ISO 9001 Certification

Building Trust Through Quality and Information Security Certifications

Here at the Clinical Informatics Research Unit protecting patient information and delivering high-quality services are fundamental to maintaining stakeholder trust. At CIRU these principles underpin everything we do. That is why we are proud to announce that we are certified with two internationally recognised standards: ISO 27001 for Information Security Management Systems (ISMS), achieved in May 2025 and ISO 9001 for Quality Management Systems (QMS), obtained just last month.

Together, these standards provide robust frameworks for managing information security, protecting sensitive data, and ensuring the consistent delivery of high-quality services and continual improvement across our operations. They provide assurance to NHS organisations, research partners, and collaborators that our processes meet recognised international standards for both information security and quality management.

Achieving and maintaining ISO 27001 and ISO 9001 certification demonstrates our Unit's commitment to safeguarding confidential information, meeting stakeholder expectations, and operating to internationally recognised best-practice standards. Our director Professor James Batchelor had the following words to say about CIRU’s recent success:

“We are excited to announce our continued high-level compliance with ISO 9001 and ISO 27001, demonstrating our additional commitment to providing our clients and stakeholders with assurances of our information security and quality systems management.”

ISO 27001 helps to ensure that confidential and sensitive information is protected throughout its lifecycle. For NHS partners, this offers confidence that data is handled responsibly, with appropriate controls in place to safeguard patient and organisational information while supporting vital research and innovation.

Complementing this, ISO 9001 focuses on quality, consistency, and continuous improvement. It encourages organisations to adopt efficient, well-managed processes that deliver reliable outcomes and respond to the evolving needs of stakeholders. For us this means regularly reviewing and enhancing our ways of working to ensure we continue to provide high-quality support for research, service improvement, and collaboration across the health and care system.

Both certifications strengthen our governance framework and reinforce our commitment to excellence. They help us meet the expectations of NHS organisations and beyond by embedding quality and information security into every aspect of our work, from project delivery and data management to stakeholder engagement and operational performance.

Most importantly, our certifications have been independently assessed and recognised by BSI, providing external validation that CIRU continues to meet the rigorous requirements of both standards. The BSI certifications demonstrate our ongoing commitment to supporting our stakeholders with confidence, integrity, and best practice, enabling research and innovation that ultimately benefits patients and the wider health and care community.