9.3.1 - Management reviews : Conducting management reviews
ISO 37001
The ISO 37001 Anti-Bribery Management Systems standard, instituted by the International Organization for Standardization in 2016, directs organizations globally in fortifying their anti-corruption frameworks. This standard is pivotal for both private and public entities of any size, focusing on active prevention, detection, and management of bribery risks.
How to Respond to This Question
To conduct effective management reviews of an anti-corruption management system, organizations should follow a structured and systematic approach:
- Schedule Regular Reviews : Management reviews should be scheduled at planned intervals to ensure continuous oversight. The frequency of these reviews can be influenced by the dynamic nature of the organization's operations and external environment.
- Review Previous Actions : Start each review by assessing the status of actions identified in previous management reviews. This helps in tracking progress and ensuring that all planned actions are implemented effectively.
- Assess Internal and External Changes : Evaluate any changes in the internal or external environment that could impact the anti-corruption management system. This includes regulatory updates, changes in business operations, or shifts in the risk landscape.
- Analyze System Performance : Scrutinize the effectiveness of the anti-corruption management system by reviewing non-compliance incidents, effectiveness of corrective actions, audit findings, and any bribery reports or investigations.
- Discuss Effectiveness of Measures : Evaluate the measures taken to mitigate identified risks, focusing on their effectiveness and identifying areas for improvement.
- Identify Opportunities for Improvement : Each review should conclude with the identification of opportunities for continuous improvement of the management system, ensuring it remains robust and responsive.
For further information and resources on managing reviews effectively, organizations can consult ISO 37001 standards and guidelines provided by [Transparency International](https://www.transparency.org).
Why It’s Important
Management reviews are crucial for several reasons:
- Ensures Relevance : They ensure that the anti-corruption management system remains relevant to the organization's needs and objectives.
- Maintains Adequacy : Reviews assess whether the system is adequately resourced and capable of achieving its intended outcomes.
- Evaluates Effectiveness : They help determine whether the system effectively prevents, detects, and addresses corruption, ensuring compliance with legal and ethical standards.
- Promotes Continuous Improvement : Regular reviews drive continuous improvement, helping organizations adapt to new challenges and changes in the regulatory landscape.
- Fosters a Culture of Integrity : By regularly reviewing and updating their anti-corruption measures, organizations reinforce a culture of transparency and integrity.
Examples
- Example A :
- Context : A multinational corporation holds bi-annual management reviews to assess their anti-corruption measures.
- Action : The reviews focus on the outcomes of recent internal audits, updates to compliance training programs, and effectiveness of their whistleblower mechanisms.
- Outcome : The company enhances its training modules and updates its policies based on the findings, leading to a reduction in compliance issues.
- Example B :
- Context : A technology firm incorporates feedback from recent bribery cases into their management review.
- Action : The review examines the breaches, discusses the responsiveness of the current system, and evaluates the effectiveness of corrective actions taken.
- Outcome : The firm implements stronger controls around third-party engagements and improves its incident response strategy.
Organizations looking for detailed guidance on conducting effective management reviews can explore best practices and templates offered by professional bodies such as the [Institute of Internal Auditors](https://www.theiia.org).