+971528732160
+971528732160
enquiry@iascertification.com

24 Sep 2026

Documented Information Under ISO 37001: The Records Your Anti-Bribery System Has to Keep

/
Posted By
/
Comments0

Planning an ISO 37001 audit? Stage 1 is largely a documentation review. See how ISO 37001 certification in Oman works before you build your evidence file.

Most anti-bribery systems fail their first audit on paper, not on principle. The policy exists. The tone from the top is genuine. But when the auditor asks for the due diligence file on a particular agent, or the record of who approved a gift last quarter, the room goes quiet.

ISO 37001 is the international standard for anti-bribery management systems, and like every management system standard it runs on evidence. “Documented information” is the term it uses. This post sets out what the standard expects you to keep, what auditors actually ask for, and where organisations come unstuck.

What does documented information mean in ISO 37001?

The phrase replaced the older split between “documents” and “records”. It covers both, and the standard signals which it means with two verbs.

Maintain means keep it current. It points at things that tell people how the system works: the policy, procedures, the scope statement, the risk criteria. If one is out of date, it is a nonconformity, even if it was perfect when written.

Retain means keep it as proof that something happened. Training completion, a due diligence outcome, a management review minute, an audit report. You do not update a retained record. You file it, protect it and produce it when asked.

Get this right and half your documentation problems disappear. A procedure “signed off” three times in three years and never revised is a maintained document that nobody maintained.

Which records does ISO 37001 name directly?

Certain clauses say plainly that documented information must be kept. Others imply it so strongly that no auditor will accept its absence. The table below covers the core set.

AreaWhat you keepMaintain or retainWhat the auditor tends to ask
Context and interested partiesInternal and external issues, including climate change; interested parties and their requirementsMaintain“When did you last review this, and what changed?”
Scope and policyWritten scope covering sites and activities; the policy and evidence it was communicatedBoth“Show me that your agents received it.”
Bribery risk assessmentMethod, criteria, the output and review datesBoth“Show me the version in force before this contract was signed.”
Due diligenceAssessments of personnel in exposed roles, projects and business associatesRetain“Show me the file for this third party.”
Competence and awarenessTraining records, awareness activity, conflict-of-interest declarationsRetain“Who was trained, on what, and when?”
ControlsGifts and hospitality approvals, donations, sponsorships, financial and non-financial controlsRetain“Show me an approval that was refused.”
Raising concerns and investigationsReports received, how they were handled, case outcomesRetain“How is confidentiality preserved here?”
Internal auditProgramme, reports, findings, follow-upRetain“Show me the audit of the anti-bribery function itself.”
Management review and corrective actionInputs, minutes, decisions with owners; nonconformities and their verified fixesRetain“Did you check whether the fix worked?”

That is the backbone. Everything else is supporting detail your own processes generate.

ISO 37001 documented information — the transaction that leaves no record

What does the climate change addition mean for context records?

Clauses 4.1 and 4.2 ask you to record the issues affecting your anti-bribery system and the parties with a stake in it. ISO 37001:2025, published in February 2025, added a requirement here: climate change must be considered as a potentially relevant issue.

The point is not to write an environmental policy. It is to ask whether climate-driven change alters your bribery exposure. Suppose an organisation starts bidding for coastal infrastructure work funded by a new adaptation programme, using unfamiliar intermediaries in a hurry. That is a changed risk picture, and your context record should show you noticed.

The 2025 edition also replaced “stakeholders” with “interested parties”. If your documents still say stakeholders, nothing breaks — but a document set untouched since 2016 tells an auditor how alive the system is.

Why are due diligence files the most examined record set?

If an auditor asks for one thing, it will be a due diligence file. This is where the paperwork most often thins out.

A due diligence record needs to show three things: what you checked, what you found, and what you decided to do about it. The third is the one people skip. A file full of screening printouts with no conclusion is raw material, not a record.

Keep the file at the level of the relationship, not the transaction. One folder per business associate: the assessment, the risk rating, any enhanced checks, the approval, the contract clauses relied on, and the next review date. When the relationship changes — new country, new scope, new owner — the file should show a fresh look. The same applies to personnel in exposed roles and to projects, and the personnel side is regularly forgotten.

Why are refusals better records than approvals?

Gifts, hospitality, donations and sponsorship registers are the easiest records to keep and the easiest to keep badly. A register with fifty approvals and zero refusals is not evidence of a working control. It is evidence of a rubber stamp.

Keep the request, the reason, the value, the decision, the decision-maker and the date. Keep the declined ones and the escalated ones. Those entries carry more weight than a hundred routine approvals.

Clause 8.4 in the 2025 edition made mergers and acquisitions an explicit non-financial control area. If you acquire a business, expect to be asked for the pre-deal anti-bribery due diligence and the post-deal integration plan. That paperwork often sits with legal and never reaches the management system.

What records cover competence, awareness and conflict of interest?

Training records are straightforward: who, what, when, and how you judged the training effective. Attendance alone is thin. A short assessment, a signed acknowledgement, or a manager’s confirmation of applied behaviour all strengthen it.

Clause 7.2.2 in the 2025 edition added conflict-of-interest awareness to employment processes. The record set now extends into recruitment and onboarding: the declaration a new hire makes, the periodic re-declaration, and what happened when somebody declared something real.

Broad awareness across the workforce and deeper competence in the audit team are different things. Our ISO training programmes cover both, and the internal auditor training pathway explains the step up.

How do you protect whistleblowers and still retain the records?

This is the hardest record set to design. You must retain enough to prove the process worked, while protecting anyone who reported in confidence.

Split the file. Keep a case record with a reference number, dates, category, actions and outcome, available to those who need it. Keep identity and contact details in a separate, tightly restricted store, linked only by the reference. Log who accessed what and when.

Auditors will not read the substance of a live investigation. They want to see that a documented route exists, that reports are logged, that decisions are recorded by somebody with authority, and that protection from retaliation is more than a policy sentence.

What records must the anti-bribery function keep?

The 2025 edition states the anti-bribery function’s role and independence more clearly than its predecessor. Your documented information should back that up.

Keep the appointment record, the defined authority, the reporting line to top management or the governing body, and — the one that gets missed — the record of that reporting actually happening. A function that reports to the board “as required”, with no minutes showing it did, has independence on paper only.

Clause 5.1.3 also makes anti-bribery culture an explicit requirement. Culture is hard to evidence, but not impossible. Leadership communications, decisions where commercial opportunity was declined on integrity grounds, and consistency of disciplinary outcomes are all legitimate records.

ISO 37001 documented information — gifts and hospitality registers exist for this

What does a good record set look like, and what does a weak one?

RecordWeak versionStrong version
Risk assessmentOne spreadsheet, undated, “reviewed annually” with no evidence of reviewVersioned, dated, shows what changed and why, references specific countries and intermediaries
Due diligence fileScreening printouts, no conclusion, no approverFindings, risk rating, decision, approver, contract controls relied on, review date
Training recordAttendance list from a single session in 2023Role-based matrix, completion dates, effectiveness check, refresher schedule
Gift registerApprovals only, all identical, one approverRequests, decisions including refusals, values, escalations, periodic analysis
Internal auditOne report covering “compliance” generallyProgramme covering every ABMS clause including the function itself, findings with owners and closure evidence
Corrective action“Staff reminded”Cause analysis, action, verification that the cause is gone

Mark your own system honestly. The gap between the columns is your audit preparation plan.

How do auditors test your record controls?

Keeping records is one requirement. Controlling them is another. The standard expects documented information to be identifiable, available where needed, adequately protected, and controlled for distribution, access, retrieval, storage, version and retention.

Four practical tests:

  • Can you find it? If producing a 2024 due diligence file takes three days and four emails, retrieval has failed.
  • Is access right? Sensitive files should be restricted. Policies should not be.
  • Is the version clear? Two versions of a procedure in circulation is a common and avoidable finding.
  • Do you know when to dispose? Write a retention schedule and follow it. Keeping everything forever is not a policy, and neither is deleting when storage fills up.

External documents count too: codes of conduct you have signed, client anti-bribery clauses, questionnaires you have returned.

Certification through IAS runs in two stages. Stage 1 examines readiness and documentation: whether the required documents exist, cover the right scope, and are internally consistent. Stage 2 examines the system working in practice. There the auditor samples — a contract, a supplier, a month of the gift register, an employee — and follows the trail to see whether the documented process is what actually happened.

Certificates then run on a three-year cycle, with surveillance audits between and recertification at the end. Surveillance looks at records accumulated during the cycle, so a system that produces evidence only in audit season is quickly visible. The certification process and ISO audit procedure pages set out the sequence, and the accreditation page explains the UQAS position behind it.

What does the 2025 transition mean for your document set?

ISO 37001:2025 replaced the 2016 edition. Certificates issued to the 2016 edition run to a transition deadline of 28 February 2027.

For documented information, the work is a gap review rather than a rewrite. Check that context records address climate change. Check terminology. Check that culture, conflict-of-interest awareness and the M&A control area appear somewhere real. Clause 10 was reordered, with 10.1 now continual improvement and 10.2 nonconformity and corrective action, so any checklist citing clause numbers needs updating.

The harmonized structure helps organisations running several standards. If you already hold ISO 9001 or ISO 27001, your existing document control can usually serve the ABMS without duplication.

  • ISO 37001:2025 current edition
  • Transition deadline 28 February 2027
  • Certification by IAS, accredited by UQAS
  • Training and audit teams kept separate

Which documentation failures show up again and again?

Documents written for the auditor, not the user. If nobody in procurement can explain your own approval threshold, the procedure has failed however well it reads.

Records with no owner. Approvals signed “Management”. Reviews attributed to a committee. Somebody’s name belongs on a decision.

Scope drift. The scope statement says one thing; the records cover something narrower. Auditors notice quickly.

Remember too that the standard addresses bribery in four directions: by the organisation, by its own personnel, by business associates acting for it, and bribery directed at the organisation. Records covering only outbound risk leave a visible gap — the inbound side, where your own staff are offered something, needs its own trail.

ISO 37001 documented information — bribery directed at an organisation needs its own records

Where does training fit?

You cannot build a defensible record set without people who know what the clauses ask for.

The Foundation course runs half a day, four hours, self-paced online with 30 days’ access. It teaches understanding of the standard. Completing it confers no qualification to audit.

The Internal auditor course runs two days, 16 hours, available classroom or in-house, live virtual, or self-paced online with 30 days’ access. It teaches you to audit your own organisation — in practice, to test records rather than count them. See ISO 37001 internal auditor training in Oman, the self-paced online route or the live virtual route.

The Lead auditor course runs five days, 40 hours, with the same three delivery routes, and prepares you to audit other organisations. Details sit on the ISO 37001 lead auditor training in Oman page and the online course platform.

On the auditor courses, assessment is continuous throughout, with a written examination closing the final day. No prior experience is required. IAS and EAS issue the certificates jointly, and the UQAS accreditation held by IAS extends to training schemes alongside certification. Trainers and auditors sit in separate teams, which impartiality requires rather than merely favours.

This article makes no claim about the law in Oman or in any other country. Nothing here states or implies a legal duty, and legal obligations are a matter for your own advisers. Neither reading this article nor finishing any of the courses it describes turns anyone into an IAS auditor, and no registration of any sort follows from either.

Worth repeating too: a certificate does not prove no bribery has occurred or will occur. What it records is that, on the date of the audit, a management system conforming to the standard was found to be in place. A certificate is not a clean record, not a recommendation and not a shield in law.

Ready to test your evidence file against the standard? Talk to us about ISO 37001 certification, or get in touch to discuss the right training route for your team.

Frequently asked questions

Does ISO 37001 give me a list of mandatory documents?

Not as a single checklist. The requirements sit in individual clauses, using “maintain” for documents and “retain” for records. The table earlier in this post gathers the core set in one place.

How long do we have to keep anti-bribery records?

The standard does not name a period. It asks you to control retention and disposition. Set a schedule you can justify against your own operating needs and follow it consistently.

Can our records be entirely electronic?

Yes. The standard is format-neutral. What matters is that records are identifiable, protected, retrievable and version-controlled.

What does a stage 1 auditor look at first?

Usually the scope statement, the policy, the bribery risk assessment and the internal audit programme. Inconsistency between those four is the fastest way to a delayed stage 2.

Do we need a separate document control system for the ABMS?

No. If you already control documents for another management system, extend it. Duplicate systems create version conflicts.

How do we keep whistleblower records without exposing identities?

Separate the case record from the identity record and restrict access to the second. Log who accessed it. Auditors test the process, not the informant.

What documentation changes does the 2025 edition force?

Climate change consideration in context records, terminology updates, explicit treatment of culture and conflict-of-interest awareness, M&A as a control area, and clause-number updates in any checklist referencing clause 10.

Where do I start if we have almost nothing?

Scope, policy, risk assessment, then due diligence. Those four generate most of the rest. The general ISO certification and system certification pages outline the wider route, and the FAQ page answers common process questions.

Leave a Reply