Management System Certification
ISO 37001 – Anti-Bribery Management System
Demonstrable anti-bribery controls — the defence that has to exist before you need it.
Why organisations certify
Key benefits of ISO 37001
What certification actually returns, stated specifically rather than generically.
Credibility
Certification is independent evidence that anti-bribery controls exist and function — considerably stronger than a policy document produced after an allegation.
Market Access
Multinational principals, development finance institutions and public tenders increasingly require demonstrable anti-bribery controls to qualify.
Risk Reduction
Risk-based due diligence on third parties addresses the route through which the substantial majority of corporate bribery actually occurs.
Operational Efficiency
Clear delegation, approval thresholds and financial controls remove the ambiguity in which improper payments are made and later disputed.
Customer Trust
Investors, partners and customers treat certified integrity governance as a material factor in counterparty selection.
Regulatory Compliance
Supports compliance with the Prevention of Corruption Act, the UK Bribery Act, the US FCPA and equivalent regimes.
How it works
Our process for ISO 37001
Every stage has a defined purpose, a realistic duration and a stated output.
- 01
Application & Quotation
2–3 working days
You submit an application form covering scope, headcount, sites and shift pattern. We review complexity, confirm audit-day allocation against accreditation rules and issue a fixed quotation.
- 02
Contract & Audit Planning
1 week
On acceptance we appoint a lead auditor with verified technical competence for your sector, agree audit dates and share the audit plan in advance.
- 03
Stage 1 — Readiness Review
1 day (typical)
A documentation and readiness assessment: scope confirmation, review of your management system documents, internal audit and management review evidence, and identification of anything that would block Stage 2.
- 04
Stage 2 — Certification Audit
2–5 days (scope dependent)
On-site assessment of the system in operation. We sample processes, interview staff, examine records and raise findings graded as major, minor or opportunity for improvement.
- 05
Corrective Action & Decision
2–4 weeks
You close out any nonconformities with root-cause analysis and evidence. An independent certification decision-maker — not the audit team — reviews the file and grants certification.
- 06
Certificate Issue
3–5 working days
A three-year certificate is issued and your organisation is listed on our public certified-client directory for verification by your customers.
- 07
Surveillance & Recertification
Annual
Surveillance audits at 12 and 24 months confirm the system remains effective. A full recertification audit is completed before the three-year expiry.
Preparation
Documents required
What we will ask to see. Having these ready before Stage 1 is the single biggest factor in a certification that runs to schedule.
- Completed and signed application form
- Certificate of incorporation / business registration
- Organisation chart and scope statement
- Management system manual or equivalent documented information
- Documented processes, procedures and work instructions
- Internal audit reports covering the full scope
- Management review minutes
- Records of corrective actions and continual improvement
- Applicable legal and regulatory licences for your activity
- Anti-bribery policy approved by the governing body
- Bribery risk assessment covering operations, geographies and third parties
- Anti-bribery compliance function appointment with defined authority and independence
- Due diligence records for business associates, agents and high-risk transactions
- Gifts, hospitality, donations and sponsorship registers with approval thresholds
- Anti-bribery clauses in contracts with business associates
- Whistleblowing / confidential reporting channel and non-retaliation policy
- Investigation records and disciplinary action evidence
- Anti-bribery training records including for high-risk roles
Not sure whether your scope is right?
Scope is the single thing most often got wrong, and it appears verbatim on your certificate. We will review yours before you apply, at no charge — it costs us less than fixing it at recertification.
Talk to a specialistOften certified together
Related standards
Standards sharing the High Level Structure can be operated as one integrated system and audited together, which reduces total audit days.
Quality Management System
Certify a quality management system that delivers consistent products and services and satisfies customers.
Learn moreInformation Security Management System
Certify an ISMS that protects the confidentiality, integrity and availability of information through assessed risk.
Learn moreSupply Chain Security Management
Certify a security management system addressing threats to cargo, facilities, transport and supply chain partners.
Learn moreCommon questions
ISO 37001 — frequently asked questions
Direct answers, including where the honest answer is inconvenient for us.
No, and the standard says so explicitly. Certification confirms that an anti-bribery management system conforming to the requirements has been implemented — it is not a warranty that bribery has never occurred or will never occur. What it demonstrates is that reasonable and proportionate procedures are in place to prevent, detect and respond to it.
ISO 37001 treats facilitation payments as bribes. Where they are illegal in the applicable jurisdiction — as they are in India — the system must prohibit them. Where an organisation faces genuine coercion, the standard expects a documented policy on how such situations are handled, recorded and reported.
The function must have appropriate competence, status, authority and independence, and direct access to the governing body. In smaller organisations it may be an existing senior role, provided there is no conflict of interest with the commercial decisions being controlled.
Question not answered here? Ask a certification specialist — we answer technical questions without requiring an enquiry first.
Talk to us
Talk to a certification expert
Tell us your scope and headcount and we will send a fixed quotation for ISO 37001 with the audit-day calculation shown.
- Quotation within 2–3 working days
- IAF MD 5 audit-day calculation included
- Full three-year cycle cost, not just the first audit
- Your details are used only to answer this enquiry
Next step
Ready to certify to ISO 37001?
We will scope it honestly, show you the calculation behind the price, and tell you plainly if the timeline you need is not achievable.