Trust Centre

Security, Privacy and Compliance at FMIS

Trust Centre

Security, data protection, and system reliability are built into how all our systems are designed and delivered. This Trust Centre brings together key information about our approach to security, privacy, and compliance, including how our systems are hosted, how data is protected, and how security is applied across development and day-to-day use.

It is intended to provide a clear overview for initial review, while also supporting more detailed security and compliance checks where needed.

FMIS information securityOur approach

  • Aligned to recognised standards, including ISO 27001, ISO 9001, and Cyber Essentials Plus
  • Delivered through secure cloud infrastructure or local installation
  • Developed and supported by the FMIS team directly
  • Built around controlled access, encryption, and monitored environments
  • Supported by regular testing, including annual independent penetration testing
Security and compliance enquiries
Security & compliance

If you have questions about security, data protection, or require documentation for a review, get in touch with our team.

Email our team Privacy policy Cookie policy
General enquiries: +44 (0) 1227 773003 Mon–Fri, 9:00–17:00 (BST/GMT)

In practiceFMIS compliance

Security is built in over the full lifecycle of the system:

  • Access is controlled through role-based permissions and multi-factor authentication
  • Data is protected in transit and at rest
  • Development follows a structured approach with controlled releases
  • Vulnerabilities are identified and resolved through ongoing scanning and testing
  • Incidents are logged, reviewed, and managed through defined processes

FMIS typically acts as a data processor, with clients retaining control of their data. We minimise reliance on subprocessors and apply consistent standards across all environments.

What you can find here

FMIS Information Security Certifications

Certifications and assurance

ISO 27001, ISO 9001, and Cyber Essentials Plus, with supporting evidence.

FMIS Secure Logon

Cloud security and infrastructure

How FMIS solutions are hosted, secured, and maintained.

FMIS data protection and privacy

Data protection and privacy

How data is handled, including roles and regulatory alignment.

FMIS information security

Secure development

How security is applied throughout the software lifecycle.

FMIS Vulnerability Management and Testing

Vulnerability management and testing

How risks are identified, tested, and resolved.

FMIS Business Continuity and Incident Management

Incident management and business continuity

How availability is maintained and incidents are handled.

multicompany, multicountry and multicurrency fixed assets

Regional compliance

How our approach aligns with UK, EU, and international requirements.

FMIS Accessibility Statement

Accessibility

FMIS Accessibility Statement, WCAG 2.2 AA Compliance and contact details.

FMIS FAQs

FAQs and documentation requests

Common questions and how to request further information.

G-Cloud 15 - Government Commercial Agency Supplier logo

FMIS awarded G-Cloud 15 supplier status

FMIS Asset Management Software awarded G-Cloud 15 Supplier Status for Fixed Asset Management, Lease Accounting, Asset Tracking & Equipment Maintenance software.
UK public-sector indexation

Indexation in UK Public Sector Fixed Asset Accounting

Understanding how indexation fits alongside revaluation is now essential for finance teams managing non-current assets in the public sector.
Non-Current Assets vs Fixed Assets In the UK public-sector

Why the UK Public Sector Is Moving from Fixed Assets to Non Current Assets

Why is the UK public sector shifting to non-current assets, and how does FMIS software enhance control and compliance?
SORP_Lease_Accounting_changes_2026