A bribery risk assessment is the document ISO 37001:2025 builds everything else on. Clause 4.5 requires it; clause 1 says the extent to which the standard’s requirements apply “depends on the factors specified in 4.1, 4.2 and 4.5”; clause 8.2 triggers due diligence where it shows more than a low risk; and the standard’s organising principle — controls that are “reasonable and proportionate according to the bribery risks the organization faces” — has no meaning without it. An auditor who wants to know whether your gifts register, your agent screening or your financial approvals are proportionate reads the bribery risk assessment first, and a thin one undermines every control in the system however well the control itself is run. This guide sets out what clause 4.5 requires, the risk factors the standard’s own text names — size, locations, sectors, and “the nature, scale and complexity of the organization’s activities” — the method for identifying, analysing and evaluating bribery risks, the scoring criteria that make “low risk” a defensible label rather than a convenient one, how the assessment drives due diligence and controls, and the five findings auditors raise against it.

What clause 4.5 requires of a bribery risk assessment
| Element | What ISO 37001:2025 expects | Evidence |
|---|---|---|
| Identify | The bribery risks the organisation could reasonably anticipate — bribery by it, its personnel and its business associates on its behalf, and bribery of them — direct and indirect | A register of risks by activity, geography, sector, transaction type and relationship |
| Analyse, assess and prioritise | Likelihood and consequence of each identified risk | Scores against defined scales |
| Evaluate existing controls | Whether the controls in place are suitable and effective against each risk | Control column with an effectiveness judgement |
| Criteria | The organisation’s own criteria for evaluating the level of bribery risk, consistent with its policy and objectives | Documented criteria, including what ‘low’ means |
| Review | Regularly, so changes and new information are reflected, and on significant change to structure or activities | Dated reviews; change triggers |
| Documented information | Retained as evidence of the assessment | The assessment file with versions |
The standard’s own risk vocabulary applies: risk is the “effect of uncertainty on objectives” (3.12), characterised by events, consequences and likelihood, and ISO 31000 is in the bibliography. The 2025 edition adds subclauses on climate change — a context factor under 4.1 — and on compliance culture, and addresses conflicts of interest expressly, which widens what the assessment has to consider. Our guide to ISO 37001:2025 covers the edition.
The risk factors a bribery risk assessment must consider
| Factor | What raises the risk | Where to look |
|---|---|---|
| Countries and locations | Operations, customers, agents or supply in jurisdictions with high perceived corruption; the bibliography points to Transparency International’s Corruption Perceptions Index and the World Bank’s governance indicators | Country list against the indices; where officials are met |
| Sectors | Extractives, construction and infrastructure, defence, pharmaceuticals and healthcare, telecoms, logistics and customs-heavy trade, public procurement generally | Sector exposure per business unit |
| Transactions and activities | Government contracts, licences and permits, customs clearance, inspections, tax matters, land, visas and work permits, regulatory approvals, charitable and political donations, sponsorships | The interactions with public officials (3.26) per process |
| Business associates | Agents, intermediaries, consultants, distributors, JV partners, lobbyists — especially on commission or success fees; the standard’s definition is deliberately broad | Associate register by type and role |
| Personnel | Roles that meet officials, approve payments, award contracts, or hold conflicts of interest (3.28) | Position-by-position exposure; declarations |
| Bribery of the organisation | Procurement, recruitment, contract award and approval roles that can be bribed by others — the standard’s scope covers bribery of the organisation and its personnel | Inbound exposure per role |
| Structure and history | Controlled organisations, minority holdings, new acquisitions, past incidents and concerns raised | Group map; incident and concerns log |
Running the bribery risk assessment
- Set the criteria first. Define likelihood and consequence scales with anchors — consequence includes criminal, civil and administrative liability, debarment, contract loss and reputation — and define the level that counts as low, because low is the threshold that switches off due diligence under 8.2. A threshold set after the scores are in is a finding.
- Map the interactions with public officials. Process by process: who meets whom, for what decision, in which country, through whom. This is the inherent-risk map most assessments skip in favour of a country list.
- Add the private-sector bribery routes. ISO 37001 covers bribery in the private and not-for-profit sectors too: kickbacks in procurement, inducements to customers’ buyers, inbound bribery of your own staff.
- Score inherent risk per row — activity × country × relationship — before controls.
- Evaluate existing controls honestly. A policy is not a control; a gifts register nobody reads is not an effective one. Rate suitability and effectiveness separately.
- Score residual risk and decide. Rows above low trigger due diligence (8.2) and the proportionate controls in 8.3–8.10; rows at low are recorded with reasons.
- Get it reviewed by the anti-bribery function and approved by top management. It sets the budget and the appetite; the governing body should see the residual-risk summary.
- Diarise the review — annually and on triggers: new country, sector, product, associate type, acquisition, incident, concern raised, legal change.
How the bribery risk assessment drives the rest of the system
| Assessment output | Clause it drives | What proportionate looks like |
|---|---|---|
| Associates and personnel above low risk | 8.2 Due diligence | Enhanced checks on the exposed few; declarations for the rest; see our anti-bribery due diligence guide |
| Payment routes exposed to bribery | 8.3 Financial controls | Approval thresholds, dual authorisation, no cash, vendor master controls |
| Processes exposed — procurement, contract award, recruitment | 8.4 Non-financial controls | Separation of duties, tender panels, recruitment checks |
| Controlled organisations and high-risk associates | 8.5, 8.6 | Controls implemented in subsidiaries; commitments from associates |
| Gifts, hospitality, donations exposure | 8.7 | Thresholds and approvals scaled to the risk of the counterparty |
| Roles needing awareness | 7.2, 7.3 | Training by exposure, not one course for all |
| Residual risks accepted | 9.3 Management review | Reviewed by top management; reported to the governing body |
The proportionality argument runs one way: from the assessment to the control. Our guide to anti-bribery due diligence covers the first and largest consequence; our guide to gifts and hospitality covers the most visible.
Five bribery risk assessment findings auditors raise
- Country list only. A CPI ranking per country with no activities, interactions or associates behind it; the assessment cannot tell an agent from a stationery supplier.
- Low by default. No criteria defining low; everything not obviously high is scored low and due diligence is switched off across the board.
- Controls rated effective by their existence. The policy is cited as the control for every row.
- Never reviewed. Dated at implementation; the acquisition, the new market and the incident since are absent.
- Inbound bribery ignored. Procurement and recruitment roles not assessed as targets; the standard’s scope covers bribery of the organisation.
Frequently asked questions
What is a bribery risk assessment under ISO 37001?
The clause 4.5 requirement to identify the bribery risks the organisation could reasonably anticipate, analyse and evaluate them against its own criteria, assess the suitability and effectiveness of existing controls, and review the assessment regularly. Clause 1 states that the extent to which the standard’s requirements apply depends on it.
How is it different from the enterprise risk register?
It is specific to bribery — by and of the organisation, its personnel and its business associates — and it is organised by activity, country, transaction and relationship rather than by strategic objective. ISO 31000 supplies the vocabulary; the content is anti-bribery.
What counts as low risk?
Whatever the organisation’s documented criteria say, set before scoring and consistent with the anti-bribery policy. Low is the threshold that determines whether due diligence under 8.2 applies, so it has to be defensible.
How often should it be reviewed?
Regularly — annually is the common cycle — and on significant change: a new country, sector, product, business associate type, an acquisition, an incident, a concern raised or a change in law.
Who should own it?
The anti-bribery function (3.8) runs it with input from sales, procurement, finance, HR and operations; top management approves it; the governing body sees the residual-risk summary.
Where this leaves you
Build the bribery risk assessment before any control: define the criteria and the meaning of low, map the interactions with officials and the private-sector routes, score inherent risk by activity, country and relationship, evaluate the controls honestly, and let the residual scores decide the due diligence, the financial and non-financial controls and the training. Then review it on every change, because under ISO 37001 the assessment is not a record of the system — it is the reason the system looks the way it does.
References
- ISO 37001:2025 — Anti-bribery management systems — Requirements with guidance for use — Second edition, February 2025; clause 1, the introduction on proportionality and the definitions are readable on the ISO Online Browsing Platform.
- UK Ministry of Justice: The Bribery Act 2010 — Guidance — Principle 3, risk assessment.
- Transparency International: Corruption Perceptions Index — Cited in the ISO 37001 bibliography as a country-risk input.
More on ISO 37001
- Bribery risk assessment — you are here
- ISO 37001:2025 explained
- Anti-bribery due diligence: clause 8.2
- Gifts and hospitality under ISO 37001
- Facilitation payments in five laws
- ISO 37001 certification cost
The Bribery Risk Assessment Methodology and Workbook — criteria, scales, the interaction map, inherent and residual scoring and the control-effectiveness column — and the registers it drives are in the ISO 37001 Anti-Bribery Toolkit, or start with the free templates.