Integrated Management Systems: Running ISO 9001, 14001 and 45001 as One

How an integrated management system combines ISO 9001, 14001 and 45001 into one framework: what gets shared, the benefits, and when not to integrate.

Integrated Management Systems: Running ISO 9001, 14001 and 45001 as One

Businesses that certify to more than one ISO standard usually get there one standard at a time. A tender asks for ISO 9001, so a quality system gets built. Two years later a principal contractor wants ISO 45001, so a safety system gets built beside it. Then an environmental condition triggers ISO 14001, and a third system appears.

The result is three document sets, three internal audit programmes, three management reviews, three sets of objectives and three separate audit visits — for one business that only has one way of actually operating. An integrated management system (IMS) collapses that back into one.

What an integrated management system is

An IMS is a single management system that satisfies the requirements of multiple standards at once. One document framework, one set of processes, one improvement cycle — with standard-specific content where the standards genuinely differ.

It is not a new standard. There is no "ISO IMS" certificate. You still certify to ISO 9001, ISO 14001 and ISO 45001 individually; what changes is that they run on shared infrastructure and are audited together.

Why it is possible: the harmonised structure

ISO deliberately aligned its management system standards onto a common ten-clause structure. All of them share:

  1. Scope
  2. Normative references
  3. Terms and definitions
  4. Context of the organisation
  5. Leadership
  6. Planning
  7. Support
  8. Operation
  9. Performance evaluation
  10. Improvement

Clauses 4, 5, 7, 9 and 10 are close to identical in intent across the standards. That means one context analysis, one leadership and policy framework, one competence and communication process, one internal audit programme and one management review can serve all three — provided each covers the subject matter of every standard in scope, and your auditors are trained across all of them through an integrated management systems auditor training course.

The real divergence sits in clauses 6 and 8: planning and operation. Quality planning deals with process risk and customer requirements; environmental planning deals with aspects, impacts and legal obligations; safety planning deals with hazards, risk controls and worker participation.

What gets shared and what stays separate

ElementShared across standardsStandard-specific
PolicyOne combined QHSE policy is commonMust address each standard's required commitments
Context and interested partiesOne analysisDifferent expectations per topic
Document and record controlOne system—
Competence and trainingOne framework and matrixTopic-specific competencies
Communication and consultationOne processISO 45001 adds mandatory worker participation
Risk assessmentOne methodologyAspects/impacts (14001), hazards (45001), process risk (9001)
Operational controlOne process architectureDifferent controls per topic
Internal auditOne programme, one scheduleCriteria include all standards
Management reviewOne meetingAgenda must cover every standard's required inputs
Nonconformity and corrective actionOne process and registerISO 45001 adds incident investigation
ObjectivesOne planning cycleObjectives for each topic

The benefits, concretely

When an IMS is not the right answer

Integration is not automatically correct.

How to integrate an existing set of systems

  1. Map what you have. List every procedure, register and form across all systems, and tag each against the clauses it serves. Duplication becomes obvious immediately.
  2. Build one clause framework. Restructure documentation to the ten-clause structure so every standard's requirements have a home.
  3. Merge the common processes first. Document control, competence, internal audit, management review, corrective action. This is where most of the saving lives.
  4. Keep risk assessments distinct but consistent. Use one methodology and risk matrix, with separate registers for aspects, hazards and process risks.
  5. Write one policy that carries each standard's required commitments.
  6. Run one integrated internal audit covering all criteria before your next external audit.
  7. Hold one management review with an agenda that covers every required input for every standard.
  8. Talk to your certification body about combining the audit programme and aligning certificate cycles.

Skills and evidence

Integrated auditing is a real skill — auditing one process against three criteria sets at once requires more preparation than a single-standard audit. Integrated management system auditor training exists precisely for this, and is worth considering for whoever runs your programme; our comparison of internal auditor and lead auditor training covers how those courses differ.

On the certification side, look for a body accredited by JAS-ANZ for every standard in your scope and experienced in combined audits — a certifier that treats them as three audits scheduled back-to-back gives you none of the efficiency. Southpac Certifications publishes an overview of integrated management system certification that sets out how combined scopes are typically handled, which is a useful reference when you are comparing proposals.

The bottom line

If your business is certified — or heading toward certification — to more than one ISO standard, integration is almost always the cheaper and more coherent option. The standards were deliberately designed to make it possible. The main risk is building an integrated system for standards you do not actually need.

If you are still deciding which standards apply, start with our comparison of ISO 9001, ISO 14001 and ISO 45001, and if the audit process itself is unfamiliar, read stage 1 vs stage 2 audits explained.