A gifts and hospitality policy is where an anti-bribery management system meets ordinary commercial life, and where most of them fail. Bribery rarely arrives labelled. It arrives as a dinner, a conference invitation, a hamper at Christmas — and the policy’s job is to draw a line people can apply without calling the legal team every time.
This guide covers what ISO 37001 requires, the five things a workable policy must fix, the register that makes it auditable, and the situations that break simple rules.

What ISO 37001 requires on gifts and hospitality
The 2025 edition — the second, which replaces ISO 37001:2016 and incorporates its 2024 amendment — places controls over gifts, hospitality, donations, sponsorships and political contributions within its operational clause, and strengthens the expectation that they are evidenced. Organizations certified to the 2016 edition transition to the 2025 revision by February 2027.
The requirement is not a prohibition. It is that the organization implements procedures designed to prevent the offering, provision or acceptance of such benefits where they could reasonably be regarded as bribery — and that it can demonstrate the procedures operate. That phrasing matters: reasonably regarded is an outside view, not an internal justification.
The five things a policy has to fix
| Decision | What good looks like |
|---|---|
| What is prohibited outright | Cash and cash equivalents, anything to or from a public official without approval, anything during a live tender or negotiation |
| Thresholds | A value below which record only, above which pre-approval — stated per currency and reviewed |
| Who approves | A named role, never the recipient’s own decision, with a route that answers in a day |
| What is recorded | Everything above a low floor, offered and received, accepted and declined |
| How refusal works | A form of words people can actually use, plus what to do with an unreturnable gift |
The last row is the one policies omit and staff need most. Declining a gift from a client in a culture where refusal is an insult requires a script, an alternative — donate to charity, share with the team, return with a letter — and management backing.
The gifts and hospitality register is the control
Written gifts and hospitality rules with no register cannot be audited, and the 2025 edition leans harder on documented evidence. A usable register records the date, who offered or received, the counterparty and their relationship to the organization, the nature and estimated value, the business rationale, the approval decision and who made it, and the outcome.
Two design points decide whether it works. Record declined offers as well as accepted ones — a register with no refusals suggests nobody is using it. And record offers made by your people, not just what comes in; outbound hospitality is where the bribery risk actually sits for most organizations.
Reading the register
The register is intelligence, not an archive. Look for clustering around a single supplier, entries that spike near tender decisions, values that sit just below the approval threshold, and staff who never record anything despite customer-facing roles. Each pattern is a question worth asking, and this is exactly the kind of testing a compliance monitoring programme should be doing.
Where simple rules break
Public officials. Many jurisdictions set near-zero tolerance regardless of value, and the definition of an official is broader than people assume — state-owned enterprise employees are often included. Give this its own rule rather than a threshold.
Facilitation payments. Small payments to speed routine administration are bribes in most legal systems, and the safe policy position is prohibition with a clear route for reporting demands and a safety exception where someone is at physical risk.
Conferences and travel. This is the largest gifts and hospitality value most organizations give. Paying for a customer’s flight and hotel to attend your event is hospitality at a value that clears most thresholds. Set specific rules: economy travel, standard accommodation, a genuine business programme, no accompanying partners.
Charitable donations and sponsorship. A donation to a charity connected to a decision-maker is the oldest route around a gifts policy. Route donations through their own approval, with due diligence on the recipient.
Intermediaries. Agents and distributors providing gifts and hospitality on your behalf are your exposure. The contract has to bind them, and the due diligence has to check.
Frequently asked questions
Does ISO 37001 ban gifts and hospitality?
No. It requires procedures preventing gifts, hospitality, donations and similar benefits from being used, or reasonably regarded as being used, for bribery — and evidence that those procedures work.
What threshold should we set?
There is no correct number. Set it from your sector, your countries and the seniority involved, apply it consistently, and review it — a threshold nobody has revisited in five years is a threshold inflation has already moved.
Do we record gifts we refused?
Yes. Refusals are among the most valuable entries: they show the policy operating and they identify counterparties testing your boundaries.
Who should approve?
Someone senior to the recipient with no interest in the relationship, with the compliance function visible on higher-value items. Self-approval is the defect an auditor looks for first.
What about the 2025 transition?
Certified organizations move to ISO 37001:2025 by February 2027. Read the operational controls and the strengthened evidence expectations against your current register before you book the audit.
Where this leaves you
Write the gifts and hospitality policy so a salesperson can apply it at a dinner without phoning anyone: a short prohibited list, one clear threshold, a named approver who answers quickly, and a script for saying no. Then run the register properly — inbound and outbound, accepted and declined — and read it for patterns rather than filing it. A policy nobody can apply produces an empty register, and an empty register is the finding.
References
- ISO 37001:2025 — anti-bribery management systems, second edition.
- UK Ministry of Justice — Bribery Act 2010 guidance — the adequate procedures principles, including hospitality.
More on anti-bribery
- Gifts and hospitality — you are here
- ISO 37001:2025 explained
- The whistleblowing policy
- ISO 37301 compliance management
Policy templates, registers and due diligence forms are in the ISO 37001 Anti-Bribery Toolkit, or start with the free ISO templates.