Assure Expenses
Assure Expenses gives your organisation the tools to proactively manage employee expenses. The system is configured to match your organisation's policies and limits, including mileage rates and home to base deductions. DVLA integration reduces corporate risk with automated vehicle and licence checks.
Features
- Accurate mileage tracking with address and distance lookup services
- Address lookup service to premise level addresses
- ESR integration: bi-directional interfaces with ESR
- System integration: interface with payroll, finance and HR systems
- OCR technology scans receipts and automatically populates expense claims
- Driver compliance: manage the recording and verification of all documentation
- Vehicle and driver documentation retrieved and populated from DVLA data
- Mobile app: record, submit and approve expenses on the go
- Over 120 built-in standard reports providing expenses spend analysis
- Corporate card management: manage credit cards, corporate and fuel cards
Benefits
- Reduce your expenses spend through accurate and compliant claims
- Reduce overspend with accurate journey distance calculations and validation
- Reduce corporate risk with driver/vehicle checks using DVLA data
- Ensure HMRC/expenses policy compliance with intuitive flags and limits
- Full visibility of claims process for employees, managers and finance
- Claimants can submit claims quicker, approvers have less to check
- Quick approval ensures faster reimbursement for employees
- Manage the entire process from your smartphone
- Reduced manual checking and processing
- Reduce expenses spend by up-to 20%; reduce processing by 80%
Pricing
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
8 6 2 6 2 2 2 6 5 8 6 8 2 4 4
Contact
RLDatix
UK Sales
Telephone: +44 (0)20 7355 5555
Email: Bid.Manager@rldatix.com
About your service
- Service categories
-
Applications
Enterprise resource management
Human capital management
- Core Human Resources Applications
- Multi cloud support
- No
Service scope
- Software add-on or extension
- No
- Cloud deployment model
- Private cloud
- Service constraints
-
RLDatix will normally perform Scheduled Maintenance activities during Out of Hours.
Emergency Maintenance may be required as a result of identifying a problem through on-going monitoring and management that could potentially cause an outage or failure of the SaaS Services. RLDatix will use reasonable endeavours to provide the Customer advance notification if possible and manage such Emergency Maintenance in such a way as to minimise impact on the Customer's operations.
Emergency Maintenance may be conducted at any time. - System requirements
-
- Internet access
- Compliant web-browser
User support
- Email or online ticketing support
- Yes
- Support response times
-
Priority-based support model, which is included at no additional cost:
• Priority 1 - Within one (1) hour - Four (4) Support Service Hours
• Priority 2 - Within one (1) hour - Sixteen (16) Support Service Hours
• Priority 3 - Within one (1) Business Day - Forty-eight (48) Support Service Hours
• Priority 4 - Within one (1) Business Day - User can manage status and priority of support tickets
- Yes
- Online ticketing support accessibility
- None or don’t know
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- No
- Onsite support
- No
- Support levels
- RLDatix provide a single, priority-based support model which is included, at no additional cost, within the pricing document provided. * Priority 1 - Within one (1) hour - Four (4) Support Service Hours * Priority 2 - Within one (1) hour - Sixteen (16) Support Service Hours * Priority 3 - Within one (1) Business Day - Forty-eight (48) Support Service Hours * Priority 4 - Within one (1) Business Day - Within the next Software release At the point of “Go Live” the customer shall be assigned a Customer Success Analyst who shall focus on two key areas in their support of the customer: *Software Adoption – The Customer Success Analyst will visit customers and work with them to help them on their journey to realise financial and non-financial benefits from the software. Once baseline information has been assessed, an Adoption Account Plan will be prepared to identify and address key areas to help organisations better utilise the software. *Proactive Support – Using dashboards to monitor performance, engagement and the level of adoption, the Customer Success Analyst in collaboration with Customer Support, will be able to alert concerns proactively or provide assistance where a situation could be improved.
- Support available to third parties
- No
Onboarding and offboarding
- Getting started
-
The RLDatix suite of projects delivers benefits rather than a software-driven programme for the organisation. Central to this is the EQUIP Business Transformation model, a structured framework enabling sustainable change and measurable outcomes. EQUIP engagements include:
• A clear case for change and agreed scope (Evaluate)
• Quantified benefits statements (Quantify)
• A structured implementation plan with governance checkpoints (Understand & Implement)
• A continuous improvement framework underpinned by reporting and data (Protect & Sustain)
Together, RLDatix training and EQUIP transformation ensure meaningful, measurable, and sustained improvements. RLDatix provides an implementation service which includes consultancy for system customisation in line with customers unique requirements; super user training for system modules, searching and reporting and administration training for post go live systems. All training is carried out with the use of coursework books. Online and offline user help files are available within the software itself. Our implementation team supports a period of user acceptance testing at implementation and handholds the customer for a 3 month period after 'go-live' before RLDatix support desk and Customer Success take over Business as Usual. - Service documentation
- Yes
- Documentation formats
-
- HTML
- Other
- Other documentation formats
- PowerPoint
- End-of-contract data extraction
- There are two primary and secure methods for data extraction at contract end. The user can perform a data extract using the included reporting engine. The reports engine allows for data to be extracted using numerous formats including CSV, Excel and Flat-File. The secondary method is for our Service Desk to perform the data extraction and use a secure courier service to deliver the data.
- End-of-contract process
- The system is a stand-alone, online solution. At the end of the contract the user has no obligation to continue with the service and there are no 'hooks' within the solution that would require use beyond the desired timeframe. Data is easily extracted by the user and if performed by the user, is at no cost.
- Documentation accessibility standard
- WCAG 2.2 AA
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Application to install
- No
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
-
The mobile version of Expenses is a dedicated app that is native to Android and iOS. This is a real app and not a HTML browser service.
The app includes GPS tracking, full submission and approval, Driver & Vehicle Duty of Care checks, credit card reconciliation and the ability to snap receipts with OCR data capture.
Some administration functions and reporting services are only available through the browser version. - Service interface
- No
- User support accessibility
- None or don’t know
- API
- Yes
- What users can and can't do using the API
-
The system is role based and an "API" role must be enabled for any user wishing to use it. It is a RESTful API so start commands such as PUT are executed against endpoints to perform the necessary actions.
API endpoints cover the entirety of the Assure Expenses system allowing the API user to GET, POST, PUT, and DELETE records, subject to normal system constraints relating to the record and the API user's permissions to access the records concerned.
Connect Expenses to your HR/Payroll system to seamlessly provide employee information in to Expenses and receive employee/expense information back in to your HR/Payroll system. - API documentation
- Yes
- API documentation formats
- HTML
- API sandbox or test environment
- Yes
- Customisation available
- Yes
- Description of customisation
- Any authorised user with the necessary role can customise the service. This extends to all areas of the system but not the layout. The functionality of the service is extremely customisable, including the ability to customise expense item types and categories, data that is captured for each type of expense, what is mandatory or not, some field labels, flag rules and limits for claim compliance, calculations(including business mileage, relocation mileage, home to base deduction calculation), reportable information, scheduling of reports, and more.
Scaling
- Independence of resources
- Assure Expenses is a cloud-based solution which enjoys the benefits of being able to automatically scale up or scale down to service demand as required. Over 21 years of processing expenses online has allowed us a unique insight into traffic patterns that means we can scale in advance based on user demand, time of day, year, month or even one-off events. Our Service Desk uses sophisticated monitor systems to watch for unusual usage patterns which can then also trigger a scale-up in the service.
Analytics
- Service usage metrics
- Yes
- Metrics types
- Transactions and usage reports built in product.
- Reporting types
- Reports on request
- Resource tagging
- Yes
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Other security clearance
- Government security clearance
- Security Clearance (SC)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- United Kingdom
- User control over data storage and processing locations
- No
- Datacentre security standards
- Managed by a third party
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- ‘IT Health Check’ performed by a CREST-approved service provider
- Protecting data at rest
- Physical access control, complying with CSA CCM v4.0
- Data sanitisation process
- Yes
- Equipment disposal approach
- Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
- Data sanitisation type
- Data Erasure
Data importing and exporting
- Data export approach
- There is an extensive data reporting service included within Assure Expenses. Data can be exported directly in CSV, Excel and Flat-File formats. Exports can also be scheduled to run at predetermined times. The reporting service includes graphing and charting tools.
- Data export formats
-
- CSV
- Other
- Other data export formats
-
- Microsoft Excel
- Flat File
- Data import formats
-
- CSV
- Other
- Other data import formats
- Microsoft Excel
Data-in-transit protection
- Data protection between buyer and supplier networks
- TLS (version 1.2 or above)
- Data protection within supplier network
- TLS (version 1.2 or above)
Availability and resilience
- Guaranteed availability
-
RLDatix guarantees a minimum of 99.8% availability.
Actual Service Availability is calculated as follows:
• Service Availability = Operational Time – Service Downtime x 100 % / Operational Time
Please refer to the terms and conditions provided for further detail. - Approach to resilience
-
Available on request.
Industry standard best practices are followed. - Outage reporting
- For any outages or system performance issues, email alerts are sent to our users administration teams. In addition there is a message notification on the logon page to alert end-users. Planned maintenance is also communicated through these channels as well as through the customer portal, our online user forum. We offer a status page showing real time and historical statistics on the uptime of our products.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Username or password
- Other
- Other user authentication
-
Single Sign-on with Multi-Factor Authentication (MFA) (Auth0) with existing identity provider.
Or
Single Sign-on (SAML 2.0) public key authentication (including by TLS client certificate)
Or
Username and password
IP address filtering for whitelisting.
On the mobile app we can authenticate with biometric authentication and/or pin authentication. - Access restrictions in management interfaces and support channels
-
The system is role based with view, add, edit and delete access roles for each element in the system. A user is assigned a role(s) with a list of elements and the permissions allowed.
Support channels are accessible through our customer portal, requiring a username and password or through the products. - Access restriction testing frequency
- At least every 6 months
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Username or password
- Other
- Description of management access authentication
-
Company ID, Username and Password and/or Single Sign On (Auth0). IP address filtering for whitelisting. On the mobile app we can authenticate with biometric authentication and/or pin authentication.
For further information on our application management access, information can be supplied upon request.
Audit information for users
- Access to user activity audit information
- Users have access to real-time audit information
- How long user audit data is stored for
- At least 12 months
- Access to supplier activity audit information
- You control when users can access audit information
- How long supplier audit data is stored for
- At least 12 months
- How long system logs are stored for
- At least 12 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
-
- CSA CSM version 4.0
- ISO/IEC 27001
- Other
- Other security governance standards
-
In addition to ISO/IEC 27001, our governance/control standards are mapped/aligned to the following other frameworks and requirements:
• ISO 9001
• ISO/IEC 27018
• NIST SP 800-53
• NCSC CAF
• Cyber Essentials Plus
• Essential Eight (ACSC Essential 8)
• NIS2
• GDPR
• HIPAA
• NCQA - Information security policies and processes
-
• Risk assessment and ongoing risk review (frequency depends on risk score).
• Define/maintain information security policies & procedures based on risk assessment and best practice.
• Implement technical and procedural controls (e.g., firewalls/encryption/access controls plus password policies and training).
• Internal and external audits to validate adherence to policies/procedures.
• Certification maintenance (e.g., ISO 27001 and Cyber Essentials Plus) as part of continuous improvement.
• Security awareness & GDPR training annually for all employees (tracked as a metric). - Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Configuration and change management approach
-
Service components are tracked through their lifecycle using an ITIL-aligned configuration management process. We maintain records of the status, location and configuration of hardware and software and keep those records current through controlled updates via standard change and request management (including reconciliation/validation activities).
Changes are raised and tracked in ServiceNow, where the workflow requires justification, risk/impact assessment, testing and backout plans, scheduling, and closure notes.
Each change is assessed for potential security impact; higher-risk changes require formal authorization/CAB review before implementation. - Vulnerability management type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Vulnerability management approach
- Our vulnerability management process includes regular automated scans, impact assessment, and remediation tracking. We prioritise using CVSS (NIST-aligned), mapping patches to NVD and Microsoft Security Bulletin ratings. Patches are deployed by severity: Critical within 14 days, Important within 30 days, Others within 90 days. For Critical issues (CVSS 9–10), corrective action plans are made within 2 weeks and resolved in 1 month; High issues (CVSS 7–8.9) are planned in 1 month and resolved in 3 months. Verification scans and independent penetration tests ensure remediation, vulnerability-mitigation, and ongoing security, with quarterly service/infrastructure testing.
- Protective monitoring type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Protective monitoring approach
- Operationally, this sits within a continuous control framework that is externally accredited/certificated by ISO27001 and ISO9001, with continual internal monitoring and external auditing.
- Incident management type
- Complies with a recognised standard, for example, CSA CCM v4.0 or ISO/IEC 27035:2011 or SSAE-18 / ISAE 3402
- Incident management approach
- Our incident-management process, guided by our Global-Incident-Management-Policy, includes: identifying and reporting incidents (security, privacy, health/safety), responding with defined roles and escalation steps, immediate reporting of ransomware to the MIRT Team Leader, and clear communication plans for internal/external stakeholders. Where notification is required by law/regulation, we prepare notifications with a dedicated contact, breach description, investigation/remediation steps, data types involved, and notification steps to individuals/authorities/law-enforcement as applicable. Evidence is documented in RLDatix, with technical resolution and risk assessment tracked. Post-incident, we conduct root cause analysis and after-action reviews to drive continuous improvement, submitting reports to the enterprise risk/compliance committee as required.
- Post-quantum cryptography secure
- Yes
Secure development
- Approach to secure software development best practice
- Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)
Public sector networks
- Connection to public sector networks
- Yes
- Connected networks
-
- Health and Social Care Network (HSCN)
- Other
- Other public sector networks
- NHS Network (N3)
Pricing
- Discount for educational organisations
- No
- Free trial available
- No
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 0%
- Between £500,001 and £1,000,000
- 0%
- Between £1,000,001 and £2,500,000
- 0%
- Between £2,500,001 and £5,000,000
- 0%
- Over £5,000,001
- 0%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- Yes
- Who accredited the ISO/IEC 27001
- DNV - Business Assurance
- ISO/IEC 27001 accreditation date
- Monday 14 October 2013
- What the ISO/IEC 27001 doesn’t cover
-
The certificate is valid for the following scope:
Design, development, management, support, delivery and availability of the RLDatix software platforms for resource planning and modelling, patient safety and risk management and transport management, transport procurement and specialist call handling solutions. All in accordance with the Statement of Applicability version 2. - ISO 28000:2022 certification
- No
- ISO 9001 certification
- Yes
- Who accredited the ISO 9001 certification
- DNV - Business Assurance
- ISO 9001 accreditation date
- Tuesday 3 October 1995
- What the ISO 9001 doesn’t cover
-
The certificate is valid for the following scope:
Design, development, implementation and support of application software and provision of associated consultancy and user training for resource planning and modelling, patient safety and risk management and transport management, transport procurement and specialist call handling solutions. - Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- 204b74d2-630c-47ae-965b-8abef4ea8e7b
- Cyber essentials plus
- Yes
- Please provide your Cyber Essentials Plus Certificate Number
- 34d8f76f-14bb-49eb-bf76-de63292b660c
- Other security certifications
- No
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- New or retained jobs on the contract workforce in the relevant area that meet the criteria set out in MAC 1b, 1c and 1d
- Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
- Plans to engage the contract workforce in deciding the most important workplace issues to address
- Monitoring of employee engagement rates (by protected characteristic) and, where necessary, the development of actions to ensure all voices are heard across the diversity of the workforce
- Employment contracts that reflect actual hours worked; steps taken to ensure employees understand their contracts and have the ability to review and adjust them if actual hours regularly exceed contracted hours
- Activities that support an environment where staff are educated about, and feel empowered to, address their physical wellbeing
- Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
- Entitlement to sick pay for the contract workforce, with provision in place for any staff who do not meet the earnings threshold for statutory sick pay, payment of sick pay from day one of absence and payment of staff on the contract workforce who are off sick a replacement income of 100% of their usual earnings for as long as possible
- Measures to support in-work progression to help people in the contract workforce, to move into higher paid work by developing new skills relevant to the contract
- Understanding of the modern slavery risks and issues affecting the market, industry, sector or country (of origin or of source) relevant to the contract, and the workforce in the supplier’s own organisation and those of its key subcontractors
- Means of influencing staff, suppliers, customers, communities and/or any other appropriate stakeholders with respect to modern slavery risks relating to the contract
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.
- Understanding of employment and relevant skills issues, and of the education and training issues relating to the contract. Illustrative examples: demographics, skills shortages, new opportunities in high growth sectors, geographic/local community and skills/employment challenges
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 3: Resilient, innovative and flexible supply chains: Support economic growth through enabling resilient businesses, opportunities for small businesses and voluntary, community and social enterprises
- Understanding of the types of businesses in the market and the level of participation by new businesses, entrepreneurs, start-ups, SMEs, VCSEs and mutuals
- Understanding of local demographics, needs and opportunities for the co-design of the goods, services and works to be delivered under the contract
-
Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero
Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.
- Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
- Collaborative ways of working with the supply chain to deliver additional environmental benefits in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
- Delivery of additional environmental benefits through the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
- Understanding of how to influence staff, suppliers, customers, communities and/or any other appropriate stakeholders through the delivery of the contract to support climate and nature protection and improvement
-
Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain
Policy Outcome 7: Creating a pipeline of opportunities: For the contract workforce, reducing barriers to entry for under-represented groups.
- Understanding of the underlying factors affecting improvements to reduce barriers to entry and training schemes for the target cohort(s) related to the contract workforce
- Understanding of issues relating to entering the contract workforce
-
Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.
Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.
- Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce
- Understanding barriers to access to health and social care services or employment opportunities e.g. digital inclusion
-