Our organization is looking to get certified in both ISO 9001 and ISO 27001 this year. I've heard that there is a lot of overlap in the high-level structure, particularly around leadership, planning, and internal audits. Is it more efficient to build one Integrated Management System (IMS), or should we keep the quality and security documentation separate to avoid confusion?
3 answers
Building an IMS is significantly more efficient in the long run. Both standards follow Annex SL, which means the clause numbers and headings are identical. You can have a single Management Review meeting, one internal audit program, and one process for handling non-conformities and corrective actions. This reduces the "documentation fatigue" that many organizations face. The only things that remain separate are the specific technical controls—Quality for 9001 and the Statement of Applicability (SoA) for 27001. An IMS ensures that security is seen as a quality characteristic of your service.
Do you have separate teams currently managing quality and IT security? The biggest hurdle to an IMS isn't the documentation; it's the internal politics of merging two different departments' workflows into one unified system.
I’ve implemented an IMS before and the cost savings on audit fees alone made it worth it. Registrars usually give a discount for integrated audits.
Nancy is right. Plus, having a single source of truth for all company policies makes onboarding new employees much faster and ensures they understand both quality and security from day one.
Steven, that is a valid concern. Currently, IT and Operations work in silos. If we designate a single "Compliance Officer" to oversee the IMS, would that satisfy the "Leadership and Commitment" requirement for both standards simultaneously?