This public procurement record has 5 releases in its history.

Award

10 Sep 2026 at 16:19

TenderUpdate

21 May 2026 at 17:57

TenderUpdate

21 May 2026 at 17:53

Tender

21 May 2026 at 17:20

Planning

23 Mar 2026 at 14:42

Summary of the contracting process

British Business Bank Plc procured a governance, risk and compliance (GRC) software service for use across its organisation and business units in the UK. The requirement is for a scalable, integrated cloud platform that consolidates risks, controls, incidents, actions and performance measures, replacing or reducing reliance on several separate systems. The service covers risk and control management, control testing, reporting and analytics, risk appetite and key risk indicators, incident management, policy management, regulatory compliance, ethics and integrity, and internal audit. It also needs to support business continuity, resilience, programme and project risk, and third-party risk management. The purpose is to improve oversight, analysis, reporting, operational efficiency, accountability and assurance against the UK Corporate Governance Code and relevant FCA expectations.

The procurement has been awarded: Decision Focus was selected for the single lot on 10 September 2026. The awarded value is £1,100,000 excluding VAT (£1,320,000 including VAT). The awarded contract runs from 7 October 2026 to 6 October 2032, with an optional two-year extension to 5 October 2034. Contract signature was scheduled for 6 October 2026. The process used a selective competitive flexible procedure with an accelerated timetable, including a procurement-specific questionnaire, invitation to participate and proof-of-concept stage. Expressions of interest were due by 5 June 2026 and enquiries by 29 May 2026. Evaluation weighted quality at 65% and the commercial offer at 35%. There were 21 initial bids, six final-stage bids and three final-stage bids from SMEs.

This award demonstrates a substantial, long-term requirement for specialist GRC technology within a central-government-backed financial organisation. Competitors would need a mature, configurable cloud platform rather than a narrow compliance product, with demonstrable capability across enterprise risk, controls, incidents, actions, policy, audit, regulatory monitoring and key risk indicators. Strong candidates would be able to provide evidence capture, traceability, automated workflows, dashboards, trend analysis and configurable reporting for senior management, committees and regulators. Integration with internal and external data sources and Microsoft Office reporting is relevant, as is appropriate use of AI-assisted tooling. Understanding of the UK Corporate Governance Code, including Provision 29, and relevant FCA expectations would support credibility. Suppliers should also be able to handle organisational growth and additional risk domains such as resilience, projects and third parties.

How relevant is this notice?

Notice Title

Governance Risk and Compliance tool

Notice Description

DELTA Access Code :4J4GPFS79V Description The Authority aims to procure a scalable, integrated Governance, Risk and Compliance (GRC) software solution, capable of supporting its organisational growth and any required regulatory obligations. The solution is intended to consolidate risk data from across the Authority into a single platform that strengthens oversight, enhances analysis & reporting, improves operational efficiency, and ensures accountability. A GRC tool may also provide the opportunity to identify data synergies and move away from several systems used across the Authority. Strategic Objectives Integrated View of the Risk and Control Environment A unified cloud-based platform will provide a single source of truth for risks, controls, incidents, actions and metrics. Full traceability will be maintained across taxonomies, business units, policies and key processes, improving framework integration, transparency and decision-making. Data Driven Culture and Analytics The system will enable trend analysis, early warning indicators and data driven insights to support proactive management of current and emerging risks. Operational Efficiency and Improved Ownership An intuitive user experience, default 'outofthebox' configurability, guided workflows and automation will reduce manual effort and embed firstline ownership of risks and controls, while supporting second line oversight and challenge. High Quality Data and Reporting Automated dashboards and configurable reporting to the Microsoft Office suite will streamline internal and external stakeholder reporting, including for senior management, committees and regulators. Assurance and Regulatory Compliance The platform will facilitate compliance with the UK Corporate Governance Code (including Provision 29) and relevant FCA expectations. Evidence trails, compliance monitoring and control testing will support a robust assurance framework. Core Capability Requirements Initial core capability requirements have been identified, with activities still ongoing to define the full scope of requirements and determine the business units which a GRC tool may be implemented into. A full prioritised list of requirements and business units identified as part of ongoing activities, will be incorporated into future specifications. The current core GRC solution must support, but not be limited to the following key modules: Risk & Control Management - Risk and control library - RCSA: inherent/residual assessments, control tiering and assessments, risk acceptances and outoftolerance management - Heat maps, bow ties and risk scoring matrices - Control improvement actions - Endtoend traceability of risk, control and incident data by risk taxonomy, business unit, policy suite, and key processes Control Testing - Structured workflows, evidence capture and reporting to support assurance activities. Data, Reporting & Analytics - Configurable automated reporting - UK Corporate Governance Code Provision 29aligned reporting - Data ingestion from internal and external sources - Use of AIassisted tooling where appropriate Risk Appetite & Key Risk Indicators - Capture, monitoring and reporting of KRIs and risk appetite metrics. Incident Management - Central reporting portal - End to end incident lifecycle management, including automations - Metrics and trend analysis Policy Management - Governance and maintenance of the policy suite - Evidence based assessment of policy effectiveness using risk, control, testing and incident data Regulatory Compliance - Compliance monitoring plan execution - Horizon scanning and analysis of regulatory changes - Impact assessment of external developments on the control environment Ethics & Integrity - Management and reporting of gifts and hospitality, conflicts of interest, personal account dealing and insider lists. Internal Audit - Audit planning and delivery workflows - Action tracking and reporting Non-Core Capabilities While not central to the initial procurement, the system should also be capable of supporting: - Business continuity and resilience - Programme/project risk management - Third party risk management

Lot Information

Lot 1

Renewal: Optional 2 year extension is applicable to this contract

Publication & Lifecycle

Open Contracting ID
ocds-h6vhtk-067195
Publication Source
Find A Tender Service
Latest Notice
https://www.find-tender.service.gov.uk/Notice/086080-2026
Current Stage
Award
All Stages
Planning, Tender, Award

Procurement Classification

Notice Type
UK6 - Contract Award Notice
Procurement Type
Standard
Procurement Category
Services
Procurement Method
Selective
Procurement Method Details
Competitive flexible procedure
Tender Suitability
SME, VCSE
Awardee Scale
SME

Common Procurement Vocabulary (CPV)

CPV Divisions

72 - IT services: consulting, software development, Internet and support

79 - Business services: law, marketing, consulting, recruitment, printing and security

90 - Sewage, refuse, cleaning and environmental services


CPV Codes

72212170 - Compliance software development services

72212442 - Financial systems software development services

79212110 - Corporate governance rating services

90711100 - Risk or hazard assessment other than for construction

Notice Value(s)

Tender Value
£1,100,000 £1M-£10M
Lots Value
£1,100,000 £1M-£10M
Awards Value
£1,100,000 £1M-£10M
Contracts Value
Not specified

Notice Dates

Publication Date
10 Sep 20265 days ago
Submission Deadline
Not specified
Future Notice Date
18 May 2026Expired
Award Date
10 Sep 20266 days ago
Contract Period
7 Oct 2026 - 6 Oct 2032 Over 5 years
Recurrence
Not specified

Notice Status

Tender Status
Complete
Lots Status
Complete
Awards Status
Active
Contracts Status
Not Specified

Contracting Authority (Buyer)

Main Buyer
British Business Bank
Contact Name
Available with D3 Tenders Premium →
Contact Email
Available with D3 Tenders Premium →
Contact Phone
Available with D3 Tenders Premium →

Buyer Location

Locality
SHEFFIELD
Postcode
S1 2GQ
Postcode Area
Sheffield
Country
England

Major Region (ITL 1)
TLE Yorkshire and The Humber
Basic Region (ITL 2)
TLE3 South Yorkshire
Small Region (ITL 3)
TLE32 Sheffield
Delivery Location
Not specified

Local Authority
Sheffield
Electoral Ward
City
Westminster Constituency
Sheffield Central

Supplier Information

Number of Suppliers
1
Supplier Name

DECISION FOCUS UK LIMITED

Further Information

Notice Documents

Open Contracting Data Standard (OCDS)

View full OCDS Record for this contracting process

JSON Markdown

The Open Contracting Data Standard (OCDS) is a framework designed to increase transparency and access to public procurement data in the public sector. It is widely used by governments and organisations worldwide to report on procurement processes and contracts.

Loading OCDS record...