Integrate ISO 9001 and ISO 14001 into One IMS: A Practical UK SME Guide
How to combine your Quality and Environmental Management Systems into a single, streamlined framework — and cut duplication, cost, and audit fatigue in the process.
In This Guide
- What Is an Integrated Management System?
- Why Combine ISO 9001 and ISO 14001?
- Shared Clauses Between the Standards
- Mapping Business Processes
- One Set of Policies & Procedures
- Managing Risks, Opportunities & Aspects
- Integrated Objectives & Performance
- Internal Audits for an IMS
- Preparing for Certification
- Common Challenges UK SMEs Face
- When to Seek IMS Support
- FAQs
Running a UK SME means wearing many hats — and managing two separate ISO management systems can feel like wearing two suits at once. If your business holds, or is working towards, both ISO 9001 (Quality Management) and ISO 14001 (Environmental Management), you may already be duplicating effort: writing near-identical policies, running parallel internal audits, and holding separate management reviews that cover much of the same ground.
There is a better way. Both standards share a common architecture — the High Level Structure (HLS), formerly known as Annex SL — which was designed specifically to make integration straightforward. This guide walks UK SME operations directors, quality managers, and environmental managers through every stage of building a single Integrated Management System (IMS) that satisfies both standards simultaneously.
"The organisations that outperform their peers on compliance are not the ones that do more — they're the ones that do it once, properly, and share the results across every function."
What Is an Integrated Management System (IMS)?
An Integrated Management System is a single framework that combines two or more management system standards into one cohesive set of processes, policies, procedures, and records. Rather than running ISO 9001 and ISO 14001 as separate, parallel systems, an IMS treats them as complementary disciplines within one operating structure.
The concept became considerably more practical when the International Organization for Standardization (ISO) introduced the High Level Structure across its major management system standards. HLS ensures that ISO 9001:2015 and ISO 14001:2015 share the same ten-clause numbering, the same core terms, and the same foundational concepts — including context of the organisation, leadership, planning, support, operation, performance evaluation, and improvement. The same foundation also makes it straightforward to extend the IMS further — adding ISO 45001 for health and safety or ISO 27001 for information security follows the exact same pattern.
What HLS Means in Practice
Clauses 1–10 are structured identically in both standards. Clause 4 (Context), Clause 5 (Leadership), Clause 6 (Planning), Clause 7 (Support), Clause 9 (Performance Evaluation), and Clause 10 (Improvement) can all be addressed with a single set of documents. Only the standard-specific requirements — quality planning in Clause 8.1–8.7 and environmental operational controls in Clause 8.1–8.2 — require distinct, discipline-specific content.
An IMS is not simply stapling two manuals together. Done well, it is a genuinely integrated operating system where quality and environmental thinking inform the same processes, the same risk assessments, the same objectives, and the same continual improvement cycle.
Why Combine ISO 9001 and ISO 14001?
For UK SMEs operating with lean teams and limited management bandwidth, the efficiency argument for integration is compelling. But the benefits extend well beyond paperwork reduction.
Operational Efficiency
Separate systems create duplication at every level: duplicate document control procedures, duplicate training records, duplicate internal audit programmes, and duplicate management reviews. Integration typically reduces total documentation volume by 30–40% and can cut internal audit time by a similar margin.
Cost Reduction
Certification bodies routinely offer combined audits for integrated management systems — a single audit visit covering both standards. This can reduce annual certification costs significantly compared to two separate audit programmes. Consultant fees, if applicable, are also more efficiently deployed against a unified scope.
Joined-Up Thinking
Quality and environmental considerations are not separate business concerns. A supply chain failure that affects product quality often has environmental implications too. An environmental incident — a chemical spill, a waste management failure — frequently represents a quality non-conformance as well. An IMS ensures that risk assessments, objectives, and corrective actions account for both dimensions simultaneously.
Regulatory and Commercial Advantage
UK procurement frameworks — particularly in construction, manufacturing, public sector contracting, and facilities management — increasingly require evidence of both quality and environmental management. An IMS positions your business to demonstrate both credentials from a single, coherent system, which can accelerate tender qualification and supply chain approval processes.
Environmental Compliance Context for UK SMEs
Post-Brexit, UK environmental regulation has diverged from EU law in certain areas, with the Environment Act 2021 establishing new domestic targets and frameworks. UK SMEs operating ISO 14001 within an IMS should ensure their legal register reflects applicable UK legislation — including the Environmental Permitting (England and Wales) Regulations 2016, the Environmental Protection Act 1990, and relevant EA/NRW/SEPA guidance — rather than defaulting to retained EU law references.
Shared Clauses Between ISO 9001 and ISO 14001
Understanding where the two standards share requirements — and where they diverge — is the foundation of intelligent integration. The following table maps the principal shared clauses and highlights the integration opportunity each presents.
| HLS Clause | ISO 9001 Requirement | ISO 14001 Requirement | Integration Opportunity |
|---|---|---|---|
| 4.1 | Understanding the organisation and its context | Same requirement | Single SWOT/PESTLE covering quality and environmental context |
| 4.2 | Understanding needs of interested parties | Same requirement | Combined stakeholder register noting quality and environmental interests |
| 5.1 | Leadership and commitment | Same requirement | Single leadership commitment statement covering both disciplines |
| 5.2 | Quality policy | Environmental policy | Combined IMS policy addressing quality and environmental commitments |
| 6.1 | Actions to address risks and opportunities | Same + environmental aspects and significant impacts | Unified risk register incorporating aspects/impacts and quality risks |
| 6.2 | Quality objectives | Environmental objectives | Single objectives framework with discipline-specific KPIs |
| 7.1–7.5 | Resources, competence, awareness, communication, documented information | Same requirements | Shared training matrix, communication plan, document control procedure |
| 9.1 | Monitoring, measurement, analysis and evaluation | Same requirement | Unified performance dashboard reporting against both sets of KPIs |
| 9.2 | Internal audit | Same requirement | Single integrated audit programme covering both standards |
| 9.3 | Management review | Same requirement | Single annual management review agenda covering both standards |
| 10.1–10.3 | Nonconformity, corrective action, continual improvement | Same requirements | Single NCR/corrective action system; improvement log covering both |
The clauses that remain standard-specific are Clause 8 (Operation) and the aspects of Clause 6.1 unique to ISO 14001. Even within Clause 8, there is significant overlap: supplier evaluation procedures, change management processes, and documented control measures serve both quality and environmental purposes with modest adaptation.
Mapping Business Processes Across Quality and Environmental Requirements
Effective integration begins with a thorough process map — a visual representation of how your organisation creates value, and where quality and environmental considerations intersect within each process.
The Turtle Diagram Approach
Many UK SMEs find the turtle diagram format useful for process mapping within an IMS context. For each core process, capture: the inputs (what triggers the process), the outputs (what it produces), the resources required (people, equipment, infrastructure), the methods and controls applied, the performance measures used to monitor effectiveness, and the responsible process owner.
Once documented in this format, the integration question becomes straightforward: for each process, are the quality controls and the environmental controls listed alongside each other, or do they live in separate documents? An IMS consolidates them into a single process description with both sets of controls visible in one place.
Identifying Environmental Aspects Within Your Processes
ISO 14001 requires organisations to determine the environmental aspects of their activities — the elements of their operations that interact or could interact with the environment. This is not separate from process mapping; it is an extension of it. As you map each process, ask: what materials and energy does this consume? What emissions, effluents, or waste does it generate? What is the environmental significance of those outputs under normal, abnormal, and emergency conditions?
Practical Example: Manufacturing Process
A manufacturing SME maps its machining process. Quality controls include dimensional inspection, tool calibration records, and operator competence verification. Environmental aspects identified within the same process include: cutting fluid consumption and disposal, metal swarf generation and segregation for recycling, energy consumption of CNC machinery, and risk of coolant spill. Both sets of controls appear in the same process procedure and are monitored through the same operational review cycle.
Creating One Set of Policies, Procedures, and Records
Documentation is often where integration feels most tangible — and where the efficiency gains are most immediately apparent. The goal is not a single enormous manual but rather a lean, logical document hierarchy that avoids duplication without sacrificing clarity.
The Three-Level Document Hierarchy
Most well-designed IMS documentation structures operate on three levels:
- Level 1 — IMS Manual (or Policy Framework): A high-level document describing the scope of the IMS, the organisation's context, leadership commitments, and the IMS policy. This single document addresses Clauses 4, 5, and the policy requirements of both standards simultaneously.
- Level 2 — Procedures: Detailed descriptions of how key processes are controlled. Shared procedures — document control, internal audit, corrective action, management review, training and competence — are written once and reference both standards where relevant. Discipline-specific procedures address standard-specific requirements separately.
- Level 3 — Records and Work Instructions: The objective evidence that procedures are being followed. Risk registers, audit reports, training records, monitoring data, management review minutes, and corrective action logs are all maintained as shared records within one system.
The Integrated Policy
An integrated IMS policy is typically a single page — concise, signed by the chief executive or managing director, and covering the organisation's commitments to both quality and environmental performance. It should reference the specific commitments required by each standard: customer focus and continual quality improvement (ISO 9001) alongside pollution prevention, compliance with environmental obligations, and environmental continual improvement (ISO 14001).
A combined policy is not merely convenient — it signals to employees, customers, and certification auditors that leadership treats quality and environmental management as equal, integrated disciplines rather than compliance tick-boxes.
Managing Risks, Opportunities, and Environmental Aspects
Risk-based thinking is central to both ISO 9001 and ISO 14001. Both standards require organisations to identify the risks and opportunities that could affect their ability to achieve intended outcomes — and to take appropriate action. For an IMS, the most elegant solution is a single risk register that captures both dimensions.
The Unified Risk Register
An integrated risk register typically includes columns for: the risk or opportunity description; the relevant standard(s) it relates to (ISO 9001, ISO 14001, or both); the likelihood and consequence ratings; the overall risk rating; the control measures in place; the residual risk rating; the owner; and the review date.
Many risks are genuinely shared: supply chain instability threatens both quality of supply and environmental compliance (where suppliers carry environmental accreditations or provide certified materials). Regulatory change — particularly relevant in the post-Brexit UK context — may affect both product quality requirements and environmental permitting conditions simultaneously.
Environmental Aspects and Significant Impacts
ISO 14001 adds a specific requirement that ISO 9001 does not share: the identification and evaluation of environmental aspects. An environmental aspect is any element of an organisation's activities, products, or services that can interact with the environment. An environmental impact is the change to the environment that results.
Significance evaluation typically considers factors including the scale of the impact, its severity, the probability of occurrence, the regulatory position, and stakeholder concerns. The output is a register of significant environmental aspects — those that require specific operational controls, objectives, or management programmes.
Lifecycle Thinking Under ISO 14001:2015
A requirement that often catches SMEs off-guard: ISO 14001:2015 requires organisations to consider a lifecycle perspective on their significant aspects — thinking beyond the factory gate to upstream impacts (raw material extraction, supplier processes) and downstream impacts (product use, end-of-life). This does not require a full lifecycle assessment, but it does mean your aspects register should acknowledge upstream and downstream considerations for significant impacts, even where direct control is limited.
Integrated Objectives and Performance Monitoring
Clause 6.2 of both standards requires the organisation to establish measurable objectives — and both standards require those objectives to be consistent with policy, account for significant risks and opportunities, be measurable where practicable, and be monitored and communicated. This is another area where a single integrated framework delivers material efficiency.
Setting IMS Objectives
Well-constructed IMS objectives are SMART — Specific, Measurable, Achievable, Relevant, and Time-bound — and they draw directly from the risk register and the policy commitments. The examples below are illustrative; your own targets should always be set against your organisation's baseline data and current performance levels. A typical IMS objective register for a UK manufacturing SME might look like this:
- Reduce customer complaint rate from 3.2% to below 1.5% by end of Q4 — addressing quality performance and customer focus
- Achieve on-time delivery performance of 95% or above by December 2025 — quality objective with supply chain implications
- Reduce total waste to landfill by 30% against the 2023 baseline by end of 2026 — significant environmental aspect
- Reduce energy consumption per unit of output by 15% against the 2023 baseline by end of 2026 — environmental and operational efficiency
- Achieve zero environmental permit breaches in the 12-month certification period — compliance obligation management
- Complete the annual IMS internal audit programme with zero overdue corrective actions by the Stage 2 audit date — system effectiveness
Performance Monitoring and the IMS Dashboard
Clause 9.1 requires both standards to monitor, measure, analyse, and evaluate performance. A single IMS performance dashboard — reviewed monthly at operational level and quarterly at senior management level — satisfies this requirement for both standards simultaneously. The dashboard should present quality KPIs alongside environmental KPIs in one coherent view. Our ongoing compliance support service can help you build and maintain this as part of a retained IMS programme.
Internal Audits for an Integrated Management System
Internal auditing is often the activity that most visibly demonstrates whether an IMS is genuinely integrated or merely two systems in a shared folder. A properly integrated audit programme audits processes — not standards — and evaluates both quality and environmental performance within the same audit visit.
Designing the Integrated Audit Programme
The audit programme should be risk-based: processes with higher combined quality and environmental risk, or those that have experienced recent non-conformances, should be audited more frequently than lower-risk processes. The programme covers all processes within the IMS scope and, over a defined cycle (typically 12 months), provides coverage against all requirements of both standards.
Each audit visit is documented on a single audit report that references both ISO 9001 and ISO 14001 clause numbers where relevant findings are recorded. Non-conformances are raised on a single corrective action log — whether they relate to a quality requirement, an environmental requirement, or both.
Auditor Competence
ISO 19011:2018 (Guidelines for auditing management systems) provides guidance on auditing integrated systems. Internal auditors should be competent against both standards — understanding the principles of environmental aspect evaluation and the methods for assessing quality management effectiveness. Many UK SMEs address this through combined IMS internal auditor training, available from UK-based training providers and professional bodies including the CQI, IEMA, and BSI.
Audit Checklist Tip
Design your internal audit checklists against processes, not clauses. A checklist for the Purchasing process should ask about supplier evaluation criteria (ISO 9001 Clause 8.4), supplier environmental performance requirements (ISO 14001 Clause 8.1), communication of relevant requirements to suppliers, and records of supplier monitoring. A single checklist, one audit visit, dual-standard coverage.
Preparing for Certification Audits
Most UKAS-accredited certification bodies offer combined certification audits for ISO 9001 and ISO 14001. This means a single Stage 1 (document review) and Stage 2 (on-site audit) visit covering both standards, audited by one or two auditors with combined competence. The cost saving versus two separate certification programmes is typically 20–35% on annual surveillance fees, with proportionally higher savings at initial certification.
Months 1–2
Gap Analysis and Project Planning
Assess current state against both standards. Identify where you already have compliant processes, where gaps exist, and where integration can deliver quick wins. Agree scope, timelines, and resource allocation.
Months 2–4
Context, Risk, and Documentation Framework
Complete context analysis, stakeholder register, and combined risk and aspects register. Draft IMS policy, objectives, and Level 2 shared procedures. Establish document control and records management system.
Months 4–6
Operational Controls and Training
Implement process-specific procedures addressing Clause 8 requirements for both standards. Deliver staff training and awareness. Establish monitoring and measurement routines.
Months 6–9
Internal Audit and Management Review
Complete first integrated internal audit cycle. Address non-conformances. Hold first IMS management review. Generate performance data against objectives.
Months 9–12
Stage 1 and Stage 2 Certification Audits
Submit documentation to certification body for Stage 1 review. Address any observations. Host Stage 2 on-site audit. Respond to any findings. Receive combined ISO 9001 and ISO 14001 certification.
What Certification Auditors Look For
A combined certification auditor is assessing whether your IMS is genuinely integrated rather than artificially combined. Key indicators include: evidence that leadership engages with quality and environmental performance in the same forums; a risk register that reflects both disciplines; objectives with measurable targets for each; internal audit reports that address both standards within process-based audits; and management review minutes covering all required inputs and outputs in a single meeting record.
Common Challenges UK SMEs Face
Integration is straightforward in principle and genuinely achievable for most UK SMEs — but it is rarely without challenges. Understanding the most common pitfalls helps you plan around them.
Treating Integration as a Documentation Exercise
The most common mistake: combining documents without integrating the underlying processes. If your quality team and environmental manager still operate independently, with separate meeting cycles, separate improvement logs, and separate reporting lines to leadership, you have two systems with shared stationery, not a genuine IMS.
Underestimating Environmental Aspect Assessment
Many businesses seeking ISO 14001 integration for the first time significantly underestimate the time and expertise required to complete a thorough aspects and impacts register. This is particularly true for businesses with complex supply chains, multiple sites, or regulated environmental activities. An incomplete or superficial aspects assessment is one of the most common major non-conformances raised at ISO 14001 certification audits.
Legal Register Maintenance
ISO 14001 requires identification of applicable legal and other requirements — and evidence that compliance is evaluated. For UK SMEs, this means maintaining an up-to-date environmental legal register covering UK-specific legislation. Post-Brexit regulatory divergence has added complexity, and keeping the legal register current is an ongoing commitment, not a one-time task. This is one of the areas where retained compliance support tends to deliver the most consistent value.
Management Bandwidth
Smaller SMEs often find that the individual managing ISO 9001 implementation is not the same person responsible for environmental compliance — and neither has capacity to lead an IMS project while running their day-to-day function. Phasing the project, or bringing in external support for the initial implementation, is a pragmatic response to this constraint.
When to Seek Integrated ISO Management System Support
Many UK SMEs successfully implement an IMS using internal resource alone — particularly where they already hold one standard and are extending to the other. However, external ISO certification support adds clear value in several situations.
- Starting from scratch: Building a combined IMS where neither standard is currently held is a significant undertaking. External consultants bring a proven framework and can compress timelines considerably.
- Environmental aspect expertise: If your team has strong quality management experience but limited environmental knowledge, specialist support for the aspects assessment, legal register, and ISO 14001 Clause 8 controls is often prudent.
- Certification readiness: Pre-assessment gap analysis and Stage 1 readiness reviews can identify issues before the certification body does — protecting your investment.
- Ongoing maintenance: Some UK SMEs retain ongoing ISO compliance support on a retained basis, covering quarterly system reviews, legal register updates, internal audit facilitation, and management review preparation.
When evaluating providers, look for demonstrable experience delivering combined ISO 9001 and ISO 14001 certifications for UK SMEs in your sector, familiarity with the certification body landscape, and a methodology that builds genuine internal capability rather than consultant dependency.
Related Goldenpath PM Services & Guides
- ISO 9001 Quality Management — Our Service
- ISO 14001 Environmental Management — Our Service
- ISO 45001 Health & Safety — Extend Your IMS Further
- ISO 27001 Information Security — Add a Fourth Standard
- Ongoing ISO Compliance Support — Retain Us Year-Round
- ISO Certification Services for UK SMEs — Full Overview
Need Integrated ISO Management System Support?
Goldenpath PM works with UK SMEs to design, implement, and maintain integrated ISO 9001 and ISO 14001 management systems — from gap analysis to certification and beyond.
Talk to Our ISO Team →Frequently Asked Questions
Can ISO 9001 and ISO 14001 be integrated?
Yes — and they are specifically designed to be. Both standards are built on the ISO High Level Structure, sharing identical clause numbering from Clause 1 to Clause 10. This common framework means that the majority of your management system infrastructure — policy, context analysis, risk management, objectives, competence and awareness, document control, internal audit, management review, and improvement processes — can be built once to satisfy both standards simultaneously. Only the discipline-specific requirements in Clause 8 (operational planning) and the environmental aspects requirements in Clause 6.1 require standard-specific content.
What documents can be shared between ISO 9001 and ISO 14001?
A significant proportion of the required documented information can be shared. Key shared documents include: the IMS policy, the scope statement, the context and stakeholder analysis, the risk register (with environmental aspects incorporated), the objectives register, the document control procedure, competence and training records, the internal audit programme and reports, management review records, and the corrective action log. Discipline-specific procedures — such as environmental aspect assessment methodology and product/service realisation controls — remain separate but are cross-referenced within the integrated framework.
How much does an integrated management system cost?
Costs vary depending on the size and complexity of your business, the current maturity of your management systems, whether you use external consultancy support, and the certification body you choose. For a typical UK SME of 20–100 employees, implementation costs (including consultant support, training, and certification) generally fall in the range of £8,000–£25,000 for a combined IMS from scratch. Annual certification and surveillance fees from UKAS-accredited bodies typically range from £2,500–£6,000 for a combined audit. Contact us for a tailored estimate based on your situation.
Is it easier to audit an integrated ISO management system?
In practice, yes — particularly for internal audits. Rather than running two separate audit programmes, an integrated audit programme audits business processes once, evaluating quality and environmental performance simultaneously within the same visit. This reduces total audit days per year and eliminates the duplication of interviewing the same staff members twice about essentially overlapping aspects of their work. External combined certification audits offer the same efficiency: one visit, one audit team, one set of findings to address.
How long does ISO 9001 and ISO 14001 implementation take?
For a UK SME implementing both standards together from a low base, a realistic timeline is 9–15 months to initial certification. This allows time for gap analysis, documentation development, staff training, operational controls, at least one internal audit cycle, a management review, and the Stage 1/Stage 2 certification audit sequence. Businesses that already hold one standard and are extending to the other typically achieve the extension within 4–9 months.
Can I extend the IMS to include ISO 45001 or ISO 27001 later?
Absolutely — and this is one of the strongest arguments for building on the HLS framework from the outset. Once your ISO 9001 and ISO 14001 IMS is established, adding ISO 45001 (Occupational Health & Safety) or ISO 27001 (Information Security) is a structured extension rather than a rebuild. Your existing policy framework, risk register, objectives, internal audit programme, and management review process all remain in place — you add the standard-specific requirements as disciplined layers on top.







