ISO 37001:2016
Anti-bribery management systems — Requirements with guidance for use
Anti-bribery management systems — Requirements with guidance for use
- Статус документа:
- Отменён
- Формат:
- Электронный (PDF)
- Количество страниц:
- 53
- Дата публикации:
- 13 октября 2016 г.
- Издание:
- ISO IS 37001 edition 1 version 1
- ICS:
- 03.100.01
ISO 37001:2016 specifies requirements and provides guidance for establishing, implementing, maintaining, reviewing and improving an anti-bribery management system. The system can be stand-alone or can be integrated into an overall management system. ISO 37001:2016 addresses the following in relation to the organization's activities: · bribery in the public, private and not-for-profit sectors; · bribery by the organization; · bribery by the organization's personnel acting on the organization's behalf or for its benefit; · bribery by the organization's business associates acting on the organization's behalf or for its benefit; · bribery of the organization; · bribery of the organization's personnel in relation to the organization's activities; · bribery of the organization's business associates in relation to the organization's activities; · direct and indirect bribery (e.g. a bribe offered or accepted through or by a third party). ISO 37001:2016 is applicable only to bribery. It sets out requirements and provides guidance for a management system designed to help an organization to prevent, detect and respond to bribery and comply with anti-bribery laws and voluntary commitments applicable to its activities. ISO 37001:2016 does not specifically address fraud, cartels and other anti-trust/competition offences, money-laundering or other activities related to corrupt practices, although an organization can choose to extend the scope of the management system to include such activities. The requirements of ISO 37001:2016 are generic and are intended to be applicable to all organizations (or parts of an organization), regardless of type, size and nature of activity, and whether in the public, private or not-for-profit sectors. The extent of application of these requirements depends on the factors specified in 4.1, 4.2 and 4.5.
Abstract
Overview
ISO 37001:2016 - Anti-bribery management systems specifies requirements and provides guidance for establishing, implementing, maintaining, reviewing and improving an anti-bribery management system. The standard applies to bribery risks across public, private and not‑for‑profit sectors and covers bribery by or of the organization, its personnel and its business associates, including direct and indirect bribery. ISO 37001:2016 is focused exclusively on bribery (not fraud, money‑laundering or antitrust offences) and can be implemented as a stand‑alone system or integrated into existing management systems.
Key topics and technical requirements
ISO 37001 follows the common high‑level structure for management system standards and includes requirements and guidance across clauses 4–10. Major technical topics include:
-
Context, scope and risk assessment
- Understanding organizational context and stakeholders
- Bribery risk assessment to determine reasonable and proportionate controls
-
Leadership and governance
- Top management and governing‑body commitment
- Anti‑bribery policy and defined roles, responsibilities and authorities
- Establishment of an anti‑bribery compliance function
-
Planning and objectives
- Actions to address risks and opportunities
- Anti‑bribery objectives and implementation plans
-
Support and competence
- Allocation of resources, competence requirements, awareness and training
- Communication and documented information controls
-
Operational controls
- Due diligence on business associates and transactions
- Financial controls (e.g. approvals, recordkeeping) and non‑financial controls
- Management of gifts, hospitality, donations and similar benefits
- Mechanisms for raising concerns, investigation and corrective action
-
Performance evaluation and improvement
- Monitoring, measurement, internal audit and management review
- Nonconformity handling, corrective actions and continual improvement
- Annex A gives practical guidance on implementation
Note: conformity with ISO 37001 reduces risk but does not guarantee bribery will never occur.
Practical applications - who uses this standard
ISO 37001 is used by organizations of all sizes and sectors to:
- Build or strengthen an anti‑bribery compliance program
- Demonstrate commitment to integrity to regulators, customers and partners
- Standardize due diligence and third‑party risk management Typical users include boards and executives, compliance officers, legal teams, internal auditors, procurement, HR and risk managers.
Related standards
ISO 37001 is compatible with and can be integrated into other management system standards such as:
- ISO 9001 (quality management)
- ISO 14001 (environmental management)
- ISO/IEC 27001 (information security)
- ISO 19600 (compliance management), ISO 26000 and ISO 31000 for broader governance and risk guidance
Keywords: ISO 37001, anti‑bribery management systems, anti‑corruption, bribery risk assessment, due diligence, compliance, governance, anti‑bribery policy.
Технические детали
- Технический комитет
- ISO/TC 309 - Governance of organizations
- SKU
- ISO 37001:2016
Похожие стандарты
Стандарты, упомянутые в описании
ISO 3700:1980
ОтменёнAnhydrous hydrogen fluoride for industrial use — Determination of water content — Conductimetric method
ISO/TS 54001:2019
ДействующийQuality management systems — Particular requirements for the application of ISO 9001:2015 for electoral organ…
Overview ISO/TS 54001:2019 - Quality management systems - Particular requirements for the application of ISO 9001:2015 for electoral organizations at all levels of government - provides sector-specif…
BS EN ISO 14002-1:2020
ДействующийEnvironmental management systems. Guidelines for using ISO 14001 to address environmental aspects and conditi…
ISO/IEC 27013:2015
ОтменёнInformation technology — Security techniques — Guidance on the integrated implementation of ISO/IEC 27001 and…
ISO 19600:2014
ОтменёнCompliance management systems — Guidelines
BS EN ISO 26000:2020
ДействующийGuidance on social responsibility.
ISO 31000:2018
ДействующийRisk management — Guidelines
Overview ISO 31000:2018 - Risk management - Guidelines provides a unified, organization‑wide approach to managing risk. It offers adaptable guidance that can be customized to any organization, sector…