What is ISO 37001?

ISO 37001 is the international standard for an Anti-Bribery Management System (ABMS) — a structured, risk-based way to prevent, detect and respond to bribery, whether it involves your own people, your business partners or third parties acting on your behalf. The current edition, ISO 37001:2016, is the version certification bodies audit against today.

The idea behind it is simple. Bribery risk is rarely spread evenly across a business — it concentrates in certain markets, deals, functions and relationships. ISO 37001 asks you to understand where your exposure really sits, put proportionate controls in place, and run a management system that keeps those controls working and evidenced over time. A distinctive feature is the role of a compliance function with real authority and independence to oversee the program.

Because it shares the same high-level structure as ISO 9001 and other modern ISO standards, it fits neatly alongside quality and other management systems. Certification is granted by an accredited certification body after a two-stage audit, and the certificate is typically valid for three years with annual surveillance visits in between. It is important to be clear about what certification means: it shows you have a reasonable, well-run system in place — it is not a guarantee that bribery will never occur.

Who needs ISO 37001?

ISO 37001 is not, in itself, a law — but it directly supports compliance with anti-corruption legislation and has become a recognized way to demonstrate that an organization takes bribery prevention seriously. If your customers, regulators, investors or partners keep asking how you manage corruption risk, this is often the answer they are looking for. It is especially valuable for:

  • Organizations operating in higher-risk markets or sectors such as construction, infrastructure, energy, defence and extractives.
  • Companies that rely on agents, intermediaries and third parties to win or deliver business.
  • Firms bidding for public-sector or international contracts where anti-bribery assurance is expected.
  • Multinationals exposed to laws with long reach, such as major anti-corruption statutes.
  • Suppliers to large enterprises whose procurement now includes anti-bribery due diligence.
  • Any organization that wants to protect its reputation and show good governance to investors and boards.

A useful test: if a bribery incident — even by a single employee or agent — could trigger legal exposure, lost contracts or serious reputational damage, ISO 37001 is worth having.

What ISO 37001 requires

ISO 37001 follows the familiar management-system pattern, so the core clauses will feel recognizable if you already hold ISO 9001. In plain terms, it asks you to:

  • Understand your context and interested parties and define the scope of your anti-bribery management system.
  • Run a bribery risk assessment — identify where you are exposed, across markets, deals, functions and third parties, and evaluate it consistently.
  • Show leadership and set an anti-bribery policy that top management and the governing body genuinely own, with a clear stance of zero tolerance.
  • Establish a compliance function with appropriate authority, resources and independence to oversee the program.
  • Apply proportionate controls — due diligence on partners and personnel, controls over gifts, hospitality and donations, financial and non-financial controls, and clauses in contracts.
  • Enable people to raise concerns — training and awareness, and a confidential way to report suspected bribery without fear of reprisal.
  • Investigate and respond to bribery concerns, and monitor, audit and review the whole system through internal audits and management review.

Crucially, the depth of each control should match your risk. A low-risk domestic firm and a multinational operating in high-risk markets can both be compliant with very different implementations. The standard repeatedly uses the word reasonable and proportionate — it is about deliberate, evidenced control, not box-ticking.

Why get ISO 37001 certified

The strongest reason many of our clients pursue ISO 37001 is protection: it helps demonstrate due diligence. If a bribery incident ever occurs, evidence that you had a recognized, well-run anti-bribery system in place can matter a great deal to regulators, courts, boards and investors. It is a visible sign that you took reasonable steps rather than turning a blind eye.

There is a commercial side too. Enterprise and public-sector procurement increasingly includes anti-corruption due diligence, and a certificate can replace repeated custom questionnaires and reassure partners who are themselves exposed to strict anti-bribery laws. In some tenders and partnerships it is becoming a condition of doing business.

Beyond that, certification gives you a genuine reduction in risk. Going through a real bribery risk assessment surfaces exposures you did not know you had — an unvetted agent, unchecked hospitality spending, no safe way to report concerns — and forces them to be owned and closed. Internally, integrity stops being a slogan and becomes a repeatable system with clear ownership, an independent compliance function and a review rhythm.

How QSE gets you certified

We have spent more than 30 years helping organizations get certified, with 900+ clients certified and a 100% first-time pass rate at the certification audit. Our 10-Step Approach turns ISO 37001 from an intimidating framework into a clear, week-by-week path.

We start by understanding your business, your markets and your real bribery exposure — not a generic template. Then we run a gap assessment against ISO 37001, facilitate the bribery risk assessment with your team, and help you stand up a right-sized management system and compliance function so the decisions are genuinely yours. Our documentation is deliberately lean: a single-level system, typically under 200 pages, written for the people who actually use it rather than to impress an auditor.

From there we help you implement the controls — due diligence, gifts and hospitality, reporting channels, training — run internal audits and a management review, then support you through both Stage 1 and Stage 2 of the certification audit. A typical project runs 4–9 months depending on your size, footprint and starting maturity. When we are done, you hold the certificate — and you own a system your team can actually run afterward, without depending on us forever.

Common pitfalls we help you avoid

  • Treating it as a paperwork policy. A code of conduct in a drawer is not a management system. Auditors look for controls that actually operate. We build a system that works day to day.
  • A risk assessment that is too generic. Bribery risk is uneven; a template that ignores your real markets and third parties will not hold up. We facilitate it so it reflects your true exposure.
  • A compliance function with no real authority. If the role cannot act independently, the audit will notice. We help you give it genuine standing and resources.
  • Ignoring third parties and agents. Much bribery risk sits with intermediaries. Weak due diligence on partners is a common gap we help you close.
  • No safe way to raise concerns. Without a trusted, confidential reporting channel, problems stay hidden. We help you build one people will actually use.
  • Over-documenting. Thick manuals no one reads become findings, not strengths. Lean, usable documentation passes audits and survives real life.
  • Assuming the certificate is a shield against all wrongdoing. It demonstrates reasonable controls, not perfection. We set the right expectation and keep the system credible.