CRAIG WILLETTS ISO & BUSINESS CONSULTANT
  • Meet Craig Willetts
    • Change The Game
    • Give Back
    • Go Paperless With ISO
    • Compliance Master
  • Business Articles
    • New Business Tips >
      • Cash Flow Planning
      • Cybersecurity Basics for SMEs
      • From Startup to Scale-Up
      • Train Your Brain
      • Organise Your Workspace
      • Colour use in Business
      • Writing a Business Plan
      • Setting KPI's
      • Website Building Instructions
      • Business Insurance
    • Business Development >
      • Building Strategic Partnerships
      • Social Media Essentials
      • Strategic Growth Planning
      • SEO Tips
      • Sell your product or service
    • General Business Tips >
      • How to price your services
      • IR35 Rules Explained
      • Meeting Tips
      • GDPR changes 2026
      • Health & Safety Law Updates
      • Making Tax Digital (MTD):
      • Problem Solving
      • Ensure Compliance
      • Health & Safety Tips
      • Cost-Effective Technology Solutions
      • Anti-Money Laundering Regulations
      • Customer Service Sector
      • Prevent burnout in your team
  • Sector specific articles
    • Security Sector
    • Construction Sector
    • Cleaning & FM Sector
    • Manufacturing Sector
    • Training Sector
    • Warehouse Sector
    • Project Management Sector
    • Healthcare Sector: Navigating CQC Compliance
  • Understanding People
    • How to Tell If Your Team Is Using AI
    • Onboarding New Employees: First 90 Days Checklist
    • Be A Great Employee
    • Understand Customers
    • Talent Management
    • How To Get The Most From Your Team
    • Stress at Work
    • Managing Remote and Hybrid Teams Effectively
    • Made it Mindset
  • ISO Standards Tips
    • Top 20 ISO Standards
    • ISO 9001 Tips
    • ISO 14001 Tips
    • ISO 45001 Tips
    • ISO 45003 Tips
    • ISO 31000 Tips
    • ISO 22301 Tips
    • ISO 27001 Tips
    • ISO 42001 Tips
    • ISO 17025 Tips
    • ISO 13485 Tips
    • ISO 18788 Tips
    • ISO 28000 Tips
    • ISO 28007 Tips
    • ISO 50001 Tips
    • ISO 17021 Tips
    • ISO 10015 Tips
    • ISO 37001 Tips
    • ISO 22000 Tips
    • ISO 37301 Tips
    • ISO 27701 Tips
    • ISO 20000 Tips
    • ISO 26000 Tips
    • ISO 15189 Tips
    • ISO 20121 Tips
    • Internal audits in plain English
    • Corrective Actions that work
    • Management Review Meeting
    • Integrating ISO Standards

 ISO 37001 Anti-Bribery Management

Picture
Bribery risk tends to hide in the places organisations look at least — agent commissions, "facilitation payments" abroad, gifts and hospitality that blur into something else. A written anti-bribery policy sitting in an intranet folder does nothing to address that. ISO 37001 exists to turn anti-bribery intent into an actual management system, with controls that get tested rather than just declared.

In this article:
- What ISO 37001 actually is
- Why it matters beyond the Bribery Act
- The core requirements explained
- Who should be considering it
- Practical steps to get started

What ISO 37001 Actually Is

ISO 37001 is the international standard specifying requirements and providing guidance for establishing, implementing, maintaining, reviewing, and improving an anti-bribery management system. It's designed to be integrated into an organisation's overall management processes, using the same high-level structure as ISO 9001 and ISO 27001, and can be implemented as a standalone system or alongside existing certifications.

Why It Matters Beyond the Bribery Act

The UK Bribery Act 2010 already creates legal exposure, including corporate liability for failing to prevent bribery by associated persons — but "adequate procedures" is a legal defence, not a management system. ISO 37001 gives that defence teeth: certification provides independently verified evidence that an organisation has implemented reasonable and proportionate anti-bribery controls, which matters enormously if an allegation ever surfaces and the organisation needs to demonstrate it took prevention seriously, not just claimed to.

The Core Requirements Explained

- Anti-bribery policy — a clear, documented commitment from top management, communicated throughout the organisation and to relevant business associates.
- Risk assessment — identifying and analysing the bribery risks the organisation faces, considering factors like sectors, countries of operation, and transaction types.
- Due diligence — proportionate checks on business associates, particularly those posing higher bribery risk, such as agents, intermediaries, and joint venture partners.
- Financial and commercial controls — designed specifically to prevent bribery, including controls over gifts, hospitality, donations, and facilitation payments.
- Reporting mechanisms — channels for employees and others to raise concerns, including whistleblowing protections, without fear of retaliation.
- Top management commitment — leadership must demonstrate visible ownership of the anti-bribery programme, not delegate it entirely and disengage.

Who Should Be Considering It

- Organisations operating internationally, particularly in markets where bribery risk is higher and local due diligence is harder to verify independently.
- Businesses working with agents, intermediaries, or joint ventures, where third-party conduct creates liability even when the organisation itself acts properly.
- Public sector suppliers and organisations bidding for government contracts, where anti-bribery credentials increasingly form part of procurement evaluation.
- Any organisation that has faced — or wants to pre-empt — scrutiny following a bribery allegation, whether against the organisation directly or a business partner.

Practical Steps to Get Started

- Conduct a genuine bribery risk assessment first. Generic policies copied from templates rarely reflect the organisation's actual risk profile — sector, geography, and business model all matter.
- Audit existing due diligence on third parties. Many organisations discover gaps here first — agents and intermediaries who were never properly vetted.
- Review gifts and hospitality policies for enforceability, not just existence. A policy nobody follows or checks is a liability, not a protection.
- Establish a confidential reporting channel if one doesn't already exist, and make sure staff actually know about it and trust it.
- Secure visible top management commitment early — auditors and, more importantly, employees can tell the difference between genuine leadership ownership and a signed-off policy document.

The Bottom Line

ISO 37001 won't eliminate bribery risk entirely — no system can — but it forces the kind of rigorous, evidenced prevention that makes a real difference if something does go wrong, both legally and reputationally.

If you'd like support building or strengthening anti-bribery controls in your organisation, CAW Consultancy can help.

Get in touch with CAW Consultancy today for a free, no-obligation consultation — visit www.cawconsultancy.co.uk to find out how we can help you stay compliant and confident.

If you need any advice or have any questions, then please get in touch - [email protected]

Don't forget to share this blog to help others with get great free advice

Picture
  • Meet Craig Willetts
    • Change The Game
    • Give Back
    • Go Paperless With ISO
    • Compliance Master
  • Business Articles
    • New Business Tips >
      • Cash Flow Planning
      • Cybersecurity Basics for SMEs
      • From Startup to Scale-Up
      • Train Your Brain
      • Organise Your Workspace
      • Colour use in Business
      • Writing a Business Plan
      • Setting KPI's
      • Website Building Instructions
      • Business Insurance
    • Business Development >
      • Building Strategic Partnerships
      • Social Media Essentials
      • Strategic Growth Planning
      • SEO Tips
      • Sell your product or service
    • General Business Tips >
      • How to price your services
      • IR35 Rules Explained
      • Meeting Tips
      • GDPR changes 2026
      • Health & Safety Law Updates
      • Making Tax Digital (MTD):
      • Problem Solving
      • Ensure Compliance
      • Health & Safety Tips
      • Cost-Effective Technology Solutions
      • Anti-Money Laundering Regulations
      • Customer Service Sector
      • Prevent burnout in your team
  • Sector specific articles
    • Security Sector
    • Construction Sector
    • Cleaning & FM Sector
    • Manufacturing Sector
    • Training Sector
    • Warehouse Sector
    • Project Management Sector
    • Healthcare Sector: Navigating CQC Compliance
  • Understanding People
    • How to Tell If Your Team Is Using AI
    • Onboarding New Employees: First 90 Days Checklist
    • Be A Great Employee
    • Understand Customers
    • Talent Management
    • How To Get The Most From Your Team
    • Stress at Work
    • Managing Remote and Hybrid Teams Effectively
    • Made it Mindset
  • ISO Standards Tips
    • Top 20 ISO Standards
    • ISO 9001 Tips
    • ISO 14001 Tips
    • ISO 45001 Tips
    • ISO 45003 Tips
    • ISO 31000 Tips
    • ISO 22301 Tips
    • ISO 27001 Tips
    • ISO 42001 Tips
    • ISO 17025 Tips
    • ISO 13485 Tips
    • ISO 18788 Tips
    • ISO 28000 Tips
    • ISO 28007 Tips
    • ISO 50001 Tips
    • ISO 17021 Tips
    • ISO 10015 Tips
    • ISO 37001 Tips
    • ISO 22000 Tips
    • ISO 37301 Tips
    • ISO 27701 Tips
    • ISO 20000 Tips
    • ISO 26000 Tips
    • ISO 15189 Tips
    • ISO 20121 Tips
    • Internal audits in plain English
    • Corrective Actions that work
    • Management Review Meeting
    • Integrating ISO Standards