Compliance

ISO 37001 and 37301: two standards, one system

When an organisation is told it must “have an integrity programme”, it usually reacts in one of two ways. Either it writes a code of ethics, publishes it on the intranet and considers the matter closed. Or it launches two parallel projects —one anti-bribery, one general compliance— with two owners, two committees and two sets of documentation nobody quite manages to maintain.

Both reactions have the same origin: it is not clear what each standard resolves or where they overlap.

What each one resolves

ISO 37001 addresses one specific risk: bribery. It is deliberately narrow, and for that reason demanding. It requires identifying where the organisation is exposed —public procurement, commercial intermediaries, tenders, commission schemes, higher-risk geographies— and responding with concrete controls: third-party due diligence, financial and non-financial controls, a gifts and hospitality policy, a whistleblowing channel with real protection for the reporter, and an investigation protocol.

ISO 37301 addresses compliance in general. Its object is not a risk but a universe: every obligation that applies to the organisation, whether legal, regulatory, contractual or a voluntary commitment taken on. Its central deliverable is the obligations map, and with it the ability to answer a question many boards cannot answer today: what do we have to comply with, who answers for each thing, and how do we know?

Put briefly: 37001 is depth on one risk; 37301 is breadth across a universe.

What they share (which is a lot)

Both standards follow the ISO high-level structure. That means the following components are one, not two:

Component Shared
Organisational context and interested parties Yes
Leadership and governing body commitment Yes
Compliance function with authority and independence Yes
Risk assessment methodology Yes, with different criteria
Competence, training and awareness Yes, with different content
Whistleblowing channel and investigation Yes
Documented information and document control Yes
Internal audit Yes, with different criteria
Management review Yes
Breach management and continual improvement Yes

What genuinely separates is narrower than it looks: bribery risk assessment has its own methodology and a finer granularity —it is assessed by process and by counterparty, not only by department— and anti-bribery third-party due diligence is a specific procedure that ISO 37301 does not require at that level of detail.

The order matters, and depends on why you are starting

Almost nobody implements both standards at once from scratch. The order is set by the reason for starting.

If the trigger is a concrete requirement —a tender asking for it, a head office imposing it, international financing conditioning on it— start with ISO 37001. It is narrower, implements faster and answers exactly what is being asked of you. Extending later to 37301 by reusing the structure has a far smaller incremental cost than the initial project.

If the trigger is management-driven —the board has no visibility of its obligations, there was a regulatory scare, you are about to enter a regulated sector— start with the ISO 37301 obligations map. It is the deliverable that creates the most immediate value, even before there is a management system around it.

That map tends to be revealing. It is often the first time the organisation sees everything it must comply with consolidated in one place, and obligations with ambiguous ownership come to light: who actually answers for data protection regulation, who for the labour obligations of contractors, who for the compliance clauses signed with a client two years ago.

Three mistakes we see frequently

Confusing the code of ethics with the system. The code declares what is expected. The system is what makes it happen: identified risks, controls assigned to specific people, evidence generated by the operation itself, and someone who reviews it. A code without a system is a statement of intent on letterhead.

Having the compliance function report to whoever it should be controlling. If the compliance officer reports to the commercial or finance director, the conflict of interest is built into the design. The standard requires authority, independence and direct access to the governing body. It does not require a full-time role —in mid-sized organisations part-time works well— but it does require that reporting line.

A whistleblowing channel nobody uses. A form on the intranet that lands in the HR inbox is not a whistleblowing channel: it is a suggestion box under another name. Without the possibility of anonymity, without independent operation and without a non-retaliation policy that has been communicated seriously, the channel exists formally and does not work in practice. A complete absence of reports through a new channel rarely means there is nothing to report.

And where does information security come in?

In three places, and it is worth planning for them from the design stage.

Personal data protection is one more obligation within the 37301 map, but its controls live in the information security system. Where an ISO/IEC 27001 ISMS exists, the compliance system does not reimplement those controls: it references them.

The whistleblowing channel handles extremely sensitive information: the reporter’s identity, allegations about identified individuals, evidence from ongoing investigations. Handling it —access control, encryption, retention, segregation— is an information security problem, not a compliance one.

Compliance evidence must have integrity and traceability to hold any value before an auditor or a regulator. Records anyone can edit without leaving a trace prove nothing. In the projects we support, that integrity is resolved with document control including versioning and hashing on SORT Redmine, the same platform that supports the ISMS.

That is why we maintain that integrity, compliance and information security are not three projects: they are three views of one management system.


Need to organise your organisation’s integrity framework? See our ISO 37001 and ISO 37301 services.

your business partner

Protecting you today, innovating for tomorrow