ExtraCollect DCA Panel Management Software
ExtraCollect is a software solution designed to make the management of outsourced debt collection and/or enforcement agencies, easier. Includes MI/BI, invoicing, account allocation/recall/recycling, operational controls, oversight features and more.
Platform has been proven under DMS and DRS debt management frameworks.
Features
- Debt collection agency panel management
- Invoice reconciliation and cash management
- management information and business intelligence
- Digital query management
- Account level activity visibility
- Debt Portfolio administration
Benefits
- Optimise the use of outsourced suppliers
- Enhanced oversight of outsourced suppliers
- Weekly balance reconciliation of all accounts
- Digital query management function
- allocate, recall and recycle accounts efficiently
Pricing
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
5 2 7 5 2 2 8 0 3 5 3 0 1 6 2
Contact
QUALCO (UK) LIMITED
Jan-Michael Lacey
Telephone: 07775664131
Email: sales@qualco.co.uk
About your service
- Service categories
-
Applications
Enterprise resource management
- Project and portfolio management
Financial
- Accounts Payable Applications
- Multi cloud support
- No
Service scope
- Software add-on or extension
- Yes, but can also be used as a standalone service
- What software services is the service an extension to
- QUALCO Collections & Recoveries platform
- Cloud deployment model
- Private cloud
- Service constraints
- ExtraCollect is hosted in an IBM UK private cloud environment
- System requirements
- Access is via a chronium browser
User support
- Email or online ticketing support
- Yes
- Support response times
- Within 4 hours, during standard office hours
- User can manage status and priority of support tickets
- No
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- No
- Onsite support
- Yes, at extra cost
- Support levels
- All Clients have an Account Manager who is the designated point of contact. Standard support is included in monthly platform fee
- Support available to third parties
- Yes
Onboarding and offboarding
- Getting started
-
We conduct an initial discovery phase to understand Client's preferred business rules, which DCAs they work with, file structures etc.
We then configure the software to the users requirements, conduct testing and training prior to go live - Service documentation
- Yes
- Documentation formats
- End-of-contract data extraction
- QUALCO automatically cuts a data file with all data owned by the Client. This is through a number of CSV files which are transferred to the user securely via sFTP.
- End-of-contract process
-
The initiation of the Exit Plan would be the expiry or termination of a Client contract, for any reason, including where notice is given by either Qualco or the Client.
The initial step will be for both the Client and Qualco to attend an Exit Strategy Meeting to define the specific deliverables of the exit activities.
This would form the ‘Exit Management Plan’.
The meeting will include review of the contractual agreement to agree which key obligations should form part of the Exit Management Plan.
A Governance structure will also be agreed to ensure the right level of oversight is maintained during the transition period.
Key considerations for the Exit Management Plan:
o Exit Plan Governance
o Account placement, recall and recycling strategy. Considering:
▪ Accounts which have reached 'end of strategy' and are no longer active
▪ Accounts which are still in an active strategy
▪ Accounts in a payment arrangement
▪ Accounts in query
o Mitigation of potential consumer detriment risks
o Communication plans
o Query closure process
o Financial processing considerations
o Invoice settlement
o Data retention or deletion
o Steps to be taken to ensure the timely and smooth handover to the Client or nominee. - Documentation accessibility standard
- None or don’t know
- How the documentation is accessible
- By request to sales@qualco.co.uk
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Opera
- Other
- Application to install
- No
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
- Same functionality across both mobile and desktop. Interface optimised for mobile access if using a mobile device.
- Service interface
- No
- User support accessibility
- None or don’t know
- API
- No
- Customisation available
- Yes
- Description of customisation
-
Some aspects of reporting can be customised as can some operational controls, including:
Add/remove DCAs from a placement
Change number of days before account recall
Amend commission rates
Amend account allocation %
Scaling
- Independence of resources
- We constantly monitor access to the platform and ensure bandwidth can accommodate all users. The nature of the solution means there are not ten's of thousands of users. The platform can comfortably handle the load.
Analytics
- Service usage metrics
- Yes
- Metrics types
- Basic information relating to which users are accessing the software, when and for how long
- Reporting types
- Reports on request
- Resource tagging
- No
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Conforms to BS7858:2019
- Government security clearance
- Baseline Personnel Security Standard (BPSS)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- United Kingdom
- User control over data storage and processing locations
- No
- Datacentre security standards
- Complies with a recognised standard (for example CSA CCM version 4.0)
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- ‘IT Health Check’ performed by a CHECK service provider
- Protecting data at rest
-
- Physical access control, complying with CSA CCM v4.0
- Encryption of all physical media
- Data sanitisation process
- Yes
- Equipment disposal approach
- Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
- Data sanitisation type
-
- Data Erasure
- Physical Destruction / Hardware containing data is completely destroyed
Data importing and exporting
- Data export approach
-
ExtraCollect can ingest data from users in the User's preferred format (usually CSV or pipe-delimited files), or using the default file schema provided by QUALCO.
Data is transferred securely via sFTP (either QUALCO's site, or the User's preferred site). - Data export formats
-
- CSV
- Other
- Other data export formats
- XML
- Data import formats
-
- CSV
- Other
- Other data import formats
- XML
Data-in-transit protection
- Data protection between buyer and supplier networks
- TLS (version 1.2 or above)
- Data protection within supplier network
- TLS (version 1.2 or above)
Availability and resilience
- Guaranteed availability
- 99%
- Approach to resilience
- Available upon request
- Outage reporting
- Client service team make direct contact with authorised representatives of Users, either by phone or email.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Public key authentication (including by TLS client certificate)
- Other
- Other user authentication
- Single Sign On using OIDC and Active Directory
- Access restrictions in management interfaces and support channels
-
Access to the ExtraCollect software solution is either via unique login, with strong password and 2FA, or via SSO. Users are role-based with least privilege access rights.
A super-Admin on the Client side will determine which users have which rights.
The system maintains a full audit of attempted access (successful and unsuccessful). - Access restriction testing frequency
- At least every 6 months
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Public key authentication (including by TLS client certificate)
- Other
- Description of management access authentication
- Single Sign On (SSO)
Audit information for users
- Access to user activity audit information
- Users receive audit information on a regular basis
- How long user audit data is stored for
- Between 6 months and 12 months
- Access to supplier activity audit information
- Users contact the support team to get audit information
- How long supplier audit data is stored for
- Between 6 months and 12 months
- How long system logs are stored for
- Between 6 months and 12 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
- ISO/IEC 27001
- Information security policies and processes
-
We are ISO27001 certified and Cyber Essential Plus accredited. We have a robust set of policies and procedures all staff are required to follow. We have comprehensive online training with tests that staff are required to undertake and pass.
Policies include:
IT & Information Security
Acceptable Use
Anti-Phishing
Clear Desk & Clear Screen
Data Backup
Data Classification
Data Retention & Erasure
User Access Control
Cryptography
Data Protection
Mobile Device
Business Continuity
Code of Conduct & Ethics
Modern Slavery & Human Trafficking
Incident Response
Quality - Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
- TBC
- Vulnerability management type
- Supplier-defined controls
- Vulnerability management approach
-
QUALCO employs a risk-based, proactive approach to threats and vulnerability management.
Continuous assessments—such as annual penetration tests and quarterly vulnerability scans—identify risks, which are prioritised and remediated swiftly.
Patch management is governed by strict timelines: critical and high-risk patches are deployed within 14 days. All systems undergo annual health checks, and patching activities are documented for compliance.
24/7 monitoring through a managed SIEM and a robust incident response plan ensure rapid detection and action.
QUALCO maintains ISO 27001 and Cyber Essentials Plus certifications, enforces supply chain security, and fosters a culture of security awareness through ongoing employee training. - Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
-
QUALCO uses a managed SIEM (from BulletProof) for 24/7 real-time monitoring of logs from network devices, firewalls, servers, and applications.
The SIEM detects suspicious activity using automated analysis, threat intelligence feeds, and regular vulnerability assessments.
When a potential compromise is found, incidents are immediately logged, escalated to the Operational Security Manager and DPO, and handled via a documented workflow (investigation, containment, eradication, recovery).
All staff must report suspected breaches without delay. For client data incidents, QUALCO notifies affected clients within 24 hours and provides ongoing updates until resolved. - Incident management type
- Supplier-defined controls
- Incident management approach
-
QUALCO’s IT security incident management uses 24/7 SIEM monitoring for rapid detection of threats.
All staff are trained to report incidents promptly, which are logged and managed in a structured workflow.
An Incident Response Team investigates, contains, and resolves incidents, documenting all actions. If personal data is involved, QUALCO notifies the ICO within 72 hours and affected clients promptly, providing updates until resolution.
All incidents are reviewed by leadership for lessons learned, driving continuous improvement and regular staff training. This ensures a robust, compliant, and responsive approach to IT security incidents. - Post-quantum cryptography secure
- Yes
Secure development
- Approach to secure software development best practice
- Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- No
- Free trial available
- No
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 1%
- Between £500,001 and £1,000,000
- 2%
- Between £1,000,001 and £2,500,000
- 3%
- Between £2,500,001 and £5,000,000
- 4%
- Over £5,000,001
- 5%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- Yes
- Who accredited the ISO/IEC 27001
- British Assessment Bureau
- ISO/IEC 27001 accreditation date
- Tuesday 22 September 2015
- What the ISO/IEC 27001 doesn’t cover
- All areas of the business are covered, with the exception of the data centre, which is covered by IBM UK's own set of accreditations (including ISO27001).
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- Yes
- Who accredited the ISO 9001 certification
- British Assessment Bureau
- ISO 9001 accreditation date
- Sunday 21 February 2021
- What the ISO 9001 doesn’t cover
- All aspects of the business are covered
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- Yes
- Who accredited the PCI DSS certification
- Self-certified
- PCI DSS accreditation date
- Tuesday 13 August 2024
- What the PCI DSS doesn’t cover
- Any card processing by Qualco UK is covered (we don't store card details). Card processing by third parties (e.g. our panel of debt collection agencies) is not covered by our PDC-DSS, rather each agency will have their own PCI-DSS in place.
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- B18bd6d0-9fa6-4dda-8671-0d354503ef67
- Cyber essentials plus
- Yes
- Please provide your Cyber Essentials Plus Certificate Number
- 91e3fd36-57c9-40ce-b297-345d134d85b6
- Other security certifications
- No
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.
- Understanding of employment and relevant skills issues, and of the education and training issues relating to the contract. Illustrative examples: demographics, skills shortages, new opportunities in high growth sectors, geographic/local community and skills/employment challenges
- Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
- Activities to support relevant sector related skills growth and sustainability in the contract workforce. Illustrative examples: careers talks, curriculum support, literacy support, safety talks and volunteering
- Delivery of apprenticeships, supported internships and T Level industry placement opportunities (Level 2, 3 and 4+) in relation to the contract
-