ISO 37001 specifies requirements for an anti-bribery management system. Certification gives public buyers, partners and lenders independent evidence that you have implemented reasonable and proportionate measures to prevent, detect and respond to bribery.
Key Requirements
| Clause | Topic | In practice |
|---|---|---|
| 4 | Context | Bribery risk assessment; scope |
| 5 | Leadership | Governing body oversight, anti-bribery policy, independent compliance function |
| 7 | Support | Competence, employment controls, training |
| 8 | Operation | Due diligence; financial and non-financial controls; business associates; gifts and hospitality; raising concerns; investigations |
| 9–10 | Evaluation and improvement | Monitoring, internal audit, reviews, corrective action |
Who Needs It?
Government contractors, construction and EPC firms, oil & gas suppliers, traders using agents, healthcare suppliers, and any organization asked about anti-corruption controls.
The Certification Process
- Application: share your scope, sites and headcount; we confirm the route and audit time.
- Proposal and agreement: written proposal and certification agreement.
- Stage 1 audit: documentation and readiness review.
- Stage 2 audit: on-site evaluation of implementation and effectiveness.
- Certification decision: made by a competent reviewer who was not on the audit.
- Surveillance and recertification: annual surveillance, recertification every three years.
What Auditors Focus On
- A bribery risk assessment that reflects your markets and partners.
- Independence and resources of the compliance function.
- Proportionate due diligence on high-risk business associates.
- Financial controls, concern-raising and investigations.
FAQs
Does ISO 37001 certification prove an organization is bribery-free?
No. It confirms that reasonable, proportionate controls are in place and operating.
Is ISO 37001 the same as ISO 37301?
No. ISO 37301 covers compliance management in general; ISO 37001 is specific to anti-bribery.