Skip to content

Insights

Integrated management systems: certify ISO 9001, 14001 & 45001 in one audit

Quality Gurus

  • ISO 9001
  • Environment & Energy
  • Health & Safety
  • Certification

We regularly meet organisations running three parallel management systems: a quality manual for ISO 9001, an environmental manual for ISO 14001, and a safety manual for ISO 45001: three document sets, three internal audit programmes, three management reviews, and three separate certification audits each cycle. Nobody designed it that way; it accumulated, one certificate at a time. The cost is not just administrative. Parallel systems drift apart, contradict each other, and teach the workforce that "the system" is paperwork rather than how the business runs.

The fix has been available since the standards were harmonised: one integrated management system (IMS), certified against all three standards in combined audits.

The Harmonized Structure clauses 4 to 10 are shared across ISO 9001, 14001 and 45001, with discipline-specific modules attached to the processes where they apply.
The shared spine is what makes integration possible. Roughly a third of the requirements are common across the standards in near-identical language.

Why integration works now

Since 2015, the major ISO management system standards share an identical ten-clause architecture: the harmonised structure. Context of the organisation, leadership, planning, support, operation, performance evaluation, improvement: the same skeleton in ISO 9001, 14001, 45001, and equally in 27001, 50001 and 22301. Roughly a third of the requirements are common across the standards in near-identical language: document control, competence, internal audit, management review, corrective action, objectives, risk-based thinking.

An IMS implements those shared requirements once, and handles the genuinely discipline-specific content (environmental aspects, hazard identification, operational quality controls) as specialised modules within one system.

One shared requirement is newer than the rest and routinely missed. Amendment 1:2024, issued in February 2024, added climate-change wording to clauses 4.1 and 4.2 across more than thirty ISO management system standards at once — including ISO 9001, 14001, 45001, 27001, 22000 and 50001. Clause 4.1 now requires the organisation to determine whether climate change is a relevant issue; clause 4.2 notes that interested parties can have climate-related requirements. It took effect immediately on publication, with no transition period, and it applies to certificates you already hold. It does not oblige you to adopt targets — only to consider the question and be able to show that you did. In an integrated system this is one determination covering all your standards, which is a small but real illustration of the integration argument.

What it saves, concretely

  • Audit days. Certification bodies price combined audits below the sum of separate ones: typically 20–30% fewer auditor-days across a cycle, because the shared clauses are audited once. Multiply across initial certification, annual surveillance and recertification.
  • One document set. One policy framework, one competence process, one corrective-action system. Duplication is not just cost: parallel procedures for the same activity are a nonconformity generator, because one always lags reality. This is among the most common audit findings we see.
  • One management review that leadership attends. Three separate reviews get delegated; one integrated business review with quality, environment and safety on a single agenda holds executive attention, and auditors notice the difference.
  • Faster addition of the next standard. Once the IMS spine exists, adding ISO 50001 or ISO 27001 becomes a module, not a project. Organisations facing customer demands for new certifications year after year feel this benefit most.

What integration is not

Integration is not merging three binders into one thicker binder. A genuine IMS is process-based: it maps the organisation's actual processes and attaches quality, environmental and safety requirements to each process where they apply. The receiving process has quality checks, environmental controls for spills and waste, and manual-handling safety requirements: described once, where the work happens, not in three chapters of three manuals.

This is also the honest test of whether your existing systems are ready for integration: if each system is a documentation shell maintained for its audit, integrating them merely consolidates the shelf-ware. Systems built on how the operation actually works integrate naturally.

When not to integrate, or not yet

  • Different scopes. If quality certification covers the whole company but safety certification covers one site, align scopes first or accept a partial integration.
  • A major transition in flight. Mid-transition to a new standard revision is the wrong moment; complete the transition, then integrate. Worth checking your calendar against the expected ISO 9001:2026 revision before committing to a date.
  • Immature systems. Integrating two systems that both fail audits produces one bigger system that fails audits. Stabilise first.

The migration path

For organisations with existing separate certificates, integration is a re-architecture project, not a restart: map the common clauses, unify the shared processes (documents, audits, review, corrective action), rebuild the operational documentation process-by-process, and schedule the certification bodies' combined audit at the next natural point in the cycle, usually recertification. Certificates continue uninterrupted throughout; done well, the workforce experiences less system, not more.

Practical steps

Count what your parallel systems cost you: audit days per cycle, duplicated procedures, hours in separate reviews. Then have the integration assessed: a short gap analysis establishes whether your systems are ready and what the combined-audit saving would be with your certification body. QG designs and implements integrated systems across quality, environment, safety, energy and information security, and our internal audit service runs integrated audit programmes that keep them healthy.

Have a question we can answer?

Book a short discovery call to talk through your current systems, sector and target standards. We'll come back with clear, practical next steps.