Skip to content

Independent standards discovery and compliance platform

How we work
European standard guide European standard guide

ISO 37001

ISO 37001

Choose ISO 37001 when your governance purchase concerns an anti-bribery management system. The practical buyer decision is how that work reaches the organisation’s transactions and relationships: a policy document at head office is a different deliverable from a system that people can use when selecting agents, approving payments or raising concerns.
Editorial guide Content updated 7 October 2026
On this page
  1. Choose the correct published document
  2. Scope: bribery, with a defined organisational boundary
  3. Make the proposed system observable
  4. Example: appointing a sales intermediary
  5. Separate the standard, implementation and assessment
  6. Frequently asked purchasing questions
  7. Primary sources and edition check

The verified product is ISO 37001:2025, an international standard. The checked purchase record is not labelled EN ISO 37001. Use the actual designation in the order and resolve any tender that asks for a different adoption instead of adding an EN prefix. Genorma and ISO identify the 2025 second edition, replacing the 2016 text and its amendment. Exact Genorma designation and history; ISO publication record.

Choose the correct published document

Scope: bribery, with a defined organisational boundary

The standard provides requirements and guidance for an anti-bribery management system, including direct and indirect bribery associated with the organisation, its personnel and business associates. It can be used independently or integrated with other management systems. Its stated subject is bribery, not every possible form of misconduct. Published scope.

For a useful brief, describe the business activities, locations and third-party relationships the project includes. Explain the decision points that worry you: a new intermediary, unfamiliar payment instructions, a gift request or a conflict around a purchasing decision. A provider should explain which work it will perform and what operational decisions remain with management.

Make the proposed system observable

An original comparison for anti-bribery service procurement
Decision areaQuestion for the provider
Third-party relationshipsWhich relationships are included and what information will the project require?
Payments and approvalsHow will proposed controls connect to actual financial and purchasing workflows?
Concerns and responsesWho receives information, decides on follow-up and controls access to sensitive records?
TrainingWhich roles need practical instruction rather than a general awareness presentation?
MaintenanceWho updates the system when business models or relationships change?

Compare deliverables, not assurances of “zero risk”. Ask how proposed forms and controls will be used in a normal transaction, what information a decision-maker will receive and how exceptions will be documented. If a service excludes third-party relationships but that is where your most important decisions occur, its low price may describe a narrower project than you need.

Example: appointing a sales intermediary

Imagine a manufacturer expanding into a new market through an intermediary. One implementation offer provides a policy, standard training and a collection of forms. Another includes workshops to map how the intermediary is selected, paid and monitored. The buyer should first decide which of those results it needs, rather than assuming the packages are equivalent because both cite ISO 37001.

A useful evaluation is to trace a hypothetical appointment from initial contact to the first payment. Who provides the information? Who decides whether it is sufficient? What happens when the requested payment arrangement changes? Which team retains the record? Those questions help the buyer identify missing responsibility and information. The example is a procurement exercise, not legal advice or a conclusion about a real intermediary.

Separate the standard, implementation and assessment

The document purchase gives access to requirements. A consultancy engagement might help develop or improve the system. An assessment or certification engagement has a different role and should state its basis and scope. Ask for each stage, charge and responsibility to be described clearly before deciding what to buy.

General quality management is a separate objective: see EN ISO 9001. If your organisation is procuring management-system certification, see EN ISO/IEC 17021-1 for the certification-body purchasing distinction. Neither link is a claim that a wider system or a certificate eliminates bribery risk.

Frequently asked purchasing questions

Is this an EN standard?

The verified product and publisher record say ISO 37001:2025. If a buyer needs a particular national or European designation, check that exact adoption with the seller; do not substitute a prefix on the basis of an informal search label.

Does it cover all fraud and misconduct?

The public scope is confined to bribery. A wider governance brief should identify its other objectives separately so that the selected document and service offer match the actual task.

Should I order the 2016 amendment separately for the new edition?

The checked 2025 life-cycle record places the 2016 edition and its 2024 amendment among withdrawn predecessors. Match supporting materials to the new edition rather than assuming an older amendment updates the new text. ISO life-cycle information.

Primary sources and edition check

Publication and purchase records checked on 7 October 2026. The examples and procurement questions are original guidance. Detailed implementation requires the applicable licensed text and decisions for the actual project.

From reading to action

Need help interpreting, implementing or testing against this standard?

Describe the product, organisation, target market and decision you need to make. We will direct you to the most relevant guide or specialist route available on the platform.

Describe your project