Procurement & supplier assurance

Give procurement the evidence before they have to chase for it.

Raeburn Consulting maintains a structured assurance set for enterprise and public-sector due diligence. We distinguish operational controls, self-assessments and independent certifications so buyers can see exactly what each claim means.

Commercial contracting

MSA, SOW, DPA, NDA, SLA, acceptable-use, data-processing, security, incident, liability, IP and subcontracting templates are maintained for appropriate engagements.

Security & resilience

Security Whitepaper, secure-development evidence, responsible disclosure, business continuity, tested backup restoration and security metrics.

Privacy & AI governance

Privacy commitments, DPA position, supplier/subprocessor governance, AI Responsible Use standard and model/provider cards.

Accessibility

The public website records completion and a pass against WCAG 2.2 Level AA accessibility testing, with ongoing re-testing after material changes.

Public-sector readiness

Registered on Find a Tender / Central Digital Platform; registration is not represented as framework membership, endorsement or contract award.

Questionnaire support

Approved response library for CAIQ, SIG-style, NIST, ISO 27001-style, Cyber Essentials-style, CAF, privacy, AI security and supplier security questions.

Assurance status language

  • Operational: a control/process is in current use.
  • Self-assessed: Raeburn has completed an internal or scheme self-assessment; this is not independent certification.
  • Independently verified/certified: used only when a current external report or certificate exists for the stated scope.
  • Registered: procurement/platform registration only; not endorsement, framework admission or award unless explicitly verified.

Governance & tender evidence

Security

Disclosure, SDLC and assurance evidence.

Business Continuity

Recovery, supplier contingency and communications.

AI Governance

Data, models, human oversight and AI security.