If we haven’t worked together before, this page explains how an engagement typically runs, from first conversation to invoice, and how we handle procurement and data security along the way. It’s a rough guide; we’re happy to adapt to your local processes and preferences.
How an engagement runs
- Step 1 — A short chat
We have a short conversation to determine what you need, and to gather enough information to offer you a quotation.
- Step 2 — Quotation
We send the quotation through with our Terms and Conditions (including our Data Processing Agreement and Schedule of Processing Activities). Quotations are valid for 14 calendar days.
- Step 3 — Procurement and purchase order
If you accept the quotation, we ask you to set us up on your procurement system and issue a purchase order (PO) before we start working. Your procurement team will usually ask us to complete a new supplier form.
- Step 4 — Getting going
Once the PO is issued we get going. For investigations, we ask you to complete a case handover form and provide copies of your relevant policies and regulations.
- Step 5 — Scope and visibility
We agree a Terms of Reference or scope document for your engagement, which you review before we begin. For investigations we maintain an investigation log throughout, so you can see the latest activity at any time.
- Step 6 — Completion and invoice
Once the work is delivered — an investigation outcome, training days, or consultancy documents — we send the invoice; payment is due within 30 calendar days. If you ask us to present at a disciplinary panel or advise on an appeal or review, that work is invoiced separately, and the investigation invoice remains payable on completion of the investigation itself.
For your procurement team
Commissioning an external supplier usually involves an internal approval process, and we’ve tried to make that as easy as possible. Our two-page capability note covers our experience, qualifications, insurance, and data security arrangements, ready for your supplier forms.
Our Data Processing Agreement (DPA) and Schedule of Processing Activities (SPA) are appended to our Terms and Conditions and are available on request before any commitment is made.
Data security
- Dedicated Microsoft 365 Business account
- OneDrive with role-based permissions
- Multi-factor authentication throughout
- No personal or shared accounts
All case documentation is handled through a dedicated Microsoft 365 Business (Enterprise) account. Data is stored in OneDrive with access controlled via role-based permissions and Multi-Factor Authentication throughout. No personal or shared accounts are used for case material.
Questions about any of this? Get in touch and we’ll talk it through.