1. Introduction
Grupo AIA Management establishes this Integrated Quality and Information Security Policy as the reference framework for the development, implementation, maintenance and continuous improvement of its Integrated Management System (IMS), in accordance with ISO 9001 and ISO/IEC 27001 standards.
Under the motto “Algorithms for a Better World”, AIA’s mission is to solve complex industrial challenges within the ICT sector through the innovative creation and application of algorithms, mathematical models and data‑science‑based solutions, while simultaneously ensuring:
- The quality of products and services
- Information security
- Legal and regulatory compliance
- Customer and stakeholder satisfaction
This policy constitutes the basis for establishing IMS objectives and is developed through regulations, procedures, operational instructions and other associated documentation.
2. Scope
This policy applies to:
- All personnel of Grupo AIA.
- Collaborators, suppliers and third parties involved in information management or service provision.
- All processes included within the scope of the IMS.
3. Principles and commitments of the Integrated Management System
3.1 Quality and customer focus
Grupo AIA is committed to:
- Designing, developing, implementing and maintaining products and services that meet customer requirements as well as applicable legal and regulatory requirements.
- Maintaining a real value proposition based on tailored solutions, innovation and knowledge transfer from basic and applied sciences.
- Continuously measuring and improving customer satisfaction as a key indicator of system performance.
- Establishing and managing an effective process structure focused on results and organizational performance improvement.
3.2 Information security
Grupo AIA protects information as a critical business asset, ensuring the principles of:
- Confidentiality: access only by authorized persons.
- Integrity: accuracy, completeness and validity of information.
- Availability: access to information when required.
- Legality: compliance with applicable regulations, especially regarding personal data protection.
An Information Security Management System based on risk management is implemented to prevent, detect and respond to security incidents that may affect business continuity.
3.3. Risk‑ and opportunity‑based approach
Management ensures that the IMS:
- Is based on the systematic identification, analysis, evaluation and treatment of risks and opportunities in both quality and information security.
- Risks are reviewed periodically, at least annually or whenever significant organizational changes occur.
- Responsible owners are assigned to each identified risk and appropriate control measures are implemented.
3.4. People, training and awareness
Management recognizes human capital as AIA’s main asset and commits to:
- Providing continuous training in quality, information security and process improvement.
- Promoting staff awareness of their role in complying with this policy.
- Encouraging staff participation in the continuous improvement of the IMS.
3.5. Roles, responsibilities and system governance
Management clearly defines and communicates:
- Defining and communicating the responsibilities and authorities required for the correct functioning of the IMS.
- The existence of an IMS Manager, a Security Manager and a Security Committee led by Management.
- The existence of a Data Protection Officer in accordance with applicable regulations.
3.6. Audit, monitoring and continuous improvement
Grupo AIA commits to:
- Planning and carrying out periodic internal and external audits.
- Evaluating IMS performance through indicators, objectives and management reviews.
- Applying corrective and improvement actions to ensure continuous improvement.
4. Communication and dissemination
This policy:
- Is communicated to and understood by all members of the organization.
- Is available to relevant interested parties.
- Is disseminated through training, awareness and internal communication activities.
5. Non‑compliance and disciplinary measures
Failure to comply with this policy may result in disciplinary measures or sanctions in accordance with applicable legislation and Grupo AIA internal procedures.
6. Review and validity
This policy enters into force upon approval and:
- Is reviewed at least once a year.
- Is updated in the event of relevant changes in:
- The organization’s context
- The services provided
- Applicable legislation
- The results of audits and risk analyses
7. Approval
Grupo AIA Management formally approves and adopts this Integrated Policy and commits to providing the resources necessary to ensure its implementation, maintenance and continuous improvement.
REGINA MARÍA LLOPIS RIVAS,
Sole Administrator