Skip to main content

Help us improve the Digital Marketplace - send your feedback

AG CONSULTANCY & APPS LTD

AG - SaaS – Applications – Content workflow and management

AG Consultancy provides content workflow and management solutions using SAP Document Management System and SAP BTP content services. We deliver full lifecycle implementation, configuration, and integration to manage documents, approvals, and records efficiently, ensuring compliant, auditable workflows optimised for governance standards and operational efficiency across enterprise business processes globally securely.

Features

  • Cloud-hosted content management application accessed through secure browser interface
  • Centralised content storage supporting documents, media and structured information
  • Configurable content workflows for creation, review and approval
  • Version control enabling tracking of content changes over time
  • Role-based access controls governing content access and permissions
  • Secure sharing of content within and across teams
  • Audit logging of content actions and workflow activities
  • Integration with existing applications and document repositories
  • Search and metadata tools supporting content discovery and organisation
  • Reporting dashboards providing visibility of content workflows and usage

Benefits

  • Improve content control through structured workflows and approval processes
  • Reduce errors using version control and governed content changes
  • Increase efficiency by automating content review and approval workflows
  • Improve collaboration with secure, shared access to managed content
  • Enhance visibility through clear tracking of content status and actions
  • Support compliance with auditable content management and access controls
  • Reduce duplication by centralising content storage and management
  • Enable faster publishing through streamlined content workflows
  • Improve discoverability using structured metadata and search capabilities
  • Scale content management easily as organisational content volumes grow

Pricing

  • Education pricing available
  • Free trial available

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at bindu.benjamin@agcapps.com. Tell them what format you need. It will help if you say what assistive technology you use.

Framework

G-Cloud 15

Service ID

8 3 4 4 5 5 0 1 0 3 9 3 0 5 7

Contact

AG CONSULTANCY & APPS LTD Bindu Benjamin
Telephone: 07775452318
Email: bindu.benjamin@agcapps.com

About your service

Service categories

Applications

Content workflow and management

  • Capture
  • Document
  • Media Services
  • Creative
  • EDiscovery and forensics

Content services

  • Enterprise Content Management Applications
  • Content Sharing and Collaboration Applications

Persuasive content management

  • Website Software
  • Digital Asset Management Applications
  • Product Content Management Applications
  • Content Marketing Applications
  • Video Platforms
  • Digital Adoption Platform

Enterprise portals and digital workspaces

  • Multi-Audience Portals
  • Integrated Employee Workspaces
Multi cloud support
Yes

Service scope

Software add-on or extension
Yes, but can also be used as a standalone service
What software services is the service an extension to
The service can extend existing application platforms, development tools and cloud services, including enterprise application stacks, integration platforms and identity services. It enhances deployment, management and monitoring capabilities while also operating as a standalone application platform for organisations without existing platform services.
Cloud deployment model
Hybrid cloud
Service constraints
The service operates within defined maintenance and operational constraints typical of a cloud-hosted SaaS platform. Planned maintenance is carried out periodically to apply updates, security patches and improvements and scheduled outside core business hours wherever possible, with advance notice provided to buyers.
The service is accessed through a supported web browser and does not require specialist hardware. Use of the service is subject to agreed service limits, such as user access roles and environment configuration boundaries, to ensure platform stability and security. The service is not dependent on specific on-premises hardware and does not require buyers to manage underlying infrastructure.
System requirements
  • Modern web browser supporting current security and encryption standards
  • Reliable internet connectivity to access the cloud-hosted service
  • User authentication credentials issued during service onboarding
  • Compatible integration endpoints for optional system integrations

User support

Email or online ticketing support
Yes
Support response times
AG responds to service-related questions during standard business hours, Monday to Friday. Initial responses are typically provided within one business day. Queries received outside business hours or at weekends are logged and acknowledged on the next working day.
Where enhanced support or extended hours are required, alternative response times and support arrangements can be agreed contractually. Response times apply to questions and service requests and are separate from incident response times, which are managed in line with agreed service priorities and SLAs
User can manage status and priority of support tickets
Yes
Online ticketing support accessibility
WCAG 2.2 AAA
Phone support
Yes
Phone support availability
24 hours, 7 days a week
Web chat support
Yes
Web chat support availability
24 hours, 7 days a week
Web chat support accessibility standard
WCAG 2.2 AAA
Web chat accessibility testing
AG has completed web chat and service interface testing with users who rely on assistive technologies to ensure accessibility and usability. Testing included use with screen readers, keyboard-only navigation and browser accessibility tools to validate compatibility and user experience.
Feedback from assistive technology users was reviewed to identify any barriers to access, including focus order, readability, navigation flow and interaction with web chat functionality. Identified issues were logged and addressed through configuration changes or platform updates where required.
Accessibility testing outcomes are incorporated into ongoing service assurance and improvement activities. Accessibility considerations are also reviewed following platform updates or changes to ensure continued compliance. Where required, additional testing can be undertaken to meet specific buyer accessibility needs or contractual requirements, supporting inclusive and accessible service delivery.
Onsite support
Yes
Support levels
The standard support level is included within the service subscription and provides access to service support during normal business hours, Monday to Friday. This level includes handling of service-related queries, guidance on platform usage, incident logging, service requests and access to service documentation. Response times are aligned to agreed service priorities.
An enhanced support level can be provided at an additional cost and includes extended support hours, accelerated response times and increased service reporting. This option is suitable for organisations with higher availability or operational assurance requirements.
For buyers requiring a more tailored service, a premium support option can be agreed contractually. This may include a named technical account manager or cloud support engineer, regular service reviews, proactive service optimisation and closer alignment with the buyer’s delivery and governance processes. Pricing for enhanced and premium support levels is dependent on scope, service hours and resource requirements and is agreed as part of the call-off contract.
All support levels are delivered using secure, authenticated service channels and are reviewed regularly to ensure continued effectiveness and value.
Support available to third parties
Yes
AI chatbot
Yes

Onboarding and offboarding

Getting started
AG supports users in starting to use the service through a structured onboarding and enablement approach designed to ensure effective and secure adoption of the application platform.
Onboarding typically begins with an initial setup and configuration phase, where user access, roles and environments are established in line with buyer requirements. Users are provided with guidance on service functionality, security controls and operational processes to support confident use of the platform.
Training is primarily delivered through online formats, including remote walkthrough sessions, knowledge transfer workshops and recorded materials where appropriate. These sessions are tailored to different user roles, such as administrators, developers and operational users. Where required and agreed contractually, onsite training can be provided at an additional cost.
Comprehensive user documentation is provided to support self-service learning and ongoing reference. Documentation includes user guides, configuration guidance, operational procedures and troubleshooting information. Documentation is made available through secure online access and updated to reflect platform changes.
During early service use, users have access to service support to answer questions and address initial issues. This ensures a smooth transition into live operation and supports effective use of the service from the outset.
Service documentation
Yes
Documentation formats
  • HTML
  • ODF
  • PDF
End-of-contract data extraction
At the end of the contract, users can extract their data using standard data export mechanisms provided by the service. Data can be exported through the secure service interface and, where applicable, via the service API, using commonly used, non-proprietary formats to support reuse and portability.
Prior to contract termination, users are given a defined period to complete data extraction activities. Guidance is provided to support users in identifying relevant data sets and completing exports successfully. Exported data includes configuration information, operational data, logs and other service-generated content associated with the buyer’s use of the platform.
Once data extraction has been completed or the agreed extraction period has ended, remaining customer data is securely deleted in line with AG’s data sanitisation and retention policies. Secure deletion processes are aligned to recognised standards and ensure customer data cannot be recovered.
This approach ensures buyers retain full access to their data, supports orderly transition to alternative services if required, and provides assurance that customer data is handled securely and responsibly at contract end.
End-of-contract process
At the end of the contract, AG supports an orderly off-boarding process to ensure continuity, data protection and contractual clarity. Buyers are notified in advance of contract expiry and provided with guidance on data extraction, access timelines and service closure activities.
Included in the contract price is continued access to the service until the contract end date, the ability to export customer data using standard export mechanisms, and secure deletion of remaining customer data following the agreed extraction period. Standard support is available during the contract term to assist with questions relating to service use and off-boarding.
Additional costs may apply where buyers request extended access beyond the contract end date, bespoke data export support, additional reporting, or assistance with transition to an alternative platform. Optional services such as extended support, consultancy, or tailored handover activities can be provided where agreed in advance.
Once the contract has ended and data extraction is complete, user access is removed and customer data is securely deleted in line with AG’s data retention and sanitisation policies. Confirmation of service termination and data deletion can be provided on request.
Documentation accessibility standard
WCAG 2.2 AAA

Using the service

Web browser interface
Yes
Supported browsers
  • Microsoft Edge
  • Firefox
  • Chrome
  • Safari
Application to install
Yes
Compatible operating systems
  • Android
  • IOS
  • Linux or Unix
  • MacOS
  • Windows
  • ChromeOS
Designed for use on mobile devices
Yes
Differences between the mobile and desktop service
The desktop service provides full access to all application platform features, including configuration, administration, reporting and management functions. It is optimised for larger screens and supports complex workflows and detailed configuration activities.
The mobile service is designed to support essential access and visibility rather than full administrative functionality. On mobile devices, users can view service status, receive notifications, access key dashboards and review information, but some advanced configuration and management features may be limited or read-only to ensure usability and security. The mobile experience prioritises responsive design, readability and ease of navigation.
Service interface
Yes
User support accessibility
WCAG 2.2 AAA
Description of service interface
The service is accessed through a secure, browser-based interface providing role-based access to application platform functionality. The interface presents dashboards, configuration screens and management tools to support application development, deployment and ongoing operation. Navigation is structured around common user tasks, with clear separation between administrative, operational and reporting functions.
Monitoring, alerts and reporting are integrated within the interface to provide visibility of platform status and activity. Configuration changes and user actions are logged to support governance and audit requirements. The interface uses responsive design principles and is compatible with accessibility standards, including keyboard navigation and assistive technologies
Accessibility standards
WCAG 2.2 AAA
Accessibility testing
AG has undertaken interface testing with users who rely on assistive technologies to ensure the service interface is accessible, usable and inclusive. Testing focused on common user journeys within the browser-based interface, including navigation, form interaction, dashboard use and access to key management functions.
Assistive technologies used during testing included screen readers, keyboard-only navigation and browser accessibility tools such as zoom, contrast controls and focus indicators. Testing assessed areas such as logical focus order, clarity of labels, consistency of navigation, readability of content and compatibility with assistive technology controls.
Feedback from assistive technology users was reviewed to identify potential barriers to access or usability issues. Where issues were identified, changes were implemented through interface configuration, layout adjustments or platform updates. Accessibility considerations are documented and incorporated into ongoing service assurance and improvement activities.
Interface accessibility is reviewed following significant updates or changes to ensure continued compatibility with assistive technologies. Where required, additional testing can be undertaken to meet specific buyer accessibility needs or contractual requirements, supporting compliance with EN 301 549 and WCAG-aligned accessibility expectations.
API
Yes
What users can and can't do using the API
The service provides a secure, authenticated API that allows authorised users to integrate, automate and manage selected aspects of the application platform. API access is controlled through role-based permissions and secure authentication mechanisms to ensure appropriate governance.
Users can set up the service through the API by onboarding application environments, registering resources, retrieving configuration templates and integrating the platform with external systems such as identity services, monitoring tools or deployment pipelines. Initial API credentials are issued during onboarding and managed by authorised administrators.
Through the API, users can make changes such as triggering application deployments, updating approved configuration parameters, retrieving platform status and performance information, and exporting operational or audit data. API interactions are logged to support traceability, auditing and incident investigation.
There are limitations on API usage to protect service integrity and security. Actions with significant service, security or availability impact, such as changes to core platform architecture, global security settings or access controls, are restricted or require approval through the service interface and formal change management processes. The API cannot be used to bypass governance controls, disable security features or directly modify underlying infrastructure.
API documentation
Yes
API documentation formats
  • Open API (also known as Swagger)
  • HTML
  • ODF
  • PDF
API sandbox or test environment
Yes
Customisation available
Yes
Description of customisation
The service is designed to be configurable to meet organisational and operational requirements while maintaining platform security and stability. Customisation focuses on configuration rather than code-level modification of the underlying platform.
Users can customise what is presented and how the service operates within defined boundaries. This includes configuring application environments, deployment pipelines, access roles, permissions, dashboards, alerts, reporting views and integration settings. Platform behaviour such as scaling rules, deployment options and notification preferences can also be configured to align with organisational processes.
Customisation is performed through the secure browser-based service interface and, where appropriate, through the service API. Configuration changes follow defined validation and governance controls to ensure changes do not negatively impact platform security, availability or compliance. Templates and predefined configuration options are provided to support consistency and reduce risk.
Who can customise the service is controlled through role-based access controls. Authorised administrators nominated by the buyer can manage platform configuration, user roles and integrations. Standard users have access to limited configuration options relevant to their role, such as viewing dashboards or managing assigned applications. AG personnel do not make configuration changes unless explicitly authorised or agreed as part of support services.

Scaling

Independence of resources
AG ensures users are not adversely affected by the demand other users place on the service through a scalable, multi-tenant SaaS architecture with logical separation of customer environments. Resources are managed using capacity controls, monitoring and automated scaling to maintain consistent performance across tenants.
Service usage is continuously monitored to identify abnormal demand or performance impacts. Platform controls, including rate limiting and workload management, are applied where appropriate to prevent excessive usage from affecting other users. Capacity planning and regular performance reviews are undertaken to ensure sufficient headroom is maintained.

Analytics

Service usage metrics
Yes
Metrics types
AG provides service usage and performance metrics to support transparency, operational oversight and service assurance. Metrics include platform availability, service uptime, user activity, environment usage, deployment activity and system performance indicators.
Operational metrics such as response times, error rates, alert volumes and service capacity trends are also available where relevant. Usage metrics support buyers in understanding how the service is being used and in identifying opportunities for optimisation or improvement.
Metrics are used as part of ongoing service management and governance, supporting service reviews, performance monitoring and continuous improvement activities. =
Reporting types
  • API access
  • Real-time dashboards
  • Regular reports
  • Reports on request
Resource tagging
Yes
FOCUS resource tagging
Yes

Resellers

Supplier type
Not a reseller

Staff security

Staff security clearance
Conforms to BS7858:2019
Government security clearance
Developed Vetting (DV)

Asset protection

Knowledge of data storage and processing locations
Yes
Data storage and processing locations
United Kingdom
User control over data storage and processing locations
Yes
Datacentre security standards
Supplier-defined controls
Penetration testing frequency
At least every 6 months
Penetration testing approach
‘IT Health Check’ performed by a CHECK service provider
Protecting data at rest
  • Physical access control, complying with CSA CCM v4.0
  • Physical access control, complying with SSAE-18 / ISAE 3402
  • Physical access control, complying with another standard
  • Encryption of all physical media
  • Scale, obfuscating techniques, or data storage sharding
Data sanitisation process
Yes
Equipment disposal approach
Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
Data sanitisation type
  • Deleted data can’t be directly accessed / Cryptographic Erasure
  • Data Erasure
  • Explicit overwriting of storage before reallocation / Secure Erase
  • Degaussing
  • Physical Destruction / Hardware containing data is completely destroyed

Data importing and exporting

Data export approach
Users can extract their data using standard data export mechanisms provided by the service. Data can be exported through the secure service interface and, where applicable, via the service API, using commonly used, non-proprietary formats to support reuse and portability.
Users are given a defined period to complete data extraction activities. Guidance is provided to support users in identifying relevant data sets and completing exports successfully. Exported data includes configuration information, operational data, logs and other service-generated content associated with the buyer’s use of the platform.
Data export formats
  • CSV
  • ODF
Data import formats
  • CSV
  • ODF

Data-in-transit protection

Data protection between buyer and supplier networks
  • Private network or public sector network
  • TLS (version 1.2 or above)
Data protection within supplier network
TLS (version 1.2 or above)

Availability and resilience

Guaranteed availability
AG guarantees availability of the application platform through defined service level agreements (SLAs) covering access to the SaaS service and core platform functionality. The service is hosted on resilient, accredited cloud infrastructure and designed to support high availability and scalability.
The standard SLA guarantees 99.5% monthly application availability, excluding planned maintenance. Availability is measured at the application layer and reflects the ability for authorised users to access and use core platform features. Planned maintenance activities are scheduled outside normal business hours wherever possible and are communicated to buyers in advance.
Service availability is monitored continuously using platform monitoring and alerting tools. Performance against availability targets is reviewed as part of regular service management and governance activities. Unplanned service disruptions are managed through defined incident management processes, with timely communication, escalation and resolution aligned to incident severity.
If the guaranteed availability level is not met, buyers may be eligible for service credits, applied as a percentage of the monthly service charge for the affected period. Service credits and thresholds are defined within the call-off contract and applied as credits against future invoices rather than cash refunds. Root cause analysis is undertaken following any SLA breach, and corrective actions are implemented.
Approach to resilience
AG designs the service to be resilient through a combination of robust architecture, operational controls and use of accredited cloud infrastructure. The service is delivered as a SaaS platform hosted on resilient, third-party cloud datacentres that are designed for high availability and fault tolerance.
The underlying datacentre infrastructure operates across multiple availability zones, providing redundancy for compute, storage and network components. This design reduces single points of failure and supports rapid recovery in the event of component or site-level issues. Datacentres comply with recognised security and resilience standards, and detailed information on datacentre certifications and architecture is available to buyers on request.
At the service level, resilience is supported through continuous monitoring, automated alerting and proactive capacity management. The platform is designed to scale in response to demand and to isolate faults to minimise impact on users. Regular backup processes and tested recovery procedures are in place to support data protection and service restoration.
Operational resilience is further reinforced through defined incident, problem and change management processes aligned to recognised best practice. Lessons learned from incidents are reviewed and fed into continuous improvement activities to strengthen resilience over time.
Outage reporting
AG reports service outages and service-impacting issues through defined service communication and incident management processes.
Outages affecting the service are communicated to authorised buyer contacts via direct email alerts, providing clear information on the issue, service impact, current status and expected next steps. Updates are issued at appropriate intervals until service restoration is confirmed.
Where applicable, outage status and incident updates are available through a secure service interface for logged-in users. In addition, an API is provided to enable programmatic access to service status and incident information, supporting integration with buyer monitoring, alerting or service management tools.
Following resolution of a significant outage, AG can provide an incident summary or post-incident report on request, outlining root cause, resolution actions and preventative measures implemented.
This approach ensures timely, transparent and controlled communication of outages, aligned with ITIL incident management practices and public sector service expectations.

Identity and authentication

User authentication needed
Yes
User authentication
Multi-Factor Authentication (MFA)
Access restrictions in management interfaces and support channels
AG restricts access to management interfaces and support channels using authenticated user accounts and role-based access controls. Access is granted on the principle of least privilege and limited to authorised users approved by the buyer. Roles define permitted actions such as configuration, deployment, monitoring and reporting.
Administrative access is restricted to authorised AG personnel and protected by additional security controls. Access rights are reviewed regularly and updated in response to role changes or leavers. All access to management interfaces and support channels is logged and monitored to support auditability, accountability and incident investigation.
Access restriction testing frequency
At least every 6 months
Management access authentication
Multi-Factor Authentication (MFA)

Audit information for users

Access to user activity audit information
Users have access to real-time audit information
How long user audit data is stored for
User-defined
Access to supplier activity audit information
Users have access to real-time audit information
How long supplier audit data is stored for
User-defined
How long system logs are stored for
User-defined

Security governance

Named board-level person responsible for service security
Yes
Security governance certified
Yes
Security governance standards
ISO/IEC 27001
Information security policies and processes
AG operates a comprehensive information security framework under a formally implemented Information Security Management System (ISMS) accredited to ISO/IEC 27001. The organisation also holds Cyber Essentials Plus and SOC 2 Type II assurance, providing independent validation of technical and operational security controls.
Information security policies are aligned to ISO 27001 control objectives, SOC 2 Trust Services Criteria and NCSC guidance. Policies cover areas including access control, data protection, incident management, vulnerability management, asset management, supplier assurance, secure development, and acceptable use. Policies are reviewed regularly to ensure continued compliance with legal, regulatory and contractual requirements, including UK GDPR and the Data Protection Act 2018. AG is registered with the Information Commissioner’s Office (ICO).
Information security governance is embedded within the organisational reporting structure. Senior management retains overall accountability for information security, supported by designated security and service management leads responsible for day-to-day implementation and oversight. Security risks, incidents and compliance issues are reported through defined governance and management review processes, ensuring appropriate visibility and decision-making.
Compliance with security policies is enforced through documented procedures, role-based access controls, technical safeguards and mandatory staff training. All personnel involved in service delivery receive regular security awareness training.
Software Security Code of Practice
Yes

Operational security

Configuration and change management standard
Supplier-defined controls
Configuration and change management approach
AG operates defined configuration and change management processes aligned to ITIL practices and ISO 27001 control objectives. Service components, including platform configurations, environments, integrations and supporting services, are recorded and tracked throughout their lifecycle using configuration records and service documentation.
Changes are requested, assessed, approved and implemented through controlled change management processes. Each change is evaluated for potential impact on service availability, security and compliance, including risks to data protection and access controls. Security impact assessments are undertaken where relevant, and changes are tested prior to release. All changes are logged, auditable and reviewed post-implementation to confirm outcomes
Vulnerability management type
Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
Vulnerability management approach
AG operates a defined vulnerability management process aligned to ISO 27001, SOC 2 Type II and Cyber Essentials Plus requirements. Potential threats are assessed through regular vulnerability scanning, review of system configurations and risk assessment activities. Information on emerging threats is obtained from trusted sources including vendor security advisories, NCSC guidance, industry alerts and independent security providers.
Identified vulnerabilities are prioritised based on severity and potential impact. Security patches and mitigations are deployed in a timely manner through controlled change management processes, with critical updates applied as soon as practicable. Remediation actions are verified and tracked to completion
Protective monitoring type
Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
Protective monitoring approach
AG operates defined protective monitoring processes to identify and respond to potential security compromises. Monitoring includes review of system logs, security alerts, audit trails and service activity generated by the platform and underlying cloud services. Anomalies or suspicious events are assessed by authorised personnel to determine potential impact and severity.
Where a potential compromise is identified, incident management procedures are initiated promptly, including investigation, containment, escalation and communication to affected parties. Security incidents are prioritised based on risk, with critical incidents responded to immediately and managed in line with defined incident response processes.
Incident management type
Complies with a recognised standard, for example, CSA CCM v4.0 or ISO/IEC 27035:2011 or SSAE-18 / ISAE 3402
Incident management approach
AG operates defined incident management processes aligned to recognised standards and ITIL practices. Pre-defined procedures are in place for common service and security events, including incident classification, prioritisation, escalation and resolution.
Users report incidents through secure support channels, including the service interface and email. All incidents are logged, tracked and managed in line with agreed service priorities and response targets. Status updates are provided during incident resolution, and incident reports or post-incident summaries are shared with authorised buyer contacts where appropriate. Lessons learned are reviewed and incorporated into continuous improvement activities to strengthen service reliability and security.
Post-quantum cryptography secure
Yes

Secure development

Approach to secure software development best practice
Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)

Public sector networks

Connection to public sector networks
Yes
Connected networks
  • Public Services Network (PSN)
  • Police National Network (PNN)
  • Health and Social Care Network (HSCN)

Pricing

Discount for educational organisations
Yes
Free trial available
Yes
Description of free trial
AG offers a limited free trial providing access to core application platform functionality and documentation. The trial supports evaluation and familiarisation only and excludes production use, formal SLAs, advanced features and enhanced support. Trial access is provided for a short, predefined period agreed in advance.

Discount percentage by annual call-off contract value (excluding VAT)

Less than £250,000
2.5%
Between £250,000 and £500,000
5%
Between £500,001 and £1,000,000
5%
Between £1,000,001 and £2,500,000
10%
Between £2,500,001 and £5,000,000
10%
Over £5,000,001
10%

Non-mandatory Standards and certifications

ISO/IEC 27001 certification
Yes
Who accredited the ISO/IEC 27001
INTERCERT
ISO/IEC 27001 accreditation date
Wednesday 19 March 2025
What the ISO/IEC 27001 doesn’t cover
N/A
ISO 28000:2022 certification
No
ISO 9001 certification
Yes
Who accredited the ISO 9001 certification
BSI
ISO 9001 accreditation date
Sunday 18 February 2024
What the ISO 9001 doesn’t cover
Please note for the Cyber Essentials and Cyber Essentials + we have valid certificates but the portal will not allow me to input the certificate number (despite following instructions given in clarifications)
Quality management systems (QMS)
Yes
CSA STAR certification
No
PCI certification
No
Cyber essentials
No
Cyber Essentials Alternative
In relation to the services you do not have a current and valid Cyber Essentials certificate which has been awarded by one of the government approved Cyber Essentials accreditation bodies but you are working towards gaining it, and will be in a position to confirm that you have been awarded a current and valid Cyber Essentials certificate by one of the government approved accreditation bodies within 12 months of the date of award.
Cyber essentials plus
No
Cyber Essentials Alternative
In relation to the services you do not have a current and valid Cyber Essentials Plus certificate which has been awarded by one of the government approved Cyber Essentials accreditation bodies but you are working towards gaining it, and will be in a position to confirm that you have been awarded a current and valid Cyber Essentials Plus certificate by one of the government approved accreditation bodies within 12 months of the date of award.
Other security certifications
Yes
Any other security certifications
SOC 2 TYPE II

Social value

Section B - Commitment for Future: Delivery
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority

    • New or retained jobs on the contract workforce in the relevant area that meet the criteria set out in MAC 1b, 1c and 1d
    • Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
    • Plans to engage the contract workforce in deciding the most important workplace issues to address
    • Monitoring of employee engagement rates (by protected characteristic) and, where necessary, the development of actions to ensure all voices are heard across the diversity of the workforce
    • Employment contracts that reflect actual hours worked; steps taken to ensure employees understand their contracts and have the ability to review and adjust them if actual hours regularly exceed contracted hours
    • Activities that support an environment where staff are educated about, and feel empowered to, address their physical wellbeing
    • Activities that support an environment where staff are educated about and feel empowered to report and address bullying and harassment
    • Activities to cascade good practice on fair working conditions throughout the supply chain
    • Offer a pay and leave entitlement to all eligible staff who become kinship carers, ideally equivalent to statutory adoption pay and leave
    • Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
    • Monitoring and reporting of gender and ethnicity pay gaps and plans to address them where necessary
    • Entitlement to sick pay for the contract workforce, with provision in place for any staff who do not meet the earnings threshold for statutory sick pay, payment of sick pay from day one of absence and payment of staff on the contract workforce who are off sick a replacement income of 100% of their usual earnings for as long as possible
    • Understanding of in-work progression issues affecting the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors
    • Measures to support in-work progression to help people in the contract workforce, to move into higher paid work by developing new skills relevant to the contract
    • Support for the contract workforce by providing career advice, and providing opportunities for staff working on the contract with in-work progression career development into known skills shortages or high growth areas
    • Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
    • Volunteering opportunities for staff
    • Understanding of the modern slavery risks and issues affecting the market, industry, sector or country (of origin or of source) relevant to the contract, and the workforce in the supplier’s own organisation and those of its key subcontractors
    • Measures to identify, mitigate and manage modern slavery risks relating to the contract and how these will be implemented
    • Outline policies and practices to be applied to or put in place for the contract to mitigate and manage modern slavery risks, including: Pre-employment checks, recruitment practices. Workplace conditions, safeguarding plans and processes in place and regular monitoring with relevant groups considered, which may include sampling
    • How these flow down the supply chain and are monitored Illustrative examples include reporting, site visits, audits, etc.
    • How to ensure business decisions re: price/cost, short lead times, payment timescales do not create modern slavery risks in the supply chain
    • Means of influencing staff, suppliers, customers, communities and/or any other appropriate stakeholders with respect to modern slavery risks relating to the contract
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.

    • Understanding of employment and relevant skills issues, and of the education and training issues relating to the contract. Illustrative examples: demographics, skills shortages, new opportunities in high growth sectors, geographic/local community and skills/employment challenges
    • Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
  • Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero

    Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.

    • Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
    • Delivery of additional environmental benefits through the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
  • Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain

    Policy Outcome 6: Employment and training: For those who face barriers to employment

    • Inclusive and accessible recruitment practices, and retention-focused activities, including those provided in the Guide for line managers on recruiting, managing and developing people with a disability or health condition
    • Working conditions which promote an inclusive working environment and promote retention and progression
    • Other measures to provide equality of opportunity for disabled people and those with health conditions into employment, including becoming a Disability Confident employer and inclusion of supported businesses in the contract supply chain
    • Inclusive and accessible development practices, including guidance for line managers on recruiting, managing and developing people with a disability or health condition

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at bindu.benjamin@agcapps.com. Tell them what format you need. It will help if you say what assistive technology you use.