+44 (0)2080591059 [email protected]

policies certificates & Licences

COST ASSURANCE, AUDIT & STRATEGY ADVISORY

WELCOME TO CFBL CONSULTING!

AUDITS      PROTOCOLS & ESG FINANCE STRATEGy & ADVISORY

standards

Our Professional Standards & Memberships

Licences 

All members who wish to engage in public practice, as defined in CIMA’s member-in-practice rules, must hold a current practising certificate.  

The CFBL practising certificate is a license to practice and is issued following admission to CIMA’s member in-practice register or following successful annual renewal.   

CIMA has an obligation to protect the public; who must have confidence in the integrity and standards of those who are licensed by the Institute.  

CIMA is aware that circumstances change. To ensure that only registered and monitored members in practice are licensed; practising certificates are only valid for one calendar year. A replacement practising certificate will be re-issued once your annual member-in-practice renewal is completed.    

A mark of professionalism  

CIMA members in practice achieve and maintain professionalism through compliance with regulations around CPD, anti-money laundering and mandatory requirement policies. The practising certificate highlights that the holder has attained a level of competency to offer management accountancy services to the public and does so in an ethical and professional manner.     

Conditions of use  

Holders of CIMA practising certificates are entitled to call themselves chartered management accountants. Find out more about the use of the title.  

To maintain their practising certificate members must renew their member in-practice status annually with CIMA. Failure to do so when requested can result in losing members in practice status, and a full reapplication being required to regain entry onto CIMA’s register.    

All members working in practice must be compliant with CIMA’s mandatory requirements. CIMA conducts quality assurance checks on these documents and selected members are required to send in copies as confirmation of compliance and to ensure they meet CIMA’s quality criteria.  

Any member found to be providing accounting services whilst not registered as a member in practice will be in breach of the Member in Practice Rules (Rule 12) and may be liable to disciplinary action by the institute. 

    Licences

    • Below is a list of our licences, scroll to review each.  
    • AICPA – CIMA Practicing Certificate  
    • Cyber Essentials Certificate  
    • Data Protection Registration Certificate  
    • FreeAgent Practitioner Certificate  
    • Prompt Payment Charter Certificate  
    • Rail Supply Group Charter Certificate  
    • RISQS Supplier Qualification Certificate  
    • Trust Pilot  
    • VAT Certificate  

      Policies

      Below is a list of our external policies, scroll further down to review each.  

      • Accessibility Statement  
      • Anti-Bribery and Corruption Policy  
      • Anti-Fraud and Corruption Policy  
      • Artificial Intelligence and Content Generation Policy  
      • Audit and Compliance Policy  
      • Change Management Policy  
      • Cloud Services and Hosting Policy  
      • Code of Conduct  
      • Code of Conduct for Digital Services  
      • Community Guidelines / Moderation Policy  
      • Complaints and Appeals Policy  
      • Conflict of Interest Policy  
      • Content Management and Publishing Policy  
      • Contract Management Policy  
      • Copyright and Intellectual Property Policy  
      • Corporate Social Responsibility (CSR) Statement  
      • Cybersecurity Policy  
      • Data Encryption and Storage Policy  
      • Data Privacy and Security Policy  
      • Data Protection Policy  
      • Device and Endpoint Security Policy  
      • Digital Identity and Trust Framework Compliance  
      • Digital Inclusion and Assisted Digital Support Policy  
      • Diversity and Inclusion Statement  
      • Donations and Sponsorship Policy  
      • Driver Safety Policy  
      • Equal Employment Opportunity Policy  
      • Equality, Diversity, and Inclusion (EDI) Statement  
      • Equality, Diversity, and Inclusion Statement  
      • Financial Transparency and Reporting Policy  
      • Freedom of Information (FOI) Policy  
      • Grant Management Policy  
      • Health and Safety Policy  
      • Health and Safety Statement  
      • Incident Response and Breach Notification Policy  
      • Information Security Policy  
      • Legal Disclaimer  
      • Meeting and Agenda Publication Policy  
      • Mobile and App Services Policy  
      • Modern Slavery and Human Trafficking Statement  
      • Multilingual and Plain Language Policy  
      • News and Announcements Policy  
      • Open Data Policy  
      • Privacy Policy  
      • Procurement and Tendering Policy  
      • Public Engagement and Consultation Policy  
      • Public Notices and Alerts Policy  
      • Quality assurance  
      • Quality Assurance Statement  
      • Records Management and Retention Policy  
      • Remote Working Policy  
      • Service Availability and Continuity Policy  
      • Service Level Agreement (SLA) Policy  
      • Social Media Use Policy  
      • Software and Patch Management Policy  
      • Spending and Budget Disclosure Policy  
      • Supplier Code of Conduct  
      • Sustainability and Net Zero Carbon Statement  
      • Sustainability and net zero carbon statement  
      • Terms of Use / Acceptable Use Policy  
      • Third-Party Integration and API Use Policy  
      • Transparency and Accountability Statement  
      • User Access and Authentication Policy  
      • User Feedback and Satisfaction Policy  
      • User Support and Helpdesk Policy  
      • Value for Money and Efficiency Policy  
      • Website Archiving Policy  
      • Website Maintenance and Uptime Policy  
      • Whistle blower Policy  
      • Workplace Health and Safety Policy 

      Diversity, Inclusion, and Equal Opportunity 

      Diversity and Inclusion Statement 

      CFBL celebrates diverse perspectives and backgrounds, understanding that a rich mix of experiences drives more innovative and effective solutions for our SME and infrastructure clients. Examples of how we achieve this are by: 

      • Hosting cultural-awareness and unconscious-bias workshops to broaden understanding and empathy across the firm. 
      • Encouraging employee-led resource groups that share experiences and best practices for inclusive teamwork. 
      • Tracking diversity metrics in recruitment, promotions, and project staffing to ensure balanced representation. 
      • Providing reasonable workplace adjustments and accessible working arrangements for employees and clients with disabilities or additional needs. 
      • Regularly reviewing workplace policies, systems, and facilities to remove barriers that may disadvantage individuals with protected characteristics. 
      • Monitoring diversity and inclusion outcomes to identify opportunities for continual improvement and support compliance with applicable equality legislation. 

       

      Equal Employment Opportunity Policy 

      Our recruitment, retention, and promotion processes ensure fair consideration for all candidates and staff, in compliance with UK employment law and best-practice guidelines. Examples of how we achieve this are by:  

      • Publishing clear selection criteria and flexible working options in all job adverts. 
      • Monitoring workforce demographics and promotion rates to identify and address any disparities. 
      • Providing line managers with training on lawful interviewing techniques and anti-discrimination practices. 
      • Offering reasonable adjustments throughout recruitment, onboarding, training, and employment to support equal access to opportunities. 
      • Investigating identified disparities through objective workforce analysis and implementing proportionate improvement measures where barriers are identified. 
      • Conducting periodic reviews of recruitment and promotion outcomes to support fairness, transparency, and compliance. 
      • Ensuring recruitment, promotion, reward, training, and employment decisions are based on merit, skills, qualifications, performance, and business requirements. 

       

      Equality, Diversity, and Inclusion Statement 

      CFBL is committed to creating an environment where all team members have equal access to opportunities, resources, and advancement, free from bias or discrimination. Examples of how we achieve this are by:  

      • Embedding EDI objectives into our annual performance goals and leadership KPIs. 
      • Implementing blind-resume reviews and diverse interview panels to minimise unconscious bias. 
      • Regularly surveying staff on inclusion experiences and acting on feedback. 
      • Monitoring progress against EDI objectives through periodic reporting and leadership oversight. 
      • Promoting inclusive leadership practices that encourage participation, respect, and equal access to professional development opportunities. 

       

      Multilingual and Plain Language Policy 

      We strive to communicate clearly and inclusively by providing key materials in multiple languages and using straightforward, professional language to serve diverse stakeholders. Examples of how we achieve this are by:  

      • Translating executive summaries of major reports into the primary languages of our client base. 
      • Applying plain-language reviews to all client deliverables to eliminate unnecessary technical terminology. 
      • Publishing guidelines on inclusive language, readability scores, and translation workflows. 
      • Providing alternative communication formats where appropriate, including accessible digital documents and supported communication methods for users with additional accessibility requirements. 
      • Periodically reviewing content against accessibility, readability, and inclusivity standards to ensure information remains understandable and accessible to diverse audiences. 

      Ethics, Integrity, and Compliance 

      We promote ethical behaviour, legal adherence, and organisational accountability.  

      Anti-Bribery and Corruption Policy 

      CFBL enforces a strict zero-tolerance approach to bribery or corruption, ensuring compliance with relevant anti-corruption regulations. Examples of how we achieve this are by:  

      • Conducting risk-based due diligence on third parties before entering any partnership. 
      • Educating staff through annual anti-bribery training, including real-world scenarios and certifications. 
      • Auditing expense claims and gifts registers to detect and investigate irregularities. 
      • Maintaining documented procedures governing gifts, hospitality, charitable contributions, and business courtesies. 
      • Conducting periodic bribery and corruption risk assessments and implementing corrective actions where vulnerabilities are identified. 

       

      Anti-Fraud and Corruption Policy 

      Fraud prevention is embedded in our operational and client-facing activities, with active monitoring, review protocols, and due diligence on financial controls. Examples of how we achieve this are by:  

      • Automating anomaly detection in high-volume financial processes. 
      • Requiring dual sign-off for large payments or consultancy agreements. 
      • Conducting scheduled fraud risk assessments and control updates. 
      • Maintaining documented fraud prevention, reporting, and escalation procedures. 
      • Regularly reviewing financial controls, delegated authorities, supplier arrangements, and approval processes to reduce fraud risk and strengthen accountability. 

       

      Audit and Compliance Policy 

      We operate under robust internal audit frameworks and cost assurance methodologies, aligning with government and infrastructure sector compliance standards. Examples of how we achieve this are by:  

      • Aligning our audit programmes to comply with recognised international standards. 
      • Conducting regular peer reviews and external quality assessments. 
      • Maintaining up-to-date compliance lists tailored to each client industry. 
      • Documenting audit findings, recommendations, and remedial actions to support continuous improvement. 
      • Periodically reviewing regulatory developments and updating internal controls and procedures where necessary. 

       

      Code of Conduct 

      CFBL team members abide by a clear set of behavioural standards, ensuring professionalism, respect, and transparency in every client engagement. Examples of how we achieve this are by:  

      • Embedding core values into onboarding and annual refresher training for all staff. 
      • Ensuring acknowledgments from every team member to reinforce accountability. 
      • Publishing conduct metrics to leadership and integrating them into performance reviews. 

       

      Complaints and Appeals Policy 

      We maintain a fair, transparent process for reviewing client or stakeholder feedback, ensuring timely resolution and continuous service improvement. Examples of how we achieve this are by:  

      • Providing clearly communicated channels through which complaints and appeals can be submitted. 
      • Acknowledging complaints within appropriate timescales and communicating expected review and resolution processes. 
      • Conducting impartial investigations and maintaining records of complaints, findings, actions, and outcomes. 
      • Providing a structured escalation and appeals process where stakeholders remain dissatisfied with an outcome. 
      • Communicating progress updates where investigations require additional time. 
      • Analysing complaint trends and lessons learned to support service improvement and operational effectiveness. 

       

      Conflict of Interest Policy 

      We proactively identify and manage any personal or financial interests that could influence our objectivity, safeguarding the impartiality of our advice. Examples of how we achieve this are by:  

      • Mandating quarterly declarations of financial and outside interests from all consultants. 
      • Establishing an independent review committee to assess and mitigate flagged conflicts. 
      • Rotating engagement teams when potential conflicts are confirmed. 
      • Maintaining a formal Conflict of Interest Register that is reviewed and updated regularly. 
      • Requiring the declaration of actual, potential, and perceived conflicts as soon as they arise. 
      • Recording identified conflicts and agreed mitigation measures to provide an auditable governance trail. 

       

      Donations and Sponsorship Policy 

      All donations or sponsorships are subject to ethical review, ensuring they align with our corporate values, are transparent, and avoid undue influence. Examples of how we achieve this are by:  

      • Reviewing funding proposals through a professional evaluation panel. 
      • Officially disclosing sponsorships and amounts in an annual transparency register. 
      • Reviewing post-funding impact to verify ethical alignment and outcomes. 
      • Conducting proportionate due diligence on recipient organisations to identify ethical, compliance, or reputational risks. 
      • Maintaining documented approval and review records to support transparency and accountability. 

       

      Freedom of Information (FOI) Policy 

      In line with applicable public sector guidelines, CFBL supports transparency by appropriately managing and responding to FOI requests within its project remit. Examples of how we achieve this are by:  

      • Publishing FOI submission protocols and response timelines. 
      • Training staff on FOI handling, redaction, records management, and exemptions. 
      • Logging all requests internally to track trends and refine disclosure practices. 
      • Preserving, locating, and supplying information held on behalf of public authority clients where contractually required. 
      • Referring formal FOI requests to the appropriate public authority where responsibility for responding rests with that authority. 
      • Maintaining records of requests, disclosures, exemptions, and outcomes to support transparency and audit requirements. 
      • Providing guidance to staff involved in public-sector projects regarding information-management responsibilities. 

       

      Legal Disclaimer 

      We maintain a clarification of the limitations and terms governing the use of CFBL’s website and published content. Examples of how we achieve this are by:  

      • Displaying prominent disclaimers on all communications and pages. 
      • Updating legal terms whenever new content or services are launched. 
      • Providing clear attribution guidelines for downloading or referencing our publications. 

       

      Quality Assurance 

      Our consultancy is governed by strict quality assurance standards, leveraging experienced professionals, peer review, and steering group oversight to deliver consistently high value to our clients. Examples of how we achieve this are by:  

      • Requiring peer review of all deliverables prior to client submission. 
      • Holding regular steering-group sessions to examine quality KPIs. 
      • Incorporating client feedback and industry benchmarks into process improvements. 

       

      Whistleblower Policy 

      Our secure, confidential reporting channels empower employees and stakeholders to raise concerns or violations without fear of retaliation. Examples of how we achieve this are by:  

      • Guaranteeing anonymity and support through formal policy safeguards. 
      • Ensuring all reports are followed by a standardised investigation protocol. 
      • Protecting whistleblowers through anti-retaliation measures and support resources. 
      • Providing multiple confidential reporting channels, including independent escalation routes where appropriate. 
      • Ensuring concerns are assessed objectively and investigated proportionately to the nature and seriousness of the matter raised. 
      • Monitoring whistleblowing outcomes and corrective actions while maintaining confidentiality. 
      • Promoting awareness of whistleblowing rights, protections, and reporting procedures through periodic training and communications. 

       

      Financial and Procurement Governance 

      We demonstrate responsible financial stewardship and ethical procurement.  

      Contract Management Policy 

      CFBL ensures rigorous contract oversight including clear deliverables, performance metrics, and review checkpoints, so that all parties meet their obligations and project goals are achieved. Examples of how we achieve this are by: 

      • Establishing contract-specific governance forums to review progress against milestones. 
      • Implementing automated tracking of key dates (e.g., deliverable submissions, renewal windows) in our contract management system. 
      • Conducting quarterly performance reviews with suppliers and clients to address issues proactively. 
      • Maintaining documented records of contract performance, risks, actions, and decisions to support accountability and audit requirements. 

       

      Financial Transparency and Reporting Policy 

      CFBL publishes clear financial statements and budget summaries for relevant projects, enabling clients and stakeholders to track expenditure and outcomes with confidence. Examples of how we achieve this are by: 

      • Sharing project-level budget dashboards via secure client portals, updated monthly. 
      • Issuing quarterly financial reports that reconcile planned versus actual spend and highlight variances. 
      • Hosting annual financial-review webinars open to stakeholders to discuss performance and forecasts. 
      • Maintaining documented governance records supporting significant financial approvals and reporting decisions. 

       

      Grant Management Policy 

      Our grant administration adheres to funder requirements, with robust application vetting, compliance monitoring, and regular reporting to secure and sustain funding. Examples of how we achieve this are by:  

      • Implementing pre-award due diligence to verify grantee eligibility and capacity. 
      • Tracking fund utilisation against milestones via a centralised management platform. 
      • Delivering interim and final grant reports, audited by an independent reviewer, to ensure accountability. 
      • Documenting funding decisions, approvals, and monitoring activities throughout the grant lifecycle. 
      • Reviewing grant outcomes against agreed objectives to support responsible stewardship of funds. 

       

      Procurement and Tendering Policy 

      We follow transparent and competitive tendering processes, awarding contracts based on merit, cost-effectiveness, and alignment with our ethical and sustainability criteria. Examples of how we achieve this are by:  

      • Publishing clear tender invitations with defined evaluation criteria. 
      • Engaging cross-functional panels, including legal, commercial, and sustainability experts to assess bids. 
      • Documenting and publishing tender outcomes and rationales to maintain stakeholder confidence. 
      • Applying objective and proportionate evaluation methodologies to support fairness and consistency. 
      • Managing procurement activities in a manner that promotes transparency, value for money, and equal treatment of suppliers. 

       

      Spending and Budget Disclosure Policy 

      We openly disclose spending thresholds and budget allocations for client engagements, supporting informed decision-making and preventing cost overruns. Examples of how we achieve this are by:  

      • Publishing threshold levels for approval tiers and associated delegation authorities in our policy handbook. 
      • Providing real-time spend trackers accessible to authorised client representatives. 
      • Documenting budget re-forecast rationales and approvals in our governance logs. 
      • Maintaining auditable records of significant spending decisions and approvals. 
      • Reviewing budgeting and forecasting practices periodically to support effective financial oversight. 

       

      Supplier Code of Conduct 

      All suppliers commit to our ethical standards, covering labour practices, environmental stewardship, and anti-corruption to qualify for procurement and our ongoing collaboration. Examples of how we achieve this are by:  

      • Embedding our Supplier Code into every procurement contract and onboarding package. 
      • Conducting periodic supplier audits to verify adherence to labour and environmental criteria. 
      • Enforcing remediation plans or contract termination when non-compliance is identified. 

       

      Value for Money and Efficiency Policy 

      We continuously assess processes, resource allocation, and supplier performance to optimise costs, streamline operations, and deliver measurable efficiencies for clients. Examples of how we achieve this are by:  

      • Applying benchmark analyses and unit-cost comparisons across similar project scopes. 
      • Facilitating quarterly efficiency reviews with project teams to identify and implement savings initiatives. 
      • Incorporating value-engineering workshops at key project stages to refine deliverables and reduce waste. 
      • Monitoring efficiency outcomes and improvement actions through periodic management reviews. 
      • Using evidence-based performance measures when assessing value, efficiency, and resource utilisation. 

       

      Health, Safety, and Wellbeing 

      We ensure a safe and healthy environment for all stakeholders and workers.  

      Driver Safety Policy 

      All business travel and site visits follow strict vehicle maintenance, driver training, and journey-planning standards to protect staff and third parties on the road. Examples of how we achieve this are by: 

      • Requiring annual driver-safety training and licence checks for all employees undertaking site visits. 
      • Mandating pre-trip vehicle inspections and adherence to defined client roads. 
      • Utilising journey-planning tools to optimise routes, reduce fatigue, and track travel incidents. 
      • Requiring vehicles used for business purposes to be appropriately maintained, roadworthy, insured, and legally compliant where applicable. 
      • Providing guidance on defensive driving, hazard awareness, fatigue management, and adverse weather conditions. 

       

      Health and Safety Policy 

      We maintain comprehensive procedures, including emergency response, road safety, and remote-work protocols to proactively identify and mitigate risks in both office and off-site settings. Examples of how we achieve this are by: 

      • Conducting regular risk assessments and emergency drills across all work settings. 
      • Publishing clear protocols for incident reporting, road safety, and first-aid arrangements. 
      • Reviewing and updating our policy annually to incorporate legal requirements and best practices. 
      • Monitoring corrective actions arising from risk assessments and incident investigations. 
      • Promoting a proactive reporting culture that encourages the identification and management of health and safety risks. 

       

      Remote Working Policy 

      We support safe and healthy home working through ergonomic guidance, check-ins, and clear communication channels to address any concerns. Examples of how we achieve this are by:  

      • Issuing home-office setup guides and offering digital equipment assessments to all remote workers. 
      • Scheduling virtual check-ins with line managers to monitor welfare and workload balance. 
      • Enforcing secure VPN access and data-protection protocols to safeguard confidential information. 
      • Providing guidance on ergonomic working practices and wellbeing management. 
      • Encouraging employees to report health, safety, wellbeing, or operational concerns arising from remote working arrangements. 

       

      Workplace Health and Safety Policy 

      Our on-site safety measures cover hazard assessments, regular training, and incident reporting to ensure a secure and supportive office environment. Examples of how we achieve this are by:  

      • Completing monthly workplace inspections and logging corrective actions for later reference. 
      • Delivering quarterly health and safety workshops, covering manual handling, fire safety, and stress management. 
      • Reporting near-misses and incidents centrally to drive continuous improvement and accountability. 
      • Reviewing workplace hazards, trends, and corrective actions through periodic management oversight. 
      • Maintaining records of inspections, training activities, and health and safety actions to support ongoing compliance and continuous improvement. 

       

      Legal, Governance, and Digital Security 

      We protect data, systems, and ensure compliance with regulatory frameworks. 

      Accessibility Statement 

      Our website and digital materials are designed for inclusive access, meeting WCAG 2.1 AA standards and providing alternative formats upon request. Examples of how we achieve this are by: 

      • Conducting semi-annual accessibility audits with assistive-technology testing. 
      • Offering downloadable text transcripts and captioning for multimedia content. 
      • Maintaining a feedback form to capture and address accessibility issues. 

       

      Artificial Intelligence and Content Generation Policy 

      We are committed to the ethical, secure, and transparent use of Artificial Intelligence technologies including generative AI, for areas like internal operations, content development and so on. Examples of how we achieve this are by: 

      • Clearly disclosing when AI-generated content, recommendations, or tools are used in reports, insights, or communications. 
      • Reviewing all AI outputs through human subject-matter experts to verify relevance, quality, and factual integrity before client distribution. 
      • Limiting the use of AI to non-sensitive contexts, ensuring no confidential data is input into public or third-party AI systems. 

       

      Cloud Services and Hosting Policy 

      We engage only certified cloud providers with robust security certifications ensuring data sovereignty and compliance with UK regulations. Examples of how we achieve this are by: 

      • Conducting annual security and compliance reviews of all cloud vendors. 
      • Ensuring data residency within approved UK/EU jurisdictions. 
      • Using cloud-native security tools for continuous configuration monitoring. 
      • Maintaining appropriate contractual, security, and compliance oversight of cloud service providers. 
      • Reviewing cloud-provider arrangements periodically to support secure and compliant service delivery. 

       

      Code of Conduct for Digital Services 

      We require all digital interactions and content to adhere to our ethical standards, including truthfulness, professionalism, and respect for user privacy. Examples of how we achieve this are by: 

      • Training digital-team members on ethical content creation and moderation. 
      • Implementing editorial review boards for all public-facing updates. 
      • Applying privacy-by-design principles when developing new features. 

       

      Copyright and Intellectual Property Policy 

      All CFBL content is protected by intellectual property laws, and we respect third-party copyrights by securing permissions and attributing sources appropriately. Examples of how we achieve this are by: 

      • Registering our publications and methodologies under UK copyright law. 
      • Requiring documented licence checks before using external content. 
      • Embedding digital watermarking in client-facing deliverables to track distribution. 

       

      Cybersecurity Policy 

      CFBL committed to maintaining a secure digital environment that protects the confidentiality, integrity, and availability of our data, systems, and client information, including regular staff training on cybersecurity awareness, secure data handling, and up-to-date security tools and encryption. Examples of how we achieve this are by: 

      • Deploying up to date firewalls and intrusion-detection systems. 
      • Conducting phishing simulations and cybersecurity training. 
      • Partnering with external experts for periodic penetration testing. 

       

      Data Encryption and Storage Policy 

      Sensitive data is encrypted both in transit and at rest using industry-standard protocols, and backups are securely stored and regularly tested. Examples of how we achieve this are by: 

      • Utilizing secure encryption channels for all internal and external data transfers. 
      • Encrypting database volumes with the latest security tools. 
      • Verifying backup integrity and restorability on a monthly basis. 

       

      Data Protection Policy 

      Our robust data protection measures include periodic risk assessments, staff training, and documented procedures to prevent unauthorised access, loss, or disclosure of sensitive information. Examples of how we achieve this are by: 

      • Running mandatory annual training on data-handling best practices for all staff. 
      • Performing quarterly risk assessments and updating controls accordingly. 
      • Documenting and testing secure data-transfer procedures with encryption. 

       

      Device and Endpoint Security Policy 

      Company-issued and personal devices used for CFBL work comply with security configurations, antivirus protection, and encrypted storage to prevent data leakage. Examples of how we achieve this are by: 

      • Requiring disk-encryption and regular endpoint-security health checks. 
      • Blocking non-compliant devices from accessing corporate networks. 

       

      Digital Identity and Trust Framework Compliance 

      CFBL aligns with national digital identity standards, ensuring secure and verifiable interactions with both public-sector bodies and private clients. Examples of how we achieve this are by: 

      • Integrating single-sign-on solutions compliant with modern standards. 
      • Periodically updating identity-proofing checks to meet regulatory changes. 
      • Verifying third-party digital credentials through accredited trust anchors. 

       

      Incident Response and Breach Notification Policy 

      In the event of a security incident, we follow a documented response plan, promptly notifying affected parties and regulators in line with ICO guidelines. Examples of how we achieve this are by: 

      • Maintaining a dedicated incident-response team with defined escalation tiers. 
      • Running tabletop exercises quarterly to validate readiness and refine procedures. 
      • Issuing breach reports to stakeholders within event of detection. 

       

      Information Security Policy 

      We enforce role-based access controls, data classification, and regular audits to guarantee confidentiality, integrity, and availability of client and company information. Examples of how we achieve this are by: 

      • Granting permissions through an identity-and-access management system. 
      • Reviewing access logs monthly to detect and revoke unnecessary privileges. 
      • Classifying all data assets and labelling them according to sensitivity levels. 

       

      Privacy Policy (GDPR & UK Data Protection Act) 

      We collect and process personal data lawfully, transparently, and only for specified purposes, ensuring rights to access, correction, and deletion are fully respected under GDPR and the UK Data Protection Act. Examples of how we achieve this are by: 

      • Publishing clear data-collection notices and consent forms on our website. 
      • Providing self-service portals for data-subject requests and forms, such as access or deletion. 
      • Conducting regular audits to ensure all processing activities align with declared purposes. 

       

      Records Management and Retention Policy 

      We maintain accurate records throughout their lifecycle, retaining documents for legally mandated periods and securely disposing of them when no longer required. Examples of how we achieve this are by: 

      • Classifying records by type and applying automated retention schedules. 
      • Utilizing secure shredding and digital-wiping services for end-of-life documents. 
      • Logging all destruction activities in an audit trail for regulatory verification. 

       

      Software and Patch Management Policy 

      All software and firmware are kept up to date through patching schedules and vulnerability scans to eliminate known security risks. Examples of how we achieve this are by: 

      • Deploying patches within defined SLA windows based on criticality. 
      • Running weekly vulnerability scanning and remediation workflows. 
      • Logging and auditing all patch deployments for compliance reporting. 

       

      Terms of Use / Acceptable Use Policy 

      Users of our website agree to lawful, respectful conduct and understand that misuse of our digital services may result in access restrictions. Examples of how we achieve this are by: 

      • Displaying clear terms on our homepage with acknowledgment. 
      • Monitoring traffic for suspicious behaviour and enforcing IP blocks when needed. 
      • Reviewing and updating the policy annually to reflect new legal or technical developments. 

       

      User Access and Authentication Policy 

      We enforce strong, unique credentials and multi-factor authentication for access to CFBL systems, with periodic reviews to revoke unnecessary permissions. Examples of how we achieve this are by: 

      • Enforcing password complexity and rotation policies via our IAM platform. 
      • Implementing hardware or software tokens for privileged-access accounts. 
      • Auditing user roles quarterly to remove outdated or unnecessary access. 

       

      Website Maintenance and Uptime Policy 

      We perform regular updates, monitoring, and redundancy checks to guarantee continuous availability and resilience of our online services and user experience. Examples of how we achieve this are by: 

      • Implementing balanced server uptime with automatic failover. 
      • Conducting off-peak maintenance and announcing windows in advance. 
      • Monitoring performance metrics in real time and triggering alerts for anomalies. 

       

      Modern Slavery and Human Trafficking Statement

      The Modern Slavery Act of 2015 

      The Modern Slavery Act came into force on 26 March 2015. The Act clarifies the existing offences of slavery and human trafficking and introduces tougher penalties. 

      The Act includes a requirement for commercial organisations such as CFBL to publish a statement each financial year setting out the steps taken to ensure that no slavery or human trafficking is taking place within its business operations or supply chain. 

      The term ‘modern slavery’ describes exploitation so severe that people are unable to leave their place of work. ‘Slavery’ refers to the condition of treating another person as property, something to be bought, sold, traded, or controlled. Victims may be controlled through debt, coercion, threats, abuse, or other forms of exploitation. The common characteristic of all forms of slavery is the deprivation of an individual’s freedom.  

      Situations that may present a particular risk of modern slavery include: 

      • Where workers have fewer protections through inadequate laws and regulations, weak or non-existent enforcement, and poor business and government accountability. 
      • Where there are high levels of poverty among workers. 
      • Where there is widespread discrimination against certain groups of workers. 
      • Where there is widespread use of migrant labour. 
      • In conflict zones. 
      • Within industries or sectors considered to be at higher risk of exploitation. 

      The risk of modern slavery affects almost every industry globally. In addition to potential legal sanctions, organisations that fail to take effective action may suffer significant reputational damage. CFBL takes this risk seriously and is committed to preventing slavery and human trafficking in all aspects of its business activities. 

      Measures to Address Modern Slavery in CFBL’s Supply Chains 

      CFBL has undertaken measures to identify, assess, and manage the associated risks of modern slavery within its supply chain and business operations.  

      Action Planning 

      Where corrective actions are necessary, CFBL management will work with the appropriate level of supplier management to address identified concerns. Where sufficient improvements are not achieved, CFBL may terminate the supplier relationship as an appropriate risk-management measure. 

      Report on the Latest Financial Year 

      CFBL is not aware of any breach of the Modern Slavery Act 2015 within its business operations or current supply chain during the current financial year. 

      CFBL Consulting’s Policy 

      CFBL Consulting is committed to upholding the highest ethical and professional standards and maintaining public confidence in its business activities. As part of that commitment, we seek to identify and mitigate the risks of modern slavery and human trafficking by: 

      • Never knowingly supporting or conducting business with organisations involved in slavery or human trafficking. 
      • Ensuring suppliers and business partners understand our expectations regarding ethical and lawful business behaviour. 
      • Requesting suppliers and business partners, where appropriate, to implement suitable anti-slavery and human trafficking policies and procedures. 
      • Encouraging the reporting of concerns and providing appropriate protection for whistleblowers. 

      CFBL’s leadership team will ensure staff are aware of this policy and that appropriate measures are implemented to prevent slavery and human trafficking within CFBL and its supply chains. 

      This policy will be reviewed annually. 

      Staff are encouraged to report any concerns relating to modern slavery to senior management through appropriate reporting channels. 

      Contract Provisions 

      CFBL will ensure that contractual arrangements with new and existing suppliers support its commitment to preventing modern slavery and human trafficking. 

      Supplier Policy 

      Supplier policies relating to modern slavery will be reviewed during procurement and supplier-selection activities to ensure alignment with CFBL’s ethical and compliance expectations.  

      Supply Chain Assessment and Reviews 

      CFBL will seek to identify vulnerabilities through supply-chain assessments and reviews. While it is not practical to audit every supplier at every level of the supply chain, CFBL will adopt a risk-based approach to ethical procurement and supplier management. 

      CFBL will ensure that procurement and tender processes support the assessment of supplier compliance with applicable legislation and ethical standards. 

      Examples of how we achieve this are by: 

      • Reviewing supplier policies relating to modern slavery and human trafficking during procurement activities. 
      • Applying proportionate supplier due-diligence processes, including supplier declarations, procurement assessments, and risk-based compliance reviews where appropriate. 
      • Identifying areas of heightened risk and implementing additional scrutiny where required. 
      • Monitoring supplier relationships and taking appropriate action where concerns are identified.  

      Whistleblowing 

      CFBL encourages whistleblowing to identify breaches of policy and contractual provisions concerning modern slavery. 

      Reporting systems are in place to help ensure whistleblower identities are protected and that appropriate support is available from Human Resources, Procurement, and Senior Leadership.  

       

        Sustainability & Net Zero Carbon Statement 

        Sustainability and Net Zero Target 

        CFBL Consulting is committed to achieving Net Zero carbon emissions by 2030. We recognise that achieving Net Zero requires continual improvement, practical operational changes, and long-term commitment across our business activities. 

        We are dedicated to strengthening our sustainability practices, reducing our environmental impact, and delivering positive environmental, social, and economic outcomes through responsible business operations.  

        Key Action Steps 

        We intend to achieve our Net Zero commitment through a combination of environmental, social, and governance initiatives. 

        Environmental Sustainability 

        • Energy Efficiency: Utilise energy-efficient systems such as high-performance insulation, LED lighting, and energy-efficient heating and cooling systems to reduce energy consumption. 
        • Renewable Energy: Support the adoption of renewable energy sources where practical to reduce reliance on fossil fuels and lower carbon emissions. 
        • Sustainable Materials: Manage waste responsibly and utilise environmentally responsible, recycled, or locally sourced materials where appropriate. 
        • Water Conservation: Implement water-saving technologies and practices to reduce unnecessary water consumption. 
        • Resource Efficiency: Promote continual environmental improvement through responsible resource management and operational efficiency measures.  

        We believe practical sustainability measures contribute positively to environmental outcomes while supporting long-term organisational resilience and responsible business operations.  

        Social Sustainability 

        As a business, we aim to create positive social value through: 

        • Promoting fair labour practices and supporting diversity and inclusion in the workplace. 
        • Supporting employee development and professional growth. 
        • Engaging with local communities and supporting social development initiatives. 
        • Promoting mental health and wellbeing awareness. 
        • Supporting flexible and remote working arrangements where appropriate.  

        By prioritising social responsibility, we aim to foster positive stakeholder relationships and contribute to sustainable community outcomes.  

        Sustainability Governance 

        We support sustainability through strong governance arrangements by: 

        • Maintaining transparency, accountability, and ethical business practices. 
        • Promoting responsible decision-making and regulatory compliance. 
        • Supporting the effective management of sustainability-related risks and opportunities. 
        • Integrating Environmental, Social and Governance (ESG) considerations into business operations where appropriate.  

        Sustainability Partners 

        We work with specialist sustainability partners to support carbon measurement, emissions reduction planning, and sustainability improvement initiatives. 

        These partnerships help us to: 

        • Measure our carbon footprint. 
        • Identify opportunities to reduce environmental impacts. 
        • Develop practical carbon-reduction strategies. 
        • Support continual improvement and progress towards Net Zero objectives.  

        Sustainability Reporting 

        CFBL supports sustainability reporting, climate-related risk awareness, and broader Environmental, Social and Governance (ESG) considerations within its services and operations. 

        Examples of how we achieve this are by: 

        • Monitoring sustainability performance and environmental impacts. 
        • Supporting climate-related reporting activities where appropriate. 
        • Working with clients, suppliers, and stakeholders on sustainability initiatives. 
        • Reporting progress against sustainability objectives on a periodic basis. 
        • Supporting organisations in understanding climate-related risks and sustainability opportunities.  

        Sustainability Roadmap 

        With a focus on continual improvement, we assess our environmental impacts and identify opportunities to reduce emissions across our operations. 

        We seek to develop practical carbon-reduction strategies that support short, medium, and long-term sustainability objectives while strengthening organisational resilience and supporting responsible growth. 

        Sustainability and ESG Finance  

        We support organisations in developing sustainability strategies, measuring emissions, identifying reduction opportunities, and improving environmental performance. 

        We also recognise the importance of reducing emissions associated with our own operations and supply chain activities, including Scope 3 emissions where practical. 

         

        Decarbonisation Targets by 2030 

         

        • Scope 1 – To reduce direct emissions generated by the company’s activities by 85%
        • Scope 2 – To reduce indirect emissions associated with purchased energy and transition towards renewable energy sources across applicable operations. 
        • Scope 3 – To reduce other indirect emissions associated with the company’s supply chain activities and absolute business travel emissions by 85%.  

         

        Progress towards these objectives will be measured against an established organisational emissions baseline and monitored through CFBL’s sustainability reporting activities to support transparency and accountability. 

        We are adapting our core ESG (Environmental, Social, and Governance) services with every client to include consideration of environmental issues. This ranges from the inclusion of climate considerations within our assurance methodologies and processes, diversity and equity within the workforce, transparency reporting, and sustainability-focused transformation programmes within our consulting services, among other initiatives.  

        We offer specialised services to help organisations develop their own Net Zero strategies, advise on sustainability best practices, and promote case studies of successful implementation. Explore more about our commitments on our website: https://www.cfbusinesslinks.com/.  

        With our sustainability practices, we aim to help organisations plan, source, deliver, finance, and measure the broader impact of products and services. We help businesses enhance resilience, agility, and sustainability through practical environmental and operational improvements. We will accomplish this through a comprehensive strategy that supports our stated decarbonisation objectives, investment in renewable energy, improved energy efficiency, and responsible carbon-reduction initiatives. We recognise the importance of transparency and accountability and will monitor progress against our sustainability objectives. 

        By following these strategies, CFBL seeks to contribute to the objectives of the Paris Agreement by supporting efforts to reduce greenhouse gas emissions and promote long-term environmental sustainability.  

         

          Transparency, Communications, and Operations

          We support open communication, service delivery, and public trust. 

          Open Data Policy 

          We make non-sensitive data openly available where appropriate, to support knowledge sharing, collaboration, and innovation across sectors. Examples of how we achieve this are by: 

          • Maintaining a searchable area of anonymised project data and industry analyses. 
          • Regularly updating open datasets following each major project milestone. 
          • Publishing data-quality documentation to guide external use and interpretation. 
          • Conducting privacy and risk reviews before publication to minimise the risk of inappropriate disclosure. 
          • Reviewing published datasets for accessibility and usability. 

           

          Transparency and Accountability Statement 

          Our operations are governed by principles of transparency, professional ethics, and measurable outcomes, with accountability built into all client engagements. Examples of how we achieve this are by: 

          • Issuing an annual performance report detailing key metrics and lessons learned. 
          • Publishing governance structures and decision-rights frameworks on our website. 
          • Inviting third-party reviews of select engagements and sharing summary findings. 

           

          Public Engagement and Consultation Policy 

          CFBL engages stakeholders in meaningful dialogue when shaping relevant policies, projects, or reports, ensuring decisions are informed, inclusive, and evidence-based. Examples of how we achieve this are by: 

          • Hosting virtual and in-person workshops during project development phases. 
          • Publishing consultation drafts with open comment periods and response summaries. 
          • Integrating stakeholder feedback into final deliverables and acknowledging contributors. 

           

          Community Guidelines / Moderation Policy 

          We maintain respectful and constructive discourse across our digital platforms, with clear rules on content moderation to prevent abuse or misinformation. Examples of how we achieve this are by: 

          • Enforcing a zero-tolerance policy for hate speech and personal attacks. 
          • Moderating comments and posts within 24 hours to remove prohibited content. 
          • Providing clear escalation paths for users to report violations and appeal moderation decisions. 

           

          Social Media Use Policy 

          Our official social media channels are used professionally to share insights, news, and thought leadership, while respecting confidentiality, brand integrity, and public expectations. Examples of how we achieve this are by: 

          • Maintaining an approved digital-content calendar reviewed by our Marketing team. 
          • Training spokespeople on compliant messaging and crisis-communication protocols. 
          • Archiving all social posts against our transparency commitments. 

           

          Meeting and Agenda Publication Policy 

          Where applicable, we publish key agendas, summaries, or decisions from governance meetings to demonstrate openness and reinforce client trust. Examples of how we achieve this are by: 

          • Uploading board and steering-group agendas at least five business days in advance. 
          • Circulating action-minute summaries to participants within 48 hours of each meeting. 
          • Making non-confidential governance documents publicly accessible via our data portal. 

           

          News and Announcements Policy 

          CFBL communicates timely updates on services, projects, and regulatory changes via our website, email lists, and social media. Examples of how we achieve this are by: 

          • Posting press releases and blog updates following appropriate internal review processes. 
          • Distributing email newsletters to subscribers with clear content sections and appropriate subscription controls. 
          • Synchronising news across our website, social media, and partner platforms. 
          • Conducting accessibility and quality reviews before publication where appropriate. 
          • Maintaining processes for updating or correcting information where published content changes or is found to be inaccurate. 

           

          Public Notices and Alerts Policy 

          Critical service updates or urgent announcements, such as policy changes or data security alerts, are published promptly and clearly through designated channels. Examples of how we achieve this are by: 

          • Publishing banner notices on our website homepage for critical alerts. 
          • Sending SMS and email notifications to registered clients during emergencies. 
          • Maintaining an alert-archive area for reference to past notices. 

           

          Service Level Agreement (SLA) Policy 

          Our SLAs define clear expectations for service delivery, response times, and escalation procedures, ensuring accountability and transparency with clients. Examples of how we achieve this are by: 

          • Specifying response and resolution targets for each service tier in client contracts. 
          • Reviewing SLA performance quarterly with clients and adjusting terms as needed. 

           

          Service Availability and Continuity Policy 

          Our business continuity plans, cloud-based infrastructure, and secure backups help maintain service availability during potential disruptions or emergencies. Examples of how we achieve this are by: 

          • Implementing cloud services with failover capabilities. 
          • Conducting semi-annual disaster-recovery drills and updating plans accordingly. 
          • Providing clients with continuity-of-service documentation and contact lists. 

           

          Change Management Policy 

          We follow a structured process for managing internal and client-facing changes to ensure minimal disruption, risk mitigation, and stakeholder alignment. Examples of how we achieve this are by: 

          • Logging all proposed changes in our Project Change Register and assessing impacts. 
          • Securing formal approvals from change-advisory boards before implementation. 
          • Communicating scheduled updates to affected parties with clear timelines and rollback options. 

           

          User Support and Helpdesk Policy 

          Dedicated support channels are available for client queries and technical issues, with defined response and resolution timeframes based on service agreements. Examples of how we achieve this are by: 

          • Operating a 24/5 helpdesk with trained support responses. 
          • Issuing ticket confirmations within 30 minutes of request submission. 
          • Providing self-service knowledge-base articles and video tutorials for common issues. 

           

          Content Management and Publishing Policy 

          All published content undergoes review for accuracy, clarity, and alignment with our values and sector-specific compliance standards. Examples of how we achieve this are by: 

          • Routing drafts through an intensive review before publishing with team members. 
          • Applying version control and maintaining a public changelog for major publications. 
          • Using standardised templates and style guides for consistency. 

           

          Website Archiving Policy 

          We preserve website content in line with data-retention and legal requirements, ensuring historical transparency and public accessibility when needed. Examples of how we achieve this are by: 

          • Automatically capturing quarterly snapshots of web pages and file attachments. 
          • Storing archives in a secure, read-only environment for ten years. 
          • Providing indexed, searchable access for audit and public-record requests. 

           

          Third-Party Integration and API Use Policy 

          Any external integrations used by CFBL are vetted for data protection, compliance, and reliability, ensuring secure collaboration and interoperability. Examples of how we achieve this are by: 

          • Conducting security and privacy assessments on third-party libraries. 
          • Restricting API keys to least-privilege scopes and rotating them regularly. 
          • Monitoring integration performance and logging all external calls for audit trails. 

           

          Mobile and App Services Policy 

          Mobile access to CFBL resources and any digital services is provided through secure, user-friendly channels compliant with accessibility and privacy standards. Examples of how we achieve this are by: 

          • Requiring MFA and device-management compliance for mobile app logins. 
          • Designing interfaces to meet recognised accessibility standards. 
          • Pushing security updates to mobile clients through managed app stores. 
          • Conducting periodic reviews of mobile applications to assess security, accessibility, and performance. 
          • Monitoring mobile-service risks and implementing appropriate security controls. 

           

          User Feedback and Satisfaction Policy 

          Client feedback is actively solicited through surveys and review sessions, enabling us to enhance service quality and align with evolving needs. Examples of how we achieve this are by: 

          • Distributing post-engagement surveys within one week of project close. 
          • Holding quarterly stakeholder review meetings to discuss satisfaction trends. 
          • Implementing action plans for improvement and reporting back on progress. 

           

          Digital Inclusion and Assisted Digital Support Policy 

          We provide additional support and accessible formats to ensure our services remain inclusive and usable for all, regardless of digital literacy or access barriers. Examples of how we achieve this are by: 

          • Offering telephone-based assistance and walk-through sessions for key deliverables. 
          • Supplying large-print and audio versions of critical documents on request. 
          • Partnering with community organisations to reach under-served user groups. 

           

          Sustainability and net zero carbon statement 

          CFBL is committed to reducing its environmental footprint by minimising emissions, adopting low-carbon practices, and supporting sustainable, climate-conscious operations. Examples of how we achieve this are by: 

          • Offsetting business‑travel emissions via certified carbon‑offset practices 
          • Prioritising renewable‑energy supplies and energy‑efficient office practices 
          • Embedding sustainability criteria in supplier selection and contract management 

           

           

           

          team

          Our Experienced Associate Team

          sectors

          Our Sectors

          Digital & Technology

          All businesses need sustainable business strategies supported by technology and digital to accomplish financial goals, transform and compete successfully. This includes AI, data analytics, cloud computing or the Internet of Things (IoT). CFBL is committed to robustly managing risk and maximising business benefits.

          Rail & Transport

          With increased cost, complexity and risk on rail infrastructure assets, projects and construction contracts, the need for a cost assurance strategy is vital to optimising costs, sustainable value, and investment return. 

          Water & Highways

          The importance of water infrastructure in supplying clean water to millions of homes and businesses is existential. While highway and road infrastructure is key in transporting goods, and passengers and accessibility to essential and ancillary services.

          Renewables

          Investment in sustainable and high-quality infrastructure managed efficiently over the project life cycle, will contribute to economic development, the achievement of ESG objectives and the Sustainable Development Goals.

          Energy & Power

          For over a decade, CFBL has been working with leaders on infrastructure projects. We are delivering projects in renewable energy and nuclear sectors. We are responsive to energy price changes, and investor and stakeholder demand. 

          Follow by Email
          YouTube200
          YouTube
          LinkedIn2.00k
          LinkedIn
          Share
          Instagram