Skip to main content

Help us improve the Digital Marketplace - send your feedback

DICTATE IT LIMITED

Digital Dictation, Speech Recognition, Outsourced Transcription, and AI solutions

We are a UK based provider of digital dictation, outsourced transcription, speech recognition and AI solutions, supplying NHS customers since 2003. Our solutions are applicable to all healthcare settings including GP practices, pharmacies, acute hospitals, mental health trusts and many more.

Features

  • 99% accurate speech recognition
  • Fully cloud based
  • Solutions exceed standard NHS security requirements
  • Integrates with existing equipment
  • Real-time dictation and summarisation
  • Retain existing individual workflow

Benefits

  • Reduced admin burden
  • Dictate anywhere
  • Speeds up clinical and secretarial day-to-day tasks
  • Enhanced document quality
  • Frees up time for patients
  • Improves Letter Turnaround Times

Pricing

  • Free trial available

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at Tenders@dictate.it. Tell them what format you need. It will help if you say what assistive technology you use.

Framework

G-Cloud 15

Service ID

8 8 2 2 8 5 7 2 7 3 3 1 1 6 0

Contact

DICTATE IT LIMITED Tenders@dictate.it
Telephone: 0203 307 1500
Email: Tenders@dictate.it

About your service

Service categories

Application Development and Deployment

AI platforms

AI software services

  • Conversational AI Software Services
  • Generative AI Software Services
  • Document AI Software Services
Multi cloud support
Yes

Service scope

Software add-on or extension
No
Cloud deployment model
Private cloud
Service constraints
None
System requirements
  • Web based application runs on modern browsers
  • Optional Windows desktop component

User support

Email or online ticketing support
Yes
Support response times
Within 24 hours
User can manage status and priority of support tickets
Yes
Online ticketing support accessibility
WCAG 2.2 AA
Phone support
Yes
Phone support availability
9 to 5 (UK time), Monday to Friday
Web chat support
Yes
Web chat support availability
9 to 5 (UK time), Monday to Friday
Web chat support accessibility standard
None or don’t know
How the web chat support is accessible
Chat bot available online from website. Direct connection to a human within the support department. Users can discuss technical issues, functionality questions, training and updates on currently open support cases.
Web chat accessibility testing
Testing with limit customers that require AT. Speech recognition is supported within the chat application, for example.
Onsite support
No
Support levels
Support costs are built into the customer contract and SLA is bespoke to each customer's requirements.

Support is available for unlimited (non P1) third-line support queries such as network functioning problems, system problem and system modifications from 08:00 – 17:30, weekdays, including bank holidays. Support cases raised outside these hours will be automatically logged ready for action the following day. The helpdesk work to KPIs that include resolving 80% of in-scope cases in 24-hours and 100% of in-scope cases in 72-hours of receipt. This is measurable and reportable.

Support agents are all ITIL certified and experienced in all aspects of the system. Each customer is allocated an account manager and has access to the customer support manager for escalations.

Dictate IT categorise each support case by Priority levels, based on severity (1-5). P1/P2 are classed as HIGH with response time within 1hr and resolution within 4 hours, as an example.

Dictate IT’s monitoring software will automatically alert the production support team if it detects any critical incidents affecting the availability of the platform. Out of hours, the receiver of the alert will validate whether the alert is a P1 critical issue and will then invoke the critical incident process.
Support available to third parties
Yes
AI chatbot
No

Onboarding and offboarding

Getting started
We offer onsite training, online training. Also customised User Guides and a e-learning platform which includes videos and feature cards.
Service documentation
Yes
Documentation formats
  • HTML
  • PDF
  • Other
Other documentation formats
  • Word
  • Powerpoint
End-of-contract data extraction
Request is put to our IT team as the contract is ending, which is then discussed in terms of method of extraction, where it needs to be sent to etc.
End-of-contract process
Archive data is still available via the platform and will deleted when the contract has ended. Dictate.IT will provide a copy of the data, if requested, prior to deletion.
Documentation accessibility standard
None or don’t know
How the documentation is accessible
Users can access the e-learning platform within the product itself or via a separate URL

Using the service

Web browser interface
Yes
Supported browsers
  • Microsoft Edge
  • Firefox
  • Chrome
  • Safari
Application to install
Yes
Compatible operating systems
  • Android
  • IOS
  • Windows
Designed for use on mobile devices
Yes
Differences between the mobile and desktop service
All core functionality is available by the mobile application.
Service interface
Yes
User support accessibility
None or don’t know
Description of service interface
The service interface is used by end user and administrative users use and manage the application. There are multiple service interfaces including web, mobile and desktop applications which the user can choose is the most suitable for them.
Accessibility standards
None or don’t know
Description of accessibility
The service is regularly tested against industry standard tools (such as Lighthouse for web applications), and these outcomes are fed into the application development process on an ongoing basis.
Accessibility testing
The application development process supports a UAT phase for each release and where our users have access to test and raise any issues found during interface testing.
API
Yes
What users can and can't do using the API
There are variety of APIs available with this service. These range from Active Directory integration to support user management, patient and demographic data feeds to support patient specific document creation and variety of APIs that support the export of data from the application to downstream systems such as EPR, EDMS, etc.

Additionally the core speech recognition and AI services are also available as APIs to facilitate integration with a customers own workflow solution.
API documentation
Yes
API documentation formats
  • Open API (also known as Swagger)
  • HTML
  • PDF
API sandbox or test environment
Yes
Customisation available
Yes
Description of customisation
There are a variety of customisations available within the application which are available via the customer administration site with many of these optionally available for individual users to customise themselves. Typical customisations include organisational structures, user management, letter templates, workflows, AI templates, UI preferences, available services, organisational/user defined canned text, keyboard shortcuts, etc.

Scaling

Independence of resources
Application usage and resource demand is monitored via a variety of tools that give real time and historical trend analysis. The application is deployed with a 50% tolerance for forecast demand and where appropriate, automated autoscaling capabilities are enabled to react to real time increases in unforecasted demand.

Analytics

Service usage metrics
Yes
Metrics types
Reporting Platform includes -
- Turnaround Times
- Admin Productivity
- Letter and Distribution Statuses
Reporting types
  • API access
  • Regular reports
  • Reports on request
Resource tagging
Yes
FOCUS resource tagging
Yes

Resellers

Supplier type
Not a reseller

Staff security

Staff security clearance
Conforms to BS7858:2019
Government security clearance
Baseline Personnel Security Standard (BPSS)

Asset protection

Knowledge of data storage and processing locations
Yes
Data storage and processing locations
United Kingdom
User control over data storage and processing locations
No
Datacentre security standards
Managed by a third party
Penetration testing frequency
At least once a year
Penetration testing approach
‘IT Health Check’ performed by a CREST-approved service provider
Protecting data at rest
  • Physical access control, complying with another standard
  • Encryption of all physical media
Data sanitisation process
Yes
Equipment disposal approach
Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
Data sanitisation type
  • Deleted data can’t be directly accessed / Cryptographic Erasure
  • Physical Destruction / Hardware containing data is completely destroyed

Data importing and exporting

Data export approach
Our approach is to remove the need for users to export their data by integrating with required 3rd party applications to automate this process to reduce administrative overhead and reduce data transfer risks. We have extensive experience in this area and have integrated with a variety of 3rd party systems to achieve this.
Data export formats
  • CSV
  • Other
Other data export formats
  • XML
  • JSON
  • PDF
  • DOCX
  • TIF
Data import formats
  • CSV
  • Other
Other data import formats
  • HL7
  • XML

Data-in-transit protection

Data protection between buyer and supplier networks
  • Private network or public sector network
  • TLS (version 1.2 or above)
  • IPsec or TLS VPN gateway
Data protection within supplier network
  • TLS (version 1.2 or above)
  • IPsec or TLS VPN gateway

Availability and resilience

Guaranteed availability
SLA guarantees system availability: Available 99.9% of time
Approach to resilience
All our services are GDPR and ISO 27001 accredited. This ensures the service resilience deals with vulnerability management and policies & procedures are in place. Our ISO management system is in place to identify, triage and mitigate any vulnerability.

Hosting services at datacentres are accounted for in our management system with protective monitoring processes being compliance with our ISO 27001 certification

Incident management policies and procedures are in place and conform to ISO 27001 requirements. These are regularly audited internally and externally.

Full policies are available on request.
Outage reporting
Outage reporting is via numerous mechanisms, including email alerts, in-product notifications, key customers phone calls, service review meetings and updates.

Planned and unplanned outages are communicated both internally and externally.

Identity and authentication

User authentication needed
Yes
User authentication
  • Multi-Factor Authentication (MFA)
  • Identity federation with existing provider (for example Google Apps)
  • Limited access network (for example PSN)
  • Dedicated link (for example VPN)
  • Username or password
Access restrictions in management interfaces and support channels
All administrative interfaces require a username and password as well as MFA in order to access. The configuration of users with access to management interfaces is managed by the customer.
Access restriction testing frequency
At least every 6 months
Management access authentication
  • Multi-Factor Authentication (MFA)
  • Username or password

Audit information for users

Access to user activity audit information
Users have access to real-time audit information
How long user audit data is stored for
At least 12 months
Access to supplier activity audit information
Users contact the support team to get audit information
How long supplier audit data is stored for
At least 12 months
How long system logs are stored for
At least 12 months

Security governance

Named board-level person responsible for service security
Yes
Security governance certified
Yes
Security governance standards
ISO/IEC 27001
Information security policies and processes
Our information security policies are all GDPR compliant and follow our ISO27001 accredited management system. All policies follow these standards and are reviewed and updated continuously. Policies are available to all staff and regular training internal staff training ensures they are understood and followed.

The information secuirty Management System is owned by senior managements who conduct regular management review meetings. This information security management team is made up of Board members, senior managers and team leads. The management team reviews and escalates any issues accordingly

The information security processes and polices are internally and externally audited through our ISO certifications.
Software Security Code of Practice
Yes

Operational security

Configuration and change management standard
Supplier-defined controls
Configuration and change management approach
For configuration management, a version-controlled repository for all code, configs, and infrastructure is maintained with environment-specific configuration files (dev, staging, production). Secrets are stored in secure vaults, never in code. All configuration parameters and dependencies are documented.

For change management, all change and release require stakeholder approval and risk assessment. All changes are documented in internal and external release notes. Deployment checklists with testing gates are used with key metrics monitored post-release.
Vulnerability management type
Supplier-defined controls
Vulnerability management approach
Threats to the service are monitored using internal vulnerability assessment tools that are executed monthly as well as annually executed independent security assessments. Critical issues identified with the service will be patched within 14 days maximum or sooner if possible. A threat intelligence report is updated weekly using internal data sources and information from external providers.
Protective monitoring type
Supplier-defined controls
Protective monitoring approach
Our internal threat intelligence reports collates threats from internal and external provider sources. Any findings are logged in our internal information governance portal where they are assigned to the relevant team to action. All critical issues will be addressed as soon as possible but as a minimum within 14 days.
Incident management type
Supplier-defined controls
Incident management approach
Our incident management processes are document as part of our ISO27001 processes. Internal users report incidents to the DPO and external users reports incidents through the customer helpdesk. All incidents will be reviewed by the Information Governance Steering Group and a root cause analysis provided which is available to customers.
Post-quantum cryptography secure
Yes

Secure development

Approach to secure software development best practice
Conforms to a recognised standard, but self-assessed

Public sector networks

Connection to public sector networks
Yes
Connected networks
Health and Social Care Network (HSCN)

Pricing

Discount for educational organisations
No
Free trial available
Yes
Description of free trial
Free Trial varies by Customer Type, Size, Product etc.

Discount percentage by annual call-off contract value (excluding VAT)

Less than £250,000
5%
Between £250,000 and £500,000
5.5%
Between £500,001 and £1,000,000
6%
Between £1,000,001 and £2,500,000
7%
Between £2,500,001 and £5,000,000
8%
Over £5,000,001
10%

Non-mandatory Standards and certifications

ISO/IEC 27001 certification
Yes
Who accredited the ISO/IEC 27001
Amtivo Group Limited T/A British Assessment Bureau Ltd
ISO/IEC 27001 accreditation date
Thursday 17 April 2025
What the ISO/IEC 27001 doesn’t cover
All was in Scope
ISO 28000:2022 certification
No
ISO 9001 certification
Yes
Who accredited the ISO 9001 certification
Amtivo Group Limited T/A British Assessment Bureau Ltd
ISO 9001 accreditation date
Thursday 17 April 2025
What the ISO 9001 doesn’t cover
All was in Scope
Quality management systems (QMS)
Yes
CSA STAR certification
No
PCI certification
No
Cyber essentials
Yes
Please provide your Cyber Essentials Certificate Number
A49adfd3-ca01-41fe-85d9-9400fd86c8a2
Cyber essentials plus
Yes
Please provide your Cyber Essentials Plus Certificate Number
778233b7-8471-4576-a4ef-0412446d7714
Other security certifications
Yes
Any other security certifications
  • DSP Toolkit
  • DTAC
  • DCB0129
  • DCB0160

Social value

Section B - Commitment for Future: Delivery
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority

    • Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at Tenders@dictate.it. Tell them what format you need. It will help if you say what assistive technology you use.