Knowledge base
ISO 37001:2025: documentation and compliance requirements
Everything ISO 37001:2025 requires you to document, clause by clause, with what an auditor asks to see for each. Written as requirements rather than as a checklist.
Prem Kumar Dvivedi · ١٢ سبتمبر ٢٠٢٦
This is what ISO 37001:2025 requires you to have, clause by clause, and what an auditor will ask to see for each of it. It covers 67 requirements across 7 areas.
It is deliberately not a checklist. A checklist asks whether you have something; this says what is required and what counts as evidence, which is the question that matters when you are building a system rather than testing one. If you would rather find out where you stand first, the same ground is covered by our free ISO 37001:2025 readiness assessment, which scores you out of 100.
4 Your organisation and your bribery risk
Clauses 4.1, 4.2, 4.3, 4.4, 4.5.
You must have written down the outside things that affect your bribery risk — countries you work in, sectors, dealing with officials, use of agents.
Evidence: A short list of these issues, with a note of when you last looked at it.
You must have written down the inside things — how you are structured, how people are paid, pressure to win work.
Evidence: The same list, covering internal issues.
You must have listed everyone with an interest — customers, regulators, staff, agents, joint venture partners, owners.
Evidence: A list of these groups and what each needs from you.
You must know which anti-bribery laws apply to you, including those from other countries that reach your business.
Evidence: A register by country. Note that some laws, such as the UK and US ones, apply beyond their own borders.
You must have written down what the anti-bribery system covers — which activities, sites, subsidiaries and relationships.
Evidence: A scope statement. How joint ventures, agents and distributors are treated.
The scope must cover where your bribery risk actually is, rather than where it is convenient.
Evidence: The link between the scope and your bribery risk assessment.
You must know what your main processes are and how they fit together.
Evidence: A process map or a list with owners.
You must have carried out a bribery risk assessment.
Evidence: A written assessment identifying where bribery could happen in your business.
It must name specific situations rather than general categories.
Evidence: Risks by activity, transaction, country, counterparty and relationship. 'Corruption risk: medium' is not an assessment.
It must judge how likely each risk is and how bad it would be, and check whether your existing controls are good enough.
Evidence: Likelihood and impact for each. An honest look at whether current controls would actually stop it.
The must be assessment redone regularly and whenever something significant changes.
Evidence: Review dates. Reassessment after entering a new market, appointing an agent or a major change.
5 Leadership, culture and the compliance role
Clauses 5.1.1, 5.1.2, 5.1, 5.2, 5.3.1, 5.3.2, 5.3.3.
The board or governing body approved the anti-bribery policy and looked at how the system is working must have been done.
Evidence: Board minutes showing anti-bribery discussed and the policy approved.
Senior management must be able to point to anti-bribery decisions they made in the last year.
Evidence: Management review notes. Money and people provided. Ask them directly.
You must have looked at whether your targets, bonuses and commission create pressure to cut corners.
Evidence: A review of incentive schemes. Evidence you considered whether the reward system encourages the behaviour you say you forbid.
The company ever walked away from work, or ended a relationship, on integrity grounds must have been done.
Evidence: A real example. This is the strongest evidence of a genuine culture, and auditors ask for it.
Senior managers must actively encourage honest behaviour and openness.
Evidence: What leaders say and do. Communications. Values in practice. This is strengthened in the 2025 version and is tested by talking to staff.
People must be able to raise a concern without fear of being punished for it.
Evidence: Evidence nobody has been penalised. Staff survey results. Ask people.
You must have a written anti-bribery policy.
Evidence: The policy, signed and dated.
It must forbid bribery, require compliance with the law, encourage people to raise concerns in good faith, and set out what happens if it is broken.
Evidence: All four points visible in the text.
The must be policy given to your people in the languages they use, and to the business partners who need it.
Evidence: Distribution records. Translations. Evidence it reached agents and intermediaries.
It must be clear who is responsible for what in the anti-bribery system.
Evidence: Organisation chart. Responsibility list.
There must be someone in charge of anti-bribery compliance who is competent, resourced and independent enough to act.
Evidence: The appointment with defined authority. Evidence they can go straight to the board. Evidence they are not reporting to the very people they oversee.
You must be able to answer: For decisions that carry more than a low bribery risk, does more than one person have to approve them?
Evidence: Written delegated authority rules. Evidence no single person can approve a high-risk deal alone.
6 Planning
Clauses 6.1, 6.2.
You must have worked out what could go wrong with the system itself, and what opportunities there are.
Evidence: A risk and opportunity list at system level, with actions, owners and dates.
You must have set anti-bribery objectives, and they must be able to be measured.
Evidence: Objectives with a target and a number.
For each one, it must be clear what will be done, by whom, by when, with what, and how you will judge it.
Evidence: An action plan covering all five points.
7 Support — people, training and documents
Clauses 7.1, 7.2.1, 7.2.2, 7.3, 7.4, 7.5.
You must provide the people, money and time the anti-bribery system needs.
Evidence: Budget. Staffing of the compliance role.
You must know what competence the compliance role and other key roles need, and do the people have it.
Evidence: Competence criteria. Training and experience records.
You must be able to answer: Do employment contracts require people to follow the anti-bribery policy, and allow you to act if they do not?
Evidence: Contract terms. Signed acknowledgements.
You must carry out checks on people going into roles with more than a low bribery risk.
Evidence: Proportionate screening records, repeated at sensible intervals, where the law allows it.
People must in those roles declare conflicts of interest.
Evidence: Declaration records, updated periodically.
You must take action when someone breaks the policy.
Evidence: Disciplinary records. Evidence the policy has teeth.
You must train people on anti-bribery, with the depth matched to the risk their job carries.
Evidence: A training programme with different content for different roles. Attendance records. Refresher frequency.
The training must tell people how to spot a bribe, how to say no to a demand, and how to report it.
Evidence: Training content covering all three, not just the policy text.
You must train or brief agents, intermediaries and other business partners where the risk warrants it.
Evidence: Records of briefings or training given to third parties.
You must have decided what to communicate about anti-bribery, to whom, when and by whom.
Evidence: A communication plan. Evidence the policy and the reporting route are visible.
You must have the documents and records the standard asks for, kept and controlled.
Evidence: A list of documents and records. Approval and version control. Confidential handling of due diligence files, concerns and investigations.
8 Controls in day-to-day business
Clauses 8.1, 8.2, 8.3, 8.4, 8.5, 8.6, 8.7, 8.8, 8.9, 8.10.
You must have put controls in place that match the risks you identified, and they must be applied everywhere in scope.
Evidence: Controls traceable to the risk assessment. Evidence they apply across sites, subsidiaries and countries, not just at head office.
You must carry out background checks on transactions, projects, partners and people where the risk is more than low.
Evidence: A due diligence procedure with risk-based triggers. Completed checks on agents, consultants, distributors, joint venture partners and significant suppliers and customers.
You must be able to answer: Do those checks find out who really owns and controls the other party?
Evidence: Beneficial ownership recorded. Screening against sanctions, politically exposed persons and adverse media.
The checks must be refreshed, rather than done once at the start.
Evidence: Review dates. Evidence older relationships have been revisited.
You must have ever declined or ended a relationship because of what due diligence found.
Evidence: Records of relationships not taken forward, and why.
You must be able to answer: Are your financial controls strong enough to stop a bribe being paid and hidden?
Evidence: Separation between who requests and who approves payment. Approval limits. Limits on cash and on payments to third parties or third countries. Accurate books with no off-record accounts. Expense claims reviewed.
You must be able to answer: Are your non-financial controls strong enough — in buying, contracting and operations?
Evidence: Competitive tendering. Approval of single-source awards. Contract award and variation approvals. Controls over who selects suppliers.
You must check that these controls are actually working, rather than assuming they are.
Evidence: Testing or sampling records.
The companies must you control apply these controls too.
Evidence: Evidence subsidiaries and controlled entities have implemented the system or equivalent controls.
Your business must partners who carry more than a low risk have their own anti-bribery controls, and you must have checked.
Evidence: Assessment of their controls. Where they have none, what you required of them instead.
You must get an anti-bribery commitment from those partners, and you must be able to act if they break it.
Evidence: Anti-bribery clauses in contracts allowing termination. Written commitments obtained. Records where a partner refused.
You must control gifts, hospitality, donations and sponsorship — with limits, approval and a record.
Evidence: A policy with money limits. A register showing who received what, its value, the reason and who approved it. Evidence the register is used, not just kept.
You must control charitable donations, political contributions and community payments.
Evidence: Approval records and the reasoning for each.
You must control travel and hospitality provided to public officials and customers.
Evidence: Approval records. Reasonableness tests applied.
If a control turns out to be too weak for a particular deal, it must be escalated before the deal goes ahead.
Evidence: An escalation route. Records where a transaction was paused, changed, declined or given extra controls. Approval of any decision to go ahead anyway, at a senior level, with reasons.
Staff must be able to and outsiders raise a concern confidentially or anonymously.
Evidence: A reporting channel independent of line management, open to third parties, in the right languages.
People must be who raise concerns protected from retaliation, and is the channel actually used.
Evidence: Written protection. A register of concerns raised and what happened. A channel that has never been used usually means people do not trust it, not that there is nothing to report.
You must investigate reports of bribery, using people who are competent and not involved themselves.
Evidence: An investigation procedure. Investigation records with findings. Independence of the investigator.
You must be able to answer: Do investigation findings lead to action — disciplinary, contractual, reporting to authorities, and changes to controls?
Evidence: Action taken. Reports to authorities where the law requires it. The risk assessment and controls revisited afterwards.
9 Checking how you are doing
Clauses 9.1, 9.2, 9.3.1, 9.3.2, 9.4.
You must have decided what you will measure about anti-bribery, and how often.
Evidence: A monitoring plan. Measures such as due diligence completed, training done, gifts register activity, concerns raised and closed, control tests passed.
You must look at the results and report them to senior management and the board.
Evidence: Analysis and reports, with dates.
You must audit the anti-bribery system, with auditors independent of what they audit.
Evidence: An audit programme. Audit reports and findings. Auditor competence and independence.
Senior management must review the system at planned intervals.
Evidence: Review dates and attendance.
The review must cover everything the standard asks for.
Evidence: An agenda covering: previous actions, changes, adequacy of the risk assessment, concerns raised, investigations, nonconformities, monitoring and audit results, resources, improvement.
The board must or governing body review the system as well, at sensible intervals.
Evidence: Board review records, separate from the management review.
The compliance must person carry out their own continuing review and report it to the top.
Evidence: Their reports to senior management and the board. Evidence their route is not filtered through the people they oversee.
10 Putting things right and getting better
Clauses 10.1, 10.2.
When something goes wrong, you must deal with it and work out why.
Evidence: Nonconformity and corrective action records with root cause.
You must check whether the same weakness exists in another country, business or relationship.
Evidence: Evidence you looked wider.
You must check later that your fix worked, and update the risk assessment.
Evidence: A follow-up record with a date. Revised risk assessment or controls.
You must be able to show the anti-bribery system is stronger than last year.
Evidence: Trends in concerns, investigations and control testing. Objectives achieved. Management review conclusions.
Using this document
Nothing above asks for a manual, a template pack, or a filing system. It asks for decisions that have been taken deliberately and can be shown to have been taken — which is a far smaller job than most organisations expect, and a different one.
Length is not compliance. A procedure nobody follows is worse than no procedure, because an auditor finds the gap between the two. The test we apply is whether the person who has to do the job recognises their own work in what is written down.
What this covers
See how this looks as a working system
Reading about a requirement and seeing the documentation that satisfies it are different things. In a short demo we open the actual manual, procedures and records set for ISO 37001, show you how each clause is answered and where your existing way of working already fits. You will know what implementation involves before you commit to it.
More reading
- Why is ISO Consulting Services Important for Businesses in Bahrain?
ISO consulting services in Bahrain helps organisations improve their processes and meet ISO requirements. They also help businesses build effective management systems that support growth and strengthen market credibility.
٢٤ يناير ٢٠٢٥
- DPDP Act: documentation and compliance requirements
Everything DPDP Act requires you to document, clause by clause, with what an auditor asks to see for each. Written as requirements rather than as a checklist.
١٢ سبتمبر ٢٠٢٦
- GDPR: documentation and compliance requirements
Everything GDPR requires you to document, clause by clause, with what an auditor asks to see for each. Written as requirements rather than as a checklist.
١٢ سبتمبر ٢٠٢٦
