Transforming Systems Limited

Transforming Systems: SHREWD ICS

SHREWD ICS allows Sustainability and Transformation Partnerships (STPs) to manage the transformation programmes necessary to create Integrated Care Systems (ICS). It covers all aspects of controlling change initiatives from initial design, through successful delivery, to realising benefits..


  • Configurable drag and drop workflow engine
  • Task & actions management
  • Evidence based governance capture
  • Risk and issues management
  • Documents management
  • Cost and activity tracking
  • Stakeholder management
  • Reports engine
  • Programme timelines map and management
  • Alerts for overdue tasks, actions and escalating risks


  • Maximises chance of successful transformation delivery
  • Measures ROI - outcomes against baseline for service delivery
  • Track progress in real time
  • Strategic planning and oversight
  • Tighter control over Programme expenditure
  • Cost savings through prioritising effective initiatives
  • Increased compliance with governance processes
  • Increased task completion through active monitoring and control
  • Reduced effort to effectively manage risks and issues
  • Enhanced collaboration across unlimited organisations


£4999 per instance per month

Service documents

G-Cloud 11


Transforming Systems Limited

Alistair Martin

07887 716759

Service scope

Service scope
Software add-on or extension No
Cloud deployment model Private cloud
Service constraints The application requires AHSN connectivity for health specific use and users should have email addresses or NHS approved equivalents. The data used is publicly available and non-patient identifiable but data sharing agreements should be put in place between the organisations within the local health community. The data is best provided via a web service or API (other options such as csv / manual upload available) so a degree of integration knowledge is useful, however full support can be provided.
System requirements
  • Current compatible browser
  • Internet connection (2mbps minimum, 5mbps recommended )
  • Capability to extract data from sources (e.g. API, webservice)

User support

User support
Email or online ticketing support Email or online ticketing
Support response times The Helpdesk (telephone and email) is available during Business Hours 08.30 to 17.00 Monday to Friday. Priority and timescale 1 (High) : Full system outage – no users at all can use the system. Response: 10 mins. Resolve 4 hours. 2 (Medium) : Partial system outage – a significant number of users are affected. Response 10 mins. Resolve: 1 business day 3 (Low): Minor – a handful of users or a part of the system is not working to Specification. Response: 10 mins. Resolve 3 business days 4 (Query) : Minimal impact. Response; 3 business days. Resolve 20 business days
User can manage status and priority of support tickets No
Phone support Yes
Phone support availability 9 to 5 (UK time), Monday to Friday
Web chat support No
Onsite support Yes, at extra cost
Support levels Ongoing technical support and a dedicated account manager is included within the monthly fees for the provision of the application. This includes the standard SLAs as follows:

Telephone and email helpdesk 08.30 to 17.00 Monday to Friday.

Priority and timescale
1 (High) : Full system outage – no users at all can use the system. Response: 10 mins. Resolve 4 hours.
2 (Medium) : Partial system outage – a significant number of users are affected. Response 10 mins. Resolve: 1 business day
3 (Low): Minor – a handful of users or a part of the system is not working to Specification. Response: 10 mins. Resolve 1 business day
4 (Query) : Minimal impact. Response; 3 business days. Resolve 20 business days.

Initial set up and additional training, integration and development services are available as per the rate card provided.
Support available to third parties Yes

Onboarding and offboarding

Onboarding and offboarding
Getting started Customers receive a detailed welcome pack that includes a high level milestone plan (itemised below).
A. SHREWD ICS Welcome Pack - Introduction
B. Communication and Engagement
• Governance Structure Key Stakeholder Contact List
• Customer Readiness Questionnaire
• Communications Plan
• Introduction to ICS Communication Example
• SHREWD ICS One Page Flyer
C. Technical
• Technical Specification Document
A dedicated Deployment Team work to the plan with customers to configure SHREWD ICS. The initial configuration can be developed within 12 weeks depending on customer readiness. The Deployment Team offer support, both business and technical, and product training throughout the deployment process with a clear transition to the Business as Usual phase where a dedicated account manager will continue to support the customer with ongoing benefits realisation.
Service documentation Yes
Documentation formats
  • ODF
  • PDF
  • Other
Other documentation formats Microsoft.doc
End-of-contract data extraction All raw data is real-time and publicly available while retained by the source organisation(s). All data provided over the duration the contract could be provided as a CSV at contract end. Other formats available at additional cost.
End-of-contract process Source data feeds are switched off and accounts suspended.

Using the service

Using the service
Web browser interface Yes
Supported browsers
  • Internet Explorer 10
  • Internet Explorer 11
  • Microsoft Edge
  • Firefox
  • Chrome
  • Safari 9+
  • Opera
Application to install No
Designed for use on mobile devices No
Accessibility standards WCAG 2.1 A
Accessibility testing None (data is presented in visual formats in order to simplify complex system wide events and does not therefore support some assistive technologies)
What users can and can't do using the API SHREWD Web APIs is used by various users to push data into the SHREWD database.
API documentation Yes
API documentation formats
  • HTML
  • ODF
  • PDF
API sandbox or test environment Yes
Customisation available Yes
Description of customisation A fully configurable workflow manager allows users to build a governance process that matches their organisational requirements - the implementation co-production approach allowing dashboards to be custom designed for each user.


Independence of resources Our primary servers are on a managed cloud provision. We have application and server monitoring in place to monitor the resource usages to automatic alerts in place to provision new resources when there is a need for more resources.


Service usage metrics Yes
Metrics types Users/Agencies/Indicators usage/breakdown/performance metrics, Indicator update frequency/breakdown/total metrics, Features usage metrics.
Reporting types
  • Real-time dashboards
  • Reports on request


Supplier type Not a reseller

Staff security

Staff security
Staff security clearance Other security clearance
Government security clearance Up to Baseline Personnel Security Standard (BPSS)

Asset protection

Asset protection
Knowledge of data storage and processing locations Yes
Data storage and processing locations United Kingdom
User control over data storage and processing locations Yes
Datacentre security standards Complies with a recognised standard (for example CSA CCM version 3.0)
Penetration testing frequency Less than once a year
Penetration testing approach Another external penetration testing organisation
Protecting data at rest
  • Physical access control, complying with another standard
  • Other
Other data at rest protection approach Health Checks are performed by an ITHC CHECK accredited third party.
Data sanitisation process Yes
Data sanitisation type Deleted data can’t be directly accessed
Equipment disposal approach Complying with a recognised standard, for example CSA CCM v.30, CAS (Sanitisation) or ISO/IEC 27001

Data importing and exporting

Data importing and exporting
Data export approach A user can select various export options including format (as below) and which specific report they wish included in the export. Bespoke exports may be available at additional cost.
Data export formats
  • CSV
  • Other
Other data export formats
  • .xls
  • SQL
Data import formats
  • CSV
  • Other
Other data import formats .xls

Data-in-transit protection

Data-in-transit protection
Data protection between buyer and supplier networks
  • Private network or public sector network
  • TLS (version 1.2 or above)
  • Legacy SSL and TLS (under version 1.2)
Data protection within supplier network
  • TLS (version 1.2 or above)
  • Other
Other protection within supplier network The primary datastore is replicated using SSL. File based data transfers are password locked and encryption done using private/public key encryption algorithm on top of TLS.

Availability and resilience

Availability and resilience
Guaranteed availability Planned maintenance is undertaken outside business hours. The SLA describes response times for unplanned outages. Performance is governed through the contract terms and conditions.
Approach to resilience Non-Disclosure Agreements are in place with all of hosting provider suppliers. A risk assessment is undertaken for each supplier, with any required actions (which can include the supplier being subject to a security audit by the hosting provider) are conducted and managed by the Director for Supplier Management in conjunction with the Security Manager. All suppliers are audited as part
of ISO 27001 third party audit policies, which are in turn assessed by qualified and impartial third party ISO 27001 compliance assessors. Due diligence is performed on any security impacting third parties prior to selection and appropriate security requirements are built into contractual agreement where necessary. All strategic suppliers are assessed for their Business Continuity provision. Once reviewed the results of the assessment are analysed to assess the supply chain risk with regard to business continuity. Those suppliers considered to be inadequately prepared to deal with a BC scenario affecting their own organisation, which could therefore impact on the hosting provider to continue normal service operations, will be subject to further auditing, via a more detailed questionnaire or onsite at their premises. Third party suppliers are audited at least annually, with a shorter (quarterly) audit cycle for critical suppliers.
Outage reporting When service has a disruption or outage, we notify the users through emails.

Identity and authentication

Identity and authentication
User authentication needed Yes
User authentication
  • Public key authentication (including by TLS client certificate)
  • Limited access network (for example PSN)
  • Username or password
Access restrictions in management interfaces and support channels Access to accounts that are created by internal admin is limited. Created accounts use two factor authentication to be able to access the interface.
Access restriction testing frequency At least every 6 months
Management access authentication 2-factor authentication

Audit information for users

Audit information for users
Access to user activity audit information Users contact the support team to get audit information
How long user audit data is stored for Between 6 months and 12 months
Access to supplier activity audit information You control when users can access audit information
How long supplier audit data is stored for At least 12 months
How long system logs are stored for At least 12 months

Standards and certifications

Standards and certifications
ISO/IEC 27001 certification No
ISO 28000:2007 certification No
CSA STAR certification No
PCI certification No
Other security certifications No

Security governance

Security governance
Named board-level person responsible for service security Yes
Security governance certified Yes
Security governance standards ISO/IEC 27001
Information security policies and processes Complies with NHS Data Security Protection Toolkit (DSPT). Policies and processes followed or used include: Email Policy, Information Asset Register, Information Asset Access Control Policy, IG Steering Group Roles and Responsibilities, Terms of Reference for Information Governance Steering Group, Physical Security Checklist, IG Awareness and Basic Training for new staff, Annual IG Refresher Training for all staff, Network Security Policy, Information Security Policy, Compliance Audit Checklist, Remote Access Policy, Mobile Computing & Teleworking Policy, Assignment of Mobile Computing Form, Portable Devices Standard Operating Procedure, Risk Assessment Impact, Incident Management Procedure, Business Continuity Management Policy, IT Disaster Recovery Plan and Business Impact Analysis Report among others. All documents pertaining to Information Governance are available and accessible to all members of staff on the company intranet. The reporting structure entails that all staff report any and all incidents to the IG Lead, who works closely with the appointed SIRO, IAO and Caldicott Guardian. Spot checks are carried out quarterly, IG refresher training courses are undertaken annually with an IG assessment carried out at the end of the year to ensure staff remain IG aware.

Operational security

Operational security
Configuration and change management standard Conforms to a recognised standard, for example CSA CCM v3.0 or SSAE-16 / ISAE 3402
Configuration and change management approach Processes are in place to ensure that all changes to the system are authorised and tested prior to being employed. These are compliant with the relevant aspects of NHS Data Security Protection Toolkit. To track components of services over time, version control is enforced and access control records are kept and monitored. All change requests are documented and assessed. All staff are trained on operational procedures maintained on the company intranet, including: Access Control and Password Management Procedures, Change Control Process, Privacy Impact Assessment & IG Checklist, Project and Change Management Control Plan, Network Security Policy and Information Security Policy.
Vulnerability management type Conforms to a recognised standard, for example CSA CCM v3.0 or SSAE-16 / ISAE 3402
Vulnerability management approach Risk assessments to identify and mitigate issues are carried out as part of a process that is compliant with the relevant aspects of NHS Data Security and Protection Toolkit i.e. Information Security Assurance, Incident Management and Investigation.
Protective monitoring type Supplier-defined controls
Protective monitoring approach Measures are put in place to detect any attacks or unauthorised activity as part of a process compliant with the relevant aspects of the NHS Data Security and Protection Toolkit i.e. Information Security Assurance, Incident Management and Investigation. Potential threats to our services are assessed through employing a 'listener', upon the detection of a threat the relevant IP address is immediately isolated and blocked, whilst a potential threat to our software products is monitored and curtailed immediately with patches deployed automatically to the affected areas.
Incident management type Conforms to a recognised standard, for example, CSA CCM v3.0 or ISO/IEC 27035:2011 or SSAE-16 / ISAE 3402
Incident management approach Procedures are in place to ensure incidents are dealt with immediately to recover a secure and available service. The guidelines apply to all staff and include: all incidents must be reported to a line manager and/or IG lead immediately; an information incident report is then completed detailing; name of the individual reporting the incident, date of the incident, where the incident occurred, details of the incident and any initial actions taken, including who the incident has been reported to and the date the report is created. The line manager / IG lead investigate the incident and employ the necessary measures.

Secure development

Secure development
Approach to secure software development best practice Conforms to a recognised standard, but self-assessed

Public sector networks

Public sector networks
Connection to public sector networks Yes
Connected networks Health and Social Care Network (HSCN)


Price £4999 per instance per month
Discount for educational organisations No
Free trial available No

Service documents

pdf document: Pricing document pdf document: Skills Framework for the Information Age rate card pdf document: Service definition document pdf document: Terms and conditions
Service documents
Return to top ↑