ISO 37001: the anti-bribery management system
We take companies in Switzerland, Italy and international markets through to ISO 37001 certification, the management system that prevents and counters bribery.
What ISO 37001 is
It is the international standard for anti-bribery management systems. The version in force is ISO 37001:2025, which replaced the 2016 edition: existing certificates have until 28 February 2027 to make the switch.
It sets out the requirements for preventing, detecting and addressing bribery — active and passive, direct and through third parties — by means of policies, controls, clear accountability and a company culture built on integrity. It follows the harmonised structure common to the other ISO standards, so it sits well alongside management systems already in place.
What the 2025 revision changes
The revision does not overturn the standard, but it updates and tightens it on several points: an anti-bribery culture becomes an explicit requirement, with a stronger role for senior management and the governing body; conflicts of interest are treated in more detail; the “anti-bribery compliance function” is defined more clearly; climate change enters the list of context factors; and due diligence on third parties (intermediaries, partners, suppliers) is reinforced. Anyone setting up the system now starts on the updated edition.
Who needs it, and why
- Companies working with public authorities or bidding for public contracts, where integrity is both a requirement and a matter of reputation.
- Organisations exposed to bribery risk by virtue of their sector, their export markets or their dealings with intermediaries and third parties.
- Groups that want to show clients, partners and investors a concrete, verifiable commitment against bribery.
- Anyone wanting to reinforce their internal control system with an internationally recognised standard.
Is it mandatory? The certification is voluntary. It is a strong competitive and reputational asset, and in a number of settings it is required or rewarded in tenders and supply relationships.
The link with the Italian 231 model
For Italian companies, ISO 37001 connects with Legislative Decree 231/2001, which governs the administrative liability of entities for bribery offences among others, and with Law 190/2012.
ISO 37001 replaces neither the 231 organisational model nor the law: the 231 model remains the instrument through which an entity evidences its diligence in order to exclude liability. ISO 37001 is, however, a recognised best practice that integrates with the 231 model, strengthens its anti-bribery component and makes it certifiable by a third-party body. In practice: a company with a 231 model finds in 37001 a way to structure and evidence its anti-bribery safeguards better; a company starting from 37001 builds a solid base for the model.
The path, step by step
- Initial review — the free preliminary assessment: where you stand, what you already have, what is missing.
- Bribery risk assessment — mapping the exposed areas and activities: the heart of the standard.
- Planning — policies, controls, roles, responsibilities.
- Building the management system — procedures, third-party due diligence, reporting channels, training.
- Training and awareness for the staff.
- Internal audit.
- Certification audit — the assessment by the independent third-party body.
- Maintenance — annual surveillance, renewal on a three-year cycle.
How the cost breaks down
There are two items and they stay separate: our consulting fee and the fee of the certification body, an independent third party. The variables are size, sector and risk exposure, the number of sites, and whether a control system is already in place or you are starting from scratch. We discuss it openly at the first contact, on your case rather than off a generic price list.
Why BS & Partners
- Ten years in business, 117 projects, work in 9 countries.
- An integrated approach: ISO 37001 grafts onto existing management systems and control models, and we set it up to talk to them rather than sit outside them.
- The firm and the way we work: the BS & Partners profile.
Frequently asked questions
Is ISO 37001 mandatory?
No, the certification is voluntary. It is, however, increasingly required or rewarded in public tenders and supply relationships, and it is a strong reputational asset for organisations exposed to bribery risk.
Does ISO 37001 replace the 231 model?
No. In Italy the 231 organisational model remains the instrument through which an entity demonstrates its diligence. ISO 37001 does not replace it: it is a recognised best practice that integrates with the 231 model, strengthens its anti-bribery component and makes it certifiable by an independent third-party body.
Does ISO 37001 certification guarantee there will be no bribery?
No, and no system can. ISO 37001 demonstrates that the organisation has adopted reasonable and proportionate measures to prevent and detect bribery: it reduces the risk and evidences diligence, but it does not remove individual responsibility.
Does it integrate with the other ISO standards?
Yes. ISO 37001 follows the harmonised structure shared by management system standards, so it combines with quality, environment, safety and information security into a single system, avoiding duplication.
The firm in numbers
- 10 years in business
- 117 projects completed
- 9 countries we have worked in
Want to prove your anti-bribery safeguards in a verifiable way?
The preliminary assessment is free: we look at the controls you already have, your risk exposure and what it takes to reach ISO 37001.
Request a free preliminary assessment
Or write to direzione@bs-partners.ch or call +41 76 731 16 99.