Determining the Scope of the Anti-bribery Management System Under ISO 37001

ISO 37001 Clause 4.3

The boundaries and applicability of the ABMS have to be defined and put in writing - what is in, what is out, and why.

ISO 37001 Clause 4.3 - Determining the Scope of the Anti-bribery Management System

Clause 4.3 requires the organisation to establish the scope of the ABMS by determining its boundaries and applicability. The scope statement is the explicit definition of what the management system covers. Three inputs feed it - the external and internal issues identified in Clause 4.1, the requirements of interested parties from Clause 4.2 and the results of the bribery risk assessment from Clause 4.5. The scope must be available as documented information.

What a Scope Statement Looks Like

A typical ABMS scope statement names the legal entity, the activities covered, the locations included and any specific carve-outs. For organisations with multiple entities or subsidiaries, the scope clarifies which are within the ABMS and which are not. Where parts of the business have been excluded, the scope should explain why - and the explanation has to be defensible against the bribery risk profile of the excluded part.

For ISO 37001 certification, the scope on the certificate is what the certification body audits against. A narrow scope can make initial certification easier but can leave parts of the business exposed if their bribery risk is significant. A scope that does not match the way the business actually operates is also a common cause of audit non-conformities.

Practical Considerations for Setting Scope

Scope decisions are driven by the bribery risk assessment. Activities that involve interactions with public officials, sales agents in higher-risk territories, customs operations or large public-sector contracts almost always have to be in scope. Activities that operate at low risk in stable regulatory environments may sit at the edge of scope, but excluding them entirely usually requires evidence rather than assertion.

The scope is reviewed when the business changes - new acquisitions, new geographies, new customer segments or significant restructures all trigger a review. Changes to the scope are themselves a planning matter under Clause 6.3.

The scope statement sits at the front of the IMS1 Manual. It needs to be precise enough that an auditor can tell what the management system applies to. 

I check the scope against what I see on the ground. If the scope says the ABMS covers UK operations but the organisation has staff in two other countries selling to public-sector clients, I want to understand why those operations are not in scope and whether the bribery risk assessment supports that exclusion.

Practical Compliance Guidance

The scope of the ABMS is documented within the IMS1-1-3-1 Procedure (Context and Scope). It records the activities, locations and entities the system covers and is reviewed whenever the business changes significantly.

The documents below support definition and review of the ABMS scope.

alphaZ document How to use it
ISO 37001 Toolkit Complete documentation set for ISO 37001:2025 compliance, including the PP-1-19 Anti-bribery procedure, anti-bribery policy, audit checklists, risk assessment and all supporting registers and forms.
F-IMS34 Anti-bribery Compliance Register Captures the high-level review of the ABMS including the scope, key controls and outstanding actions.

Note - all the above files can be downloaded with an alphaZ subscription.

Frequently Asked Questions

Yes, but the exclusion has to be justified by the bribery risk assessment. Excluding a part of the business that has a meaningful bribery risk is not defensible. Excluding a part that has minimal exposure can be acceptable if the analysis supports it and the scope statement is clear.
It does not have to match. ISO 9001 scope is about quality and customer satisfaction. ISO 37001 scope is about bribery risk. The two often overlap but the boundaries can be different - for example an ABMS might exclude a low-risk research function that is included in the QMS scope.
At least annually as part of management review, and whenever a significant change occurs - new acquisitions, new countries, new customer types or restructures. The scope is also reviewed when the bribery risk assessment surfaces material new risks in areas previously considered out of scope.

UK Legislation

The following UK legislation typically informs scope decisions because compliance applies to all commercial activities undertaken in the UK regardless of where the legal entity is based.

Further Resources

payment logos