QUICK ANSWER
Most Australian businesses that need both quality and safety certification are better served by one Integrated Management System (IMS) than two separate ones — ISO 9001 and ISO 45001 share the same Annex SL structure, so combining them cuts duplicate paperwork, audits, and management review time. Separate certification still makes sense in a handful of specific cases, covered below.
The short answer
If your business needs both ISO 9001 (quality) and ISO 45001 (safety), build them as one Integrated Management System rather than two standalone systems. They share the same high-level structure, so an integrated build avoids duplicating policies, internal audits, document control, and management review — the parts of certification that cost the most time to maintain year after year.
The exception is when your certification needs are genuinely separate: a services business with real safety exposure only in one small part of its operations, or an organisation where a tender specifically requires standalone ISO 9001 certification and safety isn’t in scope at all. Those cases are the minority, but they’re real, and worth ruling in or out before committing to a build.
ISO 9001 in one line
ISO 9001 certifies your Quality Management System — the processes, accountability, and checks that make consistent output repeatable, whether you’re delivering a product or a service.
ISO 45001 in one line
ISO 45001 certifies your Work Health & Safety Management System — the processes that identify hazards, control risk, and actively prevent injury and ill health, sitting alongside (not replacing) your legal WHS obligations.
“ISO 9001 and ISO 45001 share the same backbone — that’s exactly why building them together, rather than twice, is usually the smarter call.”
Why they integrate so cleanly
Both standards are built on the Annex SL framework, the common high-level structure ISO uses across its modern management-system standards. That means both share the same core clauses: leadership commitment, risk-based thinking, documented processes, internal audit, corrective action, and management review. In practice, this overlap is substantial — a single internal audit programme, a single management review meeting, and a single document control system can usually cover both standards at once, with standard-specific content sitting underneath that shared structure.
For a business already juggling day-to-day operations, that shared structure is the practical argument for integration: less duplicated administrative load, fewer audit days billed by your certification body, and one coherent system for your team to actually use, instead of two that quietly drift apart over time.
When separate certification makes more sense
Integration isn’t automatically the right call for every business. Standalone certification tends to make more sense when: a tender or client requirement specifies one standard only, and there’s no near-term driver to pursue the other; your safety risk profile is genuinely minimal (a small office-based consultancy, for instance) and building a full ISO 45001 system would add cost without adding real risk control; or your organisation is validating ISO certification for the first time with a single standard before committing to a broader system.
None of these rule out integrating later — a well-built standalone ISO 9001 system, using the Annex SL structure from the outset, integrates far more easily with ISO 45001 down the track than one built without that structure in mind.
When an Integrated Management System makes more sense
An IMS is generally the stronger choice when:
- Both standards are commercially required — tenders, panels, or enterprise clients ask for ISO 9001 and ISO 45001 together, which is increasingly common in construction, manufacturing, and logistics.
- Your operations carry real safety exposure — site-based, physical, or field work where hazard management is a genuine day-to-day concern, not a formality.
- Leadership time is limited — one integrated management review cycle is a materially smaller time commitment for your leadership team than running two in parallel.
- You want a single audit programme — combined surveillance audits reduce total audit days and the disruption that comes with each certification body visit.
1 audit, 2 standards
A well-built IMS runs one combined surveillance audit cycle instead of two separate ones
Where ISO 31000 (Risk Management) fits in
ISO 31000 isn’t a certifiable standard — it’s a risk management framework and set of principles, not something an auditor certifies you against. But it’s worth understanding alongside ISO 9001 and ISO 45001, because both of those standards lean heavily on risk-based thinking as a core requirement. A business that adopts ISO 31000’s framework as the common risk-management language underneath its IMS tends to end up with a more coherent system overall — one set of risk criteria and one risk register logic, instead of quality risk and safety risk being assessed in isolation from each other.
How PSMG scopes this decision with you
This isn’t a decision PSMG makes for you in the abstract — it’s scoped against your actual tender requirements, safety exposure, and team capacity in an initial gap analysis. That conversation looks at what’s actually driving the certification need, what your realistic internal resourcing looks like, and whether an integrated build or a staged, standalone-first approach fits your business better. From there, PSMG builds and supports the system end-to-end through to certification audit, working only with JAS-ANZ accredited certification partners.
View Integrated Management Pricing →
info@pspmg.com.au | 1300 810 127 | psmg.com.au