Flevy Management Insights Q&A
What are the key components of an effective compliance program to combat corruption according to ISO 37001?
     Joseph Robinson    |    Corruption


This article provides a detailed response to: What are the key components of an effective compliance program to combat corruption according to ISO 37001? For a comprehensive understanding of Corruption, we also include relevant case studies for further reading and links to Corruption best practice resources.

TLDR ISO 37001 outlines an effective anti-bribery compliance program through Leadership, Risk Assessment, Due Diligence, Financial and Non-Financial Controls, Training, and Monitoring, emphasizing continuous improvement and ethical culture.

Reading time: 6 minutes

Before we begin, let's review some important management concepts, as they related to this question.

What does Leadership, Commitment, and Responsibility mean?
What does Risk Assessment mean?
What does Due Diligence mean?
What does Monitoring, Review, and Improvement mean?


ISO 37001 is a standard designed to help organizations establish, implement, maintain, and improve an anti-bribery management system. This standard provides a series of measures and controls that represent global best practices in combating bribery and corruption. The key components of an effective compliance program under ISO 37001 include Leadership, Commitment and Responsibility, Risk Assessment, Due Diligence, Financial and Non-Financial Controls, Training and Awareness, and Monitoring, Review, and Improvement. Each of these components plays a crucial role in ensuring that an organization can effectively combat corruption and maintain integrity in all its business dealings.

Leadership, Commitment, and Responsibility

At the heart of an effective compliance program is the unequivocal commitment and leadership from the top. This involves the top management demonstrating a clear stance against bribery and corruption, which is crucial for setting the tone for the entire organization. Leadership commitment is not just about policy statements; it involves active engagement in the development, implementation, and continuous improvement of the anti-bribery management system. This includes allocating the necessary resources, appointing a compliance officer or team with direct access to the board, and ensuring that anti-bribery policies are integrated into the organization's culture and operations.

Real-world examples of leadership commitment can be observed in companies that have successfully navigated corruption scandals by taking decisive action to revamp their compliance programs. For instance, Siemens AG, after being embroiled in a massive bribery scandal, undertook a comprehensive overhaul of its compliance system, demonstrating the critical role of leadership in driving ethical business practices.

Moreover, organizations like Accenture have published insights highlighting the importance of leadership in fostering an ethical culture, emphasizing that the tone at the top sets the expectations for behavior throughout the organization.

Are you familiar with Flevy? We are you shortcut to immediate value.
Flevy provides business best practices—the same as those produced by top-tier consulting firms and used by Fortune 100 companies. Our best practice business frameworks, financial models, and templates are of the same caliber as those produced by top-tier management consulting firms, like McKinsey, BCG, Bain, Deloitte, and Accenture. Most were developed by seasoned executives and consultants with 20+ years of experience.

Trusted by over 10,000+ Client Organizations
Since 2012, we have provided best practices to over 10,000 businesses and organizations of all sizes, from startups and small businesses to the Fortune 100, in over 130 countries.
AT&T GE Cisco Intel IBM Coke Dell Toyota HP Nike Samsung Microsoft Astrazeneca JP Morgan KPMG Walgreens Walmart 3M Kaiser Oracle SAP Google E&Y Volvo Bosch Merck Fedex Shell Amgen Eli Lilly Roche AIG Abbott Amazon PwC T-Mobile Broadcom Bayer Pearson Titleist ConEd Pfizer NTT Data Schwab

Risk Assessment

Risk Assessment is a foundational element of ISO 37001, requiring organizations to conduct regular, comprehensive assessments of the internal and external risks of bribery they face. This process involves identifying areas of the business and operations that are most vulnerable to corruption, evaluating the nature and extent of these risks, and prioritizing them based on their likelihood and impact. Effective risk assessments are dynamic, reflecting changes in the business environment, and inform the development of targeted strategies to mitigate identified risks.

Consulting firms like PwC and Deloitte have emphasized the importance of a risk-based approach to compliance, noting that it enables organizations to allocate their resources more effectively, focusing on areas of highest risk. These insights are supported by data and analysis that demonstrate how a risk-based approach can enhance the efficiency and effectiveness of compliance programs.

For example, the adoption of a risk-based approach by multinational corporations operating in high-risk jurisdictions has proven effective in identifying and mitigating potential bribery and corruption risks, thereby safeguarding the organization against legal, financial, and reputational damage.

Due Diligence

Due Diligence is another critical component of ISO 37001, requiring organizations to undertake thorough investigations into their business associates, including suppliers, contractors, and agents. This process is essential for identifying potential bribery risks associated with third parties and ensuring that business relationships are established only with entities that adhere to similar ethical standards. Due diligence processes must be proportionate to the risks identified, with more in-depth investigations conducted for higher-risk associations.

Real-world examples of the importance of due diligence can be seen in cases where organizations failed to adequately vet their partners and faced significant legal and financial repercussions as a result. Conversely, companies that have implemented robust due diligence processes have been able to avoid such pitfalls, demonstrating the protective value of this practice.

Research and analysis by firms like EY and KPMG have highlighted the critical role of due diligence in an effective compliance program, offering guidance on best practices for conducting these investigations and integrating their findings into the organization's risk management framework.

Financial and Non-Financial Controls

ISO 37001 requires organizations to establish both financial and non-financial controls to prevent bribery. Financial controls involve the implementation of accounting and auditing procedures designed to ensure the integrity of financial transactions and prevent the misappropriation of assets for corrupt purposes. Non-financial controls, on the other hand, include policies and procedures related to human resources, such as background checks, promotion, and compensation practices, to mitigate the risk of bribery.

Accenture's insights into financial controls highlight the importance of transparency and accountability in financial reporting as key deterrents to corruption. Similarly, non-financial controls are emphasized by McKinsey & Company, which points out that creating a culture of integrity and ethical behavior can significantly reduce the risk of bribery and corruption.

Examples of effective implementation of these controls can be found in organizations that have successfully passed ISO 37001 certification audits, demonstrating their commitment to combating bribery and corruption through comprehensive internal controls.

Training and Awareness

Training and Awareness are essential for ensuring that all employees and relevant third parties understand the organization's anti-bribery policies, the risks of corruption, and their roles in preventing it. ISO 37001 emphasizes the need for regular, targeted training programs that are tailored to the specific risks and requirements of different roles within the organization. This includes training on recognizing and responding to bribery risks, understanding the legal implications of non-compliance, and promoting an ethical culture.

Organizations like Deloitte have published extensive materials on the development and delivery of effective anti-bribery training programs, highlighting the importance of engaging content, practical examples, and regular updates to reflect changes in the legal and regulatory environment.

Companies that have been recognized for their excellence in compliance training often share their experiences and best practices, illustrating how effective training programs can enhance employees' understanding and commitment to anti-bribery efforts.

Monitoring, Review, and Improvement

Finally, ISO 37001 requires organizations to establish processes for Monitoring, Review, and Improvement of the anti-bribery management system. This involves regular audits and reviews to assess the effectiveness of the system, identify areas for improvement, and ensure that the organization remains compliant with changing laws and standards. Continuous improvement is a key principle of ISO 37001, reflecting the understanding that the fight against bribery and corruption requires ongoing vigilance and adaptation.

Consulting firms like KPMG and PwC offer services and insights into best practices for conducting effective compliance audits, emphasizing the importance of an independent, objective assessment of the anti-bribery management system.

Organizations that have successfully improved their compliance programs in response to audit findings demonstrate the value of a proactive approach to monitoring and review, ensuring that their anti-bribery efforts remain effective over time.

Best Practices in Corruption

Here are best practices relevant to Corruption from the Flevy Marketplace. View all our Corruption materials here.

Did you know?
The average daily rate of a McKinsey consultant is $6,625 (not including expenses). The average price of a Flevy document is $65.

Explore all of our best practices in: Corruption

Corruption Case Studies

For a practical understanding of Corruption, take a look at these case studies.

Anti-Corruption Compliance in the Telecom Industry

Scenario: A multinational telecom firm is grappling with allegations of corrupt practices within its overseas operations.

Read Full Case Study

Anti-Corruption Compliance Strategy for Oil & Gas Multinational

Scenario: An international oil and gas company is grappling with the complexities of corruption risk in numerous global markets.

Read Full Case Study

Bribery Risk Management and Mitigation for a Global Corporation

Scenario: A multinational corporation operating in various high-risk markets is facing significant challenges concerning bribery.

Read Full Case Study

Fraud Mitigation Strategy for a Telecom Provider

Scenario: The organization, a telecom provider, has recently faced a significant uptick in fraudulent activities that have affected customer trust and led to financial losses.

Read Full Case Study

Anti-Bribery Compliance in Global Construction Firm

Scenario: The organization operates in the global construction industry with projects spanning multiple high-risk jurisdictions for bribery and corruption.

Read Full Case Study

Telecom Industry Fraud Detection and Mitigation Initiative

Scenario: A telecommunications company is grappling with increased fraudulent activities that are affecting its bottom line and customer trust.

Read Full Case Study




Flevy is the world's largest knowledge base of best practices.


Leverage the Experience of Experts.

Find documents of the same caliber as those used by top-tier consulting firms, like McKinsey, BCG, Bain, Deloitte, Accenture.

Download Immediately and Use.

Our PowerPoint presentations, Excel workbooks, and Word documents are completely customizable, including rebrandable.

Save Time, Effort, and Money.

Save yourself and your employees countless hours. Use that time to work on more value-added and fulfilling activities.




Read Customer Testimonials

  •  
    "Flevy is our 'go to' resource for management material, at an affordable cost. The Flevy library is comprehensive and the content deep, and typically provides a great foundation for us to further develop and tailor our own service offer."

    – Chris McCann, Founder at Resilient.World
  •  
    "If you are looking for great resources to save time with your business presentations, Flevy is truly a value-added resource. Flevy has done all the work for you and we will continue to utilize Flevy as a source to extract up-to-date information and data for our virtual and onsite presentations!"

    – Debbi Saffo, President at The NiKhar Group
  •  
    "[Flevy] produces some great work that has been/continues to be of immense help not only to myself, but as I seek to provide professional services to my clients, it give me a large "tool box" of resources that are critical to provide them with the quality of service and outcomes they are expecting."

    – Royston Knowles, Executive with 50+ Years of Board Level Experience
  •  
    "Flevy is now a part of my business routine. I visit Flevy at least 3 times each month.

    Flevy has become my preferred learning source, because what it provides is practical, current, and useful in this era where the business world is being rewritten.

    In today's environment where there are so "

    – Omar HernĂ¡n Montes Parra, CEO at Quantum SFE
  •  
    "As a consultant requiring up to date and professional material that will be of value and use to my clients, I find Flevy a very reliable resource.

    The variety and quality of material available through Flevy offers a very useful and commanding source for information. Using Flevy saves me time, enhances my expertise and ends up being a good decision."

    – Dennis Gershowitz, Principal at DG Associates
  •  
    "As a small business owner, the resource material available from FlevyPro has proven to be invaluable. The ability to search for material on demand based our project events and client requirements was great for me and proved very beneficial to my clients. Importantly, being able to easily edit and tailor "

    – Michael Duff, Managing Director at Change Strategy (UK)
  •  
    "As a young consulting firm, requests for input from clients vary and it's sometimes impossible to provide expert solutions across a broad spectrum of requirements. That was before I discovered Flevy.com.

    Through subscription to this invaluable site of a plethora of topics that are key and crucial to consulting, I "

    – Nishi Singh, Strategist and MD at NSP Consultants
  •  
    "Flevy.com has proven to be an invaluable resource library to our Independent Management Consultancy, supporting and enabling us to better serve our enterprise clients.

    The value derived from our [FlevyPro] subscription in terms of the business it has helped to gain far exceeds the investment made, making a subscription a no-brainer for any growing consultancy – or in-house strategy team."

    – Dean Carlton, Chief Transformation Officer, Global Village Transformations Pty Ltd.



Download our FREE Strategy & Transformation Framework Templates

Download our free compilation of 50+ Strategy & Transformation slides and templates. Frameworks include McKinsey 7-S Strategy Model, Balanced Scorecard, Disruptive Innovation, BCG Experience Curve, and many more.