Back to InsightsQuality Management

    Integrated Management System Certification: UK Guide

    Integrated management system certification is independent assessment of one management system meeting ISO 9001, ISO 14001 and ISO 45001 together — one policy set, one internal audit programme, one management review and one external audit cycle instead of three.

    By Ersin CETINPublished

    An ISO lead auditor and a QHSE manager review integrated management system documents on a mezzanine above a light-industrial production floor.

    Integrated management system certification is independent assessment of one management system that meets ISO 9001, ISO 14001 and ISO 45001 together, so your organisation runs a single certification cycle rather than three separate ones. In practice that means one set of quality, environmental and health and safety policies, one internal audit programme, one management review and one external assessment visit covering all three disciplines.

    This guide is written for QHSE, operations and quality managers at UK small and medium-sized organisations in manufacturing, construction and logistics. It explains what each standard covers, why the three integrate so cleanly, how certification runs from gap analysis to recertification, how accredited auditors size and price the work, and what to check before you appoint a certification body. For the wider picture of every standard we certify, see our ISO standards hub; the service itself is described on our integrated management system certification UK page. A shorter overview aimed at first-time buyers is in integrated management systems and ISO in the UK.

    Key Takeaways

    • An integrated management system (IMS) combines ISO 9001, ISO 14001 and ISO 45001 into one set of processes, cutting duplicate documentation, internal audits and management reviews.
    • Integration is practical because all three standards share the ISO Harmonised Structure: the same clauses 4 to 10, with the same core requirements.
    • Accredited certification bodies must size audits using IAF MD 5, starting from employee headcount and adjusting for risk and complexity.
    • IAF MD 11 sets the principle that requirements common to the three standards are audited once; certification bodies report total audit-time reductions of roughly a quarter to a third.
    • OHSAS 18001 is withdrawn — the IAF-set migration period closed in 2021, so only ISO 45001 counts as current health and safety certification.
    • In UK public-sector procurement ISO 9001 is a common requirement, and construction pre-qualification through the Common Assessment Standard (which replaced PAS 91 in 2023) expects accredited certification, so check a certification body's accreditation scope before you buy.

    Table of Contents

    What Is an Integrated Management System?

    An integrated management system, or IMS, is one management system that satisfies the requirements of more than one ISO standard through shared processes and documents, instead of parallel systems that repeat each other. For the QHSE core that means ISO 9001 for quality, ISO 14001 for environmental management and ISO 45001 for occupational health and safety, run as a single structure.

    Every modern ISO management system standard asks for the same building blocks: an understanding of the organisation's context and interested parties, a policy and measurable objectives, assessment of risks and opportunities, defined roles and competence, document and record control, operational planning and control, monitoring and measurement, internal audit, management review, and corrective action for continual improvement. In an IMS each of those exists once, and is written to serve quality, environmental and health and safety aims at the same time.

    The practical payoff is less duplication and fewer contradictions. One procedure controls how you raise and close a nonconformity, whether it came from a customer complaint, a spill or a near miss. One audit schedule covers the whole system. One management review looks at quality, environmental and safety performance next to each other — which is usually where the trade-offs between them become visible and get resolved.

    An IMS can extend to other standards, for example ISO/IEC 27001 for information security or ISO 22000 for food safety, because they use the same structure. This guide stays with the accredited QHSE core.

    What Integrated Management System Certification Actually Means

    Certification means an accredited certification body has audited your combined system against two or three standards in one assessment programme and issued certification — often as a single multi-standard certificate — on one three-year cycle with annual surveillance. Your organisation is certified. The body that assesses you is accredited. Those are different things, and the difference matters at tender stage.

    ISO 9001, ISO 14001 and ISO 45001 Compared

    The three standards share a structure and a management philosophy, but each governs a different risk area and tends to be demanded by a different buyer.

    AspectISO 9001 (Quality)ISO 14001 (Environmental)ISO 45001 (Health and safety)
    Primary focusConsistent products and services, customer satisfactionEnvironmental performance and compliancePrevention of work-related injury and ill health
    What it managesProcess control, risk-based thinking, improvement of quality outcomesEnvironmental aspects and impacts, compliance obligations, lifecycle viewHazard identification, OH&S risk control, worker consultation
    Who typically asks for itCustomers, OEMs and tier-1 buyers, tender evaluatorsRegulators, large clients, public-sector programmesPrincipal contractors, clients under CDM, insurers
    Typical triggerLost bid or customer mandate; recurring quality escapesPermit conditions; client environmental questionnaireSerious incident or near miss; pre-qualification requirement

    ISO 9001 is the world's most widely used management system standard, with over one million valid certificates recorded across more than 180 countries in the ISO Survey. Its requirements sit in clauses 4 to 10 and centre on understanding customer requirements, controlling the processes that deliver them, and using data to improve.

    ISO 14001 manages environmental performance: identifying aspects and impacts such as emissions, waste, discharges and energy use, keeping a register of compliance obligations, and setting objectives to control significant impacts across the lifecycle of products and services.

    ISO 45001 manages occupational health and safety. It replaced OHSAS 18001 and, unlike the old specification, follows the shared ISO structure. It is more proactive: hazards, risks and opportunities must be addressed before incidents occur, and worker consultation and participation is a formal requirement rather than an optional extra.

    Why the ISO Harmonised Structure Makes Integration Practical

    Diagram mapping the shared ISO clauses 4 to 10 across ISO 9001, ISO 14001 and ISO 45001 in an integrated management system.

    Integration works because all three standards are built on the ISO Harmonised Structure, formerly the High-Level Structure or Annex SL. Clauses 4 to 10 use the same numbering and the same core wording across ISO 9001, ISO 14001 and ISO 45001.

    In concrete terms, clause 4 (context), clause 5 (leadership), clause 6 (planning), clause 7 (support), clause 8 (operation), clause 9 (performance evaluation) and clause 10 (improvement) appear in all three standards with the same intent. So a single context and interested-parties analysis can list quality, environmental and safety interested parties together. One competence procedure covers all three. One internal audit procedure, one management review agenda and one corrective action process serve the whole system.

    The differences live mainly inside clauses 6 and 8. ISO 14001 adds environmental aspects, compliance obligations and lifecycle thinking. ISO 45001 adds hazard identification, OH&S risk assessment, safety-specific legal requirements and worker consultation. ISO 9001 keeps the tighter focus on customer requirements and product and service conformity. A well-built IMS shares clauses 4, 5, 7, 9 and 10 almost entirely, and keeps clearly labelled sections for the standard-specific parts of 6 and 8.

    ISO 45001 and the End of OHSAS 18001

    OHSAS 18001 is withdrawn. The IAF-set migration period from OHSAS 18001 to ISO 45001 closed in 2021, so certificates to it are no longer issued or maintained — the background is set out on our ISO 45001 vs OHSAS 18001 page. ISO 45001 is the only current option, and for anyone building an IMS that is helpful, because OHSAS 18001 never used the shared structure and always sat awkwardly alongside ISO 9001 and ISO 14001.

    Two changes matter most when you move across. First, structure: ISO 45001 adopts clauses 4 to 10, so it slots into an integrated system the same way ISO 14001 does. Second, emphasis: ISO 45001 expects you to be proactive, identifying and controlling hazards before harm occurs, and it requires genuine worker consultation in how the system is designed and run. If you are weighing the transition, the requirements are set out on our ISO 45001 certification page.

    How Integrated Certification Works, Step by Step

    Three-year integrated certification cycle timeline showing gap analysis, Stage 1, Stage 2, two surveillance audits and recertification.

    The route to an integrated certificate follows the same sequence as a single-standard project, with the shared clauses assessed once.

    1. Gap analysis. An assessor compares your current processes against all three standards and lists what is missing or weak. For an IMS this is efficient, because one review covers the shared clauses at once.
    2. Documentation and implementation. You build or adapt the system: integrated policy, objectives, risk and opportunity assessments, environmental aspects register, hazard and risk assessments, operational controls, and the shared procedures for document control, competence, internal audit, management review and corrective action. The system then needs to run long enough to generate records.
    3. Internal audit and management review. Before the certification body arrives you audit the whole system yourself and hold a management review. Both are mandatory. Our ISO 19011:2026 auditing guide sets out how to plan that programme, and how to prepare for an ISO 9001 audit covers the evidence auditors ask for.
    4. Stage 1 audit (readiness review). The certification body checks that the system is documented, that internal audit and management review have taken place, and that you are ready for full assessment. Stage 1 findings tell you what to fix before Stage 2.
    5. Stage 2 audit (certification assessment). The audit team assesses the system in operation against every standard in scope, gathering evidence across sites and processes. Nonconformities are graded, and major findings must be resolved before certification can be recommended — see can you fail an ISO audit? for how findings are handled in practice.
    6. Certification decision. An independent reviewer inside the certification body checks the audit file and the evidence that findings are closed, then decides on certification. Certificates are issued for a three-year period.
    7. Surveillance audits. In years one and two the certification body returns for a shorter audit to confirm the system is still working and improving. Surveillance always includes internal audit, management review, corrective action and use of certification marks — explained further in what happens after ISO certification.
    8. Recertification. Before the three-year certificate expires, a fuller audit — larger than surveillance, smaller than the initial Stage 2 — renews the cycle.

    How Accredited Auditors Size and Cost an Integrated Audit

    Accredited certification bodies do not price audits freely. They must calculate audit duration using IAF MD 5, which starts from your effective employee headcount and then adjusts for risk, complexity, number of sites, range of processes and system maturity.

    As a guide for ISO 9001, an initial audit covering Stage 1 and Stage 2 runs to roughly 1.5 auditor-days for a very small organisation of one to five staff, around five to seven auditor-days for 50 to 100 staff, and eight or more auditor-days at 150 staff and above. Results are rounded to the nearest half-day. Surveillance audits are about one third of the initial audit time and recertification about two thirds, on a three-year cycle with annual surveillance. For indicative fee ranges by standard and company size, see our ISO certification cost guide, estimate your own figure with the ISO certification price calculator, or request a tailored quote.

    How Much Does Integration Cut Audit Days?

    Bar chart comparing separate ISO 9001, ISO 14001 and ISO 45001 audits with a single integrated audit, showing roughly 25 to 33 percent fewer audit days under the IAF MD 11 principle.

    Auditing two or three standards together removes repeated assessment of the shared clauses and typically reduces total audit time by roughly a quarter to a third. IAF MD 11 establishes the principle: requirements common to the standards are audited once rather than repeated for each standard. The exact figure varies with scope and integration maturity, so treat any single percentage with caution.

    The saving comes from the shared clauses named earlier — leadership, context, system-level planning, support, internal audit, management review and improvement are assessed once for the whole system. The audit team still spends full time on the standard-specific parts, so an IMS with very different environmental and safety risk profiles saves less than one where the operational controls overlap heavily.

    There is a second, quieter saving in your own time: one set of auditors on site for one block of days, one opening and closing meeting, one corrective action round afterwards. For a lean QHSE function that internal saving often matters as much as the audit fee.

    Accredited or Certified: What UK Buyers Should Check

    Certification and accreditation are not the same, and buyers confuse them often. A certification body grants your organisation a certificate. An accreditation body assesses and approves the certification body against ISO/IEC 17021-1 and the related IAF mandatory documents. A certificate only carries weight if the body that issued it is accredited for that specific standard.

    Before appointing a body, check three things. First, that its accreditation scope actually lists ISO 9001, ISO 14001 and ISO 45001 — not just some of them. Second, whether your customers or target tenders specify a particular accreditation: in the UK, ISO 9001 is a common requirement in public-sector procurement, and construction pre-qualification through the Common Assessment Standard (which replaced PAS 91 after its withdrawal in 2023) expects UKAS-accredited certification. Third, whether the accreditation is covered by the IAF Multilateral Recognition Arrangement, designed so a certificate issued once is accepted across markets.

    UniCert holds accreditation for ISO 9001, ISO 14001 and ISO 45001 through the United Accreditation Foundation (UAF), an IAF MLA signatory, so the QHSE core in this guide sits within that scope. If a contract you are bidding for specifically names a UKAS-accredited certificate, confirm that requirement with the buyer before choosing any certification body, because accreditation marks are not interchangeable for every procurement. Our accreditation page explains the difference in full, and is UAF accreditation recognised in the UK? gives the honest answer.

    Sector Considerations: Manufacturing, Construction and Logistics

    Construction site manager and safety officer reviewing an integrated QHSE plan against site controls on a UK project.

    The management system structure is identical across sectors. What changes is the risk you are controlling, the operational detail the auditor tests, and the customer who asked for the certificate.

    Manufacturing

    For manufacturers, ISO 9001 assessment concentrates on process control, calibration, control of nonconforming output, traceability and supplier management. Environmental aspects tend to be concrete: solvents, swarf, energy, waste streams. Safety hazards are machinery, manual handling, noise and hazardous substances. Integration is usually straightforward because the same production process is the subject of all three standards. See ISO certification for manufacturing.

    Construction

    Construction organisations almost always need ISO 9001 and ISO 45001 together, and often ISO 14001 as well, because principal contractors and public bodies ask for all three at pre-qualification. The system has to align with duties under the Construction (Design and Management) Regulations 2015, particularly around planning, competence, site supervision and information flow. See ISO certification for construction.

    Logistics and Services

    For logistics and service organisations the output is less tangible, so ISO 9001 assessment looks harder at service definition, competence, subcontractor control and how you measure customer satisfaction and on-time performance. Environmental focus is often fleet emissions, fuel and packaging. See ISO certification for logistics, and for smaller service firms ISO certification for small businesses in the UK.

    Turning This Into an Integrated Certification Plan

    An integrated management system gives you one system, one audit cycle and one improvement loop across quality, environment and safety. It is practical because ISO 9001, ISO 14001 and ISO 45001 share clauses 4 to 10, and it is efficient because an accredited body can assess those shared clauses once under IAF MD 11.

    The next step for most organisations is a gap analysis against all three standards at the same time, so you can see the shared work and the standard-specific work in one list. Before you appoint a certification body, confirm that its accreditation scope covers all three standards and check whether any tender you are targeting names a specific accreditation. You can start with a free gap analysis or request a quote.

    References

    1. ISO — The ISO Survey of Certifications. Annual count of valid certificates by standard, sector and country; figures are self-reported by accredited certification bodies.
    2. ISO — ISO 9001:2015, Quality management systems — Requirements.
    3. ISO — ISO/IEC Directives Part 1, Consolidated ISO Supplement, Annex SL (Harmonised Structure for management system standards), iso.org.
    4. ISO — ISO 45001:2018, Occupational health and safety management systems.
    5. ISO and IAF — migration guidance from OHSAS 18001 to ISO 45001; the IAF-set migration period closed in 2021.
    6. IAF — MD 5:2019, Determination of Audit Time of Quality, Environmental and Occupational Health & Safety Management Systems, iaf.nu.
    7. IAF — MD 11:2013, Application of ISO/IEC 17021-1 for Audits of Integrated Management Systems, iaf.nu.
    8. ISO/IEC — ISO/IEC 17021-1:2015, Requirements for bodies providing audit and certification of management systems.
    9. IAF — Multilateral Recognition Arrangement (MLA).
    10. The Common Assessment Standard (Build UK / CHAS / Constructionline), which replaced BSI PAS 91 after its withdrawal in 2023.

    About the Author

    Ersin CETIN is an ISO Lead Auditor at UniCert who audits integrated quality, environmental and occupational health and safety management systems for UK and international organisations, across gap analysis, initial certification, surveillance and recertification. Reviewed by Eren ISMAN, Lead Auditor at UniCert, on 28 August 2026.

    Editorial note: UniCert is an accredited certification body working with organisations in the UK and internationally, accredited by the United Accreditation Foundation (UAF) for ISO 9001, ISO 14001 and ISO 45001, and an IAF MLA signatory through that accreditation. Accreditation scope and current status are published on our accreditation page.

    Frequently Asked Questions

    Can we certify to ISO 9001 first and add ISO 14001 and ISO 45001 later?

    Yes. You can certify one standard now and extend the scope at a later surveillance or recertification audit. Adding standards later usually costs more total audit time than certifying together, because the shared clauses are assessed again as each standard joins. If you already know all three are coming, integrating from the outset is the more efficient route.

    Do we need three separate certificates or one?

    Most certification bodies can issue a single certificate listing every standard in scope, separate certificates per standard, or both. The underlying assessment is the same. A single multi-standard certificate is common in tender packs because it shows at a glance that quality, environment and safety are managed in one system.

    How long does integrated certification take?

    For a UK SME building its first system, a realistic range is a few months to about a year from gap analysis to the Stage 2 audit, depending on how much already exists and how much management time is available. The system also has to run long enough to produce records, including at least one full internal audit and one management review before Stage 2.

    Is ISO 45001 certification mandatory in the UK?

    No. There is no legal requirement to hold ISO 45001 certification, and UK health and safety law applies regardless. Certification is often required commercially by principal contractors, large clients and some pre-qualification schemes, and it is one recognised way to show that safety management is systematic.

    We still hold an OHSAS 18001 certificate. Is it valid?

    No. The IAF-set migration period from OHSAS 18001 to ISO 45001 closed in 2021 and OHSAS 18001 is withdrawn, so certificates to it are no longer issued or maintained. You would need to transition to ISO 45001 through a certification audit against the current standard.

    Does an integrated audit automatically mean a cheaper audit?

    It usually means fewer total audit days than three separate audits, because the shared clauses are assessed once. It does not make each standard cheaper to run internally, and a poorly integrated system where procedures still contradict each other can take longer to audit. Preparation still decides the outcome.

    UniCert certification services background

    Take the Next Step with UniCert

    From ISO 9001 quality management to cyber security and supply chain assurance – UniCert provides the management system certification you need to unlock global markets.

    Consent to Cookies & Data Processing

    We use cookies for analytics and improving your experience. This consent is voluntary and can be revoked at any time.