Skip to main content

Help us improve the Digital Marketplace - send your feedback

AIMS Software Limited

AIMS grant management software

AIMS Grant Management System is a secure, cloud-hosted SaaS platform that supports end-to-end public sector grant management. It enables configurable workflows, online applications and portals, assessment and approvals, payments, monitoring and reporting, helping UK public bodies administer compliant, transparent and auditable grant programmes efficiently.

Features

  • Configurable end-to-end grant management workflows
  • Online application forms and applicant portals
  • Role-based access control and permissions
  • Multi-stage assessment and approval processes
  • Integrated grant payments and financial tracking
  • Real-time dashboards and management reporting
  • Secure document upload, storage and versioning
  • Automated notifications and deadline reminders
  • Audit trails for decisions, changes and payments
  • Cloud-hosted SaaS accessible via standard web browsers

Benefits

  • Reduce manual administration across the grant lifecycle
  • Improve transparency and consistency in funding decisions
  • Enable faster application review and approvals
  • Support compliant grant delivery and audit requirements
  • Provide applicants with clear, guided online processes
  • Give staff real-time visibility of grant performance
  • Reduce errors through structured workflows and validation
  • Simplify collaboration across internal and external users
  • Scale grant programmes without increasing administration effort
  • Support secure remote access for distributed teams

Pricing

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at info@aimssoftware.ie. Tell them what format you need. It will help if you say what assistive technology you use.

Framework

G-Cloud 15

Service ID

7 6 9 3 6 8 6 0 9 0 7 3 7 0 4

Contact

AIMS Software Limited Steve Buckley
Telephone: +447719958544
Email: info@aimssoftware.ie

About your service

Service categories

Applications

Content workflow and management

Enterprise portals and digital workspaces

  • Multi-Audience Portals
Multi cloud support
No

Service scope

Software add-on or extension
No
Cloud deployment model
Public cloud
Service constraints
The service is delivered as a cloud-hosted SaaS application accessed via standard modern web browsers. Planned maintenance and updates are scheduled outside core business hours wherever possible and are communicated in advance. Internet connectivity is required to access the service. Support is provided in line with the agreed support hours and service levels. The service does not require customer-managed infrastructure or specific hardware beyond a supported browser and internet access.
System requirements
  • Modern web browser including Chrome, Edge, Firefox or Safari
  • Reliable internet connection for secure cloud access
  • JavaScript and cookies enabled in the browser
  • Standard desktop, laptop or tablet device
  • Screen resolution suitable for web-based applications
  • Email access for notifications and user communications
  • PDF reader for viewing exported documents and reports
  • Secure user authentication credentials provided by the service
  • Organisation-managed endpoint security and antivirus software
  • No local software installation or specialist hardware required

User support

Email or online ticketing support
Yes
Support response times
Support requests are logged via email or the online support portal and acknowledged during standard business hours, Monday to Friday. Initial response times are provided in line with the agreed support service levels, typically within one business day. Outside standard business hours, requests are logged and responded to on the next working day. Weekend and public holiday support can be provided by prior agreement where required.
User can manage status and priority of support tickets
Yes
Online ticketing support accessibility
WCAG 2.2 AA
Phone support
Yes
Phone support availability
9 to 5 (UK time), Monday to Friday
Web chat support
No
Onsite support
Yes, at extra cost
Support levels
AIMS Software Limited provides a structured, tiered support model aligned to the needs of public sector organisations.

Standard support is included with the SaaS service and covers access to email and online ticketing support during UK business hours (9am–5pm, Monday to Friday). This includes incident logging, fault diagnosis, bug fixes, and support for standard product functionality in line with the agreed service levels.

Enhanced support options are available at additional cost and can be tailored at call-off. These may include extended support hours, higher priority response times, proactive service monitoring, and increased support capacity for peak periods.

Professional support services, such as configuration assistance, data changes, bespoke reporting, training, onboarding, and onsite support, are provided on a scoped, chargeable basis.

Where required, buyers may be assigned a named technical account manager or service delivery contact to act as a single point of coordination, support prioritisation, and escalation management. This role supports regular service reviews, planning, and ongoing optimisation of the service.

Support costs depend on the selected level of service and scope and are agreed transparently with the buyer at call-off.
Support available to third parties
Yes

Onboarding and offboarding

Getting started
AIMS Software Limited supports a structured onboarding approach tailored to each buyer’s grant programmes and delivery model. Onboarding typically includes service setup, configuration of workflows and forms, user role definition, and initial data preparation, supported by guidance from the AIMS delivery team.

Users are supported through a combination of online training sessions, workshops, and documentation. Training can be delivered remotely and, where required, onsite training can be provided on a scoped and chargeable basis. User documentation and guidance materials are made available to support day-to-day use of the service.

Buyers may adopt a train-the-trainer approach, enabling internal teams to support wider user groups such as applicants, assessors, and reviewers. During initial rollout and early live use, additional support can be provided to assist with adoption, answer questions, and address any issues identified. The onboarding approach is agreed with the buyer at call-off to ensure it is proportionate and aligned with organisational needs.
Service documentation
Yes
Documentation formats
  • HTML
  • PDF
End-of-contract data extraction
At the end of the contract, AIMS Software Limited works with the buyer to agree a structured off-boarding and data-exit approach. This typically includes a planning session to confirm timelines, such as when new applications will close, when in-flight cases will be completed, user communications, and access arrangements leading up to contract termination.

Buyers can choose from a number of data management options depending on organisational needs. This may include confirming that no data extraction is required, using standard reports and exports already generated as part of operational processes, or requesting specific data extracts. Data can be provided in commonly used, structured formats, subject to agreed scope, security controls, and data protection requirements. Where additional or bespoke data extracts are required, these are scoped and agreed separately.
End-of-contract process
At the end of the contract, AIMS Software Limited works with the buyer to manage an orderly service exit in line with the agreed termination date. This includes a planned off-boarding period to confirm timelines, access arrangements, and any agreed data handover activities. The service continues to operate until the contract end date, allowing the buyer to complete in-flight processes and prepare for transition.

The contract price includes standard exit activities, such as access to existing reports and data exports available within the service, reasonable support to clarify data structures, and secure shutdown of the service at contract termination. Following termination and any agreed data handover, the service and associated backups are securely deleted in accordance with contractual and data protection requirements, with confirmation provided.

Additional services, such as bespoke data extracts, extended access beyond the contract term, additional support, or tailored transition assistance, are not included in the standard contract price and are provided on a scoped and chargeable basis. Any such activities are agreed transparently with the buyer in advance.
Documentation accessibility standard
WCAG 2.2 AA

Using the service

Web browser interface
Yes
Supported browsers
  • Microsoft Edge
  • Firefox
  • Chrome
  • Safari
Application to install
No
Designed for use on mobile devices
Yes
Differences between the mobile and desktop service
The service uses a responsive web interface that adapts to different screen sizes. Core functionality is available on mobile devices via a supported web browser. On smaller screens, layouts are optimised for readability and navigation, and some complex configuration, administration, and reporting functions are best performed on desktop or tablet devices. No separate mobile application installation is required.
Service interface
Yes
User support accessibility
WCAG 2.2 AA
Description of service interface
The service is accessed through a secure, web-based user interface designed for public sector grant management. The interface provides role-based dashboards, guided workflows, and forms tailored to different user types, including applicants, assessors, and administrators. Navigation is intuitive and consistent, supporting task-based working, document review, approvals, and reporting. The interface is responsive and accessible via standard modern web browsers without requiring local software installation.
Accessibility standards
WCAG 2.2 AA
Accessibility testing
Accessibility considerations are incorporated into the design and ongoing development of the service interface. Testing includes the use of common assistive technologies and accessibility features, such as screen readers, keyboard-only navigation, focus indicators, and browser accessibility tools, to identify and address potential barriers.

The interface is reviewed to ensure appropriate use of labels, headings, contrast, and form validation messages. Accessibility issues identified through user feedback or internal testing are prioritised for remediation as part of continuous improvement. Where required, reasonable adjustments and alternative formats can be supported in collaboration with the buyer.
API
Yes
What users can and can't do using the API
The service provides APIs to support secure integration with external systems and organisational workflows. APIs can be used to exchange data such as application, award, payment, and reference information with authorised third-party systems, subject to role-based permissions and security controls.

APIs support automated data import and export, synchronisation with finance or identity systems, and controlled updates to defined data objects. Service configuration, business rules, workflows, and user interface elements are managed within the application and are not exposed for modification via the API.

API access is enabled as part of implementation and is subject to agreed scope, authentication, and usage controls. Limitations may apply to ensure service stability, security, and data integrity, and to prevent unauthorised configuration changes.
API documentation
Yes
API documentation formats
  • HTML
  • PDF
API sandbox or test environment
Yes
Customisation available
Yes
Description of customisation
The service can be customised through configuration to meet the needs of individual grant programmes and organisations. Customisable elements include application and assessment forms, workflows, approval stages, scoring criteria, user roles and permissions, business rules, notifications, and reporting views.

Customisation is carried out using built-in configuration tools within the service and does not require changes to the underlying software code. Configuration is typically performed by authorised administrative users or by AIMS Software Limited as part of implementation or support services, depending on buyer preference and governance requirements.

Buyers control who can make configuration changes through role-based permissions. Core platform functionality and system architecture are not altered through customisation, ensuring consistency, security, and upgradability across the service.

Scaling

Independence of resources
The service is delivered on scalable cloud infrastructure designed to support multiple organisations concurrently. Resources are managed to ensure logical separation between customers, with role-based access controls and data isolation. Capacity is monitored and scaled to accommodate changes in demand, helping to maintain consistent performance as usage fluctuates. This approach ensures that activity from one organisation does not adversely affect the availability, security, or performance of the service for other users.

Analytics

Service usage metrics
Yes
Metrics types
The service provides metrics and reporting to support operational oversight and service management. Metrics may include application volumes, workflow status, processing times, user activity, award and payment values, and scheme-level performance indicators. Management dashboards and reports support monitoring of grant delivery, workload, and progress against key milestones. Metrics are role-based and subject to access controls to ensure appropriate visibility.
Reporting types
  • Real-time dashboards
  • Regular reports
  • Reports on request
Resource tagging
No
FOCUS resource tagging
No

Resellers

Supplier type
Not a reseller

Staff security

Staff security clearance
Other security clearance
Government security clearance
Baseline Personnel Security Standard (BPSS)

Asset protection

Knowledge of data storage and processing locations
Yes
Data storage and processing locations
United Kingdom
User control over data storage and processing locations
No
Datacentre security standards
Managed by a third party
Penetration testing frequency
At least once a year
Penetration testing approach
‘IT Health Check’ performed by a CREST-approved service provider
Protecting data at rest
Encryption of all physical media
Data sanitisation process
Yes
Equipment disposal approach
A third-party destruction service
Data sanitisation type
  • Deleted data can’t be directly accessed / Cryptographic Erasure
  • Data Erasure

Data importing and exporting

Data export approach
Users can export their data using built-in reporting and data export tools within the service, providing data in commonly used, structured formats suitable for analysis, archiving, or transfer. Data exports can include applications, assessments, awards, payments, and related records, subject to user permissions. Where required, data can also be extracted through secure, controlled processes or APIs as part of agreed integration or exit arrangements. All data exports are managed in line with security and data protection requirements.
Data export formats
CSV
Data import formats
CSV

Data-in-transit protection

Data protection between buyer and supplier networks
TLS (version 1.2 or above)
Data protection within supplier network
TLS (version 1.2 or above)

Availability and resilience

Guaranteed availability
AIMS Software Limited provides the service with a high level of availability, supported by resilient cloud infrastructure, proactive monitoring, and operational controls. The service is designed to meet a target availability of 99.95%, measured over a monthly reporting period and excluding planned maintenance. Planned maintenance is scheduled outside core business hours wherever possible and is communicated in advance.

Availability targets, measurement methods, exclusions, and incident response arrangements are defined within the Service Level Agreement (SLA) agreed at call-off. The service is continuously monitored, and any incidents affecting availability are managed in line with agreed response and escalation procedures.

If availability falls below the agreed SLA levels, the SLA defines the operational remedies that apply. These include incident investigation, corrective actions, escalation, and service improvement measures designed to restore service performance and prevent recurrence.
Approach to resilience
The service is designed for resilience through a combination of robust application design, resilient cloud infrastructure, and operational controls. AIMS is delivered as a cloud-hosted SaaS solution, using enterprise-grade infrastructure that supports high availability, redundancy, and fault tolerance. Core service components are monitored continuously to detect and respond to issues that could affect availability or performance.

The underlying datacentre infrastructure is provided by a third-party cloud service provider and is designed to be resilient, incorporating physical security, redundant power and network connectivity, and environmental controls. The cloud platform supports resilience through geographically distributed facilities and built-in redundancy to reduce the risk of single points of failure.

Data is protected through regular backups and controlled recovery processes to support service continuity. Operational procedures are in place to manage incidents, perform corrective actions, and restore service promptly in the event of disruption. Further details of the resilience architecture and operational controls can be made available to buyers on request, subject to security and confidentiality considerations.
Outage reporting
Service availability is monitored continuously to identify and respond to incidents that may impact users. Where an outage or service degradation occurs, AIMS Software Limited communicates with affected buyers through direct notification channels. This typically includes email alerts to nominated service contacts, providing information on the nature of the issue, its impact, and progress towards resolution.

Updates are provided as appropriate during incident resolution, with confirmation issued once normal service has been restored. Following significant incidents, a summary and root-cause explanation can be provided on request.

The service does not currently provide a public status dashboard or an API for outage reporting. Outage communication is managed directly to ensure information is accurate, timely, and relevant to affected users, in line with agreed incident management and escalation procedures.

Identity and authentication

User authentication needed
Yes
User authentication
  • Multi-Factor Authentication (MFA)
  • Identity federation with existing provider (for example Google Apps)
  • Username or password
Access restrictions in management interfaces and support channels
Access to management interfaces and support systems is restricted to authorised personnel using role-based access controls and authenticated user accounts. Access rights are granted on a least-privilege basis and reviewed regularly. Administrative access is limited to staff with a defined business need and is protected through strong authentication controls. Support channels are accessed via authenticated systems, and customer data is only accessible where required to deliver support services. Access is revoked promptly when staff roles change or when individuals leave the organisation, in line with defined joiner, mover, and leaver processes.
Access restriction testing frequency
At least once a year
Management access authentication
  • Multi-Factor Authentication (MFA)
  • Username or password

Audit information for users

Access to user activity audit information
Users contact the support team to get audit information
How long user audit data is stored for
At least 12 months
Access to supplier activity audit information
Users contact the support team to get audit information
How long supplier audit data is stored for
At least 12 months
How long system logs are stored for
At least 12 months

Security governance

Named board-level person responsible for service security
Yes
Security governance certified
Yes
Security governance standards
  • ISO/IEC 27001
  • Other
Other security governance standards
Cyber Essentials Plus certification lapsed in January 2026. Recertification audit is scheduled for February 2026. We currently hold Cyber Essentials and maintain the required technical controls; updated CE+ certificate will be provided once issued.
Information security policies and processes
AIMS Software Limited operates a formal information security management framework aligned to ISO/IEC 27001. Information security policies cover areas including risk management, access control, secure development, incident management, supplier security, data protection, and business continuity. These policies are reviewed regularly to ensure continued effectiveness and alignment with legal, regulatory, and contractual requirements.

Responsibility for information security is owned at senior management level, with oversight provided through defined governance and reporting structures. Day-to-day security management is supported by designated roles responsible for policy implementation, risk assessment, and operational controls. Compliance with policies is reinforced through secure-by-design development practices, role-based access controls, monitoring, and regular testing.

Security incidents and risks are logged, assessed, and managed through established processes, including escalation and corrective actions where required. Independent assurance is provided through external audits and testing, including ISO 27001 and Cyber Essentials Plus certification audits and regular penetration testing. Staff are supported through awareness and training activities to ensure security policies are understood and consistently followed across the organisation.
Software Security Code of Practice
Yes

Operational security

Configuration and change management standard
Supplier-defined controls
Configuration and change management approach
Service components are version controlled and tracked throughout their lifecycle, from development through testing and deployment. Changes are managed through defined change management processes, including assessment, approval, testing, and controlled release to production. Security impacts are considered as part of change assessment, with changes reviewed for potential risks to confidentiality, integrity, and availability. Segregated environments are used to validate changes prior to release, and rollback procedures are in place where required. Changes are logged and auditable to support governance, traceability, and continuous improvement.
Vulnerability management type
Supplier-defined controls
Vulnerability management approach
Potential threats to the service are assessed through ongoing risk management, security monitoring, and regular vulnerability assessments. Vulnerabilities are prioritised based on severity, risk, and potential impact to confidentiality, integrity, and availability. Security patches and updates are tested in non-production environments and deployed in line with defined change management processes, with critical fixes prioritised for timely release. Information about emerging threats is obtained from trusted sources, including security advisories from software vendors, cloud service providers, industry bodies, and independent penetration testing conducted by a CREST-accredited provider.
Protective monitoring type
Supplier-defined controls
Protective monitoring approach
The service is monitored to detect potential security events and service anomalies using application and infrastructure monitoring tools. Monitoring focuses on identifying unusual activity, access patterns, errors, and performance indicators that may suggest a potential compromise. When a potential incident is identified, it is logged, assessed, and investigated in line with defined incident management procedures. Appropriate containment, remediation, and escalation actions are taken based on severity and impact. Incidents affecting security or availability are responded to promptly during business hours, with priority handling for higher-severity events, and managed through to resolution with corrective actions implemented as required.
Incident management type
Supplier-defined controls
Incident management approach
The organisation operates defined incident management processes covering common operational and security events, including service outages, performance issues, and suspected security incidents. Incidents can be reported by users via email, the online support portal, or phone during support hours. All incidents are logged, assessed, prioritised, and managed in line with agreed response and escalation procedures. Users are kept informed of progress as appropriate, and incidents are tracked through to resolution. For significant incidents, an incident summary and root-cause explanation can be provided on request, together with any corrective or preventive actions taken.
Post-quantum cryptography secure
No

Secure development

Approach to secure software development best practice
Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)

Public sector networks

Connection to public sector networks
No

Pricing

Discount for educational organisations
No
Free trial available
No

Discount percentage by annual call-off contract value (excluding VAT)

Less than £250,000
0%
Between £250,000 and £500,000
0%
Between £500,001 and £1,000,000
0%
Between £1,000,001 and £2,500,000
0%
Between £2,500,001 and £5,000,000
0%
Over £5,000,001
0%

Non-mandatory Standards and certifications

ISO/IEC 27001 certification
Yes
Who accredited the ISO/IEC 27001
Amtivo (Ireland) Limited
ISO/IEC 27001 accreditation date
Wednesday 15 January 2025
What the ISO/IEC 27001 doesn’t cover
As AIMS does not outsource any part of its system development to a third-party company, Control A.30 (Outsourced Development) is excluded.
ISO 28000:2022 certification
No
ISO 9001 certification
No
Quality management systems (QMS)
Yes
CSA STAR certification
No
PCI certification
No
Cyber essentials
Yes
Please provide your Cyber Essentials Certificate Number
5cbba84f-8376-4b6d-9a98-79e25e5d706f
Cyber essentials plus
No
Cyber Essentials Alternative
In relation to the services you do not have a current and valid Cyber Essentials Plus certificate which has been awarded by one of the government approved Cyber Essentials accreditation bodies but you are working towards gaining it, and will be in a position to confirm that you have been awarded a current and valid Cyber Essentials Plus certificate by one of the government approved accreditation bodies within 12 months of the date of award.
Other security certifications
No

Social value

Section B - Commitment for Future: Delivery
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.

    • Understanding of employment and relevant skills issues, and of the education and training issues relating to the contract. Illustrative examples: demographics, skills shortages, new opportunities in high growth sectors, geographic/local community and skills/employment challenges
    • Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
  • Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero

    Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.

    • Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
    • Collaborative ways of working with the supply chain to deliver additional environmental benefits in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
    • Delivery of additional environmental benefits through the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
  • Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.

    Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.

    • Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce
    • Understanding barriers to access to health and social care services or employment opportunities e.g. digital inclusion
    • Inclusive and accessible recruitment practices, development practices and retention policies that support-focused activities including those provided in the Guide for line managers on recruiting, managing and developing which support people with a disability or health condition

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at info@aimssoftware.ie. Tell them what format you need. It will help if you say what assistive technology you use.