A combined audit is one of the most practical tools available to organisations that hold certification to more than one ISO standard. Instead of running separate audits for ISO 9001, ISO 14001, and ISO 45001 at different times, a combined audit covers two or more management systems in a single audit event. The same audit team, the same site visit, the same opening and closing meetings. If your organisation is already managing multiple systems and you are not yet using combined audits, you are almost certainly spending more time and money on auditing than you need to.
On this page
This article explains what a combined audit is, how it differs from an integrated audit, when it makes sense to run one, how to plan it properly, and what auditors and quality managers need to know before walking in the door.
The Definition of a Combined Audit
ISO 19011:2018 defines a combined audit as an audit conducted at a single auditee covering two or more management system standards simultaneously. The key word is simultaneously. You are not doing two separate audits back to back. You are conducting one audit that addresses the requirements of multiple standards at the same time, using a single audit team and a coordinated audit plan.
The standards being audited remain distinct. Each has its own requirements, its own clauses, its own conformity criteria. A combined audit does not blur those boundaries. It simply removes the duplication of effort that comes from auditing shared elements, such as documented information, management review, internal audit programmes, and competence, more than once.
ISO 19011 was updated in 2026 and the concept of combined auditing remains central to how modern audit programmes are structured. If you want to understand how the guidelines have evolved, the ISO 19011:2026 update is worth reviewing before planning your next audit cycle.
Exemplar Global Recognised Training ProviderRTP No. 310970Combined Audit vs Integrated Audit: What Is the Difference?
These two terms are often used interchangeably, but they mean different things and the distinction matters in practice.
Combined Audit
A combined audit is conducted when an organisation has two or more separate management systems. The systems may share some common infrastructure, documented information, and processes, but they have not been formally merged into a single integrated management system. The auditor examines each standard separately, but does so in a coordinated way during a single visit. Findings are reported against the relevant standard. A nonconformity against ISO 45001 clause 6.1 is raised under ISO 45001, not against ISO 14001.
Integrated Audit
An integrated audit is conducted when an organisation has built a single integrated management system that addresses the requirements of multiple standards within one unified framework. The organisation has one policy, one set of objectives, one management review process, and one documented information structure that covers all standards. The audit reflects that integration. Rather than auditing each standard separately, the auditor follows processes and evaluates conformity against all applicable standards simultaneously.
In practice, most organisations in Australia sit somewhere between these two approaches. They may have started with ISO 9001 and added ISO 14001 or ISO 45001 later, resulting in systems that share some elements but are not fully integrated. A combined audit is usually the right approach in those situations. The integrated management system article on this site gives a good overview of what full integration actually involves.
Why Run a Combined Audit?
The practical reasons are compelling, and they apply equally to internal audits and third party certification audits.
Reduced Disruption to Operations
Every audit imposes a burden on the organisation being audited. Staff need to be available. Managers need to attend opening and closing meetings. Documents need to be pulled. When you run three separate audits across the year, that disruption happens three times. A combined audit concentrates the effort into one event. Staff are interviewed once instead of three times. The management team sits through one closing meeting instead of three.
Efficiency Gains From Auditing Common Elements Once
ISO 9001, ISO 14001, and ISO 45001 share a significant amount of common structure under the harmonised approach. Clause 4 covers context, interested parties, and scope for all three. Clause 5 covers leadership and policy. Clause 7 covers competence, awareness, and documented information. Clause 9 covers internal audit, monitoring, and management review. Clause 10 covers nonconformity and improvement.
In a combined audit, you examine these shared elements once. You review the management review records once and assess whether they meet the requirements of all three standards simultaneously. You interview the management representative once and cover all three systems in that conversation. That is a significant time saving compared to running three separate audits.
Better Value From Audit Resources
Whether you are running internal audits with your own team or engaging an external certification body, audit time costs money. Combined audits typically require fewer total audit days than separate audits for the same scope. Certification bodies calculate combined audit duration using a reduction factor that reflects the shared elements. The savings are real.
A More Coherent Picture of System Performance
When you audit systems separately, you can miss interactions between them. An issue with contractor management might be relevant to quality, environment, and safety simultaneously. In a combined audit, you are more likely to pick up these cross-system connections. You get a more complete picture of how the organisation actually functions.
When a Combined Audit Makes Sense
Not every organisation is ready for a combined audit. These are the conditions that make it work well.
The Organisation Holds Certification to Multiple Standards
This is the obvious starting point. If you are only certified to ISO 9001, a combined audit is not relevant. But if you hold ISO 9001 and ISO 45001 certificates, or all three of the main management system standards, a combined audit is worth considering for both your internal audit programme and your certification audits.
There Is a Reasonable Degree of System Integration
A combined audit works best when the systems share at least some common infrastructure. If the quality system and the safety system are completely separate, managed by different people with no shared documentation or processes, a combined audit will be harder to run efficiently. That said, even partially integrated systems benefit from combined auditing. The audit itself often reveals opportunities to share more elements.
The Audit Team Has Competence Across All Standards
This is non-negotiable. If you are running a combined audit covering ISO 9001 and ISO 45001, the audit team needs auditors who are competent in both standards. In a certification context, the certification body will assign auditors with the appropriate qualifications. For internal audits, you need to make sure your internal auditors have been trained in each standard they will be auditing. Running an internal combined audit with someone who only knows ISO 9001 will produce an incomplete result for the other standards.
Planning a Combined Audit
The planning phase is where combined audits succeed or fail. Get it right here and the audit itself runs smoothly.
Define the Scope and Objectives for Each Standard
Even though you are running one audit, each standard has its own scope and its own set of objectives. Document these clearly in your audit plan. The scope of the ISO 9001 audit may cover all processes involved in delivering the product or service. The scope of the ISO 45001 audit will cover all activities where workers are exposed to OH&S risks. These may not be identical, and your plan needs to reflect that.
Build a Combined Audit Plan That Maps Coverage
Your audit plan should show which clauses of each standard will be addressed in each session. A useful approach is to group sessions around processes rather than clauses. When you audit the procurement process, you cover ISO 9001 clause 8.4 on external providers, ISO 14001 requirements around environmental aspects of purchased materials, and ISO 45001 requirements around contractor management and procurement controls, all in the same session. This process-based approach is far more efficient than working through each standard clause by clause in sequence.
The process-based vs clause-based auditing article explains this approach in detail and is directly relevant to planning combined audits effectively.
Assign Auditor Responsibilities Clearly
In a combined audit with more than one auditor, be explicit about who is responsible for what. If you have one auditor who is strong on ISO 14001 and another who is strong on ISO 45001, structure the sessions to use those strengths. The lead auditor coordinates the overall audit, but individual team members can take the lead on specific standards or processes within their area of competence.
Prepare Checklists That Cross-Reference Requirements
Your audit checklists should be designed for the combined context. For each process or activity you audit, include questions that address the relevant requirements from each standard. A checklist for the management review session should include questions about ISO 9001 clause 9.3 inputs and outputs, ISO 14001 clause 9.3 requirements, and ISO 45001 clause 9.3 requirements, all in one document. This prevents you from missing coverage and makes the session more efficient.
Conducting a Combined Audit: Practical Considerations
Opening Meeting
Run one opening meeting that covers all standards in scope. Explain to the auditee that the audit will address ISO 9001, ISO 14001, and ISO 45001 simultaneously. Clarify that findings will be reported against the relevant standard. Make sure the right people are in the room. The management representative for quality, the environmental manager, and the WHS manager should all attend, or at least be available for their relevant sessions.
Following the Process, Not the Clause List
The most effective combined audits follow the organisation's processes from end to end, examining each process against the requirements of all applicable standards. Start with context and leadership, then move through operational processes, then performance evaluation. At each stage, ask questions that draw out evidence relevant to all standards in scope. When you are on the shop floor looking at a work area, you are simultaneously gathering evidence about product quality controls, environmental aspects and impacts, and hazard identification and risk controls.
Recording Findings Against the Correct Standard
Every finding must be attributed to the correct standard and clause. A nonconformity related to missing environmental monitoring records is raised against ISO 14001, even if you discovered it during a session that also covered quality and safety. Be precise in your documentation. Ambiguous attribution causes problems when the organisation needs to respond to findings and when the certification body reviews the audit report.
Closing Meeting
One closing meeting, covering findings from all standards. Present findings grouped by standard so the auditee can clearly understand what relates to each system. If you have found a nonconformity that has implications across multiple standards, for example, a management review that failed to address inputs required by both ISO 14001 and ISO 45001, explain that clearly and raise separate nonconformities against each standard.
Combined Audits in the Internal Audit Context
For organisations running their own internal audit programmes, combined audits are a practical necessity if you want to maintain a realistic audit schedule without overwhelming your internal audit resources.
Consider a small to medium business with ISO 9001, ISO 14001, and ISO 45001 certification. If they run separate internal audits for each standard, they need to cover the full scope of each system across the year. That might mean three separate audit programmes, three sets of checklists, and three rounds of audit reports. Most internal audit teams do not have the capacity for that.
A well-designed combined internal audit programme covers all three standards in a single annual cycle, with sessions structured around processes and departments. The total audit time is similar to running one thorough system audit, but the coverage spans all three standards. The key requirement is that your internal auditors are trained and competent in all the standards they are auditing. If your team has only completed ISO 9001 internal auditor training, they are not equipped to audit against ISO 14001 or ISO 45001 requirements.
Combined Audits in the Certification Context
Most accredited certification bodies offer combined certification audits for organisations holding multiple certificates. The process works as follows.
The certification body assigns an audit team with competence across all standards in scope. The audit duration is calculated based on the scope and size of the organisation, with a reduction applied to reflect the shared elements. The audit is conducted as a single event, typically over two to five days depending on the size and complexity of the organisation. Findings are reported against each standard separately. Certificates are issued separately for each standard, even though the audit was conducted as a single event.
For organisations approaching their first combined certification audit, the preparation process is similar to preparing for separate audits, but the focus shifts to making sure the shared elements of the system are genuinely integrated and not just duplicated across separate documents. Auditors will look for consistency. If the management review for quality says one thing and the management review for environment says something different about the same period, that inconsistency will attract scrutiny.
Exemplar Global Recognised Training ProviderRTP No. 310970Common Mistakes in Combined Audits
Treating It as Three Separate Audits Conducted Simultaneously
This defeats the purpose. If your audit plan simply runs through ISO 9001 clauses on day one, ISO 14001 clauses on day two, and ISO 45001 clauses on day three, you have not run a combined audit. You have run three audits with a shared opening meeting. The efficiency gains come from genuinely integrating the audit approach around processes.
Insufficient Auditor Competence
Assigning an auditor to a combined audit who is only qualified in one of the standards is a serious problem. They will miss requirements from the other standards, produce incomplete findings, and potentially give the auditee false confidence about conformity. Every auditor on the team must be competent in the standards they are responsible for auditing.
Vague Finding Attribution
Findings that say something like
nonconformity against quality and safety requirementswithout specifying the exact clause of each standard are not useful. Be precise. Each finding gets a standard, a clause, and a clear description of the evidence.
Neglecting Standard-Specific Requirements
The shared elements of the harmonised structure are easy to cover in a combined audit. The standard-specific requirements are where gaps appear. ISO 45001 has unique requirements around worker participation and consultation that have no direct equivalent in ISO 9001 or ISO 14001. ISO 14001 has specific requirements around environmental aspects and impacts and compliance obligations. Make sure your combined audit plan includes dedicated coverage of these standard-specific requirements, not just the shared clauses.
Building Auditor Competence for Combined Audits
If you want to run effective combined audits, whether internal or as a lead auditor in a certification context, you need training across all the standards you intend to audit. That means understanding the specific requirements of ISO 9001, ISO 14001, and ISO 45001, not just their shared structure.
Audit Workshop offers internal auditor and lead auditor training across all three of these standards. If you are an internal auditor looking to expand your scope from quality into environment and safety, the internal auditor courses for ISO 14001 and ISO 45001 will give you the knowledge and audit skills you need. If you are working toward a career as a lead auditor conducting combined certification audits, the lead auditor courses cover the standards in depth with a practical focus on real audit situations.
Understanding how the standards relate to each other and where their requirements diverge is fundamental to conducting a combined audit well. The guide to auditing an integrated management system covering ISO 9001, ISO 14001, and ISO 45001 together is a useful companion resource for anyone planning or conducting combined audits.













