Bloc Microfinance Bank

Integrated Management System Policy Statement

Bloc MFB is committed to maintaining and enhancing information security, business continuity, and service quality by adopting an integrated management system that aligns with ISO 27001:2022, ISO 20000:2018, and ISO 22301:2019 standards. This framework ensures the seamless integration of information security, service management, and business continuity practices across our operations.

Our core values for the Integrated Management System include:

  • Ensuring uninterrupted availability of key business resources needed to support essential operations.
  • Reducing high-priority risks related to information security, quality, service management, and business continuity on Bloc MFB’s risk register.
  • Equipping employees with the necessary skills, training, and supervision to perform their roles effectively.
  • Providing a structured and efficient recovery process for critical business operations after a disruption.
  • Minimizing information security breaches and related risks.
  • Ensuring compliance with all contractual, regulatory, and legal requirements while reducing the risk of penalties.
  • Protecting and maintaining the availability of information in line with business needs.
  • Enhancing information security awareness and culture across the organization.
  • Providing specialized training in information security, service management, quality assurance, and business continuity for key personnel.
  • Raising awareness among all employees about the importance of service quality, information security, and business continuity.
  • Upholding the confidentiality, integrity, and availability of information across all business functions.
  • Ensuring restricted access to information, allowing only authorized personnel to minimize risks.
  • Continuously optimizing business processes to promote a zero-defect and no-waste approach.
  • Prioritizing customer satisfaction at every level of service delivery.
  • Making all employees aware of their individual responsibilities in service management.
  • Committing to the continual improvement of our service, quality, information security, and business continuity systems.

The Integrated Management System policy, objectives, and targets will be reviewed annually (or as needed) by top management. This policy is communicated to all employees and stakeholders and will be made available to the public and interested parties upon request.