You’ve worked hard to achieve your first ISO certification. Now a key client is asking for a second standard, or a tender requirement has landed on your desk specifying three. The moment you start running two separate management systems, the administrative overhead increases significantly: two audit cycles, two sets of policies, two internal audit programmes, and two sets of annual fees. It quickly starts to feel like operating parallel businesses inside the same organisation.
This is exactly the problem an integrated management system (IMS) is designed to solve. Rather than treating each ISO standard as its own silo, an integrated management system brings two or more standards together into a single coordinated framework. You manage one system, undergo one audit cycle, and maintain one set of shared documentation. ISO-Cert Online Ltd has made single-audit IMS certification accessible to UK SMEs without dedicated compliance teams, at a fixed, transparent price point.
This article covers what an IMS actually is, which standards get combined most often, how to build one from the ground up, what auditors look for at certification, and what it realistically costs. By the end, you’ll have a clear picture of whether the integrated route makes sense for your business.
What an integrated management system actually is
The core idea: one system, not three folders
An IMS is not a separate ISO standard you apply for. It’s a design decision. Instead of running three management systems that each have their own policies, risk assessments, internal audits, and management reviews, you build one system that satisfies the requirements of all your chosen standards simultaneously. The structure is shared; only the domain-specific requirements sit apart.
Any well-built integrated management system rests on the same core components: a unified policy and objectives, shared documentation and record control, integrated risk management, a single internal audit programme, and one management review cycle. These aren’t duplicated for each standard, they’re designed once and built to serve all of them. That’s where the real efficiency comes from.
Why the Harmonized Structure makes this practical
ISO deliberately designed its modern management system standards to share the same high-level clause sequence. This framework, formally known as the Harmonized Structure (previously called Annex SL), runs from Clause 4 (context of the organisation) through to Clause 10 (improvement). ISO 9001, ISO 14001, and ISO 45001 all follow this same skeleton, which means the shared requirements covering leadership, planning, support, performance evaluation, and continual improvement can be written once and applied across all three.
This structural alignment is what makes an integrated management system practical rather than just a good idea on paper. The groundwork is already done inside the standards themselves. Your job during implementation is to build your system to take advantage of it, rather than recreating the same clauses three times over in three separate folders.
Which ISO standards businesses typically combine
The most common integration sets
The most frequently combined set is ISO 9001 (quality management), ISO 14001 (environmental management), and ISO 45001 (occupational health and safety). This trio is particularly common in manufacturing, construction, and operations-heavy environments where quality, environmental impact, and worker safety are all active concerns. Their requirements genuinely overlap in areas like operational planning, risk assessment, competence and training, internal audit, and continual improvement.
ISO 27001 (information security management) is increasingly added by technology companies and businesses handling sensitive client data. ISO 50001 (energy management) is a natural addition for energy-intensive organisations, and ISO 22301 (business continuity) is frequently included by businesses where service resilience is critical. An IMS isn’t a fixed combination, it scales with whatever standards your business actually needs, making it a flexible form of integrated ISO management.
Where the standards diverge, and why that’s fine
Each standard also carries domain-specific requirements that can’t be shared across the whole system. ISO 14001 requires an assessment of environmental aspects and impacts. ISO 45001 requires formal hazard identification. ISO 27001 goes further, requiring a formal information security risk treatment plan and a structured approach to asset classification. These requirements sit alongside the shared structure rather than conflicting with it. A well-designed IMS handles them as discipline-specific modules within one overall framework, not as separate systems bolted awkwardly together.
How to build an integrated management system: a practical implementation roadmap
From gap analysis to go-live
Implementation follows a clear progression. Start by defining your scope: which standards you’re integrating and what business outcomes the IMS needs to support. Then secure leadership alignment, because an IMS that lacks genuine buy-in from the top rarely survives contact with day-to-day operations. After that comes a gap analysis comparing your current practices against the combined requirements of all chosen standards. This stage is where most of the design decisions get made, and it’s worth taking seriously.
Once the gaps are mapped, you move into process and documentation design: creating shared policies, procedures, and work instructions that satisfy all applicable clauses without duplication. A phased rollout follows alongside employee training and a full cycle of internal auditing before the certification stage.
Timelines vary considerably depending on your starting point. SMEs building on an existing certified standard can often reach certification readiness in 3 to 6 months, but businesses starting from scratch or integrating more than three standards should typically allow 6 to 12 months. Existing management maturity, team capacity, and the number of standards involved all affect the pace.
Documentation: what you actually need
A common concern is that an IMS means three times the paperwork. It doesn’t. The goal is shared documentation where requirements align, and standard-specific documentation only where they genuinely diverge. Auditors expect an integrated policy, a scope document, and shared procedures for risk management, internal audit, corrective action, and management review. Standard-specific procedures cover the unique requirements, such as environmental aspects registers for ISO 14001 or hazard and risk assessments for ISO 45001.
The guiding principle here is worth remembering: documents should exist because they help you run the system, not because they fill a folder. Over-documentation is one of the most common ways IMS projects grind to a halt, so keep it lean and purposeful from the start.
Common pitfalls that slow businesses down
The gap analysis stage catches most businesses out, but it’s rarely the only stumbling block. The first mistake is treating integration as a filing exercise: putting three separate documents into one folder and calling it an IMS. Auditors see through this immediately, and it means you’ve gained none of the efficiency benefits. Rushing the gap analysis is the second problem; businesses that skip past this step tend to discover compliance gaps during the certification audit, which is the worst possible moment. The third pitfall is failing to train staff adequately, so the system exists on paper but not in practice.
Each of these is avoidable with proper planning. Build your shared processes first, verify them through internal audit, and make sure your team can explain what they do and why before the external auditor arrives.
Integrated management system certification: what auditors look for
How an integrated audit works
Rather than three separate certification audits with three separate audit teams, an integrated management system is assessed in a single audit against all your chosen standards simultaneously. The auditors examine the combined management system as a whole: shared processes, combined management review records, and a single internal audit programme that covers all standards rather than just one. This approach is typically faster, less disruptive, and cheaper than running separate audits.
The two-stage certification process still applies. Stage 1 reviews your documentation and assesses readiness; Stage 2 assesses implementation on the ground. Both stages cover all integrated standards in one process, so your team only goes through the experience once rather than repeatedly across different audit cycles.
What auditors are actually looking for
Auditors want to see that the system is genuinely integrated, not merely co-located. This means combined internal audit reports that cross-reference all standards, management review minutes that address all three domains, and staff who understand and follow shared procedures confidently. Experienced auditors are skilled at spotting a system assembled for the audit rather than operated in daily practice.
The most effective preparation is simply running the system properly from the start. If your internal audits are thorough, your management review is substantive, and your team understands the processes they follow, the certification audit becomes a confirmation of what you already know rather than an anxious test.
The business case: costs, timeframes, and where IMS fits for UK SMEs
What UK SMEs typically spend and get back
For a smaller UK business pursuing three-standard IMS certification, realistic Year 1 all-in costs (covering implementation support and certification fees) sit in the region of £3,200 to £12,000 depending on complexity and whether external consultancy is involved. A combined audit typically costs less than three separate audits, with indicative savings of roughly £700 to £2,500 per year on audit fees alone, though the actual figure varies by company size and audit scope. Documentation and admin overhead is often reported to run around 30% lower under an IMS compared with managing separate systems, and many SMEs find that the efficiency gains offset first-year investment costs within twelve months, though payback depends on your existing setup and the standards involved.
Timeframes for SMEs range from 3 to 6 months for businesses with an existing certified standard as a base, up to 12 months for those building from scratch across multiple disciplines. Surveillance visits are also consolidated under a single annual cycle, reducing the ongoing disruption that comes with staggered separate audits.
Why ISO-Cert Online Ltd makes this route accessible for SMEs
For SMEs without a dedicated compliance team, two barriers tend to dominate: cost uncertainty and process complexity. ISO-Cert Online Ltd is designed to address both. They offer single-audit IMS certification delivered entirely via remote audit, with a fixed-price model and a document portal that guides businesses through the documentation process step by step. You don’t need to know exactly where to start, the portal shows you.
Their scope covers multiple ISO standards including ISO 9001, ISO 14001, ISO 45001, ISO 27001, and ISO 22301, meaning most common IMS combinations can be handled under one provider, one process, and one annual audit cycle. For an SME managing multiple standards, that consolidation alone is worth considerable time and money each year. The service is built around the needs of smaller organisations, so the process is scaled appropriately rather than borrowed from an enterprise compliance model.
Is an IMS the right move for your business?
An integrated management system isn’t a luxury reserved for large organisations with compliance departments. It’s a smarter way for any business holding, or planning to hold, more than one ISO standard to manage its obligations without duplicating effort across parallel systems. The Harmonized Structure already does much of the structural heavy lifting at the standards level. Your job is to design shared processes that genuinely serve the business, then demonstrate through evidence that they work.
For UK SMEs looking to certify across multiple standards, the single-audit route is measurably more affordable and far less disruptive than managing separate certifications in parallel. The documentation is lighter, the audit process is streamlined, and the ongoing maintenance burden is significantly reduced.
If you’re ready to explore which IMS combination suits your business, visit ISO-Cert Online Ltd to find out more and get a fixed-price quote. One system, one audit, one straightforward path to certification.
Ready to get started?
Contact us today on +44 (0)333 014 7720 or email info@isocertonline.net for a free consultation. You can also get a quote online in minutes.
Don’t let cost hold you back from achieving ISO certification. With ISO-Cert Online, management systems certification is affordable for every business.


