CGI

Open Banking Payments (Ordo)

Ordo gives your organisation a low cost, real time, customer friendly alternative to card payments. Our simple to use APIs give you a fully customised service so you can collect payments and make refunds by invoice, eCommerce, contact centre, and point of sale at a simple fixed charge per payment.

Features

  • Customer payments via invoice, eCommerce, call centre and PoS/QRCode
  • Payment direct from customer's bank account with secure open banking
  • Irrevocable realtime payments into you bank accounts with no chargebacks
  • No payer registration or app downloads for payers to use
  • Available to 98% of consumers and small businesses
  • Customer payment authorisation already built into mobile and internet banking
  • Guaranteed payment references for auto-reconciliation and secure document delivery
  • Fully customised payer experience with your organisation's look and feel
  • Secure refunds and payouts to validated customer bank accounts
  • Ready for open banking Variable Recurring Payments (VRP)

Benefits

  • Low fixed cost per payment, not percentage of value
  • Faster payment - real time directly into your bank accounts
  • No insecure bank account or payment card data sharing
  • No interception, third party fraud risks or chargebacks
  • Simple customer experience, no data entry or sharing
  • Know immediately you've been paid with real time payment status
  • Simple payment reconciliation - you provide a locked bank reference
  • Secure communication with your customer for invoices etc
  • Widely available, payer just needs mobile or internet banking
  • Know exactly who you are paying for out payments

Pricing

£0.00 to £0.20 a transaction

  • Education pricing available
  • Free trial available

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at uk.gen.ccsframeworks@cgi.com. Tell them what format you need. It will help if you say what assistive technology you use.

Framework

G-Cloud 13

Service ID

9 4 2 8 4 7 4 8 8 6 4 9 9 8 6

Contact

CGI CCS Frameworks Team
Telephone: 08450707765
Email: uk.gen.ccsframeworks@cgi.com

Service scope

Software add-on or extension
Yes
What software services is the service an extension to
Capita Pay 360 (v13 onwards), Contis BaaS, Certua
embedded finance solutions, CGI Collections Suite,
Siemens Energy Company Managed Credit Solution
Cloud deployment model
Public cloud
Service constraints
Domestic UK sterling payments. Some corporate bank
accounts do not support open banking payments
System requirements
OAuth for secure service access

User support

Email or online ticketing support
Email or online ticketing
Support response times
Varies by severity of issue
User can manage status and priority of support tickets
No
Phone support
No
Web chat support
No
Onsite support
Yes, at extra cost
Support levels
Support is provided Mon--Fri 0900 to 1730 excluding Bank Holidays via support@ordopay.com
Support levels are shown below with support hours response times.
Platform availability is 99.5% 24x7
- Priority 1 (P1) [Total loss of the Ordo Platform] 30min response
- Priority 2 (P2) [Major functionality unavailable with no workaround available] 2 hour response
- Priority 3 (P3) [Major functionality unavailable with work around available. Minor functionality unavailable.] 4 hour response
- Service Request [Individual user affected. Business requests to the operations team] 24 hour response
Support available to third parties
Yes

Onboarding and offboarding

Getting started
Integration specialist team can support via video call/face
to face meetings, guiding users through the service
Service documentation
Yes
Documentation formats
  • PDF
  • Other
Other documentation formats
  • Word
  • Excel
  • Swagger
End-of-contract data extraction
To comply with FCA requirements, all transactional data is
held for up to 7 years (6 calendar years plus current year).
All non-essential information can be removed via our RTBR
capabilities.
End-of-contract process
At end of contract, we would agree with user whether they
wanted existing, unpaid transactions to be 'expired' or kept
open so payer can still action. Depending on level of post-contract access required we would remove functional
access.

Using the service

Web browser interface
Yes
Supported browsers
  • Internet Explorer 11
  • Microsoft Edge
  • Firefox
  • Chrome
  • Safari
  • Opera
Application to install
No
Designed for use on mobile devices
Yes
Differences between the mobile and desktop service
Mobile and desktop provide the same end-user service for payers. Mobile provides the optimal experience as the payer is taken automatically to their mobile banking app to authorise payment simply and securely via fingerprint or face-id. On desktop the user needs to either scan an Ordo generated QR code to authorise payment from their mobile banking app on their smart phone or alternatively provide login credentials to their bank's internet banking service from the desktop. The Ordo service is device aware
and screens are appropriately optimised.
Service interface
Yes
User support accessibility
None or don’t know
Description of service interface
Most users will obtain service information, e.g. updates on
payments, etc via our APIs. For smaller volume users we also
provide a web based service user interface (dashboard) that allows for generation and review of payments, etc.
Accessibility standards
None or don’t know
Description of accessibility
Not applicable for normal API access. The web dashboard, if used, can use most desktop/browser accessibility aids.
Accessibility testing
Testing with screen readers for sight impaired users has been done.
API
Yes
What users can and can't do using the API
All service features and use cases are supported via API apart from adding new receiving bank account details. Adding new bank account details require an Ordo service request for security reasons.
API documentation
Yes
API documentation formats
Open API (also known as Swagger)
API sandbox or test environment
Yes
Customisation available
Yes
Description of customisation
The look and feel of the end-user payments journey can be
customised to reflect the branding, styles, typeface and language of the billing business. This look and feel will apply to all types of payment, not just eCommerce initiated. The billing business simply provides Ordo with the digital assets and Ordo applies them to the service for the client's payments.

Scaling

Independence of resources
The service is hosted in the cloud and scalable. Performance testing, service monitoring and capacity planning are in place.

Analytics

Service usage metrics
Yes
Metrics types
Ordo provide daily monitoring for newly integrated
clients including itemised and aggregated transaction
volume and value metrics as well as transaction
completion rates Ordo provide monthly client service
reviews for the continual improvement of service
provision using aggregated transaction volume and
value metrics, transaction statuses and market price
comparison Ordo provide an API endpoint for all
transactions created by a client for their internal reporting, monitoring of transaction statuses and client
system management.
Reporting types
  • API access
  • Regular reports
  • Reports on request

Resellers

Supplier type
Reseller (no extras)
Organisation whose services are being resold
Ordo

Staff security

Staff security clearance
Other security clearance
Government security clearance
Up to Baseline Personnel Security Standard (BPSS)

Asset protection

Knowledge of data storage and processing locations
Yes
Data storage and processing locations
United Kingdom
User control over data storage and processing locations
No
Datacentre security standards
Complies with a recognised standard (for example CSA CCM version 3.0)
Penetration testing frequency
At least once a year
Penetration testing approach
‘IT Health Check’ performed by a CHECK service provider
Protecting data at rest
Encryption of all physical media
Data sanitisation process
No
Equipment disposal approach
In-house destruction process

Data importing and exporting

Data export approach
Through use of the service APIs
Data export formats
Other
Other data export formats
Via the API Json
Data import formats
  • CSV
  • Other
Other data import formats
  • API format
  • CSV (or XLS by exception)

Data-in-transit protection

Data protection between buyer and supplier networks
TLS (version 1.2 or above)
Data protection within supplier network
TLS (version 1.2 or above)

Availability and resilience

Guaranteed availability
Ordo platform is available 99.5% 24x7
Approach to resilience
The service utilises Microsoft PaaS features which offers underpinning high levels of resilience, scaling and capacity capability within the region.
Outage reporting
Email alerts

Identity and authentication

User authentication needed
Yes
User authentication
  • Username or password
  • Other
Other user authentication
Oauth2 for API
Access restrictions in management interfaces and support channels
N/A - no management console required for the services as API
integration to core client system.
Access restriction testing frequency
At least once a year
Management access authentication
Other
Description of management access authentication
N/A - no management console required for the services as API integration to core client system.

Audit information for users

Access to user activity audit information
Users contact the support team to get audit information
How long user audit data is stored for
At least 12 months
Access to supplier activity audit information
Users contact the support team to get audit information
How long supplier audit data is stored for
At least 12 months
How long system logs are stored for
At least 12 months

Standards and certifications

ISO/IEC 27001 certification
Yes
Who accredited the ISO/IEC 27001
Intertek Certification Limited
ISO/IEC 27001 accreditation date
07/04/2021
What the ISO/IEC 27001 doesn’t cover
None
ISO 28000:2007 certification
No
CSA STAR certification
No
PCI certification
No
Cyber essentials
No
Cyber essentials plus
No
Other security certifications
No

Security governance

Named board-level person responsible for service security
Yes
Security governance certified
Yes
Security governance standards
ISO/IEC 27001
Information security policies and processes
Information security policies are as approved by the FCA as part of Ordo's authorisation.

Operational security

Configuration and change management standard
Supplier-defined controls
Configuration and change management approach
CGI holds ISO27001:2013 certificates that cover outsourcing
operations and project and consultancy services in all of their
UK offices.
Vulnerability management type
Undisclosed
Vulnerability management approach
CGI holds ISO27001:2013 certificates that cover outsourcing
operations and project and consultancy services in all of their
UK offices.
Protective monitoring type
Supplier-defined controls
Protective monitoring approach
CGI holds ISO27001:2013 certificates that cover outsourcing
operations and project and consultancy services in all of their
UK offices.
Incident management type
Undisclosed
Incident management approach
CGI has a dedicated Global Security Operations Center
(GSOC) that provides ongoing security monitoring, incident
management, threat intelligence, threat management and
forensic investigation. The GSOC monitors CGI’s network
and critical assets on a 24x7 basis in geographies that CGI
operates, providing ongoing proactive testing of CGI’s
network to evaluate if controls perform as expected against
the current cyber-threats.

Secure development

Approach to secure software development best practice
Conforms to a recognised standard, but self-assessed

Public sector networks

Connection to public sector networks
No

Social Value

Fighting climate change

Fighting climate change

CGI is passionate about protecting the environment. Our UK corporate policy, backed by Science Based Targets (SBTs), is to be Net Zero by 2026 and to be operationally Carbon Neutral by the end of 2022.

We commit to:
- Achieving Net Zero, based on SBT measures, no later than 2026.
- Extending the climate change commitment into our supply chain such that 50% of our suppliers, by spend, will have set their own SBTs to reduce their climate impact by 2026.
- Applying our environmental programme ‘No Planet B’ to each opportunity. As part of ‘No Planet B’ we engage with our members, clients, suppliers and communities, to identify and deliver additional benefits including tree planting and canal restoration projects.
Covid-19 recovery

Covid-19 recovery

N/A
Tackling economic inequality

Tackling economic inequality

CGI is committed to ensuring careers in STEM are accessible for all. We will continue to provide a range of new employment and training opportunities which include professional, graduate and apprenticeships. To create new skills in the IT industry, we offer a range of IT-based apprenticeships and partner with various university training partners to deliver our Technology Industry Gold accredited Degree Apprenticeships.

We proudly support social enterprises FastFutures and Bounceback, providing mentoring, CV writing and interview skills to young people and prison leavers, enabling them to become work-ready. CGI’s EmployABILITY programme helps underrepresented students to build skills needed to pursue a successful career in STEM, through mentoring provided by our members.
Equal opportunity

Equal opportunity

At CGI we encourage diversity in our workplace and inclusivity at work is one of our priorities.

We commit to:
- Continuing to measure and reduce our Gender and Ethnicity Pay Gap
- Publishing our disability metrics
- Inclusive and accessible recruitment practices
- Investing in training and progression

CGI are proud of the progression with our Gender pay gap figures. While our ethnicity pay gap is relatively small, we know that a higher representation of minority ethnic employees at senior levels will reduce it further. This is now one of our main objectives. We recently updated our systems, enabling our members to declare whether they consider themselves to have a disability. We will publish this data through the Voluntary Reporting Framework.
Wellbeing

Wellbeing

At CGI, we are proud to care about our members. However, wellbeing isn’t an issue exclusively concerning our business; we are equally committed to supporting the wellbeing of the communities in which we operate too. We achieve this by:
- Training our members in Mental Health First Aid
- Extending health and wellbeing initiatives with our clients and suppliers
- Collaboratively identifying initiatives to support local communities

CGI are a signatory of the 'UK-wide Mental Health at Work Commitment' curated by the mental health charity 'Mind'. We will continue to invest in training to expand upon our 300 plus UK members who are already certified Mental Health First Aiders (MHFAs). These certified members have developed a strong support network for their colleagues. To supplement this and drive the integration of best practice for physical and mental health, we will provide all our members with access to ‘Oxygen’, our online wellbeing centre of expertise.

Pricing

Price
£0.00 to £0.20 a transaction
Discount for educational organisations
Yes
Free trial available
Yes
Description of free trial
Ordo customers can use the zero integration web interface via www.myordo.com, or an iOS app available through the apple app store with 20 free requests followed by using our pay as you go model for requests sent. There is no subscription required to use this service.
Link to free trial
Www.myordo.com

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at uk.gen.ccsframeworks@cgi.com. Tell them what format you need. It will help if you say what assistive technology you use.