Home · Compliance · ISO 37001
ISO certification · ISO 37001Governance

Keybridge prepares ISO 37001 certification in Iraq and Kurdistan.

Establish anti-bribery controls, responsibilities and procedures for addressing concerns. We confirm the scope and the buyer’s stated requirements before preparation starts. Buyer acceptance depends on the certificate scope, issuing body and the requirements set by the buyer. We review those requirements before preparation.

ISO 37001 Anti-bribery management systems

ISO 37001 at a glance

Published
March 2025. ISO 37001:2025 is the current edition. It replaced ISO 37001:2016, and a certificate held against the 2016 edition moves across during the transition period.
Structure
Annex SL high level structure. 10 clauses, and clauses 4 to 10 carry the auditable requirements. Annex A is guidance on implementing the controls and is not audited as a requirement.
Certifiable
Yes. The company is certified for a defined scope. The certificate says the anti-bribery system meets the standard. It does not say that no bribery has happened or that none will happen.
Certificate validity
The assessment body confirms the applicable schedule and continuing requirements for your scope.
Surveillance
The assessment body confirms the applicable schedule and continuing requirements for your scope.
Audit days, 10 to 50 people
The assessment body confirms the applicable schedule and continuing requirements for your scope.
What the scope covers
Only the sites and activities written into the scope. Anything left out of it is not covered.
What the certificate says
The company name, the standard, the scope and the dates the certificate runs.
Language of the system
We write the policy, the procedures and the training material in Arabic, Kurdish and English, because the reporting channel has to work in the language the employee actually speaks.

What ISO 37001 is

ISO 37001 is the international standard for an anti-bribery management system. It asks a company to rate where bribery risk actually sits in its business, put controls on the payments, permits, tenders and third parties where that risk is highest, train the people exposed to it, and record what happens when someone reports a concern.

What the standard requires

  1. Clauses 1 to 3 cover scope, normative references and terms. Clauses 4 to 10 are the requirements an auditor checks, and Annex A is guidance rather than a requirement.
  2. Clause 4.5, bribery risk assessment. Rate the bribery risk of every country, contract type, agent, customs step and public official contact the company deals with, and review the rating when the business changes.
  3. Clause 5, leadership. The governing body and the general manager own the system, sign the anti-bribery policy, and appoint an anti-bribery compliance function with direct access to the board.
  4. Clause 6, planning. Set anti-bribery objectives with numbers and dates, and plan the controls against the rated risks.
  5. Clause 7, support. Employment checks on staff in exposed roles, an anti-bribery clause in contracts, training for everyone exposed to the risk, and a channel for raising concerns.
  6. Clause 8.2, due diligence. Record a documented check on every agent, distributor, consultant, joint venture partner and high risk supplier before the contract is signed.
  7. Clauses 8.3 and 8.4, controls. Financial controls over payments, petty cash and approval limits, and non-financial controls over procurement, tendering, customs handling and permits.
  8. Clause 8.7, gifts and hospitality. A written rule with a value limit, a register of what was given and received, and an approval step for anything above the limit.
  9. Clauses 8.9 and 8.10, concerns and investigation. A reporting channel that protects the person who reports, and a recorded investigation for every report received.
  10. Clauses 9 and 10, evaluation and improvement. Internal audit, a review by the anti-bribery compliance function, a management review by top management and by the governing body, and a closed corrective action for every finding.

Who needs ISO 37001 in Iraq and Kurdistan

Oil and gas service companiesISO 37001 may be relevant to the management of this activity. Confirm the applicable scope and any buyer requirement before seeking certification.
Construction and EPC contractorsPublic projects run on permits, inspections and payment approvals, and each of those steps puts staff in front of a public official.
Agents, distributors and local representativesAgency relationships can create bribery risks. Review the applicable obligations and controls for agents rather than assuming every legal regime applies to every company.
Customs clearance and logistics companiesCustoms and logistics activities can involve interactions with officials and intermediaries. Document approval rules, payment controls and escalation procedures.
Medical and pharmaceutical distributorsMinistry of Health tenders and hospital supply contracts put sales staff in direct contact with public buyers and prescribers.
NGOs and UN implementing partnersReview the anti-corruption, audit and reporting conditions in each funding agreement and reflect them in your controls.
Banks, exchange and payment companiesCorrespondent banks abroad ask who approves a payment, what the limits are, and how an exception is recorded.
Security and manpower companiesLicences, site passes and work permits are issued by officials, so every one of those approvals is a risk point that has to be controlled.

The buyers that ask for ISO 37001

Buyer or listWhat they ask for
International operatorsReview this buyer’s current supplier criteria for the products or services offered. Certificate scope, buyer acceptance and tender eligibility need to be checked separately.
Foreign parent companies and joint venture partnersReview this buyer’s current supplier criteria for the products or services offered. Certificate scope, buyer acceptance and tender eligibility need to be checked separately.
UN agencies through UNGMCheck the individual procurement notice for the required certificate and scope. Registration on UNGM does not replace the tender’s qualification criteria.
Donors and development lendersCheck the financing or procurement conditions for the relevant project. Confirm whether certification is requested rather than assuming it from the sector.
EPC contractorsReview the project’s supplier requirements and the work package you intend to deliver. A contractor may set requirements beyond the certificate itself.
Ministry of Natural Resources Approved Vendor ListCheck the current registration instructions for your activity and category. Confirm whether this standard is requested and which issuing bodies are accepted.
Gulf and international buyersReview this buyer’s current supplier criteria for the products or services offered. Certificate scope, buyer acceptance and tender eligibility need to be checked separately.

What shapes your investment

  • Number of legal entities and sites, and whether the auditor has to travel to Erbil, Sulaymaniyah, Baghdad or Basra.
  • The bribery risk rating of the business, because a high rating adds auditor days and evidence.
  • Number of agents, distributors, consultants and high risk suppliers that need a due diligence check.
  • Headcount in the exposed roles, which sets how many auditor days the audit takes.
  • Number of business lines and how much they differ in the officials and permits they deal with.
  • Languages the documentation, the training and the reporting channel are delivered in.
  • How much usable policy, contract and payment control documentation already exists in the company.
  • Whether ISO 37001 is built alone or together with ISO 9001 as one system; the certification body determines the audit time.

The proposal names the scope, the deliverables and the dates before work starts.