Picker & Qualtrics Experience Management (XM) Platform for Patient and Staff Insight
A cloud platform combining Qualtrics Experience Management (XM) with Picker’s independent, pathway‑led implementation. It enables organisations to collect, analyse, and act on patient, staff, and service insight through surveys, AI‑driven analytics, and structured onboarding, training, governance, and support to accelerate improvement and assure quality.
Features
- Multi‑channel feedback collection across digital, SMS, email, and kiosks.
- AI‑driven analytics for themes, sentiment, and experience drivers.
- Closed‑loop workflows for routing, escalation, and action tracking.
- Role‑based dashboards for board, service, and frontline insight.
- Validated patient and staff question sets from Picker.
- Pathway‑led configuration: Define, Design, Deploy, Drive, Develop.
- Secure UK or EEA hosting with strong encryption controls.
- Integration via APIs with HRIS, EPR, CRM, and BI tools.
- Accessibility support including WCAG‑aligned survey and content patterns.
- Enable, Deliver, or Managed Service options for ongoing support.
Benefits
- Improve service quality through timely patient and staff insight.
- Strengthen governance with assured, evidence‑based experience reporting.
- Accelerate time to insight with AI‑supported analysis.
- Reduce duplication by unifying patient and staff feedback systems.
- Support safer care through earlier identification of experience‑related risks.
- Improve workforce culture using linked staff and patient experience data.
- Increase operational efficiency with automated follow‑up workflows.
- Build internal capability through Picker’s pathway‑led implementation support.
- Ensure consistent, inclusive feedback using validated question sets.
- Enhance decision‑making with role‑based dashboards and clear experience drivers.
Pricing
- Free trial available
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
6 2 2 1 7 6 3 9 0 0 9 2 4 1 9
Contact
PICKER INSTITUTE EUROPE
Alex Rawet
Telephone: 01865 208100
Email: picker.tenders@pickereurope.ac.uk
About your service
- Service categories
-
Application Development and Deployment
Analytics and business intelligence
- Business Intelligence
- Multi cloud support
- No
Service scope
- Software add-on or extension
- Yes, but can also be used as a standalone service
- What software services is the service an extension to
- Qualtrics XM integrates experience data with core systems such as CRM, HRIS, EPR and BI tools to automate actions and enrich operational insight. Picker designs and assures these integrations through discovery, configuration, and governance alignment, ensuring safe, reliable use whether deployed alongside existing systems or as a standalone platform.
- Cloud deployment model
- Public cloud
- Service constraints
- Customers are always on the latest version of the Qualtrics platform because upgrades are mandatory and applied automatically. Service usage is limited to the purchased subscription volumes (e.g. interactions or employee headcount); exceeding these limits may result in restricted access or require the purchase of additional capacity. Qualtrics also relies on supported browsers, identity providers, and approved integration patterns. Export formats and API rate limits may constrain very large or high‑frequency use cases. Picker helps organisations plan for these constraints through discovery, governance alignment, configuration assurance, and proactive review of volumes and integrations to ensure safe, reliable, and well‑managed adoption.
- System requirements
-
- Supported Browsers: Latest Chrome, Edge, Firefox, and Safari versions.
- Browser Features: JavaScript and cookies must be enabled.
- Security Protocol: TLS 1.2 or higher required.
- Internet Connection: Stable broadband connection for administration.
- Offline App (iOS): Requires iOS 9.0 or later.
- Offline App (Android): Requires Android 5.0 or later.
- XM App (Latest): Requires iOS 16+ or Android 12+.
- Desktop OS: Windows 7.0 or newer supported.
- Resolution: Minimum screen resolution required for dashboards.
- Ad Blockers: Disable browser ad blockers for surveys.
User support
- Email or online ticketing support
- Yes
- Support response times
-
With 24x7 coverage:
Severity 1 (Critical). Defined as Service Down/Unavailable; Total halt of business operations. Typical initial response time target is 1 hour or less.
Severity 2 (High). Defined as Major functionality impaired; Significant impact on core business operations. Typical initial response time target is 4 hours or less.
Within local business hours:
Severity 3 (Medium). Defined as Partial loss of non-critical functionality; Workaround available. Typical initial response time target is Next Business Day.
Severity 4 (Low). Defined as General question, minor issue, or request for enhancement. Typical initial response time target is 2 Business Days. - User can manage status and priority of support tickets
- No
- Phone support
- Yes
- Phone support availability
- 24 hours, 7 days a week
- Web chat support
- Yes
- Web chat support availability
- 24 hours, 7 days a week
- Web chat support accessibility standard
- None or don’t know
- How the web chat support is accessible
-
Webchat is made accessible through adherence to the WCAG 2.1 AA standards, primarily ensuring compatibility with assistive technologies like screen readers and keyboard-only navigation.
Key accessibility features include:
Semantic HTML and ARIA: The chat interface uses proper HTML structure and ARIA (Accessible Rich Internet Applications) attributes to clearly define roles, states, and properties of elements (like chat fields, send buttons, and notification alerts) for screen readers.
Keyboard Operability: All controls (sending messages, navigating conversations, opening/closing the chat window) are fully operable using only the keyboard, supporting users who cannot use a mouse.
Visual Clarity: Text contrast meets minimum WCAG standards, and dynamic content changes (new messages arriving) are communicated to screen readers via ARIA live regions without disrupting the user's focus.
Language and Focus: The chat window accurately declares the content language, and focus management is maintained; when the chat window opens or closes, focus is correctly moved to allow users to immediately interact or return to the main page content.
This systematic approach ensures the webchat tool is usable by the broadest possible audience. - Web chat accessibility testing
-
Yes, the Qualtrics Webchat/Feedback interface has been tested with users who require assistance as part of its commitment to WCAG 2.1 AA standards.
Testing is conducted through two main channels:
Internal QA: Qualtrics' dedicated accessibility teams integrate user research and QA throughout the development lifecycle, specifically testing with popular assistive technologies such as JAWS, NVDA, and VoiceOver to ensure seamless keyboard navigation and screen reader functionality.
External Validation: The platform undergoes external review and certification (e.g., via WebAIM) to validate conformance across critical, user-facing components.
These processes confirm that the interface structure and controls are accessible. However, it is crucial for buyers to note that the final accessibility of the content created and deployed within the webchat remains the customer's responsibility to ensure compliance. - Onsite support
- Yes, at extra cost
- Support levels
-
Support for the service is provided jointly by Qualtrics and Picker, depending on the level required.
Qualtrics offers:
Self-Service (Tier 0): Users access a vast knowledge base, documentation, and the Qualtrics Support AI Assistant for immediate answers to common issues.
Technical Support: Available 24/7/365, primarily for licensed users to submit tickets regarding product questions, troubleshooting, and technical issues. This includes assistance from senior product specialists for complex issues.
Account Services Support: Handles non-technical requests, such as licensing, billing, upgrades, and general account administration.
Enterprise Support (Elevated): An enhanced support option for premium customers, offering rapid and proactive assistance from senior product specialists and dedicated Technical Success Managers (TSMs) for strategic guidance.
Picker provides:
A named engagement lead and scheduled service reviews across our three support models: Enable (coaching and advisory), Deliver (time‑boxed configuration support), and Manage (end‑to‑end managed service). The team are available across UK business hours.
Picker does not replace Qualtrics platform‑level technical support but complements it with implementation, governance, and operational assurance. - Support available to third parties
- Yes
- AI chatbot
- Yes
Onboarding and offboarding
- Getting started
-
Users are supported through a structured onboarding process delivered jointly by Qualtrics and Picker. Following technical provisioning and configuration, users gain access to Qualtrics Basecamp, which provides self service online training, webinars, role specific learning paths, and documentation for administrators, researchers, and analysts.
Quick Start Guides and Welcome Tutorials help users launch their first surveys or dashboards rapidly, and depending on their subscription tier, a Qualtrics Customer Success Manager (CSM) or Technical Success Manager (TSM) may provide live, role based training to support early proficiency.
Picker complements this with onboarding via the named engagement lead. Picker provides role based training for the relevant individuals at the organisation, including hands on sessions and support with interpreting early insight.
Where organisations select Deliver or Managed Service options, Picker also establishes full programme plans and schedules to ensure deployment and upskilling of staff for the timely and reliable capture of insight through the Qualtrics platform. This combined onboarding model enables users to move quickly from platform activation to confident, safe, and effective use of patient and staff experience data. - Service documentation
- Yes
- Documentation formats
- HTML
- End-of-contract data extraction
-
When the contract ends, users extract their data through a secure, structured offboarding process that must be completed before service decommissioning. Following termination notification, the organisation specifies required data formats (such as CSV, JSON, XML) and the secure target location for transfer.
Users can export most data directly through built in Qualtrics tools, including survey responses, dashboards, and metadata. For larger datasets or full database extractions, Qualtrics’ Offboarding Manager coordinates an encrypted transfer of all confirmed Customer Data using agreed secure channels such as SFTP or a secure file transfer service.
A verification window (typically 30 days) allows the organisation to confirm data integrity before final system deletion. Data is purged only after formal sign off, in line with Qualtrics’ deletion commitments.
Picker’s role in data extraction depends on the chosen support model. Under Enable, organisations manage exports themselves using platform tools, with Picker providing guidance if required. Under Deliver, Picker supports administrators in preparing exports, documenting configuration, and ensuring safe handover. Under Manage, Picker coordinates the full offboarding workflow, including preparing and transferring exports, providing configuration records, and ensuring continuity of insight assets for transition to a new provider. - End-of-contract process
-
At the end of the contract, a structured offboarding process is initiated to ensure users can extract and retain their data before service decommissioning.
Organisations confirm required export formats (for example CSV, JSON, XML) and specify a secure destination for transfer. Most data can be exported directly through built in Qualtrics tools, including survey responses, dashboards, and metadata.
For large or complete dataset extractions, Qualtrics’ Offboarding Manager coordinates an encrypted transfer using secure channels such as SFTP. A verification window (typically 30 days) allows the organisation to confirm data integrity before final deletion. Data is removed only once formal sign off is received.
Picker’s role depends on the support model. Under Enable, the organisation performs exports using platform tools, with optional guidance from Picker. Under Deliver, Picker assists administrators with preparing exports and documentation. Under Manage, Picker leads the full offboarding workflow, including preparing and transferring exports, providing configuration records, and ensuring continuity for transition to a new provider.
Core offboarding activities, including access to export tools and Qualtrics led data deletion, are included in the contract price. Additional support from Picker, would be chargeable and related to the scope of works required. - Documentation accessibility standard
- None or don’t know
- How the documentation is accessible
-
The accessibility of Qualtrics’ onboarding and offboarding documentation is managed in line with recognised global standards for digital content. Documentation, including quick start guides, user manuals, and support articles, is primarily delivered in two formats.
1. HTML based documentation (online help)
Most support material is provided through the Qualtrics Support Portal in HTML format. This content is designed to align with WCAG 2.1 AA principles to ensure it is perceivable, operable, understandable, and compatible with assistive technologies. Accessibility features include structured headings, sufficient colour contrast, meaningful link text, and support for screen readers and keyboard only navigation.
2. PDF documents
Some formal documents, such as service definitions or administrative guides, may be supplied in PDF format. While Qualtrics aims to follow accessible PDF practices, including tagging, logical reading order, and alt text, levels of WCAG 2.1 AA conformance may vary between documents, as PDFs require deliberate authoring to ensure full accessibility.
Overall, Qualtrics’ electronic documentation generally conforms to recognised accessibility standards, including WCAG derived criteria used in the Revised U.S. Section 508 and the harmonised EN 301 549 (European standards).
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Application to install
- Yes
- Compatible operating systems
-
- Android
- IOS
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
-
The core difference lies in function: the Desktop experience is for creation and administration, while the Mobile experience is primarily for consumption and collection.
The Desktop (Browser) experience offers the full platform suite, enabling users to design complex surveys, build detailed dashboards, manage accounts, and run sophisticated analysis.
The Mobile experience uses specialised apps:
Offline Survey App: Allows data collection in the field without internet access.
XM App: Optimised for viewing dashboards, monitoring metrics, and receiving urgent alerts on the go.
Mobile is functional but does not support the deep feature set of the desktop browser environment. - Service interface
- Yes
- User support accessibility
- None or don’t know
- Description of service interface
-
The core Qualtrics Service Interface is a comprehensive, browser-based dashboard environment. Upon login, users access a centralised hub to manage projects, user accounts, and data.
The interface is logically organised, featuring separate workspaces for Project Creation (Survey Builder), Distribution, Data & Analysis, and Reporting (CX/EX Dashboards). It provides role-based access, ensuring administrators have full control over security settings and system integration points (APIs), while analysts focus on visualisations and key metrics. The interface is the primary tool for all platform administration and design tasks. - Accessibility standards
- None or don’t know
- Description of accessibility
-
The Qualtrics service is designed for accessibility under WCAG 2.1 AA standards for the end-user facing components (e.g., surveys and webchat).
Accessible Functions (Users Can Do): Respondents using screen readers (like JAWS, NVDA) or keyboard-only navigation can access, navigate, and successfully complete the vast majority of surveys and feedback forms.
Inaccessible Functions (Users Cannot Do): The complex administrative and design interface (Survey Builder, Dashboards, Analysis Tools) is often not fully accessible to those relying heavily on screen readers. Therefore, users with those needs cannot efficiently perform full platform administration, design complex survey logic, or build detailed reports. - Accessibility testing
-
Yes, the Qualtrics interface has been tested with users who require assistance as part of its commitment to WCAG 2.1 AA standards.
Testing is conducted through two main channels:
Internal QA: Qualtrics' dedicated accessibility teams integrate user research and QA throughout the development lifecycle, specifically testing with popular assistive technologies such as JAWS, NVDA, and VoiceOver to ensure seamless keyboard navigation and screen reader functionality.
External Validation: The platform undergoes external review and certification (e.g., via WebAIM) to validate conformance across critical, user-facing components.
These processes confirm that the interface structure and controls are accessible. However, it is crucial for buyers to note that the final accessibility of the content created and deployed within the webchat remains the customer's responsibility to ensure compliance. - API
- Yes
- What users can and can't do using the API
-
The Qualtrics API supports large‑scale automation and data flow management. Users can set up the service by integrating survey response data, metadata, and distributions into external data warehouses or business intelligence tools. The API enables administration tasks such as creating and managing user accounts, permissions, brands, and divisions. Users can also programmatically create, update, and deploy survey projects, including editing questions, blocks, logic, and survey flow. Contact lists can be created, updated, and synchronised to automate sampling and trigger personalised distributions. Workflow actions can be initiated through the API, allowing external systems (for example CRM or ticketing platforms) to automatically trigger surveys or follow‑up processes.
There are limitations. Qualtrics Support does not provide assistance with custom API coding, so organisations require in‑house development capability. Visual design of dashboards and survey look & feel cannot be fully configured through the API and is mainly performed in the web interface. API endpoints are subject to rate limits that restrict high‑frequency or large‑volume calls; exceeding limits may temporarily prevent further requests. Retrieving specific response IDs can require multi‑step export processes rather than a direct single call. These constraints should be considered when designing automated integrations or high‑volume data pipelines. - API documentation
- Yes
- API documentation formats
- HTML
- API sandbox or test environment
- No
- Customisation available
- Yes
- Description of customisation
-
Buyers can customise the Qualtrics service through configuration within the browser interface. Customisation is performed across four main areas.
User Experience (UX) and Logic:
Researchers and Survey Designers use the drag‑and‑drop interface and Survey Flow editor to control question types, routing, conditional logic, scoring, and respondent journeys.
Service Look & Feel:
Survey Designers and Brand Administrators configure branding, logos, colours, themes, and accessibility settings using the Look and Feel editor to align with organisational identity.
Data Flow and Integration:
IT teams or Developers customise data movement using the API or by configuring Workflow Actions. This supports integration with external systems such as CRM, HRIS, EPR, and ticketing platforms, enabling automated contact management or event‑triggered surveys.
Reporting:
Analysts and Administrators configure CX/EX dashboards, selecting metrics, filters, visualisations, and role‑based access to create tailored reporting views.
In addition, Picker customises each implementation to local requirements, including programme design, question set alignment, hierarchy structures, governance workflows, escalation patterns, dashboards, and access controls. Picker works with operational, IG, and clinical teams during discovery and design to ensure the configuration reflects local policies, priorities, and requirements. Customisation can be carried out by trained client administrators or by Picker under Enable, Deliver, or Managed Service models.
Scaling
- Independence of resources
- Qualtrics prevents performance issues caused by other users through a resilient, multi‑layered cloud architecture. It uses AWS load balancing and redundancy across multiple availability zones to distribute traffic and avoid single‑resource bottlenecks. Logical separation ensures each customer operates within an isolated tenant environment with partitioned, encrypted data. Auto‑scaling adjusts compute resources in real time to absorb sudden increases in demand without affecting other users. Intensive analytical operations are routed to dedicated database resources, preventing complex queries from impacting core survey collection or dashboard performance.
Analytics
- Service usage metrics
- Yes
- Metrics types
- Users can access key service metrics through Qualtrics’ standard dashboards. These include response rates, survey flow metrics such as drop‑off points and completion times, automated ticket generation, user activity covering logins and project creation, and dashboard load times. Qualtrics also reports core service‑level metrics used to monitor platform performance, including system availability, latency between the user and the hosting region, and incident reporting that summarises high‑severity issues and their resolution times. Together, these metrics help organisations monitor performance, understand usage patterns, and assess the reliability and responsiveness of the service.
- Reporting types
-
- Real-time dashboards
- Regular reports
- Reports on request
- Resource tagging
- No
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Reseller providing extra support
- Organisation whose services are being resold
- Qualtrics
Staff security
- Staff security clearance
- Other security clearance
- Government security clearance
- None
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
-
- United Kingdom
- European Economic Area (EEA)
- User control over data storage and processing locations
- Yes
- Datacentre security standards
- Managed by a third party
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- ‘IT Health Check’ performed by a CREST-approved service provider
- Protecting data at rest
- Other
- Other data at rest protection approach
-
Protecting data at rest and physical access relies on AWS's layered security and strong encryption.
All customer data is secured at rest using AES 256-bit encryption at the database and disk level. Qualtrics' host, AWS, ensures physical protection by meeting stringent standards like SOC 2 Type II and ISO 27001. These include layered security zones, biometric access control, and 24/7 surveillance of their data centers. Optional Data Isolation adds a second, application-level encryption layer for maximum security assurance. - Data sanitisation process
- Yes
- Equipment disposal approach
- Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
- Data sanitisation type
-
- Deleted data can’t be directly accessed / Cryptographic Erasure
- Data Erasure
- Explicit overwriting of storage before reallocation / Secure Erase
- Physical Destruction / Hardware containing data is completely destroyed
Data importing and exporting
- Data export approach
-
Users can export their data at any time using the built in tools in the Qualtrics platform. Survey responses, metadata, dashboards, and operational reports can be downloaded in open formats such as CSV, TSV, JSON, XML, Excel, and SPSS. Exports can be run on demand or scheduled, and organisations can use the API for automated or high volume data extraction. For more complex datasets, secure transfer methods such as SFTP can be used.
Picker supports organisations to manage exports safely and consistently through guidance, configuration assurance, or full service management depending on the chosen support model. - Data export formats
-
- CSV
- Other
- Other data export formats
-
- TSV: Tab‑delimited text format for large or structured datasets.
- Excel (.xlsx): Spreadsheet format for viewing and analysis.
- PowerPoint (.pptx): Export dashboards or charts into slides.
- Word (.docx): Document format for reports or summaries.
- PDF: Static format for sharing final non‑editable reports.
- SPSS: Statistical format for analysis in SPSS software.
- XML: Structured text format for complex data exchange.
- JSON: Lightweight format for APIs and web applications.
- QSF: Proprietary format for copying or backing up surveys.
- Data import formats
-
- CSV
- Other
- Other data import formats
-
- TSV: Tab‑delimited format for larger datasets.
- Excel (.xlsx): Spreadsheet format for user or response data.
- JSON: Lightweight API format for batch uploads.
- XML: Structured API format for complex data ingestion.
- SFTP: Secure automated transfer for bulk imports.
- API: Programmatic real‑time or high‑volume data streaming.
- Manual entry: Direct input for small datasets.
Data-in-transit protection
- Data protection between buyer and supplier networks
-
- TLS (version 1.2 or above)
- Other
- Other protection between networks
-
Protecting data between the buyer's network and the Qualtrics service relies on mandated, multi-layered encryption of data in transit.
All communication, including web traffic and API calls, is secured using TLS 1.2 or higher encryption. This scrambles the data as it crosses the public internet. For bulk transfers, SFTP (Secure File Transfer Protocol) provides an additional encrypted channel. Buyers can also enhance perimeter control through IP Whitelisting, restricting platform access to only approved network addresses. This combination ensures end-to-end data confidentiality. - Data protection within supplier network
- Other
- Other protection within supplier network
-
Data protection within the Qualtrics network is managed through strong encryption and strict internal access controls.
All customer data is secured at rest using industry-standard AES 256-bit encryption across the platform's database servers. Logical separation is maintained for each customer's data within the multi-tenant environment. Access to the underlying systems and data by Qualtrics personnel is restricted to a ""need-to-know"" basis, supported by monitored access logs and audited compliance with standards like SOC 2 Type II and ISO 27001. Furthermore, customers can purchase Data Isolation, which adds a second, application-level layer of encryption using customer-specific keys.
Availability and resilience
- Guaranteed availability
-
Availability Guarantee and SLA
Qualtrics warrants a high monthly system availability level of 99.93% for the production environment, excluding scheduled maintenance. The customer's exclusive remedy for a breach of this Service Level Agreement (SLA) is a Fee Credit applied to future invoices. If monthly downtime is 30 minutes or less, no credit is issued. For downtime between 31 to 120 minutes, a 5.0% credit is provided. Downtime lasting 121 to 240 minutes warrants a 7.5% credit, and any downtime of 241 minutes or greater results in a 10.0% credit on the affected service's fees. Furthermore, the customer gains the right to terminate the subscription if the SLA is breached significantly (four consecutive months, or five or more months in any 12-month period, or if availability drops below 95% in one month). - Approach to resilience
-
Qualtrics utilises AWS (Amazon Web Services) as its preferred cloud provider, ensuring the data centre setup is inherently resilient and adheres to core cloud security principles.
Resilience (High Availability)
The platform achieves resilience through redundancy across multiple Availability Zones (AZs) within a geographical region (e.g., AWS London). This prevents correlated failures. The architecture features quick failover points, redundant hardware, and auto-scaling groups to dynamically meet demand spikes, guaranteeing the committed 99.93% availability. Qualtrics also maintains an extensive Disaster Recovery Plan (DRP), tested at least twice annually.
Cloud Security Principles
Qualtrics leverages cloud principles by:
Encryption: Enforcing encryption in transit (TLS) and encryption at rest (AES-256) for all customer data.
Logical Isolation: Utilising strong logical partitioning within the multi-tenant environment, managed by high-end firewalls.
Security Services: Employing managed AWS security services and a 24/7 Security Operations Center (SOC) for continuous monitoring and intrusion detection. - Outage reporting
-
Qualtrics uses a transparent, proactive, and multi-channel system to report service outages and degradation, ensuring customers are promptly informed.
Official Status Page: The primary source is the Qualtrics Status Page (status.qualtrics.com). This page provides real-time updates on the operational status of core services and regional components (e.g., Survey Platform, CX Dashboards). Users can subscribe via email or text to receive instant notifications when an incident is posted or updated.
Notification Tiers: Outages are classified by severity (Maintenance, Warning for degraded performance, or Down for a critical issue). Notifications include the scope, affected regions, and expected resolution timeline.
In-Product Communication: During a critical outage, status messages may also be displayed within the product interface to alert logged-in administrators and users.
Scheduled Maintenance: For planned service interruptions, Qualtrics issues advance notice (typically five days) to minimise impact on customer operations.
For a customer to claim a Fee Credit under the SLA, they must submit a support ticket to Qualtrics for validation, linking the reported outage to the confirmed impact on their specific account.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Identity federation with existing provider (for example Google Apps)
- Username or password
- Access restrictions in management interfaces and support channels
- Access is restricted through mandatory Role-Based Access Control (RBAC), which is managed by the customer's Brand Administrator. RBAC enforces precise permissions, limiting user access to specific projects, data fields, and administrative functions (e.g., ensuring analysts only see data from their region). For Support Channels, users must first authenticate and explicitly grant a support agent temporary login consent for troubleshooting. All agent activity is fully logged and auditable by the customer’s administrator, adhering to a strict internal "need-to-know" principle.
- Access restriction testing frequency
- At least every 6 months
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Identity federation with existing provider (for example Google Apps)
- Username or password
Audit information for users
- Access to user activity audit information
- Users have access to real-time audit information
- How long user audit data is stored for
- Between 1 month and 6 months
- Access to supplier activity audit information
- Users contact the support team to get audit information
- How long supplier audit data is stored for
- Between 1 month and 6 months
- How long system logs are stored for
- Between 1 month and 6 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
-
- CSA CSM version 4.0
- ISO/IEC 27001
- Information security policies and processes
-
Qualtrics and Picker both operate robust Information Security Management Systems (ISMS) with clearly defined policies, responsibilities, and controls to protect confidentiality, integrity, and availability.
Qualtrics follows a formal ISMS aligned to international standards. It is independently audited against ISO 27001, SOC 2 Type II, FedRAMP High, and ISO 42001 for responsible AI governance. Cyber Essentials is held, with Plus in place from August 2026. Security governance is overseen by a dedicated Security Governance Committee, supported by risk assessments, policy reviews, and continuous improvement processes. Day to day monitoring, threat detection, and incident response are delivered by a 24/7 Security Operations Center. Policies cover access control, secure development, vulnerability management, change control, and operational security.
Picker maintains its own ISMS and is certified to ISO 27001:2022, ISO 27701:2019 (privacy information management), ISO 20252:2019 (research quality), and holds Cyber Essentials Plus. Security policies include risk management, access control, incident management, governance oversight, supplier assurance, secure configuration, and business continuity. Compliance is monitored through internal audits, external certification audits, and formal governance through the Picker Quality Assurance Forum. Picker ensures secure configuration, data handling, and governance when implementing and supporting Qualtrics services, following UK GDPR and NHS Data Security and Protection Toolkit requirements. - Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Configuration and change management approach
-
Qualtrics follows a structured change management process aligned with industry best practice. Changes are categorised as Standard, Normal, or Emergency based on risk.
Standard changes are pre-authorised with low risk; whilst Normal and Emergency changes require formal review and approval, with testing carried out in non‑production environments to confirm stability and security before deployment.
Configuration management controls maintain a secure baseline, and automated monitoring detects any deviation from approved settings. All changes are logged and auditable, ensuring traceability across the lifecycle of system components. Security impact assessments form part of the review process to ensure changes do not introduce vulnerabilities. - Vulnerability management type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Vulnerability management approach
-
The process itself is multi-layered and includes:
Continuous Scanning: Automated vulnerability scans are performed regularly on internal systems, firewalls, and application code.
Annual Penetration Testing: An independent, third-party firm conducts an annual application penetration test (aligned with CREST methodology) to actively discover security flaws.
Vulnerability Disclosure Program: Qualtrics maintains a public Vulnerability Disclosure Policy that encourages ethical security researchers to report findings responsibly.
Remediation: Identified vulnerabilities are prioritised based on their risk and severity (CVSS score) and promptly remediated by the in-house Security Operations Centre (SOC). Critical patches are applied immediately, and all activities are logged for audit purposes. - Protective monitoring type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Protective monitoring approach
-
The process itself is multi-layered and includes:
Continuous Scanning: Automated vulnerability scans are performed regularly on internal systems, firewalls, and application code.
Annual Penetration Testing: An independent, third-party firm conducts an annual application penetration test (aligned with CREST methodology) to actively discover security flaws.
Vulnerability Disclosure Program: Qualtrics maintains a public Vulnerability Disclosure Policy that encourages ethical security researchers to report findings responsibly.
Remediation: Identified vulnerabilities are prioritised based on their risk and severity (CVSS score) and promptly remediated by the in-house Security Operations Centre (SOC). Critical patches are applied immediately, and all activities are logged for audit purposes. - Incident management type
- Complies with a recognised standard, for example, CSA CCM v4.0 or ISO/IEC 27035:2011 or SSAE-18 / ISAE 3402
- Incident management approach
- The Qualtrics Incident Management process is formal, documented, and based on NIST 800-53 and ISO 27001 standards. It is driven by the 24/7 Security Operations Center (SOC). The process ensures rapid detection and analysis through sophisticated monitoring systems. Once contained, the SOC prioritises transparent customer communication via the official Status Page, detailing the scope and recovery timeline. The process is regularly tested and audited (per SOC 2 Type II requirements) to ensure continuous effectiveness in restoring service availability and integrity.
- Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- No
- Free trial available
- Yes
- Description of free trial
-
Qualtrics provides a free account with three active surveys, up to 30 questions each, and 500 total responses. It includes basic logic and templates but excludes advanced analytics, dashboards, and email distribution.
A 30‑day trial of selected paid solutions is also available with access to premium features.
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 0%
- Between £500,001 and £1,000,000
- 0%
- Between £1,000,001 and £2,500,000
- 0%
- Between £2,500,001 and £5,000,000
- 0%
- Over £5,000,001
- 0%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- Yes
- Who accredited the ISO/IEC 27001
- Moss Adams Certifications LLC
- ISO/IEC 27001 accreditation date
- Thursday 16 October 2025
- What the ISO/IEC 27001 doesn’t cover
- Anything outside of the scope of ISO27001.
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- Yes
- Who accredited the ISO 9001 certification
- TUVRheinland
- ISO 9001 accreditation date
- Saturday 1 November 2025
- What the ISO 9001 doesn’t cover
- Anything outside of the scope of ISO9001
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- 8b9f0af6-5d57-4216-bf1e-325b46e6e328
- Cyber essentials plus
- No
- Cyber Essentials Alternative
- In relation to the services you do not have a current and valid Cyber Essentials Plus certificate which has been awarded by one of the government approved Cyber Essentials accreditation bodies but you are working towards gaining it, and will be in a position to confirm that you have been awarded a current and valid Cyber Essentials Plus certificate by one of the government approved accreditation bodies within 12 months of the date of award.
- Other security certifications
- Yes
- Any other security certifications
-
- FedRAMP High
- SOC 2 Type II
- ISO 42001
- HITRUST CSF
- IRAP
- TISAX
- ISO 27017
- ISO 27018
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
- Plans to engage the contract workforce in deciding the most important workplace issues to address
- Monitoring of employee engagement rates (by protected characteristic) and, where necessary, the development of actions to ensure all voices are heard across the diversity of the workforce
- Employment contracts that reflect actual hours worked; steps taken to ensure employees understand their contracts and have the ability to review and adjust them if actual hours regularly exceed contracted hours
- Activities that support an environment where staff are educated about, and feel empowered to, address their physical wellbeing
- Activities that support an environment where staff are educated about and feel empowered to report and address bullying and harassment
- Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
- Monitoring and reporting of gender and ethnicity pay gaps and plans to address them where necessary
- Entitlement to sick pay for the contract workforce, with provision in place for any staff who do not meet the earnings threshold for statutory sick pay, payment of sick pay from day one of absence and payment of staff on the contract workforce who are off sick a replacement income of 100% of their usual earnings for as long as possible
-
Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero
Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.
- Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
- Collaborative ways of working with the supply chain to deliver additional environmental benefits in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
-
Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain
Policy Outcome 6: Employment and training: For those who face barriers to employment
- Inclusive and accessible recruitment practices, and retention-focused activities, including those provided in the Guide for line managers on recruiting, managing and developing people with a disability or health condition
- Introducing transparency to pay and reward processes
- Working conditions which promote an inclusive working environment and promote retention and progression
- Other measures to provide equality of opportunity for disabled people and those with health conditions into employment, including becoming a Disability Confident employer and inclusion of supported businesses in the contract supply chain
- Understanding of the issues affecting inequality in employment, skills and pay in the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors. Measures to tackle inequality in employment, skills and pay in the contract workforce
- Inclusive and accessible development practices, including guidance for line managers on recruiting, managing and developing people with a disability or health condition
-
Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.
Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.
- Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce
- Understanding barriers to access to health and social care services or employment opportunities e.g. digital inclusion
- Inclusive and accessible recruitment practices, development practices and retention policies that support-focused activities including those provided in the Guide for line managers on recruiting, managing and developing which support people with a disability or health condition
- Actions to invest in the physical and mental health and wellbeing of the contract workforce
-