Knowledge base
ISO 37001:2025: Documentation and Compliance Requirements
This guide explains what ISO 37001:2025 requires, clause by clause, and what evidence an auditor may ask for.
Prem Kumar Dvivedi · 12 سبتمبر 2026
It covers 67 requirements across 7 main areas.
This is not meant to be a simple checklist. A checklist only asks, “Do you have this?” This guide explains what you need to do and what evidence can show that you are actually doing it.
If you first want to understand how prepared your organisation is, you can also use an ISO 37001:2025 readiness assessment to identify gaps and measure your level of readiness.
4. Understanding Your Organisation and Bribery Risks
Clauses 4.1, 4.2, 4.3, 4.4 and 4.5
Understand external factors
You need to identify the outside factors that could create bribery risks, such as:
• Countries where you operate
• Industry or sector risks
• Dealings with government officials
• Use of agents, consultants or intermediaries
Evidence: A documented list of these factors and the date when they were last reviewed.
Understand internal factors
You also need to identify internal factors that could create bribery risks, such as:
• Organisation structure
• Employee compensation
• Sales targets
• Pressure to win business
Evidence: A documented list covering relevant internal issues.
Identify interested parties
You need to know which people or organisations have an interest in your anti-bribery system, such as:
• Customers
• Regulators
• Employees
• Agents
• Joint venture partners
• Owners
Evidence: A list of interested parties and their relevant requirements.
Identify applicable laws
You must identify the anti-bribery laws that apply to your organisation, including laws from other countries that may apply to your business activities.
Evidence: A country-wise legal and regulatory register.
Define the scope of your system
You must clearly define what your anti-bribery management system covers, including:
• Activities
• Locations
• Subsidiaries
• Agents
• Distributors
• Business relationships
Evidence: A documented scope statement.
The scope should reflect where your actual bribery risks exist.
Evidence: A clear connection between the scope and your bribery risk assessment.
Identify your key processes
You should understand your main business processes and how they are connected.
Evidence: A process map or documented list of processes and their owners.
Conduct a bribery risk assessment
You must assess where bribery could happen in your organisation.
Evidence: A documented bribery risk assessment.
The assessment should identify specific situations, not just broad categories.
For example, “corruption risk – medium” is not enough.
You should identify risks related to:
• Activities
• Transactions
• Countries
• Business partners
• Agents and intermediaries
• Specific relationships
You should also assess:
• How likely the risk is
• How serious the impact could be
• Whether existing controls are strong enough
The risk assessment must be reviewed regularly and whenever there is a significant change.
Evidence: Review dates and updated assessments after events such as entering a new market, appointing a new agent or making a major business change.
5. Leadership, Culture and Anti-Bribery Responsibilities
Clauses 5.1.1, 5.1.2, 5.1, 5.2, 5.3.1, 5.3.2 and 5.3.3
Leadership involvement
The board or governing body should approve the anti-bribery policy and review how the system is performing.
Evidence: Board meeting minutes showing discussion and approval.
Senior management should also be able to demonstrate the anti-bribery decisions they have made.
Evidence: Management review records, decisions, resources provided and actions taken.
Review incentives and targets
You should check whether:
• Sales targets
• Bonuses
• Commissions
• Other incentives
could create pressure for employees to ignore anti-bribery requirements.
Evidence: A review of incentive and reward systems.
Show that integrity affects business decisions
The organisation should be able to demonstrate that it has refused or ended business relationships where integrity concerns were identified.
Evidence: A real documented example, where applicable.
Build an ethical culture
Senior leaders should actively promote:
• Honest behaviour
• Transparency
• Speaking up
• Ethical decision-making
Evidence: Leadership communications, employee interactions and examples of values being followed in practice.
Protect people who raise concerns
Employees should be able to report concerns without fear of punishment or retaliation.
Evidence: Protection arrangements, employee feedback or survey results and evidence that people are not penalised for raising genuine concerns.
Maintain an anti-bribery policy
You must have a written anti-bribery policy.
Evidence: Approved, signed and dated policy.
The policy should:
• Prohibit bribery
• Require compliance with applicable laws
• Encourage people to report concerns in good faith
• Explain consequences for violations
The policy should be communicated to employees in appropriate languages and to relevant business partners.
Evidence: Distribution records, translations and communication records.
Define responsibilities
Everyone should understand their role and responsibility within the anti-bribery system.
Evidence: Organisation chart, responsibility matrix or role descriptions.
Appoint an anti-bribery compliance function
A competent person or function must be responsible for anti-bribery compliance.
They should have:
• Appropriate authority
• Adequate resources
• Sufficient independence
• Direct access to senior management or the governing body
Evidence: Appointment letter, responsibilities, authority and reporting structure.
Avoid one-person approval of high-risk decisions
For decisions involving more than a low bribery risk, appropriate checks and approvals should be in place.
Evidence: Delegation of authority and approval procedures showing that one person cannot independently approve a high-risk transaction.
6. Planning
Clauses 6.1 and 6.2
Identify risks and opportunities for the system
You need to identify what could go wrong with the anti-bribery management system itself and where improvements may be possible.
Evidence: Risk and opportunity register with actions, responsibilities and deadlines.
Set measurable anti-bribery objectives
You must establish anti-bribery objectives that can be measured.
Evidence: Objectives with clear targets or numbers.
For each objective, it should be clear:
• What will be done
• Who will do it
• When it will be completed
• What resources are needed
• How success will be measured
Evidence: An action plan covering all five points.
7. Support – People, Training and Documents
Clauses 7.1, 7.2.1, 7.2.2, 7.3, 7.4 and 7.5
Provide resources
The organisation must provide sufficient:
• People
• Budget
• Time
• Other resources
for the anti-bribery system.
Evidence: Budget records and staffing arrangements.
Ensure people are competent
You should identify the skills and experience required for key anti-bribery roles.
Evidence: Competence criteria, qualifications, experience and training records.
Include anti-bribery requirements in employment terms
Employment contracts should require employees to follow the anti-bribery policy and allow appropriate action when requirements are violated.
Evidence: Employment contract clauses and signed acknowledgements.
Conduct background checks
People being appointed to positions with more than a low bribery risk should undergo appropriate screening, where legally permitted.
Evidence: Background-check records and periodic reviews.
Manage conflicts of interest
Employees in relevant positions should declare conflicts of interest.
Evidence: Conflict-of-interest declarations and periodic updates.
Take action when policies are violated
There should be a process for dealing with violations.
Evidence: Disciplinary records and documented actions.
Provide risk-based training
Employees should receive anti-bribery training based on the level of risk associated with their roles.
Training should explain:
• How to identify potential bribery
• How to respond when someone asks for a bribe
• How to report concerns
Evidence: Training programme, attendance records and refresher training records.
Agents, intermediaries and other relevant business partners should also receive appropriate training or briefings when the risk requires it.
Evidence: Training or briefing records.
Communicate effectively
You should decide:
• What anti-bribery information needs to be communicated
• Who should receive it
• When it should be communicated
• Who is responsible for communicating it
Evidence: Communication plan and evidence that policies and reporting channels are communicated.
Control documents and records
Required documents and records must be properly maintained and controlled.
Evidence: Document register, version control, approval records and secure handling of confidential information such as due diligence and investigation records.
8. Anti-Bribery Controls in Daily Business
Clauses 8.1 to 8.10
Apply controls based on risk
Your controls should directly address the risks identified in your bribery risk assessment.
They should apply across all relevant:
• Locations
• Subsidiaries
• Countries
• Business activities
Evidence: Controls linked to identified risks and evidence that they are implemented across the organisation.
Conduct due diligence
You should carry out appropriate checks on higher-risk:
• Transactions
• Projects
• Employees
• Business partners
• Agents
• Consultants
• Distributors
• Joint venture partners
• Important suppliers and customers
Evidence: Due diligence procedure and completed due diligence records.
Know who you are dealing with
Due diligence should help identify the actual owners and controllers of relevant business partners.
Evidence: Beneficial ownership information and screening for:
• Sanctions
• Politically exposed persons
• Negative or adverse media
Due diligence should be reviewed periodically, not just performed when a relationship starts.
Evidence: Review dates and updated due diligence records.
If due diligence identifies serious concerns, the organisation should be able to demonstrate that it has rejected or ended a relationship where appropriate.
Evidence: Records showing the decision and reasons.
Maintain strong financial controls
Financial controls should help prevent bribery payments and prevent them from being hidden.
Controls may include:
• Separation of payment request and approval
• Approval limits
• Controls over cash payments
• Controls over third-party payments
• Controls over payments to other countries
• Accurate accounting records
• No hidden or unofficial accounts
• Review of expense claims
Evidence: Financial procedures, approvals and transaction records.
Maintain non-financial controls
Controls should also exist in areas such as:
• Procurement
• Contracting
• Supplier selection
• Operations
Examples include competitive bidding and approval of single-source purchases.
Evidence: Tender records, supplier-selection records, contract approvals and variation approvals.
Test whether controls actually work
You should periodically check whether your controls are operating effectively.
Evidence: Testing, sampling and review records.
Apply controls to controlled companies
Companies and entities under your control should also implement appropriate anti-bribery controls.
Evidence: Implementation records or equivalent controls within subsidiaries and controlled entities.
Check higher-risk business partners
Higher-risk business partners should have appropriate anti-bribery controls.
Evidence: Assessment of their controls and evidence of actions taken where controls are inadequate.
Obtain anti-bribery commitments
Relevant business partners should commit to preventing bribery and contracts should allow appropriate action if requirements are violated.
Evidence: Contract clauses, written commitments and records of partner acceptance or refusal.
Control gifts and hospitality
Gifts, hospitality, donations and sponsorships should be controlled through:
• Clear limits
• Approval requirements
• Record keeping
Evidence: Policy and register showing what was provided, its value, purpose, recipient and approval.
Control donations and contributions
Charitable donations, political contributions and community payments should also be appropriately controlled.
Evidence: Approval records and documented reasons.
Control travel and hospitality
Travel and hospitality involving government officials and customers should be appropriately reviewed and approved.
Evidence: Approval records and reasonableness checks.
Escalate high-risk situations
If existing controls are not sufficient for a particular transaction, the issue should be escalated before proceeding.
Evidence: Escalation records showing whether the transaction was:
• Paused
• Changed
• Rejected
• Given additional controls
If the organisation decides to proceed, the decision should be approved at an appropriate senior level and the reasons should be documented.
Provide reporting channels
Employees and external parties should have a way to raise concerns confidentially or anonymously.
Evidence: Independent reporting channel available to employees and relevant third parties, including appropriate languages.
Protect people from retaliation
People who raise concerns should be protected from retaliation.
The reporting system should also be trusted and usable.
Evidence: Protection policy, concern register and records showing how concerns were handled.
Investigate concerns
Reports of possible bribery should be investigated by competent and appropriately independent people.
Evidence: Investigation procedure, investigation records and documented findings.
Take action after investigations
Investigation findings should lead to appropriate action where required, such as:
• Disciplinary action
• Contractual action
• Reporting to authorities
• Improvements to controls
• Updating the risk assessment
Evidence: Investigation outcomes and follow-up actions.
9. Monitoring and Reviewing Performance
Clauses 9.1, 9.2, 9.3.1, 9.3.2 and 9.4
Decide what to measure
You should determine what anti-bribery performance indicators you will monitor and how often.
Examples include:
• Due diligence completed
• Training completed
• Gifts and hospitality records
• Concerns reported and closed
• Control testing results
Evidence: Monitoring and measurement plan.
Report results
The results should be analysed and communicated to senior management and the governing body.
Evidence: Reports, analysis and review dates.
Conduct internal audits
The anti-bribery management system should be audited by competent people who are independent of the activities being audited.
Evidence: Audit programme, audit reports, findings and auditor competence records.
Conduct management reviews
Senior management should review the anti-bribery system at planned intervals.
The review should cover areas such as:
• Previous actions
• Changes affecting the organisation
• Bribery risk assessment
• Concerns and reports
• Investigations
• Nonconformities
• Monitoring results
• Audit results
• Resources
• Improvement opportunities
Evidence: Management review agenda, minutes and action records.
Governing body review
The board or governing body should also review the anti-bribery management system at appropriate intervals.
Evidence: Board review records.
Independent compliance review
The anti-bribery compliance function should continuously monitor the system and report important findings to senior management and the governing body.
Evidence: Compliance reports and evidence of direct reporting access.
10. Corrective Action and Continual Improvement
Clauses 10.1 and 10.2
Correct problems
When something goes wrong, you should:
1. Identify the problem
2. Correct it
3. Find out why it happened
4. Take action to prevent it from happening again
Evidence: Nonconformity and corrective action records, including root-cause analysis.
Check whether the problem exists elsewhere
You should also check whether the same weakness exists in:
• Another country
• Another business unit
• Another location
• Another business relationship
Evidence: Records showing that this wider review was completed.
Check whether corrective actions worked
After implementing a corrective action, you should verify that it was effective.
You should also update the risk assessment and controls where necessary.
Evidence: Follow-up records, revised risk assessments and updated controls.
Demonstrate improvement
You should be able to show that your anti-bribery system is improving over time.
Evidence may include:
• Trends in reported concerns
• Investigation results
• Control testing results
• Achievement of objectives
• Management review conclusions
________________________________________
How to Use This Guide
The purpose of ISO 37001:2025 is not simply to create a large number of manuals, templates and documents.
The real requirement is to show that your organisation:
• Identifies its bribery risks
• Makes appropriate decisions
• Implements suitable controls
• Trains its people
• Monitors performance
• Takes action when problems occur
• Continually improves the system
The focus should be on real actions and real evidence, not just paperwork.
A long procedure does not automatically mean compliance. In fact, a procedure that nobody follows can create a bigger problem because an auditor may identify the gap between what is written and what actually happens.
The key question is:
“Does the documented system reflect what people actually do in their day-to-day work?”
If employees can recognise their actual responsibilities and activities in the documented system, the organisation is in a much stronger position to demonstrate that its ISO 37001:2025 anti-bribery management system is working effectively.
What this covers
See how this looks as a working system
Reading about a requirement and seeing the documentation that satisfies it are different things. In a short demo we open the actual manual, procedures and records set for ISO 37001, show you how each clause is answered and where your existing way of working already fits. You will know what implementation involves before you commit to it.
More reading
- Why is ISO Consulting Services Important for Businesses in Bahrain?
ISO consulting services in Bahrain helps organisations improve their processes and meet ISO requirements. They also help businesses build effective management systems that support growth and strengthen market credibility.
24 يناير 2025
- Automotive Suppliers Face Stricter Cybersecurity Assessments
Cybersecurity is becoming a key part of supplier evaluations in the automotive industry. Vehicle manufacturers now check how suppliers protect data and systems alongside quality, cost, and delivery.
13 سبتمبر 2026
- Automotive OEM Vendor Cybersecurity Assessment: Controls, Scoring and ISO Standards Mapping
What does an automotive vendor cybersecurity assessment cover?
13 سبتمبر 2026
