← Back to search results

planningFind a Tender · planning

DDaT Enterprise GRC Tooling

Buyer: NHS Business Services Authority →

BuyerNHS Business Services Authority
Statusplanning
DeadlineNot published
Value£350,000
Published6 Mar 2026

What is being bought

The purpose of this Request for Information (RFI) is to conduct market research to identify Governance, Risk and Compliance (GRC) tooling that could support DDaT governance activities. We are seeking information on platforms or tools that enable: 1. Risk Management 2. Audit Management 3. Compliance Management

Categories

IT software package 48517000IT services: consulting, software development, Internet and support 72000000

Lot details

Lot 1

No lot description published.

Statusplanning
Contract periodFrom 1 Oct 2026 to 30 Sept 2028
SME suitabilitySuitable for SMEs

What is included

ItemCategoryQuantity
1IT software package, IT services: consulting, software development, Internet and supportNot published

Comparable-procurement analytics

Benchmarked against retained Find a Tender procedures with CPV division 48. The category anchor is IT software package (48517000); this is a deliberately broad market comparator. The comparison is shown at several levels rather than pretending one company or region is always the best benchmark.

Comparison setProceduresReported bids per procedureNamed award suppliersPrice evidence
Market: CPV division 482,5761 median · 6.1 average (785 of 2,576 with a bid count)1.5 average (851 of 2,576 with named award suppliers)Not published
Same buyer12Not publishedNot publishedNot published
Similar published value (0.5×–2×)238Not publishedNot publishedNot published

“Reported bids” is an official aggregate, sometimes reported per lot; it is the closest available competition measure. “Named award suppliers” are winners, not all applicants.

Price-outcome signal

Not enough comparable procedures currently publish both a GBP tender value and a usable lowest-valid-bid value to calculate a responsible price-reduction benchmark. Tenderline deliberately does not infer a saving from named award suppliers or from missing award values.

Procurement strategy & market signals

Framework agreementNot published
Dynamic purchasing systemNot published
Competitive procurementNot published
Recurring requirementNot published
Procurement method rationaleNot published
Rationale classificationsNot published
Special regimeNot published
Covered byNot published
Submission policyNot published
Selection criteriaNot published
Risk detailsNot published

Planning & early market engagement

BudgetValue not published
No-engagement rationaleNot published
Planning documents1
Planning milestones1
MilestoneTypeDueStatus
The NHS Business Services Authority (NHSBSA) is an Arm’s Length Body of the Department of Health and Social Care, responsible for providing platforms and delivering services that support the priorities of the NHS, Government and local health economies. Over £100 billion of NHS spend flows through our systems annually. Our purpose is to deliver business service excellence to the NHS to help people live longer, healthier lives. Our vision is to be the provider of national, at scale business services for the health and social care system, transforming and delivering these services to maximise efficiency and meet customer expectations. As part of strengthening our governance capability, we are seeking to move beyond fragmented processes and manual reporting towards a dynamic, insight-driven Governance, Risk and Compliance (GRC) environment. Our ambition is to implement tooling that: • Provides near real-time visibility across organisational risk, audit, and compliance activities • Enables clear traceability between risks, controls, compliance obligations, and audit activity • Records a full history of changes to risks, controls, compliance items, and evidence, maintaining audit trails and version tracking for transparency and accountability • Supports proactive risk management and assurance, rather than retrospective reporting • Enables trend analysis and thematic insight across the organisation • Reduces duplication of effort through control reuse and structured assurance mapping • Improves accountability through clear ownership, workflow, and approval processes We are particularly interested in solutions that: • Treat GRC as an interconnected system rather than isolated processes • Provide intuitive dashboards suitable for senior leadership and governance reporting • Enable monitoring of control effectiveness and impact analysis across multiple domains • Maintain a full historical record of changes to support governance, oversight, and assurance reporting • Support scalable governance maturity over time The ambition is not merely to digitise existing processes, but to strengthen decision-making, organisational oversight, and enterprise-wide transparency through structured, connected GRC tooling. Use of Artificial Intelligence and Automation We recognise that modern Governance, Risk and Compliance (GRC) platforms increasingly incorporate artificial intelligence (AI), machine learning, and intelligent automation capabilities. As part of this market engagement, we are interested in understanding how AI-enabled functionality could enhance: • Risk identification and trend detection • Predictive risk analysis and early warning indicators • Automated control monitoring and anomaly detection • Intelligent workflow routing and prioritisation • Evidence reviews and document classification • Thematic analysis across audit findings, risks and compliance data • Reduction of manual administrative burden Any AI capability should: • Be transparent and explainable in its outputs • Support human oversight and governance decision-making • Operate within appropriate data protection, security and ethical boundaries • Clearly describe model training sources and data usage (where applicable) We are seeking insight into both current AI functionality and planned roadmap developments. Please download the documentation and send your response to this RFI via the Atamis portal ( https://atamis-1928.my.site.com/s/Welcome).engagement10 Apr 2026scheduled

Related procurements

No linked framework, prior procurement or reprocurement published.

Documents & submission route

Source data inventory

Diagnostic view. “Not published” means this current release does not provide a value.

OCIDocds-h6vhtk-066447
Latest release ID020446-2026
Latest release timestampFri Mar 06 2026 14:11:18 GMT+0000 (Coordinated Universal Time)
Sourcefind-a-tender
Official notice URLNot published
Tender statusplanning
Procurement methodNot published
Procurement method detailsNot published
Main procurement categoryservices
Above thresholdYes
Legal basis2023/54
Tender period: startNot published
Tender period: endNot published
Expression of interest deadlineNot published
Enquiry deadlineNot published
Award period: startNot published
Award period: endNot published
Submission method detailsNot published
Submission languagesNot published
Electronic catalogue policyNot published
Total tender value£350,000
Tender lots in source1
Tender items in source1
Tender documents in source0
Awards in latest release0
Contracts in latest release0
Parties in latest release1

Notice history

DateEventReference
6 Mar 2026planning020446-2026

All source data

Unmodified official OCDS data retained by Tenderline for this procurement process.

Complete current OCDS release JSON
{
  "id": "020446-2026",
  "tag": [
    "planning"
  ],
  "date": "2026-03-06T14:11:18Z",
  "ocid": "ocds-h6vhtk-066447",
  "buyer": {
    "id": "GB-PPON-PRLZ-1599-JGTT",
    "name": "NHS Business Services Authority"
  },
  "tender": {
    "id": "C429685",
    "lots": [
      {
        "id": "1",
        "status": "planning",
        "suitability": {
          "sme": true
        },
        "contractPeriod": {
          "endDate": "2028-09-30T23:59:59+01:00",
          "startDate": "2026-10-01T00:00:00+01:00"
        }
      }
    ],
    "items": [
      {
        "id": "1",
        "relatedLot": "1",
        "additionalClassifications": [
          {
            "id": "48517000",
            "scheme": "CPV",
            "description": "IT software package"
          },
          {
            "id": "72000000",
            "scheme": "CPV",
            "description": "IT services: consulting, software development, Internet and support"
          }
        ]
      }
    ],
    "title": "DDaT Enterprise GRC Tooling",
    "value": {
      "amount": 350000,
      "currency": "GBP",
      "amountGross": 420000
    },
    "status": "planning",
    "legalBasis": {
      "id": "2023/54",
      "uri": "https://www.legislation.gov.uk/ukpga/2023/54/contents",
      "scheme": "UKPGA"
    },
    "description": "The purpose of this Request for Information (RFI) is to conduct market research to identify Governance, Risk and Compliance (GRC) tooling that could support DDaT governance activities.\nWe are seeking information on platforms or tools that enable:\n1. Risk Management\n2. Audit Management\n3. Compliance Management",
    "aboveThreshold": true,
    "mainProcurementCategory": "services"
  },
  "parties": [
    {
      "id": "GB-PPON-PRLZ-1599-JGTT",
      "name": "NHS Business Services Authority",
      "roles": [
        "buyer"
      ],
      "address": {
        "region": "UKC22",
        "country": "GB",
        "locality": "Newcastle upon Tyne",
        "postalCode": "NE15 8NY",
        "countryName": "United Kingdom",
        "streetAddress": "Stella House, Goldcrest Way, Newburn Riverside"
      },
      "details": {
        "url": "https://www.nhsbsa.nhs.uk/",
        "classifications": [
          {
            "id": "publicAuthorityCentralGovernment",
            "scheme": "UK_CA_TYPE",
            "description": "Public authority - central government"
          }
        ]
      },
      "identifier": {
        "id": "PRLZ-1599-JGTT",
        "scheme": "GB-PPON"
      },
      "contactPoint": {
        "email": "nhsbsa.commercialservicesteam@nhsbsa.nhs.uk"
      }
    }
  ],
  "language": "en",
  "planning": {
    "documents": [
      {
        "id": "020446-2026",
        "url": "https://www.find-tender.service.gov.uk/Notice/020446-2026",
        "format": "text/html",
        "noticeType": "UK2",
        "description": "Preliminary market engagement notice on Find a Tender",
        "documentType": "marketEngagementNotice",
        "datePublished": "2026-03-06T14:11:18Z"
      }
    ],
    "milestones": [
      {
        "id": "engagement",
        "type": "engagement",
        "status": "scheduled",
        "dueDate": "2026-04-10T23:59:59+01:00",
        "description": "The NHS Business Services Authority (NHSBSA) is an Arm’s Length Body of the Department of Health and Social Care, responsible for providing platforms and delivering services that support the priorities of the NHS, Government and local health economies. Over £100 billion of NHS spend flows through our systems annually.\nOur purpose is to deliver business service excellence to the NHS to help people live longer, healthier lives. Our vision is to be the provider of national, at scale business services for the health and social care system, transforming and delivering these services to maximise efficiency and meet customer expectations.\nAs part of strengthening our governance capability, we are seeking to move beyond fragmented processes and manual reporting towards a dynamic, insight-driven Governance, Risk and Compliance (GRC) environment.\nOur ambition is to implement tooling that:\n• Provides near real-time visibility across organisational risk, audit, and compliance activities\n• Enables clear traceability between risks, controls, compliance obligations, and audit activity\n• Records a full history of changes to risks, controls, compliance items, and evidence, maintaining audit trails and version tracking for transparency and accountability\n• Supports proactive risk management and assurance, rather than retrospective reporting\n• Enables trend analysis and thematic insight across the organisation\n• Reduces duplication of effort through control reuse and structured assurance mapping\n• Improves accountability through clear ownership, workflow, and approval processes\nWe are particularly interested in solutions that:\n• Treat GRC as an interconnected system rather than isolated processes\n• Provide intuitive dashboards suitable for senior leadership and governance reporting\n• Enable monitoring of control effectiveness and impact analysis across multiple domains\n• Maintain a full historical record of changes to support governance, oversight, and assurance reporting\n• Support scalable governance maturity over time\nThe ambition is not merely to digitise existing processes, but to strengthen decision-making, organisational oversight, and enterprise-wide transparency through structured, connected GRC tooling.\nUse of Artificial Intelligence and Automation\nWe recognise that modern Governance, Risk and Compliance (GRC) platforms increasingly incorporate artificial intelligence (AI), machine learning, and intelligent automation capabilities.\nAs part of this market engagement, we are interested in understanding how AI-enabled functionality could enhance:\n• Risk identification and trend detection\n• Predictive risk analysis and early warning indicators\n• Automated control monitoring and anomaly detection\n• Intelligent workflow routing and prioritisation\n• Evidence reviews and document classification\n• Thematic analysis across audit findings, risks and compliance data\n• Reduction of manual administrative burden\nAny AI capability should:\n• Be transparent and explainable in its outputs\n• Support human oversight and governance decision-making\n• Operate within appropriate data protection, security and ethical boundaries\n• Clearly describe model training sources and data usage (where applicable)\nWe are seeking insight into both current AI functionality and planned roadmap developments.\nPlease download the documentation and send your response to this RFI via the Atamis portal ( https://atamis-1928.my.site.com/s/Welcome)."
      }
    ]
  },
  "initiationType": "tender"
}
Complete JSON history (1 releases)
6 Mar 2026 · 020446-2026 · planning
{
  "id": "020446-2026",
  "tag": [
    "planning"
  ],
  "date": "2026-03-06T14:11:18Z",
  "ocid": "ocds-h6vhtk-066447",
  "buyer": {
    "id": "GB-PPON-PRLZ-1599-JGTT",
    "name": "NHS Business Services Authority"
  },
  "tender": {
    "id": "C429685",
    "lots": [
      {
        "id": "1",
        "status": "planning",
        "suitability": {
          "sme": true
        },
        "contractPeriod": {
          "endDate": "2028-09-30T23:59:59+01:00",
          "startDate": "2026-10-01T00:00:00+01:00"
        }
      }
    ],
    "items": [
      {
        "id": "1",
        "relatedLot": "1",
        "additionalClassifications": [
          {
            "id": "48517000",
            "scheme": "CPV",
            "description": "IT software package"
          },
          {
            "id": "72000000",
            "scheme": "CPV",
            "description": "IT services: consulting, software development, Internet and support"
          }
        ]
      }
    ],
    "title": "DDaT Enterprise GRC Tooling",
    "value": {
      "amount": 350000,
      "currency": "GBP",
      "amountGross": 420000
    },
    "status": "planning",
    "legalBasis": {
      "id": "2023/54",
      "uri": "https://www.legislation.gov.uk/ukpga/2023/54/contents",
      "scheme": "UKPGA"
    },
    "description": "The purpose of this Request for Information (RFI) is to conduct market research to identify Governance, Risk and Compliance (GRC) tooling that could support DDaT governance activities.\nWe are seeking information on platforms or tools that enable:\n1. Risk Management\n2. Audit Management\n3. Compliance Management",
    "aboveThreshold": true,
    "mainProcurementCategory": "services"
  },
  "parties": [
    {
      "id": "GB-PPON-PRLZ-1599-JGTT",
      "name": "NHS Business Services Authority",
      "roles": [
        "buyer"
      ],
      "address": {
        "region": "UKC22",
        "country": "GB",
        "locality": "Newcastle upon Tyne",
        "postalCode": "NE15 8NY",
        "countryName": "United Kingdom",
        "streetAddress": "Stella House, Goldcrest Way, Newburn Riverside"
      },
      "details": {
        "url": "https://www.nhsbsa.nhs.uk/",
        "classifications": [
          {
            "id": "publicAuthorityCentralGovernment",
            "scheme": "UK_CA_TYPE",
            "description": "Public authority - central government"
          }
        ]
      },
      "identifier": {
        "id": "PRLZ-1599-JGTT",
        "scheme": "GB-PPON"
      },
      "contactPoint": {
        "email": "nhsbsa.commercialservicesteam@nhsbsa.nhs.uk"
      }
    }
  ],
  "language": "en",
  "planning": {
    "documents": [
      {
        "id": "020446-2026",
        "url": "https://www.find-tender.service.gov.uk/Notice/020446-2026",
        "format": "text/html",
        "noticeType": "UK2",
        "description": "Preliminary market engagement notice on Find a Tender",
        "documentType": "marketEngagementNotice",
        "datePublished": "2026-03-06T14:11:18Z"
      }
    ],
    "milestones": [
      {
        "id": "engagement",
        "type": "engagement",
        "status": "scheduled",
        "dueDate": "2026-04-10T23:59:59+01:00",
        "description": "The NHS Business Services Authority (NHSBSA) is an Arm’s Length Body of the Department of Health and Social Care, responsible for providing platforms and delivering services that support the priorities of the NHS, Government and local health economies. Over £100 billion of NHS spend flows through our systems annually.\nOur purpose is to deliver business service excellence to the NHS to help people live longer, healthier lives. Our vision is to be the provider of national, at scale business services for the health and social care system, transforming and delivering these services to maximise efficiency and meet customer expectations.\nAs part of strengthening our governance capability, we are seeking to move beyond fragmented processes and manual reporting towards a dynamic, insight-driven Governance, Risk and Compliance (GRC) environment.\nOur ambition is to implement tooling that:\n• Provides near real-time visibility across organisational risk, audit, and compliance activities\n• Enables clear traceability between risks, controls, compliance obligations, and audit activity\n• Records a full history of changes to risks, controls, compliance items, and evidence, maintaining audit trails and version tracking for transparency and accountability\n• Supports proactive risk management and assurance, rather than retrospective reporting\n• Enables trend analysis and thematic insight across the organisation\n• Reduces duplication of effort through control reuse and structured assurance mapping\n• Improves accountability through clear ownership, workflow, and approval processes\nWe are particularly interested in solutions that:\n• Treat GRC as an interconnected system rather than isolated processes\n• Provide intuitive dashboards suitable for senior leadership and governance reporting\n• Enable monitoring of control effectiveness and impact analysis across multiple domains\n• Maintain a full historical record of changes to support governance, oversight, and assurance reporting\n• Support scalable governance maturity over time\nThe ambition is not merely to digitise existing processes, but to strengthen decision-making, organisational oversight, and enterprise-wide transparency through structured, connected GRC tooling.\nUse of Artificial Intelligence and Automation\nWe recognise that modern Governance, Risk and Compliance (GRC) platforms increasingly incorporate artificial intelligence (AI), machine learning, and intelligent automation capabilities.\nAs part of this market engagement, we are interested in understanding how AI-enabled functionality could enhance:\n• Risk identification and trend detection\n• Predictive risk analysis and early warning indicators\n• Automated control monitoring and anomaly detection\n• Intelligent workflow routing and prioritisation\n• Evidence reviews and document classification\n• Thematic analysis across audit findings, risks and compliance data\n• Reduction of manual administrative burden\nAny AI capability should:\n• Be transparent and explainable in its outputs\n• Support human oversight and governance decision-making\n• Operate within appropriate data protection, security and ethical boundaries\n• Clearly describe model training sources and data usage (where applicable)\nWe are seeking insight into both current AI functionality and planned roadmap developments.\nPlease download the documentation and send your response to this RFI via the Atamis portal ( https://atamis-1928.my.site.com/s/Welcome)."
      }
    ]
  },
  "initiationType": "tender"
}