Intelligent Assessments – Continuous Assurance and Assessment Platform
Intelligent Assessments is a cloud platform for continuous assurance, maturity and capability assessments, project, programme and portfolio assurance, governance and compliance. Use existing frameworks, digitise your methodology, or have a tailored framework created. Automated scoring, benchmarking, AI-powered insights and analytics identify risks, compare performance and track improvement.
Features
- Configurable maturity and capability assessments with tailored assessment frameworks
- Project, programme and portfolio assurance assessments and health checks
- AI maturity, AI readiness and data maturity assessments
- PMO, project delivery and asset management maturity assessments
- Governance, compliance and evidence-based continuous assurance assessments
- Create tailored assessment frameworks for specific organisational requirements
- Digitise existing methodologies, frameworks and proprietary assessment IP
- Automated scoring, weighting, benchmarking and comparative analytics
- AI-assisted analysis, summaries and natural-language insight querying
- Continuous reassessment, real-time dashboards and performance trend analysis
Benefits
- Start small with tailored assessments and prove value quickly
- Reduce cost and effort developing new assessment frameworks
- Turn existing methodologies into scalable digital assessment services
- Replace fragmented spreadsheets and manual assessment consolidation
- Standardise assurance and maturity assessments across organisations
- Compare projects, programmes, teams and departments consistently
- Identify emerging risks and improvement opportunities earlier
- Track maturity and performance improvement through repeat assessments
- Reduce reporting effort through automation and AI-assisted insight
- Build reusable assessment capability instead of one-off reviews
Pricing
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
5 6 7 9 0 2 4 4 1 3 2 3 0 2 0
Contact
Intelligent Assessments
Peter Wardle
Telephone: 07487614873
Email: pete@intelligentassessments.ai
About the service
- Service categories
-
Application Development and Deployment
Analytics and business intelligence
- Business Intelligence
- Advanced and predictive analytics
- Multi cloud support
- No
Service scope
- Software add-on or extension
- No
- Cloud deployment model
- Public cloud
- Service constraints
- The service is delivered as a fully managed, browser-based SaaS and requires a modern web browser and internet access. Planned maintenance is scheduled outside normal UK business hours where possible and communicated in advance. The service is hosted on public cloud infrastructure and is not installed on customer-managed environments. Support is provided remotely and does not require specialist hardware.
- System requirements
-
- Modern web browser supporting current security standards
- Reliable internet connection for web-based access
- JavaScript enabled within the browser
- Cookies enabled for secure authentication and session management
- Screen resolution suitable for dashboard and report viewing
- Email access for user notifications and account verification
- No local software installation required
- No additional third-party software licences required
User support
- Email or online ticketing support
- Yes
- Support response times
- We aim to respond to support queries within one UK business day during normal working hours (09:00–17:30, Monday to Friday, excluding public holidays). Critical issues affecting service availability are prioritised. Weekend and out-of-hours queries are monitored but responses may be slower and are handled on the next business day unless otherwise agreed.
- User can manage status and priority of support tickets
- Yes
- Online ticketing support accessibility
- None or don’t know
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- No
- Onsite support
- No
- Support levels
-
The service includes standard support for all customers at no additional cost. Standard support covers remote assistance via email or ticketing during UK business hours (09:00–17:30, Monday to Friday, excluding public holidays). Support includes help with service usage, configuration queries, and incident resolution.
Enhanced support levels, including extended support hours or dedicated support arrangements, can be agreed by exception and priced separately if required.
A dedicated technical account manager or cloud support engineer is not provided as standard. Account oversight and escalation are handled by the supplier’s senior delivery team where appropriate. - Support available to third parties
- Yes
Onboarding and offboarding
- Getting started
-
Users start using the service through a structured onboarding process designed to enable rapid adoption. Access is provided via a secure web interface, with guided setup to create users, roles, and initial assessments. The service includes online user documentation and in-application guidance to support self-service configuration.
Remote onboarding sessions can be provided to introduce core features, demonstrate configuration options, and answer initial questions. These sessions are delivered online and focus on enabling users to independently manage assessments, surveys, and reporting.
Standard templates are available to help users get started quickly, which can be adapted to suit organisational needs. Ongoing support is provided remotely via email or ticketing during UK business hours. The service does not require onsite installation or onsite training, and no specialist hardware or software is needed beyond a modern web browser. - Service documentation
- Yes
- Documentation formats
-
- Other
- Other documentation formats
- Powerpoint
- End-of-contract data extraction
-
At the end of the contract, users can request extraction of their data held within the service. Data will be provided by the supplier in commonly used, machine-readable formats suitable for reuse and migration. Exported data includes assessment content, responses, scores, and associated metadata.
The supplier will work with the buyer to agree the scope and format of data extraction and provide guidance to support transition to alternative systems. Data extraction is performed without the need for proprietary tools.
Following confirmation that data has been successfully provided, customer data is securely deleted from the service in accordance with contractual terms and data protection requirements. - End-of-contract process
-
At the end of the contract, access to the service is withdrawn in line with the agreed contract end date. The supplier will support an orderly exit by providing the buyer with a copy of their data on request in commonly used, machine-readable formats. This includes assessment content, responses, scores, and related metadata.
Standard end-of-contract activities, including data extraction and secure deletion of customer data following confirmation of successful transfer, are included within the contract price. Data is retained for a short, agreed period to allow verification before permanent deletion in accordance with data protection requirements.
Additional services, such as bespoke data transformation, repeated extraction requests, extended data retention beyond the standard period, or additional transition support, may be provided by agreement and may incur additional cost. No proprietary tools are required to access extracted data. - Documentation accessibility standard
- None or don’t know
- How the documentation is accessible
-
Onboarding and offboarding documentation is provided in digital formats designed to be accessible using standard browser and operating system accessibility features. Documentation is available online and can be accessed using screen readers, browser zoom, and text resizing tools. Content is written in clear language, structured with headings and lists to support navigation, and does not rely on colour alone to convey meaning.
Documentation does not require specialist software and can be accessed on a range of devices. Where requested, information can be provided in alternative formats to support individual accessibility needs. The supplier reviews documentation periodically and updates it based on user feedback to improve clarity and usability.
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Opera
- Application to install
- No
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
- The service uses a responsive web interface and can be accessed on mobile devices via a web browser. Core functionality is available on mobile; however, complex configuration, reporting and dashboard analysis are best experienced on larger screens.
- Service interface
- Yes
- User support accessibility
- None or don’t know
- Description of service interface
- The service is accessed through a secure, browser-based web interface providing configuration, data capture, dashboards and reporting functionality.
- Accessibility standards
- None or don’t know
- Description of accessibility
-
The service is delivered through a browser-based web interface designed to be usable with standard accessibility features available in modern browsers. Users can navigate the interface using a keyboard, adjust browser zoom and text size, and access content without requiring specialist software or plugins. The service supports structured forms, clear labelling, and consistent layouts to aid usability.
Some advanced configuration and analytics features are more usable on larger screens and may be less effective on small mobile devices or with limited visual display capabilities. The service does not currently provide a dedicated accessibility mode or guaranteed WCAG conformance. - Accessibility testing
-
The service has not undergone formal accessibility certification or structured testing programmes with assistive technology users. Accessibility considerations have been incorporated as part of general design and development practices, including use of standard web technologies, semantic HTML, and avoidance of unnecessary visual complexity.
Informal testing has been carried out during development using built-in browser accessibility tools and basic screen reader checks to identify obvious navigation or interaction issues. Testing has primarily focused on ensuring the service remains usable with keyboard navigation and standard browser accessibility settings.
Feedback from users is actively monitored, and accessibility-related issues are prioritised where identified. The supplier is committed to improving accessibility over time and will consider formal testing with assistive technologies and remediation activities in response to customer needs and future service development. - API
- Yes
- What users can and can't do using the API
-
The service provides API access primarily to support data integration, reporting, and interoperability with other systems. Users can authenticate securely and use the API to retrieve assessment data, results, scores, and related metadata for analysis and downstream reporting.
Initial service setup, including creation of assessments, templates, users, roles, and permissions, is completed through the web-based user interface rather than the API. The API is not intended for full platform configuration or administrative setup.
Limited changes can be made through the API where supported, such as updating or synchronising selected data fields and triggering data refreshes. Core configuration changes, including assessment structure, scoring logic, weighting, and access control, are managed through the service interface to ensure consistency and governance.
API usage is subject to authentication, authorisation, and rate limiting. Not all service functionality is exposed via the API, and supported endpoints are documented for authorised users. - API documentation
- Yes
- API documentation formats
- HTML
- API sandbox or test environment
- No
- Customisation available
- Yes
- Description of customisation
- Buyers can customise the service through configuration, including assessment structure, questions, scoring, weightings, templates and user access. Customisation is achieved through the service interface and does not require bespoke development or source code changes.
Scaling
- Independence of resources
- The service is delivered as a multi-tenant SaaS hosted on scalable cloud infrastructure designed to manage varying levels of demand. Capacity is monitored and scaled to maintain consistent performance for all users. Usage controls and platform safeguards are applied to prevent individual users or workloads from adversely impacting others. The supplier monitors service performance and addresses capacity or performance issues as part of standard service operations.
Analytics
- Service usage metrics
- Yes
- Metrics types
- The service provides usage metrics such as user activity, assessment participation, and completion levels through dashboards and reports.
- Reporting types
- Real-time dashboards
- Resource tagging
- No
- FOCUS resource tagging
- No
Supplier type
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Other security clearance
- Government security clearance
- Baseline Personnel Security Standard (BPSS)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- United Kingdom
- User control over data storage and processing locations
- No
- Datacentre security standards
- Managed by a third party
- Penetration testing frequency
- Less than once a year
- Penetration testing approach
- ‘IT Health Check’ performed by a CREST-approved service provider
- Protecting data at rest
- Encryption of all physical media
- Data sanitisation process
- Yes
- Equipment disposal approach
- A third-party destruction service
- Data sanitisation type
-
- Deleted data can’t be directly accessed / Cryptographic Erasure
- Data Erasure
Data importing and exporting
- Data export approach
- Users can request export of their data from the service. The supplier provides the data in commonly used, machine-readable formats suitable for reuse and migration. Exported data includes assessment content, responses, scores, and related metadata. The supplier works with the buyer to agree the scope and format of the export and provides guidance where required. Data export does not require proprietary tools and is completed in line with contractual and data protection requirements
- Data export formats
- CSV
- Data import formats
- CSV
Data-in-transit protection
- Data protection between buyer and supplier networks
- TLS (version 1.2 or above)
- Data protection within supplier network
- TLS (version 1.2 or above)
Availability and resilience
- Guaranteed availability
-
The service is designed to be highly available and is hosted on resilient public cloud infrastructure. While no formal percentage uptime guarantee is contractually committed as standard, the service is monitored continuously and operational issues are prioritised for resolution in line with the supplier’s support processes. Planned maintenance is scheduled outside normal UK business hours where possible and communicated in advance.
Availability is measured at the service level and excludes planned maintenance and factors outside the supplier’s reasonable control.
Where availability issues materially affect service use and are attributable to the supplier, the supplier will work with the buyer to investigate the cause and agree appropriate remedial actions. Service credits or refunds are not provided as standard but may be considered by agreement on a case-by-case basis depending on the nature and duration of the issue. - Approach to resilience
-
The service is designed as a cloud-hosted, multi-tenant SaaS running on resilient public cloud infrastructure. The platform uses managed cloud services that are designed for high availability and fault tolerance, with redundancy built into core components. Capacity and performance are monitored to detect and respond to issues that could impact service availability.
The underlying datacentre infrastructure is operated by a major cloud provider and is designed to be resilient through the use of geographically separated facilities, redundant power, networking, and environmental controls. The supplier does not operate or manage physical datacentres directly and relies on the cloud provider’s certified resilience and recovery capabilities.
Data is stored on resilient storage services designed to protect against hardware failure, and regular backups are taken to support recovery. Operational processes are in place to respond to incidents, manage planned maintenance, and restore service where required. Further technical details on the resilience architecture can be provided to buyers on request where appropriate. - Outage reporting
-
Service outages or service-degrading incidents are identified through internal monitoring and operational checks. Where an outage materially affects service availability, affected customers are notified by email with details of the issue, its impact, and progress updates until resolution.
The service does not currently provide a public status dashboard or outage reporting API. Incident communication is managed directly by the supplier to ensure accurate, timely information is shared with relevant users.
Post-incident updates or summaries can be provided on request, including information on cause, resolution, and any remedial actions taken. Planned maintenance that may affect availability is communicated in advance where possible via email notifications.
Identity and authentication
- User authentication needed
- Yes
- User authentication
- Username or password
- Access restrictions in management interfaces and support channels
- Access to management interfaces is restricted to authenticated users and controlled using role-based permissions. Administrative functions are limited to authorised users with appropriate privileges, following least-privilege principles. Access rights are reviewed and updated as roles change. Support channels are restricted to named users associated with the buyer’s account, and requests are validated before action is taken. Sensitive actions are performed only by authorised personnel, with activity logged to support accountability and audit where appropriate.
- Access restriction testing frequency
- Less than once a year
- Management access authentication
- Username or password
Audit information for users
- Access to user activity audit information
- Users contact the support team to get audit information
- How long user audit data is stored for
- Between 6 months and 12 months
- Access to supplier activity audit information
- Users contact the support team to get audit information
- How long supplier audit data is stored for
- Between 6 months and 12 months
- How long system logs are stored for
- Between 6 months and 12 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- No
- Security governance approach
- Security governance is owned at director level, with clear accountability for the security of the service. Security considerations are incorporated into service design, development, and operational processes. The supplier applies recognised good practices for access control, data protection, vulnerability management, and incident response. Cloud hosting security is managed in line with shared responsibility principles, with the supplier responsible for application and data security and the cloud provider responsible for underlying infrastructure. Security risks are reviewed periodically and addressed as part of ongoing service management.
- Information security policies and processes
-
The organisation maintains a set of information security policies and operational processes that define how data is protected, risks are managed, and incidents are handled. Policies cover areas including access control, data protection, secure development, incident management, and data retention and deletion. These policies are reviewed periodically and updated as the service evolves.
Overall accountability for information security sits at director level, ensuring security decisions have appropriate authority and oversight. Day-to-day security responsibilities are managed by the technical leadership team, with escalation to the director where required.
Security policies are implemented through technical controls, cloud-provider managed services, and operational procedures. Access to systems and data is restricted based on role and least-privilege principles. Compliance with policies is supported through monitoring, logging, vulnerability management activities, and external security testing. Security incidents or policy breaches are recorded, investigated, and addressed as part of the supplier’s incident management process. - Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
- Service components are tracked through their lifecycle using version control, deployment records, and configuration management processes. Changes are planned, reviewed, and tested prior to release, with separation between development and live environments. Security impact is considered as part of change assessment, including potential effects on data protection, access controls, and service availability. Changes are deployed in a controlled manner, with rollback procedures in place where appropriate. Significant changes are reviewed by technical leadership and monitored post-deployment to confirm expected behaviour.
- Vulnerability management type
- Supplier-defined controls
- Vulnerability management approach
- Potential threats are identified through a combination of external security testing, monitoring of cloud-provider security advisories, and review of vulnerabilities affecting third-party components. Identified risks are assessed based on impact and likelihood. Patches and remediation actions are prioritised accordingly and deployed as part of controlled release processes. Security fixes are applied as soon as practicable, with higher-risk issues addressed urgently. Information on potential threats is obtained from cloud provider notifications, security bulletins, vulnerability databases, and findings from external penetration testing.
- Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
- The service is monitored using a combination of application logging, cloud-provider monitoring, and operational alerts to identify potential security incidents or service anomalies. Potential compromises are identified through unusual access patterns, error rates, or system behaviour. When an issue is detected, it is assessed to determine impact and severity, and appropriate containment and remediation actions are taken. Incidents affecting service availability or data security are prioritised and responded to promptly during business hours, with escalation where required. Lessons learned are reviewed to reduce the likelihood of recurrence.
- Incident management type
- Supplier-defined controls
- Incident management approach
- The supplier operates defined incident management processes for common service and security events. Incidents can be reported by users via email or the support ticketing process. Reported incidents are assessed, prioritised, and managed according to impact and urgency. Users are kept informed of progress during significant incidents through direct communication. Incident summaries or reports can be provided on request, including details of cause, resolution, and any corrective actions taken. Incident processes are reviewed periodically to support continuous improvement.
- Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Supplier-defined process
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- No
- Free trial available
- No
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 0%
- Between £500,001 and £1,000,000
- 0%
- Between £1,000,001 and £2,500,000
- 0%
- Between £2,500,001 and £5,000,000
- 0%
- Over £5,000,001
- 0%
Standards and certifications
- ISO/IEC 27001 certification
- No
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- No
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- No
- Cyber Essentials Alternative
- In relation to the services you do not have a current and valid Cyber Essentials certificate which has been awarded by one of the government approved Cyber Essentials accreditation bodies but you are working towards gaining it, and will be in a position to confirm that you have been awarded a current and valid Cyber Essentials certificate by one of the government approved accreditation bodies within 12 months of the date of award.
- Cyber essentials plus
- No
- Cyber Essentials Alternative
- You do not have a current and valid Cyber Essentials Plus certificate, or will not have in place within 12 months of the date of award but have an IASME certified equivalent.
- Other security certifications
- Yes
- Any other security certifications
- Independent penetration testing conducted by CREST-approved provider
Social value
- Mission: Kick start economic growth
-
To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.
- Understanding of employment and relevant skills issues, and of the education and training issues relating to the contract. Illustrative examples: demographics, skills shortages, new opportunities in high growth sectors, geographic/local community and skills/employment challenges
- Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
Policy Outcome 3: Resilient, innovative and flexible supply chains: Support economic growth through enabling resilient businesses, opportunities for small businesses and voluntary, community and social enterprises
- Understanding of the types of businesses in the market and the level of participation by new businesses, entrepreneurs, start-ups, SMEs, VCSEs and mutuals
- Activities that demonstrate a collaborative way to work with a diverse range of businesses as part of the supply chain
- Structuring of the supply chain selection process to ensure fairness (e.g. anti-corruption) and encourages participation by a diverse range of businesses, including with regard to new businesses, entrepreneurs, start-ups, SMEs, VCSEs and mutual