I've walked more than 200 clients through certification audits, and the question I hear most often isn't "how do we pass ISO 9001?" It's "why do we have three separate binders, three separate audit weeks, and three separate management review meetings for quality, environment, and safety when half the content is identical?" It's a fair question. In my view, running ISO 9001, ISO 14001, and ISO 45001 as three unconnected systems is one of the most common — and most expensive — mistakes I see in mid-size manufacturing and service organizations.
An Integrated Management System, or IMS, isn't a certification. It's an architecture decision. You still get three separate certificates and three separate scopes of conformance, but you run them through one set of processes, one document control system, one internal audit program, and one management review. Done right, it cuts administrative overhead, reduces audit fatigue, and — this is the part clients care about most — it makes the connections between quality problems, environmental risk, and worker safety visible instead of buried in three different filing cabinets.
This guide walks through what an IMS actually is, why the three standards integrate so cleanly, and the step-by-step process I use with clients to build one from scratch or consolidate three existing systems into one.
What Is an Integrated Management System (IMS)?
An IMS is a single management framework that satisfies the requirements of multiple ISO standards simultaneously — in this case ISO 9001:2015 (quality management), ISO 14001:2015 (environmental management), and ISO 45001:2018 (occupational health and safety management). Instead of maintaining three parallel document sets, three risk registers, and three internal audit schedules, you maintain one integrated set that addresses all three standards' requirements at once, with standard-specific content layered in only where the requirements genuinely diverge.
ISO 9001, ISO 14001, and ISO 45001 all share the same ten-clause Annex SL structure, which is precisely what makes a single integrated management system possible rather than three parallel ones. That shared structure — formally called the High Level Structure (HLS) — was introduced by ISO in 2012 specifically to make multi-standard integration easier, and it now underpins more than 40 different management system standards, from ISO 27001 (information security) to ISO 22301 (business continuity).
Why Integrate ISO 9001, 14001, and 45001?
The business case is straightforward once you've seen it work. Here's what I tell prospective clients who are on the fence:
- Fewer audit days. A certification body auditing an integrated system typically combines the surveillance visits into one coordinated audit week instead of three separate ones, which in my experience trims 20–30% off total annual audit costs.
- One risk register, three lenses. Clause 6.1 in all three standards requires you to determine risks and opportunities. When you run this as one process, a single hazard — say, a solvent used on the production floor — gets evaluated for quality impact, environmental release risk, and worker exposure in the same sitting, instead of three separate teams rediscovering the same hazard independently.
- One management review. Leadership sits through one meeting instead of three, and they actually see the cross-connections — a supplier quality issue that's also an environmental compliance risk, for instance.
- Lower documentation burden. Instead of three quality manuals, you maintain one integrated manual with standard-specific annexes only where genuinely necessary.
Organizations that consolidate three certifications into a single audited management system typically report meaningfully lower total conformance costs within the first renewal cycle, because combined audits, shared document control, and one internal audit calendar eliminate the redundant labor of running parallel systems. I've seen this hold true across manufacturing, GMP-adjacent, and service-sector clients alike — the savings compound because the redundancy was never in the requirements, it was in how organizations chose to organize their response to them.
The Shared Structure That Makes Integration Possible
Before you touch a single procedure, you need to understand why these three standards integrate so cleanly. All three follow the Annex SL high-level structure: the same ten clauses, largely the same core vocabulary (context of the organization, interested parties, risk-based thinking, competence, documented information), and the same plan-do-check-act logic running underneath.
Here's how the clause structure maps across the three standards:
| Clause | ISO 9001:2015 (Quality) | ISO 14001:2015 (Environmental) | ISO 45001:2018 (OH&S) |
|---|---|---|---|
| 4. Context of the Organization | Internal/external issues, interested parties, QMS scope | Environmental conditions, interested parties, EMS scope | Worker/stakeholder needs, OH&S scope |
| 5. Leadership | Quality policy, roles & responsibilities | Environmental policy, roles & responsibilities | OH&S policy, worker participation & consultation |
| 6. Planning | Risks/opportunities, quality objectives | Environmental aspects/impacts, compliance obligations, objectives | Hazard identification, risk assessment, legal requirements |
| 7. Support | Resources, competence, awareness, communication, documented info | Same core requirements, environmental focus | Same core requirements, plus worker consultation emphasis |
| 8. Operation | Operational planning, design, production controls | Operational controls, emergency preparedness | Operational controls, emergency preparedness, contractor management |
| 9. Performance Evaluation | Monitoring, internal audit, management review | Same, environmental compliance evaluation added | Same, incident investigation feeds in |
| 10. Improvement | Nonconformity/corrective action, continual improvement | Same | Same |
The differences that matter live almost entirely in Clause 6 (what risks you're planning for) and Clause 8 (what operational controls you actually run). Everything else — leadership commitment, competence, document control, internal audit mechanics, management review cadence — can be built once and shared across all three.
How to Build Your IMS: A Step-by-Step Process
Here's the sequence I use with clients, whether they're building all three systems from scratch or consolidating existing standalone certifications.
Step 1: Run an Integrated Gap Assessment
Don't assess the three standards separately — you'll end up with three disconnected findings lists that don't tell you where the real integration opportunities are. Instead, run one gap assessment against the shared Annex SL structure and flag, clause by clause, what exists, what's missing, and which requirement belongs to which standard. This is the single highest-leverage step in the whole project, because it tells you whether you're building a new system or consolidating three existing ones — a very different scope of work. I generally recommend clients start with our ISO 9001 gap analysis checklist as the backbone, then layer environmental and safety-specific criteria on top of it, since quality tends to be the most mature system in most organizations and gives you a stable foundation to build from.
Step 2: Define One Integrated Scope and Context Statement
Write a single Clause 4 context-of-the-organization statement that captures internal and external issues, interested parties, and system scope for quality, environmental, and safety simultaneously. Your interested-parties list will overlap heavily — regulators, customers, employees, neighbors — but each standard weights them differently. Quality cares most about customers; environmental cares most about regulators and community; safety cares most about your own workforce. Name that explicitly rather than pretending one generic list covers it.
Step 3: Build One Integrated Manual and Procedure Set
Rather than maintaining ISO 9001, 14001, and 45001 procedures as separate documents, write unified procedures for anything that's genuinely shared: document control, competence and training, internal audit, corrective action, management review, and communication. Keep standard-specific procedures — environmental aspects/impacts registers, hazard identification and risk assessment (HIRA), calibration and product conformity — as distinct documents that plug into the shared framework. A good rule of thumb: if the procedure answers "how do we control information" or "how do we run a meeting," integrate it. If it answers "what specifically are we controlling," keep it standard-specific.
Step 4: Align Risk Management Across All Three Disciplines
This is where integration actually pays off. Build one risk and opportunity register with three tagging fields — quality impact, environmental impact, safety impact — instead of three separate registers. A machine that's due for a bearing replacement is a quality risk (scrap and rework), an environmental risk (potential lubricant spill), and a safety risk (equipment failure injury) all at once. When one team owns that risk holistically, the mitigation plan actually addresses all three exposures instead of three separate teams independently deciding the machine "isn't their problem."
Step 5: Integrate Your Internal Audit Program
Train your internal auditors to audit all three standards in a single pass through a process, rather than sending three separate auditors through the same production line in three separate weeks. A process-based internal audit — "audit the receiving process" rather than "audit the ISO 9001 requirements" — naturally captures quality, environmental, and safety findings from that process in one visit. This is usually the change that generates the most immediate goodwill on the shop floor, because operators stop getting audited three times a year for the same activity.
Step 6: Run One Integrated Management Review
Combine your Clause 9.3 management review into a single meeting with three lenses on the agenda: quality performance (customer complaints, nonconformities, audit results), environmental performance (compliance obligations, incidents, aspect/impact changes), and safety performance (incident rates, near-misses, worker consultation outcomes). Leadership sees the whole picture in one sitting, which in my experience is where the real strategic decisions — capital investment, staffing, supplier changes — actually get made, because the tradeoffs between the three disciplines are visible in the same conversation instead of siloed across three meetings months apart.
Step 7: Decide Your Certification Strategy
You have two paths to certification once the system is built:
- Combined audit — one certification body audits all three standards during the same visit, issuing three certificates (or one multi-standard certificate, depending on the body) off a single audit trail. This is the lower-cost, lower-disruption path for most organizations.
- Sequential/staged audit — certify one standard first (typically ISO 9001, since it's usually the most mature), then add 14001 and 45001 in subsequent cycles once the integrated framework is proven. This spreads cost and organizational change over time, which matters if you're integrating into a system that doesn't have quality maturity yet.
I generally recommend the combined path for organizations that already hold at least one certification and are adding the other two, and the staged path for organizations building all three from zero. Attempting to build and certify all three simultaneously from a standing start is the single most common cause of the failed first audits I get called in to fix.
Common Pitfalls When Integrating Multiple ISO Standards
A few mistakes show up again and again in the integration projects I've inherited from other consultants or in-house teams:
- Treating the manual merge as the whole project. Combining three manuals into one document without actually integrating the risk register, audit program, and management review just relocates the redundancy — it doesn't remove it.
- Losing standard-specific nuance in the name of simplicity. ISO 45001's emphasis on worker participation and consultation (Clause 5.4) has no direct equivalent in 9001 or 14001. Flatten it into a generic "communication procedure" and you'll fail that specific clause on audit.
- Assigning ownership to one department. The most durable IMS programs I've built have a single management representative accountable for the integrated system, but with named co-owners for environmental and safety who aren't quality staff wearing extra hats. Quality people who inherit environmental and safety responsibility without genuine subject-matter depth tend to under-serve both.
- Skipping the legal register consolidation. Environmental compliance obligations and OH&S legal requirements often live in completely different tracking systems before integration. Merging them into one legal/compliance register, tagged by standard, is tedious but non-negotiable — auditors test this specifically.
How Long Does It Take, and What Does It Cost?
For an organization building all three from scratch, I typically scope 9–14 months from kickoff to triple certification, depending on operational complexity and how many locations are in scope. For an organization consolidating three existing standalone certifications into an integrated system, 4–6 months is realistic, since the underlying conformance already exists — you're restructuring the architecture, not building new controls.
Cost scales with headcount, site count, and process complexity far more than with the number of standards involved — integrating a second and third standard onto an existing framework typically adds far less cost than the first standard did, because the shared infrastructure (document control, audit program, management review) is already built. That's the entire economic argument for integrating rather than bolting on separate systems one at a time.
Frequently Asked Questions
Can you get ISO 9001, 14001, and 45001 certified at the same time?
Yes. Most accredited certification bodies offer combined or integrated audits covering all three standards in a single visit, provided your management system genuinely addresses the requirements of each. The audit typically takes longer per day than a single-standard audit, but far less total time than three separate audit cycles.
Do I need three separate manuals for an integrated management system?
No. Best practice is one integrated manual covering shared clauses (leadership, context, support, improvement) with standard-specific annexes or procedures for content that genuinely diverges — environmental aspects/impacts, hazard identification and risk assessment, and product/service conformity requirements.
What's the difference between ISO 45001 and OHSAS 18001 for integration purposes?
ISO 45001 replaced OHSAS 18001 in 2021 and, unlike its predecessor, was built on the Annex SL high-level structure from the start. That makes ISO 45001 dramatically easier to integrate with ISO 9001 and 14001 than OHSAS 18001 ever was — if your organization is still running OHSAS 18001, migrating to ISO 45001 should happen before, not after, you attempt integration.
Do I need a separate management representative for each standard?
Not necessarily, but I recommend against a single person owning all three without support. A common and effective model is one integrated management system representative accountable to leadership, with named subject-matter owners for environmental and safety who bring genuine domain expertise those disciplines require.
How much does an integrated management system save compared to three separate systems?
Most of the savings come from combined audits and shared administrative infrastructure — document control, internal audit programs, and management review — rather than from any reduction in the underlying conformance work. Organizations I've worked with typically see the clearest savings starting at the first renewal cycle, once the integrated audit program and combined certification cycle are fully in place.
If you're weighing whether to integrate now or later, start with a clause-by-clause gap assessment against all three standards before you touch a single procedure — it's the one step that tells you whether you're building a new system or consolidating three existing ones, and it changes almost everything downstream. My team at Certify Consulting runs these assessments regularly for clients moving from standalone to integrated certification, and we've maintained a 100% first-time audit pass rate across more than 200 engagements doing exactly this kind of work.
Last updated: 2026-07-28
Jared Clark
Principal Consultant, Certify Consulting
Jared Clark is the founder of Certify Consulting, helping organizations achieve and maintain compliance with international standards and regulatory requirements.