Skills and Competencies Survey
People are our most expensive resource, yet we are often unaware of what they can truly deliver. Blackthorn's skills discovery tool can perform an objective assessment of skills and competencies within the workforce, providing leadership with a clear indication of gaps in the collective capability. UK hosted up to OFFICIAL.
Features
- Qualified and objective assessment of your organisation's skills and competencies
- Online, self-assessment of your people
- Visual indication of skills and capability against expectation
- Gaps and weaknesses easily identifiable
- Customisable question-sets to match business interests and needs
- Flexibility to conduct assessments in multiple geographies
- Intuitive, clear user interface with user configured reports and dashboards
- Routing through questions based on earlier answers.
Benefits
- Clear understanding of future training / recruitment needs
- Re-use of question-sets across skills surveys
- Online (24x7) access to survey findings
- Full audit trail ensuring users fully accountable for their actions
- Secure storage of data with channel encryption on remote links
- Clean, intuitive user interface reducing any training requirements
- Wide range of supported platforms e.g. tablet, laptop, desktop.
Pricing
- Free trial available
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
5 0 5 0 7 4 0 0 5 7 8 6 0 3 3
Contact
BLACKTHORN GRC LIMITED
Ian Hardman
Telephone: 02081237989
Email: sales@blackthorn.com
About your service
- Service categories
-
Applications
Production and operations
- Production and grid management
- Other operations
Service industry and public sector operations
- Healthcare
- Education
- Public Order and Safety
- Police
- Defence
- Social Security Administration
- Adult Social Care
- Children's Social Care
- Other
- Multi cloud support
- No
Service scope
- Software add-on or extension
- No
- Cloud deployment model
-
- Public cloud
- Private cloud
- Hybrid cloud
- Service constraints
- Cloud infrastructure requires regular security patching to eliminate zero day vulnerabilities. Some patching activities will result in the suspension of services for a period of time, no more than a few minutes a month. We work with customers to identify the best time for such maintenance activity.
- System requirements
-
- Browser (minimum Windows 7, IE9 or chrome)
- Suggested connection speed of 1Mbps per concurrent user
- SSL Certificate
User support
- Email or online ticketing support
- Yes, at extra cost
- Support response times
- Support requests made by email or online are acknowledged within 30 minutes. Our acknowledgement will include a preliminary 'severity classification' based on impact to your operations: P1 (major business impact) through P4 (no discernible business impact). Initial (detailed) investigation response times and full resolution response times are tiered, based on impact (P1 to P4). Please see Service Description for more information. Support is administer 9 / 5 or 24 / 7 depending on support package purchased. If on 24 / 7 support, the above response times will be available at weekends.
- User can manage status and priority of support tickets
- Yes
- Online ticketing support accessibility
- WCAG 2.2 AA
- Phone support
- Yes
- Phone support availability
- 24 hours, 7 days a week
- Web chat support
- No
- Onsite support
- Yes, at extra cost
- Support levels
-
Our Silver support level offers our clients access to support 9am-5pm.
The cost of Silver support varies according to user numbers and starts from £600 a month.
For clients who need on call 24/7 support, we offer a Gold level support package for P1 (business critical) and P2 (business significant) support issues. This provides direct access to technical support engineers as and when need and enables maintenance windows out-of-hours.
The cost of Gold support varies according to user numbers and starts from £6,600 a month.
Further details can be found in the Service Definition and Pricing Guide documentation. - Support available to third parties
- Yes
Onboarding and offboarding
- Getting started
-
Self-service, on-line training is provided as standard. Users are provided with a URL, (to the application), training account ID and temporary password. The URL is set to point to a dedicated training system, that has been pre-configured for training purposes.
Training material is provided to guide participants.
Classroom training, either using generic materials or bespoke packages developed in partnership with the customer, is available at additional cost - Service documentation
- No
- End-of-contract data extraction
- Users are able to export the underlying database in CSV format. Information can be selectively extracted using Blackthorn's reporting functionality and user configurable filters. Additionally, a backup of the application database (MS SQL) is supplied in an unencrypted format.
- End-of-contract process
-
A backup of the MS SQL Database will be provided as part of off-boarding and at no additional cost.
Should assistance be required to migrate the database and content to a new application or platform, we will assist. Such assistance, available under Lot 3 is at additional cost if above and beyond the scope of our standard off-boarding service. For example, the provisioning of a database and content in a mutually agreed format is free of charge. Mapping data from Blackthorn's database constructs to a third-party's data constructs will incur a charge.
Servers used to deliver the retiring service (production, development, test, acceptance etc.) will be securely wiped and repurposed.
Any legacy backups not retained by the customer will be identified and securely wiped.
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Application to install
- No
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
-
Our fully functioning web application is accessible from both mobile devices and desktops but there must be stable network connection. Screen size is also an important consideration as our web pages are designed for use on screens of at least 8.9” diagonal.
Our IOS/Android/Windows App caters for off-line operation and provides full support for audit and survey functions, case specific information retrieval (if case records downloaded prior to disconnect), and case records update and maintenance. Any changes are replicated to the cloud service when a network connection is re-established. - Service interface
- Yes
- User support accessibility
- WCAG 2.2 AA
- Description of service interface
-
Most aspects of the service are configurable; a separate and dedicated service interface ensures appropriate segregation between normal business activities and system admin activities. Different system administration roles can be defined, and the rights and permissions afforded to these roles adjusted to mirror the customer’s existing hierarchical structures.
As an administrator (permissions allowing), users can configure I/O, workflow, report templates, value ranges, and object types. Importantly, the system admin function allows the right and responsibilities of standard user roles to be defined, and access control to data and case artefacts. Normally access is awarded along team or regional boundaries. - Accessibility standards
- WCAG 2.2 AA
- Accessibility testing
- We have experience of integrating our solutions with assistive technologies such as Dragon. Much of our HTML coding incorporates the ‘tags’ required by assistive technologies to help people with disabilities either access or enter information. Additionally, we have designed into our software features to aid use e.g. improved contrast and visibility for the hard of sight. Our policy to date has been to work with individual users experiencing accessibility problems and to find solutions that meet their specific needs. Incrementally, therefore, we are making our software compatible with applications that aid access but as yet have not achieved 100% coverage. It is our intention to continue with this approach.
- API
- Yes
- What users can and can't do using the API
-
We have a number of API services for consumption by third party applications.
Where Blackthorn functions are supported by an API service, the functions behave and operate as if a user was logged directly onto the application.
API requests must be serviced by a standard user account (not system account) so that there is an auditable history of all actions invoked remotely. The user account can be dedicated to API requests, or an actual user's account can be used. In both cases, the account must be marked for API usage and a separate application key is required. - API documentation
- Yes
- API documentation formats
-
- Open API (also known as Swagger)
- HTML
- API sandbox or test environment
- Yes
- Customisation available
- Yes
- Description of customisation
-
The application has a flexible user interface that allows terminology, workflow, taxonomies, form layouts, surveys, team structures etc. to be tailored to an organisation's individual needs.
A general user account, with appropriate account permissions, can configure dashboards, exports, mail merge reports, surveys etc. using an intuitive, filter based interface.
An administration account, with appropriate account permissions, can configure via the interface workflow, users, teams, taxonomies.
Scaling
- Independence of resources
-
The hosting is dedicated with fixed, predefined allocation of platform resources. This eliminates the possibility of memory bursts and contention by other parties.
Application servers are monitored and alerts automatically sent (to us) when a threshold is breached.
During our frequent service and maintenance reviews we assess performance to see if further resource should be allocated based on projections.
Additionally, the underlying architecture of the service is fully scalable allowing additional hardware (application servers) to be brought online if and when required.
Analytics
- Service usage metrics
- Yes
- Metrics types
- We monitor standard server performance such as you would expect from a hosting organisation. We also monitor the application for response times, license usage, storage, uptime, login failures, password resets etc. These stats are provided during monthly service reviews to ensure SLAs are being met and license usage is not being exceeded.
- Reporting types
-
- API access
- Real-time dashboards
- Regular reports
- Reports on request
- Resource tagging
- Yes
- FOCUS resource tagging
- Yes
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Conforms to BS7858:2019
- Government security clearance
- Developed Vetting (DV)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- United Kingdom
- User control over data storage and processing locations
- Yes
- Datacentre security standards
- Managed by a third party
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- ‘IT Health Check’ performed by a CHECK service provider
- Protecting data at rest
-
- Physical access control, complying with CSA CCM v4.0
- Other
- Other data at rest protection approach
- Data-at-rest encryption is an optional feature. Our service incorporates server side encryption. The keys are auto generated and managed by the application. Once enables, all case information including raw data and uploaded files is encrypted and saved to the database in an encrypted format. The stored information is obfuscated and cannot be accessed by the Cloud Service Provider, or Blackthorn's staff without going through the standard business logic - itself provided by user access and authentication security controls.
- Data sanitisation process
- Yes
- Equipment disposal approach
- Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
- Data sanitisation type
-
- Deleted data can’t be directly accessed / Cryptographic Erasure
- Explicit overwriting of storage before reallocation / Secure Erase
Data importing and exporting
- Data export approach
-
Facilities provided as standard to export data to CSV files.
Filters can be applied to the database to narrow down the data-sets exported at any given time. - Data export formats
- CSV
- Data import formats
-
- CSV
- Other
- Other data import formats
- Email (requires mapping)
Data-in-transit protection
- Data protection between buyer and supplier networks
-
- Private network or public sector network
- TLS (version 1.2 or above)
- Data protection within supplier network
- TLS (version 1.2 or above)
Availability and resilience
- Guaranteed availability
-
We have SLA's defining targets for initial analysis time and resolution time. The targets are a function of the severity of the incident and therefore vary. Only normal working hours count towards the measurement of response times. For example, if an incident was reported one day and not resolved until the next, the over-night non-working hours would not count in the determination of actual response times.
Response times targets for initial analysis and resolution are provided below for different priorities of incident: Priority 1, 30 minutes and 5 hours respectively: Priority 2, 4 working hours and 8 working hours respectively; Priority 3, 1 working day and 3 working days respectively;
Priority 4, 3 working days and 5 working days respectively.
Should we fail to meet these targets for an incident or KPI 3 or more times and customers are awarded service credits:
3 breaches of targets = 1% service credit, 4-5 breaches = 2%, 6-7 breaches = 3%, 8-9 breaches = 4%, 10+ breaches = 5% service credit.
We are also able to provide 24x7 support, fully details are in the accompanying product description documents. - Approach to resilience
-
Our application runs in a virtualized cloud environment. If a virtualised server fails, such as a web server, other web servers within the virtualised environment will take up the load, until a new instance of the failed server can be brought back on line (minutes).
If the primary data centre is lost, real-time data replication to the DR data centre ensure continuity of service with short Recovery Point Times. The DR facility is normally passive and has a Recovery Time Objective (RTO) of less that 4 hours. Within this recovery time, a fully operational mirror of the Production service can be up and running.
Our enhanced offering comprises of multiple production web servers, so in the event one fails, the other can continue. Obviously there are TMGs and IPS units. There is also a DR site which can be used for fail over. - Outage reporting
-
We have monitoring services installed on servers within the Data Centre but outside the main production environment. These monitoring service call API's with the application to determine its health. If the application is non-responsive, the monitor alerts us by email. Our service desk email is continuously monitored by support staff (mostly 24 x 7) to ensure outages are detected soonest and an appropriate recovery plan is executed.
The hosting provider also has monitoring software with real-time dashboards, copies of which are made available during each monthly service review meeting.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Public key authentication (including by TLS client certificate)
- Limited access network (for example PSN)
- Username or password
- Access restrictions in management interfaces and support channels
-
Our cloud service providers' management interfaces authenticate with a minimum of ID and password. 2 Factor authentication is used by suppliers offering environments with enhanced data protection. Additionally, we apply IP addressing restrictions so connections can only be made from know (approved) external devices.
Our management interfaces apply the onion ring principle of security with multiple layers of user authentication including, Bitlocker, Windows (local) authentication, VPN user authentication, RDP session (cloud) authentication. IP addressing restrictions are also applied so that access is only permissible from authorised remote support devices - Access restriction testing frequency
- At least once a year
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Public key authentication (including by TLS client certificate)
- Limited access network (for example PSN)
- Username or password
- Other
- Description of management access authentication
-
Management access is administered and controlled in the same manner as Support Access. There is no distinction. Please see 'Access Restrictions in management interfaces and support channels' above.
All access to our cloud environments is logged and cross-checked against support tickets to verify legitimacy. Auditing is conducted on a monthly basis.
Audit information for users
- Access to user activity audit information
- Users have access to real-time audit information
- How long user audit data is stored for
- At least 12 months
- Access to supplier activity audit information
- Users have access to real-time audit information
- How long supplier audit data is stored for
- At least 12 months
- How long system logs are stored for
- At least 12 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
- ISO/IEC 27001
- Information security policies and processes
-
Blackthorn GRC operates under the auspices of a high-level Information security policy, underpinned by topic-specific policies on subject such as Access Control and Security in Development. People, procedural and technical security control are the embodiment of the policies and supported by guidance documents, checklists and standards that ensure all staff are clear of their responsibilities, understand the threats and risks to information and the channels for reporting concerns. Checklist and automated audit processes are used extensively to monitor the security landscape and ensure security controls are working, e.g. we use protective monitoring in our cloud hosting environments to maintain 24x7 surveillance and immediately report suspicious or unauthorised behaviour.
Staff induction training, Acceptable Use agreements and pre-employment vetting ensure that we have trustworthy staff who are clear about their information security responsibilities.
Vendor security policies ensure that our partners, especially hosting partners, uphold our high standards and have security practices that are commensurate with our own.
Our MD is ultimately responsible for information security, but this responsibility is delegated down to ensure accountability at all levels, effective reporting and oversight. A separate audit activity, reporting to board-level, polices the system to ensures our policies, processes and procedures are being duly upheld. - Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Configuration and change management approach
-
Management approach Our Configuration and Change Management is compliant with ISO 27001.
Change management is applied over the full change life-cycle starting with a detailed account of the change, an impact assessment, and plan of the delivery steps. Change board approval is required at various control gates; the Change Board might include customer representation. Immediately prior to deployment the Change Board reconvenes to reconsider the risks, review the deployment plan, roll-back strategy, and to attest to the testing.
Our CCM process is fully documented, identifying gate keepers and associate controls. - Vulnerability management type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Vulnerability management approach
-
Our Vulnerability Management process is ISO 27001 compliant.
Vulnerability assessments are carried out using automated tools as part of every major code release. Additionally, network vulnerability assessments are conducted to identify any security weaknesses that might have been missed by regular Operating System security patching. The results are reviewed by Blackthorn and weakness mitigated either as part of development, or under full change control.
Operating System patches are deployed automatically via our Windows Server Update Service. Monthly security auditing verifies patch management effectiveness, and identifies any servers that must be restarted to complete installation. Reboots are scheduled with client authority. - Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
-
Threat management and intrusion protection monitoring at the data centre boundary protects against threats at external networks (e.g. internet, PSN, HSCN), perimeter routers and firewalls, the VM Hypervisor, and physical infrastructure. Virtualised machines hosting service applications are protected by Blackthorn's dedicated intrusion protection system looking for suspicious, unusual, or unexpected activity at application, server and virtual network level.
Our hosting provider acknowledges incidents and advises about tests to remediate. Significant incidents are escalated to ourselves, Priority 1 within 30 minutes, priority 2 within 3 hours. Alerts triggered by our PM are investigated immediately and handled within terms of our SLA. - Incident management type
- Supplier-defined controls
- Incident management approach
-
We use an instance of the Blackthorn Case Management Tool to monitor and track security incidents. Each type of incident has its own predefined workflow for coordinating the response activity and mitigating the threat as quickly as possible. Our workflows are optimised to the incident type.
Incidents can be raised through our online web portal, by emailing or phone.
Our monthly Service Management Reviews and associated reporting includes incident details (if any) and metrics showing how well we have performed against our support and remedy response times (as specified in our SLA). Controls and root causes are aligned to ISO27001. - Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Supplier-defined process
Public sector networks
- Connection to public sector networks
- Yes
- Connected networks
-
- Public Services Network (PSN)
- Health and Social Care Network (HSCN)
Pricing
- Discount for educational organisations
- No
- Free trial available
- Yes
- Description of free trial
-
This service is hosted with a commercial service provider and should not be used to run trials with confidential / PM information. All test data should be anonymised before uploading. We do not guarantee the availability of the service.
It includes the full functionality that the production system will have.
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 0%
- Between £500,001 and £1,000,000
- 0%
- Between £1,000,001 and £2,500,000
- 0%
- Between £2,500,001 and £5,000,000
- 0%
- Over £5,000,001
- 0%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- Yes
- Who accredited the ISO/IEC 27001
- BSI Group (British Standards Institute)
- ISO/IEC 27001 accreditation date
- Wednesday 8 April 2020
- What the ISO/IEC 27001 doesn’t cover
-
Our ISO 27001 certification extends to all areas of the business; there are no exclusions.
It covers software engineering, product development and support, cloud service design, and cloud service execution and delivery. Additionally, all related business operations and services such as sales, marketing, finance, HR and IT service management and customer service management. - ISO 28000:2022 certification
- No
- ISO 9001 certification
- No
- Quality management systems (QMS)
- No
- CSA STAR certification
- Yes
- CSA STAR accreditation date
- Friday 19 June 2020
- CSA STAR certification level
- Level 2: CSA STAR Attestation
- What the CSA STAR doesn’t cover
- Only Hosting in MS Azure is covered
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- 5016d77f-9e9d-45ee-ac5b-c12076889076
- Cyber essentials plus
- Yes
- Please provide your Cyber Essentials Plus Certificate Number
- Df410c50-c7b2-47f8-930d-68ec46396bb3
- Other security certifications
- Yes
- Any other security certifications
-
- Cyber Essentials +
- Hosting provider certified to ISO27001/17,18 , ISO 9001
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- New or retained jobs on the contract workforce in the relevant area that meet the criteria set out in MAC 1b, 1c and 1d
- Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
- Plans to engage the contract workforce in deciding the most important workplace issues to address
- Ensuring new workers are informed of their right to join a trade union
- Monitoring of employee engagement rates (by protected characteristic) and, where necessary, the development of actions to ensure all voices are heard across the diversity of the workforce
- Employment contracts that reflect actual hours worked; steps taken to ensure employees understand their contracts and have the ability to review and adjust them if actual hours regularly exceed contracted hours
- Activities that support an environment where staff are educated about, and feel empowered to, address their physical wellbeing
- Activities that support an environment where staff are educated about and feel empowered to report and address bullying and harassment
- Activities to cascade good practice on fair working conditions throughout the supply chain
- Offer a pay and leave entitlement to all eligible staff who become kinship carers, ideally equivalent to statutory adoption pay and leave
- Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
- Entitlement to sick pay for the contract workforce, with provision in place for any staff who do not meet the earnings threshold for statutory sick pay, payment of sick pay from day one of absence and payment of staff on the contract workforce who are off sick a replacement income of 100% of their usual earnings for as long as possible
- Plans for an appropriate income replacement policy for staff who are required to spend time away from work to care for a sick dependent or close relative
- Understanding of in-work progression issues affecting the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors
- Measures to support in-work progression to help people in the contract workforce, to move into higher paid work by developing new skills relevant to the contract
- Support for the contract workforce by providing career advice, and providing opportunities for staff working on the contract with in-work progression career development into known skills shortages or high growth areas
- Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
- Volunteering opportunities for staff
- Understanding of the modern slavery risks and issues affecting the market, industry, sector or country (of origin or of source) relevant to the contract, and the workforce in the supplier’s own organisation and those of its key subcontractors
- Measures to identify, mitigate and manage modern slavery risks relating to the contract and how these will be implemented
- Outline policies and practices to be applied to or put in place for the contract to mitigate and manage modern slavery risks, including: Pre-employment checks, recruitment practices. Workplace conditions, safeguarding plans and processes in place and regular monitoring with relevant groups considered, which may include sampling
- How these flow down the supply chain and are monitored Illustrative examples include reporting, site visits, audits, etc.
- How to ensure business decisions re: price/cost, short lead times, payment timescales do not create modern slavery risks in the supply chain
- How the supplier will work with NGOs, trade unions or other businesses to address modern slavery risk
- Means of influencing staff, suppliers, customers, communities and/or any other appropriate stakeholders with respect to modern slavery risks relating to the contract
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.
- Understanding of employment and relevant skills issues, and of the education and training issues relating to the contract. Illustrative examples: demographics, skills shortages, new opportunities in high growth sectors, geographic/local community and skills/employment challenges
- Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
- Activities to support relevant sector related skills growth and sustainability in the contract workforce. Illustrative examples: careers talks, curriculum support, literacy support, safety talks and volunteering
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 3: Resilient, innovative and flexible supply chains: Support economic growth through enabling resilient businesses, opportunities for small businesses and voluntary, community and social enterprises
- Understanding of the types of businesses in the market and the level of participation by new businesses, entrepreneurs, start-ups, SMEs, VCSEs and mutuals
- Activities that demonstrate a collaborative way to work with a diverse range of businesses as part of the supply chain
- Advertising of supply chain opportunities openly and to ensure they are accessible to a diverse range of businesses, including advertising all subcontracting opportunities on Contracts Finder
- Ensuring accessibility to contracting and subcontracting opportunities for disabled business owners and employees
- Structuring of the supply chain selection process to ensure fairness (e.g. anti-corruption) and encourages participation by a diverse range of businesses, including with regard to new businesses, entrepreneurs, start-ups, SMEs, VCSEs and mutual
- Understanding of local demographics, needs and opportunities for the co-design of the goods, services and works to be delivered under the contract
- Methods for engaging with different parts of the community (including the education system and charities representing the community) and how communities come together to inform decisions, strategy and projects to leave a positive legacy for future generations
- Plans for positive actions with community groups.
- Measures for making facilities used in the delivery of the contract available for community groups, education or training
- Measures to engage users and communities and build relationships to increase community integration build trust and influence how the contract is delivered
- Plans to respond flexibly and adapt approaches to community engagement and initiatives
- Support for community-led initiatives relevant to the contract. Illustrative examples: improving transport links; reducing loneliness; helping with English language proficiency; and facilitating social mixing among people with different backgrounds
- Collaborating with anchor institutions and community groups to make facilities available for education, training or community events
-
Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero
Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.
- Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
- Collaborative ways of working with the supply chain to deliver additional environmental benefits in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
- Delivery of additional environmental benefits through the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
- Understanding of how to influence staff, suppliers, customers, communities and/or any other appropriate stakeholders through the delivery of the contract to support climate and nature protection and improvement
- Activities to reconnect people with the environment and increase awareness of ways to protect and enhance it
-
Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain
Policy Outcome 6: Employment and training: For those who face barriers to employment
- Understanding of employment and skills issues, and of the skills and employment shortages of high growth sectors relating to the contract
- Creation of employment opportunities particularly for those who face barriers to employment, such as prison leavers, care leavers and/or who are located in deprived areas, and for people in industries with known skills shortages or in high growth sectors
- Understanding of the issues affecting the representation of disabled people in the workforce in the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors
- Introducing transparency to pay and reward processes
- Working conditions which promote an inclusive working environment and promote retention and progression
- Other measures to provide equality of opportunity for disabled people and those with health conditions into employment, including becoming a Disability Confident employer and inclusion of supported businesses in the contract supply chain
- Understanding of the issues affecting inequality in employment, skills and pay in the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors. Measures to tackle inequality in employment, skills and pay in the contract workforce
- Inclusive and accessible development practices, including guidance for line managers on recruiting, managing and developing people with a disability or health condition
-
Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain
Policy Outcome 7: Creating a pipeline of opportunities: For the contract workforce, reducing barriers to entry for under-represented groups.
- Understanding of the issues affecting the development of new skills by target cohort
- Understanding of the underlying factors affecting improvements to reduce barriers to entry and training schemes for the target cohort(s) related to the contract workforce
- Other measures to offer development opportunities for the target cohort(s) in the contract workforce
- Advertising, promotional and outreach activities designed to raise awareness of the offer to reach the target cohort
- Understanding of issues relating to entering the contract workforce
- Creation of outreach activities to create a pipeline of employees for the future contract delivery
- Advertising, promotional and outreach activities designed to raise awareness of the offer to reach the target cohort
-
Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.
Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.
- Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce
- Understanding barriers to access to health and social care services or employment opportunities e.g. digital inclusion
- Actions to invest in the physical and mental health and wellbeing of the contract workforce
-