Integrated Management Systems
An Integrated Management System (IMS) combines two or more management system standards, such as ISO/IEC 27001 (information security), ISO 9001 (quality), ISO 14001 (environment), ISO 45001 (occupational health and safety) and ISO 22301 (business continuity), into a single coherent framework instead… An Integrated Management System (IMS) combines two or more management system standards, such as ISO/IEC 27001 (information security), ISO 9001 (quality), ISO 14001 (environment), ISO 45001 (occupational health and safety) and ISO 22301 (business continuity), into a single coherent framework instead of running separate, parallel systems. Integration is made practical by the Harmonized Structure (formerly the High-Level Structure defined in Annex SL of the ISO/IEC Directives). It gives all modern ISO management system standards the same clause sequence, core text and common terms. These are Clause 4 Context of the organization, 5 Leadership, 6 Planning, 7 Support, 8 Operation, 9 Performance evaluation and 10 Improvement. Because ISO/IEC 27001:2022 follows this structure, many ISMS processes can be shared with other systems. Examples include determining interested parties and scope, setting policy and objectives, risk-based planning, competence and awareness, documented information control, internal audit, management review, and corrective action and continual improvement. Benefits include reduced duplication and documentation, consistent governance, a unified view of risk, better resource use, and combined or integrated certification audits that may reduce total audit time. For a Lead Auditor, integration requires care. Shared processes can be audited once, but evidence must still demonstrate conformity with each standard's specific requirements. For ISO/IEC 27001, the auditor must verify discipline-specific elements that generic integration may overlook. These include the information security risk assessment and treatment process (6.1.2 and 6.1.3), the Statement of Applicability, the justified inclusion and exclusion of Annex A controls, and information security objectives. The auditor should check that integration has not diluted information security, for example by merging risk registers so that confidentiality, integrity and availability are no longer clearly assessed. Guidance comes from ISO 19011 for auditing management systems, ISO/IEC 27006-1 for certification body requirements, and IAF MD 11 for integrated audits. Audit teams need combined competence across all the standards being audited. Ultimately, an effective IMS embeds information security into overall business processes and strategic direction.
Integrated Management Systems (IMS) in ISO/IEC 27001: A Complete Guide for Lead Auditors
Introduction
An Integrated Management System (IMS) combines two or more management systems into one cohesive framework. Examples include ISO/IEC 27001 (Information Security), ISO 9001 (Quality), ISO 14001 (Environment), ISO 45001 (Occupational Health and Safety), ISO 22301 (Business Continuity) and ISO/IEC 20000-1 (IT Service Management). Instead of running separate, parallel systems, the organization operates one system that meets the requirements of several standards. For an ISO 27001 Lead Auditor, understanding IMS is essential. Many organizations seeking certification already hold other ISO certifications, and auditors are often asked to perform combined or integrated audits.
Why Integrated Management Systems Are Important
1. Reduced duplication: Document control, internal audit, management review, corrective action, competence and awareness are required by almost every ISO management system standard. Integration means these are done once, not several times.
2. Cost and resource efficiency: One audit programme, one management review and one set of procedures save time and money. Certification bodies can also run combined audits, which lowers the total number of audit days.
3. Holistic risk management: Information security, quality, environmental and safety risks often overlap. An IMS lets the organization see and treat risks across disciplines in one consistent way.
4. Better alignment with business strategy: ISO 27001 Clause 5.1 requires top management to ensure the ISMS requirements are integrated into the organization's business processes. An IMS supports this by embedding management system requirements into everyday operations rather than treating them as add-ons.
5. Less confusion for staff: Employees follow one set of policies and processes instead of many overlapping and sometimes conflicting ones.
6. Continual improvement: A unified PDCA (Plan-Do-Check-Act) cycle drives improvement across all disciplines at the same time.
What an Integrated Management System Is
An IMS is a single management system that manages several aspects of an organization's performance against the requirements of multiple standards. Integration is possible mainly because of the Harmonized Structure (HS). It was previously called the High Level Structure (HLS) or Annex SL, and it is now found in Annex SL, Appendix 2 of the ISO/IEC Directives, Part 1.
The Harmonized Structure gives all modern ISO management system standards:
- Identical clause structure (Clauses 1 to 10)
- Identical core text (common requirements)
- Common terms and core definitions
The ten clauses of the Harmonized Structure are:
1. Scope
2. Normative references
3. Terms and definitions
4. Context of the organization
5. Leadership
6. Planning
7. Support
8. Operation
9. Performance evaluation
10. Improvement
Because ISO/IEC 27001:2022, ISO 9001:2015, ISO 14001:2015, ISO 45001:2018 and ISO 22301:2019 all follow this structure, an organization can build one framework. Discipline-specific requirements are then added where needed, such as the Statement of Applicability and Annex A controls for ISO 27001.
Supporting guidance:
- ISO/IEC 27001 Clause 5.1(b): top management must ensure ISMS requirements are integrated into the organization's processes.
- ISO/IEC 27001 Clause 6.1.1 Note and Clause 6.2: planning integrates with other organizational planning.
- ISO 19011:2018 (Guidelines for auditing management systems): covers combined audits, where two or more management systems are audited together.
- ISO/IEC 17021-1: governs how certification bodies plan and conduct audits, including combined and integrated audits.
- ISO/IEC 27013: guidance on the integrated implementation of ISO/IEC 27001 and ISO/IEC 20000-1.
- ISO handbook 'The Integrated Use of Management System Standards' (IUMSS): practical guidance on integration.
How an Integrated Management System Works
Levels of integration:
- Aligned systems: separate systems that share some common elements, such as one document control procedure.
- Combined systems: shared processes with some separate elements.
- Fully integrated systems: a single system with unified policy, objectives, processes and records. Discipline-specific requirements are embedded in it.
Common elements that are typically integrated:
- Context of the organization and interested parties (Clause 4)
- Integrated policy or a set of aligned policies (Clause 5.2)
- Roles, responsibilities and authorities (Clause 5.3)
- Risk and opportunity management methodology (Clause 6.1)
- Objectives and planning to achieve them (Clause 6.2)
- Resources, competence, awareness and communication (Clauses 7.1 to 7.4)
- Documented information control (Clause 7.5)
- Operational planning and control (Clause 8.1)
- Monitoring, measurement, analysis and evaluation (Clause 9.1)
- Internal audit (Clause 9.2)
- Management review (Clause 9.3)
- Nonconformity, corrective action and continual improvement (Clause 10)
Elements that remain discipline-specific for ISO 27001:
- Information security risk assessment and risk treatment (Clauses 6.1.2, 6.1.3, 8.2, 8.3)
- Statement of Applicability (SoA)
- Annex A controls (93 controls in the 2022 version, grouped into Organizational, People, Physical and Technological themes)
- Information security objectives and information-security-specific competence
Implementation approach:
1. Obtain top management commitment and define the integrated scope.
2. Perform a gap analysis against each standard.
3. Map common requirements using the Harmonized Structure as a matrix.
4. Design unified processes and add discipline-specific annexes.
5. Train staff on the integrated system.
6. Run integrated internal audits and a single management review.
7. Seek combined or integrated certification.
Auditing an IMS:
- Combined audit (ISO 19011 term): two or more management systems of different disciplines are audited together at a single auditee.
- Joint audit: two or more auditing organizations audit a single auditee. Do not confuse this with a combined audit.
- The audit team must have the competence for each discipline being audited. An ISO 27001 auditor without quality competence cannot alone judge ISO 9001 conformity.
- Audit time may be reduced because of integration, following the rules of the certification body and the IAF Mandatory Documents (for example, IAF MD 11 on the application of ISO/IEC 17021-1 for audits of integrated management systems).
- A nonconformity in a shared process, such as document control, may affect multiple standards. The auditor must record it against the relevant clauses of each standard.
- Certificates may be issued separately for each standard even when the audit is combined.
Benefits and challenges
Benefits: efficiency, consistency, fewer audits, a unified view of risk, and better engagement from top management.
Challenges: different scopes for each standard, conflicting objectives, the complexity of combined risk methods, the need for multi-competent auditors and internal staff, and the risk of diluting discipline-specific requirements such as the SoA.
Exam Tips: Answering Questions on Integrated Management Systems
1. Know the Harmonized Structure cold. Many questions test whether you know that ISO 27001 shares Clauses 4 to 10 with other standards. Remember the ten clauses and their order. Older materials may say Annex SL or High Level Structure; treat these as the same concept.
2. Identify what can and cannot be integrated. Common processes (internal audit, management review, document control, corrective action, competence) can be integrated. The ISO 27001 Statement of Applicability, information security risk assessment criteria and Annex A controls are specific to the ISMS. They must still be clearly evidenced even within an IMS.
3. Distinguish combined audit vs joint audit. Under ISO 19011, a combined audit covers multiple management systems at one auditee. A joint audit involves multiple audit organizations. This is a classic exam trap.
4. Remember audit team competence. In scenario questions, check whether the audit team has competence in every discipline audited. If not, the correct answer usually involves adding a technical expert or a qualified auditor.
5. Link to Clause 5.1(b). If a question asks which ISO 27001 requirement supports integration, cite Clause 5.1(b): integration of ISMS requirements into the organization's processes.
6. Scenario questions on nonconformities. If a shared process fails, for example an integrated internal audit programme that never covered Annex A controls, raise the nonconformity against ISO 27001 Clause 9.2. Note also its impact on the other standards where relevant. Integration does not excuse missing ISMS-specific requirements.
7. Scope awareness. An IMS may have different scopes for each standard. In questions, check that the ISMS scope (Clause 4.3) is clearly defined and documented even when the IMS scope is broader or narrower.
8. Look for the most efficient yet compliant answer. Exam answers often favour solutions that avoid duplication while still meeting every standard's requirements. Reject answers that sacrifice conformity for efficiency.
9. Policy questions. An integrated policy is acceptable if it meets the ISO 27001 Clause 5.2 requirements. It must be appropriate to the purpose, include or frame information security objectives, include commitment to applicable requirements and continual improvement, and be documented and communicated. An integrated policy that omits information security commitments is a nonconformity.
10. Management review. One integrated management review is acceptable. However, it must cover all ISO 27001 Clause 9.3 inputs, such as information security performance, risk assessment results, interested party feedback and opportunities for improvement.
11. Audit duration. Know that integration may justify reduced audit time. This is never automatic; it depends on the level of integration, as assessed by the certification body under IAF guidance.
12. Use structured answers in essay questions: define IMS, mention the Harmonized Structure, give benefits and challenges, describe audit implications, and conclude with the auditor's responsibility to verify each standard's requirements.
Sample exam question and model answer
Question: An organization certified to ISO 9001 wants to add ISO 27001 and asks if it can use its existing internal audit procedure. As lead auditor, what is your view?
Model answer: Yes. Both standards follow the Harmonized Structure, and Clause 9.2 requirements are nearly identical. The procedure may be extended into an integrated internal audit process. However, the audit programme must cover the ISMS scope, its processes and the Annex A controls declared in the SoA. Internal auditors must be competent in information security, and results must be reported to relevant management and retained as documented information. Any gaps would be a nonconformity against ISO 27001 Clause 9.2.
Key takeaways
- An IMS is one system meeting several standards, made possible by the Harmonized Structure.
- ISO 27001 Clause 5.1(b) explicitly supports integration into business processes.
- Common clauses can be shared, but ISMS-specific requirements (risk assessment, SoA, Annex A) must remain evident.
- In audits, ensure team competence for every discipline. Use ISO 19011 terminology correctly (combined vs joint audits).
- In exams, always verify that integration does not dilute any standard's requirements.
Unlock Premium Access
ISO/IEC 27001 Lead Auditor
- Access to ALL Certifications: Study for any certification on our platform with one subscription
- 3041 Superior-grade ISO/IEC 27001 Lead Auditor practice questions
- Unlimited practice tests across all certifications
- Detailed explanations for every question
- ISO 27001 LA: 5 full exams plus all other certification exams
- 100% Satisfaction Guaranteed: Full refund if unsatisfied
- Risk-Free: 7-day free trial with all premium features!