ISO 37001 is the international standard for anti-bribery management systems — and if the version you are working from says 2016, you are working from a withdrawn edition.
That is the first thing to fix, because it propagates. Supplier questionnaires, consultant proposals, internal policies and gap analyses across the market still cite the old number, and a programme built on a superseded edition is a programme that has to be redone.
Which edition of ISO 37001 is current

ISO 37001:2025 is the current edition — the second — published in February 2025, running to 47 pages and maintained by ISO/TC 309. Its stage on iso.org is 60.60, International Standard published.
The 2016 edition is recorded at stage 95.99, withdrawn, and revised by the 2025 text. The separate climate action amendment, ISO 37001:2016/Amd 1:2024, is also withdrawn — that content now lives in the current edition rather than alongside it.
What ISO 37001 actually requires
It is a management system standard, so it follows the familiar structure: context, leadership, planning, support, operation, performance evaluation, improvement. What makes it specific to bribery is a small number of demanding requirements underneath that frame.
- A bribery risk assessment covering the organisation’s activities, sectors, geographies, transactions and relationships — and repeated when things change, not once at the start.
- Due diligence on transactions, projects, business associates and personnel in positions of exposure, proportionate to the assessed risk.
- An anti-bribery compliance function with the authority and independence to act, and direct access to the governing body.
- Controls over gifts, hospitality, donations and similar benefits, defined in policy and evidenced in practice.
- Financial and non-financial controls — the second category is the one organisations forget, and it covers procurement, contracting and operational approvals.
- A route to raise concerns that protects the person raising them, and a documented investigation process.
- Governing body and top management commitment, expressed as accountability rather than a signed statement.
The standard is explicit that measures should be reasonable and proportionate to the bribery risk faced. That phrase is doing important work. It is what makes ISO 37001 workable for a fifteen-person consultancy and for a multinational, and it is also why an auditor will want to see your reasoning, not just your controls.
What it does not promise
Two limits worth stating plainly, because the standard states them and marketing material often does not.
Certification does not prove bribery has not occurred. It provides assurance that a management system meeting the requirements is in place. That is genuinely valuable — it is not the same claim.
It is not a substitute for legal advice. ISO 37001 helps you comply with anti-bribery laws; it does not tell you what the UK Bribery Act 2010, the US Foreign Corrupt Practices Act or your local equivalent require of you. The mapping between the standard and any specific statute is work you still have to do.
Certification and the transition question
ISO 37001 is certifiable, and accredited certification runs through ISO/IEC 17021-1 with ISO/IEC TS 17021-9 setting the competence requirements for anti-bribery auditors. The IAF Multilateral Recognition Arrangement has been extended to cover anti-bribery management systems, which is what makes an accredited certificate mean the same thing across borders.
On the transition from the 2016 edition: as at 15 August 2026 we could not find a published IAF General Assembly resolution setting a transition end date for ISO 37001:2025 on the IAF resolutions page. Management system transitions typically run around three years from publication, which would point at early 2028 — but that is a market norm, not a rule, and it is not a date to plan a certification audit around.
Ask your certification body directly, and ask them in writing. They are bound by whatever their accreditation body has set, and they will know the answer for your certificate specifically.
How ISO 37001 relates to neighbouring standards
| Standard | Relationship |
|---|---|
| ISO 37301 | Compliance management systems — the broader frame. ISO 37001 is the deep, single-risk sibling. Organisations with wide regulatory exposure often run 37301 with 37001 nested inside it for bribery specifically |
| ISO 27001 | Shares the management system structure, so the context, leadership, audit and management review machinery is reusable. The risk methodology is not — bribery risk is assessed differently from information security risk |
| ISO 9001 | Same structural backbone again. If you are already certified, the integration cost is far lower than the standard looks from outside |
| ISO 37002 | Whistleblowing management systems — guidance, not requirements. It is the natural companion to the “raising concerns” requirement |
The practical version: if you hold any ISO management system certificate, roughly half of ISO 37001 is machinery you already operate. The other half — risk assessment, due diligence, the compliance function, gifts and hospitality controls — is genuinely new work.
Where organisations get ISO 37001 wrong
- Treating the risk assessment as a formality. It drives the proportionality argument for every other control. A thin one undermines the whole system in an audit.
- A compliance function without independence. If the person owning anti-bribery reports to the commercial leadership whose deals they must question, the requirement is not met in substance.
- Due diligence that stops at onboarding. Business associates change ownership, jurisdiction and behaviour after the contract is signed.
- Gifts and hospitality policies with no records. The policy is the easy half; the register is what gets tested.
- Ignoring non-financial controls. Approval routes, contracting and supplier selection are where bribery risk actually sits, and financial controls alone do not reach them.
Where to start
- Confirm which edition every document you hold refers to, and retire anything citing 2016.
- Run the bribery risk assessment first. Everything proportionate flows from it, and it cannot be retrofitted convincingly.
- Decide where the compliance function sits and how it reaches the governing body.
- Map to the laws that actually apply to you — the standard will not do this for you.
- Build the registers early: gifts and hospitality, due diligence, concerns raised, investigations. They need history before an audit, not after.
- Ask your certification body about the transition deadline in writing before booking anything.
This guide reflects iso.org and the IAF resolutions page at 15 August 2026. Editions and transition arrangements change; check both before making a commitment that depends on a date.
The ISO 37001 Anti-Bribery Toolkit provides 55 editable compliance templates covering the anti-bribery policy, the bribery risk assessment, the due diligence records, the gifts and hospitality register, the concern-raising and investigation procedures, and the audit and management review artefacts.