Payroll and HR Software and Services
CGI’s Payroll and HR Solutions provides industry agnostic services, solutions, and consultancy. delivering statutory compliance and government terms and conditions. All software is HMRC approved, and includes online documents and mobile app. Bureau/SaaS and managed services, including bespoke services available. Services delivered from the UK. Secure data transfer capability included.
Features
- Software agnostic; ePayfact, IRIS, Oracle, CIPHR, Dynamics 365, SAP, Workday
- Multiple payrolls and pay cycles accommodated
- Configurable pay/grading structures, absence/family pay modules
- Pensions, including PCSPS (and Compendia), LGPS, personal and occupational pensions
- Effective date based calculations, retrospective pay, costings and overtime reassessment
- 5* Service Desk and BACS accredited Payments bureau
- Secure data transfer protocols
- Electronic documents for employees online/mobile app
- Business Intelligence reporting and analytics
- Government agencies, Justice, Policing, Probation, Prisons, Educational, Commercial organisations
Benefits
- Reduce compliance risk; HMRC approved software
- Secure data; ISO27001 (Information Security) and ISO27701 (Privacy Information Management)
- UK based Payroll specialists and support teams; named contacts provided
- Flexible configurable software reduces effort and timescales to deliver changes
- Proven Government payroll delivery capability over 20 years
- Delivery models to complement client requirements, including bespoke needs
- Access to CGI's portfolio of additional services and consultancy
- Automation, Payment Services, Document storage, Reporting and analysis
Pricing
£0.45 to £4.41 a transaction a month
Service documents
Request an accessible format
Framework
G-Cloud 14
Service ID
4 7 1 8 0 5 5 9 1 3 5 1 2 2 9
Contact
CGI
CCS Frameworks Team
Telephone: 08450707765
Email: uk.gen.ccsframeworks@cgi.com
Service scope
- Software add-on or extension
- No
- Cloud deployment model
- Private cloud
- Service constraints
- None
- System requirements
-
- Microsoft Windows
- Microsoft Edge in IE11 compatibility mode
User support
- Email or online ticketing support
- Email or online ticketing
- Support response times
- Response times vary based upon the Priority/Severity of the call in line with agreed service levels during contracted business hours.
- User can manage status and priority of support tickets
- No
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- No
- Onsite support
- Yes, at extra cost
- Support levels
-
CGI operates a ITIL aligned support service covering technical, functional and service requests, a single point of contact for all aspects of the service.
Our UK based payroll teams are on hand to provide direct support.
Support levels vary according to the service being provided. Each engagement is provided with the most effective support mechanism to deliver service excellence to the client.
Additionally, we provide Consultancy services to support the client based on their specific need/want. - Support available to third parties
- Yes
Onboarding and offboarding
- Getting started
-
CGI work with our clients to understand their existing systems, processes and people. Using a methodology developed over many years, we will produce an optimum high level system design and important strategies including data cleansing and migration, testing, training, knowledge transfer, post go-live on-site support (if applicable), support and maintenance services.
During the implementation, deliverables are reviewed against agreed acceptance criteria with additional gate reviews at key milestones.
Our implementation plans are developed using templates that have been created and refined over 40+ years of experience and cover all aspects of the project including:
• Due Diligence (if not carried out during pre-sales)
• Requirements gathering (workshops, specifications etc)
• Business Change Planning
• Communications Planning
• Design (system and processes)
• Build (system and processes)
• Testing
• Data Migration
• Training (both virtual and face-to-face, can be customised for client)
• Cut-over
• Post Go-Live Support (both virtual and face-to-face can be provided as required by the client)
• Handover to live service - Service documentation
- Yes
- Documentation formats
-
- Other
- Other documentation formats
- Standard Microsoft Office formats
- End-of-contract data extraction
- Standard electronic reports and use of reporting tools are available to clients based on service model. Support and bespoke exit data files can also be provided on request from client and subject to agreeing scope and price.
- End-of-contract process
-
When our relationship with a client ends, we will work closely with them to ensure they are offboarded from our systems and services cleanly, in line with their requirements, while maintaining the quality of our service.
Each offboarding is individual to the client, our services are not one size fits all. We will work with the client to create a detailed exit plan that gives assurance that their service will be offboarded safely and securely.
Our objective is to deliver service excellence to the client until the end of the last day of the service.
Using the service
- Web browser interface
- Yes
- Supported browsers
- Microsoft Edge
- Application to install
- No
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
- Mobile service provides employee access to payslips and other payroll/HR documents.
- Service interface
- Yes
- User support accessibility
- None or don’t know
- Description of service interface
-
EPayfact including reporting are accessed by the payroll users via web browser.
External systems, such as HR applications, can interface via flat files or XML using the General Interface Facility, via JSON with the ePayfact API, or via bespoke interfaces.
iPayview can be accessed by all employees via web browser, or Android/iOS app. - Accessibility standards
- None or don’t know
- Description of accessibility
- N/a
- Accessibility testing
- N/a
- API
- Yes
- What users can and can't do using the API
- Our solution can integrate with other systems, including Oracle, CIPHR, Microsoft Dynamics 365 and Workday. The Payroll API uses standard JSON to allow the import of HR data. Additionally, it offers the ability to import temporary adjustments to pay using any combination, of hours, amounts and rates. The API updates the system in real time allowing the user to keep the payroll data as accurate. The API also provides a means of querying the status of imports submitted via the API and their progress and any processing issues. The API utilises the same strong security protocols and protections as the main web application.
- API documentation
- Yes
- API documentation formats
-
- Open API (also known as Swagger)
- Other
- API sandbox or test environment
- Yes
- Customisation available
- No
Scaling
- Independence of resources
-
Our system is designed to scale horizontally and vertically using a modern n-tier architecture.
We use system monitoring tools to ensure there is enough capacity for all clients.
Analytics
- Service usage metrics
- No
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Other security clearance
- Government security clearance
- Up to Developed Vetting (DV)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- United Kingdom
- User control over data storage and processing locations
- No
- Datacentre security standards
- Supplier-defined controls
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- ‘IT Health Check’ performed by a CHECK service provider
- Protecting data at rest
-
- Physical access control, complying with SSAE-16 / ISAE 3402
- Physical access control, complying with another standard
- Other
- Other data at rest protection approach
- SQL server TDE encryption
- Data sanitisation process
- Yes
- Data sanitisation type
- Deleted data can’t be directly accessed
- Equipment disposal approach
- A third-party destruction service
Data importing and exporting
- Data export approach
- Depending on the service model in place, CGI can extract data on a client's behalf or, where the client undertakes the data processing they will be able to extract data directly from the system using reporting or a data dump function.
- Data export formats
-
- CSV
- Other
- Other data export formats
-
- XML
- JSON
- Plain text
- Data import formats
-
- CSV
- Other
- Other data import formats
-
- Through the predefined Excel template
- XML
- JSON
- Plain text
- Using data entry screens
Data-in-transit protection
- Data protection between buyer and supplier networks
- TLS (version 1.2 or above)
- Data protection within supplier network
- TLS (version 1.2 or above)
Availability and resilience
- Guaranteed availability
-
The Payroll System availability is at least 97% during System Core Hours.
Service Levels apply to the period between 08:00 to 18:00 Monday to Friday excluding Public holidays in England and Wales (“System Core Hours”).
The standard Service desk offers a service level of 100% availability during Helpdesk Core Hours. - Approach to resilience
-
Our data centres are ISO27001 certified and full disaster recovery and business continuity plans are in place.
The service is delivered by multiple servers for each role (ie web servers, SQL servers). The hosting platform has built in redundancy (multiple VM hosts, data on resilient storage).
Data and server images are replicated to secondary data centre for failover in DR scenario. - Outage reporting
- Infrastructure monitoring software is in place to detects failures and raises tickets directly with service desk for investigation.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Public key authentication (including by TLS client certificate)
- Username or password
- Access restrictions in management interfaces and support channels
-
Users must be connected to the CGI Network.
Users must connect over a dedicated management VPN.
Users can only access management interfaces with a separate, privileged account.
Users authenticate to the servers using their username and password. The password has to be sufficiently strong and contain at least 14 characters.
The servers are located in physically secure data centres with strict access control to data halls and the racks housing the servers. - Access restriction testing frequency
- At least once a year
- Management access authentication
-
- Public key authentication (including by TLS client certificate)
- Dedicated link (for example VPN)
- Username or password
Audit information for users
- Access to user activity audit information
- Users have access to real-time audit information
- How long user audit data is stored for
- At least 12 months
- Access to supplier activity audit information
- Users have access to real-time audit information
- How long supplier audit data is stored for
- At least 12 months
- How long system logs are stored for
- At least 12 months
Standards and certifications
- ISO/IEC 27001 certification
- Yes
- Who accredited the ISO/IEC 27001
- Intertek Certification Limited
- ISO/IEC 27001 accreditation date
- 28/03/2024
- What the ISO/IEC 27001 doesn’t cover
-
Nothing. The certification covers "The provision of outsourcing, project and consultancy services including
development and delivery activities plus the management of people,
technologies and physical security." - ISO 28000:2007 certification
- No
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Cyber essentials plus
- Yes
- Other security certifications
- Yes
- Any other security certifications
-
- ISO27701 - Data Privacy Management
- ISO22301 - Business Continuity Management
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
-
- ISO/IEC 27001
- Other
- Other security governance standards
- Application of NCSC Cloud Guidance
- Information security policies and processes
-
CGI has a series of security, integrity, and privacy policies and best practices which relate to facility and personnel security to protect client data.
These include:
• Global Privacy and Data Protection Policy
• Member Commitment to the Code of Ethics and Business Conduct
• General Office Security
• Facility Design and Construction Standards
• Third Party Access Standards
Other operational standards include:
• Network Security Standards
• Access Control Standards
• Password Security Standards
• Malicious Code Protection Standards
• Database Security Standards
• Information handling Standards
Within CGI, compliance and audit activities are performed at multiple levels to ensure our stringent security processes are being followed.
• Self-audit processes (automated and manual) are put in place to measure the effectiveness of controls and verify that security requirements have been met at the business unit level.
• Enterprise Security performs periodic assessment/review of security controls within the company.
• CGI Internal Audit performs security audits based on enterprise risks.
• CGI Corporate Security Policy establishes the baseline security rules to protect the assets of CGI and our clients.
• External auditors assess CGI for SOX compliancy and 5970/SAS 70 audits.
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
-
Our configuration and change management are based on ITIL.
A Change is raised as a result of an incident or problem or addition to the product, Impact Assessed by engineer, Technical Authority given by SME, approved for implementation by Change advisory Board including Technical Design Authority, Service delivery manager and Applications Support. - Vulnerability management type
- Supplier-defined controls
- Vulnerability management approach
-
Systems are regularly patched - only tested patches are applied.
Should a high risk vulnerability be discovered and a patch released out of cycle then it is applied assuming it passes testing.
Systems undergo an annual CHECK Penetration Test and the observations are addressed. - Protective monitoring type
- Conforms to a recognised standard, for example CSA CCM v3.0 or SSAE-16 / ISAE 3402
- Protective monitoring approach
-
CGI SOC is utilised. This gives protective monitoring that is GPG13 compliant as well as 24x7 monitoring.
Should a security event be triggered it is given a severity rating. Should the rating be high enough then Management is immediately notified as well as the CGI Control Bridge. Management will then take advice as to the course of action to take.
Other less severe alerts are emailed to Management. There are monthly meetings between Management and the SOC to examine trends. - Incident management type
- Conforms to a recognised standard, for example, CSA CCM v3.0 or ISO/IEC 27035:2011 or SSAE-16 / ISAE 3402
- Incident management approach
-
Anybody can raise an Incident with the CGI Service Desk. It is then given a priority (1-4).
There then follows 6 phases as follows:
• Detection
• Analysis
• Confinement/Containment
• Eradication/resolution
• Recovery
• Post Incident
Secure development
- Approach to secure software development best practice
- Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v3.0)
Public sector networks
- Connection to public sector networks
- No
Social Value
- Social Value
-
Social Value
- Fighting climate change
- Tackling economic inequality
- Equal opportunity
- Wellbeing
Fighting climate change
As a member of the Government Digital Sustainability Alliance, CGI leads others to protect and improve the health of our planet.
CGI in the UK has committed to achieve net zero by 2026, based on Science Based Targets (SBTs), achieving an 84% reduction in emissions across our operations from our 2019 baseline. We will use our Carbon Impact Tool to identify and track contracting body contract associated emissions, building these into our net zero plans to reduce any negative environmental impacts of contracts.
We have extended our climate change commitment into our supply chain such that 50% of our suppliers, by spend, will have set their own SBTs to reduce their climate impact by 2026. This will apply to suppliers we engage to support the delivery of call-off contracts. We are supporting suppliers through quarterly net zero knowledge sharing webinars. So far 23% of our suppliers, by spend, have set SBTs.
Our environmental engagement programme 'No Planet B' influences CGI members, clients, suppliers and communities to support environmental protection and improvement. We achieve this through activities such as litter picking and our tree and hedge planting programme where, together with clients and suppliers we have planted 19,500+ UK native trees. Our members partner with clients and suppliers on tree-planting days. We will invite contracting bodies and their ecosystem partners to participate in such activities, connecting them with the environment and increasing protection and enhancement awareness.
CGI's UN-supported research programme, Sustainability Exploration Environmental Data Science (SEEDS), brings organisations, academics and experts together to collaboratively devise/deliver environmental solutions. SEEDS is accelerating efforts to address climate change by researching climate mitigation solutions and waste reduction.
We will continue our partnerships with charities and Social Enterprises, including Canal and River Trust to mobilise action on environmental protection objectives through collaborating with local communities.Tackling economic inequality
CGI prides itself on making positive impacts on the communities where we live and work throughout the UK, mirroring the Government’s levelling-up agenda. We are growing and diversifying our supply chains, recognising the benefits this brings to our clients, including offering better value for money and providing expertise and knowledge that promotes and delivers innovative solutions.
We will continue to provide new employment and training opportunities including professional, graduate and apprenticeships, ensuring STEM careers are accessible for all. To create new skills in the IT industry, we offer a range of apprenticeships and partner with several universities to deliver our Technology Industry Gold accredited Degree Apprenticeships.
We support social enterprises including Breakthrough, providing mentoring and interview skills to prison leavers, enabling them to become work-ready. We will continue to inspire the next generation of IT professionals through our STEM camps, held across the UK in partnership with underserved schools and communities. Our CGI Young Dreamers programme works in partnership with government clients to support social mobility by broadening the future career prospects of students from underserved backgrounds.
CGI supports the Government’s priority to grow and diversify supply chains by providing opportunities for smaller organisations to work with us in delivering key solutions to our clients. Since 2016 we have provided opportunities for over 600 SMEs. We are signatories of the Prompt Payment Code. Throughout our engagements, any change control will include a check on potential inclusion of SME, Social Enterprises or new businesses. This will, where appropriate, include advertising opportunities on Contracts Finder and Find a Tender. We also welcome input from our clients, as they often have valuable insight into supplier offerings.
For transparency, we will report on the number, value and proportion of contract spend being undertaken by SMEs and Social Enterprises per call-off contract, to contracting bodies.Equal opportunity
CGI is an Equal Opportunity Employer. We commit to:
• Continuing to measure and reduce our Gender and Ethnicity Pay Gaps
• Publishing our Voluntary Reporting Framework on disability, mental health and wellbeing
• Inclusive and accessible recruitment practices
• Investing in training and progression.
CGI UK is closing its gender and ethnicity pay gaps year-on-year. Our mean gender pay gap is 6.8%, compared to 8% in 2021, surpassing the technology industry’s gender pay gap of 16%. Our mean ethnicity pay gap is 6.9%.
CGI is a Disability Confident Employer. Through recruitment, onboarding and development, we create an environment that enables members with disabilities to flourish. With a strong disability network, accessibility support and leadership commitment, we are determined that the projects we work on benefit from all talents and insights.
We will continue our partnership with Breakthrough, a social enterprise equipping prison leavers with skills to succeed in a long-term career within the technology industry. CGI supports this by hosting skills days at our offices covering mock interviews, presentation skills and public speaking.
Our inclusive and accessible recruitment practices encompass advertising vacancies within specialist communities, providing equal opportunities for underrepresented groups, and accommodating adjustments including additional assessment time and physical adjustments. We will promote our vacancies with communities including myGWork, a networking hub for LGBTQ+ professionals, and Evenbreak, a disability job board.
CGI invests in annual training that aligns with existing and emerging technologies. Our comprehensive learning and development platform provides members with learning pathways leading to certified qualifications. We will encourage rotations and secondments across industry sectors to upskill our members.
We continually review and audit our recruitment and supply chain practices to ensure our Modern Slavery commitment is delivered in practice. We will continue to instruct all CGI UK members to follow our Modern Slavery Policy.Wellbeing
Health and wellbeing are critical to the success of our members and organisation. Therefore, we are committed to fostering a health-focused environment where all members can thrive personally and professionally. However, wellbeing is not an issue exclusively concerning our business; we are equally committed to supporting the wellbeing of the communities in which we operate. We achieve this by:
• Continually investing in programmes for our workforce, including ‘Oxygen’, our wellbeing centre of expertise, our 24/7/365 Member Assistance Programme, physical wellbeing activities and Workplace Adjustments.
• Extending health and wellbeing initiatives with our clients and suppliers.
• Promoting social wellbeing for local communities to support physical and mental health.
CGI is a signatory of 'The Mental Health at Work Commitment'. We will continue to invest in training to expand upon the 300 plus UK members who are certified Mental Health First Aiders. These members have developed a strong support network for their colleagues.
We will continue to invite our clients suppliers and communities to participate in initiatives that encourage the improvement of health and wellbeing. Examples include physical movement challenges and delivering knowledge-sharing events on health and wellbeing topics such as menopause and mental health in young professionals.
CGI funds a minimum of one volunteering day per annum for each member to support local initiatives or charities, making a significant difference to the communities in which we live and work.
We collaborate with our clients and suppliers to identify opportunities to support the wellbeing of local communities. An example of this is our kit sponsorship for local community groups and sports clubs. With a track record of aiding over a thousand different groups, our programme promotes connection, physical activity, teamwork, and community cohesion. This not only benefits individuals directly involved but also contributes to the broader community’s health and wellbeing.
Pricing
- Price
- £0.45 to £4.41 a transaction a month
- Discount for educational organisations
- No
- Free trial available
- No