Much has been said about the blueprint of an integrated management system: shared clauses, one audit programme, one management review. That is the how, and it is well documented. The question managing directors in manufacturing put to me instead is a different one: what do I actually get out of it, apart from fewer binders?
The answer turns out to be bigger than expected, and it has the least to do with documents. An integrated system changes what the management team talks about when it talks about quality, security, the environment or AI. Four side issues become one management issue. This article describes four concrete effects — and what an IMS does not do.
“An integrated system does not primarily save paper. It ensures that decisions are taken once, instead of half-taken four times in four committees.” – Dr Thorsten Neumann, sales partner for manufacturing and ECA auditor for ISO 9001, 27001 and 42001
The cost advantage is the smallest of the four benefits
Let us start with the obvious point, because it can be quantified cleanly. With us, the first standard costs €179 per month, each additional one €149, with a 36-month term and a fixed price for companies with up to 30 employees. Anyone running four standards therefore pays the bundle price for three of them. You can do the maths on the pricing page.
Then there is the audit effort. An audit covering several standards is an integrated audit and follows the rules set out in MD 11 of the accreditation umbrella body Global ACI (IAF until the end of 2025). Audit time is not simply added up; it is derived from the longest individual duration plus a share for each further standard. At the same time, the same document caps the permissible reduction at a maximum of 20 percent of the total audit time. Anyone promising more is promising something that breaks the rules.
The real gain lies elsewhere: in your own calendar. One management review instead of three. One audit week instead of several. One audit report that you read once and circulate internally once. For a company whose management circle consists of four people, that matters more than the discount.
Audits become sharper, not just shorter
This is the point I see most clearly as an auditor. In separate systems I examine the same processes several times from different angles — and each time I find a partial truth. Purchasing is checked once for supplier evaluation, once for the information security of service providers, once for environmental requirements in the supply chain. Three conversations about the same process, three records, no overall picture.
In an integrated system I hold one conversation about purchasing and consider all requirements at the same time. That finds more, not less. Contradictions become visible that never come to light in separate systems, because they sit between the systems: an approval rule that conflicts with the emergency plan; a service provider that is assessed on one list and missing from another.
For you that means: the findings from an integrated audit are more useful. They concern your company, not the standard. The rules for conducting audits were recently revised in ISO 19011:2026, among other things with a stronger focus on the actual effectiveness of a system rather than on the existence of processes. That is exactly where an integrated system plays to its strengths.
The effect on culture is regularly underestimated
In separate systems, employees learn that there is “QM”, “IT security” and “the environmental officer” — three authorities, each wanting something, usually at inconvenient moments. That produces precisely the attitude that gave certification its bad reputation: you meet requirements for someone else, not for your own company.
An integrated system turns this perception around, because there is only one point of contact and one logic left. A nonconformity is a nonconformity, regardless of which standard the requirement comes from. An improvement idea goes on the same list. That sounds organisational, but it works culturally: the number of systems people have to keep in their heads drops to one.
This coincides with the development of the standards themselves. For the first time, ISO 9001:2026 explicitly requires top management to promote a quality culture and ethical behaviour, and it anchors awareness of this among all employees — as set out in the analysis of the revision. Culture is therefore no longer a subordinate clause but a subject of assessment. In a system that is perceived as an alien body, that is hard to demonstrate.
Growth: you can add a standard without starting over
The fourth benefit only shows over time and is the most valuable one for growing companies. Once the foundation is in place — context, interested parties, risk methodology, document control, audit programme — a further standard is a module, not a project.
This becomes tangible when a customer suddenly demands something new. A tender calls for ISO 27001, a corporate client asks how you handle AI, an insurer wants to see an information security management system. With a solid foundation you answer within weeks. Without one, a new project begins.
An example from our own house, stated openly: Netgen Switzerland, a Zurich-based web and digital agency, runs ISO 9001, ISO 14001, ISO 27001 and ISO 42001 as a single integrated system and has been certified in all four standards since 8 May 2026, valid until 7 May 2029. The first project was created in the platform in February 2026, and all four certifications were completed in May. The system contains 164 tasks across the standards’ clauses and 54 documents. Transparency is part of this: Christian Paredes is CEO of Eucerta AG and founder of Netgen — our own company was the test bed here. All four certificates can be verified by their number in the public register. [CHECK: If a reliable statement on the effort involved or on the audit experience at Netgen is released, a sentence belongs here — for now, deliberately only the verifiable facts.]
What an IMS does not do
To keep the picture accurate: an integrated system does not make the technical requirements any smaller. You still have to work through the Statement of Applicability of the controls under ISO 27001 exactly as before. The inventory of AI systems under ISO 42001 does not emerge from the quality documentation. You also still receive one certificate per standard, not a single combined certificate.
And it does not replace responsibility. A system that nobody maintains falls apart faster with several standards than with one, because more and more evidence has to be produced on an ongoing basis. Certificates are valid for three years from the audit date; what happens during those three years determines the value of the paper. That is why we work with dedicated caretakers — independent partners acting as internal auditors who keep the system up to date between audits.
Conclusion
The business case for an integrated management system does not add up at the level of licence costs, but at the level of decision quality. One meeting, one set of data, one list of open items: that is the difference between a system that the management team uses to steer the company, and several systems that it merely has administered.
Anyone introducing a standard today who knows that a second one will be required in two years should lay the foundation properly now. Integrating after the fact is always a conversion — and conversion costs more than building.
Your next step: Work out your combination of standards in the cost calculator, or see on the Integrated Management System page how the system is set up with us.
Further reading:




