30 years of AQU Catalunya: Quality and information security as drivers of trust and continuous improvement
Throughout 2026, the Agency has published monthly news articles reviewing its three decades of history from different perspectives. This article focuses on the Quality and Information Security Management System and all that stems from it.
In 2026, AQU Catalunya celebrates thirty years of service to the Catalan university system. Over these three decades, the Agency has consolidated its own model based on technical rigour, transparency and continuous improvement. Within this trajectory, the Quality and Information Security Management System (QISMS) has become a strategic tool for ensuring the credibility of the assessment, certification and accreditation activities carried out by the Agency.
The history of the system dates back to 2000, when AQU Catalunya obtained ISO 9002 certification. This milestone positioned the Agency among the pioneering organisations in the public sector in implementing certified management systems and represented the consolidation of a way of working based on process systematisation, documentation of activities and a commitment to improvement. Later, in 2006, the Agency adapted its system to the ISO 9001 standard, a certification it has maintained uninterruptedly ever since.
Quality culture
However, the implementation of quality went beyond obtaining a certificate. Over the years, the system has helped consolidate a culture of quality within the organisation. This culture is based on critical reflection on activities carried out, systematic analysis of results, staff participation and the ongoing search for opportunities for improvement.
One of the distinguishing features of AQU Catalunya’s model has been its commitment to process management. This approach has enabled the Agency to be understood as an integrated system of interrelated activities, facilitating coordination between areas, clarifying responsibilities and supporting data- and indicator-based decision-making. At the same time, it has fostered a cross-cutting organisational perspective focused on generating value for its stakeholders.
Assessing the assessments
Within this same context, meta-assessments have become a fundamental organisational learning tool. Evaluating the assessment processes themselves has made it possible to identify strengths, detect areas for improvement and systematically incorporate recommendations arising from accumulated experience. This ongoing review exercise is one of the most visible expressions of AQU Catalunya’s commitment to excellence.
A second major milestone came in 2015 with the incorporation of information security into the management system. The digital transformation of the Agency’s activities and the increasing handling of sensitive information made it necessary to strengthen data protection safeguards. For this reason, AQU Catalunya integrated the ISO 27001 standard into its system, creating a unique and fully integrated quality and information security model.
Continuous improvement
The integration of quality and information security represented a natural evolution of the system. The objective was to build on the quality practices already firmly established within the organisation and incorporate security requirements in a coherent and efficient manner. This integrated vision has made it possible to avoid duplication, strengthen control mechanisms and foster a shared culture based on trust and responsibility.
Today, AQU Catalunya’s QISMS guarantees the three fundamental principles of information security:
- Integrity, ensuring that information is accurate, complete and protected against improper alteration.
- Availability, ensuring that authorised individuals have access to information when they need it.
- Confidentiality, protecting access to information so that it can only be consulted by authorised individuals.
These principles complement the traditional values of quality and reinforce the trust that universities, public administrations, international agencies and society place in AQU Catalunya. Indeed, the Agency’s policy explicitly recognises that quality can no longer be discussed without incorporating information security as an essential element of good governance and service delivery.
After twenty-six years of continuous certification and more than a decade of integrating information security, the QISMS has helped professionalise management and drive hundreds of improvement actions. It has also strengthened transparency and ensured that the Agency continues to respond effectively to the evolving challenges of higher education and the digital society.
On this thirtieth anniversary, the history of the Quality and Information Security Management System is also the story of a sustained commitment to learning, innovation and trust. It is a story that continues to evolve to ensure that AQU Catalunya remains a benchmark organisation, capable of combining technical excellence, a culture of quality and information security in the service of the Catalan university system.