Tenders/Governance Risk and Compliance tool

Governance Risk and Compliance tool

British Business Bank Plc
Published: May 21, 2026
Updated: May 21, 2026
Source: uk_fts

About This Opportunity

This is a supplies contract in the information and communication technology and governance and public administration sectors, with a focus on Software and Cloud Services. Located in United Kingdom, Europe, this opportunity is open to firms and consortiums, with an estimated budget of GBP 1.1 million.

Published through UK FTS - Find a Tender Service, a national government procurement portal. Public procurement tenders follow the country's national bidding regulations and may have specific eligibility and documentation requirements for the supply of goods in the information and communication technology sector. Supply contracts typically require bidders to demonstrate product compliance with technical specifications, delivery capacity, and relevant certifications. Interested parties should review the full documentation on the original source before submitting their proposal.

Description

DELTA Access Code :4J4GPFS79V Description The Authority aims to procure a scalable, integrated Governance, Risk and Compliance (GRC) software solution, capable of supporting its organisational growth and any required regulatory obligations. The solution is intended to consolidate risk data from across the Authority into a single platform that strengthens oversight, enhances analysis & reporting, improves operational efficiency, and ensures accountability. A GRC tool may also provide the opportunity to identify data synergies and move away from several systems used across the Authority. Strategic Objectives Integrated View of the Risk and Control Environment A unified cloud-based platform will provide a single source of truth for risks, controls, incidents, actions and metrics. Full traceability will be maintained across taxonomies, business units, policies and key processes, improving framework integration, transparency and decision-making. Data Driven Culture and Analytics The system will enable trend analysis, early warning indicators and data driven insights to support proactive management of current and emerging risks. Operational Efficiency and Improved Ownership An intuitive user experience, default ‘outofthebox’ configurability, guided workflows and automation will reduce manual effort and embed firstline ownership of risks and controls, while supporting second line oversight and challenge. High Quality Data and Reporting Automated dashboards and configurable reporting to the Microsoft Office suite will streamline internal and external stakeholder reporting, including for senior management, committees and regulators. Assurance and Regulatory Compliance The platform will facilitate compliance with the UK Corporate Governance Code (including Provision 29) and relevant FCA expectations. Evidence trails, compliance monitoring and control testing will support a robust assurance framework. Core Capability Requirements Initial core capability requirements have been identified, with activities still ongoing to define the full scope of requirements and determine the business units which a GRC tool may be implemented into. A full prioritised list of requirements and business units identified as part of ongoing activities, will be incorporated into future specifications. The current core GRC solution must support, but not be limited to the following key modules: Risk & Control Management - Risk and control library - RCSA: inherent/residual assessments, control tiering and assessments, risk acceptances and outoftolerance management - Heat maps, bow ties and risk scoring matrices - Control improvement actions - Endtoend traceability of risk, control and incident data by risk taxonomy, business unit, policy suite, and key processes Control Testing - Structured workflows, evidence capture and reporting to support assurance activities. Data, Reporting & Analytics - Configurable automated reporting - UK Corporate Governance Code Provision 29aligned reporting - Data ingestion from internal and external sources - Use of AIassisted tooling where appropriate Risk Appetite & Key Risk Indicators - Capture, monitoring and reporting of KRIs and risk appetite metrics. Incident Management - Central reporting portal - End to end incident lifecycle management, including automations - Metrics and trend analysis Policy Management - Governance and maintenance of the policy suite - Evidence based assessment of policy effectiveness using risk, control, testing and incident data Regulatory Compliance - Compliance monitoring plan execution - Horizon scanning and analysis of regulatory changes - Impact assessment of external developments on the control environment Ethics & Integrity - Management and reporting of gifts and hospitality, conflicts of interest, personal account dealing and insider lists. Internal Audit - Audit planning and delivery workflows - Action tracking and reporting Non-Core Capabilities While not central to the initial procurement, the system should also be capable of supporting: - Business continuity and resilience - Programme/project risk management - Third party risk management

Data provenance

This notice is sourced from UK FTS - Find a Tender Service and was originally published on May 21, 2026. Last refreshed today. Reference: 047427-2026. BidsFactory mirrors official procurement notices and links back to the source for full legal text.

About British Business Bank Plc

British Business Bank Plc has issued 69 procurement notices on BidsFactory, including 6 currently open and 61 awarded contracts. Activity concentrates in Information & Communication Technology, Finance & Banking, and General Supplies & Services. All notices are published for United Kingdom. Notices are distributed via UK Contracts Finder and UK FTS - Find a Tender Service. Most recent publication: May 21, 2026.

Frequently asked questions about this tender

Where will the contract be performed?

The contract is for delivery in United Kingdom. Foreign bidders should review local registration, taxation, and any in-country presence requirements before submitting.

How can I submit a bid?

Visit UK FTS - Find a Tender Service to access the full notice, required documents, and submission instructions. Quote reference 047427-2026 when communicating with the contracting authority.

Who is the contracting authority?

This notice was issued by British Business Bank Plc in United Kingdom. The authority is responsible for evaluating bids, awarding the contract, and managing performance.

What type of contract is this?

This is a Supplies contract in the Information & Communication Technology sector. The classification helps bidders match the opportunity to their qualifications and registered scope of supply.

What is the estimated budget?

The estimated contract value is £1,100,000 - £1,100,000. Bidders should ensure their proposals are consistent with this range and account for any local taxes and contract execution costs.

Find tenders like this automatically

Set up alerts and filters that match your business — never miss a relevant opportunity again.

See plans

Key Details

Estimated Budget
£1,100,000 - £1,100,000
Contract Type
Supplies
Eligibility
Firms / Consortiums
Language
English
Reference
047427-2026

Source

uk_fts
uk_fts
Official Source

Contracting Authority

British Business Bank Plc
🇬🇧United Kingdom

Contact

Contact Person
Procurement

Matching Experts

Are you a consultant?

Join our Expert Network and get matched with relevant tenders.