
Adding a second standard to a working system is nothing like implementing the first one. Most of the machinery is already built, and the common mistake is running the second standard as a separate project.
Why the second one is cheaper
ISO management system standards share a common structure. Clauses 4 to 10 cover the same ground in each: context, leadership, planning, support, operation, performance evaluation and improvement. That means a business certified to ISO 9001 already has most of what ISO 14001 or ISO 45001 asks for at the management system level.
You already have document control, internal audit, management review, corrective action, competence records and objectives. None of that needs building again. What you need is the subject-specific content: environmental aspects and impacts for 14001, hazard identification and risk assessment for 45001, a Statement of Applicability for 27001.
As a rough guide, if the first standard took twelve weeks, the second added to the same system is often five or six.
Integrated, not parallel
The decision that matters is whether you run one integrated management system or two systems side by side. Two separate systems means two manuals, two audit programmes, two management reviews and two sets of records that drift apart. It roughly doubles the maintenance and it is how businesses end up resenting certification.
An integrated system has one set of core processes serving every standard. One internal audit programme covering quality, environment and safety in the same visit. One management review meeting with the required inputs for all of them on one agenda. One corrective action process, one document control system, one objectives register with different columns.
The saving is not in the implementation. It is in every year afterwards.
What genuinely has to be separate
Not everything merges. Keep these distinct:
- The registers. Environmental aspects, hazards and risks, and information security risks are different exercises with different methods.
- Legal and other requirements. Environmental and health and safety legislation are separate bodies of law and the register needs to be able to show which applies to what.
- Some objectives. A safety objective and a quality objective are rarely the same thing, though they sit in one register.
- Emergency preparedness. Required explicitly by 14001 and 45001, and the scenarios differ.
Doing it at the right moment
If you know you will eventually want a second standard, say so when the first is being built. Designing an integrated structure from the start costs almost nothing extra. Retrofitting one to a system built for a single standard is real work, because the manual, the audit programme and the review agenda all have to be reorganised.
The other timing question is the certification cycle. Adding a standard mid-cycle usually means a separate initial audit for the new standard, then the cycles align at the next recertification. Some certification bodies will align them sooner. Ask, because a combined audit visit is cheaper than two visits and less disruptive.
Transitioning to a new version
The other kind of update is a revision to a standard you already hold. Standards are reviewed periodically and revised versions come with a transition period, typically three years, during which certificates to the old version stay valid.
Two rules make transitions painless. Start early, because leaving it to the final months means competing with everyone else for assessor availability. And treat it as a gap exercise rather than a rebuild, because revisions usually change emphasis and structure rather than replacing requirements wholesale. Our guide to the ISO 27001:2022 transition works through what that looks like in practice.
What it should not do
Adding a standard should not double your paperwork. If a consultant proposes a second manual, a second audit programme and a second review cycle, ask why. For the overwhelming majority of businesses the answer is that integration would have been better and harder to sell.
We build integrated systems by default. See system implementation for how that works, or the individual standards pages for ISO 9001, ISO 14001 and ISO 45001.
‹ Back to all articles