4.3 - Determining the scope of the anti-bribery management system
ISO 37001
The ISO 37001 Anti-Bribery Management Systems standard, instituted by the International Organization for Standardization in 2016, directs organizations globally in fortifying their anti-corruption frameworks. This standard is pivotal for both private and public entities of any size, focusing on active prevention, detection, and management of bribery risks.
How to Answer This Question
1. Identify Internal and External Factors: Begin by reviewing factors that influence your organization's operations and could impact the anti-bribery management system. These might include organizational size, operational locations, business model, and types of business associations.
2. Assess the Applicability: Consider how the anti-bribery management system integrates into various aspects of your operations. Determine which business units, processes, and partnerships are affected by the system and need compliance measures.
3. Document the Scope: Clearly define and document the scope of the anti-bribery management system in an official policy or system document. This should include detailed descriptions of where and how the system applies within the organization.
4. Review and Update: Regularly review the scope to ensure it remains relevant and comprehensive in light of any changes in the organization’s structure, market conditions, or regulatory requirements.
Why It’s Important
Understanding and clearly defining the scope of an anti-bribery management system is crucial because:
- Ensures Comprehensive Coverage: It helps ensure all areas vulnerable to bribery risks are covered.
- Facilitates Targeted Controls: Specific identification of risk areas allows for more effective and targeted control measures.
- Compliance with Legal Standards: Proper scope determination is essential for compliance with international standards like ISO 37001 and legal requirements.
Examples
- Example A: Multinational Corporation
- Scenario: A multinational corporation operates across multiple countries with varying bribery risks.
- Action: The organization defines the scope of its anti-bribery system to include all foreign subsidiaries, detailing specific compliance protocols for high-risk regions.
- Reference: [ISO 37001:2016 - Anti-Bribery Management Systems by PECB](https://pecb.com/whitepaper/iso-370012016---anti-bribery-management-systems-requirements-with-guidance-for-use)
- Example B: Small Business
- Scenario: A small business engages with numerous local and national government bodies.
- Action: The scope is defined to include all interactions with public officials, incorporating risk assessments and training for staff on how to handle such engagements.
- Reference**: [ISO 37001 — Anti-bribery management systems by ISO](https://www.iso.org/iso-37001-anti-bribery-management.html)
For more detailed guidance on setting the scope of your anti-bribery management system, visit:
- ISO - International Organization for Standardization on ISO 37001: [ISO 37001 Anti-Bribery Management Systems](https://www.iso.org/iso-37001-anti-bribery-management.html)
- EuroCompliance on the regulations for certification: [REGULATIONS FOR THE CERTIFICATION OF ANTI-BRIBERY MANAGEMENT SYSTEM](https://www.eurocompliance.com)
This comprehensive approach ensures that all relevant aspects of an organization are considered, and that the anti-bribery management system effectively mitigates risks throughout the operational landscape.