SureScore Corporate Due Diligence
Corporate due diligence service that assesses organisations using automated data checks, risk scoring and adverse intelligence to identify fraud, financial crime and compliance risks. Supports supplier onboarding, grant assurance, procurement checks and ongoing monitoring for public sector and regulated organisations.
Features
- Automated corporate identity and structure checks
- Risk scoring across fraud and financial crime indicators
- Analysis of directors, ownership and control
- Adverse media and sanctions screening
- Configurable risk rules and thresholds
- Continuous or periodic monitoring options
- Secure API integration with buyer systems
- Audit logs and decision traceability
- Cloud-hosted SaaS platform
- Scalable processing for high-volume checks
Benefits
- Identify high-risk organisations quickly
- Reduce manual due diligence effort
- Improve fraud and financial crime detection
- Support procurement and grant assurance
- Enable consistent, repeatable risk decisions
- Integrate easily with existing workflows
- Strengthen regulatory compliance
- Improve auditability and transparency
- Reduce onboarding and approval delays
- Support ongoing supplier monitoring
Pricing
- Education pricing available
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
4 9 6 8 8 7 5 3 3 7 1 6 9 6 6
Contact
SureCert
Ian Savage
Telephone: 07515 816158
Email: ian@surecert.com
About your service
- Service categories
-
Applications
Enterprise resource management
- Procurement
- Project and portfolio management
Financial
- Treasury and Risk Management Applications
- Multi cloud support
- No
Service scope
- Software add-on or extension
- Yes, but can also be used as a standalone service
- What software services is the service an extension to
- The service integrates with buyer systems including procurement platforms, grant management systems, CRM systems, case management tools and internal risk platforms via secure APIs. It is commonly used alongside identity or document verification services but does not require any other SureCert services to operate.
- Cloud deployment model
- Public cloud
- Service constraints
- The service requires an internet connection and access via a supported web browser or API. Certain verification checks depend on the availability of third-party data sources, which may occasionally impact response times. Planned maintenance is scheduled outside core business hours where possible and communicated in advance. The service does not operate offline and requires users to provide suitable data, documents and images for verification.
- System requirements
-
- Modern web browser with JavaScript enabled
- Reliable internet connection
- HTTPS connectivity for secure access
- Device capable of capturing identity documents and images
- Secure email access for notifications
- API access requires HTTPS and authentication credentials
- Ability to upload images and documents
- TLS-supported network environment
- Role-based user access configured by buyer
- No local software installation required
User support
- Email or online ticketing support
- Yes, at extra cost
- Support response times
- Support requests are acknowledged within one business day. Response times vary based on issue severity, with higher-priority issues responded to more quickly. Support is provided during standard business hours, Monday to Friday. Weekend and public holiday support is not standard but may be available by prior agreement.
- User can manage status and priority of support tickets
- Yes
- Online ticketing support accessibility
- None or don’t know
- Phone support
- No
- Web chat support
- No
- Onsite support
- Yes, at extra cost
- Support levels
-
Support levels
SureCert provides structured support levels designed to meet the needs of public sector and regulated organisations.
Standard Support is included as part of the service and provides access to email/ticketing and phone support during UK business hours (9am–5pm, Monday to Friday). Support requests are prioritised by severity, with higher-impact issues responded to first.
Enhanced Support may be provided by agreement and at additional cost. This can include extended support hours, faster response times, increased support capacity during critical periods, and additional implementation or configuration support.
Onsite Support is available at extra cost where required, for example for onboarding, integration workshops, assurance activities or stakeholder sessions.
A dedicated technical contact or account manager may be assigned for larger contracts or complex integrations. Where appropriate, access to a cloud support engineer is provided to support technical onboarding, API integration and operational queries.
Support arrangements and costs are agreed contractually at call-off stage to ensure they are proportionate to the scope and risk of the service. - Support available to third parties
- Yes
Onboarding and offboarding
- Getting started
-
Buyers are supported through a structured onboarding process tailored to their delivery model. This includes remote onboarding sessions, configuration of verification workflows, user access setup, and API credential provisioning where required.
Users are supported with online documentation, integration guides, and step-by-step configuration materials. Where the service is accessed via API, technical support is provided to assist with integration and testing, including access to a sandbox environment.
Training is delivered remotely via online sessions and walkthroughs, with follow-up support available through email and ticketing. Onsite onboarding or training can be provided at additional cost where required.
This approach ensures buyers can begin using the service quickly, securely and in line with their operational and compliance requirements. - Service documentation
- Yes
- Documentation formats
-
- HTML
- End-of-contract data extraction
-
At the end of the contract, buyers can request extraction of their data through a managed offboarding process. Data is exported securely in structured, commonly used formats suitable for reuse or transfer to another system.
For API-integrated customers, data can be extracted via secure API endpoints where appropriate. For hosted services, exports are provided through secure file transfer.
Data extraction is carried out in accordance with UK GDPR requirements, ensuring confidentiality, integrity and secure handling of personal data. Buyers are supported throughout the process to ensure data is complete and usable prior to service termination. - End-of-contract process
-
At the end of the contract, a controlled offboarding process is followed. Buyer access to the service is disabled following confirmation of contract end. Where requested, buyer data is securely extracted and provided as part of the contract price.
Following confirmation that data extraction has been completed, remaining customer data is securely deleted in line with documented retention schedules, UK GDPR obligations and security policies.
Standard offboarding activities, including account closure and secure data deletion, are included within the contract price. Additional support, such as bespoke data extracts, extended retention periods, or onsite assistance, can be provided at an additional cost where required and agreed in advance. - Documentation accessibility standard
- None or don’t know
- How the documentation is accessible
- Our documentation has been developed with recognised accessibility and usability best practices in mind and reflects a good-faith effort to align with commonly accepted industry standards. Content structure, formatting, and language have been designed to promote clarity, consistency, and ease of use across a broad audience. While these practices are informed by widely adopted guidelines, the documentation has not been formally evaluated or certified against any specific external standard, such as WCAG. As a result, conformity should be understood as indicative rather than verified, and ongoing review and improvement may be required as formal testing or validation is undertaken.
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Application to install
- No
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
- It is an API and it will function the same on mobile and desktop.
- Service interface
- Yes
- User support accessibility
- None or don’t know
- Description of service interface
- The service also exposes RESTful APIs to integrate corporate due diligence directly into existing buyer systems, portals and digital services.
- Accessibility standards
- None or don’t know
- Description of accessibility
- The service is not a user interface, it is an API that can be configured by the client to ensure it meets accessibility standards.
- Accessibility testing
-
While not directly relevant to the API but when it has been delivered as part of previous solutions it meets the following:
Accessibility has been considered throughout the design and development of the service interface.
The platform is designed in line with WCAG 2.2 AA principles, including keyboard navigation support, screen reader compatibility, sufficient colour contrast, clear labelling, and logical focus order.
Testing includes internal accessibility reviews, browser-based accessibility tooling, and validation using screen readers and keyboard-only navigation.
User feedback from public sector and regulated-sector deployments has informed iterative improvements to usability and accessibility, including simplifying user journeys and reducing cognitive load.
Where required, accessibility considerations are incorporated into buyer-specific configurations and integrations to ensure end-user journeys remain inclusive and accessible. - API
- Yes
- What users can and can't do using the API
-
Users can integrate SureCert’s services into their own systems using secure RESTful APIs. Through the API, users can:
• Configure verification workflows (for example identity verification, document checks, proof of address and corporate due diligence)
• Submit identity, document and organisation data for verification
• Trigger and monitor verification processes in real time
• Retrieve verification results, risk indicators and audit data
• Manage API keys and access permissions
• Integrate verification outcomes into downstream systems and decision workflows
Changes to workflows, thresholds and integrations can be managed via the API or in conjunction with SureCert’s configuration support.
The API does not allow users to modify core verification algorithms, third-party data sources or security controls. Certain configuration changes (for example onboarding new data sources or bespoke risk rules) may require SureCert support and governance approval to ensure compliance and data protection. - API documentation
- Yes
- API documentation formats
- Open API (also known as Swagger)
- API sandbox or test environment
- Yes
- Customisation available
- Yes
- Description of customisation
-
Buyers can customise the service through configuration and integration options.
Customisable elements include:
• Verification workflows (e.g. identity checks, document types, proof of address, corporate due diligence)
• Rules and thresholds applied to verification outcomes and risk indicators
• User journeys (hosted verification journeys or embedded journeys via API)
• Integration with existing systems using APIs (e.g. case management, CRM or grant platforms)
• Branding elements within user-facing verification flows where required
Customisation is carried out via:
• Administrative configuration within the service interface
• Secure APIs and configuration settings documented for technical teams
Customisation can be performed by:
• Authorised buyer administrators through the service interface
• Buyer technical teams or approved partners using the API
All customisation is configuration-based and supported within the standard SaaS offering, ensuring maintainability, security and compliance with public sector requirements.
Scaling
- Independence of resources
- The service is built on a scalable, multi-tenant cloud architecture with logical separation between customers. Resources are monitored and managed dynamically to ensure that increases in demand from one user do not adversely affect the performance or availability experienced by others. Capacity management, performance monitoring and automated scaling controls are used to maintain consistent service levels across all users.
Analytics
- Service usage metrics
- Yes
- Metrics types
-
The service provides usage and operational metrics including verification volumes, success and failure rates, processing times, and status outcomes. Audit and activity logs are available to support compliance, assurance and reporting requirements. Metrics can be accessed for operational monitoring and service performance review, subject to user permissions and data protection controls.
Reporting can be provided on a buyer-defined basis, for example monthly, quarterly or on request, depending on operational and governance requirements. Metrics may be accessed via reports or provided to support service reviews, assurance activities and contract management. - Reporting types
- Reports on request
- Resource tagging
- No
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Reseller providing extra features and support
- Organisation whose services are being resold
- Experian
Staff security
- Staff security clearance
- Other security clearance
- Government security clearance
- Developed Vetting (DV)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- United Kingdom
- User control over data storage and processing locations
- No
- Datacentre security standards
- Complies with a recognised standard (for example CSA CCM version 4.0)
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- NCSC approved service provider
- Protecting data at rest
-
- Physical access control, complying with CSA CCM v4.0
- Physical access control, complying with SSAE-18 / ISAE 3402
- Encryption of all physical media
- Data sanitisation process
- Yes
- Equipment disposal approach
- Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
- Data sanitisation type
-
- Deleted data can’t be directly accessed / Cryptographic Erasure
- Data Erasure
- Explicit overwriting of storage before reallocation / Secure Erase
Data importing and exporting
- Data export approach
- Users can export their data through a managed and secure process. Data exports are requested via support channels or accessed through secure API endpoints where applicable. Exports are delivered using secure file transfer methods and provided in agreed, commonly used formats to ensure usability and portability. All data exports are handled in accordance with UK GDPR and information security requirements.
- Data export formats
-
- CSV
- Other
- Other data export formats
- JSON (via API exports)
- Data import formats
-
- CSV
- Other
- Other data import formats
- JSON (via API integration)
Data-in-transit protection
- Data protection between buyer and supplier networks
- TLS (version 1.2 or above)
- Data protection within supplier network
- TLS (version 1.2 or above)
Availability and resilience
- Guaranteed availability
-
The service is designed to operate with high availability using resilient cloud infrastructure and proactive monitoring. Availability targets and any applicable service levels are defined contractually at Call-Off stage, based on the buyer’s requirements and the agreed service configuration.
Where availability service levels are agreed, service credits may be applied if availability falls below the agreed threshold within a defined measurement period. Service credits are calculated as a proportion of the affected service charges and are applied in accordance with the terms set out in the Call-Off Contract or service schedule.
Planned maintenance is managed to minimise disruption and, where possible, carried out outside of core service hours with advance notice provided. Availability performance is monitored continuously and incidents are managed through defined incident and escalation processes. - Approach to resilience
-
The service is designed using resilient cloud architecture to support continuous operation and rapid recovery from failure. Critical components are deployed with redundancy and monitored continuously to detect and respond to issues quickly. Automated scaling and capacity management help ensure performance during periods of increased demand.
The underlying datacentre infrastructure is provided by third-party cloud providers operating resilient facilities with redundant power, networking and environmental controls. Data is protected through regular backups and recovery processes to support business continuity.
Resilience arrangements, including detailed architecture and disaster recovery processes, are documented and can be provided to buyers on request where required. The service is regularly reviewed and tested to ensure resilience controls remain effective and aligned with operational and security requirements. - Outage reporting
-
Service outages and incidents are managed through defined incident management processes. Where a service disruption occurs, affected buyers are notified via email and support ticket updates. Incident status and progress are tracked internally and communicated to buyers as appropriate.
Where required, outage information and status updates can be shared directly with buyers on request. Post-incident reports are produced for significant incidents, outlining impact, root cause and corrective actions taken.
The service does not rely on a public status dashboard by default, but incident information can be provided through agreed communication channels to ensure buyers are informed in a timely and transparent manner.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Username or password
- Other
- Other user authentication
- OAuth 2.0 compliant mechanism for accessing the API.
- Access restrictions in management interfaces and support channels
- Access to management interfaces and support channels is restricted using role-based access controls (RBAC). Only authorised staff with appropriate job roles are granted access to administrative functions or support tools. Access is provisioned on a least-privilege basis and reviewed regularly. Management and support access is logged and monitored, and credentials are revoked promptly when staff change roles or leave the organisation. Support systems are accessible only to authenticated users via secure internal networks and approved devices.
- Access restriction testing frequency
- At least every 6 months
- Management access authentication
-
- Username or password
- Other
- Description of management access authentication
- OAuth 2.0
Audit information for users
- Access to user activity audit information
- Users contact the support team to get audit information
- How long user audit data is stored for
- User-defined
- Access to supplier activity audit information
- Users contact the support team to get audit information
- How long supplier audit data is stored for
- User-defined
- How long system logs are stored for
- At least 12 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
- Other
- Other security governance standards
- Cyber Essentials
- Information security policies and processes
-
The organisation maintains documented information security policies and procedures covering areas including access control, data protection, incident management, vulnerability management, secure development, business continuity and data retention. These policies are aligned with recognised best practice and support compliance with UK GDPR and Cyber Essentials requirements.
Overall responsibility for information security sits at board level, with day-to-day implementation and oversight delegated to senior technical leadership. Clear reporting and escalation routes are in place for security risks and incidents, ensuring issues are reviewed, managed and addressed promptly.
Policies are communicated to relevant staff and contractors, supported by role-based access controls and security awareness activities. Compliance with policies is monitored through regular reviews, audits, vulnerability assessments and incident reporting processes. Policies and procedures are reviewed periodically and updated as required to reflect changes in risk, technology and regulatory requirements. - Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
- Configuration items and service components are tracked throughout their lifecycle using controlled versioning and configuration management tools. Changes are logged, reviewed and approved prior to implementation. Each change is assessed for potential security, performance and operational impact, with higher-risk changes subject to additional review and testing. Changes are tested in non-production environments before deployment, and rollback procedures are in place to minimise risk. Access to make configuration changes is restricted to authorised personnel and monitored to ensure accountability.
- Vulnerability management type
- Supplier-defined controls
- Vulnerability management approach
- Potential threats are identified through regular vulnerability scanning, penetration testing and security monitoring. Vulnerabilities are assessed based on risk, severity and potential impact to the service. Patches and mitigations are prioritised and deployed promptly, with critical issues addressed as a priority. Threat intelligence is informed by vendor advisories, security bulletins, cloud provider notifications and independent penetration testing findings. Remediation actions are tracked to completion and reviewed to reduce the likelihood of recurrence.
- Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
- System activity and security events are logged and monitored to identify potential compromises, including unauthorised access attempts or anomalous behaviour. Alerts are reviewed by authorised personnel and investigated promptly. Where a potential compromise is identified, incident response procedures are initiated to contain, assess and remediate the issue. Response times are prioritised based on severity, with critical incidents escalated immediately. Monitoring outputs are retained to support investigation, audit and continuous improvement.
- Incident management type
- Supplier-defined controls
- Incident management approach
- The organisation operates documented incident management processes covering common security and operational events. Incidents can be reported by users through email or the online support ticketing system. Incidents are logged, categorised by severity, and escalated according to defined procedures. Buyers are kept informed of relevant incidents through agreed communication channels, including ticket updates and email notifications. Incident reports are provided for significant incidents, outlining impact, actions taken and any remedial or preventative measures implemented.
- Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- Yes
- Free trial available
- No
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 5%
- Between £500,001 and £1,000,000
- 5%
- Between £1,000,001 and £2,500,000
- 10%
- Between £2,500,001 and £5,000,000
- 10%
- Over £5,000,001
- 15%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- No
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- No
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- Ea4ba1b0-9a88-47bc-833d-38ab1bcfb620
- Cyber essentials plus
- No
- Cyber Essentials Alternative
- None of the criteria
- Other security certifications
- No
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
- Activities that support an environment where staff are educated about, and feel empowered to, address their physical wellbeing
- Activities that support an environment where staff are educated about and feel empowered to report and address bullying and harassment
- Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
- Understanding of in-work progression issues affecting the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors
- Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.
- Understanding of employment and relevant skills issues, and of the education and training issues relating to the contract. Illustrative examples: demographics, skills shortages, new opportunities in high growth sectors, geographic/local community and skills/employment challenges
- Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
- Activities to support relevant sector related skills growth and sustainability in the contract workforce. Illustrative examples: careers talks, curriculum support, literacy support, safety talks and volunteering
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 3: Resilient, innovative and flexible supply chains: Support economic growth through enabling resilient businesses, opportunities for small businesses and voluntary, community and social enterprises
- Understanding of local demographics, needs and opportunities for the co-design of the goods, services and works to be delivered under the contract
- Methods for engaging with different parts of the community (including the education system and charities representing the community) and how communities come together to inform decisions, strategy and projects to leave a positive legacy for future generations
- Measures to involve local stakeholders and/or users in design (e.g. in the design of services, systems, products or buildings)
- Plans to respond flexibly and adapt approaches to community engagement and initiatives
-
Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero
Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.
- Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
- Delivery of additional environmental benefits through the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
- Understanding of how to influence staff, suppliers, customers, communities and/or any other appropriate stakeholders through the delivery of the contract to support climate and nature protection and improvement
-
Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain
Policy Outcome 6: Employment and training: For those who face barriers to employment
- Understanding of the issues affecting inequality in employment, skills and pay in the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors. Measures to tackle inequality in employment, skills and pay in the contract workforce
- Inclusive and accessible development practices, including guidance for line managers on recruiting, managing and developing people with a disability or health condition
-
Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.
Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.
- Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce
- Understanding barriers to access to health and social care services or employment opportunities e.g. digital inclusion
-