Governance DocsGovernance Docs
Browse Toolkits

CART

No products in the cart.

ISO Compliance Insights & Best Practices

Integrated management system risk register guide cover

Integrated Management System Risk Register: One Register 2026

An integrated management system risk register brings the risks and opportunities from quality, environmental and safety standards into a single, consistent record. ISO 9001, ISO 14001 and ISO 45001 share the Annex SL structure, and each has a planning clause that expects you to consider risks and opportunities. Keeping three separate registers means duplicated effort, conflicting ratings and confused owners. One register, with clear tags for each discipline, is easier to run and easier to audit.

This guide explains how to design the register, what each standard adds, how to rate and treat risks and how to keep the register alive through management review. It builds on our guides to the integrated management system, Annex SL and IMS implementation.

Free gap assessment

Are you ready for the 2026 edition of ISO 9001?

Score yourself against the new edition, free, including the risk and opportunity split and the clause 10 renumbering that breaks converted checklists.

Run the free ISO 9001 gap assessment →  or  View premium report sample

Why one register works

A practitioner article on combining ISO 9001 and ISO 14001 notes that most harmonised standards share identical core structures, so the skeleton of the management system is already the same. Context and interested parties are assessed once, leadership is consolidated, and the planning clause sets objectives that can satisfy several standards at once. The same logic applies to risks. A supplier failure that stops production is a quality risk, an environmental risk if it causes a spill and a safety risk if it exposes workers. In one register, you see the whole picture and treat it once.

ApproachEffect
Three separate registersDuplicated entries, different scales, unclear ownership
One register with discipline tagsOne scale, one owner per risk, filterable by standard

What each standard adds

The common planning clause covers risks and opportunities, but each standard adds its own subject matter. The register should hold all of these, so that nothing falls between disciplines.

  • Quality (ISO 9001). Risks to conformity of products and services and to customer satisfaction, and opportunities to improve.
  • Environment (ISO 14001). Environmental aspects and impacts, compliance obligations and related risks and opportunities.
  • Health and safety (ISO 45001). Hazards, occupational health and safety risks, other risks to the management system, and opportunities.

Read the exact planning clause in each standard, because the structure differs from one standard to another. For example, the environmental and safety standards ask for identification of aspects or hazards, and for compliance obligations or legal requirements, and the register should link to those inputs.

Designing the integrated management system risk register

Keep the design simple enough that people will use it. A spreadsheet or a module in your management system software can hold the following fields.

  1. ID and title. A short, unique description.
  2. Discipline tags. Quality, environment, safety, or a combination.
  3. Source. Context analysis, hazard identification, aspect assessment, audit, incident or customer feedback.
  4. Description. The risk or opportunity in plain words, including cause and effect.
  5. Inherent rating. Likelihood and consequence before controls.
  6. Existing controls. What is already in place.
  7. Residual rating. After controls.
  8. Actions. Additional treatment with owner and due date.
  9. Linked objectives and processes. Where the risk affects results.
  10. Review date. When it will be reassessed.

One rating scale

Agree a single scale for likelihood and consequence, with definitions that cover quality, environmental and safety impacts. For example, a major consequence might be defined as a serious injury, a reportable environmental release or a loss of a key customer. A common scale lets you compare and prioritise across disciplines. If safety legislation requires a different method for particular hazards, keep it as a linked assessment and record the result in the register.

Feeding the register

Feed the register from several sources so it reflects reality. Use the context and interested party analysis, process risk workshops, hazard identification and environmental aspect reviews, audit findings, incidents and near misses, complaints, supplier issues and legal changes. Assign a person to check each source on a schedule, and add or update entries. When the same source is used by separate standards, for instance a change in regulations, record it once and tag the disciplines.

Treating risks and opportunities

For each significant entry, choose an action: eliminate the risk, reduce it, transfer it, accept it or pursue an opportunity. Integrate actions into the management system, as the standards require, by linking them to objectives, procedures, training, budgets and projects. For safety hazards, follow the hierarchy of controls. Our guide to the integrated management review explains how to present results to top management.

Opportunities in an integrated management system risk register

Opportunities are often neglected because they feel optional. Give them the same structure as risks: a description, an owner, an expected benefit and an action. Examples include a process change that cuts waste and lowers cost, a safer tool that also improves productivity or a new service that meets a customer need. Review them in the same meetings, and record which were taken up and what result they delivered. This shows auditors that the planning clause is applied, not only the risk half.

Documentation and control

The register is documented information, so control it in line with your document control rules. Define who can edit it, how changes are tracked and where the master copy lives. Our guide to IMS document control covers this. Keep snapshots at management review and audit dates, so you can show what was known at the time.

Running risk workshops across disciplines

The quickest way to fill an integrated management system risk register is through short workshops by process. Bring together the process owner, a quality representative, someone who knows the environmental aspects and a safety representative, and walk through the process step by step. Ask at each step what could go wrong for customers, for the environment and for people, and what could improve. Record the results directly in the register, and agree owners before the meeting ends. Two-hour sessions for each key process are usually enough to build a solid first version.

Keep the language plain and specific. A statement such as “operator error” is too vague to act on, while “operators skip the solvent transfer checklist when the line is under time pressure” points to a real cause and a real fix.

Linking the register to objectives and audits

Every significant risk or opportunity should connect to an objective, a process or a control. When you set objectives at the start of the year, review the register for the most serious risks and opportunities and make sure objectives address them. During internal audits, use the register to plan which areas to examine, and record audit findings as new entries or updates. This closes the loop, so that the register drives your audit programme and your audits improve the register.

Measuring whether risk treatment works

Track whether actions are completed on time, and whether residual ratings fall after treatment. Report the number of high-rated risks, overdue actions and new entries at each management review. If a risk stays high after several actions, escalate it to top management for a decision on resources or on accepting the risk. A short trend chart of high risks over the year gives leaders a simple picture of whether the integrated management system risk register is doing its job.

A hypothetical example

A hypothetical food packaging company merges three registers into one. A single entry covers a solvent supplier: the risk is late delivery affecting customer orders (quality), a solvent spill during unloading (environment) and vapour exposure for warehouse staff (safety). The entry is owned by the operations manager, uses the common rating scale and lists actions: a second supplier, a contained unloading bay and improved ventilation. At the next management review, the owner presents one entry instead of three, and top management approves the budget for the bay. The example is invented for illustration.

Common mistakes with an integrated management system risk register

  • Copying three separate registers into one sheet without harmonising scales.
  • Recording only risks and ignoring opportunities.
  • No owners or dates on actions.
  • Failing to link risks to objectives and processes.
  • Not updating the register after incidents or changes.
  • Skipping the specific inputs of each standard, such as aspects and hazards.

The ISO overview of management system standards is a good reference for the common structure. Confirm requirements in your licensed copies of each standard, and ask your certification body how it audits an integrated register.

Templates for an integrated management system risk register

If you would rather not design the register, rating scale and review forms from scratch, the IMS Toolkit provides documents you can adapt. See our note on IMS certification cost when planning your budget.

Integrated management system risk register FAQ

Can we use one register for ISO 9001, 14001 and 45001?

Yes. The standards share a common structure, and a single register with discipline tags satisfies each standard’s planning requirements if the specific inputs are covered.

Do we need a separate hazard register for ISO 45001?

Not necessarily, but you need hazard identification and risk assessment. Link the detailed assessment to the register, and keep the results consistent.

Are opportunities required?

The planning clauses refer to risks and opportunities, so record some with actions and owners.

How often should the register be reviewed?

At least at management review and whenever there are significant changes, incidents or audit findings.

Who owns the register?

A management representative or quality manager maintains it, while process owners own the individual entries.

When a standard changes, know first

One email a month: edition changes, new deadlines, and what they mean for documentation you already have. No sales sequence.

We don’t spam! Read our privacy policy for more info.