Skip to main content

Help us improve the Digital Marketplace - send your feedback

FMIS

FMIS Fixed Asset Management

FMIS Fixed Asset Management is cloud-hosted fixed asset management software for UK public sector organisations. It supports the full asset lifecycle, including acquisition, depreciation, revaluation and disposal, helping finance teams maintain accurate asset records, meet accounting requirements and support audits with clear reporting and controls.

Features

  • Cloud-hosted fixed asset register with secure browser access
  • Automated depreciation calculations across multiple accounting methods
  • Asset acquisition, revaluation, impairment and disposal processing
  • Configurable asset categories, books and depreciation rules
  • Comprehensive asset reporting and audit-ready outputs
  • Asset tracking with barcode support
  • Document attachment for assets, including invoices and warranties
  • Import and export of asset data via spreadsheets
  • User access controls and full audit trail logging

Benefits

  • Maintain accurate, up-to-date asset records across the organisation
  • Reduce manual effort through automated depreciation and calculations
  • Support audits with clear, consistent asset data and reports
  • Improve financial control over asset values and lifecycle changes
  • Meet public sector accounting requirements with greater confidence
  • Track assets easily across locations, users and departments
  • Save time importing, updating and exporting asset information
  • Reduce risk through controlled access and full audit trails

Pricing

  • Education pricing available

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at johnderobeck@fmis.co.uk. Tell them what format you need. It will help if you say what assistive technology you use.

Framework

G-Cloud 15

Service ID

9 7 4 2 8 2 5 9 1 2 6 6 7 2 2

Contact

FMIS John de Robeck
Telephone: +44 (0) 1223 773003
Email: johnderobeck@fmis.co.uk

About your service

Service categories

Applications

Enterprise resource management

  • Asset life-cycle management

Financial

  • Financial and Accounting Applications
Multi cloud support
No

Service scope

Software add-on or extension
No
Cloud deployment model
  • Public cloud
  • Private cloud
Service constraints
FMIS Fixed Asset Management is delivered as a cloud-hosted service accessed via a modern web browser. Planned maintenance is scheduled outside core UK business hours where possible and communicated in advance. Internet connectivity is required to access the service. Support is provided during standard UK business hours, with additional services available by agreement.
System requirements
  • Modern web browser with internet connectivity
  • Supported browsers include Chrome, Edge, Firefox or Safari

User support

Email or online ticketing support
Yes
Support response times
FMIS operates a priority-driven support model. High-priority incidents receive an initial response within one hour during UK business hours (9am–5pm, Monday to Friday, excluding public holidays). Standard and low-priority requests are responded to within agreed service targets. Weekend support is not provided as standard but can be arranged by agreement.
User can manage status and priority of support tickets
No
Phone support
Yes
Phone support availability
9 to 5 (UK time), Monday to Friday
Web chat support
No
Onsite support
No
Support levels
FMIS provides UK-based standard support for all licensed users as part of the annual software licence. Support covers implementation assistance, user queries, configuration guidance and incident resolution. Requests can be raised by email or phone during UK business hours (9am–5pm, Monday to Friday, excluding public holidays). Support is delivered by experienced FMIS consultants and support engineers. There is no limit on the number of support requests.
Support available to third parties
Yes

Onboarding and offboarding

Getting started
FMIS supports customers in getting started through structured implementation and onboarding led by experienced consultants. This typically includes system setup, data migration support, configuration and user familiarisation delivered remotely. User documentation is provided to support day-to-day use of the service. Training is delivered as part of the implementation process and may include remote sessions tailored to customer requirements. Onsite training is not provided as standard. Ongoing support is available to assist users as they begin using the service.
Service documentation
Yes
Documentation formats
  • HTML
  • PDF
End-of-contract data extraction
FMIS Fixed Asset Management allows customers to extract their data directly from the service at any point, including at the end of the contract. Data can be exported by authorised users using built-in reporting and export tools in commonly used formats such as spreadsheets. This includes core asset records, transaction history and supporting information. Where required, FMIS can provide reasonable assistance during offboarding to support data extraction. Customers remain responsible for downloading and retaining their data prior to service termination.
End-of-contract process
At the end of the contract, customer access to FMIS Fixed Asset Management ends in line with the agreed contract terms. Customers are able to extract their data directly from the service at any point prior to termination using built-in export and reporting tools. No additional exit fees apply for standard offboarding. The contract price includes continued access to the service and standard support for the duration of the contract term. Any optional services requested by the customer, such as additional consultancy or assistance beyond standard data extraction, may be provided by agreement and charged separately. Data retention and deletion are handled in accordance with contractual and data protection requirements.
Documentation accessibility standard
None or don’t know
How the documentation is accessible
Onboarding and offboarding documentation for FMIS Fixed Asset Management is provided in digital formats and accessed through standard web browsers or commonly used document formats. Documentation is written in clear language and structured to support readability, with compatibility for standard browser accessibility features such as zoom, screen magnification and keyboard navigation. Customers can request documentation in electronic formats to support their internal accessibility requirements. Documentation has not been formally certified against specific accessibility standards but is designed to be usable with commonly available assistive technologies.

Using the service

Web browser interface
Yes
Supported browsers
  • Microsoft Edge
  • Firefox
  • Chrome
  • Safari
  • Opera
  • Other
Application to install
No
Designed for use on mobile devices
Yes
Differences between the mobile and desktop service
FMIS Fixed Asset Management can be accessed on mobile devices via a supported web browser. Core functionality is available on mobile, including asset look-up and barcode scanning where supported by the device. The desktop interface provides a larger screen layout and access to full reporting and configuration features, which are better suited to desktop use.
Service interface
Yes
User support accessibility
None or don’t know
Description of service interface
FMIS Fixed Asset Management is accessed through a secure, web-based user interface using a standard browser. The interface provides role-based access to asset records, reporting and configuration functions. It is designed for desktop use, with support for mobile browser access where appropriate, including asset look-up and barcode scanning on compatible devices.
Accessibility standards
None or don’t know
Description of accessibility
FMIS Fixed Asset Management is accessed through a standard web browser and supports built-in accessibility features such as browser zoom, keyboard navigation and screen magnification. Users can view and manage asset records, run reports and export data using these features. The interface has not been formally tested against specific accessibility standards and may not fully support all assistive technologies or accessibility needs.
Accessibility testing
FMIS has not undertaken formal certification against WCAG or EN accessibility standards. Accessibility considerations are taken into account during interface design and testing, including support for standard browser accessibility features. Formal testing with users of assistive technology has not been conducted to date.
API
Yes
What users can and can't do using the API
FMIS Fixed Asset Management provides an optional, access-controlled API to support integration and automation where required. The API can be used to retrieve asset information, create and update assets, post asset transactions, manage users with appropriate permissions, and generate general ledger postings. The API is not enabled by default and must be activated by FMIS. Once enabled, access is controlled through system configuration and user permissions within the service.

Service setup, core configuration and administrative controls are performed through the secure web-based user interface. The API is not intended for initial service provisioning or full system administration. Users cannot enable the API or generate credentials programmatically.

Authentication is performed using bearer tokens issued via a dedicated authentication endpoint. API access is limited to authorised users and actions permitted by their assigned permissions. The API is designed to support agreed integration scenarios and is subject to functional and security constraints defined by FMIS.
API documentation
Yes
API documentation formats
HTML
API sandbox or test environment
No
Customisation available
Yes
Description of customisation
FMIS Fixed Asset Management can be customised through configuration options within the service by authorised users. Customisation includes asset categories, depreciation methods, accounting rules, chart of accounts mappings, reporting parameters, user roles and permissions, and system settings. These changes are made using the secure web-based interface and, where appropriate, supported data import tools.

Customisation is typically performed by users with administrative permissions, such as finance or system administrators. End users can access and use the configured service but cannot change core system settings unless granted appropriate rights. The service is not customised through source code changes; all customisation is configuration-based to ensure consistency, supportability and upgradeability.

Scaling

Independence of resources
FMIS Fixed Asset Management is delivered as a cloud-hosted, multi-customer service with logical separation of customer data and controlled access. Capacity and performance are actively monitored and managed by FMIS to ensure consistent service levels. The service is designed so that usage by one customer does not adversely affect the availability or performance experienced by other customers under normal operating conditions.

Analytics

Service usage metrics
Yes
Metrics types
FMIS Fixed Asset Management provides service metrics through standard reporting and audit functionality. Metrics include asset volumes, asset lifecycle status, transaction history, depreciation activity, general ledger postings and user activity. These metrics support operational management, audit and reporting requirements and can be exported in standard formats for further analysis.
Reporting types
  • Regular reports
  • Reports on request
Resource tagging
No
FOCUS resource tagging
No

Resellers

Supplier type
Not a reseller

Staff security

Staff security clearance
Other security clearance
Government security clearance
Security Clearance (SC)

Asset protection

Knowledge of data storage and processing locations
Yes
Data storage and processing locations
United Kingdom
User control over data storage and processing locations
Yes
Datacentre security standards
Complies with a recognised standard (for example CSA CCM version 4.0)
Penetration testing frequency
At least once a year
Penetration testing approach
‘IT Health Check’ performed by a CHECK service provider
Protecting data at rest
  • Physical access control, complying with another standard
  • Encryption of all physical media
Data sanitisation process
Yes
Equipment disposal approach
Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
Data sanitisation type
  • Deleted data can’t be directly accessed / Cryptographic Erasure
  • Data Erasure

Data importing and exporting

Data export approach
Users can export data directly from FMIS Fixed Assets using built-in reporting and export tools. Data is available in standard formats including CSV and spreadsheet formats for reuse and analysis, and PDF for reporting and audit purposes. Where enabled, the FMIS Fixed Assets API may also be used to retrieve asset data programmatically to support agreed integration requirements. Export access is controlled by user permissions within the service.
Data export formats
  • CSV
  • Other
Other data export formats
PDF
Data import formats
  • CSV
  • Other

Data-in-transit protection

Data protection between buyer and supplier networks
TLS (version 1.2 or above)
Data protection within supplier network
  • TLS (version 1.2 or above)
  • Other
Other protection within supplier network
Data within the FMIS environment is protected through layered security controls, including network segmentation, firewalling and strict access controls between system components. Access is limited to authorised services and personnel, and security measures are monitored and maintained in line with FMIS information security policies and managed hosting provider standards.

Availability and resilience

Guaranteed availability
FMIS Fixed Asset Management is provided with a defined Availability Commitment as set out in the FMIS Licence Agreement and Schedule 2 (Service Level Targets). FMIS commits to ensuring that the Service is available at least 99.9% of the time in each calendar month, excluding Scheduled Maintenance and Permitted Downtime. Service availability is monitored by FMIS.

Where FMIS does not meet the Availability Commitment, the matter will be reviewed in accordance with the service level provisions of the Agreement, and FMIS will work with the Customer in good faith to identify and implement appropriate remedial actions.

Planned maintenance is scheduled where reasonably practicable to minimise disruption and is communicated to customers in advance.
Approach to resilience
FMIS maintains business continuity and disaster recovery arrangements aligned with recognised information security and operational resilience standards, including ISO/IEC 27001. These arrangements are designed to support service recovery and continuity in the event of a significant incident and are reviewed as part of FMIS operational governance. Further details can be provided to buyers on request.
Outage reporting
In the event of a significant service outage, FMIS will notify affected customers by email with relevant information and updates as appropriate. Minor incidents or issues that do not materially impact service availability may be managed through normal support channels. Outage communication is handled in line with FMIS operational and support procedures.

Identity and authentication

User authentication needed
Yes
User authentication
  • Multi-Factor Authentication (MFA)
  • Username or password
Access restrictions in management interfaces and support channels
Access to management interfaces and support systems is restricted to authorised FMIS personnel and customer users based on defined roles and responsibilities. Role-based access controls are used to limit access to functions and data appropriate to each user. Administrative access is granted only where required and is subject to approval and review. Access to support channels is controlled, with requests authenticated before actions are taken. Access rights are reviewed and updated as roles change.
Access restriction testing frequency
At least once a year
Management access authentication
  • Multi-Factor Authentication (MFA)
  • Username or password

Audit information for users

Access to user activity audit information
Users have access to real-time audit information
How long user audit data is stored for
At least 12 months
Access to supplier activity audit information
Users have access to real-time audit information
How long supplier audit data is stored for
At least 12 months
How long system logs are stored for
Between 1 month and 6 months

Security governance

Named board-level person responsible for service security
Yes
Security governance certified
Yes
Security governance standards
  • ISO/IEC 27001
  • Other
Other security governance standards
Cyber Essentials Plus
Information security policies and processes
FMIS operates a formal information security management framework aligned with ISO/IEC 27001. This includes documented policies covering areas such as access control, data protection, incident management, supplier security, change management and business continuity. Policies are approved by senior management and reviewed regularly to ensure continued relevance and effectiveness.

Information security governance is overseen by the FMIS Data Protection and Information Security Lead, with reporting to senior management. Compliance with policies is supported through defined procedures, staff awareness, role-based access controls and ongoing operational monitoring. Security incidents are recorded, assessed and managed in line with documented processes, with corrective actions implemented where required. Policies and controls are reviewed as part of internal audits and continuous improvement activities.
Software Security Code of Practice
Yes

Operational security

Configuration and change management standard
Supplier-defined controls
Configuration and change management approach
FMIS maintains documented configuration and change management processes to control changes to the service throughout its lifecycle. Service components and configurations are tracked and managed through defined procedures and system records. Proposed changes are assessed for operational and security impact before implementation, with appropriate approval and testing applied. Changes are implemented in a controlled manner and, where appropriate, reviewed post-implementation to ensure service stability and security are maintained.
Vulnerability management type
Supplier-defined controls
Vulnerability management approach
FMIS operates a structured vulnerability management process to identify, assess and remediate security risks affecting the service. Potential threats are assessed based on severity, exploitability and impact to the service. Vulnerability information is obtained from software vendors, managed hosting providers and recognised security advisories. Security patches and updates are prioritised and deployed in line with risk, using controlled change management processes to ensure service stability and security are maintained.
Protective monitoring type
Supplier-defined controls
Protective monitoring approach
FMIS operates protective monitoring processes to identify potential security incidents affecting the service. Monitoring includes review of system activity, alerts from hosting providers and security tooling, and investigation of anomalous behaviour. When a potential compromise is identified, incidents are assessed, contained and remediated in line with documented incident management procedures. Incidents are prioritised based on severity and impact, with response actions initiated promptly in accordance with internal escalation and communication processes.
Incident management type
Supplier-defined controls
Incident management approach
FMIS maintains documented incident management processes for responding to security and service incidents, including pre-defined procedures for common event types. Users can report incidents through established support channels, including email and phone. Incidents are logged, assessed and managed in line with internal procedures. Where appropriate, incident updates and summary reports are provided to affected customers through agreed communication channels.
Post-quantum cryptography secure
No

Secure development

Approach to secure software development best practice
Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)

Public sector networks

Connection to public sector networks
No

Pricing

Discount for educational organisations
Yes
Free trial available
No

Discount percentage by annual call-off contract value (excluding VAT)

Less than £250,000
0%
Between £250,000 and £500,000
2%
Between £500,001 and £1,000,000
4%
Between £1,000,001 and £2,500,000
6%
Between £2,500,001 and £5,000,000
8%
Over £5,000,001
10%

Non-mandatory Standards and certifications

ISO/IEC 27001 certification
Yes
Who accredited the ISO/IEC 27001
ASCB
ISO/IEC 27001 accreditation date
Friday 10 May 2019
What the ISO/IEC 27001 doesn’t cover
The ISO/IEC 27001 certification applies to FMIS’s information security management system and the delivery of FMIS cloud-hosted services. It does not extend to customer-managed environments, customer end-user devices, third-party systems not under FMIS control, or services operated independently by customers outside the FMIS platform.
ISO 28000:2022 certification
No
ISO 9001 certification
Yes
Who accredited the ISO 9001 certification
ASCB
ISO 9001 accreditation date
Monday 3 December 2018
What the ISO 9001 doesn’t cover
The ISO 9001 certification applies to FMIS’s quality management system and the processes used to deliver FMIS software and associated services. It does not cover customer-managed processes, customer use of the software, or third-party services and suppliers that are not under FMIS operational control.
Quality management systems (QMS)
Yes
CSA STAR certification
No
PCI certification
No
Cyber essentials
Yes
Please provide your Cyber Essentials Certificate Number
A1c5bc50-1b06-45b6-afea-4518af5903c4
Cyber essentials plus
Yes
Please provide your Cyber Essentials Plus Certificate Number
2ccdf53b-b352-444b-b04d-8e51db30fa51
Other security certifications
No

Social value

Section B - Commitment for Future: Delivery
  • Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero

    Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.

    • Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at johnderobeck@fmis.co.uk. Tell them what format you need. It will help if you say what assistive technology you use.