Integrated versus separate management systems

Adding a second standard raises a structural question that is easier to answer early: does it join the system you already run, or become a system of its own? Both are legitimate. The costs land in different places.

What integration actually means

Integration is not a single merged document. It is one set of records — risks, controls, owners, evidence, audits, actions and reviews — where each control declares every standard it satisfies. Clause 4 to 10 work is done once. Standard-specific requirements, such as Annex A for ISO/IEC 27001 or the AI system inventory for ISO/IEC 42001, remain distinct.

ConsiderationSeparate system per standardOne integrated system
Common clauses (4–10)Written and maintained per standardWritten once, referenced by each standard
ControlsDuplicated wording across registersOne control, mapped to every standard it meets
EvidenceCollected separately for each auditCollected once, reused across audits
Internal auditA programme per standardOne programme covering all in-scope standards
Management reviewSeveral meetings, overlapping inputsOne review with per-standard sections
Adding the next standardLargely a fresh buildMostly mapping plus the gaps that are genuinely new
Risk if scope is unclearLower — boundaries are explicitHigher — scope statements must be written carefully
Fits best whenDifferent entities, teams or scopes hold each standardShared people, systems and customers across standards

A practical route

Start with the standard a customer or tender actually requires, but build the register as if others will follow: one control set, named owners, dated evidence, explicit standard mappings. That way the second standard is an exercise in mapping and filling gaps, not a second programme. How the integrated system works sets out the structure in detail.

Deciding how to run it

Answers buyers, procurement and auditors want

Is an integrated management system allowed?+

Yes. The ISO management system standards share the Annex SL structure precisely so that common clauses — context, leadership, planning, support, performance evaluation and improvement — can be operated once across several standards.

Does integration make the audit harder?+

Not usually, but scope must be clear. Certification bodies commonly run combined or integrated audits; the body decides duration and approach. Poorly separated scope statements cause more findings than integration itself.

When is keeping them separate the better answer?+

When different legal entities, very different scopes, or entirely separate teams hold the standards, and there is little shared infrastructure or process between them.

See how your existing risks, controls and evidence could become one integrated management system

Bring what you already have — a part-finished risk register, a folder of policies, last year's audit findings — and see it mapped across the standards you need.

Prefer a conversation? Email hello@iso-standard.app — a practitioner responds within one business day.

AI-enabled — privacy-respecting

AI does the drafting. You keep the control — and the data.

How we handle data →
  • AI that assists — not replaces

    Assisted drafting for policies, risks, controls and buyer questionnaires. Every AI suggestion is reviewed and approved by you before it lands in the record.

  • Opt-in, workspace-scoped

    AI features run only when you invoke them, only against the workspace you're in. We never mine your data to answer someone else's prompt.

  • Your data stays yours

    Prompts routed via the AI Gateway to model providers whose API terms exclude your content from model training. Nothing is sold or shared for advertising.

  • Isolated by design

    Row-level security enforces workspace boundaries at the database. MFA, SSO, audit logs and least-privilege roles govern who sees what.

We never sell personal information, never share it for advertising, and never use your workspace content to train third-party models. Full sub-processor list and Acceptable Use Policy on the Trust page.

MM
Michael McCarroll
Founder · 25+ years
IT governance · Information security · AI
Why this platform exists

Enterprise-grade governance — built for the SMEs and consultants enterprise GRC forgets.

I've spent 25 years in corporate governance — aligning technology, controls and compliance with what the business is actually trying to do. Time and again, the same pattern: the organisations that win new clients aren't the ones with the biggest GRC budget. They're the ones who can demonstrate trust on demand. This platform is the tool I wanted for the SMEs and consultants I've worked with — institutional-grade governance without an institutional price tag, built on the way audits and buyer reviews actually happen.