Quality and Security Policy
Global Manager Iberia is the first interim management firm in the Iberian Peninsula to be certified by AENOR in accordance with the ISO 9001:2015 and ISO/IEC 27001:2022 standards. This is the policy that governs our Integrated Management System.
This Policy, approved by the MANAGEMENT of Global Manager Iberia (*), constitutes the framework for the conduct of our activities and relationships, and applies to all operations of our companies and trading brands, as well as to all our own staff, collaborators and subcontractors, and to anyone acting in an authorised capacity on behalf of or for the account of the organisation.
This scope of application relates to our corporate commitment and covers the entire group. The certified scope of each management system is more limited and is defined in the relevant manuals; see section 4.
(*) Global Manager Iberia is the umbrella name for the companies GLOBAL MANAGER SPAIN, S.L. and GLOBAL MANAGER PORTUGAL UNIPESSOAL LDA, and provides services based on new ways of working, in Spain and Portugal, under the trade marks EPUNTO Interim Management, The LIQUID finance, The LIQUID build and Círculo de Management.
1. Purpose
This Policy aims to meet the needs and requirements of our clients, by committing to sound professional practice and providing services that fulfil their intended purpose, whilst recognising the importance of focusing on understanding our stakeholders and preventing, and responding swiftly and effectively to, any risk situation.
It is our purpose to resolve our clients’ challenges by drawing on our global, flexible, qualified and committed talent. We regard quality as a fundamental strategy for achieving and sustaining our objectives, and information security as an integral part of delivering those services: our services rely on our own information and that entrusted to us by third parties, and protecting this information is integral to delivering our services effectively.
Management has put in place the necessary resources, responsibilities and mechanisms for the implementation, development and continuous improvement of an INTEGRATED MANAGEMENT SYSTEM, aligned with the international standards ISO 9001:2015 and ISO 27001:2022.
2. Quality Commitments
- Quality and its improvement are the responsibility of all Global Manager Iberia staff, starting with the Management.
- Quality is achieved by planning, implementing, reviewing and improving the management system, whilst always taking into account the organisation’s context, both internal and external.
- Quality is geared towards the satisfaction of all our stakeholders, meeting their needs and requirements, as well as legal and regulatory requirements and those specific to our services, including all implications associated with climate change.
- Quality is underpinned by the effectiveness of the management system, in which preventing errors is a fundamental aspect, whilst always striving for continuous improvement.
- Quality guides us to pay the utmost attention to technological developments and to the improvements that new technologies make available to us.
3. Information Security Commitments
Management assumes responsibility for the Information Security Management System and declares the following commitments:
- Alignment with the organisation’s purpose. Information security is aligned with the business strategy and the context in which we operate, and is scaled according to the assessed risk rather than a generic template.
- Protection of information. We safeguard the confidentiality, integrity and availability of our own information and that entrusted to us by clients, candidates, employees and suppliers, regardless of its format or location.
- Compliance with applicable requirements. We comply with legal, regulatory and contractual requirements regarding security and data protection — in particular Regulation (EU) 2016/679, the LOPDGDD and applicable Portuguese legislation — as well as the commitments made to clients when we act as data processors.
- Framework for objectives. This Policy forms the basis on which the information security objectives, described in section 5, are established.
- Continuous improvement. We are committed to the continuous improvement of the system, addressing any non-conformities, incidents and opportunities identified.
- Risk management as a cornerstone. We regularly identify and assess security risks, determine how to manage them, and explicitly state when a risk is not adequately addressed, rather than assuming it has been resolved.
4. Scope
The scope of the Integrated Management System is as defined in the system documentation: that of the Quality Management System in the QMS Manual and context record R-00-00, and that of the Information Security Management System in the ISMS Manual, section 2.3, together with the current Statement of Applicability.
The certified scope is more restricted than the scope of application of this Policy. In particular, the scope of the ISMS covers only GLOBAL MANAGER SPAIN, S.L. and its Valladolid office, and expressly excludes GLOBAL MANAGER PORTUGAL UNIPESSOAL LDA, the commercial offices in Madrid and Lisbon, and the design and development services provided to clients, in accordance with the ISMS Manual, section 2.3.1. References in this Policy to group companies, their offices or the legislation of the countries in which they operate do not extend the certified scope.
This Policy does not reproduce the scope: it merely refers to it, so that any updates do not result in divergent versions.
5. Framework for Objectives
Quality and information security objectives are established on a regular basis; they are measurable, communicated and reviewed during the Management Review and by the Quality and Security Committee. They are derived from:
- The analysis of the context and the analysis and assessment of risks and opportunities.
- The applicable legal, regulatory and contractual requirements.
- Recorded non-conformities, incidents, complaints and opportunities.
- The results of internal and external audits.
6. Responsibilities
Senior Management approves this Policy, allocates resources, oversees the review of the system and formally accepts residual risks. The Quality Manager governs the management system, its documentation, internal audits and non-conformities. The Chief Information Security Officer (CISO) maintains the ISMS, risk management, incident management and awareness programmes. Process owners implement the controls within their remit and provide evidence of their implementation. All staff comply with this Policy and report any incidents or suspicions.
The specific allocation of these responsibilities is recorded within the management system.
7. Specific policies
This Policy is elaborated upon in thematic policies that are mandatory and have the same binding force; these do not replace this Policy and must not contradict it: access control, password management, cryptographic controls, acceptable use of assets, secure development and acceptable use of cloud services.
Any future thematic policy is subordinate to this document.
8. Ethical conduct
Management promotes a culture of quality and security based on ethical behaviour, transparency and accountability. This Policy and the code of conduct reinforce one another and seek to ensure customer satisfaction and the trust of our stakeholders as an essential principle of our activity.
The organisation provides a confidential and secure whistleblowing channel —https://ethic.gmiberia.com— available to anyone to report irregularities, misconduct or ethical conflicts, without fear of reprisal.
9. Communication, availability and review
Quality and Safety require the participation and collaboration of everyone; therefore, this Policy is disseminated to all Global Manager Iberia staff to ensure they are aware of and understand it. It is provided upon joining the organisation and following each revision, and is permanently available within the management system. It is made available to interested parties who require it for contractual or audit purposes.
This Policy is reviewed at least once a year, and whenever there are significant changes to the organisation, the services provided, the risk context or the applicable requirements. It comes into force on the date of its approval and supersedes the previous version.
Rev. 6.0 · effective from 14/09/2026 · approved by Management. For any enquiries regarding our management system, please email legal@gmiberia.com.