Anti-bribery Management System Under ISO 37001

ISO 37001 Clause 4.4

The clause that puts the ABMS in place. Whatever I see in audit has to be reasonable and proportionate to the actual bribery risk.

ISO 37001 Clause 4.4 - Anti-bribery Management System

Clause 4.4 is the clause that establishes the ABMS itself. The previous clauses set out what to consider - this one requires the organisation to establish, implement, maintain and continually improve an anti-bribery management system, including the processes needed and their interactions.

What ISO 37001 Clause 4.4 Requires

The ABMS must include measures to identify and evaluate the risk of bribery and to prevent, detect and respond to bribery. Documentation is required - the standard expects the system to be sufficiently documented to support its operation and audit. The phrase that does most of the work in the clause is "reasonable and proportionate". The system has to match the bribery risks identified in Clause 4.5 and the context in Clause 4.1. A small business with low public-official exposure does not need the same level of control as a large multinational selling to government in higher-risk regions.

What an ABMS Looks Like in Practice

An ABMS is not a single document. It is a connected set of processes, policies, controls and records. The core building blocks are an anti-bribery policy (Clause 5.2), defined roles and an anti-bribery function (Clause 5.3), a bribery risk assessment (Clause 4.5), due diligence procedures (Clause 8.2), financial and non-financial controls (Clauses 8.3 and 8.4), arrangements for raising concerns (Clause 8.9), training and awareness (Clauses 7.2 and 7.3), monitoring and audit (Clause 9) and corrective action and improvement (Clause 10).

The integrated management system approach used (IMS) covers all of these by providing a single management system that points at supporting policies, registers and procedures. The ABMS sits within this framework rather than being a parallel system.

You do not need to start from scratch when establishing the ABMS. Most organisations already have purchasing controls, expense approval, a code of conduct and HR procedures in place. The job is to organise these around bribery risk, fill the gaps the bribery risk assessment identifies and document how the parts connect.

Reasonable and proportionate is the key phrase. It does not mean minimal effort - it means matching what you do to what your bribery risk assessment says about your organisation. If your business hands over cash to local agents in countries with weak anti-corruption regimes, your ABMS needs to look very different to one for an SME selling software to UK private-sector customers.

Practical Compliance Guidance

The management system - in integrated format (IMS) itself provides the central structure for the ABMS, with PP-1-19 as the operational anti-bribery procedure and supporting registers tracking the practical detail.

The documents below establish the ABMS framework required by Clause 4.4.

alphaZ document How to use it
ISO 37001 Toolkit Complete documentation set for ISO 37001:2025 compliance, including the anti-bribery policy, the PP-1-19 Anti-bribery procedure, audit checklists, risk assessment and all supporting registers and forms.
PP-1-19 Anti-bribery Procedure Central operational procedure setting out how the organisation identifies bribery risk, applies controls and responds to bribery concerns.
P-10 Anti-bribery and Corruption Policy Public-facing anti-bribery policy that sits within the ABMS and can be shared externally.
F-IMS34 Anti-bribery Compliance Register High-level overview of ABMS arrangements, controls and ongoing review actions.

Note - all the above files can be downloaded with an alphaZ subscription.

Frequently Asked Questions

The clause requires the ABMS to be documented to the extent necessary for its operation. A standalone manual is one way - integrating ABMS content into a wider IMS1 manual is another. What matters is that there is a coherent, retrievable description of the system that staff and auditors can follow.
It means the ABMS matches the bribery risks the organisation actually faces. The standard does not prescribe a fixed level of control - it expects the level to flex with risk. A high-risk operation gets stronger controls. A low-risk operation gets simpler controls. The bribery risk assessment is the link.
Yes. The IMS1 approach puts ABMS content alongside ISO 9001, 14001, 45001, 27001 and 22301 elements in a single integrated manual. The key requirement is that the anti-bribery elements remain identifiable and that the controls required by ISO 37001 are clearly in place.

UK Legislation

The following UK legislation drives many of the controls within the ABMS - the Bribery Act 2010 in particular makes adequate procedures the only defence against the corporate offence of failing to prevent bribery.

Further Resources

payment logos