20-20-20 Meeting #10

What is the difference between a combined management system and an integrated management system? As organizations are adopting more management system standards like ISO/IEC 20000-1 (services), ISO 9001 (quality), ISO/IEC 27001 (information security) or even ISO 140001 (environment), how are they managed? This is a great question that was answered most thoroughly by Gigi Robinson, BSI Group and long-time WG2 expert.

Gigi Robinson, BSI Group, presented wonderful foundational and advanced information around assessing integrated and combined management systems. Before reading further, understand this information applies to the policies and procedures at BSI Group and may differ in other certification bodies (CBs).

 

First, understand the difference between a combined system (multiple MSS which are not integrated) and an integrated system (there is a “single management system managing multiple aspects of the organizational performance to meet the requirements of more than one management standard, at a given level of integration” (IAF)). With a combined audit, a certificate will be presented for each MS while in an integrated system, one certificate is provided (and will list what MSs are included).

 

Second, there are pros and cons (benefits/disbenefits) to the client. With an integrated system, there is one system acting holistically which saves people time and some costs. The cons can be that of roles and responsibilities – is the organization mature enough so that all requirements are met equally and effectively? The combined management system is characterized by independent working of the various management systems (e.g., SMS, ISMS, QMS…) but there may be some integration if only due to the high level structure (HLS). The cons of a combined system are time and cost.

 

Auditors for either system are similar – auditor competence is the same and the planning for each are similar – each audit requires planning (consider size of the organization, number of systems, etc.). While each will look at the same generic audit components (organizational context, leadership, policy, internal audits, management review, improvements), the specific requirements will for each management system may take on different approaches (are the operational requirements reviewed separately or collectively?).

 

The presentation concluded with several example scenarios and lessons learned. Questions were answered around technical experts and their role in either scenario, types of reports, and the impact of change in the HLS with the addition of the climate control requirements.