01Harmonized Structure: the common framework
The Harmonized Structure (HS) is the mandatory template for ISO management system standards. It is set out in Annex SL of the ISO/IEC Directives, Part 1 (Consolidated ISO Supplement), was introduced in 2012 and has carried the name “Harmonized Structure” instead of “High-Level Structure” since the 2021 edition. It prescribes the same ten clauses for all management system standards – with the requirements in clauses 4 to 10: context of the organization, leadership, planning, support, operation, performance evaluation and improvement – complemented by identical core text and common terms and definitions. Context analysis, policy, risks and opportunities, documented information, internal audit and management review are therefore structured identically in every standard – and it is precisely this overlap that makes integration technically feasible.
02The standards landscape: 27001, 27701, 42001, 9001, 22301
All five standards follow the Harmonized Structure but differ in their subject-specific content. ISO/IEC 27001:2022 (information security, including Amendment 1:2024 addressing climate change in clauses 4.1 and 4.2) brings the Annex A controls. ISO/IEC 27701:2025 (privacy information management system, PIMS) has been a standalone management system standard since its second edition – an existing ISO 27001 certificate is no longer a prerequisite, although integration with the ISMS remains the typical case. ISO/IEC 42001:2023 is the first certifiable standard for AI management systems. ISO 9001:2015 (quality) remains valid; its successor is available as a Final Draft (FDIS, final ballot until July 2026), with publication expected around September 2026. ISO 22301:2019 (business continuity, including Amendment 1:2024) remains current; a third edition is still only at the Committee Draft stage.
03Shared document control
The requirements for documented information (HS clause 7.5) are practically identical across all five standards – creation, identification, review, approval, version control and access protection can therefore be covered by a single control process. A three-tier document hierarchy has proven effective: an integrated policy at the top, shared cross-cutting procedures (risk management, audit programme, handling of nonconformities, training) in the middle, and standard-specific work instructions and records below. A mapping matrix that assigns each document to the clauses and controls of the individual standards keeps the structure traceable for internal and external auditors – without maintaining content in multiple places.
04Combined internal and certification audits
Internally, an integrated audit programme under clause 9.2 covering several standards in a single audit is sufficient; methodological guidance is provided by ISO 19011:2026 (fourth edition, May 2026, which replaces the 2018 edition and expands, among other things, the guidance on remote and hybrid audits). For certification audits, IAF MD 11:2023 governs the application of ISO/IEC 17021-1 to integrated management systems, including the calculation of audit time: the higher the degree of integration – for example a joint management review, integrated documentation and cross-cutting processes – the more the total audit time may be reduced compared with separate audits. The prerequisites are a consolidated audit plan and an audit team that competently covers all disciplines involved.
05Efficiency gains – and typical pitfalls
The efficiency gain arises where cross-cutting processes are implemented once and credited towards several standards: context and stakeholder analysis, risk methodology, training and awareness, supplier management, management review and corrective actions. Added to this are fewer audit days and consistent statements towards customers and supervisory authorities. Typical pitfalls: different risk concepts (information security vs. quality vs. AI impact assessment) are equated too hastily; the scopes of the subsystems do not match; the integration exists only on paper while the business units continue to work separately; responsibilities between the CISO, privacy and quality owners remain unclear; and asynchronous certification cycles prevent combined audits unless they are deliberately synchronised.
06Maturity path: from parallel to integrated
Integration rarely succeeds as a big bang – the ISO handbook “The Integrated Use of Management System Standards” (IUMSS) describes a step-by-step approach. In practice, a three-stage path has proven effective: first, separate systems are harmonised through common terminology, a mapping matrix and shared document control. Next, cross-cutting processes are merged – risk management, the internal audit programme and management review. The end state is an integrated system with one policy, one set of KPIs and combined certification audits with synchronised cycles. The most mature existing system usually makes the best starting point – often the ISMS or the QMS; new topics such as ISO/IEC 42001 or ISO/IEC 27701 can then be set up as an extension rather than a parallel structure.