Integrating
ISO 9001:2026 with ISO 14001 and ISO 45001: The Harmonized Approach
The
Company That Ran Three Quality Systems (And Paid for It Three
Times)
I once consulted for a mid-sized manufacturing company that had three
separate management systems: ISO 9001 for quality, ISO 14001 for
environment, and ISO 45001 for occupational health and safety. Each had
its own manager. Each had its own documentation. Each had its own set of
internal audits, management reviews, and certification audits.
The results were predictable: audit fatigue, duplicated effort,
conflicting priorities, and three certification bodies visiting at
different times of year, each disrupting operations. The environmental
manager and the safety manager barely spoke. The quality team saw
environment and safety as distractions from “real” quality work. Total
annual cost for maintaining three separate systems: over €180,000 in
direct costs plus uncounted hours of duplicated effort.
When I proposed integration, the environmental manager said: “But our
system is different.” The safety manager said: “ISO 45001 has unique
requirements that can’t be merged.” The quality manager said: “I don’t
want to dilute our quality focus.”
They were all wrong. Within eighteen months, we had a single
integrated management system (IMS) that met all three standards with one
set of core processes, one internal audit program, one management review
cycle, and combined certification audits. The annual maintenance cost
dropped by 40%. Audit findings decreased. And — most importantly — the
cross-pollination between disciplines made each individual system
stronger.
The 2026 edition of ISO 9001 pushes harder toward integration than
any previous version. If you’re running parallel management systems,
this transition is your opportunity to fix it.
Why Integration Is Now
the Expected Norm
ISO has been moving toward integrated management systems since the
introduction of Annex SL (the high-level structure) in 2012. All ISO
management system standards now share the same ten-clause structure, the
same core definitions, and the same Plan-Do-Check-Act logic. This wasn’t
an accident — it was designed to make integration possible.
But structural compatibility is not the same as operational
integration. Many organizations have structurally compatible systems
that operate in complete isolation. They have the same clause numbers
but different teams, different processes, different audits, and
different cultures. The 2026 edition of ISO 9001 specifically
strengthens the expectation that organizations will integrate their
management systems where multiple standards are applicable.
This is driven by three factors:
Factor 1: Real-world complexity. Quality,
environmental, and safety issues are interconnected. A process change
that improves quality might increase environmental risk. A safety
improvement might affect product quality. Treating these as separate
systems means you miss the connections.
Factor 2: Efficiency. Three separate audit cycles,
three management reviews, three documentation systems — this is a
tremendous waste of resources. Integrated organizations typically reduce
their management system overhead by 30–50%.
Factor 3: Leadership engagement. Senior leaders are
fatigued by multiple management system demands. A single integrated
system with one management review cycle gets better leadership
engagement than three separate requests for their time.
The Integration
Opportunity Assessment
Before you start integrating, assess where you are. I use a simple
matrix:
Level 0 — Isolated Systems. Separate documentation,
separate teams, separate audits, separate management reviews. Each
system operates independently. Communication between system managers is
ad hoc or nonexistent.
Level 1 — Aligned Systems. Documentation references
the other systems. Some shared processes exist (e.g., document control,
internal audit). Management reviews are held separately but cover
similar ground. Certification audits are scheduled separately.
Level 2 — Coordinated Systems. Common core processes
for document control, records management, internal audit, management
review, and corrective action. Cross-functional audit teams. Combined or
sequential management reviews. Certification bodies coordinated for
combined or sequential audits.
Level 3 — Integrated Systems. Single management
system documentation. Single audit program with integrated checklists.
Single management review covering all applicable standards. Combined
certification audits. Cross-functional system management team.
Level 4 — Unified Management System. Quality,
environment, and safety are managed as a single business system. There
is no “quality system” and “environmental system” — there is one
management system that addresses all relevant aspects. Roles and
responsibilities span all disciplines. The concept of separate
management systems is obsolete.
The target for most organizations is Level 3. Level 4 is achievable
for organizations with mature management cultures, but it requires a
fundamental mindset shift that not every organization is ready for.
Building Your
Integrated Management System
Step 1: Common Core Processes
Several processes are functionally identical across ISO 9001, ISO
14001, and ISO 45001. These should be consolidated into single
integrated processes:
Document Control: One procedure, one system, one
approval workflow. Whether a document relates to quality, environment,
or safety, it goes through the same document control process. At WITTE
Automotive, we reduced 47 separate controlled document lists to one
unified document register.
Records Management: One system for identifying,
storing, protecting, retrieving, and disposing of records. Different
retention requirements apply to different record types, but the
management process is the same.
Internal Audit: One audit program, one team of
auditors, integrated audit checklists. An auditor examining a production
process simultaneously checks quality, environmental, and safety
aspects. This is where integration delivers the biggest efficiency gain
— one audit visit instead of three.
Management Review: One management review process
covering all standards. The inputs and outputs are combined into a
single comprehensive review of the management system.
Corrective Action: One nonconformity management
process. Whether the nonconformity is a quality defect, an environmental
incident, or a safety near-miss, the same investigation, root cause
analysis, and corrective action process applies.
Risk Management: One risk management framework that
addresses quality risks, environmental aspects, and safety hazards. The
methodology is consistent; the specific risks differ by discipline.
Competence and Training: One training management
system. Job descriptions include quality, environmental, and safety
responsibilities. Training matrices cover all applicable competence
requirements.
Communication: One internal and external
communication process. Quality, environmental, and safety information
flows through coordinated channels.
Step 2: Integrated
Documentation
Your integrated documentation should follow a hierarchy:
Tier 1 — Integrated Management Manual. One document
that describes your management system, references all applicable
standards, and defines the scope of each certification.
Tier 2 — Core Process Documents. Integrated
procedures for the common processes listed above. These are
standard-agnostic — they apply equally to quality, environment, and
safety.
Tier 3 — Discipline-Specific Procedures. Documents
that address requirements unique to a specific standard. For example,
environmental aspect identification (ISO 14001), hazard identification
and risk assessment (ISO 45001), or product realization planning (ISO
9001).
Tier 4 — Work Instructions. Operational documents
that integrate quality, environmental, and safety requirements at the
point of work. A work instruction for a machining process includes
quality tolerances, environmental waste controls, and safety precautions
in one document.
Step 3: Integrated
Internal Audit Program
This is where integration delivers its highest ROI. Here’s how to
structure it:
Audit Planning. Develop a single annual audit
program based on risk and status assessment. Schedule audits by process,
not by standard. Each process audit covers all applicable standard
requirements.
Auditor Competence. Train a cross-functional audit
team. Quality auditors learn to recognize environmental and safety
aspects. Environmental auditors learn to spot quality implications. In
smaller organizations, a single audit team handles all standards.
Audit Execution. An audit of the production process
simultaneously examines: product conformity (9001), environmental
aspects and impacts (14001), and worker safety (45001). One opening
meeting, one closing meeting, one audit report.
Audit Reporting. Findings are classified by standard
in the audit report but managed through a single corrective action
system. Trends are analyzed across all three disciplines.
At SNOP, integrated audits reduced our annual audit days from 42
(three separate programs) to 18 (one integrated program). The quality of
findings improved because auditors saw connections they would have
missed in single-standard audits.
Step 4: Combined Management
Review
A single management review that covers all applicable standards. The
agenda includes:
- Strategic context changes affecting any management system
- Quality, environmental, and safety performance data
- Results of integrated internal audits and external
certifications - Customer feedback, environmental complaints, and safety incident
data - Status of corrective actions across all disciplines
- Risk management covering quality, environmental, and safety
risks - Resource adequacy for the integrated system
- Improvement opportunities that span disciplines
One review, one set of action items, one leadership team making
decisions with full visibility across all management system areas.
Step 5: Certification
Strategy
Work with your certification body to achieve integrated or combined
audits. Most major certification bodies offer this service. Options
include:
Combined Audits. A single audit team assesses
multiple standards simultaneously. Typically reduces audit days by
25–35% compared to separate audits.
Sequential Audits. Audits for different standards
are conducted in sequence within the same time window, with shared
opening and closing meetings.
Integrated Surveillance. Annual surveillance audits
cover all standards in a single visit, with multi-year recertification
cycles aligned.
The Culture Challenge
Integration is ultimately a cultural change, not a documentation
change. The biggest barrier isn’t structural — it’s the professional
identity and territorial behavior of system managers.
Quality managers who’ve spent careers building quality systems may
resist “diluting” their focus. Environmental managers may fear that
safety or quality will dominate the integrated system. Safety
professionals may worry that production pressures will sideline safety
in an integrated approach.
Address these concerns directly:
-
Define clear roles. Integration doesn’t
eliminate specialist roles. It creates a coordination layer above them.
The quality manager is still responsible for quality outcomes — but
within a shared management framework. -
Ensure balanced representation. No single
discipline should dominate the integrated system. Rotate the IMS
management role or establish a coordinating committee with equal
representation. -
Measure what matters. Track performance metrics
across all three disciplines. If quality metrics improve while safety
degrades, your integration has failed. -
Celebrate cross-discipline wins. When an
integrated audit finds a connection between a quality issue and a safety
risk, celebrate it. That’s the value of integration — and it should be
visible.
Is Integration
Right for Every Organization?
Integration isn’t mandatory, and it’s not right for every situation.
Consider integration when:
- You have two or more management system certifications
- Your management system overhead is becoming a burden
- Audit fatigue is affecting organizational engagement
- Leadership is requesting streamlined governance
- Your systems are structurally compatible but operationally
isolated
Integration may not be appropriate when: – Your certifications are
held by different parts of the organization with different scopes – One
system is mature and another is in early implementation – Regulatory
requirements mandate separate systems
For most mid-sized and large organizations, the case for integration
is overwhelming. The 2026 transition is the ideal time to act.
About the Author
Peter Stasko is a Quality Director with 20+ years of
experience leading quality management systems across the automotive and
aerospace industries. He has implemented and transitioned ISO 9001
systems at Airbus, SNOP, and WITTE Automotive, and has served as a lead
auditor for IATF 16949 and ISO 9001 certifications across European
manufacturing operations. Peter specializes in practical, no-nonsense
QMS architecture — building systems that work in production
environments, not just on paper.

