Skip to main content

Help us improve the Digital Marketplace - send your feedback

Riskonnect Active Risk Limited trading as Riskonnect. Historic trading names include Xactium, Active Risk Manager (ARM), Castellan Solutions Ltd, ClearView and CAM Management Solutions Limited (CAMMS)

Riskonnect GRC, Strategy and Performance (GSP) Secure (formerly CAMMS)

GSP Secure is a public-sector-ready suite of applications for GRC, Strategy and Performance. Purpose-built to meet stringent security requirements, it helps organisations execute strategy, manage complex programmes, and operationalise GRC frameworks - aligning risk appetite to objectives through a single, trusted platform to improve strategic outcomes.

Features

  • Enterprise Risk Management. Identify, assess, and mitigate enterprise risks
  • Regulatory Compliance. Centralize compliance tracking and regulatory management
  • Internal Audit. Optimize audit planning and execution processes
  • Internal Controls. Automate control testing and monitoring activities
  • Incident Management. Capture, evaluate and remediate any incident
  • Strategic planning. Define and implement strategic and operational plans
  • Performance Management. Monitor KPIs/scorecards to assess strategy and inform decisions
  • PPM. Tools to help your PMO operate effectively and efficiently
  • Benefits Management. Track attainment of strategic outcomes not just outputs

Benefits

  • Improved Decision Making. Data-driven insights aligned to business objectives
  • Align Risk with Strategy. Facilitate a performance-led view of risk
  • Integrated. One platform, end-to-end GRC, Strategy and PPM capabilities
  • Facilitate Cultural Change. Operationalise management frameworks, driving real behavioural change
  • Rapid Time to Value – through efficient and effective onboarding
  • Scalable and Secure. Built with security engineered into every layer
  • Strong Adoption. An intuitive design, supporting engagement with all staff
  • Efficiency Gains. Automated workflows reduce burden and improve collaboration
  • Visibility. Single source of truth for risk and performance data

Pricing

  • Free trial available

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at legal@riskonnect.com. Tell them what format you need. It will help if you say what assistive technology you use.

Framework

G-Cloud 15

Service ID

7 4 9 0 9 8 4 8 9 2 1 9 5 5 3

Contact

Riskonnect Active Risk Limited trading as Riskonnect. Historic trading names include Xactium, Active Risk Manager (ARM), Castellan Solutions Ltd, ClearView and CAM Management Solutions Limited (CAMMS) Shane Yeeda
Telephone: +1 770 790 4683
Email: legal@riskonnect.com

About your service

Service categories

Applications

Enterprise resource management

  • Enterprise performance management
  • Project and portfolio management

Financial

  • Treasury and Risk Management Applications
Multi cloud support
No

Service scope

Software add-on or extension
No
Cloud deployment model
Private cloud
Service constraints
Planned Outage: Prior to a planned outage Riskonnect will send a notification email to all system champions 2 weeks prior to the outage. Within this notification all details will be provided including time, date, length of outage and reasoning. Riskonnect will maintain all planned outages after business hours.
Further, Riskonnect will Deploy severity 1 maintenance releases after business hours which will not be communicated two weeks in prior due to the urgency of the severity 1 incident. However, all the maintenance will be conducted after
business hours.
System requirements
  • Software licenses for users
  • Modern browsers supporting latest standards such as Google Chrome, Microsoft
  • Edge and other common web browsers

User support

Email or online ticketing support
Yes
Support response times
Riskonnect provides 24x7 support for urgent issues, a global hotline and online support portal.
User can manage status and priority of support tickets
Yes
Online ticketing support accessibility
None or don’t know
Phone support
Yes
Phone support availability
24 hours, 7 days a week
Web chat support
No
Onsite support
Yes, at extra cost
Support levels
All customers have access to technical and functional documentation through our Customer Success Portal 24x7 with UK based email and telephone support staff. All support related issues are logged on the portal with full visibility to the client. Each client will have a dedicated Account Executive and Customer Success Manager (CSM) for additional assistance and support as required. The CSM will hold a regular business reviews and maintain a Rolling Action Item Log to ensure you are always getting the very best out of your subscription.
Support available to third parties
No

Onboarding and offboarding

Getting started
We provide a structured onboarding experience designed to help users get started quickly and confidently. We offer a range of training options to suit different user groups, including administrators, technical users, and general users. Administrators and system champions receive onsite or virtual training delivered by our consultants, covering key system functions, configuration, and ongoing maintenance. A train-the-trainer approach is also available to support in-house knowledge transfer.

For broader user onboarding, we provide access to GSP College, our online, self-service learning platform. It includes on-demand product training, guided learning pathways, conceptual and theory-based courses, and practical tutorials developed by product and subject matter experts.

Across all training formats, we deliver a mix of demonstrations, hands-on exercises, and user-friendly documentation to ensure users are well prepared to use the system effectively.
Service documentation
Yes
Documentation formats
PDF
End-of-contract data extraction
Once a customer notifies Riskonnect of their intention to exit, Riskonnect will supply the customer’s data in extractable CSV or Excel file formats.
End-of-contract process
At the end of the contract, Riskonnect delivers the customer’s data in CSV or Excel formats as part of the standard contract price. This ensures secure retention and smooth transition of information.

All databases and backups are securely discarded after one week, with remaining data destroyed within a reasonable timeframe. A data destruction certificate can be issued on request.

Additional services, such as extended data retention, alternative formats, or extra exit-related support, may incur additional costs.

All exit responsibilities, included services, and potential additional costs are detailed in the Riskonnect Software Licensing Agreements, providing customers with clarity and assurance at the conclusion of the service.
Documentation accessibility standard
None or don’t know
How the documentation is accessible
Riskonnect provides a comprehensive range of documentation, including installation guides, user manuals, training materials, support manuals, quick reference guides, test plans, and offboarding documentation. All documentation is available in both electronic and hard-copy formats. Users can access and download the materials through the product’s built-in Help facility or via the Riskonnect online support portal, including the FAQs and documentation sections.

Using the service

Web browser interface
Yes
Supported browsers
  • Microsoft Edge
  • Firefox
  • Chrome
  • Safari
  • Opera
Application to install
No
Designed for use on mobile devices
Yes
Differences between the mobile and desktop service
The service is a cloud-based, web-accessible solution that can be used on any device through a modern browser, providing access to the system’s full functionality, including configuration and administrative tools. Complementing this, iOS and Android mobile apps are also available to offer a streamlined experience designed for quick, on-the-go actions such as viewing tasks and submitting updates. While the web application supports the complete suite of features, the mobile apps focus on core day-to-day activities, thus some complex configuration and administrative settings remain web-only to ensure ease of use and optimal performance. Both the web and mobile apps synchronise seamlessly.
Service interface
No
User support accessibility
None or don’t know
API
Yes
What users can and can't do using the API
Riskonnect GSP provide comprehensive API functionality to build middleware for customers who subscribe for API connector services. With continued enhancements in relation to interoperability representing a key focus area for our product teams, our offering in this space continues to evolve. Riskonnect also supports the building of custom API to consume REST services. We use Swagger for documentation, which is the largest framework for designing APIs using a common language and enabling the development across the whole API lifecycle, including documentation, design, testing, and deployment. Please find below our developer portal, which lists several of our documented / out of the box APIs.
https://developer.cammsconnect.co.uk/
API documentation
Yes
API documentation formats
Open API (also known as Swagger)
API sandbox or test environment
Yes
Customisation available
Yes
Description of customisation
Paid customer modifications - Functionality can be
customised to match the client's requirements.
Configuration - configurations can be adjusted by the client
system administrator.

Scaling

Independence of resources
Riskonnect ensures users are not impacted by demand from other tenants through Azure-based performance monitoring and scalable infrastructure. Our solution runs on Azure IaaS virtual machines that are continuously monitored using Azure Monitor to track load, usage, and system health. When resource thresholds are reached, capacity can be increased to maintain consistent performance. This proactive monitoring and scalable architecture ensure that high activity from one user group does not affect the experience or performance of others.

Analytics

Service usage metrics
Yes
Metrics types
The Riskonnect solution incorporates an embedded error-logging library for rolling log capture, supported by Azure Application Insights for real-time monitoring of system behaviour. All technical and functional errors are automatically recorded in rolling log files, enabling efficient tracing and root-cause analysis. While these logs are not delivered as standard reports, Riskonnect can provide customised error or monitoring reports upon request and at an agreed frequency.
Reporting types
Reports on request
Resource tagging
Yes
FOCUS resource tagging
Yes

Resellers

Supplier type
Not a reseller

Staff security

Staff security clearance
Other security clearance
Government security clearance
Developed Vetting (DV)

Asset protection

Knowledge of data storage and processing locations
Yes
Data storage and processing locations
United Kingdom
User control over data storage and processing locations
Yes
Datacentre security standards
Supplier-defined controls
Penetration testing frequency
At least once a year
Penetration testing approach
Another external penetration testing organisation
Protecting data at rest
  • Physical access control, complying with CSA CCM v4.0
  • Encryption of all physical media
  • Scale, obfuscating techniques, or data storage sharding
Data sanitisation process
Yes
Equipment disposal approach
In-house destruction process
Data sanitisation type
Explicit overwriting of storage before reallocation / Secure Erase

Data importing and exporting

Data export approach
Riskonnect solutions provide a range of standard reporting outputs that allow customers to export data in formats including PDF, Word and Excel. Many organisations also use APIs to import or export data, and Riskonnect supports this approach out of the box as its preferred integration method. A suite of standard APIs is available to facilitate data exchange with other web-based systems, and Riskonnect’s integration team continues to expand these capabilities to meet customer needs.
Data export formats
  • CSV
  • Other
Other data export formats
  • Excel
  • Word
  • PDF
  • XML
  • HTML
Data import formats
  • CSV
  • Other
Other data import formats
  • SSIS Packages
  • APIs

Data-in-transit protection

Data protection between buyer and supplier networks
  • Private network or public sector network
  • TLS (version 1.2 or above)
  • Other
Other protection between networks
Riskonnect provides strong protection between networks through SOPHOS Endpoint Security at the hosting level and Tier 1 firewalls at the network level to prevent unauthorised access. Security attributes of customer data are encrypted at rest and in transit, including all key personnel details and passwords. Riskonnect uses the Advanced Encryption Standard (AES) with a 256-bit key to ensure a high level of security. All security protocols and controls are aligned with ISO 27001 standards.
Data protection within supplier network
  • TLS (version 1.2 or above)
  • Other
Other protection within supplier network
Riskonnect maintains a Network Security Management procedure under its Information Security Policy. SOPHOS Endpoint Protection is deployed on all laptops, workstations, and servers, providing signature-based malware detection and HIDS monitoring. Any anomalous activity is immediately alerted to the responsible team. Application and database servers are protected through Azure Firewalls and Sophos Intercept X Advanced for servers exposed to public networks. Azure’s default DDoS Protection Basic is also enabled, providing automatic denial-of-service protection across all hosted services.

Availability and resilience

Guaranteed availability
https://riskonnect.com/legal-sla/
Approach to resilience
The Riskonnect service is built for high availability in the primary and disaster recovery sites. Data centers are backed up to secondary data centers in near real-time frequency. All servers are backed up to a secondary server within each data center. In the event that a failover is required, the secondary server will be used. If both servers are down, the platform will switch over the backup data center.
Outage reporting
Managed through email alerts

Identity and authentication

User authentication needed
Yes
User authentication
  • Multi-Factor Authentication (MFA)
  • Dedicated link (for example VPN)
  • Username or password
Access restrictions in management interfaces and support channels
To protect digital management services, we use a range of security measures, including role-based user access, data encryption, firewalls, and other security technologies. Our management tools and user management services are designed to limit access to authorised personnel and regularly updated to ensure the latest security protocols are in place.
Access restriction testing frequency
At least every 6 months
Management access authentication
  • Multi-Factor Authentication (MFA)
  • Dedicated link (for example VPN)
  • Username or password
  • Other
Description of management access authentication
Riskonnect uses SAML- and OpenID-based Single Sign-On (SSO) to provide secure, centralised authentication. Users authenticate once through their organisation’s identity provider—such as Azure AD or Okta—and receive a token granting access to the Riskonnect platform. MFA can also be enforced through the client’s identity provider for added security. Riskonnect does not store or manage authentication credentials; instead, it relies entirely on trusted external identity providers. All authentication data transmitted is protected with strong encryption and secure protocols. Where required, authentication for MyGov users can be validated if SAML or OpenID is supported, and Riskonnect is open to further discussion.

Audit information for users

Access to user activity audit information
Users have access to real-time audit information
How long user audit data is stored for
At least 12 months
Access to supplier activity audit information
Users contact the support team to get audit information
How long supplier audit data is stored for
At least 12 months
How long system logs are stored for
At least 12 months

Security governance

Named board-level person responsible for service security
Yes
Security governance certified
Yes
Security governance standards
ISO/IEC 27001
Information security policies and processes
As part of its information security program aligned with the ISO 27001 framework, Riskonnect maintains a comprehensive Information Security Policy that defines the controls, procedures, and responsibilities required to protect customer data.
Software Security Code of Practice
Yes

Operational security

Configuration and change management standard
Supplier-defined controls
Configuration and change management approach
Riskonnect is certified under ISO 27001 for its IT operations and software development functions. To maintain this certification, Riskonnect adheres to strict service management processes that are audited annually to ensure ongoing compliance and integrity. These processes include incident management, change management, problem management, configuration management, support, and other related service management controls.
Vulnerability management type
Supplier-defined controls
Vulnerability management approach
Riskonnect’s hosted servers operate on the latest supported version of Windows Server, with all current security patches applied and Sophos real-time antivirus monitoring enabled. The environment is protected by dual Azure Firewalls equipped with IPS, which immediately trigger alerts on any malicious activity. Any identified threats are communicated to clients promptly via electronic communication channels.

Physical access to the hosting environment is strictly controlled through a multi-layer security system, including 24/7 on-site security, biometric controls, and CCTV monitoring. Access is restricted to authorised Riskonnect personnel and approved Azure data centre staff only, ensuring a highly secure operating environment.
Protective monitoring type
Supplier-defined controls
Protective monitoring approach
Riskonnect operates a private IaaS cloud environment in the UK, certified to ISO/IEC 27001 and audited annually by accredited third-party assessors. All products are hosted on the Riskonnect Azure cloud, supported by same-site redundant hardware and offsite backups, and delivered under a 99.5% SLA.

Hosted servers run on the latest supported version of Windows Server with current security patches applied and Sophos real-time antivirus monitoring enabled. The environment is further protected by dual Azure Firewalls with Intrusion Prevention System (IPS) capabilities, which trigger alerts on any detected malicious activity. Any identified threats are communicated to clients immediately via email.
Incident management type
Supplier-defined controls
Incident management approach
Riskonnect maintains a formal Incident Response Plan as part of its standard policy. Any potential threats or security incidents identified are communicated to clients immediately through electronic communication channels. Riskonnect’s Information Security Incident Management procedure covers incident identification, reporting methods, classification, escalation paths, and full incident handling processes. All information security incidents are managed by designated personnel and other relevant internal or external parties as required. Riskonnect also utilises its own incident management software to ensure timely and effective coordination of all incident-related activities.
Post-quantum cryptography secure
No

Secure development

Approach to secure software development best practice
Conforms to a recognised standard, but self-assessed

Public sector networks

Connection to public sector networks
No

Pricing

Discount for educational organisations
No
Free trial available
Yes
Description of free trial
Access to a demonstration version of the software can be made available after a mutual non disclosure agreement has been signed

Discount percentage by annual call-off contract value (excluding VAT)

Less than £250,000
5%
Between £250,000 and £500,000
5%
Between £500,001 and £1,000,000
5%
Between £1,000,001 and £2,500,000
2%
Between £2,500,001 and £5,000,000
2%
Over £5,000,001
1%

Non-mandatory Standards and certifications

ISO/IEC 27001 certification
Yes
Who accredited the ISO/IEC 27001
A-Lign
ISO/IEC 27001 accreditation date
Tuesday 19 December 2023
What the ISO/IEC 27001 doesn’t cover
None
ISO 28000:2022 certification
No
ISO 9001 certification
No
Quality management systems (QMS)
Yes
CSA STAR certification
No
PCI certification
No
Cyber essentials
Yes
Please provide your Cyber Essentials Certificate Number
Fdf9abb4-76f7-4cfa-8f6e-3c86afef4729
Cyber essentials plus
No
Cyber Essentials Alternative
You do not have a current and valid Cyber Essentials Plus certificate, or will not have in place within 12 months of the date of award but have an IASME certified equivalent.
Other security certifications
Yes
Any other security certifications
  • ISO 22301
  • HIPPA / HITECH
  • SOC II

Social value

Section B - Commitment for Future: Delivery
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority

    • New or retained jobs on the contract workforce in the relevant area that meet the criteria set out in MAC 1b, 1c and 1d
    • Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
    • Monitoring of employee engagement rates (by protected characteristic) and, where necessary, the development of actions to ensure all voices are heard across the diversity of the workforce
    • Activities that support an environment where staff are educated about, and feel empowered to, address their physical wellbeing
    • Activities that support an environment where staff are educated about and feel empowered to report and address bullying and harassment
    • Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
    • Entitlement to sick pay for the contract workforce, with provision in place for any staff who do not meet the earnings threshold for statutory sick pay, payment of sick pay from day one of absence and payment of staff on the contract workforce who are off sick a replacement income of 100% of their usual earnings for as long as possible
    • Measures to support in-work progression to help people in the contract workforce, to move into higher paid work by developing new skills relevant to the contract
    • Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
    • Volunteering opportunities for staff
    • Understanding of the modern slavery risks and issues affecting the market, industry, sector or country (of origin or of source) relevant to the contract, and the workforce in the supplier’s own organisation and those of its key subcontractors
    • Measures to identify, mitigate and manage modern slavery risks relating to the contract and how these will be implemented

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at legal@riskonnect.com. Tell them what format you need. It will help if you say what assistive technology you use.