ISO 9001 · ISO/IEC 27001 · ISO/IEC 42001 · ISO 22301

Practical ISO management systems for ambitious startups and SMEs.

Quality, information security, AI governance and business continuity — integrated, proportionate and built to work in the real world.

ISO 9001QUALITY
ISO/IEC 27001SECURITY
ISO/IEC 42001AI
ISO 22301RESILIENCE
CroftSpurr logo mark

One coherent management system — not disconnected projects.

Why CroftSpurr?

Systems that keep up with your ambition.

CroftSpurr helps ambitious startups, SMEs, and companies who want to maximise their performance using the latest digital technologies, but at the same time protect information, govern their use of AI and strengthen resilience through practical management systems.

From ISO 9001 and ISO/IEC 27001 to ISO/IEC 42001 and business continuity, we turn complex requirements into systems that work in the real world.

Methodology shaped by Dr. Nigel Croft — former Chair of the ISO subcommittee responsible for ISO 9001 & 9004 (2010 - 2018) and the ISO Joint Technical Coordination Group for all Management System Standards (2018 - 2023).

Dr. Croft has dedicated his entire professional career, spanning over 50 years, to quality management, development, implementation and auditing of management systems standards. He is respected the world over for his ability to simplify the understanding and implementation of ISO standards.

ISO 9001

Quality

ISO/IEC 27001

Information Security

ISO/IEC 42001

AI Management

ISO 22301

Business Continuity

ISO/IEC 23894

Guidance on AI Risk Management

Two forms of experience. One practical system.

Standards authority. Business reality.

Portrait of Dr. Nigel Croft

International Standards Leadership

Principal Adviser & Mentor

Dr. Nigel Croft

Dr. Croft has dedicated his entire professional career, spanning over 50 years, to quality management, development, implementation and auditing of management systems standards. He is respected the world over for his ability to simplify the understanding and implementation of ISO standards.

From 2010 to 2018, he chaired ISO/TC 176/SC2 — the ISO subcommittee with responsibility for standards including ISO 9001 and ISO 9004. He later led international work on the harmonised structure used across ISO management system standards.

His influence on CroftSpurr is clear: focus on intended results, understand the organisation’s processes, apply risk-based thinking and avoid unnecessary bureaucracy.

As a certified BSI AI Management Practitioner, he has coordinated workshops on the role of international standards in supporting digitalization policy for governments across Africa, Asia and Latin America.

Meet Nigel →
Portrait of Matthew Spurr

Experienced Business Leadership

Managing Director

Matthew Spurr

Matthew brings more than 15 years of experience as a founder, operator and business leader.

After a decade at his previous startup, he decided that he wanted to change the dynamic and share his experience with other founders and CEOs.

In addition to having built and run AI-powered SaaS startups, Matthew has also been Marketing Director for two of the world's largest professional exhibitions (Accountex and Legalex), and in the early stages of his career, ran a niche digital PR agency.

At CroftSpurr he works closely alongside Dr. Croft to translate management system principles into clear responsibilities, usable processes and practical evidence that fit growing organisations.

Meet Matthew →

Standards expertise shaped at international level. Implementation grounded in real business.

AI Governance

AI is moving faster than most organisations’ governance.

Policies written after deployment are not enough. Organisations need to know where AI is being used, who is accountable, what could go wrong, who may be affected and how decisions will be reviewed.

ISO/IEC 42001

AI management system

ISO/IEC 23894

Guidance on AI Risk Management

ISO/IEC 42005

AI system impact assessment

ISO/IEC 38507

Governance implications of AI

Know your AI

Identify AI systems, use cases, suppliers, owners and affected parties.

Assess the risk

Evaluate reliability, bias, data, security, transparency, human oversight and potential impacts.

Establish control

Define policies, responsibilities, approval routes, monitoring, incident handling and continual improvement.

Support at every stage

A service journey, not a single deliverable.

  1. 01

    Diagnose

    Executive discovery, context review, gap analysis, readiness assessment, risk review and a prioritised implementation roadmap.

  2. 02

    Design

    Management system architecture, process mapping, policies and objectives, roles and responsibilities, proportionate documented information.

  3. 03

    Implement

    Leadership workshops, team engagement, control implementation, training and competence, evidence development, operational support.

  4. 04

    Assure

    Internal audits, supplier audits, readiness reviews, corrective action support, management review preparation, certification audit support.

  5. 05

    Improve

    Retained advisory, performance measurement, audit programme management, continual improvement, system integration, transitions.

We don't just hand over a folder of documents, then disappear.

The CroftSpurr method

Process approach. Risk-based thinking. Plan-Do-Check-Act.

It begins with what the organisation needs to achieve — not with a template.

01

Understand the context

02

Define the intended results

03

Map the real processes

04

Evaluate risks and opportunities

05

Build proportionate controls

06

Test effectiveness

07

Improve continually

08

Embed the system in the business

No template theatre. No bureaucracy for its own sake. No management system that exists only on audit day.

Integrated management systems

One business. Not four separate systems.

Quality, information security, AI governance and business continuity often involve the same leadership team, processes, risks, suppliers and evidence.

CroftSpurr can design an integrated management system that reduces duplication and gives leaders one coherent view of performance and risk.

Explore Integrated Systems →
Organisational management system
QualityInformation securityAI governancePrivacyBusiness continuityService managementEnterprise risk

Independence

Consultancy and certification are different.

CroftSpurr helps organisations understand requirements, implement their management system, conduct internal audits and prepare for certification. Independent certification is carried out by a separate certification body. This separation protects impartiality and gives customers confidence in the result. We have no affiliation with any certification body.

CroftSpurr does not sell or issue ISO certificates.

We can help clients understand how to select an appropriate independent certification body — but we never imply that certification is guaranteed.

You do not need more bureaucracy.

You need a system that makes the business stronger.

Whether you’re responding to a customer requirement, preparing for certification, or trying to bring greater control to a growing organisation, begin with a practical conversation.

Talk to CroftSpurr