Skip to main content

Help us improve the Digital Marketplace - send your feedback

J C APPLICATIONS DEVELOPMENT LIMITED

JCAD CORE Risk, Control & Compliance Management Software

JCAD is an off the shelf ERM software. It simplifies the storage, management & reporting of risk, controls, actions & compliance data. It provides easy risk & control review, risk appetite, opportunity management, system reminders & many reporting options including data output through API's to your own BI software.

Features

  • Enterprise risk & compliance management, assessment and tracking
  • Incident & opportunity management, assessment and tracking
  • Internal control management, tracking & reporting
  • Audit recommendation management
  • Auto generated emails for reviews, events and approvals
  • Realtime dashboard & API, enables BI reporting
  • Client configurable
  • Quick to implement
  • Can utilise ISO31000, OGC & IRM guidance
  • Raft of optional risk management functions

Benefits

  • Overview of all areas of compliance in one place
  • Tailored to your own framework, terminology, structure and categories
  • Tracking of all tasks/activity so nothing is missed
  • Provides a business-wide standard format for ERM
  • Easily demonstrates compliance for regulatory bodies
  • Removes need for multiple spreadsheets
  • Easily compare and analyse risk performance across the business
  • Entire organisation can view reports if necessary
  • Aligns risk to corporate objectives and tracks appetite
  • Enables linking between registers for a holistic view of risk/compliance

Pricing

  • Education pricing available
  • Free trial available

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at jcad@jcad.co.uk. Tell them what format you need. It will help if you say what assistive technology you use.

Framework

G-Cloud 15

Service ID

7 8 9 4 6 0 3 9 0 9 7 6 1 8 4

Contact

J C APPLICATIONS DEVELOPMENT LIMITED Phil Walden
Telephone: 01730 771957
Email: jcad@jcad.co.uk

About your service

Service categories

Applications

Enterprise resource management

  • Enterprise performance management
  • Project and portfolio management

Financial

  • Treasury and Risk Management Applications
Multi cloud support
No

Service scope

Software add-on or extension
No
Cloud deployment model
Private cloud
Service constraints
None
System requirements
  • Browser based
  • Edge
  • Safari
  • Mozilla
  • Chrome

User support

Email or online ticketing support
Yes
Support response times
Our support desk runs 9 - 5.30 Monday through Friday. We guarantee immediate acknowledgement and fix within 4 hours. If this is not possible we keep the client informed and there is a defined escalation process that is followed for serious issues that can not be resolved within 24 hours.
We also have a specific SLA that details support times for hosted products.
User can manage status and priority of support tickets
No
Phone support
Yes
Phone support availability
9 to 5 (UK time), Monday to Friday
Web chat support
Yes
Web chat support availability
9 to 5 (UK time), Monday to Friday
Web chat support accessibility standard
WCAG 2.2 A
Web chat accessibility testing
Web chat is a feature of our CRM system, Hubspot. Anyone using our website is able to ask a question. This feature is monitored by JCAD (through an alerts facility) to ensure timely responses are provided.
Onsite support
Yes, at extra cost
Support levels
SLA for response times is based upon severity level.

Low - Within 24 hours
Medium - Within 24 hours
High - Within 8 hours
Critical/Significant customer impact - Within 4 Hours

Hosting uptime is guaranteed to be upwards of 99.9%.

Costs for the support detailed above are included within our maintenance fee.

Each client will have access to an Implementation Consultant and an Account Manager as well as the dedicated support desk. Should the issue lie with our hosting partners then JCAD will work with them to resolve
Support available to third parties
No
AI chatbot
No

Onboarding and offboarding

Getting started
Due to the nature of the system being "off the shelf" we adopt a standard approach to implementation which means that it can be achieved quickly and with a low resource from the client.

The basic approach is as follows.

1. Client receives access to evaluation site to enable review of system prior to configuration
2. Pre-implementation meeting (remote or onsite) with assigned consultant to discuss configuration and to provide sufficient training to enable this review.
3. Over the course of an agreed timeframe - consultant and client will agree relevant customisations
4. JCAD configures database based upon discussions
5. Prototype database created
6. Further training provided to enable prototype testing (remote or onsite)
7. Changes made if necessary
8. System goes LIVE

We would normally expect an implementation to go live within 8 - 12 weeks.

Online documentation is provided as part of the system and this can be amended to fit the clients own framework.
Service documentation
Yes
Documentation formats
  • HTML
  • PDF
  • Other
Other documentation formats
  • Word
  • Mp4
End-of-contract data extraction
JCAD provide data free of charge in a simple flat file format. If a different format is required that necessitates additional consultancy work, a charge will be made.
End-of-contract process
Once the contract is terminated, all access to the cloud service will be denied. If requested within 90 days of termination JCAD will provide a data export (at no charge) of risk and control data in .csv, html or Excel format.
Documentation accessibility standard
None or don’t know
How the documentation is accessible
Onboarding materials such as training and guidance is provided throughout the implementation stages. In system help is also able to be customised by the client. There are no offboarding materials, data is simply either provided in a flat file format or irrevocably destroyed 90 days after contract termination.

Using the service

Web browser interface
Yes
Supported browsers
  • Microsoft Edge
  • Firefox
  • Chrome
  • Safari
  • Other
Application to install
No
Designed for use on mobile devices
Yes
Differences between the mobile and desktop service
The application scales for use on a smartphone rather than being an app designed for a smartphone.
Service interface
No
User support accessibility
WCAG 2.2 A
API
Yes
What users can and can't do using the API
The API allows the user/organisation to retrieve data over a secure connection for reporting purposes with applications such as Power BI or Microsoft Excel.

The API is used soley for the retrieval of data for use in external systems.
API documentation
Yes
API documentation formats
  • PDF
  • Other
API sandbox or test environment
Yes
Customisation available
Yes
Description of customisation
Common facets of ERM are able to configured by the client, this includes organisational hierarchy, taxonomy, custom fields, ERM functionality. We are aligned to common standards such as ISO31000 and the Orange Book so configuration is based around these.

Scaling

Independence of resources
We operate in the MS Azure environment - Segregated customer instances have ringfenced resources to ensure that one customer doesn't take up a disproportionate amount of a single resource.

Analytics

Service usage metrics
Yes
Metrics types
Usage metrics such as who logged in, when they logged in and what they accessed are available as a report.
Reporting types
Regular reports
Resource tagging
No
FOCUS resource tagging
No

Resellers

Supplier type
Not a reseller

Staff security

Staff security clearance
Other security clearance
Government security clearance
Security Clearance (SC)

Asset protection

Knowledge of data storage and processing locations
Yes
Data storage and processing locations
United Kingdom
User control over data storage and processing locations
No
Datacentre security standards
Complies with a recognised standard (for example CSA CCM version 4.0)
Penetration testing frequency
At least once a year
Penetration testing approach
‘IT Health Check’ performed by a CREST-approved service provider
Protecting data at rest
  • Physical access control, complying with CSA CCM v4.0
  • Physical access control, complying with SSAE-18 / ISAE 3402
  • Physical access control, complying with another standard
  • Encryption of all physical media
Data sanitisation process
Yes
Equipment disposal approach
Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
Data sanitisation type
  • Deleted data can’t be directly accessed / Cryptographic Erasure
  • Data Erasure

Data importing and exporting

Data export approach
Data is extracted by the client in Excel format. If necessary JCAD can provide assistance with this but professional services may then be involved if it is more than the provision of a .csv or .xls format of record and action data.
Data export formats
  • CSV
  • Other
Other data export formats
Excel
Data import formats
  • CSV
  • Other
Other data import formats
Excel

Data-in-transit protection

Data protection between buyer and supplier networks
TLS (version 1.2 or above)
Data protection within supplier network
TLS (version 1.2 or above)

Availability and resilience

Guaranteed availability
The infrastructure has 100% network uptime availability. We aim to provide 99.99%. Application availability outside schedule maintenance windows.
Approach to resilience
JCAD use the MS Azure environment within UK South. Production and backup data are stored in separate data centres in the UK. Further information is available on request.
Outage reporting
Email alerts in the event of an outage

Identity and authentication

User authentication needed
Yes
User authentication
  • Multi-Factor Authentication (MFA)
  • Identity federation with existing provider (for example Google Apps)
  • Username or password
  • Other
Other user authentication
IP restrictions can be applied to restrict access to the application from specific IP ranges. MFA is accomplished through the use of SSO integration.
Access restrictions in management interfaces and support channels
Access control to management interfaces are provided within the application.

Access is restricted to designated support staff at a level required for them to perform their role. An escalation process in place whereby senior staff can also interface if needed.
Access restriction testing frequency
At least once a year
Management access authentication
  • Multi-Factor Authentication (MFA)
  • Identity federation with existing provider (for example Google Apps)
  • Username or password
  • Other
Description of management access authentication
Access is restricted to designated support staff at a level required for them to perform their role. A escalation process in place whereby senior staff can also interface if needed.

Audit information for users

Access to user activity audit information
You control when users can access audit information
How long user audit data is stored for
At least 12 months
Access to supplier activity audit information
You control when users can access audit information
How long supplier audit data is stored for
At least 12 months
How long system logs are stored for
At least 12 months

Security governance

Named board-level person responsible for service security
Yes
Security governance certified
Yes
Security governance standards
ISO/IEC 27001
Information security policies and processes
We have an information security policy which is applied by our consultants when working with client data. The same policy is used in relation to our own data.
Our Head of Operations and MD are responsible for each of these respectively. Any breaches or issues will be reported to one of them.

As an ISO27001 certified organisation we take security very seriously and much of this is to ensure that processes and best practice are understood and followed.
Software Security Code of Practice
Yes

Operational security

Configuration and change management standard
Supplier-defined controls
Configuration and change management approach
We are certified ISO27001:2022 which incorporates and audits elements such as these.

All our services are monitored through threshold capacity monitoring on CPU, RAM, HDD and server availability monitoring with live SMS and email notification to support staff.

Any server changes go through a change control and risk assessment process and are logged.
Vulnerability management type
Supplier-defined controls
Vulnerability management approach
We are certified ISO27001:2022 which incorporates and audits elements such as these.

Our infrastructure has a SIEM solution providing a centralised threat detection, investigation, response, and proactive hunting across on‑premises and cloud environments. This provides vulnerability scanning to highlight any potential vulnerabilities and has virus and threat protection in place.

Patches are deployed within a short period of time to address any vulnerabilities.

Potential threat information is obtained from best practice review and industry focus based literature.
Protective monitoring type
Supplier-defined controls
Protective monitoring approach
We are certified ISO27001:2022 which incorporates and audits elements such as these.

Our infrastructure has a SIEM solution providing a centralised threat detection, investigation, response, and proactive hunting across on‑premises and cloud environments. This provides protective monitoring to highlight any potential compromises, incidents or vulnerabilities.

Potential compromises can be highlighted by industry focus literature, client feedback, penetration testing. Any potential compromise will be reviewed for mitigation requirements and based up the level of risk addressed within a short period.
Incident management type
Supplier-defined controls
Incident management approach
Incidents are recorded and assessed for root cause, resolution actions and resolution effectiveness. Common events are handled by our support team and incident tracking systems. Users can report incidents to our support team by phone or email during support hours. As part of ISO27001:2022 our incident reporting policies and procedures are recorded and actioned routinely should they occur. JCAD have a Information & Security Policy that includes details of our incident management approach.t of an incident.
Post-quantum cryptography secure
No

Secure development

Approach to secure software development best practice
Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)

Public sector networks

Connection to public sector networks
No

Pricing

Discount for educational organisations
Yes
Free trial available
Yes
Description of free trial
The free trial option provides access to a basic system with demo data so that the key functions are able to tested in the real world. This is available upon request
Link to free trial
Available as part of a due diligence process

Discount percentage by annual call-off contract value (excluding VAT)

Less than £250,000
0%
Between £250,000 and £500,000
10%
Between £500,001 and £1,000,000
10%
Between £1,000,001 and £2,500,000
10%
Between £2,500,001 and £5,000,000
10%
Over £5,000,001
10%

Non-mandatory Standards and certifications

ISO/IEC 27001 certification
Yes
Who accredited the ISO/IEC 27001
Alcumus ISOQAR
ISO/IEC 27001 accreditation date
Monday 25 March 2024
What the ISO/IEC 27001 doesn’t cover
No exclusions
ISO 28000:2022 certification
No
ISO 9001 certification
Yes
Who accredited the ISO 9001 certification
Alcumus ISOQAR
ISO 9001 accreditation date
Wednesday 19 June 2024
What the ISO 9001 doesn’t cover
No exclusions
Quality management systems (QMS)
Yes
CSA STAR certification
No
PCI certification
No
Cyber essentials
Yes
Please provide your Cyber Essentials Certificate Number
C28d184b-bf3a-43e5-946b-7b03535adbb4
Cyber essentials plus
Yes
Please provide your Cyber Essentials Plus Certificate Number
A6b7e45d-050d-4492-b017-86522a298d83
Other security certifications
No

Social value

Section B - Commitment for Future: Delivery
  • Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero

    Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.

    • Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
    • Delivery of additional environmental benefits through the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
    • Understanding of how to influence staff, suppliers, customers, communities and/or any other appropriate stakeholders through the delivery of the contract to support climate and nature protection and improvement

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at jcad@jcad.co.uk. Tell them what format you need. It will help if you say what assistive technology you use.