Skip to content

Anti-Bribery · ISO Standards

ISO 37001: anti-bribery management that goes beyond a code of conduct PDF

How to implement ISO 37001:2016 — due diligence, gifts, third parties, and what certification audits test in high-risk markets.

6 min read

ISO 37001 is an anti-bribery management system standard. It helps organizations design due diligence, controls, reporting, investigation, monitoring, and improvement around bribery risk, especially where tenders, agents, distributors, public officials, and high-risk markets are involved.

The checklist helps execute procedures, but the guide explains the decisions that matter: risk appetite, board access, third-party depth, gift and hospitality rules, investigation independence, and how anti-bribery controls work in sales pressure rather than policy language.

In 2026, customers, investors, public buyers, and joint venture partners increasingly ask for evidence that compliance programs operate. A paper policy and annual training are not enough if the people approving deals, gifts, agents, and investigations are conflicted or under-resourced. For ISO 37001, the guide should focus on the moments where business pressure meets discretion. Bribery risk often enters through agents, discounts, tenders, customs interactions, hospitality, donations, sponsorships, hiring requests, and urgent payments. Controls need to operate before the deal closes, not after revenue is booked. Due diligence should be risk-based and refreshed when ownership, market, role, or red flags change. The compliance function also needs a route around local management when allegations involve influential people. The paired checklist should therefore test governance, payment controls, approval evidence, investigation independence, and board reporting against real transactions rather than policy examples. A useful way to read the rest of this guide is to separate evidence from judgment. Evidence shows that an activity happened: a review, record, test, approval, training, scan, exercise, assessment, or decision. Judgment explains why the activity was scoped that way, why the risk treatment is proportionate, why an exception is acceptable, and what would cause the decision to change. The paired checklist should collect evidence and owners, while the guide should help teams avoid false certainty. For each topic, ask what a knowledgeable reviewer would challenge after seeing the first answer. They may ask whether the scope matches production, whether suppliers are included, whether recurring work is current, whether leadership approved trade-offs, and whether public or customer-facing claims match operations. That second layer is where preparation becomes credible. It also keeps teams from overclaiming, because a documented limitation with a plan is usually stronger than a broad statement no one can support. Keep a dated rationale beside the evidence so reviewers can see what changed, who approved the interpretation, and which operating signal would trigger a fresh review. Keep the reviewer-facing story specific enough that another team can repeat the analysis without guessing.

What ISO 37001 actually is

ISO 37001 defines requirements for an anti-bribery management system. It covers leadership, anti-bribery policy, compliance function, bribery risk assessment, due diligence, financial and non-financial controls, gifts and hospitality, reporting, investigation, corrective action, internal audit, and management review.

It does not eliminate bribery risk or replace applicable law. Instead, it provides a management-system structure for preventing, detecting, responding to, and improving controls around bribery risk.

The compliance function needs authority and independence appropriate to risk. In higher-risk environments, a program that cannot reach the board or challenge revenue leaders will struggle to show effective oversight.

Decisions the checklist will not make for you

The checklist cannot decide how much due diligence is enough. The depth should follow country risk, government touchpoints, deal value, third-party role, compensation model, ownership, reputation, and red flags.

It also cannot define acceptable gifts, hospitality, donations, sponsorships, facilitation requests, or entertainment. Rules need thresholds and examples that fit local practice while preventing disguised bribery.

The checklist cannot guarantee investigation independence. Leaders must decide who investigates allegations, how conflicts are screened, when the board is informed, and how evidence is preserved when the implicated unit is powerful.

Where anti-bribery programs actually fail

The first failure is a paper policy without operating controls. Employees complete training, but deal approvals, discounts, commissions, gifts, travel, donations, and third-party onboarding are not reviewed where bribery risk actually enters.

Board access can be weak. If compliance cannot report concerns independently to top management or the governing body, pressure from sales, regional leadership, or a major partner can mute the program before a decision matters.

Gift policies often exclude entertainment or treat it casually. Investigations may also be assigned to the implicated unit, creating obvious independence problems. Both issues make the system look designed for appearance rather than detection and response.

How to use the paired checklist

Use the checklist to map bribery risk before polishing policy. Identify markets, public-sector touchpoints, third parties, tender activity, gifts, charitable contributions, sponsorships, joint ventures, and approval points.

Attach evidence such as due diligence files, risk ratings, approval records, training, gift registers, third-party contracts, payment controls, hotline reports, investigation records, corrective actions, audit results, and board reporting.

Test the checklist against real transactions. Follow one high-risk agent, one gift or entertainment event, one tender, and one allegation from start to finish to see whether the system operates when pressure is present.

What teams get wrong

A code of conduct is an anti-bribery management system.
A code helps, but ISO 37001 expects risk assessment, due diligence, controls, reporting, investigations, monitoring, audits, and improvement.
Gifts are controlled if cash gifts are banned.
Hospitality, travel, entertainment, donations, sponsorships, and favors can carry bribery risk and need clear rules.
The local business unit can investigate its own allegations.
Investigations should account for independence, conflicts, evidence preservation, escalation, and board visibility where appropriate.

When the checklist is enough — and when it is not

  • Use the checklist to organize bribery risk assessment, third-party controls, gifts, reporting, investigations, and audit evidence.
  • Ask a registrar, compliance advisor, or anti-bribery specialist when scope, risk assessment, due diligence depth, or certification readiness is unclear.
  • Ask counsel when bribery allegations, public officials, sanctions, investigations, disclosures, employment action, or cross-border legal duties are involved.
  • Treat this guide as practical orientation, not official ISO or legal text; use the licensed standard and applicable anti-bribery laws for authoritative requirements.

Related checklists

Related field notes

The checklists and field notes provided on this website are for educational and informational purposes only. They do not constitute legal, financial, or professional advice. Completing a checklist does not guarantee compliance, certification, or immunity from audits. Always consult with a certified auditor or legal counsel for your specific organizational needs. Full disclaimer