Keybridge prepares ISO 37001 certification in Iraq and Kurdistan.
Establish anti-bribery controls, responsibilities and procedures for addressing concerns. We confirm the scope and the buyer’s stated requirements before preparation starts. Buyer acceptance depends on the certificate scope, issuing body and the requirements set by the buyer. We review those requirements before preparation.
ISO 37001 Anti-bribery management systems
ISO 37001 at a glance
- Published
- March 2025. ISO 37001:2025 is the current edition. It replaced ISO 37001:2016, and a certificate held against the 2016 edition moves across during the transition period.
- Structure
- Annex SL high level structure. 10 clauses, and clauses 4 to 10 carry the auditable requirements. Annex A is guidance on implementing the controls and is not audited as a requirement.
- Certifiable
- Yes. The company is certified for a defined scope. The certificate says the anti-bribery system meets the standard. It does not say that no bribery has happened or that none will happen.
- Certificate validity
- The assessment body confirms the applicable schedule and continuing requirements for your scope.
- Surveillance
- The assessment body confirms the applicable schedule and continuing requirements for your scope.
- Audit days, 10 to 50 people
- The assessment body confirms the applicable schedule and continuing requirements for your scope.
- What the scope covers
- Only the sites and activities written into the scope. Anything left out of it is not covered.
- What the certificate says
- The company name, the standard, the scope and the dates the certificate runs.
- Language of the system
- We write the policy, the procedures and the training material in Arabic, Kurdish and English, because the reporting channel has to work in the language the employee actually speaks.
What ISO 37001 is
ISO 37001 is the international standard for an anti-bribery management system. It asks a company to rate where bribery risk actually sits in its business, put controls on the payments, permits, tenders and third parties where that risk is highest, train the people exposed to it, and record what happens when someone reports a concern.
What the standard requires
- Clauses 1 to 3 cover scope, normative references and terms. Clauses 4 to 10 are the requirements an auditor checks, and Annex A is guidance rather than a requirement.
- Clause 4.5, bribery risk assessment. Rate the bribery risk of every country, contract type, agent, customs step and public official contact the company deals with, and review the rating when the business changes.
- Clause 5, leadership. The governing body and the general manager own the system, sign the anti-bribery policy, and appoint an anti-bribery compliance function with direct access to the board.
- Clause 6, planning. Set anti-bribery objectives with numbers and dates, and plan the controls against the rated risks.
- Clause 7, support. Employment checks on staff in exposed roles, an anti-bribery clause in contracts, training for everyone exposed to the risk, and a channel for raising concerns.
- Clause 8.2, due diligence. Record a documented check on every agent, distributor, consultant, joint venture partner and high risk supplier before the contract is signed.
- Clauses 8.3 and 8.4, controls. Financial controls over payments, petty cash and approval limits, and non-financial controls over procurement, tendering, customs handling and permits.
- Clause 8.7, gifts and hospitality. A written rule with a value limit, a register of what was given and received, and an approval step for anything above the limit.
- Clauses 8.9 and 8.10, concerns and investigation. A reporting channel that protects the person who reports, and a recorded investigation for every report received.
- Clauses 9 and 10, evaluation and improvement. Internal audit, a review by the anti-bribery compliance function, a management review by top management and by the governing body, and a closed corrective action for every finding.
Who needs ISO 37001 in Iraq and Kurdistan
The buyers that ask for ISO 37001
| Buyer or list | What they ask for |
|---|---|
| International operators | Review this buyer’s current supplier criteria for the products or services offered. Certificate scope, buyer acceptance and tender eligibility need to be checked separately. |
| Foreign parent companies and joint venture partners | Review this buyer’s current supplier criteria for the products or services offered. Certificate scope, buyer acceptance and tender eligibility need to be checked separately. |
| UN agencies through UNGM | Check the individual procurement notice for the required certificate and scope. Registration on UNGM does not replace the tender’s qualification criteria. |
| Donors and development lenders | Check the financing or procurement conditions for the relevant project. Confirm whether certification is requested rather than assuming it from the sector. |
| EPC contractors | Review the project’s supplier requirements and the work package you intend to deliver. A contractor may set requirements beyond the certificate itself. |
| Ministry of Natural Resources Approved Vendor List | Check the current registration instructions for your activity and category. Confirm whether this standard is requested and which issuing bodies are accepted. |
| Gulf and international buyers | Review this buyer’s current supplier criteria for the products or services offered. Certificate scope, buyer acceptance and tender eligibility need to be checked separately. |
What shapes your investment
- Number of legal entities and sites, and whether the auditor has to travel to Erbil, Sulaymaniyah, Baghdad or Basra.
- The bribery risk rating of the business, because a high rating adds auditor days and evidence.
- Number of agents, distributors, consultants and high risk suppliers that need a due diligence check.
- Headcount in the exposed roles, which sets how many auditor days the audit takes.
- Number of business lines and how much they differ in the officials and permits they deal with.
- Languages the documentation, the training and the reporting channel are delivered in.
- How much usable policy, contract and payment control documentation already exists in the company.
- Whether ISO 37001 is built alone or together with ISO 9001 as one system; the certification body determines the audit time.
The proposal names the scope, the deliverables and the dates before work starts.