Validate Skills Assessment Platform
VSAP is an online skills management and assessment platform enabling organisations to implement, customise, and operationalise any skills framework, including SFIA, sector-specific taxonomies, or fully bespoke models. The service provides real-time skills assessment, verification, role mapping, development planning and workforce capability management through an intuitive online environment.
Features
- Skills Framework Delivery known frameworks a bespoke.
- Job Role Builder and Role Mapping.
- Configurable Self-Assessment Engine.
- Employee, Manager and Verifier Validation Workflow.
- Real-time Reporting and Analytics.
- Task setting for competency development.
- Skill dashboard, qualification and training log.
- Career Pathway and Workforce Planning Tools.
- API integration to LMS and HRMS, SSO capabilities.
- Scalable Cloud-Based Platform.
Benefits
- Clear insight into organisational skills, strengths and capability gaps.
- Accurate alignment of job roles to defined skills frameworks.
- Evidence-based employee assessments against role.
- Accelerates skills assessment through guided workflows.
- Strengthens recruitment with objective, consistent skills evidence for candidate selection.
- Reduces training waste by pinpointing exactly which skills require investment.
- Boosts mobility and retention through clear career pathways and roles.
- Audit readiness by capturing validated evidence, comments and versioned assessments.
- Flexibility, allowing any skills or competency framework to be customised.
- Strengthens governance through hierarchical admin controls and verification workflows.
Pricing
- Education pricing available
- Free trial available
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
7 5 8 1 4 8 4 5 8 4 5 1 9 4 4
Contact
ASSESS MANAGEMENT LIMITED
Kevin Tibbs
Telephone: 07738402970
Email: kevin@validateskills.com
About your service
- Service categories
-
Applications
Enterprise resource management
Human capital management
- Talent Management Applications
- Multi cloud support
- No
Service scope
- Software add-on or extension
- Yes, but can also be used as a standalone service
- What software services is the service an extension to
- API extension to LMS, HRIS, HRMS and BI
- Cloud deployment model
- Private cloud
- Service constraints
- The platform is cloud-based and requires stable internet access and a modern browser. Scheduled maintenance may cause short periods of limited availability, always communicated in advance. Data is hosted in UK data centres. Customer administrators are responsible for configuring roles, users and custom frameworks. Evidence uploads follow reasonable file-size limits. Integrations depend on third-party system capabilities, and offline use is not supported.
- System requirements
-
- Modern web browser
- Relaiable internet connection
- Email access
- Firewall / Security Allow-Listing
- Device Compatibility
- No Additional Licences Required
- Optional Single Sign-On (SSO)
User support
- Email or online ticketing support
- Yes
- Support response times
-
We provide both email and online ticketing support.
Email and ticketing queries are monitored during UK business hours, typically 8:00 to 18:00 Monday to Friday. Technical support operates 24/7 for urgent system issues, ensuring any critical service disruptions are addressed promptly. - User can manage status and priority of support tickets
- Yes
- Online ticketing support accessibility
- WCAG 2.2 AA
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), 7 days a week
- Web chat support
- No
- Onsite support
- Yes, at extra cost
- Support levels
-
We provide three levels of support designed to meet different organisational needs.
Standard Support (included at no additional cost)
All customers receive Standard Support, which includes access to our online ticketing system and email support during UK business hours, typically 8:00 to 18:00 Monday to Friday. This covers general queries, user assistance, configuration guidance and incident reporting. Standard Support includes updates, maintenance notifications and access to our knowledge resources.
Enhanced Support (optional, chargeable)
Enhanced Support is available for customers who require priority ticket handling, extended support hours or more proactive engagement. Pricing is based on the size and complexity of the deployment and is quoted on request. Enhanced Support reduces response times and ensures faster escalation for service-impacting issues.
Premium Support / Dedicated Consultant (optional, chargeable)
Customers with more complex requirements can opt for a dedicated consultant who acts similarly to a technical account manager. This provides personalised onboarding support, periodic service reviews, assistance with role mapping or framework configuration and optional training sessions. This service is billed as a consultancy package.
We do not operate a separate cloud support engineer role; instead, technical issues are handled directly by our platform engineering team through the support desk. - Support available to third parties
- Yes
Onboarding and offboarding
- Getting started
-
We provide a structured onboarding process to help users begin using the service quickly and confidently. Every buyer receives online user documentation, including step-by-step guides for administrators, managers and employees. We also offer remote onboarding sessions to walk administrators through configuration, role setup and user management.
Optional online training workshops are available for managers or wider user groups, covering assessment workflows, verification processes and reporting.
If required, buyers can purchase onsite training or consultancy as an additional service, which can include role-mapping support, framework setup or structured implementation planning.
This combination of documentation, guided setup and optional training ensures users can adopt the service at a pace that suits their organisation.
Our software is designed for clients to be self-sufficient however if required we can manage the administration of the services for you at extra cost. We offer a dedicated account manager and administrator to ensure the smooth running of your programme. - Service documentation
- Yes
- Documentation formats
-
- HTML
- ODF
- Other
- Other documentation formats
-
- PowerPoint
- SCORM (as an additional cost option)
- End-of-contract data extraction
-
At the end of the contract, users can extract all organisational data through the administrative tools provided. Administrators can download assessments, role mappings, user records, evidence files and reporting outputs in standard formats such as CSV, XLSX or PDF.
If preferred, we can provide a full data export as part of the offboarding process. This export is delivered securely and includes all customer-owned data from the service. Any assisted or customised extraction is available as an optional, chargeable service.
After extraction is completed and confirmed, all customer data is securely deleted in line with our data retention policy. - End-of-contract process
-
At the end of the contract, we notify the buyer in advance and agree a timetable for offboarding. Administrators retain access for a defined period to extract all data using the built-in export tools. This includes user records, assessments, evidence files, role structures and reporting outputs. Once the buyer confirms successful extraction, we securely delete all customer data in line with our retention policy.
Included in the contract price:
- Continued service access until the contract end date
- Use of all self-service data export tools
- Standard support during the off-boarding period
- Secure deletion of data after extraction
Optional additional-cost services:
- Assisted or full-service data extraction in custom formats
- Consultancy to support transition to a new system
- Extended access beyond the contract end date (if required by the buyer)
This process ensures buyers maintain full control of their data while allowing for a smooth and compliant exit. - Documentation accessibility standard
- WCAG 2.2 AA
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Application to install
- No
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
-
The service is delivered through a responsive web interface that adapts to mobile, tablet and desktop devices. All core functions — including self-assessment, evidence upload, role viewing and reporting — are available on mobile.
On desktop, users benefit from a larger workspace for tasks involving extensive reading, detailed reporting or multi-screen comparisons. Mobile screens present the same features with streamlined layouts, collapsible menus and touch-optimised controls.
No separate mobile app is required, and there is no functional difference in data, permissions or account access between mobile and desktop. - Service interface
- No
- User support accessibility
- WCAG 2.2 AA
- API
- Yes
- What users can and can't do using the API
-
The service does not currently provide a public, fully featured API. All configuration, role setup, framework management and user administration are completed through the web interface, which ensures accuracy, governance and consistent data quality. Buyers do not need any technical integration work to deploy or manage the platform.
If a buyer requires automated data exchange, such as synchronising user accounts, importing organisational structures or exporting assessment results into HR or analytics systems, we can provide lightweight data integration options including secure data import and export processes. These are designed to support common onboarding and reporting workflows without requiring a full API.
Where a buyer has a specific integration need, we can offer the development of a bespoke API or custom integration endpoints as an optional, chargeable enhancement. This work is assessed on a case-by-case basis and delivered through our technical team, ensuring the solution aligns with security, data management and performance requirements.
This approach gives buyers full control over the service today, while providing a flexible path for deeper system integration if required. - API documentation
- Yes
- API documentation formats
-
- Open API (also known as Swagger)
- HTML
- ODF
- Other
- API sandbox or test environment
- Yes
- Customisation available
- Yes
- Description of customisation
-
Our platform is capable of loading any skills or process frameworks from know institutes. We have the ability to add bespoke skills frameworks to suit your own requirements. We can customise a wide range of elements within the system specific to clients needs. Administrators can create and modify job roles, define required skills, adjust competency descriptors, set departmental structures, and upload their own training library information for development indicators. Behaviours or organisational skill models can be incorporated with additional development cost dependent of the size of the change request. Administrators can also configure evidence requirements, adjust verification workflows, tailor invitation emails and set access rights for different user groups.
Customisation is completed through simple document submission and uploaded into the clients account seamlessly. The web-based administration console, allows full view in real time. Changes are applied instantly and can be managed by the buyer at any time.
Only authorised customer administrators can customise the service. Standard users cannot alter role structures, frameworks or organisational settings, ensuring governance and data consistency.
Scaling
- Independence of resources
- The service is hosted on AWS and designed so that one customer’s activity cannot affect another’s performance. We use auto-scaling to increase capacity during peak demand, load balancing to distribute traffic, and isolated tenant resources to prevent contention. Continuous performance monitoring allows us to scale proactively, ensuring stable, consistent service for all users regardless of overall platform activity.
Analytics
- Service usage metrics
- Yes
- Metrics types
-
We provide a set of service usage metrics through the administrative reporting dashboard. These include the number of active users, assessment completion rates, verification activity, role-mapping usage and overall engagement levels. Administrators can view these metrics in real time to monitor adoption and understand how the service is being used.
We do not currently provide system-level API or consumption-based usage metrics (for example bandwidth, storage utilisation or machine-level logs). If a buyer requires additional or bespoke usage reporting, this can be provided as an optional, chargeable enhancement. - Reporting types
-
- Real-time dashboards
- Regular reports
- Reports on request
- Resource tagging
- No
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Conforms to BS7858:2019
- Government security clearance
- Developed Vetting (DV)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- United Kingdom
- User control over data storage and processing locations
- Yes
- Datacentre security standards
- Complies with a recognised standard (for example CSA CCM version 4.0)
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- Another external penetration testing organisation
- Protecting data at rest
-
- Physical access control, complying with CSA CCM v4.0
- Encryption of all physical media
- Other
- Other data at rest protection approach
-
Data separation and resilience. Customer data is logically separated within the service, replicated across multiple AWS availability zones, and protected by AWS’s resilient infrastructure.
No unencrypted storage, unmanaged physical media, or legacy methods are used. - Data sanitisation process
- Yes
- Equipment disposal approach
- In-house destruction process
- Data sanitisation type
-
- Deleted data can’t be directly accessed / Cryptographic Erasure
- Data Erasure
- Explicit overwriting of storage before reallocation / Secure Erase
Data importing and exporting
- Data export approach
-
Users can request a full data export directly from Assess Management Ltd (AML). On receipt of the request, we prepare a secure export containing all customer-owned data, including user records, assessments, evidence files, role structures and reporting outputs. Data is provided in standard formats such as CSV, XLSX or PDF, depending on the content type.
Exports are delivered securely to the authorised buyer contact. Self-service export tools are not required, and AML manages the process to ensure completeness and accuracy. - Data export formats
-
- CSV
- ODF
- Other
- Other data export formats
- XLSX
- Data import formats
-
- CSV
- ODF
- Other
- Other data import formats
-
- PDF/A – for accessible, archivable documents
- HTML/HTML5 – for structured text content
- Plain text (.txt) – for simple content uploads
- Common image formats (PNG, JPEG) – for evidence
Data-in-transit protection
- Data protection between buyer and supplier networks
-
- TLS (version 1.2 or above)
- IPsec or TLS VPN gateway
- Data protection within supplier network
-
- TLS (version 1.2 or above)
- IPsec or TLS VPN gateway
Availability and resilience
- Guaranteed availability
-
We guarantee a high level of service availability supported by the resilience of our AWS-hosted infrastructure. Our guaranteed service availability is 99.5% uptime, measured monthly. This excludes planned maintenance windows, which are scheduled outside normal business hours wherever possible and communicated in advance.
If availability falls below the guaranteed level in any given month, buyers are eligible for service credits, which are applied against future invoices. Service credits are calculated proportionally based on the duration and severity of the outage.
The availability SLA covers access to the platform and core functional components, including assessment workflows, reporting, verification tools and administrative functions. It does not apply to customer-controlled factors such as local connectivity, firewall restrictions or third-party systems used for integration.
This SLA framework ensures reliable access while providing clear remedies should performance fall below expectations. - Approach to resilience
-
Our service is designed with multiple layers of resilience, supported by the underlying capabilities of AWS. Load balancing, auto-scaling and health monitoring ensure the application can handle increased demand, hardware failures or unexpected spikes without affecting performance.
Backups are performed regularly and retained according to our data-retention policy, enabling full restoration in the event of a disruption. AWS datacentres themselves use independent power, cooling and connectivity systems, providing strong physical resilience.
Connectivity to the service is encrypted and monitored continuously. We use AWS-managed infrastructure controls, including patching, environmental protection, hardware lifecycle management and secure media sanitisation, each independently audited against recognised standards such as ISO 27001, CSA CCM v4.0 and SSAE-18/ISAE 3402.
These combined measures ensure that the service remains available, secure and stable even in the event of infrastructure issues, hardware failure or external disruption. More detailed architectural resilience documentation can be provided to buyers on request. - Outage reporting
-
We report service outages and major incidents through email alerts sent directly to nominated buyer contacts. These notifications provide details of the issue, expected impact, and ongoing updates until service is restored.
We do not currently operate a public service-status dashboard or provide outage information via an API. All communications are handled through our support channels to ensure buyers receive accurate, timely updates tailored to their contract.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Username or password
- Other
- Other user authentication
- SSO (optional and at additional cost)
- Access restrictions in management interfaces and support channels
- Access to all management interfaces is strictly controlled through role-based access control (RBAC), ensuring users only see functions appropriate to their role. Administrative privileges are limited to authorised staff, protected by strong authentication and monitored for unusual activity. Support channels are also access-restricted: only verified, authorised buyer contacts or approved third parties can raise tickets or discuss account details. Support staff have limited, audited access and can only view information necessary to resolve issues. All access is logged, reviewed and governed by the principle of least privilege to prevent unauthorised use.
- Access restriction testing frequency
- Less than once a year
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Username or password
- Other
- Description of management access authentication
- Management access to the service is protected using unique user accounts with strong passwords and mandatory multi-factor authentication (MFA). Where required, access can be integrated with enterprise single sign-on (SSO) solutions, such as SAML-based identity providers. Automated and malicious access attempts are further mitigated using bot-protection controls, including reCAPTCHA. Access is logged and monitored, with alerts generated for suspicious or anomalous activity.
Audit information for users
- Access to user activity audit information
- Users contact the support team to get audit information
- How long user audit data is stored for
- At least 12 months
- Access to supplier activity audit information
- Users contact the support team to get audit information
- How long supplier audit data is stored for
- At least 12 months
- How long system logs are stored for
- At least 12 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
-
- ISO/IEC 27001
- Other
- Other security governance standards
- Cyber Essentials Plus
- Information security policies and processes
-
We operate a comprehensive information security management framework aligned with recognised industry standards, including ISO 27001 principles and AWS’s independently audited controls (CSA CCM v4.0, ISO 27001/17/18, SSAE-18/ISAE 3402). Our security policies cover data protection, access control, incident management, risk assessment, vulnerability management, backup, and secure development practices.
Information security is overseen by our Senior Management Team, with a designated security lead responsible for maintaining policies, conducting risk reviews, and ensuring operational compliance. Policies are reviewed at least annually, or sooner if legislation, technology or threat conditions change. All staff undergo security awareness training, must follow our acceptable use, data handling and confidentiality policies, and are subject to role-based access control within our systems.
We enforce secure coding standards, apply regular patching, perform internal reviews, and use AWS’s native security services for monitoring and alerting. Any suspected incident follows a defined escalation path, including assessment, containment, remediation and customer notification where required.
Compliance is ensured through internal audits, change-control processes, and continuous monitoring of platform security. This structured governance approach ensures information security is embedded across daily operations and decision-making. - Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
- We maintain a full configuration register where all service components are tracked throughout their lifecycle, including versions, dependencies and deployment history. Changes follow a defined process covering assessment, peer review, testing and scheduled release. Each change is evaluated for potential security impact, including effects on data handling, access controls and infrastructure. Security-relevant changes undergo additional review before approval. All updates are deployed through controlled, versioned pipelines to ensure traceability and minimise service disruption.
- Vulnerability management type
- Supplier-defined controls
- Vulnerability management approach
- We continuously assess potential threats using automated vulnerability scanning, dependency monitoring and security reviews of new changes. Threat intelligence is sourced from AWS security advisories, industry feeds, CVE databases and trusted security partners. Vulnerabilities are prioritised by severity, with critical issues patched as soon as practicable, typically within 24–72 hours. High and medium-risk issues follow defined remediation timelines, with all fixes validated before deployment. This ensures the service remains protected against emerging threats.
- Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
- We use continuous log monitoring, access auditing and automated alerting to identify unusual behaviour that may indicate a potential compromise. Alerts include failed login patterns, privilege escalation attempts, suspicious IP activity and anomalous application behaviour. When a potential compromise is detected, our incident response process is activated immediately. The issue is triaged, contained and investigated, with remediation actions applied as required. We begin responding to incidents as soon as alerts are triggered, with critical issues addressed within minutes and fully escalated to senior technical staff. Customers are notified promptly if an incident affects their data or service.
- Incident management type
- Supplier-defined controls
- Incident management approach
- We operate pre-defined incident response procedures for common events such as service disruption, unauthorised access attempts and data-handling issues. Users report incidents through our support ticketing system or by email, where they are immediately logged and triaged by severity. For any incident affecting service availability or customer data, we provide a formal incident report that includes a summary of the event, impact assessment, actions taken, and steps to prevent recurrence. Reports are shared directly with authorised buyer contacts once the investigation is complete.
- Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- Yes
- Free trial available
- Yes
- Description of free trial
- A 14-day free trial provides access to core features including self-assessment, reporting and basic administration. Advanced configuration, role mapping, large-scale onboarding, verification workflows and consultancy are not included. Trial duration can be extended on request for evaluation purposes.
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 10%
- Between £250,000 and £500,000
- 10%
- Between £500,001 and £1,000,000
- 10%
- Between £1,000,001 and £2,500,000
- 10%
- Between £2,500,001 and £5,000,000
- 10%
- Over £5,000,001
- 10%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- No
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- No
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- 9acb4620-3b06-44c3-ac56-5b0ec1676804
- Cyber essentials plus
- No
- Cyber Essentials Alternative
- In relation to the services you do not have a current and valid Cyber Essentials Plus certificate which has been awarded by one of the government approved Cyber Essentials accreditation bodies but you are working towards gaining it, and will be in a position to confirm that you have been awarded a current and valid Cyber Essentials Plus certificate by one of the government approved accreditation bodies within 12 months of the date of award.
- Other security certifications
- No
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- New or retained jobs on the contract workforce in the relevant area that meet the criteria set out in MAC 1b, 1c and 1d
- Understanding of in-work progression issues affecting the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors
- Measures to support in-work progression to help people in the contract workforce, to move into higher paid work by developing new skills relevant to the contract
- Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.
- Understanding of employment and relevant skills issues, and of the education and training issues relating to the contract. Illustrative examples: demographics, skills shortages, new opportunities in high growth sectors, geographic/local community and skills/employment challenges
- Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
- Activities to support relevant sector related skills growth and sustainability in the contract workforce. Illustrative examples: careers talks, curriculum support, literacy support, safety talks and volunteering
-