Management Review Under ISO 37001 Clause 9.3: What Belongs on the Table
Reviewing your ABMS this quarter? See how the review feeds a certification decision on ISO 37001 certification in Kuwait, or talk it through with the team through the contact page.
Management review is the clause most often treated as a formality. Somebody builds a deck, top management nods, the minutes say “no issues raised”, and the file closes for another year. Then an auditor asks a simple question — what did you decide, and what changed because of it — and the whole thing falls apart.
Clause 9.3 of ISO 37001 is not a meeting. It is a decision point, where the people who control money, headcount and contracts look at the evidence and say what happens next. Everything else in the standard produces information. Clause 9.3 is where that information becomes action, or is shown to have gone nowhere.
This post sets out what belongs on the table, who has to be in the room, what a weak review looks like beside a strong one, and what an auditor will ask to see.
What is the two-layer review that trips people up?
ISO 37001 is unusual among management system standards. Most ask top management to review the system. ISO 37001 asks for two reviews at two levels.
Top management reviews the anti-bribery management system at planned intervals. That is the familiar part. The standard also expects the governing body — the board, or whatever body sits above top management — to review the system at planned intervals and to receive the results of the management review.
This is deliberate. Bribery risk is frequently a risk top management itself creates, tolerates or ignores. A sales director under pressure to hit a number is not a neutral reviewer of the controls on agents’ commissions. So the standard builds in a layer above.
Trouble here usually takes one of two forms. Either there is no governing body distinct from top management — common in an owner-managed business — and nobody has documented that fact. Or a board exists, gets a one-line mention in board minutes, and there is no evidence it received anything of substance. Neither is fatal, but both need handling openly. Where no separate governing body exists, say so in your ABMS documentation and explain how independence is preserved by other means.
Why is “planned intervals” not a synonym for “annually”?
The standard says planned intervals. It does not say once a year. Once a year is simply the default most organisations settle on, and for a stable business with a modest risk profile that can be perfectly defensible.
It is less defensible when the business has changed. Suppose a contractor opens operations in three new markets during the year, appoints a dozen new intermediaries, and completes an acquisition. Waiting eleven months to review the anti-bribery implications of that is a weak answer, and auditors say so.
A practical approach is to set a baseline interval — annual for the full review — and define triggers that pull an extra review forward: a substantiated bribery allegation, a significant acquisition, a change in the leadership responsible for a high-risk region, or entry into a country the risk assessment had not covered. Write the triggers down.

What has to be on the management review agenda?
Clause 9.3 lists what the review must consider. Reading the list is easy. Producing evidence for each line is where the work sits.
Status of actions from previous reviews. The single most common failure. Last year’s review generated six actions. This year’s pack does not mention them. An auditor will ask what happened to action three, and silence is a nonconformity waiting to be written.
Changes in external and internal issues relevant to the ABMS. Clause 4.1 territory brought into the review: new markets, new products, joint ventures, restructuring, a change in the ownership of a major customer. The 2025 edition also requires climate change to be considered in clauses 4.1 and 4.2 where relevant — for an anti-bribery system that usually surfaces as permitting, carbon reporting or green financing, each with its own bribery exposure.
Information on ABMS performance. Break this down rather than leaving it as one line. It covers nonconformities and corrective actions, monitoring and measurement results, audit results, the nature and extent of bribery risks, and reports of actual or suspected bribery and how they were handled.
The effectiveness of actions taken on risks. Not whether actions were completed — whether they worked. A due diligence procedure everybody follows but which has never once produced a “do not proceed” outcome deserves a hard question.
Opportunities for continual improvement. Clause 10 was reordered in the 2025 edition so 10.1 is continual improvement and 10.2 is nonconformity and corrective action. Improvement is not a residue of problems; it is a standing item.
Which two inputs did the 2025 edition make harder to skip?
The 2025 edition sharpened two areas that now show up in reviews far more visibly.
Anti-bribery culture. Clause 5.1.3 makes culture an explicit requirement rather than an implication, so a review with nothing to say about culture is incomplete. That does not mean inventing a score. It means bringing what you genuinely have: themes from the raising-concerns channel, what internal audit heard in interviews, whether people in high-pressure roles believe they can refuse a demand and still keep their targets.
Mergers and acquisitions. Clause 8.4 adds M&A as a non-financial control area. If the organisation acquired, divested or entered a joint venture in the period, the review should cover the anti-bribery due diligence done before the deal, what was inherited, and the integration plan. A quiet acquisition the ABMS never noticed is a serious finding.
What does a weak review look like beside a strong one?
Here is the comparison as auditors tend to see it.
| Input area | What a weak review shows | What a strong review shows |
|---|---|---|
| Previous actions | “All actions closed” with no list | Each action named, owner, evidence of effect, three still open with revised dates |
| Bribery risk | Risk register attached, unchanged from last year | Which risks moved, why, and which two controls were changed as a result |
| Reported concerns | “No reports received” | Report volume, themes, outcomes, plus a question about why volume is low |
| Due diligence | Count of screenings completed | Screenings by risk tier, exceptions approved, one relationship declined and why |
| Internal audit | Audit report filed | Findings by clause, repeat findings flagged, the two that top management disagreed with |
| Training | Completion percentage | Who has not completed it, whether high-risk roles had role-specific content |
| Business associates | “No changes” | New intermediaries onboarded, contract clauses used, one agent terminated |
| Outputs | “Noted” | Six dated decisions with owners and resources committed |
The difference is not effort in the room. It is preparation before it. A strong pack is assembled over weeks by the anti-bribery compliance function and the process owners. A weak one is written the night before by a single person copying last year’s file.
Why are the outputs where clause 9.3 is judged?
An auditor spends far less time on your agenda than on what came out of it. The standard expects the review to produce decisions on continual improvement, on any need for change to the ABMS, and on resources.
Resources is the honest test. If a review concludes that third-party due diligence is under-resourced and then commits nothing, it has recorded a problem and declined to act on it. Auditors notice that gap.
Write outputs as decisions, not observations. “Third-party due diligence backlog discussed” is an observation. “Two additional analysts approved for Q2; backlog cleared by 30 June; Head of Compliance accountable” is a decision. Only the second gives you anything to review next time.
Who is responsible for what?
Confusion about roles is the second-biggest source of weak reviews. The anti-bribery compliance function prepares and reports. It does not own the decisions.
| Role | Owns | Does not own |
|---|---|---|
| Governing body | Reviewing the ABMS at planned intervals; receiving review results | Day-to-day operation of the system |
| Top management | The review itself; decisions on change and resources | Preparing the evidence pack alone |
| Anti-bribery compliance function | Compiling inputs, reporting performance and bribery matters, advising | Approving resources or accepting risk |
| Process owners | Data for their area, actions assigned to them | Deciding what the review concludes |
| Internal audit | Independent findings feeding the review | Closing its own findings |
Compared with the 2016 text, the 2025 edition spells out the role and the independence of the anti-bribery function in plainer terms. That independence matters at review time. If the person compiling the pack reports to somebody whose area the pack criticises, the review is compromised before it starts. Training that role properly matters — this is one reason organisations send that person through ISO 37001 internal auditor training in Kuwait rather than leaving them to learn from the standard alone.

What records will the auditor ask for?
Clause 9.3 requires documented information as evidence of the results of management review. In practice, expect an auditor to ask for four things.
- The agenda or input pack, showing every required input was considered.
- The attendance record, showing top management was present rather than represented by delegates.
- The decisions, with owners and dates.
- Evidence the governing body received the results, dated.
A minute saying “the ABMS was reviewed and found effective” satisfies none of these. The usual fix is simple: stop writing minutes as narrative and write them as a table of decisions.
If the ABMS is integrated with other systems — many organisations in Kuwait run it alongside ISO 9001 certification or ISO 27001 certification — a combined review is allowed. The anti-bribery content must stay identifiable. Minutes where bribery appears once under “any other business” will not pass.
Where does the review sit in a certification audit?
Certification is delivered by IAS, accredited by UQAS, and runs in two stages. Stage 1 examines readiness and documentation, which is where an auditor first checks whether a management review has actually taken place and what it covered. Stage 2 looks at the system operating in practice, and the review is re-examined against real evidence: did those decisions happen, did the resources arrive, did the risks move.
After certification the cycle runs three years with surveillance audits in between, then recertification. Every surveillance visit looks at the most recent review, so one good review followed by two thin ones is visible immediately.
What the certificate means is worth restating. What it states is that, on the date of the audit, a management system conforming to the standard was found to be in place. It does not prove that no bribery has occurred or will occur, and it is not an endorsement or a legal defence. The ISO audit procedure page sets out how the stages run, and the accreditation page explains the basis on which certificates are issued.
- Two-stage certification audit
- Three-year cycle with surveillance
- IAS certification under UQAS accreditation
- Training team kept separate from the audit team
How do you use the review to plan the 2025 transition?
Published in February 2025, ISO 37001:2025 took the place of the 2016 edition. Certificates issued to the 2016 text run to a transition deadline of 28 February 2027. If your organisation is still on 2016, the management review is the correct place to own that.
The transition brought the harmonized structure, replaced “stakeholders” with “interested parties”, added climate change consideration to clauses 4.1 and 4.2, made culture explicit in 5.1.3, added conflict-of-interest awareness to employment processes under 7.2.2, clarified the anti-bribery function’s role and independence, brought M&A into clause 8.4, and reordered clause 10.
None of that changes overnight. Put the gap analysis, the owner and the target date into the review outputs, and the transition stops being a scramble in late 2026.
How do you build the competence to run the review well?
A review is only as good as the people preparing it. Three routes are commonly used.
Running four hours — half a day — the Foundation course comes in one format only, self-paced online, and access lasts 30 days. It teaches you to understand the standard. It does not qualify anyone to audit anything, and it is a sensible starting point for a director who will chair the review but does not need audit skills.
The internal auditor course is two days, sixteen hours, available as classroom or in-house, live virtual, or self-paced online with 30 days’ access. It teaches you to audit your own organisation against the standard — the skill that produces a review pack worth reading. The self-paced ISO 37001 internal auditor course and the live virtual option both sit on the online course platform.
The lead auditor course is five days, forty hours, through the same three routes, and teaches you to audit other organisations. On each of the two auditor courses you are assessed continuously as the course proceeds, and a written examination closes the last day. No prior experience is required. IAS and EAS issue the certificates jointly, on the basis of the UQAS accreditation held by IAS, which extends to training schemes and not only to certification. The training team is kept separate from the audit team — an impartiality requirement, not a preference.
Details sit on the ISO 37001 lead auditor training in Kuwait page and in the full ISO training catalogue.
Reading this post and completing a course does not make anyone an IAS auditor. Neither confers registration of any kind.

A note on law
Nothing written here asserts anything about Kuwaiti law, or about the law of any other country. What ISO 37001 offers is an international standard for anti-bribery management systems, and adopting it is voluntary. Legal duties, and how they apply to your organisation, are a matter for your own legal advisers.
Ready to make the next review count? Start with ISO 37001 certification, read the system certification overview, or browse all ISO certification services.
Frequently asked questions
How often does ISO 37001 require a management review?
At planned intervals. The standard does not name a frequency. Annual is the common baseline, with additional reviews triggered by significant change.
Who must attend the management review?
Top management. Delegates attending in place of top management is one of the most frequent findings. The governing body reviews separately and receives the results.
What if we have no governing body?
Many organisations do not have one distinct from top management. Document that, explain how independence and oversight are maintained instead, and be ready to discuss it at audit.
Can we combine the ISO 37001 review with our ISO 9001 review?
Yes. Combined reviews are allowed. The anti-bribery inputs, discussion and decisions must remain clearly identifiable in the record.
Is a slide deck enough evidence?
Rarely on its own. A deck shows what was presented, not what was decided. Pair it with a decision record.
Our review found no issues. Is that a problem?
It invites scrutiny. A system reporting zero concerns, zero nonconformities and zero declined third parties usually means the detection is weak, not that the risk is absent. Say so in the review.
Does the anti-bribery compliance function chair the review?
No. It prepares inputs, reports on performance and bribery matters, and advises. Top management chairs and decides.
Does certification prove we have no bribery?
No. All it records is that, when the audit took place, a management system conforming to the standard was found to be in place. Nothing more.