Governance DocsGovernance Docs
Browse Toolkits

CART

No products in the cart.

ISO Compliance Insights & Best Practices

ISO 37301 compliance management systems standard

ISO 37301: The Certifiable Compliance Management Standard

ISO 37301 is the standard that turned compliance management from something you described into something you can be certified against. That single change — from guidance to requirements — is what makes it worth understanding.

Its predecessor, ISO 19600:2014, offered recommendations. You could align with it and say so, but no certification body could audit you against it, because “should” is not auditable. ISO 19600 is now withdrawn.

What ISO 37301 is

The ISO 37301 record on iso.org and what it means

ISO 37301:2021Compliance management systems — Requirements with guidance for use — was published in April 2021. It is the first edition, 40 pages, maintained by ISO/TC 309.

Two details on that record repay attention.

It sits at stage 90.93: International Standard confirmed. ISO reviewed it and kept it as it stands. That is a meaningfully different position from a standard at 90.92, where a decision to revise has been taken — so unlike some neighbouring standards, ISO 37301 is stable ground to build on.

There is a free amendment. ISO 37301:2021/Amd 1:2024 covers climate action changes and is listed at CHF 0. If your copy of the standard predates it, you are missing content you can obtain at no cost.

What a compliance management system has to contain

ISO 37301 follows the harmonised management system structure — context, leadership, planning, support, operation, performance evaluation, improvement — with compliance-specific requirements inside it.

  • Identified compliance obligations. A maintained register of what actually binds you: law, regulation, permits, contracts, codes and voluntary commitments. This is the foundational artefact and the one most often absent.
  • Compliance risk assessment, linking each obligation to the risk of failing it and to the consequence.
  • A compliance function with defined authority, competence and independence — able to reach the governing body directly.
  • Governing body and top management accountability, expressed through decisions rather than a statement of intent.
  • Controls and procedures proportionate to the assessed compliance risks.
  • A route to raise concerns that protects the person using it, plus a documented investigation process.
  • Compliance culture — treated as a requirement, not an aspiration, which surprises people the first time they read it.
  • Performance evaluation: monitoring, internal audit and management review.

The obligations register is where implementations succeed or fail. Everything else in ISO 37301 is proportionate to it, and a register assembled once by a consultant and never updated makes the whole system indefensible in an audit.

ISO 37301 and ISO 37001 together

These two are frequently confused and are genuinely complementary.

ISO 37301 ISO 37001
Covers All compliance obligations Bribery specifically
Depth Broad, one method across every obligation Deep, with detailed requirements for one risk
Current edition 2021, confirmed, free 2024 climate amendment 2025 — the 2016 edition is withdrawn
Typical use The framework an organisation runs compliance through Nested inside it where bribery exposure is material

An organisation with wide regulatory exposure and real bribery risk usually wants both: ISO 37301 as the operating frame, ISO 37001 as the specialist module inside it. Certifying to ISO 37001 alone leaves every other obligation ungoverned.

How it fits with other standards

Standard Relationship
ISO 31000 Supplies the risk method underneath the compliance risk assessment, so compliance risk is scored on the same scale as everything else
ISO 27001 Shares the management system backbone. If you hold it, the audit, review and improvement machinery is already running
ESG reporting Governance disclosures need evidence that obligations are identified and managed. A compliance management system is that evidence
ISO 37002 Whistleblowing management guidance — the natural companion to the raising-concerns requirement

Where ISO 37301 implementations go wrong

  • A compliance register that is a list of laws. An obligation is what the law requires of you, in your operations. A citation is not an obligation.
  • A compliance function without independence. If it reports to the people whose decisions it must challenge, the requirement is unmet in substance however the org chart reads.
  • Culture treated as a poster. The standard expects evidence — behaviour, decisions, consequences — not a values statement.
  • No link between obligations and controls. An auditor will trace one to the other; if the trace does not exist, the system is documentation rather than management.
  • Missing the free amendment. There is no reason to be working from the unamended text.

Where to start

  1. Build the compliance obligations register properly, by operation rather than by statute, and give each obligation an owner.
  2. Download Amendment 1 — it costs nothing.
  3. Assess compliance risk using the same method as the rest of the organisation.
  4. Fix the reporting line for the compliance function before anything else structural.
  5. Trace obligations to controls explicitly, in a form an auditor can follow.
  6. Decide whether ISO 37001 sits inside it, based on your actual bribery exposure rather than on what a certificate would look like.

This guide reflects the ISO 37301 record on iso.org at 15 August 2026: published, first edition, confirmed at stage 90.93, with the 2024 climate amendment available.

The ISO 37301 Compliance Management Toolkit provides 24 editable templates covering the compliance policy, the obligations register, the compliance risk assessment, the concern-raising and investigation procedures, and the audit and management review records.

Stay Compliance-Ready

Get compliance tips, new toolkit releases, and standard updates in your inbox.

We don’t spam! Read our privacy policy for more info.