Post Office Limited

UK · www.postoffice.co.uk · 27 vendors

Resilience scores

Technology vendors

Services catalogue

1 service in catalogue across 1 category; runs on 27 sub-vendors.

Insights

Last updated 2026-08-04 · revision 1

27 direct vendors, 240 subvendors

Direct vendors by controlling owner country (sample)

Subvendors by controlling owner country (sample)

Migration Readiness: 6/10

Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.

Post Office Limited demonstrates a moderate level of migration readiness, scoring 60, largely influenced by its architectural choices but tempered by legacy components and data gaps. A significant strength is the adoption of "Microservices Architecture" and "Agile / Scrum" methodologies, which are foundational for cloud migration and modernizing IT infrastructure. Capabilities in "Mobile Application Development" and "Robotics / RPA" further indicate a capacity for deploying and managing modern, distributed applications. However, the continued reliance on "Infomix / IBM Informix (Legacy Database Platform)" poses a substantial challenge for migration, as legacy databases often require complex re-platforming or re-architecting efforts. The use of "Concrete CMS" for its careers website also points to some legacy web infrastructure. Information regarding financial stability to fund migration, specific regulatory compliance requirements, and data residency constraints is not available, which introduces uncertainty. While the "Total Vendors: 0" data is contradictory, the reported "Vendor Geographic Diversity" across 7 countries suggests that the company is not solely tied to a single regional vendor ecosystem, which could offer some flexibility in vendor selection for migration projects. However, the unknown actual number of vendors and the associated "Vendor Lock-in Risk" prevent a more definitive assessment of vendor-related migration challenges or opportunities. The blend of modern architectural principles with entrenched legacy systems places the company in a medium readiness category, with clear opportunities for improvement by addressing its legacy database dependencies.

Compliance

11 in-scope frameworks identified; showing 3.

Modern Slavery Act 2015 — Compliant

Post Office Limited publishes an annual Modern Slavery Statement as required by Section 54 of the Modern Slavery Act 2015 for organisations with an annual turnover of £36 million or more. The statement is publicly available on the corporate website. Risk is Low because: (1) Post Office has met the transparency reporting requirement; (2) As a primarily UK-based retail and financial services company, direct modern slavery risk in its own operations is relatively low; (3) Supply chain risk exists but is managed through supplier policies.

Evidence: https://corporate.postoffice.co.uk/en/governance/reports-statements/modern-slavery-statement/

ISO 27001 (source) — Assessment Required

ISO 27001 certification is highly relevant for Post Office Limited given: (1) It processes sensitive personal and financial data for millions of UK customers; (2) It provides government identity verification services (GOV.UK One Login) which typically require robust information security frameworks; (3) The Horizon IT Scandal exposed catastrophic failures in IT system integrity and information security governance; (4) Post Office is a designated critical national infrastructure (CNI) operator; (5) Its financial services operations are FCA-regulated. The risk is High because the absence of confirmed ISO 27001 certification — combined with the documented Horizon IT failures and ICO practice recommendation — suggests information security governance may be inadequate. ISO 27001 certification would provide independent assurance that ISMS controls are in place. Without it, there is elevated risk of further regulatory action.

Evidence: https://corporate.postoffice.co.uk/en/governance/reports-statements/information-management-policy/, https://corporate.postoffice.co.uk/en/governance/reports-statements/information-commissioner-office-practice-recommendation/, https://corporate.postoffice.co.uk/en/the-horizon-it-scandal/, https://corporate.postoffice.co.uk/en/governance/reports-statements/post-office-annual-report-accounts-2024-25/

Postal Services Act 2011 — Partially Compliant

Post Office Limited operates under the Postal Services Act 2011 and is subject to Ofcom regulation as a designated universal service provider (USP) network. Post Office provides access to Royal Mail's universal postal service through its branch network. Ofcom has regulatory oversight of postal services in the UK. Risk is High because: (1) Post Office is undergoing significant transformation and branch network changes, which are subject to Ofcom consultation requirements; (2) The government's Future of Post Office consultation and subsequent response indicate ongoing regulatory uncertainty about Post Office's structure and obligations; (3) Post Office has published a response to an Ofcom consultation (listed on corporate governance page), indicating active regulatory engagement; (4) The Horizon IT Scandal has prompted Parliamentary scrutiny of Post Office's governance and accountability.

Evidence: https://corporate.postoffice.co.uk/en/governance/reports-statements/post-office-response-to-ofcom-consultation/, https://corporate.postoffice.co.uk/en/governance/reports-statements/post-office-network-report/, https://corporate.postoffice.co.uk/en/purpose-strategy/post-office-transformation/the-government-responds-to-the-future-of-post-office-consultation/, https://www.legislation.gov.uk/ukpga/2011/5/contents, https://www.ofcom.org.uk/postal-services

Financials

Three-year financials

Financial Resilience Score: 4/10

Post Office Limited's financial resilience is heavily dependent on UK Government support rather than underlying operational strength. The FY24/25 return to profitability (£154m PBT) is misleading, as it is driven entirely by £525m of Government funding recognised against exceptional items related to Horizon Shortfall Scheme settlements. The underlying trading loss of £12m represents a £34m deterioration versus prior year, and the company sits on net liabilities of £1,116m. PwC issued a qualified audit opinion and flagged material uncertainty related to going concern, tied to reliance on a non-binding Shareholder Letter of Support from DBT. On the positive side, the company benefits from full UK Government ownership, providing access to a £950m Working Capital Facility, £50m Same Day Facility (both extended to March 2028), a £39.75m fixed-term loan, and dedicated Network Subsidy Payments (£88m in FY25). Structural tailwinds in banking access (revenue +10% to £281m, 49 new Banking Hubs opened) and a profitable FRESH joint venture with Bank of Ireland (£23m post-tax profit share, £30m dividend) provide some stabilization. However, structural revenue decline in traditional counter mails, lottery exit, and the enormous £781m Remediation Matters provision create ongoing pressure. Access to capital is restricted to Government sources without approval, and the £101m IR35 tax provision plus unquantified Horizon-related contingent liabilities create further downside risk. Absent Government backing, the entity would not be financially viable.

Key strengths: 100% UK Government ownership via DBT with £950m Working Capital Facility extended to March 2028, Government funding of £525m recognised in FY25 against exceptional items, Network Subsidy Payments increased to £88m (from £50m), Banking Services revenue growth of 10% to £281m driven by high-street bank branch closures, Profitable FRESH JV with Bank of Ireland contributing £23m profit share and £30m dividend, Largest retail franchise network in Europe with 11,500+ branches, Diversified revenue across mails, banking, insurance, travel money, government services

Risk factors: PwC qualified audit opinion on £671m HSS provision and £151m deferred tax asset, Material uncertainty related to going concern flagged by auditor, Net liabilities of £1,116m at year end, Underlying trading loss of £12m in FY25 (deterioration of £34m YoY), £781m Remediation Matters provision with significant estimation uncertainty, £101m IR35 tax provision with settlement expected in 2025/26, Structural decline in traditional counter mails and loss of National Lottery contract, Ongoing Horizon IT Public Inquiry with potential additional unquantified liabilities, Horizon replacement strategy discontinued; Fujitsu contract extended to March 2027, Reliance on non-binding Shareholder Letter of Support, Restricted access to capital outside Government sources, Revenue declining 4.5% YoY (FY24 also declined 6.9%)

Revenue by geography

Revenue by product/service

Workforce by country

Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.

View the full interactive report