Combined Audits
A combined audit, as defined in ISO 19011, is an audit of two or more management systems of different disciplines carried out together at a single auditee. In the ISO/IEC 27001 context, this usually means auditing an Information Security Management System (ISMS) alongside other systems such as ISO … A combined audit, as defined in ISO 19011, is an audit of two or more management systems of different disciplines carried out together at a single auditee. In the ISO/IEC 27001 context, this usually means auditing an Information Security Management System (ISMS) alongside other systems such as ISO 9001 (quality), ISO 14001 (environment), ISO 22301 (business continuity), or ISO/IEC 20000-1 (IT service management). It differs from a joint audit, in which two or more auditing organizations audit a single auditee together. For the audit program manager, combined audits require careful planning. Because most ISO management system standards follow the Harmonized Structure (formerly Annex SL), common clauses such as context of the organization, leadership, planning, support, performance evaluation, and improvement can be audited together. This reduces duplication and lowers the burden on the auditee. However, discipline-specific requirements, such as the ISO/IEC 27001 information security risk assessment, risk treatment, the Statement of Applicability, and the Annex A controls, must still be fully evaluated. Merging audits must never weaken the depth of coverage for any standard. Key program considerations include defining clear objectives, scope, and criteria for each standard; assembling an audit team whose collective competence covers every discipline, as ISO 19011 and ISO/IEC 27006 require; and calculating audit duration appropriately, since certification bodies may apply reductions based on the degree of integration according to IAF MD 11 but must justify them. The audit plan should show which clauses and processes will be examined for each system, and responsibilities should be allocated among team members, with the audit team leader coordinating overall. Benefits include efficiency, reduced cost and disruption, and a holistic view of how integrated the organization's management systems really are. Risks include insufficient auditor expertise, superficial sampling, and unclear reporting. The audit report should therefore record findings traceable to each specific standard, so that conformity, nonconformities, and certification decisions remain distinct and defensible.
Combined Audits in an ISO/IEC 27001 Audit Programme: A Complete Guide for Lead Auditors
Introduction
Many organizations run more than one management system, for example an Information Security Management System (ISMS) under ISO/IEC 27001 alongside a Quality Management System (ISO 9001), an IT Service Management System (ISO/IEC 20000-1), a Business Continuity Management System (ISO 22301) or a Privacy Information Management System (ISO/IEC 27701). Auditing each system separately can be costly, disruptive and repetitive. A combined audit addresses this by auditing two or more management systems together. Combined audits appear in the ISO/IEC 27001 Lead Auditor syllabus under Managing an ISO/IEC 27001 audit programme. You are expected to define them precisely, tell them apart from similar terms, and explain how they affect audit programme planning.
1. What Is a Combined Audit?
ISO 19011:2018, clause 3.2, defines a combined audit as an audit carried out together at a single auditee on two or more management systems. The note to that definition adds that when two or more discipline-specific management systems are integrated into one management system, this is known as an integrated management system.
Key elements of the definition:
- Single auditee: one organization, or one part of an organization, is audited.
- Two or more management system standards: for example ISO/IEC 27001 + ISO 9001.
- Carried out together: the systems are audited during the same audit, normally with one plan, one team and one opening and closing meeting.
Distinguish it from related terms (a frequent exam trap):
- Combined audit: ONE auditee, TWO OR MORE management system standards.
- Joint audit (ISO 19011, clause 3.3): ONE auditee audited by TWO OR MORE auditing organizations, for example two certification bodies or two customers working together.
- Integrated audit: an audit of an integrated management system, where common processes such as document control, internal audit, management review and corrective action are shared across the standards. An integrated audit is a type of combined audit in which the auditee has actually merged its systems. A combined audit can still be performed when the systems are separate.
- Multi-site audit: one management system covering several sites. This is about locations, not about the number of standards.
2. Why Combined Audits Are Important
Benefits for the auditee:
- Less disruption to operations, because staff are interviewed once instead of several times.
- Lower cost and less total audit time, as overlapping requirements are assessed once.
- A holistic view of how quality, security, continuity and service management interact.
- Support for integration under the ISO Harmonized Structure (formerly Annex SL), which gives ISO/IEC 27001, ISO 9001, ISO 22301, ISO 14001 and other standards the same high-level clauses 4 to 10.
Benefits for the audit programme and audit organization:
- More efficient use of auditor resources.
- Better detection of systemic weaknesses that cut across systems, such as a weak corrective action process affecting both the QMS and the ISMS.
- Consistent findings and reporting.
Risks and challenges:
- Loss of depth: standard-specific requirements may be skipped. For ISO/IEC 27001 these include the information security risk assessment (6.1.2), risk treatment (6.1.3), the Statement of Applicability and the Annex A controls.
- Competence gaps: the team as a whole must be competent in every standard covered.
- Unclear findings: nonconformities must be traceable to the specific standard and clause.
- Unjustified time reductions: cutting audit time too much can compromise audit effectiveness.
- Different certification cycles or scopes: systems may have different scopes, boundaries or certificate dates.
3. How Combined Audits Work in Practice
3.1 Audit programme level (ISO 19011, clause 5)
The person managing the audit programme decides whether a combined audit is appropriate. Considerations include:
- The objectives of each audit, and whether they are compatible.
- The scope and boundaries of each management system. The ISMS scope may differ from the QMS scope.
- The degree of integration of the auditee's systems.
- Risks to the audit programme, such as lack of competent auditors or insufficient time.
- The resources needed: auditors, technical experts and time.
- Requirements from certification rules. ISO/IEC 17021-1 applies to certification audits, ISO/IEC 27006-1 adds ISMS-specific requirements, and IAF MD 11 covers audits of integrated management systems, including how audit time may be reduced based on the level of integration.
3.2 Planning the audit
- Produce one audit plan that clearly shows which standard and clauses each session covers.
- Group common Harmonized Structure clauses so they are assessed once for all applicable standards. These include context (4), leadership (5), planning (6), support (7), performance evaluation (9) and improvement (10).
- Allocate separate, sufficient time for standard-specific requirements. For the ISMS this means the risk assessment methodology, the SoA, Annex A control implementation and information security objectives.
- Set audit criteria for each standard separately.
- Define the audit duration, starting from the time needed for each standard individually and then applying justified reductions only for genuinely integrated elements.
3.3 Audit team composition
- The audit team leader should normally be competent in at least one of the standards and able to manage a multidisciplinary team.
- The team as a whole must cover the competence required for each discipline, including sector and technical knowledge.
- Technical experts may support the team but do not act as auditors.
3.4 Conducting the audit
- Hold a single opening meeting that explains the combined nature, scope and criteria.
- Interview process owners on shared processes once, and verify evidence against each standard.
- Collect evidence through sampling. A single piece of evidence may support conformity to several standards. For example, management review minutes may cover both ISO 9001 9.3 and ISO/IEC 27001 9.3.
- Hold team communication meetings to cross-check findings across disciplines.
3.5 Findings and reporting
- Each nonconformity must reference the specific requirement of the specific standard. If a single issue breaches several standards, state each clause affected.
- Grading (major or minor) is applied for each standard.
- The report may be one combined document, but conclusions must be clear for each management system. This matters most where certification decisions are taken separately.
- Follow-up and corrective action verification should be tracked per standard.
4. Worked Example
A cloud service provider holds ISO 9001 and ISO/IEC 27001 certificates and uses an integrated document control and internal audit process. The audit programme manager schedules a combined surveillance audit.
- Common clauses are audited once: document control (7.5), internal audit (9.2), management review (9.3) and corrective action (10.2).
- Separate sessions are planned for the ISMS: the risk assessment, the SoA, and a sample of Annex A controls such as access control, supplier security and logging.
- Separate sessions are planned for the QMS: customer requirements and product/service conformity.
- The team includes an ISMS lead auditor as team leader and a QMS auditor.
- During the audit, the team finds that internal audits did not cover several Annex A controls within the planned cycle. This is raised as a nonconformity against ISO/IEC 27001 clause 9.2 only, because the QMS internal audit coverage was adequate.
5. Exam Tips: Answering Questions on Combined Audits
Tip 1 - Know the exact definitions. Combined = one auditee, multiple management systems. Joint = one auditee, multiple auditing organizations. If a question describes two certification bodies auditing the same company, the answer is joint, not combined.
Tip 2 - Recognize the Harmonized Structure as the enabler. When asked why combined audits are feasible, mention the common high-level structure (clauses 4 to 10) shared by ISO management system standards.
Tip 3 - Always balance benefits with risks. Scenario and essay questions reward answers that say combined audits save time and reduce disruption, but must not reduce the depth of ISMS-specific auditing. Name the risk assessment, risk treatment, SoA and Annex A explicitly.
Tip 4 - Emphasize team competence. A common correct answer is that the audit team collectively must be competent in all management systems being audited. An ISO 9001-only auditor cannot alone conclude on ISMS conformity.
Tip 5 - Findings must be traceable. If asked how to report a nonconformity in a combined audit, state that it must reference the clause of each relevant standard and be graded per standard.
Tip 6 - Audit time is not simply halved. Reductions are justified only by the level of integration and must preserve audit effectiveness (see IAF MD 11 for certification audits). Answers suggesting arbitrary cuts are usually wrong.
Tip 7 - Link to audit programme management. Decisions to combine audits belong to the audit programme manager (ISO 19011, clause 5). Consider objectives, scope, risks, resources and auditee needs.
Tip 8 - Watch for scope differences. If the ISMS scope covers only part of the organization while the QMS covers all of it, the audit plan must respect each scope separately.
Tip 9 - Use structured answers. For essay questions, use the framework Definition - Purpose/Benefits - Planning considerations - Team - Conduct - Reporting - Risks. This shows complete understanding.
Tip 10 - Eliminate distractors in multiple-choice questions. Reject options claiming that a combined audit requires an integrated management system, since separate systems can still be audited together. Also reject options claiming that one report means one shared conclusion for all standards.
6. Quick Revision Summary
- Definition: an audit at a single auditee on two or more management systems (ISO 19011, 3.2).
- Not to be confused with: joint audits (multiple audit organizations) or multi-site audits.
- Enabler: the Harmonized Structure (Annex SL).
- Benefits: efficiency, less disruption, holistic view, lower cost.
- Risks: loss of depth, competence gaps, unclear findings, excessive time reduction.
- Key controls: one clear plan, a competent multidisciplinary team, sufficient time for ISMS-specific requirements, and traceable, standard-specific findings and conclusions.
- Relevant references: ISO 19011:2018, ISO/IEC 17021-1, ISO/IEC 27006-1, IAF MD 11.
Master these points and you will be able to answer definition, scenario and essay questions on combined audits with confidence in the ISO/IEC 27001 Lead Auditor exam.
Unlock Premium Access
ISO/IEC 27001 Lead Auditor
- Access to ALL Certifications: Study for any certification on our platform with one subscription
- 3041 Superior-grade ISO/IEC 27001 Lead Auditor practice questions
- Unlimited practice tests across all certifications
- Detailed explanations for every question
- ISO 27001 LA: 5 full exams plus all other certification exams
- 100% Satisfaction Guaranteed: Full refund if unsatisfied
- Risk-Free: 7-day free trial with all premium features!