Plenty of Australian businesses end up holding more than one ISO certification. Run as separate systems, that means separate sets of paperwork, separate internal audit programmes and a lot of duplication. I regularly walk into businesses with two or three near-identical document-control procedures that contradict each other in small ways, simply because they were written by different people at different times. An integrated management system (IMS) brings them together into one.

What is an integrated management system?
An integrated management system combines two or more management system standards into one coherent system with shared processes, documentation and governance, instead of separate silos. The classic Australian combination is QSE: ISO 9001 (quality), ISO 14001 (environment) and ISO 45001 (safety), or any two of the three. Just as common now are ISO 27001 (information security) alongside ISO 9001, and ISO 42001 (AI management) alongside ISO 27001, which is the natural pairing once you are governing AI and the data it runs on.
Which combination does your business need?
There is no fixed list. An integrated management system is simply a system that integrates more than one standard, so it can be any two or more, in whatever combination your operations or your clients require. What drives the choice is your exposure to risk and who is asking for the certificate.
Some patterns come up often enough to be worth naming:
| Sector | Combination we often see |
|---|---|
| Construction and civil | QSE: ISO 9001, ISO 14001 and ISO 45001 |
| Manufacturing | ISO 45001 safety and ISO 14001 environment, increasingly with ISO 27001 |
| Technology and SaaS | ISO 27001 with ISO 42001 for AI governance |
| Defence and government supply | ISO 27001, usually alongside ISO 9001 |
| White label and contract manufacture | ISO 9001 quality with ISO 27001 or ISO 42001 |
Treat those as illustrations rather than a menu. Plenty of the systems we build combine standards that would not appear on any list like this, because that is what the operation or the contract actually called for.
Why the standards fit together
Since 2015, ISO management system standards share a common framework: the harmonised structure (formerly Annex SL). They use the same high-level clauses: context, leadership, planning, support, operation, performance evaluation and improvement. Much of the system is therefore identical whichever standards you are working to, and that is exactly what makes integration possible. In practical terms, once you have written a good document-control or internal-audit procedure, you have written it for every standard in the system at once. There is no quality version and security version, just one.
Benefits of an integrated management system
- One set of core processes: document control, internal audit, management review, corrective action and risk management are shared, not duplicated for each standard.
- Less duplication and paperwork: a single system manual and aligned procedures.
- Lower audit cost: certification bodies can run combined audits, reducing audit days and fees.
- Better decisions: leadership sees performance across every standard in the system side by side, in one management review, rather than in separate meetings nobody has time for.
- A stronger culture: one consistent way of working instead of competing systems.
What’s shared and what stays specific
The “backbone” clauses are integrated once. The technical, risk-specific requirements stay distinct. A good IMS integrates the common parts and keeps the specialised parts clear:
| Shared across the IMS | Specific to each standard |
|---|---|
| Context and interested parties | ISO 9001: customer focus and quality objectives |
| Leadership and policy | ISO 14001: environmental aspects and compliance obligations |
| Risk and planning | ISO 45001: hazard identification and worker participation |
| Competence, awareness and communication | ISO 27001: risk assessment, Statement of Applicability and Annex A controls |
| Document control, internal audit, management review, corrective action, improvement | ISO 42001: AI system inventory, impact assessment and AI-specific controls |
Integrated management system certification: single or separate?
You can certify an integrated system through one certification body that audits all standards together in a combined audit. That usually means fewer audit days, lower fees and a single surveillance schedule, rather than separate audits for each certificate. You still receive a certificate for each standard, but from one system.
Is an integrated management system right for you?
An IMS makes sense if you already hold, or plan to hold, two or more certifications, or you run several of these functions as overlapping responsibilities. If you only need one standard, a single system is simpler. One caveat worth knowing: integrating a mature, well-run system with a neglected one is not a shortcut to fixing the neglected one. Integration exposes the weak parts rather than hiding them, which is useful, but plan for it.
How Streamline can help
We design integrated management systems around whichever combination you actually need: a QSE system across ISO 9001, ISO 14001 and ISO 45001, ISO 27001 sitting alongside ISO 9001, or ISO 42001 with ISO 27001 where AI governance now rides on top of information security. Whatever the mix, you get one practical system your team uses, prepared for a single combined certification audit. The result is less duplication, lower ongoing cost and a system that supports the business rather than sitting beside it.
Integrated management systems: FAQs
Which standards can be integrated?
Any of the modern ISO management system standards, because they share the same harmonised structure. In practice that usually means a QSE system (ISO 9001, ISO 14001 and ISO 45001, or two of the three), ISO 27001 alongside ISO 9001, or ISO 42001 alongside ISO 27001.
How many standards can you combine?
There is no upper limit. Two is the most common starting point, three is normal, and more is workable where the business actually carries that much risk. The constraint is usually how much the organisation can absorb at once, not the standards themselves.
Do you get one certificate or several?
Usually a separate certificate for each standard, but issued from one integrated system and a single combined audit.
Is an IMS cheaper than separate systems?
Generally yes over time: shared processes and combined audits reduce both the internal effort and the certification body’s fees.
Speak with an experienced ISO auditor
Email hello@streamline.business or call us. You’ll deal directly with an experienced ISO auditor who’ll tailor a practical approach to your business. You’re also welcome to get in touch via our contact page.
Stay in the Loop
Get an email when we post an article. Your email address will not be used for marketing, and you can unsubscribe at any time.
We handle your details in line with our privacy policy.











