IMS Risk Management Procedure Template & Guide (ISO 9001 + ISO 14001 + ISO 45001)

IMS Risk Management Procedure Template & Guide (ISO 9001 + ISO 14001 + ISO 45001)

$349
A complete, editable risk, aspect and hazard identification procedure for one integrated management system to ISO 9001, ISO 14001:2026 and ISO 45001. Three scopes reconciled location by location, three deliberately different rating scales, and nineteen integration decisions recorded.

The gap this closes

An organization certified to all three standards runs one management system on paper and, almost always, three identification exercises in practice — living in three places, rated on three scales nobody compares, reviewed on three cycles.

A complete, editable risk, aspect and hazard identification procedure for one integrated management system to ISO 9001:2015, ISO 14001:2026 and ISO 45001:2018 — written as a finished working document, not an outline.

The three scopes are not one scope

The ISO 14001 scope is declared by the organization and may legitimately exclude sites, activities or entities. The ISO 9001 scope may exclude requirements that do not apply, and whole product lines. ISO 45001 has no equivalent latitude: it applies to workers under the organization's control, and you cannot exclude a location because it is small, leased or awkward.

So there is a predictable class of location inside OH&S and outside the EMS — the sales office, the service depot, the customer site. And there is the product line excluded from the quality scope whose manufacture still generates aspects and hazards. Nothing is wrong with any of that. Not knowing is. Section 2.0 reconciles all three, location by location, and it takes about two hours.

Two identification routes, one shared spine

Hazards and aspects are found by watching the work as it is performed. Quality risk is not visible on a walkway — it lives in process performance data, a supplier's change-notification clause, a customer requirement, a repeat nonconformity. This procedure runs both routes into one shared assessment and treatment spine, which is what makes an integrated procedure honest rather than three procedures stapled together.

Strictness runs in different directions

ISO 45001 is strictest on method: the assessment methodology and criteria held as documented information, maintained and retained; the hierarchy of controls mandatory; the participation of non-managerial workers required. ISO 14001:2026 is strictest on criteria and life cycle. ISO 9001 requires the least at Clause 6.1 — and contributes the obligation that makes the document necessary, at Clause 4.4.1 c).

Appendix D records nineteen divergences, six of them genuinely three-way, each with the position adopted as house standard and the alternative rejected with its reasoning — followed by a sign-off table. Where the standards disagree, which did you follow and why? That is the answer, written down, before three certification bodies ask it separately.

What is in it

  • Section 2.0 — three-way scope reconciliation, location by location, with every gap named and what covers it.
  • Section 5.0 — Developing this process in your organization, which with Appendix E is the documented methodology ISO 45001 Clause 6.1.2.2 requires, maintained and retained, applied as the house standard to all three systems.
  • Three distinct rating scales — injury and ill health, the environmental receptor, and the intended result at risk — deliberately different in length so a rating cannot be transcribed between them.
  • The full scope of ISO 45001 Clause 6.1.2.1, including how work is organized, workload, work hours, harassment and bullying — the elements a walkway inspection cannot see.
  • The hierarchy of controls, applied to environmental controls too at four levels, with any rejection of a higher level recorded and approved.
  • Worker participation designed rather than asserted — how a concern is raised without going through a manager, and protection from detriment.
  • Established environmental significance criteria judged against the receptor, with life cycle perspective and the communication requirement.
  • A quality risk register, the ISO 9001 proportionality test, and integration into QMS processes.
  • Combinations across all three systems, including the single conditions that trigger entries in two or three registers at once.
  • Figure 1 — process interaction map, required once ISO 9001 is in scope.
  • Appendix A — the registers, kept apart. Appendix B — action and effectiveness record carrying the hierarchy level. Appendix C — desk-level work instruction with worked examples.
  • Appendix D — the integration decision record: nineteen divergences, nineteen decisions, one sign-off table.
  • Appendix E — determination worksheet. Appendix F — legal obligations outside the standards, including a ready-to-sign written certification of hazard assessment.

Buying ahead of the ISO 9001:2026 launch

ISO has confirmed that ISO 9001:2026 launches on Wednesday 16 September 2026, with a three-year transition expected. Buy this template now and the aligned revision is sent to you free when MSI issues it. You get a working procedure today and the updated one when it matters, without buying twice.

Specification

StandardsISO 9001:2015, ISO 14001:2026 and ISO 45001:2018
ClausesISO 9001 Clauses 4.4.1 and 6.1; ISO 14001 Clause 6.1; ISO 45001 Clause 6.1.2
Length81 pages — the most detailed in the family
FormatMicrosoft Word (.docx), fully editable
DeliveryInstant download
LicensePerpetual, non-exclusive license for your organization to edit, rebrand and adopt across your own sites
UpdatesISO 9001:2026 launches 16 September 2026. Buy now and the aligned revision is sent to you free when MSI issues it — no second purchase, no upgrade fee

Who it is for

Organizations holding all three certificates, and consultants supporting integrated management systems. Particularly useful for multi-site operations where the three scopes were never compared, and for any organization that walks the site once and records the results in one merged table.

Not the right combination? Every variant in this family covers one certification combination, so you buy the one document that matches your certificates rather than assembling it from singles.

The full documentation package

This procedure is one document in a wider system. If you are building or rebuilding the whole integrated documentation set rather than filling a single gap, the packages below collect the procedures and guides, and work out considerably cheaper than buying them individually.

Prefer to be invoiced? If your organization buys on a purchase order rather than by card, email info@msi-international.com or call 760-434-9141 and we will raise an invoice. Tell us which templates or package you need and we will send payment terms the same working day.

Written from what repeats. Diana Lynn has attended more than 200 certification and surveillance audits across 28 years, supporting more than 80 certifications and training more than 600 professionals. These templates encode the structural weaknesses that show up again and again, not one organization's approach generalized. Management Systems International is veteran-owned and female-owned. Questions: 760-434-9141.