Integrated Management System (IMS)
One framework. Many certifications. Audit once, certify many.

Overview
MAST's flagship Integrated Management System unifies ISO 27001, ISO 9001, ISO 14001, ISO 45001, ISO 27701, ISO 22301, ISO 20000-1 and ISO 42001 into a single governance, risk and compliance backbone. One policy suite, one risk register, one internal audit cycle, one management review — and a single body of evidence that satisfies every certification scheme you hold. The result is one-to-many coverage: do the work once, certify against many standards, cut audit fatigue by 30–50%, and give the board a single source of truth.

Seasoned consulting leader with 35+ years of experience in IT audit, compliance and digital transformation. Held leadership roles at KPMG (Technical Director, IT Audit & Assurance — 9+ years) and Wipro Consulting before joining MAST.
Size your IMS in 30 seconds.
Pick the ISO standards you want integrated, your organisation size and your target certification timeline — we will recommend a tier, indicative duration and audit-day saving versus running each standard separately.
Build your IMS scope in 4 quick steps.
Takes ~60 seconds. We will recommend a tier, indicative duration and the audit-day saving versus running each standard separately.
Head office + branches + data centres + material operating sites.
Dual IMS — Essentials
- Standards
- 2
- Duration
- ~26 wks
- Sites
- 2
- Joint audit days
- 10
- Audit-day saving
- 38%
vs running 2 separate management systems (~16 audit days).
- Single site, focused integration of two standards.
- Joint Stage 1 + Stage 2 with a single accredited body.
- Best when you already hold one certificate and want to add a second cleanly.
- Audit basis: New — no certificates yet — Full Stage 1 + Stage 2 for every standard in scope.
Indicative only. A senior consultant validates scope, sites and timeline before issuing the fixed fee.
Process flow, compliance checklist and benefits.
A visual breakdown of how the engagement runs, what evidence we leave behind, and the business outcomes you can defend at the board.
How we deliver Integrated Management System (IMS).
- 01Standards Mapping
Map clauses and controls across ISO 27001, 9001, 14001, 45001, 27701, 22301, 20000-1 and 42001 into a single normalised matrix.
- 02Integrated Design
One policy suite, one risk methodology, one Statement of Applicability and one document control framework spanning every standard in scope.
- 03Unified Implementation
Shared controls, training, supplier assurance, incident and change processes deployed once across the organisation.
- 04Combined Internal Audit
One internal audit programme and one management review covering all standards in a single cycle.
- 05Joint Certification
Coordinated Stage 1 + Stage 2 with an accredited body that audits all schemes in one engagement.
- 06Continuous Improvement
Single corrective-action, KPI and surveillance-audit calendar — sustainable beyond first certification.
What auditors and regulators expect to see.
Hallmarks of a true Integrated Management System — what joint-audit certification bodies test for when issuing multiple certificates from a single engagement.
- Annex SL clause-mapping matrix
Every clause of every standard in scope mapped to a single normalised control set.
- Unified policy suite
One policy library covering ISO 27001, 9001, 14001, 45001, 27701, 22301, 20000-1 and 42001 — no duplicates.
- Single integrated risk register
One methodology serving information security, quality, environment, safety, continuity, privacy and AI risk.
- Multi-standard Statement of Applicability
Joint SoA showing inclusions, exclusions and justifications across every certified standard.
- One internal-audit programme
Combined audit plan covering all standards in a single annual cycle.
- Combined management review
Single Clause 9.3 review feeding all certificates, the board and the regulator.
- Joint Stage 1 / Stage 2 audit plan
Coordinated calendar with one accredited body auditing every scheme in one engagement.
- Integrated surveillance and CAPA log
One corrective-action, KPI and surveillance schedule sustaining all certificates.
What you walk away with.
Joint audits replace 4+ separate engagements per year.
Do the work once, certify against ISO 27001, 9001, 14001, 45001, 27701, 22301, 20000-1 and 42001.
Single policy suite, single auditor day-rate, single platform — material savings on consulting and certification.
ISO 42001, 22301 or 20000-1 plug in additively — no rebuild of the spine.
One management review pack replaces siloed scheme-by-scheme reports.
Process owners face one auditor across all schemes, not four.
Frequently asked questions.
What is the one-to-many advantage?+
Most organisations run ISO 27001, 9001, 14001 and 45001 as separate systems with duplicate policies, audits and reviews. An IMS does the work once and certifies against many standards, cutting cost, calendar time and internal effort by 30–50%.
Which standards can be integrated?+
Any combination of ISO 27001, 27701, 9001, 14001, 45001, 22301, 20000-1, 42001 and 13485. We align them through Annex SL (the common high-level structure) so clauses, terms and management-system requirements share one backbone.
Can we add standards later?+
Yes — the IMS is designed to be additive. New standards (for example ISO 42001 for AI or ISO 22301 for business continuity) plug into the same risk register, policy framework and audit cycle without rebuilding.
Does one certification body audit everything?+
Yes. We coordinate with accredited bodies that perform joint audits across all standards in scope, issuing multiple certificates from a single audit engagement.
We already hold ISO 27001 — can we still build an IMS?+
Yes — that is the most common starting point. We re-baseline the existing ISMS as the IMS spine and layer additional standards onto it without re-certifying 27001 from scratch.
How much does an IMS cost compared to separate systems?+
An integrated programme typically runs 30–50% lower than the equivalent set of standalone implementations, with surveillance and recertification savings of 25–40% per year thereafter.
Will an IMS make our scope harder to manage?+
The opposite. One scope statement, one risk register and one audit calendar replace four or more siloed systems — fewer artefacts to maintain, not more.
Can you support multi-entity groups?+
Yes. We deliver group-level IMS with entity-specific scopes — common in financial services, healthcare groups and energy holdcos.
Does an IMS work for highly regulated industries?+
Yes — financial services (CBUAE, SAMA), healthcare (ADHICS, HIPAA), oil & gas (IEC 62443) and government clients all benefit, as regulator obligations map cleanly into the integrated framework.
Week-by-week, how Integrated Management System runs.
A disciplined sequence that compresses 6–9 month programmes into a fixed-fee, board-defensible engagement.
- Week 1–2Step 1Scope & standards selection
Confirm which ISO standards are in scope (typically 27001, 9001, 14001, 45001, 27701, 22301, 20000-1, 42001), legal entities covered, sites, processes and exclusions. Steering committee chartered and IMS policy drafted.
- Week 3–5Step 2Annex SL mapping
Clause-by-clause mapping of all in-scope standards through the Annex SL common high-level structure — context, leadership, planning, support, operation, performance evaluation and improvement merged into one matrix.
- Week 6–9Step 3Unified design
Single IMS manual, one policy suite, one risk methodology, one Statement of Applicability, one document control standard, one supplier and competence framework — each clause cross-referenced to every standard it satisfies.
- Week 10–13Step 4Integrated implementation
Shared controls, training, change, incident and supplier processes rolled out once across the organisation. Evidence repository structured by Annex SL clause with reusable tags per standard.
- Week 14–15Step 5Combined internal audit
One internal audit plan executed by Lead Auditors qualified across all in-scope standards. One management review covering objectives, risks, performance and improvement opportunities for the entire IMS.
- Week 16–20Step 6Joint certification
Coordinated Stage 1 and Stage 2 with a single accredited certification body — multiple certificates issued from one audit engagement. Nonconformity response and surveillance-audit calendar handed over.
What we leave behind.
Audit-grade artefacts your team continues to operate after handover — not a one-shot consulting deck.
Single source of truth describing the integrated management system, standards covered, exclusions, sites and legal entities.
Every clause of every in-scope standard mapped to a single IMS process, eliminating duplicate policies and audits.
One information security, quality, environmental, OH&S, privacy, continuity, service-management and AI policy set — version controlled and approved.
Single risk taxonomy covering security, quality, environment, safety, privacy, continuity, service and AI risks with one treatment plan view.
Combined SoA for ISO 27001 / 27701 / 42001 with controls cross-tagged to ISO 9001, 14001, 45001, 22301 and 20000-1 obligations.
Three-year audit calendar with one set of checklists per process covering every standard it touches.
Single board-ready KPI dashboard, performance metrics and decision log spanning the full IMS.
Evidence repository, audit plan and CB liaison artefacts prepared for a single multi-standard Stage 1 / Stage 2 audit.
One engagement, mapped to every applicable obligation.
Evidence designed once, reused across regulators — reducing audit fatigue and total cost of compliance.
| Framework | Name | Why it matters |
|---|---|---|
| ISO/IEC 27001:2022 | Information Security Management | Core ISMS layer of the IMS — Annex A controls reused as the security spine for every other standard. |
| ISO 9001:2015 | Quality Management | Process discipline, customer focus and continual improvement requirements integrated with security and privacy controls. |
| ISO 14001:2015 | Environmental Management | Environmental aspects, legal register and lifecycle thinking merged into the unified risk and supplier framework. |
| ISO 45001:2018 | Occupational Health & Safety | Worker consultation, hazard identification and incident management folded into the shared incident and audit programme. |
| ISO/IEC 27701:2019 | Privacy Information Management | Extends the ISMS with controller / processor controls — single PIMS layer serving GDPR, UAE PDPL, KSA PDPL and India DPDP obligations. |
| ISO 22301:2019 | Business Continuity Management | BIA, RTO / RPO and continuity testing integrated with incident response and supplier resilience. |
| ISO/IEC 20000-1:2018 | IT Service Management | Service catalogue, change, problem and SLM processes reused as the operational layer of the IMS. |
| ISO/IEC 42001:2023 | AI Management System | AI governance, model risk and lifecycle controls slotted into the IMS for organisations deploying AI. |
Pick the model that fits your scope.
Fixed-fee where scope is clear, phased programmes where complexity demands governance — never time-and-materials drift.
Two standards (typically ISO 27001 + ISO 9001 or 27001 + 27701). 14–18 weeks, single site.
Four standards (e.g. 27001 + 9001 + 14001 + 45001). Multi-site, 18–24 weeks with executive steering.
Five or more standards across multiple legal entities — includes joint surveillance-audit calendar and a managed compliance handover.
What separates this engagement from the alternative.
Built around Annex SL from day one — not two separate systems stitched together. One policy, one risk register, one audit cycle delivering every certificate in scope.
Every engagement is led by consultants qualified as Lead Auditors across at least three ISO standards, so design decisions hold up under any certification body.
We arrange combined Stage 1 / Stage 2 audits with a single accredited body — slashing audit days, travel and disruption versus sequential single-standard audits.
We benchmark your current audit days and evidence requests at kick-off and target a 30–50% reduction within the first surveillance cycle.
New standards (ISO 42001 for AI, ISO 22301 for continuity, ISO 13485 for medical devices) plug into the same IMS backbone without rebuilding.
DIY vs Big Four vs MAST.
An honest, side-by-side comparison of what each delivery model typically gets you.
| Dimension | DIY / Internal | Big Four | MAST |
|---|---|---|---|
| Approach to multiple standards | Separate systems per standard | Parallel workstreams, partial overlap | Single IMS built on Annex SL from day one |
| Number of policy suites | One per standard — heavy duplication | Consolidated per workstream | One unified suite covering every standard in scope |
| Internal audit effort | Audit cycle per standard | Coordinated but separate audits | One audit programme covering all standards |
| Certification audit days | Sum of every standard | Discounted but sequential | Joint Stage 1 / Stage 2 — 30–50% fewer days |
| Time to add a new standard | New project, 6–9 months | New engagement, premium fee | Plug-in to existing IMS — 8–12 weeks |
| Board reporting | Multiple disconnected reports | Sector-specific decks | Single integrated KPI dashboard |
The questions experienced buyers actually ask.
What is the minimum useful IMS?+
We typically start at two standards — most often ISO 27001 paired with either ISO 9001 (quality) or ISO 27701 (privacy). From there, ISO 14001, 45001, 22301, 20000-1 and 42001 can be layered in over subsequent cycles without rebuilding the system.
Will one certification body audit every standard?+
Yes. We coordinate with ANAB / IAF-accredited bodies that hold scopes for every ISO standard in your IMS, so a single audit engagement issues multiple certificates. This is the core mechanic of the one-to-many advantage.
How much audit-day reduction is realistic?+
Versus running separate management systems, organisations typically see a 30–50% reduction in total audit days across the three-year certification cycle, plus a 40–60% reduction in internal evidence-collection effort.
Can we keep existing certificates from different bodies?+
Yes — many clients migrate progressively. We can either consolidate all certificates to a single body at the next surveillance window, or run a hybrid for one cycle while the IMS matures.
Does the IMS work for groups with multiple legal entities?+
Yes. The IMS scope statement formally lists every legal entity, site and process covered. We routinely deliver group-wide IMS programmes where one certificate is issued per entity from a single shared management system.
How does the IMS interact with regional regulators (CBUAE, SAMA, NCA, ADHICS)?+
The IMS provides the underlying control evidence. We map each regulator's requirements to the IMS control set, so the same evidence pack satisfies CBUAE Information Security Standard, SAMA CSF, NCA ECC and ADHICS V2 alongside the ISO certificates.
Methodology, deliverables, pricing bands and reference architecture on a single board-ready page.
Choose how you'd like to engage on Integrated Management System (IMS).
Explore every facet of Integrated Management System (IMS).
Methodology, deliverables, week-by-week timeline, pricing models, industry context, tooling and extended FAQs — each on its own page for fast reference and deep linking.
Ready to scope your Integrated Management System engagement?
Tell us a little about your business — a senior consultant will reach out within one business day.