Certification of Anti-bribery Management Systems According to ISO 37001
Your Expert for Questions
Combating bribery demonstrates your elevated level of commitment
We live in a complex and interconnected world today, where high standards are set for compliance. Protecting integrity and reputation therefore presents a major challenge for companies. An anti-bribery management system (ABMS) helps demonstrate high standards and the tools you have implemented to prevent bribery. Combating bribery begins with your commitment. It ensures that risks are identified, assessed, and minimized. It is not possible to eliminate the risk of bribery, and no anti-bribery management system is capable of completely preventing and detecting bribery. However, by implementing an appropriate and proportionate anti-bribery management system, you can demonstrate that you are significantly reducing the risk of bribery in your Company. This strengthens the trust of customers and business partners and fulfills legal requirements.
Companies can demonstrate their responsible approach to preventing, detecting, and combatting bribery, for example, through independent certification of their anti-bribery management system (ABMS). The ABMS is audited according to the internationally recognized standard ISO 37001 and certified for compliance with the criteria for standard conformity using a sample procedure.
ABMS Certification: Key Benefits briefly
Improving Anti-Bribery
Compliance ISO 37001, an internationally recognized anti-bribery standard, provides a comprehensive framework for identifying, assessing, and managing risks and opportunities. Implementing this standard helps you continuously improve your compliance processes and procedures, as well as identifying and addressing weaknesses.
Increase trust and credibility
With ISO 37001 certification, you can increase the trust placed in you by customers, partners and stakeholders by demonstrating that you have taken appropriate measures to comply with laws and requirements for conducting yourself with integrity.
Competitive advantage
Certification according to ISO 37001 can be a competitive advantage for a company and help in acquiring new customers and business partners as well as in tenders.
Quick Facts About ABMS Certification
Normative requirements for an ABMS
The requirements for certification of an anti-bribery management system (ABMS) are defined in the ISO 37001:2018 standard. The standard consists of the following sections:
- Scope
- Normative references
- Terms
- Context of organization
- Leadership
- Planning
- Support
- Operations
- Evaluation of performance
- Improvement
These sections correspond to the “high-level structure” and are uniform within the currently valid management systems to enable different management systems to be integrated within the company. To be certified according to ISO 37001, a company must demonstrate that it meets all the requirements of the standard. This is done through an independent review of the documentation and an on-site audit of the implementation, adequacy, and effectiveness of the ABMS.
Challenges for companies seeking ISO 37001 certification
ISO 37001 certification is a demanding task for every company, as it is a comprehensive anti-bribery management system (ABMS) that ensures that bribery is prevented, identified, and combated within the company using appropriate measures. Some of the specific challenges that companies must address when obtaining ISO 37001 certification are:
- Comprehensive documentation: The company must create and maintain comprehensive documentation of all relevant bribery risks.
- Implementation of anti-bribery measures: The company must implement a comprehensive management system and implement security measures within its operations, as well as through controlled organizations and business partners with a commitment to combating bribery.
- Resources: The company must provide sufficient resources to effectively operate and maintain the ABMS, including financial resources, employee training, and technical infrastructure. Leadership and responsibility lie with the highest body and top management to define the anti-bribery policy, roles, responsibilities, and authorities within the organization.
- Compliance: The company must ensure that the task of combating bribery is assigned to one or more individuals and that these individuals have the appropriate competence, status, responsibility, and independence to fulfill the anti-bribery task.
- Internal audits and reviews: The company must conduct regular internal audits and reviews to ensure that the ABMS is appropriate and that all risk-mitigating measures (such as control procedures) are correctly implemented. Measures to address risks and opportunities are an important component for internal improvement opportunities.
- Management reviews: Both the company management and, if applicable, the supervisory board or the shareholders’ meeting must conduct and document regular reviews of ABMS.
These challenges require a comprehensive analysis of business processes and continuous improvement of the anti-bribery management system to ensure that the company is always up to date and that its systems and processes are continuously improved.
Important documents for ABMS
Various documents are required for ABMS certification according to ISO 37001. Here are some of the mandatory documents:
- Anti-bribery policy: This document describes the objectives and principles for combating bribery in your company, particularly through the responsibility of company management.
- Risk assessment and control plan: This involves identifying and assessing your bribery risks and describing your risk assessment and control processes. It should include how you identify threats, assess risks, plan and implement control measures, and measure the effectiveness of these measures.
- Measures for addressing risks and opportunities: Documentation of the protective measures taken to address the risks identified in the risk assessment.
- Training documentation: Documentation of the training measures that employees have undergone regarding anti-bribery. It is important that relevant personnel, business partners, and third parties are aware of how to deal with bribery risks.
- Internal audits: You must conduct internal audits at scheduled intervals (at least once a year) to obtain information on whether the anti-bribery management system is properly implemented into the company’s processes and procedures. Documentation of audit programs, audit reports, audit steps, corrective actions, traceability, and audit evidence should be collected.
- Process descriptions and records: Documentation of the processes, monitoring measures, and other records that support the operation of the anti-bribery management system and the monitoring of the fight against bribery must be documented.
- Management reviews: Top management, which is usually the senior management, should regularly evaluate the effectiveness of your anti-bribery management system and make appropriate decisions. Documentation of evaluations, feedback, and decisions must be collected. The relevant aspects for the management review are clearly defined in the ISO 37001 standard.
These documents are just a few examples of the type of documentation required for ISO 37001 certification. The exact documents required may vary depending on the company’s situation.
The Path to Your ABMS Certification
The Certification Cycle
Your company should prepare appropriately for ABMS certification so that it can be completed with minimal cost and time.
Key prerequisites for certification of the anti-bribery management system are:
- ABMS compliance with the requirements of ISO 37001
- A reasonable understanding of bribery risks among all stakeholders
- The company’s confidence that the certification process can be completed in a timely and cost-effective manner.
ISO 37001 certification follows a standardized process, which looks like this:
Implementation Phase
In this phase, you must first ensure that you meet all the requirements for certification. This includes having implemented an anti-bribery management system (ABMS) that meets the requirements of the standard. You should also have conducted a risk analysis and documented how you deal with risks that could affect confidentiality, integrity, or availability of information.
Pre-audits (dry runs) have proven to be a useful tool in preparing for certification. During a pre-audit, an external service provider can review and assess the implementation of your company’s existing requirements and the management system under consideration at your headquarters and locations regarding the desired ISO 37001 certification, as well as identify any weaknesses in compliance with the standard. While specific areas will be examined, a comprehensive audit comparable to an initial certification will not be conducted.
Important: PwC Certification Services GmbH itself does not offer any consulting or pre-audits for the implementation of your management system.
Stage 1 Audit – Readiness Assessment
If you are ready, you can apply for certification to us as an accredited certification body. During the Stage 1 audit, an auditor approved by us will check (at least partially on-site) whether your company is fundamentally ready for the Stage 2 audit. This will include, for example, checking whether your ABMS documentation meets the requirements of ISO 37001.
If weaknesses were identified during the audit, they must be analyzed and remedied with appropriate corrective measures. You usually have a specific deadline within which you must implement these.
It is reasonable to plan between 14 and a maximum of 90 calendar days between Stage 1 and Stage 2 to be able to implement an appropriate audit process.
Stage 2 Audit – Initial Certification Audit
Once you have successfully implemented the corrective actions, the Stage 2 audit will be conducted. This audit will take place on-site, and individual processes or locations can be converted into a virtual audit if necessary – based on risk analysis and case-by-case decisions. In addition to reviewing the documentation, the auditor will conduct interviews with employees to review the processes and procedures of the implemented ABMS in accordance with the requirements of ISO 37001.
Assessment and certification decision
The certification body assesses and decides the standard-compliant implementation of the requirements and, if applicable, on corrective actions resulting from the audit. Only when all requirements of the standard have been met (elimination of major nonconformities, positive assessment of the action plan and immediate actions, and corrective actions for minor nonconformities) will you receive the certificate, which is valid for three years.
Surveillance audits:
To review the effectiveness of the ABMS and ensure that it continues to meet the requirements of the standard, surveillance audits are conducted regularly. These usually take place annually. The first surveillance audit after initial certification must be conducted within 12 months of the certification decision. The optimal time for scheduling the surveillance audit is the day and month of the certificate expiry date minus three (3) months. A time window of minus (-) three (3) months and plus (+) three months can be chosen flexibly around this date in order to ensure the size of your company, the scope, the complexity of your management system with your products, services and processes as well as your stated level of effectiveness of your management system – taking into account factors such as the time of year and the possibility of certification due to, for example, temporary construction sites or activities.
Re-certification
In the third year of certification, a re-certification audit is required. This audit covers the same topics as the initial certification, but with a reduced time limit, as your management system has already been audited and maintained. Key factors for re-certification are continuous improvement and the effectiveness of corrective actions from previous audits. The re-certification audit must be fully completed prior to the certificate audit; otherwise, an initial certification audit with Stages 1 and 2 will be required.
Our Expertise, Your Advantage
PwC Certification Services as an accredited certification body
Certifications of anti-bribery management systems may only be conducted by certification bodies accredited by the national accreditation body according to DIN EN ISO/IEC 17021-1. PwC Certification Services is one such certification body accredited by the DAkkS (German Accreditation Body) (accreditation number: D-ZM-16030-02-01) and is therefore your competent certification partner for standard-compliant verification of your ABMS by an independent and neutral third party.
Documents available for download
- ISO 37001 application form (PDF, xx MB)

Valid Certificates
Our certificates inspire trust! They confirm our clients’ compliance with the underlying norms and standards, thus creating added value for marketing their services in the global marketplace. Certification grants the right to refer to the certificates we have been awarded according to established rules. This helps our clients and protects the PwC brand.
More about our valid certificates



