Named owners keep every article dated and searchable
Turns knowledge into bid advantage
Bid flow to AI rules
Secure governance categories standardise every pursuit
From first qualification to final governance
Multiple dynamic propriety data assets ie Data banks
Bespoke layers of intelligence
Dossier, pursuit and market knowledge combined
Evidence in daily use
Continuously referenced by bid and account teams
Not shelfware - active bid fuel
All layers, in sequence
3 of 18 layers live · 8 surfaces
Layers run in sequence from 1 to 18. The Market Foundation Bank holds layers 1 to 6 and the Pursuit and Win Bank holds layers 7 to 18. Live layers open straight into the content behind them. Planned layers are held in the source bank until their surfaces are built.
16Discriminator injectionEdge function · buyer-specific at runtime
Multiple dynamic propriety data assets ie Data banks
Three stores behind the engine
Knowledge is held in three separate stores. The Keelforge Data Dossier holds everything about Keelforge, the Pursuit and Win Bank holds layers 7 to 18 and the Market Foundation Bank holds layers 1 to 6.
Keelforge Data Dossier
Everything about Keelforge. The single firm record. Who we are, what we sell, what we have delivered, who signed it and when it was last checked.
dossier_entries
Executive Guardian (CEO / CFO sign-off)
Updated 2026-08-15
RetrievalAnswers first on any claim about Keelforge
Defence and national security work runs on the same governed flow with an added handling layer for classification, clearance and supply chain assurance. These are the positions the firm competes on and the proof that stands behind each one.
6 of 6 strengths
Secure by design delivery
Security architecture, assurance and accreditation built into the delivery method rather than bolted on at the end.
ProofCyber Essentials Plus and ISO 27001 scoped to delivery teams, with an auditable control ledger per engagement.
BuyersMOD, national security, critical national infrastructure
Classify the opportunity at intake and set the handling rule before any document is uploaded.
Route OFFICIAL SENSITIVE and above away from general agents, with human only drafting where the contract requires it.
Confirm clearance currency for every named person before the key people plan is submitted.
Record the procurement regime, defence or otherwise, so gate thresholds and timelines are generated correctly.
Flow security obligations to every subcontractor and hold their evidence in the same library.
Financial services layer
Where Keelforge is strong
Financial services work runs on the same governed flow with an added regulatory layer for evidence currency, named accountability and model risk. These are the positions the firm competes on and the proof that stands behind each one.
1 of 6 strengths
Third-party and outsourcing assurance
The firm's own third-party register, subcontractor evidence and exit-plan positions are surfaced in every response, in the format required by PS21/3 and equivalent regimes.
ProofSubcontractor evidence library carries signed material, service definitions and exit plans, held to the same standard as the firm's own evidence.
BuyersThird-party risk teams, procurement, operational resilience leads, group internal audit.
Classify the opportunity at intake against the buyer's regulatory perimeter and set the evidence-signing rule before any document is uploaded.
Route any material touching prudential, conduct or operational-resilience regimes through a named signatory of appropriate seniority - SMF-mapped where the buyer operates under SM&CR.
Confirm evidence currency for every cited source before the response is submitted and refuse citations older than the buyer's stated recency threshold.
Record the procurement regime - Public Contracts Regulations, PRA outsourcing, FCA operational resilience or the buyer's own framework - so gate thresholds and timelines are generated correctly.
Flow assurance obligations to every subcontractor and hold their signed evidence in the same library, refreshed on the buyer's stated cadence.
Government and public sector layer
Where Keelforge is strong
Government and public sector work runs on the same governed flow with an added transparency layer for procurement regime, social value and public accountability. These are the positions the firm competes on and the proof that stands behind each one.
6 of 6 strengths
Procurement Act 2023 fluency
Every response is drafted against the current UK procurement regime, with the correct notice type, gateway and Most Advantageous Tender language, not legacy PCR 2015 phrasing.
ProofIntake classifies the procurement regime at the outset and the drafting scaffold refuses to generate legacy phrasing on notices issued under the Procurement Act.
BuyersCentral government departments, arm's length bodies, local authorities, NHS trusts, blue light services, devolved administrations.
Social value commitments are drafted as auditable deliverables against the Social Value Model themes, with named owners, measurable outcomes and reporting cadence - not aspirational sentences.
ProofEvery social value commitment carries a Model MAC reference, an owner, a measurement method and the evidence trail that will be reported back to the buyer post-award.
BuyersCabinet Office, central government commercial teams, local authority procurement, devolved government commercial functions.
Public accountability obligations - FOI, subject access, publication of contract award notices, algorithmic transparency - are drafted into the response rather than bolted on after award.
ProofResponse includes named FOI single point of contact, ATRS record commitment where AI or automated decision-making is in scope and a pre-drafted publication schedule aligned to Contracts Finder and Find a Tender.
BuyersGovernment Digital Service, Central Digital and Data Office, information rights teams, transparency and open government leads.
Digital deliverables are drafted against WCAG 2.2 AA and the Public Sector Bodies Accessibility Regulations and inclusion commitments are drafted against the Public Sector Equality Duty from the schedule scaffold onwards.
ProofAccessibility statement template, PSED assessment position and inclusion targets are surfaced as mandatory schedule items before drafting is allowed to proceed.
BuyersGovernment service teams, NHS Digital, local authority digital and inclusion leads, equality and diversity commissioners.
Supply chain plans surface SME and VCSE participation with named partners, flowed-down obligations and the same evidence standard applied to the prime.
ProofSubcontractor register carries organisation type, SME or VCSE status, contract value share and signed evidence, exportable in the format central government reporting requires.
BuyersCabinet Office SME leads, local authority procurement, third sector partnership teams, integrated care system commercial functions.
Every decision, override and human sign-off is written to an immutable audit line, exportable to internal audit, the National Audit Office, the Public Accounts Committee and any subsequent inquiry without post-hoc reconstruction.
ProofAudit lines carry actor, role, action, timestamp and hash and can be exported in the format NAO and internal audit teams accept.
BuyersHeads of internal audit, NAO liaison, accounting officers, permanent secretaries, chief executives of arm's length bodies.
Classify the opportunity at intake against the correct procurement regime - Procurement Act 2023, legacy Public Contracts Regulations 2015 for legacy pipeline, Defence and Security Public Contracts Regulations, or devolved equivalent - and set the notice type before any document is uploaded.
Route any material touching automated decision-making, AI or algorithmic assessment through the Algorithmic Transparency Recording Standard workflow, with a named human accountable owner.
Confirm accessibility, inclusion and social value commitments before the response is submitted - no schedule is allowed to complete without a named owner and a measurable outcome for each.
Record the buyer's public accountability position - FOI publication schedule, transparency commitments, ATRS scope - so post-award reporting obligations are generated correctly.
Flow public sector obligations to every subcontractor, including SME and VCSE partners and hold their signed evidence in the same library to the same standard as the prime.
Health and social care layer
Where Keelforge is strong
Health and social care work runs on the same governed flow with an added assurance layer for clinical safety, data protection and patient-facing accountability. These are the positions the firm competes on and the proof that stands behind each one.
6 of 6 strengths
Clinical safety by design
Every model output that touches a clinical pathway carries a documented safety case. DCB0129 and DCB0160 are addressed at intake rather than retrofitted and the safety case travels with the deliverable through every review.
ProofA named clinical safety officer is appointed at intake, the hazard log opens on day one and closes on the last day of the warranty period and every material change writes to the hazard log.
BuyersNHS England Digital, NHS trusts running frontline clinical systems, Integrated Care Boards and independent sector providers.
Digital Technology Assessment Criteria and Data Security and Protection Toolkit are treated as gate conditions, not as compliance homework. The evidence pack is assembled during the bid so submission-time is the confirmation of what already exists.
ProofDTAC v3 assessment complete before commercial close, DSPT status current within the annual cycle and a documented remediation plan for any Standards Met with Improvements categorisation.
BuyersNHS trusts and Integrated Care Boards commissioning digital services, primary care networks and Health and Care providers procuring under the DTAC framework.
Every patient-facing surface meets WCAG 2.2 AA at the point of first release, not as a post-launch remediation. Accessibility is written into the acceptance criteria, tested with users with lived experience of the target condition and re-tested on every material release.
ProofNamed accessibility lead, WCAG 2.2 AA audit report from an independent assessor and user testing including at least three participants with lived experience of the target condition.
BuyersNHS trusts running patient portals, primary care networks digitising patient communication and public bodies procuring citizen-facing health services.
Information Governance is a first-class engineering concern. The Caldicott Guardian's questions are answered before they are asked. Data flow diagrams, DPIAs and Records of Processing Activities are current on the day of submission and stay current through the delivery.
ProofNamed Caldicott engagement, current DPIA and ROPA at every release and a documented data flow diagram that survives clinical audit.
BuyersNHS trusts and Integrated Care Boards processing patient-identifiable data, Health and Care providers subject to national data opt-out and any provider working with pseudonymised research datasets.
Deployment into a live clinical environment is scheduled around clinical demand, not around engineering convenience. Every change window has a named rollback owner and a named clinical sign-off. No release lands during peak clinical demand without explicit clinical leadership approval.
ProofChange advisory board with named clinical representation, documented rollback plan tested in staging and a communications plan reviewed by the affected clinical service.
BuyersNHS trusts and Integrated Care Boards running frontline clinical systems, ambulance trusts and community services managing 24/7 operations.
Every decision, sign-off and remediation writes to a governance record designed to survive external scrutiny. Regulator, commissioner and independent audit all read the same evidence chain from the same source.
ProofImmutable audit log covering intake, delivery and warranty; a documented decision register with named signatories; and a warranty-period governance summary produced within 20 working days of last delivery.
BuyersNHS trusts and Integrated Care Boards subject to Care Quality Commission oversight, providers subject to national data opt-out audits and any Health and Care provider procuring under NHS commissioning frameworks.
Every clinical pathway change opens a hazard log entry before any deployment. The hazard log closes only when the safety officer signs it off.
Patient-identifiable data never leaves the approved processing environment. Where analysis requires movement, pseudonymisation happens at the source and the mapping stays under Caldicott control.
Independent clinical safety review is scheduled at intake for any deliverable touching a clinical decision. Independent means independent of the delivery team.
WCAG 2.2 AA is a release gate for every patient-facing surface. Failing the gate blocks release until remediation lands.
Change windows are agreed with clinical leadership on a rolling four-week horizon. No exceptions during declared operational pressure escalation levels.
Article library
18 of 18 shown
Every article is owned, dated and written to be acted on. Open one to see the guidance and why it is useful, valuable and impactful to the way we bid.
Topic
Type
Value
Defence strength
Tag
Sort by
Reading list
My reading list
Nothing saved yet
Save any article with the bookmark button and it will be kept here on this device, ready to reuse.
The certifications, statements and named contacts to have ready before a tender lands. Cyber Essentials Plus, ISO 27001, DSPT and supply chain assurance.
How Keelforge knowledge is split across the Keelforge Data Dossier, the Pursuit and Win Bank (layers 7 to 18) and the Market Foundation Bank (layers 1 to 6).