Risk & Compliance Matters

ISO 37001: Answers to the 5 Questions We’ve Heard Most About the Standard

It’s been a month since ISO 37001 was published and there are some questions we have heard percolating in the compliance world about what this means. These are the questions we’ve been hearing the most:

1.What is the elevator pitch for the standard?

ISO 37001 is an international good practice standard that is focused on anti-bribery and corruption and can be used in all jurisdictions and geographies. It comes from a long-standing and well-respected international organization that is best known for quality and environmental standards that have been adopted around the world.

Bribery risks will vary depending on the size of an organization, the locations and sectors in which it operates, and the nature, scale and complexity of its activities.

It is applicable to small, medium and large organizations in all sectors, including public, private and not-for-profit. Although applicable to organizations across the spectrum, there is no one-size-fits-all solution for implementation. Bribery risks will vary depending on the size of an organization, the locations and sectors in which it operates, and the nature, scale and complexity of its activities.

In relation to the UK Bribery Act (UKBA) or the U.S. Foreign Corrupt Practices Act (FCPA) Guidance, nothing really new is required or expected as a result of ISO 37001; however, organizations will now be able to obtain certification of their programs from a third-party nonprofit organization.

2.What are the pros and cons of getting certified?

Pros:

Cons:

3. Why has this ISO standard received so much more publicity than others?

This could be because ISO 37001 is a country and statute neutral program that all organizations can use more easily than some...

It is interesting that the December 2014 ISO Standard/Guidance 19600 on Compliance Management Systems has received little attention from compliance officers, regulators and industry associations, yet ISO 37001 is receiving considerably more coverage. This could be because ISO 37001 is a country and statute neutral program that all organizations can use more easily than some of the past U.S., UK or other country centric anti-bribery and corruption guidance. It is also more proactive in feel and less punitive than FCPA and UKBA.

4.Why is there not a flurry of people trying to get certified?

Many organizations will want to review the standard carefully, let this settle in and watch for how organizations and regulators react before taking the steps toward certification. Also the risk of failing a certification attempt could open up an organization to more scrutiny and risk than before the certification process began.

Once a few large organizations complete the certification process, the standard will most likely embed and companies will begin to require certification from downstream contractors as additional due diligence. Organizations should be prepared to see these requests coming from key customers.

5.What happens if you fail to meet the certification?

Organizations will need to address any gaps identified by a failed certification attempt. Not doing so may result in greater risks in the event of a failure or misconduct since organizations will have had actual notice of issues or control failures.

What questions or answers do you have about ISO 37001? Is your organization considering certification? Let’s keep the discussion going.


Request a consultation with the Advisory Services Team to continue learning how to improve your ethics and compliance program.

View on Full Site
Disqus Comments

When Managing Whistleblower and Retaliation Risk, Tools are Important – Processes and People are Critical

‹ Previous Article

5 Key Takeaways from My Long List of Regulatory Changes Shared at ECVC2016

Next Article ›