9.3.1 - Management reviews : Communicating review results to governance body
ISO 37001
The ISO 37001 Anti-Bribery Management Systems standard, instituted by the International Organization for Standardization in 2016, directs organizations globally in fortifying their anti-corruption frameworks. This standard is pivotal for both private and public entities of any size, focusing on active prevention, detection, and management of bribery risks.
How to Respond to This Question
When considering how to effectively communicate the results of management reviews to governance bodies, follow these key steps:
- Summarize Key Findings : Clearly summarize the key findings, conclusions, and recommendations from the management review. This should focus on aspects that are relevant to strategic decision-making and governance oversight.
- Use Appropriate Channels : Ensure that the communication method aligns with the formal channels used by the governance body. This could include formal reports, presentations during board meetings, or written communications through secure channels.
- Highlight Areas Needing Attention : Specifically point out any areas that require immediate attention or significant decision-making from the governance body.
- Provide Documentation : Supply all necessary documentation that supports the findings and recommendations. This ensures that the governance body has all the information needed to make informed decisions.
- Ensure Clarity and Transparency : Communicate in clear, unambiguous language to ensure that all members of the governance body understand the implications of the review findings.
For detailed examples and guidelines, refer to resources such as the [ISO 9001 standards on management review communication](https://www.iso-9001-checklist.co.uk).
Why It’s Important
Communicating the results of management reviews to governance bodies is crucial for several reasons:
- Informed Decision-Making : Provides the governance body with the necessary information to make informed strategic decisions.
- Regulatory Compliance : Ensures compliance with legal and regulatory requirements regarding corporate governance and accountability.
- Transparency and Trust : Enhances transparency and builds trust among stakeholders by showing that the organization is committed to continuous improvement and accountability.
- Risk Management : Allows the governance body to actively participate in risk management by understanding and addressing potential risks highlighted during the reviews.
Examples
- Example A :
- Context : A technology firm conducts quarterly management reviews to assess the effectiveness of its anti-corruption measures.
- Action : Results, including identified risks and improvement opportunities, are compiled into a comprehensive report.
- Outcome : The report is presented during the quarterly board meeting, leading to the allocation of resources towards enhancing cybersecurity measures to mitigate bribery risks.
- Example B :
- Context : A multinational corporation reviews its compliance with international anti-bribery laws annually.
- Action : The management review findings highlight a need for updated training programs.
- Outcome : Summarized findings are communicated via email to all board members, followed by a detailed presentation in the next board meeting, which results in the approval of a new training initiative.
For more insights on establishing effective communication with governance bodies, organizations might consider consulting with experts in corporate governance, or reviewing guidelines provided by professional bodies such as the [Institute of Internal Auditors](https://www.theiia.org).