+971528732160
enquiry@iascertification.com

28 Sep 2026

Nonconformity and Corrective Action Under ISO 37001 Clause 10.2: What the Standard Requires

/
Posted By
/
Comments0

Something has gone wrong. A due diligence file was signed off without the checks being done. A gift was accepted and never declared. An agent was paid a commission nobody can explain. Clause 10.2 of ISO 37001 tells you what to do next — and what to do so it stops happening.

Most organisations manage the first part. They fix the thing in front of them. Audits go wrong on the second: showing that the underlying cause was found, removed and checked. This post covers what clause 10.2 asks for, what auditors look at, and where the process usually breaks down.

Building an anti-bribery system that holds up under audit? See how ISO 37001 certification in Qatar is assessed, or start with the ISO 37001 internal auditor training that teaches your own people to raise findings properly.

  • Accredited by UQAS
  • Certification and training kept separate
  • Classroom, live virtual or self-paced
  • No prior experience required

What does clause 10.2 actually tell you to do?

Strip away the wording and clause 10.2 sets out a sequence. When a nonconformity occurs, you react to it, control it, correct it and deal with the consequences. Then you evaluate whether action is needed to eliminate the cause, so the same thing does not recur elsewhere. You implement that action, review whether it worked, and change the anti-bribery management system if you need to. And you keep records of the nonconformity and what followed.

Two phrases carry most of the weight. The first is “evaluate the need” — you may decide that no corrective action is warranted, but you have to show you thought about it. The second is “appropriate to the effects.” A missed declaration on a cheap pen does not deserve the same response as a missed declaration on a hospitality package from a bidder. The standard expects proportion, not uniformity.

Where does 10.2 sit in the 2025 edition?

The international yardstick for an anti-bribery management system is ISO 37001. The current edition is ISO 37001:2025, published in February 2025, replacing the 2016 version. Any certificate still held against the 2016 edition has until 28 February 2027 to transition.

Clause 10 was reordered. Continual improvement is now 10.1 and nonconformity and corrective action is 10.2 — the reverse of the old numbering. If your procedure still says “clause 10.1 nonconformity,” that is a documentation update, not a system change, but an auditor will notice and wonder what else was never reviewed.

Two other 2025 changes touch 10.2 indirectly. Clause 5.1.3 makes anti-bribery culture an explicit requirement, which matters because a culture where nobody reports anything produces a suspiciously empty log. Clause 8.4 brings mergers and acquisitions in as a non-financial control area — a fertile source of findings, since acquired entities rarely arrive with your controls running.

What counts as a nonconformity here?

A nonconformity is a requirement not met. That requirement can come from the standard itself, from your own policies and procedures, or from a commitment made to an interested party.

Findings cluster. Due diligence not done, done late, or done at the wrong depth for the risk. Gifts and hospitality outside the threshold and never escalated. Third-party contracts without anti-bribery clauses. Training not completed by people whose roles require it. Controls that exist on paper but that nobody has operated for eight months.

Note what a nonconformity is *not*. It is not automatically an allegation of bribery. Most findings are control failures. The standard covers bribery in four directions: by the organisation, by its own personnel, by business associates acting on its behalf, and bribery directed at the organisation. A nonconformity may sit in any of those lanes, or in none of them.

ISO 37001 corrective action under clause 10.2 — the moment an investigation starts from

Why is correction not corrective action?

This is the most common confusion, and it costs organisations findings at stage 2. Correction deals with the thing that happened. Corrective action deals with why it happened. You usually need both, recorded differently.

ScenarioCorrection — fixes what happenedCorrective action — removes the cause
A supplier was onboarded with no due diligenceRun the due diligence now; suspend payments until it clearsFind why the gate did not hold — an optional system field, an untrained approver, a deadline that made skipping normal — and change it
A manager accepted hospitality above the thresholdRecord it late, return or reimburse it, brief the managerTest whether the threshold is understood at that level; fix the rule or the register if either is unclear
An agent’s commission sits outside the contracted rateStop the payment, recover if appropriate, document the decisionCheck how it cleared approval at all; strengthen the finance control that should have stopped it
Training is largely incomplete in one functionChase and complete the outstanding trainingEstablish why that function was missed — an HR feed, a contractor population outside the system — and repair the mechanism

Write only the first column and you have a fix log, not a corrective action process. Auditors read the second column.

Why react first and investigate second?

Contain the exposure first. If money is about to move, stop it. If a relationship is live, decide whether to pause it. If records could be altered, secure them.

Then deal with consequences, which are broader than the transaction. A payment might need reversing. A contract might need reviewing. An interested party might need telling. Clause 10.2 does not tell you how to run any of that. It tells you that you must, and show you did.

One practical point. Keep the investigation and the corrective action separate in your records. An investigation asks what happened and who was involved. Corrective action asks what in the system allowed it. Mixing them produces a file that is all narrative and no system change.

How do you find the real cause without turning it into a hunt?

Root cause analysis here has an awkward feature: the cause is often a person. That is exactly why it needs discipline. “Employee ignored the policy” is a fact, not a cause. Ask the next question. Why was ignoring it possible? Why was it not detected for three months? Why did the control that should have caught it fail?

You do not need a formal methodology, though five whys works fine. You do need to keep going past the first plausible answer. Suppose a distributor was paid a “market development fee” with no evidence of any market development. The first answer is that the approver did not check. The useful answer sits further along — the invoice description was free text, the approval limit sat below the threshold that triggers second review, and the approver had never been shown what a suspicious description looks like. Three system weaknesses, one apparent human failing.

A caution on culture. Nothing kills reporting faster than a process that always ends in someone being blamed. If your log shows one or two findings a year in an organisation of any size, the likeliest explanation is not excellence. It is that people have learned not to raise things. The ISO 37001 lead auditor training spends real time on how findings are worded, because wording drives whether the next one gets reported at all.

What makes action appropriate to the effects?

Proportionality is a genuine decision, not a formality. Weigh the bribery risk exposed, how many relationships the weakness touches, whether the failure was one-off or systemic, and whether the same gap exists elsewhere.

That last test is most often skipped. If a due diligence gate failed in one procurement team, check the other three. Extending an action across sites, functions and acquired entities is what turns a finding into an improvement. It is also what connects 10.2 to 10.1 — continual improvement is largely the cumulative effect of actions that were extended rather than contained.

How do you check that the action worked?

Implementing an action is not the same as closing it. Clause 10.2 requires you to review the effectiveness of what you did, and effectiveness must be shown by something other than the action having been completed.

Sampling is the usual answer. If you rewrote a due diligence procedure, pull ten files onboarded since the change and see whether the gate held. If you added a second approval to a payment type, check whether it is applied or routinely overridden. Set the review date when you set the action, and give it to someone who did not do the work.

A finding closed the day the action was completed has not been reviewed for effectiveness. It has been marked done. That distinction is one of the practical skills covered in internal auditor training.

ISO 37001 corrective action under clause 10.2 — informal payments are easy to describe and hard to fix

What do your records have to show?

Clause 10.2 requires documented information on the nature of the nonconformity, the actions taken, and the results of corrective action. Auditors read those records before interviewing anyone. Here is the difference between a file that survives and one that does not.

What the auditor looks forWeak versionVersion that holds up
Description of the nonconformity“Procedure not followed”The requirement, the evidence, the date, the process and the scope affected
Immediate correction“Actioned”What was stopped, corrected or recovered, by whom, and when
Consequences consideredBlankPayments, contracts, relationships and reporting all addressed or explicitly ruled out
Cause analysis“Human error”The control that should have prevented it and the specific reason it did not
Extent checkNot performedSame control tested in other functions, sites or entities, with the result recorded
Action taken“Staff reminded”A change to a procedure, a system setting, an approval route or a competence requirement
Effectiveness reviewClosed same daySampled after a set interval by an independent person, with what was sampled recorded
System changeNoneWhere relevant, the procedure, risk assessment or control was formally updated

Where does clause 10.2 fail in real audits?

A few patterns repeat. The log is full of corrections and empty of causes. Every cause is “training” and every action is “retrain,” which by the third occurrence is itself evidence that the cause was never found. Actions have no owner or no date. Findings sit open for a year with no escalation. Effectiveness review is a tick box. And the anti-bribery function — whose role and independence the 2025 edition states more clearly — cannot see what is closed in its name.

There is also the reverse problem: a system that raises nothing. An empty log is a finding in itself, because clause 10.2 has nothing to operate on and the audit programme has evidently not been probing.

How do certification bodies raise findings?

Certification with IAS runs in two stages — stage 1 looks at readiness and documentation, stage 2 at whether the system works in practice. Findings raised at either stage come to you for correction, cause analysis and evidence, and the same expectations apply as for your own findings. The certification process and the broader ISO audit procedure set out how that runs.

The certificate that follows then sits within a three-year cycle: surveillance audits fall in the middle of it, and recertification closes it out. Each surveillance visit looks at what you have raised and closed since the last one. That record is one of the clearest signs of whether a system is alive.

Be clear about what certification means. What gets audited is a management system. Nothing in it proves that bribery has never happened or never will, and it works neither as an endorsement nor as a legal defence. What it records is that, on the date of the audit, a management system meeting the standard was found to be in place. IAS is accredited by UQAS; details sit on the accreditation page, alongside the guidance on using certification logos. The wider ISO 37001 certification scheme works the same way.

How do you build the competence to do this?

Handling clause 10.2 well is learned, not intuited. Three routes exist.

The Foundation course runs half a day — four hours, self-paced online only, with 30 days’ access. It teaches you to understand the standard. What it will not do is make anyone qualified to audit anything.

The internal auditor course runs two days, 16 hours, and teaches you to audit your own organisation against ISO 37001. Delivery is classroom or in-house, live virtual, or self-paced online with 30 days’ access.

Spanning five days and 40 hours across those same three routes, the lead auditor course prepares you to audit other organisations. On both auditor courses you are assessed as the course proceeds, with a written examination on the last day as well. No prior experience is required. IAS and EAS issue the certificates jointly under IAS’s UQAS accreditation, which extends to training schemes and not only to certification.

One structural point: the team that trains is kept separate from the team that audits. Impartiality demands that split; it is not a house preference. The wider ISO training range sits alongside these courses.

Two things this post does not do

This article makes no claim about the law in Qatar or any other country. Nothing here describes a legal duty; legal obligations are a matter for your own advisers.

Neither reading this post nor finishing any of the courses it describes turns a person into an IAS auditor, and no registration of any sort comes with either. Course certificates record completion of training. They are not appointments.

ISO 37001 corrective action under clause 10.2 — the arrangement no control caught in time

Ready to make clause 10.2 work properly? Talk to IAS about ISO 37001 certification, train your auditors through the ISO 37001 lead auditor course, or find out more about IAS.

Frequently asked questions

What is the difference between a nonconformity and a bribery incident?

A nonconformity is a requirement not met. A bribery incident is an act. Many nonconformities involve no bribery at all — a control simply did not operate. A confirmed incident will normally also be a nonconformity.

Does every nonconformity need corrective action?

No. Clause 10.2 asks you to evaluate whether action is needed to eliminate the cause. Sometimes no systemic cause exists. Record that evaluation and the reasoning.

Who should perform root cause analysis?

Someone close enough to the process to understand it and far enough to question it — often the process owner with an internal auditor. The anti-bribery function should see findings that touch bribery risk directly.

How long can a corrective action stay open?

The standard sets no period. Your own procedure should, and you should be able to explain any action past its date.

Can we close a nonconformity on the day we fix it?

You can close the correction. You cannot close the corrective action, because effectiveness has not yet been reviewed. Set a review date and close it once evidence exists.

Our nonconformity log is nearly empty. Is that good?

Usually not. It suggests weak internal auditing, a weak reporting culture, or both. Clause 5.1.3 in the 2025 edition makes culture explicit for exactly this reason.

When do we have to move to the 2025 edition?

Certificates issued against ISO 37001:2016 must transition by 28 February 2027.

Which course suits someone handling corrective actions?

Foundation to understand the standard. The two-day internal auditor course to audit your own organisation. The five-day lead auditor course to audit others.