One system. Three standards. One audit.
Running quality, environment and safety as three separate systems triples your paperwork and your audit days. An integrated management system merges them into a single structure. One manual, one audit programme, one management review, one certification visit.
What an integrated management system is
An integrated management system is a single management framework that satisfies more than one standard at once. Rather than three manuals, three internal audit programmes and three management reviews, you operate one system with discipline-specific content where the standards genuinely differ.
This is possible because all modern ISO management system standards are written to a common high-level structure: historically known as Annex SL, now the harmonised structure. ISO 9001, ISO 14001 and ISO 45001 share identical clause numbering and largely identical requirements for context, leadership, planning, support, performance evaluation and improvement. Only the operational clauses and the risk methodology differ meaningfully.
Why integrate
Lower certification cost
Certification bodies audit shared clauses once rather than three times. Combined audits typically reduce total audit days by around a third compared with three separate certifications.
One document set to maintain
A single document control procedure, one corrective action process, one competence register. Update once instead of remembering to update three times.
One audit season
A single internal audit programme and one management review covering all three disciplines, instead of disrupting operations three times a year.
No contradictions
Separate systems drift apart. A quality procedure that conflicts with a safety procedure is a finding in both. Integration removes the contradiction at source.
What the three standards share, and where they diverge
| Clause | Integration potential | Discipline-specific content still required |
|---|---|---|
| 4: Context | Fully shared | Interested party expectations differ by discipline |
| 5: Leadership | Fully shared | Combined QHSE policy; 45001 adds worker consultation |
| 6: Planning | Partly shared | Separate registers: quality risk, aspects, hazards |
| 7: Support | Fully shared | Competence requirements differ by role |
| 8: Operation | Minimal | Largely discipline-specific. This is where the real work sits |
| 9: Performance | Fully shared | Different metrics; 14001 adds compliance evaluation |
| 10: Improvement | Fully shared | 45001 has specific incident investigation requirements |
A common mistake is collapsing the three risk processes into one generic register. Quality risks, environmental aspects and OH&S hazards are assessed by different methods against different criteria. Auditors expect to see them handled distinctly inside a shared framework.
What we do for you
Two routes to an IMS
- Build integrated from the start. If you hold no certifications, this is by far the cheapest path. One build, one implementation period, one certification event. Typical duration is sixteen to twenty-four weeks for three standards: considerably less than the forty-plus weeks three sequential projects would take.
- Integrate what you already have. If you hold one or two certificates already, we restructure the existing system to the harmonised sequence, add the missing discipline, and align your certification cycles so future audits are combined. This usually takes six to twelve weeks per standard added.
If your existing certificates were issued at different times, they expire at different times, which blocks a combined audit. Aligning them requires planning, usually a short-cycle certificate for one standard to bring the dates together. This needs to be arranged with the certification body well before renewal, and it is the single most common reason organisations stay stuck with separate audits.
Timeline and investment
| Starting point | Typical duration | Relative cost vs separate projects |
|---|---|---|
| No certifications, building 9001 + 45001 | 14–18 weeks | Around 35% less |
| No certifications, building all three | 16–24 weeks | Around 45% less |
| Hold 9001, adding 45001 | 6–10 weeks | Around 40% less |
| Hold two, adding the third | 5–9 weeks | Around 50% less |
Savings shown are indicative and depend on your headcount, number of sites and the maturity of what already exists. We confirm actual figures after the gap analysis, and we will always tell you if integration is not worth it in your case.
Questions clients ask first
Usually three certificates (one per standard) issued from a single combined audit, though some certification bodies issue a single multi-standard certificate. Either way you hold valid, separately verifiable certification for each standard, which is what clients and tender portals check.
Substantially easier. The complexity is front-loaded into the design. Once built, you maintain one document set, run one audit programme and hold one management review. The organisations that struggle are those that integrated the documents but never integrated the way they work.
Yes, and for Abu Dhabi entities we recommend it. ADOSH-SF v4.0 is a regulatory obligation rather than a certification, but its requirements map cleanly into an ISO 45001 framework as compliance obligations. Building both together avoids maintaining a parallel regulatory file. See ADOSH-SF v4.0 compliance.
Yes. Any standard written to the harmonised structure integrates the same way: ISO 27001 for information security, ISO 22301 for business continuity, ISO 50001 for energy management. Talk to us about your scope and we will advise whether integration is worthwhile.

Let’s make your next audit a non-event.
Book a free 30-minute consultation. We will tell you honestly whether you need a consultant, and if you do, exactly what it will take.