Management System FAQs: Expanding an ISO 9001 QMS into an IMS

Management System FAQs: Expanding an ISO 9001 QMS into an Integrated Management System (IMS)

ISO Management System
ISO Management System

We often get asked questions about various aspects of management systems. So, we decided to put some of the more frequently asked questions to one of our leading consultants. Those questions and his answers are being made available as a series of posts on management system FAQs. 

Alan Jones – is Qudos CEO. he has decades of experience as a management system consultant, helping hundreds of businesses to implement management systems and achieve certification to various standards including ISO9001, ISO27001, ISO14001, and ISO45001. He has conducted certification audits against multiple standards, personally trained over 1,000 internal auditors, is a well-established public-speaker, author, and broadcaster, and has played a major role in the continuing development of Qudos3 IMS software. 

In this post, the focus of our FAQs is on expanding an existing QMS into an IMS.

Background

As organizations face increasing regulatory obligations, customer expectations, and operational risks, many are finding that a standalone Quality Management System (QMS) is no longer enough to support long-term business success.

The growing adoption of standards such as ISO 14001, ISO 45001, and ISO 27001 has highlighted the benefits of bringing multiple management systems together under a single Integrated Management System (IMS.

Thanks to the common structure shared by modern ISO standards, organisations can now streamline processes, eliminate duplication, and manage quality, environmental, safety, and information security requirements more efficiently.

An IMS not only simplifies compliance and auditing but also provides a more strategic approach to governance, helping businesses improve performance, reduce risk, and drive continual improvement across the organisation.

FAQs:

Question: What is an Integrated Management System (IMS)?

An Integrated Management System (IMS) addresses the requirements of multiple management system standards on various topics in a combined system. Rather than maintaining separate systems for quality, environmental management, health and safety, information security etc. an IMS allows organizations to manage everything through a single structure.

While it was always possible, modern ISO standards share a common framework and terminology, which makes such integration much more practical and efficient than it was in the past.

 

Why should we expand our ISO 9001 QMS into an IMS?

Many organisations start with ISO 9001 and later expand into other certifications as compliance requirements increase. Those compliance requirements may be internally driven or they may be commercial imperatives or other external obligation. For example, a cohort of clients may require your organization to meet ISO 27001 for information security. If you want them as clients, your organization will need to implement the necessary controls etc.
Expanding your QMS to also meet that standard will most likely be the best way to achieve that.

An IMS can help reduce duplication, streamline processes, improve governance, strengthen risk management, and lower audit costs..  It enables management teams to oversee multiple compliance requirements in a single system. Insurers may also take certifications into account when assessing your business insurance premiums – so there can be a valuable financial imperative.

 

Which ISO standards are commonly integrated with ISO 9001?

The most common standards integrated with ISO 9001 are:

However, almost all current ISO management system standards share a similar clause structure and terminology. Therefore, an IMS can address any of them.

 

Can we use our existing ISO 9001 documentation?

Yes. You can certainly leverage a significant portion of existing QMS documentation and processes. Of course, they should be reviewed and adjusted to properly reflect a broader new scope of application.

 

Do we need separate processes for each ISO standard?

In most cases, no, you don’t.

A well-designed Integrated Management System would use shared processes that address similar requirements across multiple standards, including:

Virtually all of the clauses can be addressed in a similar – just expanding and adjusting processes to take the different subject matter into account.

Only controls specific to each compliance topic would generally require additional processes. For example, an Injury Management Process would be specific to Health & Safety. Some standards – such as ISO 27001 Information Security and ISO 42001 AI management have an Annex with additional controls that would not generally be part of a QMS.

 

What additional requirements are needed for ISO 14001?

The ‘common’ requirements need to be reviewed and adjusted to take the broader scope into account. In addition, when expanding an existing ISO 9001 system to also address ISO 14001, organizations typically need to establish some additional elements, including:

  • Environmental Policy
  • Environmental aspect and impact assessments
  • Environmental objectives and targets
  • Compliance obligation registers
  • Environmental operational controls
  • Environmental performance monitoring

The 2026 edition of ISO 14001 also strengthened some requirements. For example, organizations need to look at environmental impacts across the full life cycle of their activities, products, and services.

These requirements are then incorporated into the integrated management system.

 

What additional requirements are needed for ISO 45001?

The ‘common’ requirements need to be reviewed and adjusted to take the broader scope into account. In addition, when expanding an existing ISO 9001 system to also address ISO 45001, organizations usually need to implement some additional elements, including:

  • Hazard identification processes
  • Health and safety risk assessments
  • Worker consultation and participation mechanisms
  • Incident management procedures
  • Health and safety objectives

These requirements are then incorporated into the integrated management system.

 

What additional requirements are needed for ISO 27001?

The ‘common’ requirements need to be reviewed and adjusted to take the broader scope into account. There are a few extra requirements – in clauses 6 and 8 in particular. In addition, when expanding an existing ISO 9001 system to also address ISO 27001, organizations need to implement all the controls necessary to address the identified risks. This includes the consideration of controls listed in the standard’s Annex A. These 93 controls are divided into 4 categories:

  • Annex A5: Organizational Controls
  • Annex A6: People Controls
  • Annex A7: Physical Controls
  • Annex A8: Technological Controls

A summary of these controls is available in this Quick Guide to ISO 27001. More detailed guidance is available in ISO 27001 InfoSec Toolkit. It is not mandatory to include all of the controls in your management system, but you must consider them and apply those that are relevant. The system must include a documented SOA (Statement of Applicability) that justifies the inclusion or exclusion of each Annex A control. You may also apply additional controls of your own. For example, cyber insurance is not listed in Annex A, but for many, it is considered as a very valid way of treating risk.

These specific information security requirements are then incorporated into the integrated management system.

 

What is the first step in expanding a QMS into an IMS?

The first step is to perform a Gap Analysis. This will compare the current arrangements that you have in place with the requirements of the standard you are looking to address. In you have an effective QMS at the moment, you may be pleasantly surprised at how much of an IMS you already have in place.

When we do a Gap analysis, we use a Red / Amber / Green traffic light system to indicate compliance to each requirement. That helps to set a baseline and provide a great indication of the work to be done.

Qudos3 IMS software includes Gap Analysis templates for ISO 9001, ISO 14001, ISO 27001, ISO 45001 and many other standards and frameworks. We can also offer a Professional Gap Analysis and system planning / development service if required.

ISO Standard Gap Analysis Service
Professional Gap Analysis Service by our team of qualified and experienced lead auditors / consulatants

Can we create a single Integrated Management Policy?

Yes. In principle you can. While all ISO management System Standards have a requirement for a documented policy, they don’t prescribe that it must be a separate statement.

Many organizations with an IMS develop one integrated policy covering commitments relating to various topics – typically Quality, OHS, and Environment.

However, as a matter of opinion, this does not really convey a genuine commitment to each of the topics. Each policy must be authorised by top management and must be communicated to all workers/ It only needs to be a single page in length. If top management doesn’t consider that the peak document for say, information security management doesn’t merit a one-page document of its own, then that is perhaps not the best indicator or leadership and commitment in that regard.  The recommendation is therefore, to have separate policies for each topic.

 

Can we have one risk management process for all standards?

Yes. Many organizations implement a single risk management framework that incorporates risks relating to any compliance topic. This reduces complexity while maintaining compliance with individual ISO standards.

However, you should review your process to ensure that it is appropriate for each topic that is added to the integrated system. For example, it is very common to assess risk using a matrix model assessed values of Likelihood and Consequence combining to calculate risk levels. Those values should be defined in a appropriate way for the topics being assessed. If you have a documented procedure that defines various levels of consequence in the context of quality, they will also need to be defined in the context of the topic you are adding.

Qudos3 IMS software includes a dedicated Risk module for planning and performing assessments, and automatically generating an integrated Risk Register. This may, of course, be filtered at any time to show risk relating to a specific topic.

 

Will certification audits become more difficult?

Not necessarily. They will become longer but not in direct proportion e.g. an audit covering ISO 9001, ISO 14001, and ISO 45001 will not usually be 3 x the duration of an audit for just ISO 9001. Certification bodies apply a factor to reduce the audit time.

Certification bodies commonly perform integrated audits that assess multiple standards during the same audit program. This approach helps reduce audit duplication and minimises cost and disruption to the organization being certified.

 

What are the biggest benefits of an Integrated Management System?

Comparing an IMS with separate systems such as a QMS, and EMS and an OHSMS, the typical benefits include:

  • Reduced duplication of documentation
  • Improved efficiency and lower cost of system administration
  • Lower costs for administrative burden
  • Improved risk management
  • Stronger management oversight of compliance
  • More effective engagement of the workforce
  • Avoidance of a silo mentality within compliance teams
  • ‘Joined-up thinking’ where people throughout the organization better consider the various topics in their decision-making
  • Reduced audit costs

 

How does Qudos3 IMS software help with expanding from a QMS to an Integrated Management System?

Where do we start? This is really home ground for us.

  • Qudos3 IMS software is designed from the ground-up to be topic-neutral. Its modular is aimed at helping you effectively and efficiently address requirements common to ISO management system standards and many other compliance frameworks.
  • It is pre-set with standard references available for all the major ISO standards.
  • It is extremely configurable – enabling categories for other topics, types of records, standards and their clauses to be added as required.
  • It includes Gap Analysis templates for ISO 9001, ISO14001, ISO 27001, ISO 45001 and many other standards and frameworks.
  • Many modules have a series of template record types available for multiple topics / standards. These can be added to or customised as required.
  • It has comprehensive toolkits with guidance material and a large number of template documents for ISO 9001, ISO 14001, ISO 27001, and ISO 45001. These are reviewed and regularly updated by our in-house team of fully-qualified and experienced consultants.
  • If required, one qualified and experienced consultants can assist with you system expansion. Contact us to discuss your needs.

Qudos Management Pty Ltd.
July 2026

Are you thinking of expanding the scope your management system? Contact us

Qudos3 IMS software for smarter management systems
Qudos3 IMS software for smarter management systems

Click the LinkedIn Follow button below to follow Qudos and be the first to receive ISO management system news and further articles like this.