Organisational Roles, Responsibilities and Authorities for ISO 37001 Anti-Bribery

ISO 37001 Clause 5.3

Roles and responsibilities, the anti-bribery function with proper independence and resources, and controls on delegated decision-making.

ISO 37001 Clause 5.3 - Organisational Roles, Responsibilities and Authorities

Clause 5.3 has three parts. 5.3.1 sets the basic responsibility for the ABMS at top management level and requires roles to be assigned and communicated. 5.3.2 establishes the anti-bribery function. 5.3.3 requires controls around delegated decision-making in higher-risk situations.

ISO 37001 Clause 5.3.1 - General Responsibilities

Top management retain overall responsibility for the implementation of and compliance with the ABMS. Responsibilities and authorities for relevant roles must be assigned and communicated within the organisation. Managers at every level are responsible for applying the ABMS in their area or department, and the governing body, top management and all personnel are responsible for understanding, complying with and applying the ABMS as it relates to their work.

The simplest way to satisfy 5.3.1 is a responsibilities document - typically embedded in the IMS1 manual - that lists every role with anti-bribery responsibilities and what those responsibilities are.

ISO 37001 Clause 5.3.2 - The Anti-bribery Function

The anti-bribery function (renamed from "anti-bribery compliance function" in the 2025 revision, often abbreviated to ABF) is a defining feature of ISO 37001. The function has responsibility and authority for confirming the ABMS conforms to the standard, reporting on ABMS performance to the governing body and top management, overseeing the design and implementation of the ABMS, and providing guidance and advice to personnel and interested parties.

The function must be adequately resourced and assigned to one or more people with appropriate competence, status, authority and independence. It must have direct and prompt access to the governing body and top management to raise issues. The function can be assigned externally where appropriate - if it is, specific personnel inside the organisation must retain authority over the externally provided parts.

In smaller organisations the anti-bribery function is often a single named individual - the anti-bribery lead - who may also have other duties. The independence requirement is then met by having the anti-bribery lead report directly to top management on ABMS matters and not be the person being audited or investigated. Larger organisations typically establish an anti-bribery committee, sometimes called a Focus-ABC committee, to share the workload and provide collective independence.

ISO 37001 Clause 5.3.3 - Delegated Decision-Making

Where decision-making is delegated to personnel in areas with greater than low bribery risk, the organisation must establish a process or set of controls to confirm the decision-making process and the level of authority are appropriate and free of actual or potential conflicts of interest. Top management must review these processes at planned intervals.

In practice this typically means specifying authority limits, requiring two-person authorisation above certain thresholds, and having decisions involving public officials, agents in higher-risk regions or significant contract awards subject to appropriate oversight.

The anti-bribery function does not have to be a full-time role. In a smaller organisation it is often a senior person with a clear mandate, regular reporting time with top management and the authority to investigate or escalate without being blocked. What matters is that the role is named, resourced and able to act independently.

Independence does not mean isolation. The anti-bribery lead needs to know what is going on - in sales, in purchasing, in HR - and needs the standing to ask awkward questions. The role works when it is integrated with the rest of the management system, not parked off to one side.

I check that the anti-bribery function is named, that the person knows what the role involves, that they have access to the governing body or top management, and that they can show me reports they have made. If the anti-bribery lead has never reported anything to top management, that is usually a sign the function is not really operating.

Practical Compliance Guidance

The IMS1-2-2-1 Responsibilities records the responsibilities of every role with ABMS duties. The anti-bribery function is established through a combination of the IMS1-2-2-1 Procedure, PP-1-19 and F-IMS34 which together set out who does what and how it is reviewed.

The documents below establish and support the roles required by Clause 5.3.

alphaZ document How to use it
ISO 37001 Toolkit Complete documentation set for ISO 37001:2025 compliance, including the anti-bribery policy, the PP-1-19 Anti-bribery procedure, audit checklists, risk assessment and all supporting registers and forms.
PP-1-19 Anti-bribery Procedure Sets out the anti-bribery function, the Focus-ABC committee arrangement and the responsibilities of the anti-bribery lead.
F-IMS34 Anti-bribery Compliance Register Records the anti-bribery function, committee membership and ongoing oversight of the ABMS.
F-AB5 Focus-ABC Committee Template for setting up and recording the proceedings of an anti-bribery committee.

Note - all the above files can be downloaded with an alphaZ subscription.

Frequently Asked Questions

Yes. The standard requires the function to be adequately resourced and competent, but does not require it to be full-time. In smaller organisations the role is typically held by a senior person with other duties, with sufficient time and authority allocated to operate it properly.
Parts of it can. The standard allows top management to assign some or all of the function externally. Where this happens, specific named personnel inside the organisation must retain authority over the outsourced part. The function as a whole cannot just disappear into a third party.
It means the function can investigate, escalate and report without being blocked or influenced by the people whose activities are being assessed. In practice it means a reporting line to top management or the governing body that is separate from operational reporting, and the authority to act on findings.
No specific document is required, but the controls have to exist somewhere. Most organisations cover this through their delegation of authority document, financial limits in the purchasing procedure, or specific authority requirements written into the anti-bribery procedure.

UK Legislation

The following UK legislation interacts with ABMS roles - particularly the Bribery Act 2010 corporate offence which makes responsibility at top management level a legal as well as an ABMS matter.

Further Resources

payment logos