Integrated ISO management
Four standards, one management system. This cluster explains how quality, service management, information security and AI governance share a single spine of risks, controls, owners and evidence — and links the guides that go deeper at each stage.
Start here
The spine is the same whichever standard you hold: Risk → Control → Owner → Evidence → Audit → Action → Review → Assurance. Read how the integrated management system works for the product view, and risk, controls and evidence for the three records everything else depends on.
The four standards
One guide per standard, written for technology and professional-services organisations rather than factories.
Process approach, context, customer satisfaction and improvement.
Service catalogue, change control and service commitments.
Annex A justification, exclusions and evidence expectations.
AI inventory, impact assessment, oversight and review.
Shared foundations across the standards
Where the management system starts and stops, and why it matters.
Interested parties, issues and requirements — clause 4 done once.
A consistent risk method behind every standard you hold.
Drafting, approval, acknowledgement and review across standards.
Sampling and evidence that stands up without consuming a month.
Clause 10 as a working habit rather than an audit answer.
Sector-specific reading
Deciding how to run it
Where spreadsheets hold up, and where traceability breaks.
One register across standards, or one system per standard.
What each approach leaves behind after certification.
Scope, configuration effort and who actually operates it.
The other resource clusters
Security certification, questionnaires and trust evidence.
AI governance, impact assessment and oversight.
Service commitments, change and incident control.
Testing controls, closing actions and reviewing performance.
Running several client management systems from one workspace.
Answers buyers, procurement and auditors want
What is an integrated management system?+
One set of risks, controls, owners and evidence that satisfies the requirements of several standards at once, rather than a separate register, policy set and audit programme for each standard.
Which standards can be integrated?+
ISO 9001, ISO/IEC 20000-1, ISO/IEC 27001 and ISO/IEC 42001 share the Annex SL high-level structure — context, leadership, planning, support, operation, performance evaluation and improvement — so clauses 4 to 10 can be operated once. Cyber Essentials and GDPR obligations map into the same control set as supporting work.
Do we need all four standards?+
No. Most organisations start with one, usually ISO/IEC 27001, and add the next when a customer, tender or regulator asks for it. Starting on a shared register means the second standard is mostly mapping rather than a fresh build.
Does one certification audit cover them all?+
Certification is awarded independently by an accredited certification body. Many bodies offer combined or integrated audits covering more than one standard in a single visit, but the scope, duration and outcome are decided by that body, not by us.
See how your existing risks, controls and evidence could become one integrated management system
Bring what you already have — a part-finished risk register, a folder of policies, last year's audit findings — and see it mapped across the standards you need.
Prefer a conversation? Email hello@iso-standard.app — a practitioner responds within one business day.