Zoho Desk - for Citizen, Resident and Stakeholder Service Management
Zoho Desk is a cloud-based service management platform for public sector departments, including local and central government, NHS bodies, and universities. It enables teams to manage enquiries across multiple channels, standardise case handling, automate workflows, and report on performance, helping improve response times, transparency, and service quality.
Features
- Multichannel enquiry management across email, web, phone and social channels.
- Automated ticket routing prioritisation and escalation using configurable rules engines.
- Role based access controls support ringfenced case data handling securely.
- Configurable workflows for consistent service conformity and SLA compliance tracking.
- Knowledge base and self service portals enable faster issue resolution.
- Real time dashboards and reporting for live caseload trend analysis.
- Audit logs and activity tracking reinforce compliance accountability and governance.
- Tracks citizen enquiries, status, ownership history, interactions and response timelines
- Integrates with telephony platforms email services and public sector systems.
- Data retention controls support records management mirroring information governance policies.
Benefits
- Expedited responsiveness and reputation strengthening through consistency and automated routing
- Improved casework visibility and transparency via live custom dashboard displays
- Reduced administrative effort through automation of repetitive service management tasks.
- Real-time alerts and downstream integrations prevent delays and minimise escalations
- Greater citizen self-service functionality to reduce officer input and workload.
- Improved accountability through cross channel reporting and engagement pathway analysis.
- Supports remote and hybrid working without reliance on local infrastructure.
- Centralises communications and casework across disconnected systems and siloed teams.
- Scales to meet fluctuating demand across diverse public sector services.
- Existing system integration enables golden record single source of truth.
Pricing
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
9 0 1 5 1 3 9 1 7 1 6 9 7 6 1
Contact
ZOHO CORPORATION LIMITED
Corie Robinson
Telephone: +44 2038072092
Email: zohouk-gcloud@eu.zohocorp.com
About your service
- Service categories
-
Applications
Customer relationship management
- Customer service
- Contact centre
- Multi cloud support
- No
Service scope
- Software add-on or extension
- No
- Cloud deployment model
- Public cloud
- Service constraints
- Zoho Desk is provided as a cloud-based service and does not support on-premise deployment. Access requires a stable internet connection and a supported web browser. Planned maintenance is managed by Zoho and may result in limited service availability, with advance notice provided where possible.
- System requirements
-
- Stable internet connectivity
- Chrome (v90+) Firefox (v80+), Safari (v13+), Edge (v80+), Opera (v90+)
- Mobile Apps - Android 5.0(API Level 21 & above)
- Mobile Apps IOS (14.0 & above)
User support
- Email or online ticketing support
- Yes
- Support response times
- Zoho Desk includes standard technical support during UK business hours, defined as 09:00–17:00, Monday to Friday (excluding UK public holidays). Enhanced support options are available, including extended hours and 24/7 coverage, depending on the support plan selected. Response times vary by support tier, with initial responses typically provided within one to three hours for higher-tier plans. Weekend support availability depends on the chosen support level and agreed service terms.
- User can manage status and priority of support tickets
- Yes
- Online ticketing support accessibility
- WCAG 2.2 AA
- Phone support
- Yes
- Phone support availability
- 24 hours, 7 days a week
- Web chat support
- Yes
- Web chat support availability
- 24 hours, 7 days a week
- Web chat support accessibility standard
- WCAG 2.2 AA
- Web chat accessibility testing
-
Zoho Desk web chat has been tested as part of Zoho’s broader accessibility and usability assurance activities, with consideration given to assistive technology users. Testing includes use with screen readers, keyboard-only navigation, and browser-based accessibility tools.
Testing focuses on core web chat interactions, including opening the chat widget, navigating messages, sending and receiving responses, and closing conversations without reliance on a mouse. These activities are reviewed against relevant principles of the Web Content Accessibility Guidelines (WCAG) 2.2 AA, such as perceivability, operability, and understandability.
Where accessibility issues are identified, they are recorded and addressed through Zoho’s standard product development and release processes. Accessibility improvements are delivered as part of ongoing updates rather than one-off remediation exercises.
Zoho Desk is used by a wide range of customers, including public sector departments, who access web chat using their own assistive technologies and accessibility settings. Feedback from real-world usage helps inform continued accessibility improvements across the service. - Onsite support
- Yes, at extra cost
- Support levels
-
Zoho Desk is supported through multiple support levels to meet different operational needs.
Basic support - is provided at no additional cost and is available to all users. It includes access to online documentation, knowledge bases, and standard support channels.
Classic support - is included with paid editions of Zoho Desk and provides standard technical support during business hours, including assistance with configuration and general usage queries.
Premium support - is available at an additional cost. It offers faster response times, extended support hours (up to 24/5), remote assistance, onboarding guidance, and configuration support.
Enterprise support - is also available at an additional cost and provides the highest level of support. This includes 24/7 technical support, priority response times, and access to a named technical account manager or cloud support engineer. Enterprise support is available to buyers meeting minimum licence requirements.
Support plan pricing varies depending on the level selected and the number of user licences and is provided transparently at the point of purchase. Optional on-site support services can be arranged separately where required. - Support available to third parties
- Yes
- AI chatbot
- Yes
Onboarding and offboarding
- Getting started
-
Zoho Desk is provided as a cloud-based service with standard configuration options that allow users to start using the service quickly. New users can access online documentation, help articles, and video guides that explain core functions and common setup tasks.
Support teams can assist users during onboarding through standard support channels. Online training sessions and webinars are available to help users understand service features, configuration options, and day-to-day operation.
For larger or more complex deployments, optional enhanced support plans are available. These can include structured onboarding, remote configuration assistance, and guidance tailored to the user’s service requirements. On-site training can be arranged separately where required, subject to agreement.
These onboarding options allow public sector departments to choose the level of support appropriate to their internal capability and service complexity. - Service documentation
- Yes
- Documentation formats
- HTML
- End-of-contract data extraction
-
At the end of a contract, users can extract their data directly from Zoho Desk using the service’s built-in export functionality. Administrators can export data from key modules, including tickets, contacts, accounts, and knowledge base content.
Data can be exported in commonly used, non-proprietary formats such as CSV and XLS, supporting offline storage, reporting, or migration to another system. Exports are initiated through the Zoho Desk administrative interface and can be performed while the account remains active.
Zoho Desk also supports scheduled exports, allowing administrators to automate regular data extraction prior to contract termination if required. Access to export functionality depends on the user’s role and permissions within the service.
When a paid subscription ends and is not renewed, the account may revert to a limited edition rather than being immediately deleted. Data remains accessible for a defined period, during which users are responsible for completing any required exports. If an account is later deleted in line with data retention policies, data extraction is no longer possible.
This approach allows buyers to retrieve their data in advance of service exit without reliance on proprietary tools or supplier intervention. - End-of-contract process
-
At the end of the contract, if a Zoho Desk paid subscription is not renewed, the account is downgraded to the free edition. Data is not deleted at the point of contract expiry, but access to features available only in paid editions is removed.
While the account remains active, users can continue to access their data and use available export tools, subject to the limitations of the free edition. If the account remains inactive for an extended period (currently more than 120 days), it may be scheduled for deletion in accordance with Zoho’s data retention policies. Once deleted, data cannot be recovered or exported.
The contract price includes access to the Zoho Desk service at the agreed subscription level, standard support, and ongoing updates and maintenance. Optional services, such as enhanced support plans, onboarding assistance, training, or on-site services, are available at additional cost if required.
This approach allows public sector departments to manage service exit and data extraction in line with their internal governance requirements. - Documentation accessibility standard
- WCAG 2.2 AA
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Opera
- Other
- Application to install
- No
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
- Zoho Desk is designed to work on mobile devices. The web application is responsive and accessible through supported mobile browsers. Dedicated mobile applications for iOS and Android provide an optimised experience and support core service management functions, including viewing, updating, and responding to enquiries. Mobile-specific features include push notifications and simplified dashboards for monitoring service activity. A separate Radar for Zoho Desk application provides high-level service insights and alerts for managers on mobile devices.
- Service interface
- Yes
- User support accessibility
- WCAG 2.2 AA
- Description of service interface
- Zoho Desk provides a web-based service interface designed to support efficient case handling. Users work from configurable list views showing ticket status, priority, ownership, and due dates. Tickets display relevant context, including enquiry history, timelines, related interactions, and linked knowledge base articles. Work modes allow users to focus on specific queues or priorities. The interface supports response templates, scheduled replies, and internal comments to enable collaboration and consistent handling across service teams.
- Accessibility standards
- WCAG 2.2 AA
- Accessibility testing
-
Zoho Desk interface testing includes consideration of users who rely on assistive technologies. Testing activities cover key user journeys within the service interface, such as navigating ticket lists, opening and updating records, reading content, and submitting responses using assistive tools.
Testing includes use with screen readers, keyboard-only navigation, and browser accessibility features across commonly used operating systems and supported web browsers. Accessibility checks are informed by recognised standards and guidance, including the Web Content Accessibility Guidelines (WCAG) 2.2 AA, focusing on principles such as perceivability, operability, and understandability.
Zoho also uses a combination of automated and manual testing tools, including colour contrast and structural checks, to identify potential accessibility issues. Where issues are identified, they are logged and addressed through Zoho’s standard development and release processes.
In addition, feedback from customers, including those with staff who use assistive technologies, helps inform ongoing improvements. Accessibility testing is treated as a continuous activity and forms part of regular product updates rather than a one-off exercise. - API
- Yes
- What users can and can't do using the API
-
Zoho Desk provides RESTful APIs that allow users to integrate the service with other Zoho applications and third-party systems. Through the APIs, users can programmatically access and manage data held within Zoho Desk modules, such as tickets, contacts, accounts, and related records.
Users can use the APIs to support service setup activities, including creating, retrieving, updating, and managing records, synchronising data with other systems, and automating operational processes. Configuration changes that are exposed through the API can be applied programmatically, subject to the permissions of the authenticated user.
The APIs follow standard HTTP methods and return consistent status and error codes. API usage can be monitored through an administrative dashboard, and usage limits apply to protect service availability. Notifications are provided when usage approaches defined thresholds.
Certain service configuration activities, such as user interface layout changes, advanced workflow design, and administrative security settings, must be completed through the Zoho Desk web interface and are not fully configurable via the API. - API documentation
- Yes
- API documentation formats
- HTML
- API sandbox or test environment
- Yes
- Customisation available
- Yes
- Description of customisation
-
Zoho Desk provides RESTful APIs that allow users to integrate the service with other Zoho applications and third-party systems. Through the APIs, users can programmatically access and manage data held within Zoho Desk modules, such as tickets, contacts, accounts, and related records.
Users can use the APIs to support service setup activities, including creating, retrieving, updating, and managing records, synchronising data with other systems, and automating operational processes. Configuration changes that are exposed through the API can be applied programmatically, subject to the permissions of the authenticated user.
The APIs follow standard HTTP methods and return consistent status and error codes. API usage can be monitored through an administrative dashboard, and usage limits apply to protect service availability. Notifications are provided when usage approaches defined thresholds.
Certain service configuration activities, such as user interface layout changes, advanced workflow design, and administrative security settings, must be completed through the Zoho Desk web interface and are not fully configurable via the API.
Scaling
- Independence of resources
- Zoho Desk is delivered using a multi-tenant cloud architecture designed to manage demand across users. Service capacity is managed through automated scaling and load balancing to distribute traffic evenly and maintain consistent performance. System performance is continuously monitored, including response times and error rates. Redundancy and failover mechanisms are in place to support service availability. These measures help ensure that usage by one customer does not adversely affect the performance experienced by other users.
Analytics
- Service usage metrics
- Yes
- Metrics types
-
Zoho Desk provides built-in service metrics through configurable dashboards and reports. Metrics include ticket volumes, response and resolution times, SLA compliance, backlog levels, and agent workload. Administrators can use standard dashboards or create custom reports to support operational monitoring and performance management. Audit logs provide visibility of system activity and changes.
Management dashboards provide an overview of service performance and key indicators, and alerts can be configured to highlight unusual patterns or threshold breaches. - Reporting types
-
- API access
- Real-time dashboards
- Regular reports
- Resource tagging
- Yes
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Other security clearance
- Government security clearance
- Baseline Personnel Security Standard (BPSS)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
-
- United Kingdom
- European Economic Area (EEA)
- User control over data storage and processing locations
- Yes
- Datacentre security standards
- Managed by a third party
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- In-house
- Protecting data at rest
-
- Physical access control, complying with SSAE-18 / ISAE 3402
- Physical access control, complying with another standard
- Data sanitisation process
- Yes
- Equipment disposal approach
- A third-party destruction service
- Data sanitisation type
- Deleted data can’t be directly accessed / Cryptographic Erasure
Data importing and exporting
- Data export approach
- Users can export their data using built-in export tools within Zoho Desk, subject to their role and permissions. Data can also be exported programmatically using supported APIs. Where required, users may request assistance from Zoho support. Data subject access and export requests can be submitted through the service in line with data protection requirements.
- Data export formats
- CSV
- Data import formats
- CSV
Data-in-transit protection
- Data protection between buyer and supplier networks
- TLS (version 1.2 or above)
- Data protection within supplier network
- Other
- Other protection within supplier network
- Network traffic is encrypted when transmitted over public networks and during replication to disaster recovery environments. Zoho operates and manages its data centre network stack. Firewalls and network security controls are used to restrict unauthorised access. Network segmentation is implemented to separate systems and reduce the risk of unauthorised access to sensitive data.
Availability and resilience
- Guaranteed availability
-
Zoho Desk is provided with a service availability target of 99.9% measured on a monthly basis, excluding scheduled maintenance. Service availability status is published online, allowing users to monitor current and historical performance.
Zoho operates a formal Service Level Agreement (SLA) that defines availability commitments, measurement methodology, and exclusions. Where the agreed availability levels are not met, eligible customers may request service credits in accordance with the terms set out in the SLA. Service credits are applied to future subscription charges rather than issued as cash refunds.
Details of the SLA, including uptime calculations and service credit thresholds, are documented within Zoho’s contractual terms and are available to customers. Planned maintenance activities are managed to minimise disruption, and advance notice is provided where possible.
This approach provides transparency on service performance while offering a defined remediation mechanism if availability commitments are not achieved. - Approach to resilience
-
Zoho Desk is designed with resilience as a core consideration. Application data is stored on resilient storage and replicated between geographically separate data centres. Replication between primary and secondary environments occurs on a near real-time basis to reduce the risk of data loss.
In the event of an issue affecting a primary data centre, traffic can be redirected to secondary systems to support service continuity. Data centres are supported by multiple internet service providers to reduce dependency on a single network connection.
Physical resilience measures include redundant power supplies, backup power systems, environmental controls, and fire prevention systems. These controls are intended to support continued operation during infrastructure or environmental incidents.
Zoho also maintains business continuity and disaster recovery plans covering key operational areas, including infrastructure management and customer support. These plans are reviewed and tested periodically to ensure continued effectiveness and to support the ongoing availability of the service. - Outage reporting
-
Zoho Desk reports service outages and maintenance events through multiple channels to ensure users are informed.
A public service status dashboard is available, providing real-time and historical information on service availability, planned maintenance, and unplanned incidents. This dashboard allows users to check the current health of the service at any time.
For planned maintenance, notifications are provided in advance through service notifications and email communications. Planned activities are typically scheduled outside standard business hours where possible to minimise disruption.
For unplanned outages, status updates are published on the public dashboard and communicated to users via email. Updates are provided as information becomes available, including incident status and resolution progress.
At present, outage notifications are communicated through the dashboard and email rather than via a dedicated outage reporting API. These mechanisms provide transparency and allow public sector departments to monitor service availability and respond appropriately to incidents.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Identity federation with existing provider (for example Google Apps)
- Username or password
- Access restrictions in management interfaces and support channels
- Access to Zoho Desk management interfaces and support channels is restricted using role-based access controls and the principle of least privilege. Access is granted only to authorised personnel based on job role and business need. Production environment access is centrally managed and secured using strong authentication controls, including multi-factor authentication and secure credentials. Access is provided through restricted networks with additional security controls. All access and actions are logged and subject to regular review and audit to support accountability and data protection.
- Access restriction testing frequency
- At least every 6 months
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Username or password
Audit information for users
- Access to user activity audit information
- Users have access to real-time audit information
- How long user audit data is stored for
- At least 12 months
- Access to supplier activity audit information
- No audit information available
- How long system logs are stored for
- Between 1 month and 6 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
-
- ISO/IEC 27001
- Other
- Other security governance standards
- ISO/IEC 27701, ISO/IEC 27017, ISO/IEC 27018, ISO 9001, SOC 2 Type II, WCAG 2.1 AA, HIPAA
- Information security policies and processes
-
Zoho follows a documented information security programme aligned with recognised international standards, including ISO/IEC 27001. The programme includes technical, organisational, and physical security controls designed to protect customer data against unauthorised access, disclosure, alteration, loss, or destruction.
Zoho maintains formal information security and data protection policies covering areas such as access control, incident management, risk management, asset handling, and business continuity. These policies are communicated to relevant employees and enforced through internal controls and training.
Policies and procedures are reviewed regularly and updated as required. Compliance with these controls is independently assessed through third-party audits, including ISO and SOC assessments. - Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Configuration and change management approach
- Zoho operates documented configuration and change management processes covering applications, systems, infrastructure, and supporting services. Service components are tracked throughout their lifecycle using controlled change records and audit logs. All changes are assessed for potential security and privacy impact before implementation. Where required, changes follow approval and testing procedures. Rollback and recovery procedures are defined and documented to manage unsuccessful changes or unforeseen issues. Customers are notified in advance of changes that may have a material or adverse impact on their use of the service.
- Vulnerability management type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Vulnerability management approach
-
Zoho operates a documented vulnerability management process to identify, assess, and remediate security risks.
Potential threats are identified through a combination of automated vulnerability scanning, manual testing, and review by dedicated security teams. Threat intelligence is informed by third-party security tools, vendor advisories, public vulnerability disclosures, and responsible security reports. Identified vulnerabilities are logged, risk-rated based on severity and impact, and assigned for remediation.
Patches or mitigating controls are deployed in line with severity, with higher-risk issues prioritised for rapid resolution. Remediation activities are tracked through to closure. - Protective monitoring type
- Undisclosed
- Protective monitoring approach
-
Zoho operates protective monitoring processes to identify potential security incidents. System, application, and network activity is logged and monitored to detect anomalous behaviour, such as unusual access patterns or unauthorised activity.
Logs include security, audit, administrative, and operational events and are stored securely with restricted access. When potential compromises are identified, alerts are reviewed by security teams and investigated in line with incident response procedures.
Incidents are prioritised based on severity, with higher-risk issues addressed promptly to reduce impact and restore normal service operation. - Incident management type
- Complies with a recognised standard, for example, CSA CCM v4.0 or ISO/IEC 27035:2011 or SSAE-18 / ISAE 3402
- Incident management approach
-
Zoho operates documented incident management processes, including predefined procedures for common security, privacy, and service incidents. Incidents can be reported by users through established support channels, including the Zoho support portal and designated contact methods.
Reported incidents are logged, prioritised, investigated, and tracked through to resolution with corrective actions applied where required. Users are notified of incidents that affect their service, along with any recommended actions.
Incident updates and summary reports are provided where appropriate, supported by relevant audit or application logs. Measures are implemented to reduce the likelihood of recurrence. - Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- No
- Free trial available
- Yes
- Description of free trial
- Zoho Desk offers a free edition for up to three agents with no time limit. It includes email-based ticket management, a basic help centre, web forms, macros, and a customer portal. Advanced automation, SLAs, analytics, security controls, and premium support are not included.
- Link to free trial
- https://www.zoho.com/desk/signup.html?plan=Free&source_from=zdesk_pricing
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 0%
- Between £500,001 and £1,000,000
- 0%
- Between £1,000,001 and £2,500,000
- 5%
- Between £2,500,001 and £5,000,000
- 10%
- Over £5,000,001
- 10%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- Yes
- Who accredited the ISO/IEC 27001
- BSI
- ISO/IEC 27001 accreditation date
- Wednesday 3 September 2025
- What the ISO/IEC 27001 doesn’t cover
-
ISO/IEC 27001 certifies our Information Security Management System (ISMS) and confirms that we have appropriate governance, controls, and continual improvement processes in place to manage information security risks within the defined scope of certification.
The certification does not certify individual products or specific technical features in isolation. Instead, it applies to the management framework, policies, processes, and controls that govern how information security is implemented and operated across our in-scope services.
Activities, systems, or services outside the formally defined ISMS scope are not covered by the ISO/IEC 27001 certification. This may include third-party services or infrastructure not operated or controlled by us, or internal systems not directly involved in the delivery of certified services.
ISO/IEC 27001 also does not replace or automatically include other standards (such as ISO/IEC 27017 or ISO/IEC 27018 - Which Zoho Corporation has obtained both certifications), which address cloud-specific controls and protection of personally identifiable information and are assessed separately where applicable. - ISO 28000:2022 certification
- No
- ISO 9001 certification
- Yes
- Who accredited the ISO 9001 certification
- BSI
- ISO 9001 accreditation date
- Thursday 23 March 2023
- What the ISO 9001 doesn’t cover
-
ISO 9001:2015 certifies our Quality Management System (QMS) and confirms that we have defined, implemented, and continually improved processes to ensure consistent service delivery within the certified scope.
The certification does not certify individual products, features, or technical performance in isolation. It focuses on the management framework for quality rather than guaranteeing specific service outcomes, configurations, or performance levels for individual services.
Activities, systems, or services outside the formally defined QMS scope are not covered by the ISO 9001 certification. This may include third-party services, customer-managed configurations, or internal processes not directly involved in the delivery and support of in-scope services.
ISO 9001 also does not address information security, privacy, or data protection controls, which are covered separately under standards such as ISO/IEC 27001 and related certifications. - Quality management systems (QMS)
- Yes
- CSA STAR certification
- Yes
- CSA STAR accreditation date
- Monday 4 August 2025
- CSA STAR certification level
- Level 1: CSA STAR Self-Assessment
- What the CSA STAR doesn’t cover
-
Zoho’s listing in the CSA Security, Trust & Assurance Registry (STAR) is based on a STAR Level 1 Self-Assessment, which documents how our cloud security controls align with the Cloud Security Alliance Cloud Controls Matrix (CCM).
The STAR self-assessment applies to the security control framework and governance practices for our cloud services. It does not certify individual products, specific service configurations, or customer-managed settings in isolation.
Activities or services outside the scope of the published STAR self-assessment, including customer-controlled configurations, integrations with third-party services, or infrastructure not operated or controlled by Zoho, are not covered.
CSA STAR also does not replace other standards covering information security, privacy, or quality management, which are addressed separately through certifications such as ISO/IEC 27001 and related standards.
In summary, CSA STAR provides transparency into our cloud security controls within scope, but not independent certification or coverage of out-of-scope services or configurations. - PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- Df4a2fb2-58c7-428b-b622-0d1dbd68ae22
- Cyber essentials plus
- Yes
- Please provide your Cyber Essentials Plus Certificate Number
- 061e91c4-e56a-4f0c-a09c-66fea8d9c587
- Other security certifications
- Yes
- Any other security certifications
-
- ISO/IEC 27017 (Cloud Security Controls)
- ISO/IEC 27018 (Protection of PII in public cloud)
- ISO/IEC 27701 (Privacy Information Management / PIMS)
- SOC 2 Type II
- CSA STAR (Level 1 Self-Assessment)
- Data Security and Protection Toolkit (DSPT)
- GDPR
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
- Plans to engage the contract workforce in deciding the most important workplace issues to address
- Activities that support an environment where staff are educated about, and feel empowered to, address their physical wellbeing
- Activities that support an environment where staff are educated about and feel empowered to report and address bullying and harassment
- Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
- Monitoring and reporting of gender and ethnicity pay gaps and plans to address them where necessary
- Entitlement to sick pay for the contract workforce, with provision in place for any staff who do not meet the earnings threshold for statutory sick pay, payment of sick pay from day one of absence and payment of staff on the contract workforce who are off sick a replacement income of 100% of their usual earnings for as long as possible
- Volunteering opportunities for staff
- Understanding of the modern slavery risks and issues affecting the market, industry, sector or country (of origin or of source) relevant to the contract, and the workforce in the supplier’s own organisation and those of its key subcontractors
- Outline policies and practices to be applied to or put in place for the contract to mitigate and manage modern slavery risks, including: Pre-employment checks, recruitment practices. Workplace conditions, safeguarding plans and processes in place and regular monitoring with relevant groups considered, which may include sampling
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.
- Activities to support relevant sector related skills growth and sustainability in the contract workforce. Illustrative examples: careers talks, curriculum support, literacy support, safety talks and volunteering
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 3: Resilient, innovative and flexible supply chains: Support economic growth through enabling resilient businesses, opportunities for small businesses and voluntary, community and social enterprises
- Ensuring accessibility to contracting and subcontracting opportunities for disabled business owners and employees
-
Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero
Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.
- Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
- Delivery of additional environmental benefits through the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
-
Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain
Policy Outcome 6: Employment and training: For those who face barriers to employment
- Understanding of the issues affecting inequality in employment, skills and pay in the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors. Measures to tackle inequality in employment, skills and pay in the contract workforce
-
Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain
Policy Outcome 7: Creating a pipeline of opportunities: For the contract workforce, reducing barriers to entry for under-represented groups.
- Creation of outreach activities to create a pipeline of employees for the future contract delivery
-
Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.
Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.
- Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce
-