QHSE Management Systems
How management systems organize responsibilities, how ISO 9001, ISO 14001 and ISO 45001 fit together, and how to manage their practical interfaces.
0% complete
This course explains, in original wording, why organizations use management systems and how the ISO 9001, ISO 14001 and ISO 45001 standards relate to each other. It does not reproduce the text of any ISO standard, does not certify an organization's management system, and does not qualify you as an accredited management-system auditor or lead implementer. For the authoritative text and certification requirements, use the official ISO and accredited certification-body sources.
Why a management system, and why now
A management system connects policies, responsibilities, resources and work processes. It helps an organization apply agreed controls consistently when people, projects or contractors change. The amount of documentation should match the organization's context, risks and legal obligations.
A functioning system can reduce repeated failures, improve the evidence available for prequalification and help managers see whether controls work. Some customers, lenders or insurers may ask for certification or other evidence of control, but this depends on the contract and jurisdiction. Certification does not replace legal compliance and does not guarantee that incidents will not occur.
Plan, Do, Check, Act
ISO 9001, ISO 14001 and ISO 45001 use the Plan, Do, Check, Act cycle, usually shortened to PDCA. Plan means setting objectives and deciding how to achieve them. Do means implementing the planned processes. Check means monitoring and evaluating results. Act means correcting problems and improving the system.
A permit-to-work process provides a practical example. The organization defines the process and authorization roles, performs work under the permit, reviews how permits are used, and corrects weaknesses found during monitoring or audit. The results feed into the next planning cycle.
On reconstruction projects in Syria and the Kurdish region, teams and contractors may change between work phases. Clear responsibilities, induction, controlled documents and communication help new personnel understand the requirements that apply to their work.
One structure for three standards
ISO 9001, ISO 14001 and ISO 45001 address quality, environmental management and occupational health and safety. They use ISO's Harmonized Structure. Annex SL of the ISO/IEC Directives defines this shared approach, including common clause headings such as context, leadership, planning, support, operation, performance evaluation and improvement.
The shared structure makes integration possible. An organization may use common processes for document control, internal audit and management review, provided those processes cover the distinct requirements, scope and evidence required by each standard.
For example, one audit programme can include quality, environmental and OH&S criteria. The audit still needs competent auditors, suitable scope and enough evidence for every discipline. A common process does not automatically satisfy three standards.
The standards retain different purposes. ISO 9001 focuses on consistent products and services and customer requirements. ISO 14001 addresses environmental aspects, impacts and compliance obligations. ISO 45001 addresses OH&S hazards, risks, worker participation and safe working conditions.
How it actually runs: the eight-part loop
The Harmonized Structure is an outline, not an operating manual. The diagram below is a Myaser Academy teaching model that links eight practical management components. It is not ISO text and it is not the only valid way to organize a management system.
Read it as a loop, not a list. The top four boxes set direction: leadership commits, sets policy and objectives, organizes people and resources, and brings contractors and suppliers inside the same expectations. Risk management and business processes carry that direction into the actual work. Performance monitoring, audits and reviews then check what really happened, and feed it back through control, corrections and improvement into leadership again, closing the loop.
Mapped onto PDCA, the top four boxes are Plan. Business processes are Do. Performance monitoring, audits and reviews are Check. Control, corrections and improvement are Act, and the arrow running from Improvement back into Commitment, Leadership and Accountability is what makes this a cycle instead of a one-way chain.
Contractor and supplier management appears in the planning part of this teaching model because contractor interfaces require specific controls. Contractors may arrive with different procedures, competence records, equipment standards and working practices. The host organization must identify and manage any gaps before work begins.
Contract requirements alone do not demonstrate that controls work at the site. The host and contractor should define responsibilities, verify competence and equipment, communicate site rules, coordinate risk controls and monitor performance. Legal responsibility depends on the contract and applicable law, so this course does not assign liability.
Myaser HSE Hub's HSE Contractor Management article covers the practical side of this in more depth: prequalification, induction, supervision and close-out. Treat it as the companion piece to this lesson.
ISO 9001 and ISO 45001, side by side
ISO 9001 sets requirements for a quality management system. It focuses on consistently providing products and services that meet customer and applicable statutory and regulatory requirements, while improving the management system and customer satisfaction. Always confirm the current edition on ISO's official page because standards are revised.
Ideas used in the standards covered by this course
- Process approach: work as a chain of linked activities with defined inputs, outputs and an owner, rather than isolated departmental tasks that only meet at handover.
- Risk-based thinking: asking what could stop a process reaching its intended result, and planning for that before it happens rather than after.
- Top management commitment: leadership sets the policy, funds the system properly, and stays accountable for whether it works, rather than delegating it entirely and checking in once a year.
- Continual improvement: using audit findings, nonconformities, corrective actions and management review to make the system better over time, not just to keep it compliant on paper.
Quality and safety processes can share methods without becoming the same discipline. A corrective-action process may be used for a product nonconformity or an OH&S incident, but the investigation criteria, competence and legal requirements may differ.
ISO 45001: occupational health and safety
ISO 45001 sets requirements for an occupational health and safety management system intended to prevent work-related injury and ill health and provide safe and healthy workplaces. It replaced OHSAS 18001 and uses ISO's Harmonized Structure.
Two practical elements are worker consultation and participation, and the ongoing identification of hazards and assessment of OH&S risks. The organization must involve workers, including non-managerial workers, in relevant parts of the system. It must also review hazards and risks as work, equipment and conditions change.
A logistics yard's ISO 45001 hazard register flags reversing vehicles as a significant risk. Under the participation requirement, the yard consults forklift operators and pedestrian workers directly when choosing between physical segregation, one-way traffic routing and a dedicated banksman, rather than a manager picking a control alone from an office.
Boundary: this lesson explains what these two standards are for, in original wording. It does not certify a quality or OH&S management system, and it does not make you a quality or safety auditor.
ISO 14001 and the case for integrating
ISO 14001:2026 sets requirements for an environmental management system. It replaced ISO 14001:2015 and its 2024 climate-action amendment. Organizations should use the current published edition when implementing or auditing a system.
- Environmental aspect: an element of an activity that interacts, or could interact, with the environment, such as fuel storage, wastewater discharge or dust generation.
- Environmental impact: the change that results, for better or worse, such as soil contaminated by a fuel leak, or a wetland protected by a proper drainage plan.
- Life cycle perspective: considering environmental aspects from raw material sourcing through to end-of-life, not only the moment of use on site.
- Compliance obligations: the legal requirements and other commitments the organization has to meet, identified and reviewed rather than assumed.
The case for integrating
The shared structure allows an organization to operate an integrated management system. Common audit, document-control and management-review processes can reduce duplication when their scope covers every applicable requirement. The organization must still retain the technical competence, evidence and operational controls required for quality, environmental management and OH&S.
Integration must not blur distinct legal or technical requirements. An environmental compliance obligation is not satisfied by a safety control, and an OH&S risk assessment does not replace an environmental aspects and impacts evaluation. Contractor interfaces also require defined responsibilities and coordinated controls.
Course boundary
This course has explained how these three standards relate to each other and to day-to-day HSE practice, using original wording rather than the standard text itself. It does not certify an organization's management system, does not qualify you as an accredited auditor or lead implementer, and does not replace the official ISO standards, an organization's own management-system documentation, or the requirements of an accredited certification body.
Official references
- ISO: Management system standards
- ISO: ISO 9001, quality management systems
- ISO: ISO 14001:2026, environmental management systems
- ISO: ISO 45001:2018, occupational health and safety management systems
- ILO: Occupational safety and health
- Myaser HSE Hub: HSE Contractor Management
This course uses original wording based on these official sources. Always use the official ISO standard text and an accredited certification body for implementation or certification decisions.
Final assessment
The assessment has ten questions. A verified learner must complete all lessons and score at least 70%. The certificate confirms awareness of how these management systems relate to each other and the recorded knowledge score. It does not certify an organization's management system and does not qualify you as an accredited auditor or lead implementer.
Question 1 of 10