Back to Resources

    Why Your Compliance and Quality Systems Should Be One Thing, Not Two

    ByBrian Freer, PhD·
    Share:
    Diagram showing quality and compliance gears merging into a single integrated management system

    Many businesses run their quality management system in one place and their regulatory compliance activity somewhere else entirely. The ISO 9001 documentation is managed by the quality team. The health and safety records sit with the operations manager. The data protection records are owned by the IT department. The environmental compliance logs are filed in a folder nobody looks at until an inspection is due.

    This is not unusual. It is, in fact, the default state for most organizations that have grown their compliance obligations incrementally over time. But it is expensive, risky, and largely unnecessary.

    A 2023 paper published in the Journal of Regulatory Science by Brian Freer and Richard Fiene examines the relationship between regulatory compliance programs and quality management systems, identifies the structural problems that keep them separate, and makes a practical case for integration. This article summarizes their findings and translates them into terms relevant to UK, US, and Irish SMEs managing ISO certification alongside regulatory obligations.

    The Core Argument: Two Systems Doing One Job

    Freer and Fiene draw a useful distinction between regulatory compliance and quality programs. Regulatory compliance covers all government requirements an organization must meet. Quality programs cover standards, customer requirements, and other obligations where the organization must demonstrate conformance. ISO 9001, ISO 27001, and ISO 14001 fall into the quality program category in this framework.

    In most organizations these two bodies of obligation are managed separately, despite overlapping significantly in practice. Both require documented processes. Both require evidence of conformance. Both require internal audit and management review. Both benefit from systematic measurement and continual improvement.

    The authors argue that treating them as separate activities is not just inefficient but actively counterproductive. When regulatory compliance and quality management operate in separate silos, the measurement disciplines and continual improvement habits that quality programs develop rarely migrate to the compliance side. The result is a compliance program that meets minimum requirements but generates little learning or improvement, and a quality program that does not fully account for the regulatory context in which the business operates.

    Regulatory compliance versus quality programs

    Regulatory compliance: all government requirements facing an organization, exclusive of accounting, and the activities undertaken to conform to them.

    Quality programs: customer, international, and national standards and other requirements where an organization is obligated to show conformance.

    Source: Freer, B. & Fiene, R. (2023). Journal of Regulatory Science, 11(1).

    The Five Constraints That Hold Organizations Back

    Drawing on decades of management consulting practice, Freer and Fiene identify five structural characteristics that commonly prevent organizations from getting the most out of their management systems. These are described as drags on the optimization of management system implementation. Each is recognizable to anyone who has worked with compliance and quality programs in practice.

    Constraint

    What it looks like

    Why it matters

    1. Passive acceptance of compliance targets

    Accepting government-set requirements at face value without exploring what value additional data collection could provide

    Organizations miss opportunities to go beyond minimum compliance and derive genuine business insight from the data they are already collecting

    2. Binary yes or no measurement

    Building procedures and forms around pass or fail questions ("was the target met?") rather than continuous measurement

    Binary systems obstruct the kind of measurement and trend analysis that drives genuine improvement

    3. Parallel silos

    Maintaining separate systems for regulatory compliance and quality, each following the language and structure of its respective standard or regulation

    Duplication of effort, inconsistent records, and missed opportunities to use quality program tools to improve compliance outcomes

    4. Narrative-based procedures

    Writing procedures as dense blocks of text rather than process flowcharts and maps

    Text-heavy procedures are harder to follow, less likely to be integrated into daily workflows, and more difficult to audit effectively

    5. Department rather than process ownership

    Assigning compliance and quality responsibilities to departments rather than named individual process owners

    When accountability sits with a department rather than a person, it is unclear who is responsible for a given process, and the system has to be restructured every time the organizational chart changes

    The fifth constraint, in particular, has direct implications for ISO-certified organizations. ISO 9001 Clause 5.3 and its equivalents in other management system standards require roles, responsibilities, and authorities to be defined and communicated. But defining responsibilities at the department level rather than the individual process owner level means that accountability is diffuse, audit evidence is harder to collect, and the system has to be restructured whenever the organization changes shape.

    The fourth constraint, narrative-based procedures, is equally relevant. ISO 9001 and its High Level Structure equivalents do not prescribe a procedure format, but the research evidence reviewed by Freer and Fiene suggests strongly that process flowcharts and maps are more effective than text-based procedures for embedding processes into daily operations.

    When Regulators and Standards Converge: The FDA Example

    Freer and Fiene use a significant regulatory development as a case study for their argument. In 2022, the US Food and Drug Administration proposed aligning its Quality System Regulation for medical devices (21 CFR 820) with ISO 13485:2016, the international standard for medical device quality management. The proposal would achieve this alignment by incorporating ISO 13485 by reference into the regulation.

    This is notable because regulations are not typically written in a process framework, let alone aligned with international standards. As the authors observe, regulations tend to be written as policy narratives listing requirements and end-state outcomes that organizations must achieve. Process-based standards like ISO 13485 take a different approach, allowing organizations to set their own metrics while requiring them to demonstrate their reasoning and engage in continual improvement.

    The FDA move is significant for any organization operating in a regulated sector. It signals that the gap between regulatory compliance and quality program requirements is capable of being closed at the regulatory level, not just at the organizational level. For businesses outside medical devices, the lesson is that proactively building a management system capable of integrating regulatory and quality requirements positions an organization well for future regulatory developments.

    In the UK, similar convergence is visible in the way GDPR data protection requirements overlap with ISO 27001 information security controls. In Ireland, public sector procurement frameworks are increasingly specifying ISO standards alongside statutory compliance requirements. The direction of travel is toward integration, not further separation.

    A Practical Tool: Scoring Your Management System

    One of the more practically useful contributions of the Freer and Fiene paper is a simple scoring framework that organizations can use to assess whether their management system would benefit from a move toward a process-based integrated approach. The framework involves three dimensions.

    Dimension

    What to assess

    Score

    Regulatory complexity

    How many regulations apply to your organization? How complicated are their requirements?

    High and Complex, Medium and Standard, or Low and Simple

    System structure

    Does your management system follow the numbering and language of the standard or regulation, or is it organized around your own processes?

    Elements-based or Independent

    Procedure format

    Are your procedures written primarily as blocks of text, or do they use process flowcharts and maps?

    Primarily narrative or Primarily process

    Organizations that score High and Complex on regulatory complexity, Elements-based on system structure, and Primarily narrative on procedure format are, according to the authors, the strongest candidates for transitioning to a process-based integrated management system. The higher the complexity and the more elements-based and narrative the existing system, the greater the potential efficiency gain from integration.

    For many UK and Irish SMEs pursuing ISO 9001 alongside sector-specific regulatory obligations, this combination is common. A construction company managing ISO 9001, CDM Regulations, and CHAS accreditation simultaneously is likely running three partially overlapping information management systems. A food manufacturer managing ISO 22000 alongside FDA or FSA regulatory requirements faces the same challenge.

    What Integration Actually Delivers

    Freer and Fiene draw on research by Carvalho et al. (2015) to outline the practical benefits organizations typically experience from management system integration. Six findings are particularly relevant to SMEs.

    1. A shared resources approach: one procedure for auditing, purchasing, and corrective action rather than separate versions for each standard or regulatory framework.

    2. Easier system management: team members find it significantly easier to navigate and maintain a single integrated system.

    3. Faster audits: internal and external audits take less time when the evidence is organized around processes rather than scattered across separate compliance and quality systems.

    4. Fewer meetings: with a single system providing a unified view of compliance and quality performance, the number of separate review meetings decreases.

    5. Better understanding of the whole system: individuals develop a clearer picture of how their work connects to both compliance and quality outcomes.

    6. Reduced costs: the efficiency gains across all of the above translate into measurable cost reduction.

    The authors also note one significant challenge: the primary barrier to integration identified by Carvalho et al. is not technical but relational. It is a lack of collaboration between managers in different functional areas. In practice, the quality team and the compliance team, where these are distinct, may have developed separate habits, tools, and reporting structures over years. Integration requires both a structural change to the management system and a cultural change in how these teams work together.

    Elements-Based Versus Process-Based: What the Difference Means in Practice

    The distinction between elements-based and process-based management systems is central to the Freer and Fiene framework and worth unpacking for organizations that have not encountered the terminology before.

    An elements-based system is structured around the numbering and language of the standard or regulation it is designed to meet. The quality manual has sections numbered 4.1, 4.2, 4.3 to match ISO 9001 clause structure. The procedures are titled using the standard terminology. The advantage of this approach is that it makes it straightforward to demonstrate clause-by-clause compliance to an auditor. The disadvantage is that it creates a system that speaks the language of the standard rather than the language of the business, which makes it harder for operational staff to engage with it and easier for it to become a documentation exercise rather than a genuine management tool.

    A process-based system is structured around how the organization actually operates. Processes are identified, mapped, and owned by named individuals. The management system documentation describes how things actually get done, using the organization own language and sequencing. Standards and regulations are then mapped onto these processes, typically using cross-reference matrices, rather than the other way around.

    The process-based approach aligns directly with what ISO 9001:2015 calls for. Clause 4.4 requires organizations to determine their key processes, their interactions, their inputs and outputs, and the criteria and methods needed to control them. An elements-based system can technically satisfy this clause; a genuinely process-based system embeds it.

    What This Means for Your Organization

    If you are currently pursuing ISO 9001 certification and also managing sector-specific regulatory obligations, the Freer and Fiene framework suggests a few practical considerations.

    Map Your Full Compliance Landscape Before Building Your QMS

    Before documenting your first procedure, identify all the legal and supra-legal requirements your organization faces. Legal requirements are government regulations. Supra-legal requirements include standards, customer contractual obligations, trade association requirements, and insurance conditions. Building this inventory first means you can design a management system that addresses all of them coherently, rather than bolting regulatory compliance onto a quality system that was designed without it in mind. The ISO cost calculator can help you scope the financial implications of adding standards into the mix.

    Organize Around Processes, Not Standards

    Design your management system around how your business actually operates, and then map the requirements of each standard and regulation onto your processes. This is more work upfront than building a system around the clause structure of ISO 9001, but it produces a system that your people can actually use and that scales naturally when new requirements are added.

    Assign Individual Process Owners, Not Departmental Responsibilities

    For each key process in your management system, assign a named individual as process owner. This person is responsible for the documented process, the evidence of compliance, and the continual improvement of that process. Accountability at the individual level is clearer, easier to audit, and more resilient to organizational change than departmental ownership.

    Use Cross-Reference Matrices to Manage Multiple Standards

    If your organization operates under multiple standards (for example, ISO 9001 and ISO 45001, or ISO 9001 and sector-specific regulatory requirements), a cross-reference matrix is a practical tool for managing the overlaps and gaps. The matrix maps shared requirements across standards, identifies requirements unique to each, and helps you avoid duplicating documentation where a single procedure can satisfy multiple obligations. An experienced ISO consultant can save substantial time when building this for the first time.

    Related ISOCentral resources

    Industry Insight

    Metal fabricators and erectors of structural steel buildings face regulatory requirements and have a need for quality systems.  Companies in the UK must address HSE regulations, while US companies are required to comply with OSHA. In this sector, businesses often seek AISC certification, which is a standard for quality used internationally. HSE (UK) & OSHA (USA), along with AISC can be managed in a single process-based management system in alignment with ISO 9001 thus saving time and resources.

    Source reference

    This article is based on: Freer, B. & Fiene, R. (2023). Regulatory Compliance and Quality Programs: Constraints and Opportunities for Integration. Journal of Regulatory Science, 11(1).

    Full paper available at: regsci-ojs-tamu.tdl.org/regsci/article/view/264.

    Brian Freer, PhD, is a Research Fellow at Washington State University, and Founder of Freer Consulting Co.; Richard Fiene, PhD, is a Research Psychologist at Pennsylvania State University.

    ISOCentral has summarized and interpreted the findings of this peer-reviewed paper for an SME audience. All interpretations and practical applications are our own.

    Key article citing this paper

    A data-driven methodology for monitoring Total Quality Management (TQM) systems in the Industry 4.0 era. Barragán, C.Z., Urraca, R., Sanz-Garcia, A. (2025). Computers & Industrial Engineering. Elsevier.

    Frequently Asked Questions

    What is an integrated management system?
    An integrated management system (IMS) is a single management framework that combines the requirements of multiple standards or regulatory programs into one coherent system, rather than maintaining separate systems for each. For example, an organization might integrate ISO 9001 (quality), ISO 14001 (environment), and ISO 45001 (health and safety) into a single IMS with shared processes for auditing, corrective action, document control, and management review. Integration reduces duplication, simplifies auditing, and makes it easier for staff to understand the system as a whole.
    What is the difference between an elements-based and a process-based management system?
    An elements-based management system is structured around the numbering and language of the standard or regulation it is designed to meet, so the documentation follows the clause structure of, for example, ISO 9001. A process-based management system is structured around how the organization actually operates, with standards and regulations mapped onto existing processes rather than the other way around. Process-based systems tend to be more usable by operational staff, better integrated into daily workflows, and more resilient when the organization changes structure or adds new compliance obligations.
    Can I integrate ISO 9001 with regulatory compliance requirements?
    Yes, and research suggests that doing so can significantly reduce compliance costs and improve overall outcomes. While formal regulatory alignment between ISO standards and government regulations is uncommon outside specific sectors (such as the FDA alignment of 21 CFR 820 with ISO 13485 for medical devices), organizations can proactively integrate regulatory requirements into their ISO management systems using cross-reference matrices. These tools map shared requirements between a regulation and a standard, identify unique requirements from each, and enable a single management system to address both. ISO consultants with sector-specific experience can help design this integration.
    What are the main benefits of integrating compliance and quality management?
    Research identifies six main benefits of management system integration: a shared resources approach where one procedure covers multiple requirements; easier day-to-day system management; faster internal and external audits; fewer separate review meetings; better understanding of the whole system across the organization; and reduced costs. The primary challenge, also identified by research, is cultural rather than technical: effective integration requires collaboration between managers who may previously have operated in separate compliance and quality silos.
    Share:

    Need Help With ISO Certification?

    Get quotes from accredited registrars and ISO experts.