← Back to search results

ClosedFind a Tender · UK4

Governance Risk and Compliance tool

Buyer: British Business Bank Plc →

Participate on delta-esourcing.com ↗External submission platform

BuyerBritish Business Bank Plc
StatusClosed
Deadline5 Jun 2026
Value£1,100,000
Published21 May 2026

What is being bought

DELTA Access Code :4J4GPFS79V Description The Authority aims to procure a scalable, integrated Governance, Risk and Compliance (GRC) software solution, capable of supporting its organisational growth and any required regulatory obligations. The solution is intended to consolidate risk data from across the Authority into a single platform that strengthens oversight, enhances analysis & reporting, improves operational efficiency, and ensures accountability. A GRC tool may also provide the opportunity to identify data synergies and move away from several systems used across the Authority. Strategic Objectives Integrated View of the Risk and Control Environment A unified cloud-based platform will provide a single source of truth for risks, controls, incidents, actions and metrics. Full traceability will be maintained across taxonomies, business units, policies and key processes, improving framework integration, transparency and decision-making. Data Driven Culture and Analytics The system will enable trend analysis, early warning indicators and data driven insights to support proactive management of current and emerging risks. Operational Efficiency and Improved Ownership An intuitive user experience, default ‘outofthebox’ configurability, guided workflows and automation will reduce manual effort and embed firstline ownership of risks and controls, while supporting second line oversight and challenge. High Quality Data and Reporting Automated dashboards and configurable reporting to the Microsoft Office suite will streamline internal and external stakeholder reporting, including for senior management, committees and regulators. Assurance and Regulatory Compliance The platform will facilitate compliance with the UK Corporate Governance Code (including Provision 29) and relevant FCA expectations. Evidence trails, compliance monitoring and control testing will support a robust assurance framework. Core Capability Requirements Initial core capability requirements have been identified, with activities still ongoing to define the full scope of requirements and determine the business units which a GRC tool may be implemented into. A full prioritised list of requirements and business units identified as part of ongoing activities, will be incorporated into future specifications. The current core GRC solution must support, but not be limited to the following key modules: Risk & Control Management - Risk and control library - RCSA: inherent/residual assessments, control tiering and assessments, risk acceptances and outoftolerance management - Heat maps, bow ties and risk scoring matrices - Control improvement actions - Endtoend traceability of risk, control and incident data by risk taxonomy, business unit, policy suite, and key processes Control Testing - Structured workflows, evidence capture and reporting to support assurance activities. Data, Reporting & Analytics - Configurable automated reporting - UK Corporate Governance Code Provision 29aligned reporting - Data ingestion from internal and external sources - Use of AIassisted tooling where appropriate Risk Appetite & Key Risk Indicators - Capture, monitoring and reporting of KRIs and risk appetite metrics. Incident Management - Central reporting portal - End to end incident lifecycle management, including automations - Metrics and trend analysis Policy Management - Governance and maintenance of the policy suite - Evidence based assessment of policy effectiveness using risk, control, testing and incident data Regulatory Compliance - Compliance monitoring plan execution - Horizon scanning and analysis of regulatory changes - Impact assessment of external developments on the control environment Ethics & Integrity - Management and reporting of gifts and hospitality, conflicts of interest, personal account dealing and insider lists. Internal Audit - Audit planning and delivery workflows - Action tracking and reporting Non-Core Capabilities While not central to the initial procurement, the system should also be capable of supporting: - Business continuity and resilience - Programme/project risk management - Third party risk management

Delivery location

UK, GB

Categories

Compliance software development services 72212170Financial systems software development services 72212442Corporate governance rating services 79212110Risk or hazard assessment other than for construction 90711100

Lot details

Lot 1

No lot description published.

Statusactive
Value£1,100,000
Contract periodFrom 6 Oct 2026 to 5 Oct 2032
SME suitabilitySuitable for SMEs

Award criteria
Commercial Offer (35%)
Quality Criteria (65%)

What is included

ItemCategoryQuantity
1Compliance software development services, Financial systems software development services, Corporate governance rating services, Risk or hazard assessment other than for constructionNot published

Comparable-procurement analytics

Benchmarked against retained Find a Tender procedures with CPV division 72. The category anchor is Compliance software development services (72212170); this is a deliberately broad market comparator. The comparison is shown at several levels rather than pretending one company or region is always the best benchmark.

Comparison setProceduresReported bids per procedureNamed award suppliersPrice evidence
Market: CPV division 726,9771 median · 15.3 average (2,625 of 6,977 with a bid count)1.9 average (3,127 of 6,977 with named award suppliers)Not published
Same buyer7Not publishedNot publishedNot published
Delivery region: UK2,2031 median · 32 average (738 of 2,203 with a bid count)2.8 average (944 of 2,203 with named award suppliers)Not published
Similar published value (0.5×–2×)3903.5 median · 10.3 average (4 of 390 with a bid count)2.3 average (4 of 390 with named award suppliers)Not published

“Reported bids” is an official aggregate, sometimes reported per lot; it is the closest available competition measure. “Named award suppliers” are winners, not all applicants.

Price-outcome signal

Not enough comparable procedures currently publish both a GBP tender value and a usable lowest-valid-bid value to calculate a responsible price-reduction benchmark. Tenderline deliberately does not infer a saving from named award suppliers or from missing award values.

Procurement strategy & market signals

Framework agreementNot published
Dynamic purchasing systemNot published
Competitive procurementNot published
Recurring requirementNot published
Procurement method rationaleNot published
Rationale classificationsNot published
Special regimeNot published
Covered byGPA
Submission policyallowed
Selection criteriaNot published
Risk detailsNot published

Planning & early market engagement

BudgetNot published
No-engagement rationaleNot published
Planning documents0
Planning milestones0

No planning milestones published.

Related procurements

No linked framework, prior procurement or reprocurement published.

Documents & submission route

Source data inventory

Diagnostic view. “Not published” means this current release does not provide a value.

OCIDocds-h6vhtk-067195
Latest release ID047427-2026
Latest release timestampThu May 21 2026 16:57:42 GMT+0000 (Coordinated Universal Time)
Sourcefind-a-tender
Official notice URLhttps://www.find-tender.service.gov.uk/Notice/047427-2026
Tender statusactive
Procurement methodopen
Procurement method detailsCompetitive flexible procedure
Main procurement categoryservices
Above thresholdYes
Legal basis2023/54
Tender period: startNot published
Tender period: endNot published
Expression of interest deadline2026-06-05T12:00:00+01:00
Enquiry deadline2026-05-29T12:00:00+01:00
Award period: startNot published
Award period: end2026-09-22T23:59:59+01:00
Submission method detailshttps://www.delta-esourcing.com/respond/4J4GPFS79V
Submission languagesen
Electronic catalogue policyNot published
Total tender value£1,100,000
Tender lots in source1
Tender items in source1
Tender documents in source2
Awards in latest release0
Contracts in latest release0
Parties in latest release1

Notice history

DateEventReference
21 May 2026tenderUpdate047427-2026
21 May 2026tenderUpdate047423-2026
21 May 2026tender047402-2026
23 Mar 2026planning026336-2026

All source data

Unmodified official OCDS data retained by Tenderline for this procurement process.

Complete current OCDS release JSON
{
  "id": "047427-2026",
  "tag": [
    "tenderUpdate"
  ],
  "date": "2026-05-21T17:57:42+01:00",
  "ocid": "ocds-h6vhtk-067195",
  "buyer": {
    "id": "GB-PPON-PGTM-8337-GYXM",
    "name": "British Business Bank Plc"
  },
  "tender": {
    "id": "ocds-h6vhtk-067195",
    "lots": [
      {
        "id": "1",
        "value": {
          "amount": 1100000,
          "currency": "GBP",
          "amountGross": 1320000
        },
        "status": "active",
        "renewal": {
          "description": "Optional 2 year extension is applicable to this contract"
        },
        "hasRenewal": true,
        "suitability": {
          "sme": true,
          "vcse": true
        },
        "awardCriteria": {
          "criteria": [
            {
              "name": "Commercial Offer",
              "type": "price",
              "numbers": [
                {
                  "number": 35,
                  "weight": "percentageExact"
                }
              ]
            },
            {
              "name": "Quality Criteria",
              "type": "quality",
              "numbers": [
                {
                  "number": 65,
                  "weight": "percentageExact"
                }
              ]
            }
          ]
        },
        "contractPeriod": {
          "endDate": "2032-10-05T23:59:59+01:00",
          "startDate": "2026-10-06T00:00:00+01:00",
          "maxExtentDate": "2034-10-05T23:59:59+01:00"
        }
      }
    ],
    "items": [
      {
        "id": "1",
        "relatedLot": "1",
        "deliveryAddresses": [
          {
            "region": "UK",
            "country": "GB",
            "countryName": "United Kingdom"
          }
        ],
        "additionalClassifications": [
          {
            "id": "72212170",
            "scheme": "CPV",
            "description": "Compliance software development services"
          },
          {
            "id": "72212442",
            "scheme": "CPV",
            "description": "Financial systems software development services"
          },
          {
            "id": "79212110",
            "scheme": "CPV",
            "description": "Corporate governance rating services"
          },
          {
            "id": "90711100",
            "scheme": "CPV",
            "description": "Risk or hazard assessment other than for construction"
          }
        ]
      }
    ],
    "title": "Governance Risk and Compliance tool",
    "value": {
      "amount": 1100000,
      "currency": "GBP",
      "amountGross": 1320000
    },
    "status": "active",
    "coveredBy": [
      "GPA"
    ],
    "documents": [
      {
        "id": "conflictOfInterest",
        "description": "Not published",
        "documentType": "conflictOfInterest"
      },
      {
        "id": "047427-2026",
        "url": "https://www.find-tender.service.gov.uk/Notice/047427-2026",
        "format": "text/html",
        "noticeType": "UK4",
        "description": "Tender notice on Find a Tender",
        "documentType": "tenderNotice",
        "datePublished": "2026-05-21T17:57:42+01:00"
      }
    ],
    "procedure": {
      "features": "Procurement Specific Questionnaire \nInvitation to Participate\nProof of Concepts",
      "isAccelerated": true,
      "acceleratedRationale": "Qualifying planned procurement notice"
    },
    "legalBasis": {
      "id": "2023/54",
      "uri": "https://www.legislation.gov.uk/ukpga/2023/54/contents",
      "scheme": "UKPGA"
    },
    "awardPeriod": {
      "endDate": "2026-09-22T23:59:59+01:00"
    },
    "description": "DELTA Access Code :4J4GPFS79V\nDescription \nThe Authority aims to procure a scalable, integrated Governance, Risk and Compliance (GRC) software solution, capable of supporting its organisational growth and any required regulatory obligations. The solution is intended to consolidate risk data from across the Authority into a single platform that strengthens oversight, enhances analysis & reporting, improves operational efficiency, and ensures accountability.  A GRC tool may also provide the opportunity to identify data synergies and move away from several systems used across the Authority. \nStrategic Objectives \nIntegrated View of the Risk and Control Environment \nA unified cloud-based platform will provide a single source of truth for risks, controls, incidents, actions and metrics. Full traceability will be maintained across taxonomies, business units, policies and key processes, improving framework integration, transparency and decision-making.  \nData Driven Culture and Analytics \nThe system will enable trend analysis, early warning indicators and data driven insights to support proactive management of current and emerging risks.  \nOperational Efficiency and Improved Ownership \nAn intuitive user experience, default ‘outofthebox’ configurability, guided workflows and automation will reduce manual effort and embed firstline ownership of risks and controls, while supporting second line oversight and challenge.  \nHigh Quality Data and Reporting \nAutomated dashboards and configurable reporting to the Microsoft Office suite will streamline internal and external stakeholder reporting, including for senior management, committees and regulators.  \nAssurance and Regulatory Compliance \nThe platform will facilitate compliance with the UK Corporate Governance Code (including Provision 29) and relevant FCA expectations. Evidence trails, compliance monitoring and control testing will support a robust assurance framework. \nCore Capability Requirements \nInitial core capability requirements have been identified, with activities still ongoing to define the full scope of requirements and determine the business units which a GRC tool may be implemented into. A full prioritised list of requirements and business units identified as part of ongoing activities, will be incorporated into future specifications. \nThe current core GRC solution must support, but not be limited to the following key modules: \nRisk & Control Management \n- Risk and control library \n- RCSA: inherent/residual assessments, control tiering and assessments, risk acceptances and outoftolerance management \n- Heat maps, bow ties and risk scoring matrices \n- Control improvement actions \n- Endtoend traceability of risk, control and incident data by risk taxonomy, business unit, policy suite, and key processes \nControl Testing \n- Structured workflows, evidence capture and reporting to support assurance activities.  \nData, Reporting & Analytics \n- Configurable automated reporting \n- UK Corporate Governance Code Provision 29aligned reporting \n- Data ingestion from internal and external sources \n- Use of AIassisted tooling where appropriate  \nRisk Appetite & Key Risk Indicators \n- Capture, monitoring and reporting of KRIs and risk appetite metrics.  \nIncident Management \n- Central reporting portal \n- End to end incident lifecycle management, including automations \n- Metrics and trend analysis  \nPolicy Management \n- Governance and maintenance of the policy suite \n- Evidence based assessment of policy effectiveness using risk, control, testing and incident data  \nRegulatory Compliance \n- Compliance monitoring plan execution \n- Horizon scanning and analysis of regulatory changes \n- Impact assessment of external developments on the control environment  \nEthics & Integrity \n- Management and reporting of gifts and hospitality, conflicts of interest, personal account dealing and insider lists.  \nInternal Audit \n- Audit planning and delivery workflows \n- Action tracking and reporting  \nNon-Core Capabilities \nWhile not central to the initial procurement, the system should also be capable of supporting: \n- Business continuity and resilience \n- Programme/project risk management \n- Third party risk management",
    "enquiryPeriod": {
      "endDate": "2026-05-29T12:00:00+01:00"
    },
    "aboveThreshold": true,
    "submissionTerms": {
      "languages": [
        "en"
      ],
      "electronicSubmissionPolicy": "allowed"
    },
    "procurementMethod": "open",
    "mainProcurementCategory": "services",
    "submissionMethodDetails": "https://www.delta-esourcing.com/respond/4J4GPFS79V",
    "procurementMethodDetails": "Competitive flexible procedure",
    "expressionOfInterestDeadline": "2026-06-05T12:00:00+01:00"
  },
  "parties": [
    {
      "id": "GB-PPON-PGTM-8337-GYXM",
      "name": "British Business Bank Plc",
      "roles": [
        "buyer"
      ],
      "address": {
        "region": "UKE32",
        "country": "GB",
        "locality": "Sheffield",
        "postalCode": "S1 2GQ",
        "countryName": "United Kingdom",
        "streetAddress": "2, West Street"
      },
      "details": {
        "classifications": [
          {
            "id": "publicAuthorityCentralGovernment",
            "scheme": "UK_CA_TYPE",
            "description": "Public authority - central government"
          }
        ]
      },
      "identifier": {
        "id": "PGTM-8337-GYXM",
        "scheme": "GB-PPON"
      },
      "contactPoint": {
        "name": "Procurement",
        "email": "procurement@british-business-bank.co.uk",
        "telephone": "01142502892"
      }
    }
  ],
  "language": "en",
  "initiationType": "tender"
}
Complete JSON history (4 releases)
21 May 2026 · 047427-2026 · tenderUpdate
{
  "id": "047427-2026",
  "tag": [
    "tenderUpdate"
  ],
  "date": "2026-05-21T17:57:42+01:00",
  "ocid": "ocds-h6vhtk-067195",
  "buyer": {
    "id": "GB-PPON-PGTM-8337-GYXM",
    "name": "British Business Bank Plc"
  },
  "tender": {
    "id": "ocds-h6vhtk-067195",
    "lots": [
      {
        "id": "1",
        "value": {
          "amount": 1100000,
          "currency": "GBP",
          "amountGross": 1320000
        },
        "status": "active",
        "renewal": {
          "description": "Optional 2 year extension is applicable to this contract"
        },
        "hasRenewal": true,
        "suitability": {
          "sme": true,
          "vcse": true
        },
        "awardCriteria": {
          "criteria": [
            {
              "name": "Commercial Offer",
              "type": "price",
              "numbers": [
                {
                  "number": 35,
                  "weight": "percentageExact"
                }
              ]
            },
            {
              "name": "Quality Criteria",
              "type": "quality",
              "numbers": [
                {
                  "number": 65,
                  "weight": "percentageExact"
                }
              ]
            }
          ]
        },
        "contractPeriod": {
          "endDate": "2032-10-05T23:59:59+01:00",
          "startDate": "2026-10-06T00:00:00+01:00",
          "maxExtentDate": "2034-10-05T23:59:59+01:00"
        }
      }
    ],
    "items": [
      {
        "id": "1",
        "relatedLot": "1",
        "deliveryAddresses": [
          {
            "region": "UK",
            "country": "GB",
            "countryName": "United Kingdom"
          }
        ],
        "additionalClassifications": [
          {
            "id": "72212170",
            "scheme": "CPV",
            "description": "Compliance software development services"
          },
          {
            "id": "72212442",
            "scheme": "CPV",
            "description": "Financial systems software development services"
          },
          {
            "id": "79212110",
            "scheme": "CPV",
            "description": "Corporate governance rating services"
          },
          {
            "id": "90711100",
            "scheme": "CPV",
            "description": "Risk or hazard assessment other than for construction"
          }
        ]
      }
    ],
    "title": "Governance Risk and Compliance tool",
    "value": {
      "amount": 1100000,
      "currency": "GBP",
      "amountGross": 1320000
    },
    "status": "active",
    "coveredBy": [
      "GPA"
    ],
    "documents": [
      {
        "id": "conflictOfInterest",
        "description": "Not published",
        "documentType": "conflictOfInterest"
      },
      {
        "id": "047427-2026",
        "url": "https://www.find-tender.service.gov.uk/Notice/047427-2026",
        "format": "text/html",
        "noticeType": "UK4",
        "description": "Tender notice on Find a Tender",
        "documentType": "tenderNotice",
        "datePublished": "2026-05-21T17:57:42+01:00"
      }
    ],
    "procedure": {
      "features": "Procurement Specific Questionnaire \nInvitation to Participate\nProof of Concepts",
      "isAccelerated": true,
      "acceleratedRationale": "Qualifying planned procurement notice"
    },
    "legalBasis": {
      "id": "2023/54",
      "uri": "https://www.legislation.gov.uk/ukpga/2023/54/contents",
      "scheme": "UKPGA"
    },
    "awardPeriod": {
      "endDate": "2026-09-22T23:59:59+01:00"
    },
    "description": "DELTA Access Code :4J4GPFS79V\nDescription \nThe Authority aims to procure a scalable, integrated Governance, Risk and Compliance (GRC) software solution, capable of supporting its organisational growth and any required regulatory obligations. The solution is intended to consolidate risk data from across the Authority into a single platform that strengthens oversight, enhances analysis & reporting, improves operational efficiency, and ensures accountability.  A GRC tool may also provide the opportunity to identify data synergies and move away from several systems used across the Authority. \nStrategic Objectives \nIntegrated View of the Risk and Control Environment \nA unified cloud-based platform will provide a single source of truth for risks, controls, incidents, actions and metrics. Full traceability will be maintained across taxonomies, business units, policies and key processes, improving framework integration, transparency and decision-making.  \nData Driven Culture and Analytics \nThe system will enable trend analysis, early warning indicators and data driven insights to support proactive management of current and emerging risks.  \nOperational Efficiency and Improved Ownership \nAn intuitive user experience, default ‘outofthebox’ configurability, guided workflows and automation will reduce manual effort and embed firstline ownership of risks and controls, while supporting second line oversight and challenge.  \nHigh Quality Data and Reporting \nAutomated dashboards and configurable reporting to the Microsoft Office suite will streamline internal and external stakeholder reporting, including for senior management, committees and regulators.  \nAssurance and Regulatory Compliance \nThe platform will facilitate compliance with the UK Corporate Governance Code (including Provision 29) and relevant FCA expectations. Evidence trails, compliance monitoring and control testing will support a robust assurance framework. \nCore Capability Requirements \nInitial core capability requirements have been identified, with activities still ongoing to define the full scope of requirements and determine the business units which a GRC tool may be implemented into. A full prioritised list of requirements and business units identified as part of ongoing activities, will be incorporated into future specifications. \nThe current core GRC solution must support, but not be limited to the following key modules: \nRisk & Control Management \n- Risk and control library \n- RCSA: inherent/residual assessments, control tiering and assessments, risk acceptances and outoftolerance management \n- Heat maps, bow ties and risk scoring matrices \n- Control improvement actions \n- Endtoend traceability of risk, control and incident data by risk taxonomy, business unit, policy suite, and key processes \nControl Testing \n- Structured workflows, evidence capture and reporting to support assurance activities.  \nData, Reporting & Analytics \n- Configurable automated reporting \n- UK Corporate Governance Code Provision 29aligned reporting \n- Data ingestion from internal and external sources \n- Use of AIassisted tooling where appropriate  \nRisk Appetite & Key Risk Indicators \n- Capture, monitoring and reporting of KRIs and risk appetite metrics.  \nIncident Management \n- Central reporting portal \n- End to end incident lifecycle management, including automations \n- Metrics and trend analysis  \nPolicy Management \n- Governance and maintenance of the policy suite \n- Evidence based assessment of policy effectiveness using risk, control, testing and incident data  \nRegulatory Compliance \n- Compliance monitoring plan execution \n- Horizon scanning and analysis of regulatory changes \n- Impact assessment of external developments on the control environment  \nEthics & Integrity \n- Management and reporting of gifts and hospitality, conflicts of interest, personal account dealing and insider lists.  \nInternal Audit \n- Audit planning and delivery workflows \n- Action tracking and reporting  \nNon-Core Capabilities \nWhile not central to the initial procurement, the system should also be capable of supporting: \n- Business continuity and resilience \n- Programme/project risk management \n- Third party risk management",
    "enquiryPeriod": {
      "endDate": "2026-05-29T12:00:00+01:00"
    },
    "aboveThreshold": true,
    "submissionTerms": {
      "languages": [
        "en"
      ],
      "electronicSubmissionPolicy": "allowed"
    },
    "procurementMethod": "open",
    "mainProcurementCategory": "services",
    "submissionMethodDetails": "https://www.delta-esourcing.com/respond/4J4GPFS79V",
    "procurementMethodDetails": "Competitive flexible procedure",
    "expressionOfInterestDeadline": "2026-06-05T12:00:00+01:00"
  },
  "parties": [
    {
      "id": "GB-PPON-PGTM-8337-GYXM",
      "name": "British Business Bank Plc",
      "roles": [
        "buyer"
      ],
      "address": {
        "region": "UKE32",
        "country": "GB",
        "locality": "Sheffield",
        "postalCode": "S1 2GQ",
        "countryName": "United Kingdom",
        "streetAddress": "2, West Street"
      },
      "details": {
        "classifications": [
          {
            "id": "publicAuthorityCentralGovernment",
            "scheme": "UK_CA_TYPE",
            "description": "Public authority - central government"
          }
        ]
      },
      "identifier": {
        "id": "PGTM-8337-GYXM",
        "scheme": "GB-PPON"
      },
      "contactPoint": {
        "name": "Procurement",
        "email": "procurement@british-business-bank.co.uk",
        "telephone": "01142502892"
      }
    }
  ],
  "language": "en",
  "initiationType": "tender"
}
21 May 2026 · 047423-2026 · tenderUpdate
{
  "id": "047423-2026",
  "tag": [
    "tenderUpdate"
  ],
  "date": "2026-05-21T17:53:03+01:00",
  "ocid": "ocds-h6vhtk-067195",
  "buyer": {
    "id": "GB-PPON-PGTM-8337-GYXM",
    "name": "British Business Bank Plc"
  },
  "tender": {
    "id": "ocds-h6vhtk-067195",
    "lots": [
      {
        "id": "1",
        "value": {
          "amount": 1100000,
          "currency": "GBP",
          "amountGross": 1320000
        },
        "status": "active",
        "renewal": {
          "description": "Optional 2 year extension is applicable to this contract"
        },
        "hasRenewal": true,
        "suitability": {
          "sme": true,
          "vcse": true
        },
        "awardCriteria": {
          "criteria": [
            {
              "name": "Commercial Offer",
              "type": "price",
              "numbers": [
                {
                  "number": 35,
                  "weight": "percentageExact"
                }
              ]
            },
            {
              "name": "Quality Criteria",
              "type": "quality",
              "numbers": [
                {
                  "number": 65,
                  "weight": "percentageExact"
                }
              ]
            }
          ]
        },
        "contractPeriod": {
          "endDate": "2032-10-05T23:59:59+01:00",
          "startDate": "2026-10-06T00:00:00+01:00",
          "maxExtentDate": "2034-10-05T23:59:59+01:00"
        }
      }
    ],
    "items": [
      {
        "id": "1",
        "relatedLot": "1",
        "deliveryAddresses": [
          {
            "region": "UK",
            "country": "GB",
            "countryName": "United Kingdom"
          }
        ],
        "additionalClassifications": [
          {
            "id": "72212170",
            "scheme": "CPV",
            "description": "Compliance software development services"
          },
          {
            "id": "72212442",
            "scheme": "CPV",
            "description": "Financial systems software development services"
          },
          {
            "id": "79212110",
            "scheme": "CPV",
            "description": "Corporate governance rating services"
          },
          {
            "id": "90711100",
            "scheme": "CPV",
            "description": "Risk or hazard assessment other than for construction"
          }
        ]
      }
    ],
    "title": "Governance Risk and Compliance tool",
    "value": {
      "amount": 1100000,
      "currency": "GBP",
      "amountGross": 1320000
    },
    "status": "active",
    "coveredBy": [
      "GPA"
    ],
    "documents": [
      {
        "id": "conflictOfInterest",
        "description": "Not published",
        "documentType": "conflictOfInterest"
      },
      {
        "id": "047423-2026",
        "url": "https://www.find-tender.service.gov.uk/Notice/047423-2026",
        "format": "text/html",
        "noticeType": "UK4",
        "description": "Tender notice on Find a Tender",
        "documentType": "tenderNotice",
        "datePublished": "2026-05-21T17:53:03+01:00"
      }
    ],
    "procedure": {
      "features": "Procurement Specific Questionnaire \nInvitation to Participate\nProof of Concepts",
      "isAccelerated": true,
      "acceleratedRationale": "Qualifying planned procurement notice"
    },
    "legalBasis": {
      "id": "2023/54",
      "uri": "https://www.legislation.gov.uk/ukpga/2023/54/contents",
      "scheme": "UKPGA"
    },
    "awardPeriod": {
      "endDate": "2026-09-22T23:59:59+01:00"
    },
    "description": "Description \nThe Authority aims to procure a scalable, integrated Governance, Risk and Compliance (GRC) software solution, capable of supporting its organisational growth and any required regulatory obligations. The solution is intended to consolidate risk data from across the Authority into a single platform that strengthens oversight, enhances analysis & reporting, improves operational efficiency, and ensures accountability.  A GRC tool may also provide the opportunity to identify data synergies and move away from several systems used across the Authority. \nStrategic Objectives \nIntegrated View of the Risk and Control Environment \nA unified cloud-based platform will provide a single source of truth for risks, controls, incidents, actions and metrics. Full traceability will be maintained across taxonomies, business units, policies and key processes, improving framework integration, transparency and decision-making.  \nData Driven Culture and Analytics \nThe system will enable trend analysis, early warning indicators and data driven insights to support proactive management of current and emerging risks.  \nOperational Efficiency and Improved Ownership \nAn intuitive user experience, default ‘outofthebox’ configurability, guided workflows and automation will reduce manual effort and embed firstline ownership of risks and controls, while supporting second line oversight and challenge.  \nHigh Quality Data and Reporting \nAutomated dashboards and configurable reporting to the Microsoft Office suite will streamline internal and external stakeholder reporting, including for senior management, committees and regulators.  \nAssurance and Regulatory Compliance \nThe platform will facilitate compliance with the UK Corporate Governance Code (including Provision 29) and relevant FCA expectations. Evidence trails, compliance monitoring and control testing will support a robust assurance framework. \nCore Capability Requirements \nInitial core capability requirements have been identified, with activities still ongoing to define the full scope of requirements and determine the business units which a GRC tool may be implemented into. A full prioritised list of requirements and business units identified as part of ongoing activities, will be incorporated into future specifications. \nThe current core GRC solution must support, but not be limited to the following key modules: \nRisk & Control Management \n- Risk and control library \n- RCSA: inherent/residual assessments, control tiering and assessments, risk acceptances and outoftolerance management \n- Heat maps, bow ties and risk scoring matrices \n- Control improvement actions \n- Endtoend traceability of risk, control and incident data by risk taxonomy, business unit, policy suite, and key processes \nControl Testing \n- Structured workflows, evidence capture and reporting to support assurance activities.  \nData, Reporting & Analytics \n- Configurable automated reporting \n- UK Corporate Governance Code Provision 29aligned reporting \n- Data ingestion from internal and external sources \n- Use of AIassisted tooling where appropriate  \nRisk Appetite & Key Risk Indicators \n- Capture, monitoring and reporting of KRIs and risk appetite metrics.  \nIncident Management \n- Central reporting portal \n- End to end incident lifecycle management, including automations \n- Metrics and trend analysis  \nPolicy Management \n- Governance and maintenance of the policy suite \n- Evidence based assessment of policy effectiveness using risk, control, testing and incident data  \nRegulatory Compliance \n- Compliance monitoring plan execution \n- Horizon scanning and analysis of regulatory changes \n- Impact assessment of external developments on the control environment  \nEthics & Integrity \n- Management and reporting of gifts and hospitality, conflicts of interest, personal account dealing and insider lists.  \nInternal Audit \n- Audit planning and delivery workflows \n- Action tracking and reporting  \nNon-Core Capabilities \nWhile not central to the initial procurement, the system should also be capable of supporting: \n- Business continuity and resilience \n- Programme/project risk management \n- Third party risk management",
    "enquiryPeriod": {
      "endDate": "2026-05-29T12:00:00+01:00"
    },
    "aboveThreshold": true,
    "submissionTerms": {
      "languages": [
        "en"
      ],
      "electronicSubmissionPolicy": "allowed"
    },
    "procurementMethod": "open",
    "mainProcurementCategory": "services",
    "submissionMethodDetails": "https://www.delta-esourcing.com/respond/EH9886C8AG",
    "procurementMethodDetails": "Competitive flexible procedure",
    "expressionOfInterestDeadline": "2026-06-05T12:00:00+01:00"
  },
  "parties": [
    {
      "id": "GB-PPON-PGTM-8337-GYXM",
      "name": "British Business Bank Plc",
      "roles": [
        "buyer"
      ],
      "address": {
        "region": "UKE32",
        "country": "GB",
        "locality": "Sheffield",
        "postalCode": "S1 2GQ",
        "countryName": "United Kingdom",
        "streetAddress": "2, West Street"
      },
      "details": {
        "classifications": [
          {
            "id": "publicAuthorityCentralGovernment",
            "scheme": "UK_CA_TYPE",
            "description": "Public authority - central government"
          }
        ]
      },
      "identifier": {
        "id": "PGTM-8337-GYXM",
        "scheme": "GB-PPON"
      },
      "contactPoint": {
        "name": "Procurement",
        "email": "procurement@british-business-bank.co.uk",
        "telephone": "01142502892"
      }
    }
  ],
  "language": "en",
  "initiationType": "tender"
}
21 May 2026 · 047402-2026 · tender
{
  "id": "047402-2026",
  "tag": [
    "tender"
  ],
  "date": "2026-05-21T17:20:09+01:00",
  "ocid": "ocds-h6vhtk-067195",
  "buyer": {
    "id": "GB-PPON-PGTM-8337-GYXM",
    "name": "British Business Bank Plc"
  },
  "tender": {
    "id": "ocds-h6vhtk-067195",
    "lots": [
      {
        "id": "1",
        "value": {
          "amount": 1100000,
          "currency": "GBP",
          "amountGross": 1320000
        },
        "status": "active",
        "renewal": {
          "description": "Optional 2 year extension is applicable to this contract"
        },
        "hasRenewal": true,
        "suitability": {
          "sme": true,
          "vcse": true
        },
        "awardCriteria": {
          "criteria": [
            {
              "name": "Commercial Offer",
              "type": "price",
              "numbers": [
                {
                  "number": 35,
                  "weight": "percentageExact"
                }
              ]
            },
            {
              "name": "Quality Criteria",
              "type": "quality",
              "numbers": [
                {
                  "number": 65,
                  "weight": "percentageExact"
                }
              ]
            }
          ]
        },
        "contractPeriod": {
          "endDate": "2032-10-05T23:59:59+01:00",
          "startDate": "2026-10-06T00:00:00+01:00",
          "maxExtentDate": "2034-10-05T23:59:59+01:00"
        }
      }
    ],
    "items": [
      {
        "id": "1",
        "relatedLot": "1",
        "deliveryAddresses": [
          {
            "region": "UK",
            "country": "GB",
            "countryName": "United Kingdom"
          }
        ],
        "additionalClassifications": [
          {
            "id": "72212170",
            "scheme": "CPV",
            "description": "Compliance software development services"
          },
          {
            "id": "72212442",
            "scheme": "CPV",
            "description": "Financial systems software development services"
          },
          {
            "id": "79212110",
            "scheme": "CPV",
            "description": "Corporate governance rating services"
          },
          {
            "id": "90711100",
            "scheme": "CPV",
            "description": "Risk or hazard assessment other than for construction"
          }
        ]
      }
    ],
    "title": "Governance Risk and Compliance tool",
    "value": {
      "amount": 1100000,
      "currency": "GBP",
      "amountGross": 1320000
    },
    "status": "active",
    "coveredBy": [
      "GPA"
    ],
    "documents": [
      {
        "id": "conflictOfInterest",
        "description": "Not published",
        "documentType": "conflictOfInterest"
      },
      {
        "id": "047402-2026",
        "url": "https://www.find-tender.service.gov.uk/Notice/047402-2026",
        "format": "text/html",
        "noticeType": "UK4",
        "description": "Tender notice on Find a Tender",
        "documentType": "tenderNotice",
        "datePublished": "2026-05-21T17:20:09+01:00"
      }
    ],
    "procedure": {
      "features": "Procurement Specific Questionnaire \nInvitation to Participate\nProof of Concepts",
      "isAccelerated": true,
      "acceleratedRationale": "Qualifying planned procurement notice"
    },
    "legalBasis": {
      "id": "2023/54",
      "uri": "https://www.legislation.gov.uk/ukpga/2023/54/contents",
      "scheme": "UKPGA"
    },
    "awardPeriod": {
      "endDate": "2026-09-22T23:59:59+01:00"
    },
    "description": "Description \nThe Authority aims to procure a scalable, integrated Governance, Risk and Compliance (GRC) software solution, capable of supporting its organisational growth and any required regulatory obligations. The solution is intended to consolidate risk data from across the Authority into a single platform that strengthens oversight, enhances analysis & reporting, improves operational efficiency, and ensures accountability.  A GRC tool may also provide the opportunity to identify data synergies and move away from several systems used across the Authority. \nStrategic Objectives \nIntegrated View of the Risk and Control Environment \nA unified cloud-based platform will provide a single source of truth for risks, controls, incidents, actions and metrics. Full traceability will be maintained across taxonomies, business units, policies and key processes, improving framework integration, transparency and decision-making.  \nData Driven Culture and Analytics \nThe system will enable trend analysis, early warning indicators and data driven insights to support proactive management of current and emerging risks.  \nOperational Efficiency and Improved Ownership \nAn intuitive user experience, default ‘outofthebox’ configurability, guided workflows and automation will reduce manual effort and embed firstline ownership of risks and controls, while supporting second line oversight and challenge.  \nHigh Quality Data and Reporting \nAutomated dashboards and configurable reporting to the Microsoft Office suite will streamline internal and external stakeholder reporting, including for senior management, committees and regulators.  \nAssurance and Regulatory Compliance \nThe platform will facilitate compliance with the UK Corporate Governance Code (including Provision 29) and relevant FCA expectations. Evidence trails, compliance monitoring and control testing will support a robust assurance framework. \nCore Capability Requirements \nInitial core capability requirements have been identified, with activities still ongoing to define the full scope of requirements and determine the business units which a GRC tool may be implemented into. A full prioritised list of requirements and business units identified as part of ongoing activities, will be incorporated into future specifications. \nThe current core GRC solution must support, but not be limited to the following key modules: \nRisk & Control Management \n- Risk and control library \n- RCSA: inherent/residual assessments, control tiering and assessments, risk acceptances and outoftolerance management \n- Heat maps, bow ties and risk scoring matrices \n- Control improvement actions \n- Endtoend traceability of risk, control and incident data by risk taxonomy, business unit, policy suite, and key processes \nControl Testing \n- Structured workflows, evidence capture and reporting to support assurance activities.  \nData, Reporting & Analytics \n- Configurable automated reporting \n- UK Corporate Governance Code Provision 29aligned reporting \n- Data ingestion from internal and external sources \n- Use of AIassisted tooling where appropriate  \nRisk Appetite & Key Risk Indicators \n- Capture, monitoring and reporting of KRIs and risk appetite metrics.  \nIncident Management \n- Central reporting portal \n- End to end incident lifecycle management, including automations \n- Metrics and trend analysis  \nPolicy Management \n- Governance and maintenance of the policy suite \n- Evidence based assessment of policy effectiveness using risk, control, testing and incident data  \nRegulatory Compliance \n- Compliance monitoring plan execution \n- Horizon scanning and analysis of regulatory changes \n- Impact assessment of external developments on the control environment  \nEthics & Integrity \n- Management and reporting of gifts and hospitality, conflicts of interest, personal account dealing and insider lists.  \nInternal Audit \n- Audit planning and delivery workflows \n- Action tracking and reporting  \nNon-Core Capabilities \nWhile not central to the initial procurement, the system should also be capable of supporting: \n- Business continuity and resilience \n- Programme/project risk management \n- Third party risk management",
    "enquiryPeriod": {
      "endDate": "2026-05-29T12:00:00+01:00"
    },
    "aboveThreshold": true,
    "submissionTerms": {
      "languages": [
        "en"
      ],
      "electronicSubmissionPolicy": "allowed"
    },
    "procurementMethod": "open",
    "mainProcurementCategory": "services",
    "submissionMethodDetails": "https://www.delta-esourcing.com",
    "procurementMethodDetails": "Competitive flexible procedure",
    "expressionOfInterestDeadline": "2026-06-05T12:00:00+01:00"
  },
  "parties": [
    {
      "id": "GB-PPON-PGTM-8337-GYXM",
      "name": "British Business Bank Plc",
      "roles": [
        "buyer"
      ],
      "address": {
        "region": "UKE32",
        "country": "GB",
        "locality": "Sheffield",
        "postalCode": "S1 2GQ",
        "countryName": "United Kingdom",
        "streetAddress": "2, West Street"
      },
      "details": {
        "classifications": [
          {
            "id": "publicAuthorityCentralGovernment",
            "scheme": "UK_CA_TYPE",
            "description": "Public authority - central government"
          }
        ]
      },
      "identifier": {
        "id": "PGTM-8337-GYXM",
        "scheme": "GB-PPON"
      },
      "contactPoint": {
        "name": "Procurement",
        "email": "procurement@british-business-bank.co.uk",
        "telephone": "01142502892"
      }
    }
  ],
  "language": "en",
  "initiationType": "tender"
}
23 Mar 2026 · 026336-2026 · planning
{
  "id": "026336-2026",
  "tag": [
    "planning"
  ],
  "date": "2026-03-23T14:42:09Z",
  "ocid": "ocds-h6vhtk-067195",
  "buyer": {
    "id": "GB-PPON-PGTM-8337-GYXM",
    "name": "British Business Bank Plc"
  },
  "tender": {
    "id": "ocds-h6vhtk-067195",
    "lots": [
      {
        "id": "1",
        "value": {
          "amount": 1100000,
          "currency": "GBP",
          "amountGross": 1320000
        },
        "status": "planned",
        "renewal": {
          "description": "Optional 2 year extension is applicable to this contract"
        },
        "hasRenewal": true,
        "suitability": {
          "sme": true,
          "vcse": true
        },
        "awardCriteria": {
          "criteria": [
            {
              "name": "Commercial Offer",
              "type": "price",
              "numbers": [
                {
                  "number": 35,
                  "weight": "percentageExact"
                }
              ]
            },
            {
              "name": "Quality Criteria",
              "type": "quality",
              "numbers": [
                {
                  "number": 65,
                  "weight": "percentageExact"
                }
              ]
            }
          ]
        },
        "contractPeriod": {
          "endDate": "2032-10-31T23:59:59+01:00",
          "startDate": "2026-10-31T00:00:00+00:00",
          "maxExtentDate": "2034-10-31T23:59:59+00:00"
        }
      }
    ],
    "items": [
      {
        "id": "1",
        "relatedLot": "1",
        "deliveryAddresses": [
          {
            "region": "UK",
            "country": "GB",
            "countryName": "United Kingdom"
          }
        ],
        "additionalClassifications": [
          {
            "id": "72212170",
            "scheme": "CPV",
            "description": "Compliance software development services"
          },
          {
            "id": "72212442",
            "scheme": "CPV",
            "description": "Financial systems software development services"
          },
          {
            "id": "79212110",
            "scheme": "CPV",
            "description": "Corporate governance rating services"
          },
          {
            "id": "90711100",
            "scheme": "CPV",
            "description": "Risk or hazard assessment other than for construction"
          }
        ]
      }
    ],
    "title": "Governance Risk and Compliance tool",
    "value": {
      "amount": 1100000,
      "currency": "GBP",
      "amountGross": 1320000
    },
    "status": "planned",
    "coveredBy": [
      "GPA"
    ],
    "procedure": {
      "features": "Invitation to Participate\nInvitation to Tender\nProof of Concepts",
      "isAccelerated": true,
      "acceleratedRationale": "Qualifying planned procurement notice"
    },
    "legalBasis": {
      "id": "2023/54",
      "uri": "https://www.legislation.gov.uk/ukpga/2023/54/contents",
      "scheme": "UKPGA"
    },
    "awardPeriod": {
      "endDate": "2026-09-22T23:59:59+01:00"
    },
    "description": "Description \nThe Authority aims to procure a scalable, integrated Governance, Risk and Compliance (GRC) software solution, capable of supporting its organisational growth and any required regulatory obligations. The solution is intended to consolidate risk data from across the Authority into a single platform that strengthens oversight, enhances analysis & reporting, improves operational efficiency, and ensures accountability.  A GRC tool may also provide the opportunity to identify data synergies and move away from several systems used across the Authority. \nStrategic Objectives \nIntegrated View of the Risk and Control Environment \nA unified cloud-based platform will provide a single source of truth for risks, controls, incidents, actions and metrics. Full traceability will be maintained across taxonomies, business units, policies and key processes, improving framework integration, transparency and decision-making.  \nData Driven Culture and Analytics \nThe system will enable trend analysis, early warning indicators and data driven insights to support proactive management of current and emerging risks.  \nOperational Efficiency and Improved Ownership \nAn intuitive user experience, default ‘outofthebox’ configurability, guided workflows and automation will reduce manual effort and embed firstline ownership of risks and controls, while supporting second line oversight and challenge.  \nHigh Quality Data and Reporting \nAutomated dashboards and configurable reporting to the Microsoft Office suite will streamline internal and external stakeholder reporting, including for senior management, committees and regulators.  \nAssurance and Regulatory Compliance \nThe platform will facilitate compliance with the UK Corporate Governance Code (including Provision 29) and relevant FCA expectations. Evidence trails, compliance monitoring and control testing will support a robust assurance framework. \nCore Capability Requirements \nInitial core capability requirements have been identified, with activities still ongoing to define the full scope of requirements and determine the business units which a GRC tool may be implemented into. A full prioritised list of requirements and business units identified as part of ongoing activities, will be incorporated into future specifications. \nThe current core GRC solution must support, but not be limited to the following key modules: \nRisk & Control Management \n- Risk and control library \n- RCSA: inherent/residual assessments, control tiering and assessments, risk acceptances and outoftolerance management \n- Heat maps, bow ties and risk scoring matrices \n- Control improvement actions \n- Endtoend traceability of risk, control and incident data by risk taxonomy, business unit, policy suite, and key processes \nControl Testing \n- Structured workflows, evidence capture and reporting to support assurance activities.  \nData, Reporting & Analytics \n- Configurable automated reporting \n- UK Corporate Governance Code Provision 29aligned reporting \n- Data ingestion from internal and external sources \n- Use of AIassisted tooling where appropriate  \nRisk Appetite & Key Risk Indicators \n- Capture, monitoring and reporting of KRIs and risk appetite metrics.  \nIncident Management \n- Central reporting portal \n- End to end incident lifecycle management, including automations \n- Metrics and trend analysis  \nPolicy Management \n- Governance and maintenance of the policy suite \n- Evidence based assessment of policy effectiveness using risk, control, testing and incident data  \nRegulatory Compliance \n- Compliance monitoring plan execution \n- Horizon scanning and analysis of regulatory changes \n- Impact assessment of external developments on the control environment  \nEthics & Integrity \n- Management and reporting of gifts and hospitality, conflicts of interest, personal account dealing and insider lists.  \nInternal Audit \n- Audit planning and delivery workflows \n- Action tracking and reporting  \nNon-Core Capabilities \nWhile not central to the initial procurement, the system should also be capable of supporting: \n- Business continuity and resilience \n- Programme/project risk management \n- Third party risk management\nFor more information about this opportunity, please visit the Delta eSourcing portal at: \nhttps://www.delta-esourcing.com/tenders/UK-UK-Sheffield:-Compliance-software-development-services./7P8D4R6M38\nTo respond to this opportunity, please click here: \nhttps://www.delta-esourcing.com/respond/7P8D4R6M38",
    "communication": {
      "futureNoticeDate": "2026-05-18T23:59:59+01:00"
    },
    "enquiryPeriod": {
      "endDate": "2026-06-26T12:00:00+01:00"
    },
    "specialRegime": [
      "concession"
    ],
    "aboveThreshold": true,
    "submissionTerms": {
      "languages": [
        "en"
      ],
      "electronicSubmissionPolicy": "allowed"
    },
    "procurementMethod": "open",
    "mainProcurementCategory": "services",
    "submissionMethodDetails": "https://www.delta-esourcing.com",
    "procurementMethodDetails": "Competitive flexible procedure",
    "expressionOfInterestDeadline": "2026-06-29T12:00:00+01:00"
  },
  "parties": [
    {
      "id": "GB-PPON-PGTM-8337-GYXM",
      "name": "British Business Bank Plc",
      "roles": [
        "buyer"
      ],
      "address": {
        "region": "UKE32",
        "country": "GB",
        "locality": "Sheffield",
        "postalCode": "S1 2GQ",
        "countryName": "United Kingdom",
        "streetAddress": "2, West Street"
      },
      "details": {
        "classifications": [
          {
            "id": "publicAuthorityCentralGovernment",
            "scheme": "UK_CA_TYPE",
            "description": "Public authority - central government"
          }
        ]
      },
      "identifier": {
        "id": "PGTM-8337-GYXM",
        "scheme": "GB-PPON"
      },
      "contactPoint": {
        "name": "Procurement",
        "email": "procurement@british-business-bank.co.uk",
        "telephone": "01142502892"
      }
    }
  ],
  "language": "en",
  "planning": {
    "documents": [
      {
        "id": "026336-2026",
        "url": "https://www.find-tender.service.gov.uk/Notice/026336-2026",
        "format": "text/html",
        "noticeType": "UK3",
        "description": "Planned procurement notice on Find a Tender",
        "documentType": "plannedProcurementNotice",
        "datePublished": "2026-03-23T14:42:09Z"
      }
    ]
  },
  "initiationType": "tender"
}