9.2.1 - Internal audit : Conducting internal audits
ISO 37001
The ISO 37001 Anti-Bribery Management Systems standard, instituted by the International Organization for Standardization in 2016, directs organizations globally in fortifying their anti-corruption frameworks. This standard is pivotal for both private and public entities of any size, focusing on active prevention, detection, and management of bribery risks.
How to Respond to This Question
To ensure the anti-corruption management system complies with organizational requirements and ISO 37001, internal audits are conducted following a structured approach:
- Planning the Audit : Determine the scope, frequency, and methods of the audit. Planning includes identifying the critical areas of the anti-corruption management system that require review.
- Assigning Auditors : Select auditors who are competent and independent from the operations they assess to ensure objectivity. The selection often includes third-party auditors to enhance impartiality.
- Conducting the Audit : Auditors systematically review the system's compliance with the ISO 37001 standard and internal policies. This involves examining documentation, processes, and controls within the organization to prevent, detect, and manage bribery.
- Reporting Findings : The results of the audit are documented and reported to senior management and the compliance function. This report should include any non-compliance issues, risks identified, and recommendations for improvement.
- Follow-Up : Based on the audit findings, necessary corrective actions are implemented to address any deficiencies. This step ensures continuous improvement of the anti-corruption management system.
For detailed guidance on auditing standards, the [ISO 37001 Checklist](https://www.iso-9001-checklist.co.uk) provides comprehensive resources on internal auditing practices.
Why It’s Important
Conducting internal audits is vital because it:
- Ensures Compliance : Helps the organization verify that its anti-corruption measures are effective and meet both the ISO standard and internal criteria.
- Identifies Risks and Weaknesses : Audits highlight areas where corruption risks or compliance failures might occur, allowing the organization to take preventive measures.
- Enhances Credibility and Trust : Regular audits demonstrate the organization’s commitment to integrity and ethical practices, which can enhance stakeholder confidence.
- Drives Continuous Improvement : By identifying areas for enhancement, audits promote ongoing refinement of anti-corruption strategies and procedures.
The [International Organization for Standardization](https://www.iso.org) offers additional insights into how standards like ISO 37001 are applied and audited globally.
Examples
- Example A :
- Context : A technology firm conducts semi-annual internal audits to assess its compliance with ISO 37001.
- Action : Auditors review the firm's bribery risk assessments, training records, and due diligence processes for third-party vendors.
- Outcome : Audit findings lead to an enhanced due diligence process and updated training programs to close gaps in anti-corruption practices.
- Example B :
- Context : A construction company facing regulatory scrutiny enhances its internal audit function.
- Action : It brings in an external auditing firm to independently assess the effectiveness of its anti-corruption controls.
- Outcome : The external audit identifies previously unnoticed compliance lapses, leading to significant changes in the company's procurement and contracting processes.
For organizations seeking to establish or improve their internal audit capabilities, the [Anti-Bribery Guidance by Transparency International](https://www.antibriberyguidance.org) provides practical tools and examples.