FMIS Fixed Asset Management
FMIS Fixed Asset Management is cloud-hosted fixed asset management software for UK public sector organisations. It supports the full asset lifecycle, including acquisition, depreciation, revaluation and disposal, helping finance teams maintain accurate asset records, meet accounting requirements and support audits with clear reporting and controls.
Features
- Cloud-hosted fixed asset register with secure browser access
- Automated depreciation calculations across multiple accounting methods
- Asset acquisition, revaluation, impairment and disposal processing
- Configurable asset categories, books and depreciation rules
- Comprehensive asset reporting and audit-ready outputs
- Asset tracking with barcode support
- Document attachment for assets, including invoices and warranties
- Import and export of asset data via spreadsheets
- User access controls and full audit trail logging
Benefits
- Maintain accurate, up-to-date asset records across the organisation
- Reduce manual effort through automated depreciation and calculations
- Support audits with clear, consistent asset data and reports
- Improve financial control over asset values and lifecycle changes
- Meet public sector accounting requirements with greater confidence
- Track assets easily across locations, users and departments
- Save time importing, updating and exporting asset information
- Reduce risk through controlled access and full audit trails
Pricing
- Education pricing available
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
9 7 4 2 8 2 5 9 1 2 6 6 7 2 2
Contact
FMIS
John de Robeck
Telephone: +44 (0) 1223 773003
Email: johnderobeck@fmis.co.uk
About your service
- Service categories
-
Applications
Enterprise resource management
- Asset life-cycle management
Financial
- Financial and Accounting Applications
- Multi cloud support
- No
Service scope
- Software add-on or extension
- No
- Cloud deployment model
-
- Public cloud
- Private cloud
- Service constraints
- FMIS Fixed Asset Management is delivered as a cloud-hosted service accessed via a modern web browser. Planned maintenance is scheduled outside core UK business hours where possible and communicated in advance. Internet connectivity is required to access the service. Support is provided during standard UK business hours, with additional services available by agreement.
- System requirements
-
- Modern web browser with internet connectivity
- Supported browsers include Chrome, Edge, Firefox or Safari
User support
- Email or online ticketing support
- Yes
- Support response times
- FMIS operates a priority-driven support model. High-priority incidents receive an initial response within one hour during UK business hours (9am–5pm, Monday to Friday, excluding public holidays). Standard and low-priority requests are responded to within agreed service targets. Weekend support is not provided as standard but can be arranged by agreement.
- User can manage status and priority of support tickets
- No
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- No
- Onsite support
- No
- Support levels
- FMIS provides UK-based standard support for all licensed users as part of the annual software licence. Support covers implementation assistance, user queries, configuration guidance and incident resolution. Requests can be raised by email or phone during UK business hours (9am–5pm, Monday to Friday, excluding public holidays). Support is delivered by experienced FMIS consultants and support engineers. There is no limit on the number of support requests.
- Support available to third parties
- Yes
Onboarding and offboarding
- Getting started
- FMIS supports customers in getting started through structured implementation and onboarding led by experienced consultants. This typically includes system setup, data migration support, configuration and user familiarisation delivered remotely. User documentation is provided to support day-to-day use of the service. Training is delivered as part of the implementation process and may include remote sessions tailored to customer requirements. Onsite training is not provided as standard. Ongoing support is available to assist users as they begin using the service.
- Service documentation
- Yes
- Documentation formats
-
- HTML
- End-of-contract data extraction
- FMIS Fixed Asset Management allows customers to extract their data directly from the service at any point, including at the end of the contract. Data can be exported by authorised users using built-in reporting and export tools in commonly used formats such as spreadsheets. This includes core asset records, transaction history and supporting information. Where required, FMIS can provide reasonable assistance during offboarding to support data extraction. Customers remain responsible for downloading and retaining their data prior to service termination.
- End-of-contract process
- At the end of the contract, customer access to FMIS Fixed Asset Management ends in line with the agreed contract terms. Customers are able to extract their data directly from the service at any point prior to termination using built-in export and reporting tools. No additional exit fees apply for standard offboarding. The contract price includes continued access to the service and standard support for the duration of the contract term. Any optional services requested by the customer, such as additional consultancy or assistance beyond standard data extraction, may be provided by agreement and charged separately. Data retention and deletion are handled in accordance with contractual and data protection requirements.
- Documentation accessibility standard
- None or don’t know
- How the documentation is accessible
- Onboarding and offboarding documentation for FMIS Fixed Asset Management is provided in digital formats and accessed through standard web browsers or commonly used document formats. Documentation is written in clear language and structured to support readability, with compatibility for standard browser accessibility features such as zoom, screen magnification and keyboard navigation. Customers can request documentation in electronic formats to support their internal accessibility requirements. Documentation has not been formally certified against specific accessibility standards but is designed to be usable with commonly available assistive technologies.
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Opera
- Other
- Application to install
- No
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
- FMIS Fixed Asset Management can be accessed on mobile devices via a supported web browser. Core functionality is available on mobile, including asset look-up and barcode scanning where supported by the device. The desktop interface provides a larger screen layout and access to full reporting and configuration features, which are better suited to desktop use.
- Service interface
- Yes
- User support accessibility
- None or don’t know
- Description of service interface
- FMIS Fixed Asset Management is accessed through a secure, web-based user interface using a standard browser. The interface provides role-based access to asset records, reporting and configuration functions. It is designed for desktop use, with support for mobile browser access where appropriate, including asset look-up and barcode scanning on compatible devices.
- Accessibility standards
- None or don’t know
- Description of accessibility
- FMIS Fixed Asset Management is accessed through a standard web browser and supports built-in accessibility features such as browser zoom, keyboard navigation and screen magnification. Users can view and manage asset records, run reports and export data using these features. The interface has not been formally tested against specific accessibility standards and may not fully support all assistive technologies or accessibility needs.
- Accessibility testing
- FMIS has not undertaken formal certification against WCAG or EN accessibility standards. Accessibility considerations are taken into account during interface design and testing, including support for standard browser accessibility features. Formal testing with users of assistive technology has not been conducted to date.
- API
- Yes
- What users can and can't do using the API
-
FMIS Fixed Asset Management provides an optional, access-controlled API to support integration and automation where required. The API can be used to retrieve asset information, create and update assets, post asset transactions, manage users with appropriate permissions, and generate general ledger postings. The API is not enabled by default and must be activated by FMIS. Once enabled, access is controlled through system configuration and user permissions within the service.
Service setup, core configuration and administrative controls are performed through the secure web-based user interface. The API is not intended for initial service provisioning or full system administration. Users cannot enable the API or generate credentials programmatically.
Authentication is performed using bearer tokens issued via a dedicated authentication endpoint. API access is limited to authorised users and actions permitted by their assigned permissions. The API is designed to support agreed integration scenarios and is subject to functional and security constraints defined by FMIS. - API documentation
- Yes
- API documentation formats
- HTML
- API sandbox or test environment
- No
- Customisation available
- Yes
- Description of customisation
-
FMIS Fixed Asset Management can be customised through configuration options within the service by authorised users. Customisation includes asset categories, depreciation methods, accounting rules, chart of accounts mappings, reporting parameters, user roles and permissions, and system settings. These changes are made using the secure web-based interface and, where appropriate, supported data import tools.
Customisation is typically performed by users with administrative permissions, such as finance or system administrators. End users can access and use the configured service but cannot change core system settings unless granted appropriate rights. The service is not customised through source code changes; all customisation is configuration-based to ensure consistency, supportability and upgradeability.
Scaling
- Independence of resources
- FMIS Fixed Asset Management is delivered as a cloud-hosted, multi-customer service with logical separation of customer data and controlled access. Capacity and performance are actively monitored and managed by FMIS to ensure consistent service levels. The service is designed so that usage by one customer does not adversely affect the availability or performance experienced by other customers under normal operating conditions.
Analytics
- Service usage metrics
- Yes
- Metrics types
- FMIS Fixed Asset Management provides service metrics through standard reporting and audit functionality. Metrics include asset volumes, asset lifecycle status, transaction history, depreciation activity, general ledger postings and user activity. These metrics support operational management, audit and reporting requirements and can be exported in standard formats for further analysis.
- Reporting types
-
- Regular reports
- Reports on request
- Resource tagging
- No
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Other security clearance
- Government security clearance
- Security Clearance (SC)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- United Kingdom
- User control over data storage and processing locations
- Yes
- Datacentre security standards
- Complies with a recognised standard (for example CSA CCM version 4.0)
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- ‘IT Health Check’ performed by a CHECK service provider
- Protecting data at rest
-
- Physical access control, complying with another standard
- Encryption of all physical media
- Data sanitisation process
- Yes
- Equipment disposal approach
- Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
- Data sanitisation type
-
- Deleted data can’t be directly accessed / Cryptographic Erasure
- Data Erasure
Data importing and exporting
- Data export approach
- Users can export data directly from FMIS Fixed Assets using built-in reporting and export tools. Data is available in standard formats including CSV and spreadsheet formats for reuse and analysis, and PDF for reporting and audit purposes. Where enabled, the FMIS Fixed Assets API may also be used to retrieve asset data programmatically to support agreed integration requirements. Export access is controlled by user permissions within the service.
- Data export formats
-
- CSV
- Other
- Other data export formats
- Data import formats
-
- CSV
- Other
Data-in-transit protection
- Data protection between buyer and supplier networks
- TLS (version 1.2 or above)
- Data protection within supplier network
-
- TLS (version 1.2 or above)
- Other
- Other protection within supplier network
- Data within the FMIS environment is protected through layered security controls, including network segmentation, firewalling and strict access controls between system components. Access is limited to authorised services and personnel, and security measures are monitored and maintained in line with FMIS information security policies and managed hosting provider standards.
Availability and resilience
- Guaranteed availability
-
FMIS Fixed Asset Management is provided with a defined Availability Commitment as set out in the FMIS Licence Agreement and Schedule 2 (Service Level Targets). FMIS commits to ensuring that the Service is available at least 99.9% of the time in each calendar month, excluding Scheduled Maintenance and Permitted Downtime. Service availability is monitored by FMIS.
Where FMIS does not meet the Availability Commitment, the matter will be reviewed in accordance with the service level provisions of the Agreement, and FMIS will work with the Customer in good faith to identify and implement appropriate remedial actions.
Planned maintenance is scheduled where reasonably practicable to minimise disruption and is communicated to customers in advance. - Approach to resilience
- FMIS maintains business continuity and disaster recovery arrangements aligned with recognised information security and operational resilience standards, including ISO/IEC 27001. These arrangements are designed to support service recovery and continuity in the event of a significant incident and are reviewed as part of FMIS operational governance. Further details can be provided to buyers on request.
- Outage reporting
- In the event of a significant service outage, FMIS will notify affected customers by email with relevant information and updates as appropriate. Minor incidents or issues that do not materially impact service availability may be managed through normal support channels. Outage communication is handled in line with FMIS operational and support procedures.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Username or password
- Access restrictions in management interfaces and support channels
- Access to management interfaces and support systems is restricted to authorised FMIS personnel and customer users based on defined roles and responsibilities. Role-based access controls are used to limit access to functions and data appropriate to each user. Administrative access is granted only where required and is subject to approval and review. Access to support channels is controlled, with requests authenticated before actions are taken. Access rights are reviewed and updated as roles change.
- Access restriction testing frequency
- At least once a year
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Username or password
Audit information for users
- Access to user activity audit information
- Users have access to real-time audit information
- How long user audit data is stored for
- At least 12 months
- Access to supplier activity audit information
- Users have access to real-time audit information
- How long supplier audit data is stored for
- At least 12 months
- How long system logs are stored for
- Between 1 month and 6 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
-
- ISO/IEC 27001
- Other
- Other security governance standards
- Cyber Essentials Plus
- Information security policies and processes
-
FMIS operates a formal information security management framework aligned with ISO/IEC 27001. This includes documented policies covering areas such as access control, data protection, incident management, supplier security, change management and business continuity. Policies are approved by senior management and reviewed regularly to ensure continued relevance and effectiveness.
Information security governance is overseen by the FMIS Data Protection and Information Security Lead, with reporting to senior management. Compliance with policies is supported through defined procedures, staff awareness, role-based access controls and ongoing operational monitoring. Security incidents are recorded, assessed and managed in line with documented processes, with corrective actions implemented where required. Policies and controls are reviewed as part of internal audits and continuous improvement activities. - Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
- FMIS maintains documented configuration and change management processes to control changes to the service throughout its lifecycle. Service components and configurations are tracked and managed through defined procedures and system records. Proposed changes are assessed for operational and security impact before implementation, with appropriate approval and testing applied. Changes are implemented in a controlled manner and, where appropriate, reviewed post-implementation to ensure service stability and security are maintained.
- Vulnerability management type
- Supplier-defined controls
- Vulnerability management approach
- FMIS operates a structured vulnerability management process to identify, assess and remediate security risks affecting the service. Potential threats are assessed based on severity, exploitability and impact to the service. Vulnerability information is obtained from software vendors, managed hosting providers and recognised security advisories. Security patches and updates are prioritised and deployed in line with risk, using controlled change management processes to ensure service stability and security are maintained.
- Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
- FMIS operates protective monitoring processes to identify potential security incidents affecting the service. Monitoring includes review of system activity, alerts from hosting providers and security tooling, and investigation of anomalous behaviour. When a potential compromise is identified, incidents are assessed, contained and remediated in line with documented incident management procedures. Incidents are prioritised based on severity and impact, with response actions initiated promptly in accordance with internal escalation and communication processes.
- Incident management type
- Supplier-defined controls
- Incident management approach
- FMIS maintains documented incident management processes for responding to security and service incidents, including pre-defined procedures for common event types. Users can report incidents through established support channels, including email and phone. Incidents are logged, assessed and managed in line with internal procedures. Where appropriate, incident updates and summary reports are provided to affected customers through agreed communication channels.
- Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- Yes
- Free trial available
- No
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 2%
- Between £500,001 and £1,000,000
- 4%
- Between £1,000,001 and £2,500,000
- 6%
- Between £2,500,001 and £5,000,000
- 8%
- Over £5,000,001
- 10%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- Yes
- Who accredited the ISO/IEC 27001
- ASCB
- ISO/IEC 27001 accreditation date
- Friday 10 May 2019
- What the ISO/IEC 27001 doesn’t cover
- The ISO/IEC 27001 certification applies to FMIS’s information security management system and the delivery of FMIS cloud-hosted services. It does not extend to customer-managed environments, customer end-user devices, third-party systems not under FMIS control, or services operated independently by customers outside the FMIS platform.
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- Yes
- Who accredited the ISO 9001 certification
- ASCB
- ISO 9001 accreditation date
- Monday 3 December 2018
- What the ISO 9001 doesn’t cover
- The ISO 9001 certification applies to FMIS’s quality management system and the processes used to deliver FMIS software and associated services. It does not cover customer-managed processes, customer use of the software, or third-party services and suppliers that are not under FMIS operational control.
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- A1c5bc50-1b06-45b6-afea-4518af5903c4
- Cyber essentials plus
- Yes
- Please provide your Cyber Essentials Plus Certificate Number
- 2ccdf53b-b352-444b-b04d-8e51db30fa51
- Other security certifications
- No
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero
Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.
- Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
-