Anti-bribery Objectives and Planning to Achieve Them for ISO 37001

ISO 37001 Clause 6.2

Anti-bribery objectives - what they have to look like, where they apply and how they get planned.

ISO 37001 Clause 6.2 - Anti-bribery Objectives and Planning to Achieve Them

Clause 6.2 requires the organisation to establish anti-bribery objectives at relevant functions and levels. The objectives have to be consistent with the anti-bribery policy, measurable where practicable, take applicable requirements into account, be monitored, communicated and updated as appropriate, available as documented information and achievable.

Planning the Objectives

For each objective the standard requires the organisation to determine what is to be done, the resources required, who will be responsible, when the objective will be achieved, how the results will be evaluated, and who will impose any sanctions or penalties for failure.

The list is not unusual for an ISO objective - it is the same SMART framework used in other management systems with the addition of the question about who imposes sanctions. The sanctions point is specific to ISO 37001 and reflects the seriousness with which the standard treats failure to operate the ABMS.

Examples of Anti-bribery Objectives

Useful objectives are specific. A target like "100 percent of staff in roles with greater than low bribery exposure to complete anti-bribery training within three months of appointment" is concrete and measurable. "Complete bribery due diligence on every new business associate before contract signature" is another. "Close out all internal audit findings within 60 days" works. Vague objectives like "improve anti-bribery culture" are difficult to evidence and rarely satisfy this clause.

Where Objectives Live in the Documentation

Objectives are usually captured on a company objectives form like F-Q11 Company Objectives and reviewed as part of management review. Where the organisation runs an integrated management system, anti-bribery objectives sit alongside quality, environmental, H&S and information security objectives. The integration helps because most operational areas - procurement, HR, finance - have objectives across multiple standards and tracking them in one place keeps the workload sensible.

The mistake to avoid is setting objectives that are really just the requirements of the standard restated. Maintain an anti-bribery policy is not an objective - it is something Clause 5.2 already requires. The objective should describe a measurable improvement or target that goes beyond simply meeting the clause.

I check that objectives are written down, measurable and being tracked. I look for evidence of progress against them in management review records. An organisation that sets objectives at the start of the year and never reviews them is missing the monitoring requirement of this clause.

Practical Compliance Guidance

Anti-bribery objectives are typically documented on a company objectives form and reviewed as part of management review. The integrated approach captures objectives across all relevant ISO standards together.

The documents below support planning and tracking of anti-bribery objectives.

alphaZ document How to use it
ISO 37001 Toolkit Complete documentation set for ISO 37001:2025 compliance, including the anti-bribery policy, the PP-1-19 Anti-bribery procedure, audit checklists, risk assessment and all supporting registers and forms.
F-Q11 Company Objectives Template for setting and tracking objectives across the management system, including anti-bribery objectives.
F-Q3 ABMS Management Review Captures performance against anti-bribery objectives at planned management review intervals.

Note - all the above files can be downloaded with an alphaZ subscription.

Frequently Asked Questions

There is no fixed number. A typical ABMS has between three and six anti-bribery objectives covering the highest-risk areas - training, due diligence, control effectiveness and incident response. More than ten and the focus is usually lost. Less than three and there may not be enough coverage of the bribery risk profile.
The clause requires objectives to be monitored and updated as appropriate. Annual review at management review is the most common pattern. Where objectives have shorter timeframes the review can be more frequent. The standard does not prescribe a fixed cycle.
For each objective, the standard wants documented planning - what is being done, what resources are needed, who is responsible, when it will be achieved, how the results will be evaluated and who imposes sanctions for non-achievement. A simple table covering all of these works.

UK Legislation

The following UK legislation often shapes anti-bribery objectives because the legal obligations need to be met regardless of the ABMS scope or maturity.

Further Resources

payment logos