AssessNET Hazard Reporting
AssessNET’s Hazard Reporting Module enables users to quickly record and manage workplace hazards, including photos and videos, with automatic alerts to responsible personnel. Remedial actions can be assigned and progress tracked directly from each hazard, supporting timely resolution and risk reduction.
Features
- Real-time reporting allowing users to enter hazards with supporting data
- Upload attachments such as photos, videos and documents
- Standardised reporting forms ensuring consistency across all hazard types
- Accessible via the Portal from any internet-enabled device
- Customisable notification rules ensure alerts are sent to staff
- Automated alert distribution reduces manual notification effort.
- Pre-defined corrective measures assist users when creating actions
Benefits
- Supports prioritised responses based on assigned hazard severity
- Improves responsiveness by directing hazards to accountable users immediately
- Ensures timely awareness for relevant stakeholders, reducing potential harm
- Visibility of progress encourages accountability and reduces unresolved hazards
- Empowers frontline staff to actively participate in hazard identification
- Enhances visibility and insight into hazard patterns over time
- Supports organisational risk management and compliance objectives
Pricing
- Education pricing available
- Free trial available
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
5 3 4 2 7 5 0 4 5 6 5 8 5 9 4
Contact
RISKEX LIMITED
Richard Aylott
Telephone: +44 1908 915272
Email: r.aylott@riskex.com
About your service
- Service categories
-
Applications
Content workflow and management
- Capture
- Document
Content services
- Enterprise Content Management Applications
- Content Sharing and Collaboration Applications
Enterprise portals and digital workspaces
- Multi-Audience Portals
- Multi cloud support
- Yes
Service scope
- Software add-on or extension
- Yes, but can also be used as a standalone service
- What software services is the service an extension to
- AssessNET is a modular service. This means each AssessNET module works standalone, but integrates with others to provide you with powerful, holistic solution to meet within your budgets and/or needs.
- Cloud deployment model
- Public cloud
- Service constraints
- 99.9% service availability and support SLA
- System requirements
- None
User support
- Email or online ticketing support
- Yes
- Support response times
-
We provide a 4 hour response time within business hours.
Emergency or critical issues are monitored outside of business hours with a response time of 1 hour within business hours. - User can manage status and priority of support tickets
- Yes
- Online ticketing support accessibility
- WCAG 2.2 AAA
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- Yes, at an extra cost
- Web chat support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support accessibility standard
- WCAG 2.2 AAA
- Web chat accessibility testing
- N/A - External vendor specialising in help desk platforms
- Onsite support
- Yes, at extra cost
- Support levels
-
We offer the same core support level to every client, whatever the size of the organisation or contract. Our UK based team supports you from go live onwards, helping users with day to day queries, training guidance and configuration during business hours.
Support requests are raised through our online service desk Monday to Friday 8:30 to 17:30. Each request is logged against your account, tracked through to completion and retained as a reference history. Where an issue needs deeper investigation, it is progressed to our technical specialists and, if required, our senior team for detailed analysis and corrective action, with updates provided in line with our service targets.
If preferred, we can restrict who can submit requests to nominated contacts or a client support desk. All clients are also assigned an account manager to help coordinate support and assist with escalations.
We provide a 99.9% monthly availability commitment, excluding planned maintenance. Maintenance is carried out outside office hours wherever possible and communicated in advance. - Support available to third parties
- Yes
- AI chatbot
- Yes
Onboarding and offboarding
- Getting started
-
All onboarding clients are assigned an Account Manager and an Implementation Manager to ensure a smooth, well governed transition onto the service. We start with an implementation meeting to confirm objectives, requirements and success measures, then agree the configuration approach for your organisation.
AssessNET is designed to be intuitive for everyday users while providing the depth and control required by administrators. During onboarding we capture core system data, establish organisational structures, permissions and workflows, and support your team to configure the platform. Administrator enablement is built into this activity, with practical guidance as key settings are applied, so your team can confidently manage the service going forward.
Training can be delivered online, onsite, or as a blended approach, and is tailored to your modules, processes and audience. Sessions can cover train the trainer, role based training, individual modules, or general system overviews, and can be repeated for different teams to suit availability. Online sessions can be recorded for reuse where appropriate. If you prefer fixed training assets, we can produce a configuration specific training video on request.
All licensed users have access to in system support resources, including module guidance, manuals and self serve help content. - Service documentation
- Yes
- Documentation formats
-
- HTML
- End-of-contract data extraction
- If a client requires a data extract at the end of their contract, this can be requested via their Account Manager or through our Support Desk. In many cases, clients can also export information directly from within the system prior to licence expiry, enabling them to retain key reports and records as needed. Where a full service led extract is required, we will prepare an export of the relevant data held within the service, including any uploaded document attachments, and provide it in an agreed format using an agreed delivery method. This service is chargeable, with pricing confirmed in advance and based on the volume and complexity of the data requested.
- End-of-contract process
- Where a customer chooses not to renew, they can download and export their information using the in-system tools before access ends. If a more comprehensive extract is required, Riskex can produce this on request as a chargeable service.
- Documentation accessibility standard
- WCAG 2.2 AAA
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Opera
- Application to install
- No
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
- Our cloud platform supports mobile working through a dedicated app for Android and Apple devices, available on both phones and tablets. The app covers Risk Assessments, Incident Reporting, Audits, Inspections and Hazard reporting, and includes a built in task manager so users can view and update actions in the field. It works online and offline, capturing data without a signal and syncing later. Users can upload files and photos, and use QR code access, ideal for contractors or non account users to complete specific tasks such as incident reporting. Our web system is also mobile responsive via the browser.
- Service interface
- No
- User support accessibility
- WCAG 2.2 AAA
- API
- Yes
- What users can and can't do using the API
-
Our platform includes a RESTful API that returns JSON and is designed to integrate securely with authorised third party systems alongside our cloud service. The API enables approved applications to access and work with key operational data, including tasks, assessments, users and organisational structures, supporting both retrieval and the creation or updating of records where permitted.
Security is built in from the outset. Access is controlled for authorised systems only, and the API is delivered in line with required security standards to protect data confidentiality and integrity. To maintain strong governance, deletion of data via the API is not permitted. All API activity is fully auditable, with comprehensive logging of changes to support traceability and enable rollback where required.
Where clients have specific integration requirements, we can also design and deliver private, client specific API endpoints by request, enabling tailored data flows while maintaining the same security and audit standards. - API documentation
- Yes
- API documentation formats
-
- Open API (also known as Swagger)
- HTML
- API sandbox or test environment
- Yes
- Customisation available
- Yes
- Description of customisation
-
AssessNET is highly configurable, with several hundred settings that allow clients to tailor nomenclature, control which features are available, and adjust how information is presented. Many of these options can be managed directly by authorised client administrators through the system interface, enabling changes to be made quickly without the need to raise support requests.
The platform also supports corporate branding, including the ability to apply your preferred colours across menus, dashboards and charts, and to upload your organisation’s logo for consistent use throughout the system and on exported and printed reports.
During onboarding, your Implementation Manager will work with you to confirm the most appropriate configuration for your organisation and will highlight the full range of options available. Where a requirement falls outside of what is configurable through the standard interface, our team can provide additional support and, where needed, deliver more bespoke tailoring to meet specific operational needs.
Scaling
- Independence of resources
- Our service maintains consistent performance through a scalable, virtualised environment with load-balanced application instances. Each client’s data is logically segregated, ensuring that one client’s activity does not impact others. This architecture guarantees responsiveness and reliability, even during peak usage.
Analytics
- Service usage metrics
- Yes
- Metrics types
- The service provides a comprehensive suite of metrics accessible directly within the platform, giving end users and administrators clear visibility into system activity. Metrics cover areas such as login activity, record and task counts, incident trends, and audit tracking, providing actionable insights to support effective management and decision-making.
- Reporting types
-
- API access
- Real-time dashboards
- Regular reports
- Reports on request
- Resource tagging
- No
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Conforms to BS7858:2019
- Government security clearance
- Baseline Personnel Security Standard (BPSS)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- United Kingdom
- User control over data storage and processing locations
- No
- Datacentre security standards
- Complies with a recognised standard (for example CSA CCM version 4.0)
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- ‘IT Health Check’ performed by a CHECK service provider
- Protecting data at rest
-
- Physical access control, complying with CSA CCM v4.0
- Physical access control, complying with SSAE-18 / ISAE 3402
- Encryption of all physical media
- Scale, obfuscating techniques, or data storage sharding
- Other
- Other data at rest protection approach
- All data is encrypted at rest whilst stored in physically protected data centres. This also applies to external backup provisions and redundancy.
- Data sanitisation process
- Yes
- Equipment disposal approach
- Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
- Data sanitisation type
-
- Deleted data can’t be directly accessed / Cryptographic Erasure
- Explicit overwriting of storage before reallocation / Secure Erase
Data importing and exporting
- Data export approach
-
Comprehensive data extraction tools are available across all system modules, enabling scheduled exports to support operational and reporting needs. Extracted data is securely stored in an sFTP repository, with access credentials managed by the service provider.
For full-system data extracts, including uploaded files, clients may submit a request through their Account Manager or the Support Team. A service fee applies for these extraction requests, ensuring timely and secure delivery of the requested data. - Data export formats
-
- CSV
- Other
- Other data export formats
-
- Microsoft Excel and compatible
- JSON
- XML
- Data import formats
-
- CSV
- Other
- Other data import formats
-
- Microsoft Excel or compatible
- JSON
- XML
- Inbound API
- PDF (SDS Data)
Data-in-transit protection
- Data protection between buyer and supplier networks
- TLS (version 1.2 or above)
- Data protection within supplier network
- TLS (version 1.2 or above)
Availability and resilience
- Guaranteed availability
- We provide a 99.9% uptime commitment, with planned maintenance scheduled in advance and communicated to clients. Maintenance is carried out out-of-hours wherever possible and, unless responding to a security critical event, will always be performed outside normal business hours. All changes follow controlled release procedures with full rollback plans in place, and our service credits and remedies are defined within the contract.
- Approach to resilience
-
The service is hosted across multiple datacentres to maximise resilience, so the loss of a single site should not interrupt availability. It runs within a virtualised platform designed for high availability, with built in redundancy across multiple parallel instances to maintain service if an individual component or instance fails.
In the very rare event of a wider outage affecting the whole service, we maintain a documented disaster recovery plan to support full restoration. As part of our ISO 27001 arrangements, this plan is regularly exercised through simulated tests to validate recovery procedures and strengthen ongoing resilience. - Outage reporting
-
Planned outages are communicated through the inbuilt news feed with appropriate notice to allow clients to plan accordingly.
In addition, for any planned outage scheduled to occur or unplanned service event, clients receive direct email notifications, ensuring timely and transparent communication.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Public key authentication (including by TLS client certificate)
- Identity federation with existing provider (for example Google Apps)
- Dedicated link (for example VPN)
- Username or password
- Other
- Other user authentication
- Single Sign On can be enabled either using our native SSO capability or by integrating with a customer managed identity provider that supports WS-Federation and SAML2.0. Two factor authentication is enforced as standard for all user accounts, and every user is issued a unique username.
- Access restrictions in management interfaces and support channels
- Access to the service is tightly controlled through granular user privileges and clearly defined permission levels. Clients have no access to the underlying hosting environment; all administration is conducted securely via the application’s user interface, ensuring operational control while maintaining system integrity.
- Access restriction testing frequency
- At least every 6 months
- Management access authentication
-
- Identity federation with existing provider (for example Google Apps)
- Username or password
- Other
- Description of management access authentication
- Single Sign On can be enabled either using our native SSO capability or by integrating with a customer managed identity provider that supports WS-Federation and SAML2.0. Two factor authentication is enforced as standard for all user accounts, and every user is issued a unique username.
Audit information for users
- Access to user activity audit information
- Users have access to real-time audit information
- How long user audit data is stored for
- At least 12 months
- Access to supplier activity audit information
- Users have access to real-time audit information
- How long supplier audit data is stored for
- At least 12 months
- How long system logs are stored for
- At least 12 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
-
- CSA CSM version 4.0
- ISO/IEC 27001
- Information security policies and processes
-
Our ISO 27001:2022 certified policies and procedures govern access to infrastructure and client data, ensuring only authorized team members can access sensitive information. Access is role-based, with permissions granted according to operational need.
All staff are trained on security policies, with annual refresher training to maintain awareness. Oversight is provided by our Board of Directors, supported by system controls that ensure policies are consistently applied across the organisation.
All ISOs adopted by Riskex are UKAS accredited. - Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
-
All change requests are meticulously tracked throughout their lifecycle and incorporated into the main systems, where they continue to be monitored for support and operational integrity. All developments undergo rigorous testing against OWASP Top 10 standards and additional security controls to mitigate potential risks. Cross-browser and platform testing ensures full compatibility and a consistent user experience.
Our change management and development processes are fully aligned with ISO 27001:2022 and ISO 9001:2015, ensuring robust governance, compliance, and consistent delivery of secure, high-quality solutions. - Vulnerability management type
- Supplier-defined controls
- Vulnerability management approach
- We operate continuous security monitoring to identify vulnerabilities and maintain robust patch management routines to keep underlying software and components up to date. When a potential weakness is detected, it is assessed and prioritised through our risk management process, with remediation planned and delivered based on the severity and potential impact.
- Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
- Riskex use SIEM tooling to provide ongoing security event monitoring and alerting, with actionable reports and escalations directed to our network team for timely investigation and response.
- Incident management type
- Supplier-defined controls
- Incident management approach
- We are accredited to ISO 27001 and operate a robust, fully documented information security incident management process aligned to our Information Security Management System. This approach defines clear roles, responsibilities and escalation routes for identifying, reporting, triaging, investigating and resolving security incidents. The process is regularly reviewed and tested as part of our ISO 27001 governance and audit programme to ensure it remains effective, up to date and continuously improved.
- Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- Yes
- Free trial available
- Yes
- Description of free trial
- Free trials are available on request. Where a trial is provided, the trial period is agreed in advance and the environment is set up to reflect your requirements, including the relevant modules and an appropriate initial configuration, so you can evaluate the service in a realistic way.
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 5%
- Between £500,001 and £1,000,000
- 4%
- Between £1,000,001 and £2,500,000
- 3%
- Between £2,500,001 and £5,000,000
- 2%
- Over £5,000,001
- 1%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- Yes
- Who accredited the ISO/IEC 27001
- 3Core2 (UKAS Accredited)
- ISO/IEC 27001 accreditation date
- Monday 17 March 2014
- What the ISO/IEC 27001 doesn’t cover
-
Our scope is as follows;
The provision of cloud-based management solutions, consultancy and training
services. This is in accordance with the Statement of Applicability, Version 4 dated
18/03/2025 - ISO 28000:2022 certification
- No
- ISO 9001 certification
- Yes
- Who accredited the ISO 9001 certification
- 3Core2 (UKAS Accredited)
- ISO 9001 accreditation date
- Friday 13 September 2013
- What the ISO 9001 doesn’t cover
-
Our scope is as follows:
The provision of cloud-based management solutions, consultancy and training
services. - Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- 616d0ad9-7819-42a4-aef5-e93575cc3c64
- Cyber essentials plus
- No
- Cyber Essentials Alternative
- In relation to the services you do not have a current and valid Cyber Essentials Plus certificate which has been awarded by one of the government approved Cyber Essentials accreditation bodies but you are working towards gaining it, and will be in a position to confirm that you have been awarded a current and valid Cyber Essentials Plus certificate by one of the government approved accreditation bodies within 12 months of the date of award.
- Other security certifications
- No
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- Plans to engage the contract workforce in deciding the most important workplace issues to address
- Employment contracts that reflect actual hours worked; steps taken to ensure employees understand their contracts and have the ability to review and adjust them if actual hours regularly exceed contracted hours
- Activities to cascade good practice on fair working conditions throughout the supply chain
- Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
- Understanding of in-work progression issues affecting the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors
- Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
- Outline policies and practices to be applied to or put in place for the contract to mitigate and manage modern slavery risks, including: Pre-employment checks, recruitment practices. Workplace conditions, safeguarding plans and processes in place and regular monitoring with relevant groups considered, which may include sampling
- How these flow down the supply chain and are monitored Illustrative examples include reporting, site visits, audits, etc.
- How to ensure business decisions re: price/cost, short lead times, payment timescales do not create modern slavery risks in the supply chain
-