If your organization needs ISO 9001 for quality, ISO 27001 for information security, and now ISO 42001 for AI governance, you don't need three management systems — you need one. All three standards are built on the same skeleton, the Harmonized Structure (formerly Annex SL), which deliberately makes clauses 4–10 nearly identical across every modern ISO management system standard. An Integrated Management System (IMS) exploits that shared skeleton: one context analysis, one leadership framework, one document control process, one internal audit program — with each standard's discipline-specific requirements layered on top.
The Shared Skeleton: Annex SL / Harmonized Structure
ISO mandates the same high-level structure, core text, and common terms for all management system standards. Clauses 4–10 are identical in name and largely in content:
- Clause 4 — Context: interested parties, scope of the management system.
- Clause 5 — Leadership: top management accountability and a policy.
- Clause 6 — Planning: risk and opportunity management, objectives.
- Clause 7 — Support: competence, awareness, communication, documented information.
- Clause 8 — Operation: the discipline-specific operational controls.
- Clause 9 — Performance evaluation: monitoring, internal audit, management review.
- Clause 10 — Improvement: nonconformity, corrective action, continual improvement.
Everything except Clause 8 is generic enough to be shared. That is the whole economic argument for integration: roughly 60–70% of a management system is common machinery, and you should only pay to build it once.
What an Integrated Management System Actually Is
An IMS is a single set of processes, policies, and documentation that satisfies multiple standards simultaneously — not three parallel systems stapled together. In practice: one scope statement defining what each standard covers, one integrated policy (or a policy hierarchy), one risk framework with discipline-specific risk objects, one competence and training program, one document control system, one internal audit schedule, and one management review where all standards' KPIs are discussed together. Certification bodies audit it as an integrated audit — one audit team, one visit, three certificates.
How the Three Standards Map
The shared clauses carry different discipline content. Here's how the same clause reads under each standard:
| Clause | ISO 9001 (Quality) | ISO 27001 (InfoSec) | ISO 42001 (AI) |
|---|---|---|---|
| 4 Context | Customer needs, market, processes | Information assets, threat landscape | AI systems in scope, stakeholder impacts |
| 5 Leadership | Quality policy, customer focus | Information security policy | AI policy, accountability for AI |
| 6 Planning | Quality risks & objectives | Risk assessment, risk treatment, SoA | AI risk + impact assessment, AI SoA |
| 7 Support | Largely shared: competence, awareness, communication, documented information | ||
| 8 Operation | Product/service realization, design, suppliers, nonconforming output | Risk treatment operation, Annex A controls | AI life-cycle processes, impact assessments, Annex A controls |
| 9–10 Evaluation & improvement | Shared machinery: monitor, internal audit, management review, corrective action — run once, report per standard | ||
Where the Standards Genuinely Diverge
Integration doesn't mean pretending the standards are the same. Each has a different risk object — the thing the risk assessment is about:
- ISO 9001 manages risks to quality outcomes — product conformity and customer satisfaction.
- ISO 27001 manages risks to information security — confidentiality, integrity, availability of information assets.
- ISO 42001 manages risks from AI systems — impacts on individuals, groups, and society, plus AI-specific risk.
Each therefore needs its own risk register (or clearly separated sections of one), its own discipline objectives, and its own Statement of Applicability — both 27001 and 42001 use the SoA mechanism for their respective Annex A control sets (93 controls, 38 controls). Clause 8 is fully discipline-specific and stays separate.
The Benefits — and the Honest Trade-offs
Done well, integration compounds. One document-control system instead of three; one integrated internal audit that tests all standards in the same pass; one management review instead of three meetings producing three sets of minutes; shared competence records; and a single surveillance/certification audit visit, which alone cuts audit fees substantially. There's a subtler benefit too: disciplines stop being silos — the AI governance conversation happens in the same management review where quality and security already live.
The trade-offs are real but manageable: integrated documentation is harder to write the first time (it must satisfy the strictest standard's requirements); internal auditors need competence across all disciplines or the audit team needs mixed expertise; and a badly designed IMS can bury discipline-specific rigor inside generic process. The failure mode isn't complexity — it's dilution.
Recommended Implementation Order
- Start with your strongest existing system. Most organizations already run ISO 9001 — its process documentation and audit muscle become the chassis.
- Add ISO 27001 next. It has the heaviest risk machinery (formal risk assessment, SoA, 93 controls) — build that once and reuse the pattern.
- Layer ISO 42001 last. Its management-system clauses map 1:1 onto what you've built; the delta is the AI-specific work — impact assessments, AI system inventory, and the 38 Annex A controls.
- Harmonize documentation as you go. Merge policies, consolidate the risk framework, unify internal audit and management review — rather than bolting each standard on as a separate binder.
If you're starting from zero, the order can flip: 27001 first builds the strongest governance muscles (risk assessment, SoA discipline, evidence culture), and 9001 and 42001 slot in more easily afterward.
Baseline All Three in an Afternoon
Before designing an IMS, know where each discipline stands. Our free browser-based assessments walk you through each standard's clauses and control themes and produce PDF reports you can compare side by side: the ISO 9001 Readiness Checker, the ISO 27001 Gap Analysis, and the ISO 42001 AI Readiness Assessment. Three scores on a common 0–100 scale make the integration case (and the priority order) obvious. For deeper dives: gap analysis methodology and the ISO 42001 implementation guide.
Frequently Asked Questions
What is an integrated management system (IMS)?
A single management system — one set of processes, policies, and documentation — that satisfies multiple ISO standards at once, rather than running parallel systems for each. It works because all modern ISO management standards share the Harmonized Structure (clauses 4–10), so context, leadership, support, evaluation, and improvement processes can be shared while discipline-specific requirements (mainly Clause 8 and Annex A controls) stay separate.
Can ISO 9001, ISO 27001, and ISO 42001 really share one system?
Yes — all three follow the same high-level structure with nearly identical management clauses. Each keeps its own risk register, objectives, operational controls, and Statement of Applicability (27001 and 42001), but policies, competence, document control, internal audit, and management review can be fully integrated. Certification bodies routinely perform integrated audits covering all three in a single engagement.
Which standard should we implement first?
Build on whichever system is most mature — usually ISO 9001. If starting from scratch, ISO 27001 first is often the best foundation because its formal risk assessment and Statement of Applicability discipline are the hardest machinery to build, and both ISO 9001 and ISO 42001 then slot onto proven processes.
Does an IMS reduce audit costs?
Significantly. Certification bodies offer integrated audits — one audit team covering multiple standards in a single visit — because the shared clauses are audited once rather than three times. Combined with one surveillance cycle and one management review, total audit effort typically drops 30–40% versus three standalone certifications.
What are the risks of integrating too much?
Dilution. Each standard protects a different thing — product quality, information security, and AI impacts — so risk registers, objectives, and Clause 8 operations must remain discipline-specific. An IMS that blurs these into generic processes loses the rigor auditors test for. Share the machinery; keep the accountability separate.




