Compliance culture is the requirement in ISO 37301:2021 that surprises people the first time they read it, because it is not a value statement — it is defined, required and audited. The standard defines it as “values, ethics, beliefs and conduct that exist throughout an organization and interact with the organization’s structures and control systems to produce behavioural norms that are conducive to compliance” (3.28), and its introduction opens with the claim that organisations aiming to be successful in the long term “need to establish and maintain a culture of compliance”. The word that makes it auditable is conduct, which the standard also defines: “behaviours and practices that impact outcomes for customers, employees, suppliers, markets and communities” (3.29). Behaviour leaves evidence. This guide sets out what ISO 37301 requires of compliance culture, the five signals an auditor reads to judge it, how leadership creates or destroys it in decisions rather than speeches, how to measure it without a survey that everyone games, and the five findings that mark a culture that exists on posters only.

What ISO 37301 requires of compliance culture
| Where the requirement sits | What the standard expects | Evidence |
|---|---|---|
| Introduction | Compliance is “made sustainable by embedding it in the culture of the organization and in the behaviour and attitude of people working for it”; leadership “at all levels” and “clear values” are what embed it | The organisation’s values and how they are applied |
| 5 Leadership | Governing body and top management demonstrate commitment — through decisions, resourcing and consequences, not statements alone | Governing-body minutes; budget; decisions that cost money to stay compliant |
| 5.2 Compliance policy | A policy that sets the commitment and the framework | Policy, communicated and understood |
| 7.3 Awareness; 7.4 Communication | Personnel aware of the policy, their contribution and the implications of noncompliance; communication internal and external | Training records; communication plan and evidence |
| 8.3 Raising concerns | A route to report suspected noncompliance with protection for those who use it | Mechanism; usage; protection evidence |
| 9.1 Monitoring | Culture among the things monitored — the standard expects the organisation to evaluate the effectiveness of the CMS, which includes its culture | Indicators; survey and behavioural data; trends |
| 10 Improvement | Noncompliance addressed with corrective action — including where the cause is cultural | Root-cause records naming behaviour and leadership factors |
Our guide to ISO 37301 covers the standard; this post covers the requirement that runs through it.
The five compliance culture signals an auditor reads
| Signal | Question the auditor asks | Strong evidence | Weak evidence |
|---|---|---|---|
| 1 Leadership decisions | When compliance and revenue conflicted, what did leadership choose? | A deal declined, a launch delayed or a customer exited on compliance grounds, minuted | ‘We take compliance seriously’ in the annual report |
| 2 Consequences | What happened to the last person — including a senior one — who broke the rules? | Consistent, proportionate consequences regardless of seniority or performance | Consequences for juniors only; the top performer excused |
| 3 Speaking up | Do people raise concerns, and what happens when they do? | Concerns raised across the organisation; investigated; the person protected; outcomes communicated | Zero concerns raised in three years, presented as good news |
| 4 Resourcing and pressure | Are targets, deadlines and staffing set so compliance is possible? | Compliance capacity in plans; targets reviewed for perverse incentives | Sales targets that can only be met by cutting corners; compliance training done ‘when there is time’ |
| 5 What is measured and rewarded | Do appraisals, bonuses and promotions reflect compliant conduct? | Conduct in performance criteria; promotions withheld for conduct; compliance objectives in executive scorecards | Bonus purely on volume; conduct ‘considered’ with no example |
How leadership creates compliance culture in decisions
- Decide visibly against short-term interest at least once a year, and let people see it: the contract not signed, the shortcut not taken, the launch held.
- Apply consequences upward. One senior consequence teaches more than a hundred junior ones.
- Fund the function and the controls before the incident, not after; resourcing is a decision the standard’s clause 7.1 makes auditable.
- Remove perverse incentives. Review targets, commissions and deadlines for what they push people to do; adjust them and record why.
- Answer concerns in public. “You raised, we investigated, this changed” — without identifying the reporter — is the single strongest cultural signal available.
- Put conduct in the scorecard. Executive objectives with a compliance component; appraisal criteria that include how results were achieved.
Measuring compliance culture without a survey everyone games
| Measure | What it shows | Source |
|---|---|---|
| Concerns raised per 100 staff, by channel and by unit | Willingness to speak up; silent units stand out | 8.3 mechanism data |
| Time from concern to acknowledgement and to closure | Whether speaking up is taken seriously | Case management |
| Substantiation rate and outcome communication | Whether the route works and is seen to work | Investigation records (8.4) |
| Consequence consistency | Sanctions by seniority and performance band for comparable breaches | HR and compliance records |
| Training completion and assessment scores in exposed roles | Awareness where it matters | 7.2, 7.3 records |
| Decisions taken on compliance grounds | Leadership behaviour | Minutes; deal review records |
| Survey items on pressure, fear of retaliation and confidence in leadership | Perception — useful as a trend, not a score | Anonymous survey, same items each year |
| Near-miss and self-reported noncompliance rates | Openness; a rising self-report rate in a maturing system is often good news | 9.1 data; 10 records |
Pair perception with behaviour. A survey score of 4.5 out of 5 on “leadership takes compliance seriously” alongside zero concerns raised and a bonus scheme with no conduct component is a finding, not a result. Our guide to compliance monitoring covers the programme these measures sit in; our guide to the whistleblowing policy covers the speaking-up route.
Five signs of a compliance culture that exists on posters
- Values on the wall, exceptions in the room. The stated value and the observed decision diverge, and everyone knows which one counts.
- Consequences by seniority. The rule applies until it reaches the people who make the numbers.
- No concerns raised. Silence read as health.
- Training as the answer to everything. Every root cause becomes “retrain”, never “the target was impossible” or “the manager told them to”.
- The compliance function as owner of culture. Culture assigned to the function rather than to leadership — the function can measure it; only leadership can create it.
Frequently asked questions
Does ISO 37301 really require a compliance culture?
Yes. It defines compliance culture (3.28) and conduct (3.29), its introduction states that organisations need to establish and maintain a culture of compliance, and its leadership, awareness, raising-concerns, monitoring and improvement clauses are where auditors test it.
How can an auditor assess culture?
Through behaviour and its records: leadership decisions taken on compliance grounds, consequences applied regardless of seniority, concerns raised and handled, resourcing and targets, and what appraisals and bonuses reward. Perception surveys support the picture; they do not make it.
Who owns compliance culture?
The governing body and top management create it through decisions; managers sustain it in their areas; the compliance function measures and reports on it. Assigning ownership of culture to the function is itself a cultural finding.
What is the single most important signal?
Consequences applied to senior and high-performing people for the same conduct that would sanction a junior. Nothing else communicates as clearly what the organisation actually values.
How does this relate to ISO 37001’s anti-bribery culture?
ISO 37001:2025 defines anti-bribery culture (3.30) by adapting ISO 37301’s definition to one risk. The signals and evidence are the same, applied to bribery.
Where this leaves you
Treat compliance culture as the sum of decisions people can see: what leadership chose when it cost something, who faced consequences, what happened to the last person who spoke up, whether the targets allowed compliance, and what the bonus rewarded. Measure behaviour and pair it with perception, put the results in front of the governing body, and fix the incentives before the training — because under ISO 37301 culture is not what the organisation says about itself, it is what an auditor can see it do.
References
- ISO 37301:2021 — Compliance management systems — Requirements with guidance for use — First edition, April 2021; the definitions of compliance culture (3.28) and conduct (3.29) and the introduction on embedding compliance in culture are readable on the ISO Online Browsing Platform.
- ISO 37002:2021 — Whistleblowing management systems — Guidelines — Guidance for the raising-concerns route that culture depends on.
More on ISO 37301
- Compliance culture — you are here
- ISO 37301 explained
- The compliance function
- Compliance monitoring
- Whistleblowing policy
- Compliance risk assessment: clause 4.6
The Compliance Culture Assessment framework and survey items, the governing-body reporting template, the consequence-management procedure and the raising-concerns procedure are in the ISO 37301 Compliance Management Toolkit, or start with the free templates.