Skip to main content

Help us improve the Digital Marketplace - send your feedback

RISKEX LIMITED

AssessNET Logbook and Checklist

AssessNET’s Logbook provides clear visibility and control of all logbook tasks. Fully customisable templates enable structured questions, capture associated concerns, and trigger notifications when issues are raised. Logged data can be extracted to generate reports and analyse key concerns across the organisation.

Features

  • Create multiple Logbooks via the customisable template builder
  • Define your own question including free text and customizable questions
  • Set recurring reminders for regular checks to suit your needs
  • Raise actions based on concerns and assign to user
  • Track action status through to completion
  • Monitor completion to ensure compliance and timely reporting
  • Advanced searches across logbook entries to rapidly find specific records

Benefits

  • Create and manage templates to capture all information required
  • Define what constitutes a concern and notify when used
  • Recurring Logbook schedules ensure checks are completed on time
  • Track actions to ensure remedial concerns are completed
  • Export data for offline analysis or integration with external tools
  • Full Audit log to record all changes to records

Pricing

  • Education pricing available
  • Free trial available

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at r.aylott@riskex.com. Tell them what format you need. It will help if you say what assistive technology you use.

Framework

G-Cloud 15

Service ID

9 7 0 9 8 1 2 0 9 6 1 1 5 0 2

Contact

RISKEX LIMITED Richard Aylott
Telephone: +44 1908 915272
Email: r.aylott@riskex.com

About your service

Service categories

Applications

Content workflow and management

  • Capture
  • Document

Content services

  • Enterprise Content Management Applications
  • Content Sharing and Collaboration Applications

Enterprise portals and digital workspaces

  • Multi-Audience Portals
Multi cloud support
Yes

Service scope

Software add-on or extension
Yes, but can also be used as a standalone service
What software services is the service an extension to
AssessNET is a modular service. This means each AssessNET module works standalone, but integrates with others to provide you with powerful, holistic solution to meet within your budgets and/or needs.
Cloud deployment model
Public cloud
Service constraints
99.9% service availability and support SLA
System requirements
None

User support

Email or online ticketing support
Yes
Support response times
We provide a 4 hour response time within business hours.

Emergency or critical issues are monitored outside of business hours with a response time of 1 hour within business hours.
User can manage status and priority of support tickets
Yes
Online ticketing support accessibility
WCAG 2.2 AAA
Phone support
Yes
Phone support availability
9 to 5 (UK time), Monday to Friday
Web chat support
Yes, at an extra cost
Web chat support availability
9 to 5 (UK time), Monday to Friday
Web chat support accessibility standard
WCAG 2.2 AAA
Web chat accessibility testing
N/A - External vendor specialising in help desk platforms
Onsite support
Yes, at extra cost
Support levels
We offer the same core support level to every client, whatever the size of the organisation or contract. Our UK based team supports you from go live onwards, helping users with day to day queries, training guidance and configuration during business hours.

Support requests are raised through our online service desk Monday to Friday 8:30 to 17:30. Each request is logged against your account, tracked through to completion and retained as a reference history. Where an issue needs deeper investigation, it is progressed to our technical specialists and, if required, our senior team for detailed analysis and corrective action, with updates provided in line with our service targets.

If preferred, we can restrict who can submit requests to nominated contacts or a client support desk. All clients are also assigned an account manager to help coordinate support and assist with escalations.

We provide a 99.9% monthly availability commitment, excluding planned maintenance. Maintenance is carried out outside office hours wherever possible and communicated in advance.
Support available to third parties
Yes
AI chatbot
Yes

Onboarding and offboarding

Getting started
All onboarding clients are assigned an Account Manager and an Implementation Manager to ensure a smooth, well governed transition onto the service. We start with an implementation meeting to confirm objectives, requirements and success measures, then agree the configuration approach for your organisation.

AssessNET is designed to be intuitive for everyday users while providing the depth and control required by administrators. During onboarding we capture core system data, establish organisational structures, permissions and workflows, and support your team to configure the platform. Administrator enablement is built into this activity, with practical guidance as key settings are applied, so your team can confidently manage the service going forward.

Training can be delivered online, onsite, or as a blended approach, and is tailored to your modules, processes and audience. Sessions can cover train the trainer, role based training, individual modules, or general system overviews, and can be repeated for different teams to suit availability. Online sessions can be recorded for reuse where appropriate. If you prefer fixed training assets, we can produce a configuration specific training video on request.

All licensed users have access to in system support resources, including module guidance, manuals and self serve help content.
Service documentation
Yes
Documentation formats
  • HTML
  • PDF
End-of-contract data extraction
If a client requires a data extract at the end of their contract, this can be requested via their Account Manager or through our Support Desk. In many cases, clients can also export information directly from within the system prior to licence expiry, enabling them to retain key reports and records as needed. Where a full service led extract is required, we will prepare an export of the relevant data held within the service, including any uploaded document attachments, and provide it in an agreed format using an agreed delivery method. This service is chargeable, with pricing confirmed in advance and based on the volume and complexity of the data requested.
End-of-contract process
Where a customer chooses not to renew, they can download and export their information using the in-system tools before access ends. If a more comprehensive extract is required, Riskex can produce this on request as a chargeable service.
Documentation accessibility standard
WCAG 2.2 AAA

Using the service

Web browser interface
Yes
Supported browsers
  • Microsoft Edge
  • Firefox
  • Chrome
  • Safari
  • Opera
Application to install
No
Designed for use on mobile devices
Yes
Differences between the mobile and desktop service
Our cloud platform supports mobile working through a dedicated app for Android and Apple devices, available on both phones and tablets. The app covers Risk Assessments, Incident Reporting, Audits, Inspections and Hazard reporting, and includes a built in task manager so users can view and update actions in the field. It works online and offline, capturing data without a signal and syncing later. Users can upload files and photos, and use QR code access, ideal for contractors or non account users to complete specific tasks such as incident reporting. Our web system is also mobile responsive via the browser.
Service interface
No
User support accessibility
WCAG 2.2 AAA
API
Yes
What users can and can't do using the API
Our platform includes a RESTful API that returns JSON and is designed to integrate securely with authorised third party systems alongside our cloud service. The API enables approved applications to access and work with key operational data, including tasks, assessments, users and organisational structures, supporting both retrieval and the creation or updating of records where permitted.

Security is built in from the outset. Access is controlled for authorised systems only, and the API is delivered in line with required security standards to protect data confidentiality and integrity. To maintain strong governance, deletion of data via the API is not permitted. All API activity is fully auditable, with comprehensive logging of changes to support traceability and enable rollback where required.

Where clients have specific integration requirements, we can also design and deliver private, client specific API endpoints by request, enabling tailored data flows while maintaining the same security and audit standards.
API documentation
Yes
API documentation formats
  • Open API (also known as Swagger)
  • HTML
  • PDF
API sandbox or test environment
Yes
Customisation available
Yes
Description of customisation
AssessNET is highly configurable, with several hundred settings that allow clients to tailor nomenclature, control which features are available, and adjust how information is presented. Many of these options can be managed directly by authorised client administrators through the system interface, enabling changes to be made quickly without the need to raise support requests.

The platform also supports corporate branding, including the ability to apply your preferred colours across menus, dashboards and charts, and to upload your organisation’s logo for consistent use throughout the system and on exported and printed reports.

During onboarding, your Implementation Manager will work with you to confirm the most appropriate configuration for your organisation and will highlight the full range of options available. Where a requirement falls outside of what is configurable through the standard interface, our team can provide additional support and, where needed, deliver more bespoke tailoring to meet specific operational needs.

Scaling

Independence of resources
Our service maintains consistent performance through a scalable, virtualised environment with load-balanced application instances. Each client’s data is logically segregated, ensuring that one client’s activity does not impact others. This architecture guarantees responsiveness and reliability, even during peak usage.

Analytics

Service usage metrics
Yes
Metrics types
The service provides a comprehensive suite of metrics accessible directly within the platform, giving end users and administrators clear visibility into system activity. Metrics cover areas such as login activity, record and task counts, incident trends, and audit tracking, providing actionable insights to support effective management and decision-making.
Reporting types
  • API access
  • Real-time dashboards
  • Regular reports
  • Reports on request
Resource tagging
No
FOCUS resource tagging
No

Resellers

Supplier type
Not a reseller

Staff security

Staff security clearance
Conforms to BS7858:2019
Government security clearance
Baseline Personnel Security Standard (BPSS)

Asset protection

Knowledge of data storage and processing locations
Yes
Data storage and processing locations
United Kingdom
User control over data storage and processing locations
No
Datacentre security standards
Complies with a recognised standard (for example CSA CCM version 4.0)
Penetration testing frequency
At least once a year
Penetration testing approach
‘IT Health Check’ performed by a CHECK service provider
Protecting data at rest
  • Physical access control, complying with CSA CCM v4.0
  • Physical access control, complying with SSAE-18 / ISAE 3402
  • Encryption of all physical media
  • Scale, obfuscating techniques, or data storage sharding
  • Other
Other data at rest protection approach
All data is encrypted at rest whilst stored in physically protected data centres. This also applies to external backup provisions and redundancy.
Data sanitisation process
Yes
Equipment disposal approach
Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
Data sanitisation type
  • Deleted data can’t be directly accessed / Cryptographic Erasure
  • Explicit overwriting of storage before reallocation / Secure Erase

Data importing and exporting

Data export approach
Comprehensive data extraction tools are available across all system modules, enabling scheduled exports to support operational and reporting needs. Extracted data is securely stored in an sFTP repository, with access credentials managed by the service provider.

For full-system data extracts, including uploaded files, clients may submit a request through their Account Manager or the Support Team. A service fee applies for these extraction requests, ensuring timely and secure delivery of the requested data.
Data export formats
  • CSV
  • Other
Other data export formats
  • Microsoft Excel and compatible
  • JSON
  • XML
  • PDF
Data import formats
  • CSV
  • Other
Other data import formats
  • Microsoft Excel or compatible
  • JSON
  • XML
  • Inbound API
  • PDF (SDS Data)

Data-in-transit protection

Data protection between buyer and supplier networks
TLS (version 1.2 or above)
Data protection within supplier network
TLS (version 1.2 or above)

Availability and resilience

Guaranteed availability
We provide a 99.9% uptime commitment, with planned maintenance scheduled in advance and communicated to clients. Maintenance is carried out out-of-hours wherever possible and, unless responding to a security critical event, will always be performed outside normal business hours. All changes follow controlled release procedures with full rollback plans in place, and our service credits and remedies are defined within the contract.
Approach to resilience
The service is hosted across multiple datacentres to maximise resilience, so the loss of a single site should not interrupt availability. It runs within a virtualised platform designed for high availability, with built in redundancy across multiple parallel instances to maintain service if an individual component or instance fails.

In the very rare event of a wider outage affecting the whole service, we maintain a documented disaster recovery plan to support full restoration. As part of our ISO 27001 arrangements, this plan is regularly exercised through simulated tests to validate recovery procedures and strengthen ongoing resilience.
Outage reporting
Planned outages are communicated through the inbuilt news feed with appropriate notice to allow clients to plan accordingly.

In addition, for any planned outage scheduled to occur or unplanned service event, clients receive direct email notifications, ensuring timely and transparent communication.

Identity and authentication

User authentication needed
Yes
User authentication
  • Public key authentication (including by TLS client certificate)
  • Identity federation with existing provider (for example Google Apps)
  • Dedicated link (for example VPN)
  • Username or password
  • Other
Other user authentication
Single Sign On can be enabled either using our native SSO capability or by integrating with a customer managed identity provider that supports WS-Federation and SAML2.0. Two factor authentication is enforced as standard for all user accounts, and every user is issued a unique username.
Access restrictions in management interfaces and support channels
Access to the service is tightly controlled through granular user privileges and clearly defined permission levels. Clients have no access to the underlying hosting environment; all administration is conducted securely via the application’s user interface, ensuring operational control while maintaining system integrity.
Access restriction testing frequency
At least every 6 months
Management access authentication
  • Identity federation with existing provider (for example Google Apps)
  • Username or password
  • Other
Description of management access authentication
Single Sign On can be enabled either using our native SSO capability or by integrating with a customer managed identity provider that supports WS-Federation and SAML2.0. Two factor authentication is enforced as standard for all user accounts, and every user is issued a unique username.

Audit information for users

Access to user activity audit information
Users have access to real-time audit information
How long user audit data is stored for
At least 12 months
Access to supplier activity audit information
Users have access to real-time audit information
How long supplier audit data is stored for
At least 12 months
How long system logs are stored for
At least 12 months

Security governance

Named board-level person responsible for service security
Yes
Security governance certified
Yes
Security governance standards
  • CSA CSM version 4.0
  • ISO/IEC 27001
Information security policies and processes
Our ISO 27001:2022 certified policies and procedures govern access to infrastructure and client data, ensuring only authorized team members can access sensitive information. Access is role-based, with permissions granted according to operational need.

All staff are trained on security policies, with annual refresher training to maintain awareness. Oversight is provided by our Board of Directors, supported by system controls that ensure policies are consistently applied across the organisation.

All ISOs adopted by Riskex are UKAS accredited.
Software Security Code of Practice
Yes

Operational security

Configuration and change management standard
Supplier-defined controls
Configuration and change management approach
All change requests are meticulously tracked throughout their lifecycle and incorporated into the main systems, where they continue to be monitored for support and operational integrity. All developments undergo rigorous testing against OWASP Top 10 standards and additional security controls to mitigate potential risks. Cross-browser and platform testing ensures full compatibility and a consistent user experience.

Our change management and development processes are fully aligned with ISO 27001:2022 and ISO 9001:2015, ensuring robust governance, compliance, and consistent delivery of secure, high-quality solutions.
Vulnerability management type
Supplier-defined controls
Vulnerability management approach
We operate continuous security monitoring to identify vulnerabilities and maintain robust patch management routines to keep underlying software and components up to date. When a potential weakness is detected, it is assessed and prioritised through our risk management process, with remediation planned and delivered based on the severity and potential impact.
Protective monitoring type
Supplier-defined controls
Protective monitoring approach
Riskex use SIEM tooling to provide ongoing security event monitoring and alerting, with actionable reports and escalations directed to our network team for timely investigation and response.
Incident management type
Supplier-defined controls
Incident management approach
We are accredited to ISO 27001 and operate a robust, fully documented information security incident management process aligned to our Information Security Management System. This approach defines clear roles, responsibilities and escalation routes for identifying, reporting, triaging, investigating and resolving security incidents. The process is regularly reviewed and tested as part of our ISO 27001 governance and audit programme to ensure it remains effective, up to date and continuously improved.
Post-quantum cryptography secure
No

Secure development

Approach to secure software development best practice
Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)

Public sector networks

Connection to public sector networks
No

Pricing

Discount for educational organisations
Yes
Free trial available
Yes
Description of free trial
Free trials are available on request. Where a trial is provided, the trial period is agreed in advance and the environment is set up to reflect your requirements, including the relevant modules and an appropriate initial configuration, so you can evaluate the service in a realistic way.

Discount percentage by annual call-off contract value (excluding VAT)

Less than £250,000
0%
Between £250,000 and £500,000
5%
Between £500,001 and £1,000,000
4%
Between £1,000,001 and £2,500,000
3%
Between £2,500,001 and £5,000,000
2%
Over £5,000,001
1%

Non-mandatory Standards and certifications

ISO/IEC 27001 certification
Yes
Who accredited the ISO/IEC 27001
3Core2 (UKAS Accredited)
ISO/IEC 27001 accreditation date
Monday 17 March 2014
What the ISO/IEC 27001 doesn’t cover
Our scope is as follows;

The provision of cloud-based management solutions, consultancy and training
services. This is in accordance with the Statement of Applicability, Version 4 dated
18/03/2025
ISO 28000:2022 certification
No
ISO 9001 certification
Yes
Who accredited the ISO 9001 certification
3Core2 (UKAS Accredited)
ISO 9001 accreditation date
Friday 13 September 2013
What the ISO 9001 doesn’t cover
Our scope is as follows:

The provision of cloud-based management solutions, consultancy and training
services.
Quality management systems (QMS)
Yes
CSA STAR certification
No
PCI certification
No
Cyber essentials
Yes
Please provide your Cyber Essentials Certificate Number
616d0ad9-7819-42a4-aef5-e93575cc3c64
Cyber essentials plus
No
Cyber Essentials Alternative
In relation to the services you do not have a current and valid Cyber Essentials Plus certificate which has been awarded by one of the government approved Cyber Essentials accreditation bodies but you are working towards gaining it, and will be in a position to confirm that you have been awarded a current and valid Cyber Essentials Plus certificate by one of the government approved accreditation bodies within 12 months of the date of award.
Other security certifications
No

Social value

Section B - Commitment for Future: Delivery
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority

    • Plans to engage the contract workforce in deciding the most important workplace issues to address
    • Employment contracts that reflect actual hours worked; steps taken to ensure employees understand their contracts and have the ability to review and adjust them if actual hours regularly exceed contracted hours
    • Activities to cascade good practice on fair working conditions throughout the supply chain
    • Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
    • Understanding of in-work progression issues affecting the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors
    • Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
    • Outline policies and practices to be applied to or put in place for the contract to mitigate and manage modern slavery risks, including: Pre-employment checks, recruitment practices. Workplace conditions, safeguarding plans and processes in place and regular monitoring with relevant groups considered, which may include sampling
    • How these flow down the supply chain and are monitored Illustrative examples include reporting, site visits, audits, etc.
    • How to ensure business decisions re: price/cost, short lead times, payment timescales do not create modern slavery risks in the supply chain

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at r.aylott@riskex.com. Tell them what format you need. It will help if you say what assistive technology you use.