
ISO 37001 has received a new update, delivering an important message to organizations: an anti-bribery program cannot exist merely on paper. It must actively shape decisions, behaviors, and corporate culture.
Published in February 2025, ISO 37001:2025 replaces the 2016 edition and updates the requirements for implementing, maintaining, and continually improving an Anti-Bribery Management System (ABMS).
In practice, this elevates the role of training. It is no longer enough to prove that people received training. The organization must demonstrate that individuals were properly prepared—according to their specific risks and responsibilities—to recognize bribery scenarios and make the right choices.
What is ISO 37001?
ISO 37001 is an international standard that establishes requirements to prevent, detect, and address bribery across public, private, and non-profit sectors. It covers acts committed by the organization, its employees, or third parties acting on its behalf or involving business associates.
It is worth clarifying one detail: ISO 37001 has always been specifically focused on bribery prevention. The 2025 version simply reinforces and sharpens this scope. Other integrity risks—such as money laundering, fraud, nepotism, and certain conflicts of interest—require their own controls and can be managed in an integrated manner with ISO 37301 (Compliance Management Systems) and ISO 37002 (Whistleblowing Management Systems).
What really changed in ISO 37001:2025?
1. Anti-bribery culture takes center stage
The new edition explicitly addresses anti-bribery culture, defined as the set of values, beliefs, ethics, and behaviors that, combined with the organization’s controls, foster compliance with the anti-bribery policy.
This means that a code of conduct, annual training, and a message from the CEO alone do not prove a culture of integrity. The company must demonstrate alignment between what it preaches and what it practices:
Does leadership uphold controls even when facing aggressive sales targets?
Can employees halt a suspicious operation?
Are those who report concerns in good faith protected?
Are policy violations addressed regardless of the position of the offender?
Do people know how to act when faced with an improper request?
2. Conflicts of interest receive clearer guidelines
The revision reinforces the need to identify, declare, evaluate, and manage conflicts between personal, professional, family, financial, political, or business interests.
For training programs, this requires practical examples. Employees must understand that a conflict of interest does not always constitute wrongdoing in itself, but it can compromise—or appear to compromise—the impartiality of a decision. Training should teach people not just to “avoid conflicts,” but primarily how to recognize them, declare them, and follow the established procedure.
3. The anti-bribery function was clarified
ISO 37001:2025 clarifies the concept and responsibilities of the anti-bribery function. It can be held by the Compliance Officer, a dedicated team, or another formally designated professional, provided they have the competence, resources, authority, appropriate independence, and direct access to Top Management and the governing body (where applicable).
The anti-bribery function and the whistleblowing channel are distinct components, although they work in an integrated manner. This distinction must be reflected in training sessions: employees need to understand who holds the anti-bribery function, when to seek guidance, which situations must be escalated, and how to safely use the reporting channel.
4. Leadership becomes even more critical
The new edition delineates the responsibilities of the governing body and Top Management with greater clarity. Board members and executive leaders must not merely approve policies; they are required to oversee the ABMS, allocate resources, and actively promote an anti-bribery culture.
Consequently, leadership training cannot be identical to general employee training. Board members, directors, and managers must understand how their decisions impact the system, especially regarding:
Excessively aggressive commercial targets;
Hiring intermediaries;
Interacting with public officials;
Approving policy exceptions;
Donations and sponsorships;
Operating in high-risk markets;
Protecting whistleblowers;
Pressure to expedite payments, licenses, or contracts.
5. Structure aligned with other ISO standards
ISO 37001:2025 adopts a harmonized structure with other management system standards, simplifying integration with ISO 37301, ISO 37002, ISO 9001, and ISO 14001.
Climate change considerations have also been incorporated into the context of the organization. Companies must evaluate whether climate-related issues generate relevant risks—for instance, in environmental licensing, obtaining incentives, carbon credits, emergency donations, or environmental project contracting.
What must training programs include to comply with ISO 37001:2025?
Clause 7 of the standard addresses system support, covering competence, awareness, training, communication, and documented information. In the 2025 edition, Clause 7.3 explicitly organizes:
Personnel awareness;
Personnel training;
Business associate training;
Awareness and training programs.
For an effective program, training modules must address risk assessments, consequences, practical examples of improper offers and solicitations (how to spot them and how to respond), and the safe use of reporting channels. Concepts are necessary, but they are not enough. Employees and leaders must be able to translate the content into real-world meetings, decisions, negotiations, payments, and contracting.
Training from onboarding to planned intervals
Professionals must be made aware from the very beginning of their relationship with the organization. Subsequently, training must occur at planned intervals and be updated whenever relevant changes require a refresher.
Training business associates
A key point of the 2025 structure is the explicit emphasis on training business associates. This does not necessarily mean training every single supplier. Through risk assessment and due diligence, the organization must identify which partners act on its behalf or benefit and present more than a low bribery risk.
This group may include:
Commercial agents;
Customs brokers;
Consultants;
Representatives;
Intermediaries;
Joint venture partners;
Third parties interacting with public officials;
Suppliers involved in high-risk operations.
Learning evaluation and effectiveness
The standard requires competence and awareness, not mere attendance. Therefore, it is best practice to combine:
Knowledge assessments;
Scenario-based questions;
Minimum passing scores;
Instant feedback;
Refresher courses for those who do not pass;
Post-training evaluations via surveys, interviews, or simulations.
A certificate proves completion. An assessment demonstrates learning. Behavior and key metrics demonstrate effectiveness.
Auditable evidence
Procedures, training content, and delivery records must be kept as documented information. In an audit, claiming that “everyone was trained” is merely a statement. Certificates, reports, test results, and criteria convert that statement into verifiable evidence.
Anti-bribery culture strengthens the Compliance professional
By emphasizing anti-bribery culture, ISO 37001:2025 provides the Compliance professional with greater leverage to move beyond being a mere “rule enforcer” and act as a strategic driver of organizational culture, backed by a technical foundation to guide the company. However, this does not mean Compliance carries the burden alone: the new version reinforces that responsibility is shared among the governing body, Top Management, and leaders at all levels.
Why anti-corruption and anti-bribery training should start now
Organizations certified under the previous version must complete their transition by February 28, 2027. However, the operational record presented to auditors during transition audits starts being built today. The transition period should be leveraged to deploy risk-tailored training programs, evaluate learning outcomes, fix vulnerabilities, and generate solid evidence.
Prepare your company for ISO 37001:2025 with anti-corruption and anti-bribery training tailored to your organization’s risks. Contact TothBe to learn about our solutions for employees, leadership, and business partners.



