← All articles

Certification Process

One audit, multiple standards: how integrated certification works

Business meeting around a table with documents

Here's a pattern we see constantly. A contractor gets ISO 9001 certified because tenders demand it. A year later a principal contractor requires ISO 45001, so that gets added with a second certification body, because that's who quoted fastest at the time. Then a government client wants ISO 14001, and now the business is running three audit programs, hosting auditors three times a year, and paying three lots of fees for systems that are, in reality, one system.

If that sounds familiar, this article is about the obvious fix that surprisingly few businesses get around to: integrated certification.

One skeleton, several skins

Modern ISO management system standards are deliberately built on the same structure, something the standards world calls the harmonised structure. Leadership and commitment. Understanding your organisation and its context. Planning and risk. Competence and awareness. Document control. Internal audit. Management review. Corrective action. Whether the subject is quality, safety, environment, information security or AI governance, that skeleton is identical.

Certify the standards separately and you audit that skeleton once per standard. Your document control gets examined three times by three auditors who each write it up slightly differently. Your management review minutes get read three times. Your corrective action register gets sampled three times. Nobody learns anything new the second and third time; it's pure duplication, and you're paying for it in fees, in staff hours and in disruption.

What an integrated audit looks like

In an integrated audit, the common elements are assessed once. Then the audit goes deep on what's genuinely specific to each standard: hazard identification, consultation and incident management for ISO 45001; environmental aspects, legal obligations and waste controls for ISO 14001; customer requirements and process control for ISO 9001; access control, supplier security and incident response for ISO 27001; impact assessment and human oversight for ISO 42001.

The practical benefits stack up quickly. Fewer total audit days, which means a lower total cost; the reduction compared to separate audits is usually significant. One audit program with one set of dates, so you disrupt your operations once instead of three times. One lead auditor who sees your business whole, which produces findings that make sense together instead of three reports that occasionally contradict each other. And one certification decision cycle, so your certificates renew in step rather than expiring in a staggered dribble across the calendar.

There's a quality benefit too, and we'd argue it's the biggest one. Well-run businesses don't operate quality, safety and environment as separate universes; the same site supervisor manages all three before lunch. An integrated audit reads the business the way the business actually runs. The findings land better with your team because they describe reality rather than an org chart from a standards textbook.

When integration makes sense, and when to stage it

If you already run one management system covering several disciplines, and most modern systems are built that way, integration is close to a free win, and the next recertification is the natural moment to make the switch. If your standards currently live with different certification bodies, they can be brought together through the normal transfer process, usually timed to coincide with a scheduled audit so there's no gap in certified status and no repeated Stage 1 and Stage 2.

The main case for staging rather than integrating immediately is organisational, not technical: if your safety system is mature but your environmental system is six months old, or the two are managed by teams that barely speak, you might certify the new standard separately first and integrate at the following cycle. A good certification body will tell you honestly which situation you're in rather than defaulting to whatever earns more audit days.

What to ask for

If you hold, or need, more than one standard, ask your certification body two questions: what would an integrated program look like for our scope, and what does it cost across the full three-year cycle? Insist on the cycle price, not just year one. EVO delivers integrated audits across ISO 9001, ISO 45001, ISO 14001, ISO 27001 and ISO 42001 with fixed cycle pricing, and if you send us your current certificates we'll map what integration would save you. For most multi-standard businesses, it's the easiest money they'll save this year.

Keep reading

Get certified

Talk to a certification body that gets it

Clear scope, fixed pricing and auditors who understand how modern organisations work. Australian based, serving clients worldwide.