Secure SMS, RCS & Omnichannel Messaging for Public Sector including Healthcare
QuickSMS provides a secure, UK-hosted messaging platform delivering SMS, RCS, and API communications for appointment reminders, confirmations, recalls, and service updates. Integrated with NHS and clinical systems, it supports NHS App-style workflows, real-time reporting, ISO-certified security, and full UK GDPR and NHS DSP Toolkit compliance.
Features
- Patient Communications
- NHS Messaging Systems
- Support for NHS App-style messaging through secure API integrations.
- Two-way messaging for confirmations, questionnaires, and follow-up communications.
- Automated appointment reminders, recalls, and patient notifications.
- API compatibility with Accurx, Access Rio, EMIS, and SystmOne.
- Secure SMS and RCS messaging integrated with NHS clinical systems.
- High-volume campaign support for vaccination, screening, and recalls.
- Public Sector Messaging
- OTP, One Time Pin, SMS and RCS Messages
Benefits
- Multi-channel support: SMS, RCS, WhatsApp.
- Support two-way patient communications to improve engagement and care outcomes.
- Support NHS App-style notifications using secure API-based messaging workflows.
- Provide RCS messages with branding, links, and interactive appointment actions.
- Enable two-way SMS confirmations to improve attendance and resource planning.
- Integrate directly with clinical systems for real-time appointment messaging.
- Integrate with clinical systems using APIs and email-to-SMS gateways.
- Deliver NHS-compliant patient communications via SMS, RCS, and NHS APP
- Send automated SMS appointment reminders
- Rio, Accurx, Netcall, Patchs , SystmOne
Pricing
- Education pricing available
- Free trial available
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
8 2 1 9 9 4 7 1 8 3 0 7 0 2 9
Contact
Quick SMS Limited
Public Sector Team
Telephone: 02037408909
Email: sales@quicksms.com
About your service
- Service categories
-
Applications
Customer relationship management
- Marketing campaign management
- Customer service
- Contact centre
- Multi cloud support
- Yes
Service scope
- Software add-on or extension
- No
- Cloud deployment model
- Private cloud
- Service constraints
- The QuickSMS platform operates on a 24/7, highly available basis, with resilient UK-hosted infrastructure and continuous monitoring to ensure reliable service delivery. Planned maintenance is scheduled outside peak operational hours and communicated to customers in advance wherever possible. Message delivery is dependent on mobile network operator availability and external carrier networks. Certain advanced features may vary depending on handset capability, operating system, and communication channel, including SMS, RCS, and WhatsApp. No specialised hardware is required, and services are accessible via secure web portals and APIs.
- System requirements
-
- Customer systems must support RESTful API requests.
- TLS 1.2+ required for secure data transmission.
- Email client required for Email-to-SMS functionality.
- Valid API key for authenticated platform access.
- Modern web browser supporting JavaScript and HTTPS encryption.
- Internet connection required for accessing API and web dashboard.
- Administrative permissions to manage platform user accounts.
- Optional webhook endpoint for delivery receipts and status updates.
User support
- Email or online ticketing support
- Yes
- Support response times
- Within 30 Minutes during standard business hours 8am to 5pm Within 60 Minutes at all other times.
- User can manage status and priority of support tickets
- Yes
- Online ticketing support accessibility
- WCAG 2.2 AA
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- No
- Onsite support
- No
- Support levels
-
QuickSMS provides comprehensive, fully inclusive support for its secure messaging platform, ensuring customers receive consistent, high-quality assistance without additional cost. All customers benefit from unlimited access to email and telephone support during UK business hours (08:00–18:00, Monday to Friday), alongside continuous 24/7 platform monitoring, proactive incident detection, and structured incident management. Defined response and resolution targets are maintained in line with the published Service Level Agreement (SLA), providing clear accountability and service assurance.
For service-impacting incidents occurring outside standard business hours, an out-of-hours escalation process is available to ensure timely investigation and resolution. Each customer is assigned a named technical account manager or senior support engineer who oversees onboarding, system integration, configuration, and ongoing service optimisation. This named contact acts as a consistent point of liaison, coordinating technical support, service reviews, and compliance assurance.
QuickSMS also provides ongoing guidance on best practice, security, and regulatory alignment, supporting customers in meeting UK GDPR, NHS DSP Toolkit, and wider public-sector governance requirements. There are no separate charges for standard, enhanced, or premium support services, ensuring transparent, predictable, and cost-effective service delivery. - Support available to third parties
- Yes
Onboarding and offboarding
- Getting started
-
QuickSMS supports customers through a structured onboarding and implementation process designed to enable rapid, secure, and effective adoption of the service. Each customer is assigned a named technical account manager or senior support engineer who coordinates onboarding activities, validates readiness, and acts as a primary point of contact.
Support includes account setup, security configuration, system integration, and alignment with ISO 27001, NHS DSP Toolkit, and DTAC requirements. Customers receive access to comprehensive online user documentation, technical guides, API references, and configuration templates.
Online training is provided through remote workshops, live demonstrations, and guided setup sessions for administrators, clinical teams, and operational users. These sessions cover platform navigation, campaign management, reporting, security controls, and best practice usage. Recorded training materials and user guides are also available for ongoing reference.
Where required, tailored onboarding support and additional training sessions can be delivered to meet specific organisational needs. Ongoing assistance is provided through dedicated support channels, regular service reviews, and continuous improvement processes, ensuring users are confident, compliant, and fully supported throughout the service lifecycle. - Service documentation
- Yes
- Documentation formats
-
- HTML
- End-of-contract data extraction
-
At the end of a contract, QuickSMS supports customers through a controlled and secure data extraction process designed to ensure continuity, compliance, and data protection. Customers may request a data export through their named account manager or the support team in accordance with contractual and data protection requirements.
Data is provided in commonly used, structured formats such as CSV, JSON, or encrypted archive files, covering message logs, delivery reports, contact lists, templates, audit records, and configuration data, subject to retention policies and legal obligations. Exports are generated from secure systems and transferred using encrypted channels or secure file delivery platforms.
Prior to release, identity and authorisation checks are performed to confirm the requester’s entitlement to the data. All extraction activities are logged and reviewed in line with ISO 27001 controls and governance procedures.
Where required, QuickSMS provides technical guidance to support data migration to alternative systems. Following confirmation of successful extraction, remaining customer data is securely deleted or anonymised in accordance with UK GDPR, NHS DSP Toolkit, and contractual retention requirements, with certification available on request. - End-of-contract process
-
At the end of a contract, QuickSMS follows a structured offboarding process to ensure an orderly, secure, and compliant service closure. Customers are notified in advance of contract expiry in line with contractual notice periods and are supported by their named account manager throughout the transition.
The standard contract price includes access to the platform, core messaging services, security controls, monitoring, incident management, routine support, and standard data extraction in commonly used formats. It also includes assistance with account closure, confirmation of data deletion, and final service reporting.
Where required, additional services such as extended data retention beyond contractual periods, bespoke data migration support, complex integration assistance, or enhanced reporting may be provided as chargeable professional services, subject to prior agreement.
Upon contract termination, system access is securely withdrawn, API credentials are revoked, and messaging services are disabled in line with security procedures. Customer data is retained only for statutory and contractual purposes before being securely deleted or anonymised in accordance with UK GDPR, NHS DSP Toolkit, and governance requirements. - Documentation accessibility standard
- WCAG 2.2 AA
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Opera
- Application to install
- No
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
- Mobile Optimised Site
- Service interface
- Yes
- User support accessibility
- WCAG 2.2 AA
- Description of service interface
- The QuickSMS healthcare messaging service provides a secure, browser-based dashboard for managing SMS, RCS, and patient communications. Users can send appointment reminders, confirmations, recalls, and service notifications, configure sender IDs, manage contact lists, and access real-time delivery reports and audit trails. The platform supports REST API and Email-to-SMS integration with NHS and clinical systems. The interface is designed for clarity, accessibility, and public-sector compliance, featuring role-based access controls, responsive layouts, and intuitive workflows for administrative, clinical, and operational users.
- Accessibility standards
- WCAG 2.2 AA
- Accessibility testing
-
QuickSMS undertakes structured interface testing to ensure its platform is accessible and usable for users who rely on assistive technologies, in line with public-sector accessibility requirements and recognised best practice.
Accessibility testing is carried out during major platform releases and interface updates, using both automated and manual methods. Automated tools assess compliance with WCAG 2.1 AA standards, including colour contrast, keyboard navigation, form labelling, and semantic structure. Manual testing validates real-world usability beyond automated results.
Testing includes use of screen readers such as NVDA, JAWS, and VoiceOver to ensure menus, forms, and reports are correctly announced and navigable. Keyboard-only navigation testing confirms full functionality without a mouse. Interfaces are also tested with screen magnification, high-contrast modes, and browser accessibility settings.
Feedback is gathered from internal accessibility leads, partner organisations, and selected public-sector users who use assistive technologies in operational environments. Findings are documented, prioritised, and tracked through the development lifecycle, with remediation actions incorporated into release planning.
Accessibility is embedded within QuickSMS’s design and quality assurance processes, supported by documented procedures, regression testing, and continuous improvement, ensuring the platform remains inclusive, compliant, and usable for all users. - API
- Yes
- What users can and can't do using the API
-
The QuickSMS healthcare messaging platform provides a secure REST API that enables authorised users to integrate clinical and administrative systems with the messaging service. Through the API, customers can provision accounts, configure sender IDs, create and manage templates, maintain contact lists, submit SMS and RCS messages, schedule appointment reminders, retrieve delivery reports, and access audit logs programmatically. API credentials are issued during onboarding and managed using role-based access controls.
Users can update message templates, routing preferences, webhook endpoints, reporting configurations, and campaign parameters in real time. All changes are automatically validated to ensure compliance with security, governance, and regulatory requirements. For security and operational integrity, certain functions are restricted. Customers cannot modify core platform infrastructure, security controls, billing rules, data retention policies, or compliance configurations via the API. Any changes affecting hosting environments, encryption standards, sub-processor arrangements, or regulatory settings must be requested through QuickSMS support and approved under formal change management procedures. Rate limiting and strong authentication controls are applied to protect service availability and prevent misuse. - API documentation
- Yes
- API documentation formats
- HTML
- API sandbox or test environment
- Yes
- Customisation available
- No
Scaling
- Independence of resources
- QuickSMS protects service performance through a multi-tenant architecture with logical segregation, capacity management, and continuous monitoring aligned with ISO 27001 and Cyber Essentials Plus. Messaging queues, routing services, and application resources are isolated to prevent individual customer workloads from impacting others. Automated rate limiting, traffic prioritisation, and load balancing regulate high-volume usage and prevent congestion. Capacity is monitored in real time and scaled in line with documented planning processes. Resource utilisation is reviewed through the Integrated Management System, supporting NHS DSP Toolkit and DTAC assurance requirements.
Analytics
- Service usage metrics
- Yes
- Metrics types
- Detailed service metrics including message delivery rates, latency, route performance, error codes, queue status, throughput volumes, channel performance (SMS, RCS, WhatsApp), API utilisation and system uptime. Users can view real-time delivery events, historical reporting, cost summaries and audit logs. Metrics support compliance, monitoring and operational transparency across public-sector workloads.
- Reporting types
-
- API access
- Real-time dashboards
- Regular reports
- Reports on request
- Resource tagging
- Yes
- FOCUS resource tagging
- Yes
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Conforms to BS7858:2019
- Government security clearance
- Baseline Personnel Security Standard (BPSS)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- United Kingdom
- User control over data storage and processing locations
- No
- Datacentre security standards
- Complies with a recognised standard (for example CSA CCM version 4.0)
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- NCSC approved service provider
- Protecting data at rest
- Physical access control, complying with SSAE-18 / ISAE 3402
- Data sanitisation process
- Yes
- Equipment disposal approach
- Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
- Data sanitisation type
-
- Deleted data can’t be directly accessed / Cryptographic Erasure
- Data Erasure
- Physical Destruction / Hardware containing data is completely destroyed
Data importing and exporting
- Data export approach
- QuickSMS provides structured onboarding and implementation support to help customers adopt the service quickly and securely in line with public-sector assurance requirements. This includes account configuration, security setup, system integration support, and data protection alignment with ISO 27001, Cyber Essentials Plus, NHS DSP Toolkit, and DTAC standards. Customers receive access to online documentation, technical guides, and configuration templates. Remote training sessions and guided onboarding workshops are provided for administrators and operational users. Each customer is assigned a named technical account manager or senior support engineer who coordinates onboarding, validates readiness, and ensures a controlled transition into live service.
- Data export formats
- CSV
- Data import formats
- CSV
Data-in-transit protection
- Data protection between buyer and supplier networks
- TLS (version 1.2 or above)
- Data protection within supplier network
- TLS (version 1.2 or above)
Availability and resilience
- Guaranteed availability
-
QuickSMS guarantees 99.95% monthly service availability for its SMS, RCS, and multi-channel messaging platform in accordance with its published Service Level Agreement (SLA). Platform availability is continuously monitored through automated systems and governed by ISO 27001 and Cyber Essentials Plus controls embedded within the Integrated Management System. Performance metrics, incident records, and uptime data are reviewed regularly to ensure compliance with contractual and regulatory requirements.
Planned maintenance, security updates, and infrastructure upgrades are scheduled outside peak operational periods wherever possible and communicated to customers in advance. Events outside QuickSMS’s reasonable control, including carrier-wide outages, network failures, power disruptions, and force majeure events, are excluded from availability calculations in line with standard industry practice.
QuickSMS does not operate a service credit or refund scheme for availability shortfalls. Instead, service restoration, incident management, root cause analysis, and corrective and preventive actions are managed in accordance with contractual terms, documented procedures, and continuous improvement processes. These activities are aligned with NHS DSP Toolkit and DTAC assurance requirements, supporting service resilience, transparency, and long-term operational stability for public-sector and healthcare customers. - Approach to resilience
-
QuickSMS is designed with a resilient, high-availability architecture to ensure continuity of service for public-sector and healthcare messaging. Core platform components, including API gateways, routing engines, message queues, and delivery processors, operate in fully redundant configurations to eliminate single points of failure. Real-time monitoring, automated failover mechanisms, and intelligent load balancing maintain stable performance during traffic surges, component failures, or network disruptions.
The platform is hosted within secure UK data centre environments, including Rackspace LON5, providing resilient power, cooling, network connectivity, and physical security in line with ISO 27001 and NHS DSP Toolkit requirements. Data is stored on redundant systems with encryption at rest and continuous backup processes, supporting rapid recovery in the event of hardware faults or system failures.
Multiple delivery routes to UK and international mobile networks are maintained to ensure messaging continuity if individual carriers or routes become unavailable. Platform services are continuously health-checked, with automatic failover initiated when issues are detected. Resilience arrangements are regularly reviewed, tested, and documented within the Integrated Management System. Detailed information on network architecture, redundancy, and disaster recovery controls is available to buyers on request to maintain operational security and compliance. - Outage reporting
-
QuickSMS operates a formal incident and service status management framework aligned with ISO 27001 and Cyber Essentials Plus and embedded within its Integrated Management System. This framework defines clear procedures for incident detection, classification, escalation, communication, and resolution, ensuring consistent and transparent service management.
Service availability, planned maintenance activities, and active incidents are published through a publicly accessible service status dashboard, providing customers with real-time visibility of platform performance. Programmatic access to service status information and delivery events is also provided through secure API endpoints and webhook notifications, enabling automated monitoring and integration with customer systems.
During service-impacting incidents, automated and manual email alerts are issued to nominated customer contacts in accordance with documented escalation and communication procedures. Regular status updates are provided throughout the incident lifecycle, including progress reports, estimated resolution times, and confirmation of service restoration.
All incidents are formally documented, with root cause analyses, impact assessments, and corrective and preventive actions recorded and retained in line with governance and audit requirements. These records support compliance with NHS DSP Toolkit, DTAC, and wider regulatory assurance standards. Incident trends and performance metrics are reviewed through management review and continual improvement processes to strengthen platform resilience and service quality overtime.
Identity and authentication
- User authentication needed
- Yes
- User authentication
- Multi-Factor Authentication (MFA)
- Access restrictions in management interfaces and support channels
- QuickSMS restricts access to management interfaces and support channels through role-based access controls, strong authentication, and least-privilege principles aligned with ISO 27001 and Cyber Essentials Plus. User access is provisioned, reviewed, and revoked under documented access management procedures, with formal approval and periodic recertification. Multi-factor authentication is enforced for administrative and privileged accounts. Access to support systems and customer data is limited to authorised personnel and protected through secure ticketing platforms, session logging, and monitoring controls. All access activities are reviewed regularly through the Integrated Management System, supporting NHS DSP Toolkit, DTAC, and DPIA governance and audit requirements.
- Access restriction testing frequency
- At least every 6 months
- Management access authentication
- Multi-Factor Authentication (MFA)
Audit information for users
- Access to user activity audit information
- Users have access to real-time audit information
- How long user audit data is stored for
- User-defined
- Access to supplier activity audit information
- Users have access to real-time audit information
- How long supplier audit data is stored for
- User-defined
- How long system logs are stored for
- User-defined
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
- ISO/IEC 27001
- Information security policies and processes
-
QuickSMS operates a formally documented Information Security Management System (ISMS) aligned with ISO 27001 and Cyber Essentials Plus and embedded within its Integrated Management System. Controlled policies and procedures cover access control, data protection, incident management, asset management, risk assessment, supplier security, secure development, and business continuity.
Information security governance is owned at senior management level, with clearly defined roles, responsibilities, and reporting lines, supported by regular management review and risk oversight. Compliance is maintained through mandatory staff training, role-based access controls, internal audits, vulnerability assessments, penetration testing, and independent certification audits.
The ISMS is supported by documented risk registers, treatment plans, and continual improvement processes, ensuring emerging threats and regulatory changes are addressed proactively. Evidence of compliance and assurance activities is retained in line with governance and audit requirements.
This framework supports NHS DSP Toolkit, DTAC, and Data Protection Impact Assessment (DPIA) governance, providing customers and regulators with transparent, verifiable assurance of QuickSMS’s information security controls and operational maturity. - Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Configuration and change management approach
- QuickSMS operates a formal configuration and change management process aligned with ISO 27001 and ISO 9001 and embedded within its Integrated Management System. All infrastructure, applications, network services, and security controls are recorded in controlled asset and configuration registers and managed throughout their lifecycle. Changes are raised through documented requests and assessed for security, data protection, availability, and regulatory impact, including Cyber Essentials Plus, NHS DSP Toolkit, DTAC, and DPIA requirements. Security-related changes undergo testing, approval, and controlled release, with evidence retained for audit and customer assurance.
- Vulnerability management type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Vulnerability management approach
- QuickSMS operates a formal vulnerability management process aligned with ISO 27001 and Cyber Essentials Plus and embedded within its Integrated Management System. Potential threats are identified through continuous monitoring, vulnerability scanning, independent penetration testing, and internal risk assessments aligned with NHS DSP Toolkit and DTAC requirements. Security intelligence is sourced from the National Cyber Security Centre, vendors, and supplier alerts. Vulnerabilities are assessed for impact and exploitability and prioritised through the ISMS risk process. Critical patches and mitigations are tested and deployed promptly under documented change management procedures, with remediation evidence retained for audit and regulatory assurance.
- Protective monitoring type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Protective monitoring approach
- QuickSMS operates continuous protective monitoring aligned with ISO 27001 and Cyber Essentials Plus and embedded within its Integrated Management System. Platform, network, and application logs are centrally collected and analysed using automated alerting, anomaly detection, and intrusion detection controls. Potential compromises are identified through access monitoring, vulnerability alerts, and behavioural analysis. Suspected security incidents are immediately triaged under documented incident response procedures, with containment and recovery actions initiated without delay. High-severity incidents are responded to on a 24/7 basis. Notifications, investigations, and corrective actions are managed in accordance with NHS DSP Toolkit, DTAC, and UK GDPR requirements.
- Incident management type
- Complies with a recognised standard, for example, CSA CCM v4.0 or ISO/IEC 27035:2011 or SSAE-18 / ISAE 3402
- Incident management approach
- QuickSMS operates a formal incident management framework aligned with ISO 27001 and Cyber Essentials Plus and embedded within its Integrated Management System. Pre-defined response procedures are maintained for service outages, security incidents, data protection events, and integration failures. Incidents can be reported through dedicated support email, telephone lines, and automated monitoring alerts. All incidents are logged, prioritised, and managed in line with documented severity and escalation procedures. Customers receive regular updates during resolution. Formal incident reports, including root cause analysis and corrective actions, are issued following significant incidents and retained to support NHS DSP Toolkit, DTAC, and regulatory assurance requirements.
- Post-quantum cryptography secure
- Yes
Secure development
- Approach to secure software development best practice
- Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- Yes
- Free trial available
- Yes
- Description of free trial
- Free trial for SMS Messaging, Demo for RCS as RCS requires registration.
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 0%
- Between £500,001 and £1,000,000
- 0%
- Between £1,000,001 and £2,500,000
- 0%
- Between £2,500,001 and £5,000,000
- 0%
- Over £5,000,001
- 1%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- Yes
- Who accredited the ISO/IEC 27001
- BSI
- ISO/IEC 27001 accreditation date
- Monday 26 January 2026
- What the ISO/IEC 27001 doesn’t cover
- Not Applicable
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- Yes
- Who accredited the ISO 9001 certification
- BSI
- ISO 9001 accreditation date
- Monday 26 January 2026
- What the ISO 9001 doesn’t cover
- Not Applicable
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- 78d77b87-a04c-4cbb-a900-e784b4bc9bc4
- Cyber essentials plus
- Yes
- Please provide your Cyber Essentials Plus Certificate Number
- 6f9602be-c41f-445e-b07b-2ee2cab51ac4
- Other security certifications
- No
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- New or retained jobs on the contract workforce in the relevant area that meet the criteria set out in MAC 1b, 1c and 1d
- Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
- Plans to engage the contract workforce in deciding the most important workplace issues to address
- Ensuring new workers are informed of their right to join a trade union
- Monitoring of employee engagement rates (by protected characteristic) and, where necessary, the development of actions to ensure all voices are heard across the diversity of the workforce
- Employment contracts that reflect actual hours worked; steps taken to ensure employees understand their contracts and have the ability to review and adjust them if actual hours regularly exceed contracted hours
- Activities that support an environment where staff are educated about, and feel empowered to, address their physical wellbeing
- Activities that support an environment where staff are educated about and feel empowered to report and address bullying and harassment
- Activities to cascade good practice on fair working conditions throughout the supply chain
- Offer a pay and leave entitlement to all eligible staff who become kinship carers, ideally equivalent to statutory adoption pay and leave
- Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
- Monitoring and reporting of gender and ethnicity pay gaps and plans to address them where necessary
- Entitlement to sick pay for the contract workforce, with provision in place for any staff who do not meet the earnings threshold for statutory sick pay, payment of sick pay from day one of absence and payment of staff on the contract workforce who are off sick a replacement income of 100% of their usual earnings for as long as possible
- Plans for an appropriate income replacement policy for staff who are required to spend time away from work to care for a sick dependent or close relative
- Understanding of in-work progression issues affecting the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors
- Measures to support in-work progression to help people in the contract workforce, to move into higher paid work by developing new skills relevant to the contract
- Support for the contract workforce by providing career advice, and providing opportunities for staff working on the contract with in-work progression career development into known skills shortages or high growth areas
- Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
- Volunteering opportunities for staff
- Understanding of the modern slavery risks and issues affecting the market, industry, sector or country (of origin or of source) relevant to the contract, and the workforce in the supplier’s own organisation and those of its key subcontractors
- Measures to identify, mitigate and manage modern slavery risks relating to the contract and how these will be implemented
- Outline policies and practices to be applied to or put in place for the contract to mitigate and manage modern slavery risks, including: Pre-employment checks, recruitment practices. Workplace conditions, safeguarding plans and processes in place and regular monitoring with relevant groups considered, which may include sampling
- How these flow down the supply chain and are monitored Illustrative examples include reporting, site visits, audits, etc.
- How to ensure business decisions re: price/cost, short lead times, payment timescales do not create modern slavery risks in the supply chain
- How the supplier will work with NGOs, trade unions or other businesses to address modern slavery risk
- Means of influencing staff, suppliers, customers, communities and/or any other appropriate stakeholders with respect to modern slavery risks relating to the contract
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.
- Understanding of employment and relevant skills issues, and of the education and training issues relating to the contract. Illustrative examples: demographics, skills shortages, new opportunities in high growth sectors, geographic/local community and skills/employment challenges
- Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
- Activities to support relevant sector related skills growth and sustainability in the contract workforce. Illustrative examples: careers talks, curriculum support, literacy support, safety talks and volunteering
-
Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero
Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.
- Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
- Collaborative ways of working with the supply chain to deliver additional environmental benefits in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
- Delivery of additional environmental benefits through the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
- Understanding of how to influence staff, suppliers, customers, communities and/or any other appropriate stakeholders through the delivery of the contract to support climate and nature protection and improvement
- Activities to reconnect people with the environment and increase awareness of ways to protect and enhance it
-
Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.
Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.
- Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce
- Actions to invest in the physical and mental health and wellbeing of the contract workforce
-