Skip to main content
Category: Compliance Programs

ISO 37301

Also known as: ISO 37301:2021, ISO 37301 Compliance Management Systems
Simply put

ISO 37301 is an international standard that sets out how an organization can build and run a compliance management system (CMS). It offers a structured way to establish, implement, evaluate, maintain, and improve the processes an organization uses to meet its compliance obligations. As a voluntary standard, adopting it is a matter of choice rather than a legal requirement, though organizations may seek certification against it.

Formal definition

ISO 37301:2021 is the first-edition international standard specifying requirements and providing guidelines for establishing, developing, implementing, evaluating, maintaining, and improving an effective compliance management system (CMS). It provides a framework through which an organization can systematically identify and address its compliance obligations. As a certifiable requirements standard, its provisions are expressed in a way that can support conformity assessment; however, adoption is voluntary and does not, in itself, constitute a legal or regulatory mandate. It typically sits within the organization's broader governance and management-system architecture and does not displace binding law, regulation, or sector-specific obligations, which vary by jurisdiction and entity type. This entry is educational and not legal, audit, or compliance advice.

Why it matters

Compliance obligations rarely arrive in a single, tidy list. They accumulate across statutes, regulations, contractual commitments, and voluntary undertakings, and they shift as an organization enters new markets or lines of business. ISO 37301 matters because it offers a recognized, structured way to organize the processes an organization uses to identify and meet those obligations, rather than relying on ad hoc or personality-driven arrangements. For boards and compliance leaders, a standardized compliance management system can make it easier to demonstrate that compliance is being managed deliberately and consistently, and to evaluate and improve that management over time.

Because ISO 37301 is a certifiable requirements standard, its provisions are written in a way that can support conformity assessment, which allows an organization to seek third-party certification if it chooses. This can be useful for signaling the maturity of a compliance program to regulators, business partners, or other stakeholders. It is important to be clear, however, about what certification does and does not represent: it reflects conformity with the standard's requirements at the time of assessment, not a guarantee of compliance with any particular law or an absence of misconduct.

Equally important is what ISO 37301 is not. It is a voluntary standard, and adopting it is a matter of organizational choice rather than a legal mandate. It does not displace binding law, regulation, or sector-specific obligations, and those requirements continue to vary by jurisdiction and entity type. Organizations should treat the standard as a framework for structuring compliance management, not as a substitute for understanding and meeting the specific legal duties that apply to them.

Who it's relevant to

Chief Compliance Officers and Compliance Functions
Compliance leaders are typically the primary users of ISO 37301, since it provides a structured framework for establishing, evaluating, and improving the processes their function operates. It can help articulate how obligations are identified and managed and provide a reference point for assessing the maturity of the compliance program. It does not, however, define the specific legal obligations that apply; those must still be determined for each jurisdiction and entity.
Boards and Board Committees
Boards and their relevant committees hold oversight responsibility for compliance and may find that a recognized compliance management system supports their ability to satisfy themselves that compliance is being managed systematically. Adopting or certifying against the standard is generally a management decision informed by the board's risk and oversight expectations; the standard supports oversight but does not transfer operational compliance duties to the board.
Internal Audit and Assurance Functions
Assurance providers may use the standard's requirements as a reference framework when evaluating whether a compliance management system has been designed and is operating as intended. Because the standard's provisions are structured to support conformity assessment, they can inform audit criteria, though internal audit's role remains independent evaluation rather than ownership or operation of the compliance system itself.
General Counsel and Legal Functions
Legal teams are often involved in identifying the binding obligations a compliance management system must address and in advising on how a voluntary standard interacts with mandatory requirements. ISO 37301 provides a structure for managing obligations but does not itself define legal duties, which vary by jurisdiction and sector and require independent legal analysis.

Inside ISO 37301

Compliance Management System (CMS) Framework
ISO 37301 sets out requirements and guidance for establishing, developing, implementing, evaluating, maintaining, and improving an effective compliance management system. It is structured around the ISO high-level structure common to management system standards, addressing context, leadership, planning, support, operation, performance evaluation, and improvement.
Voluntary Certifiable Standard
ISO 37301 is a voluntary international standard, not a law or regulation. It is designed to be certifiable, meaning an organization can seek third-party certification of its compliance management system against the standard, though certification is optional and not legally required in any jurisdiction.
Leadership and Compliance Culture
The standard emphasizes the role of the governing body and top management in demonstrating leadership and commitment, and in fostering a culture of compliance. It generally distinguishes governance-level oversight responsibilities from management's operational responsibility for running the system.
Risk-Based Approach to Compliance Obligations
The standard calls for identifying compliance obligations and assessing the associated compliance risks, then designing controls proportionate to those risks. This reflects a risk-based rather than a purely rules-checklist approach.
Compliance Function and Roles
ISO 37301 addresses the establishment of a compliance function with appropriate authority, independence, and resources, and describes the assignment of roles and responsibilities across the governing body, management, and the compliance function.
Performance Evaluation and Continual Improvement
The standard incorporates monitoring, measurement, analysis, evaluation, internal audit, and management review, supporting a Plan-Do-Check-Act cycle aimed at continual improvement of the compliance management system.

Common questions

Answers to the questions practitioners most commonly ask about ISO 37301.

Does ISO 37301 certification mean an organization is legally compliant or protected from enforcement?
No. ISO 37301 is a voluntary international standard specifying requirements for a compliance management system; it is not itself a law and certification does not establish legal compliance. Certification generally indicates that an organization has a management system meeting the standard's requirements, not that it has satisfied every applicable statute, regulation, or listing rule in a given jurisdiction. Whether certification carries any mitigating weight with regulators or courts depends on the jurisdiction, the sector, and the facts. Organizations should treat this entry as educational and consult qualified legal and compliance advisers regarding their specific obligations.
Is ISO 37301 the same as ISO 31000, and does adopting one satisfy the other?
No. The two standards address different disciplines and are not interchangeable. ISO 37301 concerns compliance management systems, focused on identifying and meeting compliance obligations. ISO 31000 provides guidance on risk management principles and processes and is not designed for certification. Compliance and risk management are related but distinct functions with different ownership and objectives, so adopting one does not automatically satisfy the aims of the other. Organizations typically consider how the two interact rather than substituting one for the other.
How does ISO 37301 allocate roles between the governing body, top management, and the compliance function?
The standard generally distinguishes oversight responsibilities from operational execution. It typically expects the governing body and top management to demonstrate leadership and commitment, set the tone, and provide resources, while a designated compliance function carries out day-to-day activities such as identifying obligations and monitoring. The precise allocation depends on the entity's structure, size, and applicable governance requirements in its jurisdiction. Organizations should map these expectations to their own board, committee, management, and assurance arrangements rather than assuming a single fixed model.
What is typically involved in scoping a compliance management system to align with ISO 37301?
Scoping generally begins with identifying the organization's compliance obligations, which may include binding legal requirements as well as voluntary commitments the organization has chosen to adopt, and then defining the boundaries of the management system. The standard's process-oriented approach typically involves understanding the organization's context, interested parties, and applicable obligations before establishing objectives and controls. The appropriate scope depends on the entity type, sector, and jurisdictions in which it operates, and on management's own judgment about materiality and resources.
How can an organization assess whether its compliance controls are working as intended under an ISO 37301 aligned system?
A management system aligned with the standard generally provides for monitoring, measurement, evaluation, and internal audit of the compliance function. Assessing controls typically distinguishes whether a control is appropriately designed from whether it is operating effectively over time; these are separate questions and should not be conflated. Assurance activities and their independence, and how findings feed into management review and continual improvement, are usually part of this evaluation. The depth and frequency of assessment depend on the organization's risk profile and its own judgment.
Does an organization need external certification to benefit from ISO 37301?
Not necessarily. An organization can use the standard as a reference framework to structure or benchmark its compliance management system without pursuing formal third-party certification. Certification is one option that may support external assurance or stakeholder confidence, but the decision generally depends on the organization's objectives, stakeholder expectations, sector practice, and cost-benefit considerations. Whether certification adds value is a matter of the entity's own judgment and circumstances.
How does ISO 37301 relate to an organization's broader governance and assurance arrangements?
The standard is generally intended to be integrated with an organization's existing governance, risk, and management structures rather than operated in isolation. In practice, a compliance management system typically interacts with the board's oversight role, management's operational responsibilities, and independent assurance functions, while keeping those roles distinct. How it fits alongside other frameworks the organization uses depends on its structure, sector, and applicable requirements, and this entry is educational rather than prescriptive advice.

Common misconceptions

ISO 37301 is a legal requirement that organizations must comply with.
ISO 37301 is a voluntary international standard, not binding law. It does not itself impose legal obligations; an organization's actual legal duties arise from applicable statutes, regulations, and listing rules in the relevant jurisdictions. Adopting or certifying to the standard is a management choice, not a legal mandate.
Certification to ISO 37301 guarantees that an organization is compliant with all applicable laws or immune from enforcement.
Certification generally indicates that a compliance management system has been assessed as conforming to the standard's requirements at a point in time. It does not guarantee actual legal compliance, prevent violations, or provide a defense; regulators and courts assess conduct on their own terms, and outcomes depend on facts and jurisdiction.
ISO 37301 makes compliance solely the responsibility of the compliance function or replaces the roles of the board and management.
The standard typically allocates distinct responsibilities: the governing body provides oversight and sets the tone, management owns the operation of the system, and the compliance function supports, advises, and monitors. It does not shift the board's oversight duty to management or make the compliance function accountable for functions it does not own.

Best practices

Map your organization's actual compliance obligations to applicable laws, regulations, and voluntary commitments by jurisdiction and sector before designing controls, rather than treating the standard as a substitute for identifying those obligations.
Clarify and document the distinct roles of the governing body, top management, and the compliance function, ensuring oversight duties sit with the board and operational ownership sits with management.
Apply a risk-based approach: assess compliance risks, prioritize based on likelihood and impact, and design controls that are proportionate to the risks identified.
Establish independence, authority, and adequate resources for the compliance function so it can advise, monitor, and escalate without undue influence.
Build in performance evaluation through monitoring, internal audit, and management review, and use the results to drive continual improvement rather than treating certification as a one-time achievement.
Treat any ISO 37301 certification as evidence of system conformity at a point in time, not as proof of legal compliance, and validate that both control design and operating effectiveness are tested over time.