AIMS grant management software
AIMS Grant Management System is a secure, cloud-hosted SaaS platform that supports end-to-end public sector grant management. It enables configurable workflows, online applications and portals, assessment and approvals, payments, monitoring and reporting, helping UK public bodies administer compliant, transparent and auditable grant programmes efficiently.
Features
- Configurable end-to-end grant management workflows
- Online application forms and applicant portals
- Role-based access control and permissions
- Multi-stage assessment and approval processes
- Integrated grant payments and financial tracking
- Real-time dashboards and management reporting
- Secure document upload, storage and versioning
- Automated notifications and deadline reminders
- Audit trails for decisions, changes and payments
- Cloud-hosted SaaS accessible via standard web browsers
Benefits
- Reduce manual administration across the grant lifecycle
- Improve transparency and consistency in funding decisions
- Enable faster application review and approvals
- Support compliant grant delivery and audit requirements
- Provide applicants with clear, guided online processes
- Give staff real-time visibility of grant performance
- Reduce errors through structured workflows and validation
- Simplify collaboration across internal and external users
- Scale grant programmes without increasing administration effort
- Support secure remote access for distributed teams
Pricing
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
7 6 9 3 6 8 6 0 9 0 7 3 7 0 4
Contact
AIMS Software Limited
Steve Buckley
Telephone: +447719958544
Email: info@aimssoftware.ie
About your service
- Service categories
-
Applications
Content workflow and management
Enterprise portals and digital workspaces
- Multi-Audience Portals
- Multi cloud support
- No
Service scope
- Software add-on or extension
- No
- Cloud deployment model
- Public cloud
- Service constraints
- The service is delivered as a cloud-hosted SaaS application accessed via standard modern web browsers. Planned maintenance and updates are scheduled outside core business hours wherever possible and are communicated in advance. Internet connectivity is required to access the service. Support is provided in line with the agreed support hours and service levels. The service does not require customer-managed infrastructure or specific hardware beyond a supported browser and internet access.
- System requirements
-
- Modern web browser including Chrome, Edge, Firefox or Safari
- Reliable internet connection for secure cloud access
- JavaScript and cookies enabled in the browser
- Standard desktop, laptop or tablet device
- Screen resolution suitable for web-based applications
- Email access for notifications and user communications
- PDF reader for viewing exported documents and reports
- Secure user authentication credentials provided by the service
- Organisation-managed endpoint security and antivirus software
- No local software installation or specialist hardware required
User support
- Email or online ticketing support
- Yes
- Support response times
- Support requests are logged via email or the online support portal and acknowledged during standard business hours, Monday to Friday. Initial response times are provided in line with the agreed support service levels, typically within one business day. Outside standard business hours, requests are logged and responded to on the next working day. Weekend and public holiday support can be provided by prior agreement where required.
- User can manage status and priority of support tickets
- Yes
- Online ticketing support accessibility
- WCAG 2.2 AA
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- No
- Onsite support
- Yes, at extra cost
- Support levels
-
AIMS Software Limited provides a structured, tiered support model aligned to the needs of public sector organisations.
Standard support is included with the SaaS service and covers access to email and online ticketing support during UK business hours (9am–5pm, Monday to Friday). This includes incident logging, fault diagnosis, bug fixes, and support for standard product functionality in line with the agreed service levels.
Enhanced support options are available at additional cost and can be tailored at call-off. These may include extended support hours, higher priority response times, proactive service monitoring, and increased support capacity for peak periods.
Professional support services, such as configuration assistance, data changes, bespoke reporting, training, onboarding, and onsite support, are provided on a scoped, chargeable basis.
Where required, buyers may be assigned a named technical account manager or service delivery contact to act as a single point of coordination, support prioritisation, and escalation management. This role supports regular service reviews, planning, and ongoing optimisation of the service.
Support costs depend on the selected level of service and scope and are agreed transparently with the buyer at call-off. - Support available to third parties
- Yes
Onboarding and offboarding
- Getting started
-
AIMS Software Limited supports a structured onboarding approach tailored to each buyer’s grant programmes and delivery model. Onboarding typically includes service setup, configuration of workflows and forms, user role definition, and initial data preparation, supported by guidance from the AIMS delivery team.
Users are supported through a combination of online training sessions, workshops, and documentation. Training can be delivered remotely and, where required, onsite training can be provided on a scoped and chargeable basis. User documentation and guidance materials are made available to support day-to-day use of the service.
Buyers may adopt a train-the-trainer approach, enabling internal teams to support wider user groups such as applicants, assessors, and reviewers. During initial rollout and early live use, additional support can be provided to assist with adoption, answer questions, and address any issues identified. The onboarding approach is agreed with the buyer at call-off to ensure it is proportionate and aligned with organisational needs. - Service documentation
- Yes
- Documentation formats
-
- HTML
- End-of-contract data extraction
-
At the end of the contract, AIMS Software Limited works with the buyer to agree a structured off-boarding and data-exit approach. This typically includes a planning session to confirm timelines, such as when new applications will close, when in-flight cases will be completed, user communications, and access arrangements leading up to contract termination.
Buyers can choose from a number of data management options depending on organisational needs. This may include confirming that no data extraction is required, using standard reports and exports already generated as part of operational processes, or requesting specific data extracts. Data can be provided in commonly used, structured formats, subject to agreed scope, security controls, and data protection requirements. Where additional or bespoke data extracts are required, these are scoped and agreed separately. - End-of-contract process
-
At the end of the contract, AIMS Software Limited works with the buyer to manage an orderly service exit in line with the agreed termination date. This includes a planned off-boarding period to confirm timelines, access arrangements, and any agreed data handover activities. The service continues to operate until the contract end date, allowing the buyer to complete in-flight processes and prepare for transition.
The contract price includes standard exit activities, such as access to existing reports and data exports available within the service, reasonable support to clarify data structures, and secure shutdown of the service at contract termination. Following termination and any agreed data handover, the service and associated backups are securely deleted in accordance with contractual and data protection requirements, with confirmation provided.
Additional services, such as bespoke data extracts, extended access beyond the contract term, additional support, or tailored transition assistance, are not included in the standard contract price and are provided on a scoped and chargeable basis. Any such activities are agreed transparently with the buyer in advance. - Documentation accessibility standard
- WCAG 2.2 AA
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Application to install
- No
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
- The service uses a responsive web interface that adapts to different screen sizes. Core functionality is available on mobile devices via a supported web browser. On smaller screens, layouts are optimised for readability and navigation, and some complex configuration, administration, and reporting functions are best performed on desktop or tablet devices. No separate mobile application installation is required.
- Service interface
- Yes
- User support accessibility
- WCAG 2.2 AA
- Description of service interface
- The service is accessed through a secure, web-based user interface designed for public sector grant management. The interface provides role-based dashboards, guided workflows, and forms tailored to different user types, including applicants, assessors, and administrators. Navigation is intuitive and consistent, supporting task-based working, document review, approvals, and reporting. The interface is responsive and accessible via standard modern web browsers without requiring local software installation.
- Accessibility standards
- WCAG 2.2 AA
- Accessibility testing
-
Accessibility considerations are incorporated into the design and ongoing development of the service interface. Testing includes the use of common assistive technologies and accessibility features, such as screen readers, keyboard-only navigation, focus indicators, and browser accessibility tools, to identify and address potential barriers.
The interface is reviewed to ensure appropriate use of labels, headings, contrast, and form validation messages. Accessibility issues identified through user feedback or internal testing are prioritised for remediation as part of continuous improvement. Where required, reasonable adjustments and alternative formats can be supported in collaboration with the buyer. - API
- Yes
- What users can and can't do using the API
-
The service provides APIs to support secure integration with external systems and organisational workflows. APIs can be used to exchange data such as application, award, payment, and reference information with authorised third-party systems, subject to role-based permissions and security controls.
APIs support automated data import and export, synchronisation with finance or identity systems, and controlled updates to defined data objects. Service configuration, business rules, workflows, and user interface elements are managed within the application and are not exposed for modification via the API.
API access is enabled as part of implementation and is subject to agreed scope, authentication, and usage controls. Limitations may apply to ensure service stability, security, and data integrity, and to prevent unauthorised configuration changes. - API documentation
- Yes
- API documentation formats
-
- HTML
- API sandbox or test environment
- Yes
- Customisation available
- Yes
- Description of customisation
-
The service can be customised through configuration to meet the needs of individual grant programmes and organisations. Customisable elements include application and assessment forms, workflows, approval stages, scoring criteria, user roles and permissions, business rules, notifications, and reporting views.
Customisation is carried out using built-in configuration tools within the service and does not require changes to the underlying software code. Configuration is typically performed by authorised administrative users or by AIMS Software Limited as part of implementation or support services, depending on buyer preference and governance requirements.
Buyers control who can make configuration changes through role-based permissions. Core platform functionality and system architecture are not altered through customisation, ensuring consistency, security, and upgradability across the service.
Scaling
- Independence of resources
- The service is delivered on scalable cloud infrastructure designed to support multiple organisations concurrently. Resources are managed to ensure logical separation between customers, with role-based access controls and data isolation. Capacity is monitored and scaled to accommodate changes in demand, helping to maintain consistent performance as usage fluctuates. This approach ensures that activity from one organisation does not adversely affect the availability, security, or performance of the service for other users.
Analytics
- Service usage metrics
- Yes
- Metrics types
- The service provides metrics and reporting to support operational oversight and service management. Metrics may include application volumes, workflow status, processing times, user activity, award and payment values, and scheme-level performance indicators. Management dashboards and reports support monitoring of grant delivery, workload, and progress against key milestones. Metrics are role-based and subject to access controls to ensure appropriate visibility.
- Reporting types
-
- Real-time dashboards
- Regular reports
- Reports on request
- Resource tagging
- No
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Other security clearance
- Government security clearance
- Baseline Personnel Security Standard (BPSS)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- United Kingdom
- User control over data storage and processing locations
- No
- Datacentre security standards
- Managed by a third party
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- ‘IT Health Check’ performed by a CREST-approved service provider
- Protecting data at rest
- Encryption of all physical media
- Data sanitisation process
- Yes
- Equipment disposal approach
- A third-party destruction service
- Data sanitisation type
-
- Deleted data can’t be directly accessed / Cryptographic Erasure
- Data Erasure
Data importing and exporting
- Data export approach
- Users can export their data using built-in reporting and data export tools within the service, providing data in commonly used, structured formats suitable for analysis, archiving, or transfer. Data exports can include applications, assessments, awards, payments, and related records, subject to user permissions. Where required, data can also be extracted through secure, controlled processes or APIs as part of agreed integration or exit arrangements. All data exports are managed in line with security and data protection requirements.
- Data export formats
- CSV
- Data import formats
- CSV
Data-in-transit protection
- Data protection between buyer and supplier networks
- TLS (version 1.2 or above)
- Data protection within supplier network
- TLS (version 1.2 or above)
Availability and resilience
- Guaranteed availability
-
AIMS Software Limited provides the service with a high level of availability, supported by resilient cloud infrastructure, proactive monitoring, and operational controls. The service is designed to meet a target availability of 99.95%, measured over a monthly reporting period and excluding planned maintenance. Planned maintenance is scheduled outside core business hours wherever possible and is communicated in advance.
Availability targets, measurement methods, exclusions, and incident response arrangements are defined within the Service Level Agreement (SLA) agreed at call-off. The service is continuously monitored, and any incidents affecting availability are managed in line with agreed response and escalation procedures.
If availability falls below the agreed SLA levels, the SLA defines the operational remedies that apply. These include incident investigation, corrective actions, escalation, and service improvement measures designed to restore service performance and prevent recurrence. - Approach to resilience
-
The service is designed for resilience through a combination of robust application design, resilient cloud infrastructure, and operational controls. AIMS is delivered as a cloud-hosted SaaS solution, using enterprise-grade infrastructure that supports high availability, redundancy, and fault tolerance. Core service components are monitored continuously to detect and respond to issues that could affect availability or performance.
The underlying datacentre infrastructure is provided by a third-party cloud service provider and is designed to be resilient, incorporating physical security, redundant power and network connectivity, and environmental controls. The cloud platform supports resilience through geographically distributed facilities and built-in redundancy to reduce the risk of single points of failure.
Data is protected through regular backups and controlled recovery processes to support service continuity. Operational procedures are in place to manage incidents, perform corrective actions, and restore service promptly in the event of disruption. Further details of the resilience architecture and operational controls can be made available to buyers on request, subject to security and confidentiality considerations. - Outage reporting
-
Service availability is monitored continuously to identify and respond to incidents that may impact users. Where an outage or service degradation occurs, AIMS Software Limited communicates with affected buyers through direct notification channels. This typically includes email alerts to nominated service contacts, providing information on the nature of the issue, its impact, and progress towards resolution.
Updates are provided as appropriate during incident resolution, with confirmation issued once normal service has been restored. Following significant incidents, a summary and root-cause explanation can be provided on request.
The service does not currently provide a public status dashboard or an API for outage reporting. Outage communication is managed directly to ensure information is accurate, timely, and relevant to affected users, in line with agreed incident management and escalation procedures.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Identity federation with existing provider (for example Google Apps)
- Username or password
- Access restrictions in management interfaces and support channels
- Access to management interfaces and support systems is restricted to authorised personnel using role-based access controls and authenticated user accounts. Access rights are granted on a least-privilege basis and reviewed regularly. Administrative access is limited to staff with a defined business need and is protected through strong authentication controls. Support channels are accessed via authenticated systems, and customer data is only accessible where required to deliver support services. Access is revoked promptly when staff roles change or when individuals leave the organisation, in line with defined joiner, mover, and leaver processes.
- Access restriction testing frequency
- At least once a year
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Username or password
Audit information for users
- Access to user activity audit information
- Users contact the support team to get audit information
- How long user audit data is stored for
- At least 12 months
- Access to supplier activity audit information
- Users contact the support team to get audit information
- How long supplier audit data is stored for
- At least 12 months
- How long system logs are stored for
- At least 12 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
-
- ISO/IEC 27001
- Other
- Other security governance standards
- Cyber Essentials Plus certification lapsed in January 2026. Recertification audit is scheduled for February 2026. We currently hold Cyber Essentials and maintain the required technical controls; updated CE+ certificate will be provided once issued.
- Information security policies and processes
-
AIMS Software Limited operates a formal information security management framework aligned to ISO/IEC 27001. Information security policies cover areas including risk management, access control, secure development, incident management, supplier security, data protection, and business continuity. These policies are reviewed regularly to ensure continued effectiveness and alignment with legal, regulatory, and contractual requirements.
Responsibility for information security is owned at senior management level, with oversight provided through defined governance and reporting structures. Day-to-day security management is supported by designated roles responsible for policy implementation, risk assessment, and operational controls. Compliance with policies is reinforced through secure-by-design development practices, role-based access controls, monitoring, and regular testing.
Security incidents and risks are logged, assessed, and managed through established processes, including escalation and corrective actions where required. Independent assurance is provided through external audits and testing, including ISO 27001 and Cyber Essentials Plus certification audits and regular penetration testing. Staff are supported through awareness and training activities to ensure security policies are understood and consistently followed across the organisation. - Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
- Service components are version controlled and tracked throughout their lifecycle, from development through testing and deployment. Changes are managed through defined change management processes, including assessment, approval, testing, and controlled release to production. Security impacts are considered as part of change assessment, with changes reviewed for potential risks to confidentiality, integrity, and availability. Segregated environments are used to validate changes prior to release, and rollback procedures are in place where required. Changes are logged and auditable to support governance, traceability, and continuous improvement.
- Vulnerability management type
- Supplier-defined controls
- Vulnerability management approach
- Potential threats to the service are assessed through ongoing risk management, security monitoring, and regular vulnerability assessments. Vulnerabilities are prioritised based on severity, risk, and potential impact to confidentiality, integrity, and availability. Security patches and updates are tested in non-production environments and deployed in line with defined change management processes, with critical fixes prioritised for timely release. Information about emerging threats is obtained from trusted sources, including security advisories from software vendors, cloud service providers, industry bodies, and independent penetration testing conducted by a CREST-accredited provider.
- Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
- The service is monitored to detect potential security events and service anomalies using application and infrastructure monitoring tools. Monitoring focuses on identifying unusual activity, access patterns, errors, and performance indicators that may suggest a potential compromise. When a potential incident is identified, it is logged, assessed, and investigated in line with defined incident management procedures. Appropriate containment, remediation, and escalation actions are taken based on severity and impact. Incidents affecting security or availability are responded to promptly during business hours, with priority handling for higher-severity events, and managed through to resolution with corrective actions implemented as required.
- Incident management type
- Supplier-defined controls
- Incident management approach
- The organisation operates defined incident management processes covering common operational and security events, including service outages, performance issues, and suspected security incidents. Incidents can be reported by users via email, the online support portal, or phone during support hours. All incidents are logged, assessed, prioritised, and managed in line with agreed response and escalation procedures. Users are kept informed of progress as appropriate, and incidents are tracked through to resolution. For significant incidents, an incident summary and root-cause explanation can be provided on request, together with any corrective or preventive actions taken.
- Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- No
- Free trial available
- No
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 0%
- Between £500,001 and £1,000,000
- 0%
- Between £1,000,001 and £2,500,000
- 0%
- Between £2,500,001 and £5,000,000
- 0%
- Over £5,000,001
- 0%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- Yes
- Who accredited the ISO/IEC 27001
- Amtivo (Ireland) Limited
- ISO/IEC 27001 accreditation date
- Wednesday 15 January 2025
- What the ISO/IEC 27001 doesn’t cover
- As AIMS does not outsource any part of its system development to a third-party company, Control A.30 (Outsourced Development) is excluded.
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- No
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- 5cbba84f-8376-4b6d-9a98-79e25e5d706f
- Cyber essentials plus
- No
- Cyber Essentials Alternative
- In relation to the services you do not have a current and valid Cyber Essentials Plus certificate which has been awarded by one of the government approved Cyber Essentials accreditation bodies but you are working towards gaining it, and will be in a position to confirm that you have been awarded a current and valid Cyber Essentials Plus certificate by one of the government approved accreditation bodies within 12 months of the date of award.
- Other security certifications
- No
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.
- Understanding of employment and relevant skills issues, and of the education and training issues relating to the contract. Illustrative examples: demographics, skills shortages, new opportunities in high growth sectors, geographic/local community and skills/employment challenges
- Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
-
Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero
Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.
- Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
- Collaborative ways of working with the supply chain to deliver additional environmental benefits in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
- Delivery of additional environmental benefits through the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
-
Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.
Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.
- Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce
- Understanding barriers to access to health and social care services or employment opportunities e.g. digital inclusion
- Inclusive and accessible recruitment practices, development practices and retention policies that support-focused activities including those provided in the Guide for line managers on recruiting, managing and developing which support people with a disability or health condition
-