One System.
Three Standards.
Zero Duplication.
How UK SMEs can combine ISO 9001, ISO 14001, and ISO 45001 into a single Integrated Management System — and run quality, environmental, and health & safety compliance from one streamlined framework.
Jump to a section
Most UK SMEs reach ISO certification one standard at a time. ISO 9001 often comes first — driven by client contracts or tender requirements. ISO 14001 follows as environmental expectations grow. ISO 45001 arrives when health and safety obligations, sector regulation, or supply chain pressure demand a certified occupational health and safety management system.
By the time a business holds all three, they are often managing three parallel systems: three sets of policies, three risk registers, three internal audit programmes, and three management reviews. The administrative burden is considerable — and entirely unnecessary. All three standards are designed to be integrated, and a well-built triple IMS reduces ongoing compliance management to a single, coherent framework.
This guide is written for UK SME operations directors, quality managers, environmental managers, and H&S leads who are ready to stop duplicating effort and start managing quality, environmental, and occupational safety from one system.
Understanding the Three Standards
Before integration, it helps to be clear on what each standard demands and where it adds distinct value to your business.
9001
Quality Management System
Focuses on consistently meeting customer requirements, enhancing customer satisfaction, and driving continual improvement of quality performance. Covers design, production, service delivery, and post-delivery support processes.
Our ISO 9001 support →14001
Environmental Management System
Requires organisations to identify significant environmental aspects, manage legal compliance obligations, set environmental objectives, and drive continual reduction in environmental impact across the lifecycle of their activities and services.
Our ISO 14001 support →45001
Occupational Health & Safety
Focuses on eliminating work-related injury and ill-health through hazard identification, risk control, worker consultation and participation, emergency preparedness, and compliance with health and safety legislation.
Our ISO 45001 support →The standards address different disciplines — but they share the same management system architecture, the same planning cycle, and many of the same core processes. That convergence is the foundation of triple integration.
Why Integrate All Three?
The efficiency case for integrating two standards is well understood. Integrating a third amplifies those gains significantly — and introduces benefits that two-standard integration cannot deliver alone.
One System of Record
A triple IMS means one policy framework, one document hierarchy, one risk register, one set of objectives, one audit programme, and one management review process. Every compliance activity happens once and counts for all three standards. The reduction in administrative overhead versus three separate systems is substantial — typically in the range of 50–60% on documentation and internal audit effort once the system is properly embedded.
Interdisciplinary Risk Thinking
A chemical handling process does not have a quality risk that is separate from an environmental risk that is separate from a health and safety risk. They are the same process, and the risks are interconnected. A triple IMS forces that interdisciplinary view into your risk register, your operational controls, your training, and your incident investigation. Non-conformances in one discipline are automatically assessed for implications in the other two.
Commercial and Procurement Advantage
UK construction, manufacturing, facilities management, and public sector supply chains increasingly require evidence of all three certifications as a condition of approved supplier status. A triple IMS allows your business to demonstrate quality, environmental, and H&S compliance from a single, coherent system — which strengthens tender submissions and simplifies supplier qualification documentation. Many clients who require Achilles or Constructionline accreditation will find that a triple IMS significantly streamlines those applications too.
Reduced Certification Cost
Major UK UKAS-accredited certification bodies — including BSI, NQA, and Bureau Veritas — offer combined audits covering all three standards in a single visit programme. Running a combined audit is considerably less expensive than maintaining three separate annual audit programmes.
Already hold one or two standards?
If your business currently holds ISO 9001 and is adding ISO 14001 and ISO 45001, or holds two and is extending to three, the integration project is significantly lighter. Your existing context analysis, risk framework, document control, audit programme, and management review provide the foundation. See our ongoing ISO compliance support for how we help businesses extend and maintain their systems.
The High Level Structure: Why Triple Integration Works
The reason a triple IMS is structurally achievable — rather than merely aspirational — is the ISO High Level Structure (HLS), also referred to as the Harmonized Structure. All three standards are built on the same ten-clause framework, with identical clause numbering, compatible requirements language, and the same plan-do-check-act cycle.
This was a deliberate design decision by ISO to make multi-standard integration practical. Clause 4 through Clause 10 are structured identically across ISO 9001:2015, ISO 14001:2015, and ISO 45001:2018 — meaning the same management system infrastructure can address all three simultaneously.
| Clause | Title | 9001 | 14001 | 45001 | Integration Opportunity |
|---|---|---|---|---|---|
| 4 | Context of the organisation | ✦ | ✦ | ✦ | One SWOT/PESTLE; one stakeholder register covering quality, environmental, and OH&S interests |
| 5 | Leadership & commitment | ✦ | ✦ | ✦ | Single IMS policy signed by MD; combined leadership commitment statement |
| 6 | Planning (risks, opportunities, objectives) | ✦ | ✦ | ✦ | Unified risk register incorporating quality risks, environmental aspects, and OH&S hazards; shared objectives template |
| 7 | Support (resources, competence, awareness, communication, documented information) | ✦ | ✦ | ✦ | Single training matrix; one communication plan; shared document control procedure covering all three standards |
| 8 | Operation | ✦ | ✦ | ✦ | Operational procedures annotated for quality, environmental, and H&S controls within the same document |
| 9 | Performance evaluation | ✦ | ✦ | ✦ | Single IMS dashboard; one internal audit programme; one management review covering all three standards |
| 10 | Improvement | ✦ | ✦ | ✦ | One nonconformity and corrective action log; shared continual improvement register |
The standard-specific requirements — ISO 14001's environmental aspects register, ISO 45001's hazard identification and risk assessment (HIRA) and worker consultation requirements under Clause 5.4, and ISO 9001's customer satisfaction monitoring under Clause 9.1.2 — sit as clearly labelled discipline-specific sections within the unified structure. They do not require separate systems; they require dedicated sections within one system.
Creating One Set of Policies, Procedures, and Records
A well-structured triple IMS document hierarchy operates on three levels: the IMS Policy and Scope at Level 1, shared and discipline-specific procedures at Level 2, and records and work instructions at Level 3. The objective is a lean document set that eliminates duplication without creating ambiguity about which standard each document addresses.
| Document | 9001 | 14001 | 45001 | Approach |
|---|---|---|---|---|
| IMS Policy | ✦ | ✦ | ✦ | Fully Shared |
| Scope Statement (Cl. 4.3) | ✦ | ✦ | ✦ | Fully Shared |
| Context & Stakeholder Register | ✦ | ✦ | ✦ | Fully Shared |
| Risk & Opportunity Register | ✦ | ✦ | ✦ | Fully Shared |
| IMS Objectives Register | ✦ | ✦ | ✦ | Partially Shared |
| Document Control Procedure | ✦ | ✦ | ✦ | Fully Shared |
| Competence & Training Records | ✦ | ✦ | ✦ | Fully Shared |
| Internal Audit Programme & Reports | ✦ | ✦ | ✦ | Fully Shared |
| Management Review Records | ✦ | ✦ | ✦ | Fully Shared |
| Nonconformity & Corrective Action Log | ✦ | ✦ | ✦ | Fully Shared |
| Legal & Compliance Register | ✦ | ✦ | ✦ | Partially Shared |
| Environmental Aspects Register | — | ✦ | — | 14001 Specific |
| Hazard ID & Risk Assessment (HIRA) | — | — | ✦ | 45001 Specific |
| Emergency Preparedness & Response | — | ✦ | ✦ | Partially Shared |
| Customer Satisfaction Monitoring | ✦ | — | — | 9001 Specific |
| Worker Consultation & Participation Records | — | — | ✦ | 45001 Specific |
The Combined IMS Policy
A single IMS policy document is one of the most visible signals of genuine integration. It should be signed by the managing director and cover — in plain, committed language — the organisation's obligations to all three disciplines: delivering quality products and services that meet customer requirements (ISO 9001); managing and minimising environmental impact and preventing pollution (ISO 14001); and protecting the health, safety, and wellbeing of workers and others affected by the organisation's activities (ISO 45001). It must also reference the commitment to comply with applicable legal obligations and pursue continual improvement across all three areas. One page, three standards, one signature.
Mapping Processes Across All Three Standards
Process mapping is the engine room of a triple IMS. ISO 9001 and ISO 14001 both require organisations to determine their processes and interactions (Clause 4.4). ISO 45001 adds the requirement to identify hazards and assess OH&S risks within those processes (Clause 6.1.2). The integration opportunity is to map processes once — and annotate them for quality, environmental, and H&S considerations simultaneously.
Process Hierarchy for a Triple IMS
Organise your process map into three tiers: management processes (strategic planning, management review, internal audit, improvement), core operational processes (design, production, service delivery, procurement, maintenance, emergency response), and support processes (HR, IT, document control, facilities management). This three-tier architecture is standard-agnostic and forms the skeleton of your IMS.
Annotating for Three Disciplines
For each operational process, capture the quality controls (inspection criteria, customer specifications, design requirements), environmental aspects and controls (material consumption, waste, emissions, spill risk), and H&S hazards and controls (physical hazards, chemical hazards, ergonomic risks, safe systems of work, PPE requirements). The goal is a single process procedure that a quality auditor, an environmental auditor, and a health and safety auditor can all navigate — finding the evidence relevant to their standard without hunting through a separate system.
Practical Example: Maintenance Process
A facilities management SME maps its planned maintenance process. Quality controls: planned maintenance schedule, equipment records, calibration status. Environmental aspects: lubricant disposal, refrigerant handling under F-Gas Regulations 2015, waste generated during maintenance. OH&S hazards: working at height under the Working at Height Regulations 2005, electrical isolation, confined space entry, manual handling. All three sets of controls documented in one procedure, reviewed in one audit, managed by one process owner.
Assign a Single Process Owner
For each core process, name one person accountable for quality outputs, environmental performance, and safety controls within that process. This eliminates the common SME problem of quality, environmental, and H&S being managed by different people who rarely discuss the same process — and who produce conflicting records when things go wrong.
Managing Risks Across Quality, Environment, and Safety
Each of the three standards has its own risk planning requirements — but they are structurally compatible and can be addressed within a single unified framework.
ISO 9001 requires identification of risks and opportunities that could affect the ability to achieve intended quality outcomes (Clause 6.1). ISO 14001 requires identification of environmental aspects and their significant impacts alongside applicable legal obligations (Clauses 6.1.2–6.1.3). ISO 45001 requires hazard identification and OH&S risk assessment, with worker participation in that process (Clauses 6.1.1–6.1.2 and Clause 5.4).
The Triple IMS Risk Register
An integrated risk register for a triple IMS combines all three risk streams into a single document, with clear columns distinguishing the discipline, the relevant standard, and the controls applicable. Entries that have cross-disciplinary implications — a hazardous chemical that is both an environmental aspect and an OH&S hazard, and whose mishandling could also cause a quality non-conformance — are tagged against all relevant standards and assessed for each dimension. One register means one review cycle, one owner per risk, and one corrective action system.
The Environmental Aspects Register
ISO 14001 requires a dedicated assessment of environmental aspects — the elements of your activities, products, and services that interact with the environment. Significance evaluation considers scale, severity, probability of occurrence, the regulatory position, and stakeholder concerns. The significant aspects register drives environmental operational controls and objectives. Under ISO 14001:2015, organisations must also consider a lifecycle perspective — acknowledging upstream impacts (raw material extraction, supplier processes) and downstream impacts (product use, end-of-life disposal), even where direct control is limited.
The Hazard Identification and Risk Assessment (HIRA)
ISO 45001 requires a systematic HIRA covering all activities, workplaces, and persons who could be affected — including contractors, visitors, and remote workers. The HIRA must consider human factors, past incidents, changes to processes, and emergency scenarios. It must be reviewed whenever there are changes to the work environment, after incidents, and at planned intervals. The HSE's five steps to risk assessment methodology is widely used by UK SMEs as a practical framework for HIRA development.
Legal Register — Three Standards, One Document
All three standards require identification of applicable legal and other requirements. For UK SMEs, this means a legal register covering:
- Quality: product liability law, sector-specific regulations (e.g. construction product regulation, food safety legislation)
- Environmental: Environment Act 2021; Environmental Permitting (England and Wales) Regulations 2016; Environmental Protection Act 1990; applicable Environment Agency, Natural Resources Wales, or SEPA guidance
- Health & Safety: Health and Safety at Work Act 1974; Management of Health and Safety at Work Regulations 1999; COSHH Regulations 2002; sector-specific HSE Approved Codes of Practice
A shared register format with discipline-specific columns satisfies all three standards in one document — reviewed at least annually and updated when legislation changes.
Setting Objectives Across All Three Disciplines
Clause 6.2 of all three standards requires measurable objectives consistent with policy, derived from risks and opportunities, and monitored over time. A unified objectives framework — one document, one reporting cycle, one management review discussion — satisfies all three requirements simultaneously.
Objectives must be SMART (Specific, Measurable, Achievable, Relevant, and Time-bound) and must specify what will be done, what resources will be required, who will be responsible, when it will be completed, and how results will be evaluated. A typical triple IMS objectives register for a UK SME might include:
- Quality: Reduce customer complaint rate below a defined threshold; maintain on-time delivery above target; improve first-pass yield in core production
- Environmental: Reduce energy consumption per unit of output against base year; reduce total waste to landfill by a target percentage; achieve zero environmental permit non-compliances
- H&S: Reduce lost-time incident rate against previous year; close all high-priority HIRA actions within defined timescale; maintain near-miss reporting above minimum threshold to drive proactive safety culture
- System performance: Complete full IMS internal audit cycle with zero overdue corrective actions; achieve zero major non-conformances at external surveillance audit
Performance Dashboard
A single monthly IMS performance dashboard — presenting quality, environmental, and H&S KPIs in one view — is both an efficiency gain and a cultural signal. When leadership reviews all three disciplines in the same meeting, using the same dashboard, it demonstrates that quality, environmental, and safety performance are treated as equally important business outcomes. This satisfies the Clause 9.1 monitoring and measurement requirement for all three standards simultaneously.
Internal Audits for a Triple IMS
An integrated audit programme for a triple IMS audits business processes — not standards. Each audit visit evaluates the quality, environmental, and H&S dimensions of the process being audited, and generates a single audit report with findings referenced to the relevant clause of each applicable standard. This is both more efficient and more useful than three separate audit programmes.
Designing the Programme
The audit programme must be risk-based (Clause 9.2 of all three standards) and cover all processes within the IMS scope over the defined audit cycle — typically 12 months. Higher-risk processes — those with recent non-conformances, high environmental significance, or significant OH&S risk — should be audited more frequently. The programme is reviewed and updated at management review, taking account of changes to the business, risk profile, and previous audit findings.
Internal Auditor Competence
Internal auditors for a triple IMS must be competent against all three standards. They need to understand the requirements of ISO 9001, ISO 14001, and ISO 45001, the methods for evaluating quality management effectiveness, environmental aspect significance, and OH&S risk control adequacy. IRCA-certified combined IMS internal auditor training is available from several UK providers. ISO 19011:2018 — the ISO guidelines for auditing management systems — is the reference document for audit programme design and auditor competence.
Triple IMS Audit Checklist Approach
For each process audited, design a single checklist that covers: customer requirements and quality controls (ISO 9001, Cl. 8); environmental aspects and operational controls (ISO 14001, Cl. 8.1); hazard controls, safe systems of work, and emergency preparedness (ISO 45001, Cl. 8.1–8.2); competence and awareness of all three disciplines (Cl. 7.2–7.3 across all standards); and relevant legal compliance evidence (Cl. 9.1.2, ISO 14001 and ISO 45001). One process, one audit visit, three-standard coverage.
Preparing for Triple Certification
A combined certification audit covering all three standards is available from most major UK UKAS-accredited certification bodies. Certification is valid for three years, with annual surveillance audits required in years one and two, and a full recertification audit at year three. All audits can be conducted as a single combined visit for a triple IMS.
The following phases outline the typical implementation journey for a UK SME:
Gap Analysis Against All Three Standards
Use a triple-column gap analysis matrix mapped to HLS clauses. For each clause, record what exists, what is missing for ISO 9001, ISO 14001, and ISO 45001. This baseline defines the integration project scope, priorities, and realistic timeline to certification.
IMS Scope, Policy, and Context
Draft the IMS scope statement covering all three standards. Complete context of the organisation analysis and stakeholder register. Draft the combined IMS policy signed by top management. These documents are reviewed at Stage 1 and form the foundation of the entire system.
Risk Register, Aspects Register, and HIRA
Build the unified risk register incorporating quality risks, environmental aspects and impacts, and OH&S hazards and risks. Establish the legal register for all three disciplines. These documents drive your objectives, operational controls, and internal audit focus.
Procedures, Objectives, and Operational Controls
Develop shared procedures (document control, internal audit, NCR and corrective action, management review, training). Set IMS objectives covering quality, environmental, and H&S KPIs. Implement process-level operational controls addressing Clause 8 requirements for all three standards.
Training, Awareness, and Worker Consultation
Deliver IMS awareness training across the business. Establish the worker consultation and participation process required by ISO 45001 Clause 5.4 — this is a specific, audited requirement, not a one-off exercise. Update the competence matrix. Begin generating operational records and monitoring data against objectives.
Internal Audit Cycle and Management Review
Complete at least one full integrated internal audit cycle covering all three standards. Address all non-conformances and record corrective actions. Hold IMS management review using a combined agenda that satisfies all input and output requirements for all three standards in a single meeting with documented minutes.
Stage 1 and Stage 2 Certification Audits
Submit IMS documentation to the certification body for Stage 1 review. Address any observations. Host Stage 2 on-site audit. Respond to any findings within the agreed timescale. Receive combined ISO 9001, ISO 14001, and ISO 45001 certification from your chosen UKAS-accredited body.
Realistic Timelines
For a UK SME building a triple IMS from scratch, a realistic timeline to initial combined certification is typically 6–12 months, depending on the maturity of existing systems and the internal resource available. Our own website notes that single-standard implementation typically takes 2–6 months — adding two additional standards with a properly integrated approach extends that range. Businesses already holding one standard are typically looking at a similar range for the remaining two. Businesses already holding two standards can typically achieve triple certification within 3–6 months. A free gap assessment will give you a much more precise estimate for your specific situation. Book a free discovery call to discuss your timeline.
Common Challenges UK SMEs Face
Treating Integration as a Filing Exercise
The most common mistake is consolidating documents into shared folders without changing how quality, environmental, and H&S management actually operates day-to-day. Genuine integration means the same team, the same meetings, the same escalation routes, and the same improvement cycle — not just shared stationery. Certification auditors will probe whether the system is lived, not just documented.
Underestimating the HIRA and Environmental Aspects Assessment
Both the environmental aspects assessment and the OH&S HIRA are more demanding than many SMEs anticipate — particularly when starting from a quality management base. A superficial aspects register and a one-off HIRA are among the most common triggers for major non-conformances at ISO 14001 and ISO 45001 certification audits. Both registers must be dynamic, reviewed when processes change, updated after incidents, and tested during internal audits.
Worker Consultation — a Specific ISO 45001 Obligation
ISO 45001 Clause 5.4 requires formal processes for worker consultation and participation in hazard identification, risk assessment, incident investigation, and OH&S management decisions. This is not satisfied by an annual H&S survey. Auditors expect to see records of structured worker involvement — toolbox talks, safety committee meetings, documented feedback from workers, and evidence that their input has influenced decisions. The HSE provides guidance on worker involvement that is useful context for UK SMEs building this requirement into their IMS.
Legal Register Maintenance Across Three Disciplines
A triple IMS legal register spans product quality legislation, environmental law, and health and safety regulation. The legal register must be reviewed regularly — at least annually — to capture changes in legislation, updated guidance, and new applicable requirements. Post-Brexit regulatory divergence means UK environmental law in particular is an evolving landscape that cannot be managed by retaining outdated EU references.
Internal Auditor Competence Across All Three Standards
Auditing a triple IMS requires competence against all three standards. Many SMEs find their existing internal audit team is trained on ISO 9001 only. Investment in combined IMS internal auditor training — or bringing in external support to co-audit until internal capability is established — is essential for a credible and effective audit programme.
When to Seek External IMS Support
Triple IMS implementation is achievable with internal resource — but the combination of three standards, the complexity of the environmental and H&S discipline-specific requirements, and the volume of documentation and training involved makes it a genuinely demanding project for a lean SME team. External integrated ISO management system support adds most value in the following situations:
- Building from scratch across all three: A proven framework and structured project approach from experienced ISO consultants compresses timelines and avoids the trial-and-error cost of independent implementation
- Environmental and H&S expertise gaps: Businesses with a strong quality management base but limited environmental management or OH&S expertise benefit from specialist support on aspects assessment, HIRA methodology, legal register construction, and Clause 8 operational controls
- Certification readiness assurance: A pre-assessment gap review and Stage 1 readiness check from an experienced IMS provider identifies weaknesses before the certification body does — protecting the investment in the certification process
- Ongoing compliance maintenance: Retained IMS support covering system reviews, legal register updates, internal audit facilitation, and management review preparation is a cost-effective alternative to maintaining full in-house quality, environmental, and H&S management capacity year-round
Ready to bring all three standards into one system?
Goldenpath PM provides hands-on triple IMS support for UK SMEs — from initial gap analysis to combined ISO 9001, ISO 14001, and ISO 45001 certification, and ongoing compliance maintenance. Based in Kings Lynn, working with SMEs across the UK.
Frequently Asked Questions
Can ISO 9001, ISO 14001, and ISO 45001 all be integrated into one management system?
Yes — and the standards are specifically structured to make this possible. All three are built on the ISO Harmonized Structure (HLS), which provides identical clause numbering and compatible requirements language across all three. The majority of the management system infrastructure — policy, context, risk management, objectives, document control, internal audit, management review, and improvement — can be built once to satisfy all three simultaneously. Only discipline-specific requirements (environmental aspects register, HIRA, customer satisfaction monitoring, and worker consultation records) require standard-specific sections within the unified framework.
What documents are shared across all three standards?
The core shared documents include: the IMS policy; the scope statement; the context and stakeholder register; the risk and opportunity register; the objectives register; the document control procedure; competence and training records; the internal audit programme and reports; management review records; the nonconformity and corrective action log; and the legal compliance register. Standard-specific documents — the environmental aspects register (ISO 14001), the HIRA (ISO 45001), worker consultation records (ISO 45001), and the customer satisfaction monitoring process (ISO 9001) — are maintained as clearly cross-referenced documents within the IMS framework. See our ISO 9001, ISO 14001, and ISO 45001 pages for more on each standard's specific requirements.
How long does it take to implement a triple IMS and achieve certification?
For a UK SME building a triple IMS from scratch, a realistic timeline to combined certification is broadly 6–12 months, depending on the maturity of existing systems and the internal resource committed to the project. Businesses already holding one standard are typically looking at a similar range to add the remaining two simultaneously. Those already holding two standards can typically achieve triple certification within 3–6 months. These are general guidance figures — a free gap assessment will give a much more accurate estimate for your business. Book a free discovery call to discuss your specific situation.
Is a combined certification audit available for all three standards?
Yes. All major UK UKAS-accredited certification bodies — including BSI, NQA, and Bureau Veritas — offer combined audit programmes covering ISO 9001, ISO 14001, and ISO 45001 in a single visit cycle. Certification is valid for three years with annual surveillance audits required in years one and two — all of which can be conducted as a single combined visit. Running a combined programme is considerably more cost-effective than maintaining three separate certification programmes.
How does ISO 45001 differ from the other two standards in a triple IMS?
ISO 45001:2018 introduces two requirements that have no direct equivalent in ISO 9001 or ISO 14001: the hazard identification and risk assessment (HIRA), which must cover all activities, persons, and conditions including emergency scenarios; and worker consultation and participation (Clause 5.4), which requires formal, ongoing processes for worker involvement in hazard identification, risk assessment, incident investigation, and OH&S management decisions. Both require dedicated content and ongoing evidence generation within the IMS, and are commonly the areas most thoroughly tested during certification audits for businesses extending from an existing ISO 9001 or ISO 14001 base. The Health and Safety Executive (HSE) provides useful free guidance on both risk assessment and worker involvement for UK SMEs.
How much does a triple IMS cost to implement and certify?
Costs vary significantly depending on your business size, number of sites, sector complexity, and the maturity of your existing systems. At Goldenpath, all engagements are fixed-fee — you receive a clear, all-inclusive proposal following a free discovery call, with no hidden extras or scope creep charges. Certification body fees are separate, but we'll guide you to the most appropriate UKAS-accredited option for your situation. Get in touch or view our FAQs for more on how we price our engagements.







