Internal Audit for ISO 37001 Anti-Bribery
ISO 37001 Clause 9.2
Internal audit - planned audits checking conformance and implementation, with auditors selected for objectivity and impartiality.
ISO 37001 Clause 9.2 - Internal Audit
Clause 9.2 is the most prescriptive performance evaluation clause. It sets out four sub-clauses covering the audit purpose, the audit programme, the proportionality of audits, and the requirement for objectivity and impartiality of the auditors.
9.2.1 - Purpose of Internal Audit
The clause requires internal audits at planned intervals to provide information on whether the ABMS conforms to the organisation's own requirements for the system, conforms to ISO 37001:2025, and is effectively implemented and maintained. All three are tested by every audit cycle - the audits are not just paperwork checks.
9.2.2 - The Audit Programme
The audit programme covers frequency, methods, responsibilities, planning requirements and reporting. The programme has to consider the importance of the processes concerned and the results of previous audits - so areas with higher bribery risk and areas where past audits identified issues get audited more often. Each audit defines its objectives, criteria and scope. Auditors are selected for objectivity and impartiality. Results are reported to the relevant managers, the anti-bribery function, top management and (where it exists) the governing body. Documented evidence is retained.
9.2.3 - Audits Reasonable, Proportionate and Risk-based
The audits are reasonable, proportionate and risk-based - they cover bribery, violations of the policy or ABMS, business associate non-conformity with the requirements imposed on them, and weaknesses or improvement opportunities. The risk-based principle means audit effort is concentrated where the bribery risk is greatest.
9.2.4 - Objectivity and Impartiality
The auditors have to be objective and impartial - they cannot audit their own area of responsibility. The clause lists acceptable options - an independent function or person, the anti-bribery function (except for the function's own area), personnel from another department, an external third party, or a group drawing on any of the above. For smaller organisations external support is often the practical answer.
The audit programme connects directly to the bribery risk assessment. If the risk assessment rates a particular activity as significant, the audit programme audits that activity. The proportionality principle stops audit becoming a tickbox exercise where every clause gets the same treatment regardless of risk - which would dilute the audit effort where it actually matters.
The objectivity rule is the one that catches small organisations. The person who runs the procurement process cannot be the person who audits whether procurement is meeting the anti-bribery controls. There is usually a way around it - someone from a different department, swap-audit arrangements with another company, or external support - but it has to be planned, not improvised.
I look at the audit programme, the schedule on ER11, the individual audit reports, the checklists used, and the evidence of follow-up. I want to see audits that actually tested the controls in place rather than just confirmed documentation existed. The full-clause checklist for ISO 37001 is the strongest evidence the audit covered the standard properly.
Practical Compliance Guidance
Internal audit is governed by the audit programme on ER11, conducted using F-Q2 and the A-C 37001 full-clause checklist, with findings logged on ER1 and improvements tracked using F-Q16.
The documents below support the internal audit activities required by Clause 9.2.
| alphaZ document | How to use it |
|---|---|
| ISO 37001 Toolkit | Complete documentation set for ISO 37001:2025 compliance, including the anti-bribery policy, the PP-1-19 Anti-bribery procedure, audit checklists, risk assessment and all supporting registers and anti-bribery forms. |
| ER11 Audit Schedule | Annual audit schedule covering the ABMS - frequency, scope, auditor and target completion. |
| F-Q2 Audit Checklist | General internal audit checklist used during ABMS internal audits. |
| A-C Management System ABMS Audit Checklist | Full-clause ISO 37001:2025 audit checklist for full-system ABMS audits. |
| ER1 Issues and Actions Register | Logs audit findings and tracks corrective actions to closure. |
| F-Q16 Improvement Request | Used to record and track improvement actions arising from audit findings. |
Note - all the above files can be downloaded with an alphaZ subscription.
Frequently Asked Questions
UK Legislation
Internal audit supports demonstration of due diligence in respect of bribery prevention - relevant to the corporate offences in UK legislation.
