Home/Services/Certification/ISO 37001:2016

ISO 37001:2016

International standard for Anti-Bribery Management Systems (ABMS).

Overview
What is ISO 37001?

ISO 37001 is an internationally recognized Anti-Bribery Management System standard designed to help organizations prevent, detect, respond to, and address bribery. The standard provides a structured framework for establishing anti-bribery policies, conducting bribery risk assessments, implementing controls, performing due diligence on business relationships, raising awareness, investigating concerns, and continually improving anti-bribery practices.

ISO 37001 does not guarantee that bribery will never occur. Instead, it helps organizations demonstrate that reasonable and proportionate measures have been implemented to manage bribery risks and support ethical business conduct. The standard addresses bribing of public officials and private individuals, facilitation payments, gifts and hospitality, and bribery by and on behalf of associated persons — including agents, intermediaries, subsidiaries, joint venture partners, and supply chain participants.

The standard is aligned with the ISO High Level Structure and can be integrated with ISO 9001, ISO 37301 (Compliance Management Systems), and other management system standards. It can be applied by organizations of any size, sector, or industry — and is scalable to the nature and extent of the bribery risks faced by the organization implementing it.

Key Themes
What does the standard focus on?
Anti-Bribery Governance
The standard establishes requirements for anti-bribery governance structures, policies, accountabilities, and oversight arrangements, embedding anti-bribery management into the organization’s overall governance and management decision-making at both governing body and operational level.
Ethical Business Conduct
ISO 37001 requires organizations to establish and communicate a clear commitment to ethical conduct through anti-bribery policies, behavioral expectations, and a culture in which bribery is neither tolerated nor facilitated across the organization and its associated persons.
Bribery Risk Assessment
Organizations must conduct structured assessments of their exposure to bribery risk, taking into account country risk, sector risk, transaction types, business relationships, and the nature of activities conducted by the organization and its associated persons, including agents and intermediaries.
Due Diligence
The standard requires appropriate due diligence on transactions, projects, and business relationships where bribery risk has been identified, enabling organizations to assess and manage risks associated with third parties, agents, intermediaries, joint venture partners, and other associated persons.
Financial and Non-Financial Controls
ISO 37001 addresses the implementation of financial and non-financial controls designed to prevent, detect, and address bribery, including controls over gifts, hospitality, facilitation payments, donations, sponsorships, and procurement and contracting processes.
Reporting and Investigation
Organizations must establish confidential reporting mechanisms enabling individuals to raise bribery concerns without fear of retaliation, and must maintain processes for investigating concerns and responding appropriately to confirmed or suspected bribery incidents.
Leadership Commitment
The standard places specific obligations on governing bodies and top management to demonstrate active commitment to anti-bribery management, including the adoption of an anti-bribery policy, allocation of appropriate resources, and direct oversight of the anti-bribery compliance function.
Continual Improvement
A systematic commitment to improving the effectiveness of the anti-bribery management system through performance measurement, monitoring, internal audit, management review, and the systematic application of corrective actions in response to nonconformities and incidents.
Applicability
Who typically implements ISO 37001?
Government Contractors
Organizations supplying goods and services to government and public sector clients, where the risk of bribery in procurement processes and contract performance is elevated and where certification may be required or expected as a supplier qualification criterion.
State-Owned Enterprises
Public sector companies and government-controlled entities operating in commercial markets, where governance of anti-bribery risks is subject to heightened public, regulatory, and legislative scrutiny.
Financial Institutions
Banks, investment managers, insurance companies, and other regulated financial organizations where anti-bribery controls form part of broader compliance, anti-money-laundering, and governance obligations.
Construction Companies
Construction and engineering organizations operating domestically and internationally, where exposure to bribery risk — particularly in permitting, public procurement, and contract award processes — is recognized across all major anti-corruption frameworks.
Energy and Infrastructure Organizations
Organizations operating in the energy, utilities, and infrastructure sectors, where long-duration projects, complex supply chains, natural resource concessions, and government interactions create elevated bribery risk profiles.
Healthcare Organizations
Healthcare providers, pharmaceutical companies, and medical device manufacturers operating in environments where interactions with public officials and healthcare professionals create sector-specific anti-bribery risks, including in procurement and product approval processes.
Manufacturing Companies
Manufacturing organizations operating international supply chains, procurement programs, and sales activities in markets where corruption risk is a material consideration for governance, compliance, and commercial sustainability.
Professional Services Firms
Consulting, legal, accounting, and advisory organizations providing services to clients across multiple sectors and jurisdictions, where anti-bribery controls are a component of professional standards, client expectations, and regulatory obligations.
Technology Companies
Technology developers, integrators, and service providers operating in markets where procurement processes, licensing arrangements, and sales activities create interactions with public officials or parties in positions of authority over contracting decisions.
Organizations in Elevated Risk Environments
Any organization operating in geographies, sectors, or transactional contexts where corruption and bribery risk has been identified as elevated, and where a structured, governed anti-bribery management framework is appropriate to the scale and nature of that risk.
Benefits
Why organizations pursue certification
Improved Anti-Bribery Governance
A structured ABMS establishes clear accountability for anti-bribery management at governance and operational levels, embedding anti-bribery oversight into organizational decision-making, management processes, and the responsibilities of the governing body.
Enhanced Organizational Integrity
Documented policies, behavioral expectations, training, and communication requirements support a culture of integrity in which ethical business conduct is reinforced consistently across the organization and its associated persons.
Improved Risk Management
Systematic bribery risk assessment, due diligence processes, and transaction-specific controls enable organizations to identify, evaluate, and manage bribery risks in a structured, documented, and auditable manner proportionate to the risk profile of the organization.
Greater Stakeholder Confidence
Independent certification demonstrates to customers, investors, partners, procurement authorities, and other stakeholders that the organization has implemented and maintains an independently assessed anti-bribery management framework.
Support for Ethical Business Practices
Anti-bribery policies, controls on gifts and hospitality, facilitation payment procedures, and due diligence processes help embed ethical business practices into commercial activities, contracting, and third-party relationships across the supply chain.
Improved Due Diligence Processes
Structured due diligence requirements for business partners, agents, intermediaries, and joint venture partners reduce exposure to third-party bribery risk and support more informed commercial decision-making in high-risk markets and relationships.
Enhanced Regulatory Confidence
An independently assessed ABMS may be recognized by regulators, prosecutors, and enforcement authorities as evidence of genuine commitment to prevention, which can be relevant to enforcement decisions, deferred prosecution agreements, and the assessment of liability.
Strengthened Reputation
Certification supports the organization’s reputation for integrity and ethical conduct among clients, partners, employees, investors, and other stakeholders in an environment of increasing transparency, accountability, and ESG expectations.
Continual Improvement
Systematic monitoring, internal audit, management review, and corrective action processes ensure that the anti-bribery management system remains effective, current, and responsive to evolving bribery risks, regulatory developments, and business contexts.
Regulatory Context
Is ISO 37001 certification required?

ISO 37001 certification is generally voluntary. There are no general legal requirements mandating ISO 37001 certification in any major jurisdiction, although anti-bribery and anti-corruption legislation imposes substantive obligations on organizations and individuals in most markets. Anti-bribery and anti-corruption obligations arise under a range of domestic and international instruments, including the UK Bribery Act, the US Foreign Corrupt Practices Act, the OECD Convention on Combating Bribery of Foreign Public Officials, and domestic anti-corruption legislation across jurisdictions.

Several of these instruments include provisions recognizing the existence of adequate anti-bribery procedures as a relevant factor in assessing liability, enforcement decisions, or the availability of statutory defenses. In this context, an independently assessed ISO 37001 management system may be referred to as evidence of reasonable and proportionate anti-bribery measures in enforcement proceedings or regulatory assessments.

In public procurement, infrastructure concessions, and regulated sectors, ISO 37001 certification is increasingly cited in supplier qualification requirements, codes of conduct, and contractual obligations. Some procuring authorities and major corporate clients treat certification as evidence of baseline anti-bribery capability. Organizations operating in high-risk industries or markets may pursue certification to demonstrate commitment to integrity, support supplier qualification, and provide governance assurance to investors, lenders, and joint venture partners.

Certification Journey
How certification works
01
Application
The organization submits an application and scope information for certification. Exelera reviews the scope of activities, geographic footprint, sites, and certification requirements.
02
Application Review
Exelera reviews the application, confirms the certification scope, assesses the nature of the organization’s activities and bribery risk profile, identifies any specific requirements, and prepares the certification proposal and audit program.
03
Stage 1 Audit
Evaluation of anti-bribery management system documentation, bribery risk assessment processes, anti-bribery policy documentation, governance arrangements, and organizational readiness for Stage 2 conformance assessment.
04
Stage 2 Audit
On-site evaluation of the implementation and effectiveness of the ABMS, including anti-bribery controls, due diligence processes, reporting mechanisms, training and awareness activities, investigation procedures, and conformity with all applicable standard requirements.
05
Certification Decision
Independent review of the audit report and findings by a Certification Decision Maker not involved in the audit, followed by a formal certification decision.
06
Certificate Issuance
Following a positive certification decision, Exelera issues the certificate and publishes the organization on the public certification register.
07
Surveillance Audit — Year 1
Scheduled surveillance visit conducted no later than 12 months after the certification decision to verify continued conformance, assess the operation of anti-bribery controls, and review corrective actions from prior audits.
08
Surveillance Audit — Year 2
Continued verification of ABMS implementation, risk assessment currency, due diligence processes, reporting mechanism effectiveness, and the application of corrective actions from prior audit cycles.
09
Recertification Audit
Comprehensive reassessment of the full anti-bribery management system scope conducted prior to renewal of the certification cycle at the end of year three.
10
Certification Renewal
Following a successful recertification audit and positive certification decision, a new three-year certification cycle commences.
FAQ
Common questions
ISO 37001 is an international standard for Anti-Bribery Management Systems. It specifies requirements for establishing, implementing, maintaining, and improving an anti-bribery management system and provides guidance to help organizations prevent, detect, and respond to bribery. The standard is intended to help organizations implement reasonable and proportionate anti-bribery measures, demonstrate commitment to ethical business conduct, and provide assurance to governing bodies, senior management, investors, business partners, and other stakeholders that the organization is actively managing bribery risks in a structured and independently assessed manner.
No. ISO 37001 does not guarantee that bribery will not occur. No management system standard can guarantee the elimination of risk. The standard is designed to help organizations implement reasonable and proportionate measures to prevent, detect, and respond to bribery. Certification demonstrates that an anti-bribery management system meeting the requirements of the standard has been assessed by an independent certification body — not that bribery has been or can be entirely prevented. The standard explicitly acknowledges this limitation in its scope.
ISO 37001 can be implemented by any organization of any size, sector, or ownership structure — including private companies, public sector organizations, government agencies, state-owned enterprises, non-governmental organizations, and not-for-profit entities. The standard is designed to be scalable and adaptable to the size of the organization and the nature and extent of the bribery risks it faces. A small organization with limited resources can implement ISO 37001 proportionately to its specific risk profile and operational context.
Yes. ISO 37001 is applicable to organizations of any size. The standard is designed to be scalable, and Exelera adapts the audit program to reflect the size, complexity, and risk profile of the organization being assessed. Smaller organizations should not expect a proportionally lighter burden in meeting the substantive requirements of the standard, but audit duration and documentation expectations are calibrated to reflect their scale and operational context. The key determining factor is the nature and extent of bribery risk rather than organizational size alone.
ISO 37001 provides a structured management system framework within which an organization’s anti-bribery and anti-corruption activities can be governed, documented, implemented, and independently assessed. It establishes requirements for risk assessment, due diligence, controls, training, reporting mechanisms, investigation procedures, and management review — providing a comprehensive and auditable basis for anti-bribery programs. Certification against the standard provides independent evidence that the anti-bribery management system has been assessed as meeting internationally recognized requirements, which can support governance programs, compliance initiatives, and stakeholder reporting.
The time required depends on the size of the organization, the complexity of its activities, its geographic footprint, and the maturity of its existing anti-bribery policies, risk assessment processes, and controls. For an organization that has established documented anti-bribery procedures and controls, the process from initial application to certificate issuance typically takes between three and six months. Larger organizations with more complex operations, multiple jurisdictions, significant third-party relationships, or early-stage anti-bribery documentation may require a longer program.
Following initial certification, surveillance audits are conducted annually — with the first surveillance no later than 12 months after the certification decision and the second no later than 24 months. A full recertification audit is required at the end of the three-year certification cycle before the certificate can be renewed.
ISO 37001 certificates are valid for three years from the date of the certification decision, subject to satisfactory completion of annual surveillance audits. Certification lapses if surveillance audits are not completed within the required timeframe, or if the certificate is suspended or withdrawn due to nonconformity or other grounds.
Certification transfers are possible in most cases. Exelera will review the existing certification, audit history, and current conformance status as part of the transfer assessment. Transfer audits are typically shorter than initial certification audits, reflecting the documented history of conformance. Contact Exelera for specific guidance on the transfer process and the information required to initiate a transfer review.
Applications can be submitted through the Exelera website or by contacting the certification team directly. The application process involves providing information about the organization’s scope of activities, geographic footprint, sites, employee headcount, and existing anti-bribery management documentation. Exelera will review the application and prepare a certification proposal for consideration.
Related Standards
Standards commonly implemented alongside ISO 37001