[email protected]
Accredited Certification Body · IAS & IAF Member · Certificates Verifiable Online
HomeStandardsISO 37001

Get Your ISO 37001 Quote

Takes 30 seconds · a specialist responds within 2 business hours
Step 1 of 2
CertificationTrainingCompliance Audits
Not sure - guide me
ISO 37001
No spam. No obligation. A clear quote.
15,000+Certified Clients
30+Countries Served
IAS · IAFAccredited
ISO 37001:2016 / 2025 · Anti-Bribery Management System

Bribery risk controlled, and independently audited so the bid stays alive

ISO 37001 certifies that an organisation runs an anti-bribery programme with teeth: risk assessed activity by activity, due diligence on agents and intermediaries, limits on gifts and hospitality, and a reporting channel people actually use. It is what prime contractors, development banks and joint venture partners ask for before they sign.

You need ISO 37001 if…

  • !A prime contractor has made anti-bribery certification a condition of staying on the approved supplier list.
  • !You win work through agents or intermediaries in markets you do not control directly.
  • !A development bank or export credit agency is financing the project and has asked how bribery is managed.
  • !Someone raised a concern about a payment and there was no channel to raise it through.
  • !Your work touches customs, permits, licences or inspections where facilitation payments are routinely expected.
  • !The board wants external verification that the policy on paper is actually operating in the field.
What it is

A management system standard for preventing, detecting and responding to bribery. It covers bribery by the organisation, by its staff, and by the agents, distributors and partners acting on its behalf, as well as bribery of the organisation.

Who issues it

An accredited certification body audits in two stages and issues the certificate. It certifies that the programme is reasonably designed and operating; it cannot prove no bribery has occurred.

Validity

The certificate runs three years, with an annual surveillance audit and a full recertification audit before the third year ends.

Who gets asked for it

Contractors, suppliers and intermediaries in construction, defence, energy, transport and public procurement, and any business bidding through agents overseas.

9of 25 industries

Where this certification is demanded

ISO 37001 is applicable across 9 of the 25 industries SIS covers. The pages below set out the specific reason it comes up in each one.

Defence IndustryTransport and LogisticsPublic SectorConstruction IndustryEnergy IndustryBanking and Finance+3 more

What ISO 37001 Actually Requires

The backbone an implementer has to build, in the order it usually gets built.

1
Bribery risk assessment

Assess exposure by activity, country, counterparty and transaction type, and review it when the business enters a new market or appoints a new agent.

2
Policy & governance

The governing body and top management approve the anti-bribery policy, prohibit retaliation, and hold oversight themselves rather than delegating it entirely.

3
Compliance function

A named anti-bribery compliance function with direct access to the governing body, authority to stop a transaction, and no conflicting commercial targets.

4
Due diligence

Proportionate checks on personnel in exposed roles, on projects, and on business associates: agents, distributors, consultants, joint venture partners and major suppliers.

5
Financial & commercial controls

Payment approvals, segregation of duties, recorded limits for gifts, hospitality, donations and sponsorship, and anti-bribery commitments written into contracts.

6
Concerns, investigation, review

A confidential reporting channel, a documented investigation process, monitoring of controls, internal audit, and management review with findings reported upward.

How ISO 37001 Certification Works

No black box. A defined, time-bound route from first call to certificate in hand.

Application & Proposal

Scoping turns on where you operate, how much work is won through agents or intermediaries, whether public officials are involved, and how many entities sit inside the certified boundary.

1–2 days

Gap Review & Readiness

The policy is almost never the problem. Agent due diligence is. A commission gets agreed on a call, the file is opened afterwards, and nobody can say what was checked.

1–2 weeks

Stage 1 + Stage 2 Audit

Stage 1 examines the risk assessment, policy and compliance function. Stage 2 samples agent contracts, due diligence records, hospitality entries and how raised concerns were handled.

Scheduled around operations

Certificate Issued

The certificate names the certified scope, and a buyer’s integrity team will check it against the accreditation body’s register before accepting it. Annual surveillance re-tests the agent files first.

Valid 3 years
A single-entity programme is usually certifiable in six to twelve weeks; groups with agents across several countries take longer, and SIS can phase entities so the first certificate lands before a bid deadline.

Industries That Need ISO 37001

🛡️
Defence Industry
Open full page →
Why it applies hereDefence procurement is among the most corruption-exposed sectors globally, with agents, offsets and intermediaries all creating exposure. ISO 37001 puts third-party due diligence, gifts and hospitality controls and a protected reporting channel in place, and gives the board a certified answer when a tender asks how bribery risk is managed. It is increasingly expected in international bids and joint ventures.Typical trigger: Agent due diligence; international bids
🚚
Transport and Logistics
Open full page →
Why it applies hereFreight, customs and port operations involve frequent contact with officials and agents, creating facilitation payment exposure across borders. ISO 37001 establishes third-party due diligence, controls over agents and clearing houses, and a reporting channel, which multinational shippers subject to FCPA and UK Bribery Act require of their logistics providers.Typical trigger: Multinational shipper compliance
🏛️
Public Sector
Open full page →
Why it applies herePublic procurement is the single largest bribery risk surface in most economies. ISO 37001 establishes due diligence over contractors and intermediaries, gifts and hospitality controls, conflict of interest declarations and a protected reporting channel, giving a department a certified and externally verified answer on how it manages integrity risk.Typical trigger: Procurement integrity; public accountability
🏗️
Construction Industry
Open full page →
Why it applies hereConstruction involves permits, inspections, land approvals, subcontractor selection and intermediaries, giving it one of the highest bribery risk profiles of any sector. ISO 37001 establishes third-party due diligence, gifts and hospitality controls and a protected reporting channel, which multinational clients and development banks now require of contractors.Typical trigger: Client and development bank requirements
Energy Industry
Open full page →
Why it applies hereLarge energy procurement, land acquisition, licensing and grid connection approvals create significant bribery exposure across intermediaries and contractors. ISO 37001 establishes due diligence, gifts and hospitality controls and reporting channels, which development finance institutions and international partners require.Typical trigger: Procurement and licensing exposure
🏦
Banking and Finance
Open full page →
Why it applies hereBanking exposure to bribery arises through intermediaries, correspondent relationships, procurement and lending decisions. ISO 37001 establishes due diligence, gifts and hospitality controls, conflict of interest management and protected reporting, supporting the integrity expectations of regulators and correspondent partners.Typical trigger: Correspondent and intermediary risk
🚆
Railways
Open full page →
Why it applies hereRailway procurement involves very large contracts, agents and long approval chains, creating significant bribery exposure. ISO 37001 establishes third-party due diligence, gifts and hospitality controls and protected reporting, which international suppliers and development banks require of participants in railway programmes.Typical trigger: Large-contract procurement integrity
🚢
Import and Export Industry
Open full page →
Why it applies hereCross-border trade involves customs, port and inspection authorities across jurisdictions, with agents and clearing houses creating facilitation payment exposure. ISO 37001 establishes third-party due diligence, controls over intermediaries and protected reporting, which multinational counterparties increasingly require.Typical trigger: Customs and agent exposure
🛢️
Oil and Gas Industry
Open full page →
Why it applies hereThe sector combines large contracts, licensing decisions, agents and operations in high-risk jurisdictions, giving it persistent corruption exposure. ISO 37001 establishes third-party due diligence, gifts and hospitality controls and protected reporting, which international operators and partners require of every contractor in the chain.Typical trigger: Agent and licensing exposure; partner requirements

Commonly taken alongside

Anti-bribery is one obligation family inside a wider compliance system, so ISO 37001 and ISO 37301 are commonly certified together with a shared obligations register, risk method and internal audit programme, which cuts the combined audit down to fewer days than two separate assessments.

Not Sure Which Certification You Need?

Three questions. The selector reads the same industry-to-standard mapping this whole site is built on, then shortlists what applies to you.

Question 1 of 3

Which sector best describes your organisation?

The audit begins with your intermediaries, not your policy

An auditor will pick one intermediary off your commission list and ask who actually owns that company. What happens in the next ten minutes tells you whether you are ready.

Get My Free Quote →

What ISO 37001 Changes for Your Business

Certification is not a certificate on the wall. It is a working system that pays for itself.

📝

Bids stop being disqualified

Integrity questions in prequalification are answered with an accredited certificate and audit report instead of a self-declaration a buyer has no reason to accept.

🕵️

Agents are actually checked

Due diligence becomes a file rather than a conversation: ownership, sanctions screening, commission rationale and a documented decision to appoint or decline.

📞

Concerns surface internally

A tested reporting channel means the first person to hear about a questionable payment is your compliance function, not a regulator or a journalist.

⚖️

Evidence of adequate procedures

Where the law offers a defence based on preventive procedures, an independently audited system is the kind of evidence that defence is built from.

🏦

Lenders and partners satisfied

Development finance institutions and joint venture partners run their own integrity checks. A certified system shortens that review and removes a common condition precedent.

🌐

One answer for every market

Different jurisdictions ask the same questions in different words. One certified programme answers all of them without rebuilding evidence for each.

Knowledge Base - Downloads

Practical documents prepared by our auditors. Fill the short form once and every download on the page unlocks.

PDF GUIDE

ISO 37001 implementation guide for exposed sectors

How the clauses translate into a working programme, with the evidence an auditor expects at each stage and the failure points that recur.

TEMPLATE

Third-party due diligence questionnaire and scoring guide

A tiered questionnaire for agents, distributors and consultants covering beneficial ownership, connections to officials, commission basis and sanctions screening, with scoring guidance.

CHECKLIST

Gift, hospitality and donation controls

Thresholds, approval routes and register fields that hold up when an auditor samples register entries against expense claims and payment records.

WHITEPAPER

Bribery risk in agent-led sales models

Where exposure concentrates when third parties win work on your behalf, which controls actually reduce it, and what auditors sample first.

🔒 Documents are locked. Fill the form once to unlock every download.

Frequently Asked Questions

Straight answers to what buyers ask before they commit to ISO 37001.

Does ISO 37001 certification prove no bribery is happening?
No, and the standard says so plainly. Certification confirms that a programme meeting the requirements is designed and operating at the time of audit. Bribery is concealed by nature and no audit can rule it out. What certification demonstrates is that the organisation identified its exposure, put proportionate controls in place, and can show they run.
Which version applies, the 2016 edition or the 2025 edition?
ISO 37001 has been revised, and certificates are moving from the 2016 edition to the current one over a defined transition period. New certifications are audited against the current edition. If you already hold a 2016 certificate, SIS handles the transition at a surveillance or recertification audit rather than as a separate exercise, provided the gaps are closed.
Do agents and distributors have to be certified too?
No. The obligation is on you to assess their bribery risk, run proportionate due diligence, obtain anti-bribery commitments in contract, and monitor the relationship. Certification of the third party is not required. Where a business associate is high risk and refuses commitments or transparency about ownership and commission, that refusal is itself the finding.
Can the compliance function sit with the finance or legal director?
It can, provided the role has direct access to the governing body, sufficient authority and resource, and no conflict with commercial targets. In smaller organisations combining roles is normal and auditable. It becomes a non-conformity when the person responsible for anti-bribery also owns the sales target the bribery risk arises from.
What does the auditor actually look at during Stage 2?
Records, mostly. Due diligence files for a sample of agents and suppliers, the gift and hospitality register against expense claims, payment approvals for unusual transactions, training records for staff in exposed roles, reports received through the concerns channel and how each was investigated and closed, plus board minutes showing oversight.
How does this sit alongside an existing compliance programme?
ISO 37001 slots into ISO 37301 as one obligation family among many. If you already run a compliance management system, most of the structure exists: obligations register, risk assessment, training, monitoring and review. The anti-bribery work adds third-party due diligence, gift and hospitality controls and the protected reporting requirements specific to bribery.
Email Us
✉ EmailGet Quote