Integrated Management Systems — Multiple Standards, One System
You are managing ISO 9001 and ISO 14001 as two separate programs. Or you are about to add ISO 45001 to an existing quality system and do not know where it fits. Or you have three certifications, three audit programs, three management reviews, and three corrective action registers — and none of them talk to each other.
Some organizations call this multi-standard ISO management; whatever the name, it does not have to work this way.
At Wintersmith Advisory, integration is not something we solve after the fact. It is designed into the system from the beginning.
The Problem With Running Standards in Parallel
Every ISO management system standard requires the same core infrastructure. Document control. Internal audit. Corrective action. Management review. Risk-based thinking. Continual improvement. The clause numbers differ across standards. The underlying requirements are the same.
Organizations that certify to multiple standards sequentially — ISO 9001 first, then ISO 14001 a few years later, then ISO 45001 — frequently build separate systems for each. Separate document hierarchies. Separate audit schedules. Separate corrective action logs. Separate management review meetings. The same information gets entered into multiple systems. The same processes get audited multiple times. The same leadership team sits through multiple reviews covering the same organizational context from different angles.
None of that duplication adds value. All of it adds cost — in management time, in audit fees, in the organizational overhead of maintaining infrastructure that does not need to exist three times.
The integrated management system approach builds the shared infrastructure once and runs all applicable standards through it. The result is a system that is simpler to maintain, less expensive to audit, and easier for your people to understand — because there is one system, not several.
What Integration Actually Means
Integration is not the same as combination. Combining standards means stacking them — taking separate programs and putting them in the same binder. The documents are adjacent but the systems are not connected. Integration means building a single management system architecture where shared elements are truly shared — designed, owned, and operated once — and standard-specific elements are modular additions within the shared structure.
The shared elements that every ISO management system standard requires break down into a few groups:
Organizational context, interested parties, leadership commitment, policy, and objectives and planning across the system
Support functions such as document control and competence management, shared across every applicable standard
Operational planning and control processes, designed once and reused across all certified frameworks
Performance evaluation through internal audit and management review, and continual improvement through corrective action
These elements do not need to be duplicated. They need to be designed in a way that serves all applicable standards simultaneously.
The standard-specific elements — environmental aspects and impacts for ISO 14001 Consultant, hazard identification and risk assessment for ISO 45001 Consultant, information security risk treatment for ISO 27001 Consultant, and IT service governance for ISO 20000 — are added as defined modules within the shared architecture. They connect to the shared infrastructure rather than duplicating it.
The practical result is that your internal audit program runs one cycle that covers all applicable standards. Your management review covers all applicable standards in a single meeting with a single structured agenda. Your corrective action process handles nonconformities regardless of which standard they originate from. Your document control system manages all system documentation under one framework.
Which Combinations Make Sense
Not every combination of standards is natural, and the right architecture depends on your industry, your operations, and your customer requirements.
Quality, Environment, and Safety — ISO 9001, ISO 14001, ISO 45001
This is the most common integration for manufacturing, construction, and industrial organizations. The three standards share the most infrastructure, are published in a common high-level structure specifically designed to facilitate integration, and are frequently required together by customers and regulators in industrial sectors. Combined audits — where a single certification body audits all three standards in a single visit — are widely available and significantly reduce total audit days and fees. Most organizations begin this path with ISO 9001 Consultant support before layering in the other two.
Quality and Information Security — ISO 9001 and ISO 27001
This combination is increasingly common for technology companies, professional services firms, and organizations that handle sensitive client data alongside quality management obligations. The standards have compatible architectures and share document control, internal audit, corrective action, and management review requirements. Organizations pursuing both benefit from building a single integrated system rather than running a quality system and a separate information security management system.
Aerospace Quality and Cybersecurity — AS9100 and CMMC
This combination applies to aerospace and defense organizations that hold AS9100 certification and have CUI handling obligations under CMMC. AS9100 Certification Consultant and CMMC 2.0 Compliance Consulting have different focus areas but substantial infrastructure overlap — document control, corrective action, internal audit, risk management, and supplier controls all appear in both frameworks. Building a shared architecture reduces duplication and makes CMMC remediation more manageable for organizations with an existing AS9100 system.
Medical Device Quality and Information Security — ISO 13485 and ISO 27001
Digital health companies, health IT organizations, and medical device companies with software components increasingly need both. ISO 13485 Consultant Services governs the quality management system for the device. ISO 27001 governs the information security management system for the software, data, and infrastructure. The standards have compatible structures and can be integrated efficiently for organizations that need both.
Broader Integration — ISO 22301, ISO 42001, and ISO 20000
Business continuity management under ISO 22301 integrates naturally into existing frameworks, particularly for organizations where continuity obligations are regulatory or contractual. AI management under ISO 42001 is increasingly relevant for organizations that already hold ISO 27001 and are adding AI governance obligations. IT service management under ISO 20000 follows the same pattern for technology-driven organizations layering service governance on top of an existing system. Each adds standard-specific requirements to a shared infrastructure rather than a parallel one.
The Architecture Decision — Where Most Organizations Get It Wrong
The most common mistake in multi-standard management is making the integration decision too late. Organizations certify to ISO 9001 with a system that was designed as a standalone quality management system — specific structure, specific document hierarchy, specific processes. When they add ISO 14001 two years later, the existing system does not accommodate it cleanly. The result is a retrofit that works but is messier than it needs to be.
The cleaner approach is to design for integration from the start — even if you are only certifying to one standard initially. A system built with the high-level structure and modular architecture that facilitates integration is no more complex to implement for one standard, and it is significantly easier to extend when a second or third standard is added.
For organizations that already have standalone certified systems and are adding standards, the question is whether to retrofit or rebuild. Retrofitting is faster but less clean; rebuilding takes longer but produces a system that is genuinely integrated. The right answer depends on how mature the existing system is and how many additional standards are being added.
Common Gaps in Multi-Standard Organizations
Most multi-standard organizations share the same four gaps, regardless of industry:
Management review: separate reviews per standard miss cross-standard patterns and produce disconnected decisions
Internal audit: independent programs create inconsistent findings and unnecessary burden for process owners audited multiple times
Corrective action: fragmented logs across systems hide patterns that only appear when nonconformities are analyzed together
Document control: separate hierarchies and approval processes manage the same organizational information in triplicate
An integrated system closes all four by design — one review, one audit cycle, one corrective action process, and one document control structure serving every applicable standard.
How We Design and Implement Integrated Systems
We approach integrated management system work differently from single-standard implementation — because the design decisions made early have long-term consequences for how maintainable and auditable the system is.
Engagements move through the same four phases regardless of how many standards are in scope:
Discovery and architecture: map current certified systems against integration opportunities and shared infrastructure requirements
Implementation: build standard-specific modules within the shared architecture, in sequence or in parallel
Certification and audit coordination: prepare evidence and combined-audit scheduling across every applicable standard
Optimization: monitor consolidated KPIs and refine the system through ongoing surveillance and management review
The output of the first phase is a system architecture that defines what is shared, what is standard-specific, how the document hierarchy is structured, and how audit, corrective action, and management review will be organized.
Implementing a System for integrated programs is structured around that shared architecture, with standard-specific modules added in sequence or in parallel depending on your certification timeline. We work with your quality, environmental, safety, and security teams — or the cross-functional team responsible for all of them — to build a system that actually reflects how your organization operates across all applicable standards.
Certification Consulting for multi-standard programs includes preparing for combined audits, coordinating with your certification body on integrated scheduling, and ensuring your evidence portfolio satisfies all applicable standards without duplication. Once certified, the system moves into ongoing surveillance, monitored against the same consolidated KPIs established during design.
Integrated ISO Management Consultant is available as a standalone service for organizations that need design and implementation support specifically for multi-standard integration rather than single-standard implementation.
Frequently Asked Questions
When does it make sense to move to a multi-standard, integrated approach?
The signals are consistent: you are planning or mid-way through certifying to a second or third standard, documentation and processes are starting to duplicate across systems, audit complexity is increasing, or risk management practices differ by team. Any one is a reasonable trigger to design around a shared architecture.
Can a standard be added to our existing certified system later?
Yes, but it depends on how the original system was built. A system designed with a modular, high-level structure extends cleanly. A system built as a standalone program for one standard usually needs a retrofit — workable, but less clean than designing for integration up front.
Does integration work across any combination of standards?
Only where the frameworks are genuinely adjacent. Quality, environmental, and safety standards integrate cleanly because they share a common high-level structure, as do quality and information security, or aerospace quality and cybersecurity. Frameworks without meaningful shared infrastructure add complexity rather than removing it.
Related Standards & Services
The combinations above cover quality, environmental, safety, information security, aerospace, and medical device frameworks. Two standards extend that same architecture for organizations with broader scope: ISO 22301 Consultant for business continuity management, and ISO 42001 Consulting for AI governance.
Contact us.
info@wintersmithadvisory.com
(801) 477-6329