A guide for delegates in Oman who will audit their own anti-bribery management system.
Most people ask what a course covers. Ask instead what it judges. ISO 37001 internal auditor training in Oman is assessed two ways across two days. A tutor watches how you work through the exercises. At the end there is a written examination. This page sets out both, so nothing about the assessment surprises you on the day.
Assessed as you work, then on paper. Browse the wider internal auditor training range, or ask what your assessment will involve.
- Two days, 16 hours
- Classroom, virtual or self-paced
- Continuous assessment plus a written paper
- Certificate issued by IAS with EAS
Table of Contents
ToggleWhat does the course actually assess?
The course exists to prove one thing. Can you plan and carry out an internal audit of an anti-bribery management system, gather evidence, write findings and report them to your own management? Every exercise and every examination question leads back to that sentence.
That is a narrower target than it first appears. You are not assessed on how much of ISO 37001:2025 you can recite, nor on your opinion of your employer's controls. You are assessed on process, evidence and judgement. Three things are judged throughout:
- Can you find the requirement? Given a situation, can you point to the clause that applies?
- Can you find the evidence? Do you know what record, interview or observation would settle the question?
- Can you write it down defensibly? Would a reader who was not in the room reach the same conclusion?
None of the three can be skipped. Someone who knows the standard well but writes vague findings will struggle. So will someone who writes beautifully but cannot cite a clause.
What are the two streams of assessment?
Assessment on this course runs in two streams that overlap.
The first stream is continuous. From the opening session onwards, the tutor is forming a view of your work. This is not a test you sit at a desk. It is a running judgement built from your checklists, your questions during role-play interviews, your written nonconformity statements and your contributions to group reviews.
The second stream is the written examination. It comes at the end of the taught content. It is a closed piece of individual work, and it is marked against a fixed scheme rather than against the rest of your group.
The two streams answer different questions. Continuous assessment asks whether you can do the job. The written paper asks whether you understand what the job rests on. A delegate who performs well in exercises but cannot explain the underlying requirements has learned a routine, not a discipline.
We do not publish a pass mark, a question count or a duration for the written paper; those details are confirmed at booking for your delivery route.

What is the tutor watching during the exercises?
Delegates often assume the tutor is watching for right answers. In practice, the tutor is watching for behaviour. Four behaviours come up again and again in assessment notes.
Sampling reasoning. You cannot look at everything. When you choose six gift-register entries out of many, can you say why those six? A stated rationale beats a large sample chosen at random.
Question discipline. In role-play interviews, closed questions get you nowhere. "Do you follow the due diligence procedure?" invites a yes. "Walk me through the last supplier you onboarded" produces evidence. Tutors note which style you default to under pressure.
Separating fact from inference. An auditee says the training was delivered. That is a statement, not a record. Delegates who write "training was completed" when they have only been told so are corrected early.
Handling pushback. In one exercise, the auditee disagrees with your finding. The assessment is not about winning. It is about whether you return to the evidence calmly and restate what you saw.
None of it is secret. Tutors say up front what they look for, and feed back as the days go on.

What is assessed each day, and what does good look like?
The table below maps the two days onto the assessment. The sequence may be adjusted for in-house groups, but the assessed areas stay the same.
| Day and session | What is assessed | How it is assessed | What good looks like |
|---|---|---|---|
| Day 1, opening | Grasp of ABMS scope and the four directions of bribery | Short group tasks and tutor questioning | You distinguish bribery by the organisation, by its people, by business associates, and bribery aimed at the organisation |
| Day 1, mid-morning | Navigation of ISO 37001:2025 | Clause-finding drills against short scenarios | You reach the right clause quickly and say why neighbouring clauses do not apply |
| Day 1, afternoon | Audit planning under clause 9.2 | Drafting an audit plan for a supplied scenario | The plan states scope, criteria, method and who will be interviewed, with a reason for each |
| Day 1, close | Checklist construction | Review of your ISO 37001 audit checklist against the scenario | Questions are open, traceable to a clause, and ask for evidence rather than confirmation |
| Day 2, morning | Evidence gathering and interviewing | Role-play interviews with tutor observation | You follow trails, ask for records, and record what you actually saw or read |
| Day 2, midday | Classifying and grading findings | Written nonconformity statements, peer and tutor review | Each statement names the requirement, the evidence and the gap, in that order |
| Day 2, afternoon | Reporting and follow-up | Drafting a short report section and a corrective action discussion | The report is usable by management without further explanation |
| Day 2, close | Underlying knowledge | The written examination | Answers show understanding of requirements, not memorised phrases |
Read the table as a preparation aid: it shows where attention is paid.
What does the written examination cover?
The paper draws on the whole taught content. Its subject matter falls into recognisable groups, and knowing them is the best preparation available.
The standard itself. Requirements of ISO 37001:2025 and how the clauses relate. Expect questions that place a situation in front of you and ask which requirement bears on it.
The 2025 edition. February 2025 brought the present edition in, and ISO 37001:2016 stepped aside. You should know what changed and why it matters to an auditor. The harmonized structure. "Stakeholders" replaced by "interested parties". Clauses 4.1 and 4.2 requiring climate change to be considered as an issue. Clause 5.1.3 making anti-bribery culture an explicit requirement. Clause 7.2.2 adding conflict-of-interest awareness to employment processes. A clearer statement of the anti-bribery function's role and independence. Clause 8.4 adding mergers and acquisitions as a non-financial control area. Clause 10 reordered, with 10.1 continual improvement and 10.2 nonconformity and corrective action.
Audit principles and terms. Audit criteria, audit evidence, objective evidence, nonconformity, observation, opportunity for improvement. These words have to mean the same thing to you as they do to a reviewer.
Clause 9.2 in operation. Programme design, frequency, independence of auditors, reporting lines, and the records that show the programme ran.
Practical judgement. Short scenarios where you decide whether something is a nonconformity, and if so against what.
Organisations still holding a 2016 certificate have until 28 February 2027 to transition. That date shapes the internal audit programme of many organisations in Oman right now.
Why does the ISO 37001:2025 edition matter to assessment?
An auditor who audits against a superseded edition creates work for everyone. That is why the current edition is treated as assessed knowledge rather than background reading.
The effect on your audit is practical. If your context analysis under clauses 4.1 and 4.2 has never mentioned climate change, that is a gap you should recognise. If employment processes say nothing about conflicts of interest, clause 7.2.2 is where you look. If a recent acquisition was never assessed as a bribery risk, clause 8.4 is the place to raise it.
Culture is the change delegates find hardest to audit. Clause 5.1.3 makes anti-bribery culture an explicit requirement, and culture leaves untidy records. Exercises push you to find what evidence does exist: leadership communications, how concerns were handled, whether decisions matched stated policy.
What does clause 9.2 require of both assessments?
Everything you are assessed on sits inside clause 9.2 internal audit. It is worth being precise about what that clause asks for.
It requires internal audits at planned intervals. Those audits must show whether the anti-bribery management system conforms to the organisation's own requirements and to the standard, and whether it is effectively implemented and maintained. It requires a programme that takes account of importance and of previous results. It requires defined criteria and scope for each audit, and auditor selection that protects objectivity and impartiality. It requires results reported to relevant management, and retained documented information as evidence.
Read that list again as an assessment specification: every sentence in it can become a question or an exercise.
An internal audit programme is not a single event. It is a schedule across a period, usually a year, covering every part of the ABMS in a planned way. Your organisation owns it, and your findings go to your own management.
Later, a certification body auditor will look at your internal audit records as evidence that clause 9.2 is being met. Your reports become someone else's audit evidence. That is why report quality carries weight in assessment. It is not, however, a substitute for certification. Internal audits certify nothing. The certification route is separate, and our certification process overview explains how it runs.
Why does objectivity catch people out?
Here is the difference that defines this course. You will audit your own organisation. You already know the people. You may have helped build the process you are now auditing.
Technique is teachable in two days. Objectivity is harder, and it is assessed deliberately. Exercises put you in awkward positions on purpose. Your manager's department. A process you wrote. A colleague you sit beside. The tutor is watching what you do about it.
The assessed answer is never "be more objective". It is procedural. Declare the conflict. Swap the scope. Have a second auditor cover that area. Record the decision so a reader can see it was handled.
| Situation | Acceptable | Not acceptable | What assessment looks for |
|---|---|---|---|
| Auditing a procedure you personally wrote | No | — | You declare it and ask to swap scope |
| Auditing a peer's department | Yes, with care | — | You stick to evidence and avoid assumed knowledge |
| Auditing your own line manager's area | Rarely | Usually | You raise it before the audit, not after |
| Auditing a friend's process | Yes | — | You ask the same questions you would ask a stranger |
| Using knowledge you have from outside the audit | — | No | You ask for the record rather than relying on memory |
The last row causes the most argument. Delegates often say they already know the answer. Ask for the evidence anyway. The finding then stands on the record rather than on your word.
How are findings and reports assessed?
Continuous assessment leans heavily on what you write. Three elements are expected in every nonconformity statement.
- The requirement. The clause, or the internal rule, that has not been met.
- The evidence. What you saw, read or were shown, identified well enough that someone else could find it.
- The gap. A plain statement of the difference between the two.
Statements that mix in an opinion or a recommended fix are marked down. Write "the gift register is poorly maintained" and you have offered nothing but a view. "Clause 8.7 requires controls over gifts and hospitality. Four of six entries reviewed for the third quarter lacked approver names. The register does not evidence approval." That is a finding.
Tone is assessed too, for a practical reason. You have to work with these people on Monday. A report that reads as an accusation makes the next audit harder.
How should you prepare for each assessment area?
You do not need to prepare in advance. The course teaches everything it assesses, and no prior auditing experience is required. Familiarity with the standard is recommended, and it makes the two days easier.
Use this table during the course, and again before the paper.
| Assessment area | What the course gives you | What to revisit before the paper |
|---|---|---|
| Structure of ISO 37001:2025 | A guided walk through every clause, with worked examples | The clause numbers you keep having to look up |
| The four directions of bribery | Case discussion covering each direction in turn | Which direction each of your own controls addresses |
| The 2025 changes | A change-by-change briefing against the 2016 edition | Climate change in 4.1 and 4.2, culture in 5.1.3, M&A in 8.4, reordered clause 10 |
| Audit terminology | Definitions used consistently through every exercise | The difference between a nonconformity and an observation |
| Clause 9.2 requirements | Programme design worked through end to end | Independence, reporting to management, retained records |
| Planning and checklists | Two supervised drafting sessions | How you justified your sample |
| Interviewing | Role-play with direct tutor feedback | Your own habit of asking closed questions |
| Writing findings | Peer review of your written statements | Requirement, evidence, gap — in that order |
| Reporting | A drafted report section and follow-up discussion | What management needs in order to act |
| Objectivity | Decision exercises with conflicts built in | The procedural response to each conflict type |

How does assessment work on each delivery route?
The course runs three ways. The assessed content is the same in each. The mechanics differ, so choose with that in mind.
Classroom or in-house. Held at an IAS training centre or at your own premises. Continuous assessment happens in the room, with live interviews and immediate feedback. In-house delivery lets exercises use scenarios close to your own operations.
Virtual instructor-led. Delivered over web conferencing. Exercises run in breakout groups, and the tutor moves between them as in a classroom. The written paper is administered under the arrangements confirmed at booking.
Self-paced. Thirty days of access to the material, worked through at your own pace via the online course platform. Interactive assessment is structured differently here. If you want the full role-play component, a tutor-led route suits better.
Whichever route you take, ISO 37001 internal auditor training is two days, 16 hours of instruction. You can see how it sits beside our other programmes on the ISO training page.
Internal auditor or lead auditor: how do the assessments differ?
The distinction matters when you are choosing, so here it is once. This two-day internal auditor course prepares you to audit your own organisation, under a programme your organisation owns. The lead auditor course is a longer, separate product. It prepares people to audit other organisations, and it is assessed to a different depth, particularly on leading an audit team.
If your job is to run internal audits at your employer, the two-day route is the right one. If you intend to audit third parties, look at the lead auditor programme instead.
What does your certificate say, and what are its limits?
Complete the course successfully and a certificate of completion comes to you in the joint names of IAS and EAS. Behind the course sits the UQAS accreditation that IAS holds, and that accreditation reaches training schemes as well as certification; IAS and EAS run the two days together. See our accreditation page, and about us for the organisation itself.
One point about how we are set up. Whoever teaches you here sits apart from the people who conduct audits. Impartiality rules demand that division; it is not a matter of internal taste. It is also why completing a course here gives you no standing in any certification decision.
What this course does not do
Completing ISO 37001 internal auditor training does not make you an auditor for IAS. It does not certify your employer. It does not confer any registration, and it is not a route into working for us. The certificate records that you completed the course and met its assessment. That is a real and useful thing. It is not more than that.
Certification of an organisation is a separate process with separate rules. If that is what you need, start with system certification. Certification never proves that no bribery has occurred or will occur. What it evidences is the presence of a management system built to the standard's requirements.
A note on local law
This page makes no claim about the law in Oman. Nothing here states or implies a legal requirement, a regulatory expectation or any official approval, for the course or for ISO 37001 certification. The standard is voluntary. How it relates to any legal obligation your organisation carries is a question for your own legal advisers, not for a training page.
Who should sit this course in Oman?
The course suits anyone who will be named on an internal audit programme for an anti-bribery management system. That includes compliance and ethics staff, internal audit teams, quality and management system professionals, legal and procurement staff, finance and risk people, and managers whose departments will be audited.
There are no entry conditions. Familiarity with ISO 37001:2025 is recommended and will make the second day easier.
Organisations often send delegates from several functions together. That builds an internal audit programme where auditors can cover each other's areas, solving many objectivity problems before they arise.
If you already run internal audits against other standards, the transfer is quick. Colleagues who audit to ISO 9001, ISO 45001, ISO 14001, ISO 27001 or ISO 22301 will recognise the harmonized structure immediately. What is new is the subject matter: bribery risk, due diligence on business associates, gifts and hospitality, and the anti-bribery function's independence.
Know what you are being assessed on before you book. Tell us your delivery route and we will confirm the assessment arrangements — get in touch with the Oman team or review the full internal auditor course range.
Frequently asked questions
What is ISO 37001 internal auditor training?
A two-day, 16-hour course preparing you to plan and carry out internal audits of an anti-bribery management system. It covers ISO 37001:2025, audit technique, evidence, findings and reporting, and is assessed continuously plus by written examination.
What is the pass mark, and how many questions are there?
We do not publish a pass mark, a question count or an examination duration. Those details are confirmed at booking for your chosen delivery route.
How many days and hours does the course take?
Two days, 16 hours of instruction. The self-paced route gives 30 days of access to the material instead of a fixed two-day timetable.
Do I need experience to take the assessment?
No. No prior auditing experience is required. Familiarity with the standard is recommended, and reading the clause structure beforehand will make the exercises easier.
Can I audit my own department?
Generally not, and this is assessed directly. Clause 9.2 requires auditor selection that protects objectivity. The expected response is procedural: declare the conflict, swap scope, record the decision.
How often must internal audits be done?
At planned intervals set by your own programme; the standard fixes no frequency. Let the importance of each area and previous audit results drive it. Most organisations plan across a year.
Does this make me an IAS auditor, or certify my employer?
No to both. The certificate records your completion of the course. It gives you no role with IAS and it certifies nothing about your organisation.
Will a certification body auditor look at my internal audit work?
Very likely. Records of internal audits are the ordinary proof that clause 9.2 is being satisfied. That is why report quality is assessed on this course rather than treated as an afterthought.