ISO 37001
Evidence request list. 42 controls, 42 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.
Context
Determine external and internal issues relevant to the anti-bribery management system and its ability to achieve outcomes.
- PESTLE or SWOT analysis
- Jurisdictional bribery risk briefing
- Regulatory register
- Sector risk assessment
- Context analysis not refreshed
- Foreign operations excluded
- No regulatory horizon scan
Identify interested parties relevant to the ABMS and their relevant requirements regarding anti-bribery.
- Stakeholder register
- Legal and contractual requirements log
- Engagement plan
- Customer and investor anti-bribery clauses
- Business partner expectations omitted
- No tracking of regulator expectations
- Public anti-bribery commitments unverified
Define the boundaries and applicability of the anti-bribery management system including controlled entities.
- Documented ABMS scope
- Subsidiary inclusion list
- Justification for exclusions
- Scope review minutes
- JV and minority holdings not addressed
- Scope statement outdated
- Exclusions undocumented
Conduct regular bribery risk assessment to identify, analyze, evaluate, and prioritize bribery risks the organization faces.
- Bribery risk assessment methodology
- Bribery risk register
- High-risk activity inventory
- Annual reassessment report
- Generic risk assessment not bribery-specific
- No coverage of public official interactions
- Risk owners undefined
ISO 37001: Improvement
Continual improvement methodology. Control from ISO 37001 framework, domain: ISO 37001: Improvement.
- Continual improvement plan
- Corrective action register
- Investigation reports
- Lessons learned log
- Improvement not data-driven
- Investigations slow
- Lessons learned not shared
Corrective and preventive actions. Control from ISO 37001 framework, domain: ISO 37001: Improvement.
- Continual improvement plan
- Corrective action register
- Investigation reports
- Lessons learned log
- Improvement not data-driven
- Investigations slow
- Lessons learned not shared
Innovation and change management. Control from ISO 37001 framework, domain: ISO 37001: Improvement.
- Continual improvement plan
- Corrective action register
- Investigation reports
- Lessons learned log
- Improvement not data-driven
- Investigations slow
- Lessons learned not shared
ISO 37001: Leadership & Planning
Quality policy and objectives. Control from ISO 37001 framework, domain: ISO 37001: Leadership & Planning.
- Anti-bribery policy
- Quality objectives
- Resource plan
- Roles and responsibilities matrix
- Policy not communicated to third parties
- Objectives not measurable
- Roles unstaffed
Leadership commitment to quality. Control from ISO 37001 framework, domain: ISO 37001: Leadership & Planning.
- Anti-bribery policy
- Quality objectives
- Resource plan
- Roles and responsibilities matrix
- Policy not communicated to third parties
- Objectives not measurable
- Roles unstaffed
Risk-based thinking and planning. Control from ISO 37001 framework, domain: ISO 37001: Leadership & Planning.
- Anti-bribery policy
- Quality objectives
- Resource plan
- Roles and responsibilities matrix
- Policy not communicated to third parties
- Objectives not measurable
- Roles unstaffed
Resource management for quality. Control from ISO 37001 framework, domain: ISO 37001: Leadership & Planning.
- Anti-bribery policy
- Quality objectives
- Resource plan
- Roles and responsibilities matrix
- Policy not communicated to third parties
- Objectives not measurable
- Roles unstaffed
Organizational roles and responsibilities. Control from ISO 37001 framework, domain: ISO 37001: Leadership & Planning.
- Anti-bribery policy
- Quality objectives
- Resource plan
- Roles and responsibilities matrix
- Policy not communicated to third parties
- Objectives not measurable
- Roles unstaffed
ISO 37001: Operational Controls
Operational planning and control. Control from ISO 37001 framework, domain: ISO 37001: Operational Controls.
- Due diligence procedure
- Third party register
- Gifts and hospitality log
- Operational control matrix
- Due diligence not risk-tiered
- Gifts log under-reported
- Third party controls inconsistent
Requirements for products and services. Control from ISO 37001 framework, domain: ISO 37001: Operational Controls.
- Due diligence procedure
- Third party register
- Gifts and hospitality log
- Operational control matrix
- Due diligence not risk-tiered
- Gifts log under-reported
- Third party controls inconsistent
Design and development controls. Control from ISO 37001 framework, domain: ISO 37001: Operational Controls.
- Due diligence procedure
- Third party register
- Gifts and hospitality log
- Operational control matrix
- Due diligence not risk-tiered
- Gifts log under-reported
- Third party controls inconsistent
Control of externally provided processes. Control from ISO 37001 framework, domain: ISO 37001: Operational Controls.
- Due diligence procedure
- Third party register
- Gifts and hospitality log
- Operational control matrix
- Due diligence not risk-tiered
- Gifts log under-reported
- Third party controls inconsistent
Production and service provision controls. Control from ISO 37001 framework, domain: ISO 37001: Operational Controls.
- Due diligence procedure
- Third party register
- Gifts and hospitality log
- Operational control matrix
- Due diligence not risk-tiered
- Gifts log under-reported
- Third party controls inconsistent
ISO 37001: Performance Evaluation
Monitoring, measurement, and analysis. Control from ISO 37001 framework, domain: ISO 37001: Performance Evaluation.
- Compliance KPI dashboard
- Internal audit plan
- Management review minutes
- Nonconformity log
- KPIs not leading indicators
- Audit scope narrow
- Review actions not closed
Internal audit program. Control from ISO 37001 framework, domain: ISO 37001: Performance Evaluation.
- Compliance KPI dashboard
- Internal audit plan
- Management review minutes
- Nonconformity log
- KPIs not leading indicators
- Audit scope narrow
- Review actions not closed
Management review process. Control from ISO 37001 framework, domain: ISO 37001: Performance Evaluation.
- Compliance KPI dashboard
- Internal audit plan
- Management review minutes
- Nonconformity log
- KPIs not leading indicators
- Audit scope narrow
- Review actions not closed
Customer satisfaction measurement. Control from ISO 37001 framework, domain: ISO 37001: Performance Evaluation.
- Compliance KPI dashboard
- Internal audit plan
- Management review minutes
- Nonconformity log
- KPIs not leading indicators
- Audit scope narrow
- Review actions not closed
Nonconformity and corrective action. Control from ISO 37001 framework, domain: ISO 37001: Performance Evaluation.
- Compliance KPI dashboard
- Internal audit plan
- Management review minutes
- Nonconformity log
- KPIs not leading indicators
- Audit scope narrow
- Review actions not closed
Improvement
Address nonconformities through correction, root cause analysis, and corrective actions to prevent recurrence.
- Nonconformity register
- RCA documentation
- Corrective action plans
- Effectiveness verification
- Symptom-only fixes
- No effectiveness check
- Patterns not analysed
Leadership
Governing body demonstrates leadership and commitment by approving anti-bribery policy and providing oversight.
- Board-approved anti-bribery policy
- Board minutes on ABMS
- Annual ABMS report to board
- Tone-from-top communications
- Board not briefed on ABMS performance
- Policy approved once never reviewed
- No board challenge of incidents
Top management ensures ABMS integration into business processes and provides resources for effectiveness.
- ABMS budget
- Process integration matrix
- Management review minutes
- Top management performance objectives
- ABMS treated as compliance silo
- Insufficient resources
- No top-management KPIs
Establish, approve, and communicate an anti-bribery policy that prohibits bribery and commits to legal compliance and continual improvement.
- Anti-bribery policy
- Multi-language translations
- Policy acknowledgement records
- Public website posting
- Policy only in head-office language
- Acknowledgements not tracked
- No annual reaffirmation
Assign a compliance function with appropriate competence, status, authority, and independence to oversee the ABMS.
- Anti-bribery compliance function charter
- Direct reporting line to governing body
- Function head CV and competencies
- Budget independence
- Function reports through finance or legal only
- Insufficient authority
- No direct board access
Operation
Investigate and respond to suspected or actual bribery including documenting findings and corrective actions.
- Investigation procedure
- Case management system
- Closure reports
- Disciplinary records
- Investigations led by implicated managers
- No case management
- Lessons not captured
Conduct risk-based due diligence on business associates posing more than low bribery risk before engagement and during the relationship.
- Third-party risk tiering
- Due diligence questionnaires
- Enhanced due diligence reports
- Ongoing monitoring evidence
- One-time diligence only
- No enhanced diligence for high-risk
- Owners and PEPs not identified
Implement financial controls that manage bribery risk including segregation of duties, approvals, and accurate books.
- Authority matrix
- Payment approval workflows
- Reconciliation evidence
- Accounting policy
- Cash payments unmonitored
- No SOD in payment systems
- Off-book accounts present
Implement non-financial controls such as procurement, operations, and sales controls to manage bribery risk.
- Procurement policy
- Tender controls
- Sales discount approvals
- Operational SOD
- Procurement bypassed for low value
- No sales discount governance
- Operations not in scope
Require controlled organizations and where feasible business associates to implement anti-bribery controls or commit to equivalent measures.
- Anti-bribery contract clauses
- Subsidiary attestations
- Compliance certification template
- Audit rights documentation
- Standard clauses not used
- No certification refresh
- Audit rights never exercised
Implement procedures requiring business associates to commit to anti-bribery in proportion to risk.
- Vendor code of conduct
- Anti-bribery certifications
- Termination clauses
- Periodic recertification
- Certifications collected once
- No termination triggers
- Vendor code unread
Implement procedures controlling gifts, hospitality, donations, sponsorships, and similar benefits to prevent bribery.
- Gifts and hospitality policy
- Pre-approval workflow
- Gifts register
- Periodic register review
- Register incomplete
- Thresholds not enforced
- Public officials not flagged
Where controls cannot be implemented, manage residual risk including declining or terminating engagements.
- Escalation protocol
- Risk acceptance log
- Termination decisions
- Senior management approval records
- No formal acceptance process
- Engagements continue despite red flags
- Approval levels too low
Provide accessible reporting channels that allow personnel and external parties to report bribery concerns confidentially without retaliation.
- Whistleblowing channel
- Anonymous reporting option
- Anti-retaliation policy
- Awareness materials
- Channels in one language only
- Anonymity not preserved
- No retaliation monitoring
Performance
Determine what needs monitoring and measurement and evaluate ABMS performance and effectiveness.
- ABMS KPI set
- Monitoring procedures
- Trend analysis
- Effectiveness reports
- No leading indicators
- Data quality poor
- Reports descriptive not evaluative
Conduct internal audits at planned intervals to provide information on whether the ABMS conforms and is effectively implemented.
- Internal audit charter
- Risk-based audit plan
- Audit reports
- Findings tracker
- Audit plan not risk-based
- Independence compromised
- Findings not closed
Top management reviews ABMS at planned intervals to ensure continuing suitability, adequacy, and effectiveness.
- Management review agenda
- Review pack
- Minutes with decisions
- Action tracker
- Review tick-box
- No challenge
- Actions not tracked
Support
Ensure persons doing work under the ABMS are competent based on education, training, and experience.
- Anti-bribery competency profiles
- Training completion records
- Knowledge assessments
- Refresher schedule
- No role-based training
- High-risk roles undertrained
- No competency assessment
Conduct pre-employment due diligence on personnel exposed to more than low bribery risk.
- Pre-employment screening policy
- Sanctions and adverse media checks
- Reference verification
- Periodic re-screening for high-risk roles
- No screening for promotions
- Adverse media checks omitted
- Re-screening not performed
Provide awareness and training on bribery risks, ABMS, and personal obligations to all personnel.
- Awareness communications calendar
- Role-specific training modules
- Training attendance records
- Effectiveness measurement
- Generic e-learning only
- Training not refreshed
- No effectiveness measurement
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the ISO 37001 framework page.