Get Your ISO 37301 Quote
Every obligation you carry, in one register with a name against it
ISO 37301 certifies a compliance management system: a live register of the laws, licence conditions, codes and contract terms that bind you, an owner for each, and evidence they are being met. It is the standard regulators, boards and large customers recognise when they ask how compliance is actually run.
You need ISO 37301 ifβ¦
- !A regulator asked for your obligations register and you produced a spreadsheet nobody had updated in months.
- !You operate in several jurisdictions and heard about a rule change from a customer rather than internally.
- !A penalty or licence condition has landed and the board wants to know how it was missed.
- !The compliance function exists but has no defined authority, budget or reporting line to the board.
- !A tender asks for evidence of a certified compliance management system, not a policy document.
- !Obligations are tracked department by department, so nobody can see the whole picture in one place.
A management system standard for how an organisation identifies the obligations it must meet, assigns them to owners, controls the risk of breaching them, and demonstrates the system works. It covers legal, regulatory, contractual and voluntary commitments alike.
A certifiable requirements standard, audited and certified by an accredited certification body. It replaced ISO 19600, which was guidance only and could not be certified.
The certificate runs three years, subject to an annual surveillance audit, with recertification audited before the third year closes.
Regulated businesses, listed groups, public bodies and organisations operating across several jurisdictions where one missed rule stops shipments or trading.
Where this certification is demanded
ISO 37301 is applicable across 16 of the 25 industries SIS covers. The pages below set out the specific reason it comes up in each one.
What ISO 37301 Actually Requires
The backbone an implementer has to build, in the order it usually gets built.
Identify every legal, regulatory, licence, code and contractual obligation that applies, record its source and owner, and keep it current as rules change.
Rate each obligation by likelihood and consequence of breach, so controls concentrate where a failure would halt operations or attract enforcement.
The governing body approves a compliance policy, and top management demonstrates it through decisions, targets and how breaches are treated when they are inconvenient.
An independent compliance function with defined authority and resource, plus trained owners in the business who can explain the obligations they hold.
Approval steps, checks and records built into the activities that create exposure, together with due diligence over third parties acting on your behalf.
Measure compliance performance, investigate breaches and near misses, run internal audits, report to the governing body, and correct the underlying cause.
How ISO 37301 Certification Works
No black box. A defined, time-bound route from first call to certificate in hand.
Application & Proposal
Scoping depends on the number of jurisdictions and licence regimes you operate under, the entities in the certified boundary, and whether an existing compliance function already reports centrally.
1β2 daysGap Review & Readiness
A licensing condition changed eighteen months ago. The lawyer who spotted it emailed two people and left the company. Nothing in the register records that it was ever evaluated.
1β2 weeksStage 1 + Stage 2 Audit
Stage 1 reviews the obligations register, risk method and reporting lines. Stage 2 samples obligations end to end: who owns it, which control meets it, and what evidence exists.
Scheduled around operationsCertificate Issued
The certificate states the scope and entities covered. Surveillance looks at what changed: regulations amended since the audit, and whether the register shows somebody evaluated each one.
Valid 3 yearsIndustries That Need ISO 37301
Commonly taken alongside
Not Sure Which Certification You Need?
Three questions. The selector reads the same industry-to-standard mapping this whole site is built on, then shortlists what applies to you.
Which sector best describes your organisation?
Most compliance registers fail on ownership, not coverage
Most ISO 37301 audits go wrong in the same place: obligations listed but never assigned, so nobody can say who evaluated them or when. Coverage is rarely the problem; ownership is.
Get My Free Quote βWhat ISO 37301 Changes for Your Business
Certification is not a certificate on the wall. It is a working system that pays for itself.
One register, many jurisdictions
Obligations from every market sit in one place with an owner, so a change in one country is assessed against every entity it touches.
Change is caught early
Regulatory monitoring becomes a defined task with a review cycle, so amendments are actioned before an inspection or a blocked shipment reveals them.
Evidence for supervisors
When a regulator asks how you know you comply, the answer is a register, control owners, evaluation records and an independent audit report.
Breaches investigated properly
A defined process for investigating breaches and near misses means causes get fixed rather than the same failure repeating in another department.
Fewer customer compliance audits
Large customers auditing your compliance arrangements accept an accredited certificate and audit summary in place of their own on-site review.
Board gets a real picture
Compliance reporting moves from assurance by exception to measured performance. A governing body can discharge its oversight duty on that; it cannot on a verbal assurance.
Knowledge Base - Downloads
Practical documents prepared by our auditors. Fill the short form once and every download on the page unlocks.
Building a compliance obligations register
How to structure sources, owners, controls and evaluation evidence so the register survives an audit rather than growing stale.
Compliance obligation and control matrix
Fields for obligation, source, jurisdiction, entity, owner, control, evidence and review date, with worked examples drawn from several regulated sectors.
ISO 37301 readiness checklist for both stages
What the auditor will ask for at Stage 1 and Stage 2, with the record that answers each question.
Managing compliance across multiple jurisdictions
How multinational organisations keep a single register usable when obligations differ by entity, market and licence condition, without splitting it apart.
Frequently Asked Questions
Straight answers to what buyers ask before they commit to ISO 37301.
How is ISO 37301 different from ISO 19600?
Does the certificate mean we are compliant with every law?
What goes into the obligations register, and how detailed?
Can ISO 37301 be certified for one part of the group only?
Who should own the compliance function for certification purposes?
How much work is the annual surveillance audit?
Start ISO 37301 certification with an accredited body
Accreditation is what makes the certificate mean something to a supervisor. Your obligations register gets read the way an inspector would read it, before an inspector does.
Get My Free Quote β WhatsApp Us