft Azure and leverage Azure network and encryption controls. FISCAL Technologies operates under an ISO 27001-certified ISMS and holds Cyber Essentials accreditation.

Availability and resilience

Guaranteed availability
FISCAL aims for 99.5% availability, with historic performance figures available to support and updates communicated quarterly through the contract duration
Approach to resilience
FISCAL leverages the resilience of Microsoft 's Azure platform using availability (Availability Zones/Regions) and site-level redundancy (see Microsoft Trust Center for detailed facility controls).
The application and data are deployed with logical redundancy and multi-region redundancies for customer data. Customer data stays within their selection geographic region, but can span several datacentres.
Backups are automated and encrypted with defined RTO/RPO and stored multi-regionally for resilience.
Edge protections include Cloudflare WAF and Microsoft load balancing to allow connectivity redundancies and reduce risk of service degradation.
Outage reporting
Status dashboard: Our support portal (Minerva) displays real-time service status using RAG indicators:
- Red: Full outage preventing multiple or all customers from accessing the product
- Amber: Issues impacting some elements or specific customers
- Green: No issues impacting customers

The support page provides detailed outage information including current investigation actions, resolution timelines, and confirmation when resolved.

Email alerts: Customers are notified via email of any critical outages or issues affecting their service, with regular updates throughout the incident until resolution.

Identity and authentication

User authentication needed
Yes
User authentication
  • Multi-Factor Authentication (MFA)
  • Public key authentication (including by TLS client certificate)
  • Identity federation with existing provider (for example Google Apps)
  • Username or password
  • Other
Other user authentication
Users authenticate via Auth0 using username/password or Single Sign-On (SSO) integration with the customer's identity provider (Microsoft Entra ID, ADFS, Google, Okta, and others).

Password authentication enforces minimum 14 characters with complexity requirements. Auth0 provides brute force protection, breached password detection, and suspicious IP throttling.

SSO customers retain full control over their authentication policies including MFA requirements.

Sessions timeout after configurable inactivity periods (15 minutes to 1 hour) or maximum 12 hours.

Customer administrators manage user access through role-based access control (RBAC) within the platform.
Access restrictions in management interfaces and support channels
Management interfaces: FISCAL staff access backend infrastructure via Microsoft Entra ID with mandatory MFA and conditional access policies requiring device compliance. Privileged access uses Azure Privileged Identity Management (PIM) requiring peer review authorisation, MFA re-verification, and time-limited elevation. All privileged actions are audit logged.

Support channels: Support staff have no default access to customer environments. Access requires an open Zendesk ticket with customer authorisation, subject to the same Entra ID, MFA, conditional access, and device compliance controls.
Access restriction testing frequency
At least once a year
Management access authentication
  • Multi-Factor Authentication (MFA)
  • Public key authentication (including by TLS client certificate)
  • Username or password
  • Other
Description of management access authentication
Management interfaces: FISCAL staff access backend infrastructure via Microsoft Entra ID with mandatory MFA and conditional access policies requiring device compliance. Privileged access uses Azure
Privileged Identity Management (PIM) requiring peer review authorisation, MFA re-verification, and time-limited elevation. All privileged actions are audit logged.

Support channels: Support staff have no default access to customer environments. Access requires an open Zendesk ticket with customer authorisation, subject to the same Entra ID, MFA, conditional access, and device compliance controls.

Audit information for users

Access to user activity audit information
Users receive audit information on a regular basis
How long user audit data is stored for
At least 12 months
Access to supplier activity audit information
Users have access to real-time audit information
How long supplier audit data is stored for
User-defined
How long system logs are stored for
At least 12 months

Security governance

Named board-level person responsible for service security
Yes
Security governance certified
Yes
Security governance standards
  • ISO/IEC 27001
  • Other
Other security governance standards
Cyber Essentials
Information security policies and processes
FISCAL maintains a comprehensive ISMS and is ISO 27001 accredited and Cyber Essentials certified.

Policies & processes
Core Information Security Policy supported by topic-specific policies (access control, cryptography, acceptable use, data protection, incident management, etc.).
Policies are version-controlled, published in the ISMS platform and follow the Policy Governance process.
Policies are reviewed annually by the Director of IT & Security and approved by the Senior Leadership Team.
Changes are communicated via mandatory read, awareness training, onboarding, and email notifications.
Security is embedded in delivery through a DevSecOps approach and secure development responsibilities are assigned to development leads and architects.

Reporting & governance
Information Security Forum (ISF) meets quarterly to review risks, incidents, policies and ISMS improvements.
CISO / Director of IT & Security and TISO are responsible for the information security programme.
Reporting structure:
- Director of IT & Security (CISO) reports to executive leadership
- Chief Technology & Product Officer (CTPO) works closely with CISO on product security
- IT Team reports to the Director of IT
- Development Leads report to the CTPO
- Chief Software Architect responsible for secure design
Software Security Code of Practice
Yes

Operational security

Configuration and change management standard
Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
Configuration and change management approach
All infrastructure and application configurations are defined as code and stored in version control, providing a complete audit trail of every change throughout the service lifecycle.

Every change follows a formal review process: changes must be linked to a tracked work item, pass automated, performance, code quality, SAST and DAST, and be approved by a peer reviewer. Reviewers assess potential security impact including customer impact, data protection, secure communications, stability, and risks from third-party components.

Production releases require sign-off from senior engineers at release readiness meetings. Automated pipelines deploy changes, with Terraform plans reviewed before applying to production.
Vulnerability management type
Supplier-defined controls
Vulnerability management approach
We assess threats through continuous automated scanning:
Dependency vulnerability scanning identifies risks in third-party components.
Code quality, SAST, and DAST scanning detects weaknesses in our code, secure configuration and running environment.
Web application scanning detects security weaknesses in our live services.
Vulnerabilities are scored using industry-standard CVSS ratings.

Patch deployment targets are based on severity: critical and high vulnerabilities within 2 weeks, medium within 4-8 weeks, and low within 3-6 months. Critical security fixes are deployed via emergency release processes.

Threat information is gathered from vulnerability databases integrated with our scanning tools, UK-NCSC, US-CISA, and vendor security advisories and recommendations.
Protective monitoring type
Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
Protective monitoring approach
Potential compromises are identified through real-time monitoring of our platform using Azure Defender, Application Insights and Prometheus, with automated alerts configured for anomalous behaviour, security events, and system faults. Staff report suspected incidents immediately via our helpdesk.

When a potential compromise is detected, incidents are classified by security impact (confidentiality, integrity, availability) and assigned priority levels. Critical incidents trigger immediate response with dedicated resources and a live incident channel. High-priority incidents are addressed before all others.

For incidents affecting customer data, we notify affected customers within 24 hours with details of scope, impact, and remediation measures.
Incident management type
Complies with a recognised standard, for example, CSA CCM v4.0 or ISO/IEC 27035:2011 or SSAE-18 / ISAE 3402
Incident management approach
We maintain documented incident management procedures with pre-defined processes for common security events including service disruption, access violations, system faults, and data breaches. Incidents are classified by impact (confidentiality, integrity, availability) and prioritised as Critical, High, Medium, or Low.

Users report incidents via our helpdesk, with product-related incidents tracked in our development management system. Critical and high-priority incidents trigger immediate escalation to senior management.

For incidents affecting customer data, we notify affected customers within 24 hours with details of scope, impact, and remediation measures. Post-incident reports document root cause analysis and corrective actions.
Post-quantum cryptography secure
Yes

Secure development

Approach to secure software development best practice
Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)

Public sector networks

Connection to public sector networks
No

Pricing

Discount for educational organisations
No
Free trial available
Yes
Description of free trial
We offer a free 'proof of value' - the customer provides AP data and we create a snapshot of current/historical AP risk exposure using the same preventative risk management approach that underpins the FISCAL software. We can show the results produced by the software without integration or obligation

Discount percentage by annual call-off contract value (excluding VAT)

Less than £250,000
0%
Between £250,000 and £500,000
25%
Between £500,001 and £1,000,000
40%
Between £1,000,001 and £2,500,000
60%
Between £2,500,001 and £5,000,000
70%
Over £5,000,001
80%

Non-mandatory Standards and certifications

ISO/IEC 27001 certification
Yes
Who accredited the ISO/IEC 27001
British Assessment Bureau
ISO/IEC 27001 accreditation date
Monday 2 February 2015
What the ISO/IEC 27001 doesn’t cover
There are not any exempt areas of the standard. All controls are in scope.
ISO 28000:2022 certification
No
ISO 9001 certification
No
Quality management systems (QMS)
No
CSA STAR certification
No
PCI certification
No
Cyber essentials
Yes
Please provide your Cyber Essentials Certificate Number
Ae2ef55a-c845-4abb-a957-06e911aa4c7c
Cyber essentials plus
No
Cyber Essentials Alternative
You do not have a current and valid Cyber Essentials Plus certificate, or will not have in place within 12 months of the date of award but have an IASME certified equivalent.
Other security certifications
No

Social value

Section B - Commitment for Future: Delivery
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.

    • Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
  • Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero

    Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.

    • Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
    • Delivery of additional environmental benefits through the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at smarter@fiscaltec.com. Tell them what format you need. It will help if you say what assistive technology you use.