SGRII Insights  ·  Management Systems  ·  2026

Foundation First: Why Integration Only Works When the Documents Work

The management system community has spent twenty years perfecting the architecture of integration. It has spent considerably less time asking whether the individual buildings were structurally sound before connecting them.

S

SGRII Performance & Digital Solutions

Management Systems Practice  ·  April 2026  ·  9 min read

I

SGRII Pillar Lens

Integration

Integration is the fourth SGRII pillar — but it is not the first step. Integration means connected workflows: audit, compliance, performance, and control systems working together, not in silos. That only works when each system can stand alone first. A connected workflow built on incomplete individual systems is not integration. It is shared fragility with a single point of failure that spans every certificate on the wall.

Every year, management system conferences dedicate keynote sessions to the Integrated Management System. Certification bodies publish guides on combining ISO 9001, ISO 14001, and ISO 45001 into a single framework. Consultants pitch IMS implementation as the logical next move for any organisation that has achieved its first certification.

And every year, Stage 2 auditors open the same management review records, scan the same risk registers, and find the same problem: a beautifully integrated system built on a foundation that was never finished.

The Annex SL Paradox

Annex SL — the high-level structure that aligned clause numbering across ISO management system standards — was one of the most significant contributions to the field in the last twenty years. It made integration look compelling: same clause numbers, same terms, compatible requirements. Combining standards should be a matter of architecture, not reinvention.

But Annex SL created an unintended consequence the field has been reluctant to name. By making integration look easy, it gave organisations permission to start integrating before the individual systems were complete.

The result is a specific category of IMS that passes Stage 2 audits on the strength of its architecture while concealing gaps in individual standard requirements. The document control procedure covers three standards simultaneously. The management review record addresses nine mandatory inputs in two paragraphs. The risk register applies to “all applicable standards” without being specific enough to satisfy any of them.

This is not integration. It is compression. And compression, in a management system context, means the standard-specific requirements — the ones that give each certification its meaning — get smoothed over in the pursuit of efficiency.

What a Document Architecture Problem Actually Looks Like

In ISO 27001 implementations, the document architecture problem takes three specific forms.

The risk register is the most common failure site. In a well-designed ISMS, the risk register is scoped to information security risks — threats to confidentiality, integrity, and availability of information assets. The methodology is documented, the asset register provides input, treatment plans link to Annex A controls, and residual risk acceptance is recorded with appropriate sign-off authority. In an integrated system where “efficiency” was prioritised over precision, the risk register becomes a hybrid: information security risks alongside operational risks, reputational risks, and environmental risks, served by a shared methodology designed for every standard simultaneously. It satisfies none of them precisely.

The Statement of Applicability is the second. The SoA is an ISMS-specific document — it has no equivalent in ISO 9001 or ISO 14001. When organisations create an “integrated” SoA-equivalent covering controls across multiple standards, they produce something that is not quite an SoA and not quite anything else: a controls matrix lacking the exclusion justification rigour that ISO 27001 requires, confusing auditors from both disciplines.

The management review is the third. ISO 27001 Clause 9.3 specifies mandatory inputs including information security performance, risk treatment plan status, and continual improvement opportunities. ISO 9001 Clause 9.3 requires customer satisfaction data, objectives performance, and process conformity trends. These are materially different agendas. An integrated review attempting both in ninety minutes produces records that satisfy neither standard’s evidence requirements under audit scrutiny.

The Uncomfortable Question Nobody Asks

If integration was applied to systems that were individually incomplete, what exactly has been integrated?

An underdeveloped ISMS combined with an underdeveloped QMS does not produce an integrated management system. It produces a combined system with two sets of documentation gaps and one set of shared procedures designed to cover both — and therefore covering neither completely. The certificate says ISMS. The certificate says QMS. The architecture says IMS. The audit evidence says it is a documentation exercise that achieved certification without achieving the management system maturity the certification was designed to represent.

This is a systemic problem the certification industry is structurally reluctant to address — because addressing it would mean acknowledging that a significant proportion of existing multi-standard certificates are built on systems that would not withstand a rigorous clause-by-clause assessment of each standard in isolation.

What Foundation-First Actually Means

Foundation-first does not mean refusing to integrate. It means refusing to integrate before the individual systems are structurally complete.

In practice, this requires a specific discipline: shared procedures should only be shared where the underlying requirements are genuinely equivalent — not merely similar. Document control, internal audit programme management, and NC & CA process can be shared across standards without meaningful loss of rigour, because the requirements are structurally identical. Risk management, management review, and performance evaluation cannot — because the requirements are standard-specific in ways that shared documents cannot accommodate without compromising both.

The ISMS risk register must be an ISMS risk register. The QMS risk register must reflect quality-specific risks. They can sit in the same file. They cannot be the same register. The management review for ISO 27001 must address the ISO 27001 mandatory inputs. The management review for ISO 9001 must address the ISO 9001 mandatory inputs. They can happen in the same meeting with separate agenda sections. They cannot happen in the same ninety-minute session with a single set of minutes.

This is not inefficiency. This is the minimum evidence quality that each certification is meant to represent.

The SGRII Position

The SGRII thesis on integration is direct: you cannot connect what is not yet complete. Integration is the fourth pillar in the SGRII framework — deliberately positioned after Systems, Governance, and Risk — because connected workflows only deliver value when each workflow can function independently first. An integrated management system built on incomplete individual systems is not a connected workflow. It is shared fragility.

Every SGRII framework is built on a single principle: each standard must be implementable as a complete, standalone system before integration is considered. The ISO 27001:2022 ISMS Framework is designed to satisfy a Stage 2 audit conducted on that standard alone — independently of any other certification. The document structures use compatible formats across standards (same risk register architecture, same NC & CA register design, same management review input structure) specifically to enable integration. But they are built and validated as standalone systems first. The integration layer is an additional capability, not a shortcut through individual system development.

A certificate is not evidence that a management system works. It is evidence that the system satisfied the requirements of an audit conducted on a specific day by a specific auditor. Whether the system actually governs the organisation’s operations — whether it produces the outcomes it was designed to produce — is a different question. And one that only foundation-quality documentation can answer.

THE SGRII ISO 27001:2022 ISMS FRAMEWORK

The SGRII ISO 27001:2022 ISMS Framework is built as a standalone, audit-defensible system first — with document architecture designed to survive a clause-by-clause Stage 2 assessment before integration is considered.

6 core modules covering all 93 Annex A controls, compatible structures across standards, and a document architecture engineered for integration without compression of individual standard requirements.

GET THE ISMS FRAMEWORK — FROM $149 ›

The Question Worth Asking

Integration as a goal is not wrong. A coherent management system that governs quality, environmental performance, information security, and occupational safety through compatible processes and shared governance is a legitimate organisational objective — and one that Annex SL makes genuinely achievable.

But integration as a starting point — or as a justification for not finishing individual system development — is a structural risk that most organisations accept without examining directly.

The next time an organisation describes its “IMS,” the question worth asking is not how many standards it covers. The question is: if each standard were audited in isolation — if the auditor could only see the documents and evidence relevant to that single certification — would every system pass on its own merits?

The answer is less often yes than the certificate would suggest.

SGRII ISO 27001:2022 ISMS FRAMEWORK

Two tiers. One framework. Choose the depth your organisation needs.

Professional

$149

Modules 01–06  ·  Self-implementing SME

✓

Foundation Guide + ISMS System Manual (9 sections, full scope)

✓

10 core procedures: asset classification through management review

✓

15 templates incl. standalone Risk Register & SoA (not a hybrid)

✓

9-phase implementation roadmap designed for standalone completion first

✓

Audit Pack with evidence checklist for Stage 2 readiness

GET PROFESSIONAL ›
MOST COMPLETE

Premium

$349

11 deliverables  ·  Compliance Manager & Consultant

✓

Everything in Professional (Modules 01–06)

✓

E1: DI Register + Annex A Map — integration-ready, 93/93 controls mapped with cross-standard reference fields

✓

E2: Risk & Opportunity Register — standalone IS risk methodology, structurally compatible for IMS integration

✓

E3: ISMS Compliance Checklist — clause-by-clause verification before integration is considered

✓

O7: Annex A Implementation Guide — 93 controls fully evidenced, ready for multi-standard alignment

GET PREMIUM ›

Both tiers include immediate download  ·  Lifetime access  ·  Designed for Stage 2 audit readiness

Join the Conversation

If your organisation holds multiple ISO certifications: could each system pass a standalone audit today — or is the certificate covering gaps that integration has obscured? Leave your answer below.

We read every comment. Practitioners sharing real audit experience get a response from the SGRII team directly.

Build it, don’t just read about it

SGRII ISO/IEC 27001:2022 ISMS Framework

All 93 Annex A controls, Statement of Applicability, risk register and audit pack — built for certification readiness.

View the Framework → Get the newsletter

Coverage is not compliance. SGRII frameworks provide structured coverage, templates and guidance. They are designed for audit defensibility and structured for certification readiness; they do not certify you, do not guarantee a successful audit, and are not legal advice. The official ISO standard remains the only authoritative source of requirements.

Leave a Reply

Discover more from SGRII Performance & Digital Solutions

Subscribe now to keep reading and get access to the full archive.

Continue reading