Exemplar Global Certified Courses from USD 99. Ending Soon!

Auditing an IMS: How to Audit ISO 9001, ISO 14001 and ISO 45001 Together

AW

Team @ Audit Workshop

14 min read
Auditing an IMS: How to Audit ISO 9001, ISO 14001 and ISO 45001 Together

Why Auditing an IMS Is a Different Job

If you have only ever audited a single standard, walking into an integrated management system audit for the first time can feel disorienting. The organisation has one system, one set of documents, one management review, and one internal audit programme covering ISO 9001, ISO 14001 and ISO 45001 simultaneously. Your job is to assess conformance with all three standards without duplicating effort, missing critical requirements, or spending three times as long on site.

This is not just about efficiency. Auditing an IMS well requires a genuine understanding of where the three standards share common ground and where they diverge. Get that wrong, and you will either audit the same things three times over or, worse, leave whole areas of one standard completely unexamined.

This article is a practical guide to planning and conducting an IMS audit. It covers the structural logic that makes combined auditing possible, the areas where each standard pulls in its own direction, and the techniques that experienced auditors use to keep the audit coherent from opening meeting to closing meeting.

Understanding the High Level Structure: Your Foundation for IMS Auditing

The reason auditing three standards together is feasible at all comes down to the Harmonised Structure, sometimes called Annex SL. ISO 9001:2015, ISO 14001:2015 and ISO 45001:2018 all follow the same ten clause framework. Clauses 4 through 10 cover context, leadership, planning, support, operation, performance evaluation and improvement in the same sequence across all three standards.

This shared architecture means that when you audit Clause 5.1 leadership and commitment, you are looking at the same fundamental requirement across all three standards. Top management needs to demonstrate commitment to the quality management system, the environmental management system and the OH&S management system. In an integrated organisation, much of this evidence appears in a single integrated policy, a single management review, and the same set of leadership behaviours.

For a deeper look at how the Harmonised Structure works and why it matters for auditors, see our article on what is the High Level Structure in ISO standards.

Where the Standards Align

The following clauses are substantially similar across all three standards and can typically be audited together without switching between separate checklists:

  • Clause 4.1 and 4.2: Context of the organisation and interested parties. One context analysis should address quality, environmental and OH&S considerations together.
  • Clause 5.1: Leadership and commitment. One set of leadership behaviours, one integrated policy.
  • Clause 5.3: Roles, responsibilities and authorities. One organisational chart, one set of role descriptions.
  • Clause 6.3: Planning of changes. One change management process.
  • Clause 7.1 to 7.5: Support requirements covering resources, competence, awareness, communication and documented information.
  • Clause 9.1.1: Monitoring and measurement. One performance monitoring framework.
  • Clause 9.2 and 9.3: Internal audit and management review. One audit programme, one management review process.
  • Clause 10.2: Nonconformity and corrective action. One corrective action system.

Where the Standards Diverge

The operational clauses are where the three standards separate. Each standard has discipline specific requirements that reflect its particular focus:

  • ISO 9001 Clause 8: Customer requirements, design and development, control of externally provided processes, production and service provision, release of products and services, and control of nonconforming outputs.
  • ISO 14001 Clause 6.1.2: Environmental aspects and impacts assessment. Clause 8.1 operational control including lifecycle perspective. Clause 8.2 emergency preparedness and response (environmental focus).
  • ISO 45001 Clause 6.1.2: Hazard identification and OH&S risk assessment. Clause 5.4 worker consultation and participation. Clause 8.1.2 hierarchy of controls. Clause 8.1.3 management of change. Clause 8.1.4 procurement and contractor management from an OH&S perspective.

Understanding this split is the key to structuring your audit plan. Audit the common clauses together. Audit the discipline specific clauses separately, but look for integration evidence along the way.

Planning an IMS Audit: Getting the Structure Right

Before you arrive on site, your audit plan needs to reflect the integrated nature of the system. A poorly structured IMS audit plan will either treat the three standards as completely separate audits conducted back to back, or will collapse everything into a single undifferentiated session that misses standard specific requirements.

Decide on Your Audit Approach

There are two main approaches to structuring an IMS audit: process based and clause based. For an IMS, a process based approach usually works better. Instead of working through each standard clause by clause, you follow the organisation's key processes and test all three standards as you go.

For example, when you audit the procurement process, you are simultaneously checking ISO 9001 Clause 8.4 (control of externally provided processes), ISO 14001 Clause 8.1 (operational control of suppliers with significant environmental aspects), and ISO 45001 Clause 8.1.4.1 (OH&S requirements for procurement). One process, three standards, one audit session.

This approach is more efficient, more realistic, and tends to reveal integration gaps that a clause based approach would miss. If the organisation claims to have an integrated system but the quality manager knows nothing about the environmental aspects register, that is a finding worth raising.

Build a Cross Reference Matrix

Before writing your audit plan, build a simple matrix that maps each clause of each standard to the relevant process or area in the organisation. This tells you which areas of the business you need to visit, which documents to request, and which clauses each session will cover.

A typical IMS audit plan for a mid sized organisation might look like this:

  • Session 1: Opening meeting, context and leadership (Clauses 4, 5 across all three standards)
  • Session 2: Planning (Clause 6 across all three standards, including aspects and impacts, hazard identification, and quality risks)
  • Session 3: Support requirements (Clause 7 across all three standards)
  • Session 4: Operations, quality focus (ISO 9001 Clause 8)
  • Session 5: Operations, environmental focus (ISO 14001 Clause 8)
  • Session 6: Operations, OH&S focus (ISO 45001 Clause 8)
  • Session 7: Performance evaluation (Clause 9 across all three standards)
  • Session 8: Improvement and corrective action (Clause 10 across all three standards)
  • Session 9: Closing meeting

This structure keeps the common clauses integrated while giving each standard the focused attention it needs in the operational areas.

Auditing the Common Clauses: Efficiency Without Shortcuts

When auditing the common clauses, your goal is to gather evidence that satisfies all three standards in a single line of questioning. This requires preparation. You need to know exactly what each standard requires before you sit down with the auditee.

Context and Interested Parties

Ask to see the organisation's context analysis. In an integrated system, this should address internal and external issues relevant to quality, environment and OH&S in one document or set of documents. Check that the interested parties register captures stakeholders relevant to all three disciplines. Regulators, customers, workers, neighbours, and community groups may all appear, but the environmental regulator and the workers compensation insurer need to be there as much as the key customer.

A common finding in IMS audits is that the context analysis was originally built for ISO 9001 and then environmental and OH&S considerations were added as an afterthought. The result is a quality focused context analysis with a few environmental and safety notes appended. That is not genuine integration, and a certification auditor will notice.

Leadership and Policy

An integrated policy is one of the most visible signs of genuine integration. Ask to see it. Check that it contains commitments specific to each standard: customer satisfaction for quality, environmental protection and pollution prevention for the environment, and worker consultation and the elimination of hazards for OH&S.

Then test whether leadership commitment is real. Ask top management how they demonstrate their commitment to each of the three systems. Ask workers what the policy means to them. The gap between the written policy and lived behaviour is where IMS audits often find their most significant findings.

Management Review

In an integrated system, there should be one management review that covers all three standards. Check the agenda and minutes against the mandatory inputs for each standard. ISO 9001 requires customer satisfaction data and supplier performance. ISO 14001 requires compliance evaluation results and environmental performance against objectives. ISO 45001 requires incident data, worker participation outcomes and OH&S performance trends.

A management review that covers quality metrics but skips environmental compliance evaluation or incident trends is a nonconformity, regardless of how thorough it is on the quality side.

Auditing the Discipline Specific Clauses

This is where IMS auditing becomes genuinely demanding. Each standard has operational requirements that require specific technical knowledge and specific lines of questioning.

ISO 9001: Quality Operations

When auditing ISO 9001 specific requirements in an IMS, focus on the customer facing processes. Clause 8 covers a lot of ground: how customer requirements are determined and reviewed, how design and development is controlled if applicable, how externally provided products and services are managed, and how production and service provision is controlled.

In an IMS context, look for integration between quality controls and environmental or OH&S controls at the operational level. For example, a production process might have quality inspection points, environmental waste management requirements, and machine guarding requirements all applying to the same workstation. A genuinely integrated system will address all three in the same work instruction or procedure. Separate quality, environmental and safety procedures for the same task are a sign of a paper integrated system rather than a genuinely integrated one.

ISO 14001: Environmental Operations

The aspects and impacts assessment is the engine of an environmental management system. When auditing this in an IMS context, check that the assessment covers activities relevant to the organisation's scope, including those controlled by contractors. Look for significant aspects that have operational controls, objectives, or both.

The lifecycle perspective is a requirement specific to ISO 14001 that often gets lost in IMS audits. The organisation must consider environmental impacts across the lifecycle of its products and services, not just in its own operations. Check whether this thinking has influenced procurement decisions, product design, or customer communication.

For more detail on what auditors look for in this area, see our article on ISO 14001 aspects and impacts: what auditors check and why.

ISO 45001: OH&S Operations

Hazard identification is to ISO 45001 what aspects and impacts is to ISO 14001. It is the discipline specific planning tool that drives everything else. In an IMS audit, check that hazard identification is genuinely ongoing, not a document created at implementation and never updated. New tasks, new equipment, new chemicals, new workers, and new contractors should all trigger a review.

Worker consultation and participation under Clause 5.4 is unique to ISO 45001 and is often under audited in IMS contexts. Ask workers directly whether they are consulted on hazard identification, risk assessment, and changes to the OH&S system. Ask how they raise OH&S concerns and what happens when they do. Documented consultation records that workers have never seen are a red flag.

The hierarchy of controls under Clause 8.1.2 is another area that deserves focused attention. Check that the organisation has genuinely considered elimination and substitution before defaulting to administrative controls and PPE. A risk register full of PPE controls with no evidence that higher order controls were considered is a common finding.

Our article on auditing occupational health and safety under ISO 45001 covers these requirements in more detail.

Common IMS Audit Findings

After conducting IMS audits across a range of industries, certain patterns emerge. These are the findings that appear most often.

Integration Is Cosmetic, Not Real

Many organisations have an integrated management system on paper but operate three separate systems in practice. The quality manager manages quality, the environmental officer manages environment, and the safety officer manages safety. They share a document numbering system and a management review agenda, but there is no genuine cross functional integration.

Evidence of this includes separate corrective action registers for each standard, separate internal audit programmes that never cross discipline boundaries, and management review minutes that address each standard in isolated sections with no connection between them.

Objectives Are Not Integrated

Quality objectives, environmental objectives and OH&S objectives that exist in separate documents with no relationship to each other suggest that the organisation has not thought about how the three systems interact. A genuinely integrated system will have objectives that reflect the organisation's overall strategic direction, with quality, environmental and OH&S components that reinforce each other rather than competing for resources.

Internal Audits Cover All Three Standards in Name Only

Ask to see the internal audit programme and recent audit reports. If the audit programme shows combined IMS audits but the audit reports only contain findings against one or two of the three standards, something is wrong. Either the auditors are not competent across all three standards, or the audit plan is not genuinely integrated.

Auditor competence is a legitimate audit finding. If the organisation's internal auditors have only been trained in ISO 9001, they cannot credibly audit the environmental and OH&S requirements of an IMS. Check their training records.

Emergency Preparedness Is Fragmented

Both ISO 14001 and ISO 45001 require emergency preparedness and response planning. In many organisations, these are separate plans developed by different people with no coordination. A chemical spill, for example, has both environmental and OH&S dimensions. The response plan should address both. If the environmental emergency plan and the OH&S emergency plan are separate documents that contradict each other or leave gaps between them, that is a finding.

Practical Tips for Conducting the Audit on Site

A few practical points that make a real difference in IMS audits.

Be Transparent About Which Standard You Are Auditing at Any Given Moment

When you shift from a common clause to a discipline specific requirement, tell the auditee. Something like:

We have just covered the management review requirements that are common to all three standards. Now I want to focus specifically on the environmental compliance evaluation, which is a requirement of ISO 14001 Clause 9.1.2.
This helps the auditee follow your line of questioning and prevents confusion when you ask about things that are not relevant to all three standards.

Record Findings Against Specific Standard Clauses

Every finding in your audit report must be referenced to a specific clause of a specific standard. A nonconformity that says the management review did not cover all required inputs is not good enough. You need to specify which standard's management review inputs were missing and cite the relevant clause. In an IMS audit, this discipline is essential.

Look for Integration Evidence, Not Just Conformance Evidence

The whole point of an IMS is that the three systems work together. As you audit, keep asking yourself: is this genuinely integrated, or is it three systems sharing a filing cabinet? The most valuable findings in an IMS audit are the ones that reveal where integration has broken down, because those findings point to real systemic weaknesses rather than paperwork gaps.

Training for IMS Auditing

Auditing an IMS competently requires knowledge of all three standards, not just one. An auditor who knows ISO 9001 well but has never studied ISO 14001 or ISO 45001 will miss significant areas in an IMS audit. This is why IMS specific auditor training exists and why it is increasingly valued by employers and certification bodies alike.

If you are building your credentials for IMS auditing, the most direct path is to complete lead auditor or internal auditor training that covers all three standards together, rather than accumulating separate qualifications over time. Integrated training builds the cross standard thinking that IMS auditing demands.

Audit Workshop offers training at Foundation, Internal Auditor and Lead Auditor levels across ISO 9001, ISO 14001 and ISO 45001, including integrated IMS programmes designed for auditors who want to work across all three standards. If you are preparing to audit or manage an IMS, our IMS lead auditor training is built around exactly this kind of practical, cross standard audit thinking.

For those who want to understand where they sit on the qualification path before committing to a course, our article on ISO lead auditor vs internal auditor: which course do you need is a good starting point.

Frequently Asked Questions

Yes, provided the auditor has demonstrated competence in all three standards. ISO 19011 requires that auditors have the knowledge and skills relevant to the standards they are auditing. An auditor who holds qualifications in ISO 9001, ISO 14001 and ISO 45001 can conduct a combined IMS audit alone, though for larger or more complex organisations an audit team with complementary expertise is often more practical.
Start Learning

Ready to Build Real Audit Skills?

Join practitioners training with ISO auditors who've conducted 500+ external certification audits.

ISO 9001:2015 Lead Auditor

Quality Management Systems (QMS)

Lead AuditorSelf-Paced Online
Digital Badge
Limited timeUSD 199(original price USD 789)
ISO 45001:2018 Lead Auditor

Occupational Health and Safety Management Systems (OHSMS)

Lead AuditorSelf-Paced Online
Digital Badge
Limited timeUSD 199(original price USD 789)
ISO 14001:2026 Lead Auditor

Environmental Management Systems (EMS)

Lead AuditorSelf-Paced Online
Digital Badge
Limited timeUSD 199(original price USD 789)
Exemplar Global Recognised Training Provider digital badge

Audit Workshop is an Exemplar Global Recognised Training Provider

Globally Recognised, Certified Training

Pass an Exemplar Global Certified course and you earn a Certificate of Attainment and an Exemplar Global digital badge. Audit Workshop graduates can apply for third-party Personnel Certification through Exemplar Global.

  • 12 months of Graduate certification
  • Access to Exemplar Global Community
  • Access to self-coaching assessment
  • Access to webinars, events, and online resources
Learn Anytime

No fixed schedule. Start, pause, and pick up exactly where you left off.

Instant Certificate

Download your digital certificate the moment you complete the course.

Practical Content

Every lesson is built from real-world ISO auditing experience.

Lifetime Access

Course materials are yours to keep and revisit long after you complete.