Bribery Risk Assessment for ISO 37001
ISO 37001 Clause 4.5
The cornerstone of the standard. Without a current, considered bribery risk assessment the rest of the ABMS has nothing to anchor to.
ISO 37001 Clause 4.5 - Bribery Risk Assessment
Clause 4.5 sits at the heart of ISO 37001:2025. It requires the organisation to complete a bribery risk assessment at planned intervals and to use it to design and continually improve the ABMS. Every other clause in the standard either feeds the bribery risk assessment or responds to it. If the assessment is wrong, weak or out of date, the rest of the system loses its connection to actual risk.
What ISO 37001 Clause 4.5 Requires
The bribery risk assessment must identify the bribery risks the organisation can reasonably expect to face, taking the Clause 4.1 context factors into account. It must analyse, assess and prioritise the identified risks. It must evaluate the suitability and effectiveness of existing controls. Clause 4.5.2 adds the requirement to determine criteria for the organisation's own bribery risk levels, considering its policies and objectives. Clause 4.5.3 requires review at planned intervals and whenever significant organisational changes occur. Clause 4.5.4 requires the assessment to be retained as documented information demonstrating it has been conducted and used to design and improve the ABMS.
The 2025 revision of the standard tightened the review wording from "on a regular basis" to "at planned intervals" - aligning the clause with the wider Annex SL convention and removing ambiguity about what counts as regular.
How the Bribery Risk Assessment Works in Practice
A typical bribery risk assessment lists each significant activity, transaction type or relationship category, identifies the specific bribery risks each one could give rise to, scores the inherent risk before controls, lists the controls in place and scores the residual risk after controls. Where residual risk is still above the organisation's own tolerance, additional controls are identified and tracked through to implementation.
The factors that typically appear in the analysis include geography, sector, type of customer (public versus private), use of third-party intermediaries, complexity of supply chains, gift and hospitality activity, and the existence of any incentive arrangements that could push individuals toward inappropriate behaviour.
Scoring and Criteria
The standard does not prescribe a scoring method. A simple likelihood-versus-consequence matrix is common - the same approach used elsewhere in the management system - with the residual rating compared against pre-set criteria for what the organisation considers low, moderate or high. The criteria themselves are part of the documented information required by Clause 4.5.2.
The assessment template provided as RA-AB1 uses a single document approach - inherent risk, controls in place, residual risk and any additional actions in one place. This makes it easier to review periodically and easier to defend in audit because every element of Clause 4.5 is visible on the same page.
Be specific. A bribery risk assessment with vague entries like risk of bribery in supplier relationships, moderate, controls in place tells nobody anything useful. Name the supplier categories, name the geographies, name the activities. The point of the document is to expose actual exposure, not to look reassuring.
I check three things on the bribery risk assessment - that it has been reviewed at the planned interval, that the controls listed actually exist somewhere in the ABMS, and that the residual risks above the tolerance level have actions assigned with owners and dates. If any of those three is missing, the assessment is not doing its job.
Practical Compliance Guidance
The bribery risk assessment is the foundation document of the ABMS. RA-AB1 Bribery Risk Assessment provides a worked example using the F-Q36 risk assessment format, while F-IMS34 tracks the higher-level review and ongoing actions arising from the assessment.
The documents below support the bribery risk assessment process required by Clause 4.5.
| alphaZ document | How to use it |
|---|---|
| ISO 37001 Toolkit | Complete documentation set for ISO 37001:2025 compliance, including the anti-bribery policy, the PP-1-19 Anti-bribery procedure, audit checklists, risk assessments and all supporting registers and forms. |
| RA-AB1 Bribery Risk Assessment | Worked example bribery risk assessment showing inherent risk, controls and residual risk for typical activity categories - a starting point that can be adapted to the organisation. |
| F-IMS34 Anti-bribery Compliance Register | Captures the high-level review of the ABMS including the date the bribery risk assessment was last completed and the actions arising from it. |
| ER1 Issues Actions Register | Tracks actions arising from the bribery risk assessment from identification through to closure. |
Note - all the above files can be downloaded with an alphaZ subscription.
Frequently Asked Questions
UK Legislation
The following UK legislation establishes the legal exposures the bribery risk assessment exists to identify and control.
