
ISO 37001 and Bribery-Risk Controls
Key components of an anti-bribery system include leadership, risk assessment, due diligence, controls, reporting, and investigation.
Leadership and the compliance function
Leadership commitment and the authority of the compliance function are essential so the system does not exist only on paper.
Bribery-risk assessment
Risks need to be considered by country, sector, transaction, project, third party, role, and business model.
Due diligence and controls
Due diligence needs to be proportionate to risk. Financial and non-financial controls help prevent improper transactions.
Reporting and improvement
Organizations need to provide reporting channels, protection for reporting persons, investigations, disciplinary action, and corrective action.