Documented Information for ISO 37001 Anti-Bribery
ISO 37001 Clause 7.5
What documents the ABMS must include, how they are created and updated, and how they are controlled.
ISO 37001 Clause 7.5 - Documented Information
Clause 7.5 has three parts. 7.5.1 covers general requirements. 7.5.2 covers the creation and update of documented information. 7.5.3 covers control of documented information.
ISO 37001 Clause 7.5.1 - General
The ABMS must include the documented information specifically required by ISO 37001:2025 plus any documented information the organisation determines is necessary for the effectiveness of the system. The standard explicitly requires documentation of the bribery risk assessment (Clause 4.5.4), the scope (Clause 4.3), the anti-bribery policy (Clause 5.2), competence evidence (Clause 7.2.1), training records (Clause 7.3), the awareness programme (Clause 7.3.1), audit programme records (Clause 9.2), management review results (Clause 9.3) and non-conformity and corrective action records (Clause 10.2). Other documents are at the organisation discretion.
ISO 37001 Clause 7.5.2 - Creating and Updating
When creating or updating documented information, the organisation must address identification and description (such as title, date, author or reference number), format and media (paper or electronic, language, software version) and approval and review for suitability.
Note - the clause uses the word "such as" before listing examples like title, date, author and reference number. None of those individual items are individually required by the standard. The clause requires appropriate identification and description - the specific format is determined by the organisation.
ISO 37001 Clause 7.5.3 - Control of Documented Information
Documented information must be controlled to be available and suitable for use when needed and protected from improper use, loss of confidentiality and loss of integrity. The organisation must address distribution, access, retrieval and use, storage and preservation including legibility, control of changes including version control, and retention and disposition. Documented information of external origin that the organisation determines is necessary for the ABMS must be identified as appropriate and controlled.
This is the document control clause familiar from every other ISO management system. Anti-bribery does not need a different document control approach to quality, environmental or information security. The integrated approach lets one document control system serve all the standards in scope.
The document register and the anti-bribery procedure together cover most of what 7.5 requires. The register tracks every controlled document with its version and review date. The procedure sets out the rules for creating, approving and changing documents. An audit checklist based on the standard helps confirm that all the required documented information is actually in place.
I look for control evidence - version numbers, approval dates, owners. I check that documents I see in operation match the version on the register. And I check that documented information specifically required by the standard - bribery risk assessment, audit records, management review records - is actually present and dated within sensible review intervals.
Practical Compliance Guidance
ABMS documents are tracked through a document register that records every controlled document with its current version, owner and review date. The same register typically serves all the standards in scope where the IMS is integrated.
The documents below support the documented information requirements of Clause 7.5.
| alphaZ document | How to use it |
|---|---|
| ISO 37001 Toolkit | Complete documentation set for ISO 37001:2025 compliance, including the anti-bribery policy, the PP-1-19 Anti-bribery procedure, audit checklists, risk assessment and all supporting registers and anti-bribery forms. |
| F-IMS20 Document Register | Master register of all controlled documents within the management system, including version, owner and review date. |
| PP-1-19 Anti-bribery Procedure | Sets out the central rules for the ABMS including how documents are created, approved and updated. |
| ISO 37001:2025 Correlation | Maps each clause of ISO 37001:2025 to the alphaZ documents that satisfy the documented information requirements. |
Note - all the above files can be downloaded with an alphaZ subscription.
Frequently Asked Questions
UK Legislation
The following UK legislation creates legal retention or evidential expectations that interact with ABMS document control.
