ANTI-BRIBERY
ISO 37001 certification
An anti-bribery management system connects bribery-risk assessment with responsibilities, due diligence, controls and review. Describe the activities and business relationships in scope so the assessment can consider how your arrangements operate in practice.
AT A GLANCE
STANDARD REFERENCE
ISO 37001:2025
Anti-Bribery Management System
ASSESSMENT SUBJECT
Your management system
Certification applies to the agreed organizational scope.
Your application identifies the edition, activities and sites to be assessed.
UNDERSTAND THE STANDARD
What is ISO 37001 certification?
ISO 37001 addresses anti-bribery management systems. It concerns arrangements for identifying and managing bribery-related risk and responding to relevant concerns. Certification is not a guarantee that bribery has never occurred or will never occur in an organization.
Map the activities and relationships that need consideration. Intermediaries, purchasing decisions, projects, gifts and business relationships may raise different questions depending on the organization. A practical system connects its risk assessment with responsibilities and controls rather than relying only on a policy statement.
START WITH THE BOUNDARY
Make the scope clear.
Identify the entities, activities, locations and relevant relationships included in the proposed system. Explain how the organization controls or influences associated operations. Avoid describing a selected subsidiary’s system as though it automatically covers an entire corporate group.
FROM INTENT TO EVIDENCE
Show how your system works.
These are examples of relevant information, not a universal list of mandatory documents. The evidence depends on your activities and applicable requirements.
01
Bribery-risk assessment and the rationale for relevant controls.
02
Due diligence arrangements appropriate to the organization’s relationships.
03
Responsibilities, communication and routes for raising concerns.
04
Monitoring, investigation-related arrangements and improvement evidence where applicable.
A PRACTICAL EXAMPLE
Put the scope into context.
A business using a sales intermediary should be able to explain how the relationship is assessed, approved and monitored. A contract signature does not necessarily explain the ongoing decision process. This is an illustrative governance question, not a conclusion that any particular relationship is improper.
Use this example to prepare your own scope and evidence.
HOW CERTIFICATION WORKS
A clear route from enquiry to decision.
01
Scope & application
Describe the activities, sites and standard you want assessed.
02
Assessment planning
Agree arrangements based on the application and programme.
03
Audit & response
Demonstrate the system and address findings with evidence.
04
Decision & review
Certification follows a decision, with continuing assessment as applicable.
An application or completed audit does not guarantee certification.
EDITION & APPLICATION
Confirm the right basis for assessment.
The planning reference is ISO 37001:2025. Applicable amendments, transition arrangements and the edition for your application must be confirmed before assessment is agreed.
Check the official ISO publication information. Use the official publication record to check the edition and related amendments.
CONNECTED MANAGEMENT NEEDS
Considering several standards?
Shared processes can support a coordinated system. Explain the common boundaries and the differences.
FREQUENTLY ASKED QUESTIONS
ISO 37001: frequently asked questions
Clear answers before you take the next step.
Does ISO 37001 provide immunity from investigation or liability?
No such claim should be made. Certification concerns the management system and does not replace the organization’s obligations or the role of relevant authorities. Specific legal questions need appropriate legal advice.
Does a written anti-bribery policy prove that the system operates?
A policy sets expectations, but the assessment also needs relevant evidence of responsibilities, risk-based decisions, communication, monitoring and responses in practice.
Should intermediaries be mentioned in an application?
Describe relevant business relationships and how responsibilities are managed. This helps establish an accurate scope; it does not imply that a particular relationship is improper.
Can ISO 37001 be assessed with other standards?
Other systems may share responsibilities or processes with ISO 37001, but each retains its own requirements. Explain the intended standards, sites and boundaries when discussing an integrated assessment.
What affects the cost and timing of ISO 37001 certification?
The scope, activities, personnel, locations and applicable programme determine the proposed assessment work. Readiness and responses to findings also affect timing. Request a quotation based on your actual organization.
START WITH YOUR ORGANIZATION
Discuss ISO 37001 with EQRM.
Tell us your activities, locations and ISO 37001 requirements. We’ll review availability and the scope of the proposed engagement.