Governance DocsGovernance Docs
Browse Toolkits

CART

No products in the cart.

ISO Compliance Insights & Best Practices

anti-bribery due diligence explained

Anti-Bribery Due Diligence: A Complete Guide to ISO 37001 Cl. 8.2

Anti-bribery due diligence is the requirement of clause 8.2 of ISO 37001:2025 that turns a bribery risk assessment into decisions about specific people and deals. The standard defines it precisely: a “process to further assess the nature and extent of the bribery risk and help organizations make decisions in relation to specific transactions, projects, activities, business associates and personnel” (3.29). The word that matters is further — due diligence is not the risk assessment repeated, it is the next step down, applied where the risk assessment under clause 4.5 says the exposure is more than low, and proportionate to it. The other word that matters is the breadth of “business associate”, which the standard says is “deliberately broad”: clients, customers, joint venture partners, outsourcing providers, contractors, consultants, suppliers, agents, distributors, intermediaries and investors. This guide explains what clause 8.2 requires, how to tier business associates and personnel so the due diligence is proportionate, what to check at each tier and what evidence to keep, how to decide and document the outcome, and how to keep due diligence alive after onboarding — the point at which most programmes stop.

Anti-bribery due diligence under ISO 37001 clause 8.2: from risk assessment to decision
4.5 bribery risk assessment → where risk is more than low → 8.2 due diligence on transactions, projects, activities, business associates, personnel → decide: proceed, conditions, decline → refresh on trigger.

What clause 8.2 requires of anti-bribery due diligence

Element What ISO 37001:2025 expects Evidence
Trigger Due diligence where the bribery risk assessment (4.5) indicates more than a low risk for the transaction, project, activity, business associate or personnel category Risk assessment output with the threshold defined
Subjects Transactions, projects and activities; business associates (3.25); personnel in positions of exposure (3.24: directors, officers, employees, temporary staff, volunteers) Tiering rules per subject type
Purpose To further assess the nature and extent of the risk and to inform the decision to proceed, proceed with conditions, or not Decision recorded with rationale
Proportionality Depth and method reasonable and proportionate to the assessed risk — the standard’s organising principle Tier definitions; enhanced procedures for the highest tier
Timing Before the relationship, transaction or appointment, and repeated when circumstances change Dates; refresh triggers; renewal cycle
Documented information Retained as evidence under 7.5 Due diligence file per subject

Two related clauses feed it. Clause 8.5 requires the organisation to implement anti-bribery controls in controlled organisations and to seek them from business associates that pose more than a low risk; clause 8.6 requires anti-bribery commitments from those business associates where practicable. Due diligence is how the organisation knows which associates those are. Our guide to the bribery risk assessment covers the clause 4.5 output that sets the trigger.

Tiering business associates for anti-bribery due diligence

Tier Who falls in it Depth of anti-bribery due diligence Refresh
Enhanced Agents, intermediaries, consultants and distributors who deal with public officials or win business on your behalf; JV partners; associates in high-risk countries or sectors; anyone paid on success or commission Full questionnaire, ownership and control to beneficial owners, sanctions and adverse-media screening, public-official connections, reference checks, interview, site visit where warranted, contractual commitments (8.6), audit rights Annually and on trigger
Standard Suppliers and contractors with public-sector exposure; customers in high-risk jurisdictions; outsourcing providers handling regulated interactions Questionnaire, ownership check, sanctions and adverse-media screening, anti-bribery commitment in contract Every two to three years and on trigger
Basic Low-risk suppliers, customers and service providers identified as low risk by the 4.5 assessment Declaration and contract clause; screening at onboarding At renewal
Out of scope Associates the risk assessment rates low with documented reasons None beyond the assessment record When the assessment changes

Tier by the risk assessment, not by spend or seniority. The agent on a $40,000 retainer who meets the licensing authority is enhanced; the $4 million equipment supplier with no government contact may be basic. The definition of business associate should be read, the standard says, “in line with the bribery risk profile of the organization to apply to business associates which can reasonably expose the organization to bribery risks”. Our guide to the third-party risk assessment covers the wider TPRM tiering the anti-bribery tier sits inside.

What anti-bribery due diligence checks

Check What you are looking for Source Red flag
Identity, ownership and control Who really owns and controls the associate; beneficial owners Corporate registries; declarations; screening databases Opaque ownership; nominee shareholders; recently formed for this deal
Public-official connections Owners, directors or key staff who are, or are related to, public officials (3.26) Declarations; PEP screening; local knowledge Undisclosed relative of the official who awards the contract
Reputation and record Investigations, prosecutions, debarments, adverse media Sanctions and debarment lists; media; references Prior bribery allegations; debarment by a development bank
Commercial rationale Why this associate, why this fee, what service is actually provided Business case; comparable rates Commission above market; vague deliverables; success fees to reach an official
Payment terms Where and to whom payments go Bank details; invoices Offshore accounts; payments to third parties; cash
Their own programme Anti-bribery policy, training, controls, willingness to commit Questionnaire; policy copies; contract Refusal to sign anti-bribery commitments
Personnel in exposed positions Conflicts of interest (3.28, addressed in the 2025 edition), prior conduct, undisclosed interests Pre-employment screening; declarations; periodic re-declaration Undisclosed interest in a supplier or customer

Anti-bribery due diligence: deciding and documenting

  1. Record the tier and why. The risk assessment reference, the factors, the tier.
  2. Record what was checked, by whom, when, and what was found. Screening results, questionnaire, documents obtained.
  3. Assess the red flags. Each flag gets a finding: resolved with evidence, mitigated with a condition, or unresolved.
  4. Decide at the right level. Enhanced-tier decisions go to the anti-bribery function and, for the highest exposure, top management; the decision is proceed, proceed with conditions, or decline, with rationale.
  5. Impose the conditions. Anti-bribery commitments (8.6), controls (8.5), audit rights, payment controls, training, termination rights — written into the contract.
  6. Set the refresh date and triggers and diarise them.

Keeping anti-bribery due diligence alive after onboarding

Due diligence that stops at onboarding is the most common finding, because business associates change: ownership, jurisdiction, the officials they deal with, the people they employ. Refresh on trigger — a change of ownership or key personnel, a new country or public-sector customer, an adverse-media hit, a payment anomaly, a concern raised under 8.9, a missed renewal of commitments — and on cycle by tier. Monitor between refreshes with screening alerts, payment review under the financial controls (8.3), and the gifts and hospitality register, which often surfaces a relationship changing before the associate does. Our guide to the vendor due diligence checklist covers the onboarding controls that keep new associates from arriving unassessed.

Frequently asked questions

What is anti-bribery due diligence under ISO 37001?
The clause 8.2 process, defined in 3.29, of further assessing the nature and extent of bribery risk to inform decisions on specific transactions, projects, activities, business associates and personnel — applied where the bribery risk assessment indicates more than a low risk, and proportionate to it.

Do we have to do it on every supplier?
No. Clause 8.2 is triggered by the risk assessment. Associates rated low with documented reasons need no more than the assessment record; the depth rises with the tier.

What counts as a business associate?
The standard’s definition is deliberately broad: clients, customers, joint venture and consortium partners, outsourcing providers, contractors, consultants, sub-contractors, suppliers, vendors, advisers, agents, distributors, representatives, intermediaries and investors — read in line with the organisation’s bribery risk profile.

Does it cover our own staff?
Yes. Personnel in positions of exposure — the standard defines personnel as directors, officers, employees, temporary staff or workers and volunteers — are subject to due diligence, including conflicts of interest, which the 2025 edition addresses expressly.

How often should it be refreshed?
Enhanced tier annually and on trigger; standard tier every two to three years and on trigger; basic tier at renewal. Triggers include ownership change, new countries or public-sector customers, adverse media, payment anomalies and concerns raised.

Where this leaves you

Run anti-bribery due diligence as the second step of the risk assessment: tier by exposure, check ownership, officials, record, rationale and payments at a depth proportionate to the tier, decide at the right level with a written rationale, write the conditions into the contract, and refresh on trigger. The file that shows all of that, per associate, is what clause 8.2 means by documented information — and what an auditor, a prosecutor or a customer will ask to see.

References

More on ISO 37001

The Business Associate Due Diligence Procedure and Questionnaire, the tiering matrix, the personnel screening and conflict-of-interest declaration forms, the anti-bribery commitment clauses and the due diligence register are in the ISO 37001 Anti-Bribery Toolkit, or start with the free templates.

When a standard changes, know first

One email a month: edition changes, new deadlines, and what they mean for documentation you already have. No sales sequence.

We don’t spam! Read our privacy policy for more info.