Skip to main content

Help us improve the Digital Marketplace - send your feedback

JAAMA LTD

Key2 Fleet Management System

Key2 drives digital transformation for public-sector fleets, delivering complete asset lifecycle control from acquisition to disposal. Features include paperless workflows, mobile apps, DVSA Earned Recognition, and document automation. Integrated modules streamline management of drivers, workshops, fuel, compliance, defects, hire and accidents, supported by advanced reporting and API-driven or automated integrations.

Features

  • Full fleet management platform combing vehicle, asset and driver records
  • MOT, service, inspection compliance visibilty and automated alerts
  • Automated DVLA licence check integration against drivers
  • Real-time customisable dashboards across roles with interactive graphs and indicators
  • Configurable report builder and export studio for fleet analytics
  • Integrated document management to store and access attachments against records
  • Digitise maintenance and workshop operations including scheduling, procurement and invoicing
  • Pool vehicle and short term hire management with auto-allocation functionality
  • Driver mobile app digitising vehicle check workflows and defect reporting
  • Workshop technician app for job, performance and cost tracking

Benefits

  • Optimised maintenance scheduling and fuel management capability for cost tracking
  • Vehicle and associated asset lifecycle tracking within single linked records
  • Customisable risk thresholds for automated driver risk profiling
  • Fuel card data import functionality for accurate fuel cost monitoring
  • Drill-down capability on all data points for complex reporting
  • Suite of standard reports for rapid deployment, with customisation available
  • Eliiminate data silos with centralised record and document storage
  • SSO, DVSA, DVLA, Oracle, Fuel Card and vehicle telematics integrations
  • Automatic compliance notifications at configurable intervals to nominated users
  • Extend vehicle lifespan, improve workshop efficiency and reduce costs

Pricing

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at sales@jaama.co.uk. Tell them what format you need. It will help if you say what assistive technology you use.

Framework

G-Cloud 15

Service ID

3 8 5 9 3 3 0 5 6 6 6 6 4 9 4

Contact

JAAMA LTD Sales
Telephone: 08448484333
Email: sales@jaama.co.uk

About your service

Service categories

Applications

Supply chain management

  • Logistics and transportation management
Multi cloud support
No

Service scope

Software add-on or extension
No
Cloud deployment model
Private cloud
Service constraints
None
System requirements
  • Minimum 1Mbps per concurrent user or 30Mbps available bandwidth
  • Connection latency between client and server should be below 50ms
  • 1Gbps LAN connectivity for multi-server environments
  • Intel Core i3 1.7Ghz and 4GB RAM
  • 100 Mbps Ethernet or Faster
  • Windows 10 or 11
  • Screen Resolution: 1024 x 768 or greater

User support

Email or online ticketing support
Yes
Support response times
System Availability- P1: Response 1 hour, P2: Response 4 hours,P3: Response 4 hours.
User can manage status and priority of support tickets
Yes
Online ticketing support accessibility
WCAG 2.2 A
Phone support
Yes
Phone support availability
9 to 5 (UK time), Monday to Friday
Web chat support
No
Onsite support
Yes, at extra cost
Support levels
System Availability- P1: Response 1 hour, P2: Response 4 hours,P3: Response 4 hours.
Support available to third parties
No

Onboarding and offboarding

Getting started
The Setup Service provides a structured, best practice “plug and play” installation of the standard fleet software product, ensuring that public sector customers begin with a consistent, reliable and fully supported foundation. The service covers all essential preparatory activities required to establish the hosted environment, deploy the standard software components and equip users to begin operating the system effectively from day one. This approach supports a smooth and consistent mobilisation process across all implementations.

Scope of the Setup Service: Hosting Environment Provisioning and Configuration, SQL Licensing and Commissioning, Deployment of Standard Software Components, Baseline System Configuration, Standard User Training

Optionally, customers can use our implementation services team for more specific customisations, data migration and other specific hands on services.
Service documentation
Yes
Documentation formats
  • PDF
  • Other
Other documentation formats
  • Word
  • Video content
End-of-contract data extraction
When a Key2 contract ends, hosted customers must confirm by the contract expiry date whether they want to retain their system data. If this is agreed in advance, data extraction can be completed on the day of termination. If no confirmation is provided, Jaama will automatically remove all data three months after the cancellation date. The only exception is for organisations using the Driver Licence Checking Service, where DVLA regulations require retention of driver mandate records for seven years. Key2 supports data extraction through its reporting and export tools through SFTP, enabling customers to download data in formats such as Excel, CSV, PDF, and text. These exports can include all relevant operational and historical data, filtered by criteria and time frames, and can be scheduled or run on demand using the integrated report writer and scheduler.
End-of-contract process
We have a standard process for exit, supported by a fixed charge, which includes providing the client with their data in a predefined standard format such as CSV files or SQL tables. This process also covers the secure transfer of data via an approved method such as SFTP, the orderly decommissioning of the hosted environment, and the secure disposal of all customer data in line with our data‑retention and security policies. Where custom additional exit support is required, additional services can be provided at the stated additional charge and will be subject to a quotation and Order Form.
Documentation accessibility standard
WCAG 2.2 AA

Using the service

Web browser interface
Yes
Supported browsers
  • Microsoft Edge
  • Firefox
  • Chrome
Application to install
Yes
Compatible operating systems
  • Android
  • IOS
  • Windows
Designed for use on mobile devices
Yes
Differences between the mobile and desktop service
The core Key2 application runs on desktops, whereas applications such as MyVehicle App and MyTechnician App are designed to run on Android or iOS devices.
Service interface
Yes
User support accessibility
WCAG 2.2 A
Description of service interface
The Key2 service interface is built on Microsoft .NET technology, using Microsoft SQL Server and XML data structures. It is designed as a relational database, ensuring that data captured in one module, cascades across related modules to eliminate duplication. The interface is intuitive and familiar to users of Microsoft applications, featuring toolbars, dropdown menus, and quick and advanced search functions. Dashboards provide configurable operational charts and compliance alerts tailored to user roles. Multiple access points, including the MyVehicle and MyTechnician App for iOS and Android, supports offline working.
Accessibility standards
None or don’t know
Description of accessibility
Key2 is accessible through multiple interfaces tailored to different user roles. The core application runs on the Microsoft .NET Framework and requires a Windows operating system, providing a rich desktop experience for fleet administrators. Our Touchscreen Module operates on Windows devices and can be deployed on ruggedised tablets or fixed terminals within workshops. Our Apps are available for both iOS and Android devices. Key2 web-based portals ensure that various Jaama products can be used across smartphones, tablets, and desktop environments, with features like push notifications, barcode scanning, and electronic document handling to optimise accessibility and usability in varied operational contexts
Accessibility testing
Key2 is delivered via ClickOnce which delivers a rich user interface with the look and feel of a standard Windows application, and operates as a desktop-style application rather than a browser-based service. Because it is not a web application, it does not fall within the scope of WCAG accessibility requirements.
However, our other web-based platforms, such as Maintenance Exchange and the MyDriver Portal, are designed and maintained to meet WCAG standards, ensuring they are accessible and compliant for all users.
API
Yes
What users can and can't do using the API
Users can fully manage organisational and supplier data through the Purchase Order API, retrieving, creating, and updating organisation structures and levels, including user-defined fields, supplier records and references. Users can retrieve Service, Maintenance, and Repair records. Purchase orders and delivery receipt notes can be retrieved and updated.
Users can retrieve vehicles allocated to a driver or search by registration number via the MyVehicle App API; insert non-system vehicle records; submit checklists for system, rental, or non-system vehicles; record fuel purchases, odometer readings, defects, accident reports; request images, checklist submissions or callbacks for specific vehicles; retrieve fleet policy details and app version information.
Users can import mileage data via the Tachomaster Mileage API, retrieving odometer readings and duty end times, updating Key2’s vehicle details and period summaries. Validation checks ensure registration numbers, odometer readings, and dates are accurate before processing.
The Tachomaster Driver API enables importing and updating driver details from Tachomaster including names, employment dates, and Tachomaster card numbers.
Users cannot override mandatory validation rules and missing critical fields will result in validation failure. Error handling cannot be skipped. Failed validations require manual correction in the relevant Batch Area, ensuring compliance and accuracy before data can be processed further.
API documentation
Yes
API documentation formats
PDF
API sandbox or test environment
Yes
Customisation available
Yes
Description of customisation
Users can personalise their Key2 Dashboard, displaying operational charts, data sets and KPIs relevant to each role. The wizard-based report writer creates tailored reports by selecting criteria, output fields, calculated fields, and formatting options, with the ability to schedule and export reports in multiple formats.
User administrators can define granular RBAC limiting visibility, editorial or deletion rights at a system-wide or module-specific level. Restrictions can be applied to organisational structures, ensuring users only see data relevant to their department. User-defined fields can be created to capture bespoke data attributes including text, numeric values, dates, yes/no options, and customisable menus. Once configured, they are fully reportable via standard or custom reports. These can be integrated into import and export routines via the Import Studio.
Users can configure Standard Jobs with predefined labour times and parts, manage stock control rules, and set criteria for stock checks. Organisations can tailor barcode integration and label generation to streamline workshop and stores processes. The Asset Type Management module defines custom asset categories, acquisition methods, maintenance schedules, and replacement profiles. Document templates can be customised to reflect organisational branding and terminology, supported by the Menu Manager, which ensures consistency in dropdown menus and system language.

Scaling

Independence of resources
We implement a dedicated and segregated architecture where each hosted Key2 system operates within its own unique database and credentials, ensuring complete data isolation. The service is not multi-tenanted, so customer data is never stored together. Hosting options include shared server infrastructure with strict database segregation, as well as dedicated SQL Server or fully customised hosting for additional isolation. The infrastructure is built on a fully redundant, high-performance platform with low-latency connectivity capable of scaling to over 20Gbit bandwidth, which prevents performance degradation during demand spikes. Systems are backed up every 30 minutes and replicated across multiple sites for resilience.

Analytics

Service usage metrics
No

Resellers

Supplier type
Not a reseller

Staff security

Staff security clearance
Other security clearance
Government security clearance
Security Clearance (SC)

Asset protection

Knowledge of data storage and processing locations
Yes
Data storage and processing locations
United Kingdom
User control over data storage and processing locations
No
Datacentre security standards
Complies with a recognised standard (for example CSA CCM version 4.0)
Penetration testing frequency
At least once a year
Penetration testing approach
‘IT Health Check’ performed by a CHECK service provider
Protecting data at rest
  • Encryption of all physical media
  • Other
Other data at rest protection approach
All hosting environment databases are encrypted using SQL Server TDE with AES-256 encryption. Company laptops have whole-disk encryption via Microsoft BitLocker (AES-256). Access requires both a secure password and multi-factor authentication. Mobile devices and portable storage media are similarly encrypted, with strict handling procedures to prevent unauthorised access or physical loss. Encryption keys are managed through generation, storage, rotation, and destruction, and are protected against modification, loss, or disclosure. Sensitive files transmitted internally or externally must be encrypted and compressed, with keys shared through separate secure channels.
Data sanitisation process
Yes
Equipment disposal approach
Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
Data sanitisation type
Explicit overwriting of storage before reallocation / Secure Erase

Data importing and exporting

Data export approach
Our Export Studio and integrated Report Writer allows authorised users to manually extract data in Excel (.xlsx), CSV, PDF, text, and ASCII. These tools provide advanced filtering, grouping, and sorting options across operational, financial, compliance, historical records and custom fields, enabling users to define selection criteria and apply conditional parameters to specify relevant data for export.
Key2 Scheduler automates export at predefined intervals and can be delivered to email addresses, network paths, or FTP/SFTP locations. Key2’s underlying Microsoft SQL Server architecture enables secure connectivity for bulk extraction or integration with external business intelligence tools such as Power BI.
Data export formats
  • CSV
  • Other
Other data export formats
  • XLSX
  • PDF
  • Text
  • ASCII
Data import formats
  • CSV
  • Other
Other data import formats
  • XLSX
  • PDF
  • Text
  • ASCII

Data-in-transit protection

Data protection between buyer and supplier networks
  • TLS (version 1.2 or above)
  • Other
Other protection between networks
Cross-network data exchange is protected in line with ISO 27001 standards. The network is segmented using VLANs and internal firewalls, with Access Control Lists to control traffic, and servers exposed to public networks are placed in a DMZ for added security. Remote access is only permitted via OpenVPN with multi-factor authentication. Continuous monitoring tools such as PRTG and Microsoft 365 alerts detect anomalies and data leakage, with weekly threat intelligence reviews and proactive patching. Customer backups are securely replicated between Jaama sites and its ISO 27001-certified data centre. Third-party processors or controllers must adhere to strict contractual security requirements.
Data protection within supplier network
  • TLS (version 1.2 or above)
  • Other
Other protection within supplier network
Jaama’s network is segmented using VLANs with perimeter firewalls and reverse proxy systems. Servers requiring external access are placed in a DMZ. Wireless networks secured with WPA2 Enterprise authentication. Guest networks are physically separated. Remote access is only permitted via a VPN using IPsec or TLS, supported by secure authentication through a RADIUS server.
Whole-disk hardware encryption with AES-256 via BitLocker, combined with multi-factor authentication and RBAC. Servers and hosted environments use TLS (data in transit) and AES-256 (data at rest). AES, RSA, and SHA variants are enforced, encryption keys are securely stored in LastPass Enterprise or protected network volumes.

Availability and resilience

Guaranteed availability
Jaama has a high level of availability in its SLA, currently 99.9% scheduled uptime for the Key2 service. This is supported by hosting the solution in a Tier 3+ data centre operated by Node4, combined with proactive monitoring and capacity planning under ISO27001 and ISO9001 frameworks. Unscheduled downtime is reported as negligible, and performance metrics are regularly reviewed to ensure compliance with SLA commitments. These measures ensure that customers experience consistent service availability and reliability throughout the contract period.
Approach to resilience
The service is hosted in a Tier 3+ Node4 Data Centre, complemented by infrastructure across geographically separate sites with daily data replication for redundancy. Node4’s ISO-certified facilities and Jaama’s secure offices provide robust physical protection.
A comprehensive Business Continuity Plan (BCP) underpins service resilience, defining clear recovery procedures and roles. Key2 is prioritized as the critical system, with a maximum allowable downtime of 24 hours. Regular scenario-based tests and a hybrid working model ensure operational flexibility during incidents.
Technical resilience is reinforced through excess hosting capacity, weekly-tested backups, and automated monitoring tools like PRTG for proactive issue detection. UPS systems safeguard against power outages, enabling uninterrupted service or controlled shutdowns when necessary.
Security and stability are maintained through a secure development lifecycle, segregated environments, and formal ITIL-based change management processes. Regular code reviews, penetration testing, and regression testing prevent vulnerabilities and ensure reliable updates.
Finally, risk management is embedded in operations, addressing threats such as malware, data leakage, and hardware failure. Controls include multi-factor authentication, encryption, anti-malware solutions, and ISO-certified infrastructure supported by Dell maintenance contracts.
Together, these measures deliver a resilient, secure, and dependable Key2 platform, giving clients confidence in continuity and data protection.
Outage reporting
Jaama is committed to keeping clients fully informed during any service disruption. Our structured Crisis Communication framework ensures that updates are timely and accurate throughout an outage. When a major incident occurs, customers are notified as soon as the issue is confirmed. This is primarily done through email alerts which include details of the outage, its impact, and the estimated time for resolution. Where possible, the Key2 system will also display alerts or messages to inform users of service interruptions. If email delivery fails or wider communication is required, updates may be posted on Jaama’s website, social media platforms, or issued via press releases. Regular updates are provided during the outage, typically on an hourly basis for major incidents, and a final resolution message is sent once services are restored. All communications follow strict protocols outlined in Jaama’s Business Continuity Plan to ensure accuracy, timeliness, and compliance with ISO 27001 standards.

Identity and authentication

User authentication needed
Yes
User authentication
  • Multi-Factor Authentication (MFA)
  • Identity federation with existing provider (for example Google Apps)
  • Username or password
  • Other
Other user authentication
Users access the system using unique credentials controlled by the organisation. Password complexity and history policies can be enforced, along with mandatory password changes at predefined intervals. The User and Group Management module allows administrators to configure access rights at a detailed level. Key2 supports SAML-based SSO and integrates fully with Active Directory or Azure AD. For AD integration, ADFS (Active Directory Federation Services) is required to enable SSO. A complete audit trail is kept for login and logout attempts, including successful and failed attempts, along with time, date, and device details.
Access restrictions in management interfaces and support channels
Access to management interfaces is restricted through privileged access rights (reviewed periodically), Role-Based Access Control (RBAC), segregation of duties, with audit logs of account activity. Sensitive operations require re-authentication, and multi-factor authentication is strongly available for high-risk systems. Secure protocols are employed, with additional measures like session timeouts and account lockouts after repeated failed attempts.
Support channels implement strict controls to prevent unauthorised access. Password reset procedures, secure communication of passwords are in place. Reset credentials are time-limited to reduce risk. Multi-factor authentication is employed for accounts accessing sensitive personal data. Staff receive GDPR and data governance training.
Access restriction testing frequency
At least once a year
Management access authentication
  • Multi-Factor Authentication (MFA)
  • Identity federation with existing provider (for example Google Apps)
  • Username or password

Audit information for users

Access to user activity audit information
Users have access to real-time audit information
How long user audit data is stored for
At least 12 months
Access to supplier activity audit information
Users have access to real-time audit information
How long supplier audit data is stored for
At least 12 months
How long system logs are stored for
At least 12 months

Security governance

Named board-level person responsible for service security
Yes
Security governance certified
Yes
Security governance standards
  • CSA CSM version 4.0
  • ISO/IEC 27001
  • Other
Other security governance standards
ISO 9001
Information security policies and processes
Our integrated Quality and Information Security Management System (QMS/ISMS) is certified to ISO 9001:2015 and ISO 27001:2022. Our governance principles include a strong commitment from senior leadership to ensure that policies align with strategic goals, resources are available, and continual improvement is promoted. The scope of the system covers software development, customer-specific solutions, hosting services, training, and support. Jaama maintains legal compliance by being registered with the ICO (Registration No. Z9786731) and keeping a Legislation Register for GDPR and other statutory requirements. Information Security objectives are documented, measurable, and reviewed regularly. All processes, policies, and templates are maintained under strict version control to ensure consistency and accuracy, with a dedicated suite of information, data protection and security-related policies and incident reporting mechanisms that all staff must adhere to as a contractual prerequisite.
Information Security Policy; Email & Internet Acceptable Use Policy; Anti-Malware Policy; Backup Policy; Encryption Policy; Remote Working & Mobile Device Policy; Access Control Policy; Password Policy; Incident Reporting Procedure; Data Protection Policy; Data Retention Policy; Records of Processing Activities (ROPA); Threat Intelligence Process; Artificial Intelligence (AI) Policy; Clear Desk & Clear Screen Policy; Network Security Policy; IT Asset & Disposal Policy; Supplier Risk Management & Purchase Order Process.
Software Security Code of Practice
Yes

Operational security

Configuration and change management standard
Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
Configuration and change management approach
Our QMS and ISMS complies with ISO 9001 and 27001 standards.
Systems, applications, and infrastructure are securely configured and maintained using secure coding principles, separation of development, test, and production environments and configuration management tools for version and access control.
Hardware, software, and data assets are inventoried according to security requirements. Ownership and acceptable use rules are documented and enforced.
Changes management follows documented procedures including: impact assessments; authorisation controls; testing and acceptance prior to Go Live; stakeholder communication plan; emergency and contingency planning; change logs approvals, and implementations; updated operational and user; business continuity and disaster recovery planning.
Vulnerability management type
Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
Vulnerability management approach
Our ISO 27001-certified ISMS includes proactive identification and assessment of vulnerabilities through a formal risk register, evaluating information assets for confidentiality, integrity, and availability impacts. Risks are scored based on likelihood and severity, and appropriate treatment strategies such as risk acceptance, avoidance, mitigation, or transfer are applied. Jaama actively monitors trusted sources, including Microsoft Security Bulletins and industry threat intelligence, to identify emerging vulnerabilities. Critical patches are deployed within 14 days, and continuous monitoring tools are used to detect anomalies such as failed logins or suspicious activity. Internal audits ensure ongoing effectiveness and continuous improvement.
Protective monitoring type
Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
Protective monitoring approach
Jaama employs CCTV, motion detectors, intrusion detection, and alarm systems to detect unauthorised physical access. Sensitive areas are restricted and monitored.
All user activities, exceptions, faults, and security events are logged and reviewed regularly, safeguarded against tampering and unauthorised access, with administrator privileges tightly controlled.
Automated PRTG and firewall alerts monitor networks, systems, and applications for unusual behaviour. Real-time alerts and dashboards support proactive detection and escalation of incidents, fully integrated with incident reporting and response procedures. This integration ensures that any detected security event is escalated and resolved promptly, minimising risk and maintaining compliance.
Incident management type
Complies with a recognised standard, for example, CSA CCM v4.0 or ISO/IEC 27035:2011 or SSAE-18 / ISAE 3402
Incident management approach
Jaama’s incident management processes begins with identifying and categorising incidents, using a tiered response structure: the Gold Team provides strategic command and decision-making, the Silver Team manages tactical responses and resource allocation, and the Bronze Team handles operational tasks. Initial actions focus on stabilisation and communication notifications. For cyber incidents or data breaches, the process integrates the Major Incident Management Process and the Incident Reporting Procedure, which include escalation protocols and compliance with legal reporting obligations. Employees are required to report suspected breaches or policy violations promptly. All actions, decisions, and costs are documented, and lessons learned are captured.
Post-quantum cryptography secure
No

Secure development

Approach to secure software development best practice
Conforms to a recognised standard, but self-assessed

Public sector networks

Connection to public sector networks
No

Pricing

Discount for educational organisations
No
Free trial available
No

Discount percentage by annual call-off contract value (excluding VAT)

Less than £250,000
0%
Between £250,000 and £500,000
0%
Between £500,001 and £1,000,000
0%
Between £1,000,001 and £2,500,000
0%
Between £2,500,001 and £5,000,000
0%
Over £5,000,001
0%

Non-mandatory Standards and certifications

ISO/IEC 27001 certification
Yes
Who accredited the ISO/IEC 27001
NQA
ISO/IEC 27001 accreditation date
Wednesday 2 April 2025
What the ISO/IEC 27001 doesn’t cover
Outsourced Development (Annex A control 8.30)
ISO 28000:2022 certification
No
ISO 9001 certification
Yes
Who accredited the ISO 9001 certification
NQA
ISO 9001 accreditation date
Thursday 3 April 2025
What the ISO 9001 doesn’t cover
None
Quality management systems (QMS)
Yes
CSA STAR certification
No
PCI certification
No
Cyber essentials
No
Cyber Essentials Alternative
In relation to the services you do not have a current and valid Cyber Essentials certificate which has been awarded by one of the government approved Cyber Essentials accreditation bodies but you are working towards gaining it, and will be in a position to confirm that you have been awarded a current and valid Cyber Essentials certificate by one of the government approved accreditation bodies within 12 months of the date of award.
Cyber essentials plus
No
Cyber Essentials Alternative
In relation to the services you do not have a current and valid Cyber Essentials Plus certificate which has been awarded by one of the government approved Cyber Essentials accreditation bodies but you are working towards gaining it, and will be in a position to confirm that you have been awarded a current and valid Cyber Essentials Plus certificate by one of the government approved accreditation bodies within 12 months of the date of award.
Other security certifications
No

Social value

Section B - Commitment for Future: Delivery
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority

    • New or retained jobs on the contract workforce in the relevant area that meet the criteria set out in MAC 1b, 1c and 1d
    • Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
    • Plans to engage the contract workforce in deciding the most important workplace issues to address
    • Ensuring new workers are informed of their right to join a trade union
    • Monitoring of employee engagement rates (by protected characteristic) and, where necessary, the development of actions to ensure all voices are heard across the diversity of the workforce
    • Employment contracts that reflect actual hours worked; steps taken to ensure employees understand their contracts and have the ability to review and adjust them if actual hours regularly exceed contracted hours
    • Activities that support an environment where staff are educated about, and feel empowered to, address their physical wellbeing
    • Activities that support an environment where staff are educated about and feel empowered to report and address bullying and harassment
    • Offer a pay and leave entitlement to all eligible staff who become kinship carers, ideally equivalent to statutory adoption pay and leave
    • Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
    • Entitlement to sick pay for the contract workforce, with provision in place for any staff who do not meet the earnings threshold for statutory sick pay, payment of sick pay from day one of absence and payment of staff on the contract workforce who are off sick a replacement income of 100% of their usual earnings for as long as possible
    • Understanding of in-work progression issues affecting the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors
    • Measures to support in-work progression to help people in the contract workforce, to move into higher paid work by developing new skills relevant to the contract
    • Support for the contract workforce by providing career advice, and providing opportunities for staff working on the contract with in-work progression career development into known skills shortages or high growth areas
    • Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
    • Volunteering opportunities for staff
    • Understanding of the modern slavery risks and issues affecting the market, industry, sector or country (of origin or of source) relevant to the contract, and the workforce in the supplier’s own organisation and those of its key subcontractors
    • Measures to identify, mitigate and manage modern slavery risks relating to the contract and how these will be implemented
    • Outline policies and practices to be applied to or put in place for the contract to mitigate and manage modern slavery risks, including: Pre-employment checks, recruitment practices. Workplace conditions, safeguarding plans and processes in place and regular monitoring with relevant groups considered, which may include sampling
    • How the supplier will work with NGOs, trade unions or other businesses to address modern slavery risk
    • Means of influencing staff, suppliers, customers, communities and/or any other appropriate stakeholders with respect to modern slavery risks relating to the contract
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.

    • Understanding of employment and relevant skills issues, and of the education and training issues relating to the contract. Illustrative examples: demographics, skills shortages, new opportunities in high growth sectors, geographic/local community and skills/employment challenges
    • Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
    • Activities to support relevant sector related skills growth and sustainability in the contract workforce. Illustrative examples: careers talks, curriculum support, literacy support, safety talks and volunteering
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 3: Resilient, innovative and flexible supply chains: Support economic growth through enabling resilient businesses, opportunities for small businesses and voluntary, community and social enterprises

    • Understanding of the types of businesses in the market and the level of participation by new businesses, entrepreneurs, start-ups, SMEs, VCSEs and mutuals
    • Ensuring accessibility to contracting and subcontracting opportunities for disabled business owners and employees
    • Understanding of local demographics, needs and opportunities for the co-design of the goods, services and works to be delivered under the contract
    • Collaborating with anchor institutions and community groups to make facilities available for education, training or community events
  • Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero

    Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.

    • Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
    • Collaborative ways of working with the supply chain to deliver additional environmental benefits in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
    • Delivery of additional environmental benefits through the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
    • Understanding of how to influence staff, suppliers, customers, communities and/or any other appropriate stakeholders through the delivery of the contract to support climate and nature protection and improvement
    • Activities to reconnect people with the environment and increase awareness of ways to protect and enhance it
  • Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain

    Policy Outcome 6: Employment and training: For those who face barriers to employment

    • Creation of employment opportunities particularly for those who face barriers to employment, such as prison leavers, care leavers and/or who are located in deprived areas, and for people in industries with known skills shortages or in high growth sectors
    • Delivery of training schemes and programmes to address any identified skills gaps and under-representation in the workforce for the contract (e.g. prison leavers, care leavers, kinship carers, disabled people)
    • Advertising, promotional and outreach activities designed to raise awareness of the offer to reach the target cohort
    • Understanding of the issues affecting the representation of disabled people in the workforce in the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors
    • Collection of the views and expertise of disabled people and their representative organisations on successfully supporting disabled employees or applicants
    • Inclusive and accessible recruitment practices, and retention-focused activities, including those provided in the Guide for line managers on recruiting, managing and developing people with a disability or health condition
    • Working conditions which promote an inclusive working environment and promote retention and progression
    • Other measures to provide equality of opportunity for disabled people and those with health conditions into employment, including becoming a Disability Confident employer and inclusion of supported businesses in the contract supply chain
    • Understanding of the issues affecting inequality in employment, skills and pay in the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors. Measures to tackle inequality in employment, skills and pay in the contract workforce
    • Inclusive and accessible development practices, including guidance for line managers on recruiting, managing and developing people with a disability or health condition
  • Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain

    Policy Outcome 7: Creating a pipeline of opportunities: For the contract workforce, reducing barriers to entry for under-represented groups.

    • Understanding of the issues affecting the development of new skills by target cohort
    • Understanding of the underlying factors affecting improvements to reduce barriers to entry and training schemes for the target cohort(s) related to the contract workforce
    • Other measures to offer development opportunities for the target cohort(s) in the contract workforce
    • Advertising, promotional and outreach activities designed to raise awareness of the offer to reach the target cohort
    • Understanding of issues relating to entering the contract workforce
    • Creation of outreach activities to create a pipeline of employees for the future contract delivery
    • Content of the outreach activity is designed to suit the target cohort
    • Advertising, promotional and outreach activities designed to raise awareness of the offer to reach the target cohort
  • Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.

    Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.

    • Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce
    • Understanding barriers to access to health and social care services or employment opportunities e.g. digital inclusion
    • Inclusive and accessible recruitment practices, development practices and retention policies that support-focused activities including those provided in the Guide for line managers on recruiting, managing and developing which support people with a disability or health condition
    • Actions to invest in the physical and mental health and wellbeing of the contract workforce

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at sales@jaama.co.uk. Tell them what format you need. It will help if you say what assistive technology you use.