Skip to main content

We've saved some files called cookies on your device. These cookies are:

  • essential for the site to work
  • to help improve our website by collecting and reporting information on how you use it

We would also like to save some cookies to help tailor communications.

BETA
You're viewing an updated version of this service - your feedback will help us to improve it.

Contract Award Notice

Provision of an ISO27001 Internal Auditor - Readvertised

  • First published: 08 January 2025
  • Last modified: 08 January 2025
  • Record interest

     

  • This file may not be fully accessible.

  •  

The buyer is not using this website to administer the notice.

To record your interest or obtain additional information or documents please find instructions within the Full Notice Text. (NOTE: Contract Award Notices and Prior Information Notices do not normally require a response)

Contents

Summary

OCID:
ocds-kuma6s-146365
Published by:
Social Care Wales
Authority ID:
AA0289
Publication date:
08 January 2025
Deadline date:
-
Notice type:
Contract Award Notice
Has documents:
No
Has SPD:
No
Has Carbon Reduction Plan:
No

Abstract

Introduction ISO 27001 is an internationally recognised standard for managing and maintaining information security within businesses. It outlines the requirements for an information security management system (ISMS), and provides a framework for establishing, implementing, maintaining and continually improving business information security. Social Care Wales has held ISO 27001:2013 certification since 2008, achieving our most recent triennial recertification in April 2024. We are amid transitioning to the 27001:2022 standard and are due to transition in February 2025. What is required / ‘The Requirements’ We are seeking the provision of an ISO 27001 Internal Auditor to evaluate and ensure the continued effectiveness and compliance of our Information Security Management System (ISMS) in accordance with the ISO 27001 standard. The audit should be performed independently and aligned with the requirements of the ISO IEC 27001:2013 (ISO 27001) standard. The Internal Auditor will: - Prepare and agree an ISMS audit scope and engagement letter with Social Care Wales; - Review and assess the ISMS documentation, including policies, procedures, and controls in line with the standard; - Plan and execute internal audits, including the preparation of audit plans and schedules; - Interview relevant personnel and gather evidence to assess compliance and effectiveness; - Evaluate the implementation of risk assessments and treatment plans; - Analyse audit findings and prepare detailed reports outlining strengths, weaknesses, and recommendations for improvement; - Present findings to senior management and relevant stakeholders; - Follow up on previous audit findings to ensure corrective actions have been implemented; - Follow through any external certification audit findings and remedial actions received by Social Care Wales. Please see Specification for more detail

Full notice text

CONTRACT AWARD NOTICE – NATIONAL

SERVICES

1 Authority Details

1.1

Authority Name and Address


Social Care Wales

South Gate House, Wood Street,

Cardiff

CF10 1EW

UK

Procurement Team

+44 3003033444


http://www.socialcare.wales

2 Contract Details

2.1

Title

Provision of an ISO27001 Internal Auditor - Readvertised

2.2

Description of the contract

Introduction

ISO 27001 is an internationally recognised standard for managing and maintaining

information security within businesses. It outlines the requirements for an information security management system (ISMS), and provides a framework for establishing, implementing, maintaining and continually improving business information security.

Social Care Wales has held ISO 27001:2013 certification since 2008, achieving our most recent triennial recertification in April 2024. We are amid transitioning to the 27001:2022 standard and are due to transition in February 2025.

What is required / ‘The Requirements’

We are seeking the provision of an ISO 27001 Internal Auditor to evaluate and ensure the continued effectiveness and compliance of our Information Security Management System (ISMS) in accordance with the ISO 27001 standard.

The audit should be performed independently and aligned with the requirements of the ISO IEC 27001:2013 (ISO 27001) standard.

The Internal Auditor will:

- Prepare and agree an ISMS audit scope and engagement letter with Social Care Wales;

- Review and assess the ISMS documentation, including policies, procedures, and controls in line with the standard;

- Plan and execute internal audits, including the preparation of audit plans and schedules;

- Interview relevant personnel and gather evidence to assess compliance and effectiveness;

- Evaluate the implementation of risk assessments and treatment plans;

- Analyse audit findings and prepare detailed reports outlining strengths, weaknesses, and recommendations for improvement;

- Present findings to senior management and relevant stakeholders;

- Follow up on previous audit findings to ensure corrective actions have been implemented;

- Follow through any external certification audit findings and remedial actions received by Social Care Wales.

Please see Specification for more detail

2.3

Notice Coding and Classification

72810000 Computer audit services
79212000 Auditing services
79212200 Internal audit services
1000 WALES
1010 West Wales and The Valleys
1011 Isle of Anglesey
1012 Gwynedd
1013 Conwy and Denbighshire
1014 South West Wales (Carmarthenshire, Pembrokeshire, Ceredigion)
1015 Central Valleys (Merthyr Tydfil, Rhondda Cynon Taf)
1016 Gwent Valleys (Torfaen, Blaenau Gwent, Caerphilly)
1017 Bridgend and Neath Port Talbot
1018 Swansea
1020 East Wales
1021 Monmouthshire and Newport
1022 Cardiff and Vale of Glamorgan
1023 Flintshire and Wrexham
1024 Powys

2.4

Estimated Total Value

3 Procedure

3.1

Type of Procedure

Single stage

4 Award of Contract

4.1

Successful Bidders

4.1.1

Name and Address of successful supplier, contractor or service provider





Tmc3 Limited

81-83A Allerton Road, Mossley Hill,

Liverpool

L182DA

AF




5 Other Information

5.1

Reference number attributed to the notice by the contracting authority

N/a

5.2

Date of Contract Award

 08-01-2025

5.3

Number of tenders received

7

5.4

Other Information

(WA Ref:147136)

5.5

Additional Documentation

N/a

5.6

Publication date of this notice:

 08-01-2025

Coding

Commodity categories

ID Title Parent category
79212000 Auditing services Accounting and auditing services
72810000 Computer audit services Computer audit and testing services
79212200 Internal audit services Auditing services

Delivery locations

ID Description
1017 Bridgend and Neath Port Talbot
1022 Cardiff and Vale of Glamorgan
1015 Central Valleys (Merthyr Tydfil, Rhondda Cynon Taf)
1013 Conwy and Denbighshire
1020 East Wales
1023 Flintshire and Wrexham
1016 Gwent Valleys (Torfaen, Blaenau Gwent, Caerphilly)
1012 Gwynedd
1011 Isle of Anglesey
1021 Monmouthshire and Newport
1024 Powys
1014 South West Wales (Carmarthenshire, Pembrokeshire, Ceredigion)
1018 Swansea
1000 WALES
1010 West Wales and The Valleys

Alert region restrictions

The buyer has restricted the alert for this notice to suppliers based in the following regions.

ID Description
There are no alert restrictions for this notice.

Document family

Notice details
Publication date:
28 November 2024
Deadline date:
12 December 2024 00:00
Notice type:
Contract Notice
Authority name:
Social Care Wales
Publication date:
08 January 2025
Notice type:
Contract Award Notice
Authority name:
Social Care Wales

About the buyer

Main contact:
N/a
Admin contact:
N/a
Technical contact:
N/a
Other contact:
N/a

Further information

Date Details
No further information has been uploaded.

0800 222 9004

Lines are open 8:30am to 5pm Monday to Friday.

Rydym yn croesawu galwadau'n Gymraeg.

We welcome calls in Welsh.