Governance · Published

ISO 37001
Anti-bribery management.

A management system to prevent, detect and respond to bribery through proportionate policy, due diligence, controls and reporting.

At a glance

What this edition means.

Current edition2025
Previous edition2016
AmendmentNone listed
Revision statusCurrent edition

Publication: 2025-02. Verified against the publisher record on 25 September 2026. A future revision can change the current status.

Practical application

Start with how work happens.

Identify exposure in transactions and relationships, conduct due diligence where warranted, train relevant roles and make reporting safe.

First four moves

  1. Map exposure by activity and geography
  2. Set proportionate controls
  3. Train and communicate
  4. Investigate concerns and improve

Clause implementation

Move from requirement to working evidence.

The main clauses below are implementation prompts for ISO 37001:2025. Clauses 1–3 establish scope, references and vocabulary; use the purchased edition for exact terms and all subclauses. Each evidence example is a possible record, not a claim that one named document is mandatory.

4

Context and scope

How to meet the intent. Define boundaries, interested parties, relevant requirements, process interfaces and what is outside scope. Revisit scope after material change. Identify bribery exposure in activities, locations, transactions, partners and interested parties.

What to create or retain. Bribery risk assessment; Scope and process map

Verification. Choose a recent real transaction, check the owner and requirement, then record whether the control achieved its intended outcome. Use the licensed edition to check the exact applicability and subclauses.

5

Leadership and policy

How to meet the intent. Assign accountability, approve a policy that reflects real priorities and make responsibilities clear to the people doing the work. Establish anti-bribery policy, governance, compliance function and reporting routes.

What to create or retain. Due diligence records; Policy and role assignment

Verification. Choose a recent real transaction, check the owner and requirement, then record whether the control achieved its intended outcome. Use the licensed edition to check the exact applicability and subclauses.

6

Planning

How to meet the intent. Decide which risks, opportunities and objectives matter; set owners, resources, measures and review dates. Assess bribery risk and plan proportionate objectives, due diligence and controls.

What to create or retain. Financial and non-financial controls; Risk and objective plan

Verification. Choose a recent real transaction, check the owner and requirement, then record whether the control achieved its intended outcome. Use the licensed edition to check the exact applicability and subclauses.

7

Support

How to meet the intent. Provide people, competence, communication, infrastructure and controlled information needed for reliable delivery. Provide resources, training, awareness, communication and protected information.

What to create or retain. Reports and response records; Competence and document records

Verification. Choose a recent real transaction, check the owner and requirement, then record whether the control achieved its intended outcome. Use the licensed edition to check the exact applicability and subclauses.

8

Operation

How to meet the intent. Run the planned controls in live work, manage suppliers and changes, and retain enough evidence to show what happened. Apply due diligence, financial and non-financial controls, gifts rules and speak-up procedures.

What to create or retain. Bribery risk assessment; Operational control and change records

Verification. Choose a recent real transaction, check the owner and requirement, then record whether the control achieved its intended outcome. Use the licensed edition to check the exact applicability and subclauses.

9

Performance evaluation

How to meet the intent. Monitor outcomes, audit against defined criteria and use management review to make documented decisions. Monitor controls and concerns, investigate where appropriate, audit and review leadership decisions.

What to create or retain. Due diligence records; Monitoring, audit and review decisions

Verification. Choose a recent real transaction, check the owner and requirement, then record whether the control achieved its intended outcome. Use the licensed edition to check the exact applicability and subclauses.

10

Improvement

How to meet the intent. Respond to failures, address causes, check effectiveness and revise the system using what was learned. Correct weak controls and verify that response reduces the identified exposure.

What to create or retain. Financial and non-financial controls; Nonconformity and effectiveness checks

Verification. Choose a recent real transaction, check the owner and requirement, then record whether the control achieved its intended outcome. Use the licensed edition to check the exact applicability and subclauses.

Evidence to examine

Look for working arrangements.

01

Bribery risk assessment

Check whether this is current, owned and used in decisions or delivery.

02

Due diligence records

Check whether this is current, owned and used in decisions or delivery.

03

Financial and non-financial controls

Check whether this is current, owned and used in decisions or delivery.

04

Reports and response records

Check whether this is current, owned and used in decisions or delivery.

Next step

Use a tool to frame discussion.

Source and scope

Know what you are reading.