The Harmonized Structure (HS) is the mandatory template for ISO management system standards. It is set out in Annex SL of the ISO/IEC Directives, Part 1 (Consolidated ISO Supplement), was introduced in 2012 and has carried the name “Harmonized Structure” instead of “High-Level Structure” since the 2021 edition. It prescribes the same ten clauses for all management system standards – with the requirements in clauses 4 to 10: context of the organization, leadership, planning, support, operation, performance evaluation and improvement – complemented by identical core text and common terms and definitions. Context analysis, policy, risks and opportunities, documented information, internal audit and management review are therefore structured identically in every standard – and it is precisely this overlap that makes integration technically feasible.
Integrated Management Systems (IMS)
How to merge ISO/IEC 27001, 27701 and 42001 as well as ISO 9001 and ISO 22301 into a single management system based on the Harmonized Structure – from document control to the combined certification audit.
Organisations operating an ISMS to ISO/IEC 27001 today rarely stop at one standard: privacy (ISO/IEC 27701), AI governance (ISO/IEC 42001), quality (ISO 9001) and business continuity (ISO 22301) each bring their own management system requirements. Building these systems in parallel produces redundant documents, competing processes and multiple audits covering the same questions. Since ISO made the Harmonized Structure (formerly High-Level Structure, Annex SL) mandatory for management system standards, they share the same clause structure, core text and terminology – the technical foundation for running them as one integrated management system (IMS). This article shows what integration looks like in practice for document control, the audit programme and certification, and where the typical pitfalls lie.
The Essentials at a Glance
Six topic blocks — tap to expand.
The standards landscape: five standards, one structure
All five standards follow the Harmonized Structure but differ in their subject-specific content — tap a standard.
- Brings the Annex A controls.
- Amendment 1:2024 adds the consideration of climate change in clauses 4.1 and 4.2.
- A standalone management system standard since its second edition — an existing ISO 27001 certificate is no longer a prerequisite.
- Integration with the ISMS remains the typical case.
- The first certifiable standard for AI management systems.
- Remains valid; its successor is available as a Final Draft (FDIS).
- Final ballot until July 2026; publication expected around September 2026.
- Remains current, including Amendment 1:2024.
- A third edition is still only at the Committee Draft stage.
Standards & Sources
The content on this page is based on the following publicly available guides and studies.
ISO/IEC Directives, Part 1 – Consolidated ISO Supplement, Annex SL (Harmonized Structure)
Mandatory template for management system standards: ten clauses, identical core text, common terminology; known as the “Harmonized Structure” (formerly High-Level Structure) since the 2021 edition.
The Integrated Use of Management System Standards (IUMSS)
ISO handbook (2nd edition, November 2018) with a process model and case studies on integrating several management system standards into one management system.
IAF MD 11:2023 – Application of ISO/IEC 17021-1 for Audits of Integrated Management Systems
Mandatory document for certification bodies on calculating audit time for IMS audits; the possible reduction of the total audit time depends on the degree of integration.
ISO/IEC 27001:2022 (inkl. Amd 1:2024)
Current ISMS standard in the Harmonized Structure; Amendment 1:2024 adds the consideration of climate change in clauses 4.1 and 4.2.
ISO/IEC 27701:2025
Second edition of the PIMS standard, now a standalone management system standard – ISO/IEC 27001 is no longer a certification prerequisite.
ISO 19011:2026 – Guidelines for auditing management systems
Fourth edition (May 2026) of the guidelines for auditing management systems, including expanded guidance on remote and hybrid audits; the basis for integrated internal audit programmes.
Related Services
Several standards, one system?
In a no-obligation initial consultation, we jointly assess where your management systems stand today and which integration step is worth taking next – from standards mapping to the combined audit.