Integrated versus separate management systems
Adding a second standard raises a structural question that is easier to answer early: does it join the system you already run, or become a system of its own? Both are legitimate. The costs land in different places.
What integration actually means
Integration is not a single merged document. It is one set of records — risks, controls, owners, evidence, audits, actions and reviews — where each control declares every standard it satisfies. Clause 4 to 10 work is done once. Standard-specific requirements, such as Annex A for ISO/IEC 27001 or the AI system inventory for ISO/IEC 42001, remain distinct.
| Consideration | Separate system per standard | One integrated system |
|---|---|---|
| Common clauses (4–10) | Written and maintained per standard | Written once, referenced by each standard |
| Controls | Duplicated wording across registers | One control, mapped to every standard it meets |
| Evidence | Collected separately for each audit | Collected once, reused across audits |
| Internal audit | A programme per standard | One programme covering all in-scope standards |
| Management review | Several meetings, overlapping inputs | One review with per-standard sections |
| Adding the next standard | Largely a fresh build | Mostly mapping plus the gaps that are genuinely new |
| Risk if scope is unclear | Lower — boundaries are explicit | Higher — scope statements must be written carefully |
| Fits best when | Different entities, teams or scopes hold each standard | Shared people, systems and customers across standards |
A practical route
Start with the standard a customer or tender actually requires, but build the register as if others will follow: one control set, named owners, dated evidence, explicit standard mappings. That way the second standard is an exercise in mapping and filling gaps, not a second programme. How the integrated system works sets out the structure in detail.
Deciding how to run it
Where spreadsheets hold up, and where traceability breaks.
One register across standards, or one system per standard.
What each approach leaves behind after certification.
Scope, configuration effort and who actually operates it.
Answers buyers, procurement and auditors want
Is an integrated management system allowed?+
Yes. The ISO management system standards share the Annex SL structure precisely so that common clauses — context, leadership, planning, support, performance evaluation and improvement — can be operated once across several standards.
Does integration make the audit harder?+
Not usually, but scope must be clear. Certification bodies commonly run combined or integrated audits; the body decides duration and approach. Poorly separated scope statements cause more findings than integration itself.
When is keeping them separate the better answer?+
When different legal entities, very different scopes, or entirely separate teams hold the standards, and there is little shared infrastructure or process between them.
See how your existing risks, controls and evidence could become one integrated management system
Bring what you already have — a part-finished risk register, a folder of policies, last year's audit findings — and see it mapped across the standards you need.
Prefer a conversation? Email hello@iso-standard.app — a practitioner responds within one business day.