ISO 37301 Compliance Management Systems

Confirms that an organisation has identified every law, regulation, contract term and internal rule it must observe, and manages compliance with them.

ITS own scheme

This standard is not covered by our IAS or UAF accreditation scopes. ITS certifies it under its own scheme. See our accreditations →

What this certification proves

ISO 37301 does not certify that you have never broken a law. Nobody can certify that. It certifies that the laws, regulations, contract terms and internal rules you must observe are listed exhaustively, each has an owner, and there is a mechanism that notices when one is not being met.

The key concept is the compliance obligation, which is broader than legislation — it includes licence conditions, contractual undertakings, industry codes and your own code of ethics.

An audit does not measure the thickness of the rulebook. It asks whether the obligations register is current — whether recent amendments to the law are reflected — and whether the reporting channel actually works.

Who this is for

  • Financial, healthcare, construction and public-sector organisations facing heavy regulation
  • Organisations exposed to serious-accident or fair-trade liability
  • Holding companies and groups needing compliance oversight across subsidiaries
  • Organisations that must demonstrate adequate procedures to regulators

🌱 How this relates to ESG

G Governance

Maps squarely onto the G (Governance) pillar. «Ethics and compliance framework», the most frequently asked governance question, is exactly this standard's content.

  • Korea's K-ESG guideline, G domain «ethical management» and «risk management» — code of conduct, reporting channel, action on violations
  • GRI 2-23 to 2-27 — policy commitments, mechanisms for seeking advice and raising concerns, and compliance with laws and regulations, including fines
  • Korea's Serious Accidents Punishment Act — where a chief officer must show that safety and health obligations were discharged, systematic obligation management is defence evidence
  • Fair-trade compliance programmes (CP) and statutory compliance officer regimes share the same structure, so they can be run together
  • Pairs with ISO 37001 — 37001 goes deep on bribery, 37301 goes wide across every obligation

What certification gives you

How the requirements are structured

This is the overall shape of what the standard asks for. Working through it in this order is a sensible way to prepare.

ISO 37301Compliance Management SystemsP · 조항 4 · 5 · 6PlanBuild a completeobligations register…D · 조항 7 · 8DoAppoint thecompliance function;…C · 조항 9CheckMeasure complianceperformance; audit…A · 조항 10ActRemove causes ofviolations and keep…
계획 → 실행 → 점검 → 개선이 한 번으로 끝나지 않고 계속 돕니다. 심사에서 보는 것도 «이 바퀴가 실제로 도는가» 입니다.
ClauseTitleIn plain terms
4ContextIdentify applicable laws, regulations, contracts and internal rules to build the compliance obligations register, and set the scope.
5LeadershipTop management sets the compliance policy and establishes a compliance function — independence is essential.
6PlanningAssess «how serious would it be if this obligation were breached» and set priorities and objectives.
7SupportPeople, budget, training, the reporting channel and documented information.
8OperationRun the controls, receive reports, investigate and act.
9Performance evaluationMeasure compliance indicators; audit internally and review.
10ImprovementAfter a violation, remove the cause and revise the register and controls.

※ This is a summary written to help you, not the text of the standard. Please refer to the published standard for the exact requirements.

Before you apply, please check

Having these in place makes the audit considerably smoother. If you are not ready yet, you are still welcome to get in touch — we will set out what to do first, with a timeline.

  • Is there a documented register of applicable laws and regulations, and is it current? Reflecting recent amendments is the crucial part
  • Does each obligation have a named owning department and person?
  • Is a compliance function or officer appointed, and is it independent of the business units?
  • Is there a reporting channel with protection for the person reporting? Can reports be anonymous?
  • Has compliance training been delivered, with attendance records?
  • Are there records of investigation and action where a violation occurred?
  • Have you carried out at least one internal audit yourselves? (required before the audit)
  • Does management review cover compliance status, with minutes?
See the 8-step certification process →

You can apply for ISO 37301 certification here

Tell us your organisation’s size and the standards you need, and we will send you the audit duration and a fee proposal. You are free to decide after seeing it.

Tel 02-786-9242Email info@itscert.or.krFax 02-6940-9317

※ ITS Certification Body does not provide management system consultancy. Auditing and consultancy must remain separate. What we can do is explain the certification process and what you need to have in place.

Which audit division handles this

Audits against this standard are carried out by our 반부패심사본부. See the organisation chart →