Best Practices

Several ISO standards at once: how to build an IMS

Two or three standards at the same time sounds like three times the work. Because the standards share the same basic structure, it isn't. The blueprint for an integrated management system, step by step.

Thomas Werner
Thomas Werner
CCO Eucerta AG + CEO Eucerta Germany GmbH
6 min read
Several ISO standards at once: how to build an IMS

I hear this sentence regularly in initial conversations: “We might manage ISO 9001. But 27001 on top of that? Not with our team.” The concern is understandable, and yet it rests on a false calculation. Two standards do not mean twice the work. With clean planning they mean roughly a third more than a single standard on its own.

The reason lies in how the standards themselves are built. This article describes how to use that in practice: which parts you build only once, in which order you proceed, how the audit runs, and why integrated projects fail when they do fail. This is about the how. Why an integrated system also pays off after the certificate is a topic of its own.

“Anyone who introduces two standards separately writes half of it twice and has it audited twice. The substantive gain from that duplication is zero.” – Thomas Werner, CCO Eucerta AG and Lead Auditor

The shared basic structure is the whole trick

Years ago, ISO determined that all management system standards would be written to the same pattern. Today that pattern is called the Harmonized Structure; it was previously known as Annex SL. It prescribes the sequence of clauses, large parts of the core text and the shared terminology.

The consequence: ISO 9001, ISO 14001, ISO 27001 and ISO 42001 all have the same structure. Context of the organisation, leadership, planning, support, operation, performance evaluation, improvement — in that order, in each of these standards, with largely identical requirement text. An overview of the Harmonized Structure shows this in detail.

That is not formalism, it is your lever. A management system that properly meets clauses 4 to 10 once meets them for every standard involved. What remains is the technical core of each standard — and that is considerably smaller than everything around it.

What you build exactly once

The parts you need only once are, as it happens, the most demanding ones. From audit practice, these are they:

  • The context analysis: which internal and external issues affect your company.
  • The consideration of interested parties: who expects something from you, and what exactly.
  • The methodology for risks and opportunities: assessment criteria, responsibilities, review cycle.
  • The control of documented information: how documents are created, approved, versioned and archived.
  • The internal audit programme: an annual plan covering all standards.
  • The management review: one meeting with top management, one basis for decisions.
  • The handling of nonconformities and corrective actions: one procedure, one list.

What remains standard-specific is the technical core. ISO 9001 wants processes, customer satisfaction and a quality culture. ISO 27001 requires risk treatment including a statement of applicability for the controls from Annex A. ISO 14001 needs the consideration of environmental aspects and compliance obligations. ISO 42001 needs the inventory of AI systems and the impact assessment. You attach these modules to the shared foundation — they do not replace it.

The order that works in practice

There is no universally correct standard to start with, only the one that fits your reason for starting. My recommendation after many projects:

  1. Clarify the trigger. Is a customer demanding a certificate, or is an insurer pushing? Start with the standard that relieves that pressure.
  2. Define the scope for all standards at the same time. A scope extended later creates rework in every document.
  3. Build the shared clauses completely before you move into the technical modules. Anyone who starts with Annex A will be reorganising everything later.
  4. Add the technical modules standard by standard. Here the respective specialist departments do the work, no longer top management alone.
  5. Carry out one internal audit covering the entire system, not three small ones.
  6. Hold one management review that covers all standards.

One detail that saves projects: name a person who is responsible for the system, even if they do not develop everything themselves. Where three departments look after three standards “in parallel”, three systems emerge again — only this time in one folder.

What runs differently in the audit

An audit covering several standards is an integrated audit and follows its own rules. The framework for this is set out in document MD 11 of the accreditation umbrella body Global ACI (IAF until the end of 2025) of the International Accreditation Forum, which governs the application of ISO/IEC 17021 to such audits.

Two points from it are of practical relevance to you. First: audit time is not simply added up. It is calculated from the longest individual audit time plus a share for each additional standard. Second: the permissible reduction is limited and must not exceed 20 percent of the total audit time. Anyone who promises you a halving of audit days is promising something the rules do not allow.

You still save in real terms: one opening meeting, one closing meeting, one audit report, one appointment in your calendar instead of several audit weeks a year. With us the audit runs digitally, and every certificate issued can be verified by its number in the public register. Certificates are valid for three years from the audit date, and in between we carry out surveillance via the platform.

Why integrated projects fail

I see three mistakes again and again. The first is aiming too high: four standards at once in a company where an internal audit has never taken place. Two are then the better start, with the third following at the next surveillance audit.

The second mistake is a mountain of documents as an end in itself. An integrated system is meant to merge documents, not multiply them. If there are more files after the consolidation than before, something has gone wrong.

The third is the relapse after the certificate. A system that nobody maintains falls apart by the time of the surveillance audit — faster with several standards, because more evidence has to be generated on an ongoing basis. That is why we work with dedicated caretakers: independent partners as internal auditors who keep the system alive between audits. Our partner network shows who is available in your region.

On the costs: with us the first standard costs 179 euros a month, each additional one 149 euros, with a 36-month term and a fixed price for up to 30 employees. The Integrated management system page shows how this adds up for your selection of standards.

Conclusion

Several standards at once is not a topic reserved for corporate groups. For small and medium-sized companies it is in fact the cheaper route, because the expensive foundation is only created once. The condition is discipline in the order: first the scope, then the shared clauses, then the technical modules, then one audit covering everything.

Anyone who instead patches on one standard after another after the fact pays for the integration later — and pays more, because then it is a matter of rebuilding rather than building.

Your next step: Work out your combination of standards in the cost calculator, or use the express certification to have it checked how far along your system already is.

Further reading:

#Integrated management system#ISO 9001#ISO 27001#IMS
Share:

About the Author

Thomas Werner
Thomas Werner
CCO Eucerta AG + CEO Eucerta Germany GmbH

Leads the certification body in Germany and is responsible for the qualification of all auditors.