Most organisations that hold more than one ISO certificate run them as separate systems. Quality has its manual, its procedures and its internal audits. Environment has another set. Health and safety has a third, and information security a fourth. Each has its own document register, its own corrective action log and its own management review. The same people sit in four meetings to discuss overlapping risks, and the same auditors ask for the same evidence in four different formats. PAS 99 exists to end that duplication.
What Is PAS 99?
PAS 99 is a Publicly Available Specification published by BSI, the UK national standards body. Its full title is "Specification of common management system requirements as a framework for integration", and the current edition at the time of writing is PAS 99:2012. It sets out the requirements that management system standards have in common, so an organisation can meet them once, in one integrated management system, rather than separately for every standard it certifies to.
PAS 99 does not replace ISO 9001, ISO 14001, ISO 45001 or ISO/IEC 27001. Each standard still has requirements that are unique to its discipline, such as operational controls for environmental aspects or the Annex A controls in ISO/IEC 27001. PAS 99 provides the common skeleton, and the specific requirements of each standard hang from it.
Certification bodies can assess an integrated management system against PAS 99, usually alongside the certificates for the underlying ISO standards. For many organisations, though, the real value is not another certificate. It is running one system instead of four.
Why PAS 99 Still Matters in 2026
PAS 99 was written to align with the common structure that ISO introduced for all its management system standards, known originally as Annex SL and now as the Harmonized Structure. Every recent ISO management system standard follows it, including ISO 9001, ISO 14001, ISO 45001, ISO/IEC 27001 and the newer ISO/IEC 42001 for AI management systems. That shared structure is what makes integration practical.
Three developments make integration more relevant now than when PAS 99 was first published:
- More standards per organisation: many organisations now hold three or four certificates, and some are adding ISO/IEC 42001 as they govern AI
- Common changes across standards: in 2024 ISO added a climate change amendment to its management system standards, asking organisations to consider whether climate change is a relevant issue when they determine their context. One integrated context and risk process handles that once
- Revisions in progress: ISO 9001 and ISO 14001 are both being revised, and an integrated system absorbs revisions to shared clauses in one place rather than several
The Harmonized Structure in Brief
Every ISO management system standard that follows the Harmonized Structure uses the same ten clauses. Clauses 1 to 3 cover scope, references and definitions. Clauses 4 to 10 contain the requirements, and they are the same headings in every standard:
- Clause 4, context of the organisation: internal and external issues, interested parties and the scope of the system
- Clause 5, leadership: commitment, policy, roles and responsibilities
- Clause 6, planning: risks and opportunities, objectives and planning of changes
- Clause 7, support: resources, competence, awareness, communication and documented information
- Clause 8, operation: the discipline-specific controls
- Clause 9, performance evaluation: monitoring, internal audit and management review
- Clause 10, improvement: nonconformity, corrective action and continual improvement
Most of these clauses can be met once for the whole organisation. Clause 8 is where the standards differ most, and even there processes such as change management and supplier control can often be shared.
Which Standards Can Be Integrated?
PAS 99 can integrate any management system standards that share the common structure. The most common combinations are:
- ISO 9001 for quality management
- ISO 14001 for environmental management
- ISO 45001 for occupational health and safety
- ISO/IEC 27001 for information security
- ISO 22000 for food safety
- ISO 22301 for business continuity and ISO 50001 for energy management
- ISO/IEC 42001 for AI management systems
What an Integrated Management System Looks Like in Practice
An integrated management system is not a single thick manual. It is a set of shared processes that every discipline uses. In practice that means:
- One context and risk process, with a single register of risks and opportunities that covers quality, environmental, safety and information security issues
- One document control process, so every policy, procedure and record follows the same approval, version and review rules
- One legal and other requirements register, covering obligations such as the Occupational Health and Safety Act and the National Environmental Management Act in South Africa
- One internal audit programme, with audits planned by risk across all standards rather than by standard
- One nonconformity and corrective action process, so an incident, an audit finding and a customer complaint are all investigated and closed the same way
- One management review, where leadership sees the performance of the whole system at once
- One competence and training record for every role
The Benefits of Integration
The first benefit is less duplication. Shared processes mean fewer documents to maintain, fewer registers to reconcile and fewer meetings to hold.
The second is better decisions. When quality, safety, environmental and security risks sit in one register, leadership can see which risks really matter most, rather than comparing four separate lists that use four scoring methods.
The third is more efficient audits. International Accreditation Forum guidance, IAF MD 11, allows certification bodies to audit an integrated management system in a combined audit and, where the integration is genuine, to reduce total audit time. The saving depends on how integrated the system really is, so a combined audit of four separate systems in one folder gains little.
The fourth is resilience. A single corrective action process means lessons from a safety incident can improve a quality procedure, and a single change process means an operational change is assessed for all its risks at once.
How to Implement PAS 99
Integration works best as a structured project rather than a document merge:
- Start with a gap assessment of each existing system against its own standard and against PAS 99, so you know what is shared and what is unique
- Map the common requirements clause by clause, and decide which existing process becomes the single process for each
- Build one risk and opportunity register and one legal register, then retire the separate versions
- Merge document control, internal audit, corrective action and management review into single processes
- Keep discipline-specific operational controls where they belong, but link them to the shared processes
- Train people on the integrated processes, not on the standards
- Agree a certification strategy with your certification body, including whether you want combined audits
In South Africa, check that your certification body is accredited by SANAS, or by another member of the International Accreditation Forum, for each standard in your scope.
Common Pitfalls
The most common failure is integration on paper only. The manual is merged, but each discipline still keeps its own spreadsheet of actions, its own audit schedule and its own risk scoring. Auditors see through it quickly, and the organisation keeps all the duplication it hoped to remove.
The second is losing discipline-specific rigour. Integration should share processes, not dilute requirements. An environmental aspects register and an information security risk assessment still need their specific methods, even when they feed one risk picture.
The third is tooling. Integrated processes are hard to run across disconnected spreadsheets and shared drives, because nothing links an audit finding to the risk it affects or the action that closes it.
How MSX® Supports PAS 99
MSX® is the integrated management system within the XGRC® platform. It merges governance, risk, compliance and operational systems into one framework, so ISO 9001, ISO 14001, ISO 45001, ISO/IEC 27001 and other standards run on shared processes and one set of records. Document control, internal audits, nonconformities, corrective actions and management review are handled once, and each record can be linked to every standard it supports.
Because MSX® shares one data foundation with SHEQX®, ENVIRX® and MSXCyber®, safety incidents, environmental monitoring and information security controls feed the same integrated picture. For a practical view of how that works, see the PAS 99 integrated management system use case, or start with the ISO compliance overview for readiness guides to each standard.