ISO 37001 Anti-Bribery Management Systems
Confirms that an organisation has identified where bribery could occur in its business and has controls, reporting channels and investigation procedures in place.
What this certification proves
ISO 37001 does not certify that no one in your organisation will ever pay or take a bribe. No standard can. It certifies that you have identified where bribery could realistically occur, put controls on those points, and created a channel through which someone can report it safely.
The centre of the standard is the bribery risk assessment — which counterparties, transactions, countries and business partners carry exposure, and what happens at each. It also requires an anti-bribery compliance function that is independent enough to report to the governing body, and due diligence on third parties, because most bribery in practice is paid by agents rather than employees.
An audit looks less at the policy document and more at the due-diligence files and whether the reporting channel is genuinely usable.
Who this is for
- Organisations dealing with public bodies, permits or licences
- Organisations in public procurement or large-company supplier registration
- Organisations operating in overseas markets with third-party agents and distributors
- Groups needing a demonstrable anti-corruption posture for investors
🌱 How this relates to ESG
G GovernanceMaps directly onto the G (Governance) pillar. Anti-corruption is one of the most consistently asked questions in governance assessment.
- GRI 205 (Anti-corruption) — asks for risk assessment, training and confirmed incidents. This standard produces all three
- Korea's K-ESG guideline, G domain «ethical management» — code of conduct, reporting channel, action on violations
- UN Global Compact Principle 10 — businesses should work against corruption in all its forms
- Public procurement and group supplier evaluation — an anti-bribery certificate is often a scoring item
- Pairs with ISO 37301 (compliance) — 37001 goes deep on one obligation, 37301 goes wide across all of them
What certification gives you
- You find out where bribery could occur before a regulator doesSee the 8-step process →
- Due diligence on agents and partners — most bribery is paid by third parties, not employeesRequest audit duration and fees →
- A reporting channel means you hear about problems before the press or prosecutors doCheck a certified organisation →
- Evidence of adequate procedures if an incident ever has to be defendedCertification mark rules →
- Pairs with ISO 37301 for compliance obligations beyond briberySee ISO 37301 →
How the requirements are structured
This is the overall shape of what the standard asks for. Working through it in this order is a sensible way to prepare.
| Clause | Title | In plain terms |
|---|---|---|
| 4 | Context | Identify where you operate and with whom, and carry out the bribery risk assessment. Set the scope. |
| 5 | Leadership | The governing body and top management lead, and an independent compliance function is appointed. |
| 6 | Planning | Set anti-bribery objectives and plan how to reach them. |
| 7 | Support | Competence, employment procedures, training, awareness and documented information. |
| 8 | Operation | Due diligence, financial and non-financial controls, gifts and hospitality, raising concerns and investigating. |
| 9 | Performance evaluation | Monitor, audit internally, and report to the governing body. |
| 10 | Improvement | Correct and improve after incidents and audit findings. |
※ This is a summary written to help you, not the text of the standard. Please refer to the published standard for the exact requirements.
Before you apply, please check
Having these in place makes the audit considerably smoother. If you are not ready yet, you are still welcome to get in touch — we will set out what to do first, with a timeline.
- Is there a documented bribery risk assessment covering counterparties, countries and transaction types?
- Is an anti-bribery compliance function appointed, and can it report to the governing body independently?
- Is there due diligence on agents, distributors and major suppliers, with files to show for it?
- Are there rules and records for gifts, hospitality, donations and sponsorship?
- Is there a reporting channel, and does it protect the person reporting? Can reports be anonymous?
- Have staff had anti-bribery training, with attendance records?
- Are there records of investigations and the action taken?
- Have you carried out at least one internal audit yourselves? (required before the audit)
You can apply for ISO 37001 certification here
Tell us your organisation’s size and the standards you need, and we will send you the audit duration and a fee proposal. You are free to decide after seeing it.
Tel 02-786-9242Email info@itscert.or.krFax 02-6940-9317
※ ITS Certification Body does not provide management system consultancy. Auditing and consultancy must remain separate. What we can do is explain the certification process and what you need to have in place.
Which audit division handles this
Audits against this standard are carried out by our 반부패심사본부. See the organisation chart →
