Integrated Management System: Running ISO Standards as One
An integrated management system is what you build when you hold more than one ISO certificate and refuse to pay for the same work twice. It is one system, one document library, and one audit rhythm, carrying several certificates at once.
This post covers what actually integrates, what has to stay separate, and how to sequence the build. It is the practical companion to our per-standard guides and to the combinations tool.
What an Integrated Management System Is
An integrated management system (IMS) merges the requirements of two or more management system standards into a single operating system for the business.
The usual candidates:
- ISO 9001 for quality management
- ISO 14001 for environmental management
- ISO 45001 for occupational health and safety
- ISO 27001 for information security
- ISO 22301 for business continuity
Integration is possible because these standards share the Annex SL harmonized structure. Every one of them has the same 10 clauses in the same order: scope, normative references, terms, context, leadership, planning, support, operation, performance evaluation, improvement.
That shared skeleton is not a coincidence. ISO designed it so organizations could stop maintaining parallel systems that say the same thing in different words.
One point worth stating plainly, because it causes confusion in procurement conversations: there is no IMS certificate. You are certified to ISO 9001, and to ISO 14001, and to ISO 45001. The IMS is the internal architecture that produces all three from one set of processes. Anything marketed as integrated management system certification is really a combined audit against several standards.
What Actually Integrates
The shared layer is larger than most teams expect. These clauses can be written once and applied to every standard in scope.
Clause 4, Context. One analysis of internal and external issues, one interested parties register, one scope statement listing all standards in scope. Your customers, regulators, employees, and neighbours do not change identity depending on which standard you are looking at.
Clause 5, Leadership. One management commitment, one set of assigned roles and responsibilities, one policy or a combined policy document. ISO 45001 adds worker consultation and participation on top, which is genuinely extra work.
Clause 7, Support. This is the single biggest integration win. Resources, competence, awareness, communication, and documented information are close to word-for-word identical across the standards. One training matrix, one competence record set, one document control procedure, one communication plan.
Clause 9, Performance Evaluation. One internal audit programme, one audit calendar, one management review meeting with an agenda section per standard. Auditors expect to see management review minutes covering all scopes together, and a single meeting is easier to evidence than three.
Clause 10, Improvement. One nonconformity and corrective action process, one register, one root cause method. A defect, a spill, an injury, and a security incident all route through the same workflow with different categorization.
What Has to Stay Separate
Integration fails when teams try to merge the risk work. Each standard has a different risk object, and each requires its own register built by its own method.
| Standard | Standard-specific artifact | Cannot be merged because |
|---|---|---|
| ISO 9001 | Process map, customer requirements, product conformity records | Quality risk is about defects and customer satisfaction |
| ISO 14001 | Environmental aspects and impacts register, lifecycle perspective | Impact significance is assessed against the environment |
| ISO 45001 | Hazard identification, OH&S risk assessment, worker consultation records | Risk is injury and ill health, with a required hierarchy of controls |
| ISO 27001 | Statement of Applicability, Annex A controls, risk treatment plan | Annex A is a fixed control set with no equivalent elsewhere |
| ISO 22301 | Business impact analysis, recovery objectives, continuity plans | Risk is measured in downtime, not defect or injury rate |
Objectives stay separate too. Defect rate, emissions intensity, recordable injury rate, and mean time to recover are different metrics measured by different people. Set them under one management review, but do not try to force them into one scorecard.
The other thing that stays separate is legal obligation tracking, at least in content. Most organizations run one legal register with a section per standard, which keeps maintenance in one place while keeping the environmental permits distinguishable from the safety regulations.
The ISO 27001 Exception
ISO 27001 integrates at the clause level exactly like the others, and then stops.
Clauses 4 through 10 merge normally. Context, leadership, planning, support, operation, performance evaluation, and improvement all fold into the shared layer with no special handling.
Annex A does not merge. ISO 27001 carries 93 controls across four themes, and requires a Statement of Applicability that justifies the inclusion or exclusion of every one of them. No other management system standard has this. Treat it as an information security layer sitting on top of the shared system rather than something to be blended in.
The practical consequence: an organization adding ISO 27001 to an existing ISO 9001 and ISO 14001 system gets the clause work close to free, and still faces the full Annex A gap assessment. For how the two sit together, see ISO 9001 vs ISO 27001. For the continuity overlap, see ISO 22301 vs ISO 27001.
An Integrated Management System Example
Here is what the document set looks like in practice for a QHSE build covering ISO 9001, ISO 14001, and ISO 45001.
Shared documents (written once):
- IMS manual with scope covering all three standards
- Context and interested parties analysis
- Combined QHSE policy signed by top management
- Roles, responsibilities, and authorities matrix
- Competence and training procedure with one training matrix
- Document and record control procedure
- Internal audit procedure and one annual audit programme
- Management review procedure and one meeting record
- Nonconformity and corrective action procedure with one register
- Legal and other requirements register
Standard-specific documents:
- Process map and customer requirement records (9001)
- Environmental aspects and impacts register, lifecycle considerations (14001)
- Hazard identification and risk assessment, worker consultation records, emergency preparedness (45001)
That is roughly ten shared documents against six standard-specific ones. Run separately, the same coverage takes closer to thirty documents, most of them saying the same thing three times.
Sequencing the Build
Building all standards simultaneously from zero is possible but rarely the fastest route to a certificate.
If you hold nothing yet. Certify the standard your customers are actually asking for, and build the shared clause layer properly while you do it. Design clause 4, 5, 7, 9, and 10 documents to be standard-agnostic from day one, so that adding the second certificate is an increment rather than a rewrite.
If you already hold one certificate. Adding the second is typically three to five months of work rather than the six to twelve a first system takes. The gap is the standard-specific risk register, the objectives, and the operational controls in clause 8.
If you hold two and want a third. At this point the marginal cost is almost entirely clause 6 and clause 8 work, plus whatever unique artifact the new standard demands, which is Annex A and the SoA for ISO 27001.
Book a combined certification audit rather than separate ones. One audit team, one visit, shared time on the clauses that are identical. It costs less than the sum of separate audits, though not as little as one, because the auditor still needs dedicated hours on each standard's risk work.
For the per-standard depth behind an IMS build, see the ISO 9001 guide, the ISO 14001 guide, the ISO 45001 guide, and the ISO 22301 guide. For the environment and safety pair specifically, see ISO 14001 vs ISO 45001. To see where controls overlap across frameworks, use the overlap tool. Service detail lives on the ISO 9001 and ISO 27001 pages.
Frequently Asked Questions
What is an integrated management system? A single management system satisfying two or more standards at once: one document library, one audit programme, one management review, with standard-specific content layered on top. Integration works because these standards share the Annex SL 10-clause structure.
What is the difference between IMS and ISO? ISO publishes the standards and you are certified against each one separately. An IMS is internal architecture, not a standard, and there is no IMS certificate. You hold an ISO 9001 certificate and an ISO 14001 certificate; the IMS is what produces both from one set of processes.
What is the purpose of an IMS? To stop paying for the same work several times, and to stop separate systems drifting into contradiction. A large share of clause content is functionally identical across standards, and an IMS builds that shared layer once.
What is an integrated management system for ISO 9001, 14001, and 45001? The most common configuration, often called QHSE. Context, leadership, support, audit, review, and improvement are written once. The quality process map, the environmental aspects register, and the hazard identification work stay separate.
Can ISO 27001 be part of an integrated management system? Yes at the clause level, since it uses the same Annex SL structure. Annex A and the Statement of Applicability do not merge, because no other management system standard has an equivalent fixed control set.
How long does it take to build an integrated management system? A first system is typically six to twelve months to certification readiness. Adding a second standard to a working system is usually three to five months, because the shared clauses already exist.
Building More Than One ISO Certificate?
ShieldKey Solutions designs integrated management systems rather than stacking separate programs. We build the shared Annex SL layer once, keep each standard's risk register properly distinct, and sequence certification around the deadline that is actually driving you.