A combined internal audit covers two or more management system standards in one visit, against one plan, with one report. Organizations running quality, health and safety, environment and security separately audit the same process four times a year and ask the same manager the same questions each time — which is why the combined approach is the first thing most QHSE programmes should fix.
This guide covers what can genuinely be merged, what cannot, how to plan the programme, and the competence problem that decides whether it works.

What a combined internal audit actually merges
The unit of audit changes. Instead of auditing ISO 9001 clause 8.4 and later ISO 45001 clause 8.1.4, you audit procurement — once — and test it against every requirement that lands on it. The auditor asks how suppliers are selected, and the same answer feeds the quality, safety and environmental findings.
| Merges cleanly | Stays standard-specific |
|---|---|
| Context, interested parties, scope | Environmental aspects and impacts |
| Leadership, roles, policy commitments | Hazard identification and worker consultation |
| Risk and opportunity process, objectives | Product realisation and design controls |
| Competence, awareness, communication, documents | Legal compliance evaluation, per discipline |
| Monitoring, management review, improvement | Emergency preparedness, incident investigation |
Roughly two-thirds of the clause content is shared because the standards are written to a common structure — the same reason an integrated management system manual is possible at all. The remaining third is where a combined internal audit needs discipline, because that is where a generalist auditor runs out of depth.
Planning the programme
- Start from processes, not clauses. List the processes that make up the organization, then map every applicable requirement onto each. That map is the audit programme.
- Set frequency by risk, not by standard. A high-hazard process may need auditing twice a year against safety and once against quality. Nothing requires equal treatment.
- Cover every clause of every standard within the cycle. This is the rule that catches people out — merging visits does not reduce coverage obligations, and a clause missed across the cycle is a finding at the certification audit.
- Write one checklist per process, with the source marked. Each question carries the standard and clause it comes from, so findings can be reported separately when a certification body wants them that way.
- Report once, tag by standard. One report the process owner can act on, with each finding tagged so the management review can still see quality, safety and environmental trends apart.
- Keep independence intact. Auditors still cannot audit their own work, and combining disciplines makes that harder to arrange in a small team, not easier.
The competence problem
A combined internal audit needs auditors who understand every standard in the visit, and most organizations have a quality auditor who is uncomfortable with hazard controls or a safety auditor who has never read a calibration record. Two workable answers: pair auditors and let each lead their discipline within one visit, or train a small core team properly and accept that it takes a year. What does not work is sending one auditor with four checklists and hoping.
What a combined internal audit gains, and what it costs
The gains are real: fewer interruptions for the business, findings that reflect how work actually happens, and an end to the situation where the same weak procurement process generates three unrelated corrective actions. Audit time typically falls, though less than people expect — the saving is in travel, setup and repeated interviews, not in the testing itself.
The cost is concentration. One weak auditor now weakens three standards at once, and one badly scoped visit leaves gaps across the whole system. The programme needs a review at the end of each cycle asking which clauses were actually tested, not just which visits happened.
Frequently asked questions
Is a combined internal audit allowed?
Yes. No management system standard requires separate audits per standard. Each requires an internal audit programme covering its own requirements at planned intervals — one programme can satisfy several.
Does it mean one certification audit too?
Combined external audits are normal where one certification body holds all the standards, and audit days are reduced rather than merged. That is the body’s decision, not yours.
Do we need one report or several?
One report works for the business. Keep findings tagged by standard so each management system can still demonstrate coverage and trends.
Can the same person audit quality and safety?
Only with competence in both. Auditor competence is an explicit requirement, and a combined programme raises the bar rather than lowering it.
How do we prove full clause coverage?
Maintain a matrix of clause against audit, updated as the cycle runs. It is the document a certification auditor asks for when the programme is process-based rather than clause-based.
Where this leaves you
Build the combined internal audit programme around your processes, map every applicable clause onto them, and keep a coverage matrix so nothing falls between visits. Set frequency by risk rather than by standard, pair auditors where competence is thin, and report once with findings tagged. The point is not to save audit days — it is to stop asking the same manager the same question four times and getting four disconnected corrective actions out of it.
References
- ISO 19011:2018 — guidelines for auditing management systems, including combined audits and auditor competence.
- ISO management system standards — the family sharing the harmonized structure.
More on integrated systems
- The combined internal audit — you are here
- QHSE documentation in four tiers
- The QHSE management system
- Clause 9: performance evaluation
Audit programmes, process checklists and the coverage matrix are in the QHSE Documentation Bundles, or start with the free ISO templates.