IAF MD 11 – Audits of integrated management systems to ISO/IEC 17021-1

If organisations have implemented at least two management system standards that are to be audited and, where applicable, certified (e.g. ISO 9001 and ISO/IEC 27001), specific requirements arise for conformity assessment bodies (such as us) in preparing and conducting the audit. These are set out in IAF MD 11:2023.

Integrated management system

According to IAF MD 11:2023, an integrated management system is defined as follows:

"A single management system that manages multiple aspects of organisational operations in order to meet the requirements of more than one management standard with a given degree of integration. A management system can range from a combined system, to which separate management systems for each set of audit criteria/standards are added, to an integrated management system (IMS) that shares a single set of documentation, management system elements and responsibilities."

Degree of integration

The key term in this definition is the "degree of integration". This represents the extent to which at least two management system standards are integrated into a single central management system. Integration relates to that central management system and to whether – and to what extent – it is able to integrate the documentation, appropriate management system elements and responsibilities in respect of two or more sets of audit criteria/standards.

Assessing the degree of integration

According to IAF MD 11:2023, the degree of integration is measured by, among others, the following aspects, which must be assessed and evaluated by the client concerned:

  1. An integrated set of documentation, including work instructions, where applicable at an appropriate stage of development,
  2. Management reviews that take into account the organisation's overall business strategy and business plan,
  3. An integrated approach to internal audits,
  4. An integrated approach to the organisation's policy and objectives,
  5. An integrated approach to system processes,
  6. An integrated approach to improvement mechanisms (corrective and preventive actions; measurement and continual improvement), and
  7. Integrated management support and responsibilities.

Why is the degree of integration so important?

The level of integration is directly linked to the audit time. To determine the audit time for an audit of an IMS covering two or more management system standards/specifications, the required audit time must be calculated separately for each management system standard. The sum of the respective audit times represents the time required for the IMS audit. This effort can then be reduced further depending on the degree of integration. However, if the IMS does not display a sufficient level of integration, the audit time may also increase. Alongside the complexity of auditing an IMS compared with individual management system audits, it is of central importance that the audit programme and audit plans cover all areas and activities relating to each management system standard affected by the scope of the audit.

Example

Let us take a hypothetical worked example. You are planning to certify your quality management system (hereinafter "QMS") to ISO 9001 and your information security management system (hereinafter "ISMS") to ISO/IEC 27001. The audit time required for the QMS is 5 days and for the ISMS 8 days. The total effort is therefore 13 days.

Now let us assume that the QMS and ISMS display a very high degree of integration and have already been through several cycles. This can lead to a reduction in audit time of up to 20%. Let us assume 15% – the audit effort would be reduced from 13 to 11 days.

This entry does not claim to cover all individual requirements of IAF MD 11:2023 in full. Rather, it is intended as a summary of the key requirements – particularly from a client perspective.

Go back