Exemplar Global Certified Courses from USD 99. Ending Soon!

What Is an Integrated Audit? A Plain English Guide for Auditors

AW

Team @ Audit Workshop

13 min read
What Is an Integrated Audit? A Plain English Guide for Auditors

An integrated audit is a single audit that evaluates two or more management systems at the same time, using one audit team, one audit plan, and one set of findings. Instead of running a separate ISO 9001 audit one month and an ISO 45001 audit the next, you combine them into one coordinated exercise. The result is less disruption for the organisation, less time spent preparing, and a more coherent picture of how the management systems actually interact in practice.

If your organisation holds certification to more than one ISO standard, or if you are an auditor building skills across quality, environment, and safety, understanding integrated audits is essential. This article explains what an integrated audit is, how it differs from a combined audit, when it makes sense to run one, how to plan it, and what challenges you are likely to encounter.

The Difference Between an Integrated Audit and a Combined Audit

These two terms are often used interchangeably, but they describe different approaches. Getting the distinction right matters when you are planning an audit programme or discussing scope with a certification body.

Combined Audits

A combined audit audits two or more management systems at the same organisation at the same time, but treats each standard separately. The audit team works through the requirements of ISO 9001, then ISO 14001, then ISO 45001 as distinct bodies of requirements. There may be some shared administration, like a single opening meeting, but the audit trails remain largely separate. Each standard gets its own checklist, its own evidence, and its own findings.

Integrated Audits

An integrated audit goes further. It audits the management systems as a unified whole, following processes rather than standards. When you walk through a manufacturing operation, for example, you gather evidence against quality, environmental, and safety requirements simultaneously. You ask one question that covers multiple standards at once. You follow one process thread and pick up conformity evidence for all three systems as you go.

The practical difference is significant. A combined audit might take two days and feel like two audits bolted together. A well-executed integrated audit of the same scope might take one and a half days and produce richer, more connected findings because you are looking at the whole system, not three fragments of it.

ISO 19011 acknowledges both approaches. If you want to understand the broader framework that governs how audit programmes are structured, the article on what is an integrated management system gives useful context on why organisations choose to unify their systems in the first place.

Why Organisations Run Integrated Audits

The motivation is almost always practical. Audits take time, and time costs money. Every hour an operations manager spends being interviewed by an auditor is an hour not spent running operations. When an organisation holds three certifications, running three separate internal audits every year creates real fatigue across the business.

Reduced Audit Burden

The most immediate benefit is fewer audit days. Common clauses across ISO 9001, ISO 14001, and ISO 45001 such as context of the organisation, leadership, documented information, internal audit, and management review do not need to be audited three times. In an integrated audit, you cover those elements once and apply the evidence across all three standards.

More Realistic Picture of the System

Management systems do not operate in separate silos. A procurement decision affects quality, environmental impact, and safety simultaneously. When you audit procurement as a single process, you see how all three systems interact. You are more likely to spot systemic weaknesses that would be invisible if you only looked through one lens at a time.

Better Use of Auditor Time

For internal auditors especially, integrated audits make better use of limited resources. Most organisations cannot afford a dedicated quality auditor, a separate environmental auditor, and a separate safety auditor. A competent internal auditor trained across all three standards can deliver more value in less time through an integrated approach.

Alignment with How the Business Actually Works

Processes do not care which standard they belong to. A welding process has quality requirements, environmental controls for fumes and waste, and safety controls for arc flash and fumes. Auditing it as one process rather than three separate visits reflects how the work actually happens and makes the audit more meaningful to the people being audited.

When Integrated Audits Make Sense and When They Do Not

Integrated audits are not always the right choice. They work best in specific conditions.

When They Work Well

  • The organisation has a genuinely integrated management system, not three separate systems that happen to coexist
  • The audit team has competence across all standards being audited
  • The processes being audited are genuinely shared across the standards
  • The organisation is experienced with audits and can manage the pace of an integrated exercise
  • The certification body agrees to the integrated approach for external audits

When They Are More Difficult

  • The management systems are genuinely separate, with different owners, different documentation, and no shared processes
  • The auditor only holds competence in one or two of the standards
  • The organisation is new to certification and still learning each system individually
  • One standard requires significantly more technical depth, for example, a complex environmental compliance situation that needs dedicated attention

If the systems are not actually integrated, running an integrated audit can create confusion. You end up forcing connections that do not exist and missing genuine gaps because you are trying to cover too much at once.

How to Plan an Integrated Audit

Planning is where integrated audits succeed or fail. The temptation is to take three separate checklists and merge them into one document. That approach rarely works well in practice.

Start With Processes, Not Clauses

Map out the key processes in the organisation first. For a construction company, that might be: tendering, mobilisation, site execution, subcontractor management, inspection and testing, and demobilisation. For each process, identify which standards have requirements that apply. Then build your audit trail around the processes, not the clause numbers.

This is the core discipline of process-based auditing applied across multiple standards at once. The article on auditing an IMS across ISO 9001, 14001 and 45001 together goes into the practical mechanics of this in detail.

Map Common Clauses First

ISO 9001, ISO 14001, and ISO 45001 all share the same high level structure. Clauses 4 through 10 cover the same topics across all three standards. When you are planning an integrated audit, identify which common clauses you will cover once and record evidence against all three standards simultaneously. Context, leadership, planning, support, operations, performance evaluation, and improvement are all candidates for this treatment.

Standard-specific requirements then get their own dedicated time. Environmental aspects and impacts, legal compliance registers, hazard identification, and quality-specific operational controls all need focused attention that cannot be shared across standards.

Build an Integrated Audit Plan

Your audit plan should show time allocations by process, not by standard. A session labelled Procurement Process covers clause 8.4 of ISO 9001, operational control under ISO 14001, and procurement requirements under ISO 45001 simultaneously. The plan should note which standards are being covered in each session so the auditee knows what to prepare.

Assign Audit Team Responsibilities

If you are running an integrated audit with a team, be explicit about who leads each process session and who covers which standard requirements. In a two-person team, one auditor might focus primarily on quality and safety evidence while the other focuses on environmental evidence, but both follow the same process thread. Debrief after each session to compare notes before moving on.

Auditor Competence for Integrated Audits

This is the most significant constraint. An integrated audit is only as good as the auditor's competence across all standards being audited. You cannot effectively audit ISO 45001 requirements if you do not understand what hazard identification and operational controls actually require. You cannot audit ISO 14001 aspects and impacts if you cannot recognise what an environmental aspect looks like in an operational context.

What Competence Is Required

ISO 19011 is clear that auditors must have the knowledge and skills relevant to the management systems being audited. For an integrated audit covering ISO 9001, ISO 14001, and ISO 45001, that means the auditor needs genuine working knowledge of all three standards, not just a surface-level familiarity.

In practice, most experienced internal auditors who have worked across quality, environment, and safety functions can develop this competence. It does not require three separate lead auditor qualifications, but it does require deliberate study and practical experience with each standard.

Specialist Technical Knowledge

Some industries require technical expertise beyond standard knowledge. Auditing a chemical plant's environmental management system requires understanding of chemical handling, spill containment, and emissions monitoring. If your audit team does not have that knowledge, you may need a technical expert to support the integrated audit, even if the management system elements can be covered by the core team.

What an Integrated Audit Looks Like in Practice

Consider a civil construction company certified to ISO 9001, ISO 14001, and ISO 45001. Here is how an integrated internal audit of their site operations might flow.

Opening Meeting

One opening meeting covers all three standards. The auditor explains the scope, confirms the processes to be covered, and notes that the audit will assess conformity across quality, environmental, and safety requirements simultaneously. The site manager, quality manager, and HSE manager are all present.

Document Review

The auditor reviews the site-specific management plan, which in a well-integrated system is a single document covering quality, environmental, and safety requirements for the project. Evidence gathering covers documented information requirements across all three standards in one sitting.

Site Walk and Process Interviews

Walking the site, the auditor observes earthworks operations. In a single observation, they assess: whether inspection and test points are being followed (quality), whether erosion and sediment controls are in place and effective (environment), and whether plant operators are following safe work method statements and wearing required PPE (safety). One walk, three standards.

Interviewing the site supervisor, the auditor asks questions that draw out evidence across all three areas. Rather than returning three times with three different checklists, the conversation covers competence, awareness, operational controls, and incident reporting in one sitting.

Findings and Closing Meeting

Findings are presented by process, not by standard. A nonconformity might reference both ISO 9001 clause 8.1 and ISO 14001 clause 8.1 if the same operational control failure affects both systems. This approach makes findings more meaningful to the business because they reflect real operational failures rather than abstract clause references.

Common Challenges in Integrated Audits

Even experienced auditors find integrated audits demanding. Here are the challenges that come up most often.

Losing Track of Coverage

When you are following a process thread across three standards simultaneously, it is easy to realise at the end of the day that you covered quality and safety thoroughly but barely touched environmental requirements. Build a coverage matrix into your working papers that you update after each session. This keeps you honest about gaps before it is too late to address them.

Auditee Confusion

Some auditees find it disorienting when the auditor jumps between quality, environmental, and safety questions in the same conversation. Manage this by being transparent. Tell the auditee at the start of each session which areas you will be covering and why. Most people adapt quickly once they understand what is happening.

Nonconformity Attribution

When you raise a finding, you need to be precise about which standard and clause it relates to. A failure to control a subcontractor might be a nonconformity against ISO 9001 clause 8.4, ISO 14001 clause 8.1, and ISO 45001 clause 8.1.4.2 simultaneously. Document each reference clearly. Do not bundle them into a vague finding that references multiple clauses without explaining what the actual failure was against each one.

Time Pressure

Integrated audits can feel rushed if not planned carefully. The efficiency gains are real, but they do not mean you can cover the same content in half the time. Be realistic about what can be covered in a day and prioritise based on risk. High-risk processes deserve more time regardless of which standard they fall under.

Integrated Audits and Certification Bodies

If your organisation is seeking or maintaining third-party certification across multiple standards, discuss the integrated approach with your certification body early. Most accredited certification bodies are comfortable with combined and integrated audit approaches, and many actively encourage them for organisations with mature integrated management systems.

The certification body will still need to ensure their audit team has competence across all standards being audited. In practice, this often means a lead auditor with multi-standard competence, or a team where different members hold competence in different standards. The audit report will still address each standard's requirements individually, even if the evidence was gathered through an integrated process.

If you are building your internal audit programme and want to understand how to structure it for multiple standards, the article on how to integrate management systems covers the system design decisions that make integrated auditing easier.

Building Your Skills for Integrated Auditing

Becoming effective at integrated audits takes time and deliberate practice. The foundation is solid competence in each individual standard. You cannot integrate what you do not understand separately. Start by building genuine depth in one standard, then expand to the others.

Practical experience matters more than theoretical knowledge here. The best way to develop integrated audit skills is to shadow an experienced auditor conducting an integrated audit, then conduct your own with oversight. Pay attention to how they move between standards within a single process conversation, how they structure their working papers, and how they present multi-standard findings clearly.

At Audit Workshop, our IMS Lead Auditor training covers auditing across ISO 9001, ISO 14001, and ISO 45001 as an integrated discipline. If you are working toward lead auditor credentials or want to build genuine multi-standard audit competence, that course is designed for exactly this purpose. Our founder Dilawar Laghari has conducted hundreds of external audits across all three standards, and the training reflects what integrated auditing actually looks like in the field, not just in theory.

Frequently Asked Questions

A combined audit covers multiple standards at the same organisation at the same time but treats each standard separately, with distinct checklists and audit trails. An integrated audit goes further by auditing the management systems as a unified whole, following processes rather than standards and gathering evidence against multiple standards simultaneously within each process session. Integrated audits tend to be more efficient and produce more connected findings, but they require greater auditor competence and work best when the management systems are genuinely integrated.
Start Learning

Ready to Build Real Audit Skills?

Join practitioners training with ISO auditors who've conducted 500+ external certification audits.

ISO 9001:2015 Lead Auditor

Quality Management Systems (QMS)

Lead AuditorSelf-Paced Online
Digital Badge
Limited timeUSD 199(original price USD 789)
ISO 45001:2018 Lead Auditor

Occupational Health and Safety Management Systems (OHSMS)

Lead AuditorSelf-Paced Online
Digital Badge
Limited timeUSD 199(original price USD 789)
ISO 14001:2026 Lead Auditor

Environmental Management Systems (EMS)

Lead AuditorSelf-Paced Online
Digital Badge
Limited timeUSD 199(original price USD 789)
Exemplar Global Recognised Training Provider digital badge

Audit Workshop is an Exemplar Global Recognised Training Provider

Globally Recognised, Certified Training

Pass an Exemplar Global Certified course and you earn a Certificate of Attainment and an Exemplar Global digital badge. Audit Workshop graduates can apply for third-party Personnel Certification through Exemplar Global.

  • 12 months of Graduate certification
  • Access to Exemplar Global Community
  • Access to self-coaching assessment
  • Access to webinars, events, and online resources
Learn Anytime

No fixed schedule. Start, pause, and pick up exactly where you left off.

Instant Certificate

Download your digital certificate the moment you complete the course.

Practical Content

Every lesson is built from real-world ISO auditing experience.

Lifetime Access

Course materials are yours to keep and revisit long after you complete.