Guide · Systems

What is an integrated management system?

An integrated management system (IMS) runs quality, environment and safety as one framework instead of three parallel systems. For a small business chasing ISO 9001, 14001 and 45001, it's the difference between one set of paperwork and three — and the standards were deliberately rebuilt to make it possible. Here's how it works and when it's worth it.

The definition, without the jargon

An IMS is a single management system that satisfies more than one ISO standard at once — most commonly ISO 9001 (quality), ISO 14001 (environment) and ISO 45001 (health and safety). Instead of a quality manual, an environmental manual and a safety manual each with its own document register, risk process and audit schedule, you run one framework where each piece of machinery serves all three standards, and only the genuinely subject-specific parts exist separately.

It is not a fourth standard and there's no "IMS certificate". You still get certified against each standard individually — the IMS is simply the intelligent way to hold them.

ISO 9001 vs ISO 14001 vs ISO 45001

The three standards ask the same style of question about different subjects:

ISO 9001ISO 14001ISO 45001
FocusQuality — delivering what the customer ordered, consistentlyEnvironment — controlling how your work affects air, water, land and resourcesHealth and safety — preventing injury and ill health at work
Who it protectsYour customers (and your reputation)The environment and the community around your workYour workers, contractors and visitors
Key registersCustomer requirements, suppliers, nonconformancesAspects & impacts, environmental legal obligationsHazards and WHS risks, safety legal obligations, incidents
Typical audit evidenceJob records, inspection results, complaint handling, supplier reviewsWaste and monitoring data, spill kit checks, licence complianceSWMS, toolbox talks, incident investigations, consultation records

Why the standards integrate so cleanly

This isn't a workaround — it's by design. Since their current editions, all three standards follow Annex SL, ISO's mandated high-level structure. Every one of them has the same ten clauses in the same order: scope, references, terms, then context of the organisation, leadership, planning, support, operation, performance evaluation and improvement. Clause 7.5 is document control in all three. Clause 9.2 is internal audit in all three. Clause 9.3 is management review in all three.

When three standards make the same demand in the same clause, meeting it three separate times is pure waste. Annex SL exists precisely so you don't have to.

What's shared — and what stays specific

In a well-built IMS, all of this runs once, covering every standard in scope:

  • Document control — one register, one versioning method, one approval process.
  • Risk methodology — one way of rating and treating risk, applied to quality, environmental and safety risks alike.
  • Competence and training — one training matrix per person, not three.
  • Internal audit — one audit program that checks each area against every applicable standard in a single visit.
  • Management review — one meeting with an agenda that covers all three sets of inputs.
  • Corrective action — one process for raising, investigating and closing out issues, whatever their flavour.

What stays standard-specific is the subject matter itself: the aspects & impacts register for ISO 14001, the hazard and WHS risk registers for ISO 45001, and customer requirements and product conformity for ISO 9001. Those are different questions with different answers — everything around them is the same machinery.

Rule of thumb

Roughly 60–70% of the clauses across ISO 9001, 14001 and 45001 are common machinery. Build it once and the second and third standards mostly mean adding their registers and controls — not building new systems.

The payoff for a small business

Integration isn't an academic preference — it changes the workload and the invoice:

  • One audit program, not three. Certification bodies offer combined audits: one Stage 1, one Stage 2, one surveillance visit a year covering all standards in scope. Because shared clauses are assessed once, combined audits take fewer days and cost meaningfully less than three separate programs.
  • One management review. The owner sits down once with an agenda covering quality, environment and safety inputs — not three meetings saying two-thirds the same things.
  • Roughly a third of the paperwork. One document set, one risk method, one training matrix, one action log. For a business where the "compliance department" is the owner's Tuesday evening, that's the difference between a system that stays alive and three folders that quietly go stale.
  • One version of the truth. Parallel systems inevitably drift — the safety manual says one thing about training, the quality manual another, and the auditor finds the gap. An IMS can't contradict itself.

There's a softer payoff too: an integrated system reads like your business actually runs. Your site supervisor doesn't think in standards — a spill is an environmental issue, a safety issue and probably a quality issue all at once. In an IMS it's raised once, investigated once and closed once, with the record counting toward every standard it touches. That's why integrated systems get used between audits, while parallel ones get dusted off the week before.

When not to integrate

If your clients only ask for one standard, build one standard — don't construct a three-headed system for certificates nobody is requesting. The good news is that this isn't a fork in the road: a system built properly on the Annex SL structure is the foundation of an IMS. Start with ISO 9001 (or whichever standard your market demands), and when a tender asks for 14001 or 45001, you add that standard's registers and controls to machinery that already exists. The IMS grows; you never start over.

How to build one

  1. Map the shared clauses. Lay the standards side by side — Annex SL means they already line up — and mark what's common: context, leadership, document control, competence, audit, review, improvement.
  2. Write one policy set. One integrated policy (or three short aligned ones) signed by the owner, covering quality, environment and safety commitments.
  3. Run integrated registers. One risk register with quality, environmental and safety risks tagged by type; one legal obligations register; one action log; one training matrix. Add the standard-specific registers — aspects, hazards — alongside.
  4. Combine the routines. One internal audit schedule and one management review agenda covering every standard in scope, so the evidence generates itself as the system runs.

One system, three standards, built for you

Answer about 20 questions about your business and BigTick generates your complete integrated ISO 9001, 14001 & 45001 management system — shared machinery, standard-specific registers, and the routines that keep it audit-ready.

Start a free trial

Frequently asked questions

Is an IMS a separate certification?

No. There's no "ISO IMS certificate" — you're certified against each standard individually. The IMS is simply one framework holding them all, audited in one combined visit, producing a certificate per standard in scope.

Can we get certified to all three at once?

Yes. Certification bodies routinely run combined audits covering 9001, 14001 and 45001 in a single Stage 1 and Stage 2, issuing all three certificates together — in fewer audit days than three separate programs would take.

Is an IMS harder to audit?

Easier, in practice. One document set and one set of records means less to maintain and fewer inconsistencies for an auditor to find. Three parallel systems describing the same business three different ways is where findings breed.

What does IMS software do?

It holds the shared machinery — documents, risks, training, audits, actions, management review — in one place, tagged to the standards each item serves, so one entry counts across all three. The best of it also builds the system around your business rather than handing you empty registers.

Do small businesses need all three standards?

Only if clients ask. Many businesses need just ISO 9001; construction, trades and field services increasingly face tenders demanding all three. Start with what's required — a system built on the Annex SL structure extends to the next standard with a fraction of the original effort.

Related guides

A plain-English guide to integrated management systems, not a substitute for the standards or certification advice.