Get Your ISO 37001 Quote
Bribery risk controlled, and independently audited so the bid stays alive
ISO 37001 certifies that an organisation runs an anti-bribery programme with teeth: risk assessed activity by activity, due diligence on agents and intermediaries, limits on gifts and hospitality, and a reporting channel people actually use. It is what prime contractors, development banks and joint venture partners ask for before they sign.
You need ISO 37001 if…
- !A prime contractor has made anti-bribery certification a condition of staying on the approved supplier list.
- !You win work through agents or intermediaries in markets you do not control directly.
- !A development bank or export credit agency is financing the project and has asked how bribery is managed.
- !Someone raised a concern about a payment and there was no channel to raise it through.
- !Your work touches customs, permits, licences or inspections where facilitation payments are routinely expected.
- !The board wants external verification that the policy on paper is actually operating in the field.
A management system standard for preventing, detecting and responding to bribery. It covers bribery by the organisation, by its staff, and by the agents, distributors and partners acting on its behalf, as well as bribery of the organisation.
An accredited certification body audits in two stages and issues the certificate. It certifies that the programme is reasonably designed and operating; it cannot prove no bribery has occurred.
The certificate runs three years, with an annual surveillance audit and a full recertification audit before the third year ends.
Contractors, suppliers and intermediaries in construction, defence, energy, transport and public procurement, and any business bidding through agents overseas.
Where this certification is demanded
ISO 37001 is applicable across 9 of the 25 industries SIS covers. The pages below set out the specific reason it comes up in each one.
What ISO 37001 Actually Requires
The backbone an implementer has to build, in the order it usually gets built.
Assess exposure by activity, country, counterparty and transaction type, and review it when the business enters a new market or appoints a new agent.
The governing body and top management approve the anti-bribery policy, prohibit retaliation, and hold oversight themselves rather than delegating it entirely.
A named anti-bribery compliance function with direct access to the governing body, authority to stop a transaction, and no conflicting commercial targets.
Proportionate checks on personnel in exposed roles, on projects, and on business associates: agents, distributors, consultants, joint venture partners and major suppliers.
Payment approvals, segregation of duties, recorded limits for gifts, hospitality, donations and sponsorship, and anti-bribery commitments written into contracts.
A confidential reporting channel, a documented investigation process, monitoring of controls, internal audit, and management review with findings reported upward.
How ISO 37001 Certification Works
No black box. A defined, time-bound route from first call to certificate in hand.
Application & Proposal
Scoping turns on where you operate, how much work is won through agents or intermediaries, whether public officials are involved, and how many entities sit inside the certified boundary.
1–2 daysGap Review & Readiness
The policy is almost never the problem. Agent due diligence is. A commission gets agreed on a call, the file is opened afterwards, and nobody can say what was checked.
1–2 weeksStage 1 + Stage 2 Audit
Stage 1 examines the risk assessment, policy and compliance function. Stage 2 samples agent contracts, due diligence records, hospitality entries and how raised concerns were handled.
Scheduled around operationsCertificate Issued
The certificate names the certified scope, and a buyer’s integrity team will check it against the accreditation body’s register before accepting it. Annual surveillance re-tests the agent files first.
Valid 3 yearsIndustries That Need ISO 37001
Commonly taken alongside
Not Sure Which Certification You Need?
Three questions. The selector reads the same industry-to-standard mapping this whole site is built on, then shortlists what applies to you.
Which sector best describes your organisation?
The audit begins with your intermediaries, not your policy
An auditor will pick one intermediary off your commission list and ask who actually owns that company. What happens in the next ten minutes tells you whether you are ready.
Get My Free Quote →What ISO 37001 Changes for Your Business
Certification is not a certificate on the wall. It is a working system that pays for itself.
Bids stop being disqualified
Integrity questions in prequalification are answered with an accredited certificate and audit report instead of a self-declaration a buyer has no reason to accept.
Agents are actually checked
Due diligence becomes a file rather than a conversation: ownership, sanctions screening, commission rationale and a documented decision to appoint or decline.
Concerns surface internally
A tested reporting channel means the first person to hear about a questionable payment is your compliance function, not a regulator or a journalist.
Evidence of adequate procedures
Where the law offers a defence based on preventive procedures, an independently audited system is the kind of evidence that defence is built from.
Lenders and partners satisfied
Development finance institutions and joint venture partners run their own integrity checks. A certified system shortens that review and removes a common condition precedent.
One answer for every market
Different jurisdictions ask the same questions in different words. One certified programme answers all of them without rebuilding evidence for each.
Knowledge Base - Downloads
Practical documents prepared by our auditors. Fill the short form once and every download on the page unlocks.
ISO 37001 implementation guide for exposed sectors
How the clauses translate into a working programme, with the evidence an auditor expects at each stage and the failure points that recur.
Third-party due diligence questionnaire and scoring guide
A tiered questionnaire for agents, distributors and consultants covering beneficial ownership, connections to officials, commission basis and sanctions screening, with scoring guidance.
Gift, hospitality and donation controls
Thresholds, approval routes and register fields that hold up when an auditor samples register entries against expense claims and payment records.
Bribery risk in agent-led sales models
Where exposure concentrates when third parties win work on your behalf, which controls actually reduce it, and what auditors sample first.
Frequently Asked Questions
Straight answers to what buyers ask before they commit to ISO 37001.
Does ISO 37001 certification prove no bribery is happening?
Which version applies, the 2016 edition or the 2025 edition?
Do agents and distributors have to be certified too?
Can the compliance function sit with the finance or legal director?
What does the auditor actually look at during Stage 2?
How does this sit alongside an existing compliance programme?
Start ISO 37001 certification with an accredited body
The programme gets audited where it is actually tested: the intermediary relationships you do not control directly. The certificate scope is written to satisfy whoever asked you for it.
Get My Free Quote → WhatsApp Us