{"id":6157,"date":"2026-09-28T05:08:44","date_gmt":"2026-09-28T05:08:44","guid":{"rendered":"https:\/\/iasiso-gulf.com\/BH\/blog\/planning-an-internal-audit-programme-clause-9-2\/"},"modified":"2026-09-28T05:08:44","modified_gmt":"2026-09-28T05:08:44","slug":"planning-an-internal-audit-programme-clause-9-2","status":"publish","type":"post","link":"https:\/\/iasiso-gulf.com\/BH\/blog\/planning-an-internal-audit-programme-clause-9-2\/","title":{"rendered":"How to Plan an Internal Audit Programme Under ISO 37001 Clause 9.2"},"content":{"rendered":"<style>.ias-c h2,.ias-c h3,.ias-c .ias-faq-title{font-weight:700 !important;text-align:left !important;}.ias-c h2:not(.ias-faq-title){font-size:22px !important;line-height:1.3 !important;margin:30px 0 12px !important;color:#B02B2C !important;}.ias-c h3{font-size:18px !important;line-height:1.35 !important;margin:24px 0 10px !important;color:#B02B2C !important;}.ias-c p,.ias-c li{text-align:justify;line-height:1.7;color:#212529;}.ias-c ul{margin:0 0 18px 20px;}.ias-c li{margin-bottom:8px;}.ias-c a,.ias-c td a,.ias-c li a,.ias-c p a{font-weight:700 !important;text-decoration:underline !important;text-underline-offset:2px;color:#B02B2C !important;}.ias-fig{margin:24px auto;padding:0;max-width:600px;}.ias-fig img{width:100%;height:auto;display:block;border-radius:6px;}.ias-fig figcaption{font-size:13px;color:#6b6360;text-align:center;margin-top:8px;font-style:italic;}.ias-qa{background:#fbf6f6;border-left:4px solid #B02B2C;padding:18px 22px;margin:0 0 26px;border-radius:4px;}.ias-qa .ias-qa-t{font-weight:700;color:#B02B2C;font-size:16px;margin:0 0 10px;text-transform:uppercase;letter-spacing:.4px;}.ias-qa ul{margin:0 0 0 18px;}.ias-qa li{margin-bottom:7px;text-align:justify;}.ias-byline{font-size:13px;color:#6b6360;margin:0 0 18px;font-style:italic;}.ias-tw{width:100%;border-collapse:collapse;margin:18px 0 26px;font-size:15px;}.ias-tw thead th{background:#B02B2C !important;color:#fff !important;font-weight:700 !important;text-align:left !important;padding:11px 13px !important;border:1px solid #B02B2C !important;}.ias-tw td{border:1px solid #e6dede !important;padding:10px 13px !important;color:#212529 !important;vertical-align:top;}.ias-tw tbody tr:nth-child(even) td{background:#fbf6f6 !important;color:#212529 !important;}.ias-tw tbody tr:nth-child(odd) td{background:#fff !important;color:#212529 !important;}.ias-src{font-size:12.5px;color:#6b6360;margin:-14px 0 24px;font-style:italic;}.ias-quote{border-left:4px solid #B02B2C;background:#fbf6f6;padding:16px 20px;margin:22px 0;font-style:italic;color:#212529;text-align:justify;}.ias-bio{background:#fbf6f6;border:1px solid #e6dede;border-radius:6px;padding:18px 22px;margin:26px 0;}.ias-bio .ias-bio-t{font-weight:700;color:#B02B2C;margin:0 0 8px;font-size:16px;}.ias-bio p{margin:0;font-size:14.5px;}.ias-c .ias-faq-title{font-size:1.5em;font-weight:700;color:#B02B2C !important;margin:34px 0 14px;}.ias-faq-item{border:1px solid #e6dede;border-radius:5px;margin-bottom:10px;background:#fff;}.ias-faq-q{cursor:pointer;padding:13px 44px 13px 16px;font-weight:700;color:#212529;position:relative;list-style:none;line-height:1.5;}.ias-faq-q::-webkit-details-marker{display:none;}.ias-faq-q::after{content:\"+\";position:absolute;right:16px;top:50%;transform:translateY(-50%);color:#B02B2C;font-size:22px;font-weight:700;line-height:1;}.ias-faq-item[open] .ias-faq-q::after{content:\"\u2212\";}.ias-faq-a{padding:0 16px 14px;}.ias-faq-a p{margin:0;font-size:15px;}.ias-cta{background:#B02B2C;color:#fff !important;padding:22px 24px;border-radius:6px;margin:28px 0 0;}.ias-cta p{color:#fff !important;margin:0 0 8px;}.ias-cta a{color:#fff !important;text-decoration:underline !important;}@media(max-width:640px){.ias-tw{font-size:13.5px;}.ias-tw td,.ias-tw thead th{padding:8px 9px !important;}}.elementor-widget-sidebar,.elementor-widget-sidebar *{font-family:\"Inter\",Arial,Helvetica,sans-serif !important;}.elementor-widget-sidebar .widget-title,.elementor-widget-sidebar h2,.elementor-widget-sidebar h3{font-family:\"Poppins\",\"Inter\",Arial,sans-serif !important;}.gdlr-social-share{display:none !important;}.ias-c .ias-fig{display:block !important;margin-left:auto !important;margin-right:auto !important;float:none !important;}.ias-c,.ias-c p,.ias-c li,.ias-c td,.ias-c th,.ias-c blockquote,.ias-c summary,.ias-c div{font-family:\"Inter\",Arial,Helvetica,sans-serif !important;}.ias-c h2,.ias-c h3,.ias-c .ias-faq-title,.ias-c .ias-qa-t,.ias-c .ias-bio-t{font-family:\"Poppins\",\"Inter\",Arial,sans-serif !important;}.ias-c h2:not(.ias-faq-title){font-size:25px !important;}.ias-c h3{font-size:20px !important;}.ias-c p,.ias-c li{font-size:16px !important;line-height:1.7 !important;color:#000 !important;}.ias-c td,.ias-c th{font-size:15px !important;}.ias-c .ias-faq-a p,.ias-c .ias-bio p,.ias-c .ias-byline,.ias-c .ias-src{font-size:15px !important;}.ias-c .ias-faq-q{color:#333 !important;}.ias-c .ias-byline,.ias-c .ias-src,.ias-c figcaption{color:#8d8d8d !important;}.ias-c .ias-cta p,.ias-c .ias-cta a,.ias-c .ias-cta strong{color:#fff !important;}.ias-c .ias-tw thead th{color:#fff !important;}.ias-c h2:not(.ias-faq-title),.ias-c h3,.ias-c .ias-faq-title{color:#0A4D8C !important;}.ias-c p strong,.ias-c li strong,.ias-c td strong{color:#333 !important;}.ias-fig.ias-fig-photo{max-width:480px;}.ias-fig.ias-fig-wide{max-width:820px;}@media(max-width:860px){.ias-fig.ias-fig-wide{max-width:100%;}}.ias-c ul{list-style:disc outside !important;padding-left:22px !important;margin:0 0 18px 8px !important;}.ias-c ul li{list-style:disc outside !important;display:list-item !important;}.ias-c a,.ias-c li a,.ias-c p a,.ias-c td a{text-decoration:underline !important;font-weight:700 !important;color:#B02B2C !important;}.ias-c .ias-cta a{color:#fff !important;}.ias-c .ias-band{background:#fbf6f6;border:1px solid #e6dede;border-radius:10px;padding:14px 18px;margin:20px 0;}.ias-c .ias-band ul{display:flex !important;flex-wrap:wrap;gap:6px 26px;margin:0 !important;padding:0 !important;list-style:none !important;}.ias-c .ias-band ul li{list-style:none !important;display:block !important;font-size:15px !important;color:#333 !important;font-weight:600;}.ias-c .ias-band ul li:before{content:\"\\2713\";color:#B02B2C;font-weight:700;margin-right:8px;}.ias-c .ias-cta2{background:#B02B2C;border-radius:10px;padding:16px 20px;margin:24px 0;}.ias-c .ias-cta2 p{margin:0 !important;color:#fff !important;font-size:16px !important;}.ias-c .ias-cta2 p a{color:#fff !important;text-decoration:underline !important;font-weight:700 !important;}.ias-cta2,.ias-cta2 p,.ias-cta2 li,.ias-cta2 strong,.ias-cta2 b,.ias-c .ias-cta2 p strong,.ias-c .ias-cta2 li strong,.ias-c .ias-cta2 td strong,.elementor .ias-c .ias-cta2 p strong,.elementor .ias-c .ias-cta2 li strong,.elementor .ias-c .ias-cta2 td strong{color:#fff!important}<\/style>\n<div class=\"ias-c\">\n<p>An internal audit programme is the part of an anti-bribery management system that checks itself. Clause 9.2 of ISO 37001 asks you to plan, establish, implement and maintain one. Most organisations read that sentence, build a spreadsheet with twelve rows in it, and call the job done. Then the certification body asks why the high-risk joint venture in a distant market has never been audited, while the stationery cupboard has been audited twice.<\/p>\n<p>This post is about the planning, not the auditing. How to decide what gets audited, how often, by whom, and how to show the programme was driven by bribery risk rather than by convenience.<\/p>\n<div class=\"ias-cta2\">\n<p><strong>Planning your first ABMS audit cycle?<\/strong> The two-day <a href=\"\/BH\/iso-37001-internal-auditor-training-in-bahrain\/\">ISO 37001 internal auditor training in Bahrain<\/a> covers programme design as well as audit technique, and the same team can talk you through <a href=\"\/BH\/iso-37001-certification-in-bahrain\/\">ISO 37001 certification<\/a> when you are ready.<\/p>\n<\/div>\n<h2>What demands does clause 9.2 place on you?<\/h2>\n<p>Strip the clause back and it wants three things. That internal audits happen at planned intervals. That they tell you whether the anti-bribery management system conforms both to your own requirements and to the standard, and is effectively implemented and maintained. And that there is a programme behind them, not a series of unconnected events.<\/p>\n<p>The word &#8220;programme&#8221; is doing real work. A programme has a shape: frequency, methods, responsibilities, planning requirements and reporting. It takes account of the importance of the processes concerned, changes affecting the organisation, and the results of previous audits. An audit schedule is a list of dates. A programme is an argument about where the risk sits, written down.<\/p>\n<p>Note the second half of the conformity test too. &#8220;Your own requirements&#8221; means your policy, your procedures, your due diligence thresholds, your gift and hospitality rules. Many internal audits only check the standard. They miss the more useful question: are we doing what we said we would do?<\/p>\n<h2>Why start from the bribery risk assessment, not the clause list?<\/h2>\n<p>The most common way to build a bad programme is to take the standard&#8217;s clause numbering and turn it into an audit calendar. January for clause 4, February for clause 5, and so on. It looks tidy. It tells you almost nothing.<\/p>\n<p>Bribery risk is not spread evenly across an organisation. It concentrates: around procurement, around agents and intermediaries, around sales into markets where deals are won through relationships, around anything involving cash or discretionary approvals. Your audit programme should be lumpy in the same places your risk assessment is lumpy.<\/p>\n<p>So the first input to planning is the bribery risk assessment. The second is the list of processes and business associates at the sharp end. The third is history \u2014 what previous audits found, what the reporting channel received, what due diligence flagged and what was waved through anyway. Risk assessment is a separate clause and a separate subject; here, treat it as the raw material you plan from.<\/p>\n<figure class=\"ias-fig\"><img loading=\"lazy\" src=\"https:\/\/iasiso-gulf.com\/BH\/wp-content\/uploads\/2026\/09\/iso-37001-blog-bh-fig1.jpg\" alt=\"ISO 37001 internal audit programme \u2014 weighing where audit effort should fall\" width=\"1000\" height=\"684\" loading=\"lazy\" decoding=\"async\" \/><\/figure>\n<h2>How do you cover all four directions of bribery?<\/h2>\n<p>ISO 37001 deals with bribery in four directions: by the organisation, by its own personnel acting on its behalf, by business associates acting for it, and bribery directed at the organisation. Programmes routinely cover the first two and forget the rest.<\/p>\n<p>Business associates are usually where the exposure is. Suppose a firm sells through regional distributors. They are not employees. They win tenders. Nobody in head office sees how. A programme that never reaches distributor due diligence, contract clauses, commission structures or the evidence behind a large &#8220;market development&#8221; payment is not auditing the real risk.<\/p>\n<p>Bribery directed at the organisation is hardest to plan for. It means someone offering an inducement to your procurement officer or tender evaluator. Auditing it means looking at declared gifts, at conflict-of-interest declarations, and at whether refusals ever get reported at all.<\/p>\n<h2>How do you defend the audit intervals you choose?<\/h2>\n<p>There is no required frequency in the standard. &#8220;Planned intervals&#8221; is deliberately open. That freedom is uncomfortable, so people default to &#8220;everything, once a year&#8221; \u2014 too much for low-risk areas and far too little for high-risk ones.<\/p>\n<p>A better approach is banding. Decide three or four risk bands, place each process or entity into one, and set a frequency per band. High-risk areas might be audited every six months. Medium-risk annually. Low-risk once per three-year cycle, or by sampling. What matters is that the banding is written down, traces back to the risk assessment, and can be explained without improvising.<\/p>\n<p>Then build in triggers. A programme should change when the organisation changes. New market entry, a significant acquisition, a new category of intermediary, a substantiated allegation, a senior departure from a control role \u2014 each should pull an audit forward. The 2025 edition puts mergers and acquisitions among the non-financial control areas under clause 8.4, and an acquisition is exactly the sort of event that should reopen a settled programme.<\/p>\n<h2>What does a weak programme look like beside a sound one?<\/h2>\n<div class=\"ias-tscroll\">\n<table class=\"ias-tw\">\n<thead>\n<tr>\n<th>Programme element<\/th>\n<th>Weak version<\/th>\n<th>Sound version<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td>Basis for scope<\/td>\n<td>Clause-by-clause calendar copied from the standard<\/td>\n<td>Derived from the bribery risk assessment, revisited when risk changes<\/td>\n<\/tr>\n<tr>\n<td>Coverage of business associates<\/td>\n<td>Out of scope; &#8220;they are not our staff&#8221;<\/td>\n<td>Agents, distributors and joint venture partners audited through due diligence files, contracts and payment evidence<\/td>\n<\/tr>\n<tr>\n<td>Frequency<\/td>\n<td>Everything once a year, same month each year<\/td>\n<td>Risk-banded intervals, plus documented triggers that pull audits forward<\/td>\n<\/tr>\n<tr>\n<td>Auditor selection<\/td>\n<td>Whoever is free that week<\/td>\n<td>Chosen for competence and objectivity, never auditing their own work<\/td>\n<\/tr>\n<tr>\n<td>Evidence gathered<\/td>\n<td>Confirms the procedure exists<\/td>\n<td>Tests whether it was followed, on named sampled transactions<\/td>\n<\/tr>\n<tr>\n<td>Findings<\/td>\n<td>Long list of minor documentation gaps<\/td>\n<td>Graded by consequence, each with a cause, an owner and a date<\/td>\n<\/tr>\n<tr>\n<td>Reporting<\/td>\n<td>Emailed to the process owner and filed<\/td>\n<td>Reported to the anti-bribery function and top management, feeding management review<\/td>\n<\/tr>\n<tr>\n<td>Programme review<\/td>\n<td>Never revisited until next year<\/td>\n<td>Reviewed against results; weak areas get more attention next cycle<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/div>\n<p>Mark honestly which column your programme lives in. Most sit somewhere between, and the useful work is finding the two or three rows where the gap is widest.<\/p>\n<h2>Who may audit what, and how do you keep objectivity?<\/h2>\n<p>Clause 9.2 requires that auditors do not audit their own work. Small organisations find that far tougher to deliver than the wording suggests. If the compliance officer wrote the due diligence procedure, trained people on it and approved the exceptions, that person cannot audit it credibly.<\/p>\n<p>Three workable answers. Cross-audit between functions, so finance audits procurement&#8217;s controls and procurement audits finance&#8217;s. Use a second site or a group function. Or bring in a competent external auditor where internal independence cannot be achieved \u2014 this is still your internal audit, not a certification audit.<\/p>\n<p>The 2025 edition states the anti-bribery function&#8217;s role and independence more clearly than the 2016 text did. That function often receives audit results, which makes it awkward for it to be the sole auditor of controls it owns. Separate the roles on paper before an external auditor separates them for you. A grid makes the overlaps obvious.<\/p>\n<div class=\"ias-tscroll\">\n<table class=\"ias-tw\">\n<thead>\n<tr>\n<th>Activity<\/th>\n<th>Top management<\/th>\n<th>Anti-bribery function<\/th>\n<th>Audit programme manager<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td>Setting programme objectives<\/td>\n<td>Approves and resources<\/td>\n<td>Advises on risk priorities<\/td>\n<td>Drafts and proposes<\/td>\n<\/tr>\n<tr>\n<td>Deciding scope and frequency<\/td>\n<td>Reviews for adequacy<\/td>\n<td>Confirms alignment with risk assessment<\/td>\n<td>Decides and documents<\/td>\n<\/tr>\n<tr>\n<td>Appointing auditors<\/td>\n<td>Not involved day to day<\/td>\n<td>Checks independence is real<\/td>\n<td>Selects on competence and objectivity<\/td>\n<\/tr>\n<tr>\n<td>Approving individual audit plans<\/td>\n<td>Not involved<\/td>\n<td>Consulted on sensitive scopes<\/td>\n<td>Approves<\/td>\n<\/tr>\n<tr>\n<td>Receiving audit results<\/td>\n<td>Receives summary and trends<\/td>\n<td>Receives all reports<\/td>\n<td>Compiles and distributes<\/td>\n<\/tr>\n<tr>\n<td>Correcting nonconformities<\/td>\n<td>Holds owners accountable<\/td>\n<td>Advises on root cause<\/td>\n<td>Tracks to closure<\/td>\n<\/tr>\n<tr>\n<td>Reviewing programme effectiveness<\/td>\n<td>Reviews at management review<\/td>\n<td>Comments on coverage gaps<\/td>\n<td>Prepares the evidence<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/div>\n<p>Adapt the column headings to your own structure. The point is that no single person should occupy the whole row.<\/p>\n<figure class=\"ias-fig\"><img loading=\"lazy\" src=\"https:\/\/iasiso-gulf.com\/BH\/wp-content\/uploads\/2026\/09\/iso-37001-blog-bh-fig2.jpg\" alt=\"ISO 37001 internal audit programme \u2014 reaching the transactions where value actually moves\" width=\"1000\" height=\"667\" loading=\"lazy\" decoding=\"async\" \/><\/figure>\n<h2>How does a planning decision work in practice?<\/h2>\n<p>Suppose a mid-sized engineering contractor in Bahrain has four business lines. Two sell to private clients on open tender. One works through three agents in neighbouring markets. One acquired a small maintenance firm last year.<\/p>\n<p>A clause-driven programme would audit &#8220;clause 8&#8221; once. A risk-driven one looks different. The agent-led line gets audited twice: once on due diligence and contract terms, once on commission payments and the evidence behind them. The acquired firm gets an early audit of whether its people, contracts and controls were actually absorbed into the ABMS, because integration after an acquisition is where controls quietly fail. The direct-sale lines get one audit each, focused on gifts and hospitality around tender periods. Central functions are sampled.<\/p>\n<p>That is seven audit events instead of twelve, and it will find more. Write the reasoning into the programme document, because in two years nobody will remember it.<\/p>\n<h2>How do you audit the 2025 additions?<\/h2>\n<p>ISO 37001:2025 was published in February 2025 and replaced the 2016 edition. If you certified against 2016, your programme has blind spots. The transition deadline for 2016 certificates is 28 February 2027, and the programme is one of the first places the change shows up.<\/p>\n<p>Several additions deserve their own scope lines. Clauses 4.1 and 4.2 now require climate change to be considered in context and in the needs of interested parties \u2014 the term &#8220;stakeholders&#8221; having become &#8220;interested parties&#8221; throughout. An explicit requirement for anti-bribery culture arrives with clause 5.1.3. Clause 7.2.2 adds conflict-of-interest awareness to employment processes, so recruitment, promotion and performance management sit inside audit scope in a way they may not have before. Clause 10 is reordered: 10.1 continual improvement, 10.2 nonconformity and corrective action.<\/p>\n<p>Culture is the hard one. You cannot sample a culture. You can test proxies: whether concerns raised were closed with a reason, whether anyone was penalised for losing business by refusing a demand, whether managers can describe the policy without reading it.<\/p>\n<h2>How is the audit actually done?<\/h2>\n<p>The programme should state methods, not just dates. Interviews, document review, transaction sampling, walkthroughs, remote review of systems \u2014 each suits different risks. Testing whether a gift register reflects reality means talking to people and cross-checking expense claims, not reading the register.<\/p>\n<p>Decide sampling in advance. &#8220;We reviewed a selection of payments&#8221; is a weak sentence. &#8220;We selected twelve payments above the approval threshold, across three business lines, and traced each to contract, invoice and approval&#8221; is auditable. The <a href=\"\/BH\/iso-audit-procedure\/\">ISO audit procedure overview<\/a> is a useful reference when setting conventions that will later face an external auditor.<\/p>\n<h2>How do you report findings and close the loop?<\/h2>\n<p>An audit whose report nobody acts on is worse than no audit. It creates a record of a known problem and no response to it.<\/p>\n<p>Grade findings by consequence, not by how annoyed the auditor was. A missing signature on a low-value form and an unvetted agent in a high-risk market are not both &#8220;minor&#8221;. Each finding needs a cause, an owner, an agreed action and a date. Corrective action under clause 10.2 means addressing the cause, not just the instance. Results feed management review and the next cycle of planning. If an area produces repeat findings, audit it more, not less.<\/p>\n<h2>Where does internal audit meet certification?<\/h2>\n<p>Internal audit is yours. Certification audit is not. IAS carries out ISO 37001 certification under UQAS accreditation, in two stages: stage 1 examines readiness and documentation, stage 2 whether the system works in practice. The certificate then runs on a three-year cycle with surveillance audits in between, then recertification. More detail sits on the <a href=\"\/BH\/certification-process\/\">certification process page<\/a> and the <a href=\"\/BH\/accreditation\/\">accreditation page<\/a>.<\/p>\n<p>At stage 2, your programme is itself evidence. External auditors look at coverage, at auditor independence, at whether findings were closed, and at whether the programme reflects your risk assessment. A thin programme raises doubts about everything else.<\/p>\n<p>Be clear about what a certificate is. It does not prove that no bribery has occurred or ever will. It records that a management system meeting the standard was found in place at the time of audit. It is not a clean bill of health, an endorsement, or a legal defence.<\/p>\n<div class=\"ias-band\">\n<ul>\n<li>Accredited certification through IAS<\/li>\n<li>UQAS-accredited scheme<\/li>\n<li>Training delivered separately from audit<\/li>\n<li>Classroom, live virtual and self-paced routes<\/li>\n<\/ul>\n<\/div>\n<h2>How do you build auditor competence?<\/h2>\n<p>You cannot staff a programme with people who have read the standard once. The <a href=\"https:\/\/onlinecourse.eascertification.com\/internal-auditor\/online-sl-iso-37001-training\/\" target=\"_blank\" rel=\"noopener\">ISO 37001 internal auditor course<\/a> runs two days, sixteen hours, and teaches you to audit your own organisation against the standard. It is available in the classroom or in-house, as <a href=\"https:\/\/onlinecourse.eascertification.com\/internal-auditor\/virtual-iso-37001-training\/\" target=\"_blank\" rel=\"noopener\">live virtual training<\/a>, or self-paced online with 30 days&#8217; access.<\/p>\n<p>If the need is understanding rather than auditing, the foundation course is half a day, four hours, self-paced online only, with 30 days&#8217; access. It will not qualify anyone to audit anything. To audit other organisations, the <a href=\"\/BH\/iso-37001-lead-auditor-training-in-bahrain\/\">lead auditor route<\/a> is five days and forty hours, with the same three delivery options. Assessment on both auditor courses runs through the course and ends in a written examination on the final day. No prior experience is required.<\/p>\n<p>IAS and EAS issue the certificates jointly, relying on the UQAS accreditation held by IAS, which reaches training schemes and not only certification. Trainers sit in one team and auditors in another, a split that impartiality demands rather than merely recommends. The same applies to <a href=\"\/BH\/internal-auditor-training\/\">internal auditor training across standards<\/a> and the wider <a href=\"\/BH\/iso-training\/\">ISO training catalogue<\/a>.<\/p>\n<figure class=\"ias-fig\"><img loading=\"lazy\" src=\"https:\/\/iasiso-gulf.com\/BH\/wp-content\/uploads\/2026\/09\/iso-37001-blog-bh-fig3.jpg\" alt=\"ISO 37001 internal audit programme \u2014 the moment an audit programme exists to detect\" width=\"1000\" height=\"561\" loading=\"lazy\" decoding=\"async\" \/><\/figure>\n<h2>Two things this post does not do<\/h2>\n<p>It makes no claim about the law in any country. Nothing here states or implies a legal duty; legal obligations are a matter for your own advisers, not for an article about a standard.<\/p>\n<p>And reading it, or completing any course described in it, does not make anyone an IAS auditor and confers no registration of any kind. Course certificates record attendance and assessment. They are not an appointment.<\/p>\n<div class=\"ias-cta2\">\n<p><strong>Ready to build a programme that holds up at stage 2?<\/strong> Talk to the team through the <a href=\"\/BH\/contact-us\/\">contact page<\/a>, browse <a href=\"\/BH\/iso-certification\/\">ISO certification services<\/a> and <a href=\"\/BH\/system-certification\/\">system certification<\/a>, or start on the <a href=\"https:\/\/onlinecourse.eascertification.com\/\" target=\"_blank\" rel=\"noopener\">online course platform<\/a>. Common queries are answered in the <a href=\"\/BH\/faq\/\">FAQ<\/a>.<\/p>\n<\/div>\n<section class=\"ias-faq-section\">\n<h2 class=\"ias-faq-title\">Frequently asked questions<\/h2>\n<details class=\"ias-faq-item\">\n<summary class=\"ias-faq-q\">How often must internal audits be carried out under clause 9.2?<\/summary>\n<div class=\"ias-faq-a\">\n<p>The standard says &#8220;planned intervals&#8221; and does not set a number. You choose the intervals and you justify them from bribery risk, process importance, changes in the organisation and previous audit results.<\/p>\n<\/div>\n<\/details>\n<details class=\"ias-faq-item\">\n<summary class=\"ias-faq-q\">Can one person audit the whole anti-bribery management system?<\/summary>\n<div class=\"ias-faq-a\">\n<p>Only if that person did not design or run the things being audited. In practice a single-auditor programme almost always breaches the objectivity requirement somewhere. Cross-auditing or an external internal auditor usually solves it.<\/p>\n<\/div>\n<\/details>\n<details class=\"ias-faq-item\">\n<summary class=\"ias-faq-q\">Does the internal audit programme have to cover suppliers and agents?<\/summary>\n<div class=\"ias-faq-a\">\n<p>It has to cover the controls you apply to them \u2014 due diligence, contract terms, payment evidence, monitoring. You are not auditing the agent&#8217;s own management system; you are auditing whether your controls over that relationship work.<\/p>\n<\/div>\n<\/details>\n<details class=\"ias-faq-item\">\n<summary class=\"ias-faq-q\">What records does clause 9.2 expect us to keep?<\/summary>\n<div class=\"ias-faq-a\">\n<p>Evidence that the programme was implemented, and the audit results. In practice: the programme document, audit plans, auditor appointments, working papers, reports and corrective actions through to closure.<\/p>\n<\/div>\n<\/details>\n<details class=\"ias-faq-item\">\n<summary class=\"ias-faq-q\">Under clause 5.1.3, what does auditing anti-bribery culture look like?<\/summary>\n<div class=\"ias-faq-a\">\n<p>Indirectly. Look at how concerns were handled, whether anyone was penalised for refusing business, whether leaders&#8217; decisions match the stated policy, and whether people can explain the rules in their own words.<\/p>\n<\/div>\n<\/details>\n<details class=\"ias-faq-item\">\n<summary class=\"ias-faq-q\">Can we use the same programme structure as our ISO 9001 audits?<\/summary>\n<div class=\"ias-faq-a\">\n<p>The mechanics transfer well, and many organisations run combined programmes alongside <a href=\"\/BH\/iso-9001-certification-in-bahrain\/\">ISO 9001 certification<\/a> or <a href=\"\/BH\/iso-27001-certification-in-bahrain\/\">ISO 27001<\/a>. The scoping logic does not transfer. Bribery risk concentrates differently from quality or information security risk.<\/p>\n<\/div>\n<\/details>\n<details class=\"ias-faq-item\">\n<summary class=\"ias-faq-q\">What is the most common weakness external auditors find in these programmes?<\/summary>\n<div class=\"ias-faq-a\">\n<p>Coverage that does not match the risk assessment, and findings raised but never closed. Both are visible from the documents alone.<\/p>\n<\/div>\n<\/details>\n<details class=\"ias-faq-item\">\n<summary class=\"ias-faq-q\">Where do we start if we have no programme at all?<\/summary>\n<div class=\"ias-faq-a\">\n<p>With the risk assessment and a one-page banding of processes and business associates. Frequency, methods and auditor assignment follow from that. Getting one or two people trained first is usually faster than drafting in the dark.<\/p>\n<p>*Written by the IAS Gulf editorial team for readers responsible for anti-bribery management systems.*<\/p>\n<\/div>\n<\/details>\n<\/section>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>An internal audit programme is the part of an anti-bribery management system that checks itself. Clause 9.2 of ISO 37001 asks you to plan, establish, implement and maintain one. Most organisations read that sentence, build a spreadsheet with twelve rows in it, and call the job done. Then the certification body asks why the high-risk&#8230; <\/p>\n<div class=\"clear\"><\/div>\n<p><a href=\"https:\/\/iasiso-gulf.com\/BH\/blog\/planning-an-internal-audit-programme-clause-9-2\/\" class=\"gdlr-button with-border excerpt-read-more\">Read More<\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[],"class_list":["post-6157","post","type-post","status-publish","format-standard","hentry","category-uncategorized"],"_links":{"self":[{"href":"https:\/\/iasiso-gulf.com\/BH\/wp-json\/wp\/v2\/posts\/6157","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/iasiso-gulf.com\/BH\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/iasiso-gulf.com\/BH\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/iasiso-gulf.com\/BH\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/iasiso-gulf.com\/BH\/wp-json\/wp\/v2\/comments?post=6157"}],"version-history":[{"count":0,"href":"https:\/\/iasiso-gulf.com\/BH\/wp-json\/wp\/v2\/posts\/6157\/revisions"}],"wp:attachment":[{"href":"https:\/\/iasiso-gulf.com\/BH\/wp-json\/wp\/v2\/media?parent=6157"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/iasiso-gulf.com\/BH\/wp-json\/wp\/v2\/categories?post=6157"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/iasiso-gulf.com\/BH\/wp-json\/wp\/v2\/tags?post=6157"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}