Compliance and integrity

ISO 37301 compliance management system

Compliance is not signing a declaration: it is knowing which obligations apply, who answers for each one, how they are controlled and what evidence is left behind. ISO 37301 turns that into an auditable system.

Typical duration
6 to 12 months
Delivery
Blended — on site and remote
Support
SORT Redmine included
Integrates with
ISO 37001 and ISO/IEC 27001

Objective and scope

We build the map of compliance obligations —legal, regulatory, contractual and voluntary— assess the risks associated with each, define controls and owners, and establish the monitoring, reporting and improvement cycle. The outcome is that the Board can answer, with evidence, what obligations the organisation has and how it is managing them.


Project phases

Phase 1

Obligations map

We identify and classify the applicable obligations: national and sector legislation, regulator requirements, contractual obligations and voluntary commitments taken on.

Phase 2

Compliance risks

We assess the likelihood and consequence of breaching each obligation, taking into account penalties, reputational impact and business continuity.

Phase 3

Controls and owners

We assign an owner and a control to each material obligation, and document the evidence that must be generated in each case.

Phase 4

Monitoring, reporting and audit

We establish indicators, the reporting cycle to the governing body, internal audit and the handling of breaches.


What the implementation includes

  • Map of compliance obligations
  • Compliance policy
  • Compliance function and governance
  • Compliance risk assessment
  • Matrix of controls and owners
  • Code of conduct
  • Whistleblowing channel and investigation
  • Indicators and reporting to the Board
  • Breach management and improvement
  • Role-based training

Frequently asked questions

Where should we start?

With the obligations map. It is the deliverable that creates the most immediate value and, in many organisations, the first time everything that must be complied with is consolidated in one place.

How does it relate to personal data protection?

Uruguay’s Law 18.331 and the rules issued by the data protection authority are obligations that go into the map. The compliance system manages them like any other obligation, drawing on the ISMS controls where one exists.

Is it useful if we already have ISO 37001?

Yes, and the incremental effort is smaller. They share structure, compliance function, whistleblowing channel and internal audit; what is added is the breadth of the obligations universe.

your business partner

Protecting you today, innovating for tomorrow