Why Integration Makes Sense
If your organisation is certified to ISO 9001 for quality, ISO 14001 for environment, and ISO 45001 for safety, you already know the problem. Three separate management reviews. Three sets of objectives. Three audit programmes. Three document control systems. People in your team get confused about which procedure to follow, and your internal auditors spend half their time working out which standard they are auditing against at any given moment.
On this page
An integrated management system, commonly called an IMS, brings those three systems together into a single framework. One policy. One set of procedures where the requirements overlap. One management review that covers all three standards at once. Done properly, integration reduces duplication, cuts the administrative burden, and makes the system easier for everyone in the organisation to understand and follow.
This article walks through how to actually integrate management systems in practice. Not the theory. The practical steps, the common pitfalls, and the decisions you need to make along the way.
What Makes Integration Possible
The reason integration works is the High Level Structure, also known as Annex SL or the Harmonised Structure. ISO designed this common framework so that all modern management system standards share the same clause numbering and structure. ISO 9001, ISO 14001, and ISO 45001 all follow the same ten clause layout, from context of the organisation through to continual improvement.
That shared structure means the requirements in Clause 4 (context), Clause 5 (leadership), Clause 6 (planning), Clause 7 (support), Clause 9 (performance evaluation), and Clause 10 (improvement) are largely compatible across all three standards. You can write a single procedure for internal audits that satisfies all three. You can hold one management review that covers quality, environmental, and safety performance together. You can maintain one set of documented information requirements rather than three parallel systems.
To understand the full picture of what each standard covers and where they differ, the article ISO 9001 vs ISO 14001 vs ISO 45001: Key Differences Explained is worth reading before you begin your integration project.
Exemplar Global Recognised Training ProviderRTP No. 310970Step One: Map Where the Requirements Overlap
Before you start rewriting any documents, sit down with the three standards and map the common requirements against each other. A simple spreadsheet works well for this. List the clause numbers down the left column, then add a column for each standard showing what that clause requires.
You will quickly see that some clauses are almost identical across all three standards. Internal audit requirements, management review inputs and outputs, competence and awareness, documented information control, corrective action processes. These are your integration wins. One procedure covers all three.
Other clauses are standard specific. ISO 14001 has environmental aspects and impacts. ISO 45001 has hazard identification and the hierarchy of controls. ISO 9001 has customer requirements, design and development, and control of externally provided products and services. These clauses need to remain distinct. You can reference them from a common framework, but you cannot collapse them into each other without losing the specific requirements each standard demands.
The Integration Matrix
A practical tool here is an integration matrix. Down one side, list your existing procedures and documents. Across the top, list the three standards. Mark which clauses each document currently addresses. You will immediately see where you have three separate documents doing the same job, and where you have genuine gaps that need standard specific content.
This matrix also becomes useful evidence during your certification audits. When an auditor asks how your system addresses a particular clause, you can point directly to the relevant procedure and show which standards it satisfies.
Step Two: Decide Your Integration Model
There are three common approaches to integration, and the right one depends on your organisation's size, complexity, and how mature your existing systems are.
Full Integration
A fully integrated system has one policy, one set of procedures, one risk register, one internal audit programme, and one management review. The documents address all three standards simultaneously. This works well for small to medium organisations where one or two people manage the entire system. It produces the least paperwork and is easiest to maintain.
The risk with full integration is that if your procedures are not written carefully, you can end up with documents that technically reference all three standards but do not actually satisfy any of them in enough depth. Every clause still needs to be addressed. Integration does not mean you can skip requirements.
Partial Integration
Partial integration keeps the common elements together (policy, objectives framework, internal audit procedure, management review, corrective action) while maintaining separate procedures for the standard specific requirements. So you would have one corrective action procedure, but separate environmental aspects and impacts registers and hazard identification processes.
This is the most common approach and generally the most practical. It gives you the efficiency of integration where it is straightforward, without forcing artificial combinations where the standards genuinely diverge.
Aligned but Separate
Some organisations keep three largely separate systems but align them so they use the same templates, the same document numbering system, and the same management review structure. This is the lightest touch option. It reduces some duplication but does not deliver the full benefits of integration.
This approach is worth considering if you are certifying to the three standards at very different times, or if different parts of your organisation are responsible for different systems and genuine integration would create confusion rather than clarity.
Step Three: Write an Integrated Policy
One of the most visible integration steps is combining your quality policy, environmental policy, and OH&S policy into a single integrated policy. Many organisations do this and it works well, provided the integrated policy actually addresses the specific commitments each standard requires.
ISO 9001 requires the policy to commit to satisfying applicable requirements and to continual improvement of the QMS. ISO 14001 requires commitments to protecting the environment, fulfilling compliance obligations, and continual improvement of the EMS. ISO 45001 requires commitments to providing safe and healthy working conditions, eliminating hazards, fulfilling legal requirements, and worker consultation and participation.
An integrated policy can cover all of these in a few well written paragraphs. The key is that it must be genuinely meaningful, not a generic statement that could apply to any organisation anywhere. It should reflect what your organisation actually does and the specific environmental and safety risks you face.
Step Four: Build an Integrated Objectives Framework
Setting objectives is one area where integration requires care. Each standard has specific requirements about what objectives must address. ISO 9001 quality objectives need to be measurable and consistent with the quality policy. ISO 14001 environmental objectives must take into account significant environmental aspects and compliance obligations. ISO 45001 OH&S objectives must take into account applicable legal requirements and the results of hazard identification and risk assessment.
You can absolutely present all objectives in a single register or table. Many organisations use a combined objectives register with a column indicating which standard each objective relates to. What you want to avoid is creating one generic objective that is meant to satisfy all three standards but is actually too vague to satisfy any of them.
A practical tip: review your objectives during a single integrated management review meeting, but keep the evidence trail clear about which standard each objective is connected to. Your certification auditors will check this.
Step Five: Integrate Your Internal Audit Programme
The internal audit programme is one of the biggest practical wins from integration. Instead of running three separate audit programmes that may overlap, conflict, or leave gaps, you run one programme that covers all three standards across the audit cycle.
Your audit programme still needs to address all clauses of all three standards over time, with frequency based on risk. The difference is that when you audit a process, you can audit it against all three standards in a single audit. When you are in the warehouse auditing how materials are received and stored, you can check quality requirements (inspection, traceability), environmental requirements (spill containment, waste segregation), and safety requirements (manual handling, forklift traffic management) all in the same audit session.
This is called a combined audit or integrated audit, and it is significantly more efficient than running three separate audits of the same process. It also gives you a more complete picture of how well the process is actually managed. For more on building a programme that works across multiple standards, the article How to Build an Internal Audit Programme From Scratch covers the fundamentals in detail.
Audit Checklists for an IMS
Your audit checklists need to reflect the integrated approach. Rather than three separate checklists for the same process, build one checklist that covers the relevant clauses from all three standards. Organise it by process rather than by standard clause. This keeps the audit focused on how the work is actually done, rather than jumping between three different frameworks mid conversation.
Step Six: Integrate Management Review
Running one management review that covers all three standards is one of the clearest efficiency gains from integration. The inputs required by ISO 9001, ISO 14001, and ISO 45001 overlap significantly. All three require review of audit results, performance against objectives, corrective actions, and opportunities for improvement. ISO 45001 adds incident investigation results and worker participation. ISO 14001 adds compliance evaluation results and the status of environmental aspects.
A well structured integrated management review agenda can cover all of these in a single meeting. Present quality, environmental, and safety performance data together. Review all objectives together. Identify improvement opportunities across all three systems. Document the outputs in a single set of minutes that clearly addresses the requirements of all three standards.
The meeting should be structured so that it is clear which items relate to which standard, but there is no requirement to hold three separate meetings. Certification auditors generally accept integrated management reviews without difficulty, provided the minutes demonstrate that all required inputs were considered and all required outputs were produced.
Step Seven: Align Documented Information
Document control is another area where integration pays off. Instead of three separate document control procedures, one procedure covers all three standards. Instead of three separate registers of documented information, one register lists all your documents and records with a column indicating which standard or standards each one satisfies.
The practical challenge here is version control. When you revise a document that addresses all three standards, you need to ensure the revision still satisfies all three. A simple review checklist at the document revision stage helps with this. Before approving a revised procedure, check it against the relevant clauses of each applicable standard.
Common Integration Mistakes to Avoid
Collapsing Requirements That Should Stay Separate
The most common mistake is trying to force requirements that genuinely differ into a single document or process. Environmental aspects and impacts, hazard identification, and customer requirements are fundamentally different processes. They can sit in the same management system framework, but they cannot be combined into one procedure without losing the specific requirements of each standard.
Creating a System That Only the Quality Manager Understands
Integration should make the system simpler for everyone, not just for the person who built it. If your integrated procedures are so dense that workers cannot find what is relevant to them, the system has failed at its core purpose. Consider creating role specific guides or process maps that show each team what they need to know and do, without requiring them to navigate the entire integrated system.
Losing Traceability to Standard Requirements
When certification auditors review your integrated system, they need to be able to trace how each clause of each standard is addressed. If your integration has been so thorough that this traceability is lost, you will have a difficult audit. Maintain a cross reference matrix that maps your documents and procedures to the specific clauses of each standard.
Treating Integration as a One Time Project
Integration is not something you do once and then leave alone. As the standards are revised (ISO 14001 has recently been updated to the 2026 edition, and ISO 9001 has a revision in progress), your integrated system needs to be reviewed and updated. Build standard revision reviews into your management review agenda so that changes to any of the three standards trigger a review of the relevant integrated procedures.
For those currently managing an ISO 14001 system, the ISO 14001:2026 transition guide covers what has changed and what your integrated system will need to address before the April 2029 deadline.
Getting Certification for an Integrated System
Most accredited certification bodies offer combined audits where one audit team assesses your organisation against all three standards simultaneously. This is more efficient than three separate certification audits and generally costs less in total. When requesting a combined audit, confirm with your certification body that the audit team includes auditors with competence across all three standards.
Your certification body will issue separate certificates for each standard, even when the audit is conducted as a combined exercise. The integrated nature of your system does not change the certification outcome. You will still receive individual ISO 9001, ISO 14001, and ISO 45001 certificates.
During a combined certification audit, the auditors will want to see that each standard is genuinely addressed, not just referenced. They will follow the audit trail for each standard specific requirement, even within your integrated documents. Prepare your team to be able to explain which parts of your integrated procedures address which standard requirements. That level of familiarity demonstrates that your integration is real, not just cosmetic.
Exemplar Global Recognised Training ProviderRTP No. 310970Is Integration Right for Every Organisation
Honestly, not always. For a small business certifying to just one standard, integration is not relevant. For an organisation that has just implemented its first management system, attempting to integrate three standards simultaneously can be overwhelming. It is often better to get one system working well before adding the others.
Integration delivers the most value when all three systems are already established and the duplication and administrative overhead has become genuinely burdensome. At that point, the efficiency gains from integration are real and significant. For organisations considering whether to certify to multiple standards at once or build up gradually, the What Is an Integrated Management System article provides a solid foundation for that decision.
Building the Skills to Audit an IMS
If you are an internal auditor working within an integrated system, or an ISO consultant helping clients build one, you need to be comfortable auditing across all three standards simultaneously. That requires understanding not just the common structure but the specific technical requirements of each standard, including environmental aspects and impacts under ISO 14001, hazard identification and the hierarchy of controls under ISO 45001, and customer focus and process control under ISO 9001.
Audit Workshop offers training at Foundation, Internal Auditor, and Lead Auditor levels across ISO 9001, ISO 14001, and ISO 45001. If you are working with or planning to implement an integrated management system, building your competence across all three standards gives you the practical skills to audit, maintain, and improve the system with confidence. The IMS Lead Auditor course specifically covers how to audit all three standards together, which is exactly the skill set organisations with integrated systems need from their auditors and consultants.













