
ISO 37001
A Practical Guide to Enhancing Organizational Integrity
Discover how ISO 37001 can transform your organization by integrating robust anti-corruption management systems. Suitable for all types of organizations, this international standard provides concrete guidelines for preventing, detecting, and managing corruption. Learn to implement an effective anti-corruption policy, assess risks, and boost transparency and trust within your enterprise.
Question index
General
- 4.1 -Operational Framework
- 4.2 - Understanding the needs and expectations of stakeholders
- 4.3 - Determining the scope of the anti-bribery management system
- 4.4 - Anti-bribery management system
- 4.5 - Bribery risk assessment : Identification of Risks
- 4.5 - Bribery risk assessment : Sources of risks
- 4.5 - Bribery risk assessment : Identification of Risks
- 4.5 - Bribery risk assessment : Framework: relationships & control
- 4.5.2 - Analysis and Evaluation
- 4.5.3 - Existing Controls
- 4.5.4 - Monitoring and review
- 5.1.1 - Commitment demonstrated by governing body
- 5.1.1 - Approval of anti-corruption policy
- 5.1.1 - Alignment of strategy and anti-corruption policy
- 5.1.1 - Review of anti-corruption management system
- 5.1.1 - Resource allocation
- 5.1.1 - Control over implementation and effectiveness
- 5.1.2 - Establishment and maintenance of the system
- 5.1.2 - System review
- 5.1.2 - Resource allocation
- 5.1.2 - Control and effectiveness
- 5.1.2 - Integration into management processes
- 5.1.2 - Communication strategies
- 5.1.2 - Promotion of anti-corruption culture
- 5.1.2 - Support for management functions
- 5.1.2 - Resource allocation for anti-corruption
- 5.1.2. - Anti-corruption communication strategies
- 5.1.2 - Promotion of reporting mechanisms
- 5.1.2 - Protection against retaliation
- 5.1.2 - Reporting to governing Body
- 5.2 - Anti-bribery policy : Explicit prohibition of corruption
- 5.2 - Anti-bribery policy : Compliance with laws
- 5.2 - Anti-bribery policy : Tailoring policy to organizational objectives
- 5.2 - Anti-bribery policy : Framework for anti-corruption objectives
- 5.2 - Anti-bribery policy : Manifestation of commitment
- 5.2 - Anti-bribery policy : Encouragement of reporting
- 5.2 - Anti-bribery policy : Continuous improvement
- 5.2 - Anti-bribery policy : Compliance function authority
- 5.2 - Anti-bribery policy : Consequences for non-compliance
- 5.3.1 - Top management responsibility
- 5.3.1 - Assignment of responsibilities and authorities
- 5.3.1 - Managerial compliance
- 5.3.2 - Anti-bribery compliance function : Role and authority
- 5.3.2 - Anti-bribery compliance function : Resource allocation
- 5.3.2 - Access to governing body and top management
- 5.3.3 - Decision maker conflict of interest : Managing conflicts of interest
- 6.1 - Ensuring system objectives achievement
- 6.1 - Preventing adverse effects
- 6.1 - Monitoring and evaluating system effectiveness
- 6.1 - Planning for risk management and improvement
- 6.2 - Anti-bribery objectives and planning to achieve them : Establishing anti-corruption objectives
- 6.2 - Anti-bribery objectives and planning to achieve them : Aligning objectives with policy
- 6.2 - Anti-bribery objectives and planning to achieve them : Measurability of objectives
- 6.2 - Anti-bribery objectives and planning to achieve them : Objectives reflecting organization and risks
- 6.2 - Anti-bribery objectives and planning to achieve them : Ensuring objectives are achievable
- 6.2 - Anti-bribery objectives and planning to achieve them : Organizing objective monitoring
- 6.2 - Anti-bribery objectives and planning to achieve them : Communicating objectives
- 6.2 - Anti-bribery objectives and planning to achieve them : Updating objectives
- 6.2 - Anti-bribery objectives and planning to achieve them : Retaining documentation on objectives
- 6.2 - Anti-bribery objectives and planning to achieve them : Specifying action plans for objectives
- 7.1 - Resource identification for system maintenance
- 7.2.1 - Competence : Determining personnel competencies
- 7.2.1 - Competence : Competency measures and evaluation
- 7.2.1 - Competence : Ensuring appropriate competencies
- 7.2.1 - Competence : Documenting competency evaluations
- 7.2.2.1 - Compliance with employment conditions
- 7.2.2.1 - Distribution and training on policy
- 7.2.2.1 - Disciplinary procedures for policy violations
- 7.2.2.1 - Protection for non-participation or reporting
- 7.2.2.2 - Procedures for high-risk positions
- 7.3 - Awareness and training : Regular anti-corruption training
- 7.3 - Awareness and training : Training high-risk business associates
- 7.3 - Awareness and training
- 7.4 - Communication : Internal and external communication process
- 7.4 - Communication : Policy availability and communication
- 7.5.1 - Documented information : Retention of required documented information
- 7.5.2 - Documented information : Accuracy of documented information
- 7.5.3 - Documented information : Documented information protection
- 7.5.3 - Documented information : Control of externally originated information
- 8.1 - Operation and planning : Planning and control of anti-corruption processes
- 8.2 - Due diligence : Assessment of corruption risk
- 8.3 - Financial controls : Financial controls against corruption
- 8.4 - Non-financial controls : Non-financial controls against corruption
- 8.5.1 - Controls and due diligence for controlled organizations and business associates : Enforcement of anti-corruption system for associates
- 8.5.2 - Controls and due diligence for controlled organizations and business associates : Evaluating associates' anti-corruption controls
- 8.6 - anti-bribery commitments : Commitment of business associates to prevent corruption
- 8.7 - Gifts, donations and benefits : Procedures against improper benefits
- 8.8 - Managing inadequate anti-bribery controls : Handling unmanageable corruption risks
- 8.9 - Raising concerns : Facilitating corruption reporting
- 8.9 - Raising concerns : Confidentiality of reporting process
- 8.9 - Raising concerns : Allowance for anonymous reports
- 8.9 - Raising concerns : Protection against retaliation for reporting
- 8.9 - Raising concerns : Establishing a corruption concern point of contact
- 8.9 - Raising concerns : Familiarizing personnel with reporting procedures
- 8.10 - Investigating and dealing with cases of bribery : Investigating reported corruption concerns
- 8.10 - Investigating and dealing with cases of bribery : Actions required upon discovering corruption
- 8.10 - Investigating and dealing with cases of bribery : Empowering investigators
- 8.10 - Investigating and dealing with cases of bribery : Ensuring cooperation in investigations
- 8.10 - Investigating and dealing with cases of bribery : Reporting investigation outcomes to compliance
- 8.10 - Investigating and dealing with cases of bribery : Confidentiality of investigation results
- 8.10 - Investigating and dealing with cases of bribery : Independence of investigators
- 9.1 - Determining monitoring needs and responsibilities
- 9.1 - Retaining monitoring and measuring documentation
- 9.1 - Evaluating anti-corruption outcomes
- 9.2.1 - Internal audit : Conducting internal audits
- 9.2.2 - Internal audit : Planning audit programs
- 9.2.3 : Internal audit : Audit design principles
- 9.2.4 - Internal audit : Ensuring auditor independence
- 9.3.1 - Management reviews : Conducting management reviews
- 9.3.1 - Management reviews : Outcomes of management reviews
- 9.3.1 - Management reviews : Communicating review results to governance body
- 9.3.2 - Management reviews : Governance body reviews of the system
- 9.4 - Review by the anti-bribery compliance function : Ongoing assessments by compliance function
- 9.4 - Review by the anti-bribery compliance function : Compliance function reporting frequency
- 10.1 - Improvement: Non-conformity and corrective action : Reacting to non-compliance
- 10.1 - Improvement: Non-conformity and corrective action : Implementing corrective actions
- 10.2 - Continuous improvement : Improving the management system