Book an Appointment

Integrated Management Systems (IMS)

How to merge ISO/IEC 27001, 27701 and 42001 as well as ISO 9001 and ISO 22301 into a single management system based on the Harmonized Structure – from document control to the combined certification audit.

Organisations operating an ISMS to ISO/IEC 27001 today rarely stop at one standard: privacy (ISO/IEC 27701), AI governance (ISO/IEC 42001), quality (ISO 9001) and business continuity (ISO 22301) each bring their own management system requirements. Building these systems in parallel produces redundant documents, competing processes and multiple audits covering the same questions. Since ISO made the Harmonized Structure (formerly High-Level Structure, Annex SL) mandatory for management system standards, they share the same clause structure, core text and terminology – the technical foundation for running them as one integrated management system (IMS). This article shows what integration looks like in practice for document control, the audit programme and certification, and where the typical pitfalls lie.

The Essentials at a Glance

01

Harmonized Structure: the common framework

The Harmonized Structure (HS) is the mandatory template for ISO management system standards. It is set out in Annex SL of the ISO/IEC Directives, Part 1 (Consolidated ISO Supplement), was introduced in 2012 and has carried the name “Harmonized Structure” instead of “High-Level Structure” since the 2021 edition. It prescribes the same ten clauses for all management system standards – with the requirements in clauses 4 to 10: context of the organization, leadership, planning, support, operation, performance evaluation and improvement – complemented by identical core text and common terms and definitions. Context analysis, policy, risks and opportunities, documented information, internal audit and management review are therefore structured identically in every standard – and it is precisely this overlap that makes integration technically feasible.

02

The standards landscape: 27001, 27701, 42001, 9001, 22301

All five standards follow the Harmonized Structure but differ in their subject-specific content. ISO/IEC 27001:2022 (information security, including Amendment 1:2024 addressing climate change in clauses 4.1 and 4.2) brings the Annex A controls. ISO/IEC 27701:2025 (privacy information management system, PIMS) has been a standalone management system standard since its second edition – an existing ISO 27001 certificate is no longer a prerequisite, although integration with the ISMS remains the typical case. ISO/IEC 42001:2023 is the first certifiable standard for AI management systems. ISO 9001:2015 (quality) remains valid; its successor is available as a Final Draft (FDIS, final ballot until July 2026), with publication expected around September 2026. ISO 22301:2019 (business continuity, including Amendment 1:2024) remains current; a third edition is still only at the Committee Draft stage.

03

Shared document control

The requirements for documented information (HS clause 7.5) are practically identical across all five standards – creation, identification, review, approval, version control and access protection can therefore be covered by a single control process. A three-tier document hierarchy has proven effective: an integrated policy at the top, shared cross-cutting procedures (risk management, audit programme, handling of nonconformities, training) in the middle, and standard-specific work instructions and records below. A mapping matrix that assigns each document to the clauses and controls of the individual standards keeps the structure traceable for internal and external auditors – without maintaining content in multiple places.

04

Combined internal and certification audits

Internally, an integrated audit programme under clause 9.2 covering several standards in a single audit is sufficient; methodological guidance is provided by ISO 19011:2026 (fourth edition, May 2026, which replaces the 2018 edition and expands, among other things, the guidance on remote and hybrid audits). For certification audits, IAF MD 11:2023 governs the application of ISO/IEC 17021-1 to integrated management systems, including the calculation of audit time: the higher the degree of integration – for example a joint management review, integrated documentation and cross-cutting processes – the more the total audit time may be reduced compared with separate audits. The prerequisites are a consolidated audit plan and an audit team that competently covers all disciplines involved.

05

Efficiency gains – and typical pitfalls

The efficiency gain arises where cross-cutting processes are implemented once and credited towards several standards: context and stakeholder analysis, risk methodology, training and awareness, supplier management, management review and corrective actions. Added to this are fewer audit days and consistent statements towards customers and supervisory authorities. Typical pitfalls: different risk concepts (information security vs. quality vs. AI impact assessment) are equated too hastily; the scopes of the subsystems do not match; the integration exists only on paper while the business units continue to work separately; responsibilities between the CISO, privacy and quality owners remain unclear; and asynchronous certification cycles prevent combined audits unless they are deliberately synchronised.

06

Maturity path: from parallel to integrated

Integration rarely succeeds as a big bang – the ISO handbook “The Integrated Use of Management System Standards” (IUMSS) describes a step-by-step approach. In practice, a three-stage path has proven effective: first, separate systems are harmonised through common terminology, a mapping matrix and shared document control. Next, cross-cutting processes are merged – risk management, the internal audit programme and management review. The end state is an integrated system with one policy, one set of KPIs and combined certification audits with synchronised cycles. The most mature existing system usually makes the best starting point – often the ISMS or the QMS; new topics such as ISO/IEC 42001 or ISO/IEC 27701 can then be set up as an extension rather than a parallel structure.

Standards & Sources

The content on this page is based on the following publicly available guides and studies.

ISO/IEC · 2021

ISO/IEC Directives, Part 1 – Consolidated ISO Supplement, Annex SL (Harmonized Structure)

Mandatory template for management system standards: ten clauses, identical core text, common terminology; known as the “Harmonized Structure” (formerly High-Level Structure) since the 2021 edition.

ISO · 2018

The Integrated Use of Management System Standards (IUMSS)

ISO handbook (2nd edition, November 2018) with a process model and case studies on integrating several management system standards into one management system.

International Accreditation Forum · 2023

IAF MD 11:2023 – Application of ISO/IEC 17021-1 for Audits of Integrated Management Systems

Mandatory document for certification bodies on calculating audit time for IMS audits; the possible reduction of the total audit time depends on the degree of integration.

ISO/IEC · 2022

ISO/IEC 27001:2022 (inkl. Amd 1:2024)

Current ISMS standard in the Harmonized Structure; Amendment 1:2024 adds the consideration of climate change in clauses 4.1 and 4.2.

ISO/IEC · 2025

ISO/IEC 27701:2025

Second edition of the PIMS standard, now a standalone management system standard – ISO/IEC 27001 is no longer a certification prerequisite.

ISO · 2026

ISO 19011:2026 – Guidelines for auditing management systems

Fourth edition (May 2026) of the guidelines for auditing management systems, including expanded guidance on remote and hybrid audits; the basis for integrated internal audit programmes.

Several standards, one system?

In a no-obligation initial consultation, we jointly assess where your management systems stand today and which integration step is worth taking next – from standards mapping to the combined audit.