Adding a second standard without starting again
Sooner or later a customer, a regulator or a parent company asks for a second certificate: business continuity next to information security, compliance next to quality. The instinct is to start again: another manual, another audit programme, another management review. The reason that instinct is wrong is structural, and it is worth understanding before the second project is scoped.
What makes something a management system
A management system is not a folder of documents. Four features decide it: an objective carried by top management, defined processes with named owners, evidence that those processes are actually lived, and a mechanism that detects deviations and triggers improvement. Take the fourth away and what remains is a document collection, recognisable as such in the first audit.
The shared structure
The ISO directives prescribe the same outline for all management system standards. It is commonly referred to as Annex SL or the High Level Structure, and newer editions speak of a harmonised structure. For a user this means that knowing one of these standards makes the others navigable.
| Clause | Content | Core question |
|---|---|---|
| 4 Context of the organisation | Environment, interested parties, scope | What is the system for, and who expects what |
| 5 Leadership | Commitment of top management, policy, roles and authorities | Who carries it |
| 6 Planning | Risks and opportunities, objectives, planning of changes | What is to be achieved, and what stands in the way |
| 7 Support | Resources, competence, awareness, communication, documented information | With what |
| 8 Operation | Planning, control and performance of the activities | How, day to day |
| 9 Performance evaluation | Monitoring and measurement, internal audit, management review | Is it working |
| 10 Improvement | Nonconformities, corrective actions, continual improvement | What is being changed |
Clauses 1 to 3 contain scope, normative references and terms, and are not the subject of implementation.
What differs between the standards
The mechanics stay the same; the subject differs. ISO/IEC 27001 adds a risk assessment and treatment referencing a set of controls, plus the Statement of Applicability. ISO 22301 adds business impact analysis, continuity strategies and exercises. ISO 37301 adds the identification of compliance obligations and compliance risks. ISO 9001 adds customer- and product-related requirements. Anyone already operating one of these standards has the greater part of the structure for the next one already standing.
That answers the second-certificate question. You are not building a second system. You are adding a subject to one you already have.
The control loop
The structure maps a cycle of plan, do, check and act: clause 6 plans, clause 8 performs, clause 9 checks, clause 10 acts. The cycle is why a management system can never be finished. It is also where systems fall asleep: internal audits get postponed, the management review is dropped, open actions run on without a date.
The integrated management system
| Can be shared | Subject-specific |
|---|---|
| Context and interested parties | Risk methodology per subject |
| Policy framework and document control | Substantive requirements |
| Role model and training process | Specialist competence requirements |
| Audit programme and pool of auditors | Depth of examination per standard |
| Management review | Inputs and metrics |
| Nonconformity and action procedure | Assessment criteria |
The benefit is one audit programme instead of three, one management review instead of several, and one action register covering all subjects. The precondition is a common scope, or at least a clean mapping of the differing scopes onto one another. In a group where certificates are held by different entities, that mapping is the actual work, not the documentation.
Relationship to statutory requirements
Rules such as the GDPR, DORA or the NIS2 Implementation Act do not require a certified management system. They do require its components: a risk assessment, appropriate measures, evidence, verification of effectiveness, and a recognisable leadership responsibility. An existing management system is therefore the cheapest carrier structure for new regulatory requirements, because it has already organised the production of evidence.
The failure modes
Systems fail in recognisable ways. The system gets built for the certificate rather than for operation. The control loop stops after the first pass. Every subject gets its own documents, audits and reporting lines. And the management review consists of a presentation without decisions.