What ISO 37001 is
ISO 37001 is the standard for preventing bribery. It asks you to assess where bribery risk exists, put controls around gifts, agents, donations and procurement, and show that leadership takes it seriously.
For US companies it connects to the Foreign Corrupt Practices Act (FCPA), which carries heavy penalties. A certified anti-bribery program is evidence of good-faith effort and is valued by government contractors and firms operating overseas.
The standard focuses on bribery specifically, not fraud or general ethics, so it is narrower and more auditable than a broad compliance program.
How to get certified
- Run a bribery risk assessment across markets, agents and transactions.
- Put controls in place: due diligence, gift and hospitality rules, financial controls and reporting channels.
- Appoint a compliance function and train staff and third parties.
- Run the program, then complete an internal audit and management review.
- Engage a certification body and pass the two-stage audit.
- Maintain through annual surveillance audits.
Always use an accredited certification body
In the US, look for a body accredited by ANAB. An accredited certificate is the one customers, regulators and buyers actually trust — and you can confirm any certificate through IAF CertSearch.
How much ISO 37001 costs
Due diligence on agents and partners is the effort that scales. Companies with many overseas intermediaries pay more.
The standard pairs well with existing FCPA compliance work, so much of the groundwork may already exist.
Legal review of your program is a sensible extra cost that sits outside certification.
Calculate your cost range → Get free quotes →