Determining the Scope of the Anti-bribery Management System Under ISO 37001
ISO 37001 Clause 4.3
The boundaries and applicability of the ABMS have to be defined and put in writing - what is in, what is out, and why.
ISO 37001 Clause 4.3 - Determining the Scope of the Anti-bribery Management System
Clause 4.3 requires the organisation to establish the scope of the ABMS by determining its boundaries and applicability. The scope statement is the explicit definition of what the management system covers. Three inputs feed it - the external and internal issues identified in Clause 4.1, the requirements of interested parties from Clause 4.2 and the results of the bribery risk assessment from Clause 4.5. The scope must be available as documented information.
What a Scope Statement Looks Like
A typical ABMS scope statement names the legal entity, the activities covered, the locations included and any specific carve-outs. For organisations with multiple entities or subsidiaries, the scope clarifies which are within the ABMS and which are not. Where parts of the business have been excluded, the scope should explain why - and the explanation has to be defensible against the bribery risk profile of the excluded part.
For ISO 37001 certification, the scope on the certificate is what the certification body audits against. A narrow scope can make initial certification easier but can leave parts of the business exposed if their bribery risk is significant. A scope that does not match the way the business actually operates is also a common cause of audit non-conformities.
Practical Considerations for Setting Scope
Scope decisions are driven by the bribery risk assessment. Activities that involve interactions with public officials, sales agents in higher-risk territories, customs operations or large public-sector contracts almost always have to be in scope. Activities that operate at low risk in stable regulatory environments may sit at the edge of scope, but excluding them entirely usually requires evidence rather than assertion.
The scope is reviewed when the business changes - new acquisitions, new geographies, new customer segments or significant restructures all trigger a review. Changes to the scope are themselves a planning matter under Clause 6.3.
The scope statement sits at the front of the IMS1 Manual. It needs to be precise enough that an auditor can tell what the management system applies to.
I check the scope against what I see on the ground. If the scope says the ABMS covers UK operations but the organisation has staff in two other countries selling to public-sector clients, I want to understand why those operations are not in scope and whether the bribery risk assessment supports that exclusion.
Practical Compliance Guidance
The scope of the ABMS is documented within the IMS1-1-3-1 Procedure (Context and Scope). It records the activities, locations and entities the system covers and is reviewed whenever the business changes significantly.
The documents below support definition and review of the ABMS scope.
| alphaZ document | How to use it |
|---|---|
| ISO 37001 Toolkit | Complete documentation set for ISO 37001:2025 compliance, including the PP-1-19 Anti-bribery procedure, anti-bribery policy, audit checklists, risk assessment and all supporting registers and forms. |
| F-IMS34 Anti-bribery Compliance Register | Captures the high-level review of the ABMS including the scope, key controls and outstanding actions. |
Note - all the above files can be downloaded with an alphaZ subscription.
Frequently Asked Questions
UK Legislation
The following UK legislation typically informs scope decisions because compliance applies to all commercial activities undertaken in the UK regardless of where the legal entity is based.
