ISO 37301
Compliance Management Systems
ISO 37301:2021 at a glance
- Current edition
- ISO 37301:2021 - Compliance management systems — Requirements with guidance for use
- Published
- 2021
- Status
- Published
- Type of standard
- Management system standard
- Certifiable
- Yes — organizations can be certified by an accredited body
- Previous edition
- ISO 19600:2014
- Official ISO page
- View ISO 37301:2021 on iso.org
- Last verified
Overview
Certifiable requirements for a compliance management system, replacing the guidance-only ISO 19600:2014
ISO 37301:2021 specifies requirements and provides guidance for establishing, developing, implementing, evaluating, maintaining and improving an effective compliance management system (CMS). It was published in April 2021 by ISO/TC 309 and cancelled and replaced ISO 19600:2014, which was guidance only. The change from guidance to requirements is the significant point: organizations can now be certified against ISO 37301 by an accredited certification body.
The standard is applicable to all organizations regardless of type, size, nature of activity, or whether they are public, private or not-for-profit. It is built on the principles of good governance, proportionality, transparency and sustainability, and uses ISO's harmonized structure, so it integrates readily with ISO 9001, ISO 14001, ISO 27001, ISO 45001 and in particular ISO 37001.
A central concept is the compliance obligation: requirements that an organization must comply with (laws, regulations, permits, court orders, binding agreements) and those it chooses to comply with (codes of conduct, standards, contractual commitments, community expectations). The organization must systematically identify these obligations, evaluate the associated compliance risks, and design controls proportionate to them.
Governance requirements are prominent. The standard requires the governing body and top management to demonstrate leadership and commitment and to promote a culture of compliance, and requires a compliance function with defined responsibility, authority, competence and access to the governing body. It also allocates compliance responsibilities to management at all levels and to all personnel — compliance is explicitly not the sole property of a single department.
Operational requirements cover controls and procedures for identified compliance risks, due diligence, processes for raising concerns (with protection against retaliation), and processes for investigating and responding to non-compliance. Performance evaluation requires monitoring, measurement, analysis and evaluation of compliance performance, internal audit, and management review including review by the governing body. Improvement covers corrective action following non-compliances and continual improvement.
ISO 37301 is commonly used as the umbrella system into which topic-specific systems are integrated — most often ISO 37001 (anti-bribery), and increasingly ISO 37002 (whistleblowing management), ISO/IEC 27701 (privacy) and ISO 37000 (governance of organizations). Certification is available through accredited certification bodies and is frequently sought by regulated firms and by suppliers that need to evidence compliance maturity to customers.
Purpose
To specify auditable requirements for a compliance management system that identifies an organization's compliance obligations, evaluates and controls compliance risk, and embeds a culture of compliance under the oversight of the governing body.
Key Benefits
- Provides certifiable requirements for compliance management, where its predecessor ISO 19600 offered only guidance
- Creates a single structured inventory of compliance obligations across jurisdictions and topics
- Ties controls to an explicit assessment of compliance risk rather than to generic checklists
- Defines the roles of the governing body, top management, the compliance function and line management
- Establishes protected channels for raising concerns and a defined investigation process
- Integrates with ISO 37001, ISO 37002 and other harmonized-structure management systems
- Supports demonstration of compliance maturity to regulators, customers and business partners
- Provides an internal audit and management review cycle focused specifically on compliance performance
- Applies equally to private companies, public bodies and non-profits
- Helps consolidate fragmented, department-level compliance activity into one governed system
Key Requirements
- Determine the organization's context, interested parties and the scope of the compliance management system
- Identify compliance obligations, both mandatory and voluntarily adopted, and keep them current
- Assess compliance risks arising from those obligations and evaluate existing controls
- Demonstrate leadership and commitment from the governing body and top management, including promotion of a compliance culture
- Establish a compliance policy consistent with the organization's values and obligations
- Assign a compliance function with defined responsibility, authority, independence and access to the governing body
- Allocate compliance responsibilities to management and personnel at all levels
- Set compliance objectives and plan actions to achieve them
- Ensure competence, awareness, training and appropriate communication on compliance matters
- Maintain documented information sufficient for the effectiveness of the system
- Implement controls and procedures to manage compliance obligations and risks, including due diligence
- Operate a process for raising concerns with protection against retaliation, and a process for investigation
- Monitor, measure, analyse and evaluate compliance performance, and conduct internal audits
- Conduct management review and review by the governing body, and act on non-compliances with corrective action and continual improvement
Who Needs This Standard?
Organizations that must demonstrate systematic management of legal and regulatory obligations — regulated sectors such as financial services, healthcare, energy and telecoms, public sector bodies, multinationals managing obligations across jurisdictions, and suppliers whose customers require evidence of compliance governance.
Where to get ISO 37301
The full text of ISO 37301 is copyrighted and is sold by ISO and its national member bodies — buy the official edition on iso.org, or order the same document from your national standards body, often at a member price. Sites offering a free PDF of the complete standard are not authorised to distribute it, and the files circulating there are frequently superseded editions, partial scans or altered copies, with no way to tell which. What is legitimately free is the standard's page on iso.org: the abstract, the current edition and status, the table of contents, and a preview of the opening sections. This page summarises the scope and requirements of ISO 37301 in our own words; it does not reproduce the standard's text and is not a substitute for the published document.
Get our free implementation resources
Send me the implementation checklist for ISO 37301, plus an alert when this standard is revised, withdrawn or replaced. Free, no account needed.
We'll only email you about this standard. Unsubscribe anytime.
Need help getting certified?
Certificates for ISO 37301 are issued by accredited certification bodies, not by ISO itself. Tell us what stage you are at and we will put you in touch with people who work with this standard — implementation support, audit or training. Free and no obligation.
Get help with ISO 37301 certification
In a hurry? You can also compare provider quotes on CertBetter (affiliate link — we earn a commission, and it stays free for you).