Beta

This is a new service and pages are being tested and improved. Give feedback to help improve it.

Check you have access

To use AssureAssist you need:

  • a link to AssureAssist — sent to you by your Assurance Lead or Admin
  • login details — sent automatically by AssureAssist from [email protected], with your username and a temporary password.

If you haven’t received either, contact your Assurance Lead or Admin.

Once you have logged in you will be prompted to set up a new password and two stage authentication.

Once this is set up occasionally an error message will appear when loading, as a work around remove everything in the URL after ‘https://scout2.nista.grid.civilservice.gov.uk’ and go to that URL.

The summary page will now appear. If you have further issues, contact the assurance lead.

Note: the email address is case sensitive, ensure it is enters as stated in the temporary password email.

Change your cookie preferences to view this content

Content from vimeo.com cannot be displayed due to your current cookie consent preference. To view this content, please review your cookie consent preferences.

Make sure your training is current

AssureAssist supports the assurance process, it doesn’t change how reviews work or what good assurance practices looks like.

NISTA’s ‘Review team: Briefing note’ includes information for review teams about their role in a forthcoming assurance review, outlining responsibilities and actions needed to enable full participation.

NISTA’s ‘Programme team and senior responsible owners: Briefing note’ provides the senior responsible owner and programme or project manager with key information about their role in a forthcoming assurance review.

NISTA’s ‘NISTA assurance review toolkit’ has products and guidance to support the delivery of central government’s most complex and high risk projects.

What to expect from the timings

AssureAssist fits into the normal review timeline rather than replacing it. A typical review involves:

  • an initial planning meeting, usually a couple of weeks before the review
  • a review period of around two weeks

With AssureAssist document analysis that would take days happens in minutes, freeing the team to spend the review period on analysis, discussion and professional judgement rather than working through documents.

What you can put into AssureAssist

Before uploading anything, confirm the material is appropriate to go into AssureAssist check classification, commercially sensitive information, legal privilege and any third-party or project-specific handling restrictions. If you’re unsure, check before you upload, not after.

When documents are uploaded, AssureAssist will pseudonymise them. This means it will remove or mask personal data, such as names, email addresses or other details that could identify a person.

Where AssureAssist runs and how your data is handled

AssureAssist is hosted on Amazon Web Services (AWS) and sits fully within Cabinet Office infrastructure.

AssureAssist is aligned to Secure by Design principles and its data is held on the Cabinet Office GRID platform, and secure up to OFFICIAL-SENSITIVE.

AssureAssist cannot be used for SECRET or TOP SECRET documentation.

Data retention

Project data is held for 30 days after the review completes, then deleted by the AssureAssist Administrator.

Personal data (your name and email) is removed 30 days after the review completes.

For full detail, see the AssureAssist data protection and privacy policy.

Back to top