ISO 9001 · ISO/IEC 27001 · ISO/IEC 42001 · ISO 22301
Quality, information security, AI governance and business continuity — integrated, proportionate and built to work in the real world.
One coherent management system — not disconnected projects.
Why CroftSpurr?
CroftSpurr helps ambitious startups, SMEs, and companies who want to maximise their performance using the latest digital technologies, but at the same time protect information, govern their use of AI and strengthen resilience through practical management systems.
From ISO 9001 and ISO/IEC 27001 to ISO/IEC 42001 and business continuity, we turn complex requirements into systems that work in the real world.
Methodology shaped by Dr. Nigel Croft — former Chair of the ISO subcommittee responsible for ISO 9001 & 9004 (2010 - 2018) and the ISO Joint Technical Coordination Group for all Management System Standards (2018 - 2023).
Dr. Croft has dedicated his entire professional career, spanning over 50 years, to quality management, development, implementation and auditing of management systems standards. He is respected the world over for his ability to simplify the understanding and implementation of ISO standards.
ISO 9001
Quality
ISO/IEC 27001
Information Security
ISO/IEC 42001
AI Management
ISO 22301
Business Continuity
ISO/IEC 23894
Guidance on AI Risk Management
Why organisations come to CroftSpurr
They begin with a commercial problem, an important customer requirement or a level of risk they can no longer ignore.
A major customer, procurement team or tender requires evidence of quality, security or governance.
The organisation has grown beyond informal founder-led processes and responsibilities are becoming unclear.
Customers are asking difficult questions about information security, access, suppliers, incidents and data.
AI is already being used, but policies, responsibilities, risk assessments and oversight have not kept pace.
Too much knowledge sits with particular founders, employees or suppliers.
The organisation needs credible plans for outages, cyber incidents, supplier failures or other disruption.
Two forms of experience. One practical system.

International Standards Leadership
Principal Adviser & MentorDr. Croft has dedicated his entire professional career, spanning over 50 years, to quality management, development, implementation and auditing of management systems standards. He is respected the world over for his ability to simplify the understanding and implementation of ISO standards.
From 2010 to 2018, he chaired ISO/TC 176/SC2 — the ISO subcommittee with responsibility for standards including ISO 9001 and ISO 9004. He later led international work on the harmonised structure used across ISO management system standards.
His influence on CroftSpurr is clear: focus on intended results, understand the organisation’s processes, apply risk-based thinking and avoid unnecessary bureaucracy.
As a certified BSI AI Management Practitioner, he has coordinated workshops on the role of international standards in supporting digitalization policy for governments across Africa, Asia and Latin America.
Meet Nigel →
Experienced Business Leadership
Managing DirectorMatthew brings more than 15 years of experience as a founder, operator and business leader.
After a decade at his previous startup, he decided that he wanted to change the dynamic and share his experience with other founders and CEOs.
In addition to having built and run AI-powered SaaS startups, Matthew has also been Marketing Director for two of the world's largest professional exhibitions (Accountex and Legalex), and in the early stages of his career, ran a niche digital PR agency.
At CroftSpurr he works closely alongside Dr. Croft to translate management system principles into clear responsibilities, usable processes and practical evidence that fit growing organisations.
Meet Matthew →Standards expertise shaped at international level. Implementation grounded in real business.
Our core expertise
Build consistent processes, improve customer confidence and create a stronger foundation for growth.
A structured approach to protecting information, managing security risk and answering customer assurance.
Accountable, transparent and risk-based governance for organisations developing, providing or using AI.
Prepare to respond to disruption, protect critical activities and recover more effectively.
AI Governance
Policies written after deployment are not enough. Organisations need to know where AI is being used, who is accountable, what could go wrong, who may be affected and how decisions will be reviewed.
ISO/IEC 42001
AI management system
ISO/IEC 23894
Guidance on AI Risk Management
ISO/IEC 42005
AI system impact assessment
ISO/IEC 38507
Governance implications of AI
Identify AI systems, use cases, suppliers, owners and affected parties.
Evaluate reliability, bias, data, security, transparency, human oversight and potential impacts.
Define policies, responsibilities, approval routes, monitoring, incident handling and continual improvement.
Support at every stage
Executive discovery, context review, gap analysis, readiness assessment, risk review and a prioritised implementation roadmap.
Management system architecture, process mapping, policies and objectives, roles and responsibilities, proportionate documented information.
Leadership workshops, team engagement, control implementation, training and competence, evidence development, operational support.
Internal audits, supplier audits, readiness reviews, corrective action support, management review preparation, certification audit support.
Retained advisory, performance measurement, audit programme management, continual improvement, system integration, transitions.
We don't just hand over a folder of documents, then disappear.
The CroftSpurr method
It begins with what the organisation needs to achieve — not with a template.
Understand the context
Define the intended results
Map the real processes
Evaluate risks and opportunities
Build proportionate controls
Test effectiveness
Improve continually
Embed the system in the business
No template theatre. No bureaucracy for its own sake. No management system that exists only on audit day.
Who we help
Build customer and investor confidence without importing enterprise bureaucracy too early.
Strengthen security, service delivery, quality and AI governance for demanding B2B customers.
Governance across AI design, development, supply, deployment, monitoring and change.
Control employee use, supplier risk, data exposure and decision-making impacts.
Replace informal practices with scalable, measurable systems.
Demonstrate credible management of quality, security, continuity and supplier risk.
Integrated management systems
Quality, information security, AI governance and business continuity often involve the same leadership team, processes, risks, suppliers and evidence.
CroftSpurr can design an integrated management system that reduces duplication and gives leaders one coherent view of performance and risk.
Explore Integrated Systems →Independence
CroftSpurr helps organisations understand requirements, implement their management system, conduct internal audits and prepare for certification. Independent certification is carried out by a separate certification body. This separation protects impartiality and gives customers confidence in the result. We have no affiliation with any certification body.
CroftSpurr does not sell or issue ISO certificates.
We can help clients understand how to select an appropriate independent certification body — but we never imply that certification is guaranteed.
Insights
Quality
Read article →
AI
Read article →
ISO/IEC 23894
Read article →
Startups
Read article →
Continuity
Read article →
Integration
Read article →
Whether you’re responding to a customer requirement, preparing for certification, or trying to bring greater control to a growing organisation, begin with a practical conversation.