Digistaff Intelligent Automation UCDS Processing
Our solution will validate, and automatically process your ATLAS and LCTR files from DWP. It is available on all of the leading Revs & Bens Software; NEC Revenues & Benefits, MRI One Revenues & Benefits, Civica OpenRevenues and the new Civica Cloud platform.
Features
- Fully Managed Service, no training or upskilling required
- Digital Process Automation for HB & CTRS
- Processes HB Stops and CTRS Changes
- Creates & Sends the MGP1 Return
- Creates New Claims Where Required for CTRS
- Usable With Existing UCDS Automation or as Standalone
- Works with NEC, MR, Civica OpenRevenues & Civica Cloud
- Same Day Updates Using Your Business Rules
- Works the User Interface or the system APIs
- Attended Access to Searchlight for Additional Details Requirements
Benefits
- Higher Completion and Accuracy rates
- Industry Leading Productivity 24/7
- Increased Efficiency and Accuracy
- Application, System and Process Agnostic
- Reduced Operating Costs
- Same Day Processing/Reduction in LA Error
- Releases Staff to Undertake Higher Value Tasks
- Quick Deployment
- Instantly Scalable Resource
- You pay for the solution not the number of licenses.
Pricing
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
5 1 8 2 2 2 1 9 3 6 9 0 6 8 0
Contact
Digistaff
Andy Heys
Telephone: 07824305347
Email: andy.heys@digistaff.co.uk
About your service
- Service categories
-
Application Development and Deployment
Application platforms
- Robotic process automation
- Multi cloud support
- Yes
Service scope
- Software add-on or extension
- No
- Cloud deployment model
- Private cloud
- Service constraints
- None
- System requirements
- None - Infrastructure, Application & System Agnostic
User support
- Email or online ticketing support
- Yes
- Support response times
- All initial tickets are responded to within 24 hours, Monday to Friday. Tickets raised on the weekend will be responded to on the next working day.
- User can manage status and priority of support tickets
- No
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- No
- Onsite support
- Yes, at extra cost
- Support levels
-
Standard help-desk hours are Mon-Fri 9 - 5 excluding UK Public Holidays.
There are three defined sub-sets of fault:- “Category 1” - a fault which makes the Software unusable. Target response time two hours; target resolution 24 hours “Category 2” - a Fault which has a material effect upon the functionality, accuracy or performance of any function of the Software upon which Customer relies. Target response time of four hours; target resolution 48 hours. “Category 3” - a minor or cosmetic Fault. Target response time four hours; target resolution seven days.
Support is include in the cost.
We do not provide a technical account manager or cloud support engineer - Support available to third parties
- Yes
Onboarding and offboarding
- Getting started
- A combination of onsite / online training and workshops and user documentation following industry best practice.
- Service documentation
- No
- End-of-contract data extraction
- No process data is stored within our infrastructure. As part of any contract agreement there will be a controlled return or deletion of customer data.
- End-of-contract process
-
Within the price of the contract will be a provision of automated processes that remain the intellectual property of Digistaff. Off-boarding of clients is included in the price of the contract.
Digistaff follows as a minimum, the UK’s current standard for Data wiping as set out by HMG CESG IS5 Baseline and Enhanced. This standard dictates that hard drives must be overwritten a minimum of three times.
PROCESS:
The process that is followed by Digistaff engineers is as follows:
a. Hard drives are removed from service at the end of a contract, when upgrades are performed or when a hard drive is replaced due to a fault.
b. Drives are places into a logged queue marking them for data wiping.
c. Drives are stored for 30 days before being processed further.
d. Once 30 days has passed, an engineer puts the drive through the erasing process
e. If the wiping process succeeds then the drive is either disposed of or marked for re-use where in accordance with Digistaff policies.
f. If the wiping process fails, the process is restarted from point d.
Using the service
- Web browser interface
- No
- Application to install
- Yes
- Compatible operating systems
- Windows
- Designed for use on mobile devices
- No
- Service interface
- No
- User support accessibility
- None or don’t know
- API
- No
- Customisation available
- Yes
- Description of customisation
- The solution can be configured to the customers requirements to meet the needs of their local LCTR schemes. Digistaff will undertake the customisation of the solution based upon the requirements of the customer.
Scaling
- Independence of resources
- Each client has an independent environment and our service is built on a consumption model. The more we use the more we expand our infrastructure and service so there is no detrimental effect on any clients.
Analytics
- Service usage metrics
- Yes
- Metrics types
- Workforce utilisation, process performance and completion rates.
- Reporting types
-
- Real-time dashboards
- Regular reports
- Reports on request
- Resource tagging
- No
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Conforms to BS7858:2019
- Government security clearance
- Baseline Personnel Security Standard (BPSS)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- United Kingdom
- User control over data storage and processing locations
- Yes
- Datacentre security standards
- Managed by a third party
- Penetration testing frequency
- At least every 6 months
- Penetration testing approach
- Another external penetration testing organisation
- Protecting data at rest
-
- Physical access control, complying with CSA CCM v4.0
- Physical access control, complying with SSAE-18 / ISAE 3402
- Encryption of all physical media
- Data sanitisation process
- Yes
- Equipment disposal approach
- A third-party destruction service
- Data sanitisation type
- Explicit overwriting of storage before reallocation / Secure Erase
Data importing and exporting
- Data export approach
- Via downloadable XML
- Data export formats
-
- CSV
- ODF
- Other
- Other data export formats
- XML
- Data import formats
-
- CSV
- ODF
- Other
- Other data import formats
- XML
Data-in-transit protection
- Data protection between buyer and supplier networks
- IPsec or TLS VPN gateway
- Data protection within supplier network
-
- TLS (version 1.2 or above)
- IPsec or TLS VPN gateway
- Legacy SSL and TLS (under version 1.2)
Availability and resilience
- Guaranteed availability
- Network availability - 99% Infrastructure availability - 99% Availability is based on the total number of operating hours of a given calendar month and excludes planned and emergency maintenance.
- Approach to resilience
-
Digistaff uses UKFast as hosting provider, their resilience standard is:
UKFast owns and operates a 5.52MW tier 3 1,000 rack data centre estate. This contains multiple physically separate buildings, connected by dedicated fibre. High voltage power connections are provided from four separate primary sub-stations. All mission-critical services including Standby Generation, Cooling systems and UPS (uninterruptible power system) are provided at N+1 or greater across the whole facility. The complex has a power density of over 6KW per square foot, providing diverse A & B power to each data rack, and all eCloud service platforms are supported from quadruple power feeds. The data centre complex is supported by 9MW of standby generation with over 100,000 litres of fuel storage and eight hour fuel supply SLA. All critical services are supported by 4.6MW of UPS power and 4.9MW of data centre cooling. The public sector hosting suite has fully resilient networking, switches, carrier-redundant leased lines, power and backup generators, all separated from the rest of the UKFast network and data centre complex. - Outage reporting
- Initially email alerts, we are looking to expand this to provide a private dashboard in the near future.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Dedicated link (for example VPN)
- Username or password
- Access restrictions in management interfaces and support channels
- Role Based Access and Privileged Identity Management.
- Access restriction testing frequency
- At least once a year
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Public key authentication (including by TLS client certificate)
- Limited access network (for example PSN)
- Dedicated link (for example VPN)
- Username or password
Audit information for users
- Access to user activity audit information
- Users have access to real-time audit information
- How long user audit data is stored for
- User-defined
- Access to supplier activity audit information
- Users have access to real-time audit information
- How long supplier audit data is stored for
- User-defined
- How long system logs are stored for
- User-defined
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
- ISO/IEC 27001
- Information security policies and processes
- In line with ISO27001 accreditation and governance procedures
- Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
-
Change management system operational which documents all changes, responsible parties, time of change and senior-level sign off. All changes pass through a Change Advisory Board (CAB).
Changes to processes are tracked through audit logs in the Blue Prism software.
Change requests are evaluated for potential security risks. Once approved, they are implemented through a controlled approach using the various control mechanisms in Blue Prism. - Vulnerability management type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Vulnerability management approach
- Vulnerability scan run once per Quarter and critical vulnerabilities patched within 30 days.
- Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
- Internally designed and developed threat monitoring system is run on all infrastructure.
- Incident management type
- Complies with a recognised standard, for example, CSA CCM v4.0 or ISO/IEC 27035:2011 or SSAE-18 / ISAE 3402
- Incident management approach
- ISO27001-complaint processes and systems for incident response are operational.
- Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- No
- Free trial available
- No
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 0%
- Between £500,001 and £1,000,000
- 0%
- Between £1,000,001 and £2,500,000
- 0%
- Between £2,500,001 and £5,000,000
- 0%
- Over £5,000,001
- 0%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- Yes
- Who accredited the ISO/IEC 27001
- Approachable
- ISO/IEC 27001 accreditation date
- Sunday 12 May 2024
- What the ISO/IEC 27001 doesn’t cover
- Covers all elements of the service provision only
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- No
- Quality management systems (QMS)
- No
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- Cfc48ab7-539f-451b-ad15-a352e40ac23b
- Cyber essentials plus
- No
- Cyber Essentials Alternative
- In relation to the services you do not have a current and valid Cyber Essentials Plus certificate which has been awarded by one of the government approved Cyber Essentials accreditation bodies but you are working towards gaining it, and will be in a position to confirm that you have been awarded a current and valid Cyber Essentials Plus certificate by one of the government approved accreditation bodies within 12 months of the date of award.
- Other security certifications
- No
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
- Monitoring and reporting of gender and ethnicity pay gaps and plans to address them where necessary
- Entitlement to sick pay for the contract workforce, with provision in place for any staff who do not meet the earnings threshold for statutory sick pay, payment of sick pay from day one of absence and payment of staff on the contract workforce who are off sick a replacement income of 100% of their usual earnings for as long as possible
- Plans for an appropriate income replacement policy for staff who are required to spend time away from work to care for a sick dependent or close relative
- Understanding of in-work progression issues affecting the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors
- Measures to support in-work progression to help people in the contract workforce, to move into higher paid work by developing new skills relevant to the contract
- Support for the contract workforce by providing career advice, and providing opportunities for staff working on the contract with in-work progression career development into known skills shortages or high growth areas
- Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
- Volunteering opportunities for staff
-