Call us now: (603) 6280 6835
Reliable International Certification Body
  • Home
  • About
    • Quality Policy and Certification Policy
    • ISO Certification Process
    • Certificate Search
  • Standard
    • ISO 9001 Certification
    • ISO 22000 Certification
    • ISO 14001 Certification
    • ISO 45001 Certification
    • ISO 27001 Certification
    • ISO 37001 Certification
    • ISO 41001 Certification
    • HACCP Certification
    • GMP Certification
  • News & Resources
  • FAQ
  • Contact Us
  • Get a Quote
  • Search
  • Menu

ISO 37001 Requirements Malaysia

What Are the ISO 37001 Requirements and Where Should You Start?

ISO 37001 is the international standard for Anti-Bribery Management Systems (ABMS). It provides organisations with a structured framework to prevent, detect and respond to bribery risks through leadership commitment, risk assessment, due diligence, financial controls and continual improvement.

For organisations operating in Malaysia, ISO 37001 is particularly relevant because it supports the implementation of anti-bribery controls that may contribute to an organisation’s “adequate procedures” under Section 17A of the Malaysian Anti-Corruption Commission (MACC) Act 2009. While certification is voluntary, many organisations implement ISO 37001 to strengthen governance, improve stakeholder confidence and demonstrate their commitment to ethical business practices.

So, what are the actual ISO 37001 requirements? Here’s a simple breakdown.

ISO 37001 contains 10 clauses.

  • Clauses 1 to 3 explain the scope, references, and definitions.
  • Clauses 4 to 10 contain the actual certification requirements.

If you’re implementing ISO 37001 Certification Malaysia, these are the clauses you need to focus on.

Clause 4: Context of the Organization

Before setting up any controls, you need to understand where bribery risks could happen in your business. This clause requires you to:

  1. Identify internal and external issues.
  2. Understand the needs of interested parties.
  3. Define the scope of the Anti-Bribery Management System.
  4. Establish the processes needed to manage bribery risks.

Examples of Internal and External Issues

External issues: Industry corruption trends, regulatory requirements, government dealings, country risk

Internal issues: Company culture, sales incentives, procurement practices, existing compliance controls

Clause 5: Leadership

ISO 37001 places significant responsibility on top management. Leaders must show that anti-bribery is taken seriously, not just documented. They are required to:

  • Establish an anti-bribery policy
  • Communicate zero tolerance for bribery
  • Assign responsibilities
  • Provide resources
  • Support the compliance function

Anti-Bribery Compliance Function

The organization must appoint a person or team responsible for overseeing the anti-bribery system. This function should have independence, authority, and direct access to top management.

Clause 6: Planning

This clause focuses on bribery risk assessment and planning actions to address those risks. You need to identify bribery risks, evaluate likelihood and impact, then implement the control and set anti-bribery objectives.

Typical Anti-Bribery Objectives

Examples include:

  • 100% employee training completion
  • Due diligence on all high-risk third parties
  • Zero unresolved whistleblowing cases
  • Quarterly compliance reviews

Clause 7: Support

Your anti-bribery system won’t work unless people know what to do. This clause covers resources, people competency, awareness of the internal and external people on the anti-bribery, communication channel within the organization, and how the organization documents the information.

Employees in higher-risk roles like people in the sales team, procurement personnel, senior management, or finance staff should receive targeted training.

Clause 8: Operation

This is the heart of ISO 37001. It requires operational controls to prevent bribery in day-to-day activities.

Key Operational Controls:

Due Diligence

During certification audits, organisations are expected to demonstrate that appropriate due diligence has been performed before appointing high-risk business partners. This may include evaluating the background, ownership structure, reputation, sanctions exposure, conflicts of interest and previous compliance history of agents, consultants, distributors, contractors or joint venture partners. The level of due diligence should be proportionate to the bribery risk involved.

Financial Controls

Examples include:

  • Approval limits
  • Segregation of duties
  • Expense verification

Non-Financial Controls

Examples include:

  • Tender controls
  • Procurement reviews
  • Contract approvals

Gifts, Hospitality, and Donations

The organization must control:

  • Gifts
  • Entertainment
  • Sponsorships
  • Political contributions
  • Charitable donations

Speak-Up Mechanisms

Employees and stakeholders must be able to report concerns confidentially.

Investigations

Suspected bribery cases must be investigated and documented.

Clause 9: Performance Evaluation

You need to regularly check whether the anti-bribery system is working. This includes:

  • Monitoring and measurement
  • Internal audits
  • Management reviews

The internal audit team periodically reviews whether controls are implemented effectively and conducts a management review meeting, which includes the top management, HOD, and internal audit team, to evaluate:

  • Audit findings
  • Incident trends
  • Risk changes
  • Improvement opportunities

Clause 10: Improvement

When issues are identified, the organization must:

  • Correct the problem
  • Investigate root causes
  • Implement corrective actions
  • Improve the system

The goal is continuous improvement, not just maintaining certification.

Mandatory ISO 37001 Documents

Document Purpose
Anti-bribery Policy Demonstrates leadership commitment and organisational expectations.
Risk Assessment Identifies bribery risks and determines appropriate controls.
Due Diligence Procedure & Records Shows evaluation of third parties before engagement.
Training Records Provides evidence that relevant personnel have received appropriate anti-bribery awareness.
Gift and Hospitality Register Monitors gifts, hospitality and benefits to reduce bribery risks.
Investigation Records Demonstrates that reported concerns are investigated consistently.
Internal audit reports &
Management review minutes
Ensure internal self-check before a 3rd party comes to audit

Who Should Implement ISO 37001?

ISO 37001 is suitable for organisations of any size or sector, particularly those exposed to bribery risks, including:

  • Construction companies
  • Engineering firms
  • Oil & gas companies
  • Government contractors
  • Property developers
  • Manufacturers
  • Financial institutions
  • Logistics companies
  • Healthcare organisations
  • Higher education institutions

ISO 37001 is not mandatory, but it provides a structured framework that may support an organisation’s anti-bribery programme and contribute to implementing “adequate procedures” under Section 17A. However, certification alone does not guarantee compliance with legal requirements or establish a statutory defence. Organisations remain responsible for implementing appropriate anti-bribery measures based on their own risks.

Common Findings During ISO 37001 Certification Audits

Certification audits frequently identify opportunities for improvement such as:

Leadership commitment

  • Anti-bribery policy not effectively communicated.
  • Top management involvement not adequately demonstrated.

Risk Assessment

  • Risk assessments too generic
  • Risks not updated when business activities change.

Due Diligence

  • Third-party assessments incomplete.
  • No documented approval before engagement.

Gifts and Hospitality

  • Registers not maintained.
  • Approval thresholds unclear.

Training

  • Only HR received training.
  • High-risk departments excluded.

Internal Audit

  • Anti-bribery controls not included in audit programme.

Corrective Action

  • Root causes not adequately analysed.

Frequently Asked Questions (FAQ)

What documents are required for ISO 37001?

Typical documented information includes:

  • Anti-bribery policy
  • Risk assessments
  • Due diligence records
  • Training records
  • Gift and hospitality register
  • Investigation reports
  • Internal audit reports
  • Management review records

The specific documentation depends on the organisation’s size, complexity and bribery risk profile.

What is the difference between ISO 37001 implementation and certification?

Implementation involves establishing and operating an Anti-Bribery Management System that meets ISO 37001 requirements. Certification is an independent assessment conducted by an accredited certification body to determine whether the system conforms to the standard.

How Long Does It Take to Implement ISO 37001?

Company Size Estimated Timeline
Small business 2–4 months
Medium-sized company 4–8 months
Large organization 6–12 months

The timeline depends on your existing controls and how committed management is.

Can ISO 37001 be integrated with ISO 9001?

Yes. ISO 37001 follows the Annex SL structure used by ISO 9001, ISO 14001, ISO 45001 and ISO 27001, making it suitable for integration into an Integrated Management System (IMS).

Is ISO 37001 Worth It?

For many businesses, absolutely. It helps you:

  • Reduce corruption risks
  • Strengthen compliance
  • Build trust with customers and regulators
  • Support Section 17A readiness
  • Protect your company’s reputation

And if you regularly deal with government contracts or international clients, certification can be a strong competitive advantage.

To know more about ISO 37001? Contact us now!

Related Posts:

ISO 37001 requirements for anti-bribery management system implementation

ISO 37001 Requirements Explained | Complete Guide for Malaysian Businesses

July 14, 2026
Read more
https://www.pearl-certification.com/wp-content/uploads/2026/07/young-businessman-working-from-his-office-counting-cash-money-scaled.jpg 1707 2560 siti siti https://www.pearl-certification.com/wp-content/uploads/2023/06/Pearl-Certification-logo-web-1.png siti siti2026-07-14 01:57:592026-07-23 07:44:29ISO 37001 Requirements Explained | Complete Guide for Malaysian Businesses
mechanical engineering electrical construction

ISO Certification for Engineering Industry

July 21, 2021
Read more
https://www.pearl-certification.com/wp-content/uploads/2021/07/engineering-mechanical-electrical-construction.jpg 801 1200 pearladmin https://www.pearl-certification.com/wp-content/uploads/2023/06/Pearl-Certification-logo-web-1.png pearladmin2021-07-21 13:25:192022-08-06 09:27:16ISO Certification for Engineering Industry
iso 9001 14001 45001 construction

ISO Certification for Construction Industry

April 20, 2021
Read more
https://www.pearl-certification.com/wp-content/uploads/2021/04/iso-construction.jpg 935 1400 pearladmin https://www.pearl-certification.com/wp-content/uploads/2023/06/Pearl-Certification-logo-web-1.png pearladmin2021-04-20 08:28:012022-08-06 09:56:13ISO Certification for Construction Industry
Sistem Pengurusan Berkualiti ISO 9001

Kepentingan ISO 9001 Terhadap Syarikat Pembinaan

March 14, 2021
Read more
https://www.pearl-certification.com/wp-content/uploads/2021/03/Sistem-Pengurusan-Berkualiti-ISO-9001.jpg 580 1500 pearladmin https://www.pearl-certification.com/wp-content/uploads/2023/06/Pearl-Certification-logo-web-1.png pearladmin2021-03-14 16:24:562026-01-16 03:46:16Kepentingan ISO 9001 Terhadap Syarikat Pembinaan
CIDB ISO 9001

ISO 9001 Requirement for CIDB

December 30, 2019
Read more
https://www.pearl-certification.com/wp-content/uploads/2019/12/CIDB-ISO-9001.jpg 730 1500 pearladmin https://www.pearl-certification.com/wp-content/uploads/2023/06/Pearl-Certification-logo-web-1.png pearladmin2019-12-30 05:36:482026-01-16 03:45:57ISO 9001 Requirement for CIDB
PreviousNext

Recent Posts

  • ISO 37001 Requirements Explained | Complete Guide for Malaysian Businesses
  • ISO Certification and ESG in Malaysia | How ISO Standards Support ESG
  • ISO 9001 for Hospital Organizations: Towards a More Quality and Competitive Healthcare System
  • How to Get HACCP Certification in Malaysia
  • How to Get ISO 14001 Certification in Malaysia
  • How to Get ISO 27001 Certification in Malaysia
  • How to Get ISO 45001 Certification in Malaysia
  • Comparison between ISO 14001:2026 & ISO 14001:2015
  • Revision of ISO 14001 to 2026

Pearl Certification Sdn Bhd (1311494-U)

ZP-02-11, Zest Point, Lebuhraya Bukit Jalil, 47180 Puchong, Selangor, Malaysia.

Email : info@pearl-certification.com

Tel : +603-6280 6835

Pearl ISO certification body DSM

Standards

  • ISO 9001 – Quality Management System
  • ISO 22000 – Food Safety Management System
  • ISO 45001 – Occupational Health and Safety Management System
  • ISO 14001 – Environmental Management System
  • ISO 27001 – Information Security Management System
  • GMP – Good Manufacturing Practices
  • HACCP – Hazard Analysis Critical Control Point
© Copyright - Pearl Certification Sdn Bhd | Privacy Policy
  • Facebook
  • Linkedin
  • Youtube
ISO Certification and ESG in Malaysia | How ISO Standards Support ESG iso certification and esg
Scroll to top

This is a notification that can be used for cookie consent or other important news. It also got a modal window now! Click "learn more" to see it!

OKLearn More

Cookie and Privacy Settings

How we use cookies

We may request cookies to be set on your device. We use cookies to let us know when you visit our websites, how you interact with us, to enrich your user experience, and to customize your relationship with our website.

Click on the different category headings to find out more. You can also change some of your preferences. Note that blocking some types of cookies may impact your experience on our websites and the services we are able to offer.

Essential Website Cookies

These cookies are strictly necessary to provide you with services available through our website and to use some of its features.

Because these cookies are strictly necessary to deliver the website, you cannot refuse them without impacting how our site functions. You can block or delete them by changing your browser settings and force blocking all cookies on this website.

Other external services

We also use different external services like Google Webfonts, Google Maps and external Video providers. Since these providers may collect personal data like your IP address we allow you to block them here. Please be aware that this might heavily reduce the functionality and appearance of our site. Changes will take effect once you reload the page.

Google Webfont Settings:

Google Map Settings:

Vimeo and Youtube video embeds:

Privacy Policy

You can read about our cookies and privacy settings in detail on our Privacy Policy Page.

Click to Chat
Click to Chat
Click to Chat
Click to Chat
Click to Chat