Home Certification ISO 37001

ANTI-BRIBERY

ISO 37001 certification

An anti-bribery management system connects bribery-risk assessment with responsibilities, due diligence, controls and review. Describe the activities and business relationships in scope so the assessment can consider how your arrangements operate in practice.

AT A GLANCE

STANDARD REFERENCE

ISO 37001:2025

Anti-Bribery Management System

ASSESSMENT SUBJECT

Your management system

Certification applies to the agreed organizational scope.
Your application identifies the edition, activities and sites to be assessed.

UNDERSTAND THE STANDARD

What is ISO 37001 certification?

ISO 37001 addresses anti-bribery management systems. It concerns arrangements for identifying and managing bribery-related risk and responding to relevant concerns. Certification is not a guarantee that bribery has never occurred or will never occur in an organization.
Map the activities and relationships that need consideration. Intermediaries, purchasing decisions, projects, gifts and business relationships may raise different questions depending on the organization. A practical system connects its risk assessment with responsibilities and controls rather than relying only on a policy statement.

START WITH THE BOUNDARY

Make the scope clear.

Identify the entities, activities, locations and relevant relationships included in the proposed system. Explain how the organization controls or influences associated operations. Avoid describing a selected subsidiary’s system as though it automatically covers an entire corporate group.

FROM INTENT TO EVIDENCE

Show how your system works.

These are examples of relevant information, not a universal list of mandatory documents. The evidence depends on your activities and applicable requirements.

01

Bribery-risk assessment and the rationale for relevant controls.

02

Due diligence arrangements appropriate to the organization’s relationships.

03

Responsibilities, communication and routes for raising concerns.

04

Monitoring, investigation-related arrangements and improvement evidence where applicable.

A PRACTICAL EXAMPLE

Put the scope into context.

A business using a sales intermediary should be able to explain how the relationship is assessed, approved and monitored. A contract signature does not necessarily explain the ongoing decision process. This is an illustrative governance question, not a conclusion that any particular relationship is improper.
Use this example to prepare your own scope and evidence.

HOW CERTIFICATION WORKS

A clear route from enquiry to decision.

01

Scope & application

Describe the activities, sites and standard you want assessed.

02

Assessment planning

Agree arrangements based on the application and programme.

03

Audit & response

Demonstrate the system and address findings with evidence.

04

Decision & review

Certification follows a decision, with continuing assessment as applicable.
An application or completed audit does not guarantee certification.

EDITION & APPLICATION

Confirm the right basis for assessment.

The planning reference is ISO 37001:2025. Applicable amendments, transition arrangements and the edition for your application must be confirmed before assessment is agreed.
Check the official ISO publication information. Use the official publication record to check the edition and related amendments.

CONNECTED MANAGEMENT NEEDS

Considering several standards?

Shared processes can support a coordinated system. Explain the common boundaries and the differences.

FREQUENTLY ASKED QUESTIONS

ISO 37001: frequently asked questions

Clear answers before you take the next step.
No such claim should be made. Certification concerns the management system and does not replace the organization’s obligations or the role of relevant authorities. Specific legal questions need appropriate legal advice.
A policy sets expectations, but the assessment also needs relevant evidence of responsibilities, risk-based decisions, communication, monitoring and responses in practice.
Describe relevant business relationships and how responsibilities are managed. This helps establish an accurate scope; it does not imply that a particular relationship is improper.
Other systems may share responsibilities or processes with ISO 37001, but each retains its own requirements. Explain the intended standards, sites and boundaries when discussing an integrated assessment.
The scope, activities, personnel, locations and applicable programme determine the proposed assessment work. Readiness and responses to findings also affect timing. Request a quotation based on your actual organization.

START WITH YOUR ORGANIZATION

Discuss ISO 37001 with EQRM.

Tell us your activities, locations and ISO 37001 requirements. We’ll review availability and the scope of the proposed engagement.