CRAIG WILLETTS ISO & BUSINESS CONSULTANT
  • Meet Craig Willetts
    • Change The Game
    • Give Back
    • Go Paperless With ISO
    • Compliance Master
  • Business Articles
    • New Business Tips >
      • Cash Flow Planning
      • Cybersecurity Basics for SMEs
      • From Startup to Scale-Up
      • Train Your Brain
      • Organise Your Workspace
      • Colour use in Business
      • Writing a Business Plan
      • Setting KPI's
      • Website Building Instructions
      • Business Insurance
    • Business Development >
      • Building Strategic Partnerships
      • Social Media Essentials
      • Strategic Growth Planning
      • SEO Tips
      • Sell your product or service
    • General Business Tips >
      • How to price your services
      • IR35 Rules Explained
      • Meeting Tips
      • GDPR changes 2026
      • Health & Safety Law Updates
      • Making Tax Digital (MTD):
      • Problem Solving
      • Ensure Compliance
      • Health & Safety Tips
      • Cost-Effective Technology Solutions
      • Anti-Money Laundering Regulations
      • Customer Service Sector
      • Prevent burnout in your team
  • Sector specific articles
    • Security Sector
    • Construction Sector
    • Cleaning & FM Sector
    • Manufacturing Sector
    • Training Sector
    • Warehouse Sector
    • Project Management Sector
    • Healthcare Sector: Navigating CQC Compliance
  • Understanding People
    • How to Tell If Your Team Is Using AI
    • Onboarding New Employees: First 90 Days Checklist
    • Be A Great Employee
    • Understand Customers
    • Talent Management
    • How To Get The Most From Your Team
    • Stress at Work
    • Managing Remote and Hybrid Teams Effectively
    • Made it Mindset
  • ISO Standards Tips
    • Top 20 ISO Standards
    • ISO 9001 Tips
    • ISO 14001 Tips
    • ISO 45001 Tips
    • ISO 45003 Tips
    • ISO 31000 Tips
    • ISO 22301 Tips
    • ISO 27001 Tips
    • ISO 42001 Tips
    • ISO 17025 Tips
    • ISO 13485 Tips
    • ISO 18788 Tips
    • ISO 28000 Tips
    • ISO 28007 Tips
    • ISO 50001 Tips
    • ISO 17021 Tips
    • ISO 10015 Tips
    • ISO 37001 Tips
    • ISO 22000 Tips
    • ISO 37301 Tips
    • ISO 27701 Tips
    • ISO 20000 Tips
    • ISO 26000 Tips
    • ISO 15189 Tips
    • ISO 20121 Tips
    • Internal audits in plain English
    • Corrective Actions that work
    • Management Review Meeting
    • Integrating ISO Standards

Integrating ISO Standards 

Picture
Every ISO management system standard, whether it governs quality, environmental impact, information security or workplace safety, is built from the same architectural blueprint. This shared foundation is what allows companies to run several certifications side by side without duplicating half their paperwork, yet it is also precisely where organisations trip up, because looking similar on paper is not the same as behaving identically in practice.

The common backbone across standards is called Annex SL, the high-level structure that ISO now mandates for all its management system standards, including ISO 9001, ISO 14001, ISO 45001, ISO 27001 and ISO 22301. Before this structure existed, organisations that tried to combine systems ran into major difficulties in terms of excessive documents, duplication of tasks, and inadequate management of the resources needed for the management systems, and Annex SL was introduced specifically to facilitate the integration of certifiable management standards.

Because of Annex SL, every one of these standards now shares the same clause numbering and core concepts: context of the organisation, leadership commitment, planning and risk-based thinking, support and resources, operational planning, performance evaluation, and continual improvement. A quality manager reading ISO 45001 for the first time will recognise the same skeleton they know from ISO 9001, just applied to worker safety instead of product conformity. This is precisely why cross-discipline requirements so often overlap: document control, internal audit programmes, management review meetings, corrective action processes, and competence and training requirements all show up almost identically across standards, just pointed at different subject matter, quality outcomes in one case, environmental impact in another, information confidentiality in a third.

The practical benefits of recognising this shared structure are significant. Organisations that integrate rather than run parallel systems can consolidate what would otherwise be four sets of procedures, four document control systems, four internal audit programmes and four management reviews into one, and one procedure often satisfies requirements from multiple standards, with one audit checking compliance against all of them at once. Cost savings follow naturally, since external certification audits cost less when combined into a single integrated audit rather than paying for separate visits for each standard.

This is why certain combinations of standards are now pursued together as a matter of course. ISO 9001, ISO 14001, ISO 45001 and ISO 27001 are more commonly pursued in tandem today, driven by global supply chain expectations and stakeholder pressures, precisely because their shared Annex SL structure means the underlying management disciplines, planning, leadership, monitoring, review, transfer easily from one subject area to another. Manufacturing businesses typically integrate quality, environmental and safety systems, while IT companies more often combine quality with information security, reflecting where the practical overlaps in day-to-day operations naturally occur.

Where companies consistently go wrong is in assuming that structural similarity means the content is interchangeable. The temptation is to treat a shared clause number as a shared requirement, when in fact the standards are based on different models, specify different elements, and state similar requirements in different wording, meaning that although the standards are compatible and the models are not contradictory, this compatibility does not mean the specific obligations are identical. A generic "risk assessment" procedure built for ISO 9001's product-quality risks will not automatically satisfy ISO 45001's requirements around physical hazard identification, nor will it capture the confidentiality, integrity and availability risk model that ISO 27001 demands. Each standard's risk concept is shaped by its discipline, and treating them as one universal risk register often produces a document that technically exists but does not actually meet any standard's intent.

A related and very common mistake is confusing integration with rewriting everything from scratch, or alternatively, integration with cosmetic merging. Some organisations assume they need to rewrite every procedure, while others spend months reorganising documentation without improving how work is actually performed, and some successfully combine their manuals but leave employees following the same disconnected processes they used before, so the resulting system looks different on paper but doesn't function any differently in day-to-day operations. This is the paperwork trap: a beautifully unified manual sitting on top of teams that never actually changed how they operate, which auditors will eventually notice.

Specialised standards resist full integration more than generic ones, and companies often overestimate how far the Annex SL commonality extends. Some standards may pose challenges to integration due to their specialized or industry-specific requirements, for example ISO 27001's emphasis on information security controls and ISO 50001's focus on energy management, both of which involve highly technical, discipline-specific control sets that cannot simply be absorbed into a generic quality or safety procedure. Attempting to force these technical annexes into a generic shared process is a frequent source of non-conformities, because the depth of subject-matter expertise required for an information security risk treatment plan, for instance, is simply not equivalent to a generic corrective action form borrowed from the quality system.

Another overlooked issue is governance and ownership. Conflicting policies and responsibilities are a primary cause of failed integration, and organisations that maintain nominally separate systems frequently end up with duplicate documents, siloed responsibilities, and audit fatigue, spending more time managing the systems than actually improving performance. Even after committing to integration, many businesses underestimate the audit competence problem: auditors must be well-versed in all relevant ISO standards, and businesses must carefully align policies, procedures, and competencies to ensure a cohesive system that genuinely enhances performance, which is a much higher bar than simply appointing one management representative to sign off on everything.

Finally, companies commonly overlook the fact that shared documentation, while efficient, introduces its own risk of silent failure. Because ISO standards are structured similarly using the Annex SL framework, there are numerous areas where documentation overlaps, but if updates are not carefully tracked across every affected clause, human error can result in some documents being missed, leading to confusion or mistakes down the line and eventually non-conformances at the external audit. Shared systems demand more discipline in change control, not less, because a single missed update can now create a gap across several certifications simultaneously rather than just one.

In practice, the standards that succeed at integration are the ones where a company uses the Annex SL commonality as a genuine starting point for one lean operating system, while still respecting that each discipline, quality, environment, safety, information security, energy, brings its own technical depth, its own risk model, and its own specialist competence requirements that cannot be flattened into a single generic template. The organisations that stumble are almost always the ones that mistake structural resemblance for substantive equivalence, assuming that because two standards share a clause number, they must share the same answer.
​

If you need any advice or have any questions, then please get in touch - [email protected]

Don't forget to share this blog to help others with get great free advice

Picture
  • Meet Craig Willetts
    • Change The Game
    • Give Back
    • Go Paperless With ISO
    • Compliance Master
  • Business Articles
    • New Business Tips >
      • Cash Flow Planning
      • Cybersecurity Basics for SMEs
      • From Startup to Scale-Up
      • Train Your Brain
      • Organise Your Workspace
      • Colour use in Business
      • Writing a Business Plan
      • Setting KPI's
      • Website Building Instructions
      • Business Insurance
    • Business Development >
      • Building Strategic Partnerships
      • Social Media Essentials
      • Strategic Growth Planning
      • SEO Tips
      • Sell your product or service
    • General Business Tips >
      • How to price your services
      • IR35 Rules Explained
      • Meeting Tips
      • GDPR changes 2026
      • Health & Safety Law Updates
      • Making Tax Digital (MTD):
      • Problem Solving
      • Ensure Compliance
      • Health & Safety Tips
      • Cost-Effective Technology Solutions
      • Anti-Money Laundering Regulations
      • Customer Service Sector
      • Prevent burnout in your team
  • Sector specific articles
    • Security Sector
    • Construction Sector
    • Cleaning & FM Sector
    • Manufacturing Sector
    • Training Sector
    • Warehouse Sector
    • Project Management Sector
    • Healthcare Sector: Navigating CQC Compliance
  • Understanding People
    • How to Tell If Your Team Is Using AI
    • Onboarding New Employees: First 90 Days Checklist
    • Be A Great Employee
    • Understand Customers
    • Talent Management
    • How To Get The Most From Your Team
    • Stress at Work
    • Managing Remote and Hybrid Teams Effectively
    • Made it Mindset
  • ISO Standards Tips
    • Top 20 ISO Standards
    • ISO 9001 Tips
    • ISO 14001 Tips
    • ISO 45001 Tips
    • ISO 45003 Tips
    • ISO 31000 Tips
    • ISO 22301 Tips
    • ISO 27001 Tips
    • ISO 42001 Tips
    • ISO 17025 Tips
    • ISO 13485 Tips
    • ISO 18788 Tips
    • ISO 28000 Tips
    • ISO 28007 Tips
    • ISO 50001 Tips
    • ISO 17021 Tips
    • ISO 10015 Tips
    • ISO 37001 Tips
    • ISO 22000 Tips
    • ISO 37301 Tips
    • ISO 27701 Tips
    • ISO 20000 Tips
    • ISO 26000 Tips
    • ISO 15189 Tips
    • ISO 20121 Tips
    • Internal audits in plain English
    • Corrective Actions that work
    • Management Review Meeting
    • Integrating ISO Standards