Compliance and integrity

ISO 37001 anti-bribery management system

A certifiable framework to prevent, detect and respond to bribery. It does not promise bribery will never happen: it demonstrates that the organisation did what was reasonable to prevent it, which is exactly what clients, partners and regulators assess.

Typical duration
6 to 12 months
Delivery
Blended — on site and remote
Support
SORT Redmine included
Integrates with
ISO 37301 and ISO/IEC 27001

Objective and scope

We implement the complete system: anti-bribery policy, a compliance function with authority and independence, bribery risk assessment by process and by counterparty, third-party due diligence, financial and non-financial controls, management of gifts and hospitality, a whistleblowing channel with protection for the reporter, and incident investigation.


Project phases

Phase 1

Assessment and bribery risk evaluation

We identify the real exposures: sectors, geographies, dealings with public officials, intermediaries, tenders and commission schemes.

Phase 2

System design

Anti-bribery policy, compliance function, due diligence procedures, financial and non-financial controls, and a policy on gifts, hospitality and donations.

Phase 3

Implementation and culture

Role-based training, communication to business partners, and the launch of the whistleblowing channel and the investigation protocol.

Phase 4

Audit and certification

Independent internal audit, management review and support through to the certification audit.


What the implementation includes

  • Bribery risk assessment
  • Anti-bribery policy
  • Anti-bribery compliance function
  • Third-party due diligence
  • Financial and non-financial controls
  • Gifts and hospitality policy
  • Anti-bribery contract clauses
  • Whistleblowing channel and reporter protection
  • Investigation protocol
  • Role-based training and awareness

Frequently asked questions

Is it mandatory in Uruguay?

It is not mandatory as a general rule, but it is increasingly requested as a requirement in public tenders, in contracts with multinationals and in international financing operations.

How does it relate to ISO 37301?

ISO 37001 addresses one specific risk —bribery— while ISO 37301 covers compliance in general. Many organisations implement 37001 first because of a concrete requirement, then extend to 37301 reusing the structure.

Does it require a full-time compliance officer?

Not necessarily. The standard requires a compliance function with authority, independence and adequate resources. In mid-sized organisations this is usually resolved with a part-time role reporting directly to the governing body.

your business partner

Protecting you today, innovating for tomorrow