Primary Focus: integrated management system problems
Secondary Focus: IMS integration, integrated management system, ISO management systems, IMS implementation, ISO 9001 ISO 14001 ISO 45001 ISO 27001

An organization can hold four ISO certifications and still have four separate management systems.

That may sound contradictory, but it is a common reality.

A company may have ISO 9001 for quality, ISO 14001 for environmental management, ISO 45001 for occupational health and safety, and ISO 27001 for information security—yet each system may still have its own risk register, audit programme, procedures, KPIs, corrective-action workflow and management review.

On paper, the organization has an Integrated Management System (IMS).

In practice, it has four systems sitting next to each other.

This distinction matters.

In 2026, ISO published the third edition of Integrated management systems – A practical guide, specifically to help organizations using multiple management system standards build one cohesive and efficient system. ISO describes the integration challenge in terms of duplicated processes, inconsistent documentation and unnecessary effort, and provides a three-step model: Prepare, Connect and Integrate.

The real question for management, therefore, is not:

“Do we have an IMS?”

It is:

“Are our management systems actually operating as one business system?”

What Does a “Not Really Integrated” IMS Look Like?

Imagine a manufacturing company certified to four standards.

It has:

  • A Quality Manager responsible for ISO 9001
  • An EHS Manager responsible for ISO 14001 and ISO 45001
  • An IT/Security Manager responsible for ISO 27001
  • Separate risk registers
  • Separate internal audit schedules
  • Separate corrective-action systems
  • Separate KPIs
  • Separate management-review presentations

The organization may describe itself as having an IMS.

But employees experience something different.

A production manager may receive:

Quality audit findings → from Quality

Safety observations → from EHS

Environmental findings → from Sustainability/EHS

Cybersecurity actions → from IT

Each function may be performing correctly.

The problem is that the business process is not integrated.

This is the central IMS problem:

Integration is not the same as coexistence.

Four systems using the same logo, document template or management-system manual do not automatically become one integrated management system.

The Four Levels of IMS Integration

A useful way to understand the problem is to look at integration as a maturity journey.

Level What happens Typical situation
Level 1 – Separate Each standard operates independently Four systems, four owners
Level 2 – Coordinated Activities are scheduled together Combined audit calendar, shared meetings
Level 3 – Integrated Common processes are managed together Shared risks, audits, corrective actions
Level 4 – Business-led Management requirements are embedded into business processes ISO requirements become part of normal operations

Many organizations believe they are at Level 3 because they have a document called an “IMS Manual.”

But the more important test is what happens on the shop floor, at a project site, in procurement, during management review and when something goes wrong.

Problem 1: Four Risk Registers for One Business

One of the clearest signs of weak integration is multiple risk registers.

Consider a supplier that provides a critical component.

Quality may identify:

Risk of defective components.

EHS may identify:

Risk associated with unsafe handling.

Environmental management may identify:

Environmental impact associated with the supplier’s process.

Information security may identify:

Risk of unauthorized access to supplier-related information.

Business continuity may identify:

Risk of production interruption if the supplier fails.

These are not necessarily five unrelated business events.

They may originate from one supplier relationship.

The better question

Instead of asking:

“Which ISO standard owns this risk?”

Ask:

“What business process creates this risk, and which consequences does it have?”

That change in perspective is fundamental to IMS.

A simple illustration

Suppose a company has 100 identified risks.

If each of four functions maintains its own register containing 100 entries, management could potentially be reviewing 400 risk records.

That does not mean 400 unique risks exist.

There may be significant duplication.

If integration identifies even 25% overlap:

400 records × 25% = 100 potentially overlapping records.

The point is not that every organization will achieve exactly 25% reduction. The illustration shows why counting risk registers is less useful than understanding risk relationships.

Problem 2: The Same Corrective Action Appears Four Times

Another common IMS problem occurs after an incident.

Imagine a machine failure causes:

  • Product defects
  • Production downtime
  • Excessive energy consumption
  • A worker safety concern

Four functions may investigate the same event.

Quality opens a corrective action.

EHS opens another.

Environmental management opens another.

Operations opens another.

The company now has four investigations describing different pieces of the same problem.

This can create a dangerous situation:

Each department fixes its symptom while nobody fixes the system problem.

An integrated corrective-action process should ask:

  1. What happened?
  2. What was the immediate cause?
  3. What were the underlying causes?
  4. Which business processes were affected?
  5. Which management-system requirements were affected?
  6. Does the issue indicate a broader systemic problem?
  7. What action will prevent recurrence?

The objective is not to eliminate specialist investigations.

It is to connect them around the underlying business problem.

Problem 3: Separate Audits Are Creating Audit Fatigue

Consider a company with:

  • 10 quality audits
  • 8 environmental audits
  • 10 safety audits
  • 6 information-security audits

That is potentially:

10 + 8 + 10 + 6 = 34 audit activities

The actual number will vary significantly by organization and certification arrangements. But the illustration shows how quickly audit activity can become fragmented.

Now consider a business process such as procurement.

A process-based integrated audit could examine:

Procurement

Quality

  • Supplier quality
  • Incoming-material requirements
  • Supplier performance

Environment

  • Environmental criteria
  • Relevant environmental impacts

OH&S

  • Contractor safety
  • Competence
  • Safety-related purchasing controls

Information security

  • Supplier access
  • Confidential information
  • Cybersecurity requirements

Instead of asking four auditors to examine procurement independently, the organization can assess the process as a whole, while retaining specialist competence where required.

ISO’s 2026 guide specifically includes practical guidance for integrated audits and management reviews.

Problem 4: Management Review Becomes Four Presentations

Here is another warning sign.

The leadership team receives:

Presentation 1

Quality performance

Presentation 2

Environmental performance

Presentation 3

Health & safety performance

Presentation 4

Information-security performance

Each presentation may be technically correct.

But what does management actually need to know?

They need to understand:

How is the organization performing, where are the biggest risks, what is changing, and what decisions are required?

A mature IMS should help management connect these issues.

For example:

New production line

Higher production volume

Potential quality risks

Higher energy consumption

New environmental aspects

New machinery hazards

New operational technology

Additional cybersecurity exposure

Training and competency requirements

That is a business decision with multiple management-system consequences.

An integrated system makes those connections visible.

Problem 5: KPIs Are Measuring Departments Instead of Processes

Another common problem is KPI fragmentation.

Imagine:

Function KPI
Quality Customer complaints
Environment Waste generated
Safety Lost-time injuries
Information security Security incidents

These KPIs are useful.

But management may still lack a clear view of the performance of the underlying process.

For example, a manufacturing process could be evaluated using a broader performance dashboard:

Quality: First-pass yield

Environment: Energy consumed per unit

Safety: Recordable incident rate / safety observations

Operations: Overall equipment effectiveness

Customer: On-time delivery

Security: Relevant access/control incidents

The objective is not to create a giant dashboard.

In fact, more KPIs can make an IMS worse if employees spend more time collecting data than managing performance.

The better approach is to identify the relatively small number of indicators that help management understand whether critical business processes are achieving their objectives.

Problem 6: Employees Don’t Know Which System Applies

This is perhaps the most practical test.

Ask an employee:

“You have identified a problem in your process. What do you do?”

If the answer is:

“It depends. If it is a quality issue, I contact Quality. If it is a safety issue, I contact EHS. If it is an information-security issue, I contact IT.”

the system may still be functionally separated.

A better experience is:

“I report the issue through our business process. The system determines which requirements and specialists need to be involved.”

That is what integration should feel like to employees.

The IMS Integration Test

ASPM Consulting can use a simple diagnostic framework to assess whether an organization’s IMS is genuinely integrated.

Score each area from 0 to 2:

0 = Separate

1 = Partially coordinated

2 = Integrated

Area Score
Governance /2
Risk management /2
Compliance management /2
Business processes /2
Documentation /2
Internal audits /2
Corrective actions /2
Performance monitoring /2
Management review /2
Continual improvement /2
Total /20

Illustrative interpretation

0–7: Fragmented

The standards largely operate independently.

8–13: Coordinated

There is some cooperation, but core systems remain departmental.

14–17: Integrated

Common processes are shared and management has a more consolidated view.

18–20: Business-led IMS

Management-system requirements are deeply embedded into business processes and decision-making.

This is an illustrative maturity framework, not an ISO scoring method or certification requirement.

The Mandar Pandit Perspective: Integration Should Follow the Business

Mandar Pandit
Founder & Director | Lean Six Sigma, ISO & Risk Advisory Expert

From a Lean Six Sigma and management-system perspective, one of the biggest mistakes organizations make is starting with documents instead of processes.

If you begin with four standards, you naturally see four sets of requirements.

If you begin with the business, you see:

Customers → Processes → Risks → People → Resources → Performance → Improvement

The ISO requirements then become controls supporting those processes.

That is a fundamentally different way of designing an IMS.

For example, instead of creating separate procedures for quality, safety and environmental management, ask:

“How does our organization actually plan and execute production?”

Then identify where quality, environmental and safety requirements belong within that process.

This reduces the distance between the management system and the way people actually work.

The Praveen Shekdar Perspective: IMS Must Create Business Value

Praveen Shekdar
Director | ASPM Consulting | Business Transformation & Risk Advisory Leader

An IMS should not become another layer of administration.

The real test is whether management can use the system to answer practical business questions:

  • Where are our highest enterprise risks?
  • Which processes are underperforming?
  • Which corrective actions address systemic issues?
  • Where are compliance obligations changing?
  • Which investments will reduce multiple risks?
  • Are our resources aligned with business priorities?
  • Are quality, safety, environmental and information-security objectives competing or supporting one another?

If management still has to consolidate four separate reports manually before making these decisions, the organization may have integrated documentation without integrated management.

The goal should be to make the management system part of the organization’s operating model.

A Real-World Scenario: The Supplier Problem

Consider a mid-sized engineering company purchasing a critical component from an external supplier.

The supplier begins delivering late.

Quality sees:

Higher defect rates.

Operations sees:

Production delays.

Procurement sees:

Supplier-performance deterioration.

Finance sees:

Higher expediting costs.

Customer service sees:

Potential delivery delays.

EHS may see:

Additional handling and temporary storage requirements.

Information security may see:

Increased exchange of technical information with the supplier.

A fragmented system could generate multiple departmental actions.

An integrated system starts with the supplier-management process and asks:

What is happening to this supplier relationship, what risks does it create, and what coordinated action is required?

That is the difference between managing standards and managing the business.

What Should Actually Be Integrated?

Integration does not mean making every requirement identical.

Some elements are naturally common.

Good candidates for integration

  • Leadership and governance
  • Business objectives
  • Risk and opportunity methodology
  • Document and information control
  • Competence and awareness
  • Internal audit planning
  • Corrective-action management
  • Management review
  • Performance monitoring
  • Continual improvement

Areas that may require specialist treatment

  • Environmental aspects and impacts
  • OH&S hazard identification
  • Information-security risk controls
  • Specific legal and regulatory controls
  • Technical operational controls
  • Standard-specific monitoring requirements

This distinction is important.

A good IMS integrates what should be integrated while preserving the specialist controls that must remain distinct.

ISO’s 2026 guide similarly focuses on connecting multiple management-system standards with existing governance, risk, compliance and operational practices rather than simply merging documents.

A Practical IMS Integration Roadmap

ISO’s current practical guide uses three broad stages:

Prepare → Connect → Integrate.

Organizations can translate that into a practical implementation sequence.

Step 1: Map the Current Systems

List:

  • Standards
  • Policies
  • Procedures
  • Risk registers
  • Audits
  • KPIs
  • Corrective actions
  • Management reviews
  • Compliance obligations

Do not change anything yet.

First understand what exists.

Step 2: Map the Business Processes

Identify the organization’s core processes.

For example:

Sales → Design → Procurement → Production → Delivery → Customer Support

Then identify support processes such as:

HR → IT → Maintenance → Finance → Facilities

Step 3: Map Requirements to Processes

Instead of asking:

“Where is the ISO 9001 procedure?”

ask:

“Where in the business process is this requirement controlled?”

This is where integration begins.

Step 4: Identify Duplication

Look for:

  • Multiple risk registers
  • Duplicate forms
  • Duplicate audits
  • Duplicate corrective actions
  • Multiple training databases
  • Repeated management meetings
  • Conflicting KPIs

Step 5: Build Common Processes

Create common workflows where appropriate.

For example:

One corrective-action process

with specialist categorization for:

Quality | Environment | OH&S | Security | Compliance

Step 6: Retain Specialist Controls

Do not force specialist requirements into generic processes merely to achieve a visually “clean” IMS.

Integration should improve control—not weaken it.

Step 7: Measure Integration

Use the maturity framework or another internally defined measurement approach.

Then ask:

“Are we becoming more integrated, or simply adding more documentation?”

The 80/20 Principle of IMS Integration

A useful way to think about IMS design is the 80/20 principle.

Suppose four management systems contain 100 activities each.

That gives:

4 × 100 = 400 activity entries

But many activities may address similar management-system functions.

If 40% of activities can reasonably be managed through common processes:

400 × 40% = 160 potentially overlapping activities

That does not mean an organization can simply delete 160 activities.

Instead, it indicates where management should investigate opportunities to:

  • Combine workflows
  • Share information
  • Coordinate audits
  • Consolidate reporting
  • Clarify responsibilities
  • Remove duplicate controls

The numerical example is illustrative. The actual integration opportunity depends on the organization’s standards, processes, risks and existing system maturity.

Why IMS Projects Sometimes Fail

Integration can fail when organizations focus on documents rather than management.

Common warning signs include:

1. “Let’s create one huge IMS manual.”

A larger manual does not necessarily mean better integration.

2. “Let’s combine every procedure.”

Not every procedure should be combined.

3. “Let’s use one risk register for everything.”

A single spreadsheet does not create integrated risk management.

4. “Let’s reduce the number of audits.”

Audit reduction should be an outcome of better process-based planning—not the primary objective.

5. “Let’s make every KPI common.”

Different functions may legitimately need different measures.

6. “The consultant will integrate the documentation.”

The organization—not the consultant—owns the management system.

A consultant can provide structure, challenge assumptions and accelerate implementation, but integration ultimately has to be embedded into how the business operates.

How to Know Your IMS Is Actually Working

Ask these seven questions:

  1. Can management see major organizational risks across functions?
  2. Can one business problem trigger coordinated action across relevant functions?
  3. Are audits planned around processes rather than only standards?
  4. Are corrective actions addressing systemic causes?
  5. Are management reviews focused on business performance rather than four separate presentations?
  6. Do employees experience one clear system for reporting and managing issues?
  7. Can the organization explain how its ISO systems support business objectives?

If the answer to most is yes, your IMS is probably moving beyond documentation toward genuine integration.

If the answer is mostly no, you may have multiple management systems with an IMS label.

Frequently Asked Questions

Is having multiple ISO certifications the same as having an IMS?

No.

An organization can hold several ISO certifications while operating largely separate management systems.

An IMS concerns how the systems are connected and managed, particularly where requirements overlap.

Can ISO 9001, ISO 14001, ISO 45001 and ISO 27001 be integrated?

Yes, they can be integrated where their requirements and business processes overlap.

However, integration does not remove the specific requirements or specialist controls associated with each standard.

Does an IMS require one risk register?

No.

A common organizational risk methodology can be useful, but different disciplines may require specialized risk assessments.

The objective is connected risk management, not necessarily one spreadsheet.

Does an IMS mean one procedure for everything?

No.

Some processes benefit from common procedures. Others require specialist controls.

Trying to force every requirement into one procedure can actually increase complexity.

Can integrated audits replace all separate audits?

Not automatically.

Organizations can coordinate or integrate internal audits where appropriate, but audit scope, competence, certification arrangements and standard-specific requirements still need to be considered.

How can I tell whether our IMS is genuinely integrated?

Look beyond the documentation.

Examine risk management, business processes, audits, corrective actions, KPIs, management review and employee experience.

If each function still works independently, the system may be coordinated rather than integrated.

Is IMS suitable for SMEs?

Yes.

But an SME should avoid copying the complexity of a large organization’s IMS.

The system should be proportionate to the organization’s size, risks, processes, resources and objectives.

Does ISO require organizations to have an IMS?

No.

ISO’s 2026 Integrated management systems – A practical guide is guidance for organizations using or planning to use multiple management-system standards. ISO explicitly notes that the guide is supportive guidance and does not add auditable requirements or give preference to a specific standard.

What is the biggest IMS problem?

One of the biggest problems is confusing administrative consolidation with operational integration.

Putting documents into one folder does not make an IMS.

Connecting governance, risks, processes, people, controls, performance and improvement is what creates meaningful integration.

From Four ISO Systems to One Business System

The purpose of an Integrated Management System is not to create a larger compliance structure.

It is to create a better way of managing the organization.

If Quality, Environment, OH&S and Information Security each maintain their own objectives, risks, audits, corrective actions and management reviews, the organization may still be managing four systems.

The transformation begins when those requirements are connected to the same business processes, risks and management decisions.

ISO’s 2026 practical guide reinforces this direction by framing integration around preparing the organization, connecting management-system requirements with existing processes, and integrating them into day-to-day operations and continual improvement.

For business leaders, the question should therefore change from:

“How many ISO systems do we have?”

to:

“How effectively do our management systems work together to improve business performance?”

That is where an IMS starts creating real value.

ASPM Consulting can support organizations in assessing fragmented management systems, identifying integration opportunities, mapping ISO requirements to business processes, strengthening risk management, and developing an IMS aligned with operational and strategic objectives.

The end goal is simple:

Not four systems managed under one roof—but one business framework capable of addressing multiple management priorities.

Recommended next step

If your organization already operates multiple ISO management systems, start with an IMS integration and maturity assessment.

Map your:

Standards → Processes → Risks → Controls → Audits → KPIs → Corrective Actions → Management Reviews

Then identify where the systems are genuinely integrated—and where they are simply operating in parallel.

That gap is often where the biggest improvement opportunity lies.