10.1 - Improvement: Non-conformity and corrective action : Implementing corrective actions

ISO 37001

Managing non-compliance effectively is crucial for maintaining the integrity and effectiveness of an anti-corruption management system. This involves not only addressing the non-compliance itself but also documenting every step of the process to ensure transparency and accountability.

How to Respond to This Question

 Documenting Non-compliance and Corrective Actions  

-   Initial Documentation  : Record the details of the non-compliance as soon as it is identified. This should include the date, nature of the non-compliance, and involved parties.

-   Investigation Results  : Document the findings from the investigation into the non-compliance, detailing the root causes and any contributing factors.

-   Corrective Actions  : Record the corrective actions decided upon and the rationale for these choices. This includes who is responsible for implementing these actions and the timeline for completion.

 Ensuring Adequacy and Effectiveness  

-   Review of Actions  : Regularly review the effectiveness of the corrective actions. This can be done through follow-up assessments or audits to ensure the actions have addressed the non-compliance adequately.

-   Updating Documentation  : Continuously update the documentation to reflect any new insights or adjustments to the corrective actions to ensure ongoing compliance and improvement.

Why It’s Important

-   Accountability  : Detailed records ensure that all actions taken are transparent and can be audited, promoting accountability within the organization.

-   Continuous Improvement  : Documenting both non-compliance and corrective actions helps in identifying trends or recurring issues, which can be vital for continuous improvement efforts.

-   Regulatory Compliance  : Many industries are subject to strict regulatory requirements regarding the management of non-compliance, making thorough documentation necessary.

Examples

 Example A: Handling of a Data Breach  

-   Situation  : A breach in data security leading to unauthorized access to sensitive information.

-   Documentation  : The IT team documents the breach details, actions taken to seal the breach, and measures implemented to prevent future occurrences.

-   Outcome  : Improved security protocols and training programs for staff on data security.

 Example B: Vendor Compliance Issue  

-   Situation  : A vendor fails to comply with the organization’s anti-bribery policies.

-   Documentation  : The compliance team records the details of the vendor’s non-compliance, the review process, and the penalties or corrective measures applied.

-   Outcome  : Enhanced vendor screening processes and better compliance monitoring mechanisms.

For further reading on the documentation and handling of non-compliance, resources such as [ISO 37001:2016](https://www.iso.org/standard/65034.html) provide guidelines on implementing an effective anti-bribery management system. Additional insights can be found in guidelines provided by the [Transparency International](https://www.transparency.org) on anti-bribery measures.

Through these structured approaches, organizations can ensure that their anti-corruption measures are not only reactive but also proactive in preventing future non-compliance.