ISO 37001
Definition
ISO 37001
ISO 37001 is the standard for anti-bribery management systems, which set requirements for preventing and detecting bribery. Its outsourcing weight sits in third-party due diligence, because agents and intermediaries are where most of the real exposure actually lives.
Bribery risk in outsourced operations rarely involves your own staff.
It involves the local agent who handles permits, the intermediary who secures a licence, the subcontractor who deals with customs — these are the people acting in your name in places where you have no presence.
United States law has long recognised this. The Foreign Corrupt Practices Act reaches payments made to any person while knowing that all or a portion of such money or thing of value will be offered, given, or promised, directly or indirectly, to any foreign official.
Key takeaways
- ISO 37001:2025 was published in February 2025, replacing the 2016 first edition.
- The 2025 revision strengthens third-party due diligence requirements.
- The anti-bribery compliance function was renamed the anti-bribery function.
- Certification does not create a legal defence, though it evidences reasonable procedures.
How it works
ISO 37001 requires an organisation to run a management system aimed at preventing, detecting and responding to bribery. It covers policy, leadership, risk assessment, due diligence, controls, reporting and investigation.
The 2025 edition is the current one. DNV records that ISO 37001:2025 was published on 3 February 2025, replacing ISO 37001:2016, with a transition period anticipated at two years.
One renaming matters because it changes what you ask for. DNV notes that the term anti-bribery compliance function has been replaced with anti-bribery function in ISO 37001:2025, with a clearer description of its responsibilities and operational independence.
Operational independence is the substantive change hiding in that renaming. A function that reports to the people whose deals it reviews is not independent — whatever the organisation chart says.
Due diligence is where the standard meets outsourcing. It asks an organisation to assess the bribery risk of its transactions, projects and business associates, and to act proportionately on what it finds.
| Third party | Typical bribery exposure |
|---|---|
| Local agent or fixer | Permits, inspections, licence renewals |
| Customs broker | Clearance speed and classification |
| Recruitment intermediary | Visa and work permit processing |
| Joint venture partner | Government contract access |
| Subcontracted logistics | Port and road-checkpoint payments |
None of those people appear on your payroll — all of them can create liability for you, which is the reason the due diligence requirement exists.
Examples
Anti-bribery controls are tested at the edges of an organisation rather than at its centre, which is precisely where outsourcing operates. Each example here began as a buyer question nobody on the sales side expected.
A company entering a new market appoints a local agent to handle licensing. That relationship is the highest bribery risk in the whole operation and frequently the least documented.
A buyer requires certification from its outsourced logistics provider, having concluded that checkpoint payments were a real exposure. The requirement sits alongside its broader compliance outsourcing programme.
A firm’s certified system flags an intermediary with undisclosed government connections. Due diligence produced the finding, and the contract was restructured before the relationship began.
A group treats the standard as one strand of its corporate social responsibility (CSR) reporting, which is defensible presentationally and tells investors very little about actual controls.
Related terms
Anti-bribery work overlaps with governance reporting, regulatory services and the roles that run them, and the categories blur. Every term below is given one reading, and the adjacent reading belongs elsewhere.
- Compliance outsourcing: buying regulatory capability as a service, rather than certifying your own system.
- Corporate social responsibility (CSR): voluntary commitments with no audit standard behind them.
- ESG (environmental, social and governance): an investor reporting frame in which anti-bribery is one governance input.
- Risk outsourcing: transferring exposure commercially, which bribery liability resists.
- Compliance officer: the role running the function, now titled differently under the 2025 edition.
- ISO certification: the general audit mechanism behind ISO management standards.
- Vendor management outsourcing: running supplier assurance, where due diligence is actually performed.
FAQ
Which edition is current?
ISO 37001:2025, published in February 2025. It replaced the 2016 first edition, with a transition period anticipated at around two years.
Does certification protect against prosecution?
No. It can evidence that reasonable procedures were in place, which matters in some jurisdictions, but it is not a defence in itself.
What changed in the 2025 edition?
Third-party due diligence requirements were strengthened, and the anti-bribery compliance function was renamed the anti-bribery function with clearer operational independence.
Why does it matter for outsourcing specifically?
Because bribery exposure concentrates in agents, intermediaries and subcontractors acting on your behalf in markets where you have no direct presence.
Is it relevant to office-based BPO work?
Less than to logistics or construction, but not zero. Visa processing, permits and local licensing all involve government touchpoints.
Who should the anti-bribery function report to?
Somewhere independent of the commercial teams whose transactions it reviews. Operational independence is explicit in the current edition.
Review source partners in the Outsource Accelerator hubs directory and check the due diligence reaches your actual intermediaries.







Independent




