ISO 37001
ISO 37001 is an international standard that sets out how an organization can build a management system to prevent, detect, and address bribery. It provides a structured, voluntary framework of requirements and guidance rather than a law, and organizations can adopt it to strengthen their anti-bribery controls. The most recent version is ISO 37001:2025, which updates the original 2016 edition.
ISO 37001 is a voluntary international management-system standard specifying requirements and providing guidance for establishing, implementing, maintaining, reviewing, and improving an anti-bribery management system (ABMS). Consistent with the ISO management-system model, it typically addresses matters such as anti-bribery policy, leadership and governance commitment, risk-based due diligence, controls, monitoring, and continual improvement. The standard generally defines bribery as the offering, promising, giving, accepting, or soliciting of an undue advantage of any value, whether directly or indirectly. It is a certifiable standard that organizations may adopt voluntarily; it is not itself binding law and does not replace applicable anti-bribery or anti-corruption legislation, which varies by jurisdiction. The original edition, ISO 37001:2016, was superseded by ISO 37001:2025, which reportedly includes enhanced provisions. This entry is educational and not legal, audit, or compliance advice; whether and how to implement or certify against the standard depends on an organization's facts, sector, and jurisdiction.
Why it matters
Bribery exposes organizations to legal liability, financial loss, and reputational damage, and it typically implicates multiple anti-corruption laws that vary by jurisdiction. ISO 37001 matters because it offers a structured, internationally recognized framework that an organization can adopt to build and demonstrate an anti-bribery management system (ABMS). By setting out requirements for policy, governance commitment, risk-based due diligence, controls, and monitoring, the standard gives organizations a common reference point for organizing anti-bribery efforts that might otherwise be fragmented across functions.
Because ISO 37001 is a certifiable standard, an organization can seek third-party certification as evidence that it has implemented an ABMS aligned with the standard's requirements. This can be relevant when responding to counterparties, regulators, or business partners who expect a demonstrable anti-bribery program. It is important to keep the standard's role in perspective, however: ISO 37001 is voluntary and is not itself binding law. Certification does not guarantee that bribery will not occur, nor does it substitute for compliance with applicable anti-bribery and anti-corruption legislation, which differs by jurisdiction, sector, and entity type.
For governance and compliance professionals, the value of ISO 37001 lies in its function as a benchmarking and organizing tool rather than a legal shield. Whether and how to implement or certify against the standard depends on an organization's specific facts, risk profile, and regulatory environment, and it should be evaluated alongside, not in place of, the legal requirements that apply to the organization.
Who it's relevant to
Inside ISO 37001
Common questions
Answers to the questions practitioners most commonly ask about ISO 37001.