731 901 601
Integrating ISO 9001:2026 with ISO 14001 and ISO 45001 — how to build a single integrated management system

Integrating ISO 9001:2026 with ISO 14001 and ISO 45001 — how to build a single integrated management system

Companies that have simultaneously implemented quality, environmental and occupational health and safety management systems are increasingly asking one question: will the update of ISO 9001 to the 2026 version force a divergence between the standards that have hitherto functioned within the organisation as a single, coherent system? The answer is reassuring – the new version of the standard does not deviate from the High-Level Structure, which has for years been the foundation for the integration of ISO 9001, ISO 14001 and ISO 45001. However, it is worth knowing where minor discrepancies requiring attention may arise, and where the update to the standard actually presents an opportunity to organise and simplify the entire integrated system.

Why is it possible to integrate these three standards at all?

A common structure – the same chapter numbering, the same basic terms and definitions, and a similar approach to the context of the organisation, leadership, planning and performance evaluation – has for years enabled companies to operate a single integrated management system (IMS) rather than three separate systems with overlapping documentation. This means a single management review covering quality, the environment and health and safety, a single internal audit procedure, and a shared register of risks and opportunities, in which individual risks are simply flagged as relating to a specific area.

A practical consequence of this common architecture is also the use of a single, consistent set of terminology throughout the organisation. Instead of a separate glossary of terms for quality, one for the environment and another for health and safety, staff learn a single set of definitions – such as ‘organisational context’, ‘interested parties’, ‘risk’, ‘objective’ and ‘competence’ – which significantly reduces the time needed to bring new staff up to speed with the system and facilitates joint training sessions.

What changes with ISO 9001:2026 from an integration perspective

The update to the standard does not alter the overall structure, but introduces slightly more detailed requirements regarding the documentation of links between risks and organisational decisions, as well as a greater emphasis on the resilience of processes and the supply chain. In practice, this means that within an integrated system, it is worth expanding the common risk register to include a column showing what specific quality-related action resulted from a given risk – in the same way that this has long been documented in ISO 14001 with regard to environmental aspects, or in ISO 45001 with regard to health and safety hazards.

The second point of convergence concerns the approach to staff competence and awareness – ISO 9001:2026 places greater emphasis on documenting that staff understand the impact of their work on quality, which aligns well with the corresponding requirements regarding environmental and health and safety awareness. In an integrated system, this can be incorporated into a single, shared training and competence assessment programme, rather than maintaining three separate records.

A joint register of risks and opportunities in practice

In many organisations, the risk register has so far operated as three separate spreadsheets – one for quality, one for environmental aspects and one for health and safety risks – which had to be manually collated during management reviews. An integrated approach, reinforced by the new ISO 9001:2026 requirements regarding the tracking of links between risks and decisions, allows for the maintenance of a single register with an additional column indicating the area (quality, environment, health and safety) and a column detailing the specific action triggered by a given risk.

This structure has two practical advantages. Firstly, it makes it easier to identify risks that affect several areas simultaneously – for example, a production line failure may simultaneously constitute a quality risk, an environmental risk (spillage, waste) and an occupational health and safety risk (hazard to staff), and maintaining a single register allows this link to be seen immediately, rather than only when comparing three separate documents. Secondly, it reduces the time spent on management reviews – instead of three separate agenda items, a single, joint review of risks and opportunities is sufficient, broken down by area where necessary.

Combined audit – what’s changing and what remains the same

For years, certification bodies have been offering combined audits for companies holding certificates under several standards at the same time. The update to ISO 9001 does not affect the very possibility of conducting such an audit, but in the first audit cycle following the implementation of the new version of the standard, it is worth expecting that the auditor will devote slightly more time to checking the quality aspect than to the environmental and health and safety aspects – this is a natural consequence of the fact that it is precisely this part of the system that is currently undergoing changes. It is advisable to synchronise the date of the combined audit with the timetable and transition period for the move from ISO 9001:2015 to ISO 9001:2026.

When full integration is not the best solution

Integrating three standards into a single system is not always the right approach for every organisation, and it is worth making this clear before making such a decision under pressure to update to ISO 9001. In companies where individual systems are overseen by completely different teams (quality department, HSE department, environmental compliance department) and have little overlap in their day-to-day work, forced integration may cause more confusion than it brings benefits – especially if the individual teams are only just learning to collaborate on shared documentation.

Similarly, in organisations at an early stage of implementing one of these systems – for example, a company that is only just certifying to ISO 45001 whilst having had a mature quality management system in place for years – it is often better to establish the new system within its own structure and only plan integration once both systems have become operationally established. The ISO 9001:2026 update does not require integration with other standards – this is a business decision, not a formal requirement, and it is worth making this decision consciously rather than automatically.

How to plan the integration process step by step

Organisations that decide to carry out integration as part of their ISO 9001 update usually fare best by adopting a phased approach, rather than attempting to combine everything at once. A good starting point is mapping – comparing the requirements of the individual chapters of all three standards side by side and identifying which parts of the documentation already overlap, and which are managed separately despite the actual similarity of their content.

The next step is to harmonise those areas that yield the greatest reduction in administrative workload with the least risk – most commonly these are: management review, the internal audit procedure, documentation and records management, and training. Only at a later stage should more complex areas, such as a common risk register or uniform system performance indicators, be integrated, as this is where the differences between the standards are greatest and require more time to refine the methodology.

At the end of this process, it is worth conducting an internal audit covering the entire integrated system, rather than three separate audits carried out one after the other – this is the best way to check whether the integration actually simplifies the system’s operation, or merely transfers the existing complexity into a single, larger document.

What to look out for when updating integrated documentation

The greatest risk in integration is not incompatibility between standards, but internal inconsistency within the documentation, which arises when some sections are updated to comply with the new version of ISO 9001, whilst others – relating to the environment and health and safety – remain unchanged. It is worth treating the update of the standard as an opportunity to review the entire integrated system, rather than just the quality-related section, even if formally only one of the three standards is changing.

It is also good practice to appoint a single person or team responsible for the consistency of the entire integrated documentation – even if different authorised representatives are formally responsible for the individual standards. This role of ‘consistency guardian’ helps to avoid situations where the same procedures exist in two slightly different versions, which is one of the most common causes of non-conformities identified during audits of integrated management systems.

Updating documentation is a good opportunity to organise the entire ISO 9001 Quality Management System and adapt it to the organisation’s current needs. We also help to integrate it with ISO 14001 and ISO 45001, enabling the company to benefit from a single, coherent system and a shared audit schedule.

 

Read other posts

ISO 45001 in industrial manufacturing – specific requirements and key risks

ISO 45001 in industrial manufacturing – specific requirements and key risks

Manufacturing plants are among the work environments with the highest level of risk complexity. Machinery, chemicals, noise, shift work and high pressure to meet production targets create an environment in which the risk of an accident is structurally higher than in the service sector or an office. read more
How does ISO 22716 help secure contracts with retail chains?

How does ISO 22716 help secure contracts with retail chains?

A cosmetic product on the shelf of a large retail chain is the result of a lengthy process – and it’s not just about the formula, packaging or price. read more
ISO 3834 – the key to markets that pay more

ISO 3834 – the key to markets that pay more

Polish welding companies have one of the best reputations in Europe when it comes to workmanship and value for money. And yet many of them hit a glass ceiling when trying to enter Western European markets or secure a contract with an international client. read more
More posts