Management System

A management system is the documented framework of policy, objectives, roles, processes and evidence with which an organisation steers and improves one subject deliberately. The ISO standards for information security, business continuity, compliance and quality share the same base structure, which is what makes running several systems together possible.

GRCLast reviewed:

Adding a second standard without starting again

Sooner or later a customer, a regulator or a parent company asks for a second certificate: business continuity next to information security, compliance next to quality. The instinct is to start again: another manual, another audit programme, another management review. The reason that instinct is wrong is structural, and it is worth understanding before the second project is scoped.

What makes something a management system

A management system is not a folder of documents. Four features decide it: an objective carried by top management, defined processes with named owners, evidence that those processes are actually lived, and a mechanism that detects deviations and triggers improvement. Take the fourth away and what remains is a document collection, recognisable as such in the first audit.

The shared structure

The ISO directives prescribe the same outline for all management system standards. It is commonly referred to as Annex SL or the High Level Structure, and newer editions speak of a harmonised structure. For a user this means that knowing one of these standards makes the others navigable.

ClauseContentCore question
4 Context of the organisationEnvironment, interested parties, scopeWhat is the system for, and who expects what
5 LeadershipCommitment of top management, policy, roles and authoritiesWho carries it
6 PlanningRisks and opportunities, objectives, planning of changesWhat is to be achieved, and what stands in the way
7 SupportResources, competence, awareness, communication, documented informationWith what
8 OperationPlanning, control and performance of the activitiesHow, day to day
9 Performance evaluationMonitoring and measurement, internal audit, management reviewIs it working
10 ImprovementNonconformities, corrective actions, continual improvementWhat is being changed

Clauses 1 to 3 contain scope, normative references and terms, and are not the subject of implementation.

What differs between the standards

The mechanics stay the same; the subject differs. ISO/IEC 27001 adds a risk assessment and treatment referencing a set of controls, plus the Statement of Applicability. ISO 22301 adds business impact analysis, continuity strategies and exercises. ISO 37301 adds the identification of compliance obligations and compliance risks. ISO 9001 adds customer- and product-related requirements. Anyone already operating one of these standards has the greater part of the structure for the next one already standing.

That answers the second-certificate question. You are not building a second system. You are adding a subject to one you already have.

The control loop

The structure maps a cycle of plan, do, check and act: clause 6 plans, clause 8 performs, clause 9 checks, clause 10 acts. The cycle is why a management system can never be finished. It is also where systems fall asleep: internal audits get postponed, the management review is dropped, open actions run on without a date.

The integrated management system

Can be sharedSubject-specific
Context and interested partiesRisk methodology per subject
Policy framework and document controlSubstantive requirements
Role model and training processSpecialist competence requirements
Audit programme and pool of auditorsDepth of examination per standard
Management reviewInputs and metrics
Nonconformity and action procedureAssessment criteria

The benefit is one audit programme instead of three, one management review instead of several, and one action register covering all subjects. The precondition is a common scope, or at least a clean mapping of the differing scopes onto one another. In a group where certificates are held by different entities, that mapping is the actual work, not the documentation.

Relationship to statutory requirements

Rules such as the GDPR, DORA or the NIS2 Implementation Act do not require a certified management system. They do require its components: a risk assessment, appropriate measures, evidence, verification of effectiveness, and a recognisable leadership responsibility. An existing management system is therefore the cheapest carrier structure for new regulatory requirements, because it has already organised the production of evidence.

The failure modes

Systems fail in recognisable ways. The system gets built for the certificate rather than for operation. The control loop stops after the first pass. Every subject gets its own documents, audits and reporting lines. And the management review consists of a presentation without decisions.

Browse all entriesBack to top

Frequently asked questions

See compliance run on your real assets

Rizzqo turns framework requirements into owned tasks on the assets you already have, and prices the risk in real money.

Made in GermanyEU-hostedMulti-framework