Venturalítica
Let's talk
Courtesy translation. The approved and signed text is the Spanish version. Read the signed version

Quality policy

v2 · approved on 28 July 2026 (2026-07-28)

Contents

Controlled document

What Venturalítica does, and why that decides its quality policy

Venturalítica does assurance and regulatory governance of artificial intelligence systems: a product that evaluates AI systems and projects their conformity, and the professional services that accompany it (scope, clause 4.3).

That makes quality not a support function here. It is what is sold. A client buys from Venturalítica the confidence of being able to demonstrate before a regulator, an auditor or a client of their own that their AI system complies. An organisation that sells that and cannot demonstrate it of itself does not have a compliance problem: it has a product problem.

Hence the strategic direction this policy sustains —client zero: Venturalítica governs its own quality with the same method it sells, and this versioned management system is at once the company's real system and the demonstration that the method works. And hence the value that orders decisions: proof, not promises — what is claimed is backed by evidence verifiable by a third party, or it is not claimed.

Commitments

Venturalítica commits to:

  1. Meeting applicable requirements — those of its clients, the legal and regulatory ones, and those it imposes on itself. Where a regulatory requirement affects the client and not Venturalítica, it is attended to just the same: that is the product's ground.
  2. Continually improving the suitability, adequacy and effectiveness of the management system, with the cycle of findings and corrective actions as its engine and the management review as its channel.
  3. Not over-claiming. No public statement about the product, about compliance or about the state of the management system goes beyond what the evidence sustains. "Aligned with" is not "certified".
  4. Sustaining the conformity of what is delivered: nothing is released without its verification in green, and every AI-assisted output with relevant effect passes through human decision before taking effect.
  5. Listening to the client: satisfaction is measured, not assumed, and complaints enter through the same channel as any nonconformity.

Framework for the quality objectives

This policy is the framework from which the quality objectives derive: each objective must be traceable to one of the five commitments above, be measurable, have an owner, a baseline and a cadence, and be reviewed at the management review.

The objectives in force —with their metric, target, owner, baseline and linked risks— are not transcribed here: they are single-source data in objectives.yaml and are consulted in the objectives register. Copying them into this policy would only create a second version that would age worse than the first.

Principles that develop it

  1. Customer focus. Understanding and satisfying the client's needs is the priority.
  2. Process approach. Results are achieved by managing activities as interrelated processes, not as loose tasks.
  3. Evidence-based quality. Decisions rest on verifiable data, and versioned change is the act of compliance.
  4. Continual improvement. Quality is a permanent objective, not a state reached.
  5. Compliance. Applicable legal, regulatory and contractual requirements are respected.

Communication and availability

The policy is communicated to every person working under the organisation's control upon their onboarding, with record kept in their person file, and is made available to the relevant interested parties, through the channels the system keeps in force at any given time and with the record that §7.5.3 requires.

Review

At least annually and at every management review; also upon significant changes of context, of scope or of strategic direction.

Status register

not part of the signed document

ISO 9001:2015

Certification in progress.

Checked on 2026-09-07

ISO/IEC 27001

Planned.

Checked on 2026-09-07

ISO/IEC 42001

Planned.

Checked on 2026-09-07

This register is reviewed, and each row says when it was checked. If something does not add up, tell us.

Provenance of this copy: management system repository, commit 1346604, sha256 7f01054f7995, vendored on 2026-09-07.