BETAThis is a new independent transparency project, not an official government website. The data is sourced from public registers and may contain errors, so always verify against the official source. If you find a problem, please report it here.
DELTA Access Code :4J4GPFS79V
Description
The Authority aims to procure a scalable, integrated Governance, Risk and Compliance (GRC) software solution, capable of supporting its organisational growth and any required regulatory obligations. The solution is intended to consolidate risk data from across the Authority into a single platform that strengthens oversight, enhances analysis & reporting, improves operational efficiency, and ensures accountability. A GRC tool may also provide the opportunity to identify data synergies and move away from several systems used across the Authority.
Strategic Objectives
Integrated View of the Risk and Control Environment
A unified cloud-based platform will provide a single source of truth for risks, controls, incidents, actions and metrics. Full traceability will be maintained across taxonomies, business units, policies and key processes, improving framework integration, transparency and decision-making.
Data Driven Culture and Analytics
The system will enable trend analysis, early warning indicators and data driven insights to support proactive management of current and emerging risks.
Operational Efficiency and Improved Ownership
An intuitive user experience, default ‘outofthebox’ configurability, guided workflows and automation will reduce manual effort and embed firstline ownership of risks and controls, while supporting second line oversight and challenge.
High Quality Data and Reporting
Automated dashboards and configurable reporting to the Microsoft Office suite will streamline internal and external stakeholder reporting, including for senior management, committees and regulators.
Assurance and Regulatory Compliance
The platform will facilitate compliance with the UK Corporate Governance Code (including Provision 29) and relevant FCA expectations. Evidence trails, compliance monitoring and control testing will support a robust assurance framework.
Core Capability Requirements
Initial core capability requirements have been identified, with activities still ongoing to define the full scope of requirements and determine the business units which a GRC tool may be implemented into. A full prioritised list of requirements and business units identified as part of ongoing activities, will be incorporated into future specifications.
The current core GRC solution must support, but not be limited to the following key modules:
Risk & Control Management
Control Testing
Data, Reporting & Analytics
Risk Appetite & Key Risk Indicators
Incident Management
Policy Management
Regulatory Compliance
Ethics & Integrity
Internal Audit
Non-Core Capabilities
While not central to the initial procurement, the system should also be capable of supporting:
| Supplier | Identifier | Award Value | Lots Won | Cross-References |
|---|---|---|---|---|
| Decision Focus | Procurement ID: PDRQ-4187-JNMR | £1,100,000 | 1 lot Lot 1 | - |
Taken from this notice, not from Companies House. Check the original notice — details change and are not updated here.
This procurement was divided into 1 lots, each awarded separately. 21 bids were received in total.
| Lot | Value | Bids Received | Awarded To | Status |
|---|---|---|---|---|
| Lot 1 Oct 2026 – Oct 2032 | £1,100,000 | 21 | Decision Focus | active |
Weightings from the notice.