Exemplar Global Certified Courses from USD 99. Ending Soon!

What Is a Combined Audit? A Practical Guide for Auditors and Quality Managers

AW

Team @ Audit Workshop

14 min read
What Is a Combined Audit? A Practical Guide for Auditors and Quality Managers

A combined audit is one of the most practical tools available to organisations that hold certification to more than one ISO standard. Instead of running separate audits for ISO 9001, ISO 14001, and ISO 45001 at different times, a combined audit covers two or more management systems in a single audit event. The same audit team, the same site visit, the same opening and closing meetings. If your organisation is already managing multiple systems and you are not yet using combined audits, you are almost certainly spending more time and money on auditing than you need to.

This article explains what a combined audit is, how it differs from an integrated audit, when it makes sense to run one, how to plan it properly, and what auditors and quality managers need to know before walking in the door.

The Definition of a Combined Audit

ISO 19011:2018 defines a combined audit as an audit conducted at a single auditee covering two or more management system standards simultaneously. The key word is simultaneously. You are not doing two separate audits back to back. You are conducting one audit that addresses the requirements of multiple standards at the same time, using a single audit team and a coordinated audit plan.

The standards being audited remain distinct. Each has its own requirements, its own clauses, its own conformity criteria. A combined audit does not blur those boundaries. It simply removes the duplication of effort that comes from auditing shared elements, such as documented information, management review, internal audit programmes, and competence, more than once.

ISO 19011 was updated in 2026 and the concept of combined auditing remains central to how modern audit programmes are structured. If you want to understand how the guidelines have evolved, the ISO 19011:2026 update is worth reviewing before planning your next audit cycle.

Combined Audit vs Integrated Audit: What Is the Difference?

These two terms are often used interchangeably, but they mean different things and the distinction matters in practice.

Combined Audit

A combined audit is conducted when an organisation has two or more separate management systems. The systems may share some common infrastructure, documented information, and processes, but they have not been formally merged into a single integrated management system. The auditor examines each standard separately, but does so in a coordinated way during a single visit. Findings are reported against the relevant standard. A nonconformity against ISO 45001 clause 6.1 is raised under ISO 45001, not against ISO 14001.

Integrated Audit

An integrated audit is conducted when an organisation has built a single integrated management system that addresses the requirements of multiple standards within one unified framework. The organisation has one policy, one set of objectives, one management review process, and one documented information structure that covers all standards. The audit reflects that integration. Rather than auditing each standard separately, the auditor follows processes and evaluates conformity against all applicable standards simultaneously.

In practice, most organisations in Australia sit somewhere between these two approaches. They may have started with ISO 9001 and added ISO 14001 or ISO 45001 later, resulting in systems that share some elements but are not fully integrated. A combined audit is usually the right approach in those situations. The integrated management system article on this site gives a good overview of what full integration actually involves.

Why Run a Combined Audit?

The practical reasons are compelling, and they apply equally to internal audits and third party certification audits.

Reduced Disruption to Operations

Every audit imposes a burden on the organisation being audited. Staff need to be available. Managers need to attend opening and closing meetings. Documents need to be pulled. When you run three separate audits across the year, that disruption happens three times. A combined audit concentrates the effort into one event. Staff are interviewed once instead of three times. The management team sits through one closing meeting instead of three.

Efficiency Gains From Auditing Common Elements Once

ISO 9001, ISO 14001, and ISO 45001 share a significant amount of common structure under the harmonised approach. Clause 4 covers context, interested parties, and scope for all three. Clause 5 covers leadership and policy. Clause 7 covers competence, awareness, and documented information. Clause 9 covers internal audit, monitoring, and management review. Clause 10 covers nonconformity and improvement.

In a combined audit, you examine these shared elements once. You review the management review records once and assess whether they meet the requirements of all three standards simultaneously. You interview the management representative once and cover all three systems in that conversation. That is a significant time saving compared to running three separate audits.

Better Value From Audit Resources

Whether you are running internal audits with your own team or engaging an external certification body, audit time costs money. Combined audits typically require fewer total audit days than separate audits for the same scope. Certification bodies calculate combined audit duration using a reduction factor that reflects the shared elements. The savings are real.

A More Coherent Picture of System Performance

When you audit systems separately, you can miss interactions between them. An issue with contractor management might be relevant to quality, environment, and safety simultaneously. In a combined audit, you are more likely to pick up these cross-system connections. You get a more complete picture of how the organisation actually functions.

When a Combined Audit Makes Sense

Not every organisation is ready for a combined audit. These are the conditions that make it work well.

The Organisation Holds Certification to Multiple Standards

This is the obvious starting point. If you are only certified to ISO 9001, a combined audit is not relevant. But if you hold ISO 9001 and ISO 45001 certificates, or all three of the main management system standards, a combined audit is worth considering for both your internal audit programme and your certification audits.

There Is a Reasonable Degree of System Integration

A combined audit works best when the systems share at least some common infrastructure. If the quality system and the safety system are completely separate, managed by different people with no shared documentation or processes, a combined audit will be harder to run efficiently. That said, even partially integrated systems benefit from combined auditing. The audit itself often reveals opportunities to share more elements.

The Audit Team Has Competence Across All Standards

This is non-negotiable. If you are running a combined audit covering ISO 9001 and ISO 45001, the audit team needs auditors who are competent in both standards. In a certification context, the certification body will assign auditors with the appropriate qualifications. For internal audits, you need to make sure your internal auditors have been trained in each standard they will be auditing. Running an internal combined audit with someone who only knows ISO 9001 will produce an incomplete result for the other standards.

Planning a Combined Audit

The planning phase is where combined audits succeed or fail. Get it right here and the audit itself runs smoothly.

Define the Scope and Objectives for Each Standard

Even though you are running one audit, each standard has its own scope and its own set of objectives. Document these clearly in your audit plan. The scope of the ISO 9001 audit may cover all processes involved in delivering the product or service. The scope of the ISO 45001 audit will cover all activities where workers are exposed to OH&S risks. These may not be identical, and your plan needs to reflect that.

Build a Combined Audit Plan That Maps Coverage

Your audit plan should show which clauses of each standard will be addressed in each session. A useful approach is to group sessions around processes rather than clauses. When you audit the procurement process, you cover ISO 9001 clause 8.4 on external providers, ISO 14001 requirements around environmental aspects of purchased materials, and ISO 45001 requirements around contractor management and procurement controls, all in the same session. This process-based approach is far more efficient than working through each standard clause by clause in sequence.

The process-based vs clause-based auditing article explains this approach in detail and is directly relevant to planning combined audits effectively.

Assign Auditor Responsibilities Clearly

In a combined audit with more than one auditor, be explicit about who is responsible for what. If you have one auditor who is strong on ISO 14001 and another who is strong on ISO 45001, structure the sessions to use those strengths. The lead auditor coordinates the overall audit, but individual team members can take the lead on specific standards or processes within their area of competence.

Prepare Checklists That Cross-Reference Requirements

Your audit checklists should be designed for the combined context. For each process or activity you audit, include questions that address the relevant requirements from each standard. A checklist for the management review session should include questions about ISO 9001 clause 9.3 inputs and outputs, ISO 14001 clause 9.3 requirements, and ISO 45001 clause 9.3 requirements, all in one document. This prevents you from missing coverage and makes the session more efficient.

Conducting a Combined Audit: Practical Considerations

Opening Meeting

Run one opening meeting that covers all standards in scope. Explain to the auditee that the audit will address ISO 9001, ISO 14001, and ISO 45001 simultaneously. Clarify that findings will be reported against the relevant standard. Make sure the right people are in the room. The management representative for quality, the environmental manager, and the WHS manager should all attend, or at least be available for their relevant sessions.

Following the Process, Not the Clause List

The most effective combined audits follow the organisation's processes from end to end, examining each process against the requirements of all applicable standards. Start with context and leadership, then move through operational processes, then performance evaluation. At each stage, ask questions that draw out evidence relevant to all standards in scope. When you are on the shop floor looking at a work area, you are simultaneously gathering evidence about product quality controls, environmental aspects and impacts, and hazard identification and risk controls.

Recording Findings Against the Correct Standard

Every finding must be attributed to the correct standard and clause. A nonconformity related to missing environmental monitoring records is raised against ISO 14001, even if you discovered it during a session that also covered quality and safety. Be precise in your documentation. Ambiguous attribution causes problems when the organisation needs to respond to findings and when the certification body reviews the audit report.

Closing Meeting

One closing meeting, covering findings from all standards. Present findings grouped by standard so the auditee can clearly understand what relates to each system. If you have found a nonconformity that has implications across multiple standards, for example, a management review that failed to address inputs required by both ISO 14001 and ISO 45001, explain that clearly and raise separate nonconformities against each standard.

Combined Audits in the Internal Audit Context

For organisations running their own internal audit programmes, combined audits are a practical necessity if you want to maintain a realistic audit schedule without overwhelming your internal audit resources.

Consider a small to medium business with ISO 9001, ISO 14001, and ISO 45001 certification. If they run separate internal audits for each standard, they need to cover the full scope of each system across the year. That might mean three separate audit programmes, three sets of checklists, and three rounds of audit reports. Most internal audit teams do not have the capacity for that.

A well-designed combined internal audit programme covers all three standards in a single annual cycle, with sessions structured around processes and departments. The total audit time is similar to running one thorough system audit, but the coverage spans all three standards. The key requirement is that your internal auditors are trained and competent in all the standards they are auditing. If your team has only completed ISO 9001 internal auditor training, they are not equipped to audit against ISO 14001 or ISO 45001 requirements.

Combined Audits in the Certification Context

Most accredited certification bodies offer combined certification audits for organisations holding multiple certificates. The process works as follows.

The certification body assigns an audit team with competence across all standards in scope. The audit duration is calculated based on the scope and size of the organisation, with a reduction applied to reflect the shared elements. The audit is conducted as a single event, typically over two to five days depending on the size and complexity of the organisation. Findings are reported against each standard separately. Certificates are issued separately for each standard, even though the audit was conducted as a single event.

For organisations approaching their first combined certification audit, the preparation process is similar to preparing for separate audits, but the focus shifts to making sure the shared elements of the system are genuinely integrated and not just duplicated across separate documents. Auditors will look for consistency. If the management review for quality says one thing and the management review for environment says something different about the same period, that inconsistency will attract scrutiny.

Common Mistakes in Combined Audits

Treating It as Three Separate Audits Conducted Simultaneously

This defeats the purpose. If your audit plan simply runs through ISO 9001 clauses on day one, ISO 14001 clauses on day two, and ISO 45001 clauses on day three, you have not run a combined audit. You have run three audits with a shared opening meeting. The efficiency gains come from genuinely integrating the audit approach around processes.

Insufficient Auditor Competence

Assigning an auditor to a combined audit who is only qualified in one of the standards is a serious problem. They will miss requirements from the other standards, produce incomplete findings, and potentially give the auditee false confidence about conformity. Every auditor on the team must be competent in the standards they are responsible for auditing.

Vague Finding Attribution

Findings that say something like

nonconformity against quality and safety requirements
without specifying the exact clause of each standard are not useful. Be precise. Each finding gets a standard, a clause, and a clear description of the evidence.

Neglecting Standard-Specific Requirements

The shared elements of the harmonised structure are easy to cover in a combined audit. The standard-specific requirements are where gaps appear. ISO 45001 has unique requirements around worker participation and consultation that have no direct equivalent in ISO 9001 or ISO 14001. ISO 14001 has specific requirements around environmental aspects and impacts and compliance obligations. Make sure your combined audit plan includes dedicated coverage of these standard-specific requirements, not just the shared clauses.

Building Auditor Competence for Combined Audits

If you want to run effective combined audits, whether internal or as a lead auditor in a certification context, you need training across all the standards you intend to audit. That means understanding the specific requirements of ISO 9001, ISO 14001, and ISO 45001, not just their shared structure.

Audit Workshop offers internal auditor and lead auditor training across all three of these standards. If you are an internal auditor looking to expand your scope from quality into environment and safety, the internal auditor courses for ISO 14001 and ISO 45001 will give you the knowledge and audit skills you need. If you are working toward a career as a lead auditor conducting combined certification audits, the lead auditor courses cover the standards in depth with a practical focus on real audit situations.

Understanding how the standards relate to each other and where their requirements diverge is fundamental to conducting a combined audit well. The guide to auditing an integrated management system covering ISO 9001, ISO 14001, and ISO 45001 together is a useful companion resource for anyone planning or conducting combined audits.

Frequently Asked Questions

A combined audit covers two or more separate management systems in a single audit event, with findings reported against each standard individually. An integrated audit is conducted where the organisation has built a single unified management system that addresses multiple standards within one framework. In practice, combined audits are more common because most organisations have separate systems that share some elements rather than a fully integrated system.
Start Learning

Ready to Build Real Audit Skills?

Join practitioners training with ISO auditors who've conducted 500+ external certification audits.

ISO 9001:2015 Lead Auditor

Quality Management Systems (QMS)

Lead AuditorSelf-Paced Online
Digital Badge
Limited timeUSD 199(original price USD 789)
ISO 45001:2018 Lead Auditor

Occupational Health and Safety Management Systems (OHSMS)

Lead AuditorSelf-Paced Online
Digital Badge
Limited timeUSD 199(original price USD 789)
ISO 14001:2026 Lead Auditor

Environmental Management Systems (EMS)

Lead AuditorSelf-Paced Online
Digital Badge
Limited timeUSD 199(original price USD 789)
Exemplar Global Recognised Training Provider digital badge

Audit Workshop is an Exemplar Global Recognised Training Provider

Globally Recognised, Certified Training

Pass an Exemplar Global Certified course and you earn a Certificate of Attainment and an Exemplar Global digital badge. Audit Workshop graduates can apply for third-party Personnel Certification through Exemplar Global.

  • 12 months of Graduate certification
  • Access to Exemplar Global Community
  • Access to self-coaching assessment
  • Access to webinars, events, and online resources
Learn Anytime

No fixed schedule. Start, pause, and pick up exactly where you left off.

Instant Certificate

Download your digital certificate the moment you complete the course.

Practical Content

Every lesson is built from real-world ISO auditing experience.

Lifetime Access

Course materials are yours to keep and revisit long after you complete.