COMPLIANCE
ISO 37301 certification
A compliance management system connects relevant obligations with ownership, operating processes, monitoring and response. Explain how the organization identifies changes and acts on concerns across the activities proposed for certification.
AT A GLANCE
STANDARD REFERENCE
ISO 37301:2021
Compliance Management System
ASSESSMENT SUBJECT
Your management system
Certification applies to the agreed organizational scope.
Your application identifies the edition, activities and sites to be assessed.
UNDERSTAND THE STANDARD
What is ISO 37301 certification?
ISO 37301 addresses compliance management systems: the way an organization identifies relevant obligations, allocates responsibilities and evaluates its compliance arrangements. Certification does not amount to a finding that the organization complies with every law or contract in every jurisdiction.
Begin by explaining how obligations enter the organization and how changes are identified. A register is useful only when responsibilities, decisions and operational processes connect to it. Different functions may interpret the same obligation differently unless there is a clear method for resolving questions.
START WITH THE BOUNDARY
Make the scope clear.
Describe the entities, activities and locations included and the relationships with functions outside the scope. A group policy may apply widely while the actual management system under assessment has narrower boundaries. Explain both the shared arrangements and the limits.
FROM INTENT TO EVIDENCE
Show how your system works.
These are examples of relevant information, not a universal list of mandatory documents. The evidence depends on your activities and applicable requirements.
01
The method used to identify and evaluate applicable obligations.
02
Assigned responsibilities and relevant communication.
03
Monitoring, escalation and response to identified concerns.
04
Evaluation of the system and evidence that lessons influence decisions.
A PRACTICAL EXAMPLE
Put the scope into context.
When a business introduces a new service, an existing list of obligations may no longer describe the operating context. The practical question is how the change is reviewed before delivery starts and who has authority to resolve uncertainties. This example is educational and does not identify a legal requirement for any specific country.
Use this example to prepare your own scope and evidence.
HOW CERTIFICATION WORKS
A clear route from enquiry to decision.
01
Scope & application
Describe the activities, sites and standard you want assessed.
02
Assessment planning
Agree arrangements based on the application and programme.
03
Audit & response
Demonstrate the system and address findings with evidence.
04
Decision & review
Certification follows a decision, with continuing assessment as applicable.
An application or completed audit does not guarantee certification.
EDITION & APPLICATION
Confirm the right basis for assessment.
The planning reference is ISO 37301:2021. Applicable amendments, transition arrangements and the edition for your application must be confirmed before assessment is agreed.
Check the official ISO publication information. Use the official publication record to check the edition and related amendments.
CONNECTED MANAGEMENT NEEDS
Considering several standards?
Shared processes can support a coordinated system. Explain the common boundaries and the differences.
FREQUENTLY ASKED QUESTIONS
ISO 37301: frequently asked questions
Clear answers before you take the next step.
How is this different from ISO 37001?
ISO 37001 focuses on anti-bribery management. ISO 37301 addresses compliance management more broadly. There may be shared processes, but one certificate should not be presented as the other.
Does a compliance register demonstrate the whole system?
A register can help identify obligations, but it should connect to assigned responsibilities, operational decisions, monitoring and responses when concerns arise.
Can a group policy cover subsidiaries outside the certificate scope?
A policy may apply across a group while a certificate covers selected entities or activities. The certification claim must follow the stated scope, not the widest reach of a policy.
Can ISO 37301 be assessed with other standards?
Other systems may share responsibilities or processes with ISO 37301, but each retains its own requirements. Explain the intended standards, sites and boundaries when discussing an integrated assessment.
What affects the cost and timing of ISO 37301 certification?
The scope, activities, personnel, locations and applicable programme determine the proposed assessment work. Readiness and responses to findings also affect timing. Request a quotation based on your actual organization.
START WITH YOUR ORGANIZATION
Discuss ISO 37301 with EQRM.
Tell us your activities, locations and ISO 37301 requirements. We’ll review availability and the scope of the proposed engagement.