Governance DocsGovernance Docs
Browse Toolkits

CART

No products in the cart.

ISO Compliance Insights & Best Practices

ISO 37001 anti-bribery management systems — the 2025 edition

ISO 37001:2025 Anti-Bribery: What the New Edition Requires

ISO 37001 is the international standard for anti-bribery management systems — and if the version you are working from says 2016, you are working from a withdrawn edition.

That is the first thing to fix, because it propagates. Supplier questionnaires, consultant proposals, internal policies and gap analyses across the market still cite the old number, and a programme built on a superseded edition is a programme that has to be redone.

Free gap assessment

Is risk management actually changing decisions?

A maturity assessment against all eight principles, the framework and the process, free. Nobody can certify you to ISO 31000, so this scores distance from good practice instead.

Run the free ISO 31000 maturity assessment →

Which edition of ISO 37001 is current

ISO 37001 editions — the 2025 standard and the withdrawn 2016 edition

ISO 37001:2025 is the current edition — the second — published in February 2025, running to 47 pages and maintained by ISO/TC 309. Its stage on iso.org is 60.60, International Standard published.

The 2016 edition is recorded at stage 95.99, withdrawn, and revised by the 2025 text. The separate climate action amendment, ISO 37001:2016/Amd 1:2024, is also withdrawn — that content now lives in the current edition rather than alongside it.

What ISO 37001 actually requires

It is a management system standard, so it follows the familiar structure: context, leadership, planning, support, operation, performance evaluation, improvement. What makes it specific to bribery is a small number of demanding requirements underneath that frame.

  • A bribery risk assessment covering the organisation’s activities, sectors, geographies, transactions and relationships — and repeated when things change, not once at the start.
  • Due diligence on transactions, projects, business associates and personnel in positions of exposure, proportionate to the assessed risk.
  • An anti-bribery compliance function with the authority and independence to act, and direct access to the governing body.
  • Controls over gifts, hospitality, donations and similar benefits, defined in policy and evidenced in practice.
  • Financial and non-financial controls — the second category is the one organisations forget, and it covers procurement, contracting and operational approvals.
  • A route to raise concerns that protects the person raising them, and a documented investigation process.
  • Governing body and top management commitment, expressed as accountability rather than a signed statement.

The standard is explicit that measures should be reasonable and proportionate to the bribery risk faced. That phrase is doing important work. It is what makes ISO 37001 workable for a fifteen-person consultancy and for a multinational, and it is also why an auditor will want to see your reasoning, not just your controls.

What it does not promise

Two limits worth stating plainly, because the standard states them and marketing material often does not.

Certification does not prove bribery has not occurred. It provides assurance that a management system meeting the requirements is in place. That is genuinely valuable — it is not the same claim.

It is not a substitute for legal advice. ISO 37001 helps you comply with anti-bribery laws; it does not tell you what the UK Bribery Act 2010, the US Foreign Corrupt Practices Act or your local equivalent require of you. The mapping between the standard and any specific statute is work you still have to do.

Certification and the transition question

ISO 37001 is certifiable, and accredited certification runs through ISO/IEC 17021-1 with ISO/IEC TS 17021-9 setting the competence requirements for anti-bribery auditors. The IAF Multilateral Recognition Arrangement has been extended to cover anti-bribery management systems, which is what makes an accredited certificate mean the same thing across borders.

On the transition from the 2016 edition: IAF MD 30:2025, Transition Requirements for ISO 37001:2025 (issued 10 October 2025), sets a two-year transition ending 28 February 2027. Its key timescale: certification bodies to be transitioned by their accreditation bodies by 28 February 2026; initial certification and recertification to ISO 37001:2025 only from 31 August 2026; certified clients transitioned — at a scheduled surveillance audit or a special transition audit — by 28 February 2027, when 2016-edition certificates expire. (Updated 19 September 2026; an earlier version of this post, written before MD 30 was published, said no transition date had been set.) IAF itself ceased operations on 1 January 2026 and its role passed to Global Accreditation Cooperation Incorporated (Global ACI), but MD 30 remains the transition document. Our guide to ISO 37001 certification cost prices the transition.

Confirm the dates with your certification body in writing — they are bound by what their accreditation body has set, and a certificate that lapses on 28 February 2027 costs a full initial audit rather than a transition.

How ISO 37001 relates to neighbouring standards

Standard Relationship
ISO 37301 Compliance management systems — the broader frame. ISO 37001 is the deep, single-risk sibling. Organisations with wide regulatory exposure often run 37301 with 37001 nested inside it for bribery specifically
ISO 27001 Shares the management system structure, so the context, leadership, audit and management review machinery is reusable. The risk methodology is not — bribery risk is assessed differently from information security risk
ISO 9001 Same structural backbone again. If you are already certified, the integration cost is far lower than the standard looks from outside
ISO 37002 Whistleblowing management systems — guidance, not requirements. It is the natural companion to the “raising concerns” requirement

The practical version: if you hold any ISO management system certificate, roughly half of ISO 37001 is machinery you already operate. The other half — risk assessment, due diligence, the compliance function, gifts and hospitality controls — is genuinely new work.

Where organisations get ISO 37001 wrong

  • Treating the risk assessment as a formality. It drives the proportionality argument for every other control. A thin one undermines the whole system in an audit.
  • A compliance function without independence. If the person owning anti-bribery reports to the commercial leadership whose deals they must question, the requirement is not met in substance.
  • Due diligence that stops at onboarding. Business associates change ownership, jurisdiction and behaviour after the contract is signed.
  • Gifts and hospitality policies with no records. The policy is the easy half; the register is what gets tested.
  • Ignoring non-financial controls. Approval routes, contracting and supplier selection are where bribery risk actually sits, and financial controls alone do not reach them.

Where to start

  1. Confirm which edition every document you hold refers to, and retire anything citing 2016.
  2. Run the bribery risk assessment first. Everything proportionate flows from it, and it cannot be retrofitted convincingly.
  3. Decide where the compliance function sits and how it reaches the governing body.
  4. Map to the laws that actually apply to you — the standard will not do this for you.
  5. Build the registers early: gifts and hospitality, due diligence, concerns raised, investigations. They need history before an audit, not after.
  6. Ask your certification body about the transition deadline in writing before booking anything.

This guide reflects iso.org and the IAF resolutions page at 15 August 2026. Editions and transition arrangements change; check both before making a commitment that depends on a date.

The ISO 37001 Anti-Bribery Toolkit provides 55 editable compliance templates covering the anti-bribery policy, the bribery risk assessment, the due diligence records, the gifts and hospitality register, the concern-raising and investigation procedures, and the audit and management review artefacts.

When a standard changes, know first

One email a month: edition changes, new deadlines, and what they mean for documentation you already have. No sales sequence.

We don’t spam! Read our privacy policy for more info.