Industry

Integrated Management System: Running 9001 + 14001 + 45001 with One Document Set

Igera Solutions Team
September 18, 2026
8 min read
Integrated Management System: Running 9001 + 14001 + 45001 with One Document Set
🎧 Listen with AI Voice

2-minute executive summary

⚡ Quick Answer in 30s

Build an IMS on the shared Annex SL structure of ISO 9001, 14001 and 45001 — one document set, fewer audit days, less duplicated paperwork.

✓ Citing current regulationsSee detailed guide below ↓

IgeraIndustria Quality Team  ·  Updated 2026-09-18  ·  9 min read

Part of the Programa 1: Audits content series  ·  clause-by-clause guides for ISO 9001, 14001, 45001, 50001 and 27001

An Integrated Management System (IMS) merges ISO 9001, ISO 14001 and ISO 45001 into a single set of policies, procedures and records instead of three parallel systems. It works because all three standards share the same Annex SL "High Level Structure" — ten identical clause numbers covering context, leadership, planning, support, operation, performance evaluation and improvement. For a small or mid-size manufacturer, that shared skeleton means one management review meeting, one internal audit programme and one document control system can legally satisfy all three certifications at once.

Why Annex SL makes integration realistic, not just theoretical

Before the 2015 revisions, ISO 9001, ISO 14001 and OHSAS 18001 (the predecessor to ISO 45001) each had their own clause structure, their own terminology, and — in practice — their own binder. Quality had one manual, environmental had another, and safety had a third. Integration meant building a bridge between three incompatible architectures, and most attempts at it produced a document map nobody could follow during an audit.

Annex SL changed that by fixing a common skeleton for every new or revised management system standard: Clause 4 Context of the Organization, Clause 5 Leadership, Clause 6 Planning, Clause 7 Support, Clause 8 Operation, Clause 9 Performance Evaluation, and Clause 10 Improvement. ISO 9001:2015, ISO 14001:2015 and ISO 45001:2018 all follow this numbering. Clause 6.1 in ISO 9001 asks you to determine risks and opportunities to quality objectives; Clause 6.1 in ISO 14001 asks the same question about environmental aspects; Clause 6.1 in ISO 45001 asks it about hazards. Same clause, same logic, different subject matter.

That structural identity is what makes a single document set defensible in front of an auditor. You are not forcing three standards into one format for convenience — you are recognising that they were written, deliberately, to fit together.

What actually gets merged — and what stays separate

Integration does not mean writing one 40-page manual that mentions quality, environment and safety in the same sentence everywhere. It means identifying which processes are genuinely generic across the three standards and merging only those, while keeping subject-specific content — legal registers, hazard inventories, product specifications — in their own place, cross-referenced from the shared core.

Process Merge into one? Why
Document control procedure (Clause 7.5) Yes Approval, version control and distribution rules don't change by subject matter
Internal audit programme (Clause 9.2) Yes One audit schedule can cover all three scopes per site visit
Management review (Clause 9.3) Yes One meeting, one agenda, one set of minutes covering all three inputs
Corrective action / nonconformity procedure (Clause 10) Yes Root cause and closure logic is identical regardless of source
Competence and training matrix (Clause 7.2) Yes One employee record can list quality, environmental and safety competencies together
Risk register — quality risks (6.1 QMS) Partially Same register format, but different risk owners and criteria per standard
Aspects and impacts register (14001) No Subject-specific content; link it from the shared risk register instead
Hazard identification and risk assessment (45001) No Requires worker participation and specific methodology (e.g. HIRA)
Legal and compliance register Partially One register, tagged by standard, is common practice — but obligations differ by subject

The practical payoff: fewer audit days, less duplicated paperwork

The business case for integration is concrete, not just tidier filing. Certification bodies price audits by auditor-days on site, and most of them — AENOR, Bureau Veritas, SGS, TÜV, DNV, DQS and LRQA among them — offer an integrated audit option where one auditor (or a small team) reviews all three standards during the same visit, following one audit plan against the shared Annex SL clauses plus the standard-specific requirements. That typically reduces the total combined audit days compared with three separate audits scheduled on different weeks, because the auditor is not re-establishing context, re-reviewing the organisational chart, or re-running the same document control sampling three times — exact savings vary by certification body and system complexity, so ask your certification body for an integrated-audit quote rather than assuming a fixed percentage.

The internal cost saving is usually larger than the external one. A quality manager who has to prepare three separate management review packs, three audit schedules and three sets of corrective action logs loses real hours every month to administrative duplication — hours that don't improve anything. Consolidating those into one system with tagged, filterable records for each standard removes that overhead without weakening any individual system's compliance.

There is a second, less obvious benefit: cross-standard visibility. A near-miss safety incident often has an environmental angle (a chemical spill) and sometimes a quality angle (a defective guard that also let bad product through). A merged corrective action log surfaces those connections; three separate logs bury them in three separate binders that nobody cross-checks.

Common mistakes when building an IMS

  • Merging documents before mapping requirements. Combine the procedures first without confirming every clause of all three standards is still addressed, and gaps appear — usually in the standard-specific clauses (14001's 6.1.2 aspects, 45001's worker participation requirements) that get diluted when writers default to quality-system language.
  • One audit checklist for everything. A generic internal audit checklist misses standard-specific evidence requirements — auditors still need to sample environmental legal compliance and safety worker consultation records separately, even inside a combined audit visit.
  • No single owner. IMS projects that report to three different department heads with no overall coordinator tend to fragment back into silos within a year of certification.
  • Ignoring the differences in Clause 6.1. The risk-based-thinking clause looks identical across the three standards but asks fundamentally different questions — quality risk to objectives, environmental aspects and impacts, and occupational hazards are not the same exercise and can't be assessed with one generic risk matrix.
  • Skipping worker/employee participation for 45001. Unlike 9001 and 14001, ISO 45001 mandates documented worker consultation and participation (Clause 5.4). Folding safety into a management-only IMS process without that consultation trail is a common major nonconformity.
  • Treating integration as a one-off project instead of an operating model. The document set needs the same document control discipline — revision history, approval, distribution — applied consistently, or it drifts back into three versions of the truth within a couple of review cycles.

A practical sequence for building the IMS

Organisations that integrate successfully tend to follow a similar order: map all three standards' requirements against the shared Annex SL clause numbers first, in a spreadsheet or matrix; identify which processes are genuinely generic (document control, internal audit, management review, corrective action, competence) versus subject-specific (aspects/impacts, hazard assessment, product requirements); write the generic processes once, with clear scope statements covering all three standards; keep subject-specific procedures separate but cross-referenced from the shared documents; and run a combined internal audit cycle that samples all three scopes using both the shared checklist items and standard-specific evidence points.

// IgeraIndustria RAG demo — IMS management review prep

Quality Manager: What open corrective actions do we have across quality, environmental and safety, and are any overdue?

IgeraIndustria: Based on your Integrated Corrective Action Log (IMS-CAR-2026, Rev 4): 6 open actions. 2 quality-related (CAR-2026-041, CAR-2026-044, both within due date). 3 environmental (CAR-2026-039 overdue by 8 days — waste segregation nonconformity from the Q2 internal audit, owner: Site Environmental Coordinator; CAR-2026-042 and CAR-2026-045 within due date). 1 safety (CAR-2026-043, within due date — guarding modification on line 4). Recommend flagging CAR-2026-039 for escalation at this quarter's management review per IMS-MR-Procedure section 4.2.

Where an IMS strains a lean team — and where AI-assisted document retrieval helps

The single biggest practical obstacle to running an integrated system well isn't writing the merged procedures — it's keeping people able to find the right answer fast when a procedure spans three standards' worth of cross-references. A shift supervisor investigating an incident needs to know, in the moment, which clause of which document applies: is this a 45001 near-miss procedure, a 14001 environmental incident report, or both? In a paper-based or shared-drive IMS, that answer often means opening three folders and reading introductions to figure out which one is relevant.

This is the exact problem an AI system that answers directly from a company's own IMS documentation solves — not by summarising ISO standards in general, but by searching the organisation's actual merged procedures, corrective action logs and risk registers, and citing the specific clause or document reference the answer came from. Ask "what's our procedure for a chemical spill in the paint booth" and the system pulls the relevant section of the integrated operational control procedure, names the document and revision number, and does not need three separate lookups across three separate systems. For a lean quality team running 9001, 14001 and 45001 together with limited headcount, that kind of source-cited retrieval is what keeps the integration a genuine efficiency gain instead of a maintenance burden that quietly reverts to three silos.

Frequently asked questions

Do all three standards need to be certified at the same time to build an IMS?

No. Many organisations build the IMS incrementally — certifying ISO 9001 first, then adding 14001 and 45001 on the shared structure as the business grows. The document architecture (shared clause numbering, one document control system) can be designed from the start even if only one standard is currently certified, which makes adding the others later far less disruptive than retrofitting three separate systems.

Can one auditor certify all three standards in a single visit?

Often yes, if the certification body offers integrated audits and the auditor (or audit team) holds competence across all three standards. Some certification bodies use a lead auditor with generalist competence plus a technical specialist for safety or environmental clauses on larger or higher-risk sites. Confirm with your certification body how they structure integrated audit teams before assuming a single-auditor visit.

Does an IMS reduce the number of nonconformities raised?

Not automatically — nonconformities depend on how well the system actually operates, not on the document architecture. What integration does reduce is duplicated administrative nonconformities (e.g., inconsistent document control practices across three separate systems), because there's only one document control procedure to get right instead of three.

Is a single management review meeting enough to cover all three standards?

Yes, provided the agenda and minutes explicitly capture every input required by each standard's Clause 9.3 — quality performance, environmental performance including compliance obligations, and safety performance including incident data and worker participation feedback. A combined agenda with separate line items per standard, reviewed in one meeting, satisfies all three as long as the minutes show each input was actually addressed.

What's the biggest reason IMS projects fail?

Merging documents without a genuine owner responsible for keeping the integration coherent over time. Initial integration projects are usually well resourced; the failure mode is drift afterward, when quality, environmental and safety teams each start maintaining their own local versions again because nobody is accountable for the shared system as a whole.

Does ISO 50001 (energy management) fit the same integration model?

Yes — ISO 50001:2018 also follows the Annex SL structure, so the same shared-clause approach (document control, internal audit, management review, corrective action) extends to energy management. Organisations running 9001, 14001, 45001 and 50001 together typically use one combined internal audit programme and one management review covering all four.

How long does it take to integrate three existing standalone systems?

This varies significantly by organisation size, document volume and how divergent the existing systems already are — there's no reliable universal timeframe to quote. A realistic planning approach is to scope the requirements-mapping exercise first, then estimate the document consolidation and internal audit cycle from there, rather than assuming a fixed duration in advance.

Disclaimer: This article is informational and does not constitute professional certification, legal or compliance advice. Integration approaches, audit structures and timelines vary by certification body and by national accreditation rules. Confirm specifics — including how your chosen certification body structures integrated audits — directly with that certification body before planning your IMS project.

Stop searching three binders for one answer. IgeraIndustria answers from your own integrated 9001 + 14001 + 45001 documentation, citing the exact clause or procedure.

See IgeraIndustria in action

Programa 1: Audits — the series that ties it together

This guide sits alongside our clause-by-clause breakdowns of ISO 9001, ISO 14001, ISO 45001, ISO 50001 and ISO 27001, each walking through Clauses 4 through 10 with sector-specific examples. If you're building or auditing an integrated system, start with the clause-by-clause series for whichever standard you're least familiar with, then come back to this guide to see how the pieces fit together.

Article reviewed by IgeraIndustria Quality Team, updated 2026-09-18. References: ISO/IEC Directives Part 1, Annex SL (High Level Structure); ISO 9001:2015; ISO 14001:2015; ISO 45001:2018; ISO 50001:2018.

#integrated management system#ISO 9001 14001 45001 integration#IMS document control#Annex SL high level structure#combined ISO audit#quality environment safety management system#integrated audit certification body#ISO integrated management system SME#Integriertes Managementsystem#ISO 9001 14001 45001#Annex SL High Level Structure#IMS Zertifizierung#kombiniertes internes Audit#Managementbewertung ISO#Dokumentenlenkung QM-System#ISO Integration Fertigung

Ask this article

IA 2026

Igera's AI answers questions citing the facts and regulations in this article

2 of 2 free queries

Suggested questions (click to test):

Diagnóstico Interactivo 60s

Technical Compliance & Industrial Operations Diagnostic

Analyze speed of access to regulations (CTE, OSH, CE) in your plant or jobsite

Pregunta 1 de 3

How do technicians and operators access safety protocols and manuals?

Was this article helpful?

⚙️IgeraIndustriaOperations Template
GUÍA DESCARGABLE (TXT)

Preventive Maintenance & ISO 9001/45001 Industrial Checklist

Floor inspection template for machine operations, failure tracking and unplanned downtime reduction.

  • Shift inspection standardization for plant operators
  • Up to 40% faster anomaly response times
  • Full traceability for ISO audits and HSE compliance

Instant download · No card · 100% spam-free

Share this article

Help spread knowledge by sharing this content with your network