4.5.4 - Monitoring and review

ISO 37001

Understanding how your organization maintains records of its bribery risk assessments is crucial for continuous improvement and compliance with ISO 37001.

How to Answer This Question

1.   Maintain Comprehensive Records  : Ensure your organization keeps detailed records that demonstrate the conduct of bribery risk assessments. This includes documenting the methodologies used, the risks identified, and how these assessments influence the design or enhancement of the anti-bribery management system.

2.   Specify Documentation Practices  : Describe the specific types of documents maintained, such as risk assessment reports, decision logs, and updates to the anti-bribery management system. Ensure these documents are accessible and stored securely.

Why It’s Important

-   Regulatory Compliance  : Keeping thorough documentation proves compliance with international standards like ISO 37001 and can be crucial during audits or legal inquiries.

-   Systematic Improvement  : Documented records allow for tracking changes and improvements over time, helping to refine the anti-bribery measures and adapt to new risks.

-   Stakeholder Assurance  : Comprehensive documentation reassures stakeholders, including investors, regulators, and partners, of the organization's commitment to fighting bribery.

Examples

-   Example A: Large Corporation  

 -   Context  : Operates in multiple high-risk jurisdictions.

 -   Documentation Practice  : Maintains a dynamic risk register updated semi-annually and after significant corporate events, such as mergers or market expansions.

 -   Outcome  : Enables timely adjustments to the anti-bribery management system and provides audit trails for compliance verification.

-   Example B: Small Enterprise  

 -   Context  : Engages primarily in domestic markets with occasional overseas contracts.

 -   Documentation Practice  : Documents risk assessments annually or when undertaking significant new contracts.

 -   Outcome  : Ensures that the enterprise remains aware of and responsive to evolving bribery risks without overburdening resources.

For further guidance on maintaining records for bribery risk assessments and leveraging them to enhance your anti-bribery management system, explore the following resources:

-   Anti-bribery interview TCO Certified  : [Access the Anti-bribery questionnaire](https://tcocertified.com/industry/updates-and-changes/anti-bribery-management-system-saq-and-process-chemicals-asl/)

-   ISO 37001:2016 - Anti-Bribery Management Systems  : [PECB detailed guidelines](https://pecb.com/whitepaper/iso-370012016---anti-bribery-management-systems-requirements-with-guidance-for-use)

Documented evidence of conducting and utilizing bribery risk assessments not only fulfills ISO 37001 requirements but also strengthens the integrity and effectiveness of your organization's anti-bribery efforts.