The ISO 37001:2025 transition is the job that every organization holding an anti-bribery certificate has to plan for, and the sooner you start the less it costs. The 2016 edition has been withdrawn by ISO, and certification bodies are moving their clients to the new edition during a defined transition period.
This guide explains what changed, how big the change really is, how to run a gap analysis and what evidence your auditor will look for. It is written for compliance officers and anti-bribery function owners who already run a working system. Dates and transition rules are set by accreditation and certification bodies, so confirm them with yours; the figures below are what published sources reported at the time of writing.
Free gap assessment
Is risk management actually changing decisions?
A maturity assessment against all eight principles, the framework and the process, free. Nobody can certify you to ISO 31000, so this scores distance from good practice instead.
Run the free ISO 31000 maturity assessment → or View premium report sample
What the ISO 37001:2025 transition involves
ISO 37001 is the international standard for anti-bribery management systems. The 2025 edition replaces the 2016 edition, and ISO lists the 2016 version as withdrawn. It was published in February 2025, following the climate change amendment of 2024 that added a requirement to consider climate change in determining context.
Because the standard was updated to the harmonized structure used by ISO management system standards, much of the change is editorial and structural. One certification body summarizes the impact on certified sites as minimal, although it advises organizations to review how the structural adjustments and clarified requirements affect their systems. That is the right mindset: not a rebuild, but a disciplined gap review.
For a refresher on the basics, see our overview of ISO 37001 anti-bribery.
Key changes to plan for in the ISO 37001:2025 transition
Published summaries of the changes point to a handful of themes. Verify each against the text of the standard you purchased, because summaries differ in detail.
- Harmonized structure: clause titles and common terms line up with other ISO standards
- Anti-bribery culture: a dedicated emphasis for leadership and the governing body
- Climate change: considered when you determine internal and external issues
- Conflict of interest: addressed in employment processes
- Mergers and acquisitions: added as a non-financial control area
- Business partner training: dedicated requirements
- Continual improvement: moved ahead of nonconformity and corrective action in the clause order
Deadline and timeline for the ISO 37001:2025 transition
One certification body reports a transition deadline of 28 February 2027, by which all certified sites must have completed the move. Certification bodies can set their own earlier internal cutoffs, such as requiring a transition audit at your next surveillance or recertification, so ask yours for a written schedule.
Work backward from the audit date. A typical plan leaves three months for the gap analysis and document updates, two months for implementation and an internal audit, and one month for management review before the certification audit. Smaller organizations can move faster; organizations with many entities take longer. Treat these as illustrative figures.
| Area | ISO 37001:2016 | ISO 37001:2025 (reported change) |
|---|---|---|
| Structure | Earlier management system layout | Harmonized structure with common ISO terminology |
| Culture | Leadership commitment and policy | Dedicated emphasis on an anti-bribery culture |
| Context | Internal and external issues | Climate change considered in context |
| People | Employment procedures and training | Conflict of interest added to employment processes |
| Controls | Financial and non-financial controls | Mergers and acquisitions risk identified as a control area |
| Partners | Training for personnel | Dedicated training requirements for business partners |
| Improvement | Nonconformity first | Continual improvement leads the clause |
Step-by-step gap analysis
Start with the clause-by-clause comparison. Use the standard’s own text, not a summary. For each new or changed requirement, record whether your current documents already cover it, what must be edited and who owns the work.
Then test the controls, not just the paper. A culture requirement is met by evidence: leadership messages, surveys, training and decisions where someone chose the ethical option at a cost. Conflict of interest should appear in hiring and in your declaration process. M&A risk needs a due diligence step in any deal workflow. Our guides to bribery risk assessment and anti-bribery due diligence show what good looks like.
Documents and records to update
Update the anti-bribery policy and the scope statement first, since they drive everything else. Then review the following.
- Context and interested parties register, including climate change
- Bribery risk assessment methodology and register
- Governing body and top management commitment records
- Anti-bribery function charter and competence records
- Employment procedures, conflict of interest declarations and training
- Due diligence procedures for projects, partners, and transactions, including M&A
- Gifts and hospitality rules, see gifts and hospitality policy
- Reporting and investigation procedures, see raising concerns and whistleblowing policy
- Internal audit program and management review agenda
How to prepare your auditor evidence
Auditors will sample. Prepare a single evidence pack that shows the changes in practice. Examples include the updated risk assessment with its date and approver, training logs that include business partners, a conflict of interest register, a sample due diligence file, a management review record covering the new inputs and an internal audit report that tested the changed requirements.
If you also run a broader compliance system, check overlaps. Our comparison of ISO 37001 vs ISO 37301 explains where the two fit. Keep facilitation payment rules consistent with your policy; see facilitation payments.
Budget and effort for the ISO 37001:2025 transition
Most of the effort is internal. Audit fees may rise slightly because of extra transition audit time, and some certification bodies add time to a surveillance or recertification audit. For wider cost context, see ISO 37001 certification cost. As a rough guide, organizations that already run a mature system spend weeks, not months, on the transition; those with thin documentation spend much longer.
Templates shorten the drafting. The ISO 37001 Toolkit includes editable policy, risk assessment, due diligence, training and audit documents, so you can update your existing set rather than rewrite it. For the standard itself, see the ISO page for the ISO 37001 standard.
Who should own the ISO 37001:2025 transition
Assign a single owner, usually the anti-bribery compliance function, and a sponsor on the governing body or top management. The owner runs the plan, but the work touches many teams. Human resources updates employment procedures and conflict of interest declarations. Legal and corporate development add bribery risk checks to acquisitions and joint ventures. Procurement and sales adjust business partner onboarding and training. Finance confirms that financial controls still reflect the risk assessment. Put these tasks on a shared tracker with dates and review it every two weeks until the transition audit is complete.
Leadership and culture evidence
Culture is the hardest requirement to evidence because it is about behavior, not paperwork. Collect proof that leaders communicate the anti-bribery stance and act on it: recorded messages, meeting minutes where bribery risk was discussed, examples of business declined because a partner failed due diligence, and results of staff surveys or interviews about whether people feel able to raise concerns. A few well-chosen examples with dates and decisions are more persuasive than a long policy. Ask your internal auditor to interview people at different levels and sites so you learn what they actually say before your certification auditor does.
Training and communication for employees and partners
The new emphasis on business partner training means you should decide which partners present enough risk to need it, what they must learn and how you will record completion. High-risk partners, such as agents, distributors and intermediaries dealing with public officials, deserve live sessions and a signed acknowledgment. Lower-risk partners may receive a short guide and a link to your code of conduct. Update employee training as well so it explains conflict of interest, acquisition risk and the new culture message. Record attendance, test results and dates, and schedule a refresh at a fixed interval so the records stay current through the next surveillance cycle.
Internal audit and management review before the transition audit
Run an internal audit that targets the changed requirements before the certification body arrives. Sample a recent acquisition or partner onboarding, confirm that the conflict of interest process works, check the risk assessment for the climate change consideration and read the minutes of the last management review to see whether the new inputs were discussed. Record findings and close them with corrective action. Then hold a management review that includes the transition status, audit results, bribery risk changes and resource needs, and keep the minutes. These two records tell the auditor the system is being steered, not merely maintained.
Common mistakes in the ISO 37001:2025 transition
The most frequent error is waiting for the deadline. Audit calendars fill up and there is no slack for findings. A second is editing documents without changing practice; auditors will ask staff how they apply the new requirements. A third is ignoring business partners, who now need attention in training. Finally, some teams forget to update their internal audit plan, so the first time the changed clauses are tested is during the certification audit.
ISO 37001:2025 Transition FAQ
When was ISO 37001:2025 published?
ISO lists the 2025 edition as the replacement for the 2016 edition, which it shows as withdrawn. Published summaries place publication in February 2025.
What is the transition deadline?
One certification body reports 28 February 2027. Your own certification body sets the operational schedule, so ask for it in writing.
Is the change large?
Published assessments describe the impact on certified sites as minimal, but structural changes and some new emphasis areas still require a gap review.
Do I need a new certificate?
Yes. Certification to the 2025 edition is demonstrated at a transition audit, often combined with a surveillance or recertification audit.
What documents change first?
Start with the policy, scope, context register and risk assessment, then employment, due diligence, training, audit and management review records.