Panacea e-Procurement
eProcurement SaaS for public sector sourcing, tendering and early market engagement. Supports requirement analysis, procurement planning, below- and above-threshold procedures, evaluation and moderation. Integrated contract, supplier and performance management with KPIs, reporting and audit trails. Publishes notices, maintains contract registers and Transparency data, with APIs and Central Digital Platform integration.
Features
- Procurement planning pipeline market engagement and end- to-end contract lifecycle
- Compliant notice publication Contracts Finder Find a Tender CDP integration
- Collaboration with Cabinet Office supporting upcoming regulations and policy changes
- Collaboration with Cabinet Office supporting upcoming regulations and policy changes
- Supplier data capture using CDP tokens and automated validation
- Unified procurement database ensuring data integrity consistency and controlled access
- Contract based expenditure reporting with finance system integration or imports
- Spend controls enforcing contract values supplier limits and approval thresholds
- Performance monitoring covering KPIs risk sustainability and social value
- Secure document repository central records audit logs and version control
Benefits
- Confidence procurement activity remains compliant with evolving UK regulations
- Reduced risk through validated supplier data and controlled information reuse
- Improved transparency using structured records notices dashboards and audit trails
- Better contract oversight through live expenditure and performance reporting
- Stronger governance enforcing spend limits approvals and contract controls
- Faster compliant procurement through reusable templates and guided workflows
- Clear management information supporting planning assurance and decision making
- Improved supplier engagement through intuitive secure portals and messaging
- Reduced duplication using shared validated data across procurement activities
- Scalable platform supporting future regulatory change without disruptive reconfiguration
Pricing
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
8 2 4 5 8 6 4 3 8 1 2 3 5 1 7
Contact
PANACEA APPLICATIONS LIMITED
Rachel Wynne
Telephone: 02079760116
Email: tenders@panacea-software.com
About your service
- Service categories
-
Applications
Enterprise resource management
- Procurement
- Multi cloud support
- No
Service scope
- Software add-on or extension
- No
- Cloud deployment model
- Private cloud
- Service constraints
- There are no service constraints beyond those standard for Software as a Service. Panacea Sourcing is accessed via a modern, supported web browser and does not require specialist hardware or local software installation. Users must follow standard information security practices, including maintaining the confidentiality of their login credentials. Planned maintenance is infrequent and, where possible, scheduled outside core UK business hours with advance notice provided. No other service-specific constraints apply.
- System requirements
-
- Web-enabled device with modern, supported internet browser
- Stable internet connection for browser-based access
User support
- Email or online ticketing support
- Yes
- Support response times
- Panacea Software responds to all support requests and questions raised by email, ticket or telephone within four working hours, in line with our published Support Services Policy. Our helpdesk is manned from 9am to 5.30pm on every UK working day. Interactive online support materials, user guides, videos and predictive help and tooltips are available to all users 24/7. Support tickets, emails and calls are logged, tracked and prioritised to ensure timely and effective resolution.
- User can manage status and priority of support tickets
- No
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- No
- Onsite support
- Yes, at extra cost
- Support levels
-
Panacea Software provides award-winning support services to all users as a standard part of the subscription, including buyers, internal stakeholders, evaluators and supplier users, with no additional mandatory support tiers. All subscribers and users have access to our UK-based helpdesk, available during UK working days, with all support requests responded to within four working hours in line with our published Support Services Policy. Support is provided via a secure helpdesk portal, email and telephone.
Subscribers are assigned a dedicated Account Manager and Customer Success Executive who provide ongoing relationship management, regular service reviews and proactive support to ensure successful adoption and continued value. Our Technical Support Executives and in-house development team provide expert second- and third-line support where required.
All users, including free users (such as suppliers and evaluators), have access to comprehensive online support materials, user guides, videos and in-system predictive help and tool-tips, available 24/7 at no additional cost. There are no separate charges for standard support, account management or customer success services. Any enhanced or out-of-scope services, if requested, are agreed transparently in advance.
“The support from the Panacea team is invaluable. Very few suppliers provide this level of support so efficiently and consistently.” – Council - Support available to third parties
- Yes
Onboarding and offboarding
- Getting started
-
Panacea Software follows a robust, structured approach to help subscribers establish, implement and roll out the service, tailored to their requirements and intended outcomes.
Each subscriber is assigned a dedicated implementation team, including an Account Manager, Customer Success Executive and Technical Support, who work with nominated administrators to agree scope, timelines and configuration. Implementation typically includes system configuration, user setup, data migration where required, and preparation for go-live.
Training is delivered onsite and or online, according to the subscriber’s preferences, and is role-based. Initial training focuses on Administrator Users, providing detailed understanding of the software, settings, permissions, templates and workflows. A supported train-the-trainer approach follows to enable effective rollout to all Key Users across the organisation. Targeted online sessions are also provided for Free Users, such as suppliers and evaluators, focusing on relevant tasks.
All training is supported by comprehensive user documentation, guides and videos, available directly within the Panacea Software interface. Training sessions are recorded and shared for future reference.
Following go-live, users have ongoing access to Panacea Software’s award-winning support desk, online guidance and refresher training. Our dedicated team continue to support administrators and Key Users throughout the contract to drive adoption and maximise value long-term. - Service documentation
- Yes
- Documentation formats
-
- HTML
- Other
- Other documentation formats
-
- Online documentation embedded within the Panacea Software interface
- PDF user guides and reference documents
- Microsoft Word documents for detailed guidance
- Microsoft Excel spreadsheets for configuration and data examples
- Recorded training videos and walkthroughs
- Templated onboarding emails with guidance and links
- End-of-contract data extraction
-
Panacea Applications Limited provides a clear and controlled end-of-contract process to ensure subscribers can retrieve their data efficiently and securely from Panacea Software.
On termination or expiry of the contract, subscribers are provided with restricted access to the relevant modules of Panacea Software for a minimum period of 10 business days. During this time, authorised users can extract their data independently using the standard export tools provided within the service. These tools enable the export of structured data held within the platform, allowing subscribers to retain full access to their information without reliance on Panacea Applications Limited staff.
Where required, the access period may be extended by written agreement, subject to GDPR and data protection requirements.
Following completion of the agreed data extraction period, all subscriber data is securely deleted in accordance with Panacea Applications Limited’s data retention and information security policies.
If requested, Panacea Applications Limited can also support a managed exit through an agreed Exit Plan. This may include additional services such as extended access, data mapping, or assistance preparing data for import into a replacement system. Any such services are optional and provided by agreement, with costs agreed in advance. - End-of-contract process
-
At the end of the contract, Panacea Applications Limited follows a clear and structured process to ensure an orderly and low-risk exit for subscribers.
Throughout the contract term, including up to termination, subscribers continue to receive full access to Panacea Software’s award-winning support desk and proactive support from their dedicated Customer Success Executive. This ensures administrators and Key Users remain supported right up to the end of the service, including during planning for contract expiry or transition.
The standard contract price includes a defined end-of-contract period during which subscribers retain restricted access to Panacea Software to extract their data using the built-in export tools. Authorised users can retrieve their data independently without mandatory involvement from Panacea Applications Limited. Following completion of the agreed access period, subscriber data is securely deleted in accordance with Panacea Applications Limited’s data retention and information security policies.
Where additional assistance is required, Panacea Applications Limited can provide optional exit services under an agreed Exit Plan. These may include extended access, data mapping, or support preparing data for migration to a replacement system. Such services are optional, provided only at the subscriber’s request, and are chargeable at the agreed daily rate, with costs confirmed in advance. - Documentation accessibility standard
- WCAG 2.2 AA
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Opera
- Other
- Application to install
- No
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
- Panacea Software is delivered through a fully responsive web interface. All screens automatically adapt to the size and resolution of the device in use, with layouts and content resizing accordingly. The main navigation menu is collapsible, enabling effective use on smaller screens while maintaining a consistent user experience across desktop, laptop, tablet and mobile devices. No separate mobile application is required. Users can securely access the service from a modern web browser. The same service is available regardless of device. For activities involving detailed configuration, reporting or data management, a larger-screen device is recommended to provide optimal usability and visibility.
- Service interface
- Yes
- User support accessibility
- WCAG 2.2 AA
- Description of service interface
- The Panacea Software service interface is intuitive, interactive and configurable, providing role-based access to tools, data and functionality. The interface presents users only with the features and data relevant to their role, enabling efficient and collaborative working while maintaining governance and control. Administrators can configure the interface and permissions to reflect organisational structures and governance requirements. Key Users can manage, monitor and report on activity across buyers, colleagues and suppliers, while Free Users (including Suppliers, Stakeholders and Evaluators) access a streamlined interface focused on completing required tasks. Panacea Software is accessed securely online, without installation, through a standard web browser.
- Accessibility standards
- WCAG 2.2 AA
- Accessibility testing
-
Our interface testing for WCAG 2.2 AA compliance incorporated comprehensive evaluation with users of assistive technology. We conducted systematic testing using NVDA (NonVisual Desktop Access) and Windows Narrator screen readers to ensure full accessibility for users with visual impairments. This testing verified that all interactive elements, form fields, navigation structures, and dynamic content are properly announced and accessible via keyboard navigation. Testing focused on common assistive technologies and interaction methods used by public sector users.
We commissioned an external independent accessibility audit which identified specific issues for remediation. These were then systematically addressed and resolved to ensure compliance.
Additionally, we integrated Axe Core within our .NET NuGet automated testing framework to provide continuous accessibility validation throughout the development lifecycle. This automated testing identifies WCAG 2.2 AA violations at the code level, catching issues before deployment and maintaining compliance as the interface evolves.
We maintain a publicly available accessibility statement on our website. The combination of independent audit, manual assistive technology testing, and automated checks ensures both technical compliance and practical usability for users relying on assistive technologies. - API
- Yes
- What users can and can't do using the API
-
Panacea Software provides a secure, RESTful External Endpoint API that allows authorised third-party systems to integrate with a subscriber’s Panacea Software dataset. It uses standard JSON payloads and industry-standard REST conventions. The API is typically used to integrate finance, ERP and reporting systems (e.g. Power BI), and is pull-based, initiated and controlled by the consuming system.
Users can set up API access by generating a unique API key within Panacea Software, available only to users with appropriate permissions. This key is used by authorised external systems to authenticate API requests over encrypted HTTPS connections. API documentation is embedded within the Panacea Software interface and maintained from the live OpenAPI specification.
Through the API, users can retrieve structured data including contract (Requirement) data, supplier records, procurement activity, and spend and commitment data. Controlled write access is supported for selected datasets, such as submission of paid invoice data and synchronisation of specific supplier identifiers.
Users cannot use the API to bypass Panacea Software’s governance, permissions or data partitioning. API access is scoped to the issuing subscriber or contracting authority, cannot cross organisational boundaries, and is subject to rate limiting and audit logging to protect service availability and data integrity. - API documentation
- Yes
- API documentation formats
- Open API (also known as Swagger)
- API sandbox or test environment
- Yes
- Customisation available
- Yes
- Description of customisation
-
Panacea Software is highly configurable, allowing buyers to tailor the service to their organisational, governance and operational requirements without custom code.
What can be customised: Customisation options include user roles and permissions, workflows and approval rules, templates and forms, questionnaires and evaluation models, code formats (such as budget, cost centre and GL codes), reporting views, notifications, supplier data requirements, and data structures used for finance and ERP integration. Subscribers can also apply organisational branding, including logos and colour schemes, and configure consent statements to align with GDPR and data protection policies.
How users can customise: Configuration is performed through intuitive, role-based administration screens within Panacea Software. Changes can be applied at contracting authority, organisation, team or module level and take effect immediately. Templates, questionnaires and workflows can be amended and reused as requirements evolve.
Who can customise: Authorised Administrator Users within the subscriber organisation can manage configuration settings and user roles. Where required, Panacea Software’s support team can assist administrators and undertake more complex configuration on the subscriber’s behalf, subject to agreement and governance controls.
All configuration changes are controlled through user permissions and recorded in audit logs to support governance, accountability and compliance requirements.
Scaling
- Independence of resources
- Panacea Software is hosted on enterprise-grade, automatically scalable private cloud infrastructure within UK Tier III data centres. Each subscriber operates within a securely isolated instance of Panacea Software, with dedicated databases and logical data separation, ensuring that one subscriber’s activity cannot impact another’s performance or data. Platform capacity is proactively monitored, with automated alerts and 24x7 monitoring by Panacea Applications Limited and its hosting provider. The hosting environment is resilient and geo-redundant, supporting high availability and rapid failover. Planned maintenance is performed outside business hours, and performance is continuously reviewed to ensure consistent service delivery for all subscribers.
Analytics
- Service usage metrics
- Yes
- Metrics types
-
Panacea Software provides subscribers with direct access to service usage and activity metrics through on-screen dashboards and reports. Users view and analyse audit logs and user activity data, including logins, actions taken, changes made, supporting governance and compliance. All reports can be filtered and exported for further analysis.
Panacea Applications Limited also reports on support, maintenance and approved change request activity as part of regular contract review meetings.
Panacea Software is delivered as a fully managed SaaS service, so metrics are provided at application level rather than underlying cloud infrastructure. Resource tagging and FOCUS tagging are not applicable. - Reporting types
-
- Real-time dashboards
- Regular reports
- Resource tagging
- No
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Other security clearance
- Government security clearance
- Baseline Personnel Security Standard (BPSS)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- United Kingdom
- User control over data storage and processing locations
- No
- Datacentre security standards
- Complies with a recognised standard (for example CSA CCM version 4.0)
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- ‘IT Health Check’ performed by a CREST-approved service provider
- Protecting data at rest
-
- Physical access control, complying with SSAE-18 / ISAE 3402
- Encryption of all physical media
- Data sanitisation process
- Yes
- Equipment disposal approach
- Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
- Data sanitisation type
-
- Deleted data can’t be directly accessed / Cryptographic Erasure
- Data Erasure
- Explicit overwriting of storage before reallocation / Secure Erase
- Physical Destruction / Hardware containing data is completely destroyed
Data importing and exporting
- Data export approach
- Users can export data directly from Panacea Software using built-in export tools available throughout the service. Intuitive column pickers, filters and sorting options, enable onscreen review of data before export and enable users to extract the information they require. Exports are available in Excel and PDF, with graphical outputs available where applicable for reporting. Data can also be accessed and exported via the Panacea Software API for integration with external systems. For subscribers using Purchase-to-Pay functionality, data can be automatically exported in configured formats for direct import into finance or ERP systems to support charging, commitment management, and payment processing.
- Data export formats
-
- CSV
- Other
- Other data export formats
-
- Microsoft Excel spreadsheets (.xlsx)
- PDF documents for reports and records
- HTML web pages for on-screen data and reports
- Graphical reports exported as PDF
- JSON via API for system integration
- Data import formats
-
- CSV
- Other
- Other data import formats
-
- Microsoft Excel spreadsheets using provided import schema
- Configured Excel templates for data migration and setup
Data-in-transit protection
- Data protection between buyer and supplier networks
- TLS (version 1.2 or above)
- Data protection within supplier network
- TLS (version 1.2 or above)
Availability and resilience
- Guaranteed availability
-
Panacea Software is designed, hosted and operated to deliver a 99.9% Service Availability target, excluding planned maintenance. The service is hosted on enterprise-grade private cloud platforms within UK Tier III standard data centres, providing resilient infrastructure with redundancy across power, cooling and networking. This design enables systems to be maintained and updated without taking the service offline and supports expected uptime in excess of 99.95%.
Service availability is measured against total unplanned downtime and is monitored continuously. A 99.9% availability target equates to less than 8.76 hours of unplanned downtime per annum. Platform performance and availability are proactively monitored using automated tools, with alerts escalated to on-call engineers for rapid investigation and resolution.
Panacea Applications Limited operates 24x7 monitoring and follows defined incident management and defect resolution processes, with response times set out in the published Support and Maintenance Policy.
Planned maintenance is scheduled outside normal business hours wherever possible and communicated in advance. Panacea Applications Limited does not provide automatic service credits or refunds for availability; remedies are provided in accordance with the contract, using commercially reasonable efforts to restore service promptly and minimise user impact. - Approach to resilience
-
Panacea Software is designed to be resilient across infrastructure, platform and operational layers, ensuring availability, data protection and recoverability.
It is hosted on enterprise-grade private cloud infrastructure within UK Tier III standard data centres. These facilities provide resilient design across power, cooling and network connectivity, with multiple redundant paths and the ability to carry out maintenance without service interruption. Physical access to datacentre facilities is strictly controlled, monitored 24x7 and independently accredited, supporting strong asset protection.
The hosting platform is geo-redundant, with data replicated to a secondary UK location to support disaster recovery if the primary site is unavailable. Panacea Software includes robust backup arrangements, with frequent backups stored securely and protected against unauthorised access. Recovery processes are defined and tested to ensure data integrity and timely restoration.
Availability, capacity and performance are continuously monitored using automated tooling, with alerts escalated to on-call engineers for rapid investigation. Planned maintenance is scheduled outside normal business hours wherever possible and communicated in advance.
Operational resilience is supported by formal business continuity and disaster recovery plans, maintained and tested in line with our ISO/IEC 27001-certified information security management system. This layered approach ensures Panacea Software remains resilient, recoverable and secure under exceptional conditions. - Outage reporting
-
Panacea Software uses proactive monitoring and structured communications to report service outages and minimise impact on subscribers. Root causes and lessons learned are reviewed to prevent recurrence and improve service resilience.
Service availability and performance are continuously monitored 24x7 using automated monitoring and alerting tools. Any unplanned outages or degradation are detected in real time and escalated to on-call engineers for immediate investigation and resolution, in line with Panacea Applications Limited’s incident management procedures.
Subscribers are notified of planned maintenance or service interruptions in advance via prominent on-screen announcements within Panacea Software, and by email, with details of the expected impact and timing. Where an unplanned outage occurs that materially affects service availability, subscribers are informed by email as soon as practicable, with updates provided as the issue is investigated and resolved.
Panacea Software does not currently provide a public status dashboard or outage reporting API. Instead, outage information is communicated directly to affected subscribers, ensuring accurate and relevant information is shared without exposing sensitive operational detail.
Service performance, availability and incident history are reviewed as part of regular contract review meetings, and summary reports can be provided to subscribers on request to support service assurance and governance.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Identity federation with existing provider (for example Google Apps)
- Username or password
- Access restrictions in management interfaces and support channels
- Access to Panacea Software, its management interfaces and support channels is restricted to authorised users only, using role-based access controls. Users authenticate using secure credentials, with Multi-Factor Authentication supported. Subscribers are encouraged to enable Single Sign-On (SSO) for all internal users, allowing access to be governed by their corporate identity provider, and to require two-factor authentication for external users, including suppliers. Access permissions are assigned by role and applied by administrators. All access attempts and actions are logged, with controls in place to detect and block repeated failed login attempts. Support channel access is restricted to authorised users only
- Access restriction testing frequency
- At least every 6 months
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Identity federation with existing provider (for example Google Apps)
- Dedicated link (for example VPN)
- Username or password
Audit information for users
- Access to user activity audit information
- Users have access to real-time audit information
- How long user audit data is stored for
- At least 12 months
- Access to supplier activity audit information
- Users contact the support team to get audit information
- How long supplier audit data is stored for
- At least 12 months
- How long system logs are stored for
- At least 12 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
- ISO/IEC 27001
- Information security policies and processes
-
Panacea Applications Limited operates a formal information security management framework aligned to its ISO/IEC 27001:2022–certified Integrated Management System, which is also certified to ISO 9001 and ISO 14001. This framework defines the policies, processes and controls governing the secure delivery of Panacea Software.
Information security policies cover, as a minimum, data protection and privacy, access control and authentication, asset and configuration management, secure software development, change management, vulnerability management, incident response, business continuity and disaster recovery. These policies are supported by documented procedures and technical controls embedded within Panacea Software and its hosting environment.
Responsibility for information security is clearly defined. The Technical Director holds overall accountability, with operational responsibility delegated to senior technical staff. Compliance with security policies is monitored through regular management review, internal audits and independent external audits as part of ISO certification.
All personnel receive security awareness and role-based training, including induction training, regular refresher sessions and external cyber security updates where appropriate. Secure development and operational processes include regular testing, vulnerability assessment, penetration testing, and disaster recovery exercises.
Relevant information security policies and controls are available to users within the Panacea Software interface and support materials, supporting user awareness and compliance with organisational security requirements. - Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Configuration and change management approach
- We operate formal configuration and change management processes governed by our ISO/IEC 27001:2022–certified management system all Panacea Software components are version-controlled and tracked throughout their lifecycle, from development through testing, release and maintenance. Changes are logged, assessed and approved using controlled workflows, with audit trails. Each change is evaluated for functional impact, potential security implications, data protection and access controls. Changes undergo peer review, security review and structured testing, including regression testing, before release. Changes are reviewed and approved by appropriate technical and security roles prior to release. Releases follow a controlled deployment process to protect service integrity and security.
- Vulnerability management type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Vulnerability management approach
- We operate a structured vulnerability management process governed by our ISO/IEC 27001:2022–certified management system. Potential threats are identified through continuous monitoring, automated security tooling, vulnerability scanning, penetration testing and review of supplier and industry advisories. All identified vulnerabilities are logged, risk-assessed and prioritised based on severity and potential impact. Security patches and mitigations are deployed promptly within defined patching schedules, with critical updates applied as a priority. Hosting platforms and operating systems are regularly patched, and protective controls monitor and block malicious activity. Threat intelligence is sourced from accredited security providers, software vendors, penetration testing partners and recognised cyber-security advisories.
- Protective monitoring type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Protective monitoring approach
- PPanacea Applications Limited operates continuous protective monitoring governed by its ISO/IEC 27001:2022-certified management system. Potential compromises are identified through 24x7 monitoring of application, platform and security logs, automated alerting, intrusion detection controls and regular vulnerability and penetration testing. Suspicious activity is investigated promptly by on-call technical staff, with incidents logged, assessed and prioritised according to severity. Confirmed security incidents are contained, remediated and escalated in line with defined incident response procedures. Response times are governed by severity-based SLAs, with critical incidents addressed as a priority to minimise impact and restore secure service operation with post-incident review to strengthen controls continually.
- Incident management type
- Complies with a recognised standard, for example, CSA CCM v4.0 or ISO/IEC 27035:2011 or SSAE-18 / ISAE 3402
- Incident management approach
- We operate incident management processes governed by our ISO/IEC 27001:2022-certified information security management system, with business continuity and emergency preparedness embedded through our integrated ISO 14001 framework. Pre-defined procedures manage common operational, security and availability incidents. Users report incidents to our helpdesk by email, ticket or telephone. All incidents are logged, assessed and prioritised by severity, with escalation to on-call technical staff and management as required. Incidents are investigated, contained and resolved according to defined response procedures, with business continuity measures invoked where necessary. Incident updates and reports are provided to affected subscribers by email and through service review meetings.
- Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- No
- Free trial available
- No
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 10%
- Between £500,001 and £1,000,000
- 15%
- Between £1,000,001 and £2,500,000
- 25%
- Between £2,500,001 and £5,000,000
- 30%
- Over £5,000,001
- 35%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- Yes
- Who accredited the ISO/IEC 27001
- Amtivo Group Limited T/A British Assessment Bureau Ltd.
- ISO/IEC 27001 accreditation date
- Thursday 28 December 2017
- What the ISO/IEC 27001 doesn’t cover
- Not applicable, all services within scope are covered.
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- Yes
- Who accredited the ISO 9001 certification
- Amtivo Group Limited T/A British Assessment Bureau Ltd.
- ISO 9001 accreditation date
- Tuesday 29 April 2008
- What the ISO 9001 doesn’t cover
- Not applicable, all services within scope are covered.
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- 14147e95-b41b-4a94-9820-2681bc02e730
- Cyber essentials plus
- No
- Cyber Essentials Alternative
- You do not have a current and valid Cyber Essentials Plus certificate, or will not have in place within 12 months of the date of award but have an IASME certified equivalent.
- Other security certifications
- No
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- New or retained jobs on the contract workforce in the relevant area that meet the criteria set out in MAC 1b, 1c and 1d
- Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
- Plans to engage the contract workforce in deciding the most important workplace issues to address
- Activities that support an environment where staff are educated about and feel empowered to report and address bullying and harassment
- Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
- Understanding of in-work progression issues affecting the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors
- Measures to support in-work progression to help people in the contract workforce, to move into higher paid work by developing new skills relevant to the contract
- Understanding of the modern slavery risks and issues affecting the market, industry, sector or country (of origin or of source) relevant to the contract, and the workforce in the supplier’s own organisation and those of its key subcontractors
- Outline policies and practices to be applied to or put in place for the contract to mitigate and manage modern slavery risks, including: Pre-employment checks, recruitment practices. Workplace conditions, safeguarding plans and processes in place and regular monitoring with relevant groups considered, which may include sampling
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.
- Understanding of employment and relevant skills issues, and of the education and training issues relating to the contract. Illustrative examples: demographics, skills shortages, new opportunities in high growth sectors, geographic/local community and skills/employment challenges
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 3: Resilient, innovative and flexible supply chains: Support economic growth through enabling resilient businesses, opportunities for small businesses and voluntary, community and social enterprises
- Understanding of the types of businesses in the market and the level of participation by new businesses, entrepreneurs, start-ups, SMEs, VCSEs and mutuals
-
Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero
Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.
- Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
- Understanding of how to influence staff, suppliers, customers, communities and/or any other appropriate stakeholders through the delivery of the contract to support climate and nature protection and improvement
-
Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain
Policy Outcome 6: Employment and training: For those who face barriers to employment
- Understanding of employment and skills issues, and of the skills and employment shortages of high growth sectors relating to the contract
- Understanding of the issues affecting the representation of disabled people in the workforce in the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors
- Inclusive and accessible recruitment practices, and retention-focused activities, including those provided in the Guide for line managers on recruiting, managing and developing people with a disability or health condition
- Working conditions which promote an inclusive working environment and promote retention and progression
- Understanding of the issues affecting inequality in employment, skills and pay in the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors. Measures to tackle inequality in employment, skills and pay in the contract workforce
-
Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain
Policy Outcome 7: Creating a pipeline of opportunities: For the contract workforce, reducing barriers to entry for under-represented groups.
- Understanding of the issues affecting the development of new skills by target cohort
- Understanding of the underlying factors affecting improvements to reduce barriers to entry and training schemes for the target cohort(s) related to the contract workforce
- Understanding of issues relating to entering the contract workforce
-
Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.
Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.
- Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce
- Understanding barriers to access to health and social care services or employment opportunities e.g. digital inclusion
- Inclusive and accessible recruitment practices, development practices and retention policies that support-focused activities including those provided in the Guide for line managers on recruiting, managing and developing which support people with a disability or health condition
-