ISO 37001:2016 PDF
Anti-bribery management systems — Requirements with guidance for use
Anti-bribery management systems — Requirements with guidance for use
- Статус документа:
- Отменён
- Формат:
- Электронный (PDF)
- Количество страниц:
- 53
- Дата публикации:
- 13 октября 2016 г.
- Издание:
- ISO IS 37001 edition 1 version 1
- ICS:
- 03.100.01
ISO 37001:2016 specifies requirements and provides guidance for establishing, implementing, maintaining, reviewing and improving an anti-bribery management system. The system can be stand-alone or can be integrated into an overall management system. ISO 37001:2016 addresses the following in relation to the organization's activities: · bribery in the public, private and not-for-profit sectors; · bribery by the organization; · bribery by the organization's personnel acting on the organization's behalf or for its benefit; · bribery by the organization's business associates acting on the organization's behalf or for its benefit; · bribery of the organization; · bribery of the organization's personnel in relation to the organization's activities; · bribery of the organization's business associates in relation to the organization's activities; · direct and indirect bribery (e.g. a bribe offered or accepted through or by a third party). ISO 37001:2016 is applicable only to bribery. It sets out requirements and provides guidance for a management system designed to help an organization to prevent, detect and respond to bribery and comply with anti-bribery laws and voluntary commitments applicable to its activities. ISO 37001:2016 does not specifically address fraud, cartels and other anti-trust/competition offences, money-laundering or other activities related to corrupt practices, although an organization can choose to extend the scope of the management system to include such activities. The requirements of ISO 37001:2016 are generic and are intended to be applicable to all organizations (or parts of an organization), regardless of type, size and nature of activity, and whether in the public, private or not-for-profit sectors. The extent of application of these requirements depends on the factors specified in 4.1, 4.2 and 4.5.
Abstract
Overview
ISO 37001:2016 - Anti-bribery management systems specifies requirements and provides guidance for establishing, implementing, maintaining, reviewing and improving an anti-bribery management system. The standard applies to bribery risks across public, private and not‑for‑profit sectors and covers bribery by or of the organization, its personnel and its business associates, including direct and indirect bribery. ISO 37001:2016 is focused exclusively on bribery (not fraud, money‑laundering or antitrust offences) and can be implemented as a stand‑alone system or integrated into existing management systems.
Key topics and technical requirements
ISO 37001 follows the common high‑level structure for management system standards and includes requirements and guidance across clauses 4–10. Major technical topics include:
-
Context, scope and risk assessment
- Understanding organizational context and stakeholders
- Bribery risk assessment to determine reasonable and proportionate controls
-
Leadership and governance
- Top management and governing‑body commitment
- Anti‑bribery policy and defined roles, responsibilities and authorities
- Establishment of an anti‑bribery compliance function
-
Planning and objectives
- Actions to address risks and opportunities
- Anti‑bribery objectives and implementation plans
-
Support and competence
- Allocation of resources, competence requirements, awareness and training
- Communication and documented information controls
-
Operational controls
- Due diligence on business associates and transactions
- Financial controls (e.g. approvals, recordkeeping) and non‑financial controls
- Management of gifts, hospitality, donations and similar benefits
- Mechanisms for raising concerns, investigation and corrective action
-
Performance evaluation and improvement
- Monitoring, measurement, internal audit and management review
- Nonconformity handling, corrective actions and continual improvement
- Annex A gives practical guidance on implementation
Note: conformity with ISO 37001 reduces risk but does not guarantee bribery will never occur.
Practical applications - who uses this standard
ISO 37001 is used by organizations of all sizes and sectors to:
- Build or strengthen an anti‑bribery compliance program
- Demonstrate commitment to integrity to regulators, customers and partners
- Standardize due diligence and third‑party risk management Typical users include boards and executives, compliance officers, legal teams, internal auditors, procurement, HR and risk managers.
Related standards
ISO 37001 is compatible with and can be integrated into other management system standards such as:
- ISO 9001 (quality management)
- ISO 14001 (environmental management)
- ISO/IEC 27001 (information security)
- ISO 19600 (compliance management), ISO 26000 and ISO 31000 for broader governance and risk guidance
Keywords: ISO 37001, anti‑bribery management systems, anti‑corruption, bribery risk assessment, due diligence, compliance, governance, anti‑bribery policy.
Технические детали
- Технический комитет
- ISO/TC 309 - Governance of organizations
- SKU
- ISO 37001:2016
Похожие стандарты
Стандарты, упомянутые в описании
SIST ISO 37001:2025
ДействующийAnti-bribery management systems - Requirements with guidance for use
Overview SIST ISO 37001:2025 - Anti-bribery management systems - Requirements with guidance for use specifies requirements and guidance to establish, implement, maintain, review and continually impro…
ISO 19443:2018/Amd 1:2024
ДействующийQuality management systems — Specific requirements for the application of ISO 9001:2015 by organizations in t…
Overview ISO 19443:2018/Amd 1:2024 is an important amendment to the ISO 19443:2018 standard, which specifies quality management system requirements tailored for organizations within the supply chain…
EN ISO 14001:2026
ДействующийEnvironmental management systems - Requirements with guidance for use (ISO 14001:2026)
Overview EN ISO 14001:2026 - Environmental management systems - Requirements with guidance for use - is an internationally recognized standard developed by CEN with the objective of providing organiz…
ISO/IEC 27001:2022/Amd 1:2024
ДействующийInformation security, cybersecurity and privacy protection — Information security management systems — Requir…
Overview ISO/IEC 27001:2022/Amd 1:2024 is the latest amendment to the internationally recognized ISO/IEC 27001 standard, which establishes requirements for information security management systems (IS…
BS ISO 19600:2014
ОтменёнCompliance management systems. Guidelines
1 Scope This International Standard provides guidance for establishing, developing, implementing, evaluating, maintaining and improving an effective and responsive compliance management system within…
SIST EN ISO 26000:2020
ДействующийGuidance on social responsibility (ISO 26000:2010)
Overview EN ISO 26000:2020 (ISO 26000:2010) - Guidance on social responsibility - provides non‑certifiable, practical guidance for organizations of any size or sector on implementing and promoting so…