Home / Governance and Compliance / Integrated Management System
Integrated Management System
Current status, stated precisely
The Integrated Management System of AXIA Resources is implemented and in operation, with controlled documentation, measured indicators and an internal audit carried out. The certification process is in progress and, until certificates are issued by an accredited body, AXIA does not declare itself certified to any of the standards listed on this page.
What our Integrated Management System is
The IMS is the structured set of policies, procedures, forms and records that organizes how AXIA Resources plans, executes, checks and improves its activities. It is integrated because the six standards operate on the same structure, the same scope and the same processes — avoiding parallel controls and duplicated information.
Standards within the certification scope
| Standard | Subject | What it ensures in our operations |
|---|---|---|
| ABNT NBR ISO 9001:2015 | Quality | Standardizes the delivery of services, defines acceptance criteria, measures customer satisfaction and turns complaints into improvement. |
| ABNT NBR ISO 14001:2015 | Environment | Identifies environmental aspects and impacts, controls waste and resources, keeps licensing up to date and prepares the emergency response. |
| ABNT NBR ISO 37301:2021 | Compliance | Maps legal, regulatory and contractual obligations, assesses compliance risks and maintains a reporting channel with whistleblower protection. |
| ABNT NBR ISO 37001 | Anti-bribery | Assesses bribery risk by transaction and partner, applies due diligence, controls gifts and hospitality and records interactions with public officials. |
| ABNT NBR ISO/IEC 27001:2022 | Information Security | Protects service information and the technical database through access management, tested backup, monitoring and incident response. |
| ABNT NBR ISO/IEC 27701:2019 | Privacy | Extends information security to the protection of personal data, with a record of processing operations, legal bases and fulfillment of data subjects’ rights. |
In addition, ABNT NBR ISO 45001:2018 (Occupational Health and Safety) is applied as an institutional standard and legal obligation, without seeking certification at this stage.
How the system is maintained
Controlled documentation
Every document is versioned in the official repository, with its change history, preparation by the Multidisciplinary Committee and approval by the Board of Directors recorded.
Measured performance
Objectives with a baseline and target, indicators measured monthly by the 5th business day, and trend analysis over the series.
Internal audit
Annual risk-proportionate program, with an impartial auditor, declared sampling and findings with traceable evidence.
Management review
The Board of Directors periodically reviews performance, risks, incidents, audits and improvements, and records its decisions in minutes.
Corrective action
A deviation triggers immediate correction, root cause analysis, an action with an assigned owner and deadline, and verification of effectiveness before closure.
Competence
Competence matrix by role, annual training plan and verification of understanding — not merely an attendance list.
Governance of control functions
The functions required by the standards and by law are formally designated, with direct access to the Board of Directors and with an independent external alternate for cases in which impartiality so requires:
| Function | Holder | Basis |
|---|---|---|
| Personal Data Protection Officer (DPO) | Ms. Nayaara Rodrigues de Brito | LGPD (Brazil’s General Data Protection Law), art. 41 · ISO/IEC 27701:2019, 6.3.1 |
| Compliance Officer | Ms. Nayaara Rodrigues de Brito | ISO 37301:2021, 5.3.2 |
| Person responsible for the anti-bribery function | Ms. Nayaara Rodrigues de Brito | ISO 37001, 5.3.2 |
| Alternate for the three functions | Mr. Sanclé Albuquerque Independent External Specialist | Mandatorily takes over when the case involves the Board of Directors or the holder |
Documentation repository
The Management System documentation is kept in a controlled repository, with automatic versioning, change history and access control. The training platform and competence records are kept in a dedicated distance-learning environment.
Institutional addresses of the Management System
- wiki.axiaresources.com.br — IMS documentation repository: manuals, policies, procedures, forms and records
- ead.axiaresources.com.br — platform for training, onboarding and recording acceptance of the policies
Access is restricted to employees, authorized third parties and designated auditors. Access requests for audit purposes may be sent to contato@axiaresources.com.br.