{"id":6596,"date":"2026-09-24T07:02:12","date_gmt":"2026-09-24T07:02:12","guid":{"rendered":"https:\/\/iasiso-gulf.com\/OM\/blog\/records-iso-37001-expects-you-to-keep\/"},"modified":"2026-09-24T07:02:12","modified_gmt":"2026-09-24T07:02:12","slug":"records-iso-37001-expects-you-to-keep","status":"publish","type":"post","link":"https:\/\/iasiso-gulf.com\/OM\/blog\/records-iso-37001-expects-you-to-keep\/","title":{"rendered":"Documented Information Under ISO 37001: The Records Your Anti-Bribery System Has to Keep"},"content":{"rendered":"<style>.ias-c h2,.ias-c h3,.ias-c .ias-faq-title{font-weight:700 !important;text-align:left !important;}.ias-c h2:not(.ias-faq-title){font-size:22px !important;line-height:1.3 !important;margin:30px 0 12px !important;color:#B02B2C !important;}.ias-c h3{font-size:18px !important;line-height:1.35 !important;margin:24px 0 10px !important;color:#B02B2C !important;}.ias-c p,.ias-c li{text-align:justify;line-height:1.7;color:#212529;}.ias-c ul{margin:0 0 18px 20px;}.ias-c li{margin-bottom:8px;}.ias-c a,.ias-c td a,.ias-c li a,.ias-c p a{font-weight:700 !important;text-decoration:underline !important;text-underline-offset:2px;color:#B02B2C !important;}.ias-fig{margin:24px auto;padding:0;max-width:600px;}.ias-fig img{width:100%;height:auto;display:block;border-radius:6px;}.ias-fig figcaption{font-size:13px;color:#6b6360;text-align:center;margin-top:8px;font-style:italic;}.ias-qa{background:#fbf6f6;border-left:4px solid #B02B2C;padding:18px 22px;margin:0 0 26px;border-radius:4px;}.ias-qa .ias-qa-t{font-weight:700;color:#B02B2C;font-size:16px;margin:0 0 10px;text-transform:uppercase;letter-spacing:.4px;}.ias-qa ul{margin:0 0 0 18px;}.ias-qa li{margin-bottom:7px;text-align:justify;}.ias-byline{font-size:13px;color:#6b6360;margin:0 0 18px;font-style:italic;}.ias-tw{width:100%;border-collapse:collapse;margin:18px 0 26px;font-size:15px;}.ias-tw thead th{background:#B02B2C !important;color:#fff !important;font-weight:700 !important;text-align:left !important;padding:11px 13px !important;border:1px solid #B02B2C !important;}.ias-tw td{border:1px solid #e6dede !important;padding:10px 13px !important;color:#212529 !important;vertical-align:top;}.ias-tw tbody tr:nth-child(even) td{background:#fbf6f6 !important;color:#212529 !important;}.ias-tw tbody tr:nth-child(odd) td{background:#fff !important;color:#212529 !important;}.ias-src{font-size:12.5px;color:#6b6360;margin:-14px 0 24px;font-style:italic;}.ias-quote{border-left:4px solid #B02B2C;background:#fbf6f6;padding:16px 20px;margin:22px 0;font-style:italic;color:#212529;text-align:justify;}.ias-bio{background:#fbf6f6;border:1px solid #e6dede;border-radius:6px;padding:18px 22px;margin:26px 0;}.ias-bio .ias-bio-t{font-weight:700;color:#B02B2C;margin:0 0 8px;font-size:16px;}.ias-bio p{margin:0;font-size:14.5px;}.ias-c .ias-faq-title{font-size:1.5em;font-weight:700;color:#B02B2C !important;margin:34px 0 14px;}.ias-faq-item{border:1px solid #e6dede;border-radius:5px;margin-bottom:10px;background:#fff;}.ias-faq-q{cursor:pointer;padding:13px 44px 13px 16px;font-weight:700;color:#212529;position:relative;list-style:none;line-height:1.5;}.ias-faq-q::-webkit-details-marker{display:none;}.ias-faq-q::after{content:\"+\";position:absolute;right:16px;top:50%;transform:translateY(-50%);color:#B02B2C;font-size:22px;font-weight:700;line-height:1;}.ias-faq-item[open] .ias-faq-q::after{content:\"\u2212\";}.ias-faq-a{padding:0 16px 14px;}.ias-faq-a p{margin:0;font-size:15px;}.ias-cta{background:#B02B2C;color:#fff !important;padding:22px 24px;border-radius:6px;margin:28px 0 0;}.ias-cta p{color:#fff !important;margin:0 0 8px;}.ias-cta a{color:#fff !important;text-decoration:underline !important;}@media(max-width:640px){.ias-tw{font-size:13.5px;}.ias-tw td,.ias-tw thead th{padding:8px 9px !important;}}.elementor-widget-sidebar,.elementor-widget-sidebar *{font-family:\"Roboto\",Arial,Helvetica,sans-serif !important;}.elementor-widget-sidebar .widget-title,.elementor-widget-sidebar h2,.elementor-widget-sidebar h3{font-family:\"Poppins\",\"Roboto\",Arial,sans-serif !important;}.gdlr-social-share{display:none !important;}.ias-c .ias-fig{display:block !important;margin-left:auto !important;margin-right:auto !important;float:none !important;}.ias-c,.ias-c p,.ias-c li,.ias-c td,.ias-c th,.ias-c blockquote,.ias-c summary,.ias-c div{font-family:\"Roboto\",Arial,Helvetica,sans-serif !important;}.ias-c h2,.ias-c h3,.ias-c .ias-faq-title,.ias-c .ias-qa-t,.ias-c .ias-bio-t{font-family:\"Poppins\",\"Roboto\",Arial,sans-serif !important;}.ias-c h2:not(.ias-faq-title){font-size:25px !important;}.ias-c h3{font-size:20px !important;}.ias-c p,.ias-c li{font-size:16px !important;line-height:1.7 !important;color:#000 !important;}.ias-c td,.ias-c th{font-size:15px !important;}.ias-c .ias-faq-a p,.ias-c .ias-bio p,.ias-c .ias-byline,.ias-c .ias-src{font-size:15px !important;}.ias-c .ias-faq-q{color:#333 !important;}.ias-c .ias-byline,.ias-c .ias-src,.ias-c figcaption{color:#8d8d8d !important;}.ias-c .ias-cta p,.ias-c .ias-cta a,.ias-c .ias-cta strong{color:#fff !important;}.ias-c .ias-tw thead th{color:#fff !important;}.ias-c h2:not(.ias-faq-title),.ias-c h3,.ias-c .ias-faq-title{color:#0A4D8C !important;}.ias-c p strong,.ias-c li strong,.ias-c td strong{color:#333 !important;}.ias-fig.ias-fig-photo{max-width:480px;}.ias-fig.ias-fig-wide{max-width:820px;}@media(max-width:860px){.ias-fig.ias-fig-wide{max-width:100%;}}.ias-c ul{list-style:disc outside !important;padding-left:22px !important;margin:0 0 18px 8px !important;}.ias-c ul li{list-style:disc outside !important;display:list-item !important;}.ias-c a,.ias-c li a,.ias-c p a,.ias-c td a{text-decoration:underline !important;font-weight:700 !important;color:#B02B2C !important;}.ias-c .ias-cta a{color:#fff !important;}.ias-c .ias-band{background:#fbf6f6;border:1px solid #e6dede;border-radius:10px;padding:14px 18px;margin:20px 0;}.ias-c .ias-band ul{display:flex !important;flex-wrap:wrap;gap:6px 26px;margin:0 !important;padding:0 !important;list-style:none !important;}.ias-c .ias-band ul li{list-style:none !important;display:block !important;font-size:15px !important;color:#333 !important;font-weight:600;}.ias-c .ias-band ul li:before{content:\"\\2713\";color:#B02B2C;font-weight:700;margin-right:8px;}.ias-c .ias-cta2{background:#B02B2C;border-radius:10px;padding:16px 20px;margin:24px 0;}.ias-c .ias-cta2 p{margin:0 !important;color:#fff !important;font-size:16px !important;}.ias-c .ias-cta2 p a{color:#fff !important;text-decoration:underline !important;font-weight:700 !important;}.ias-cta2,.ias-cta2 p,.ias-cta2 li,.ias-cta2 strong,.ias-cta2 b,.ias-c .ias-cta2 p strong,.ias-c .ias-cta2 li strong,.ias-c .ias-cta2 td strong,.elementor .ias-c .ias-cta2 p strong,.elementor .ias-c .ias-cta2 li strong{color:#fff!important}<\/style>\n<div class=\"ias-c\">\n<p class=\"ias-byline\"><em>A practical guide for compliance officers, quality managers and internal auditors in Oman.<\/em><\/p>\n<div class=\"ias-cta2\">\n<p><strong>Planning an ISO 37001 audit?<\/strong> Stage 1 is largely a documentation review. See how <a href=\"\/OM\/iso-37001-certification-in-oman\/\">ISO 37001 certification in Oman<\/a> works before you build your evidence file.<\/p>\n<\/div>\n<p>Most anti-bribery systems fail their first audit on paper, not on principle. The policy exists. The tone from the top is genuine. But when the auditor asks for the due diligence file on a particular agent, or the record of who approved a gift last quarter, the room goes quiet.<\/p>\n<p>ISO 37001 is the international standard for anti-bribery management systems, and like every management system standard it runs on evidence. &#8220;Documented information&#8221; is the term it uses. This post sets out what the standard expects you to keep, what auditors actually ask for, and where organisations come unstuck.<\/p>\n<div id=\"ez-toc-container\" class=\"ez-toc-v2_0_78 counter-hierarchy ez-toc-counter ez-toc-grey ez-toc-container-direction\">\n<div class=\"ez-toc-title-container\">\n<p class=\"ez-toc-title\" style=\"cursor:inherit\">Table of Contents<\/p>\n<span class=\"ez-toc-title-toggle\"><a href=\"#\" class=\"ez-toc-pull-right ez-toc-btn ez-toc-btn-xs ez-toc-btn-default ez-toc-toggle\" aria-label=\"Toggle Table of Content\"><span class=\"ez-toc-js-icon-con\"><span class=\"\"><span class=\"eztoc-hide\" style=\"display:none;\">Toggle<\/span><span class=\"ez-toc-icon-toggle-span\"><svg style=\"fill: #999;color:#999\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" class=\"list-377408\" width=\"20px\" height=\"20px\" viewBox=\"0 0 24 24\" fill=\"none\"><path d=\"M6 6H4v2h2V6zm14 0H8v2h12V6zM4 11h2v2H4v-2zm16 0H8v2h12v-2zM4 16h2v2H4v-2zm16 0H8v2h12v-2z\" fill=\"currentColor\"><\/path><\/svg><svg style=\"fill: #999;color:#999\" class=\"arrow-unsorted-368013\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" width=\"10px\" height=\"10px\" viewBox=\"0 0 24 24\" version=\"1.2\" baseProfile=\"tiny\"><path d=\"M18.2 9.3l-6.2-6.3-6.2 6.3c-.2.2-.3.4-.3.7s.1.5.3.7c.2.2.4.3.7.3h11c.3 0 .5-.1.7-.3.2-.2.3-.5.3-.7s-.1-.5-.3-.7zM5.8 14.7l6.2 6.3 6.2-6.3c.2-.2.3-.5.3-.7s-.1-.5-.3-.7c-.2-.2-.4-.3-.7-.3h-11c-.3 0-.5.1-.7.3-.2.2-.3.5-.3.7s.1.5.3.7z\"\/><\/svg><\/span><\/span><\/span><\/a><\/span><\/div>\n<nav><ul class='ez-toc-list ez-toc-list-level-1 ' ><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-1\" href=\"https:\/\/iasiso-gulf.com\/OM\/blog\/records-iso-37001-expects-you-to-keep\/#what-does-documented-information-mean-in-iso-37001\" >What does documented information mean in ISO 37001?<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-2\" href=\"https:\/\/iasiso-gulf.com\/OM\/blog\/records-iso-37001-expects-you-to-keep\/#which-records-does-iso-37001-name-directly\" >Which records does ISO 37001 name directly?<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-3\" href=\"https:\/\/iasiso-gulf.com\/OM\/blog\/records-iso-37001-expects-you-to-keep\/#what-does-the-climate-change-addition-mean-for-context-records\" >What does the climate change addition mean for context records?<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-4\" href=\"https:\/\/iasiso-gulf.com\/OM\/blog\/records-iso-37001-expects-you-to-keep\/#why-are-due-diligence-files-the-most-examined-record-set\" >Why are due diligence files the most examined record set?<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-5\" href=\"https:\/\/iasiso-gulf.com\/OM\/blog\/records-iso-37001-expects-you-to-keep\/#why-are-refusals-better-records-than-approvals\" >Why are refusals better records than approvals?<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-6\" href=\"https:\/\/iasiso-gulf.com\/OM\/blog\/records-iso-37001-expects-you-to-keep\/#what-records-cover-competence-awareness-and-conflict-of-interest\" >What records cover competence, awareness and conflict of interest?<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-7\" href=\"https:\/\/iasiso-gulf.com\/OM\/blog\/records-iso-37001-expects-you-to-keep\/#how-do-you-protect-whistleblowers-and-still-retain-the-records\" >How do you protect whistleblowers and still retain the records?<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-8\" href=\"https:\/\/iasiso-gulf.com\/OM\/blog\/records-iso-37001-expects-you-to-keep\/#what-records-must-the-anti-bribery-function-keep\" >What records must the anti-bribery function keep?<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-9\" href=\"https:\/\/iasiso-gulf.com\/OM\/blog\/records-iso-37001-expects-you-to-keep\/#what-does-a-good-record-set-look-like-and-what-does-a-weak-one\" >What does a good record set look like, and what does a weak one?<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-10\" href=\"https:\/\/iasiso-gulf.com\/OM\/blog\/records-iso-37001-expects-you-to-keep\/#how-do-auditors-test-your-record-controls\" >How do auditors test your record controls?<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-11\" href=\"https:\/\/iasiso-gulf.com\/OM\/blog\/records-iso-37001-expects-you-to-keep\/#what-does-the-2025-transition-mean-for-your-document-set\" >What does the 2025 transition mean for your document set?<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-12\" href=\"https:\/\/iasiso-gulf.com\/OM\/blog\/records-iso-37001-expects-you-to-keep\/#which-documentation-failures-show-up-again-and-again\" >Which documentation failures show up again and again?<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-13\" href=\"https:\/\/iasiso-gulf.com\/OM\/blog\/records-iso-37001-expects-you-to-keep\/#where-does-training-fit\" >Where does training fit?<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-14\" href=\"https:\/\/iasiso-gulf.com\/OM\/blog\/records-iso-37001-expects-you-to-keep\/#frequently-asked-questions\" >Frequently asked questions<\/a><\/li><\/ul><\/nav><\/div>\n<h2><span class=\"ez-toc-section\" id=\"what-does-documented-information-mean-in-iso-37001\"><\/span>What does documented information mean in ISO 37001?<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p>The phrase replaced the older split between &#8220;documents&#8221; and &#8220;records&#8221;. It covers both, and the standard signals which it means with two verbs.<\/p>\n<p><strong>Maintain<\/strong> means keep it current. It points at things that tell people how the system works: the policy, procedures, the scope statement, the risk criteria. If one is out of date, it is a nonconformity, even if it was perfect when written.<\/p>\n<p><strong>Retain<\/strong> means keep it as proof that something happened. Training completion, a due diligence outcome, a management review minute, an audit report. You do not update a retained record. You file it, protect it and produce it when asked.<\/p>\n<p>Get this right and half your documentation problems disappear. A procedure &#8220;signed off&#8221; three times in three years and never revised is a maintained document that nobody maintained.<\/p>\n<h2><span class=\"ez-toc-section\" id=\"which-records-does-iso-37001-name-directly\"><\/span>Which records does ISO 37001 name directly?<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p>Certain clauses say plainly that documented information must be kept. Others imply it so strongly that no auditor will accept its absence. The table below covers the core set.<\/p>\n<div class=\"ias-tscroll\">\n<table class=\"ias-tw\">\n<thead>\n<tr>\n<th>Area<\/th>\n<th>What you keep<\/th>\n<th>Maintain or retain<\/th>\n<th>What the auditor tends to ask<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td>Context and interested parties<\/td>\n<td>Internal and external issues, including climate change; interested parties and their requirements<\/td>\n<td>Maintain<\/td>\n<td>&#8220;When did you last review this, and what changed?&#8221;<\/td>\n<\/tr>\n<tr>\n<td>Scope and policy<\/td>\n<td>Written scope covering sites and activities; the policy and evidence it was communicated<\/td>\n<td>Both<\/td>\n<td>&#8220;Show me that your agents received it.&#8221;<\/td>\n<\/tr>\n<tr>\n<td>Bribery risk assessment<\/td>\n<td>Method, criteria, the output and review dates<\/td>\n<td>Both<\/td>\n<td>&#8220;Show me the version in force before this contract was signed.&#8221;<\/td>\n<\/tr>\n<tr>\n<td>Due diligence<\/td>\n<td>Assessments of personnel in exposed roles, projects and business associates<\/td>\n<td>Retain<\/td>\n<td>&#8220;Show me the file for this third party.&#8221;<\/td>\n<\/tr>\n<tr>\n<td>Competence and awareness<\/td>\n<td>Training records, awareness activity, conflict-of-interest declarations<\/td>\n<td>Retain<\/td>\n<td>&#8220;Who was trained, on what, and when?&#8221;<\/td>\n<\/tr>\n<tr>\n<td>Controls<\/td>\n<td>Gifts and hospitality approvals, donations, sponsorships, financial and non-financial controls<\/td>\n<td>Retain<\/td>\n<td>&#8220;Show me an approval that was refused.&#8221;<\/td>\n<\/tr>\n<tr>\n<td>Raising concerns and investigations<\/td>\n<td>Reports received, how they were handled, case outcomes<\/td>\n<td>Retain<\/td>\n<td>&#8220;How is confidentiality preserved here?&#8221;<\/td>\n<\/tr>\n<tr>\n<td>Internal audit<\/td>\n<td>Programme, reports, findings, follow-up<\/td>\n<td>Retain<\/td>\n<td>&#8220;Show me the audit of the anti-bribery function itself.&#8221;<\/td>\n<\/tr>\n<tr>\n<td>Management review and corrective action<\/td>\n<td>Inputs, minutes, decisions with owners; nonconformities and their verified fixes<\/td>\n<td>Retain<\/td>\n<td>&#8220;Did you check whether the fix worked?&#8221;<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/div>\n<p>That is the backbone. Everything else is supporting detail your own processes generate.<\/p>\n<figure class=\"ias-fig\"><img loading=\"lazy\" src=\"https:\/\/iasiso-gulf.com\/OM\/wp-content\/uploads\/2026\/09\/iso-37001-blog-om-fig1.jpg\" alt=\"ISO 37001 documented information \u2014 the transaction that leaves no record\" width=\"1000\" height=\"561\" loading=\"lazy\" decoding=\"async\" \/><\/figure>\n<h2><span class=\"ez-toc-section\" id=\"what-does-the-climate-change-addition-mean-for-context-records\"><\/span>What does the climate change addition mean for context records?<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p>Clauses 4.1 and 4.2 ask you to record the issues affecting your anti-bribery system and the parties with a stake in it. ISO 37001:2025, published in February 2025, added a requirement here: climate change must be considered as a potentially relevant issue.<\/p>\n<p>The point is not to write an environmental policy. It is to ask whether climate-driven change alters your bribery exposure. Suppose an organisation starts bidding for coastal infrastructure work funded by a new adaptation programme, using unfamiliar intermediaries in a hurry. That is a changed risk picture, and your context record should show you noticed.<\/p>\n<p>The 2025 edition also replaced &#8220;stakeholders&#8221; with &#8220;interested parties&#8221;. If your documents still say stakeholders, nothing breaks \u2014 but a document set untouched since 2016 tells an auditor how alive the system is.<\/p>\n<h2><span class=\"ez-toc-section\" id=\"why-are-due-diligence-files-the-most-examined-record-set\"><\/span>Why are due diligence files the most examined record set?<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p>If an auditor asks for one thing, it will be a due diligence file. This is where the paperwork most often thins out.<\/p>\n<p>A due diligence record needs to show three things: what you checked, what you found, and what you decided to do about it. The third is the one people skip. A file full of screening printouts with no conclusion is raw material, not a record.<\/p>\n<p>Keep the file at the level of the relationship, not the transaction. One folder per business associate: the assessment, the risk rating, any enhanced checks, the approval, the contract clauses relied on, and the next review date. When the relationship changes \u2014 new country, new scope, new owner \u2014 the file should show a fresh look. The same applies to personnel in exposed roles and to projects, and the personnel side is regularly forgotten.<\/p>\n<h2><span class=\"ez-toc-section\" id=\"why-are-refusals-better-records-than-approvals\"><\/span>Why are refusals better records than approvals?<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p>Gifts, hospitality, donations and sponsorship registers are the easiest records to keep and the easiest to keep badly. A register with fifty approvals and zero refusals is not evidence of a working control. It is evidence of a rubber stamp.<\/p>\n<p>Keep the request, the reason, the value, the decision, the decision-maker and the date. Keep the declined ones and the escalated ones. Those entries carry more weight than a hundred routine approvals.<\/p>\n<p>Clause 8.4 in the 2025 edition made mergers and acquisitions an explicit non-financial control area. If you acquire a business, expect to be asked for the pre-deal anti-bribery due diligence and the post-deal integration plan. That paperwork often sits with legal and never reaches the management system.<\/p>\n<h2><span class=\"ez-toc-section\" id=\"what-records-cover-competence-awareness-and-conflict-of-interest\"><\/span>What records cover competence, awareness and conflict of interest?<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p>Training records are straightforward: who, what, when, and how you judged the training effective. Attendance alone is thin. A short assessment, a signed acknowledgement, or a manager&#8217;s confirmation of applied behaviour all strengthen it.<\/p>\n<p>Clause 7.2.2 in the 2025 edition added conflict-of-interest awareness to employment processes. The record set now extends into recruitment and onboarding: the declaration a new hire makes, the periodic re-declaration, and what happened when somebody declared something real.<\/p>\n<p>Broad awareness across the workforce and deeper competence in the audit team are different things. Our <a href=\"\/OM\/iso-training\/\">ISO training programmes<\/a> cover both, and the <a href=\"\/OM\/internal-auditor-training\/\">internal auditor training pathway<\/a> explains the step up.<\/p>\n<h2><span class=\"ez-toc-section\" id=\"how-do-you-protect-whistleblowers-and-still-retain-the-records\"><\/span>How do you protect whistleblowers and still retain the records?<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p>This is the hardest record set to design. You must retain enough to prove the process worked, while protecting anyone who reported in confidence.<\/p>\n<p>Split the file. Keep a case record with a reference number, dates, category, actions and outcome, available to those who need it. Keep identity and contact details in a separate, tightly restricted store, linked only by the reference. Log who accessed what and when.<\/p>\n<p>Auditors will not read the substance of a live investigation. They want to see that a documented route exists, that reports are logged, that decisions are recorded by somebody with authority, and that protection from retaliation is more than a policy sentence.<\/p>\n<h2><span class=\"ez-toc-section\" id=\"what-records-must-the-anti-bribery-function-keep\"><\/span>What records must the anti-bribery function keep?<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p>The 2025 edition states the anti-bribery function&#8217;s role and independence more clearly than its predecessor. Your documented information should back that up.<\/p>\n<p>Keep the appointment record, the defined authority, the reporting line to top management or the governing body, and \u2014 the one that gets missed \u2014 the record of that reporting actually happening. A function that reports to the board &#8220;as required&#8221;, with no minutes showing it did, has independence on paper only.<\/p>\n<p>Clause 5.1.3 also makes anti-bribery culture an explicit requirement. Culture is hard to evidence, but not impossible. Leadership communications, decisions where commercial opportunity was declined on integrity grounds, and consistency of disciplinary outcomes are all legitimate records.<\/p>\n<figure class=\"ias-fig\"><img loading=\"lazy\" src=\"https:\/\/iasiso-gulf.com\/OM\/wp-content\/uploads\/2026\/09\/iso-37001-blog-om-fig2.jpg\" alt=\"ISO 37001 documented information \u2014 gifts and hospitality registers exist for this\" width=\"1000\" height=\"667\" loading=\"lazy\" decoding=\"async\" \/><\/figure>\n<h2><span class=\"ez-toc-section\" id=\"what-does-a-good-record-set-look-like-and-what-does-a-weak-one\"><\/span>What does a good record set look like, and what does a weak one?<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<div class=\"ias-tscroll\">\n<table class=\"ias-tw\">\n<thead>\n<tr>\n<th>Record<\/th>\n<th>Weak version<\/th>\n<th>Strong version<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td>Risk assessment<\/td>\n<td>One spreadsheet, undated, &#8220;reviewed annually&#8221; with no evidence of review<\/td>\n<td>Versioned, dated, shows what changed and why, references specific countries and intermediaries<\/td>\n<\/tr>\n<tr>\n<td>Due diligence file<\/td>\n<td>Screening printouts, no conclusion, no approver<\/td>\n<td>Findings, risk rating, decision, approver, contract controls relied on, review date<\/td>\n<\/tr>\n<tr>\n<td>Training record<\/td>\n<td>Attendance list from a single session in 2023<\/td>\n<td>Role-based matrix, completion dates, effectiveness check, refresher schedule<\/td>\n<\/tr>\n<tr>\n<td>Gift register<\/td>\n<td>Approvals only, all identical, one approver<\/td>\n<td>Requests, decisions including refusals, values, escalations, periodic analysis<\/td>\n<\/tr>\n<tr>\n<td>Internal audit<\/td>\n<td>One report covering &#8220;compliance&#8221; generally<\/td>\n<td>Programme covering every ABMS clause including the function itself, findings with owners and closure evidence<\/td>\n<\/tr>\n<tr>\n<td>Corrective action<\/td>\n<td>&#8220;Staff reminded&#8221;<\/td>\n<td>Cause analysis, action, verification that the cause is gone<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/div>\n<p>Mark your own system honestly. The gap between the columns is your audit preparation plan.<\/p>\n<h2><span class=\"ez-toc-section\" id=\"how-do-auditors-test-your-record-controls\"><\/span>How do auditors test your record controls?<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p>Keeping records is one requirement. Controlling them is another. The standard expects documented information to be identifiable, available where needed, adequately protected, and controlled for distribution, access, retrieval, storage, version and retention.<\/p>\n<p>Four practical tests:<\/p>\n<ul>\n<li><strong>Can you find it?<\/strong> If producing a 2024 due diligence file takes three days and four emails, retrieval has failed.<\/li>\n<li><strong>Is access right?<\/strong> Sensitive files should be restricted. Policies should not be.<\/li>\n<li><strong>Is the version clear?<\/strong> Two versions of a procedure in circulation is a common and avoidable finding.<\/li>\n<li><strong>Do you know when to dispose?<\/strong> Write a retention schedule and follow it. Keeping everything forever is not a policy, and neither is deleting when storage fills up.<\/li>\n<\/ul>\n<p>External documents count too: codes of conduct you have signed, client anti-bribery clauses, questionnaires you have returned.<\/p>\n<p>Certification through IAS runs in two stages. Stage 1 examines readiness and documentation: whether the required documents exist, cover the right scope, and are internally consistent. Stage 2 examines the system working in practice. There the auditor samples \u2014 a contract, a supplier, a month of the gift register, an employee \u2014 and follows the trail to see whether the documented process is what actually happened.<\/p>\n<p>Certificates then run on a three-year cycle, with surveillance audits between and recertification at the end. Surveillance looks at records accumulated during the cycle, so a system that produces evidence only in audit season is quickly visible. The <a href=\"\/OM\/certification-process\/\">certification process<\/a> and <a href=\"\/OM\/iso-audit-procedure\/\">ISO audit procedure<\/a> pages set out the sequence, and the <a href=\"\/OM\/accreditation\/\">accreditation<\/a> page explains the UQAS position behind it.<\/p>\n<h2><span class=\"ez-toc-section\" id=\"what-does-the-2025-transition-mean-for-your-document-set\"><\/span>What does the 2025 transition mean for your document set?<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p>ISO 37001:2025 replaced the 2016 edition. Certificates issued to the 2016 edition run to a transition deadline of <strong>28 February 2027<\/strong>.<\/p>\n<p>For documented information, the work is a gap review rather than a rewrite. Check that context records address climate change. Check terminology. Check that culture, conflict-of-interest awareness and the M&amp;A control area appear somewhere real. Clause 10 was reordered, with 10.1 now continual improvement and 10.2 nonconformity and corrective action, so any checklist citing clause numbers needs updating.<\/p>\n<p>The harmonized structure helps organisations running several standards. If you already hold <a href=\"\/OM\/iso-9001-certification-in-oman\/\">ISO 9001<\/a> or <a href=\"\/OM\/iso-27001-certification-in-oman\/\">ISO 27001<\/a>, your existing document control can usually serve the ABMS without duplication.<\/p>\n<div class=\"ias-band\">\n<ul>\n<li>ISO 37001:2025 current edition<\/li>\n<li>Transition deadline 28 February 2027<\/li>\n<li>Certification by IAS, accredited by UQAS<\/li>\n<li>Training and audit teams kept separate<\/li>\n<\/ul>\n<\/div>\n<h2><span class=\"ez-toc-section\" id=\"which-documentation-failures-show-up-again-and-again\"><\/span>Which documentation failures show up again and again?<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p><strong>Documents written for the auditor, not the user.<\/strong> If nobody in procurement can explain your own approval threshold, the procedure has failed however well it reads.<\/p>\n<p><strong>Records with no owner.<\/strong> Approvals signed &#8220;Management&#8221;. Reviews attributed to a committee. Somebody&#8217;s name belongs on a decision.<\/p>\n<p><strong>Scope drift.<\/strong> The scope statement says one thing; the records cover something narrower. Auditors notice quickly.<\/p>\n<p>Remember too that the standard addresses bribery in four directions: by the organisation, by its own personnel, by business associates acting for it, and bribery directed at the organisation. Records covering only outbound risk leave a visible gap \u2014 the inbound side, where your own staff are offered something, needs its own trail.<\/p>\n<figure class=\"ias-fig\"><img loading=\"lazy\" src=\"https:\/\/iasiso-gulf.com\/OM\/wp-content\/uploads\/2026\/09\/iso-37001-blog-om-fig3.jpg\" alt=\"ISO 37001 documented information \u2014 bribery directed at an organisation needs its own records\" width=\"1000\" height=\"561\" loading=\"lazy\" decoding=\"async\" \/><\/figure>\n<h2><span class=\"ez-toc-section\" id=\"where-does-training-fit\"><\/span>Where does training fit?<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p>You cannot build a defensible record set without people who know what the clauses ask for.<\/p>\n<p>The <strong>Foundation<\/strong> course runs half a day, four hours, self-paced online with 30 days&#8217; access. It teaches understanding of the standard. Completing it confers no qualification to audit.<\/p>\n<p>The <strong>Internal auditor<\/strong> course runs two days, 16 hours, available classroom or in-house, live virtual, or self-paced online with 30 days&#8217; access. It teaches you to audit your own organisation \u2014 in practice, to test records rather than count them. See <a href=\"\/OM\/iso-37001-internal-auditor-training-in-oman\/\">ISO 37001 internal auditor training in Oman<\/a>, the <a href=\"https:\/\/onlinecourse.eascertification.com\/internal-auditor\/online-sl-iso-37001-training\/\" target=\"_blank\" rel=\"noopener\">self-paced online route<\/a> or the <a href=\"https:\/\/onlinecourse.eascertification.com\/internal-auditor\/virtual-iso-37001-training\/\" target=\"_blank\" rel=\"noopener\">live virtual route<\/a>.<\/p>\n<p>The <strong>Lead auditor<\/strong> course runs five days, 40 hours, with the same three delivery routes, and prepares you to audit other organisations. Details sit on the <a href=\"\/OM\/iso-37001-lead-auditor-training-in-oman\/\">ISO 37001 lead auditor training in Oman<\/a> page and the <a href=\"https:\/\/onlinecourse.eascertification.com\/\" target=\"_blank\" rel=\"noopener\">online course platform<\/a>.<\/p>\n<p>On the auditor courses, assessment is continuous throughout, with a written examination closing the final day. No prior experience is required. IAS and EAS issue the certificates jointly, and the UQAS accreditation held by IAS extends to training schemes alongside certification. Trainers and auditors sit in separate teams, which impartiality requires rather than merely favours.<\/p>\n<p>This article makes no claim about the law in Oman or in any other country. Nothing here states or implies a legal duty, and legal obligations are a matter for your own advisers. Neither reading this article nor finishing any of the courses it describes turns anyone into an IAS auditor, and no registration of any sort follows from either.<\/p>\n<p>Worth repeating too: a certificate does not prove no bribery has occurred or will occur. What it records is that, on the date of the audit, a management system conforming to the standard was found to be in place. A certificate is not a clean record, not a recommendation and not a shield in law.<\/p>\n<div class=\"ias-cta2\">\n<p><strong>Ready to test your evidence file against the standard?<\/strong> Talk to us about <a href=\"https:\/\/www.iascertification.com\/iso-37001-certification\/\" target=\"_blank\" rel=\"noopener\">ISO 37001 certification<\/a>, or <a href=\"\/OM\/contact-us\/\">get in touch<\/a> to discuss the right training route for your team.<\/p>\n<\/div>\n<section class=\"ias-faq-section\">\n<h2 class=\"ias-faq-title\"><span class=\"ez-toc-section\" id=\"frequently-asked-questions\"><\/span>Frequently asked questions<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<details class=\"ias-faq-item\">\n<summary class=\"ias-faq-q\">Does ISO 37001 give me a list of mandatory documents?<\/summary>\n<div class=\"ias-faq-a\">\n<p>Not as a single checklist. The requirements sit in individual clauses, using &#8220;maintain&#8221; for documents and &#8220;retain&#8221; for records. The table earlier in this post gathers the core set in one place.<\/p>\n<\/div>\n<\/details>\n<details class=\"ias-faq-item\">\n<summary class=\"ias-faq-q\">How long do we have to keep anti-bribery records?<\/summary>\n<div class=\"ias-faq-a\">\n<p>The standard does not name a period. It asks you to control retention and disposition. Set a schedule you can justify against your own operating needs and follow it consistently.<\/p>\n<\/div>\n<\/details>\n<details class=\"ias-faq-item\">\n<summary class=\"ias-faq-q\">Can our records be entirely electronic?<\/summary>\n<div class=\"ias-faq-a\">\n<p>Yes. The standard is format-neutral. What matters is that records are identifiable, protected, retrievable and version-controlled.<\/p>\n<\/div>\n<\/details>\n<details class=\"ias-faq-item\">\n<summary class=\"ias-faq-q\">What does a stage 1 auditor look at first?<\/summary>\n<div class=\"ias-faq-a\">\n<p>Usually the scope statement, the policy, the bribery risk assessment and the internal audit programme. Inconsistency between those four is the fastest way to a delayed stage 2.<\/p>\n<\/div>\n<\/details>\n<details class=\"ias-faq-item\">\n<summary class=\"ias-faq-q\">Do we need a separate document control system for the ABMS?<\/summary>\n<div class=\"ias-faq-a\">\n<p>No. If you already control documents for another management system, extend it. Duplicate systems create version conflicts.<\/p>\n<\/div>\n<\/details>\n<details class=\"ias-faq-item\">\n<summary class=\"ias-faq-q\">How do we keep whistleblower records without exposing identities?<\/summary>\n<div class=\"ias-faq-a\">\n<p>Separate the case record from the identity record and restrict access to the second. Log who accessed it. Auditors test the process, not the informant.<\/p>\n<\/div>\n<\/details>\n<details class=\"ias-faq-item\">\n<summary class=\"ias-faq-q\">What documentation changes does the 2025 edition force?<\/summary>\n<div class=\"ias-faq-a\">\n<p>Climate change consideration in context records, terminology updates, explicit treatment of culture and conflict-of-interest awareness, M&amp;A as a control area, and clause-number updates in any checklist referencing clause 10.<\/p>\n<\/div>\n<\/details>\n<details class=\"ias-faq-item\">\n<summary class=\"ias-faq-q\">Where do I start if we have almost nothing?<\/summary>\n<div class=\"ias-faq-a\">\n<p>Scope, policy, risk assessment, then due diligence. Those four generate most of the rest. The <a href=\"\/OM\/iso-certification\/\">general ISO certification<\/a> and <a href=\"\/OM\/system-certification\/\">system certification<\/a> pages outline the wider route, and the <a href=\"\/OM\/frequently-asked-question\/\">FAQ page<\/a> answers common process questions.<\/p>\n<\/div>\n<\/details>\n<\/section>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>A practical guide for compliance officers, quality managers and internal auditors in Oman. Planning an ISO 37001 audit? Stage 1 is largely a documentation review. See how ISO 37001 certification in Oman works before you build your evidence file. Most anti-bribery systems fail their first audit on paper, not on principle. The policy exists. The&#8230; <\/p>\n<div class=\"clear\"><\/div>\n<p><a href=\"https:\/\/iasiso-gulf.com\/OM\/blog\/records-iso-37001-expects-you-to-keep\/\" class=\"gdlr-button with-border excerpt-read-more\">Read More<\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[],"class_list":["post-6596","post","type-post","status-publish","format-standard","hentry","category-uncategorized"],"_links":{"self":[{"href":"https:\/\/iasiso-gulf.com\/OM\/wp-json\/wp\/v2\/posts\/6596","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/iasiso-gulf.com\/OM\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/iasiso-gulf.com\/OM\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/iasiso-gulf.com\/OM\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/iasiso-gulf.com\/OM\/wp-json\/wp\/v2\/comments?post=6596"}],"version-history":[{"count":0,"href":"https:\/\/iasiso-gulf.com\/OM\/wp-json\/wp\/v2\/posts\/6596\/revisions"}],"wp:attachment":[{"href":"https:\/\/iasiso-gulf.com\/OM\/wp-json\/wp\/v2\/media?parent=6596"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/iasiso-gulf.com\/OM\/wp-json\/wp\/v2\/categories?post=6596"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/iasiso-gulf.com\/OM\/wp-json\/wp\/v2\/tags?post=6596"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}