Most internal audit programmes are strongest at the start and weakest at the end. Raising a finding is satisfying. Chasing it six weeks later is not. This ISO 37001 internal auditor training in Qatar is built around that unloved final step: proving that a corrective action did what it promised. Over two days you learn to plan an audit, gather evidence, write a defensible finding, and then verify the fix instead of accepting it. The course is for auditing your own organisation's anti-bribery management system under clause 9.2. It is delivered by IAS with EAS.
Book the two-day internal auditor course for your own audit team through the IAS internal auditor training programme, in classroom, in-house, virtual or self-paced format in Qatar.
What is the gap between a fix promised and a fix proved?
Here is a pattern you will recognise. An internal audit finds that gifts above a threshold were not declared. The department head responds quickly. A new declaration form is written, an email goes out, and the action is marked complete. The finding is closed. Twelve months later the same issue appears again.
Nothing dishonest happened. The action was real. It simply was not effective, and nobody checked. Closure was granted on the strength of a document rather than on evidence of changed behaviour.
That gap is where most anti-bribery management systems quietly lose ground. It is also where an internal auditor adds the most value. A correction that has been verified is worth more to your management than five new findings that have not.
Good ISO 37001 internal auditor training treats verification as a skill with its own techniques, not as administrative tidying. On this course you spend a meaningful share of the sixteen hours on it.
- Two days, 16 hours of instruction
- Classroom, in-house, virtual or self-paced
- No prior auditing experience required
- Certificate issued by IAS with EAS
What does clause 9.2 require of you?
Clause 9.2 of ISO 37001 asks the organisation to run internal audits at planned intervals. The audits must tell management whether the anti-bribery management system conforms to the organisation's own requirements, conforms to the standard, and is effectively implemented and maintained.
Read the last part again. Effectively implemented. The clause does not ask whether controls exist on paper. It asks whether they work in practice.
An internal audit programme has to be planned, and the plan has to consider the importance of the processes involved and the results of previous audits. Previous audits means previous findings. It means the actions that came out of them. A programme that never revisits last year's corrective actions is not really considering previous results at all.
Clause 9.2 also expects auditors to be objective and impartial, and expects results to be reported to relevant management. Nothing in the clause says an auditor closes their own finding on trust. The course teaches you to read the clause the way a certification body auditor will read it, and to build an internal audit programme that can survive that reading.
Why is action taken not the same as action effective?
Delegates often arrive believing corrective action means "do something about it". The standard's expectation is narrower and more useful.
There are three separate things, and they get confused constantly:
- Correction. The immediate repair. The undeclared gift is recorded late. The missing due diligence file is completed.
- Corrective action. Removing the cause, so the same failure does not recur. Why was the gift not declared? Did anyone know the threshold?
- Verification of effectiveness. Evidence, gathered after the action, that the cause is genuinely gone.
Most closed findings in a young management system have only the first. The correction is done, the corrective action is described, and effectiveness is assumed.
A trained internal auditor separates those three in writing. You will practise phrasing a finding so the response cannot collapse into a quick patch. You will also practise the harder conversation: telling a colleague that their action was real, sensible, and still does not close the finding.

What counts as proof that a fix worked?
Verification fails when the auditor accepts the artefact that was created *by* the action instead of evidence produced *after* it. A new policy proves a policy was written. It proves nothing about conduct.
The table below is the working tool you will use in class. It comes back in every exercise on day two.
| Claimed fix | What would actually prove it | What only looks like proof |
|---|---|---|
| New gifts and hospitality threshold issued | Declarations logged after the issue date, tested against invoices and expense claims for the same period | A copy of the signed policy and its revision number |
| Anti-bribery awareness training rolled out | Sampled staff explaining, in their own words, what they must refuse and who they tell | An attendance sheet and a completion percentage |
| Due diligence tightened for high-risk agents | Files for agents engaged after the change, showing the new depth applied before contract signature | A revised due diligence procedure with a new flowchart |
| Conflict-of-interest declarations added at hiring | Completed declarations in recent personnel files, including for internal transfers and promotions | An updated recruitment checklist |
| Approval limits reduced for facilitation-risk payments | System configuration evidence plus a sample of transactions rejected or escalated since the change | A memo from finance announcing the new limits |
| Whistleblowing channel made anonymous | Test submission records, response times, and evidence that reports reached the anti-bribery function | A poster in the staff canteen and an intranet banner |
| Contract clauses added for business associates | Executed contracts signed after the change containing the clause, sampled across regions | A clause library entry and legal sign-off email |
Two habits come out of that table. First, always look at the period *after* the action, never before. Second, sample from the real population, not from the examples your auditee has prepared.
When can a finding be closed, and when does it stay open?
Closure is a decision, and decisions need criteria. Without them, closure drifts towards whoever is most persuasive or most senior.
| Situation | Closure decision | What the auditor records |
|---|---|---|
| Action complete, effectiveness evidence sampled and clean | Close | Sample size, period covered, evidence reviewed, date verified |
| Action complete, but too recent for any output to exist yet | Keep open, set a verification date | Action accepted; effectiveness check scheduled |
| Action complete, sample shows the old behaviour continuing | Keep open, escalate | New evidence, why the action did not reach the cause |
| Action addresses the symptom only | Keep open | Stated cause, why the action does not remove it |
| Action delayed, with an agreed revised date and owner | Keep open, track | Reason for delay, revised date, who approved it |
| Evidence offered is the procedure itself | Keep open | Request for post-implementation evidence |
| Finding overtaken by a process that no longer exists | Close with justification | Written rationale, confirmation the process has genuinely ceased |
| Same finding raised in a previous cycle and closed before | Keep open, treat as recurrence | Link to the earlier finding and its closure evidence |
That last row matters more than the others. A repeat finding is a signal about your verification, not only about the auditee. If something you closed has come back, the closure itself was weak. The course teaches you to say that in a report without turning it into blame.

How is the two-day internal auditor course built?
ISO 37001 internal auditor training runs to sixteen hours, split across two days. Day one gives you the standard and the audit method. Day two puts you in front of evidence and makes you decide.
| Session | Day one focus | Day two focus |
|---|---|---|
| Opening | ISO 37001:2025 structure, the four directions of bribery risk | Review of day one findings, written for real |
| Core teaching | Clause 9.2, programme planning, audit criteria, checklists | Follow-up planning, sampling after change, effectiveness testing |
| Practical work | Evidence types, questioning technique, note-taking | Verification exercise using the proof table, closure decisions |
| Group work | Building an ISO 37001 audit checklist from the clauses | Defending a closure decision to a sceptical peer group |
| Close | Writing conformity and nonconformity statements | Reporting to management, then written examination |
The written examination sits at the end. Assessment runs continuously through both days as well, so the tutor sees how you handle evidence, not only how you answer questions. Both elements count.
You leave with your own checklist draft, a follow-up register format, and a set of worked verification examples you can reuse at your desk.
How do you re-test a control after the fix?
Re-testing is the practical core of day two. It is not complicated, but it needs discipline.
Start by defining the population correctly. If the control changed on a particular date, your population begins on that date. Anything earlier belongs to the old system and tells you nothing about the fix.
Next, decide your sample before you look at the data. Auditors who choose samples after browsing the records tend, without meaning to, to pick the tidy ones.
Then test the control the way it is supposed to operate, end to end. If a payment above a threshold must be escalated, find payments above the threshold and follow them. Do not ask whether escalations happened. Find transactions and see.
Finally, look for the workaround. When a control tightens, work finds another route. Payments split into smaller amounts. Approvals move to a different cost centre. Gifts become "sponsorships". Re-testing that ignores displacement misses the point entirely.

How do you audit colleagues you already know?
An internal auditor audits their own organisation. You will audit people you sit with, travel with and eat lunch with. Technique is rarely the hard part. Objectivity is.
Verification makes this sharper than the original audit did. Raising a finding can feel like reporting a system problem. Refusing to close a finding feels like doubting a person.
Some rules help, and the course works through them properly:
- Do not audit work you performed, designed or approved yourself.
- Do not verify a corrective action you helped to design, however sensible your idea was.
- Say what evidence would satisfy you at the moment you raise the finding, not later.
- Put the verification date in writing when the action is agreed.
- Keep the finding about the control, and the evidence about the record.
Where an organisation is small and everybody has touched everything, you manage the conflict rather than pretending it is absent. You can pair auditors across departments. You can have a second person review closure decisions. You can escalate to the anti-bribery function. What you cannot do is verify your own work and call it independent.
What did ISO 37001:2025 change for follow-up?
For anti-bribery management systems, the international standard is ISO 37001. ISO 37001:2016 has given way to ISO 37001:2025, which appeared in February 2025. Organisations holding certificates to the 2016 edition transition by 28 February 2027.
The changes that affect an internal auditor most:
- The standard now follows the harmonized structure used across modern management system standards, so an auditor familiar with ISO 9001 or ISO 27001 will find the shape familiar.
- "Stakeholders" is now "interested parties".
- Climate change has to be weighed under clauses 4.1 and 4.2, both as a context issue and within what interested parties need.
- Clause 5.1.3 puts anti-bribery culture on the page as a stated requirement.
- Awareness of conflicts of interest is pulled into hiring and employment processes by clause 7.2.2.
- The 2025 text is clearer about the anti-bribery function — both its remit and its independence.
- Non-financial controls under clause 8.4 have widened to take in mergers and acquisitions.
- The two subclauses of clause 10 change places: continual improvement becomes 10.1, nonconformity and corrective action 10.2.
Culture under clause 5.1.3 changes verification work more than anything else on that list. Culture cannot be evidenced by a document. You verify it through what people say, what gets escalated, what gets refused, and what happens to the person who refuses. The course shows you how to gather that evidence without turning an audit into an opinion survey.
ISO 37001 covers bribery in four directions: by the organisation, by its own personnel, by business associates acting on its behalf, and bribery directed at the organisation. Verification should cover all four. In practice, the fourth is the one most follow-up work forgets.
Internal auditor or lead auditor: which course do you need?
The distinction is simple. Across two days, this course readies you to audit the organisation that employs you. A lead auditor course is a longer, different product, built for people who audit other organisations and lead audit teams.
If your job is to run first-party audits under clause 9.2 and report to your own management, the internal auditor course is the right one. IAS runs lead auditor courses across other standards too, including ISO 45001, ISO 14001, ISO 22301 and ISO 50001. The full training catalogue sets out the range.
How is the course delivered, and who should attend?
You can take ISO 37001 internal auditor training in the way that fits your organisation:
- Classroom or in-house. At your own premises in Qatar, or at an IAS training centre. In-house works well when a whole audit team trains together on real examples.
- Virtual instructor-led. Web conferencing carries the class live; the tutor and the exercises do not change.
- Self-paced. ISO 37001 training online, with 30 days of access to the course material, through the EAS online course platform.
No prior auditing experience is required. Familiarity with ISO 37001 is recommended, because two days is not long enough to learn the standard from zero and audit it as well.
The course suits compliance and ethics staff, internal audit and risk teams, quality and management system coordinators, legal and procurement staff, HR professionals handling declarations and screening, and managers asked to sit on an audit programme. Organisations in Qatar working across construction, energy services, logistics, hospitality and professional services often draw internal auditors from several of those functions at once. That mix is an advantage, not a problem, because it spreads the follow-up load.
How is the course assessed, and what does the certificate not mean?
Assessment is continuous through the course and finishes with a written examination. Delegates who complete it are given a certificate of completion carrying both IAS and EAS.
The course comes from IAS working alongside EAS. Training schemes fall inside IAS's UQAS accreditation, as does its certification work. Trainers and auditors work as separate teams inside IAS. Impartiality demands that division rather than convenience, and it holds regardless of who books the course.
Two things need saying plainly. Nobody becomes an IAS auditor by finishing ISO 37001 internal auditor training. It is not a route into auditing for IAS, and it confers no auditor status with IAS or EAS. Your employer, equally, earns no certificate from the fact that you sat in the room. Your organisation's anti-bribery management system is certified, if at all, through a separate certification process carried out by a certification body. Training your people and certifying your system are different things with different evidence.
Internal audits are also not a substitute for certification. They are one input that a certification body's auditor will examine, as evidence that clause 9.2 is being met. That is exactly why verified closures matter. When an external auditor samples your follow-up register, well-evidenced closures speak for the whole programme.
A note on local law
What is set out here is a training course, together with what an international standard asks for. It makes no statement about the law in Qatar. Nothing here should be read as legal advice, as a claim about any legal obligation, or as a statement that any authority requires this course, this standard or certification to it. If you need to understand how anti-bribery obligations apply to your organisation, take qualified legal advice in your own jurisdiction.
Where does certification fit alongside internal auditing?
Internal auditing under clause 9.2 is your organisation's own check on itself. Certification is a separate, independent assessment. The two support each other, but neither replaces the other.
If your organisation is considering certification, the ISO 37001 certification route in Qatar sets out what that involves, and the general certification process explains the stages. IAS also operates system certification and product certification across other standards. Organisations that already hold certificates should read the guidance on using certification logos before publishing any claim.
Train your team to close findings properly. Ask about the two-day ISO 37001 internal auditor course in classroom, in-house, virtual or self-paced format — contact IAS in Qatar to arrange dates for your audit team.
Frequently asked questions
What is ISO 37001 internal auditor training?
It is a course that prepares you to plan and carry out internal audits of an anti-bribery management system in your own organisation. You learn to gather evidence, write findings, verify corrective actions and report to your own management under clause 9.2.
Over how many days does the internal auditor course run?
Two, carrying sixteen hours of instruction. Choose self-paced and those two fixed days become 30 days of access to the material.
Do I need auditing experience before attending?
No. No prior auditing experience is required. Familiarity with ISO 37001 is recommended so that the two days can focus on audit practice.
Can I audit my own department?
Auditing work you performed, designed or approved yourself is not acceptable under clause 9.2's objectivity expectation. In a small organisation, manage the conflict by swapping auditors between departments or having closure decisions reviewed by someone else.
Can I verify a corrective action that I suggested?
No. If you helped design the fix, you should not be the person who judges whether it worked. The course covers practical ways to hand that verification to another auditor.
How often must internal audits be done?
Clause 9.2 requires audits at planned intervals, determined by the organisation. The programme should reflect the importance of the processes concerned and the results of previous audits. The standard does not fix a frequency for you.
What if the same finding keeps coming back?
Treat it as a recurrence and reopen it. A repeat finding usually means the earlier closure was granted on weak evidence. Say so in the report, factually, and link the two findings.
Can the course be run at our own premises in Qatar?
Yes. In-house delivery is available at your site, which lets the exercises use your own audit programme, findings and follow-up register. You can read more about IAS or explore the Qatar services overview.
*Prepared by the IAS training team, delivered by IAS with EAS under IAS's UQAS accreditation.*