Governance DocsGovernance Docs
Browse Toolkits

CART

No products in the cart.

ISO Compliance Insights & Best Practices

ISO 37001 raising concerns and bribery investigation process

ISO 37001 Raising Concerns: Whistleblowing and Investigations 2026

ISO 37001 raising concerns is the part of an anti-bribery management system that decides whether anyone will tell you when something is wrong, and what happens next when they do. A programme can have a strong policy, training and due diligence, and still fail if staff do not trust the reporting route or if investigations are handled by the people who are implicated.

This guide covers the requirements on raising concerns and on investigating and dealing with bribery, which sit in clauses 8.9 and 8.10 in the numbering of the 2016 edition. The current edition is ISO 37001:2025, and the wording below is drawn from published commentary on the standard’s requirements, so check exact text in your licensed copy. For the overall standard, see our guide to ISO 37001:2025.

Free gap assessment

Is risk management actually changing decisions?

A maturity assessment against all eight principles, the framework and the process, free. Nobody can certify you to ISO 31000, so this scores distance from good practice instead.

Run the free ISO 31000 maturity assessment →  or  View premium report sample

What ISO 37001 raising concerns requires

Commentary on the standard describes the raising-concerns requirement as a set of procedures that encourage and enable people to report in good faith, or on the basis of a reasonable belief, any attempted, suspected or actual bribery, or any violation of or weakness in the anti-bribery system. The reports may come from employees, business associates or others, and the organisation must make them easy to use.

RequirementWhat it means in practice
Encourage and enable reportingA visible policy, several routes and clear instructions
ConfidentialityProtect the identity of the reporter and of others named
AnonymityThe system should permit anonymous reports
No retaliationProhibit retaliation against those who report in good faith
AdvicePersonnel can get guidance from an appropriate person on what to do about a concern

Anonymity is expressed as something the system should permit, not a strict obligation, while confidentiality and the ban on retaliation are firm expectations, according to the commentary. Because national law may add stronger protections, align your procedure with the whistleblower rules that apply where you operate.

Designing routes people will use

People raise concerns when they trust the route, which is the core of ISO 37001 raising concerns. Offer more than one: a line manager, the compliance function, an independent hotline operated by a third party, a web form and a postal address. Publish the routes in the code of conduct, on the intranet and in the training you give. Tell suppliers and other business associates how they can report too, and put it in contracts and onboarding materials. Test the routes, because a hotline number that goes to an unattended voicemail undermines the whole system.

ISO 37001 raising concerns: handling reports

Set out what happens from the moment a report arrives. Acknowledge receipt promptly. Log the report in a case register with a reference number and a restricted access list. Triage it by seriousness and by who is involved, so that a report about a senior manager goes to someone independent of that manager. Decide whether it needs investigation, and record the reasons. Where you are allowed to, tell the reporter what happens next and when they can expect an outcome, without disclosing confidential information. Our bribery risk assessment guide explains how the findings can feed back into your risk picture.

Investigating and dealing with bribery

Alongside ISO 37001 raising concerns, the second requirement covers what the organisation does with a report or a suspicion. Commentary describes a system that assesses and, where appropriate, investigates any bribery or violation that is reported, detected or reasonably suspected. Several features stand out.

  1. Independence. The investigation is carried out by, and reported to, personnel who are not part of the role or function being investigated.
  2. Confidentiality. The investigation and its results are handled confidentially.
  3. Reporting to the compliance function. Results are reported to the anti-bribery compliance function, and to other compliance functions as appropriate.
  4. Appropriate action. If the investigation finds bribery or a violation, the organisation takes suitable action.
  5. Corrective follow-up. Weaknesses found lead to corrective action on the system itself. See the compliance function guide for how that function should operate.

The commentary also notes that the organisation may need qualified people to carry out the work, for example investigators with legal or forensic skills, and that the governing body or top management should be told about serious cases. Use external counsel where the matter is complex, involves senior people or may lead to a disclosure to authorities.

Protecting the reporter and the accused

Fairness runs both ways. Protect reporters from retaliation, and treat the person under investigation with due process: tell them of the allegation at the right time, give them a chance to respond, and avoid conclusions before the evidence is examined. Keep records securely, restrict access and follow data protection rules for the case file. Where the allegation involves a public official or a third party, involve legal counsel before contacting them.

Communication, training and culture

The best procedure fails without a culture that supports it. Top management should say, in words and in action, that reporting is welcome and retaliation will not be tolerated. Include ISO 37001 raising concerns in induction and refresher training, with realistic scenarios such as a request for an unusual payment or a gift offered during a tender. Show leaders acting on cases, without breaching confidentiality, by sharing anonymised outcomes: how many reports were received, how many were investigated and what changed as a result. Managers need training too, because most reports first reach a line manager, who must know not to investigate alone or to warn the subject, and to pass it on to the compliance function at once.

Metrics for management review

Track the number of reports by channel, time to acknowledge and to close, share of reports substantiated, cases involving business associates, retaliation complaints and the outcomes of corrective actions. Use the trends, not just the totals. A rise in reports after a training campaign may signal growing trust, while a sudden fall may signal a problem. Report these figures to top management at least at each management review, so oversight is based on evidence.

Evidence auditors look for on ISO 37001 raising concerns

Auditors do not expect you to have uncovered bribery. They expect to see a working system. Typical evidence includes the whistleblowing or raising-concerns procedure, records of communication to staff and business associates, training material that covers reporting, the case register with anonymised statistics, examples of cases handled from receipt to closure, and management review records that show top management sees the numbers. Zero reports for years can itself raise a question, either about trust in the route or about awareness. Keep trend data and explain it.

A hypothetical example

A distributor with 600 staff receives an anonymous web report that a sales manager offered cash to a customs broker. The compliance officer logs the case, sees that the report involves a manager in the sales division and assigns an investigator from internal audit, who is independent of sales. The investigator reviews expense records, interviews the broker’s contact under counsel’s guidance and reports to the compliance officer and the chief executive. Evidence supports the allegation. The company dismisses the manager, notifies the authorities on advice, suspends the broker and adds a new control on payments to customs agents. Results go to the next management review, with the reporter’s identity protected throughout. The example is illustrative only.

Common weaknesses in ISO 37001 raising concerns

  • One route. Reporting only through the line manager, who may be part of the problem.
  • Little awareness. Staff do not know the route exists, or business associates have never been told.
  • No independence. The person investigating is close to the subject.
  • Weak confidentiality. Case files are visible to too many people.
  • No feedback. Reporters never learn what happened, so they stop reporting.
  • No corrective action. Cases are closed, but the system is unchanged.

Whistleblowing sits at the meeting point of anti-bribery, employment and data protection law. Several jurisdictions give reporters statutory protection, some require specific channels for organisations above a size threshold, and privacy law may limit how long you keep case data and who may see it. Cross-border groups face conflicts, for example when local rules restrict transfers of personal data in a report to a head office. Take legal advice on your procedure in each place you operate, and record the outcome. Document the advice, adapt the procedure where local law is stricter than the standard, and review it whenever the law changes.

Documents and templates

The records for these clauses are a raising-concerns procedure, an investigation procedure, a case register, a reporter and subject communication template, a case report format and a management review summary. The ISO 37001 Toolkit includes templates for these, which you can adapt to your organisation and local law. Read the Volkov Law commentary on ISO 37001 concerns and investigations for a practitioner view, and see ISO 37001 vs ISO 37301 if you also run a wider compliance system.

ISO 37001 raising concerns FAQ

Does ISO 37001 require anonymous reporting?

Commentary says the system should permit anonymous reporting, while confidentiality and protection from retaliation are firmer requirements. Check the exact wording in your copy of the standard.

Who should investigate a bribery allegation?

Someone independent of the function being investigated, often internal audit, legal or an external investigator, reporting to the compliance function.

What if there are no reports?

Auditors may ask why. Check that staff and associates know the routes, that they trust them, and that training covers reporting.

Should business associates be able to report?

Yes. Reports can come from anyone, and you should make the routes known to suppliers, agents and other associates.

When a standard changes, know first

One email a month: edition changes, new deadlines, and what they mean for documentation you already have. No sales sequence.

We don’t spam! Read our privacy policy for more info.