Governance DocsGovernance Docs
Browse Toolkits

CART

No products in the cart.

ISO Compliance Insights & Best Practices

ISO 37001 vs ISO 37301 explained

ISO 37001 vs ISO 37301: 6 Clear Differences Explained (2026)

ISO 37001 vs ISO 37301 is a question of depth against breadth. ISO 37001:2025 is the anti-bribery management system standard — “applicable only to bribery”, as its scope says, with requirements that go deep into one risk: a bribery risk assessment, due diligence, financial and non-financial controls, gifts and hospitality, raising concerns and investigation. ISO 37301:2021 is the compliance management system standard — the successor to ISO 19600 guidance, now certifiable — that covers every compliance obligation an organisation has, from competition law to data protection to sanctions, at a level that lets each obligation be identified, assessed, controlled and monitored.

Both come from ISO/TC 309, both use the harmonized structure, both are certifiable, and ISO 37001’s introduction says an anti-bribery policy “is a component of an overall compliance policy” and names ISO 37301 as the standard that specifies “requirements for a general compliance management system”. This guide compares the two clause by clause, sets out the six differences that decide which you need, explains the 2025 and 2026 edition position of each, and shows how to run ISO 37001 nested inside ISO 37301 as one system with one audit.

ISO 37001 vs ISO 37301: one risk in depth, all obligations in breadth
ISO 37001:2025 — anti-bribery management system, one risk, deep controls · ISO 37301:2021 — compliance management system, all obligations, the frame the anti-bribery policy sits inside.

ISO 37001 vs ISO 37301 at a glance

Dimension ISO 37001:2025 ISO 37301:2021
Title Anti-bribery management systems — Requirements with guidance for use Compliance management systems — Requirements with guidance for use
Edition Second edition, February 2025 (replaces 2016 and its Amd 1:2024); CHF 196; transition ends 28 February 2027 under IAF MD 30 First edition, April 2021 (replaces ISO 19600:2014 guidance); Amd 1:2024 (climate change); reviewed and confirmed 2026
Committee ISO/TC 309, Governance of organizations ISO/TC 309
Scope Bribery only — by and of the organisation, its personnel and business associates, direct and indirect All compliance obligations — legal, regulatory, contractual, voluntary — the organisation chooses to bring into scope
Risk assessment 4.5 Bribery risk assessment 4.5 Compliance obligations; 4.6 Compliance risk assessment
Operational clauses 8.2 Due diligence; 8.3 Financial controls; 8.4 Non-financial controls; 8.5 Controlled organisations and business associates; 8.6 Anti-bribery commitments; 8.7 Gifts, hospitality, donations; 8.8 Managing inadequacy of controls; 8.9 Raising concerns; 8.10 Investigating and dealing with bribery 8.2 Establishing controls and procedures; 8.3 Raising concerns; 8.4 Investigation processes
The function Anti-bribery function (3.8): person(s) with responsibility and authority for the ABMS Compliance function with access to the governing body
Certifiable Yes; auditor competence under ISO/IEC TS 17021-9 Yes

The six differences that decide ISO 37001 vs ISO 37301

  1. One risk or all of them. ISO 37001 lists in clause 1 exactly what it addresses: bribery in the public, private and not-for-profit sectors, by and of the organisation, its personnel and business associates, direct and indirect. ISO 37301 covers whatever obligations the organisation identifies under 4.5 — and a bribery law is one of them. If the board’s question is “are we protected against bribery”, ISO 37001; if it is “do we manage compliance”, ISO 37301.
  2. Depth of the operational requirements. ISO 37001 has nine operational subclauses on one risk, including due diligence proportionate to assessed risk, financial and non-financial controls, and controls over gifts, hospitality, donations and similar benefits. ISO 37301 has three generic ones — controls and procedures, raising concerns, investigation — that apply to every obligation. An ISO 37301 system that brought bribery into scope would still have to design the ISO 37001 controls itself.
  3. Due diligence. ISO 37001 defines it (3.29) and requires it (8.2) on transactions, projects, activities, business associates and personnel where the risk is more than low. ISO 37301 has no equivalent clause; due diligence is one of the controls an organisation may establish under 8.2.
  4. The function’s mandate. Both require a function with authority and access to the governing body. ISO 37001’s is the anti-bribery function — clarified in the 2025 edition — and it can sit inside a compliance function; ISO 37301’s compliance function owns the whole obligations register.
  5. What the certificate says to the market — the ISO 37001 vs ISO 37301 question buyers actually ask. An ISO 37001 certificate answers a bribery-specific question from a customer, a lender, a public-sector buyer or a prosecutor assessing adequate procedures. An ISO 37301 certificate answers a governance question from a regulator or a board.
  6. Edition timing. ISO 37001 has just changed — new certifications from 31 August 2026 are to the 2025 edition only — while ISO 37301:2021 was confirmed in 2026 with only the 2024 climate amendment. Our guide to ISO 37001:2025 covers the changes; our guide to ISO 37301 covers the compliance standard.

ISO 37001 vs ISO 37301: where they are the same

On ISO 37001 vs ISO 37301 the shared ground is most of the text. Clauses 4.1–4.4, 5, 6, 7, 9 and 10 are harmonized core text in both, with anti-bribery or compliance wording: context, interested parties, scope, leadership and policy, roles, risks and opportunities to the system, objectives, resources, competence, awareness, communication, documented information, monitoring, internal audit, management review and improvement.

Both standards define compliance culture (ISO 37301, 3.28) or anti-bribery culture (ISO 37001, 3.30 — adapted, the standard says, from ISO 37301’s definition), both require a raising-concerns route and an investigation process, and ISO 37001’s introduction states it “can be used in conjunction with” ISO 37301 and ISO 37002. ISO 37001’s definition of anti-bribery culture as “values, ethics, beliefs and conduct that exist throughout an organization” is the compliance-culture idea applied to one risk.

Choosing between ISO 37001 and ISO 37301

Situation Recommendation Why
Sales through agents or intermediaries; public-sector customers; operations in high-risk countries ISO 37001 The exposure is bribery; the deep controls and due diligence are what buyers and prosecutors look for
Regulated business with many obligations — financial services, pharma, energy ISO 37301, with ISO 37001 nested if bribery risk is material The obligations register is the problem; bribery is one row that may deserve its own depth
Tender or customer clause naming ISO 37001 ISO 37001 Meet the clause; add ISO 37301 later if governance wants it
Board wants one compliance framework and one certificate ISO 37301 Breadth first; the anti-bribery controls become 8.2 controls inside it
Adequate-procedures defence under the UK Bribery Act or equivalent ISO 37001 Its structure follows the six principles of the UK guidance closely: proportionate procedures, top-level commitment, risk assessment, due diligence, communication, monitoring
Already certified to one Integrate the other Shared core text; one audit under Global ACI-TECH-3-008 (ex-IAF MD 11)

ISO 37001 vs ISO 37301 resolved: running one inside the other

  1. One obligations register (37301 4.5) with anti-bribery laws — UK Bribery Act 2010, U.S. FCPA, local statutes, the UN and OECD conventions — as entries.
  2. One risk assessment method, two depths. The 37301 compliance risk assessment (4.6) rates every obligation; the 37001 bribery risk assessment (4.5) goes deeper on the one that needs it. Our guide to the bribery risk assessment covers the deep version.
  3. One policy set: a compliance policy with the anti-bribery policy as a component — the arrangement ISO 37001’s introduction describes.
  4. One function, two mandates: the compliance function owns the register; the anti-bribery function — which may be the same people — owns the ABMS, with access to the governing body for both.
  5. ISO 37001’s clause 8 as the bribery controls under ISO 37301’s 8.2: due diligence, financial and non-financial controls, gifts and hospitality, commitments from business associates.
  6. One raising-concerns route and one investigation process serving both (37301 8.3–8.4; 37001 8.9–8.10), with ISO 37002 guidance for whistleblowing.
  7. One audit programme, one management review, one integrated certification audit.

Frequently asked questions

Is ISO 37301 a replacement for ISO 37001?
No. ISO 37301 covers all compliance obligations at a generic level; ISO 37001 covers bribery in depth with requirements — due diligence, financial and non-financial controls, gifts and hospitality — that ISO 37301 does not contain. ISO 37001’s introduction positions the anti-bribery policy as a component of an overall compliance policy.

Can we certify to both with one audit?
Yes. Both use the harmonized structure and come from ISO/TC 309; integrated audits reduce audit time under Global ACI-TECH-3-008. Anti-bribery auditors must meet ISO/IEC TS 17021-9.

Which edition of each applies?
ISO 37001:2025 — with certification to the 2025 edition only from 31 August 2026 and the 2016 edition’s certificates expiring 28 February 2027 under IAF MD 30 — and ISO 37301:2021 with Amd 1:2024, confirmed by ISO in 2026.

Is ISO 19600 still relevant?
ISO 19600:2014 was guidance, not certifiable, and was withdrawn when ISO 37301:2021 replaced it. Documents citing ISO 19600 should be updated.

Which one do customers ask for?
Customers, lenders and public buyers concerned about bribery ask for ISO 37001. Regulators and boards concerned with governance across all obligations ask for ISO 37301. Many organisations end up with both, nested.

Where this leaves you

Decide ISO 37001 vs ISO 37301 by the question being asked of you. Bribery exposure, a tender clause or an adequate-procedures defence points to ISO 37001:2025; a wide obligations landscape and a board wanting one framework points to ISO 37301:2021; and where both are true, nest the anti-bribery system inside the compliance system, run one register, one function and one audit, and let the 37001 clause 8 controls be the deep row in the 37301 table.

References

More on ISO 37001

The anti-bribery policy and manual, the bribery risk assessment workbook, the due diligence procedures, the gifts and hospitality register, the raising-concerns and investigation procedures and the cross-mapping to ISO 37301 are in the ISO 37001 Anti-Bribery Toolkit, or start with the free templates.

When a standard changes, know first

One email a month: edition changes, new deadlines, and what they mean for documentation you already have. No sales sequence.

We don’t spam! Read our privacy policy for more info.