allclouds.pl
allclouds.pl / Quality policy

Integrated Management System Policy

(quality, information security, environment, business continuity, artificial intelligence)

List of paragraphsISO certificates
IMS PolicyVersion 7.0 · approved on 7 August 2026
Component policies
BVBureau Veritas · 7 ISO standards in one system
Integrated management system

One management system
Seven ISO standards. One auditor

All certificates are issued for the same integrated system — not for separate “projects”. The ISO 42001 certificate covers software design and production, the methodology, and consulting and training activities

Bureau Veritasthe certification body for all seven standards
0 nonconformitiesin the ISO/IEC 42001 certification audit (22.05.2026)
ISO/IEC42001
Artificial intelligence management

ISO/IEC 42001:2023 — the first issued by Bureau Veritas in Poland

Certificate no. PL019296, valid 18.06.2026–17.06.2029. The system covers evidence, protection of confidential data and accountability for the use of AI

How we passed the audit in 1.5 months
Information security and cloud
ISO/IEC27001
Information securityno. PL016445/3/Pvalid until 07.08.2027
ISO/IEC27017
Cloud service securityno. PL018690/2/Nvalid until 22.02.2029
ISO/IEC27018
Personal data in the cloudno. PL018690/1/Nvalid until 22.02.2029
Organisational foundation
ISO9001
Quality managementno. PL016445/3/Pvalid until 07.08.2027
ISO22301
Business continuityno. PL018690/2/Pvalid until 22.02.2029
ISO14001
Environmental managementno. PL016445/3/Pvalid until 07.08.2027
LIST OF PARAGRAPHS

The IMS Policy in ten paragraphs

Paragraphs 3–7 are component policies — each corresponds to the standards to which the system is certified

POLICY TEXT
§ 1

Purpose, scope and normative basis

  1. The Integrated Management System Policy (the “IMS Policy”) expresses the overall intentions and direction of allclouds.pl sp. z o.o. (the “Organisation”) with regard to quality, information security, environmental protection, business continuity and artificial intelligence management, as formally established by Top Management.

  2. The IMS Policy covers the activities defined in §2 of the IMS Manual: IT consulting and training, supply and servicing of hardware, software and IT systems, delivery of IT projects, including comprehensive IT staffing services, and software design and production.

  3. The scopes of the component systems, in accordance with clause 4.3 of the relevant standards, are defined as follows:

    • the Quality Management System and the Business Continuity Management System — the entire Organisation and all its products,
    • the Information Security Management System — all of the Organisation’s information assets, including information stored in the public cloud; for this reason the Organisation extends its ISMS with the requirements of PN-EN ISO/IEC 27017 and PN-EN ISO/IEC 27018,
    • the Environmental Management System — the Organisation’s head office premises and the external server room in which the Organisation maintains its own computing infrastructure under a colocation model,
    • the Artificial Intelligence Management System — additionally, beyond the scope indicated in paragraph 2, the Cognitive Deployment Framework (CDF).
  4. Specific notes on the implementation of PN-EN ISO/IEC 27017 and PN-EN ISO/IEC 27018 (§2¹ of the IMS Manual):

    • the Organisation’s activities comply with these standards to the extent that its core and supporting processes are or may be carried out in the cloud,
    • the Organisation acts as a cloud service customer within the meaning of PN-EN ISO/IEC 27017 and as a controller of personal data (PII controller) transferred for processing in the public cloud within the meaning of clause 3.3 of PN-EN ISO/IEC 27018; the Organisation entrusts personal data received from clients to cloud service providers for further processing on the basis of data processing agreements,
    • the Organisation is the controller of the personal data of its team members and of subcontractors and processors under agreements with clients and subcontractors,
    • the Organisation is a customer of Microsoft Azure and Asana cloud services,
    • the Organisation anticipates the possibility of creating a cloud service supply chain, as referred to in clause 4.2 of PN-EN ISO/IEC 27017, when its clients are ready to implement such solutions, and undertakes to ensure compliance with these standards if such a chain is created,
    • the Organisation has the human and organisational resources to provide, via the cloud, storage, network and workstation virtualisation services, database and application development and migration of client operations to the cloud; when selecting a provider, the Organisation is guided by the Client’s requirements and the commitments arising from this Policy.
  5. Specific notes on the implementation of ISO/IEC 42001:2023 (§2² of the IMS Manual):

    • the CDF product covered by the Artificial Intelligence Management System comprises: the CDF methodology used in client projects, the CDF Platform — a web application for managing AI deployments, the CogOps service (CDF Phase F6) — continuous operation of AI systems, and the Cognitive SLA service — guaranteeing the quality of AI reasoning,
    • CDF as a product covered by the Artificial Intelligence Management System is not subject to certification under PN-EN ISO 9001, PN-EN ISO/IEC 27001, PN-EN ISO/IEC 27017, PN-EN ISO/IEC 27018, PN-EN ISO 14001 and PN-EN ISO 22301, whose scope is defined in paragraph 2,
    • the other products and development work of the SAIE ecosystem referred to in §3(2) are subject to the principles of §7 of this Policy and the AI Usage Policy; their inclusion under these principles does not extend the certification scope of the Artificial Intelligence Management System. Extending the scope requires a prior amendment to §2² of the IMS Manual and notification to the certification body.
  6. The IMS Policy implements the requirements of the following standards:

    • PN-EN ISO 9001:2015-10 — quality management systems (clause 5.2),
    • PN-EN ISO/IEC 27001:2023-08 — information security management systems (clause 5.2),
    • PN-EN ISO/IEC 27017:2021-07 and PN-EN ISO/IEC 27018:2020-11 — security controls for cloud services and protection of personal data in the public cloud (clause 5),
    • PN-EN ISO 14001:2015-09 — environmental management systems (clause 5.2),
    • PN-EN ISO 22301:2020-04 — business continuity management systems (clause 5.2),
    • ISO/IEC 42001:2023 — artificial intelligence management system (clause 5.2).
  7. The IMS Policy applies to all employees, associates and subcontractors acting on behalf of the Organisation, to the extent relevant to the tasks entrusted to them.

  8. The IMS Policy consists of: the Quality Policy (§3), the Information Security Policy (§4), the Environmental Policy (§5), the Business Continuity Policy (§6) and the Artificial Intelligence Management System Policy (§7).

§ 2

Top Management Declaration

  1. On the basis set out in clause 5.2.1(d) of PN-EN ISO 9001, clause 5.2(d) of PN-EN ISO/IEC 27001, clause 5.2.1(e) of PN-EN ISO 14001, clause 5.2.1(d) of PN-EN ISO 22301 and clause 5.2 of ISO/IEC 42001, Top Management declares its continuous commitment to improving the Integrated Management System.

  2. If, during day-to-day work or during an audit of the Organisation, it is found that any of the relevant requirements of the implemented standards is not met or could be met more fully, the Organisation will take appropriate improvement or corrective action.

  3. Top Management undertakes to meet the applicable requirements of the implemented standards, the legal requirements relevant to the Organisation’s activities and the expectations of interested parties, and to provide the resources necessary for the operation and improvement of the IMS.

  4. Through continuous improvement of management, the Organisation ensures reliable and timely delivery. The component systems are consistent and interlinked with respect to the procedures for setting objectives, control of documents and records, training, monitoring, measurement and control of nonconformities, corrective action and management review.

  5. This Policy provides the framework for setting and reviewing the IMS objectives, defined in §5 of the IMS Manual and monitored in the Organisation’s task management system.

§ 3

Quality Policy

ISO 9001

Top Management, in accordance with clause 5.2.1 of PN-EN ISO 9001:2015, establishes, implements, communicates and declares that it maintains a Quality Policy with the following content.

  1. The Organisation offers the Client comprehensive, innovative, unique and competitively priced solutions that enable a high level of functionality of the IT systems implemented, and in particular their security.

  2. The Organisation’s offering is the Sovereign Artificial Intelligence Ecosystem (SAIE), which consists of:

    • TWIN:DESK — the AI digital desk; a sovereign AI workspace that brings together work modules, model choice and organisational knowledge in one configurable place (core product),
    • PROXY:AI — a gateway for services, rules and compliance; a single point of control for every language model call, covering data classification, routing, policy enforcement, cost accounting and an immutable log (core product),
    • CDF Platform — an AI implementation methodology ensuring the effectiveness and compliance of deployments; the overarching layer above the other elements of the ecosystem,
    • SAVANT-AI — a cognitive system forming the sovereign knowledge core of the organisation (research and development work),
    • GENESIS-AI — an agent factory; an environment for producing and orchestrating autonomous AI agents (research and development work),
    • HCG — methods for improving work, and CDT — the employee’s cognitive digital twin; methodological layers expressing the Organisation’s adopted philosophy of working with AI.
  3. The Organisation achieves the objective set out in paragraph 1 by:

    • maintaining lasting and positive relationships with Clients, learning about and analysing their needs and consistently meeting the Client’s requirements and business objectives,
    • following the latest trends in the IT market and the economy,
    • building competence on the basis of a permanent group of experienced specialists in many areas of IT and other areas relevant to achieving the Organisation’s objectives, and striving to raise their qualifications,
    • maintaining stable, long-term relationships with business partners that provide access to expert knowledge of the products offered,
    • building a range of its own services,
    • designing and delivering solutions that allow a quick return on the Client’s investment,
    • ensuring timely and reliable fulfilment of contractual obligations.
  4. With respect to the core products referred to in paragraph 2, the Organisation adopts the following quality commitments:

    • sovereignty as a property of the product, not a declaration — every deployment variant (sovereign cloud, on-premises, appliance, air-gapped mode) delivers the full functional scope, and the choice of variant determines only where data is processed,
    • compliance enforced by technical means — regulatory requirements are enforced by the product architecture (data classification, routing, approval thresholds, log), not by a policy provision that can be circumvented,
    • traceability and accountability — every model call and every agent action leaves a record that makes it possible to reconstruct the course of events and present evidence for audit purposes,
    • human oversight proportionate to risk — the level of autonomy is explicit and controlled, and tasks of high risk require human approval,
    • no dependence on a single vendor — an open technology stack makes it possible to replace the model layer without rebuilding the system at the Client’s site,
    • interoperability within the ecosystem — SAIE products and development work use a common control layer provided by PROXY:AI.
  5. With respect to the research and development work referred to in paragraph 2, the Organisation separates the scope of research work from its commercial activities, documents the technology readiness levels achieved and does not present the results of development work as ready for production deployment before their maturity has been confirmed.

  6. Top Management undertakes to meet the relevant requirements of PN-EN ISO 9001:2015, the legal requirements relevant to the Organisation’s activities and the expectations of interested parties, and to continuously improve the Quality Management System.

  7. Risks of the processes covered by the Quality Management System are managed in the IMS Risk Register, in accordance with the Risk Assessment Methodology and the risk management procedure.

  8. The measurable objectives of the Quality Management System are set out in §5 of the IMS Manual and are reviewed during the management review.

§ 4

Information Security Policy

ISO/IEC 27001ISO/IEC 27017ISO/IEC 27018

Top Management, demonstrating due commitment and with the aim of ensuring compliance with the implemented information security standards, in accordance with clause 5.2 of PN-EN ISO/IEC 27001:2023-08, clause 5 of PN-EN ISO/IEC 27017 and clause 5 of PN-EN ISO/IEC 27018, adopts an Information Security Policy with the following content.

  1. The Information Security Policy applies to the Organisation’s entire information system, including information stored by the Organisation and its clients in public clouds. The context of cloud use is defined in §1(4).

  2. The Organisation strives to ensure the highest level of security of the information covered by the Information Security Management System and to ensure compliance with all relevant legal requirements.

  3. The Management Board takes the necessary steps to ensure appropriate protection of information assets — including personal data for which the Organisation is the controller or processor — against all identified threats.

  4. The method of risk estimation, the risk evaluation criteria and risk management are described in the Risk Assessment Methodology and the procedure for risk management and asset inventory. The risk analysis considers separately the loss of confidentiality, integrity and availability of information, taking into account the specific nature of cloud services.

  5. Information is protected in proportion to its value, in accordance with the Information Classification Procedure. The list of controls applied is set out in the current Statement of Applicability, which is reviewed at least once a year and after each risk analysis.

  6. Access to classified and sensitive information is granted on a need-to-know basis. Information processing facilities have been implemented with redundancy sufficient to meet availability requirements.

  7. Security requirements for ICT systems also apply to third parties and are reflected in the contracts concluded. Services provided by third parties are regularly monitored and audited.

  8. Information security events and incidents are reported to the Management Representative for the IMS or to the Technical Director; the procedure is set out in the Incident Management Procedure.

  9. Every team member is trained at least once a year in the principles and requirements of this Policy and the related documents.

  10. The Management Board is responsible for establishing and implementing the Information Security Policy. Its implementation is overseen by the Management Representative for the IMS and the Technical Director. All members of staff are responsible for its implementation in accordance with their duties and positions.

  11. The measurable objectives of the Information Security Management System are set out in §5 of the IMS Manual.

§ 5

Environmental Policy

ISO 14001
  1. Top Management, recognising the importance of environmentally friendly action, sets a direction aimed at systematically striving to minimise the environmental impact of the Organisation’s activities in the design, delivery and servicing of IT systems, the supply and servicing of hardware, software and IT systems, the delivery of IT projects, software design and production, and consulting and training activities.

  2. The Environmental Management System implemented aims to:

    • secure management support for environmental protection activities,
    • formally declare management’s commitment to implementing an environmental protection programme,
    • define environmental objectives and plan their achievement,
    • identify risks and opportunities,
    • inform and train employees,
    • establish a system of continual improvement,
    • assess the effectiveness of operation and document the activities carried out,
    • involve all of the Organisation’s employees in implementing the environmental policy.
  3. Within its capabilities and the boundaries of the Environmental Management System, the Organisation undertakes to prevent pollution caused by its activities and to meet the relevant legal requirements in this area.

  4. The physical boundaries of the Environmental Management System cover the Organisation’s head office premises and the external server room in which the Organisation maintains its own computing infrastructure under a colocation model, in accordance with §1(3). Within the colocation boundaries, the Organisation controls those environmental aspects it has an influence on — in particular the electricity consumption of its own computing infrastructure, its energy efficiency and the handling of waste electrical and electronic equipment; aspects under the control of the facility operator are treated by the Organisation as aspects it can influence, and are reflected in the requirements set for the provider.

§ 6

Business Continuity Policy

ISO 22301
  1. In accordance with clause 5.2.1 of PN-EN ISO 22301, Top Management establishes and announces the Business Continuity Management System Policy with the content set out in this paragraph.

  2. The Organisation operates in a narrow and difficult market; the systems it builds operate on highly sensitive data, on whose flow the proper functioning of key public institutions often depends. The Organisation therefore ensures continuity of service in order to maintain high service quality, appropriate to the requirements and to the security of client data.

  3. The Organisation strives to provide employees with a stable workplace that operates independently of disruptions originating in the external or internal environment, as a condition for maintaining a permanent team carrying out software design and production.

  4. Top Management, acting through the Management Representative for the IMS, will meet the applicable requirements of PN-EN ISO 22301 and align its activities with the relevant legal requirements.

§ 7

Artificial Intelligence Management System (AIMS) Policy

ISO/IEC 42001
  1. In accordance with clause 5.2 of ISO/IEC 42001:2023, Top Management establishes the Artificial Intelligence Management System Policy, which sets out the intended strategic direction and the principles of artificial intelligence management in the Organisation.

  2. The AIMS Policy applies to:

    • all AI systems designed, deployed, operated or maintained by the Organisation,
    • the CDF methodology (Cognitive Deployment Framework) as a product and service delivered to clients,
    • the products and development work of the SAIE ecosystem — TWIN:DESK, PROXY:AI, SAVANT-AI and GENESIS-AI — at all stages of their life cycle, subject to §1(5),
    • all employees, associates and subcontractors acting on behalf of the Organisation,
    • the entire AI services supply chain — from concept to system retirement.
  3. The Organisation adopts the following principles of artificial intelligence management:

    • responsible AI development and deployment — every AI system is built with accountability, transparency and security in mind at every stage of its life cycle,
    • transparency — every artefact created with the involvement of AI is labelled with the AI-assisted tag in the task management system, the code repository, documents and internal communication,
    • human oversight (human in command) — the level of oversight is adjusted to the risk category and the level of autonomy of the system (LOA) in accordance with the CDF methodology; no AI artefact reaches a client without human review,
    • privacy and data protection — confidential and restricted data is not transferred to external language models; personal data processed by AI systems is subject to a data protection impact assessment (DPIA),
    • fairness and non-discrimination — the Organisation identifies and mitigates bias in AI systems; HR decisions may not be made solely by AI,
    • security of AI systems — the Organisation applies a security by design approach at all phases of the AI system life cycle; the use of unauthorised AI tools (Shadow AI) is prohibited.
  4. The AIMS Policy refers in particular to ISO/IEC 42001:2023, ISO/IEC 27001:2023-08, ISO/IEC 23894:2023, Regulation (EU) 2024/1689 (EU AI Act), Regulation (EU) 2016/679 (GDPR), Regulation (EU) 2022/2554 (DORA), Directive (EU) 2022/2555 (NIS2) together with the Polish National Cybersecurity System Act, and the NIST AI RMF.

  5. The Management Board declares its full commitment to implementing, maintaining and continually improving the AIMS, including ensuring that the AIMS Policy is consistent with the Organisation’s strategic direction as a Sovereign AI Platform Company, integrating AIMS requirements with business processes and the CDF product strategy, providing the necessary resources, appointing a Management Representative for the IMS responsible for overseeing the AIMS and supporting the AI Council as the main decision-making body on AI matters.

  6. The principles set out in this paragraph are detailed in the AI Usage Policy (AI-GOV_POL_AIUsage) and the related documents.

§ 8

Communication, availability and version control

  1. The IMS Policy is communicated to employees and understood within the Organisation; it is the basis for setting IMS objectives and for assessing its continuing suitability.

  2. The IMS Policy is made available to employees in electronic collections on OneDrive and on the ISO information panel in the Organisation’s task management system, and to interested parties on the allclouds.pl website.

  3. There is a single approved text of the IMS Policy. The text published on the allclouds.pl website must be identical to the internal text and bear the version number and date of approval. The Management Representative for the IMS is responsible for the consistency of both texts.

  4. The published text is updated within 7 working days of the approval of a new version by the Management Board.

§ 9

Policy Review

  1. The IMS Policy is reviewed at least once a year as part of the management review, and in addition whenever there is a significant change in the Organisation’s context, the scope of certification, legal requirements or the results of risk analysis.

  2. The review covers an assessment of the suitability, adequacy and effectiveness of the Policy and its consistency with the IMS objectives and the IMS Risk Register.

  3. Amendments to the IMS Policy are approved by the Management Board by resolution.

§ 10

Final provisions

  1. This Policy supersedes the content of §4 of the IMS Manual v6.1 (§4a–§4e) and the text of the IMS Policy previously published on the allclouds.pl website. Until IMS Manual v6.2 is issued, §4 of the IMS Manual shall apply as worded in this Policy.

  2. The Policy enters into force on the date of its approval by the Management Board and remains valid until it is replaced by a new version.

  3. In matters not regulated by this Policy, the provisions of the IMS Manual and the detailed IMS policies and procedures apply.

Version: 7.0 · Date of approval: 7 August 2026

Top of page
NEXT

What else to explore

Quality policyCDF methodology
Next step
CDF methodology

AI implementation step by step: initial assessment, phases F0⁠–⁠F6, oversight and CogOps

Next: CDF methodology
SAIEThree layers, one AI workspace — the problem, the solution and who it is for
TWIN:DESKAI workspace: domain assistants, company knowledge, agents and 48 features
PROXY:AIAI control gateway: policies, Zero-Code Switch, WORM log and 54 features
inLABsallclouds.pl research projects and prototypes

https://www.allclouds.pl/en/polityka-jakosci/