RFP QuestBeta
Awarded · ResultStage · award

British Business Bank Plc

Governance Risk and Compliance tool

Business ServicesCPV 72212170
Value£1,100,000
Awarded9 Sept 2026
Published10 Sept 2026
RegionNationwide

£1,100,000 — awarded.

Outcome — awarded
Decision Focus
Awarded value£1.1m
Award date9 Sept 2026

This is a contract result notice, not an open opportunity. Details from the official award data.

Who to contact
Procurement
procurement@british-business-bank.co.uk
01142502892

The procurement contact named on the official notice.

Contract value in context
£1.1mtotal contract value
median £120k
this tender£0£3.5m

This is a large award for IT Services — above three-quarters of comparable contracts. Based on 36,449 valued IT Services tenders in our corpus.

The brief

DELTA Access Code :4J4GPFS79V Description The Authority aims to procure a scalable, integrated Governance, Risk and Compliance (GRC) software solution, capable of supporting its organisational growth and any required regulatory obligations.

The solution is intended to consolidate risk data from across the Authority into a single platform that strengthens oversight, enhances analysis & reporting, improves operational efficiency, and ensures accountability.

A GRC tool may also provide the opportunity to identify data synergies and move away from several systems used across the Authority.

Strategic Objectives Integrated View of the Risk and Control Environment A unified cloud-based platform will provide a single source of truth for risks, controls, incidents, actions and metrics.

Full traceability will be maintained across taxonomies, business units, policies and key processes, improving framework integration, transparency and decision-making.

Data Driven Culture and Analytics The system will enable trend analysis, early warning indicators and data driven insights to support proactive management of current and emerging risks.

Operational Efficiency and Improved Ownership An intuitive user experience, default ‘outofthebox’ configurability, guided workflows and automation will reduce manual effort and embed firstline ownership of risks and controls, while supporting second line oversight and challenge.

High Quality Data and Reporting Automated dashboards and configurable reporting to the Microsoft Office suite will streamline internal and external stakeholder reporting, including for senior management, committees and regulators.

Assurance and Regulatory Compliance The platform will facilitate compliance with the UK Corporate Governance Code (including Provision 29) and relevant FCA expectations.

Evidence trails, compliance monitoring and control testing will support a robust assurance framework.

Core Capability Requirements Initial core capability requirements have been identified, with activities still ongoing to define the full scope of requirements and determine the business units which a GRC tool may be implemented into.

A full prioritised list of requirements and business units identified as part of ongoing activities, will be incorporated into future specifications.

The current core GRC solution must support, but not be limited to the following key modules: Risk & Control Management - Risk and control library - RCSA: inherent/residual assessments, control tiering and assessments, risk acceptances and outoftolerance management - Heat maps, bow ties and risk scoring matrices - Control improvement actions - Endtoend traceability of risk, control and incident data by risk taxonomy, business unit, policy suite, and key processes Control Testing - Structured workflows, evidence capture and reporting to support assurance activities.

Data, Reporting & Analytics - Configurable automated reporting - UK Corporate Governance Code Provision 29aligned reporting - Data ingestion from internal and external sources - Use of AIassisted tooling where appropriate Risk Appetite & Key Risk Indicators - Capture, monitoring and reporting of KRIs and risk appetite metrics.

Incident Management - Central reporting portal - End to end incident lifecycle management, including automations - Metrics and trend analysis Policy Management - Governance and maintenance of the policy suite - Evidence based assessment of policy effectiveness using risk, control, testing and incident data Regulatory Compliance - Compliance monitoring plan execution - Horizon scanning and analysis of regulatory changes - Impact assessment of external developments on the control environment Ethics & Integrity - Management and reporting of gifts and hospitality, conflicts of interest, personal account dealing and insider lists.

Internal Audit - Audit planning and delivery workflows - Action tracking and reporting Non-Core Capabilities While not central to the initial procurement, the system should also be capable of supporting: - Business continuity and resilience - Programme/project risk management - Third party risk management

Requirements

What the notice asks for

01

The Authority aims to procure a scalable

The Authority aims to procure a scalable, integrated Governance, Risk and Compliance (GRC) software solution, capable of supporting its organisational growth and any required regulatory obligations.

02

A GRC tool may also provide

A GRC tool may also provide the opportunity to identify data synergies and move away from several systems used across the Authority.

03

Integrated View of the Risk and Control

Integrated View of the Risk and Control Environment.

04

A unified cloud-based platform will provide

A unified cloud-based platform will provide a single source of truth for risks, controls, incidents, actions and metrics.

05

Full traceability will be maintained across taxonomies

Full traceability will be maintained across taxonomies, business units, policies and key processes, improving framework integration, transparency and decision-making.

Sentences from the notice that state an obligation, surfaced automatically and shown in the order they appear. Not an exhaustive list — always confirm against the tender documents.

The gates

What this notice demands of you

1 named, none in explicit obligation language. Each one is quoted from the notice.

FCA authorisationRegulator registrations
The platform will facilitate compliance with the UK Corporate Governance Code (including Provision 29) and relevant FCA expectations.

Matched against the notice text, so this is a floor — the tender pack will demand things the notice never mentions. “Says must” means the quoted sentence itself used obligation language; anything ambiguous is left as a mention.

Buyer intelligence

Make the case to bid

Reveal who to approach at British Business Bank Plc, and generate a go-to-market strategy from their news, accounts and people.

Sign up free to unlock buyer intelligence

Free to start. Named contacts come from published notices; the strategy is generated from the buyer’s news, accounts and people.

Source & provenance
OCID
ocds-h6vhtk-067195
Stage
award · Awarded
Source
Find a Tender
Buyer ref
086080-2026
View the original notice on Find a Tender

Contains public sector information licensed under the Open Government Licence v3.0. Source data © Crown copyright.

Market context

Who wins this kind of work

The suppliers and buyers around this opportunity — drawn from official award data. Drag to orbit; click a node to explore.

Top suppliers & buyers in IT Services

This view needs WebGL, which this browser has turned off.

British Business Bank Plc’s tender network

This view needs WebGL, which this browser has turned off.