Document management
One way of creating, approving and updating documents.
Management systems
ISO 9001, ISO/IEC 27001 and ISO/IEC 42001 share the same basic structure. We help you use that: one coherent management environment with shared processes — and specific requirements where they really differ.
The standards share a common high-level structure (the “Harmonized Structure”). These elements can usually be shared:
One way of creating, approving and updating documents.
One role model and one approach to training and competence.
Objectives that connect quality, security and AI where it makes sense.
A combined audit program instead of separate audit cycles.
One management review that covers all systems.
One process for nonconformities, root causes and follow-up.
A consistent approach to risks and opportunities, with specific methods where needed.
One improvement cycle for the whole organization.
Which systems, processes and documents already exist — and who uses them?
Which processes can be shared, and where do requirements genuinely differ?
A structure with a shared core and standard-specific modules.
Merge without disrupting certificates or daily operations.
Combined audits, reviews and improvement cycles.
Integrate before you replace
An existing QMS is usually the best starting point for an ISMS. We extend what works instead of building a parallel system.
Shared structure
The standards share the same basic structure. What can be shared is handled once.
ISO 9001
Quality (QMS)
ISO/IEC 27001
Information security (ISMS)
ISO/IEC 42001
AI governance (AIMS)
An integrated management system combines several management system standards — for example ISO 9001, ISO/IEC 27001 and ISO/IEC 42001 — into one coherent system. Shared elements such as document control, audits, reviews and corrective actions are handled once; standard-specific requirements are added as modules.
Many certification bodies offer combined audits for integrated systems. Whether and how this works for you depends on your certification body and scope — we help you prepare for it.
Usually a substantial part of the management framework: context, leadership, document control, internal audit, management review, corrective actions and improvement. What is new is mainly the information security risk assessment, the Annex A controls and the Statement of Applicability.
ISO/IEC 42001 uses the same structure. Organizations that already run an ISMS or QMS can add AI governance as another module instead of creating a new silo.
Build a working ISMS and prepare for ISO/IEC 27001 certification — together with your team and on top of the tools you already use.
Introduce or maintain a quality management system according to ISO 9001 — practical, process-oriented and ready to integrate with other standards.
Get an overview of AI use, set clear rules, assess risks and prepare for the EU AI Act and ISO/IEC 42001 — without creating another silo.
What ISO 9001 and ISO/IEC 27001 have in common, which processes an integrated management system (IMS) can share, and what remains specific to each standard.
What AI governance means, what ISO/IEC 42001 is, what the EU AI Act requires after the 2026 Digital Omnibus amendment, and how both connect to an existing ISMS.
Certification is not the finish line. What ISMS maintenance involves, which activities recur every year, and how to avoid the pre-audit panic.
Let us look at what you already have. The answer is usually: more than you think.