ISO 37001 Certification: Anti-Bribery Management System
- Other sectors
- Finance
- Government
- Healthcare
- Automotive and aerospace
- Food and beverage
- Maritime
- Energy
A structured approach to improve trust and transparency, manage risks and safeguard your company's reputation.
ISO 37001 Certification: Anti-Bribery Management System
Certification of your anti-bribery management system to ISO 37001 demonstrates your organisation's commitment to building a transparent, ethical and accountable business. This commitment helps to safeguard your reputation, enhance stakeholder confidence, and strengthen your position as a responsible and trustworthy partner.
ISO 37001 provides a structured framework for establishing and maintaining an effective anti-bribery management system. By applying its requirements, your organisation can improve its ability to identify potential bribery risks and implement controls proportionate to its level of exposure. This demonstrates that effective measures are in place and sustained over time, supporting responsible business conduct and long-term organisational resilience.
What is the ISO 37001 standard?
ISO 37001 is a management system standard applicable to organisations in the public, private and not-for-profit sectors. It sets out requirements for establishing, implementing, maintaining and continually improving an anti-bribery management system. The standard focuses on leadership commitment, risk-based thinking, proportionate controls, and continual improvement. While it specifically addresses bribery, organisations may choose to extend the scope of their management system to include related issues such as fraud or money laundering.
The standard addresses both bribery by the organisation and bribery of the organisation by external parties. It covers situations involving employees, as well as business associates acting on the organisation's behalf or in connection with its activities. The standard provides a systematic approach to managing bribery risks and supports compliance with applicable anti-bribery legislation and voluntary commitments.
ISO 37001 helps you achieve:
- Clear roles, responsibilities and oversight of anti-bribery activities
- A structured approach to identify and address bribery-related exposure
- More consistent application of controls across processes and functions
- Improved due diligence on activities, projects, business associates and transactions
- Continual improvement of anti-bribery measures over time
The standard promotes a risk-based, process-driven approach and is built on ISO's Harmonised Structure (HS). This provides a consistent framework, enabling seamless integration with other management system standards such as ISO 9001 for quality management, ISO 37301 for compliance management systems, and ISO/IEC 27001 for information security management.
Value of ISO 37001 certification
Certification to ISO 37001 by an independent third party demonstrates that your anti-bribery management system meets the requirements of the standard and that you can effectively apply anti-bribery principles across your operations. It provides credible assurance that your organisation has established structured, well-governed measures to identify and manage bribery-related risks.
As a result, you get:
- Increased trust and credibility with customers, partners and investors in high-risk or regulated markets
- Stronger ability to compete where anti-bribery assurance is expected or required
- Reduced exposure to legal, financial and reputational consequences of bribery
- Independent insights from external auditors to identify gaps and strengthen controls
- Greater transparency and integrity across your value chain through verified controls
- More effective reporting, monitoring, investigation, review and corrective action processes
- Clear demonstration of commitment to ethical conduct for stakeholders and employees
While certification of your management system to ISO 37001 cannot guarantee that bribery will not occur, it verifies that you have a structured and effective management system designed to reduce the likelihood of such situations and support an appropriate response if they arise.
Customers
Certificates
People trained annually
Countries
How to get certified to ISO 37001
To become certified, you first have to an anti-bribery management system compliant with ISO 37001. DNV is an accredited certification body for ISO 37001 and ready to support your journey, from initial training to gap-analysis and certification.
As a DNV customer, you also get access to a suite of digital tools that can help you ensure compliance, continually improve and manage your entire certification journey with us.
Learn how to get started and be certified
-
-
Obtain the standard:
Get a licensed copy of the relevant standard and familiarise yourself with the requirements to decide whether certification or registration to this standard is appropriate for your organisation.
-
Review available literature and apply digital tools
Explore available literature, guidance from the standard owners (e.g. ISO/TS 9002 for ISO 9001, ISO 14004 for ISO 14001) and digital sources and tools that can support implementation. As a DNV customer, you also get access to tailored tools that can help you.
-
-
-
Assemble a team and define strategy:
Implementing a management system should be a strategic decision for the entire organisation. Senior management must be engaged in the decision, committed to it, and involved in shaping the system. They decide the business strategy the management system should support. In addition, you need a dedicated team to develop and implement your management system.
-
Determine competence needs:
First, your team responsible for implementing and maintaining the management system needs a thorough understanding of the chosen standards. Later, the wider organisation needs awareness training. DNV offers a variety of public and in-house courses worldwide that meet competence development needs at all levels of your organisation.
-
-
-
Review consultant options:
Independent consultants can advise on a workable, realistic and cost-effective implementation strategy if you do not already have this competence or capacity in-house.
-
Develop management system documentation:
Decide on an appropriate platform for your documented information (e.g. software, process map- or SharePoint-based). The right platform is important to ensure effective management, communication and implementation.
-
-
-
Determine, manage and document processes:
First, identify key processes – what they are, how they work and how they interact. Each process should have a clear purpose, defined responsibilities and expected outputs. The level of documented information needed depends on the organisation’s size, complexity and the importance of each process, but it must include the relevant processes and other documented information needed to deliver intended outcomes and comply with the chosen standard’s requirements.
-
Implement management system:
Clear communication and appropriate competence training are essential. During the implementation phase, you will work to ensure that your organisation operates in line with defined and documented processes. Once this is achieved, you can demonstrate the system’s compliance and effectiveness.
-
-
-
Select a certification body/registrar:
Selecting the right certification body or registrar can make a difference throughout your certification journey. DNV offers a trusted partnership approach, a risk-based approach and a range of free digital tools to help you manage your certification journey before, during and after the audit.
-
Consider a pre-audit gap analysis:
Consider a preliminary evaluation by your certification body or registrar to identify and correct non-conformities before starting the official certification process. The purpose is to identify areas of non-conformance or weakness, allowing you to address them before the official certification process begins.
-
ISO 37001 - FAQ
-
ISO 37001 is the international standard for establishing, implementing, maintaining and continually improving an anti-bribery management system. It provides a structured and globally recognised framework to help organisations prevent, detect and respond to bribery in a consistent and proportionate manner.
The standard focuses specifically on bribery and is applicable to organisations of any size, sector or location. It addresses both bribery committed by the organisation and bribery directed at it, including situations involving employees or business associates acting on its behalf.
-
Achieving ISO 37001 certification begins with leadership commitment, clear implementation objectives, and the development of appropriate competence and awareness across the organisation. You need to establish an anti-bribery management system that reflects your organisational context, legal obligations and exposure to bribery risks, supported by proportionate controls and documented processes.
Once the system is in place, internal audits and management reviews help to confirm readiness for certification. An independent third party, such as DNV, then assesses whether your anti-bribery management system meets the requirements of ISO 37001.
While certification cannot guarantee that bribery will not occur, it demonstrates that you have a structured and compliant system in place to reduce the likelihood of such incidents and to respond appropriately should they arise.
-
ISO 37001 clause 4.5 requires organisations to carry out a systematic and documented bribery risk assessment. Its purpose is to identify, analyse and evaluate bribery risks that could affect the organisation, ensuring that controls remain appropriate to the level of exposure.
The clause requires organisations to understand both the nature and extent of their bribery risks by considering internal and external factors, legal obligations, and the expectations of interested parties. This understanding informs the design of appropriate controls, the need for due diligence, and the effective allocation of resources.
-
ISO 37001 clause 8.7 sets out requirements for how an organisation manages suspected or actual bribery. It requires the establishment of clear and confidential reporting channels for raising concerns, along with defined procedures for investigating allegations and taking appropriate corrective action.
These processes must ensure protection against retaliation and that concerns are handled objectively and without undue delay. The clause also requires that competent personnel review reported issues and ensure that outcomes lead to appropriate action, including addressing any underlying weaknesses in the anti-bribery management system.
This approach helps ensure that the system not only prevents bribery but also detects and responds to issues in a structured and credible manner.
ISO 37001 Training
More information
ISO 37001
Download our flyer.