Integrated management systems: ISO 27001 with ISO 9001, and how the audit is timed
“Audit of an IMS could result in increased time, but where it results in reduction, it shall not exceed 20% from the starting point T (2.1.1 ii).” — IAF MD 11:2023, 2.1.2, the rule every accredited certification body applies to integrated audits.
If your organisation already holds ISO 9001 and is adding ISO 27001, or wants both, the question is whether to run them as one management system or two. The standards are designed to be combined, and the accreditation rules say exactly how much audit time integration can save. The answer is useful, and more modest than the word “integrated” suggests.
Separate, combined or integrated
| Separate systems | Combined audit | Integrated management system | |
|---|---|---|---|
| What it is | Two management systems, audited on different days | Two systems, audited in one visit | “A single management system managing multiple aspects of organizational performance to meet the requirements of more than one management standard, at a given level of integration (1.3).” |
| Documentation | Two sets | Two sets | One set, covering both standards |
| Internal audit and management review | Run twice | Run twice | One programme, one review that covers both |
| Audit time | Each standard's own table | Starts at the sum T, little or no reduction | Starts at the sum T; reduction up to 20% |
| Audit report | Separate | Integrated or separate | Integrated or separate — each finding traceable to its standard |
The accreditation rules describe it as a spectrum: “A management system may range from a combined system adding separate management systems for each set of audit criteria/standard, to an Integrated Management System, sharing in single system documentation, management system elements, and responsibilities.” Where you sit on it is not your label to choose. It is confirmed by the certification body — at application, again at Stage 1, and at every audit after that.
Why ISO 27001 and ISO 9001 fit together
Both standards are built on the same skeleton. ISO/IEC 27001:2022 says: “This document applies the high-level structure, identical sub-clause titles, identical text, common terms, and core definitions defined in Annex SL of ISO/IEC Directives, Part 1, Consolidated ISO Supplement, and therefore maintains compatibility with other management system standards that have adopted the Annex SL.” ISO 9001:2026 says: “This document applies the harmonized approach as published in the ISO/IEC Directives related to the development of management system standards. The intention is to support alignment and facilitate the integration of the requirements and recommendations of one or more management system standards into an organization’s management system.”
Annex SL, now the harmonized structure
Annex SL is the part of the ISO/IEC Directives that fixes the clause numbers, clause titles, common text and core definitions for management system standards. The current version is published as the harmonized structure, approved in 30 July 2025. Clauses 4 to 10 — context, leadership, planning, support, operation, performance evaluation, improvement — mean the same thing in both standards, and much of the wording is shared.
“Much”, not “all”. We compared the current harmonized text with ISO/IEC 27001:2022 clause by clause where both can be read (4.1 to 6.3): 79–100% of each common clause's wording appears, in order, in the standard. Each standard then adds its own requirements — the risk assessment and Statement of Applicability in ISO 27001, customer and product requirements in ISO 9001.
What integrates, and what does not
The shared clauses integrate naturally: one policy framework, one set of documented-information rules, one internal audit programme, one management review, one corrective action process. The discipline-specific parts do not merge — ISO 9001 itself says: “This document does not include requirements specific to other management systems, such as those for environmental management, occupational health and safety management, or asset management.” and ISO 27001's Annex A controls have no counterpart in ISO 9001.
How integrated audit time is calculated
This document is mandatory for the consistent application of clause 9.1.6 of ISO/IEC 17021-1 by certification bodies (CBs) for planning and delivery of audits of Integrated Management Systems (IMS). It sets out the method step by step. The certification body shall:
| Step | |
|---|---|
| i | Calculate the required audit time for each management system standard/specification separately (applying all relevant factors provided for by the relevant application documents and/or scheme rules for each standard, e.g. IAF MD5, ISO 22003-1, ISO/IEC 27006). |
| ii | Calculate the starting point T for the duration of the audit of the IMS by adding the sum of the individual parts (e.g. T = A + B + C). |
| iii | Adjust the starting point figure by taking into account factors that may increase or reduce (see Annex 1) the time required for the audit. |
What can reduce it
The factors for reduction “shall include but are not limited to”:
- The extent to which the organization’s management system is integrated.
- The ability of the organization’s personnel to respond to questions concerning more than one management systems standard.
- The availability of auditor(s) competent to audit more than one management system standard/specification.
And for increase: “The complexity of the audit of an IMS compared with single management system audits.”
The reduction grid
Annex 1 of the document turns the first and third factors into a grid. The rows are the level of integration; the columns are how far the audit team can audit more than one standard each.
| Level of integration | Ability 20% | Ability 40% | Ability 60% | Ability 80% | Ability 100% |
|---|---|---|---|---|---|
| 100% | 0% | 5% | 10% | 15% | 20% |
| 80% | 0% | 5% | 10% | 15% | 15% |
| 60% | 0% | 5% | 10% | 10% | 10% |
| 40% | 0% | 5% | 5% | 5% | 5% |
| 20% | 0% | 0% | 0% | 0% | 0% |
We read these values at the grid points printed in the figure; for positions in between, the certification body decides. The top-right corner is the 20% ceiling, and a system that is only one-fifth integrated gets nothing.
What “integrated” has to mean
The document lists what characterises an integrated system — “(but not limited to)”:
- An integrated documentation set, including work instructions to a good level of development, as appropriate.
- Management Reviews that consider the overall business strategy and plan.
- An integrated approach to internal audits.
- An integrated approach to policy and objectives.
- An integrated approach to systems processes.
- An integrated approach to improvement mechanisms (corrective and preventive action; measurement and continual improvement).
- Integrated management support and responsibilities.
“The CB must decide the percentage level of integration based upon the extent to which the organization’s management system meets the above criteria.” Two policies stapled together do not score.
Worked figures: ISO 27001 plus ISO 9001
ISO 27001 days come from the ISMS audit-time table the certification body uses; ISO 9001 days from IAF MD 5, Table QMS 1. Both are the table starting figures before any other adjustment, for a single site.
| People in scope | ISO 27001 | ISO 9001 | Sum T | T less 10% (60% / 60% on the grid) | T less 20% (the ceiling) |
|---|---|---|---|---|---|
| 10 | 5 | 2 | 7 | 6.3 | 5.6 |
| 25 | 7 | 3 | 10 | 9 | 8 |
| 50 | 10 | 5 | 15 | 13.5 | 12 |
| 100 | 12 | 7 | 19 | 17.1 | 15.2 |
| 250 | 14 | 9 | 23 | 20.7 | 18.4 |
At 25 people, the saving at the ceiling is 2 audit days on the initial audit. Surveillance and recertification in both regimes run at about a third and two thirds of the initial time — IAF MD 5 says surveillance is “about 1/3 of the audit time spent on the initial certification audit” — so the proportional saving carries through the cycle.
The saving is on days, not on requirements
“All applicable requirements of each management system standard/specification relevant to the scope of the IMS shall be audited.” An integrated audit covers every requirement of both standards. What it removes is duplication: one opening and closing meeting, one report, one look at shared processes such as document control.
Where the time goes back
The annex lists the efficiencies that justify the reduction:
- Time saved due to one opening and one closing meeting.
- Time saved as one integrated audit report is produced.
- Time saved in optimized logistics.
- Time saved in auditor team meetings.
- Time saved auditing common elements simultaneously, e.g. document control.
What changes during the certification cycle
At Stage 1
“During a Stage One Audit, the audit team shall confirm the level of integration of the IMS. The CB shall review and modify, as necessary, the audit duration that was based on information provided at the application stage.” If you declared a highly integrated system at application and Stage 1 finds two systems sharing a folder, expect the quote to move.
At every later audit
The certification body must confirm that the level of integration has not changed during the cycle, so that the audit durations still apply. See surveillance audits and recertification.
When something goes wrong in one standard
“The CB shall consider the impact that a nonconformity found for one of the management system standard(s)/specification(s) has on the compliance with the other management system standard(s)/specification(s).” And for the certificate itself: “If certification to one or more management system standard(s)/specification(s) is subject to suspension, reduction or withdrawal the CB shall investigate the impact of this on the certification to other management system standard(s)/specification(s).” Integration links the two certificates' fortunes as well as their audits.
We do not audit, certify or consult, and are paid the same fixed fee per enquiry whichever certification body or consultancy you use. The figures above are the published starting points; a certification body's quote adds its own adjustments for sites and complexity.
Where this fits
- ISO 27001 vs ISO 9001
- What ISO 27001 costs
- Cost calculator
- Stage 1 and Stage 2
- Running the ISMS in your existing tools
Common questions
What is an integrated management system?
In the words of the accreditation rules: “A single management system managing multiple aspects of organizational performance to meet the requirements of more than one management standard, at a given level of integration (1.3).” In practice it means one set of documents, one internal audit programme and one management review serving, for example, ISO 27001 and ISO 9001 together, rather than two systems side by side.
Can ISO 27001 and ISO 9001 be integrated?
Yes, and both standards say they are built for it. ISO/IEC 27001:2022 says it applies Annex SL's high-level structure and “identical text”; ISO 9001:2026 says it applies the harmonized approach “to support alignment and facilitate the integration” of more than one management system standard.
Does an integrated audit take fewer days?
It can, within a limit. The certification body adds the separate audit times together to get a starting point, then may reduce it: “Audit of an IMS could result in increased time, but where it results in reduction, it shall not exceed 20% from the starting point T (2.1.1 ii).” At 25 people that is 7 days for ISO 27001 plus 3 for ISO 9001 — 10 days — and no fewer than 8 after the maximum reduction.
What decides how big the reduction is?
How integrated your system really is, and whether the auditors are qualified in more than one of the standards. IAF MD 11 gives a grid: at full integration with every auditor qualified for every standard, 20%; at 20% integration, nothing.
Do we get one audit report or two?
Either is possible. “Audit reports can be integrated or separate, with respect to the management systems audited. Each finding raised in an integrated report shall be traceable to the applicable management system standard(s)/specification(s).” What is not possible is auditing less: “All applicable requirements of each management system standard/specification relevant to the scope of the IMS shall be audited.”
If one certificate is suspended, what happens to the other?
The certification body has to look at it. “If certification to one or more management system standard(s)/specification(s) is subject to suspension, reduction or withdrawal the CB shall investigate the impact of this on the certification to other management system standard(s)/specification(s).”
What is Annex SL?
The part of the ISO/IEC Directives that sets the common structure and text every recent management system standard shares — now published as the harmonized structure. It is why ISO 27001 and ISO 9001 have the same clause numbers and titles, and why integrating them is possible at all.
Sources cited on this page
- IAF MD 11:2023, Application of ISO/IEC 17021-1 for Audits of Integrated Management Systems (Issue 3)
- IAF MD 5:2023, Determination of Audit Time of Quality, Environmental, and Occupational Health & Safety Management Systems (Issue 4, Version 3)
- ISO/IEC 27006 audit time table, reproduced in full in an accredited certification body's published audit-duration procedure (QSI-TL.04 rev 21)
- ISO/IEC Harmonized structure for MSS with guidance for use (formerly Annex SL Appendix 2 of the ISO/IEC Directives, Part 1), approved 30 July 2025
- ISO/IEC 27001:2022, official preview (clauses 1 to 6.3 and contents), read first-hand
- ISO 9001:2026, Quality management systems — Requirements, official preview (foreword, introduction, clauses 1–3), read first-hand
- BS EN ISO/IEC 17021-1:2015, clauses 9.1.3, 9.5.4 and 9.6 (audit programme, surveillance, recertification, suspension), full text
Every figure above was read from the source it is attributed to on 20 September 2026. Figures that are our own arithmetic rather than a published rule are labelled as estimates wherever they appear. How we check this.
Adding ISO 27001 to ISO 9001?
Say which certificates you hold and how many people are in scope. Integration decides the audit days.
Your enquiry is ready to send
Here is what happens after you submit:
- Your answers go to ISO 27001 consultancies that advertise for your sector.
- No more than three of them may contact you, using the details you gave.
- You decide who, if anyone, you speak to. You are committed to nothing.
We are not a certification body and cannot issue, arrange or influence a certificate. Only a UKAS-accredited certification body can do that, and you appoint it yourself.