Audit Readiness Group
GlossaryThe standard3 min read

What is Annex SL?

Annex SL is the shared ten-clause structure behind ISO 9001, ISO 27001, and other management system standards. It is why one management system can carry more than one certificate.

What it is

Annex SL is an internal ISO drafting rule, not a standard you get certified against. It requires every management system standard to use the same top-level structure, the same core text for common requirements, and the same vocabulary.

The structure is ten clauses. The first three carry no requirements. Clauses 4 through 10 are: context of the organization, leadership, planning, support, operation, performance evaluation, improvement.

ISO 9001:2015 follows it. So does ISO 27001 for information security, ISO 14001 for environment, and ISO 45001 for occupational health and safety. Each adds discipline-specific requirements in clause 8 and around it, but the skeleton is identical.

For a manufacturer this has a practical consequence. Clause 9.2 internal audit means the same thing in both standards. So do management review, corrective action, competence, and documented information. The machinery you build once serves more than one certificate.

When you will hear it

From a consultant explaining why a second certification costs less than the first. That is usually true, and Annex SL is the reason.

In an integrated management system conversation, where a company decides to run one set of procedures, one audit program, and one management review that covers two or three standards at once.

From a customer who wants both a quality certificate and evidence that you protect their data. That pairing is becoming routine in defense and aerospace supply chains.

What the auditor expects to see

If you claim an integrated system, the auditor expects the shared clauses to actually be shared. One internal audit program that covers both scopes, with auditors competent in each. One management review agenda that includes the inputs both standards require. One corrective action process.

What fails is a system that says integrated and runs parallel: two audit schedules, two review meetings, two sets of records, and one of each pair quietly neglected.

Note that the discipline-specific parts do not merge. A quality auditor is not qualified to audit access control, and an information security auditor is not qualified to audit calibration. Integration is structural, not a substitute for competence in each field.

Common mistakes

Assuming the overlap is larger than it is. The shared skeleton is real, but the operational clause in each standard is where most of the work lives, and those do not overlap much. Expect the structure to transfer and the content not to.

Integrating before the first system is stable. Adding a second standard to a quality system that is not yet passing its own audits multiplies the findings rather than the benefit.

Forgetting that scopes can differ. Your quality certificate may cover one plant while your information security scope covers the whole company. That is allowed and common, and the documentation has to be clear about which is which.

FAQ

Is Annex SL still called that?

The structure was renamed the harmonized structure in 2021, and the numbered clauses shifted slightly in the update. Most people in practice still say Annex SL, and the meaning is the same.

Does an ISO 9001 certificate help with ISO 27001?

It helps with the parts built on the shared skeleton: audit program, management review, document control, corrective action, competence. It does nothing for the information security controls themselves, which are the larger half of the work.

Can one auditor certify both?

One certification body can, if it holds accreditation for both standards and assigns auditors competent in each. In practice you often meet two auditors on the same visit.

Which one should we do first?

Usually the one a customer is asking for. Where both are being asked for at once, quality first is the common order, because the management system habits it builds are what an information security system then reuses.

Tell us which audit is on your calendar.

A gap assessment is a flat-fee, on-site project led by a certified ISO 9001 lead auditor. Three founding-client spots are open for the quality practice.

We prepare you for certification. We never issue it. Your registrar's independence is the point.

Author: David AshbyUpdated 2026-09-12Audit Readiness Group