ISO 9001, 14001 & 45001: An Integrated Management System Is More Than Certificates on the Wall
A recent discussion got me thinking about something I see far too often with ISO management systems.
A business works hard to achieve certification to ISO 9001, ISO 14001 or ISO 45001 or perhaps an Integrated Management System (IMS) combining two or all three standards. It successfully passes the audit, receives the certificate or certificates and puts them proudly on the wall.
Job done.
Except it isn’t.
In many ways, that is where the real work starts.
Whether you have one ISO standard or an IMS combining two or three, your management system shouldn’t be a set of documents that only comes out when an auditor is due.
It should become part of how the business is actually run every day.
What should your ISO management system actually do?
Depending on the standard or standards your business holds, your management system should help you manage important areas of your organisation:
ISO 9001 – Quality Management
Are you consistently delivering what your customers expect? Are your processes controlled? Are you learning from complaints, mistakes and opportunities for improvement?
ISO 14001 – Environmental Management
Do you understand the environmental impact of your activities? Are you managing waste, resources, emissions and environmental risks? Are you meeting your environmental obligations?
ISO 45001 – Occupational Health & Safety
Are you identifying hazards and controlling risks? Are employees, contractors and others working under your control protected? Are people involved and consulted about health and safety?
Whether you hold one standard or combine two or all three within an IMS, they should provide something much more useful than a certificate.
They should provide a management system that helps you run a better business.
One, two or three standards – it is still your business
This is why, where a business holds more than one standard, I am a big supporter of an integrated approach.
Your business doesn’t suddenly become a different organisation depending on whether you’re looking at quality, environmental management or health and safety.
The same people are involved.
The same operations are taking place.
The same suppliers and subcontractors are often involved.
The same management team is making decisions.
And many of the risks, opportunities, objectives, audits and actions overlap.
So if you have two or three standards, why manage them as completely separate systems?
A well-designed IMS can bring together areas such as:
- policies and objectives;
- risks and opportunities;
- legal and other requirements;
- roles and responsibilities;
- competence and training;
- document control;
- supplier and subcontractor management;
- operational controls;
- communication;
- internal audits;
- non-conformances and corrective actions;
- management reviews; and
- continual improvement.
It can make compliance simpler and more useful, rather than simply creating more paperwork.
The certificate isn’t the management system
Businesses often start their ISO journey because a customer has requested certification, it’s required for a tender or framework, or they want to demonstrate their credentials when competing for work.
And that’s perfectly understandable.
ISO certification can be commercially valuable.
But there’s a danger of concentrating so heavily on passing the audit that the reason behind the management system gets forgotten.
ISO 9001 isn’t just about passing a quality audit.
ISO 14001 isn’t just about having an environmental policy.
ISO 45001 isn’t just about having risk assessments.
And an IMS certainly isn’t about creating a huge folder of documents that nobody looks at for eleven months of the year.
The documents need to reflect what actually happens in the business.
From the office to the site
In my previous operational roles, I wasn’t interested in whether a procedure looked fantastic sitting in a folder.
I wanted to know whether it was actually happening.
That meant getting out onto sites, auditing operations, speaking to the people doing the work and checking that the systems we’d put in place were genuinely being followed.
Because there can be a very big difference between:
“This is our procedure.”
and
“This is what we actually do.”
And that difference is exactly where risk can hide.
Internal audits should add value
An internal audit shouldn’t simply be a practice run for the certification auditor.
It should be asking:
Is our management system actually working?
Are processes being followed?
Are objectives being monitored?
If you have ISO 14001, are your environmental aspects and impacts still relevant?
If you have ISO 45001, are your health and safety controls effective?
Are suppliers and subcontractors being monitored?
Have actions from previous audits actually been closed?
Are employees aware of the management system and their responsibilities?
Are customer complaints, incidents, near misses and non-conformances being used to improve the business?
And perhaps one of the most important questions:
Does what happens in practice match what your management system says happens?
Finding a problem during an internal audit isn’t necessarily a bad thing.
I’d much rather identify a gap, help the business understand it and get it corrected than have it discovered following a customer complaint, environmental incident, accident or external certification audit.

I want it to be right
When I support a business with ISO, my aim isn’t simply to help them get through the audit.
Of course I want them to achieve or maintain their certification.
But I also want their management system to work for them.
I want the documents to reflect their actual business.
I want employees to understand the processes rather than simply being told there is an ISO system.
I want management to be able to use the information within the system to make better decisions.
I want businesses identifying risks before they become problems.
And I want them using their certification to demonstrate to potential customers that they are a well-managed, responsible and safe organisation.
Because when an ISO management system is implemented properly, whether that’s ISO 9001, ISO 14001, ISO 45001 or an IMS combining them, it can help you:
Improve quality. Reduce environmental impact. Protect people. Reduce risk. Demonstrate compliance. And ultimately, help you win and retain work.
That’s far more valuable than a certificate on the wall.
A question for businesses with ISO certification
If your external ISO audit wasn’t due for another three years, would your management system still be used tomorrow?
If the answer is “probably not”, your system may not be as embedded in your business as you think.
And that’s something worth looking at.
Compliance Compass
Helping you reduce risk, improve compliance and win work.
Anne Ashman
anne.ashman@compliance-compass.co.uk
compliance-compass.co.uk
