How to Decide the Scope of Your ISO 37001 Anti-Bribery Management System
Thinking about certification? See how ISO 37001 certification in Saudi Arabia works before you fix your scope. The boundary you write now is the boundary an auditor will test later.
Scope is the first real decision in an anti-bribery management system, and the one most teams rush. People treat it as a paragraph to be written at the end, once the policy and procedures are done. It works the other way round. The boundary decides which risks you assess, which people you train, which contracts you check and which parts of the business an auditor may walk into. Get it wrong and you spend a year building controls in the wrong places.
This post is about that one decision. Risk assessment method, due diligence design and management review are separate subjects. Here we stay on the boundary: what goes inside it, what sits outside, and how to write it so it survives an audit.
What does scope actually mean in ISO 37001?
Scope is the answer to a simple question: which parts of this organisation does the anti-bribery management system apply to?
It has three dimensions, and confusing them is the most common early error.
- Organisational: which legal entities, divisions and functions.
- Geographic: which countries, sites, offices, plants, project locations.
- Activity: which products, services, contracts and processes.
A scope naming only the entity is not a scope. Nor is one naming only an office address. You need all three, and they must agree.
An anti-bribery management system is measured against ISO 37001. The current edition is ISO 37001:2025, published February 2025, replacing the 2016 version. Where a certificate was issued against the 2016 edition, it stays valid only until the transition cut-off of 28 February 2027. Set your scope against the 2025 text.
Why start with the organisation, not the certificate?
The instinct is to ask “what do we want on the certificate?” That is backwards. Ask instead: where can bribery realistically happen to us or through us?
Suppose a contracting group runs three businesses: civil works, facilities management and a small equipment trading arm. The civil works business bids for large tenders through agents. The trading arm imports goods and deals with customs brokers. The facilities arm sells to a handful of long-standing private clients.
Two of those three carry obvious exposure. A scope drawn around “the head office” captures neither. A scope drawn around “civil works division, named offices, tendering and project delivery for infrastructure contracts” tells you exactly where to look.
Start from the risk picture. Then decide the boundary. Then write it down.
What do the four directions of bribery do to your boundary?
ISO 37001 deals with bribery in four directions:
- bribery by the organisation itself;
- bribery by its own personnel acting on its behalf;
- bribery by business associates acting for it;
- bribery directed at the organisation.
That fourth one changes scope thinking for many teams. If someone is trying to bribe your procurement staff, tender evaluators or quality inspectors, those functions belong inside the boundary — even though they never hand anything to anybody. A scope covering only outward-facing sales and tendering misses half the standard.

How do legal entities, sites and activities differ in a scope statement?
Teams routinely answer one and assume they have answered all three. A legal entity can operate from six locations. A site can host two entities. Tendering can run across both. Write them out separately, then reconcile.
Ask, entity by entity: does this one make its own commercial decisions, hold its own contracts, appoint its own agents? If so, it is hard to justify leaving it out while keeping its parent in.
Ask, site by site: what actually happens here? A warehouse with no purchasing authority carries different risk to a project site that raises variation orders and signs off subcontractor claims.
Ask, activity by activity: who has discretion? Discretion plus value equals exposure. Anyone who can approve, reject, prioritise or delay something a third party wants is someone the system needs to cover.
What can you leave out, and what can you not?
You may exclude parts of the organisation. You may not exclude them because they are inconvenient.
A defensible exclusion has a reason a stranger can follow. A dormant subsidiary with no staff and no transactions can go. So can a recently acquired business still running on separate systems, for a defined period, provided you say so plainly.
An indefensible exclusion removes the risky part. If your agent-led export business sits outside the boundary and your domestic direct-sales business sits inside, an auditor will ask why. “It was harder” is not an answer.
The test: if an outsider read your scope statement, then a list of your real activities, would they feel misled? If yes, redraw it.
Why do business associates sit outside the boundary but inside the risk?
This causes more argument than any other part of scope.
Your agents, distributors, consultants, subcontractors and intermediaries are not part of your management system. You do not certify them. But their conduct on your behalf is squarely within the standard’s concern, so your controls over them are inside your scope.
So the scope statement does not list your business associates. It covers the processes that govern them — selection, due diligence, contracting, payment, monitoring, termination. Those belong to you. The boundary follows your control, not your relationships.
What does a defensible scope statement look like?
| Feature | Weak scope statement | Defensible scope statement |
|---|---|---|
| Entities named | “The Company and its subsidiaries” | Each entity named, with the ones excluded and the reason |
| Locations | “Saudi Arabia” | Named offices, plants and project locations, with a rule for new sites |
| Activities | “All business activities” | Tendering, procurement, contract award, subcontractor management, agent appointment |
| Exclusions | None mentioned, though several exist | Stated openly, each with a justification a third party can follow |
| Relationship to risk | No link shown | Traces directly to the risk assessment findings |
| Interfaces | Silent on shared services | Says how group functions such as legal and finance are covered |
| Change rule | None | Says who reviews the scope and when |
| Audit outcome | Long clarification at stage 1; scope rewritten | Confirmed at stage 1, tested as written at stage 2 |
The right-hand column is not longer because it is wordier. It is longer because somebody actually made decisions.
Keep the statement itself to a short, readable paragraph or two. Plain sentences, no legal drafting. A workable shape:
Then check three things. Does every word correspond to something real? Could a stranger tell from it what you do? Does it match what your website, tender documents and contracts say about you? Mismatches between the scope statement and public claims get picked up quickly, and they are awkward to explain.
If you plan to display a certification mark later, read the guidance on the correct usage of certification logos first. The mark must reflect the scope, not the whole group.
What does the 2025 edition change for scope?
ISO 37001:2025 moved to the harmonized structure and replaced “stakeholders” with “interested parties“. Clauses 4.1 and 4.2 now also require climate change to be considered when you understand the organisation and the expectations of interested parties. The practical point: clause 4 is where scope comes from. Understand the context, identify interested parties, and the boundary follows. Scope is the output of that work, not a document-control exercise.
Clause 5.1.3 made anti-bribery culture an explicit requirement. Culture does not stop at an entity boundary — a further reason to be honest about exclusions rather than clever about them.
Clause 8.4 added mergers and acquisitions as a non-financial control area. So if your organisation buys businesses, the scope needs a rule for what happens to an acquired entity. Does it come inside the boundary at completion? After integration? After its own risk assessment? Say which. An unwritten rule becomes a gap the first time a deal closes.
Joint ventures are harder. A JV you control looks like a subsidiary. One you do not control looks like a business associate. A 50/50 arrangement looks like neither. Decide on control in practice, not shareholding alone, and record the reasoning.

How do you decide borderline cases?
| Question | If yes | If no |
|---|---|---|
| Does this unit hold its own contracts or appoint its own agents? | Bring it in scope | Consider covering it through the parent’s processes |
| Can staff here approve, reject or prioritise something of value to a third party? | Bring it in scope | Lower priority, but record the judgement |
| Is this entity dormant, with no staff and no transactions? | Exclusion is defensible | Treat as operating and assess it |
| Is the activity performed for you by a third party? | Keep the control process in scope, not the third party | No scope action |
| Was this entity acquired within the current cycle and still separate? | Time-limited exclusion, stated openly | Bring it in scope |
| Does the exclusion remove your highest-risk activity? | Redraw the boundary | Exclusion may stand |
| Would an outsider reading the scope be surprised by what is missing? | Redraw the boundary | Scope is probably sound |
Work through it entity by entity and keep the completed sheet. It is evidence of a reasoned decision, which is exactly what an auditor wants to see.
How do auditors test your scope?
Certification runs in two stages. Stage 1 looks at readiness and documentation. Whether the system actually functions day to day is what stage 2 examines. Scope gets attention in both, for different reasons.
At stage 1, the auditor checks that the boundary is clear, justified and consistent with your risk assessment. Expect questions about exclusions, how the scope was decided and who approved it.
At stage 2, the auditor tests what the scope claims. If you named a project site, they may want to see it. If you said agent appointment is covered, they will sample agent files. A scope that overstates coverage creates findings; one that understates it creates doubt.
The certification process and the wider ISO audit procedure explain how the stages fit together. Certification runs on a three-year cycle with surveillance audits in between, then recertification — so the scope you set is the scope you live with for a while.
Worth saying plainly: a certificate does not prove that no bribery has happened or will happen. It records one thing: that on the audit date, a system meeting the standard was found operating. Treat it as none of the following: a guarantee of innocence, a recommendation, or a shield in law.
What are the most common scope mistakes?
Copying the ISO 9001 scope. Quality scope is built around products and processes. Anti-bribery scope is built around where discretion and value meet. The ISO 9001 certification boundary rarely transfers cleanly.
Writing the scope before the risk assessment. Then the risk assessment finds exposure outside the boundary, and nobody wants to reopen the decision.
Leaving shared services unaddressed. Group legal, group finance and group procurement often sit in an entity that is not in scope while doing work that is. Say how that is handled.
Silence on exclusions. An unstated exclusion reads as concealment even when it was an oversight.
Never revisiting it. New site, new country, new acquisition, new agent network — each is a trigger to look again. Put a review point in the system: who owns the scope, what triggers a review, how a change is approved. If a change affects a live certificate, tell your certification body. Extending a certificate to a new entity or site is routine; discovering the extension at a surveillance audit is not.
Where does training fit?
Scope decisions are easier when the people making them understand the standard. The Foundation course is half a day, four hours, self-paced online, thirty days’ access. It teaches you to understand the standard. What it will not do is give anybody the qualifications to audit.
ISO 37001 internal auditor training is two days, sixteen hours, and teaches you to audit your own organisation — including whether the scope holds up. ISO 37001 lead auditor training is five days, forty hours, and teaches you to audit other organisations. Both run in classroom or in-house format, live virtual, or self-paced online with thirty days’ access. The live virtual route suits teams spread across sites.
On the auditor courses you are assessed continuously as the course proceeds, with a written examination closing the final day. No prior experience is required. IAS and EAS issue the certificates jointly, backed by IAS’s UQAS [accreditation](https://iasiso-gulf.com/SA/accreditation/) — an accreditation extending to training schemes and not only to certification.
The team that delivers ISO training is kept separate from the team that audits. Impartiality rules demand that separation; it is not a matter of house preference. You can also see internal auditor courses and lead auditor courses across other standards.
- ISO 37001:2025 current edition
- IAS certification under UQAS accreditation
- Classroom, live virtual and self-paced routes
- Training and audit teams kept separate

Two things this post is not
This post makes no claim about the law in Saudi Arabia or any other country. Legal duties and obligations are matters for your own legal advisers. Nothing here is legal advice.
Reading this post, or completing any course mentioned in it, does not make anyone an IAS auditor. It confers no registration of any kind.
Ready to set your boundary and have it tested properly? Learn how ISO 37001 certification is delivered by IAS, explore system certification across standards, or read more about the organisation behind it.
Frequently asked questions
Can I certify just one division?
Yes, provided the boundary is honest and the exclusion has a reason. Problems arise when the excluded part carries the higher risk.
Does the scope have to cover every country we operate in?
No. It has to cover the entities, sites and activities you name. What it must not do is imply coverage you do not have.
Do our agents and distributors go in the scope statement?
No. They are business associates, not part of your system. Your controls over them — selection, due diligence, contracting, monitoring — are in scope.
What if we acquire a company mid-cycle?
Apply the rule you wrote in advance — usually a defined settling period, then entry after its own risk assessment. Clause 8.4 of the 2025 edition treats acquisitions as a control area, so document the approach.
Can the scope change after certification?
Yes. Tell your certification body when it does. Extending or reducing scope is a normal process handled through the certification cycle.
Is the scope the same as the risk assessment?
No. The risk assessment tells you where the exposure is. The scope says which of it the system covers. The two must be consistent, and the scope should come second.
Do we need to include bribery aimed at us?
Yes. The standard covers bribery directed at the organisation as well as bribery by it. That is why procurement, inspection and approval functions belong inside the boundary.
Who should approve the scope?
Top management. It is a governance decision, not a documentation task, and the approval should be recorded.