About
I’m Chris Martin, the person you’ll actually work with if you engage Alavanca — not a name on a letterhead pointing you toward whoever’s free.
My background is in information security. I hold a Master’s degree in Risk Management, along with Lead Auditor certifications in both ISO 27001 and ISO 9001. Before consulting, I spent time in military service, where risk isn’t theoretical — it’s operational, and the discipline around managing it sticks with you. That’s the mindset I bring to compliance work: identify the real risk, don’t pad the report, don’t sell you more than you need.
Alavanca was founded in 2022, originally as a broader governance, risk, and compliance consultancy. It’s since sharpened its focus onto four areas where I can genuinely add value: information security (ISO 27001), quality management (ISO 9001), AI governance (ISO 42001 and the EU AI Act), and GDPR compliance. I recently published The Business Manager’s Guide to GDPR, with a follow-up on EU AI Act compliance in progress.
I’m based in Spain and work with clients across the EU, in person where it helps and remotely where it doesn’t matter. Most of my clients are small and mid-sized businesses — from 1-person operations to teams of around 200 — because that’s where I think the biggest gap exists between “needs proper compliance” and “can’t justify a Big Four price tag.”
If you want a straight answer about whether you actually need a certification, or you’re not sure which framework applies to you, that’s exactly what the scoping call is for.
ISO 27001 Lead Auditor
Certified Lead Auditor in information security management systems.
ISO 42001 Internal Auditor
AI Management Systems
ISO 9001 Lead Auditor
Certified Lead Auditor in quality management systems.
MSc Risk Management
Master's degree in Risk Management.
Published Author
The Business Manager's Guide to GDPR. EU AI Act guide in progress.
Note: certification audits are always performed by an accredited certification body, not by Alavanca directly. Alavanca’s role is gap analysis, advisory, and implementation support through to that audit — across ISO 27001, ISO 9001, and ISO 42001.
