-
-
FOI request (FOIR-850435041)
Core Back-Office Software and ERP Systems
Requested Tue 23 June 2026
Responded Fri 24 July 2026I am writing to you under the Freedom of Information Act 2000 (and the Freedom of Information (Scotland) Act 2002, where applicable) to request information regarding the software systems the council currently uses to manage its core back-office business functions.
For each of the following six business areas, please provide the details requested below:
1. Finance and Accounting (e.g., General Ledger, Budgeting, Treasury)
2. Human Resources (HR) and Payroll (e.g., Core HR, Time & Attendance, Payroll processing)
3. Procurement and Sourcing (e.g., E-Procurement, Contract Management)
4. Asset and Facilities Management (e.g., Enterprise Asset Management, Fleet tracking)
5. Project and Portfolio Management (e.g., Capital project tracking, Resource allocation)
6. Citizen and Frontline Integrations (e.g., core CRM or Billing systems that integrate with the back office)
For EACH of the six business areas listed above, please provide the following:
• System Name: (The name of the software)
• Supplier/Vendor Name: (If the system was developed in-house, please simply state "In-house")
• System Architecture: Please specify which of the following best describes the setup:
• Part of a full, integrated Enterprise Resource Planning (ERP) system.
• A standalone Commercial Off-The-Shelf (COTS) application.
• A bespoke, in-house developed solution.
• Hosting: Is the system hosted on-premise, managed off-premise by the supplier, or delivered via a Cloud/SaaS model?
• Contract Expiry Date: When does the current contract for this system expire (please include any viable extension periods)?
• Whether the council plans to change the system in the future
Additional Note: If the council utilises a single, integrated ERP system (e.g., SAP, Oracle, Microsoft Dynamics) to cover multiple business areas listed above, please state the name of the overarching ERP and confirm which specific modules are currently active.
If providing all the requested information exceeds the statutory cost limit under Section 12 of the Act, please prioritise providing the data for items 1 (Finance) and 2 (HR and Payroll).
I would prefer to receive this information in an electronic format, ideally as an Excel spreadsheet or a clearly formatted table.
Response
Notice of Refusal
Disclosure of information relating to ICT Infrastructure and security constitutes a security risk as it would leave the Council's computer assets more vulnerable to a malicious hacking attack. This means that disclosure would:
• Make the Council more vulnerable to crime (Section 31)
• Risk harming the systems on which the day-to-day business of the Council relies (Section 43) Section 31 (Law Enforcement)
Section 31(1)(a) states that information is exempt if its disclosure is likely to prejudice the prevention or detection of crime. ICO guidance states that this can be used to protect information on a public authority's systems which would make it more vulnerable to crime.
This exemption can be used by a public authority that has no law enforcement function:
• To protect the work of one that does
• To withhold information that would make anyone, including the public authority itself, more vulnerable to crime. The crime in question would be a malicious attack on the Council's computer systems.
Since the disclosure of the withheld information would make the Council's systems more vulnerable to such crime, the exemption is engaged.
The exemption is subject to the public interest test. There is an overwhelming public interest in keeping the Council's computer systems secure which would be served by non-disclosure. This outweighs the public interest in accountability and transparency that would be served by disclosure.
Section 43 (Commercial Interests) Section 43(2) states that information is exempt if its disclosure would, or would be likely to, prejudice the commercial interests of any person (including the public authority holding it).
Disclosure of information relating to ICT security puts the council at risk of a malicious hacking attack. This would compromise the Council's ability to provide its services and carry out 'business-as-usual' should our systems be compromised. Were our systems to be compromised, the cost of a system recovery would be detrimental to the Council's commercial interests.
The exemption is subject to the public interest test. There is an overwhelming public interest in keeping the Council's computer systems secure which would be served by non-disclosure. This outweighs the public interest in accountability and transparency that would be served by disclosure
-
-
Freedom of Information
Contact
Contact us if you have a question about democratic services.
Comments
The content on this page is the responsibility of our Democratic Services team.
