Skip to content

Evidence request lists

ISO 37001

Evidence request list. 42 controls, 42 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.

Context

ISO37001-4.1
Understanding the Organization and Its Context

Determine external and internal issues relevant to the anti-bribery management system and its ability to achieve outcomes.

Artefacts an auditor will ask for
  • PESTLE or SWOT analysis
  • Jurisdictional bribery risk briefing
  • Regulatory register
  • Sector risk assessment
Where this commonly fails
  • Context analysis not refreshed
  • Foreign operations excluded
  • No regulatory horizon scan
ISO37001-4.2
Interested Parties

Identify interested parties relevant to the ABMS and their relevant requirements regarding anti-bribery.

Artefacts an auditor will ask for
  • Stakeholder register
  • Legal and contractual requirements log
  • Engagement plan
  • Customer and investor anti-bribery clauses
Where this commonly fails
  • Business partner expectations omitted
  • No tracking of regulator expectations
  • Public anti-bribery commitments unverified
ISO37001-4.3
Scope of the ABMS

Define the boundaries and applicability of the anti-bribery management system including controlled entities.

Artefacts an auditor will ask for
  • Documented ABMS scope
  • Subsidiary inclusion list
  • Justification for exclusions
  • Scope review minutes
Where this commonly fails
  • JV and minority holdings not addressed
  • Scope statement outdated
  • Exclusions undocumented
ISO37001-4.5
Bribery Risk Assessment

Conduct regular bribery risk assessment to identify, analyze, evaluate, and prioritize bribery risks the organization faces.

Artefacts an auditor will ask for
  • Bribery risk assessment methodology
  • Bribery risk register
  • High-risk activity inventory
  • Annual reassessment report
Where this commonly fails
  • Generic risk assessment not bribery-specific
  • No coverage of public official interactions
  • Risk owners undefined

ISO 37001: Improvement

ISO37001-16
Continual improvement methodology

Continual improvement methodology. Control from ISO 37001 framework, domain: ISO 37001: Improvement.

Artefacts an auditor will ask for
  • Continual improvement plan
  • Corrective action register
  • Investigation reports
  • Lessons learned log
Where this commonly fails
  • Improvement not data-driven
  • Investigations slow
  • Lessons learned not shared
ISO37001-17
Corrective and preventive actions

Corrective and preventive actions. Control from ISO 37001 framework, domain: ISO 37001: Improvement.

Artefacts an auditor will ask for
  • Continual improvement plan
  • Corrective action register
  • Investigation reports
  • Lessons learned log
Where this commonly fails
  • Improvement not data-driven
  • Investigations slow
  • Lessons learned not shared
ISO37001-18
Innovation and change management

Innovation and change management. Control from ISO 37001 framework, domain: ISO 37001: Improvement.

Artefacts an auditor will ask for
  • Continual improvement plan
  • Corrective action register
  • Investigation reports
  • Lessons learned log
Where this commonly fails
  • Improvement not data-driven
  • Investigations slow
  • Lessons learned not shared

ISO 37001: Leadership & Planning

ISO37001-01
Quality policy and objectives

Quality policy and objectives. Control from ISO 37001 framework, domain: ISO 37001: Leadership & Planning.

Artefacts an auditor will ask for
  • Anti-bribery policy
  • Quality objectives
  • Resource plan
  • Roles and responsibilities matrix
Where this commonly fails
  • Policy not communicated to third parties
  • Objectives not measurable
  • Roles unstaffed
ISO37001-02
Leadership commitment to quality

Leadership commitment to quality. Control from ISO 37001 framework, domain: ISO 37001: Leadership & Planning.

Artefacts an auditor will ask for
  • Anti-bribery policy
  • Quality objectives
  • Resource plan
  • Roles and responsibilities matrix
Where this commonly fails
  • Policy not communicated to third parties
  • Objectives not measurable
  • Roles unstaffed
ISO37001-03
Risk-based thinking and planning

Risk-based thinking and planning. Control from ISO 37001 framework, domain: ISO 37001: Leadership & Planning.

Artefacts an auditor will ask for
  • Anti-bribery policy
  • Quality objectives
  • Resource plan
  • Roles and responsibilities matrix
Where this commonly fails
  • Policy not communicated to third parties
  • Objectives not measurable
  • Roles unstaffed
ISO37001-04
Resource management for quality

Resource management for quality. Control from ISO 37001 framework, domain: ISO 37001: Leadership & Planning.

Artefacts an auditor will ask for
  • Anti-bribery policy
  • Quality objectives
  • Resource plan
  • Roles and responsibilities matrix
Where this commonly fails
  • Policy not communicated to third parties
  • Objectives not measurable
  • Roles unstaffed
ISO37001-05
Organizational roles and responsibilities

Organizational roles and responsibilities. Control from ISO 37001 framework, domain: ISO 37001: Leadership & Planning.

Artefacts an auditor will ask for
  • Anti-bribery policy
  • Quality objectives
  • Resource plan
  • Roles and responsibilities matrix
Where this commonly fails
  • Policy not communicated to third parties
  • Objectives not measurable
  • Roles unstaffed

ISO 37001: Operational Controls

ISO37001-06
Operational planning and control

Operational planning and control. Control from ISO 37001 framework, domain: ISO 37001: Operational Controls.

Artefacts an auditor will ask for
  • Due diligence procedure
  • Third party register
  • Gifts and hospitality log
  • Operational control matrix
Where this commonly fails
  • Due diligence not risk-tiered
  • Gifts log under-reported
  • Third party controls inconsistent
ISO37001-07
Requirements for products and services

Requirements for products and services. Control from ISO 37001 framework, domain: ISO 37001: Operational Controls.

Artefacts an auditor will ask for
  • Due diligence procedure
  • Third party register
  • Gifts and hospitality log
  • Operational control matrix
Where this commonly fails
  • Due diligence not risk-tiered
  • Gifts log under-reported
  • Third party controls inconsistent
ISO37001-08
Design and development controls

Design and development controls. Control from ISO 37001 framework, domain: ISO 37001: Operational Controls.

Artefacts an auditor will ask for
  • Due diligence procedure
  • Third party register
  • Gifts and hospitality log
  • Operational control matrix
Where this commonly fails
  • Due diligence not risk-tiered
  • Gifts log under-reported
  • Third party controls inconsistent
ISO37001-09
Control of externally provided processes

Control of externally provided processes. Control from ISO 37001 framework, domain: ISO 37001: Operational Controls.

Artefacts an auditor will ask for
  • Due diligence procedure
  • Third party register
  • Gifts and hospitality log
  • Operational control matrix
Where this commonly fails
  • Due diligence not risk-tiered
  • Gifts log under-reported
  • Third party controls inconsistent
ISO37001-10
Production and service provision controls

Production and service provision controls. Control from ISO 37001 framework, domain: ISO 37001: Operational Controls.

Artefacts an auditor will ask for
  • Due diligence procedure
  • Third party register
  • Gifts and hospitality log
  • Operational control matrix
Where this commonly fails
  • Due diligence not risk-tiered
  • Gifts log under-reported
  • Third party controls inconsistent

ISO 37001: Performance Evaluation

ISO37001-11
Monitoring, measurement, and analysis

Monitoring, measurement, and analysis. Control from ISO 37001 framework, domain: ISO 37001: Performance Evaluation.

Artefacts an auditor will ask for
  • Compliance KPI dashboard
  • Internal audit plan
  • Management review minutes
  • Nonconformity log
Where this commonly fails
  • KPIs not leading indicators
  • Audit scope narrow
  • Review actions not closed
ISO37001-12
Internal audit program

Internal audit program. Control from ISO 37001 framework, domain: ISO 37001: Performance Evaluation.

Artefacts an auditor will ask for
  • Compliance KPI dashboard
  • Internal audit plan
  • Management review minutes
  • Nonconformity log
Where this commonly fails
  • KPIs not leading indicators
  • Audit scope narrow
  • Review actions not closed
ISO37001-13
Management review process

Management review process. Control from ISO 37001 framework, domain: ISO 37001: Performance Evaluation.

Artefacts an auditor will ask for
  • Compliance KPI dashboard
  • Internal audit plan
  • Management review minutes
  • Nonconformity log
Where this commonly fails
  • KPIs not leading indicators
  • Audit scope narrow
  • Review actions not closed
ISO37001-14
Customer satisfaction measurement

Customer satisfaction measurement. Control from ISO 37001 framework, domain: ISO 37001: Performance Evaluation.

Artefacts an auditor will ask for
  • Compliance KPI dashboard
  • Internal audit plan
  • Management review minutes
  • Nonconformity log
Where this commonly fails
  • KPIs not leading indicators
  • Audit scope narrow
  • Review actions not closed
ISO37001-15
Nonconformity and corrective action

Nonconformity and corrective action. Control from ISO 37001 framework, domain: ISO 37001: Performance Evaluation.

Artefacts an auditor will ask for
  • Compliance KPI dashboard
  • Internal audit plan
  • Management review minutes
  • Nonconformity log
Where this commonly fails
  • KPIs not leading indicators
  • Audit scope narrow
  • Review actions not closed

Improvement

ISO37001-10.2
Nonconformity and Corrective Action

Address nonconformities through correction, root cause analysis, and corrective actions to prevent recurrence.

Artefacts an auditor will ask for
  • Nonconformity register
  • RCA documentation
  • Corrective action plans
  • Effectiveness verification
Where this commonly fails
  • Symptom-only fixes
  • No effectiveness check
  • Patterns not analysed

Leadership

ISO37001-5.1.1
Governing Body Leadership

Governing body demonstrates leadership and commitment by approving anti-bribery policy and providing oversight.

Artefacts an auditor will ask for
  • Board-approved anti-bribery policy
  • Board minutes on ABMS
  • Annual ABMS report to board
  • Tone-from-top communications
Where this commonly fails
  • Board not briefed on ABMS performance
  • Policy approved once never reviewed
  • No board challenge of incidents
ISO37001-5.1.2
Top Management Leadership

Top management ensures ABMS integration into business processes and provides resources for effectiveness.

Artefacts an auditor will ask for
  • ABMS budget
  • Process integration matrix
  • Management review minutes
  • Top management performance objectives
Where this commonly fails
  • ABMS treated as compliance silo
  • Insufficient resources
  • No top-management KPIs
ISO37001-5.2
Anti-Bribery Policy

Establish, approve, and communicate an anti-bribery policy that prohibits bribery and commits to legal compliance and continual improvement.

Artefacts an auditor will ask for
  • Anti-bribery policy
  • Multi-language translations
  • Policy acknowledgement records
  • Public website posting
Where this commonly fails
  • Policy only in head-office language
  • Acknowledgements not tracked
  • No annual reaffirmation
ISO37001-5.3.2
Anti-Bribery Compliance Function

Assign a compliance function with appropriate competence, status, authority, and independence to oversee the ABMS.

Artefacts an auditor will ask for
  • Anti-bribery compliance function charter
  • Direct reporting line to governing body
  • Function head CV and competencies
  • Budget independence
Where this commonly fails
  • Function reports through finance or legal only
  • Insufficient authority
  • No direct board access

Operation

ISO37001-8.10
Investigating and Dealing with Bribery

Investigate and respond to suspected or actual bribery including documenting findings and corrective actions.

Artefacts an auditor will ask for
  • Investigation procedure
  • Case management system
  • Closure reports
  • Disciplinary records
Where this commonly fails
  • Investigations led by implicated managers
  • No case management
  • Lessons not captured
ISO37001-8.2
Business Associate Due Diligence

Conduct risk-based due diligence on business associates posing more than low bribery risk before engagement and during the relationship.

Artefacts an auditor will ask for
  • Third-party risk tiering
  • Due diligence questionnaires
  • Enhanced due diligence reports
  • Ongoing monitoring evidence
Where this commonly fails
  • One-time diligence only
  • No enhanced diligence for high-risk
  • Owners and PEPs not identified
ISO37001-8.3
Financial Controls

Implement financial controls that manage bribery risk including segregation of duties, approvals, and accurate books.

Artefacts an auditor will ask for
  • Authority matrix
  • Payment approval workflows
  • Reconciliation evidence
  • Accounting policy
Where this commonly fails
  • Cash payments unmonitored
  • No SOD in payment systems
  • Off-book accounts present
ISO37001-8.4
Non-Financial Controls

Implement non-financial controls such as procurement, operations, and sales controls to manage bribery risk.

Artefacts an auditor will ask for
  • Procurement policy
  • Tender controls
  • Sales discount approvals
  • Operational SOD
Where this commonly fails
  • Procurement bypassed for low value
  • No sales discount governance
  • Operations not in scope
ISO37001-8.5
Anti-Bribery Commitments by Controlled Parties

Require controlled organizations and where feasible business associates to implement anti-bribery controls or commit to equivalent measures.

Artefacts an auditor will ask for
  • Anti-bribery contract clauses
  • Subsidiary attestations
  • Compliance certification template
  • Audit rights documentation
Where this commonly fails
  • Standard clauses not used
  • No certification refresh
  • Audit rights never exercised
ISO37001-8.6
Commitments to Anti-Bribery by Business Associates

Implement procedures requiring business associates to commit to anti-bribery in proportion to risk.

Artefacts an auditor will ask for
  • Vendor code of conduct
  • Anti-bribery certifications
  • Termination clauses
  • Periodic recertification
Where this commonly fails
  • Certifications collected once
  • No termination triggers
  • Vendor code unread
ISO37001-8.7
Gifts, Hospitality, Donations, Sponsorships

Implement procedures controlling gifts, hospitality, donations, sponsorships, and similar benefits to prevent bribery.

Artefacts an auditor will ask for
  • Gifts and hospitality policy
  • Pre-approval workflow
  • Gifts register
  • Periodic register review
Where this commonly fails
  • Register incomplete
  • Thresholds not enforced
  • Public officials not flagged
ISO37001-8.8
Managing Inadequate Anti-Bribery Controls

Where controls cannot be implemented, manage residual risk including declining or terminating engagements.

Artefacts an auditor will ask for
  • Escalation protocol
  • Risk acceptance log
  • Termination decisions
  • Senior management approval records
Where this commonly fails
  • No formal acceptance process
  • Engagements continue despite red flags
  • Approval levels too low
ISO37001-8.9
Raising Concerns

Provide accessible reporting channels that allow personnel and external parties to report bribery concerns confidentially without retaliation.

Artefacts an auditor will ask for
  • Whistleblowing channel
  • Anonymous reporting option
  • Anti-retaliation policy
  • Awareness materials
Where this commonly fails
  • Channels in one language only
  • Anonymity not preserved
  • No retaliation monitoring

Performance

ISO37001-9.1
Monitoring, Measurement, Analysis, Evaluation

Determine what needs monitoring and measurement and evaluate ABMS performance and effectiveness.

Artefacts an auditor will ask for
  • ABMS KPI set
  • Monitoring procedures
  • Trend analysis
  • Effectiveness reports
Where this commonly fails
  • No leading indicators
  • Data quality poor
  • Reports descriptive not evaluative
ISO37001-9.2
Internal Audit of ABMS

Conduct internal audits at planned intervals to provide information on whether the ABMS conforms and is effectively implemented.

Artefacts an auditor will ask for
  • Internal audit charter
  • Risk-based audit plan
  • Audit reports
  • Findings tracker
Where this commonly fails
  • Audit plan not risk-based
  • Independence compromised
  • Findings not closed
ISO37001-9.3
Management Review

Top management reviews ABMS at planned intervals to ensure continuing suitability, adequacy, and effectiveness.

Artefacts an auditor will ask for
  • Management review agenda
  • Review pack
  • Minutes with decisions
  • Action tracker
Where this commonly fails
  • Review tick-box
  • No challenge
  • Actions not tracked

Support

ISO37001-7.2.1
Employee Competence

Ensure persons doing work under the ABMS are competent based on education, training, and experience.

Artefacts an auditor will ask for
  • Anti-bribery competency profiles
  • Training completion records
  • Knowledge assessments
  • Refresher schedule
Where this commonly fails
  • No role-based training
  • High-risk roles undertrained
  • No competency assessment
ISO37001-7.2.2.1
Employee Due Diligence

Conduct pre-employment due diligence on personnel exposed to more than low bribery risk.

Artefacts an auditor will ask for
  • Pre-employment screening policy
  • Sanctions and adverse media checks
  • Reference verification
  • Periodic re-screening for high-risk roles
Where this commonly fails
  • No screening for promotions
  • Adverse media checks omitted
  • Re-screening not performed
ISO37001-7.3
Anti-Bribery Awareness and Training

Provide awareness and training on bribery risks, ABMS, and personal obligations to all personnel.

Artefacts an auditor will ask for
  • Awareness communications calendar
  • Role-specific training modules
  • Training attendance records
  • Effectiveness measurement
Where this commonly fails
  • Generic e-learning only
  • Training not refreshed
  • No effectiveness measurement
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the ISO 37001 framework page.