Integrated Management Systems: Running ISO 9001, 14001 and 45001 as One
How an integrated management system combines ISO 9001, 14001 and 45001 into one framework: what gets shared, the benefits, and when not to integrate.

Businesses that certify to more than one ISO standard usually get there one standard at a time. A tender asks for ISO 9001, so a quality system gets built. Two years later a principal contractor wants ISO 45001, so a safety system gets built beside it. Then an environmental condition triggers ISO 14001, and a third system appears.
The result is three document sets, three internal audit programmes, three management reviews, three sets of objectives and three separate audit visits — for one business that only has one way of actually operating. An integrated management system (IMS) collapses that back into one.
What an integrated management system is
An IMS is a single management system that satisfies the requirements of multiple standards at once. One document framework, one set of processes, one improvement cycle — with standard-specific content where the standards genuinely differ.
It is not a new standard. There is no "ISO IMS" certificate. You still certify to ISO 9001, ISO 14001 and ISO 45001 individually; what changes is that they run on shared infrastructure and are audited together.
Why it is possible: the harmonised structure
ISO deliberately aligned its management system standards onto a common ten-clause structure. All of them share:
- Scope
- Normative references
- Terms and definitions
- Context of the organisation
- Leadership
- Planning
- Support
- Operation
- Performance evaluation
- Improvement
Clauses 4, 5, 7, 9 and 10 are close to identical in intent across the standards. That means one context analysis, one leadership and policy framework, one competence and communication process, one internal audit programme and one management review can serve all three — provided each covers the subject matter of every standard in scope, and your auditors are trained across all of them through an integrated management systems auditor training course.
The real divergence sits in clauses 6 and 8: planning and operation. Quality planning deals with process risk and customer requirements; environmental planning deals with aspects, impacts and legal obligations; safety planning deals with hazards, risk controls and worker participation.
What gets shared and what stays separate
| Element | Shared across standards | Standard-specific |
|---|---|---|
| Policy | One combined QHSE policy is common | Must address each standard's required commitments |
| Context and interested parties | One analysis | Different expectations per topic |
| Document and record control | One system | — |
| Competence and training | One framework and matrix | Topic-specific competencies |
| Communication and consultation | One process | ISO 45001 adds mandatory worker participation |
| Risk assessment | One methodology | Aspects/impacts (14001), hazards (45001), process risk (9001) |
| Operational control | One process architecture | Different controls per topic |
| Internal audit | One programme, one schedule | Criteria include all standards |
| Management review | One meeting | Agenda must cover every standard's required inputs |
| Nonconformity and corrective action | One process and register | ISO 45001 adds incident investigation |
| Objectives | One planning cycle | Objectives for each topic |
The benefits, concretely
- Fewer audit days. A combined certification audit is shorter than three separate ones because shared clauses are assessed once. This is the most visible cost saving.
- One internal audit programme. Auditing a process once against three sets of criteria is far more efficient than three visits to the same team.
- One management review meeting instead of three, with a single, complete picture of business performance.
- No contradictory procedures. Separate systems drift; you end up with two versions of the same site induction saying different things.
- Better decisions. Quality, environmental and safety risks are usually the same operational risks viewed from different angles. Assessing them together surfaces trade-offs that separate systems hide.
- Less resistance from staff. People experience one way of working, not three overlapping bureaucracies.
When an IMS is not the right answer
Integration is not automatically correct.
- If only one standard is genuinely required, do not build for three. Scope creep is the fastest way to create an unused system.
- If the businesses are genuinely different, a group with a manufacturing arm and a professional services arm may be better served by separate systems with different scopes.
- If one standard is far more mature than the others, integrating too early can drag the mature system down to the lowest common denominator. Build the weaker system up first, then merge.
- If certification timing differs sharply, aligning cycles takes planning. Certification bodies can usually align certificate expiry dates, but it is worth raising early.
How to integrate an existing set of systems
- Map what you have. List every procedure, register and form across all systems, and tag each against the clauses it serves. Duplication becomes obvious immediately.
- Build one clause framework. Restructure documentation to the ten-clause structure so every standard's requirements have a home.
- Merge the common processes first. Document control, competence, internal audit, management review, corrective action. This is where most of the saving lives.
- Keep risk assessments distinct but consistent. Use one methodology and risk matrix, with separate registers for aspects, hazards and process risks.
- Write one policy that carries each standard's required commitments.
- Run one integrated internal audit covering all criteria before your next external audit.
- Hold one management review with an agenda that covers every required input for every standard.
- Talk to your certification body about combining the audit programme and aligning certificate cycles.
Skills and evidence
Integrated auditing is a real skill — auditing one process against three criteria sets at once requires more preparation than a single-standard audit. Integrated management system auditor training exists precisely for this, and is worth considering for whoever runs your programme; our comparison of internal auditor and lead auditor training covers how those courses differ.
On the certification side, look for a body accredited by JAS-ANZ for every standard in your scope and experienced in combined audits — a certifier that treats them as three audits scheduled back-to-back gives you none of the efficiency. Southpac Certifications publishes an overview of integrated management system certification that sets out how combined scopes are typically handled, which is a useful reference when you are comparing proposals.
The bottom line
If your business is certified — or heading toward certification — to more than one ISO standard, integration is almost always the cheaper and more coherent option. The standards were deliberately designed to make it possible. The main risk is building an integrated system for standards you do not actually need.
If you are still deciding which standards apply, start with our comparison of ISO 9001, ISO 14001 and ISO 45001, and if the audit process itself is unfamiliar, read stage 1 vs stage 2 audits explained.