HSE Incident Management & Reporting
The HSE Incident Management & Reporting service is a cloud-based application for recording, managing, investigating, and analysing workplace health and safety incidents. It provides structured incident capture, workflow-driven follow-up actions, and management reporting to support organisational health and safety obligations, including alignment with RIDDOR reporting requirements.
Features
- Digital incident reporting forms accessible via desktop and mobile devices
- Structured capture of injury, near-miss, hazard, and safety event data
- Configurable incident categories and severity classifications
- Workflow-driven investigation and follow-up actions
- RIDDOR-aligned data capture fields to support statutory reporting
- Role-based access controls
- Automated notifications and task assignments
- Management dashboards and incident trend reporting
- Integration with Microsoft 365 identity, email, and collaboration services
Benefits
- Consistent and auditable incident reporting across the organisation
- Improved response times through automated workflows
- Reduced administrative overhead compared to paper-based processes
- Improved visibility of health and safety risks and trends
- Supports regulatory reporting obligations without duplicating data
- Data remains within the organisation’s Microsoft 365 environment
Pricing
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
6 3 4 7 1 5 4 6 8 5 5 8 0 8 6
Contact
OFFICELABS LIMITED
Graham Bidwell
Telephone: 01392 24 0 365
Email: sales@officelabs.co.uk
About your service
- Service categories
-
Applications
Enterprise resource management
Human capital management
- Core Human Resources Applications
- Multi cloud support
- No
Service scope
- Software add-on or extension
- Yes
- What software services is the service an extension to
- The service operates independently and does not require additional third-party platforms beyond Microsoft 365. Optional configuration and enhancement services are available separately.
- Cloud deployment model
- Public cloud
- Service constraints
-
Requires an active Microsoft 365 tenant
Internet connectivity required
RIDDOR assessment and submission remain the responsibility of the customer - System requirements
-
- Microsoft 365 subscription
- Modern web browser (Edge, Chrome, Firefox, Safari)
- User accounts managed via Microsoft Entra ID
User support
- Email or online ticketing support
- Yes
- Support response times
- Support requests submitted via email or the online ticketing system are monitored during UK business hours, Monday to Friday, excluding public holidays. Initial responses are typically provided within one business day. Requests received outside business hours are reviewed on the next working day. Response times may vary depending on the nature and priority of the request.
- User can manage status and priority of support tickets
- Yes
- Online ticketing support accessibility
- None or don’t know
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- No
- Onsite support
- Yes, at extra cost
- Support levels
-
Support is provided as a standard service level included with the software subscription. This includes access to email and online ticketing support during UK business hours, Monday to Friday, excluding public holidays. Support covers incident logging, fault investigation, and resolution of software-related issues.
Enhanced support services, including extended support hours, prioritised response, onsite assistance, and advisory support, are available at additional cost and are procured separately under appropriate Cloud Support listings.
OfficeLabs does not provide a dedicated technical account manager or cloud support engineer as part of the standard software subscription. Where required, customers may procure named technical resources, implementation support, or ongoing service management through separate Cloud Support services.
All support requests are managed through a structured ticketing process, with issues prioritised based on impact and urgency. - Support available to third parties
- Yes
Onboarding and offboarding
- Getting started
-
Users can start using the service through a structured onboarding process supported by documentation and guided configuration within the service interface. Documentation enables administrators to configure the service, set permissions, and tailor reporting to organisational requirements.
Optional onboarding assistance, including remote guidance sessions, configuration support, and administrator training, is available at additional cost under appropriate Cloud Support services. These services are not mandatory to use the software and are designed to help administrators become self-sufficient in managing and operating the service following initial setup. - Service documentation
- Yes
- Documentation formats
- End-of-contract data extraction
-
Users can extract service data using standard export and reporting capabilities prior to contract termination. Outputs such as reports, configuration data, and analysis results can be exported in commonly used digital formats.
Where the service connects to external repositories or platforms, the underlying source data remains under the buyer’s control and is not affected by contract termination. Users are responsible for exporting any required data before the end of the contract term.
Optional assistance with data extraction, validation, or transition planning is available at additional cost under appropriate Cloud Support services but is not required to complete data extraction. - End-of-contract process
-
At the end of the contract term, access to the service is withdrawn in line with the agreed notice period. Users are responsible for exporting any required reports, outputs, or configuration data before access ends.
The contract price includes access to the software service and standard support during the contract term only. No automatic data migration, extended access, or post-termination services are included. Optional transition support, assisted data extraction, or consultancy services can be provided at additional cost under separate Cloud Support services where required.
Ownership and control of any external or source data connected to the service remain with the buyer at all times. - Documentation accessibility standard
- None or don’t know
- How the documentation is accessible
-
Documentation is provided in digital formats accessible via standard web browsers. Users can apply browser-based accessibility features such as zoom, text resizing, screen magnification, and keyboard navigation. Content is structured to support clear navigation and readability.
Where documentation is hosted or delivered via third-party platforms, accessibility is dependent on the features supported by those platforms and standard browser technologies. Users can request reasonable adjustments or alternative formats where required.
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Application to install
- No
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
-
The service provides the same core functionality on both mobile and desktop devices. Differences are limited to interface layout and screen scaling to suit the form factor of the device.
On mobile devices, screens are optimised for touch interaction and smaller displays, with content presented in a single-column layout where appropriate. On desktop devices, the interface takes advantage of larger screens to display additional information simultaneously.
All data capture, workflows, permissions, and reporting capabilities are consistent across mobile and desktop access. - Service interface
- Yes
- User support accessibility
- None or don’t know
- Description of service interface
- The service provides a secure, browser-based user interface for configuring data sources, managing discovery activities, and viewing analysis results. Users can access dashboards, reports, and administrative functions through role-based access controls. The interface supports search, filtering, and export of discovery outputs to support governance, migration, and data management activities. No client-side software installation is required to access the interface.
- Accessibility standards
- None or don’t know
- Description of accessibility
- The service is accessed through a standard web browser and supports common accessibility features provided by modern browsers and operating systems, such as keyboard navigation, screen magnification, and zoom. Users can access dashboards, reports, and configuration features through the web interface. Some advanced configuration and data analysis functions may be less suitable for certain assistive technologies due to the complexity of the workflows.
- Accessibility testing
- No formal user testing has been conducted specifically with users of assistive technologies. Accessibility is supported through the underlying software platform and standard browser accessibility features. Where accessibility issues are identified, these can be raised through the support process and are reviewed to determine whether reasonable adjustments can be made.
- API
- No
- Customisation available
- Yes
- Description of customisation
-
Users can customise the service through configuration and administrative settings without the need for custom code.
Customisation options include the ability to configure incident types and categories, define data fields captured during incident reporting, and tailor forms to reflect organisational health and safety processes. Workflow stages, task assignments, and notification rules can be adjusted to support internal escalation and investigation procedures.
Role-based access controls allow organisations to define who can view, create, update, or manage incidents. Reporting views and dashboards can be configured to surface metrics relevant to the organisation.
All configuration is performed within the customer’s Microsoft 365 environment using standard administrative tools.
Scaling
- Independence of resources
-
Users are not affected by demand from other organisations because the service is deployed and operated within each buyer’s own Microsoft 365 environment. Application data, permissions, and usage are isolated to the buyer’s tenant and are not shared across customers.
Service performance and capacity are governed by Microsoft 365 and Power Platform tenant controls, including service-level resource management and throttling applied by Microsoft. Any demand generated by one buyer does not consume resources allocated to another buyer.
Within a buyer’s tenant, administrators can manage access, capacity, and usage through standard Microsoft 365 and Power Platform administration controls.
Analytics
- Service usage metrics
- Yes
- Metrics types
-
The service provides operational and usage metrics derived from data captured within the application and the underlying Microsoft Power Platform services.
Metrics available include the number of incidents recorded, incident types and categories, status and resolution outcomes, time taken to progress incidents through workflow stages, user activity related to incident creation and updates, and reporting volumes over defined periods.
Where enabled through Microsoft 365 and Power Platform services, administrators can also access audit and usage information relating to user interactions, data changes, and application access. The availability and granularity of metrics depend on service configuration, licensing, and user permissions. - Reporting types
-
- Real-time dashboards
- Regular reports
- Resource tagging
- No
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Conforms to BS7858:2019
- Government security clearance
- Security Clearance (SC)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- United Kingdom
- User control over data storage and processing locations
- Yes
- Datacentre security standards
- Managed by a third party
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- Another external penetration testing organisation
- Protecting data at rest
-
- Physical access control, complying with another standard
- Encryption of all physical media
- Data sanitisation process
- Yes
- Equipment disposal approach
- A third-party destruction service
- Data sanitisation type
-
- Deleted data can’t be directly accessed / Cryptographic Erasure
- Data Erasure
Data importing and exporting
- Data export approach
-
Users can export data using built-in reporting and export features available through the browser-based service interface. Authorised users can download reports, analysis outputs, and configuration data directly without the need for additional tools.
Where the service connects to or analyses external repositories, the underlying source data remains in place and is not moved, copied, or extracted by the service. - Data export formats
-
- CSV
- Other
- Other data export formats
-
- CSV
- Structured text formats for analysis outputs
- Data import formats
-
- CSV
- Other
- Other data import formats
- Structured text formats for configuration data
Data-in-transit protection
- Data protection between buyer and supplier networks
- TLS (version 1.2 or above)
- Data protection within supplier network
- TLS (version 1.2 or above)
Availability and resilience
- Guaranteed availability
-
The service is delivered as a cloud-based application operating within the buyer’s Microsoft 365 environment. Availability of the service is dependent on the availability of Microsoft 365, the Microsoft Power Platform, and the buyer’s internet connectivity.
No specific uptime percentage is guaranteed as part of the standard service offering. Access to the service is provided on an “as provided” basis. The contract price does not include service credits, automatic refunds, or bespoke service level agreements linked to availability.
Availability issues are managed through the support process in line with incident management procedures. Any enhanced availability commitments or additional service levels would need to be agreed separately and are not included as part of the standard software subscription. - Approach to resilience
-
The service leverages the built-in resilience and high-availability features of the Microsoft 365 and Power Platform cloud services. These platforms provide redundancy across infrastructure components such as compute, storage, and networking to reduce the impact of individual component failures.
Microsoft applies platform-level monitoring, fault detection, and automated recovery processes to maintain service continuity. Data is stored within Microsoft-managed cloud services that support replication and backup in line with Microsoft’s service design.
Physical datacentre security, environmental controls, power resilience, and network connectivity are provided by Microsoft as part of the underlying cloud platform. Information regarding Microsoft’s resilience architecture and datacentre operations is published by Microsoft and can be referenced where required. - Outage reporting
-
Service availability issues can be reported through the supplier’s support channels, including email or online ticketing. Users will receive updates on incident status and resolution through the support process.
Where availability issues relate to Microsoft 365 or the Power Platform, additional information may be available via Microsoft’s Service Health Dashboard within the Microsoft 365 admin centre. The service does not provide a dedicated public status dashboard or customer-accessible outage reporting API.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Identity federation with existing provider (for example Google Apps)
- Username or password
- Access restrictions in management interfaces and support channels
-
Access to management interfaces is restricted using role-based access controls provided by Microsoft 365 and the Microsoft Power Platform. Users authenticate through Microsoft Entra ID, and access is granted only to authorised users assigned appropriate roles within the buyer’s tenant.
Administrative permissions control who can configure the service, manage data, and access reporting features. Support channels are restricted to authorised buyer contacts, with requests managed through authenticated email or ticketing systems.
Supplier access to customer environments is not provided by default and is only granted where explicitly authorised by the buyer for support purposes. - Access restriction testing frequency
- At least once a year
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Identity federation with existing provider (for example Google Apps)
- Username or password
Audit information for users
- Access to user activity audit information
- Users have access to real-time audit information
- How long user audit data is stored for
- User-defined
- Access to supplier activity audit information
- Users contact the support team to get audit information
- How long supplier audit data is stored for
- At least 12 months
- How long system logs are stored for
- At least 12 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
- ISO/IEC 27001
- Information security policies and processes
-
OfficeLabs operates a formal information security management framework aligned with ISO/IEC 27001. Documented policies and procedures cover areas including access control, data protection, incident management, risk assessment, supplier management, and business continuity. Policies are reviewed regularly to ensure continued relevance and effectiveness.
Overall responsibility for information security sits with a named board-level role, supported by operational security leads who oversee day-to-day implementation. Security risks are identified, assessed, and managed through a structured risk management process, with findings escalated where required.
Compliance with security policies is supported through defined processes, role-based responsibilities, staff awareness activities, and internal review mechanisms. Security incidents and weaknesses are reported through established channels and managed in line with documented incident response procedures.
Third-party services used in the delivery of the service are assessed as part of supplier and risk management processes to ensure appropriate security controls are in place. The effectiveness of information security controls is monitored and reviewed as part of ongoing governance activities. - Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
- Configuration items relating to the service are identified and managed through documented configuration and change management processes. Changes are requested, assessed, approved, and implemented in a controlled manner, with records maintained to track components throughout their lifecycle. Proposed changes are reviewed for potential security, availability, and operational impact before implementation. Where changes may affect security controls, additional risk assessment and mitigation steps are applied. Changes are tested where appropriate and implemented in line with defined procedures to reduce the risk of unintended impact.
- Vulnerability management type
- Supplier-defined controls
- Vulnerability management approach
- Potential threats are identified through a combination of vendor security advisories, cloud provider notifications, vulnerability disclosures, and internal review. Reported vulnerabilities are assessed based on risk, impact, and exploitability. Remediation actions are prioritised accordingly. Security patches and updates are applied in a controlled manner and within reasonable timescales based on severity and operational impact. Where vulnerabilities relate to third-party components or hosting platforms, remediation is coordinated with the relevant suppliers. Vulnerability status and remediation actions are tracked through established operational security processes.
- Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
- Protective monitoring activities are used to identify potential security events and compromises through review of service logs, alerts, and notifications from underlying platforms and suppliers. Potential incidents are assessed to determine impact and severity. Where a compromise is suspected, predefined incident response procedures are followed to contain, investigate, and remediate the issue. Incidents are responded to promptly and prioritised based on risk and potential impact, with escalation applied where necessary in line with documented security and incident management processes.
- Incident management type
- Supplier-defined controls
- Incident management approach
- The organisation operates documented incident management processes covering identification, assessment, response, and resolution of security and service incidents. Pre-defined procedures are in place for common incident types to support consistent handling and escalation. Users can report incidents through email or the online ticketing system. Incidents are logged, prioritised based on impact and urgency, and managed through to resolution. Where appropriate, users are provided with updates and post-incident information outlining the nature of the incident, actions taken, and any relevant follow-up.
- Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- No
- Free trial available
- No
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 3%
- Between £500,001 and £1,000,000
- 5%
- Between £1,000,001 and £2,500,000
- 7%
- Between £2,500,001 and £5,000,000
- 10%
- Over £5,000,001
- 12%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- Yes
- Who accredited the ISO/IEC 27001
- Alcumus ISOQAR
- ISO/IEC 27001 accreditation date
- Tuesday 7 October 2025
- What the ISO/IEC 27001 doesn’t cover
-
The ISO/IEC 27001:2022 certification applies to the OfficeLabs Information Security Management System (ISMS) as defined in the documented scope and Statement of Applicability.
The certification does not cover customer-owned systems, infrastructure, networks, or devices that are not operated or managed by OfficeLabs, including client environments accessed for consultancy or delivery purposes. It also does not extend to third-party platforms or services used by OfficeLabs, except where these are governed through supplier due diligence, contractual controls, and ongoing risk management within the ISMS.
End-user locations, home networks, and personal equipment are not directly certified, beyond the organisational policies and controls applied to remote working. Activities, information assets, or processing operations that fall outside the formally defined ISMS scope are also excluded.
As with all management system certifications, the ISO/IEC 27001 certification is based on limited audit sampling and does not guarantee the absence of all non-conformances.
All information assets, systems, and services within the defined scope are managed in accordance with ISO/IEC 27001:2022, with risks outside the scope addressed through governance, supplier management, contractual obligations, and risk assessment processes. - ISO 28000:2022 certification
- No
- ISO 9001 certification
- No
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- 89b8902b-27bd-4ea6-a83b-54fad105966b
- Cyber essentials plus
- Yes
- Please provide your Cyber Essentials Plus Certificate Number
- 8c841283-44fe-4dc5-85ee-6208d10fd4a5
- Other security certifications
- No
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
- Employment contracts that reflect actual hours worked; steps taken to ensure employees understand their contracts and have the ability to review and adjust them if actual hours regularly exceed contracted hours
- Activities that support an environment where staff are educated about and feel empowered to report and address bullying and harassment
- Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
- Measures to support in-work progression to help people in the contract workforce, to move into higher paid work by developing new skills relevant to the contract
- Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.
- Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
-