ISO 37001 certification: anti-bribery management guide
What an anti-bribery management system does, why organizations seek assurance, and how to prepare for certification.
Overview
What an anti-bribery management system does, why organizations seek assurance, and how to prepare for certification.
What it is
ISO 37001 provides certifiable requirements for preventing, detecting, and responding to bribery. Its risk-based controls include leadership, an anti-bribery function, risk assessment, financial and non-financial controls, due diligence, gifts and hospitality, reporting, investigations, training, monitoring, and corrective action.
Why it matters
Certification may support partner due diligence, tender requirements, governance, and a defensible compliance programme. It does not prove bribery never occurred, create immunity, or replace anti-corruption laws, reporting duties, investigations, or enforcement decisions.
How to obtain it or demonstrate compliance
- Define the legal entity, sites, products, services, and processes inside the certification scope.
- Buy or lawfully access the current standard and perform a documented gap assessment.
- Implement objectives, responsibilities, controls, records, competence, and corrective-action processes.
- Complete internal audits and a management review, then close identified gaps.
- Select a competent certification body—preferably accredited for the standard and sector—and verify its status.
- Complete the stage 1 and stage 2 audits, correct nonconformities, and maintain certification through surveillance and recertification.
What to review
- Confirm the current edition, certification scope, sites, legal entities, exclusions, and certificate validity.
- Map applicable laws, regulator duties, contracts, customer requirements, and sector-specific controls separately from the voluntary standard.
- Test whether policies operate in practice and whether records support each material claim before the external audit.
- Describe the standard, edition, scope, certification body, accreditation, and limitations accurately in procurement and marketing.
What to do next
Treat certification as an operating system, not a document project. Assign accountable owners, measure performance, investigate failures, correct root causes, and keep evidence current between audits.
Official sources and further reading
- ISO 37001 — Anti-bribery management systems — International Organization for Standardization
- Certification — ISO does not perform certification — International Organization for Standardization
This article provides general educational information and is not legal advice. Rules and outcomes depend on your facts and jurisdiction. Consult a qualified local professional before acting.
Jurisdiction
International standard or scheme; accreditation, recognition, and legal effect vary by country and market
Review status
Editorially reviewed by the LegalGPT Editorial Team. Not independently reviewed by a licensed attorney.