ISAO — International Standards Accreditation Organization home pageVerify a certificate

Menu

Governance and risk

ISO 37001:2025

Anti-bribery management systems

ISO 37001 sets out requirements for an anti-bribery management system.

Key facts

Edition
Current edition (2025)
Replaces
ISO 37001:2016 (in transition)

A certified organisation has an anti-bribery policy backed by its leadership, assesses its bribery risks, applies proportionate controls such as due diligence and financial checks, trains its people, gives them a safe way to raise concerns, and investigates what is reported. The 2025 edition gives explicit attention to anti-bribery culture and to conflicts of interest.

Who it suits

Organisations that bid for public contracts, deal with public officials, work through agents, distributors or joint venture partners, or operate in higher-risk sectors and countries. It also suits organisations whose customers, lenders or investors ask for evidence of bribery controls, and public bodies that want to show their own integrity arrangements.

What certification involves

ISAO, or a certification body accredited for ISO 37001, audits the system in two stages: first the scope, the bribery risk assessment, the policy and readiness; then how controls work in practice, for example due diligence on business associates, gifts and hospitality, financial approvals, training and the handling of concerns. The certificate states the scope. Certification cannot show that no bribery has taken place; it shows that the organisation has measures in place, proportionate to its risks, to prevent bribery and to detect and deal with it. Certificates are normally valid for three years, with surveillance audits at least once a year and a recertification audit before expiry. ISAO carries out this certification itself, and also accredits certification bodies to do it. Every certificate ISAO issues, and every certificate issued under ISAO accreditation, is recorded on the public register.

Key themes

  • An anti-bribery policy and visible leadership commitment that support an anti-bribery culture
  • An anti-bribery function with the authority and independence to oversee the system
  • A bribery risk assessment that shapes the controls
  • Due diligence on higher-risk transactions, projects and business associates
  • Financial and non-financial controls, including gifts, hospitality, donations and sponsorship
  • Identifying and managing conflicts of interest
  • Raising concerns without fear of retaliation, and investigating and acting on them

Edition and transition

Current edition
ISO 37001:2025
Replaces
ISO 37001:2016Previous edition, in transition
Transition period under ISAO accreditation
Contact us

ISO 37001:2025, the second edition, was published in February 2025. It replaces ISO 37001:2016 and that edition's 2024 climate change amendment. The revision gives weight to a culture in which bribery is not tolerated, brings conflicts of interest within the system, sets out more fully what the anti-bribery function is for, carries the climate change wording into the text and moves to ISO's current common structure for management system standards.

A certificate to ISO 37001:2016 can stay valid during the transition period, but not beyond its own expiry date and only while it is not suspended or withdrawn. An organisation moves to the new edition through an audit by its certification body, usually combined with a surveillance or recertification audit.

Check a certificate for ISO 37001:2025

  • Enter the certificate number or verification code at Verify a certificate, or scan the QR code on the certificate. The record shows the certificate's status today, for example valid, suspended, withdrawn or expired.
  • Compare the organisation name, scope and sites on the record with the copy you were given. Check that the scope covers the entity, activities and locations you deal with: a certificate for one subsidiary does not cover a whole group.
  • Check who issued the certificate, as named on the record. Where a certification body accredited by ISAO issued it, the record shows the status of that accreditation and its accreditation number, and says so if the accreditation did not cover ISO 37001:2025 when the certificate was issued.
  • During the transition a valid certificate may still name ISO 37001:2016, the previous edition: check it in the same way.
  • If the certificate is not on the register, ISAO cannot confirm it: it may have been issued under another accreditation, or a detail may be wrong. Ask the issuing body, and report a concern if something does not look right.

This is ISAO’s own summary, not the text of the standard. Copies of ISO 37001:2025 can be bought from ISO or from national standards bodies.