EmploymentCheck E-Bulk Online Disclosure and Barring Service (DBS) E-Broker Platform
The EmploymentCheck solution provides an accredited cloud-based e-Bulk and E-broker platform for all levels of DBS checks. Our E-Broker status allows registered organisations to utilise a compliant e-bulk platform through their own registration. Checks can be fully managed via the online portal, with real time updates and extensive functionality.
Features
- DBS approved E-Bulk system via an accredited E-Broker.
- Online application, ID verification, and submission process.
- Integrated Update Service Module for ongoing check management.
- Integrated postcode lookup tool for accurate address entry.
- Fully hosted, maintained and DBS compliant system.
- Comprehensive reporting suite with dashboards and analytics.
- Integrated online verification module (Digital ID for DBS).
- Intelligent auto-validation ensures accurate data submissions.
- Flexible email suite with reminders and notifications.
- Supports full range of DBS checks seamlessly.
Benefits
- Error-free applications through smart validation technology.
- Reduced abandonment with automated applicant email reminders.
- Expert support offered by dedicated internal team members.
- Fast results via an efficient online platform.
- Real-time application management through dashboards and reporting.
- Smartphone and tablet accessible for mobile convenience.
- Unlimited online DBS checks without restrictions.
- Continuous improvements from internal development teams.
- Simple transactional billing with transparent pricing.
- No downloads required, instant cloud-based access.
Pricing
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
8 6 9 3 0 7 8 2 2 1 8 5 2 6 0
Contact
Employment Check
G-Cloud Enquiries
Telephone: 03301249996
Email: csgprocurement@csltd.org.uk
About your service
- Service categories
-
Applications
Enterprise resource management
Human capital management
- Core Human Resources Applications
- Multi cloud support
- No
Service scope
- Software add-on or extension
- No
- Cloud deployment model
- Hybrid cloud
- Service constraints
- To utilise the E-Broker service, organisations must meet minimum annual check volumes stipulated by the DBS and be accredited as a Registered Body (RBs) or Responsible Organisation (ROs). Our internal team of experts can assist with the DBS registration during our comprehensive onboarding process. For organisations processing under the thresholds, an Umbrella body service is available through a quick and easy setup process.
- System requirements
-
- Internet connection
- Use of a modern web browser/mobile device
User support
- Email or online ticketing support
- Yes
- Support response times
-
Self service support requests can be logged through our CRM system. Customers have access to raise both service incidents and service requests via the portal. Our response targets are categorised by severity as below
P1 - response time 2 working hours - full service unavailability
P2 - response time 5 working hours - major functionality unavailability
P3 - response time 10 working hours - minor functionality unavailability
P4 - response time 10 working hours - service requests
Support requests trigger notifications to dedicated support teams. Support offered Monday to Friday across a 9-5 schedule. - User can manage status and priority of support tickets
- Yes
- Online ticketing support accessibility
- None or don’t know
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- No
- Onsite support
- Yes, at extra cost
- Support levels
-
For all customers, ongoing user support is provided as standard as part of the service provision for no additional cost. Additionally, during the onboarding process, we provide extensive webinar training for customers which is delivered by a team of DBS experts, this covers system functionality and best practice guidance. As part of this training, comprehensive user guides and operational videos are shared to accompany the system training.
As part of our BAU support lifecycle, customers have access to both operational and technical experts, covering all aspects of service provision.
In addition to operational contacts, customers are introduced to a dedicated account manager who oversees contractual matters and engages regularly to strengthen relationships, ensure service excellence, and provide a clear channel for raising queries. Our skilled account management team collaborates closely with operational and technical experts, aligning strategy with delivery to guarantee customers achieve maximum value and seamless platform utilisation.
For users engaging with the platform, integrated assistance is provided through intuitive tooltips, validation prompts, and informative popups displayed on screen. The system is carefully designed with usability as a core principle, ensuring simplicity, clarity, and effortless user experience. - Support available to third parties
- No
Onboarding and offboarding
- Getting started
-
E-Bulk customers are allocated a dedicated onboarding lead to guide them through the registration/re-registration process with the DBS. Regular catch up calls are arranged to offer ongoing assistance throughout this process, offering a means of raising queries and providing clear guidance on actions and next steps. We provide a webinar training session for all new customers and comprehensive user guides. BAU support includes training videos, user guides and access to raise calls to our teams of DBS operational and technical experts.
New users are guided through simple and easy to follow workflows, minimising support requests logged to internal team. Intelligent validation, tooltips and information popups are embedded into efficient workflows to guide users through the application journey. - Service documentation
- Yes
- Documentation formats
-
- HTML
- Other
- Other documentation formats
- Word
- End-of-contract data extraction
- Upon notification of contact end, a clearly defined exit plan will be produced to outline key dates and events. In coordination with the customer, copies of data can be provided upon request upon contract end. The extracted data for the client can be provided as a SQL Schema, this will contain all the required data in plain English using the ASCII codeset. Alternative data extracts can be provided in a custom format, requirements for which can be defined by the customer and implemented by technical support teams. Data extracts can be securely shared with customers offboarding from the service, ensuring personal data exported from the system remains protected in transit between the parties.
- End-of-contract process
-
The end of contract process is included as part of the standard service provision at no additional cost. A clearly defined off boarding plan will be agreed between the customer and the EmploymentCheck support team. The plan will cover revocation of system access at an agreed date, including the option for limited view only access which can be granted to a select group of users to allow for the management of applications processed prior to the end of contract to continue for a limited period.
Copies of the data stored within the system can also be provided to the customer in an agreed format. All data will be destroyed in line with contractual agreements at contract end after the minimum retention period. - Documentation accessibility standard
- None or don’t know
- How the documentation is accessible
-
System documentation is produced with accessibility in mind, with the aim to ensure all users can access relevant documentation in a suitable format. Documentation is made available in a variety of easily accessible formats such as html, word and pdf. Plain language is used throughout such documentation and the format follows a clear and organised structure, providing a logical flow and table of contents.
Descriptive wording used for links and text displayed is a clear format, standard fonts, and generic text colours to ensure that documents are legible.
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Opera
- Application to install
- No
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
- All features are available through mobile or the desktop implementations. The interface is optimised for smaller screens which accessed through mobile devices. Mouse and keyboard actions can be completed via touch-based navigation through mobile devices.
- Service interface
- Yes
- User support accessibility
- None or don’t know
- Description of service interface
-
The EmploymentCheck platform is designed with security and usability at its core. Users access clear workflows and intuitive dashboards through a modern, browser-based interface on any internet-enabled device.
Real-time updates are captured in audit logs and reflected across responsive dashboards, supported by flexible, customisable features. Role-based permissions safeguard sensitive information, while built-in notifications, tooltips, search functionality, and intelligent validation enhance productivity.
The interface combines powerful functionality with an accessible design, ensuring maximum efficiency and ease of use. - Accessibility standards
- None or don’t know
- Description of accessibility
-
EmploymentCheck is committed to continually improving accessibility across our platform. We aim to develop functionality with accessibility in mind, with the goal that all content is designed to be easy to use, read, and understand .
Our accessibility statement outlines our current position, including areas where ongoing development is required. We recognise there are aspects we can improve, and we are actively implementing major system upgrades to enhance accessibility across all areas of the platform. Ensuring we offer an accessible platform is an ongoing commitment which is a key component of our software development lifecycle. - Accessibility testing
-
To assess and improve the accessibility of the EmploymentCheck web application interface on an ongoing bases, a combination of automated tools, manual checks, and user testing has been, and continues to be, undertaken against the standards outlined under Web Content Accessibility Guidelines (WCAG).
To complement these methods, structured interface testing has been conducted with users of assistive technologies, including screen readers, voice recognition software, and alternative input devices. This process focused on validating that navigation, form completion, and dashboard interactions are perceivable, operable, and understandable across different user needs.
Testing also included scenarios with high‑contrast modes, keyboard‑only navigation, and magnification tools to ensure compatibility and responsiveness. - API
- No
- Customisation available
- Yes
- Description of customisation
-
Customers can opt for a bespoke customisation that allows them to select colours, images and content of their instance to reflect their organisation branding. Brand identity can be retained and extensive customisation options are provided as part of the standard service provision. During the onboarding stage of the contract provision, implementation contacts will work with customers to ensure the build of the platform meets customer requirements and maintains a familiar look and feel.
Customers can also specify sub-domain preference for their unique instance of the platform, to accompany the colours, images and homepage content made visible to front end users.
Customers are also provided with the ability to customise the set up of their system including user account privileges, system settings and reporting functionality. Aspects of functionality can be customised on a customer by customer basis, tailoring the system to suit the needs of individual business units. The majority of this functionality can be managed on a self-service basis by customers.
Post go live, further updates to the instance can be made to branding which can be raised as support request and actioned by internal support teams.
Scaling
- Independence of resources
-
EmploymentCheck uses a multi-tenanted approach for its platform and each customer has its own separate database to ensure segregation and security both from other clients and third parties. Load balanced application servers are used to manage traffic and dynamically distribute load at busy periods.
The platform is built on eCloud Virtual Private Cloud (VPC) infrastructure. The infrastructure is provisioned and supported by ANS Group Ltd, a market leading infrastructure partner. The solution is designed with high availability and resilience as a key objective and operates cross isolated subnets, Internal IP ranges control access in line with firewall rules.
Analytics
- Service usage metrics
- Yes
- Metrics types
- Customers are able to run service usage reports directly from the system as standard - these management information reports are included as part of the standard report suite offered to all customers.. A monthly KPI pack containing benchmarked MI against the system totals/averages is provided to all customers to help refine processes and best practice.
- Reporting types
-
- Real-time dashboards
- Regular reports
- Reports on request
- Resource tagging
- No
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Other security clearance
- Government security clearance
- Baseline Personnel Security Standard (BPSS)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- United Kingdom
- User control over data storage and processing locations
- No
- Datacentre security standards
- Managed by a third party
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- ‘IT Health Check’ performed by a CREST-approved service provider
- Protecting data at rest
-
- Physical access control, complying with another standard
- Scale, obfuscating techniques, or data storage sharding
- Data sanitisation process
- Yes
- Equipment disposal approach
- A third-party destruction service
- Data sanitisation type
-
- Deleted data can’t be directly accessed / Cryptographic Erasure
- Data Erasure
- Explicit overwriting of storage before reallocation / Secure Erase
- Physical Destruction / Hardware containing data is completely destroyed
Data importing and exporting
- Data export approach
- Data can be exported from the system in CSV or PDF format. Use of the system includes access to a bespoke report builder and a set of standard reports which cover key metrics, the data output can be saved locally in a CSV of PDF format. Four bulk upload functions exist on the system, each requires the completion of a template CSV file which allows for applications, users and Business Units to be uploaded in bulk to the system. Automated SFTP processes can also be established for the secure transfer of data between the EmploymentCheck platform and external applications.
- Data export formats
-
- CSV
- Other
- Other data export formats
- Data import formats
- CSV
Data-in-transit protection
- Data protection between buyer and supplier networks
- TLS (version 1.2 or above)
- Data protection within supplier network
- TLS (version 1.2 or above)
Availability and resilience
- Guaranteed availability
- We commit to minimum service availability of at least 99.9% over a 24/7 365 schedule. All planned maintenance is conducted outside of core business ours (9-5 across a Mon-Fri schedule). All planned maintenance which requires system downtime is communicated at least working 20 days in advance of the planned implementation date. Service credits for unavailability are not included as standard.
- Approach to resilience
- The EmploymentCheck solution is architecturally designed with resilience and high availability in mind, enterprise grade infrastructure and load-balanced, multi-tenanted solutions are deployed to provide effective resilience to minimise service disruption wherever possible. Additional information is available on request in relation to our approach to resilience. A market leading infrastructure provider offer robust and reliable infrastructure, ensuring critical data and applications are always available and secure. The ISO-certified data centres operate with redundant power; every site has uninterruptible power supply systems and standby diesel generators to keep the site functioning in case of mains supply failure. N+1 redundancy giving 100% uptime SLA on power, cooling and fire suppression systems.
- Outage reporting
-
Unplanned service disruptions are handled as part of a clearly defined business continuity and disaster recovery plan. Should the plan be invoked, email alerts are issued to all key customer contacts, advising customers of the identified issue and planned resolution, additional updates are provided throughout the incident as part of a robust incident management process conducted in line with ISO 27001.
Planned maintenance for system changes which will impact system access are conducted outside of core business hours (9-5 across a Mon-Fri schedule) are communicated at least 20 days in advance of the planned change. All key customer contacts are notified via email of the planned outage, reason for outage and any additional information which needs to be shared. In such instances, a visible notification banner is also placed across the system in advance of the implementation date to provide notice to end users.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Identity federation with existing provider (for example Google Apps)
- Username or password
- Access restrictions in management interfaces and support channels
-
Full role based access controls are implemented across the platform, this offers a clear and robust structure for protecting sensitive data from unauthorised access. Management interfaces are restricted to named individuals, with access controls in place to prevent external access. Technical security measures such as MFA, IP address whitelisting as well as organisation policies are adopted to protect access to management interfaces.
Support channel credentials are only provided to named customer contacts and account restrictions ensure that access to these support channels is managed and contained. - Access restriction testing frequency
- At least every 6 months
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Username or password
- Other
- Description of management access authentication
- IP Address whitelisting
Audit information for users
- Access to user activity audit information
- Users have access to real-time audit information
- How long user audit data is stored for
- At least 12 months
- Access to supplier activity audit information
- Users have access to real-time audit information
- How long supplier audit data is stored for
- At least 12 months
- How long system logs are stored for
- At least 12 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- No
- Security governance approach
- All aspects of service delivery are conducted in line with ISO 27001 requirements via accredited partners. Governance is structured around risk-based decision making, ensuring that security controls are proportionate to identified threats and vulnerabilities. Security policies are documented, approved by senior management, and communicated across the organisation. Procedures cover areas such as access control, encryption, incident response, and supplier management, ensuring consistent application of security practices. Policies are reviewed annually or following significant changes in the threat landscape.
- Information security policies and processes
-
The EmploymentCheck solution is maintained by an ISO 27001 accredited provider, by ITIL certified support staff. All aspects of service delivery are conducted in line with obligatory requirements as part of ISO 27001 which covers the security processes followed by all members of staff. All staff are fully aware of their own information security requirements; these include but are not limited to the following:
• Ongoing E-learning Training - all employees are required to undertaken regular E-learning courses covering a range of topics including GDPR, Information Governance and Information Security.
• Policies and procedures –staff have access to a range of procedure documents relating to their own specific roles and responsibilities, these are reviewed on an ongoing basis to ensure they are up to date.
• Locked devices – Part of our information security policy stipulates that all devices are locked when an employee leaves their desk for any reason, this remains true when working remotely to avoid sharing of confidential information. - Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
-
EmploymentCheck operates a ‘process-based approach’ regarding Change Management. Through standard, repeatable, documented processes we will be able to improve quality of outputs (reduce errors and make processes more efficient) and deliver a consistent, positive experience to customers. This also helps us plan and understand the impact of changes.
The ISO framework underpins how we approach and manage change, for the EmploymentCheck solution, risk is carefully considered and assessed as part of any future change, full impact assessments are undertaken where required to ensure the full scale of the change is considered, particularly when changes could impact upon customer data. - Vulnerability management type
- Supplier-defined controls
- Vulnerability management approach
-
The EmploymentCheck utilise daily tenable scans to monitor the ongoing security posture of the application. This provides comprehensive visibility of the internal and external threat factors. Using these comprehensive scans, we are able to identify and remediate potential risks at an earlier stage. This enables us to act swiftly on any vulnerabilities, reducing exposure time and strengthening overall resilience against cyber threats.
EmploymentCheck commits to annual penetration testing undertaken by third parties with CREST accreditations to ensure independent verification of the software. - Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
-
The EmploymentCheck solution has active monitoring in place to detect attacks from malicious IP address ranges, IP blocklists are applied within the firewall service if required.
Each login attempt which is made is recorded in a comprehensive audit log, visible only to EmploymentCheck analysts and developers. The audit log includes both successful and unsuccessful login attempts, with a timestamp recorded for each attempt. The IP address of the user attempting to login to the system is recorded, this information is purged in line with GDPR. - Incident management type
- Supplier-defined controls
- Incident management approach
-
EmploymentCheck has a clearly defined incident management process based on the ITIL principles.
This procedure guides staff through the Major Incident (MI) process. To ensure all members of staff are familiar with all processes and procedures in relation to the management of a MI.
EmploymentCheck is responsible for ensuring the confidentiality, integrity, and availability of the data and information assets that it processes and stores in its ICT systems. - Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- No
- Free trial available
- No
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 0%
- Between £500,001 and £1,000,000
- 0%
- Between £1,000,001 and £2,500,000
- 0%
- Between £2,500,001 and £5,000,000
- 0%
- Over £5,000,001
- 0%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- No
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- Yes
- Who accredited the ISO 9001 certification
- British Assessment Bureau
- ISO 9001 accreditation date
- Wednesday 28 May 2025
- What the ISO 9001 doesn’t cover
- N/A
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- 5817108e-2d1c-4c69-992e-cd517247a40e
- Cyber essentials plus
- No
- Cyber Essentials Alternative
- None of the criteria
- Other security certifications
- No
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
- Plans to engage the contract workforce in deciding the most important workplace issues to address
- Monitoring of employee engagement rates (by protected characteristic) and, where necessary, the development of actions to ensure all voices are heard across the diversity of the workforce
- Activities that support an environment where staff are educated about, and feel empowered to, address their physical wellbeing
- Activities that support an environment where staff are educated about and feel empowered to report and address bullying and harassment
-