Security & trust

Risk Management

Understand risks and manage them through clear responsibilities and review.

Risk assessment

Risk assessment forms part of our information security management system. The process considers assets, threats and vulnerabilities, assesses likelihood and impact, and records risk owners and treatment decisions.

A full assessment is required annually, with reassessment after significant changes and assessment at the start of sensitive-data projects. This helps connect the changing platform and organisation with the security priorities that need attention.

  • Identify the information and services a risk could affect.
  • Assess likelihood and impact to support prioritisation.
  • Record ownership, treatment and the reasons behind risk decisions.
Explore security governance

Supplier security

Supplier assessment considers security requirements, third-party responsibilities and the dependencies used to deliver the platform. Cloud providers, supporting services and customer-selected integrations each have a role in the complete service arrangement.

Our supplier procedures consider assurance and contractual requirements. Your own connected systems remain part of your service design, so assess their permissions, processing locations and operational dependencies alongside Govform.

  • Identify the purpose and information involved in each supplier relationship.
  • Consider supplier security assurance and the responsibilities being agreed.
  • Review material changes to providers or connected service dependencies.
Explore processing and supplier discussions

Turn risks into accountable actions

Risk assessment supports decisions about treatment, acceptance and escalation. Named owners and a maintained register connect an identified concern with the person responsible for addressing it and the action selected.

Treatment can involve changing controls or working practices, while accepted risks require a recorded justification. Higher risks are escalated through the management process so they receive the appropriate attention.

  • Choose actions according to the assessed impact and likelihood.
  • Assign ownership for implementing and reviewing the treatment.
  • Revisit risks when services, dependencies or circumstances change.

Assess the service you intend to run

Your service’s risk profile depends on the information it handles, its users, connected systems and operational importance. Platform controls provide a foundation, while your chosen configuration determines how those controls support the journey.

Use QA and assurance review to check authentication, permissions, exports, integrations and failure handling. Institutional engagements can scope questionnaires, technical discussions and additional service-specific assurance work.

  • Map sensitive information and access needs before going live.
  • Review critical dependencies and the effect of an outage or failed action.
  • Agree evidence and support requirements with the relevant service owners.
Discuss service-specific assurance
Build with confidence

Secure services start with a conversation.

Talk to our team about your organisation’s security requirements, hosting choices and the services you want to deliver.