EHS compliance director presenting ISO 45001, 9001 and 14001 integration framework on a glass whiteboard

Integrated Systems: Achieving Organizational Excellence Through Combined Compliance

LAW: Integrated Management Systems
Integrated Systems: Achieving Organizational Excellence Through Combined Compliance
An Integrated Management System (IMS) combines multiple compliance frameworks (most commonly ISO 45001 (occupational health and safety), ISO 9001 (quality management), and ISO 14001 (environmental management)) into a single, coordinated management system. Rather than running three separate compliance programmes with separate documentation, audits, and review cycles, an IMS aligns them under a common structure. This article explains the legal and regulatory context of integrated systems, the employer obligations each framework imposes, and how integration supports both compliance and organisational performance.
Legal Disclaimer: This article provides educational information about management system standards and regulatory frameworks. It does not constitute legal advice. Organisations should consult qualified legal counsel and certified management system professionals when implementing compliance programmes or seeking certification.

Law Summary

ISO 45001:2018
OHS Management
International standard for occupational health and safety management systems. Replaced OHSAS 18001. Specifies requirements for an OHS management system to enable organisations to provide safe workplaces and prevent work-related injury and illness.
ISO 9001:2015
Quality Management
International standard for quality management systems. The world’s most widely implemented management system standard. Specifies requirements for a QMS that demonstrates the ability to consistently provide products and services that meet customer and regulatory requirements.
ISO 14001:2015
Environmental Management
International standard for environmental management systems. Provides a framework for protecting the environment, preventing pollution, and improving environmental performance. Widely required by supply chain customers in manufacturing and industrial sectors.

Who Must Comply

ISO standards are voluntary international standards, not legally mandated regulations. No organisation is legally required by law to hold ISO 45001, ISO 9001, or ISO 14001 certification. However, compliance with these standards is effectively mandatory in many business contexts:

Supply chain requirements
Major manufacturers, automotive OEMs, aerospace companies, and government contractors frequently require ISO 9001 and ISO 14001 certification as a condition of supplier approval. ISO 45001 is increasingly included in supply chain requirements in the UK, EU, and Australia.
Government and public sector contracts
Many government procurement processes in the US, UK, EU, and Australia require ISO 9001 certification for product and service suppliers. ISO 14001 is required for environmental services contractors. ISO 45001 is increasingly specified in public sector OHS requirements.
Regulatory compliance credit
OSHA’s Voluntary Protection Programs (VPP) and Strategic Partnership Program recognise organisations with effective OHS management systems, which ISO 45001 supports. EPA’s National Environmental Performance Track (now replaced by sector-specific programmes) recognised ISO 14001 implementation.
Insurance and risk management
Employers’ liability and commercial insurers in several markets offer premium reductions for ISO 45001 or OHSAS 18001 certified organisations. ISO 14001 certification can reduce environmental liability insurance premiums. Risk management frameworks increasingly reference ISO management system standards.

Applicable Standards and the High Level Structure

The practical integration of ISO 45001, ISO 9001, and ISO 14001 is made possible by the High Level Structure (HLS), also known as Annex SL. The HLS is a common framework adopted by ISO for all new and revised management system standards. It gives all three standards an identical clause structure (Clauses 1-10), identical core text in shared clauses, and common definitions for shared terms. This means that where ISO 9001, ISO 14001, and ISO 45001 address the same management system requirement (context, leadership, planning, support, operation, performance evaluation, improvement), they use compatible language and documentation structures that can be merged into a single integrated system.

HLS Clause
ISO 9001
ISO 14001
ISO 45001
4: Context
Customer and regulatory context
Environmental context and compliance obligations
OHS context, worker participation, and legal requirements
5: Leadership
Quality policy, roles, responsibilities
Environmental policy, roles, responsibilities
OHS policy, roles, responsibilities, worker consultation
6: Planning
Risks, opportunities, quality objectives
Environmental aspects, impacts, objectives
Hazard identification, risk assessment, OHS objectives
9: Evaluation
Customer satisfaction, internal audit, management review
Environmental compliance evaluation, audit, review
OHS performance monitoring, incident review, management review
10: Improvement
Nonconformity, corrective action, continual improvement
Nonconformity, corrective action, continual improvement
Incident investigation, nonconformity, corrective action, improvement

Key Definitions

Integrated Management System (IMS)
A single management system that combines the requirements of two or more ISO management system standards into one documented, implemented, and audited system, eliminating duplication between separate management systems.
High Level Structure (HLS)
ISO’s common framework for all management system standards. Provides an identical 10-clause structure, core text, and common definitions across ISO 9001, ISO 14001, ISO 45001, and other management system standards, making integration possible.
Certification
Third-party assessment and confirmation by an accredited certification body that an organisation’s management system meets the requirements of a specific ISO standard. Certification is voluntary but required by many customers and regulators.
Compliance Obligations
The legal requirements and other requirements that an organisation must or chooses to comply with, relating to its quality, OHS, and environmental aspects. ISO 14001 and ISO 45001 both require organisations to identify and address their compliance obligations as part of planning.
Risk-Based Thinking
The HLS approach to planning that requires organisations to identify risks and opportunities across all management system areas (quality, OHS, environmental) and plan actions to address them. Replaces the preventive action clause of earlier standards.
Interested Parties
Persons or organisations that can affect, be affected by, or perceive themselves to be affected by an organisation’s decisions or activities. All three ISO management system standards require organisations to identify and understand the needs and expectations of relevant interested parties.

Employer Responsibilities Under Each Standard

1
ISO 45001: Occupational Health and Safety Obligations
Leadership commitment: Top management must demonstrate leadership by taking responsibility for the OHS management system, ensuring integration with business processes, and directing and supporting persons to contribute to its effectiveness.
Worker participation: ISO 45001 has a stronger worker participation requirement than its predecessor (OHSAS 18001). Organisations must consult workers and worker representatives in developing, planning, implementing, evaluating, and acting to improve the OHS management system.
Hazard identification and risk assessment: Systematic identification of hazards, assessment of OHS risks, and determination of appropriate controls using the hierarchy of controls (elimination, substitution, engineering, administrative, PPE).
Legal and other requirements: Determination and access to the applicable legal and other requirements relating to OHS hazards, and ensuring these are integrated into the OHS management system and kept current.
OSHA alignment: ISO 45001 requirements are broadly aligned with OSHA’s injury and illness prevention programme (IIPP) framework and OSHA’s Recommended Practices for Safety and Health Programs. ISO 45001 certification does not substitute for OSHA compliance but provides a structured system that supports it.
2
ISO 9001: Quality Management Obligations
Customer focus: The organisation must determine, understand, and consistently meet customer requirements and applicable statutory and regulatory requirements related to its products and services.
Process approach: Processes that affect product and service conformity must be identified, managed, and controlled. Process interactions, resources, responsibilities, and performance indicators must be defined.
Documented information: The organisation must maintain documented information required by the standard and retain documented information as evidence of conformity. Specific documents (quality policy, quality objectives, process documents) are mandatory.
Internal audit and management review: Planned internal audits at defined intervals to assess conformity and effectiveness of the QMS. Management review at planned intervals to ensure the QMS remains suitable, adequate, and effective.
3
ISO 14001: Environmental Management Obligations
Environmental aspects and impacts: The organisation must determine its environmental aspects (elements of its activities that interact with the environment), evaluate their significance, and address significant environmental aspects through controls, objectives, or both.
Compliance obligations: Determination of applicable legal requirements (environmental regulations, permits, licences) and other requirements, and ensuring the organisation meets them. Evaluation of compliance at planned intervals.
Emergency preparedness: Identification of potential environmental emergencies, establishment of procedures to prevent or mitigate their environmental impact, and periodic testing and review of those procedures.
Life cycle perspective: ISO 14001 requires consideration of environmental aspects across the life cycle of products and services, from raw material acquisition through end-of-life disposal, not only those aspects under direct organisational control.

Employee Rights Under an Integrated Management System

Right to participate in OHS management
ISO 45001 requires worker participation and consultation in developing and reviewing OHS hazard identification processes, risk assessments, controls, training needs, and the OHS objectives. Workers and worker representatives must be able to raise OHS concerns without fear of reprisal.
Right to report hazards and nonconformities
All three standards require processes for reporting nonconformities, hazards, and concerns. Workers must be able to report without fear of reprisal, and their reports must be evaluated and responded to. ISO 45001 specifically requires that workers can report incidents and hazardous situations.
Right to training and competence
All three standards require that persons doing work that affects quality, environmental, or OHS performance are competent to do so. Organisations must determine required competence, provide training or other development, and evaluate its effectiveness.
Right to remove from imminent danger
ISO 45001 explicitly requires that workers have the right to remove themselves from work situations that they believe present an imminent and serious danger to their life or health, and must be protected from undue consequences for doing so.

Compliance Requirements: What Implementation Requires

Documented Management System
All three standards require documented information that defines the scope of the system, the policies, the processes, and the responsibilities. An IMS combines these into a single document structure: one policy, one set of procedures covering all three systems, one document control system.
Internal Audit Programme
Each standard requires a planned internal audit programme. An IMS allows these to be combined into integrated audits that assess compliance with all three standards simultaneously, reducing the total audit burden on operational areas.
Management Review
All three standards require periodic management review of the management system’s performance and effectiveness. An IMS allows a single integrated management review that covers quality, environmental, and OHS performance against a common agenda.
Corrective Action System
All three standards require a nonconformity and corrective action process that identifies root causes and prevents recurrence. An IMS uses a single corrective action system for quality, environmental, and OHS nonconformities, creating a unified view of organisational improvement needs.

Common Violations and Non-Conformities

Standard
Non-Conformity Type
What Is Typically Found
ISO 45001
Worker participation
OHS decisions made without worker consultation. Hazard identification conducted only by management. No evidence of worker input into risk assessment or OHS objectives.
ISO 45001
Hierarchy of controls
Controls selected without documented evidence of applying the hierarchy. PPE implemented as a first control where engineering or administrative controls were practicable.
ISO 14001
Compliance evaluation
Compliance obligations identified but no periodic evaluation of actual compliance status. Environmental permits in place but not reviewed against current operations.
ISO 9001
Documented information
Procedures not kept current. Work instructions describe outdated processes. Retained records (evidence of conformity) cannot be located during audit.
All three
Management review
Management review conducted but outputs not documented. Actions arising from management review not tracked to completion. Review inputs incomplete against standard requirements.

Penalties and Consequences

ISO non-conformities vs regulatory violations

ISO standards are voluntary; non-conformities found during certification audits result in the requirement to implement corrective actions and demonstrate resolution before certification is granted or maintained, not in fines or legal penalties. Suspension or withdrawal of ISO certification by the certification body is the primary consequence of unresolved major non-conformities.

However, the underlying regulatory obligations that ISO management system standards help organisations meet: OSHA regulations, EPA environmental permits, state safety laws, carry their own penalties. A failure in an ISO 45001 programme that also constitutes an OSHA violation remains subject to OSHA penalty. An ISO 14001 compliance evaluation failure that corresponds to a permit violation remains subject to EPA or state enforcement action.

Commercial consequences: Loss of ISO certification in sectors where it is a supply chain requirement results in loss of approved supplier status and potentially loss of contracts. The commercial impact of certification loss frequently exceeds the direct cost of compliance remediation.

Compliance Checklist: IMS Implementation Essentials

Foundation
Scope of IMS defined and documented
Integrated policy covering quality, OHS, and environment
Interested parties identified for all three systems
Legal and other requirements identified for all three
Planning and Operation
Integrated risk and opportunity assessment
Objectives set for quality, OHS, and environmental performance
Worker participation evidenced in OHS planning
Competence requirements determined and training provided
Evaluation and Improvement
Integrated internal audit programme in place
Integrated management review conducted at defined intervals
Single corrective action system for all three standards
Compliance evaluation conducted for environmental and OHS obligations

Key Takeaways

ISO standards are voluntary but commercially mandatory in many sectors
No law requires ISO 9001, ISO 14001, or ISO 45001 certification. In practice, supply chain requirements, government procurement conditions, and insurance frameworks make certification effectively mandatory for organisations operating in many industrial and manufacturing sectors. Understanding which requirements apply to a specific organisation requires reviewing customer contracts, procurement specifications, and industry sector requirements.
Integration reduces compliance burden without reducing compliance depth
Organisations that implement ISO 9001, ISO 14001, and ISO 45001 as three separate systems typically run three separate audit programmes, three management reviews, and three corrective action systems. Integration under the HLS combines these without reducing the depth of compliance with each standard. The efficiency gains from integration are real and substantial, particularly for internal audit and management review activities.
ISO compliance does not substitute for regulatory compliance
ISO 45001 certification does not satisfy OSHA legal obligations; it provides a management system framework that helps organisations meet those obligations. ISO 14001 certification does not substitute for EPA permit compliance. An organisation can hold ISO certification and still be in violation of applicable regulations if its management system is not effectively implementing the regulatory requirements that fall within its compliance obligations. The two operate in parallel, not as alternatives.

Frequently Asked Questions

Can an organisation be certified to all three standards simultaneously?
Yes. An integrated management system can be assessed for certification against ISO 9001, ISO 14001, and ISO 45001 in a combined audit by an accredited certification body. Combined certification audits are now standard practice among major certification bodies accredited by UKAS, ANAB, IAS, and DAkkS.
How does ISO 45001 differ from OSHA’s requirements?
ISO 45001 is a management system standard that specifies how an organisation should structure its OHS programme, while OSHA regulations specify specific technical requirements (permissible exposure limits, equipment standards, training requirements) that must be met regardless of what management system is used. ISO 45001 helps organisations identify and meet their OSHA obligations through a systematic management approach, but it does not replace those obligations. An organisation with ISO 45001 certification must still comply with each applicable OSHA standard.
What is the difference between ISO 45001 and the previous OHSAS 18001 standard?
OHSAS 18001 was a British Standards Institution (BSI) specification, not an ISO standard. ISO 45001:2018 replaced it as the international OHS management system standard. Key differences include: ISO 45001 uses the HLS (enabling IMS integration); ISO 45001 has significantly stronger worker participation requirements; ISO 45001 requires consideration of the broader organisational context and interested parties; and ISO 45001 takes a more explicit risk-based approach. OHSAS 18001 certification was withdrawn and all organisations were required to transition to ISO 45001 by March 2021.

Government and Regulatory Sources

  • ISO – ISO 45001: Occupational Health and Safety Management
  • ISO – ISO 9001: Quality Management Systems
  • ISO – ISO 14001: Environmental Management Systems
  • OSHA – Recommended Practices for Safety and Health Programs
  • OSHA – Voluntary Protection Programs (VPP)
VelSafe Compliance Library
One System. Every Standard. Full Coverage.
ISO 9001, ISO 14001, and ISO 45001 are easier to manage together than apart. VelSafe covers integrated management systems, compliance law, and workplace safety in one place. Start with our library of law and compliance resources built for safety and quality professionals.
Explore Law and Compliance

Add a Comment

Your email address will not be published. Required fields are marked *