7.5.1 - Documented information : Retention of required documented information

ISO 37001

The ISO 37001 Anti-Bribery Management Systems standard, instituted by the International Organization for Standardization in 2016, directs organizations globally in fortifying their anti-corruption frameworks. This standard is pivotal for both private and public entities of any size, focusing on active prevention, detection, and management of bribery risks.

How to Answer the Question

To comply with ISO 37001 standards, organizations must implement procedures to maintain necessary documented information on their anti-corruption management systems. Here's how:

1.   Document Management System  :

  -   Implementation  : Adopt a document management system that allows for secure storage, easy retrieval, and proper archiving of documents related to anti-corruption measures.

  -   Accessibility  : Ensure that all necessary documents are easily accessible to authorized personnel while maintaining security and confidentiality.

2.   Documentation Requirements  :

  -   Details to Include  : Keep records that detail the date, content, and recipient of any anti-corruption training or communication. Also, maintain documentation on risk assessments, due diligence activities, and any incidents of non-compliance or bribery.

  -   Retention Period  : Define and adhere to a document retention policy that specifies how long different types of documents should be kept, based on legal requirements and the organization's needs.

3.   Regular Reviews  :

  -   Schedule Reviews  : Periodically review the documented information to ensure it remains current and relevant to the organization's anti-corruption efforts.

  -   Update Documentation  : Promptly update documentation to reflect any changes in the anti-corruption policy, procedures, or the risk environment.

Why It's Important

Retaining documented information is critical for several reasons:

-   Compliance with ISO 37001  : Proper documentation is a core requirement of the ISO 37001 standard, which helps organizations demonstrate their commitment to effective anti-corruption practices.

-   Evidence of Due Diligence  : Well-maintained records serve as evidence of the organization's efforts to prevent corruption, which is crucial in the event of legal or regulatory scrutiny.

-   Continuous Improvement  : Documented information supports the ongoing evaluation and improvement of the anti-corruption management system.

Examples

-   Example A  :

 -   Context  : A technology firm implements a new anti-bribery policy.

 -   Action  : The firm develops a comprehensive documentation protocol that includes logging all training sessions, policy acknowledgments by employees, and audits.

 -   Outcome  : The well-documented approach enables the firm to quickly respond to a regulatory inquiry, demonstrating compliance and avoiding penalties.

-   Example B  :

 -   Context  : An international non-profit organization faces high corruption risks in multiple regions.

 -   Action  : The organization adopts a cloud-based document management system to store and track all anti-corruption compliance documents, including risk assessments and incident reports.

 -   Outcome  : This system enhances the organization's ability to monitor compliance across different regions and provides a clear audit trail for external auditors.

For further guidelines on document retention and management related to ISO 37001:

- [International Anti-Corruption Academy](https://www.iaca.int)

- [ISO 37001 Resources](https://www.iso.org/iso-37001-anti-bribery-management.html)