ISO 37001:2025
The New Anti-Bribery Management System Standard

What UK organisations need to know about the revised global anti-bribery framework

Executive Summary

Lawyer refuses to accept bribe from business person

ISO 37001:2025 is the second edition of the international Anti-Bribery Management Systems standard. Published in February 2025, it replaces ISO 37001:2016 and provides a structured management-system framework for preventing, detecting and responding to bribery.

The revised standard applies across public, private and not-for-profit organisations and addresses direct and indirect bribery involving organisations, personnel and business associates.

The revision is not simply an exercise in updating anti-bribery policies.

It places greater emphasis on areas such as:

  • anti-bribery culture;
  • conflicts of interest;
  • planned changes;
  • governance;
  • training;
  • due diligence;
  • business associates;
  • controls;
  • monitoring and review.

For UK organisations operating internationally, participating in public procurement, managing distributors or agents, or working in higher-risk jurisdictions, ISO 37001:2025 can provide a structured framework for demonstrating that anti-bribery controls are integrated into the organisation rather than existing only as legal statements.

PJR began offering audits to ISO 37001:2025 in 2025 and its UKAS accreditation schedule includes ISO 37001:2025.

Why ISO 37001 Matters

Anti-bribery controls have traditionally been fragmented.

An organisation might have:

  • an anti-bribery policy;
  • a gifts and hospitality procedure;
  • a whistleblowing channel;
  • supplier due diligence;
  • financial controls;
  • compliance training.

The problem is that these controls can operate independently.

ISO 37001 approaches anti-bribery as a management system.

That means the organisation needs to understand:

Where are we exposed?

What controls do we have?

Are those controls appropriate to our risks?

Are they operating?

Do we monitor them?

Do we investigate failures?

Do we improve the system?

That is fundamentally different from simply publishing an anti-corruption policy.

What Is New in ISO 37001:2025?

The revised standard retains much of the familiar structure of the 2016 edition.

PJR’s review describes the changes as relatively limited but important, particularly in relation to anti-bribery culture, conflicts of interest, planning of changes and clearer requirements surrounding the anti-bribery function.

ISO itself describes the standard as a framework for establishing, implementing, maintaining and continually improving a system designed to prevent, detect and respond to bribery.

The most important lesson is therefore:

Do not treat the 2025 edition as a policy rewrite. Treat it as a governance-system review.

Anti-Bribery Culture

One of the most important developments is the explicit visibility given to anti-bribery culture.

Culture is difficult because it cannot be established simply by signing a policy.

Consider two organisations.

Organisation A

  • publishes a zero-tolerance policy;
  • provides annual online training;
  • requires employees to sign declarations.

Organisation B

Does all of the above, but additionally:

  • leadership openly discusses ethical decision-making;
  • employees can challenge inappropriate requests;
  • high-risk commercial incentives are reviewed;
  • management evaluates behavioural indicators;
  • employees know how to report concerns;
  • senior management acts consistently when breaches occur.

Organisation B demonstrates a stronger anti-bribery culture.

This is the direction of travel created by ISO 37001:2025.

Conflicts of Interest

A conflict of interest may exist even where no bribery has occurred.

Examples include:

  • an employee selecting a supplier owned by a relative;
  • a manager approving expenses involving a personal connection;
  • an intermediary recommending a business associate in which they have an undisclosed financial interest.

This creates a critical management question:

“How does the organisation identify, disclose and manage conflicts?”

A mature system should address:

  • declaration mechanisms;
  • approval processes;
  • escalation;
  • recordkeeping;
  • management of actual and potential conflicts;
  • consequences of non-disclosure.

The control should be proportionate to risk.

Third-Party Risk

For many organisations, the greatest anti-bribery exposure is outside the organisation.

Business associates can include:

  • agents;
  • distributors;
  • intermediaries;
  • consultants;
  • contractors;
  • joint-venture partners;
  • suppliers;
  • representatives.

ISO 37001 specifically addresses controls involving business associates and due diligence.

This is important because an organisation cannot simply say:

“Our employee did not make the payment.”

An intermediary may create significant legal, financial and reputational exposure.

A structured third-party programme should consider:

Before engagement

  • who is the party?
  • who owns it?
  • what services will it provide?
  • where will it operate?
  • why is the relationship necessary?
  • how will it be compensated?

During the relationship

  • what monitoring occurs?
  • are payments appropriate?
  • are invoices supported?
  • have circumstances changed?
  • has risk increased?

At renewal

  • does due diligence need updating?
  • has ownership changed?
  • has the country risk changed?
  • has the business relationship changed?

Financial and Non-Financial Controls

Anti-bribery systems require more than financial controls.

Financial controls can include:

  • approval thresholds;
  • segregation of duties;
  • payment controls;
  • expense review;
  • invoice verification;
  • unusual-payment monitoring.

Non-financial controls can include:

  • recruitment controls;
  • procurement procedures;
  • gifts and hospitality;
  • sponsorships;
  • donations;
  • charitable contributions;
  • lobbying;
  • political interactions;
  • business-associate approval.

The strength of the system depends on the interaction between the two.

Due Diligence Should Be Risk-Based

A common weakness is applying identical due diligence to every third party.

A £500 office-supply supplier is not necessarily equivalent to a politically connected intermediary operating in a high-risk jurisdiction.

A mature system therefore uses proportionality.

Risk factors might include:

  • geography;
  • sector;
  • government interaction;
  • role of the intermediary;
  • ownership;
  • compensation;
  • transaction value;
  • regulatory environment;
  • history;
  • adverse information.

Higher risk should produce stronger due diligence and controls.

Training Is Not the Same as Competence

Many organisations measure anti-bribery training by completion rates.

For example:

“98% of employees completed the annual e-learning.”

That is useful evidence, but it does not demonstrate understanding.

A procurement manager may need to understand:

  • conflicts;
  • supplier due diligence;
  • gifts;
  • procurement controls.

A sales manager may need to understand:

  • agents;
  • government customers;
  • hospitality;
  • commissions.

A senior executive may need to understand:

  • governance;
  • risk;
  • reporting;
  • culture;
  • escalation.

Training should therefore reflect actual exposure.

Planned Changes

Management-system standards increasingly recognise that change itself creates risk.

For anti-bribery management, major changes can include:

  • entering a new country;
  • appointing a local agent;
  • acquiring a company;
  • restructuring procurement;
  • introducing new commissions;
  • changing ownership;
  • entering government contracts.

The question should become:

“What new anti-bribery risks does this change create?”

This can prevent organisations from discovering control weaknesses after the transaction has already occurred.

Monitoring and Internal Audit

An anti-bribery system should be tested.

Monitoring may consider:

  • gifts and hospitality;
  • third-party due diligence;
  • unusual payments;
  • expense trends;
  • whistleblowing reports;
  • training;
  • conflicts;
  • control effectiveness.

Internal audits should go beyond confirming that documents exist.

For example:

Instead of asking:

“Do you have a third-party procedure?”

the organisation could sample ten third parties and ask:

  • Was risk assessed?
  • Was due diligence completed?
  • Was approval obtained?
  • Was the contract appropriate?
  • Were payments consistent with approval?
  • Was ongoing monitoring performed?

This is evidence of system effectiveness.

Whistleblowing and Reporting

An organisation needs ways to surface concerns.

A reporting mechanism must be more than an email address on the intranet.

Employees and relevant external parties should understand:

  • what can be reported;
  • how to report;
  • confidentiality arrangements;
  • escalation;
  • protection against inappropriate retaliation;
  • what happens after a report.

The organisation should also monitor whether the reporting system is functioning.

An organisation with no reported concerns is not automatically an organisation with no misconduct.

It may also indicate that employees do not trust the system.

Investigations and Corrective Action

When a potential bribery concern emerges, the organisation needs a controlled process for:

Receive → assess → investigate → decide → remediate → monitor

The objective is not simply to close a case.

The organisation should ask:

  • What happened?
  • Why did it happen?
  • Which control failed?
  • Was the failure isolated?
  • Could similar failures occur elsewhere?
  • Does training need to change?
  • Does due diligence need to change?
  • Does management oversight need to change?

That is continual improvement applied to anti-bribery.

ISO 37001 and UK Business

ISO 37001 is particularly relevant to UK organisations involved in:

  • international trade;
  • infrastructure;
  • construction;
  • defence;
  • financial and professional services;
  • public procurement;
  • regulated activities;
  • complex supply chains;
  • international agents and distributors.

The standard can also support organisations that want a consistent anti-bribery framework across multiple jurisdictions.

ISO confirms that the framework applies to organisations of any size and across public, private and not-for-profit sectors.

Transition From ISO 37001:2016

ISO 37001:2016 is withdrawn and ISO 37001:2025 is the current edition.

PJR has stated that it began offering audits against the 2025 edition in November 2025. PJR’s published material also references the applicable transition requirements and the end of validity of the previous edition.

Existing certificate holders should therefore engage their certification body early and establish:

  • current certificate status;
  • transition audit timing;
  • revised documentation;
  • revised internal-audit criteria;
  • training requirements;
  • updated business-associate controls.

Why ISO 37001 Should Not Be Treated as a Legal Exercise

A legal programme asks:

“What laws apply?”

A management system asks:

“How does the organisation consistently manage this risk?”

The two approaches complement each other.

ISO 37001 does not replace legal advice, compliance obligations or investigation processes.

It provides a structured framework within which these controls can operate.

PJR’s Certification Role

PJR states that it offers certification auditing against ISO 37001:2025 and is accredited by UKAS for the standard within its applicable management-system accreditation scope.

For an organisation seeking certification, independence matters.

The certification body should independently assess whether the management system meets the applicable requirements.

The organisation itself remains responsible for designing and operating its anti-bribery system.

Conclusion

ISO 37001:2025 represents an important shift in the way organisations should think about anti-bribery.

The future is not:

policy + training + annual declaration.

It is:

risk + governance + culture + due diligence + controls + reporting + monitoring + continual improvement.

For UK organisations competing internationally, the ability to demonstrate a functioning anti-bribery management system can become an important part of organisational credibility.

PJR Registrars

Independent certification for organisations seeking recognised anti-bribery management-system assurance.

Call Now Button