Overlap and maturity assessment
We map which standards the company holds or wants to implement, where documentation is duplicated between existing systems, and the real level of integration it's starting from, not just the declared one.
An integrated management system isn't three systems sharing a folder: it's a single structure that meets the common requirements of ISO 9001, ISO 14001 and ISO 45001 at once, and can be extended to other certifiable standards.
Integrating is not adding up. A company with ISO 9001, ISO 14001 and ISO 45001 certified separately usually carries three manuals, three internal audit calendars, three management reviews and three risk matrices that say similar things in different words. An integrated management system (IMS) brings together the part all three standards require alike (context, leadership, planning, support, performance evaluation and improvement) and keeps separate what is specific to each: customer satisfaction in 9001, environmental aspects in 14001, hazard identification in 45001.
This is possible because, for more than a decade, ISO management-system standards have not each been written their own way. They share the same skeleton: what the 12th edition (2021) of the ISO/IEC Directives, Part 1 established as the harmonized structure (formerly the high level structure, or Annex SL), a structure later editions have kept, with the same clauses 4 to 10, the same core terms and much of the same wording. ISO 9001:2015, ISO 14001:2015 and ISO 45001:2018 share that skeleton, and so do ISO/IEC 27001:2022 and ISO 50001:2018: which is why a well-built IMS is never limited to three standards: it can be extended.
In practice, integrating means a single manual, one context and interested-parties matrix, one risk-and-opportunity matrix that covers all three approaches, one internal audit programme and one management review where quality, environment and occupational safety are dealt with together. The certification body can audit all three standards in a single visit, with a real but bounded time saving set by a mandatory International Accreditation Forum document (IAF MD 11), not by how fast anyone wants to go.
Integrating dilutes no standard. 45001 still requires its hierarchy of controls under clause 8.1.2, 14001 its identification of significant environmental aspects, 9001 its customer focus. What changes is where each thing lives: policy, document management, change management and the non-conformity and improvement cycle are sustained once for all three, and each standard adds its own chapter on top of that common base.
Starting here isn't always the right move. If the company is only pursuing one standard, or is transitioning the one it already holds to the 2026 edition, the starting point is that standard on its own; our ISO 9001:2026 transition and ISO 14001:2026 transition pages cover that case. An IMS makes sense once the company already has, or is about to implement, more than one certifiable system.
At Summum Calidad we design the integrated system's architecture, train the team and coordinate the audit with the ENAC-accredited certification body of your choice. We've supported ISO implementations in Castilla y León and the Canary Islands since 2007, with close to 200 certifications accompanied; the certificate is issued by the certification body, we build the system. For the step-by-step detail, our blog covers what an integrated management system is and how 9001, 14001 and 45001 are integrated, including a 120-day plan.
Integration isn't a sales trick: it reflects that ISO 9001, ISO 14001 and ISO 45001 have shared the same regulatory skeleton for years, the harmonized structure (formerly the high level structure, or Annex SL) introduced by the 12th edition (2021) of the ISO/IEC Directives, Part 1 and kept in later editions, valid for every management-system standard. Clauses 4 to 10 are common in title and largely in wording; what changes is the technical content each standard hangs on them.
| Clause | What the common structure requires | What each standard adds |
|---|---|---|
| 4. Context of the organisation | Determine internal and external issues and relevant interested parties | 9001: customer expectations · 14001: environmental conditions · 45001: workers and their participation |
| 5. Leadership | Single policy, roles and responsibilities assigned from top management | 9001: customer focus · 14001: protection of the environment · 45001: preventing injury and ill health |
| 6. Planning | Risk-and-opportunity matrix, measurable objectives, planning of change (6.3) | 9001: conformity risks · 14001: environmental aspects · 45001: hazard identification (6.1.2) |
| 7. Support | Shared resources, competence and document control | Specific training: internal auditing, environmental management, prevention |
| 8. Operation | Common operational planning and control, external providers | 9001: design and production · 14001: environmental emergencies · 45001: hierarchy of controls (8.1.2) |
| 9. Performance evaluation | One internal audit programme and one management review for all three standards | Own indicators: customer satisfaction, environmental performance, incident and accident rate |
| 10. Improvement | A single non-conformity, corrective action and continual improvement procedure | Each finding is traced to the standard or standards it affects |
This split is what makes it possible to keep a single manual without losing the detail each standard requires: the common part lives once, each standard's technical part lives within that same structure.
Sharing a clause doesn't mean sharing it word for word. What an integrated system genuinely unifies is this:
What isn't integrated is the specific technical content: 45001's hazards, 14001's environmental aspects or 9001's design control each keep their own analysis, within the same common structure.
The time an integrated audit takes isn't freely negotiable: it's set by IAF MD 11:2023, a mandatory document of the International Accreditation Forum for certification bodies. The calculation starts by adding the time to audit each standard separately (T = A + B + C, clause 2.1.1) and is adjusted for three factors: the system's real level of integration, staff's ability to answer for more than one standard, and the availability of auditors competent in several at once.
The limit is explicit: where there is a reduction, it cannot exceed 20% of the starting point (clause 2.1.2). It's not an automatic discount for requesting an IMS; the certification body confirms the declared level of integration at the stage 1 audit. The document distinguishes a "combined system" (standards coexisting with separate documentation) from a genuine "integrated system" (which shares documentation and responsibilities): the more real the integration, the greater the room for adjustment.
The IMS doesn't have to stop at three standards. ISO/IEC 27001:2022 (information security) and ISO 50001:2018 (energy management) share the same harmonized structure, so adding them reuses the manual, the context matrix and the management review cycle already built. Each standard's own part is added on top: information asset risk analysis and Annex A controls for ISO 27001, or the energy review and performance indicators (EnPIs) for ISO 50001.
Extending doesn't mean rebuilding the system: it's audited as a scope extension within the existing certification cycle, under the same IAF MD 11 criteria as the initial integration. If your already-integrated system is also transitioning to the 2026 edition of a base standard, it's worth planning both changes together: the ISO 9001:2026 transition and the ISO 14001:2026 transition touch exactly the part an IMS shares.
We map which standards the company holds or wants to implement, where documentation is duplicated between existing systems, and the real level of integration it's starting from, not just the declared one.
We build the single integrated manual, the context and interested-parties matrix, the risk-and-opportunity matrix and the legal requirements matrix, keeping each standard's specific clauses separate.
We train the team on a single system, not three parallel ones. The quality, environment or safety manager works from the same dashboard and the same non-conformity and improvement procedures.
We coordinate a joint stage 1 and stage 2 audit for the integrated standards with the certification body, with the time adjustment allowed by the real, documented and justified level of integration.
The operational detail: what we deliver as part of the work and what we keep alive afterwards.
Integrated system manual
Single policy, scope and structure document that replaces the separate manuals of each standard.
Consolidated risk-and-opportunity matrix
One register covering quality risks, significant environmental aspects and occupational hazards, with their treatment and owner.
Single legal requirements matrix
Live list of obligations applicable to all three standards, with compliance status and the person responsible for keeping it current.
Integrated internal audit programme
Calendar and scope of internal audits covering all three standards, coordinated with our internal audit service when contracted separately.
Per-standard indicator dashboard
Single panel with quality, environmental and occupational safety indicators, reviewed in the same management review.
Roadmap for extending to additional standards
Route map for adding ISO/IEC 27001 or ISO 50001 to the already-integrated system, reusing the common part already built.
Normas y reglamentos verificados que aplican a este servicio: Harmonized structure: ISO/IEC Directives, Part 1 (introduced in the 12th edition, 2021, and kept in later editions), ISO 9001:2015, ISO 14001:2015….
The integrated system is sustained between audits with the maintenance service, audited through the internal audit programme and, when it generates many indicators at once, benefits from a shared dashboard.
A newly certified integrated system needs the same ongoing maintenance as a single one, but with more pieces to coordinate: a joint calendar, joint indicators and a joint management review.
View service → calidadThe integrated internal audit programme required by clause 9.2 of all three standards can be outsourced to auditors qualified in more than one standard at once.
View service → sistemasAn IMS with three blocks of indicators becomes easier to use once the dashboard stops being a spreadsheet and becomes a BI panel maintained by Summum Sistemas.
View service →Any standard built on the harmonized structure of the ISO/IEC Directives, Part 1: 9001, 14001, 45001, ISO/IEC 27001, ISO 50001, ISO 22301 or ISO 37001, among others. In SMEs it's usual to start with 9001, 14001 and 45001, then extend later depending on the activity.
It can reduce audit time, but with a limit: the reduction cannot exceed 20% of what auditing each standard separately would cost (IAF MD 11:2023, clause 2.1.2), and only if the system's level of integration justifies it. It's not an automatic discount for asking for an IMS; the certification body confirms that level at the stage 1 audit.
It's not essential, but it helps: if the company already has 9001 in place, much of the documented structure and the continual improvement cycle is already built. An IMS can also be designed from scratch, implementing several standards at once, which is usually more efficient than certifying them one after another.
It depends on the certification body: some issue a single certificate covering all three standards, others one per standard even when the audit is joint. What's common is the audit: one visit instead of three separate processes.
It transitions the same way, and it's worth using the transition's document review to also revisit the shared part of the IMS. Check our ISO 9001:2026 and ISO 14001:2026 transition pages before planning the change calendar.
Yes. Both standards share the same harmonized structure as ISO 9001, 14001 and 45001, so they're added by reusing the manual and improvement cycle already built. They bring their own specific part: information security risk analysis in 27001, the energy review in 50001.
It depends on how many standards and how alike the systems already are. If they're in good shape, it can be completed before the next surveillance audit; if they carry documentation debt, that needs resolving first.
It can be a single auditor with accredited competence across every standard in scope, or a team with an audit team leader competent in at least one and specialists covering the rest (IAF MD 11:2023). What doesn't change is that everything applicable in each standard gets audited: integration can only reduce the time, not the scope.