Already thinking past stage 2? ISO 37001 certification in Qatar is a three-year arrangement, not a single visit. Ask IAS what years one, two and three will actually require of your team — talk to the Qatar office.
- Certificates issued by IAS under UQAS accreditation
- Two-stage initial audit, then annual surveillance
- Assessed against ISO 37001:2025
- Training delivered by IAS with EAS, separate from the audit team
Written by the IAS assessment team for organisations in Qatar that are past the planning stage.
Most guidance about anti-bribery certification stops when the certificate is issued. That is the easy part. The hard part is the twenty-four months after it, when the consultant has gone, the project budget has closed, and the anti-bribery function has a day job again. This page is about that period: surveillance visits, keeping a system alive between audits, the changes you must report to your certification body, why certificates get suspended or withdrawn, and what recertification asks for in year three.
If you are earlier in the journey, the certification process page covers the initial route. Read this one anyway. The decisions that make maintenance cheap or expensive are nearly all made before the first audit.

What does ISO 37001 certification in Qatar commit you to?
ISO 37001 defines the anti-bribery management system, commonly abbreviated to ABMS, at international level. It sets out what an organisation must put in place to prevent, detect and respond to bribery. The current edition is ISO 37001:2025, published in February 2025, which replaced the 2016 version. Certificates held against the 2016 edition need to transition by 28 February 2027.
The standard deals with bribery in four directions. Bribery by the organisation itself. Bribery by its own people acting on its behalf. Bribery by business associates — agents, distributors, subcontractors, joint venture partners — acting for it. And bribery aimed at the organisation, where someone is trying to buy your staff. A system that only defends one of those four is not conformant, and surveillance auditors in Qatar tend to find the gap in the third and fourth.
What you commit to on the day the certificate is issued is this: the system stays running, evidence keeps accumulating, and an auditor comes back to look at it. The audit cycle is a two-stage initial assessment, then the certificate, then surveillance audits each year, then recertification. Nothing about that cycle is passive. A certificate is a statement that a system was working when it was looked at, and that it is expected to keep working. Where firms in Qatar get into trouble is treating the certificate as an asset that sits in a drawer.
Commercially, the pressure is straightforward. Buyers ask. Main contractors ask subcontractors. Parent companies push requirements down to Gulf subsidiaries. Those requests come back every year as verification requests, which is why a lapsed or suspended certificate is more damaging than never having held one.
What does the certification cycle look like?
The pattern below is the standard three-year shape. Durations, sample sizes and visit dates depend on your size, sites and risk profile, and are set by IAS when your programme is planned. Use the table for what happens, not for how long it takes.
| Point in the cycle | What is being asked | What usually gets sampled | Common failure |
|---|---|---|---|
| Stage 1 | Is the system designed and documented, and are you ready? | Bribery risk assessment, policy, scope, function's terms of reference | Scope excludes an associate-heavy business line |
| Stage 2 | Is it actually operating? | Due diligence files, gift and hospitality register, training records, concern reports | Records that all start the month before the audit |
| Certificate issued | — | — | Team disbands, ownership becomes unclear |
| Surveillance, year one | Has it kept running, and were the stage 2 findings closed properly? | Corrective actions, internal audit, management review, new business associates | Corrective action closed with a promise, not evidence |
| Surveillance, year two | Is it maturing, and has anything material changed? | Risk assessment update, controls over new activities, investigation records | Risk assessment never revisited after certification |
| Recertification | Does the whole system still conform, across the full scope? | Everything above, over the full cycle, plus effectiveness | Three years of evidence with an eighteen-month hole in it |
What does a surveillance auditor actually open?
Surveillance is not a shorter repeat of stage 2. It is a sample, chosen deliberately, and the choices are fairly predictable once you have watched a few.
The first thing opened is usually the previous report. Every nonconformity raised last time gets re-tested — not the paperwork closing it, the thing itself. If your due diligence on agents was inconsistent, the auditor picks agents onboarded since, not the ones you fixed.
Second is anything with a date on it. Training completion, internal audit, management review, risk assessment review, register entries. Dates are how an auditor tells a live system from a revived one. Twelve gift register entries spread across the year read very differently from twelve entered in one week.
Third is whatever changed. New country of operation, new joint venture, new major client, a restructure that moved the anti-bribery function under someone it now reports on.
Fourth is the concern-raising route. Auditors test whether it works, whether people know it exists, and whether whistleblowers are protected in practice. A channel nobody has ever used is not automatically a finding. A channel nobody has heard of is.
The ISO audit procedure page sets out how IAS structures visits. A related piece on what a surveillance audit looks at covers a different scheme, but the sampling logic carries over.
How do you keep the system alive between audits?
Systems do not fail on audit day. They fail quietly, some time in month four, and the failure is discovered a year later.
The organisations that maintain ISO 37001 certification in Qatar without drama tend to run a simple rhythm rather than an annual scramble:
- Every month. Gifts, hospitality, donations and sponsorship entries reviewed and signed off by someone who is not the person who received or gave them. Ten minutes if done monthly. Two days if done annually.
- Every quarter. New business associates checked against the due diligence tier they were assigned. New starters in exposed roles confirmed as trained, including on conflicts of interest.
- Twice a year. A short internal audit slice rather than one large one. Small slices find things; one big annual audit finds whatever is on the surface that week.
- Annually, before surveillance. Risk assessment reviewed against what the business actually did this year. Management review held with real inputs and real decisions, minuted.
- Whenever it happens. Concerns logged, investigations recorded, outcomes documented even where nothing was substantiated. A closed investigation with no written outcome is a gap.
Clause 5.1.3 of the 2025 edition makes anti-bribery culture an explicit requirement, which raises the bar on this rhythm. Culture is not evidenced by a poster. It is evidenced by decisions — a refused gift, a supplier not appointed, a bid walked away from, and the record showing why.

Which changes are you obliged to report?
This is the clause most certified clients have never read. Your agreement with your certification body requires you to notify IAS, without waiting for the next visit, when something material changes. Reporting it is routine. Not reporting it, and having the auditor discover it at surveillance, is not.
Tell IAS when any of these happen:
- Legal name, ownership or control changes, including acquisition by or of another business.
- A change of address, or a new site that falls inside the certified scope.
- Activities are added or dropped — a new service line, a new sector, a new country of operation.
- The scope of the management system itself changes.
- The anti-bribery function changes hands, or its reporting line moves.
- Anything happens that could affect the system's ability to keep meeting the standard.
Mergers and acquisitions deserve their own line. Clause 8.4 of the 2025 edition brings M&A in explicitly as a non-financial control area. If you acquire a company, you have acquired its bribery risk, its associates and its history. An auditor will ask what due diligence was done before the deal closed, not after.
How do certificates get suspended or withdrawn?
Certificates are not withdrawn as a surprise. There is a sequence, and there are usually several exits from it.
A major nonconformity is a failure that breaks a requirement outright — no bribery risk assessment, no functioning due diligence, no anti-bribery function, or a control that exists on paper and nowhere else. It carries a deadline for correction, with evidence, and often a follow-up visit.
A minor nonconformity is a lapse in an otherwise working system. One missed register review. A training record not filed. These are corrected and verified at the next visit. Minors matter when they repeat: the same minor three cycles running stops being a lapse and starts being a system that does not self-correct.
Suspension typically follows a major nonconformity not corrected in time, a surveillance audit that was due and did not happen, repeated postponement or refusal of access, misuse of certification marks, or a change so significant that the certified scope no longer describes the organisation. A suspended certificate is not valid, and you must stop presenting it as though it were.
Withdrawal comes after a suspension that is not resolved, or where the system has stopped functioning altogether. Getting back afterwards is not a quick re-issue.
The two avoidable causes, in practice, are missed surveillance visits and logo misuse. The first is a diary problem. The second is usually marketing acting in good faith — putting an accreditation mark on a product, or on a document outside the certified scope. The logo usage guideline is worth sending to whoever controls your templates, before they need it.
What does the 2025 edition mean inside a running system?
If you certified against ISO 37001:2016, you have until 28 February 2027 to move to the 2025 edition. Most organisations will do it at a surveillance or recertification visit rather than as a separate exercise. The table below is written for a system already in operation: what changed, and what an auditor will want to see in your live records because of it.
| What changed in ISO 37001:2025 | What your running system has to show |
|---|---|
| Harmonized common ISO structure adopted | Cross-references, procedure numbering and internal audit checklists updated to the new clause map |
| "Stakeholders" replaced by "interested parties" | Context and communication records using the current term, not a find-and-replace over one document |
| Clauses 4.1 and 4.2 require climate change to be considered | A recorded consideration of whether climate change is relevant to your context and interested parties, with the reasoning either way |
| Clause 5.1.3 makes anti-bribery culture an explicit requirement | Evidence of leadership behaviour and decisions, not only a signed policy |
| Clause 7.2.2 adds conflict-of-interest awareness to employment processes | Recruitment, onboarding and role-change records showing conflicts of interest were addressed |
| The anti-bribery function's role and independence stated more clearly | Terms of reference, reporting line and authority documented, with independence that survives an org chart change |
| Clause 8.4 adds mergers and acquisitions as a non-financial control area | Pre-deal due diligence and post-deal integration of controls, evidenced |
| Clause 10 reordered — continual improvement at 10.1, nonconformity and corrective action at 10.2 | Improvement treated as an ongoing input, not only as a reaction to findings |
Transition is mostly documentary if your system was working. It is a rebuild if it was not.
What does recertification in year three ask for?
Recertification is a full-scope assessment, not a large surveillance visit. The auditor looks across the whole cycle, and asks a question surveillance does not: has this system been effective?
Effectiveness is judged on evidence of the system doing something. Risks reassessed as the business changed. Due diligence that led to a decision, including occasionally a negative one. Concerns raised, handled and closed. Internal audit findings that led to changes. Training that reached the right roles rather than everybody equally.
Plan it early enough that the audit, any corrective action and the certificate decision all fit before the current certificate expires. Leaving it to the final weeks is the commonest way to end up with a gap in cover — and a gap is exactly what a client's procurement portal flags.
What does it cost to hold ISO 37001 certification in Qatar?
We do not publish figures here, because audit effort depends on your headcount, number of sites, risk profile, scope and how many business associates sit inside it. IAS will quote for the full three-year cycle rather than the first audit alone, and you should insist on seeing it that way. A quotation that covers stage 1 and stage 2 only tells you about a third of what ISO 37001 certification in Qatar costs.
The variables that move the price:
- Scope. Every site and activity you include is audited. Include what you genuinely need certified, not everything you own.
- Business associates. A high-volume agent and subcontractor network takes more sampling than a short direct-supply chain.
- Risk profile. Sectors and dealings with higher exposure carry more audit time.
- Multi-standard programmes. If you also hold ISO 9001, ISO 27001 or ISO 22301, combining visits reduces disruption and travel.
The larger cost is internal and recurring: the anti-bribery function's time, due diligence checks, register reviews, internal audits. Budget it as an annual line. Organisations that fund only year one usually pay more in year three, because they rebuild rather than maintain.
Where do certified organisations lose the most time?
Patterns from surveillance and recertification visits, rather than from the initial audit:
Ownership evaporates after certification. The project lead moves on, the function becomes a title without authority, and nobody is sure who signs off the gift register. Name a deputy at the start.
The risk assessment is frozen at day one. The business opened a new line and took on twenty subcontractors, and the risk assessment still describes the company that existed at stage 2.
Corrective actions are closed with intentions. "Staff have been reminded" is not evidence. What changed, who verified it, and what does the record look like now?
Due diligence is a one-off. Associates are screened at onboarding and never again, even after the relationship's value or exposure changes materially.
Records are made for the auditor. A year of activity compressed into the fortnight before a visit is visible from the first page.
Surveillance dates drift. Postponements accumulate, the anniversary passes, and a diary problem becomes a suspension.
What does the certificate not say, and what about accreditation and marks?
The issuing body is IAS, operating under UQAS accreditation. That accreditation belongs to IAS as the certification body — it is not transferred to you. Your organisation becomes certified. It does not become accredited, and describing itself as accredited is one of the quickest ways to attract a marks-misuse finding. Details are on the accreditation page and on the group's accreditation overview.
Now the important limit. An ISO 37001 certificate does not prove that no bribery has taken place in your organisation, and it does not promise that none will. The standard states this about itself. What the certificate says is narrower: an independent body examined your anti-bribery management system against a defined set of requirements, sampled the evidence, and found it conformant on the days it looked. Anyone selling it as proof of a clean history is misdescribing it.
Certificates issued by IAS can be checked through the certification search. Point clients there rather than emailing scans.
Which training keeps the system running?
The system is maintained by people, and the people change. Lead auditor and internal auditor training is delivered by IAS together with EAS, under IAS's UQAS accreditation, which covers training schemes as well as certification. The team that delivers training is kept separate from the team that audits — that separation is an impartiality requirement, not an administrative preference.
Training does not certify anything. Completing a course qualifies an individual to do a job; it does not make an organisation conformant, and no course substitutes for an audit. What it does change is the quality of your internal audits, and internal audit quality is the single best predictor of a quiet surveillance visit.
For a system in maintenance, internal auditor training is usually the more useful of the two, with lead auditor training for those running the programme. The wider training catalogue and the EAS online courses cover scheduling.

How this page was checked
The technical content here comes from ISO 37001 itself, from the changes introduced in the 2025 edition, and from how IAS runs its audit programme. Clause references and the 28 February 2027 transition date were checked against the published standard.
Plainly stated: this page makes no claim about the law in Qatar. It does not say that ISO 37001 certification is required, mandated, regulated or endorsed by any authority here, and nothing on it should be read that way. Where we describe pressure to certify, that pressure is commercial — tenders, buyers, main contractors, parent companies. For any question about legal obligation, take advice from a qualified professional in Qatar. We do not give it, and a certification body should not.
No client names, figures, audit durations or prices are given, because we would have to invent them. Anything specific to your organisation comes from a scoping conversation, not from a web page.
Your next step
If you are certified, do three things this month. Put every remaining visit in the cycle into a shared calendar with a named owner. Read your certification agreement's notification clause and check nothing on the list has already happened unreported. Then open your risk assessment and ask whether it describes the business you run today.
If you are not certified yet, ask for a quotation covering the whole cycle and plan the maintenance rhythm before stage 1, not after the certificate arrives.
Background reading: the system certification overview, the ISO certification index, about IAS, the general FAQ and the IAS Qatar home page.
Book the whole cycle, not just the first audit. Send IAS your scope, sites and business associate profile, and ask for a three-year programme — request a quotation for ISO 37001 certification in Qatar.
Frequently asked questions
How soon after certification is the first surveillance audit?
Surveillance is annual within the three-year cycle, with the first visit scheduled against your certification decision date. IAS confirms the window when the programme is set. Treat it as a fixed anniversary, not a moveable one.
Is surveillance the same as the stage 2 audit?
No. Surveillance samples parts of the system, weighted toward previous findings, dated records and anything that has changed. Recertification is the full-scope assessment.
Can our certificate be suspended over a logo?
Misuse of certification marks is a recognised route to suspension, though a first instance is usually corrected. The logo guideline tells you what is permitted where.
Our anti-bribery manager has resigned. Is that reportable?
Report a change to the anti-bribery function or its reporting line. The requirement is that the function has authority and independence — an interim arrangement that reports to the wrong person will be a finding.
How do we prove anti-bribery culture at an audit?
Through decisions, not statements. Refused gifts, declined suppliers, escalations, conflicts declared and managed. Clause 5.1.3 made this explicit in the 2025 edition.
Does climate change really apply to an anti-bribery system?
Clauses 4.1 and 4.2 require you to consider it when determining context and interested parties. A short, recorded consideration with your reasoning is what an auditor expects to see.
Can we combine ISO 37001 surveillance with our other certifications?
What if we never receive a single bribery concern?
That is not automatically a finding. What matters is whether the channel works, whether people know about it, and whether protection for whistleblowers is real. Auditors will test awareness.