Anti-bribery Management System Under ISO 37001
ISO 37001 Clause 4.4
The clause that puts the ABMS in place. Whatever I see in audit has to be reasonable and proportionate to the actual bribery risk.
ISO 37001 Clause 4.4 - Anti-bribery Management System
Clause 4.4 is the clause that establishes the ABMS itself. The previous clauses set out what to consider - this one requires the organisation to establish, implement, maintain and continually improve an anti-bribery management system, including the processes needed and their interactions.
What ISO 37001 Clause 4.4 Requires
The ABMS must include measures to identify and evaluate the risk of bribery and to prevent, detect and respond to bribery. Documentation is required - the standard expects the system to be sufficiently documented to support its operation and audit. The phrase that does most of the work in the clause is "reasonable and proportionate". The system has to match the bribery risks identified in Clause 4.5 and the context in Clause 4.1. A small business with low public-official exposure does not need the same level of control as a large multinational selling to government in higher-risk regions.
What an ABMS Looks Like in Practice
An ABMS is not a single document. It is a connected set of processes, policies, controls and records. The core building blocks are an anti-bribery policy (Clause 5.2), defined roles and an anti-bribery function (Clause 5.3), a bribery risk assessment (Clause 4.5), due diligence procedures (Clause 8.2), financial and non-financial controls (Clauses 8.3 and 8.4), arrangements for raising concerns (Clause 8.9), training and awareness (Clauses 7.2 and 7.3), monitoring and audit (Clause 9) and corrective action and improvement (Clause 10).
The integrated management system approach used (IMS) covers all of these by providing a single management system that points at supporting policies, registers and procedures. The ABMS sits within this framework rather than being a parallel system.
You do not need to start from scratch when establishing the ABMS. Most organisations already have purchasing controls, expense approval, a code of conduct and HR procedures in place. The job is to organise these around bribery risk, fill the gaps the bribery risk assessment identifies and document how the parts connect.
Reasonable and proportionate is the key phrase. It does not mean minimal effort - it means matching what you do to what your bribery risk assessment says about your organisation. If your business hands over cash to local agents in countries with weak anti-corruption regimes, your ABMS needs to look very different to one for an SME selling software to UK private-sector customers.
Practical Compliance Guidance
The management system - in integrated format (IMS) itself provides the central structure for the ABMS, with PP-1-19 as the operational anti-bribery procedure and supporting registers tracking the practical detail.
The documents below establish the ABMS framework required by Clause 4.4.
| alphaZ document | How to use it |
|---|---|
| ISO 37001 Toolkit | Complete documentation set for ISO 37001:2025 compliance, including the anti-bribery policy, the PP-1-19 Anti-bribery procedure, audit checklists, risk assessment and all supporting registers and forms. |
| PP-1-19 Anti-bribery Procedure | Central operational procedure setting out how the organisation identifies bribery risk, applies controls and responds to bribery concerns. |
| P-10 Anti-bribery and Corruption Policy | Public-facing anti-bribery policy that sits within the ABMS and can be shared externally. |
| F-IMS34 Anti-bribery Compliance Register | High-level overview of ABMS arrangements, controls and ongoing review actions. |
Note - all the above files can be downloaded with an alphaZ subscription.
Frequently Asked Questions
UK Legislation
The following UK legislation drives many of the controls within the ABMS - the Bribery Act 2010 in particular makes adequate procedures the only defence against the corporate offence of failing to prevent bribery.
