Skip to main content
Category: Anti-Bribery and Corruption

ISO 37001

Also known as: Anti-bribery management systems standard, ISO 37001:2016, ISO 37001:2025
Simply put

ISO 37001 is an international standard that sets out how an organization can build a management system to prevent, detect, and address bribery. It provides a structured, voluntary framework of requirements and guidance rather than a law, and organizations can adopt it to strengthen their anti-bribery controls. The most recent version is ISO 37001:2025, which updates the original 2016 edition.

Formal definition

ISO 37001 is a voluntary international management-system standard specifying requirements and providing guidance for establishing, implementing, maintaining, reviewing, and improving an anti-bribery management system (ABMS). Consistent with the ISO management-system model, it typically addresses matters such as anti-bribery policy, leadership and governance commitment, risk-based due diligence, controls, monitoring, and continual improvement. The standard generally defines bribery as the offering, promising, giving, accepting, or soliciting of an undue advantage of any value, whether directly or indirectly. It is a certifiable standard that organizations may adopt voluntarily; it is not itself binding law and does not replace applicable anti-bribery or anti-corruption legislation, which varies by jurisdiction. The original edition, ISO 37001:2016, was superseded by ISO 37001:2025, which reportedly includes enhanced provisions. This entry is educational and not legal, audit, or compliance advice; whether and how to implement or certify against the standard depends on an organization's facts, sector, and jurisdiction.

Why it matters

Bribery exposes organizations to legal liability, financial loss, and reputational damage, and it typically implicates multiple anti-corruption laws that vary by jurisdiction. ISO 37001 matters because it offers a structured, internationally recognized framework that an organization can adopt to build and demonstrate an anti-bribery management system (ABMS). By setting out requirements for policy, governance commitment, risk-based due diligence, controls, and monitoring, the standard gives organizations a common reference point for organizing anti-bribery efforts that might otherwise be fragmented across functions.

Because ISO 37001 is a certifiable standard, an organization can seek third-party certification as evidence that it has implemented an ABMS aligned with the standard's requirements. This can be relevant when responding to counterparties, regulators, or business partners who expect a demonstrable anti-bribery program. It is important to keep the standard's role in perspective, however: ISO 37001 is voluntary and is not itself binding law. Certification does not guarantee that bribery will not occur, nor does it substitute for compliance with applicable anti-bribery and anti-corruption legislation, which differs by jurisdiction, sector, and entity type.

For governance and compliance professionals, the value of ISO 37001 lies in its function as a benchmarking and organizing tool rather than a legal shield. Whether and how to implement or certify against the standard depends on an organization's specific facts, risk profile, and regulatory environment, and it should be evaluated alongside, not in place of, the legal requirements that apply to the organization.

Who it's relevant to

Chief Compliance Officers
Compliance leaders may use ISO 37001 as a reference framework to structure or benchmark an anti-bribery program, covering policy, risk-based due diligence, controls, and monitoring. They should treat the standard as a voluntary tool that complements, rather than replaces, the specific anti-bribery and anti-corruption laws applicable to their organization.
Boards and Audit or Risk Committees
Boards and their committees generally hold oversight responsibility for the organization's approach to bribery risk. ISO 37001's emphasis on leadership and governance commitment can inform how a board evaluates management's anti-bribery efforts, though the board's role remains oversight rather than operational implementation of the management system.
General Counsel
Legal counsel may consider ISO 37001 when advising on how the organization structures and evidences its anti-bribery controls. They should be clear that the standard is not binding law and does not substitute for compliance with applicable anti-bribery legislation, which varies by jurisdiction.
Internal Auditors and Assurance Functions
Assurance functions may assess whether an anti-bribery management system is designed and operating consistently with ISO 37001's requirements, whether or not the organization pursues formal certification. Their work provides independent evaluation and should be distinguished from management's ownership of the controls themselves.
Organizations Engaging Third Parties or Partners
Entities that face counterparty or partner expectations around anti-bribery controls may find ISO 37001 relevant, since certification can serve as evidence of an implemented management system. Whether to adopt or certify against the standard depends on the organization's facts, sector, and risk profile.

Inside ISO 37001

Anti-Bribery Management System (ABMS)
The core subject of the standard: a structured, documented system of policies, procedures, and controls designed to help an organization prevent, detect, and respond to bribery. ISO 37001 specifies requirements for establishing, implementing, maintaining, and improving such a system, but it is a voluntary international standard rather than a legal requirement.
Anti-bribery policy and leadership commitment
The standard generally calls for a documented anti-bribery policy and demonstrated commitment from the governing body and top management. It typically distinguishes the oversight role of the governing body from the operational implementation responsibilities of management.
Compliance function and oversight
ISO 37001 generally contemplates a designated anti-bribery compliance function with appropriate authority and independence to oversee the ABMS. This reflects the compliance discipline rather than internal audit assurance or enterprise risk management, which remain distinct.
Bribery risk assessment
A recurring assessment of the organization's exposure to bribery risk, generally informing the design of proportionate controls. The standard's approach is risk-based, so controls are expected to be calibrated to identified risks rather than applied uniformly.
Due diligence and controls
Provisions typically addressing due diligence on transactions, projects, business associates, and personnel, alongside financial and non-financial controls, gifts and hospitality controls, and controls over third parties acting on the organization's behalf.
Reporting, investigation, and response
Mechanisms for raising concerns (including provisions intended to protect those who report in good faith), and procedures for investigating and responding to suspected or actual bribery.
Monitoring, review, and continual improvement
Requirements generally covering performance monitoring, internal audit of the ABMS, management review, and corrective action, reflecting the plan-do-check-act structure common to ISO management system standards.
Certification and conformity
Organizations may seek third-party certification of conformity with ISO 37001, though certification is optional and is not itself a legal mandate or a guarantee against bribery occurring.

Common questions

Answers to the questions practitioners most commonly ask about ISO 37001.

Does ISO 37001 certification prove that an organization is free of bribery or guarantee it will not face enforcement action?
No. ISO 37001 is a management system standard that specifies requirements for establishing, implementing, and maintaining an anti-bribery management system; it is designed to help an organization prevent, detect, and respond to bribery. Certification indicates that a conformity assessment body has assessed the management system against the standard's requirements at a point in time, not that bribery has been or will be eliminated. It does not provide assurance that no bribery has occurred, and it does not confer legal immunity. Whether an anti-bribery program mitigates enforcement exposure depends on applicable law, the facts of a given matter, and how regulators or prosecutors in the relevant jurisdiction evaluate compliance efforts. Certification may be one factor an organization can point to, but it is not determinative, and treatment varies by jurisdiction.
Is ISO 37001 a legal requirement that organizations must adopt?
Generally, no. ISO 37001 is a voluntary international standard, not binding law. It is not a statute, regulation, or listing rule, and adopting or certifying to it is typically a matter of organizational choice rather than legal obligation. That said, in some contexts a customer, business partner, sector body, or public procurement process may require or favor certification as a contractual or eligibility condition. Adoption of the standard also does not replace the need to comply with applicable anti-bribery and anti-corruption laws, which exist independently and vary by jurisdiction. Organizations should treat ISO 37001 as a framework that can support, but does not substitute for, compliance with binding legal requirements.
How does ISO 37001 relate to an organization's existing compliance program and other management systems?
ISO 37001 is generally intended to be integrated with, rather than operate separately from, an organization's broader compliance and governance arrangements. It shares the common high-level structure used across many ISO management system standards, which is designed to facilitate alignment with systems such as those addressing quality or information security. In practice, an organization can typically embed the standard's anti-bribery requirements within its existing compliance framework, internal control environment, and risk management processes. How the standard maps onto an existing program depends on the organization's size, sector, risk profile, and current controls, and the integration approach is a matter for management judgment. This description is educational and not legal or compliance advice.
Who within an organization is responsible for the anti-bribery management system under ISO 37001?
Responsibilities are typically distributed across governance and management roles, and the standard is generally structured to reflect this separation. The governing body and top management are ordinarily expected to demonstrate leadership and commitment and to set the anti-bribery policy and overall direction, consistent with an oversight role. Day-to-day design, implementation, and operation of controls generally sit with management. The standard also contemplates a designated anti-bribery compliance function with responsibility and authority for overseeing the management system's operation, though the specifics of how that role is structured depend on the organization. Assurance activities, such as internal audit, are generally distinct from those who own and operate the controls. The precise allocation should reflect the organization's structure and applicable governance expectations.
What role does risk assessment play in implementing ISO 37001?
Risk assessment is generally a foundational element. The standard is typically built around identifying and assessing the organization's exposure to bribery so that controls can be designed and prioritized proportionately to that exposure. This often involves considering the nature of the organization's activities, sectors, geographies, business relationships, and transactions. Distinguishing risk concepts matters here: assessing exposure before controls is different from evaluating the risk that remains after controls are applied, and both likelihood and impact are typically considered. The output of a bribery risk assessment generally informs the scope and rigor of due diligence, controls, and monitoring. How an organization conducts and documents this assessment is a matter of methodology and judgment, and it should be revisited as circumstances change.
How is the effectiveness of an ISO 37001 anti-bribery management system maintained over time?
Maintaining effectiveness generally relies on ongoing monitoring, review, and improvement rather than a one-time implementation. The standard typically contemplates activities such as monitoring performance, conducting internal audits, management review, and taking corrective action where deficiencies are found. It is generally useful to distinguish whether controls are appropriately designed from whether they are operating effectively in practice, as a well-designed control can still fail in execution. Where certification is pursued, it is generally subject to periodic surveillance and recertification by the conformity assessment body, but such activities occur at points in time and do not provide continuous assurance. The frequency and depth of monitoring depend on the organization's risk profile and resources, and this description is educational rather than audit or compliance advice.

Common misconceptions

Certification to ISO 37001 makes an organization legally compliant with all anti-bribery laws.
ISO 37001 is a voluntary international standard, not binding law. Conformity or certification does not substitute for compliance with applicable anti-bribery statutes and regulations, which vary by jurisdiction. Whether a certified system satisfies any given legal expectation depends on the facts and the relevant law, and this entry is educational rather than legal advice.
Implementing ISO 37001 guarantees that bribery will not occur, or provides a legal defense if it does.
The standard is designed to help reduce and manage bribery risk on a reasonable and proportionate basis; it does not eliminate residual risk. Whether a compliance program is treated favorably by authorities or courts depends on jurisdiction-specific rules and the circumstances, and cannot be assumed from certification alone.
ISO 37001 covers all forms of fraud, corruption, and financial crime.
The standard's scope is focused on bribery. Broader financial crime, fraud, money laundering, and other misconduct are typically addressed by separate frameworks and legal requirements and fall outside the standard's stated scope.

Best practices

Treat ISO 37001 as one input into a broader compliance program and confirm alignment with applicable anti-bribery laws in each relevant jurisdiction, seeking qualified legal advice where obligations are uncertain.
Ground the ABMS in a documented, periodically refreshed bribery risk assessment so that controls are proportionate to identified exposures rather than applied uniformly.
Clarify accountability by distinguishing the governing body's oversight role, management's implementation responsibilities, the compliance function's oversight of the ABMS, and internal audit's independent assurance.
Ensure the anti-bribery compliance function has sufficient authority, resources, and independence, and establish clear reporting lines to the governing body or a relevant committee.
Extend due diligence and controls to third parties and business associates, and document the rationale for the level of scrutiny applied to each relationship.
Operate confidential reporting channels with protection for good-faith reporters, and use monitoring, internal audit, and management review to test both control design and operating effectiveness and to drive continual improvement.