
Companies that have simultaneously implemented quality, environmental and occupational health and safety management systems are increasingly asking one question: will the update of ISO 9001 to the 2026 version force a divergence between the standards that have hitherto functioned within the organisation as a single, coherent system? The answer is reassuring – the new version of the standard does not deviate from the High-Level Structure, which has for years been the foundation for the integration of ISO 9001, ISO 14001 and ISO 45001. However, it is worth knowing where minor discrepancies requiring attention may arise, and where the update to the standard actually presents an opportunity to organise and simplify the entire integrated system.
A common structure – the same chapter numbering, the same basic terms and definitions, and a similar approach to the context of the organisation, leadership, planning and performance evaluation – has for years enabled companies to operate a single integrated management system (IMS) rather than three separate systems with overlapping documentation. This means a single management review covering quality, the environment and health and safety, a single internal audit procedure, and a shared register of risks and opportunities, in which individual risks are simply flagged as relating to a specific area.
A practical consequence of this common architecture is also the use of a single, consistent set of terminology throughout the organisation. Instead of a separate glossary of terms for quality, one for the environment and another for health and safety, staff learn a single set of definitions – such as ‘organisational context’, ‘interested parties’, ‘risk’, ‘objective’ and ‘competence’ – which significantly reduces the time needed to bring new staff up to speed with the system and facilitates joint training sessions.
The update to the standard does not alter the overall structure, but introduces slightly more detailed requirements regarding the documentation of links between risks and organisational decisions, as well as a greater emphasis on the resilience of processes and the supply chain. In practice, this means that within an integrated system, it is worth expanding the common risk register to include a column showing what specific quality-related action resulted from a given risk – in the same way that this has long been documented in ISO 14001 with regard to environmental aspects, or in ISO 45001 with regard to health and safety hazards.
The second point of convergence concerns the approach to staff competence and awareness – ISO 9001:2026 places greater emphasis on documenting that staff understand the impact of their work on quality, which aligns well with the corresponding requirements regarding environmental and health and safety awareness. In an integrated system, this can be incorporated into a single, shared training and competence assessment programme, rather than maintaining three separate records.
In many organisations, the risk register has so far operated as three separate spreadsheets – one for quality, one for environmental aspects and one for health and safety risks – which had to be manually collated during management reviews. An integrated approach, reinforced by the new ISO 9001:2026 requirements regarding the tracking of links between risks and decisions, allows for the maintenance of a single register with an additional column indicating the area (quality, environment, health and safety) and a column detailing the specific action triggered by a given risk.
This structure has two practical advantages. Firstly, it makes it easier to identify risks that affect several areas simultaneously – for example, a production line failure may simultaneously constitute a quality risk, an environmental risk (spillage, waste) and an occupational health and safety risk (hazard to staff), and maintaining a single register allows this link to be seen immediately, rather than only when comparing three separate documents. Secondly, it reduces the time spent on management reviews – instead of three separate agenda items, a single, joint review of risks and opportunities is sufficient, broken down by area where necessary.

For years, certification bodies have been offering combined audits for companies holding certificates under several standards at the same time. The update to ISO 9001 does not affect the very possibility of conducting such an audit, but in the first audit cycle following the implementation of the new version of the standard, it is worth expecting that the auditor will devote slightly more time to checking the quality aspect than to the environmental and health and safety aspects – this is a natural consequence of the fact that it is precisely this part of the system that is currently undergoing changes. It is advisable to synchronise the date of the combined audit with the timetable and transition period for the move from ISO 9001:2015 to ISO 9001:2026.
Integrating three standards into a single system is not always the right approach for every organisation, and it is worth making this clear before making such a decision under pressure to update to ISO 9001. In companies where individual systems are overseen by completely different teams (quality department, HSE department, environmental compliance department) and have little overlap in their day-to-day work, forced integration may cause more confusion than it brings benefits – especially if the individual teams are only just learning to collaborate on shared documentation.
Similarly, in organisations at an early stage of implementing one of these systems – for example, a company that is only just certifying to ISO 45001 whilst having had a mature quality management system in place for years – it is often better to establish the new system within its own structure and only plan integration once both systems have become operationally established. The ISO 9001:2026 update does not require integration with other standards – this is a business decision, not a formal requirement, and it is worth making this decision consciously rather than automatically.
Organisations that decide to carry out integration as part of their ISO 9001 update usually fare best by adopting a phased approach, rather than attempting to combine everything at once. A good starting point is mapping – comparing the requirements of the individual chapters of all three standards side by side and identifying which parts of the documentation already overlap, and which are managed separately despite the actual similarity of their content.
The next step is to harmonise those areas that yield the greatest reduction in administrative workload with the least risk – most commonly these are: management review, the internal audit procedure, documentation and records management, and training. Only at a later stage should more complex areas, such as a common risk register or uniform system performance indicators, be integrated, as this is where the differences between the standards are greatest and require more time to refine the methodology.
At the end of this process, it is worth conducting an internal audit covering the entire integrated system, rather than three separate audits carried out one after the other – this is the best way to check whether the integration actually simplifies the system’s operation, or merely transfers the existing complexity into a single, larger document.
The greatest risk in integration is not incompatibility between standards, but internal inconsistency within the documentation, which arises when some sections are updated to comply with the new version of ISO 9001, whilst others – relating to the environment and health and safety – remain unchanged. It is worth treating the update of the standard as an opportunity to review the entire integrated system, rather than just the quality-related section, even if formally only one of the three standards is changing.
It is also good practice to appoint a single person or team responsible for the consistency of the entire integrated documentation – even if different authorised representatives are formally responsible for the individual standards. This role of ‘consistency guardian’ helps to avoid situations where the same procedures exist in two slightly different versions, which is one of the most common causes of non-conformities identified during audits of integrated management systems.
Updating documentation is a good opportunity to organise the entire ISO 9001 Quality Management System and adapt it to the organisation’s current needs. We also help to integrate it with ISO 14001 and ISO 45001, enabling the company to benefit from a single, coherent system and a shared audit schedule.