MyKnow Compliance, Capability and Competency Management platform
Assess workforce competency, behavioural capability, and decision-making in complex, safety-critical environments.
Cognisco uses behavioural assessments and situational judgement tests (SJTs) to measure applied knowledge, confidence, and judgement.
Cognisco identifies skills gaps/matrix and behaviour gaps, mitigates people risk, evidences due diligence, and supports targeted training, workforce development, and compliance assurance.
Features
- Behavioural and decision-making assessments using Situational Judgement Tests
- Workforce competency frameworks and capability assessment platform
- Customisable knowledge, confidence, and skills assessments
- 360-degree feedback including self, peers, and managers
- Flexible assessments for formal, regulated, and exam use
- Tools to identify technical skills gaps and support training programmes
- Role-based access with dashboards and management reporting
- API and webhook integration with HR and learning systems
- Biometric invigilation and candidate identity verification
- UK-hosted SaaS on Microsoft Azure
Benefits
- Clear visibility of workforce competency and operational readiness
- Reduced risk in safety-critical and regulated roles
- Evidence of compliance, assurance, and due diligence
- Measures real-world application of knowledge and judgement
- Reduced people risk, incidents, and litigation exposure
- Targeted learning interventions addressing identified skills gaps
- Improved workforce planning and talent development decisions
- Secure assessments preventing fraud and impersonation
- Supports career progression and competency-based development
- Enables organisational culture and behavioural change
Pricing
- Education pricing available
- Free trial available
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
8 2 7 6 7 1 2 7 0 3 3 1 9 5 3
Contact
COGNISCO LIMITED
Amanda Knight
Telephone: 01234 757520
Email: information@cognisco.com
About your service
- Service categories
-
Application Development and Deployment
Analytics and business intelligence
- Business Intelligence
- Multi cloud support
- No
Service scope
- Software add-on or extension
- Yes, but can also be used as a standalone service
- What software services is the service an extension to
-
Civil Service Learning and other Learning Management Systems.
HR/Workforce Management and Employee Engagement processes.
Risk and Regulatory Compliance systems and processes.
Certification and examination systems. - Cloud deployment model
-
- Public cloud
- Private cloud
- Service constraints
- No
- System requirements
-
- Chrome latest version plus the previous version
- Safari latest version plus the previous version
- Edge (Chromium) latest version plus the previous version
- Opera latest version plus the previous version
- Firefox latest version plus the previous version
User support
- Email or online ticketing support
- Yes
- Support response times
- Office hours only, Monday to Friday 9-5:30. SLA levels to be agreed individually in contract.
- User can manage status and priority of support tickets
- No
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- Yes
- Web chat support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support accessibility standard
- WCAG 2.2 AA
- Web chat accessibility testing
- Can be delivered if required.
- Onsite support
- Yes, at extra cost
- Support levels
-
This is a web-based application with Technical/User support provided by phone and email.
For new clients face-to-face training of Tenant Administrators as part of induction is often provided onsite, or via webinars, videoconferencing and phone as required.
We build strong relationships with clients and have frequent meetings to develop projects at inception, with quarterly meetings to maintain continuous improvement.
Relationship management is vital to the bespoke nature of our business and we work hard to make it highly effective and retain clients. - Support available to third parties
- Yes
- AI chatbot
- No
Onboarding and offboarding
- Getting started
-
For new clients face-to-face training of Super Admins as part of induction is often provided on-site, or via webinars, videoconferencing and phone as required. Users are supported both via their own Super Admins and directly by Cognisco via our Support Team as needed.
We focus on building strong relationships with clients and have frequent meetings to develop projects at inception with key users, with quarterly meetings to maintain continuous improvement.
We provide on-going support and training through our highly expert team to current and new users which is included as part of the overall service. We use a helpdesk ticketing system to ensure we tag every request, and then support with email, on-line, phone, videoconferencing, webinar or face-to-face support as required.
Relationship management is vital to the bespoke nature of our business and we work hard to make it highly effective and retain clients. - Service documentation
- Yes
- Documentation formats
-
- HTML
- ODF
- Other
- Other documentation formats
-
- Online documentation
- Microsoft Office formats
- End-of-contract data extraction
-
Clients have multiple options for extracting data including:
Data can be retrieved from the system via the administration function;
Data can be downloaded as extracts which can be standard format or customised;
System and data can be maintained for live access if required;
Archive database and system to be accessible for audit purposes;
Remove personal data and retain anonymised results;
Securely destroy data and back-ups as requested.
We are GDPR compliant and all our data is stored within the UK. - End-of-contract process
-
When a client's contract ends, there are options to pay for a data archiving service, a read-only site for an agreed period of time, or for a certified full data destruction service.
If these services are not requested, all client access will be turned-off and the site closed down.
Data will be retained for a further 30-days, after which all personal data will be anonymised and will be irretrievable. We will inform the client that their personal data has been removed from our system. - Documentation accessibility standard
- WCAG 2.2 A
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Opera
- Application to install
- No
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
-
Application and User Interface has been optimised for mobile devices and tablets.
E.g assessments broken into bite-sized learning. - Service interface
- No
- User support accessibility
- WCAG 2.2 AA
- API
- Yes
- What users can and can't do using the API
-
APIs will be configurable to allow clients to provide and receive notifications from the system.
These will be REST based Web APIs that use JSON payloads and will be authenticated using OAUTH. - API documentation
- Yes
- API documentation formats
- API sandbox or test environment
- Yes
- Customisation available
- Yes
- Description of customisation
-
System is highly customisable which is a key feature and benefit to create and support bespoke applications for each client, and multiple applications within clients.
The following can all be customised:
Subject and content of all assessments to include application of knowledge, behaviour, and culture to client;
Customisation of off-the-shelf assessments for specific client environments and contexts.
Benchmarks, standards, competencies, regulations and compliance applications.
Approved Authors can write, edit and customise assessment content.
Client Super Administrators/Managers can customise user-access, reset assessments, manage and approve competencies.
Team Leaders can approve evidence for competency, approve competency and allocate assessments.
Assigned assessors can award competencies.
Scaling
- Independence of resources
- Service implements automatic scaling to meet demand.
Analytics
- Service usage metrics
- Yes
- Metrics types
-
System usage can be reviewed at multiple levels by System Administrators and Team Manager roles.
System Administrators can have access to metrics for all users, whilst Team Managers only have access to their team's metrics. Multiple levels of team can be set up.
Metrics include current usage, last access, changes made and new data added etc.
Metrics are a primary feature of the system to enable current, past and future status of users to be managed and monitored, and whether they are compliant, competent and up-to-date with qualifications.
Additional service metrics can be provided on request. - Reporting types
-
- API access
- Real-time dashboards
- Regular reports
- Reports on request
- Resource tagging
- Yes
- FOCUS resource tagging
- Yes
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Conforms to BS7858:2019
- Government security clearance
- Security Clearance (SC)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- United Kingdom
- User control over data storage and processing locations
- Yes
- Datacentre security standards
- Complies with a recognised standard (for example CSA CCM version 4.0)
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- Another external penetration testing organisation
- Protecting data at rest
-
- Physical access control, complying with CSA CCM v4.0
- Physical access control, complying with SSAE-18 / ISAE 3402
- Encryption of all physical media
- Data sanitisation process
- Yes
- Equipment disposal approach
- Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
- Data sanitisation type
- Deleted data can’t be directly accessed / Cryptographic Erasure
Data importing and exporting
- Data export approach
- Data exports and data extraction services can be purchased.
- Data export formats
-
- CSV
- ODF
- Data import formats
- CSV
Data-in-transit protection
- Data protection between buyer and supplier networks
- TLS (version 1.2 or above)
- Data protection within supplier network
- TLS (version 1.2 or above)
Availability and resilience
- Guaranteed availability
- 99.9% Up time guaranteed over the course of a year to exclude planned maintenance.
- Approach to resilience
- System is designed to be highly resilient to government standards. Available on request.
- Outage reporting
- We monitor and record availability of the service and alert support of any unavailability.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Username or password
- Other
- Other user authentication
-
The service defines a complete set of roles that control and restrict access to the various parts of the system.
Users can access via a login or access directly via one-time-use url link without login access. - Access restrictions in management interfaces and support channels
-
The service defines a complete set of roles that control and restrict access to the various parts of the system.
Access to Internal Management Systems which set access are controlled using corporate identities and roles at multiple levels. This enables degrees of access for different personnel within each client application.
Users can access via a login or access directly via one-time-use url link without login access.
Access requiring biometric validation can be enabled to ensure identification validation as required. - Access restriction testing frequency
- At least once a year
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Username or password
- Other
- Description of management access authentication
- Management access can be restricted to specific IP addresses if required.
Audit information for users
- Access to user activity audit information
- Users contact the support team to get audit information
- How long user audit data is stored for
- User-defined
- Access to supplier activity audit information
- Users contact the support team to get audit information
- How long supplier audit data is stored for
- User-defined
- How long system logs are stored for
- User-defined
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
-
- CSA CSM version 4.0
- ISO/IEC 27001
- Other
- Other security governance standards
-
ISO 9001:2015
Cyber Essentials - Information security policies and processes
-
ISO27001 2022 standard processes and policies are followed.
ISO9001 2015 standard processes and policies are followed.
Cyber Essentials standard processes and policies are followed.
We have a dedicated QA who reports to Head of Operations, reporting to the CEO and Board. - Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Configuration and change management approach
- All components of our service are maintained within a software development lifecycle management tool including a software versioning control system. Changes identified from various parts of the business are documented and lodged within this tool and allocated to developers to implement. All changes are considered from a security impact and tested via our dedicated testing team.
- Vulnerability management type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Vulnerability management approach
- Our service benefits from advanced auto threat detection on our SQL servers and databases including SQL injection. The auto threat detection service maintains details of all current and new potential threats and applies these to our service automatically. All system operating systems are auto-patched by our provider.
- Protective monitoring type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Protective monitoring approach
- Our service runs a number of monitoring services that automatically notify us of any potential issues. Any issue requiring manual intervention will be assigned a priority ticket, triaged and remediated as soon as possible. All such tickets are responded too within 24 hours.
- Incident management type
- Complies with a recognised standard, for example, CSA CCM v4.0 or ISO/IEC 27035:2011 or SSAE-18 / ISAE 3402
- Incident management approach
- Users report problems either by phone or via our support desk email. Issues are triaged and responded too within our standard SLA. Incidents are logged in our support management system and responses provided to the User.
- Post-quantum cryptography secure
- Yes
Secure development
- Approach to secure software development best practice
- Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- Yes
- Free trial available
- Yes
- Description of free trial
-
Trial options depend on the type of service of interest to the user.
We can provide demo versions of off the shelf assessments, access to demo apps, Free trial periods, indicative reports and user experience and other options. - Link to free trial
- Www.cognisco.com/test-drive
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 10%
- Between £500,001 and £1,000,000
- 15%
- Between £1,000,001 and £2,500,000
- 20%
- Between £2,500,001 and £5,000,000
- 25%
- Over £5,000,001
- 30%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- Yes
- Who accredited the ISO/IEC 27001
- Citation ISO Certification/IASME
- ISO/IEC 27001 accreditation date
- Tuesday 1 July 2025
- What the ISO/IEC 27001 doesn’t cover
- N/A
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- Yes
- Who accredited the ISO 9001 certification
- Citation Limited
- ISO 9001 accreditation date
- Tuesday 14 January 2025
- What the ISO 9001 doesn’t cover
- N/A
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- 1d96f316-7073-498f-bfc0-8a1560875a38
- Cyber essentials plus
- No
- Cyber Essentials Alternative
- In relation to the services you do not have a current and valid Cyber Essentials Plus certificate which has been awarded by one of the government approved Cyber Essentials accreditation bodies but you are working towards gaining it, and will be in a position to confirm that you have been awarded a current and valid Cyber Essentials Plus certificate by one of the government approved accreditation bodies within 12 months of the date of award.
- Other security certifications
- No
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- Measures to support in-work progression to help people in the contract workforce, to move into higher paid work by developing new skills relevant to the contract
- Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
-