Submit.com logo
  1. Blogs
  2. 9 Compliance Checks for Grant Software in Local Government

9 Compliance Checks for Grant Software in Local Government

9 Compliance Checks for Grant Software in Local Government

Posted on: July 31, 2026

l

by Richa Padhi

Today: August 2, 2026






9 Compliance Checks for Grant Software in Local Government

9 Compliance Checks for Grant Software in Local Government

Before buying grant management software, a local authority should confirm it provides a complete audit trail, role-based access, UK GDPR alignment, recognised security certifications and accessible application forms, and that it can be bought through a compliant procurement route. These nine checks cover the ground auditors and scrutiny committees examine.

Most grant teams shortlist software on features: form building, scoring, reporting. Then information governance, legal and procurement get involved, and the questions change. Where does the data sit? Can we prove a panel decision was fair two years later? Will this pass a Cyber Essentials check? Can we buy it without a full tender?

Answer those early and you avoid a shortlist favourite failing at the final gate. The checks below are the ones that decide whether a platform is fit for a council to run public money through. Turn them into a scorecard and score every vendor against the same list.


Nine compliance checks for grant management software A numbered checklist of nine compliance and audit checks for local government grant software, from independent security certifications to data hosting and retention controls. Nine compliance checks at a glance 1Independent security certifications 2UK GDPR and a signed data processing agreement 3A complete, tamper-resistant audit trail 4Role-based permissions and separation of duties 5Transparency Code reporting and export 6Subsidy Control Act record-keeping 7Accessible application forms (WCAG 2.2 AA) 8A compliant procurement route 9Data hosting, residency and retention controls

1. Does it hold independent security certifications your governance team recognises?

Start here, because it is often the check that removes vendors from the running fastest. Two certifications matter most for a council: Cyber Essentials, the UK government backed scheme that is frequently a contractual requirement for suppliers handling public sector data (NCSC, Cyber Essentials), and SOC 2, an independent audit of how a supplier manages security controls over time.

Ask for the certificate, not a claim on a marketing page, and check the date. Submit.com holds SOC 2 Type 1 and Type 2 and is Cyber Essentials certified, with the detail set out on its security and compliance page.

2. Is it aligned to UK GDPR, with a signed data processing agreement?

Grant applications hold personal data, and often special category data: household circumstances, health, financial hardship. Under UK GDPR and the Data Protection Act 2018, your council remains the data controller, so you need a data processing agreement that names the vendor as processor, lists sub-processors, and sets out data minimisation, retention and breach handling (ICO, UK GDPR guidance).

Ask to see the DPA before you sign anything, and check the platform supports a Data Protection Impact Assessment for higher-risk schemes. If a vendor cannot produce a DPA on request, treat that as a finding.

3. Can it produce a complete, tamper-resistant audit trail?

This is the check that protects you when a decision is challenged. An audit trail is a timestamped record of who did what and when across every application: each score entered, each tag applied, each internal comment, each message sent. When a scrutiny committee, an internal auditor or an FOI request asks how a particular award was decided, the answer should already exist in the system rather than being reconstructed from inboxes.

Submit.com logs every score, tag, comment and message against the person who made it and the time it happened, and feeds that record straight into reporting. You can read how the audit trail and reporting tools work in practice.

4. Does it enforce role-based permissions and separation of duties?

A reviewer, an administrator and a finance officer should not all see the same thing. Role-based permissions let you decide exactly what each person can view and do, so external panel members see only the applications assigned to them and cannot access personal data they have no reason to touch.

Separation of duties matters just as much: the person who scores an application should not be the same person who approves the payment. Check the platform lets you split those roles and evidence the split. Submit.com supports granular role-based permissions for staff and external reviewers alongside its audit trail, so who did what stays clear.

5. Can you meet Transparency Code reporting from the same records?

English councils publish spend and certain grant and contract data under the Local Government Transparency Code 2015 (GOV.UK, Local Government Transparency Code 2015). If your grant data lives in a system that cannot export cleanly, transparency publishing and FOI responses become a manual scramble every time.

Check you can filter the underlying records and export them, usually to CSV, in a shape your publishing and finance colleagues can use without rekeying. The reporting should draw on the same data your reviewers already entered, not a separate spreadsheet kept alongside.

6. Does it capture what you need for Subsidy Control Act reporting?

Grants to businesses can count as subsidies under the Subsidy Control Act 2022, and awards above the relevant threshold must be recorded on the government subsidy transparency database (legislation.gov.uk, Subsidy Control Act 2022). That means your application and assessment records need to capture the fields you will later have to report against, including the recipient, the amount and the purpose.

You do not need the software to make the subsidy assessment for you. You do need it to hold the right information in a structured, exportable form so the assessment and any reporting are straightforward rather than a retrospective data-gathering exercise.

7. Are the application forms accessible to WCAG 2.2 AA?

Your applicant portal is a public sector digital service, so it falls under the Public Sector Bodies (Websites and Mobile Applications) Accessibility Regulations 2018, which require conformance with WCAG 2.2 level AA (GOV.UK accessibility guidance; W3C, WCAG 2.2). A form that residents cannot complete with a screen reader or keyboard is both a compliance gap and a barrier to the people your funding is meant to reach.

Ask each vendor for an accessibility statement covering the applicant-facing forms, and test the live portal with your own accessibility tools before you commit. Do not accept a general assurance without evidence for the pages applicants actually use.

8. Can you buy it through a compliant procurement route?

A platform that ticks every other box is no use if you cannot buy it within your procurement rules. Where a supplier is on an approved framework such as G-Cloud on the Digital Marketplace, a council can procure compliantly without running a full open tender, subject to its own standing orders (Crown Commercial Service, Digital Marketplace).

Submit.com is a G-Cloud listed supplier and publishes its pricing openly, so you can size the cost against your budget before committing time to a full evaluation. You can review the current figures on the pricing page.

9. Where is the data hosted, and can you control retention and exit?

Three questions belong together here. Where is the data physically hosted, and by which cloud provider? Can you set your own retention and deletion policies so records are kept no longer than they need to be? And if you leave, how do you export everything cleanly? Get these in writing rather than relying on a sales conversation.

Submit.com hosts on AWS infrastructure, offers configurable data retention and deletion, and states that customers retain ownership of all their data. Confirm the hosting region and data residency arrangements that apply to your contract directly with the vendor before you sign.

Turn the nine checks into a scorecard

Score every shortlisted platform against the same nine checks, and ask for evidence rather than assurances: the certificate, the DPA, the accessibility statement, a live look at the audit trail. The pattern that separates a genuine public sector platform from a general form builder is simple. The compliance features are built into the workflow, not bolted on, and the vendor can prove it.

Note for Irish councils

If you run grant programmes for an Irish local authority, the same nine checks apply, but the frameworks differ. GDPR still governs data protection, accessibility follows S.I. No. 358/2020, and procurement runs through eTenders and the Office of Government Procurement rather than G-Cloud. Confirm the specific obligations with your own procurement and data protection colleagues.

Frequently asked questions

What compliance requirements apply to grant management software in UK local government?

UK local authorities must meet UK GDPR and the Data Protection Act 2018, publish spend and decision data under the Local Government Transparency Code 2015, record subsidies under the Subsidy Control Act 2022, and make digital services accessible to WCAG 2.2 AA under the Public Sector Bodies Accessibility Regulations 2018. Grant management software should support all four.

Why does a grant management system need an audit trail?

An audit trail gives a timestamped record of who scored, changed, approved or communicated on each application. Scrutiny committees, internal auditors and FOI responses all rely on it. Without one, proving that a decision was fair and properly made means reconstructing it from emails and spreadsheets.

Is Cyber Essentials required for public sector software?

Cyber Essentials is a UK government backed scheme and is often a contractual requirement for suppliers handling public sector data. Many councils also look for SOC 2 as an independent security audit. Submit.com holds Cyber Essentials and SOC 2 Type 1 and Type 2 certifications.

Can councils buy grant management software without running a full tender?

Yes. Where the supplier is listed on an approved framework such as G-Cloud on the Digital Marketplace, a council can buy compliantly without a full open tender, subject to its own procurement rules. Submit.com is a G-Cloud listed supplier.

See the compliance features before you commit

Submit.com is built for UK and Irish public sector grant teams, with the audit trail, role-based permissions and certifications these checks call for. Get a quote scoped to your programmes, or see the platform first.

Request a quote

Prefer to look first? Book a demo and we will walk you through the audit trail live.



Related Posts

Comments

0 Comments

Submit a Comment