Integrated Management System: Combining ISO Standards

By July 25th, 2026ISO Audit And Certificate6 min read

Integrated Management System: Combining ISO Standards

An Integrated Management System (IMS) is a single unified framework that combines two or more management system standards – such as ISO 9001, ISO 14001, ISO 45001 and ISO 27001 – into one coherent system of policies, processes and procedures. Instead of operating separate quality, environmental, health and safety and information security systems, an IMS uses the common high-level structure (Annex SL) to share documentation, audits and management processes across all standards. The result is lower cost, less duplication and simpler compliance.

Published: July 2026  |  Last updated: July 2026  |  Author: Bitrixme Compliance Team

What Is an Integrated Management System?

An IMS treats each adopted standard as a module within a single management architecture. The common clauses – context of the organisation, leadership, planning, support, operation, performance evaluation and improvement – are managed once and apply to all standards. The standard-specific requirements sit alongside each other within the same operational framework. An organisation certified to ISO 9001, ISO 14001, ISO 45001 and ISO 27001 through an IMS maintains one document control procedure, one internal audit programme, one management review process and one corrective action system, not four.

Standards That Can Be Integrated

Any management system standard that follows the Annex SL high-level structure can be integrated. The following ISO standards share this common framework and are the most frequently combined in an IMS.

StandardSubjectCommon Clause Compatibility
ISO 9001:2015Quality managementFull (Annex SL)
ISO 14001:2015Environmental managementFull (Annex SL)
ISO 45001:2018Occupational health and safetyFull (Annex SL)
ISO 27001:2022Information security managementFull (Annex SL)
ISO 22301:2019Business continuity managementFull (Annex SL)
ISO 22000:2018Food safety managementFull (partial alignment)
ISO 20000-1:2018IT service managementFull (partial alignment)
ISO 37001:2016Anti-bribery managementFull (Annex SL)
ISO 42001:2023Artificial intelligence managementFull (Annex SL)

Benefits of Integration

The business case for an IMS rests on measurable reductions in cost, complexity and audit burden. Operating separate management systems for each standard creates duplicate documentation, separate training programmes, multiple internal audits and disconnected management reviews. Integration consolidates these into a single efficient system.

BenefitSeparate SystemsIntegrated SystemTypical Improvement
Documentation volume4+ manuals, dozens of separate procedures1 manual, shared procedures30 – 50% reduction
Internal audit days4 – 8 days per standard per year4 – 6 days total per year30 – 50% reduction
External audit daysDetermined per standard (e.g. ISO 9001: 3 days, ISO 27001: 5 days)IAF MD 11 allows combined audit day reductions20 – 30% reduction
Management review meetings4 separate meetings per year1 combined meeting per year75% reduction
Training deliverySeparate awareness for each standardUnified management system awareness40 – 60% reduction
Three-year certification costSum of individual standard costs10 – 25% less than sum10 – 25% cost reduction

The Integration Approach: High-Level Structure

The Annex SL framework provides a standardised template for all ISO management system standards. Every Annex SL standard is organised into the same ten-clause structure: Scope, Normative References, Terms and Definitions, Context of the Organisation, Leadership, Planning, Support, Operation, Performance Evaluation, and Improvement. This common structure allows organisations to write one set of core procedures that satisfy the identical clauses across all standards. The standard-specific requirements then fit into the relevant clause as additional content. For example, the Context of the Organisation clause must address interested parties for quality (ISO 9001), environmental conditions (ISO 14001), worker consultation (ISO 45001) and information security risks (ISO 27001), all within one documented process.

Implementation Steps

  • Gap analysis. Assess your current management systems against all target standards simultaneously. Identify where existing processes already satisfy multiple standards and where gaps exist.
  • Design the integrated framework. Map common clauses to shared procedures. Define which documents are shared and which remain standard-specific.
  • Develop the integrated manual. Write a single management system manual that describes how the organisation addresses each clause across all standards.
  • Align operational processes. Integrate standard-specific requirements into existing workflows. For example, add information security controls to the document review process rather than creating a separate security review step.
  • Train internal auditors. Internal auditors must understand how the IMS works across all standards, not just one. Combined audit checklists are essential.
  • Conduct an integrated internal audit. Before external certification, run a full internal audit of the IMS covering all standards in scope.
  • Engage a certification body for combined certification. Work with a certification body that offers combined audits under IAF MD 11 to maximise audit day savings.

Common Challenges

Organisations face three recurring challenges when building an IMS. The first is scope complexity – not all standards apply to all parts of the business, and defining the scope for each within the integrated system requires careful mapping. The second is auditor competence – internal auditors must be trained across multiple standards, and external auditors must hold qualifications in all standards being audited. The third is maintaining the IMS over time – as standards are revised, the integrated documentation must be updated coherently rather than one standard at a time.

FAQ

What is an Integrated Management System?

An IMS is a single management framework that combines two or more ISO management system standards, sharing common policies, procedures and audit processes to reduce duplication and cost.

Which ISO standards can be integrated?

Any standard that follows the Annex SL high-level structure can be integrated. The most common combinations are ISO 9001 + ISO 14001 + ISO 45001, with ISO 27001 added for information security.

How much does an IMS save compared to separate systems?

Organisations typically save 10 to 25 percent on certification costs and 30 to 50 percent on documentation and audit time. The savings increase with the number of standards integrated.

Can I certify my IMS as a single system?

Yes. Most certification bodies offer combined certification audits for integrated management systems under IAF Mandatory Document 11. The auditor issues separate certificates for each standard but conducts a single combined audit.

What is Annex SL?

Annex SL is the ISO framework that defines the high-level structure, identical core text and common terms for all ISO management system standards. It was introduced to make integrated management systems practical and straightforward.

How long does it take to implement an IMS?

For an organisation with existing certifications, integrating them into an IMS typically takes 3 to 6 months. For a first-time implementation of multiple standards simultaneously, allow 8 to 14 months depending on scope and resource.

Ready to integrate your management systems? Contact our compliance team for an IMS gap assessment, or message us on WhatsApp.