What ISO 37001 is and why buyers ask for it
ISO 37001 is the international standard for an Anti-Bribery Management System (ABMS). It sets out the measures an organisation can put in place to prevent, detect and respond to bribery — covering its own conduct, that of its staff, and that of the business partners and intermediaries acting on its behalf. It is designed to be practical and proportionate to the bribery risk an organisation actually faces.
The commercial case is strongest where corruption risk is real and scrutinised. Organisations bidding for public contracts, operating in higher-risk markets, or working through agents increasingly need to demonstrate a credible anti-corruption programme — and a certificate from an independent body carries more weight than a policy document. In the India market and in cross-border trade generally, ISO 37001 has become a recognised way to evidence integrity. It is part of the governance-focused ISO Certifications portfolio that ABS supports.
What the certification audit covers
Certification is a two-stage assessment that examines how bribery risk is managed, including:
- Bribery risk assessment across operations, markets and relationships
- Anti-bribery policy and leadership commitment
- Due diligence on transactions, projects and business partners
- Controls over gifts, hospitality and donations
- Financial and non-financial controls that reduce opportunity for bribery
- Raising concerns and investigation — including whistleblowing mechanisms
Surveillance audits across the three-year cycle confirm the programme remains active and proportionate to the risks. Evidence of genuine operation, not just documented policy, is what auditors look for.
How ABS helps
We prepare you for the certification audit in five steps, tailored to ISO 37001:
- Scope and gap assessment — we agree the scope of your anti-bribery management system and assess what you already have against the standard, so you know exactly what to close.
- Implementation — we help you run the bribery risk assessment, set the anti-bribery policy, and put in place due diligence, gifts-and-hospitality controls, financial and non-financial controls, and a channel for raising concerns.
- Internal audit and management review — we help you run the internal audit and management review the standard requires, so the system has a record of operating before the audit.
- Readiness check — a pre-assessment, approached the way an auditor would approach it, highlights anything still to close.
- Audit support — we support you through the certification body’s Stage 1 and Stage 2 audits and help you close any findings.
Transitioning to the 2025 edition
ISO 37001:2025 is the current, second edition, replacing ISO 37001:2016. It introduces a stronger emphasis on anti-bribery culture, renames the “anti-bribery compliance function” to the “anti-bribery function” with a clearer remit, and expects more involvement from the governing body and top management. Organisations certified to the 2016 edition have until February 2027 to transition. We support transition assessments for organisations certified to the 2016 edition — mapping your existing system to the 2025 requirements and closing the gaps.
Typical timeline
For most organisations, ISO 37001 implementation and certification readiness takes around 12–16 weeks from kick-off, depending on the complexity of your operations and the maturity of existing controls. Organisations with significant third-party exposure typically sit at the longer end. Each engagement begins with a fixed-price scoping call and a proposal within 24 hours.
Common questions
Does ISO 37001 certification guarantee that no bribery occurs?
No certification can guarantee that bribery never happens. What ISO 37001 demonstrates is that you have implemented reasonable, internationally recognised measures to prevent, detect and respond to bribery — a distinction regulators in many jurisdictions look on favourably.
Who needs ISO 37001?
Organisations exposed to bribery risk — those operating in higher-risk markets or sectors, bidding for public contracts, or relying on agents and intermediaries — use it to demonstrate integrity to partners, regulators and customers. It is especially relevant in financial services and cross-border trade.
How does ISO 37001 relate to broader compliance management?
ISO 37001 targets bribery specifically, while compliance management standards (such as ISO 37301) cover compliance obligations more broadly. Many organisations run ISO 37001 as a focused, certifiable programme within a wider framework, often alongside quality certification like ISO 9001.
How long does ISO 37001 certification take?
For most organisations, ISO 37001 implementation and certification readiness takes around 12–16 weeks from kick-off, depending on the complexity of your operations and the maturity of existing controls. Organisations with significant third-party exposure typically sit at the longer end.
What does ABS do, and what does the certification body do?
ABS prepares you for certification: we agree the scope of your anti-bribery management system, assess the gaps, help you implement it, support your internal audit and management review, check readiness and support you through the audits. The certification body, an independent, accredited organisation you choose, carries out the Stage 1, Stage 2 and surveillance audits, makes the certification decision and issues the certificate.
How long is an ISO 37001 certificate valid?
Three years. The certification body carries out surveillance audits in the first and second years, and a recertification audit before the three-year cycle ends.
Which edition of ISO 37001 is current, and is there a transition?
The current edition is ISO 37001:2025, published in February 2025. Since 31 August 2026, new certifications and recertifications are to the 2025 edition only, and organisations certified to ISO 37001:2016 must complete their transition by 28 February 2027, after which 2016-edition certificates are no longer valid.