Integration 9001 · 14001 · 45001

Integrated management system

An integrated management system isn't three systems sharing a folder: it's a single structure that meets the common requirements of ISO 9001, ISO 14001 and ISO 45001 at once, and can be extended to other certifiable standards.

Base standardsISO 9001 · ISO 14001 · ISO 45001
Extendable toISO/IEC 27001 · ISO 50001
ScopeSMEs with more than one certifiable management system

Integrating is not adding up. A company with ISO 9001, ISO 14001 and ISO 45001 certified separately usually carries three manuals, three internal audit calendars, three management reviews and three risk matrices that say similar things in different words. An integrated management system (IMS) brings together the part all three standards require alike (context, leadership, planning, support, performance evaluation and improvement) and keeps separate what is specific to each: customer satisfaction in 9001, environmental aspects in 14001, hazard identification in 45001.

This is possible because, for more than a decade, ISO management-system standards have not each been written their own way. They share the same skeleton: what the 12th edition (2021) of the ISO/IEC Directives, Part 1 established as the harmonized structure (formerly the high level structure, or Annex SL), a structure later editions have kept, with the same clauses 4 to 10, the same core terms and much of the same wording. ISO 9001:2015, ISO 14001:2015 and ISO 45001:2018 share that skeleton, and so do ISO/IEC 27001:2022 and ISO 50001:2018: which is why a well-built IMS is never limited to three standards: it can be extended.

In practice, integrating means a single manual, one context and interested-parties matrix, one risk-and-opportunity matrix that covers all three approaches, one internal audit programme and one management review where quality, environment and occupational safety are dealt with together. The certification body can audit all three standards in a single visit, with a real but bounded time saving set by a mandatory International Accreditation Forum document (IAF MD 11), not by how fast anyone wants to go.

Integrating dilutes no standard. 45001 still requires its hierarchy of controls under clause 8.1.2, 14001 its identification of significant environmental aspects, 9001 its customer focus. What changes is where each thing lives: policy, document management, change management and the non-conformity and improvement cycle are sustained once for all three, and each standard adds its own chapter on top of that common base.

Starting here isn't always the right move. If the company is only pursuing one standard, or is transitioning the one it already holds to the 2026 edition, the starting point is that standard on its own; our ISO 9001:2026 transition and ISO 14001:2026 transition pages cover that case. An IMS makes sense once the company already has, or is about to implement, more than one certifiable system.

At Summum Calidad we design the integrated system's architecture, train the team and coordinate the audit with the ENAC-accredited certification body of your choice. We've supported ISO implementations in Castilla y León and the Canary Islands since 2007, with close to 200 certifications accompanied; the certificate is issued by the certification body, we build the system. For the step-by-step detail, our blog covers what an integrated management system is and how 9001, 14001 and 45001 are integrated, including a 120-day plan.

The harmonized structure, clause by clause

Integration isn't a sales trick: it reflects that ISO 9001, ISO 14001 and ISO 45001 have shared the same regulatory skeleton for years, the harmonized structure (formerly the high level structure, or Annex SL) introduced by the 12th edition (2021) of the ISO/IEC Directives, Part 1 and kept in later editions, valid for every management-system standard. Clauses 4 to 10 are common in title and largely in wording; what changes is the technical content each standard hangs on them.

ClauseWhat the common structure requiresWhat each standard adds
4. Context of the organisationDetermine internal and external issues and relevant interested parties9001: customer expectations · 14001: environmental conditions · 45001: workers and their participation
5. LeadershipSingle policy, roles and responsibilities assigned from top management9001: customer focus · 14001: protection of the environment · 45001: preventing injury and ill health
6. PlanningRisk-and-opportunity matrix, measurable objectives, planning of change (6.3)9001: conformity risks · 14001: environmental aspects · 45001: hazard identification (6.1.2)
7. SupportShared resources, competence and document controlSpecific training: internal auditing, environmental management, prevention
8. OperationCommon operational planning and control, external providers9001: design and production · 14001: environmental emergencies · 45001: hierarchy of controls (8.1.2)
9. Performance evaluationOne internal audit programme and one management review for all three standardsOwn indicators: customer satisfaction, environmental performance, incident and accident rate
10. ImprovementA single non-conformity, corrective action and continual improvement procedureEach finding is traced to the standard or standards it affects

This split is what makes it possible to keep a single manual without losing the detail each standard requires: the common part lives once, each standard's technical part lives within that same structure.

What the three standards actually share

Sharing a clause doesn't mean sharing it word for word. What an integrated system genuinely unifies is this:

  • Integrated policy: a single document covering quality, environmental and occupational safety commitments, instead of three separate statements.
  • Interested parties and context matrix: customers, suppliers, authorities, workers and community, with their relevant expectations per standard.
  • Risk-and-opportunity matrix: a single register that distinguishes each risk's origin but is reviewed in the same cycle.
  • Management of change (6.3): a relevant change (production line, supplier, facility) is assessed once from all three angles.
  • Non-conformity and corrective action: a common procedure, with each finding traced to the standard it affects.
  • Internal audit and management review: one programme and one meeting, not three.

What isn't integrated is the specific technical content: 45001's hazards, 14001's environmental aspects or 9001's design control each keep their own analysis, within the same common structure.

The integrated audit: what IAF MD 11 allows

The time an integrated audit takes isn't freely negotiable: it's set by IAF MD 11:2023, a mandatory document of the International Accreditation Forum for certification bodies. The calculation starts by adding the time to audit each standard separately (T = A + B + C, clause 2.1.1) and is adjusted for three factors: the system's real level of integration, staff's ability to answer for more than one standard, and the availability of auditors competent in several at once.

The limit is explicit: where there is a reduction, it cannot exceed 20% of the starting point (clause 2.1.2). It's not an automatic discount for requesting an IMS; the certification body confirms the declared level of integration at the stage 1 audit. The document distinguishes a "combined system" (standards coexisting with separate documentation) from a genuine "integrated system" (which shares documentation and responsibilities): the more real the integration, the greater the room for adjustment.

From 9001, 14001 and 45001 to ISO/IEC 27001 or ISO 50001: how to extend it

The IMS doesn't have to stop at three standards. ISO/IEC 27001:2022 (information security) and ISO 50001:2018 (energy management) share the same harmonized structure, so adding them reuses the manual, the context matrix and the management review cycle already built. Each standard's own part is added on top: information asset risk analysis and Annex A controls for ISO 27001, or the energy review and performance indicators (EnPIs) for ISO 50001.

Extending doesn't mean rebuilding the system: it's audited as a scope extension within the existing certification cycle, under the same IAF MD 11 criteria as the initial integration. If your already-integrated system is also transitioning to the 2026 edition of a base standard, it's worth planning both changes together: the ISO 9001:2026 transition and the ISO 14001:2026 transition touch exactly the part an IMS shares.

The Integrated management system process.

The process · four stages
01

Overlap and maturity assessment

We map which standards the company holds or wants to implement, where documentation is duplicated between existing systems, and the real level of integration it's starting from, not just the declared one.

02

Designing the common architecture

We build the single integrated manual, the context and interested-parties matrix, the risk-and-opportunity matrix and the legal requirements matrix, keeping each standard's specific clauses separate.

03

Cross-cutting implementation and training

We train the team on a single system, not three parallel ones. The quality, environment or safety manager works from the same dashboard and the same non-conformity and improvement procedures.

04

Integrated audit and certification

We coordinate a joint stage 1 and stage 2 audit for the integrated standards with the certification body, with the time adjustment allowed by the real, documented and justified level of integration.

What is included

What Integrated management system includes.

The operational detail: what we deliver as part of the work and what we keep alive afterwards.

  • Integrated system manual

    Single policy, scope and structure document that replaces the separate manuals of each standard.

  • Consolidated risk-and-opportunity matrix

    One register covering quality risks, significant environmental aspects and occupational hazards, with their treatment and owner.

  • Single legal requirements matrix

    Live list of obligations applicable to all three standards, with compliance status and the person responsible for keeping it current.

  • Integrated internal audit programme

    Calendar and scope of internal audits covering all three standards, coordinated with our internal audit service when contracted separately.

  • Per-standard indicator dashboard

    Single panel with quality, environmental and occupational safety indicators, reviewed in the same management review.

  • Roadmap for extending to additional standards

    Route map for adding ISO/IEC 27001 or ISO 50001 to the already-integrated system, reusing the common part already built.

Marco normativo

The regulatory framework

Normas y reglamentos verificados que aplican a este servicio: Harmonized structure: ISO/IEC Directives, Part 1 (introduced in the 12th edition, 2021, and kept in later editions), ISO 9001:2015, ISO 14001:2015….

ISO Harmonized structure: ISO/IEC Directives,… Sets the common clauses 4 to 10 and the core terms of management-system standards, including 9001, 14001, 45001, 27001 and 50001. Formerly known as 'Annex SL'.
ISO ISO 9001:2015 Customer-focused quality management system; contributes customer focus and control of design and production processes to the IMS.
ISO ISO 14001:2015 Environmental management system; contributes the identification of significant environmental aspects and impacts and emergency preparedness.
ISO ISO 45001:2018 Occupational health and safety management system; contributes hazard identification and the hierarchy of controls under clause 8.1.2.
IAF IAF MD 11:2023 Calculation of integrated audit time: starting point T = A + B + C and a maximum 20% reduction where the level of integration justifies it (clauses 2.1.1 and 2.1.2).
ISO ISO/IEC 17021-1:2015 Requirements for auditing and certifying management systems, including confirming the level of integration at the stage 1 audit.

Frequently asked questions about Integrated management system.

Which standards can be integrated into a management system?

Any standard built on the harmonized structure of the ISO/IEC Directives, Part 1: 9001, 14001, 45001, ISO/IEC 27001, ISO 50001, ISO 22301 or ISO 37001, among others. In SMEs it's usual to start with 9001, 14001 and 45001, then extend later depending on the activity.

Does integrating really cut the time or cost of the audit?

It can reduce audit time, but with a limit: the reduction cannot exceed 20% of what auditing each standard separately would cost (IAF MD 11:2023, clause 2.1.2), and only if the system's level of integration justifies it. It's not an automatic discount for asking for an IMS; the certification body confirms that level at the stage 1 audit.

Do we need ISO 9001 already in place to start an integrated system?

It's not essential, but it helps: if the company already has 9001 in place, much of the documented structure and the continual improvement cycle is already built. An IMS can also be designed from scratch, implementing several standards at once, which is usually more efficient than certifying them one after another.

Does an integrated system mean one certificate or several?

It depends on the certification body: some issue a single certificate covering all three standards, others one per standard even when the audit is joint. What's common is the audit: one visit instead of three separate processes.

What happens to the 2026 transition of ISO 9001 and 14001 if we have an integrated system?

It transitions the same way, and it's worth using the transition's document review to also revisit the shared part of the IMS. Check our ISO 9001:2026 and ISO 14001:2026 transition pages before planning the change calendar.

Can ISO/IEC 27001 or ISO 50001 be integrated into the same system?

Yes. Both standards share the same harmonized structure as ISO 9001, 14001 and 45001, so they're added by reusing the manual and improvement cycle already built. They bring their own specific part: information security risk analysis in 27001, the energy review in 50001.

How long does it take to integrate systems already certified separately?

It depends on how many standards and how alike the systems already are. If they're in good shape, it can be completed before the next surveillance audit; if they carry documentation debt, that needs resolving first.

Is the certification audit carried out by a single auditor?

It can be a single auditor with accredited competence across every standard in scope, or a team with an audit team leader competent in at least one and specialists covering the rest (IAF MD 11:2023). What doesn't change is that everything applicable in each standard gets audited: integration can only reduce the time, not the scope.