Contact us
Illustration for ISO management-system services

ISO 37001

ISO 37001 anti-bribery management consulting

ISO 37001 consulting helps organisations manage bribery risks in agency relationships, procurement, sales and high-risk transactions. Vosurein reviews the scope, existing processes and evidence, then helps define responsibilities, implementation steps and internal reviews.

Discuss ISO 37001 Anti-Bribery Management System consulting needs

For Your Business

Who this service is for and when to start

Organisations working with agents, procurement, tenders, cross-border transactions or several layers of partners can start with their higher-risk activities. Consulting also supports customer requests, group policy integration and transition from a system based on the 2016 edition.

Management, business, procurement, and finance must all participate to ensure that policies correspond to actual transactions and approval methods.

The Challenge

Common challenges faced by businesses

While the anti-bribery policy is fully written, the approval of gifts, hospitality, donations, or agency fees lacks background, making it difficult to judge appropriateness. If due diligence is conducted only once at the signing stage, new risks may be missed after changes in cooperation methods.

The reporting mechanism often only has a mailbox and does not clearly assign responsibilities for handling, confidentiality, and follow-up. The system needs to allow problems to be raised and properly addressed.

Our Approach

Methods and applicable requirements

ISO 37001:2025 is the second edition of requirements and usage guidance for the Anti-Bribery Management System, replacing the 2016 edition. It applies to public and private sectors and non-profit organizations, addressing direct and indirect bribery risks. A management system cannot guarantee that bribery will not occur and does not cover all types of fraud and illegal activities.

Risk and Due Diligence

Identify situations needing closer checks based on the transaction, location, relationship and roles involved. Define what business partner information is needed and who approves and updates it. The depth of due diligence should reflect risk.

Financial and Non-Financial Controls

Check how payment, procurement, delegated authority and the giving or receiving of benefits connect. Retain the reasons for decisions and approval evidence. Review exceptions that could bypass normal procedures; complete accounting records alone are not enough.

Reporting and Incident Improvement

Define who receives reports, protects confidentiality, avoids conflicts of interest and follows up improvements. Agree specialist roles where legal responsibility or investigations are involved. Management system consulting does not determine the legal outcome of individual cases.

Process

Consulting scope and process

  1. Review bribery risks in business activities

    Confirm transactions and partnerships, review policies, past incidents, and high-risk management gaps.

  2. Establish Approval and Investigation Processes

    Assign responsibility for due diligence, the giving or receiving of benefits, payments and exceptions.

  3. Implement Training and Record-Keeping

    Select actual cases to verify execution evidence, ensuring personnel understand reporting and approval methods.

  4. Review Control Effectiveness

    Track incidents and audit findings, assist management review, and prepare updated systems.

Preparation

What documents do companies need to prepare?

  • Business and Partners: Locations, transaction types, agents, and other partnerships.
  • Risk and Investigation: Risk assessment, due diligence, and review records.
  • Authorization and Interactions: Policies and approval samples for payments, procurement, gifts, and entertainment.
  • Reporting and Improvement: Training, report handling, and summary of improvement follow-ups.

For an initial discussion, provide a summary or de-identified sample. Share full records under the agreed scope, access permissions and confidentiality arrangements. Check whether existing records are still valid before filling gaps; there is no assumption that every document must be rewritten.

Project Planning

Estimating time and cost

Assess based on transaction complexity, overseas locations, number of partners, and completeness of existing controls. In-depth background checks, individual case investigations, and legal services must be confirmed separately, and confidentiality and authorization for sensitive data should be arranged.

Each project specifies the number of on-site interviews, document revisions, training sessions, internal-audit support activities and improvement reviews, together with responsibilities. Third-party certification, specialist testing, engineering and legal services are not included in consulting fees by default. Confirm transition schedules for existing certificates with the certification body.

FAQ

Frequently asked questions

Does an anti-bribery system mean bribery will not occur?

No. The system is a method to identify, handle, and continuously review risks, and cannot guarantee that incidents will not happen; legal responsibility and investigation expertise must be confirmed separately.

Can ISO 37001 replace all fraud management?

No. ISO 37001 focuses on anti-bribery management. Other fraud, money laundering and competition law matters need separate controls under the applicable requirements.

Does every business partner need the same level of due diligence?

Consulting helps define proportionate due diligence and updating methods based on risks and relationships. The aim is to explain why measures were chosen, not to accumulate as many documents as possible.

Must an existing system based on the 2016 edition be rewritten?

First compare the existing system with the 2025 edition. Reuse controls and implementation evidence where they remain suitable. Confirm transition arrangements with the certification body.

Is it only the finance department that needs to be involved?

No. Sales, procurement and management decisions can also involve the giving or receiving of benefits. These teams need to agree financial and non-financial controls together.

Does completing consulting guarantee a certificate?

No certificate is issued automatically. Vosurein helps establish and pilot the system and review evidence. An independent third party assesses and issues certificates under its applicable scheme. Before applying, check the certification scope, accreditation status and customer acceptance. We do not guarantee certification or fabricate records.

Related

Related services and enquiries

Please share your industry, activities and sites in scope, existing management systems and target completion date so we can define the scope of work.Contact Vosurein

Content checked: . Applicable versions and requirements depend on the company’s circumstances.

Let's Talk

Start a conversation about your needs.

Tell us how the work is done today and when you hope to finish,
so we can agree the scope and way of working together.

Discuss your service needsBack to ISO management-system contents