Skip to main content

Help us improve the Digital Marketplace - send your feedback

MRI SOFTWARE LIMITED

MRI Advanced Financials

Delivered in conjunction with our partner Advanced, cloud-based financial management system designed with sector-specific configurations to address the unique needs of various industries. It offers real-time reporting, budgeting, procurement, AI automation and scalability for growing teams, multi-entity accounting and remote work, reducing manual tasks, improving accuracy, and delivering instant insights.

Features

  • Real-time financial reporting and analysis across all cost centres.
  • Budget management with approval workflows and spending controls.
  • Integrated procurement and invoice processing.
  • Customisable dashboards for tracking budgets, forecasts, and performance.
  • Multi-entity and consolidated accounting.
  • Integration with payroll, HR, and other core systems.
  • Scalable system supporting growing finance teams.
  • Intuitive interface reducing training time and user support needs.
  • Secure cloud-based access from any device, anytime, anywhere.
  • Budget modelling and forecasting.

Benefits

  • Reduce manual data entry, freeing finance teams for analysis.
  • Speed up month-end close with efficient reconciliations and workflows
  • Improve budget control by monitoring spend against plans in real-time.
  • Achieve accuracy and consistency with one unified source of truth.
  • Give leaders instant visibility of financial performance with clear reports.
  • Reduce errors with and speed up processes with AI automation.
  • Support remote working with secure browser-based finance access.
  • Enable quick adoption with fast and efficient implementation processes.
  • Help non-finance users self-serve reports, reducing ad-hoc requests to finance.
  • Scale easily as teams grow without expensive infrastructure upgrades.

Pricing

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at tenders@mrisoftware.com. Tell them what format you need. It will help if you say what assistive technology you use.

Framework

G-Cloud 15

Service ID

5 9 8 1 7 1 8 1 2 0 6 7 0 8 5

Contact

MRI SOFTWARE LIMITED Claire Brown
Telephone: 020 3861 7100
Email: tenders@mrisoftware.com

About the service

Service categories

Applications

Enterprise resource management

Financial

  • Financial and Accounting Applications
  • Accounts Payable Applications
  • Accounts Receivable Applications
  • Treasury and Risk Management Applications
  • Travel and Expense Management Applications
  • Corporate Tax Management Applications
Multi cloud support
No

Service scope

Software add-on or extension
No
Cloud deployment model
Private cloud
Service constraints
The solution only requires an internet connection and a device that supports the latest browsers. Any planned maintenance will be completed (where possible) outside of core office hours and customers will be notified in advance.
System requirements
  • Latest internet browsers
  • Internet connection

User support

Email or online ticketing support
Yes
Support response times
Email or online ticketing support Yes Support response times MRI’s Global Client Support group will make every reasonable effort to ensure that submitted cases are assigned the proper level of Severity. Submitted cases will be responded to in the order in which they are received, with consideration given for higher Severity levels. Response Time is the time it takes before a Global Client Support agent makes initial contact with the individual who submitted case. Standard Service: Normal Priority - 6 Hours, Serious Priority - 3 hours, Critical Priority - Live Call Only
User can manage status and priority of support tickets
No
Phone support
Yes
Phone support availability
9 to 5 (UK time), Monday to Friday
Web chat support
No
Onsite support
Yes, at extra cost
Support levels
We include support within our annual fee. Support includes a named Account Manager and a Client Support Helpdesk. The Client Support Helpdesk also serves as the contact for all cloud support requests for trained users. Cases and incidents can be recorded and viewed in the client portal on a 24/7 basis. The Portal provides clients with information on support cases, regardless of whether a call is logged via a phone call or via the portal. We categorize our priority levels as:Normal - An area of core functionality is generating errors but this is not preventing the Client from performing day to day use of the Software. A workaround may be available.Serious - The production system is able to run core processes but other functionality is significantly impaired. Client’s ability to carry out day to day use of the Software is severely impacted. There is no reasonably acceptable workaround.Critical - The production system is significantly impaired with core functionality essentially unavailable. Client’s day to day use of the software is severely impacted. There is no available workaround. Response time targets: Critical Priority-Live call Serious Priority-3 hours Normal Priority-6 hours
Support available to third parties
No

Onboarding and offboarding

Getting started
Onboarding (training) is available and follows a train the trainer approach. Our training includes an overview of relevant legislation, walk through the system modules and a 'hands on' session supported by step-by-step user guides. Sessions are delivered in a supportive environment designed to facilitate learning. All applicable documentation will be provided in a pre-agreed format.
Data migration strategies and configurations will be agreed upon as part of the project kick-off, with the right plan set out based upon customer needs, capacity and budget. Throughout the project, our data migration consultant will advise on the mapping of MRI fields to the current sources to ensure the data is loaded accurately. The process will be iterative, and as part of the validation exercise, our consultants will be in regular contact to advise on data cleansing and corrections as necessary.
Service documentation
Yes
Documentation formats
  • HTML
  • PDF
End-of-contract data extraction
Data can be exported from the system via reporting tools in CSV format to MS Excel which can then be used to import into other applications.
End-of-contract process
Clients will have the ability to export to Microsoft Excel© from every list screen from within the system.

If Clients are unable to extract their data using data export or standard reports MRI can provide with a copy of your data on exit.

The data will be provided in a predetermined format. If there are requirements which are different from our standard approach, we can discuss these with Clients to draw up an appropriate exit plan.

The initial de-commissioning (powering down of client-server images and movement to non-production storage) takes place on the agreed date (e.g. contract end date) with permanent de-commissioning taking place one month after the initial de-commissioning date (backups removed, and server images purged). Any restrictions shall be determined by the contract.
Documentation accessibility standard
WCAG 2.2 AA

Using the service

Web browser interface
Yes
Supported browsers
  • Microsoft Edge
  • Firefox
  • Chrome
  • Safari
  • Opera
Application to install
No
Designed for use on mobile devices
Yes
Differences between the mobile and desktop service
The core Financials has been designed for the most used devices for core Finance users. It’s primary use is for extended monitors (1920x1080) or laptop screens where users will get an experience which is for its intended purpose. The design will be dynamic and optimised with appropriate zoom functionalities for both, using clear input field structure which will responsively adjust to suit the user’s preferences. However, we understand that some light users require access via mobile for the approval of transactions and as such have designed our procurement portals and air approvals applications to enable mobile interaction for this purpose.
Service interface
Yes
User support accessibility
WCAG 2.2 AA
Description of service interface
User Interface and Integration Browser-Based Access: All services are accessible via a browser without requiring desktop plugins. Integration Options: Flexible integration services are available through RESTful APIs, SFTP, email, and other communication channels, facilitating comprehensive data exchange and system connectivity.
Accessibility standards
WCAG 2.2 AA
Accessibility testing
We are committed to providing solutions that are accessible to the widest possible audience and in the past have tested our solution with tools such as Windows Narrator and JAWS screen reader.
API
Yes
What users can and can't do using the API
Create, Read, Update, Delete functions are available.
API documentation
Yes
API documentation formats
  • Open API (also known as Swagger)
  • HTML
API sandbox or test environment
No
Customisation available
Yes
Description of customisation
Configurable controls and policy settings.

Scaling

Independence of resources
The server infrastrucure is based on a virtualised infrastructure which is monitored 24x7. Services are automatically migrated across the virtual infrastructure to automatically load balance the entire infrastructure. This ensures that no one service is unduely impacted by load placed on the infrastructure by other users. If another service is using a large amount of resources, other services are automatically migrated to other servers in the virtual infrastructure that are being utilised to a lesser extent.

Analytics

Service usage metrics
Yes
Metrics types
System access reports are available from within the system. Service metrics are available from within the system covering user activity (search actions performed, etc.,) in addition to business transactions. Infrastructure is monitored in real time with proactive monitoring ahead of agreed thresholds being breached, whereby incident management action is triggered.
Reporting types
  • Real-time dashboards
  • Reports on request
Resource tagging
No
FOCUS resource tagging
No

Supplier type

Supplier type
Reseller providing extra support
Organisation whose services are being resold
OneAdvanced

Staff security

Staff security clearance
Other security clearance
Government security clearance
Developed Vetting (DV)

Asset protection

Knowledge of data storage and processing locations
Yes
Data storage and processing locations
  • United Kingdom
  • European Economic Area (EEA)
  • Other locations
User control over data storage and processing locations
No
Datacentre security standards
Managed by a third party
Penetration testing frequency
At least once a year
Penetration testing approach
‘IT Health Check’ performed by a CHECK service provider
Protecting data at rest
  • Encryption of all physical media
  • Other
Other data at rest protection approach
Our SQL databases are encrypted at rest using transparent data encryption. Physical access control, inline with ISO27001
Data sanitisation process
Yes
Equipment disposal approach
Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
Data sanitisation type
Deleted data can’t be directly accessed / Cryptographic Erasure

Data importing and exporting

Data export approach
There are options to export through: a) provided export processes; b) reports; c) download function for listed data; d) through the use of Bring Your Own BI (BYOBI) users can access and export data using their own BI tools.
Data export formats
  • CSV
  • Other
Other data export formats
  • JSON
  • XML
Data import formats
  • CSV
  • Other
Other data import formats
  • Via an Import Toolkit
  • XML
  • Spreadsheet upload functions from Excel are also supported
  • JSON

Data-in-transit protection

Data protection between buyer and supplier networks
  • TLS (version 1.2 or above)
  • Other
Other protection between networks
All data through the application is delivered over a secure connection (as a web site - password protected, API through token authentication - OAUTH2). No data stores are publicly accessable and are protected by multiple security layers.
Data protection within supplier network
  • TLS (version 1.2 or above)
  • Other
Other protection within supplier network
No data is moved into the corporate network and only resides in the private cloud. All access to the cloud environment is restricted to security checked personal. Multi factor authentication is used to secure access. Access to the cloud servers is only via the corporate network. If not directly on the corporate network an IPSEC MFA connection is required to the corporate network to gain access.

Availability and resilience

Guaranteed availability
We use commercially reasonable efforts to ensure availability twenty -four (24) hours a day, seven (7) days a week, except for: (a) planned downtime (of which we provide adequate notice and will schedule to the extent practicable during the weekend hours), or (b) any unavailability caused by circumstances beyond our reasonable control, including without limitation, Force Majeure events or internet service provider failures or delays. We host our solution in a UK-based Tier 3 data centre that is designed to deliver high availability.
Approach to resilience
Available on request.
Outage reporting
The Advanced Event Management service will monitor the environment and provide: Proactive monitoring and alerting of thresholds and events, Root Cause Analysis of identified problems, Reporting and trend analysis System and application-specific knowledge and tasks. When thresholds are breached within the PaaS environment, staff nominated to receive alerts will be informed via email or SMS. Advanced will respond to alerts and remediate any issues within the supported environment.

Identity and authentication

User authentication needed
Yes
User authentication
  • Multi-Factor Authentication (MFA)
  • Username or password
Access restrictions in management interfaces and support channels
All users have a unique username and password to ensure only authorised users are accessing the solution. Further restrictions can be put in place including an IP whitelist ensuring only approve IP addresses can access the system.
Multi-factor Authentication and Single Sign On may be configured as required.
Access restriction testing frequency
At least every 6 months
Management access authentication
  • Multi-Factor Authentication (MFA)
  • Username or password

Audit information for users

Access to user activity audit information
Users have access to real-time audit information
How long user audit data is stored for
User-defined
Access to supplier activity audit information
Users have access to real-time audit information
How long supplier audit data is stored for
User-defined
How long system logs are stored for
Between 6 months and 12 months

Security governance

Named board-level person responsible for service security
Yes
Security governance certified
Yes
Security governance standards
ISO/IEC 27001
Information security policies and processes
All staff are issued with our security policy when they join and confirm that they understand and will adhere to this. Our security policy is supported by processes and procedures such as our data breach reporting, new starters and leavers procedures. Our software development process incorporate privacy by design with security at the heart of everything that we do. All staff are trained on our security processes when they join and have regular refresher training. Our policies and processes are regularly reviewed by our operations managers and the outputs of these reviews are, in turn, reviewed with senior management. The focus of these reviews are the performance and ongoing applicability of our security quality management system.
Software Security Code of Practice
Yes

Operational security

Configuration and change management standard
Supplier-defined controls
Configuration and change management approach
Implementation is managed according to a pre-defined process. Change log items are identified early in the implementation process. These are assessed for size and impact to determine if the change will be done, won't be done (notwithstanding the customer may disagree) or might be done as an additional cost item. If the change falls outside (or it is not clear) of the existing DPIA for the software then the change will be assessed by the dedicated Data Compliance Manager. Once agreed changes are built, tested and accepted as would be the case for core functionality.
Vulnerability management type
Supplier-defined controls
Vulnerability management approach
Regular internal risk assessments, scheduled audit, penetration testing (internal and external) and market best practice bench marking. Subject to QA patch release process, patches are released as soon as available.
Protective monitoring type
Supplier-defined controls
Protective monitoring approach
We use industry best practices and applications to protect information confidentiality, integrity, and availability. Manual and automated alerting monitor performance, security, unauthorised access, and data breaches. Continuous monitoring tools provide anomaly detection, threat intelligence, and alerting for user actions, errors, and network traffic. Automated alerts enable swift IT response. Network controls include blacklists, whitelists, SPF for email validation, IDS sensors, and IPS devices. Incidents are logged and managed by policy, with critical and high priority incidents addressed immediately. Customers are informed promptly if impacted. Incident management and disaster recovery plans are regularly tested and reviewed.
Incident management type
Supplier-defined controls
Incident management approach
Our support Help Desk includes first, second and third line support based and will acknowledge and respond to your incident within one working day. Should our first line support team not be able to resolve your issue at first point of contact, it will be categorised, prioritised and passed to our second or third line support teams.
Post-quantum cryptography secure
Yes

Secure development

Approach to secure software development best practice
Conforms to a recognised standard, but self-assessed

Public sector networks

Connection to public sector networks
No

Pricing

Discount for educational organisations
No
Free trial available
No

Discount percentage by annual call-off contract value (excluding VAT)

Less than £250,000
0%
Between £250,000 and £500,000
0%
Between £500,001 and £1,000,000
0%
Between £1,000,001 and £2,500,000
0%
Between £2,500,001 and £5,000,000
0%
Over £5,000,001
0%

Standards and certifications

ISO/IEC 27001 certification
Yes
ISO/IEC 27001 accredited by
Schellman
ISO/IEC 27001 accreditation date
Thursday 4 December 2025
What the ISO/IEC 27001 doesn’t cover
MRI has a number of separate ISO 27001 certifications covering a number of different solutions and hosting environments. However, not all of our solutions are covered by these certifications.
ISO 28000:2022 certification
No
ISO 9001 certification
No
Quality management systems (QMS)
Yes
CSA STAR certification
No
PCI certification
No
Cyber essentials
Yes
Cyber Essentials Certificate Number
Ca5535b7-d879-43af-807e-2fd63222a772
Cyber essentials plus
Yes
Cyber Essentials Plus Certificate Number
8b90bd0e-99b7-4c8f-a863-e742eecf1be4
Other security certifications
Yes
Any other security certifications
  • SOC 1 Type 2
  • SOC 2 Typw 2

Social value

Mission: Kick start economic growth

To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority

  • New or retained jobs on the contract workforce in the relevant area that meet the criteria set out in MAC 1b, 1c and 1d
  • Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
  • Plans to engage the contract workforce in deciding the most important workplace issues to address
  • Ensuring new workers are informed of their right to join a trade union
  • Monitoring of employee engagement rates (by protected characteristic) and, where necessary, the development of actions to ensure all voices are heard across the diversity of the workforce
  • Employment contracts that reflect actual hours worked; steps taken to ensure employees understand their contracts and have the ability to review and adjust them if actual hours regularly exceed contracted hours
  • Activities that support an environment where staff are educated about, and feel empowered to, address their physical wellbeing
  • Activities that support an environment where staff are educated about and feel empowered to report and address bullying and harassment
  • Activities to cascade good practice on fair working conditions throughout the supply chain
  • Offer a pay and leave entitlement to all eligible staff who become kinship carers, ideally equivalent to statutory adoption pay and leave
  • Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
  • Monitoring and reporting of gender and ethnicity pay gaps and plans to address them where necessary
  • Entitlement to sick pay for the contract workforce, with provision in place for any staff who do not meet the earnings threshold for statutory sick pay, payment of sick pay from day one of absence and payment of staff on the contract workforce who are off sick a replacement income of 100% of their usual earnings for as long as possible
  • Understanding of in-work progression issues affecting the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors
  • Measures to support in-work progression to help people in the contract workforce, to move into higher paid work by developing new skills relevant to the contract
  • Support for the contract workforce by providing career advice, and providing opportunities for staff working on the contract with in-work progression career development into known skills shortages or high growth areas
  • Understanding of the modern slavery risks and issues affecting the market, industry, sector or country (of origin or of source) relevant to the contract, and the workforce in the supplier’s own organisation and those of its key subcontractors

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at tenders@mrisoftware.com. Tell them what format you need. It will help if you say what assistive technology you use.