Skip to main content

Picture an organisation certified to ISO 9001, 45001, 14001 and 27001.

Quality sits with operations, in a spreadsheet that one person defends with their life. Safety sits with HR, in a different spreadsheet. Environmental sits with whoever raised their hand in a meeting eighteen months ago. Security sits with IT, in SharePoint, in a folder structure that made sense at the time.

Four systems. Four internal audits. Four management reviews. Four sets of corrective actions. Four separate periods of quiet panic, spaced through the year like unpleasant public holidays.

Everyone in that organisation is doing the same work four times. Most of them don't know the others are doing it.

The standards were built to be combined

Here's the bit that tends to surprise people. ISO didn't design these standards to be run in isolation. They share a common structure, called Annex SL, which means the management system requirements underneath the technical content are close to identical.

Context of the organisation. Leadership. Planning. Support. Operation. Performance evaluation. Improvement. Same skeleton, different muscles.

So when your quality manager writes a document control procedure and your security manager writes a document control procedure, they are answering the same clause with two documents that will eventually contradict each other. Usually at the worst moment.

What genuinely combines

Document control. One procedure, one repository, one approval path. Whether a document is a safety procedure or an access control policy changes the content, not the way it's versioned and approved.

Internal audit. This is the big one. A single audit programme can cover all four systems, with an auditor visiting a department once and asking about quality, safety, environmental and security in the same sitting. Your operations manager will be so grateful they may cry.

Management review. Clause 9.3 appears in every one of these standards and asks for broadly the same inputs. Running four separate reviews for the same leadership team is a fine way to ensure that by the fourth one, nobody is listening.

Corrective actions. One process, one register, one method for root cause analysis. A nonconformity is a nonconformity regardless of which standard caught it.

Risk management. The criteria differ, obviously. A safety risk and an information security risk are assessed on different terms. The method for identifying, rating, treating, assigning and reviewing them does not need to differ at all.

Training and competence records. One record per person, covering everything they've been trained on, rather than four systems each convinced they hold the definitive version.

Supplier management. Your suppliers affect quality, safety, environmental performance and security, sometimes all at once. Assessing them four times through four processes is how organisations end up with four different answers about the same vendor.

What doesn't combine

Plenty. Your hazard register is not your risk register. Environmental aspects and impacts are their own discipline. The Statement of Applicability belongs to ISO 27001 alone. Safety consultation requirements under 45001 have no equivalent anywhere else.

Integration means sharing the machinery, not pretending the standards are interchangeable. Anyone who tells you a single document can satisfy all four is selling something, and it isn't compliance.

What changes when you do it properly

The audit burden drops in a way people find genuinely startling. One programme, one schedule, one set of findings, one improvement plan.

Leadership gets a single view of organisational risk rather than four reports arriving at four meetings with four different formats and no shared vocabulary.

The evidence stops being duplicated. Training records, supplier assessments, incident data and management review minutes get captured once and used wherever they're needed.

And the person who has been quietly holding one of these systems together on their own gets to stop doing that.

Where to start if you're already certified

You don't need to rebuild everything. Pick the shared processes first, starting with internal audit and management review, because they deliver the most relief for the least disruption. Merge the document control next. Leave the technical content alone entirely.

The mistake is trying to integrate everything in one heroic quarter. The organisations that do this well treat it as a series of small consolidations, usually timed around audit cycles that were happening anyway.

Need help getting your ducks in a row?

de.iterate runs ISO 9001, 45001, 14001, 27001, 42001 and 20+ other frameworks from one platform, with shared registers, evidence and assurance tasks underneath them.

Book a demo and we'll show you what one system instead of four looks like.