[email protected]
Accredited Certification Body · IAS & IAF Member · Certificates Verifiable Online
HomeStandardsISO 37301

Get Your ISO 37301 Quote

Takes 30 seconds · a specialist responds within 2 business hours
Step 1 of 2
CertificationTrainingCompliance Audits
Not sure - guide me
ISO 37301
No spam. No obligation. A clear quote.
15,000+Certified Clients
30+Countries Served
IAS · IAFAccredited
ISO 37301:2021 · Compliance Management System

Every obligation you carry, in one register with a name against it

ISO 37301 certifies a compliance management system: a live register of the laws, licence conditions, codes and contract terms that bind you, an owner for each, and evidence they are being met. It is the standard regulators, boards and large customers recognise when they ask how compliance is actually run.

You need ISO 37301 if…

  • !A regulator asked for your obligations register and you produced a spreadsheet nobody had updated in months.
  • !You operate in several jurisdictions and heard about a rule change from a customer rather than internally.
  • !A penalty or licence condition has landed and the board wants to know how it was missed.
  • !The compliance function exists but has no defined authority, budget or reporting line to the board.
  • !A tender asks for evidence of a certified compliance management system, not a policy document.
  • !Obligations are tracked department by department, so nobody can see the whole picture in one place.
What it is

A management system standard for how an organisation identifies the obligations it must meet, assigns them to owners, controls the risk of breaching them, and demonstrates the system works. It covers legal, regulatory, contractual and voluntary commitments alike.

Who issues it

A certifiable requirements standard, audited and certified by an accredited certification body. It replaced ISO 19600, which was guidance only and could not be certified.

Validity

The certificate runs three years, subject to an annual surveillance audit, with recertification audited before the third year closes.

Who gets asked for it

Regulated businesses, listed groups, public bodies and organisations operating across several jurisdictions where one missed rule stops shipments or trading.

16of 25 industries

Where this certification is demanded

ISO 37301 is applicable across 16 of the 25 industries SIS covers. The pages below set out the specific reason it comes up in each one.

Defence IndustryFood and Food ProductsPublic SectorPharmaceutical IndustrySolar IndustryConstruction Industry+10 more

What ISO 37301 Actually Requires

The backbone an implementer has to build, in the order it usually gets built.

1
Obligations register

Identify every legal, regulatory, licence, code and contractual obligation that applies, record its source and owner, and keep it current as rules change.

2
Compliance risk assessment

Rate each obligation by likelihood and consequence of breach, so controls concentrate where a failure would halt operations or attract enforcement.

3
Governance & culture

The governing body approves a compliance policy, and top management demonstrates it through decisions, targets and how breaches are treated when they are inconvenient.

4
Compliance function & competence

An independent compliance function with defined authority and resource, plus trained owners in the business who can explain the obligations they hold.

5
Controls in the process

Approval steps, checks and records built into the activities that create exposure, together with due diligence over third parties acting on your behalf.

6
Evaluation & improvement

Measure compliance performance, investigate breaches and near misses, run internal audits, report to the governing body, and correct the underlying cause.

How ISO 37301 Certification Works

No black box. A defined, time-bound route from first call to certificate in hand.

Application & Proposal

Scoping depends on the number of jurisdictions and licence regimes you operate under, the entities in the certified boundary, and whether an existing compliance function already reports centrally.

1–2 days

Gap Review & Readiness

A licensing condition changed eighteen months ago. The lawyer who spotted it emailed two people and left the company. Nothing in the register records that it was ever evaluated.

1–2 weeks

Stage 1 + Stage 2 Audit

Stage 1 reviews the obligations register, risk method and reporting lines. Stage 2 samples obligations end to end: who owns it, which control meets it, and what evidence exists.

Scheduled around operations

Certificate Issued

The certificate states the scope and entities covered. Surveillance looks at what changed: regulations amended since the audit, and whether the register shows somebody evaluated each one.

Valid 3 years
Most organisations certify in eight to fourteen weeks, or sooner where a fixed supervisory review or tender date lets SIS prioritise the audit slot, with the obligations register taking the bulk of that time.

Industries That Need ISO 37301

🛡️
Defence Industry
Open full page →
Why it applies hereDefence suppliers sit under export control law, industrial security rules, offset obligations and procurement regulation at the same time. ISO 37301 pulls these into a single compliance management system with an obligations register, assigned control owners and periodic evaluation, so gaps surface internally rather than during a government audit.Typical trigger: Export control; regulatory audit readiness
🍲
Food and Food Products
Open full page →
Why it applies hereFood businesses carry a dense obligation load: food business licensing, labelling and claims rules, weights and measures, export certification and destination-country requirements. ISO 37301 maintains a live obligations register with assigned owners, so a labelling rule change or a new import requirement is picked up and actioned before a consignment is rejected at the border.Typical trigger: Labelling and export compliance
🏛️
Public Sector
Open full page →
Why it applies hereDepartments operate under statute, financial rules, procurement regulation, audit observations and court directions simultaneously. ISO 37301 consolidates these obligations into a managed register with assigned owners and periodic evaluation, so compliance failures are found internally rather than in an audit report or a public interest litigation.Typical trigger: Statutory and audit compliance
💊
Pharmaceutical Industry
Open full page →
Why it applies herePharmaceutical companies face drug law, environmental rules, marketing practice codes, clinical trial regulation, data protection and export controls at once. ISO 37301 maintains one obligations register with assigned owners and evaluation cycles, so regulatory change is tracked and evidenced rather than discovered during an inspection.Typical trigger: Multi-jurisdiction regulatory load
☀️
Solar Industry
Open full page →
Why it applies hereSolar businesses operate under land, electricity, grid connection, incentive scheme and content requirement rules that change frequently and differ by state and country. ISO 37301 tracks these obligations with assigned owners so eligibility for tariffs and incentives is not lost through an unnoticed regulatory change.Typical trigger: Incentive eligibility; multi-state regulation
🏗️
Construction Industry
Open full page →
Why it applies hereContractors operate under building codes, labour law, environmental consents, safety regulation and contract-specific obligations simultaneously, across multiple jurisdictions. ISO 37301 consolidates these into a managed obligations register with owners and evaluation, reducing the exposure that surfaces in disputes and regulatory action.Typical trigger: Multi-jurisdiction obligations; disputes
⚗️
Chemical Industry
Open full page →
Why it applies hereChemical companies operate under hazardous substance rules, transport regulations, environmental consents, precursor controls and export restrictions at once, with heavy penalties for lapses. ISO 37301 tracks these obligations with assigned owners and structured evaluation, so change is managed proactively.Typical trigger: Hazardous substance and export rules
🔌
Electricals and Electronics Industry
Open full page →
Why it applies hereManufacturers face restricted substance rules, e-waste obligations, product safety regulation, conflict minerals reporting and export controls across multiple markets. ISO 37301 maintains one obligations register with owners and evaluation cycles, so a regulatory change in an export market is caught before shipments are blocked.Typical trigger: Product compliance across markets
Energy Industry
Open full page →
Why it applies hereEnergy businesses operate under electricity regulation, environmental law, safety rules, tariff orders and renewable purchase obligations at once. ISO 37301 consolidates these into a managed obligations register with assigned owners, so regulatory change is tracked and evidenced rather than found in a penalty order.Typical trigger: Regulatory and tariff obligations
🧵
Textile Industry
Open full page →
Why it applies hereExporters face restricted substance rules, labelling requirements, labour law, customs and duty preference conditions across multiple destination markets. ISO 37301 maintains one obligations register with assigned owners so a change in an importing market is picked up before shipments are held or penalised.Typical trigger: Export market compliance
🚗
Automotive Industry
Open full page →
Why it applies hereSuppliers face product safety and recall regulation, emissions rules, restricted substances, export controls and customer-specific requirements at once. ISO 37301 consolidates these obligations with assigned owners and evaluation cycles, reducing the exposure that surfaces during a recall investigation.Typical trigger: Recall and product safety exposure
🏦
Banking and Finance
Open full page →
Why it applies hereFinancial institutions carry an exceptionally dense obligation load across prudential rules, conduct, anti-money laundering, data protection and consumer protection. ISO 37301 consolidates these into a managed register with assigned owners and structured evaluation, and is directly applicable to the compliance function itself.Typical trigger: Compliance function structure; supervisory review
🚢
Import and Export Industry
Open full page →
Why it applies hereTraders operate under export controls, sanctions, customs valuation, origin rules, product regulation and duty preference conditions across many markets simultaneously. ISO 37301 maintains one obligations register with assigned owners so a rule change in any market is caught before a shipment is seized or penalised.Typical trigger: Sanctions, origin and customs rules
🏭
Manufacturing Industries
Open full page →
Why it applies hereManufacturers face product safety, environmental, labour, export control and customer-specific obligations across multiple markets. ISO 37301 consolidates these into a managed obligations register with assigned owners and evaluation cycles, so compliance gaps are found internally rather than in a recall or enforcement action.Typical trigger: Product and market regulation
🛢️
Oil and Gas Industry
Open full page →
Why it applies hereOperators and contractors work under petroleum regulation, environmental law, safety cases, export controls and contractual obligations across jurisdictions. ISO 37301 consolidates these into a managed register with assigned owners and evaluation, so obligations are demonstrably tracked rather than assumed.Typical trigger: Multi-jurisdiction regulatory load
🚬
Tobacco Industry
Open full page →
Why it applies hereThe sector operates under some of the densest regulation in commerce: excise, licensing, advertising restrictions, packaging and labelling rules, and track-and-trace obligations differing by market. ISO 37301 maintains a managed obligations register with assigned owners so changes are implemented before enforcement action follows.Typical trigger: Excise, labelling and advertising rules

Commonly taken alongside

Compliance, anti-bribery and risk management share a register, a risk method and an internal audit programme, so certifying ISO 37301 with ISO 37001 and running them against ISO 31000 lets SIS audit the common clauses once and cut several days from the combined assessment.

Not Sure Which Certification You Need?

Three questions. The selector reads the same industry-to-standard mapping this whole site is built on, then shortlists what applies to you.

Question 1 of 3

Which sector best describes your organisation?

Most compliance registers fail on ownership, not coverage

Most ISO 37301 audits go wrong in the same place: obligations listed but never assigned, so nobody can say who evaluated them or when. Coverage is rarely the problem; ownership is.

Get My Free Quote →

What ISO 37301 Changes for Your Business

Certification is not a certificate on the wall. It is a working system that pays for itself.

📚

One register, many jurisdictions

Obligations from every market sit in one place with an owner, so a change in one country is assessed against every entity it touches.

⏱️

Change is caught early

Regulatory monitoring becomes a defined task with a review cycle, so amendments are actioned before an inspection or a blocked shipment reveals them.

🧾

Evidence for supervisors

When a regulator asks how you know you comply, the answer is a register, control owners, evaluation records and an independent audit report.

🧯

Breaches investigated properly

A defined process for investigating breaches and near misses means causes get fixed rather than the same failure repeating in another department.

🤝

Fewer customer compliance audits

Large customers auditing your compliance arrangements accept an accredited certificate and audit summary in place of their own on-site review.

🏛️

Board gets a real picture

Compliance reporting moves from assurance by exception to measured performance. A governing body can discharge its oversight duty on that; it cannot on a verbal assurance.

Knowledge Base - Downloads

Practical documents prepared by our auditors. Fill the short form once and every download on the page unlocks.

PDF GUIDE

Building a compliance obligations register

How to structure sources, owners, controls and evaluation evidence so the register survives an audit rather than growing stale.

TEMPLATE

Compliance obligation and control matrix

Fields for obligation, source, jurisdiction, entity, owner, control, evidence and review date, with worked examples drawn from several regulated sectors.

CHECKLIST

ISO 37301 readiness checklist for both stages

What the auditor will ask for at Stage 1 and Stage 2, with the record that answers each question.

WHITEPAPER

Managing compliance across multiple jurisdictions

How multinational organisations keep a single register usable when obligations differ by entity, market and licence condition, without splitting it apart.

🔒 Documents are locked. Fill the form once to unlock every download.

Frequently Asked Questions

Straight answers to what buyers ask before they commit to ISO 37301.

How is ISO 37301 different from ISO 19600?
ISO 19600 was a guidance document. You could follow it, but no certification body could certify against it because it contained recommendations rather than requirements. ISO 37301 restates the same thinking as auditable requirements, so a certification body can assess conformity and issue an accredited certificate. Organisations that implemented ISO 19600 usually find the structural work already done.
Does the certificate mean we are compliant with every law?
No. It certifies that a system for identifying, managing and evaluating compliance obligations is in place and working. An auditor samples obligations and tests whether each has an owner, a control and evidence. Certification does not verify legal compliance item by item, and no certification body is competent to give a legal opinion on your obligations.
What goes into the obligations register, and how detailed?
Everything that binds you: statutes and regulations, licence and permit conditions, court or regulator directions, industry codes you have adopted, customer contract terms and voluntary commitments. Detail should go to the level at which someone can own it and evidence it. A single line saying environmental law applies is not auditable; the specific consent condition is.
Can ISO 37301 be certified for one part of the group only?
Yes. Scope is defined by entity, site and activity, and it is common to certify a regulated subsidiary or a single market first and extend later. The scope statement on the certificate must make the boundary unambiguous, because customers and regulators read it. SIS will not issue a scope that implies wider coverage than was audited.
Who should own the compliance function for certification purposes?
Someone with defined authority, adequate resource, and direct access to the governing body. It need not be a full-time role in a smaller organisation, and combining it with legal or risk is acceptable. What fails audit is a compliance owner with no budget, no reporting line above the operational management being assessed, and no ability to escalate.
How much work is the annual surveillance audit?
Considerably less than certification. Surveillance focuses on what changed: new or amended obligations, breaches and near misses since the last visit, internal audit and management review output, and progress on previous findings. It typically runs one to two days depending on scope. Recertification in year three is broader and reviews the whole system again.
Email Us
✉ EmailGet Quote