- Certificates issued by IAS under UQAS accreditation
- Written for teams of 30–200 people
- Current edition: ISO 37001:2025
- Two-stage audit, then annual surveillance
Most anti-bribery material assumes you have a compliance director, a legal team and a case management platform. Plenty of companies in Oman have none of those. They have an owner, a general manager, a finance lead, a few project managers and between thirty and two hundred staff. A client or a parent company has now asked whether they are certified, and the honest answer is not yet.
This page is for that company. It sets out what the standard genuinely requires at your size, what it does not, who can realistically hold the anti-bribery function, and how to avoid building a compliance machine you will quietly abandon in eighteen months. The standard expects this. It ties the depth of your controls to the bribery risk you actually face, not to a fixed template.
Written by the IAS technical team for applicants who will run the system themselves, not hand it to a department.
Start with a conversation, not a manual. Tell us your headcount, sectors and who asks you for evidence, and we'll describe the audit. Contact IAS in Oman, or read how certification works first.

Table of Contents
ToggleWhat does ISO 37001 certification in Oman require at thirty to two hundred people?
The international standard for an anti-bribery management system — an ABMS — is ISO 37001. Its logic will feel familiar if you already hold ISO 9001. You decide what you are trying to prevent, put controls in place, keep records showing the controls ran, and check whether they worked.
At your size the requirement list is the same as anyone else's. What differs is the scale of each answer. You still need a bribery risk assessment, an anti-bribery policy, an anti-bribery function with real authority, due diligence, financial and non-financial controls, rules and records for gifts, hospitality and donations, a way to raise concerns, protection for those who do, an investigation process, role-appropriate training, monitoring, internal audit and management review.
None of that has to be long. A risk assessment for a fifty-person trading company can be six pages. A policy can be two. The auditor is not measuring paper. They ask whether the controls match the risk, whether someone owns them, and whether they happened.
The most common mistake we see in ISO 37001 certification in Oman is not neglect but over-building: a downloaded framework built for a listed group, with regional compliance officers you do not employ and committees that never met. That fails faster than a thin but honest system, because the records will not match the document.
What are the four directions of bribery risk?
The standard is explicit that bribery runs in four directions, and every one of them applies to a small company.
- By the organisation itself — a payment made to win or keep work.
- By your own personnel, acting on your behalf, whether or not anyone senior knew.
- By business associates acting for you: agents, sponsors, brokers, freight forwarders, subcontractors, consultants.
- Directed at you — someone offering your buyer, your estimator or your site supervisor an inducement.
Smaller organisations focus on the first direction and forget the other three. In practice the third and fourth are where the exposure sits. A company of eighty people may use a dozen intermediaries it has never assessed, and one procurement officer with sole discretion over suppliers. That concentration exists precisely because the company is small.
The fourth direction matters commercially too. If your staff can be induced, your buyers are exposed through you. That is often the real reason a client is asking about certification.

What do the 2025 edition and the 2027 deadline mean for you?
ISO 37001:2025 was published in February 2025 and replaced ISO 37001:2016. Certificates issued against the 2016 edition run to a transition deadline of 28 February 2027. Certifying for the first time is simple: you go straight to the 2025 edition and the deadline does not concern you. If you hold a 2016 certificate, fold the transition into a surveillance or recertification visit rather than running it as a separate project.
The changes are real but modest, and most make the standard easier to apply at small scale.
| What the 2025 edition changed | Why | What a 30–200 person company does about it |
|---|---|---|
| Structure now follows the common ISO format | Alignment with ISO 9001 and the rest | Hold another certificate? Map the shared clauses once and reuse them |
| "Stakeholders" became "interested parties" | Consistent ISO wording | A terminology sweep of your policy and context note. An hour's work |
| Clauses 4.1 and 4.2 require climate change to be considered | Carried in from the 2024 amendment | A short, honest paragraph in your context note: what is relevant, what is not |
| Clause 5.1.3 makes anti-bribery culture explicit | Behaviour, not just documents | Your easiest win. Leadership is visible in a small firm — record what it does |
| Clause 7.2.2 adds conflict-of-interest awareness to employment processes | Conflicts drive real bribery | A declaration step in hiring and annual reviews. Keep the forms |
| The anti-bribery function's role and independence are clearer | Ambiguity in the 2016 text | Name the person, write down their authority, give them a route to the top |
| Clause 8.4 adds mergers and acquisitions as a non-financial control area | Deals inherit other people's problems | Never acquire anything? Say so. If you might, define the check now |
| Clause 10 reordered: improvement at 10.1, nonconformity and corrective action at 10.2 | Improvement leads, correction follows | A numbering change in your procedure. No new work |

Who holds the anti-bribery function when nobody's title says compliance?
This is the question that stops most small applicants, so here is a direct answer. The standard requires an anti-bribery function with authority and independence. It does not require a full-time compliance officer, a department, or a particular job title.
An existing employee can hold it, provided three things are true. They can look at anything relevant. They can reach top management or the governing body directly, without passing through the person whose conduct might be in question. And they do not review their own decisions.
That last condition rules out some obvious candidates. The head of sales is a poor choice, because sales is where much of the risk sits. A finance manager works for financial controls but is awkward if procurement reports to them. At this size the role often lands with a quality or HSE manager who already runs ISO 9001, an operations director with no revenue target, or the company secretary. An external adviser can support the role, but someone inside must own it.
Write the appointment down. One page: who holds it, what they can access, who they report to, and what happens if the report concerns their own line manager. Auditors ask about that escape route more often than about the job description.
How do you size the bribery risk assessment to the work you actually win?
The bribery risk assessment is the foundation. Every other control should be traceable back to it. It is also where over-building starts, so keep it anchored to real work.
Start from your revenue. List how you win business, by route: direct tender, repeat client, agent, distributor, framework, subcontract. For each route, ask who has discretion and what an inducement would look like in practice. Then do the same for spending: procurement, logistics, recruitment, and any point where a third party can slow you down.
Score it however you like, as long as you are consistent. High, medium and low is fine. The auditor checks whether high-risk items have controls attached and whether low-risk ones have a reason recorded.
Two things matter at your size. Concentration is a risk in itself: one person holding both approval and payment is a finding, whatever the sums. And an agent paid on commission for winning large contracts is almost always high risk.
Review the assessment yearly, and whenever something changes. New country, new agent, new sector, new major client: each is a trigger.
What is the proportionate version of each requirement?
Here is the requirement list translated: the standard, what it reasonably looks like at thirty to two hundred people, and what an auditor will ask to see.
| Requirement area | Proportionate version at your size | Evidence the auditor looks for |
|---|---|---|
| Bribery risk assessment | Six to twelve pages, by revenue route and spend category | The document, the scoring logic, dated review records |
| Anti-bribery policy | Two plain-language pages, signed at the top | The policy, plus proof it reached staff and business associates |
| Anti-bribery function | One named person, written authority, direct reporting line | Appointment record, and evidence the line has been used |
| Leadership and culture (5.1.3) | Standing management-meeting item; visible response to concerns | Minutes, internal messages, how a real incident was handled |
| Due diligence | Tiered: light for low risk, documented for agents and high-risk partners | Completed checks for named third parties, not a blank template |
| Financial controls | Approval split from payment; thresholds; no cash facilitation | Approval matrix, sample transactions, exception records |
| Non-financial controls, incl. M&A (8.4) | Supplier selection and contracting rules; a defined pre-acquisition check | Contract clauses, tender files, the M&A check if used |
| Gifts, hospitality, donations | A clear threshold, a register, and the habit of using it | The register, with entries that look like real business life |
| Raising concerns | A route around line management, plus a stated protection commitment | The channel, the protection wording, any reports received |
| Investigation | A short procedure naming who investigates and who is excluded | The procedure, and the file for any case that arose |
| Training, incl. conflicts (7.2.2) | Short role-specific sessions; more for sales, procurement, finance | Attendance records, materials, conflict declarations |
| Monitoring, internal audit, management review | One annual internal audit, one documented review | Audit report, review minutes, actions with owners and dates |
If you have run an internal audit under another standard, the mechanics carry over. Our ISO audit procedure note covers the approach, and internal auditor training exists if nobody has done it.
What does ISO 37001 certification in Oman not require you to build?
It is worth being equally clear about the things people assume are compulsory and are not.
- A compliance department. Not required, not implied. One competent person with authority is enough at this size.
- A commercial whistleblowing platform. A monitored external address or an independent line can satisfy the requirement, provided it genuinely bypasses line management.
- Background screening on every supplier. Due diligence is risk-based. Treating a stationery supplier and a commission agent identically suggests you have not thought about risk at all.
- A separate manual for every clause. Applicants often produce fourteen documents where four would do. Fewer, shorter documents audit better.
- Software. Spreadsheets and a shared folder are fine if they are controlled and current.
- Certifying the whole group. Scope can sit around a legal entity, a site or a business line, as long as the boundary is stated honestly.
Cutting the system down to what you can run is not a compromise. It is the correct reading of the standard.
Which three controls carry most of the weight?
If you only get three things right in year one, make them these.
Gifts and hospitality. Set a threshold that fits your market, then register everything above it — offered, given, received and declined. An empty register in a business that entertains clients is not evidence of restraint. It is evidence the register is not used.
Due diligence on business associates. Tier it. Most suppliers need a basic check. Agents, sponsors, consultants and anyone paid on success need more: ownership, how they are paid, and whether the fee makes commercial sense. Put anti-bribery clauses and a right to terminate into the contract.
Raising concerns. In a company of eighty people, everyone knows who reported what. Pretending otherwise fails. Give people a route that does not go through their manager, name a recipient outside their reporting line, and say plainly what protection means. Then protect anyone who uses it, visibly. Culture under clause 5.1.3 is judged on that moment, not on a poster.
How does the audit cycle run, from application to recertification?
The route is the same for every applicant, whatever the size.
1. Application and review. You describe your organisation, headcount, sites, sectors and scope. We confirm what the audit must cover.
2. Stage 1. A readiness review of your risk assessment, policy, function appointment and core records. Small applicants get most of their value here.
3. Stage 2. The main audit. We test whether the controls operate, by sampling records and interviewing the people who do the work — not only whoever wrote the documents.
4. Findings and closure. Nonconformities are raised with a stated basis in the standard. You correct them and show evidence.
5. Certificate. Issued by IAS under its UQAS accreditation.
6. Surveillance. Annual checks that the system is still running.
7. Recertification. A fuller audit at the end of the cycle.
Stage 1 is not a formality. For a company with no compliance history, it is the cheapest correction you will ever get. Issued certificates can be confirmed through the IAS certificate search.
What does the certificate prove, and what does it not?
This deserves saying plainly, because it is the point clients most often get wrong.
A certificate against ISO 37001 does not prove that no bribery has occurred in your organisation. It does not prove that none will occur. The standard says as much about itself. Certification shows that an independent certification body examined your anti-bribery management system against the requirements and found it in place and operating at the time of audit.
That is a genuine claim and a useful one. It is not a clean bill of health. If a client asks whether your certificate means their supply chain is bribery-free, the correct answer is no, followed by what it does mean.
The same applies to accreditation. IAS is accredited by UQAS as a certification body. You end up certified. You do not end up accredited. The distinction shows up in tender responses more often than you would expect. Our accreditation page explains the relationship, with further background on the IAS accreditation page. Mark usage is governed by the logo usage guideline.
Where do smaller applicants lose the most time?
Patterns repeat. These cost applicants of your size the most weeks.
Writing the manual before the risk assessment. The documents then describe a system nobody designed. Do the risk assessment first, roughly if need be, and let it drive the writing.
Downloading a framework built for a multinational. It arrives with regional officers, tiered committees and a case workflow. None of it exists in your company, and every reference becomes a finding at stage 2.
Leaving the anti-bribery function unappointed. Applicants arrive at stage 1 with a full document set and nobody named. The appointment takes an afternoon and blocks everything until done.
Registers that start on audit day. A gifts register with three entries, all dated last week, tells the auditor exactly what happened. Start it early.
Confusing scope with ambition. Certifying every group entity from a standing start is a long project. One entity done properly, then extended, is usually faster.
No evidence of leadership. Culture is explicit at 5.1.3, and in a small firm it is easy to show and easy to forget. Put anti-bribery on a management agenda and keep the minutes.
What are the fees and hours, and where does training fit?
We do not publish prices here, because an honest figure depends on your headcount, sites, countries, business associates and existing certifications. A fifty-person consultancy with direct clients and a fifty-person contractor working through agents in three markets are not the same audit. Ask, and you get a number tied to your scope.
The cost that surprises people is internal hours, not fees. Most of the first-cycle effort sits with the person holding the anti-bribery function, plus finance and whoever manages third parties. Existing certification reduces it noticeably, because context, internal audit, management review and document control already run. Companies holding ISO 9001 certification in Oman find the shared clauses transfer with light editing, and the same applies to ISO 27001, ISO 45001, ISO 14001 and ISO 22301. Related updates, including the ISO 9001 2026 revision, sit on our blog.
Training is separate work by separate people. Where needed, it is delivered by IAS and EAS together, under the same UQAS accreditation, by a team that is not the audit team. That separation is deliberate. Training does not shorten your audit, pre-approve your system, or amount to certification. Options include ISO training and the EAS online courses. At your size, sending one person to a solid internal auditor course beats training everyone.
How this page was checked
Every factual statement here comes from the requirements of ISO 37001:2025 and from how IAS runs audits. The edition date, the February 2027 deadline and the clause changes above are drawn from the standard itself. The audit sequence is the one we operate.
This page takes no position on legal obligation. Nothing here says or implies that ISO 37001 is required by any statute, decree, regulator, ministry or government body in Oman, or that certification satisfies any legal obligation. No authority is named and none is implied. Where the page refers to pressure to certify, that pressure is commercial: tender conditions, buyer requirements, partner expectations, parent-company policy.
Nothing here is legal advice. If you need to know how anti-bribery obligations apply to your business, ask a qualified adviser in the relevant jurisdiction. We audit management systems; that is the boundary of what we do. No prices, audit durations, client counts or case studies appear anywhere on this page, because those depend on your scope and we will not invent them.
Your next step
If a client has asked the question and you are starting from nothing, the order is straightforward. Appoint the anti-bribery function this month. Draft a rough risk assessment by revenue route. Open the gifts register now, so it has history by the time we visit. Then book stage 1 and let it tell you what is missing while correction is still cheap.
You can read more about us on the about us page, browse the full range of ISO certification services, or look at system certification. General questions are answered on our FAQ page, and the Oman home page lists everything we cover in this market.
Get a scope-based quotation for ISO 37001 certification in Oman. Send us your headcount, sites, sectors and the third parties you rely on. We'll come back with what the audit covers and what it takes. Contact IAS in Oman — and if you'd rather start by understanding the audit, read the certification process.
Frequently asked questions
We have sixty staff and no compliance officer. Can we still certify?
Yes. The standard requires an anti-bribery function, not a department. One suitable employee with written authority and a direct line to top management satisfies it.
Can our finance manager hold it?
Often, but check the reporting lines. If procurement or payments report to them, they review their own decisions, and that gap gets raised at audit.
Is ISO 37001 certification in Oman legally required?
Nothing here interprets the law of Oman or anywhere else. The demand we see comes from tenders, clients, partners and parent companies — commercial pressure, not legal.
Do we need whistleblowing software?
No. A monitored external address or an independent line works, provided it bypasses line management and people trust it.
How do you protect a whistleblower when everyone knows everyone?
You cannot promise anonymity in a small team, so do not. Promise protection, name a recipient outside the person's reporting line, and act visibly when someone uses it.
We're already certified to ISO 9001. Does that help?
Considerably. The 2025 edition uses the common ISO structure, so context, leadership, internal audit, management review and improvement largely carry across.
Does certification make us accredited?
No. IAS holds accreditation from UQAS as a certification body. Your organisation becomes certified. The two words are not interchangeable in a tender response.
Can we certify one entity rather than the whole group?
Yes, provided the scope boundary is clear and honest. Many smaller groups certify one entity first and extend later.