Can ISO 37001 Help Your Company Comply with Section 17A of the MACC Act?
If you run a business in Malaysia, Section 17A is something you can’t ignore. It makes companies responsible if employees, agents, or partners commit bribery, even if management didn’t know. That’s where ISO 37001 helps. It gives your company a clear system to prevent bribery and show you’ve taken proper steps to control the risk.
So yes, ISO 37001 can support Section 17A compliance.
What Is Section 17A of the MACC Act?
Section 17A of the Malaysian Anti-Corruption Commission (SPRM) Act introduced corporate liability for corruption.
This means a company can be prosecuted if a person associated with the organization gives or offers a bribe to obtain or retain business or secure an advantage.
Associated persons may include:
- Employees
- Directors
- Agents
- Distributors
- Contractors
- Joint venture partners
The penalties are serious:
- A fine of not less than 10 times the value of the gratification, or RM1 million, whichever is higher
- Imprisonment of up to 20 years
- Possible liability for directors and senior management
That’s why companies are paying much closer attention to anti-bribery controls.
Does Section 17A Require ISO 37001 Certification?
No. Section 17A does not require companies to be certified to ISO 37001.
However, the law allows organizations to defend themselves if they can prove they had adequate procedures in place to prevent corruption. ISO 37001 is widely recognized as one of the strongest frameworks for demonstrating those procedures.
So while certification is voluntary, it can significantly strengthen your compliance position.
The T.R.U.S.T. Principles and ISO 37001
The government’s Guidelines on Adequate Procedures are built around five principles:
T – Top Level Commitment
Senior management must lead by example.
R – Risk Assessment
The organization must identify corruption risks.
U – Undertake Control Measures
Controls and procedures must be implemented.
S – Systematic Review, Monitoring and Enforcement
The system must be monitored and enforced.
T – Training and Communication
Employees and stakeholders must be informed and trained.
These principles align closely with the requirements of ISO 37001.
How ISO 37001 Supports Section 17A Compliance
|
Section 17A Requirement |
How ISO 37001 Helps |
| Top-level commitment | Anti-bribery policy and leadership involvement. |
| Risk assessment | Formal bribery risk assessments. |
| Control measures | Due diligence, approvals, and financial controls. |
| Monitoring and review | Internal audits and management reviews. |
| Training and communication | Employee awareness and training programs. |
Real-World Example
Imagine your sales agent pays a bribe to secure a government contract.
Under Section 17A, your company may be liable even if management wasn’t directly involved.
If your organization can demonstrate that it:
- Conducted due diligence on the agent
- Included anti-bribery clauses in the contract
- Provided training
- Monitored activities
- Had reporting mechanisms in place
You’ll be in a much stronger position to show that adequate procedures existed. That is exactly what ISO 37001 is designed to document.
Common Misconceptions
“We’re a small company, so this doesn’t apply to us.”
Section 17A applies regardless of company size.
“We already have a code of conduct.”
A code of conduct is useful, but on its own, it usually isn’t enough.
“Certification guarantees legal protection.”
Certification helps, but it does not provide automatic immunity.
“This is only for large corporations.”
ISO 37001 can be scaled to fit SMEs as well.
Common Implementation Mistakes
Companies often struggle when they:
- Copy generic templates
- Perform superficial risk assessments
- Ignore third-party due diligence
- Provide minimal training
- Keep poor records
- Treat certification as a box-ticking exercise
ISO 37001 works best when it reflects your actual business risks.
Is ISO 37001 Worth It?
For many Malaysian companies, yes. If your business deals with regulators, tenders, agents, or higher-risk transactions, ISO 37001 can strengthen governance and support your Section 17A readiness. It also provides reassurance to customers, investors, and business partners.
Related Posts:
https://www.pearl-certification.com/wp-content/uploads/2026/08/business-man-show-money-bank-note-make-financial-plan-invite-people-sell-buy-house-car-monetary-properties-loan-credit-insurance-concept-scaled.jpg
1709
2560
aisyah
https://www.pearl-certification.com/wp-content/uploads/2023/06/Pearl-Certification-logo-web-1.png
aisyah2026-08-21 02:29:222026-08-21 02:30:28ISO 41001 for Property Management
https://www.pearl-certification.com/wp-content/uploads/2026/08/closeup-shot-metal-handcuffs-dollars-scaled.jpg
1707
2560
aisyah
https://www.pearl-certification.com/wp-content/uploads/2023/06/Pearl-Certification-logo-web-1.png
aisyah2026-08-21 02:02:572026-08-21 02:02:57ISO 37001 and Section 17A MACC Act – Complete Guide for Malaysian Companies
https://www.pearl-certification.com/wp-content/uploads/2026/08/developer-identifying-server-issues-scaled.jpg
1440
2560
aisyah
https://www.pearl-certification.com/wp-content/uploads/2023/06/Pearl-Certification-logo-web-1.png
aisyah2026-08-18 07:07:082026-08-20 01:39:19ISO 27001 certification for data centres
https://www.pearl-certification.com/wp-content/uploads/2026/08/standard-quality-control-collage-concept-scaled.jpg
1440
2560
aisyah
https://www.pearl-certification.com/wp-content/uploads/2023/06/Pearl-Certification-logo-web-1.png
aisyah2026-08-18 02:47:422026-08-20 01:40:50ISO 27001 Certification for SMEs: Secure Your Business with Confidence
https://www.pearl-certification.com/wp-content/uploads/2026/08/person-working-html-computer-scaled.jpg
1707
2560
aisyah
https://www.pearl-certification.com/wp-content/uploads/2023/06/Pearl-Certification-logo-web-1.png
aisyah2026-08-05 01:51:512026-08-20 01:42:50ISO 27001 certification for software companies
https://www.pearl-certification.com/wp-content/uploads/2026/08/corporate-businessmen-working-tablet-office-scaled.jpg
1440
2560
aisyah
https://www.pearl-certification.com/wp-content/uploads/2023/06/Pearl-Certification-logo-web-1.png
aisyah2026-08-04 08:54:452026-08-04 08:54:45ISO 9001:2026 Transition Guide – Timeline, Key Changes & How to Prepare
https://www.pearl-certification.com/wp-content/uploads/2026/07/young-businessman-working-from-his-office-counting-cash-money-scaled.jpg
1707
2560
aisyah
https://www.pearl-certification.com/wp-content/uploads/2023/06/Pearl-Certification-logo-web-1.png
aisyah2026-07-14 01:57:592026-07-23 07:44:29ISO 37001 Requirements Explained | Complete Guide for Malaysian BusinessesPearl Certification Sdn Bhd (1311494-U)
ZP-02-11, Zest Point, Lebuhraya Bukit Jalil, 47180 Puchong, Selangor, Malaysia.
Email : info@pearl-certification.com
Tel : +603-6280 6835

Standards
- ISO 9001 – Quality Management System
- ISO 22000 – Food Safety Management System
- ISO 45001 – Occupational Health and Safety Management System
- ISO 14001 – Environmental Management System
- ISO 27001 – Information Security Management System
- GMP – Good Manufacturing Practices
- HACCP – Hazard Analysis Critical Control Point









