ISO 37001
Anti-Bribery Management Systems
ISO 37001:2025 at a glance
- Current edition
- ISO 37001:2025 - Anti-bribery management systems — Requirements with guidance for use
- Published
- 2025
- Status
- Published
- Type of standard
- Management system standard
- Certifiable
- Yes — organizations can be certified by an accredited body
- Previous edition
- ISO 37001:2016
- Official ISO page
- View ISO 37001:2025 on iso.org
- Last verified
Overview
Requirements for an anti-bribery management system, enabling organizations to prevent, detect and respond to bribery; second edition published 2025
ISO 37001 specifies requirements, and gives guidance, for establishing, implementing, maintaining, reviewing and improving an anti-bribery management system (ABMS). The second edition, ISO 37001:2025, cancels and replaces ISO 37001:2016. The standard was developed by ISO/TC 309 (Governance of organizations) and is written so that it can operate as a stand-alone management system or be integrated into an existing management system such as ISO 37301 (compliance) or ISO 9001.
The standard addresses bribery in the organization's own activities, bribery by its personnel acting on its behalf, and bribery by business associates acting on its behalf, as well as bribery of the organization and its personnel. It covers bribery in the public, private and not-for-profit sectors, direct and indirect bribery, and bribery in any jurisdiction. It does not specifically address fraud, cartels, money laundering or other anti-competitive practices, although an organization may choose to extend the scope of its system to cover them.
ISO 37001 follows ISO's harmonized structure for management system standards, so its main clauses run from Clause 4 (context of the organization) through leadership, planning, support, operation, performance evaluation and improvement. Distinctive anti-bribery content sits mainly in the planning and operation clauses: a documented bribery risk assessment, an anti-bribery policy, an anti-bribery compliance function, and controls over the areas where bribery risk concentrates.
Those operational controls include due diligence on transactions, projects, personnel and business associates; financial and non-financial controls; controls over gifts, hospitality, donations, sponsorships and political contributions; commitments from business associates; procedures for raising concerns (including a channel that permits anonymous reporting where lawful) and protection from retaliation; and procedures for investigating and dealing with suspected bribery. The standard also requires employment procedures, training and awareness proportionate to assessed risk.
Governance is a defining feature: the standard assigns explicit duties to the governing body and top management, and requires the anti-bribery compliance function to have direct access to them and adequate independence and authority. Performance evaluation covers monitoring, internal audit, management review and review by the governing body.
Accredited third-party certification to ISO 37001 is widely available, and the standard is commonly referenced in tenders, in supply chain integrity programmes, and by organizations demonstrating adequate procedures under legislation such as the UK Bribery Act, the US Foreign Corrupt Practices Act and the EU's anti-corruption measures. ISO is explicit that conformity — including certification — cannot provide assurance that no bribery has occurred or will occur; the system is designed to make bribery substantially less likely and to be able to detect and respond to it.
ISO 37001 is normally implemented alongside ISO 37301 (compliance management systems), ISO 37002 (whistleblowing management systems) and ISO 37000 (governance of organizations), and its risk-based approach is compatible with ISO 31000.
Purpose
To give organizations of any size or sector a structured, risk-based management system for preventing, detecting and responding to bribery, and a recognised basis on which that system can be audited and certified.
Key Benefits
- Provides an internationally recognised framework for anti-bribery controls that can be audited by an independent certification body
- Focuses effort where bribery risk is highest through a documented bribery risk assessment
- Clarifies the responsibilities of the governing body, top management and the anti-bribery compliance function
- Establishes consistent controls over gifts, hospitality, donations and political contributions
- Extends due diligence and anti-bribery commitments to agents, intermediaries, distributors and other business associates
- Supports demonstration of adequate or reasonable procedures under national anti-bribery legislation
- Creates auditable evidence trails for investigations and regulatory engagement
- Provides a protected route for personnel and third parties to raise concerns
- Integrates with ISO 37301, ISO 37002 and other management systems using the harmonized structure
- Frequently accepted by customers and public bodies as evidence of integrity due diligence in tendering
Key Requirements
- Determine internal and external issues, interested parties and the scope of the anti-bribery management system
- Conduct and document a bribery risk assessment, and review it periodically and after significant change
- Establish an anti-bribery policy that prohibits bribery and requires compliance with anti-bribery laws
- Assign an anti-bribery compliance function with adequate independence, authority, competence and resources
- Define the duties of the governing body and top management, including oversight of the system
- Set anti-bribery objectives and plan how they will be achieved and measured
- Provide training and awareness proportionate to assessed bribery risk
- Apply employment procedures covering recruitment, performance, promotion and disciplinary action
- Perform risk-based due diligence on transactions, projects, activities, personnel and business associates
- Implement financial and non-financial controls, including procurement and contracting controls
- Control gifts, hospitality, donations, sponsorships and similar benefits
- Obtain anti-bribery commitments from business associates where risk warrants it
- Operate procedures for raising concerns, including anonymity where lawful, and prohibit retaliation
- Investigate and deal with suspected or actual bribery, and take corrective action
- Monitor, internally audit, and review the system at management and governing body level
Who Needs This Standard?
Organizations of any size or sector exposed to bribery risk — particularly those operating internationally, in public procurement, or through agents and intermediaries. It is most used in construction, engineering, extractives, defence, healthcare, pharmaceuticals, financial services and by public bodies and state-owned enterprises.
Where to get ISO 37001
The full text of ISO 37001 is copyrighted and is sold by ISO and its national member bodies — buy the official edition on iso.org, or order the same document from your national standards body, often at a member price. Sites offering a free PDF of the complete standard are not authorised to distribute it, and the files circulating there are frequently superseded editions, partial scans or altered copies, with no way to tell which. What is legitimately free is the standard's page on iso.org: the abstract, the current edition and status, the table of contents, and a preview of the opening sections. This page summarises the scope and requirements of ISO 37001 in our own words; it does not reproduce the standard's text and is not a substitute for the published document.
Get our free implementation resources
Send me the implementation checklist for ISO 37001, plus an alert when this standard is revised, withdrawn or replaced. Free, no account needed.
We'll only email you about this standard. Unsubscribe anytime.
Need help getting certified?
Certificates for ISO 37001 are issued by accredited certification bodies, not by ISO itself. Tell us what stage you are at and we will put you in touch with people who work with this standard — implementation support, audit or training. Free and no obligation.
Get help with ISO 37001 certification
In a hurry? You can also compare provider quotes on CertBetter (affiliate link — we earn a commission, and it stays free for you).