NEWS

Are Your ISO Management Systems Working Together – Or Creating More Work? Integrated Management Systems | ISO 9001 | ISO 14001 | ISO 45001 | ISO 27001

Welcome to the September edition of the QHSE Aberdeen Knowledge Hub.

Over recent months, we’ve looked individually at Information Security, Environmental Management, Health & Safety, Quality, ESG, Sustainability and Carbon Reporting.

This month, we’re bringing many of those subjects together.

If your organisation operates more than one ISO Management System, there’s an important question worth asking:

Are your systems actually working together—or are they creating unnecessary work?

An effective Integrated Management System (IMS) can bring Quality, Environmental, Health & Safety and Information Security requirements together within one practical management framework.

The objective shouldn’t be to create more paperwork.

It should be to create a management system that helps you run the business.


What is an Integrated Management System?

An Integrated Management System, commonly referred to as an IMS, combines the requirements of two or more management system standards into a single, coordinated framework.

For example, an organisation certified to:

doesn’t necessarily need three completely separate management systems.

And if ISO 27001 Information Security is also relevant to the organisation, many common management processes can be coordinated while still addressing the specific requirements of each standard.

Rather than maintaining separate processes for everything, an integrated approach can bring together common elements such as:

  • Leadership and responsibilities
  • Organisational context
  • Risks and opportunities
  • Objectives and KPIs
  • Document control
  • Competence and training
  • Internal auditing
  • Corrective actions
  • Management review
  • Continual improvement

The result can be a simpler and more effective management system that is easier for employees to understand, use and maintain.


Why Integrate ISO 9001, ISO 14001 and ISO 45001?

One of the problems we sometimes see is that organisations have gained ISO certifications at different stages of their development.

ISO 9001 may have come first.

ISO 14001 was added when a customer or tender required it.

ISO 45001 followed as the organisation grew.

Before long, the business can find itself operating multiple procedures, registers, objectives, audit programmes and management reviews.

Integration provides an opportunity to simplify.

A well-designed Integrated Management System can help:

✔ Reduce duplicated processes and documentation

✔ Create clearer roles and responsibilities

✔ Coordinate internal audits

✔ Bring objectives and KPIs together

✔ Improve management review

✔ Provide greater visibility of organisational risk

✔ Make document control easier

✔ Improve employee understanding

✔ Support continual improvement

Most importantly, it can make the management system feel like part of the business rather than something that exists solely for an ISO audit.


We Practice What We Preach

At QHSE ABERDEEN LIMITED , we don’t just advise businesses on ISO Management Systems.

We operate them ourselves.

QHSE Aberdeen holds certification to:

ISO 9001 – Quality Management

ISO 14001 – Environmental Management

ISO 45001 – Occupational Health & Safety

Operating our own Integrated Management System gives us first-hand experience of what is involved in maintaining multiple ISO certifications—and why keeping the system practical matters.

Article content
ISO 9001/14001/45001 Certs

Our auditors are also qualified Lead Auditors, bringing both technical knowledge and practical auditing experience to the management systems we develop, audit and support for our clients.

We don’t believe an ISO Management System should be unnecessarily complicated, filled with procedures nobody uses or designed simply to get through a certification audit.

We believe in creating simplified, bespoke and fit-for-purpose management systems that reflect how an organisation actually operates.

A good management system should:

  • Make sense to the people using it
  • Meet the requirements of the applicable ISO standards
  • Remove unnecessary duplication
  • Integrate with existing business processes
  • Make internal and external auditing easier
  • Support business objectives and continual improvement
  • Grow and adapt alongside the organisation

Your management system should work for your business—not your business for the management system.


Is Your Management System Becoming Too Complicated?

Ask yourself a few questions.

Do different departments use different versions of documents?

Do you maintain separate registers containing much of the same information?

Are actions only reviewed when an audit is approaching?

Do ISO responsibilities sit with one person rather than being embedded across the business?

Are management reviews lengthy exercises carried out primarily because the standard requires them?

Do employees understand the system—or does only the QHSE Manager really know how it works?

If any of those sound familiar, your organisation may benefit from reviewing how its management systems are structured.

Simplifying a management system doesn’t mean reducing compliance.

Done properly, it means removing unnecessary complexity while improving control.


ISO 9001:2026 – An Important September Update

September is particularly significant for Quality Management.

The Final Draft International Standard for the next edition of ISO 9001 has been approved, with the sixth edition scheduled for publication during September 2026.

For organisations currently certified to ISO 9001:2015, this doesn’t mean ripping up your existing Quality Management System and starting again.

Instead, it provides an ideal opportunity to review whether your current system remains effective, proportionate and aligned with the way your organisation operates today.

The revised standard retains the familiar management system framework while introducing targeted updates, including greater clarity around leadership and quality culture, risks and opportunities, and alignment with other ISO Management System standards.

QHSE Aberdeen will continue to monitor the publication and transition requirements and will provide practical updates to our clients and Knowledge Hub news subscribers as further information becomes available.https://www.iso.org/standard/88464.html


ISO 14001:2026 – Have You Started Preparing?

While ISO 9001 is approaching publication, the new edition of ISO 14001:2026 was published in April. https://www.iso.org/standard/14001

The updated Environmental Management System standard retains the established ISO 14001 framework but provides clearer guidance and increased focus on areas including environmental performance, climate change, biodiversity, resource efficiency, leadership and governance.

For organisations currently certified to the previous edition, now is the time to understand the changes and begin planning an orderly transition.

This is also an excellent opportunity for organisations operating ISO 9001, ISO 14001 and ISO 45001 to consider whether their systems are genuinely integrated—or simply sitting alongside one another.


Internal Auditing – One Audit or Three?

Internal auditing is one of the areas where integration can provide significant benefits.

If your organisation operates ISO 9001, ISO 14001 and ISO 45001, you don’t necessarily need completely separate audit programmes for each standard.

An integrated internal audit programme can examine how processes perform across Quality, Environmental and Health & Safety requirements simultaneously.

For example, when auditing a purchasing or supplier management process, an auditor might consider:

  • Quality and supplier performance
  • Environmental requirements
  • Health & Safety risks
  • Legal and compliance obligations
  • Competence
  • Documentation
  • Corrective actions

This can provide management with a much more complete picture of how effectively the process is working.

But effective integrated auditing requires competent auditors who understand both the standards and the practical operation of the business

Article content
Clauses

Training & Development

Developing competent internal auditors is one of the best investments an organisation can make in its Management System.

At QHSE Aberdeen, we deliver a range of ISO, Internal and Lead Auditor training courses in Aberdeen, including CQI | The Chartered Quality Institute & IRCA | International Register of Certificated Auditors certified training and bespoke in-house programmes.

Courses may include:

  • ISO 9001 Lead Auditor
  • ISO 9001 Internal Auditor
  • ISO 14001 Internal and Conversion training
  • ISO 45001 Internal and Conversion training
  • IMS Internal Auditor – ISO 9001, ISO 14001 & ISO 45001
  • ISO 27001 Internal Auditor
  • Bespoke ISO Awareness Training
Article content
September Training
Article content
October Training

Our courses focus not simply on understanding clauses, but on helping delegates understand why the requirements exist and how to apply them in real organisations.

See our training page here..


A client asked…?

Should I be adding AI to my risks and opportunities register?

If you haven’t done so already, then yes. This would be recommended for several reasons. The changing landscape around AI can be both a risk and an opportunity for most businesses. Clause 6.1 of ISO Management System Requirements standards requires organisations to “address risks and opportunities” and act on them. AI could be used to improve your own operations (ISO 9001:2026); a lack of control around AI use could be considered an in(ISO 27001:2022).  AI use could certainly be an identified input for the consideration of environmental aspects and impacts (ISO 14001:2026).   Do the opportunities outweigh the risks? There is no single yes or no answer. Much will depend on your organisation’s applicable AI usage and data security policies. If asking AI to draft an article based on specified parameters can be delivered in 30 seconds, saving you a day’s work (opportunity) without compromising confidential information or data security (risk), then your business may classify this as acceptable. Remember, articles generated by AI should always be treated as a draft with the content fact-checked and modified to suit your own style, so this will utilise some of your time again.  To ensure that information security is not compromised, you will need to think about how AI could be used in your business, what it will have access to or have uploaded into it, identify what could go wrong (the risk) and what you plan to do about it (your controls).  Doing this is becoming increasingly essential for businesses that are certified to ISO 27001, but it’s a good idea for all businesses, especially if you are deploying custom agents or setting up any decisions to be made by AI models.  AI can also be an opportunity for your information security management system, with AI increasingly informing threat intelligence and automated defences.   Something to consider for your aspects and impacts documentation: during training, the energy consumption required for AI LLMs (Large Language Models) to operate is huge. This is driven by the processing power demands of training large models and running data centre servers 24 hours a day, seven days a week. The Magazine of Energy Institute noted that ‘training OpenAI’s GPT-4 (with well over a trillion parameters) consumed over 50 GWh of electricity’1.   On a far smaller scale, the power use per standard text query is around 0.24 Wh (Gemini) and 0.34 Wh (ChatGPT2). Perhaps not much when 1 kWh of CO2e = 0.196 to 0.233 kg of CO2e. However, if you think about how many times per day you and your colleagues ask ChatGPT or Google Gemini or others a question (business-related or otherwise), energy consumption can begin to have an impact. Multiply that by the billions of queries these systems get per day…   Also, the water consumption to keep data centres running should be considered as part of the lifecycle process: cooling systems for servers to maintain stable operating temperatures and prevent overheating, and electricity supply, which may come from gas and nuclear power stations that evaporate water during operation.   So perhaps the question is ‘Should I be adding AI to my quality risks and opportunities register, my information security risk and opportunities register, and my environmental aspects and impacts register?’ The answer is still yes.   If you would like some assistance with how to record, measure, and report your risks and opportunities or your greenhouse gas emissions, give QHSE Aberdeen a call. References: Magazine of Energy Institute https://knowledge.energyinst.org/new-energy-world/article?id=139859 How much energy does Googles AI use? We did the Math https://cloud.google.com/blog/products/infrastructure/measuring-the-environmental-impact-of-ai-inference AI’s Thirst for Water – Rich Kenny, Avinash Lunj and Alexandra Kis, 17 September 2025 https://sustainableict.blog.gov.uk/2025/09/17/ais-thirst-for-water/ OpenAI CEO Sam Altman’s blog article ‘The Gentle Singularity’. https://blog.samaltman.com/the-gentle-singularity What are data centres and how sustainable are they? https://post.parliament.uk/research-briefings/post-pn-0762/ Scottish Parliament Information Centre (SPICe) blog on Data Centres in Scotland. DSIT Research and Analysis:  Cyber Security Risks to Artificial Intelligence Cyber security risks to artificial intelligence – GOV.UK NIST blog: Managing Cyber Security and Privacy Risks in the Age of Artificial Intelligence  Managing Cybersecurity and Privacy Risks in the Age of Artificial Intelligence: Launching a New Program at NIST | NIST


QHSE Aberdeen Team Update

RECRUITMENTPlayHiring

As demand for our consultancy and training services continues to grow, we’re continuing to strengthen the QHSE Aberdeen team.

If you feel confident in your knowledge and want to share it with others, then check out our careers page.. https://www.qhseaberdeen.com/careers/

Our clients increasingly require expertise across multiple disciplines—from Quality, Health & Safety and Environmental Management to Information Security, DSEAR, ESG and specialist auditing.

That breadth of knowledge allows us to provide clients with joined-up QHSE support rather than treating each requirement in isolation.


Do You Need a Full-Time QHSE Manager?

Not necessarily.

For many SMEs, employing a full-time senior QHSE professional isn’t required or commercially viable.

Our fractional QHSE support allows organisations to access experienced QHSE Consultants and Lead Auditors for an agreed number of days each month.

We can help manage:

  • ISO Management Systems
  • Internal audits
  • Management reviews
  • Compliance obligations
  • Risk assessments
  • Client questionnaires
  • Supplier audits
  • Corrective actions
  • Certification preparation
  • Ongoing QHSE improvement

In effect, we can become an extension of your QHSE team—or your QHSE department.


Looking Ahead

As we move towards the final quarter of 2026, this is a good time to ask whether your Management System still reflects your organisation.

Businesses change.

Teams grow.

Customers change.

New legislation emerges.

New ISO standards are introduced.

And management systems need to evolve with them.

If your ISO system has become overly complicated, duplicated or difficult to maintain, perhaps it’s time to simplify it.

At QHSE ABERDEEN LIMITED , we help organisations develop practical Integrated Management Systems covering ISO 9001, ISO 14001, ISO 45001 and ISO 27001, designed around the organisation rather than an off-the-shelf template.

Because ultimately:

ISO certification isn’t about creating more paperwork.

It’s about creating better businesses.


Final Thoughts

An effective Integrated Management System should provide structure, clarity and confidence.

It should help management understand risk.

It should help employees understand what is expected of them.

It should provide customers with confidence.

And it should help the organisation continually improve.

That’s what a good Management System is supposed to do.

If you’re considering ISO certification in Aberdeen, looking to integrate existing ISO 9001, ISO 14001 and ISO 45001 systems, preparing for the new ISO 9001:2026 edition, or simply wondering whether your existing Management System could be made easier to manage, we’d be happy to have a conversation.

Sometimes simplifying the system is the biggest improvement you can make.

Simplify. Integrate. Improve.

The QHSE Aberdeen Team

Share:

Archives

Recent Posts