Can ISO 9001 and ISO 27001 be audited together?

They can be audited together where the management systems, proposed scopes and audit arrangements support it. An integrated audit assesses more than one standard during the same audit, while still covering the applicable requirements of each.

ISO 9001 addresses quality management. ISO 27001 addresses information security management. Shared processes can help connect the two, but one certificate does not replace the other.

What does integration look like?

Integration may include shared document control, management review, internal audits, objectives, corrective action and responsibilities. It needs to be visible in how the organisation works, rather than only in a combined manual.

Some activities remain specific to each standard. The audit still needs the right competence and enough time to assess both management systems within their scopes.

Does a combined audit mean fewer audit days?

Not automatically. Audit planning considers each standard, the organisation's activities and the actual level of integration. Sharing documents or booking the audits together is not enough to establish a particular duration or saving.

What should we prepare for a quote?

Describe the scope proposed for each standard, the locations and people involved, and which management-system processes are shared. Explain where responsibilities, internal audits and management review are integrated, and where they remain separate.

Include any existing certificates and relevant customer requirements. ACS can review the proposed arrangement and discuss the audit work before quoting.