https://www.pearl-certification.com/wp-content/uploads/2026/07/young-businessman-working-from-his-office-counting-cash-money-scaled.jpg
1707
2560
siti siti
https://www.pearl-certification.com/wp-content/uploads/2023/06/Pearl-Certification-logo-web-1.png
siti siti2026-07-14 01:57:592026-07-23 07:44:29ISO 37001 Requirements Explained | Complete Guide for Malaysian BusinessesISO 37001 Requirements Malaysia
What Are the ISO 37001 Requirements and Where Should You Start?
ISO 37001 is the international standard for Anti-Bribery Management Systems (ABMS). It provides organisations with a structured framework to prevent, detect and respond to bribery risks through leadership commitment, risk assessment, due diligence, financial controls and continual improvement.
For organisations operating in Malaysia, ISO 37001 is particularly relevant because it supports the implementation of anti-bribery controls that may contribute to an organisation’s “adequate procedures” under Section 17A of the Malaysian Anti-Corruption Commission (MACC) Act 2009. While certification is voluntary, many organisations implement ISO 37001 to strengthen governance, improve stakeholder confidence and demonstrate their commitment to ethical business practices.
So, what are the actual ISO 37001 requirements? Here’s a simple breakdown.
ISO 37001 contains 10 clauses.
- Clauses 1 to 3 explain the scope, references, and definitions.
- Clauses 4 to 10 contain the actual certification requirements.
If you’re implementing ISO 37001 Certification Malaysia, these are the clauses you need to focus on.
Clause 4: Context of the Organization
Before setting up any controls, you need to understand where bribery risks could happen in your business. This clause requires you to:
- Identify internal and external issues.
- Understand the needs of interested parties.
- Define the scope of the Anti-Bribery Management System.
- Establish the processes needed to manage bribery risks.
Examples of Internal and External Issues
External issues: Industry corruption trends, regulatory requirements, government dealings, country risk
Internal issues: Company culture, sales incentives, procurement practices, existing compliance controls
Clause 5: Leadership
ISO 37001 places significant responsibility on top management. Leaders must show that anti-bribery is taken seriously, not just documented. They are required to:
- Establish an anti-bribery policy
- Communicate zero tolerance for bribery
- Assign responsibilities
- Provide resources
- Support the compliance function
Anti-Bribery Compliance Function
The organization must appoint a person or team responsible for overseeing the anti-bribery system. This function should have independence, authority, and direct access to top management.
Clause 6: Planning
This clause focuses on bribery risk assessment and planning actions to address those risks. You need to identify bribery risks, evaluate likelihood and impact, then implement the control and set anti-bribery objectives.
Typical Anti-Bribery Objectives
Examples include:
- 100% employee training completion
- Due diligence on all high-risk third parties
- Zero unresolved whistleblowing cases
- Quarterly compliance reviews
Clause 7: Support
Your anti-bribery system won’t work unless people know what to do. This clause covers resources, people competency, awareness of the internal and external people on the anti-bribery, communication channel within the organization, and how the organization documents the information.
Employees in higher-risk roles like people in the sales team, procurement personnel, senior management, or finance staff should receive targeted training.
Clause 8: Operation
This is the heart of ISO 37001. It requires operational controls to prevent bribery in day-to-day activities.
Key Operational Controls:
Due Diligence
During certification audits, organisations are expected to demonstrate that appropriate due diligence has been performed before appointing high-risk business partners. This may include evaluating the background, ownership structure, reputation, sanctions exposure, conflicts of interest and previous compliance history of agents, consultants, distributors, contractors or joint venture partners. The level of due diligence should be proportionate to the bribery risk involved.
Financial Controls
Examples include:
- Approval limits
- Segregation of duties
- Expense verification
Non-Financial Controls
Examples include:
- Tender controls
- Procurement reviews
- Contract approvals
Gifts, Hospitality, and Donations
The organization must control:
- Gifts
- Entertainment
- Sponsorships
- Political contributions
- Charitable donations
Speak-Up Mechanisms
Employees and stakeholders must be able to report concerns confidentially.
Investigations
Suspected bribery cases must be investigated and documented.
Clause 9: Performance Evaluation
You need to regularly check whether the anti-bribery system is working. This includes:
- Monitoring and measurement
- Internal audits
- Management reviews
The internal audit team periodically reviews whether controls are implemented effectively and conducts a management review meeting, which includes the top management, HOD, and internal audit team, to evaluate:
- Audit findings
- Incident trends
- Risk changes
- Improvement opportunities
Clause 10: Improvement
When issues are identified, the organization must:
- Correct the problem
- Investigate root causes
- Implement corrective actions
- Improve the system
The goal is continuous improvement, not just maintaining certification.
Mandatory ISO 37001 Documents
| Document | Purpose |
| Anti-bribery Policy | Demonstrates leadership commitment and organisational expectations. |
| Risk Assessment | Identifies bribery risks and determines appropriate controls. |
| Due Diligence Procedure & Records | Shows evaluation of third parties before engagement. |
| Training Records | Provides evidence that relevant personnel have received appropriate anti-bribery awareness. |
| Gift and Hospitality Register | Monitors gifts, hospitality and benefits to reduce bribery risks. |
| Investigation Records | Demonstrates that reported concerns are investigated consistently. |
| Internal audit reports & Management review minutes |
Ensure internal self-check before a 3rd party comes to audit |
Who Should Implement ISO 37001?
ISO 37001 is suitable for organisations of any size or sector, particularly those exposed to bribery risks, including:
- Construction companies
- Engineering firms
- Oil & gas companies
- Government contractors
- Property developers
- Manufacturers
- Financial institutions
- Logistics companies
- Healthcare organisations
- Higher education institutions
ISO 37001 is not mandatory, but it provides a structured framework that may support an organisation’s anti-bribery programme and contribute to implementing “adequate procedures” under Section 17A. However, certification alone does not guarantee compliance with legal requirements or establish a statutory defence. Organisations remain responsible for implementing appropriate anti-bribery measures based on their own risks.
Common Findings During ISO 37001 Certification Audits
Certification audits frequently identify opportunities for improvement such as:
Leadership commitment
- Anti-bribery policy not effectively communicated.
- Top management involvement not adequately demonstrated.
Risk Assessment
- Risk assessments too generic
- Risks not updated when business activities change.
Due Diligence
- Third-party assessments incomplete.
- No documented approval before engagement.
Gifts and Hospitality
- Registers not maintained.
- Approval thresholds unclear.
Training
- Only HR received training.
- High-risk departments excluded.
Internal Audit
- Anti-bribery controls not included in audit programme.
Corrective Action
- Root causes not adequately analysed.
Frequently Asked Questions (FAQ)
What documents are required for ISO 37001?
Typical documented information includes:
- Anti-bribery policy
- Risk assessments
- Due diligence records
- Training records
- Gift and hospitality register
- Investigation reports
- Internal audit reports
- Management review records
The specific documentation depends on the organisation’s size, complexity and bribery risk profile.
What is the difference between ISO 37001 implementation and certification?
Implementation involves establishing and operating an Anti-Bribery Management System that meets ISO 37001 requirements. Certification is an independent assessment conducted by an accredited certification body to determine whether the system conforms to the standard.
How Long Does It Take to Implement ISO 37001?
| Company Size | Estimated Timeline |
| Small business | 2–4 months |
| Medium-sized company | 4–8 months |
| Large organization | 6–12 months |
The timeline depends on your existing controls and how committed management is.
Is ISO 37001 Worth It?
For many businesses, absolutely. It helps you:
- Reduce corruption risks
- Strengthen compliance
- Build trust with customers and regulators
- Support Section 17A readiness
- Protect your company’s reputation
And if you regularly deal with government contracts or international clients, certification can be a strong competitive advantage.
Related Posts:
https://www.pearl-certification.com/wp-content/uploads/2026/07/young-businessman-working-from-his-office-counting-cash-money-scaled.jpg
1707
2560
siti siti
https://www.pearl-certification.com/wp-content/uploads/2023/06/Pearl-Certification-logo-web-1.png
siti siti2026-07-14 01:57:592026-07-23 07:44:29ISO 37001 Requirements Explained | Complete Guide for Malaysian Businesses
https://www.pearl-certification.com/wp-content/uploads/2021/07/engineering-mechanical-electrical-construction.jpg
801
1200
pearladmin
https://www.pearl-certification.com/wp-content/uploads/2023/06/Pearl-Certification-logo-web-1.png
pearladmin2021-07-21 13:25:192022-08-06 09:27:16ISO Certification for Engineering Industry
https://www.pearl-certification.com/wp-content/uploads/2021/04/iso-construction.jpg
935
1400
pearladmin
https://www.pearl-certification.com/wp-content/uploads/2023/06/Pearl-Certification-logo-web-1.png
pearladmin2021-04-20 08:28:012022-08-06 09:56:13ISO Certification for Construction Industry
https://www.pearl-certification.com/wp-content/uploads/2021/03/Sistem-Pengurusan-Berkualiti-ISO-9001.jpg
580
1500
pearladmin
https://www.pearl-certification.com/wp-content/uploads/2023/06/Pearl-Certification-logo-web-1.png
pearladmin2021-03-14 16:24:562026-01-16 03:46:16Kepentingan ISO 9001 Terhadap Syarikat PembinaanPearl Certification Sdn Bhd (1311494-U)
ZP-02-11, Zest Point, Lebuhraya Bukit Jalil, 47180 Puchong, Selangor, Malaysia.
Email : info@pearl-certification.com
Tel : +603-6280 6835

Standards
- ISO 9001 – Quality Management System
- ISO 22000 – Food Safety Management System
- ISO 45001 – Occupational Health and Safety Management System
- ISO 14001 – Environmental Management System
- ISO 27001 – Information Security Management System
- GMP – Good Manufacturing Practices
- HACCP – Hazard Analysis Critical Control Point








