Overview
ISO 37003:2025 - Fraud control management systems - Guidance for organizations managing the risk of fraud - provides practical guidance for developing, implementing and maintaining an effective fraud control management system (FCMS). It covers fraud prevention, early detection and effective response to fraud events, and addresses fraud committed:
- internally and externally,
- in collaboration with business associates or third parties,
- by persons acting on behalf of the organization,
while noting it is not intended for consumer fraud prevention. ISO 37003:2025 applies to all organizations regardless of size, sector or legal form.
Key topics and technical requirements
The standard follows a management-system approach and addresses essential FCMS components:
- Context of the organization - understanding internal/external factors and interested parties; defining FCMS scope and interfaces with other risk functions.
- Fraud risk assessment - identifying, analyzing and prioritizing fraud risks (internal, external, third‑party and collusive fraud).
- Leadership and governance - roles for governing bodies, top management commitment, fraud control policy and delegated decision‑making.
- Fraud control function - establishment of an accountable function and integration with information security and internal audit.
- Planning and objectives - setting measurable fraud control objectives and actions to address risks and opportunities.
- Support and competence - allocating resources, competency requirements, employment processes, awareness and training for personnel and business associates.
- Communication and documented information - promoting the FCMS, record keeping and confidentiality controls.
- Operations - operational planning, fraud prevention measures (including integrity frameworks and conflict‑of‑interest management), detection, response and continual improvement.
Practical applications - who uses ISO 37003
ISO 37003 is a practical guide for:
- Risk managers, compliance and fraud officers building or maturing an FCMS.
- Internal audit, legal, HR and security teams aligning policies, investigation and response processes.
- Boards and senior management seeking governance, oversight and assurance over fraud risk.
- Consultants and service providers designing controls, training and fraud detection programs.
- Organizations that need to integrate fraud control with existing management systems (e.g., information security or enterprise risk).
Benefits include clearer governance, improved early detection, reduced financial and reputational loss, and stronger third‑party controls.
Related standards
ISO 37003 complements established frameworks and management standards such as:
- ISO 37001 (Anti‑bribery management systems),
- ISO 31000 (Risk management),
- ISO 27001 (Information security management).
Organizations commonly use ISO 37003 together with these standards to build an integrated approach to integrity, risk and security.