Certa Care Management Software
Certa is a complete digital care management platform that supports person‑centred care planning, intelligent rostering, mobile working and real‑time reporting. It helps providers deliver safe, efficient and compliant services, giving them the tools to evidence CQC requirements and achieve outstanding care quality across their organisation.
Features
- Automated scheduling matches care workers to visits using intelligent allocation
- Person-centred care planning captures individual service user needs and preferences
- Mobile app enables care workers to record visits in real-time
- Client portal keeps service users and families informed and engaged
- Open REST API enables integration with external systems
- Real-time dashboards provide operational insights alongside customisable reports
- Multi-factor authentication ensures secure user access
- Responsive interface works on any device with a modern browser
- Automated financial calculations ensure accurate worker pay and funder billing
- High availability of 99.9% with automated failover and hourly backups
Benefits
- Reduce workload through automated scheduling while ensuring: continuity, preferences, compliance
- Minimise travel costs by optimising routes and reducing journey time
- Increase visibility of service delivery using customisable/ role-specific homescreen dashboards
- Streamline billing processes ensuring accurate invoicing and timely worker payments
- Empower clients with real-time updates and communication via the portal
- Maximise utilisation of contracted hours by identifying gaps in capacity
- Ensure service continuity with offline mobile capability during connectivity issues
- Reduce duplicate work via API integration connecting external business systems
- Custom electronic forms supporting auto-fill from historical care records
- Manage workflows end‑to‑end, enforce compliance and carer fitness to work.
Pricing
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
5 1 6 4 1 1 5 0 8 9 5 9 9 7 3
Contact
CACI LIMITED
CACI Digital Marketplace Sales Team
Telephone: 0207 602 6000
Email: bid.team@caci.co.uk
About your service
- Service categories
-
Applications
Production and operations
- Other operations
Service industry and public sector operations
- Healthcare
- Adult Social Care
- Children's Social Care
- Other
- Multi cloud support
- No
Service scope
- Software add-on or extension
- No
- Cloud deployment model
- Private cloud
- Service constraints
-
Certa is exclusively hosted on AWS and cannot be deployed to other cloud providers (Azure, Google Cloud) or on-premise infrastructure. The service is limited to AWS London (eu-west-2) region only and cannot be deployed to other AWS regions.
Maximum availability is 99.9%; higher availability levels cannot be offered without multi-region deployment.
The Certa application requires internet connectivity and cannot function in air-gapped or offline-only environments. No planned maintenance downtime is required for platform updates or releases. - System requirements
-
- HTML5 web browser required for access
- Internet connection with minimum 1Mbps bandwidth for optimal user performance
- Android 12 or later operating system for mobile app users
- IOS 16 or later operating system required for mobile app
- Minimum 2GB RAM recommended for desktop devices accessing web interface
- Minimum 1GHz CPU processor speed recommended for desktop web access
- Mobile data connectivity 5G 4G 3G or WiFi for app
User support
- Email or online ticketing support
- Yes
- Support response times
-
Certa’s standard response times are based on incident priority during support hours (Monday–Friday, 08:00–18:00 UK time, excluding public holidays). Priority 0 (Critical) incidents receive a response within 30 minutes. Priority 1(N) and Priority 1 within 4 hours; Priority 2 within 48 hours; Priority 3 within 30 days. The 24/7 Support Ticket
A Customer Portal is available for logging incidents at any time, although responses are provided only during standard hours. Weekend and out‑of‑hours responses are not included as standard. Enhanced, chargeable support is available and extends response availability outside standard hours for Priority 0 incidents . - User can manage status and priority of support tickets
- Yes
- Online ticketing support accessibility
- WCAG 2.2 A
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- No
- Onsite support
- Yes, at extra cost
- Support levels
-
CACI offers two support tiers for Certa to meet the varying needs of care providers. These include:
Standard Support - This provides comprehensive incident management Monday to Friday, 08:00-18:00 UK time (excluding public holidays), delivered through a 24/7 online ticketing portal. Response times are priority-based: Priority 0 (Critical) incidents receive response within 30 minutes, Priority 1 within 4 hours, Priority 2 within 48 hours, and Priority 3 within 30 days. Customers access a real-time support dashboard to view, track, and escalate tickets. Standard Support includes direct access to technical staff, incident triage, resolution activities, automated weekly incident reports, and monthly SLA performance reporting. Pricing for Standard Support is included within the core subscription and scales with user numbers.
Enhanced Support - This extends Priority 0 (Critical) incident coverage to 06:30-22:30 UK time, seven days per week, including bank holidays. This ensures critical service disruptions receive immediate attention outside standard business hours, with the same 30-minute response and 24-hour resolution targets. Enhanced Support pricing is quoted individually based on organisation size and specific requirements.
Tailored support arrangements to meet specific operational needs can be discussed, as with Enhanced Support, this is chargeable and with costs available upon request. - Support available to third parties
- No
Onboarding and offboarding
- Getting started
-
CACI provides a structured onboarding approach to support customers in adopting Certa effectively. As standard, this includes remote, instructor‑led training sessions supported by user documentation, quick‑reference guides and access to an online knowledge base. Certa has been designed with an intuitive, user‑centred interface to support straightforward adoption and reduce the learning curve for new users.
Training is delivered using a train‑the‑trainer model, enabling nominated super users to support wider rollout.
Additional role‑specific training modules can be delivered on a chargeable basis where needed. A dedicated training (or test) environment can likewise be provided as a chargeable option to support safe practice during onboarding and for future training needs.
Self‑paced materials, including recordings of remote training sessions and step‑by‑step guidance, are made available to support different learning styles throughout implementation.
Where customers require more tailored training packages or onsite delivery, these can be arranged as chargeable options, scoped according to customer need. This allows each customer to select the level of onboarding support appropriate to their implementation. - Service documentation
- Yes
- Documentation formats
-
- HTML
- Other
- Other documentation formats
- Docx (Microsoft Word)
- End-of-contract data extraction
-
At the outset of the contract, CACI will work with the customer to agree an end‑of‑contract exit plan where required. If a customer chooses not to renew and provides written notice, the agreed exit activities will be initiated.
Customers can extract their own data at any time using the standard export methods available within Certa, including reporting exports, scheduled extracts and programmatic access via the public API. Where a customer requires CACI to support or perform data extraction, or produce bespoke export formats, this is available as a chargeable service under the agreed exit plan.
Once the customer confirms that all required data has been successfully retrieved, CACI will securely delete the customer’s Certa environment in line with contractual, data‑retention and disposal policies. - End-of-contract process
-
At the end of the contract, customers can extract their data from Certa using the standard export capabilities included within the service. CACI will work with the customer to follow the agreed exit approach, ensuring that data is returned, surrendered or deleted as instructed, subject to technical feasibility. Once the customer confirms that all required data has been successfully retrieved, CACI will securely delete the Certa environment in line with contractual data‑retention and disposal obligations.
Any requirements beyond standard export capabilities, such as bespoke data migration to successor systems, custom data transformation, or extended transition support, can be provided as chargeable services, scoped and costed in advance. - Documentation accessibility standard
- WCAG 2.2 AA
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Opera
- Application to install
- No
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
- The responsive web interface provides identical functionality whether accessed from desktop, tablet, or mobile browsers, with the layout adapting to screen size. Certa also includes Intouch, a dedicated mobile app for support workers. Intouch offers streamlined functionality optimised for field-based care delivery, including visit recording, care plan access, note updates, and schedule management. A key difference is offline capability: Intouch continues functioning without internet connectivity, synchronising data when connection is restored, whilst the web interface requires internet connectivity for full functionality.
- Service interface
- Yes
- User support accessibility
- WCAG 2.2 AA
- Description of service interface
- Users access Certa through an HTML5 compatible web browser. No client-side installation is required.
- Accessibility standards
- WCAG 2.2 AA
- Accessibility testing
-
Certa is designed to be accessible and inclusive, following recognised WCAG accessibility principles across its web application, client portal and the Intouch mobile app. Accessibility considerations are built into the design and development lifecycle, including clear visual hierarchy, descriptive hyperlink text, compliant colour contrast and layouts that support easy navigation for users requiring additional assistance.
Certa undergoes structured accessibility testing using third‑party tools to validate interface behaviour and colour contrast. Any identified non‑conformances are addressed wherever feasible prior to release. CACI also maintains a continuous accessibility enhancement roadmap, which includes regular gap analysis and planned improvements to align with emerging WCAG updates and evolving best practice.
These standards apply consistently across the full Certa ecosystem:
Certa web application for administrative and office‑based users
Certa client portal for clients, families and authorised representatives
Intouch, the included mobile app for support workers delivering care.
Certa is optimised for modern browsers and operating systems; some older versions may not support all accessibility capabilities. By embedding accessibility into our development and QA processes, Certa enables users to access and view the service comfortably and consistently across platforms. - API
- Yes
- What users can and can't do using the API
-
The Certa REST API enables comprehensive integration for querying and updating care management data. Users can query operational information including service users (clients), care plans, schedules, visits, staff records, organisations, and financial data. The API supports creating new records, updating existing information, and invoking business processes programmatically using standard HTTP methods with JSON-formatted responses.
Common integration scenarios include connecting Certa with finance systems for invoicing automation, HR systems for staff management, CRM platforms, and other care sector applications such as NHS Medicines API integration. The API is publicly accessible over HTTPS requiring no VPN or private network configuration.
The API does not provide direct access to administrative functions like user provisioning or system configuration management, which remain within the user interface. The API cannot modify core system architecture or access functionality outside documented endpoints. API usage limits apply to ensure service performance and availability for all users.
Integration setup involves authentication configuration and endpoint familiarisation through interactive Swagger documentation. Changes to integrated systems are made through standard REST patterns following the documented API structure. - API documentation
- Yes
- API documentation formats
- Open API (also known as Swagger)
- API sandbox or test environment
- No
- Customisation available
- Yes
- Description of customisation
-
System administrators can customise the client and family portal appearance, including banner background colour, banner text colour and organisation logo upload, enabling branding aligned with each customer’s identity.
Certa provides a flexible configuration framework during and after implementation. CACI supplies standard configuration templates, and trained administrators can adjust many elements themselves, such as user‑defined fields, care‑planning components, assessment templates, non‑contact event types, medication record structures, and service hierarchies (areas, teams and grades). Where required,
CACI can support further configuration as a chargeable service, subject to scope and agreement.
Certa supports single sign‑on through federation with third‑party identity providers (OIDC, SAML 2.0).
Reporting is highly configurable through the integrated Metabase environment. Users can adapt standard reports or create new dashboards and visualisations, exporting outputs in Excel, CSV or JSON.
Scaling
- Independence of resources
-
Certa provides each customer with dedicated AWS accounts, ensuring complete separation from other customers. Each application environment is deployed to its own dedicated AWS account with independent databases, file storage, and processing resources, eliminating any risk of performance in one customer's environment being impacted by processing occurring in another.
Additionally, Certa's mission-critical components are predominantly serverless (Lambda, DynamoDB, S3), which scale automatically to meet demand. This serverless architecture ensures performance scales elastically with each customer's usage without resource contention between customers.
Analytics
- Service usage metrics
- Yes
- Metrics types
-
CACI provides service‑level metrics as part of ongoing contract management, including service availability, incident volumes and response/resolution performance against targets. These metrics support transparency and help customers monitor service performance.
Within Certa, administrators (and users where permitted) also have access to a wide range of operational usage information through built‑in dashboards and reporting.
Users can also find data at a client level, including; client activity, visit delivery, workforce scheduling, medication activity, outcomes recording and other service workflows, depending on the customer’s configuration.
Infrastructure‑level and security‑related monitoring is undertaken by CACI to help proactively maintain service availability and minimise disruption. - Reporting types
-
- Real-time dashboards
- Regular reports
- Resource tagging
- No
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Other security clearance
- Government security clearance
- Security Clearance (SC)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- United Kingdom
- User control over data storage and processing locations
- No
- Datacentre security standards
- Complies with a recognised standard (for example CSA CCM version 4.0)
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- ‘IT Health Check’ performed by a CHECK service provider
- Protecting data at rest
-
- Physical access control, complying with SSAE-18 / ISAE 3402
- Encryption of all physical media
- Data sanitisation process
- Yes
- Equipment disposal approach
- Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
- Data sanitisation type
-
- Deleted data can’t be directly accessed / Cryptographic Erasure
- Explicit overwriting of storage before reallocation / Secure Erase
Data importing and exporting
- Data export approach
-
Users can export data from Certa through several methods. The embedded Metabase reporting platform enables users to download report outputs directly from the interface in a range of formats. Scheduled extracts can be configured to run automatically, with outputs emailed to nominated recipients or stored for download.
For programmatic access, Certa provides a public REST API that supports data retrieval in JSON format. Where appropriate, direct SQL query access to the reporting database can also be enabled to support external business‑intelligence or analytics tools.
Any assistance with API use, integrations or custom data‑extraction setup is available as a chargeable service. - Data export formats
-
- CSV
- Other
- Other data export formats
-
- JSON format for structured data export and API integration
- Excel format for spreadsheet-compatible data analysis and reporting
- PDF format for formatted reports and client information sheets
- Data import formats
- CSV
Data-in-transit protection
- Data protection between buyer and supplier networks
- TLS (version 1.2 or above)
- Data protection within supplier network
-
- TLS (version 1.2 or above)
- Other
- Other protection within supplier network
- Beyond TLS 1.2+ encryption, Certa implements multiple layers of network protection. Cloud environments operate on logically separated networks with dedicated AWS accounts per customer ensuring complete isolation. Protection includes Checkpoint firewalls with Intrusion Prevention Systems, F5 ASM Web Application Firewalls, and AWS-native security features including GuardDuty for threat detection. IP whitelisting restricts access, and networks are designed around least privilege and deny-by-default principles. All HTTPS S3 connections enforce AES-256 encryption, and comprehensive logging monitors all network activity.
Availability and resilience
- Guaranteed availability
-
Certa operates with a 99.9% availability target, 24 hours per day, 7 days per week, 365 days per year. Service level performance is measured and reported monthly, excluding any permitted downtime from the calculation.
This high availability is achieved through AWS serverless components (Lambda, DynamoDB, S3) deployed across multiple Availability Zones within the London (eu-west-2) region. Automated failover capabilities ensure service continuity even during component failures. Should a single availability zone experience failure, service continues seamlessly from other zones with minimal impact on users.
For non-serverless components, CACI has implemented redundant instances with automated failover across availability zones without human intervention.
Disaster Recovery Parameters:
Recovery Point Objective (RPO): 1 hour
Recovery Time Objective (RTO): 8 hours
Arrangements relating to any remedies or service‑credit mechanisms are agreed contractually with customers as part of individual call‑off terms. - Approach to resilience
-
Certa is designed for high availability and fault tolerance through its serverless AWS architecture deployed exclusively in the UK (eu-west-2 London region). This region comprises three geographically separate Availability Zones, each with independent power, cooling, and networking infrastructure, ensuring no single point of failure at the datacentre level.
The serverless architecture utilises AWS Lambda, DynamoDB, S3, and API Gateway—all inherently designed for multi-AZ redundancy with automated failover. These managed services automatically distribute workloads across healthy infrastructure without manual intervention. Hourly snapshot backups are taken of all data stores, supporting a Recovery Point Objective (RPO) of 1 hour and Recovery Time Objective (RTO) of 8 hours.
CACI maintains documented procedures for recovery across various disaster scenarios, tested and refined through regular DR exercises. Continuous monitoring via AWS CloudWatch enables proactive identification and resolution of potential issues before they impact service availability. The 99.9% availability SLA reflects confidence in this resilient design. - Outage reporting
-
CACI uses multiple channels to communicate service outages and incidents to customers. The CACI Support Portal allows customers to view and manage open incidents, changes and service requests at any time.
Automated email notifications are issued to designated contacts when service disruptions occur, with Priority 0 (Critical) incidents triggering immediate updates, including System Down Reports. Planned maintenance windows are communicated in advance, typically outside core business hours. Weekly open‑incident summaries are also provided.
For high‑priority or widespread issues, CACI may contact affected customers directly, including by phone. Service performance and incident trends are reviewed as part of scheduled contract‑management meetings.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Identity federation with existing provider (for example Google Apps)
- Username or password
- Access restrictions in management interfaces and support channels
-
Management access to Certa AWS accounts is restricted to encrypted corporate VPNs or internal CACI machines. Privileged access is only provided to vetted CACI personnel granted permission in accordance with their role. CACI applies Role-Based Access Controls (RBAC) and the principle of least privilege to grant minimum necessary permissions.
Cloud environments are deployed on logically separated networks. Releases are controlled via automated CI/CD pipelines requiring senior engineer approval. Access is periodically reviewed and promptly removed for leavers. All actions are recorded in audit logs accessible to privileged CACI personnel. - Access restriction testing frequency
- At least once a year
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Dedicated link (for example VPN)
Audit information for users
- Access to user activity audit information
- Users have access to real-time audit information
- How long user audit data is stored for
- User-defined
- Access to supplier activity audit information
- Users have access to real-time audit information
- How long supplier audit data is stored for
- User-defined
- How long system logs are stored for
- User-defined
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
- ISO/IEC 27001
- Information security policies and processes
-
CACI manages sensitive data for public- and private‑sector customers and ensures confidentiality, integrity and availability at all times. We operate a formal Information Security Management System (ISMS) with policies, procedures and technical controls aligned to the ISO27000 series, and certified to ISO27001 since 2006. CACI also holds Data Seal and Cyber Essentials certifications.
Our ISMS incorporates the NCSC 14 Cloud Security Principles, 10 Steps to Cyber Security, 12 Supply Chain Principles, and the Government’s Technology Code of Practice. Compliance is supported through regular internal and external audits, extensive KPI monitoring, and customer‑led reviews.
CACI maintains a company‑wide risk management programme, with formal risk assessments conducted at least annually. Risks relating to confidentiality, integrity and availability are managed through defined controls, security configuration, and operational processes. We run ongoing initiatives to minimise human‑factor risks, including screening, confidentiality agreements, security awareness training and mandatory induction education, with disciplinary processes enforced where required.
Technical protections include highly available infrastructure, encrypted offsite backups, regular patching, firewalling, intrusion detection and antivirus protection. Independent penetration tests are completed annually.
Security governance is embedded into business‑as‑usual operations, ensuring that policies are consistently followed and that information security remains a core organisational priority. - Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
-
Certa software and configuration is managed using infrastructure-as-code principles, with all components controlled in Bitbucket including tracking of approvals and automated checks. Each file constitutes a configurable item tracked through its lifetime.
Changes are formally instigated through logging issues in Jira and managed through development, test, release, and deployment cycles. Releases are controlled via automated CI/CD pipelines with senior engineer approval. Security impact is assessed during scoping, with information security risks considered when documenting designs. All changes follow CACI's Change Control Policy, which documents how changes are managed to minimise risk and impact. - Vulnerability management type
- Supplier-defined controls
- Vulnerability management approach
- CACI operates a structured vulnerability‑management process aligned with ISO 27001 and Cyber Essentials requirements. Potential threats are identified through continuous vulnerability scanning, supported by annual penetration testing conducted by a CHECK‑accredited supplier. Threat intelligence from recognised security sources is monitored to identify emerging risks promptly. All vulnerabilities are assessed, prioritised by severity and remediated within defined timeframes. Patches for Critical and High‑risk issues follow Cyber Essentials‑compliant deployment schedules, typically within 14 days of release, with lower‑severity items addressed through planned maintenance. Remediation is tracked through CACI’s Vulnerability Management Policy to ensure timely resolution and sustained security assurance.
- Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
-
CACI monitors Certa using continuous protective‑monitoring controls to identify unusual or potentially malicious activity. Security events and system logs are automatically collected and analysed for anomalies, with alerts raised to CACI’s security team when behaviour falls outside expected patterns.
If a potential compromise is detected, incidents are evaluated immediately by trained personnel and managed in accordance with CACI’s Security Incident Policy and Response Procedure. Any issue affecting a customer environment is communicated promptly.
Incident response times follow Certa’s standard support model, with alerts reviewed as they arise and actions prioritised based on severity to ensure timely investigation and resolution. - Incident management type
- Supplier-defined controls
- Incident management approach
-
CACI operates pre-defined incident management processes aligned to ITIL v4, with incidents classified by priority level from P0 (Critical) to P3 (Trivial). Each priority has defined response and resolution targets.
Users report incidents via the CACI Support Ticket Portal, available 24/7 for logging. The assigned caller oversees the incident from logging to closure, with the Customer Care Team providing updates and coordinating resolution.
Incident reports include root cause analysis, resolution taken, and System Down Reports for P0 incidents. Monthly reporting provides SLA statistics, with weekly open incident reports emailed to designated contacts. - Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- No
- Free trial available
- No
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 0%
- Between £500,001 and £1,000,000
- 0%
- Between £1,000,001 and £2,500,000
- 0%
- Between £2,500,001 and £5,000,000
- 0%
- Over £5,000,001
- 0%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- Yes
- Who accredited the ISO/IEC 27001
- British Standards Institute
- ISO/IEC 27001 accreditation date
- Tuesday 11 April 2006
- What the ISO/IEC 27001 doesn’t cover
- Our ISO27001 certification covers all CACI services, offices, and data centres.
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- Yes
- Who accredited the ISO 9001 certification
- LRQA Group Ltd
- ISO 9001 accreditation date
- Friday 30 March 2001
- What the ISO 9001 doesn’t cover
-
The following services are not covered by our ISO 9001 certification:
Acorn Datasets, Paycheck and StreetValue
Individual Level Data - Demographic Propensity Models and Financial Lifestage Segmentation
Insite
Pin Routes - Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- 2bca6ecb-5ff5-4d86-8fca-97c234b2ebd5
- Cyber essentials plus
- Yes
- Please provide your Cyber Essentials Plus Certificate Number
- 1ee56f96-0fae-4a36-a7e4-618bd3a1c940
- Other security certifications
- Yes
- Any other security certifications
- Data Seal
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- New or retained jobs on the contract workforce in the relevant area that meet the criteria set out in MAC 1b, 1c and 1d
- New apprenticeships on the contract workforce in the relevant area that meet the criteria set out in MAC 1b
- Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
- Plans to engage the contract workforce in deciding the most important workplace issues to address
- Ensuring new workers are informed of their right to join a trade union
- Monitoring of employee engagement rates (by protected characteristic) and, where necessary, the development of actions to ensure all voices are heard across the diversity of the workforce
- Employment contracts that reflect actual hours worked; steps taken to ensure employees understand their contracts and have the ability to review and adjust them if actual hours regularly exceed contracted hours
- Activities that support an environment where staff are educated about, and feel empowered to, address their physical wellbeing
- Activities that support an environment where staff are educated about and feel empowered to report and address bullying and harassment
- Activities to cascade good practice on fair working conditions throughout the supply chain
- Offer a pay and leave entitlement to all eligible staff who become kinship carers, ideally equivalent to statutory adoption pay and leave
- Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
- Monitoring and reporting of gender and ethnicity pay gaps and plans to address them where necessary
- Entitlement to sick pay for the contract workforce, with provision in place for any staff who do not meet the earnings threshold for statutory sick pay, payment of sick pay from day one of absence and payment of staff on the contract workforce who are off sick a replacement income of 100% of their usual earnings for as long as possible
- Understanding of in-work progression issues affecting the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors
- Measures to support in-work progression to help people in the contract workforce, to move into higher paid work by developing new skills relevant to the contract
- Support for the contract workforce by providing career advice, and providing opportunities for staff working on the contract with in-work progression career development into known skills shortages or high growth areas
- Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
- Volunteering opportunities for staff
- Understanding of the modern slavery risks and issues affecting the market, industry, sector or country (of origin or of source) relevant to the contract, and the workforce in the supplier’s own organisation and those of its key subcontractors
- Measures to identify, mitigate and manage modern slavery risks relating to the contract and how these will be implemented
- Outline policies and practices to be applied to or put in place for the contract to mitigate and manage modern slavery risks, including: Pre-employment checks, recruitment practices. Workplace conditions, safeguarding plans and processes in place and regular monitoring with relevant groups considered, which may include sampling
- How these flow down the supply chain and are monitored Illustrative examples include reporting, site visits, audits, etc.
- How to ensure business decisions re: price/cost, short lead times, payment timescales do not create modern slavery risks in the supply chain
- Means of influencing staff, suppliers, customers, communities and/or any other appropriate stakeholders with respect to modern slavery risks relating to the contract
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.
- Understanding of employment and relevant skills issues, and of the education and training issues relating to the contract. Illustrative examples: demographics, skills shortages, new opportunities in high growth sectors, geographic/local community and skills/employment challenges
- Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
- Activities to support relevant sector related skills growth and sustainability in the contract workforce. Illustrative examples: careers talks, curriculum support, literacy support, safety talks and volunteering
- Delivery of apprenticeships, supported internships and T Level industry placement opportunities (Level 2, 3 and 4+) in relation to the contract
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 3: Resilient, innovative and flexible supply chains: Support economic growth through enabling resilient businesses, opportunities for small businesses and voluntary, community and social enterprises
- Understanding of the types of businesses in the market and the level of participation by new businesses, entrepreneurs, start-ups, SMEs, VCSEs and mutuals
- Activities to identify opportunities to open up sub-contracts under the prime contract to a diverse range of businesses, including new businesses, entrepreneurs, start-ups, SMEs, VCSEs and mutuals
- Plans for engaging a diverse range of businesses in engagement activities prior to appointing subcontractors (including activities prior to award of the main contract and during the contract term)
- Activities that demonstrate a collaborative way to work with a diverse range of businesses as part of the supply chain
- Ensuring accessibility to contracting and subcontracting opportunities for disabled business owners and employees
- Structuring of the supply chain selection process to ensure fairness (e.g. anti-corruption) and encourages participation by a diverse range of businesses, including with regard to new businesses, entrepreneurs, start-ups, SMEs, VCSEs and mutual
- Understanding of local demographics, needs and opportunities for the co-design of the goods, services and works to be delivered under the contract
- Methods for engaging with different parts of the community (including the education system and charities representing the community) and how communities come together to inform decisions, strategy and projects to leave a positive legacy for future generations
- Measures to involve local stakeholders and/or users in design (e.g. in the design of services, systems, products or buildings)
- Plans for positive actions with community groups.
- Measures for making facilities used in the delivery of the contract available for community groups, education or training
- Measures to engage users and communities and build relationships to increase community integration build trust and influence how the contract is delivered
- Plans to respond flexibly and adapt approaches to community engagement and initiatives
- Support for community-led initiatives relevant to the contract. Illustrative examples: improving transport links; reducing loneliness; helping with English language proficiency; and facilitating social mixing among people with different backgrounds
- Collaborating with anchor institutions and community groups to make facilities available for education, training or community events
-
Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero
Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.
- Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
- Collaborative ways of working with the supply chain to deliver additional environmental benefits in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
- Delivery of additional environmental benefits through the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
- Understanding of how to influence staff, suppliers, customers, communities and/or any other appropriate stakeholders through the delivery of the contract to support climate and nature protection and improvement
- Activities to reconnect people with the environment and increase awareness of ways to protect and enhance it
-
Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain
Policy Outcome 6: Employment and training: For those who face barriers to employment
- Understanding of employment and skills issues, and of the skills and employment shortages of high growth sectors relating to the contract
- Creation of employment opportunities particularly for those who face barriers to employment, such as prison leavers, care leavers and/or who are located in deprived areas, and for people in industries with known skills shortages or in high growth sectors
- Delivery of training schemes and programmes to address any identified skills gaps and under-representation in the workforce for the contract (e.g. prison leavers, care leavers, kinship carers, disabled people)
- Advertising, promotional and outreach activities designed to raise awareness of the offer to reach the target cohort
- Understanding of the issues affecting the representation of disabled people in the workforce in the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors
- Collection of the views and expertise of disabled people and their representative organisations on successfully supporting disabled employees or applicants
- Inclusive and accessible recruitment practices, and retention-focused activities, including those provided in the Guide for line managers on recruiting, managing and developing people with a disability or health condition
- Introducing transparency to pay and reward processes
- Offering a range of quality opportunities with routes of progression if appropriate, e.g. T Level industry placements, students supported into higher level apprenticeships.
- Working conditions which promote an inclusive working environment and promote retention and progression
- Other measures to provide equality of opportunity for disabled people and those with health conditions into employment, including becoming a Disability Confident employer and inclusion of supported businesses in the contract supply chain
- Understanding of the issues affecting inequality in employment, skills and pay in the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors. Measures to tackle inequality in employment, skills and pay in the contract workforce
- Inclusive and accessible development practices, including guidance for line managers on recruiting, managing and developing people with a disability or health condition
-
Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain
Policy Outcome 7: Creating a pipeline of opportunities: For the contract workforce, reducing barriers to entry for under-represented groups.
- Understanding of the issues affecting the development of new skills by target cohort
- Understanding of the underlying factors affecting improvements to reduce barriers to entry and training schemes for the target cohort(s) related to the contract workforce
- Other measures to offer development opportunities for the target cohort(s) in the contract workforce
- Advertising, promotional and outreach activities designed to raise awareness of the offer to reach the target cohort
- Understanding of issues relating to entering the contract workforce
- Creation of outreach activities to create a pipeline of employees for the future contract delivery
- Content of the outreach activity is designed to suit the target cohort
- Advertising, promotional and outreach activities designed to raise awareness of the offer to reach the target cohort
-
Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.
Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.
- Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce
- Understanding barriers to access to health and social care services or employment opportunities e.g. digital inclusion
- Inclusive and accessible recruitment practices, development practices and retention policies that support-focused activities including those provided in the Guide for line managers on recruiting, managing and developing which support people with a disability or health condition
- Actions to invest in the physical and mental health and wellbeing of the contract workforce
-