Many businesses run their quality management system in one place and their regulatory compliance activity somewhere else entirely. The ISO 9001 documentation is managed by the quality team. The health and safety records sit with the operations manager. The data protection records are owned by the IT department. The environmental compliance logs are filed in a folder nobody looks at until an inspection is due.
This is not unusual. It is, in fact, the default state for most organizations that have grown their compliance obligations incrementally over time. But it is expensive, risky, and largely unnecessary.
A 2023 paper published in the Journal of Regulatory Science by Brian Freer and Richard Fiene examines the relationship between regulatory compliance programs and quality management systems, identifies the structural problems that keep them separate, and makes a practical case for integration. This article summarizes their findings and translates them into terms relevant to UK, US, and Irish SMEs managing ISO certification alongside regulatory obligations.
The Core Argument: Two Systems Doing One Job
Freer and Fiene draw a useful distinction between regulatory compliance and quality programs. Regulatory compliance covers all government requirements an organization must meet. Quality programs cover standards, customer requirements, and other obligations where the organization must demonstrate conformance. ISO 9001, ISO 27001, and ISO 14001 fall into the quality program category in this framework.
In most organizations these two bodies of obligation are managed separately, despite overlapping significantly in practice. Both require documented processes. Both require evidence of conformance. Both require internal audit and management review. Both benefit from systematic measurement and continual improvement.
The authors argue that treating them as separate activities is not just inefficient but actively counterproductive. When regulatory compliance and quality management operate in separate silos, the measurement disciplines and continual improvement habits that quality programs develop rarely migrate to the compliance side. The result is a compliance program that meets minimum requirements but generates little learning or improvement, and a quality program that does not fully account for the regulatory context in which the business operates.
Regulatory compliance versus quality programs
Regulatory compliance: all government requirements facing an organization, exclusive of accounting, and the activities undertaken to conform to them.
Quality programs: customer, international, and national standards and other requirements where an organization is obligated to show conformance.
Source: Freer, B. & Fiene, R. (2023). Journal of Regulatory Science, 11(1).
The Five Constraints That Hold Organizations Back
Drawing on decades of management consulting practice, Freer and Fiene identify five structural characteristics that commonly prevent organizations from getting the most out of their management systems. These are described as drags on the optimization of management system implementation. Each is recognizable to anyone who has worked with compliance and quality programs in practice.
Constraint | What it looks like | Why it matters |
|---|---|---|
1. Passive acceptance of compliance targets | Accepting government-set requirements at face value without exploring what value additional data collection could provide | Organizations miss opportunities to go beyond minimum compliance and derive genuine business insight from the data they are already collecting |
2. Binary yes or no measurement | Building procedures and forms around pass or fail questions ("was the target met?") rather than continuous measurement | Binary systems obstruct the kind of measurement and trend analysis that drives genuine improvement |
3. Parallel silos | Maintaining separate systems for regulatory compliance and quality, each following the language and structure of its respective standard or regulation | Duplication of effort, inconsistent records, and missed opportunities to use quality program tools to improve compliance outcomes |
4. Narrative-based procedures | Writing procedures as dense blocks of text rather than process flowcharts and maps | Text-heavy procedures are harder to follow, less likely to be integrated into daily workflows, and more difficult to audit effectively |
5. Department rather than process ownership | Assigning compliance and quality responsibilities to departments rather than named individual process owners | When accountability sits with a department rather than a person, it is unclear who is responsible for a given process, and the system has to be restructured every time the organizational chart changes |
The fifth constraint, in particular, has direct implications for ISO-certified organizations. ISO 9001 Clause 5.3 and its equivalents in other management system standards require roles, responsibilities, and authorities to be defined and communicated. But defining responsibilities at the department level rather than the individual process owner level means that accountability is diffuse, audit evidence is harder to collect, and the system has to be restructured whenever the organization changes shape.
The fourth constraint, narrative-based procedures, is equally relevant. ISO 9001 and its High Level Structure equivalents do not prescribe a procedure format, but the research evidence reviewed by Freer and Fiene suggests strongly that process flowcharts and maps are more effective than text-based procedures for embedding processes into daily operations.
When Regulators and Standards Converge: The FDA Example
Freer and Fiene use a significant regulatory development as a case study for their argument. In 2022, the US Food and Drug Administration proposed aligning its Quality System Regulation for medical devices (21 CFR 820) with ISO 13485:2016, the international standard for medical device quality management. The proposal would achieve this alignment by incorporating ISO 13485 by reference into the regulation.
This is notable because regulations are not typically written in a process framework, let alone aligned with international standards. As the authors observe, regulations tend to be written as policy narratives listing requirements and end-state outcomes that organizations must achieve. Process-based standards like ISO 13485 take a different approach, allowing organizations to set their own metrics while requiring them to demonstrate their reasoning and engage in continual improvement.
The FDA move is significant for any organization operating in a regulated sector. It signals that the gap between regulatory compliance and quality program requirements is capable of being closed at the regulatory level, not just at the organizational level. For businesses outside medical devices, the lesson is that proactively building a management system capable of integrating regulatory and quality requirements positions an organization well for future regulatory developments.
In the UK, similar convergence is visible in the way GDPR data protection requirements overlap with ISO 27001 information security controls. In Ireland, public sector procurement frameworks are increasingly specifying ISO standards alongside statutory compliance requirements. The direction of travel is toward integration, not further separation.
A Practical Tool: Scoring Your Management System
One of the more practically useful contributions of the Freer and Fiene paper is a simple scoring framework that organizations can use to assess whether their management system would benefit from a move toward a process-based integrated approach. The framework involves three dimensions.
Dimension | What to assess | Score |
|---|---|---|
Regulatory complexity | How many regulations apply to your organization? How complicated are their requirements? | High and Complex, Medium and Standard, or Low and Simple |
System structure | Does your management system follow the numbering and language of the standard or regulation, or is it organized around your own processes? | Elements-based or Independent |
Procedure format | Are your procedures written primarily as blocks of text, or do they use process flowcharts and maps? | Primarily narrative or Primarily process |
Organizations that score High and Complex on regulatory complexity, Elements-based on system structure, and Primarily narrative on procedure format are, according to the authors, the strongest candidates for transitioning to a process-based integrated management system. The higher the complexity and the more elements-based and narrative the existing system, the greater the potential efficiency gain from integration.
For many UK and Irish SMEs pursuing ISO 9001 alongside sector-specific regulatory obligations, this combination is common. A construction company managing ISO 9001, CDM Regulations, and CHAS accreditation simultaneously is likely running three partially overlapping information management systems. A food manufacturer managing ISO 22000 alongside FDA or FSA regulatory requirements faces the same challenge.
What Integration Actually Delivers
Freer and Fiene draw on research by Carvalho et al. (2015) to outline the practical benefits organizations typically experience from management system integration. Six findings are particularly relevant to SMEs.
A shared resources approach: one procedure for auditing, purchasing, and corrective action rather than separate versions for each standard or regulatory framework.
Easier system management: team members find it significantly easier to navigate and maintain a single integrated system.
Faster audits: internal and external audits take less time when the evidence is organized around processes rather than scattered across separate compliance and quality systems.
Fewer meetings: with a single system providing a unified view of compliance and quality performance, the number of separate review meetings decreases.
Better understanding of the whole system: individuals develop a clearer picture of how their work connects to both compliance and quality outcomes.
Reduced costs: the efficiency gains across all of the above translate into measurable cost reduction.
The authors also note one significant challenge: the primary barrier to integration identified by Carvalho et al. is not technical but relational. It is a lack of collaboration between managers in different functional areas. In practice, the quality team and the compliance team, where these are distinct, may have developed separate habits, tools, and reporting structures over years. Integration requires both a structural change to the management system and a cultural change in how these teams work together.
Elements-Based Versus Process-Based: What the Difference Means in Practice
The distinction between elements-based and process-based management systems is central to the Freer and Fiene framework and worth unpacking for organizations that have not encountered the terminology before.
An elements-based system is structured around the numbering and language of the standard or regulation it is designed to meet. The quality manual has sections numbered 4.1, 4.2, 4.3 to match ISO 9001 clause structure. The procedures are titled using the standard terminology. The advantage of this approach is that it makes it straightforward to demonstrate clause-by-clause compliance to an auditor. The disadvantage is that it creates a system that speaks the language of the standard rather than the language of the business, which makes it harder for operational staff to engage with it and easier for it to become a documentation exercise rather than a genuine management tool.
A process-based system is structured around how the organization actually operates. Processes are identified, mapped, and owned by named individuals. The management system documentation describes how things actually get done, using the organization own language and sequencing. Standards and regulations are then mapped onto these processes, typically using cross-reference matrices, rather than the other way around.
The process-based approach aligns directly with what ISO 9001:2015 calls for. Clause 4.4 requires organizations to determine their key processes, their interactions, their inputs and outputs, and the criteria and methods needed to control them. An elements-based system can technically satisfy this clause; a genuinely process-based system embeds it.
What This Means for Your Organization
If you are currently pursuing ISO 9001 certification and also managing sector-specific regulatory obligations, the Freer and Fiene framework suggests a few practical considerations.
Map Your Full Compliance Landscape Before Building Your QMS
Before documenting your first procedure, identify all the legal and supra-legal requirements your organization faces. Legal requirements are government regulations. Supra-legal requirements include standards, customer contractual obligations, trade association requirements, and insurance conditions. Building this inventory first means you can design a management system that addresses all of them coherently, rather than bolting regulatory compliance onto a quality system that was designed without it in mind. The ISO cost calculator can help you scope the financial implications of adding standards into the mix.
Organize Around Processes, Not Standards
Design your management system around how your business actually operates, and then map the requirements of each standard and regulation onto your processes. This is more work upfront than building a system around the clause structure of ISO 9001, but it produces a system that your people can actually use and that scales naturally when new requirements are added.
Assign Individual Process Owners, Not Departmental Responsibilities
For each key process in your management system, assign a named individual as process owner. This person is responsible for the documented process, the evidence of compliance, and the continual improvement of that process. Accountability at the individual level is clearer, easier to audit, and more resilient to organizational change than departmental ownership.
Use Cross-Reference Matrices to Manage Multiple Standards
If your organization operates under multiple standards (for example, ISO 9001 and ISO 45001, or ISO 9001 and sector-specific regulatory requirements), a cross-reference matrix is a practical tool for managing the overlaps and gaps. The matrix maps shared requirements across standards, identifies requirements unique to each, and helps you avoid duplicating documentation where a single procedure can satisfy multiple obligations. An experienced ISO consultant can save substantial time when building this for the first time.
Related ISOCentral resources
Industry Insight
Metal fabricators and erectors of structural steel buildings face regulatory requirements and have a need for quality systems. Companies in the UK must address HSE regulations, while US companies are required to comply with OSHA. In this sector, businesses often seek AISC certification, which is a standard for quality used internationally. HSE (UK) & OSHA (USA), along with AISC can be managed in a single process-based management system in alignment with ISO 9001 thus saving time and resources.
Source reference
This article is based on: Freer, B. & Fiene, R. (2023). Regulatory Compliance and Quality Programs: Constraints and Opportunities for Integration. Journal of Regulatory Science, 11(1).
Full paper available at: regsci-ojs-tamu.tdl.org/regsci/article/view/264.
ISOCentral has summarized and interpreted the findings of this peer-reviewed paper for an SME audience. All interpretations and practical applications are our own.
Key article citing this paper
A data-driven methodology for monitoring Total Quality Management (TQM) systems in the Industry 4.0 era. Barragán, C.Z., Urraca, R., Sanz-Garcia, A. (2025). Computers & Industrial Engineering. Elsevier.
