Why Every Recent ISO Standard Looks the Same
Pull up ISO 9001:2015 next to ISO 27001:2022, and something odd happens. Clause 5 is "Leadership" in both. Clause 9.2 is "Internal audit" in both. Clause 10 is "Improvement" in both. These are two standards written for completely different purposes, quality management in one case, information security in the other, and yet they read like siblings.
That is not a coincidence, and it is not because ISO ran out of ideas. It is Annex SL, and if you are managing more than one certification, understanding what it does and doesn't do will save you a lot of duplicated work.
I have built integrated management systems for clients running ISO 9001, ISO 45001, and ISO 27001 at the same time, and the single biggest efficiency gain isn't a clever software tool. It's recognizing that the clause structure is already shared, so the documentation, the internal audit program, and the management review can be shared too.
What Annex SL Actually Is
Annex SL is a document within the ISO/IEC Directives, Part 1, Consolidated ISO Supplement. It sets out a mandatory "High Level Structure" (HLS) that every new or revised ISO management system standard has to follow. In the 2021 edition of the Directives, ISO relocated and relabeled this content as Appendix 2, calling it the "Harmonized Structure," though most practitioners, and most consultants including me, still call it Annex SL out of habit.
Before Annex SL existed, ISO management system standards were written independently. ISO 9001 had its own clause numbering, ISO 14001 had its own, and mapping requirements between the two meant building a cross-reference matrix by hand. Annex SL, introduced through the 2012 consolidated supplement, changed that by forcing every technical committee writing a new management system standard to start from the same ten-clause skeleton, the same core definitions, and much of the same core text.
Here is the plain statement of what that means in practice: Annex SL standardizes where a requirement has to live in the document, not what the organization has to do about it. The clause numbers are identical across standards. The substance underneath them is not.
The Ten Clauses Every HLS Standard Shares
Every management system standard built on Annex SL, from ISO 9001 to ISO 22301 to the newer ISO 42001, uses this same top-level structure:
| Clause | Title | What it generally covers |
|---|---|---|
| 1 | Scope | What the standard applies to and its boundaries |
| 2 | Normative references | Other documents the standard depends on |
| 3 | Terms and definitions | Shared vocabulary, often pointing to ISO's common terms |
| 4 | Context of the organization | Internal/external issues, interested parties, scope of the management system |
| 5 | Leadership | Top management commitment, policy, roles and responsibilities |
| 6 | Planning | Risk and opportunity, objectives, planning of changes |
| 7 | Support | Resources, competence, awareness, communication, documented information |
| 8 | Operation | Operational planning and control specific to the discipline |
| 9 | Performance evaluation | Monitoring, measurement, internal audit, management review |
| 10 | Improvement | Nonconformity, corrective action, continual improvement |
This applies to ISO 9001:2015 (quality), ISO 14001:2015 (environmental), ISO 45001:2018 (occupational health and safety), ISO 27001:2022 (information security), ISO 22301:2019 (business continuity), ISO 37301:2021 (compliance management), and ISO 42001:2023 (AI management systems), among others. If your organization holds two or three of these certificates, your document control system, your internal audit checklist, and your management review agenda can all be built once and reused, because the top-level architecture is genuinely the same document.
Same Numbers, Different Content: Where Standards Diverge
This is where people get the wrong idea about Annex SL. They assume shared numbering means shared requirements, and that assumption causes real audit findings. The clause number tells you where to look. It does not tell you what you'll find there.
Clause 6.1.2 is the cleanest example I know of. Every HLS standard addresses risk somewhere around 6.1, but what each standard actually asks for at 6.1.2 diverges sharply once you get past the heading:
| Standard | Clause 6.1.2 title | What it actually requires |
|---|---|---|
| ISO 9001:2015 | Actions to address risks and opportunities | Determine risks and opportunities relevant to product/service conformity and customer satisfaction, and plan actions proportionate to their effect |
| ISO 45001:2018 | Hazard identification and assessment of risks and opportunities | A structured, three-part process: hazard identification (6.1.2.1), assessment of OH&S risks (6.1.2.2), and assessment of OH&S opportunities (6.1.2.3) |
| ISO 27001:2022 | Information security risk assessment | A defined, repeatable risk assessment process producing consistent, valid, and comparable results, tied directly to the Annex A control set |
| ISO 42001:2023 | AI risk assessment | Assessment of AI-specific risks across the AI system lifecycle, feeding into risk treatment at 6.1.3 and a separate AI system impact assessment at 6.1.4 |
ISO 9001 splits this across two sub-clauses — 6.1.1 (general risk and opportunity determination) and 6.1.2 (planning the actions) — rather than issuing a single 6.1.2 requirement; the table above collapses both into one row for comparison.
Four standards, one clause number, four different bodies of evidence an auditor will expect to see. An organization that assumes its ISO 9001 risk register satisfies ISO 45001's clause 6.1.2 will fail an OH&S audit, because ISO 45001 specifically requires hazard identification as a distinct, documented step before you get to risk assessment at all.
The divergence goes further at clause 8, "Operation," which is really just a placeholder each technical committee fills with the actual discipline-specific work: production and service provision controls in ISO 9001, operational planning and control plus emergency preparedness in ISO 45001, the full Annex A control implementation in ISO 27001, and PRPs and HACCP-based food safety controls in ISO 22000:2018. Clause 8 is where the shared skeleton ends and the real subject matter of the standard begins.
Clause 10 has its own quiet history worth knowing if you're managing a transition. ISO/IEC 27001:2013 ran nonconformity and corrective action at 10.1 and continual improvement at 10.2. The 2022 revision swapped them: continual improvement moved to 10.1, and nonconformity and corrective action moved to 10.2. If you're referencing an older gap assessment or an older internal audit checklist built against the 2013 text, that swap alone can throw off your clause mapping.
Why This Matters If You're Certifying to More Than One Standard
Here's the practical payoff. Because clauses 4, 5, 7, 9, and most of 6 and 10 carry near-identical intent across standards, you can build a single integrated management system (IMS) manual instead of three separate ones. One policy covers leadership commitment. One procedure covers document control. One internal audit program and one management review cycle satisfy all your certifications simultaneously. You don't need three separate management review meetings for ISO 9001, ISO 14001, and ISO 45001. You need one meeting with an agenda broad enough to cover all three, because clause 9.3 asks for essentially the same inputs and outputs in each standard.
This is also why certification bodies increasingly offer integrated or combined audits: the auditor walks through the shared clauses once, then branches into discipline-specific evidence at clauses 6.1.2, 7 (competence requirements for a specific discipline), and 8. A well-built IMS turns three audit days into two, not because the auditor is skipping anything, but because the shared clauses genuinely don't need to be re-verified three separate times.
I'll say the blunt version: if your management system documents restate the same leadership commitment statement in three different manuals with three different clause numbers, you are paying for redundant paperwork that Annex SL already told you how to eliminate.
Building an Integrated Management System on the Annex SL Skeleton
If you're consolidating certifications, the sequence that works is straightforward:
- Map your current standards to the HLS clause list. Confirm which of your standards are Annex SL-based (ISO 9001, 14001, 45001, 27001, 22301, 37301, 42001, and others) versus which are not. ISO 13485 retains its own legacy structure. IATF 16949 is a different case: it's built directly on ISO 9001:2015's Annex SL clause numbering, adding automotive-specific sub-clauses like 6.1.2.1, 7.1.1.1, and 9.1.1.1 rather than replacing the structure underneath them — so treat it as Annex SL-based with automotive overlays, not as a non-HLS standard.
- Build one master document at clauses 4, 5, 7, 9, and 10. Context, leadership, support, performance evaluation, and improvement can usually run as single shared procedures with discipline-specific appendices where needed.
- Keep clause 6.1.2 and clause 8 discipline-specific. Don't try to force a single risk methodology to cover quality risk, OH&S hazards, information security risk, and AI risk with one generic risk matrix. Each standard's technical committee wrote 6.1.2 the way it did for a reason.
- Run one internal audit program with discipline-specific auditor competence. The audit schedule can be unified; the auditors checking clause 8 evidence for ISO 27001 need different technical competence than those checking clause 8 evidence for ISO 45001.
- Hold one management review with a broadened agenda. Clause 9.3 inputs are similar enough across standards that a single quarterly review covering all certifications, with discipline-specific data feeding into a common set of decisions, satisfies the intent of each standard without triplicating the meeting.
Common Mistakes When Treating Annex SL as a Checklist
The most frequent error I see is copying a risk register built for ISO 9001 straight into an ISO 45001 or ISO 27001 implementation because the clause number matches. It doesn't transfer. Hazard identification under ISO 45001 clause 6.1.2.1 is a distinct documented activity, not a byproduct of a general business risk exercise, and auditors know the difference.
The second mistake is assuming Annex SL applies to every ISO standard. It doesn't. Product and testing standards, sector-specific standards published before 2012 that haven't been revised since, and standards like ISO 13485 for medical devices retain their own structure, even where they've absorbed some HLS language informally. Always check the actual clause list of the specific standard edition you're certifying against rather than assuming.
The third mistake is treating the shared clauses as lighter-weight because they're "common." Clause 9.2, internal audit, and clause 10.2, nonconformity and corrective action, are exactly where most certification bodies write major findings, precisely because they're the clauses every auditor has the most practice evaluating.
Frequently Asked Questions
Does every ISO standard use Annex SL? No. Annex SL applies to management system standards developed or revised after its 2012 introduction, including ISO 9001:2015, ISO 14001:2015, ISO 45001:2018, ISO 27001:2022, ISO 22301:2019, and ISO 42001:2023. Product standards and some legacy sector standards, like ISO 13485, sit outside this structure.
If two standards share a clause number, do they share the same requirement? Only in general intent, not in specific content. Clause 6.1.2 exists in ISO 9001, ISO 45001, ISO 27001, and ISO 42001, but each standard defines a different risk-related activity underneath that number, from OH&S hazard identification to AI risk assessment.
What changed between ISO 27001:2013 and ISO 27001:2022 in the shared clauses? Clauses 10.1 and 10.2 were reversed: continual improvement moved from 10.2 to 10.1, and nonconformity and corrective action moved from 10.1 to 10.2. This swap is specific to the ISO 27001 2013-to-2022 transition, not a broader HLS-wide change, so the fix is narrow: repoint any corrective-action form, procedure, or internal audit checklist that still cites "10.1" for nonconformity, since that number now means something else.
Can one internal audit satisfy multiple ISO certifications at once? Yes, for the shared clauses. An integrated audit program can verify clauses 4, 5, 7, 9, and 10 once across all certified standards, provided the auditor also has the specific technical competence to assess the discipline-specific content at clause 6.1.2 and clause 8 for each standard.
Is Annex SL still called that, or has the name changed? Both, and the rename didn't touch the substance — the ten-clause skeleton and shared core text moved from Annex SL to Appendix 2 of the 2021 ISO/IEC Directives unchanged; only the label and location shifted. In practice, expect "Annex SL" to keep showing up for years in audit reports, consultant proposals, and older certificates even as ISO's own documents now say "Harmonized Structure."
If you're weighing which certifications to pursue together, or trying to figure out whether your current documentation actually satisfies the discipline-specific requirements hiding underneath a shared clause number, that's a scoping conversation worth having before you schedule an audit. Our ISO consultants work through exactly this kind of clause-by-clause gap assessment, and if AI governance is part of what you're building toward, our ISO 42001 consulting page walks through how that newest HLS standard fits alongside the others.
Last updated: 2026-08-25
Jared Clark
Principal Consultant, Certify Consulting
Jared Clark is the founder of Certify Consulting, helping organizations achieve and maintain compliance with international standards and regulatory requirements.