Services / ISO 37001 certification
ISO 37001 anti-bribery management system certification
Show customers, partners and public buyers that you prevent, detect and respond to bribery with a system that is audited independently, from $800.
From $800Certified by EUROTECH

- Accredited by IAB and INTAQS
- Issuing certificates since 2004
- Online or on-site audits worldwide
- Verify any EUROTECH certificate
What ISO 37001 certification covers
ISO 37001 sets the requirements for an anti-bribery management system. It covers bribery in all its forms: offered or received, direct or through third parties, involving public officials or private companies. It applies to any organization, but it is most often asked for in public procurement, construction, energy, defence, healthcare and companies with agents and intermediaries in many countries.
The audit looks at how you assess bribery risk and the controls that follow from it. That includes the anti-bribery policy, a compliance function with enough independence and authority, due diligence on higher-risk transactions, business associates and staff in sensitive positions, controls on gifts, hospitality, donations and sponsorships, financial and non-financial controls, and a channel for raising concerns without fear of retaliation.
ISO 37001 cannot promise that no bribery will ever happen. What it asks for, and what the auditor checks, are reasonable and proportionate measures designed to prevent, detect and respond to it.
- Stage 1 review of the bribery risk assessment, policy and documented system
- Stage 2 audit of controls, due diligence, training and investigations
- Certification decision and three-year certificate
- Certificate listed on our verification portal
- Yearly surveillance audits and recertification
The standard also expects the governing body, such as the board, to oversee the system. The auditor checks that the board receives anti-bribery information and acts on it, not only that management has approved a policy.
Choosing the scope and the audit format
Some organizations certify the whole company; others start with the business units or countries where bribery risk is highest. The scope should be honest about where the risk sits. A scope that leaves out the sales office in a high-risk market while covering the head office is unlikely to convince buyers.
Much of the ISO 37001 audit is document review and interviews: risk assessment, due diligence files, gift registers, finance controls, training records and investigation files. These suit online auditing well. For larger organizations or higher-risk operations, interviews in person at key sites can add value, and we discuss this when we quote.
ISO 37001 shares the high-level structure of other management system standards and fits closely with ISO 37301 for compliance management. Many organizations run anti-bribery inside a wider compliance management system and certify both together.
Group structures need care. If subsidiaries or joint ventures fall outside the scope, the standard still expects you to consider the bribery risk they create for the certified organization, for example through shared agents or intercompany payments.
What decides the price
ISO 37001 certification with EUROTECH starts at $800. Audit time depends on the size and risk profile of what is in scope.
- Number of people in scope, with attention to staff in sensitive roles
- Countries and sites where you operate or use agents
- Business associates: agents, distributors, joint venture partners and subcontractors
- Exposure to public officials through tenders, licences, permits or customs
- Integration with ISO 37301 or other management systems
We confirm audit days and all fees in a written quote. A clear register of business associates with their risk ratings and due diligence status saves audit time.
Organizations with many intermediaries, such as agents paid on commission in several countries, usually need more audit time, because due diligence and payment controls are sampled for a representative number of them.
How ISO 37001 certification works with us

Step 1
Scope and quote
We agree the units, countries and business associates in scope and quote the audit in writing.

Step 2
Stage 1 review
We review your bribery risk assessment, policy, compliance function and controls.

Step 3
Stage 2 audit
The auditor samples due diligence, gifts, payments, training and investigation files.

Step 4
Certificate and surveillance
After the decision you receive the ISO 37001 certificate, with yearly surveillance audits.
Bribery law in the markets you serve
We certify ISO 37001 for organizations in the USA, Europe, Asia and Africa. Anti-bribery law reaches across borders. The US Foreign Corrupt Practices Act applies to many companies with links to the USA, the UK Bribery Act covers organizations that carry on business in the UK, and most countries have their own laws on bribery of public officials and, increasingly, private bribery.
Some of these laws give weight to whether an organization had adequate procedures to prevent bribery. ISO 37001 certification does not provide legal immunity, but a working, audited system is strong evidence of the procedures you had in place.
Local practice also matters. Gift customs, facilitation payment risks and the role of agents differ by country, and your risk assessment and controls should reflect where you actually work.
What to expect during the audit
The auditor will test how risk assessment drives controls. If your assessment says a market or a type of transaction is high risk, the auditor expects to see stronger due diligence, approvals and monitoring there, and will pick files from those areas.
Typical samples include: due diligence on recently appointed agents or distributors, the gift and hospitality register with approvals, payments to third parties checked against contracts and services delivered, training records for staff in sensitive roles, and concerns raised through the reporting channel with how they were investigated.
The auditor will also speak with the compliance function and senior management about their role and oversight, because leadership commitment is central to the standard.
Contracts with business associates are reviewed for anti-bribery clauses where the risk calls for them: commitments to comply, audit rights and the right to terminate if bribery occurs. The auditor checks that these clauses exist where your own procedure says they should.
Findings are graded as major or minor, and certification is decided on the evidence. You receive a written report explaining every finding.
Keeping the certificate
Keep the bribery risk assessment current as you enter new markets, take on new agents or bid for new types of contracts. Refresh due diligence on business associates at intervals that match their risk, keep training going for staff in sensitive roles and monitor the effectiveness of controls through internal audits.
Measure what the system does: due diligence completed on time, training completion for sensitive roles, gift register entries reviewed, concerns raised and closed. These indicators give management review something concrete to discuss and give the surveillance auditor evidence of effectiveness.
Surveillance audits look at any concerns raised and investigations since the last visit, changes in risk, and how management reviews the system. Tell us about major changes in scope, such as entering a high-risk country or an acquisition, so the audit plan reflects them.
Questions buyers ask
How much does ISO 37001 certification cost?
With EUROTECH it starts at $800. People, countries, business associates, public exposure and integration set the final price.
Does ISO 37001 protect us from prosecution?
No. It does not give legal immunity. An audited system is evidence of the procedures you had in place, which some laws take into account.
Does ISO 37001 cover private bribery?
Yes. It covers bribery involving public officials and private parties, offered or received, directly or through third parties.
What is due diligence under ISO 37001?
A proportionate check on higher-risk transactions, business associates and staff in sensitive positions, to decide whether to proceed and what controls to apply.
Can ISO 37001 be combined with ISO 37301?
Yes. Anti-bribery often runs inside a wider compliance management system, and both can be audited together.
Can the audit be done online?
Much of it can. For larger or higher-risk organizations, some interviews at key sites may be planned in person.
Related services
- ISO 37301 certification
From $800
- ISO 31000 assessment
From $800
- ISO 9001 certification
From $800
Get a quote for ISO 37001 certification
Tell us your company, sites and the standard you need. We reply with a written quote and the audit plan.
Prefer to talk? Call +1 307 205 1833
Monday to Friday, 09:00 to 18:00 (US Mountain Time)
