Governance. Risk. Compliance. Cybersecurity.
Compliance & Certification

Integrated Management System (IMS)

One framework. Many certifications. Audit once, certify many.

Integrated Management System (IMS) — ISO certification stamp on an audit document, MAST Consulting Group

Overview

MAST's flagship Integrated Management System unifies ISO 27001, ISO 9001, ISO 14001, ISO 45001, ISO 27701, ISO 22301, ISO 20000-1 and ISO 42001 into a single governance, risk and compliance backbone. One policy suite, one risk register, one internal audit cycle, one management review — and a single body of evidence that satisfies every certification scheme you hold. The result is one-to-many coverage: do the work once, certify against many standards, cut audit fatigue by 30–50%, and give the board a single source of truth.

Anil Sahore
Lead partner for this service
Anil SahoreHead of Advisory — Regulatory and Compliance

Seasoned consulting leader with 35+ years of experience in IT audit, compliance and digital transformation. Held leadership roles at KPMG (Technical Director, IT Audit & Assurance — 9+ years) and Wipro Consulting before joining MAST.

Estimator

Size your IMS in 30 seconds.

Pick the ISO standards you want integrated, your organisation size and your target certification timeline — we will recommend a tier, indicative duration and audit-day saving versus running each standard separately.

Interactive estimator

Build your IMS scope in 4 quick steps.

Takes ~60 seconds. We will recommend a tier, indicative duration and the audit-day saving versus running each standard separately.

Step progress4 of 4 complete
ISO standards in scope2 selected

Pick every standard you want integrated. Start with the “Core” pair — most clients add more later.

Head office + branches + data centres + material operating sites.

Recommended tier
Live preview

Dual IMS — Essentials

Fixed-fee
Standards
2
Duration
~26 wks
Sites
2
Joint audit days
10
Audit-day saving
38%

vs running 2 separate management systems (~16 audit days).

  • Single site, focused integration of two standards.
  • Joint Stage 1 + Stage 2 with a single accredited body.
  • Best when you already hold one certificate and want to add a second cleanly.
  • Audit basis: New — no certificates yetFull Stage 1 + Stage 2 for every standard in scope.
Get a fixed-fee proposal

Indicative only. A senior consultant validates scope, sites and timeline before issuing the fixed fee.

At a glance

Process flow, compliance checklist and benefits.

A visual breakdown of how the engagement runs, what evidence we leave behind, and the business outcomes you can defend at the board.

Process flow

How we deliver Integrated Management System (IMS).

  1. 01
    Standards Mapping

    Map clauses and controls across ISO 27001, 9001, 14001, 45001, 27701, 22301, 20000-1 and 42001 into a single normalised matrix.

  2. 02
    Integrated Design

    One policy suite, one risk methodology, one Statement of Applicability and one document control framework spanning every standard in scope.

  3. 03
    Unified Implementation

    Shared controls, training, supplier assurance, incident and change processes deployed once across the organisation.

  4. 04
    Combined Internal Audit

    One internal audit programme and one management review covering all standards in a single cycle.

  5. 05
    Joint Certification

    Coordinated Stage 1 + Stage 2 with an accredited body that audits all schemes in one engagement.

  6. 06
    Continuous Improvement

    Single corrective-action, KPI and surveillance-audit calendar — sustainable beyond first certification.

Compliance checklist

What auditors and regulators expect to see.

Hallmarks of a true Integrated Management System — what joint-audit certification bodies test for when issuing multiple certificates from a single engagement.

  • Annex SL clause-mapping matrix

    Every clause of every standard in scope mapped to a single normalised control set.

  • Unified policy suite

    One policy library covering ISO 27001, 9001, 14001, 45001, 27701, 22301, 20000-1 and 42001 — no duplicates.

  • Single integrated risk register

    One methodology serving information security, quality, environment, safety, continuity, privacy and AI risk.

  • Multi-standard Statement of Applicability

    Joint SoA showing inclusions, exclusions and justifications across every certified standard.

  • One internal-audit programme

    Combined audit plan covering all standards in a single annual cycle.

  • Combined management review

    Single Clause 9.3 review feeding all certificates, the board and the regulator.

  • Joint Stage 1 / Stage 2 audit plan

    Coordinated calendar with one accredited body auditing every scheme in one engagement.

  • Integrated surveillance and CAPA log

    One corrective-action, KPI and surveillance schedule sustaining all certificates.

Benefits

What you walk away with.

30 to 50 percent audit-day reduction

Joint audits replace 4+ separate engagements per year.

One body of evidence, many certificates

Do the work once, certify against ISO 27001, 9001, 14001, 45001, 27701, 22301, 20000-1 and 42001.

Lower programme cost

Single policy suite, single auditor day-rate, single platform — material savings on consulting and certification.

Faster to add new standards

ISO 42001, 22301 or 20000-1 plug in additively — no rebuild of the spine.

Unified board and regulator reporting

One management review pack replaces siloed scheme-by-scheme reports.

Lower audit fatigue across the business

Process owners face one auditor across all schemes, not four.

FAQ

Frequently asked questions.

What is the one-to-many advantage?+

Most organisations run ISO 27001, 9001, 14001 and 45001 as separate systems with duplicate policies, audits and reviews. An IMS does the work once and certifies against many standards, cutting cost, calendar time and internal effort by 30–50%.

Which standards can be integrated?+

Any combination of ISO 27001, 27701, 9001, 14001, 45001, 22301, 20000-1, 42001 and 13485. We align them through Annex SL (the common high-level structure) so clauses, terms and management-system requirements share one backbone.

Can we add standards later?+

Yes — the IMS is designed to be additive. New standards (for example ISO 42001 for AI or ISO 22301 for business continuity) plug into the same risk register, policy framework and audit cycle without rebuilding.

Does one certification body audit everything?+

Yes. We coordinate with accredited bodies that perform joint audits across all standards in scope, issuing multiple certificates from a single audit engagement.

We already hold ISO 27001 — can we still build an IMS?+

Yes — that is the most common starting point. We re-baseline the existing ISMS as the IMS spine and layer additional standards onto it without re-certifying 27001 from scratch.

How much does an IMS cost compared to separate systems?+

An integrated programme typically runs 30–50% lower than the equivalent set of standalone implementations, with surveillance and recertification savings of 25–40% per year thereafter.

Will an IMS make our scope harder to manage?+

The opposite. One scope statement, one risk register and one audit calendar replace four or more siloed systems — fewer artefacts to maintain, not more.

Can you support multi-entity groups?+

Yes. We deliver group-level IMS with entity-specific scopes — common in financial services, healthcare groups and energy holdcos.

Does an IMS work for highly regulated industries?+

Yes — financial services (CBUAE, SAMA), healthcare (ADHICS, HIPAA), oil & gas (IEC 62443) and government clients all benefit, as regulator obligations map cleanly into the integrated framework.

Methodology

Week-by-week, how Integrated Management System runs.

A disciplined sequence that compresses 6–9 month programmes into a fixed-fee, board-defensible engagement.

  1. Week 1–2
    Step 1
    Scope & standards selection

    Confirm which ISO standards are in scope (typically 27001, 9001, 14001, 45001, 27701, 22301, 20000-1, 42001), legal entities covered, sites, processes and exclusions. Steering committee chartered and IMS policy drafted.

  2. Week 3–5
    Step 2
    Annex SL mapping

    Clause-by-clause mapping of all in-scope standards through the Annex SL common high-level structure — context, leadership, planning, support, operation, performance evaluation and improvement merged into one matrix.

  3. Week 6–9
    Step 3
    Unified design

    Single IMS manual, one policy suite, one risk methodology, one Statement of Applicability, one document control standard, one supplier and competence framework — each clause cross-referenced to every standard it satisfies.

  4. Week 10–13
    Step 4
    Integrated implementation

    Shared controls, training, change, incident and supplier processes rolled out once across the organisation. Evidence repository structured by Annex SL clause with reusable tags per standard.

  5. Week 14–15
    Step 5
    Combined internal audit

    One internal audit plan executed by Lead Auditors qualified across all in-scope standards. One management review covering objectives, risks, performance and improvement opportunities for the entire IMS.

  6. Week 16–20
    Step 6
    Joint certification

    Coordinated Stage 1 and Stage 2 with a single accredited certification body — multiple certificates issued from one audit engagement. Nonconformity response and surveillance-audit calendar handed over.

Deliverables

What we leave behind.

Audit-grade artefacts your team continues to operate after handover — not a one-shot consulting deck.

IMS manual & scope statement

Single source of truth describing the integrated management system, standards covered, exclusions, sites and legal entities.

Annex SL clause-mapping matrix

Every clause of every in-scope standard mapped to a single IMS process, eliminating duplicate policies and audits.

Unified policy & procedure suite

One information security, quality, environmental, OH&S, privacy, continuity, service-management and AI policy set — version controlled and approved.

Integrated risk register

Single risk taxonomy covering security, quality, environment, safety, privacy, continuity, service and AI risks with one treatment plan view.

Statement of Applicability (multi-standard)

Combined SoA for ISO 27001 / 27701 / 42001 with controls cross-tagged to ISO 9001, 14001, 45001, 22301 and 20000-1 obligations.

Combined internal audit programme

Three-year audit calendar with one set of checklists per process covering every standard it touches.

Integrated management review pack

Single board-ready KPI dashboard, performance metrics and decision log spanning the full IMS.

Joint certification readiness pack

Evidence repository, audit plan and CB liaison artefacts prepared for a single multi-standard Stage 1 / Stage 2 audit.

Regulators & frameworks

One engagement, mapped to every applicable obligation.

Evidence designed once, reused across regulators — reducing audit fatigue and total cost of compliance.

FrameworkNameWhy it matters
ISO/IEC 27001:2022Information Security ManagementCore ISMS layer of the IMS — Annex A controls reused as the security spine for every other standard.
ISO 9001:2015Quality ManagementProcess discipline, customer focus and continual improvement requirements integrated with security and privacy controls.
ISO 14001:2015Environmental ManagementEnvironmental aspects, legal register and lifecycle thinking merged into the unified risk and supplier framework.
ISO 45001:2018Occupational Health & SafetyWorker consultation, hazard identification and incident management folded into the shared incident and audit programme.
ISO/IEC 27701:2019Privacy Information ManagementExtends the ISMS with controller / processor controls — single PIMS layer serving GDPR, UAE PDPL, KSA PDPL and India DPDP obligations.
ISO 22301:2019Business Continuity ManagementBIA, RTO / RPO and continuity testing integrated with incident response and supplier resilience.
ISO/IEC 20000-1:2018IT Service ManagementService catalogue, change, problem and SLM processes reused as the operational layer of the IMS.
ISO/IEC 42001:2023AI Management SystemAI governance, model risk and lifecycle controls slotted into the IMS for organisations deploying AI.
Engagement tiers

Pick the model that fits your scope.

Fixed-fee where scope is clear, phased programmes where complexity demands governance — never time-and-materials drift.

Fixed fee
Dual IMS

Two standards (typically ISO 27001 + ISO 9001 or 27001 + 27701). 14–18 weeks, single site.

Phased programme
Quad IMS

Four standards (e.g. 27001 + 9001 + 14001 + 45001). Multi-site, 18–24 weeks with executive steering.

Programme + rollout
Enterprise IMS

Five or more standards across multiple legal entities — includes joint surveillance-audit calendar and a managed compliance handover.

Why MAST

What separates this engagement from the alternative.

True one-to-many design

Built around Annex SL from day one — not two separate systems stitched together. One policy, one risk register, one audit cycle delivering every certificate in scope.

Multi-standard Lead Auditors

Every engagement is led by consultants qualified as Lead Auditors across at least three ISO standards, so design decisions hold up under any certification body.

Joint-audit coordination

We arrange combined Stage 1 / Stage 2 audits with a single accredited body — slashing audit days, travel and disruption versus sequential single-standard audits.

Audit-fatigue reduction guarantee

We benchmark your current audit days and evidence requests at kick-off and target a 30–50% reduction within the first surveillance cycle.

Additive by design

New standards (ISO 42001 for AI, ISO 22301 for continuity, ISO 13485 for medical devices) plug into the same IMS backbone without rebuilding.

Compare

DIY vs Big Four vs MAST.

An honest, side-by-side comparison of what each delivery model typically gets you.

DimensionDIY / InternalBig FourMAST
Approach to multiple standardsSeparate systems per standardParallel workstreams, partial overlapSingle IMS built on Annex SL from day one
Number of policy suitesOne per standard — heavy duplicationConsolidated per workstreamOne unified suite covering every standard in scope
Internal audit effortAudit cycle per standardCoordinated but separate auditsOne audit programme covering all standards
Certification audit daysSum of every standardDiscounted but sequentialJoint Stage 1 / Stage 2 — 30–50% fewer days
Time to add a new standardNew project, 6–9 monthsNew engagement, premium feePlug-in to existing IMS — 8–12 weeks
Board reportingMultiple disconnected reportsSector-specific decksSingle integrated KPI dashboard
Extended FAQs

The questions experienced buyers actually ask.

What is the minimum useful IMS?+

We typically start at two standards — most often ISO 27001 paired with either ISO 9001 (quality) or ISO 27701 (privacy). From there, ISO 14001, 45001, 22301, 20000-1 and 42001 can be layered in over subsequent cycles without rebuilding the system.

Will one certification body audit every standard?+

Yes. We coordinate with ANAB / IAF-accredited bodies that hold scopes for every ISO standard in your IMS, so a single audit engagement issues multiple certificates. This is the core mechanic of the one-to-many advantage.

How much audit-day reduction is realistic?+

Versus running separate management systems, organisations typically see a 30–50% reduction in total audit days across the three-year certification cycle, plus a 40–60% reduction in internal evidence-collection effort.

Can we keep existing certificates from different bodies?+

Yes — many clients migrate progressively. We can either consolidate all certificates to a single body at the next surveillance window, or run a hybrid for one cycle while the IMS matures.

Does the IMS work for groups with multiple legal entities?+

Yes. The IMS scope statement formally lists every legal entity, site and process covered. We routinely deliver group-wide IMS programmes where one certificate is issued per entity from a single shared management system.

How does the IMS interact with regional regulators (CBUAE, SAMA, NCA, ADHICS)?+

The IMS provides the underlying control evidence. We map each regulator's requirements to the IMS control set, so the same evidence pack satisfies CBUAE Information Security Standard, SAMA CSF, NCA ECC and ADHICS V2 alongside the ISO certificates.

Take it with you
Download the Integrated Management System (IMS) 1-pager.

Methodology, deliverables, pricing bands and reference architecture on a single board-ready page.

Request the PDF
Get started

Ready to scope your Integrated Management System engagement?

Tell us a little about your business — a senior consultant will reach out within one business day.

By submitting you agree to be contacted by a MAST consultant. We never share your details.