Anti-bribery due diligence is the requirement of clause 8.2 of ISO 37001:2025 that turns a bribery risk assessment into decisions about specific people and deals. The standard defines it precisely: a “process to further assess the nature and extent of the bribery risk and help organizations make decisions in relation to specific transactions, projects, activities, business associates and personnel” (3.29). The word that matters is further — due diligence is not the risk assessment repeated, it is the next step down, applied where the risk assessment under clause 4.5 says the exposure is more than low, and proportionate to it. The other word that matters is the breadth of “business associate”, which the standard says is “deliberately broad”: clients, customers, joint venture partners, outsourcing providers, contractors, consultants, suppliers, agents, distributors, intermediaries and investors. This guide explains what clause 8.2 requires, how to tier business associates and personnel so the due diligence is proportionate, what to check at each tier and what evidence to keep, how to decide and document the outcome, and how to keep due diligence alive after onboarding — the point at which most programmes stop.

What clause 8.2 requires of anti-bribery due diligence
| Element | What ISO 37001:2025 expects | Evidence |
|---|---|---|
| Trigger | Due diligence where the bribery risk assessment (4.5) indicates more than a low risk for the transaction, project, activity, business associate or personnel category | Risk assessment output with the threshold defined |
| Subjects | Transactions, projects and activities; business associates (3.25); personnel in positions of exposure (3.24: directors, officers, employees, temporary staff, volunteers) | Tiering rules per subject type |
| Purpose | To further assess the nature and extent of the risk and to inform the decision to proceed, proceed with conditions, or not | Decision recorded with rationale |
| Proportionality | Depth and method reasonable and proportionate to the assessed risk — the standard’s organising principle | Tier definitions; enhanced procedures for the highest tier |
| Timing | Before the relationship, transaction or appointment, and repeated when circumstances change | Dates; refresh triggers; renewal cycle |
| Documented information | Retained as evidence under 7.5 | Due diligence file per subject |
Two related clauses feed it. Clause 8.5 requires the organisation to implement anti-bribery controls in controlled organisations and to seek them from business associates that pose more than a low risk; clause 8.6 requires anti-bribery commitments from those business associates where practicable. Due diligence is how the organisation knows which associates those are. Our guide to the bribery risk assessment covers the clause 4.5 output that sets the trigger.
Tiering business associates for anti-bribery due diligence
| Tier | Who falls in it | Depth of anti-bribery due diligence | Refresh |
|---|---|---|---|
| Enhanced | Agents, intermediaries, consultants and distributors who deal with public officials or win business on your behalf; JV partners; associates in high-risk countries or sectors; anyone paid on success or commission | Full questionnaire, ownership and control to beneficial owners, sanctions and adverse-media screening, public-official connections, reference checks, interview, site visit where warranted, contractual commitments (8.6), audit rights | Annually and on trigger |
| Standard | Suppliers and contractors with public-sector exposure; customers in high-risk jurisdictions; outsourcing providers handling regulated interactions | Questionnaire, ownership check, sanctions and adverse-media screening, anti-bribery commitment in contract | Every two to three years and on trigger |
| Basic | Low-risk suppliers, customers and service providers identified as low risk by the 4.5 assessment | Declaration and contract clause; screening at onboarding | At renewal |
| Out of scope | Associates the risk assessment rates low with documented reasons | None beyond the assessment record | When the assessment changes |
Tier by the risk assessment, not by spend or seniority. The agent on a $40,000 retainer who meets the licensing authority is enhanced; the $4 million equipment supplier with no government contact may be basic. The definition of business associate should be read, the standard says, “in line with the bribery risk profile of the organization to apply to business associates which can reasonably expose the organization to bribery risks”. Our guide to the third-party risk assessment covers the wider TPRM tiering the anti-bribery tier sits inside.
What anti-bribery due diligence checks
| Check | What you are looking for | Source | Red flag |
|---|---|---|---|
| Identity, ownership and control | Who really owns and controls the associate; beneficial owners | Corporate registries; declarations; screening databases | Opaque ownership; nominee shareholders; recently formed for this deal |
| Public-official connections | Owners, directors or key staff who are, or are related to, public officials (3.26) | Declarations; PEP screening; local knowledge | Undisclosed relative of the official who awards the contract |
| Reputation and record | Investigations, prosecutions, debarments, adverse media | Sanctions and debarment lists; media; references | Prior bribery allegations; debarment by a development bank |
| Commercial rationale | Why this associate, why this fee, what service is actually provided | Business case; comparable rates | Commission above market; vague deliverables; success fees to reach an official |
| Payment terms | Where and to whom payments go | Bank details; invoices | Offshore accounts; payments to third parties; cash |
| Their own programme | Anti-bribery policy, training, controls, willingness to commit | Questionnaire; policy copies; contract | Refusal to sign anti-bribery commitments |
| Personnel in exposed positions | Conflicts of interest (3.28, addressed in the 2025 edition), prior conduct, undisclosed interests | Pre-employment screening; declarations; periodic re-declaration | Undisclosed interest in a supplier or customer |
Anti-bribery due diligence: deciding and documenting
- Record the tier and why. The risk assessment reference, the factors, the tier.
- Record what was checked, by whom, when, and what was found. Screening results, questionnaire, documents obtained.
- Assess the red flags. Each flag gets a finding: resolved with evidence, mitigated with a condition, or unresolved.
- Decide at the right level. Enhanced-tier decisions go to the anti-bribery function and, for the highest exposure, top management; the decision is proceed, proceed with conditions, or decline, with rationale.
- Impose the conditions. Anti-bribery commitments (8.6), controls (8.5), audit rights, payment controls, training, termination rights — written into the contract.
- Set the refresh date and triggers and diarise them.
Keeping anti-bribery due diligence alive after onboarding
Due diligence that stops at onboarding is the most common finding, because business associates change: ownership, jurisdiction, the officials they deal with, the people they employ. Refresh on trigger — a change of ownership or key personnel, a new country or public-sector customer, an adverse-media hit, a payment anomaly, a concern raised under 8.9, a missed renewal of commitments — and on cycle by tier. Monitor between refreshes with screening alerts, payment review under the financial controls (8.3), and the gifts and hospitality register, which often surfaces a relationship changing before the associate does. Our guide to the vendor due diligence checklist covers the onboarding controls that keep new associates from arriving unassessed.
Frequently asked questions
What is anti-bribery due diligence under ISO 37001?
The clause 8.2 process, defined in 3.29, of further assessing the nature and extent of bribery risk to inform decisions on specific transactions, projects, activities, business associates and personnel — applied where the bribery risk assessment indicates more than a low risk, and proportionate to it.
Do we have to do it on every supplier?
No. Clause 8.2 is triggered by the risk assessment. Associates rated low with documented reasons need no more than the assessment record; the depth rises with the tier.
What counts as a business associate?
The standard’s definition is deliberately broad: clients, customers, joint venture and consortium partners, outsourcing providers, contractors, consultants, sub-contractors, suppliers, vendors, advisers, agents, distributors, representatives, intermediaries and investors — read in line with the organisation’s bribery risk profile.
Does it cover our own staff?
Yes. Personnel in positions of exposure — the standard defines personnel as directors, officers, employees, temporary staff or workers and volunteers — are subject to due diligence, including conflicts of interest, which the 2025 edition addresses expressly.
How often should it be refreshed?
Enhanced tier annually and on trigger; standard tier every two to three years and on trigger; basic tier at renewal. Triggers include ownership change, new countries or public-sector customers, adverse media, payment anomalies and concerns raised.
Where this leaves you
Run anti-bribery due diligence as the second step of the risk assessment: tier by exposure, check ownership, officials, record, rationale and payments at a depth proportionate to the tier, decide at the right level with a written rationale, write the conditions into the contract, and refresh on trigger. The file that shows all of that, per associate, is what clause 8.2 means by documented information — and what an auditor, a prosecutor or a customer will ask to see.
References
- ISO 37001:2025 — Anti-bribery management systems — Requirements with guidance for use — Second edition, February 2025; the definitions of due diligence (3.29), business associate (3.25), personnel (3.24), public official (3.26) and conflict of interest (3.28) are readable on the ISO Online Browsing Platform.
- UK Ministry of Justice: The Bribery Act 2010 — Guidance — Principle 4, due diligence, and the associated-person concept.
More on ISO 37001
- Anti-bribery due diligence — you are here
- ISO 37001:2025 explained
- Bribery risk assessment: clause 4.5
- Gifts and hospitality under ISO 37001
- Third-party risk assessment
- ISO 37001 certification cost
The Business Associate Due Diligence Procedure and Questionnaire, the tiering matrix, the personnel screening and conflict-of-interest declaration forms, the anti-bribery commitment clauses and the due diligence register are in the ISO 37001 Anti-Bribery Toolkit, or start with the free templates.