Most companies here don't go looking for an anti-bribery standard. They run into it — as a line in a pre-qualification questionnaire, a field in a vendor registration portal, or a clause a main contractor has passed down. Suddenly a bid depends on it. This page is written for the person assembling that submission, and it treats ISO 37001 certification in Saudi Arabia as what it usually is in practice: evidence you have to hand somebody else, who will judge it.
- Accredited certification body
- UQAS accreditation
- Auditors who work on Gulf project supply chains
- Two-stage audit, no surprises
Written by the IAS audit team for Saudi Arabia. Reviewed against ISO 37001:2025.

A certificate bought to tick a box gets you through the portal, then fails the first client audit that goes near it. A system built properly survives that audit and makes the next three pre-qualifications easier. Both cost roughly the same to obtain, and very different amounts afterwards.
What does a bid team need to know first?
- ISO 37001 sets out what an anti-bribery management system (ABMS) must contain, as an international standard.
- The current edition is ISO 37001:2025, published in February 2025, replacing ISO 37001:2016.
- Certificates issued to the 2016 edition stop being valid on 28 February 2027.
- The standard addresses bribery in four directions, including bribery aimed at your company.
- Certification does not prove bribery has never happened in your business. The standard is explicit about that limit.
- The cycle: an initial audit in two stages, a certificate, a surveillance visit each year, and a fuller reassessment to close the cycle.
- IAS issues certification under its UQAS accreditation. You become certified; you do not become accredited.
- Scope wording decides whether a client accepts your certificate. Get it right before the audit.
Working to a bid deadline? Send us the pre-qualification clause and the entities it names. We'll tell you what scope you actually need. Talk to the IAS team in Saudi Arabia.
Why does ISO 37001 certification in Saudi Arabia show up in pre-qualification?
Work in this market reaches most companies through somebody bigger. An operator awards a package. A main contractor splits it. A supplier joins a vendor list and waits. At every handover there's a registration or pre-qualification step, and business-ethics requirements have been drifting into those steps for years.
The pressure is commercial, not legal. A parent company abroad has told its board the supply chain is screened. An operator was burned once on an agent's commission and now asks every bidder the same questions. That's a buyer deciding what it will accept, and buyers here have become specific about it.
What is the certificate actually evidence of?
Be blunt about this internally. A certificate is not a character reference. It is a third party's statement that, on the dates of the audit, your organisation had an anti-bribery management system meeting the standard within a defined scope, and that auditors saw it operating.
That's a narrow claim, and a useful one, because everything in it is checkable. A client auditor can ask for the risk assessment, the due diligence file on a named agent, last quarter's gifts register, training records, and the last management review minutes. If those exist and are dated and coherent, the certificate holds up. If the auditor finds a policy signed eighteen months ago and nothing since, it becomes a liability — it now looks like you told the client something untrue.
So the working test for every implementation decision is simple. *Will this survive somebody else's audit of us?* Not our auditor's. Theirs.
What does ISO 37001 cover?
ISO 37001 sets requirements for a management system dedicated to one risk: bribery. It doesn't cover fraud, competition matters, sanctions or money laundering, though a sensible system touches the same records.

The four directions you must consider are:
- Bribery by the organisation, or on its behalf.
- Bribery by your own personnel, in connection with your business.
- Bribery by business associates acting for you — agents, sponsors, consultants, subcontractors, JV partners.
- Bribery directed at the organisation or its people — someone trying to buy your inspector, your quantity surveyor, your procurement officer.
On project supply chains the fourth direction is the live one, and it's the one applicants forget. If your people sign off deliveries, approve variations, witness tests or release retention, they are worth bribing. A risk assessment that only looks outward won't convince an experienced auditor, or a client's compliance team.
What does certification not prove?
The standard says this about itself, and it's worth repeating in your bid documents. Certification does not prove that no bribery has occurred in connection with your organisation, and it does not prove that none will occur. No management system delivers that. What certification supports is a reasonable claim that you have controls proportionate to the bribery risks you face, and that an independent body examined them.
Say that plainly if a client asks. Overclaiming loses a compliance reviewer fast, because they already know the limit and are checking whether you do.
How far does your responsibility extend to subcontractors, agents and sponsors?
Your exposure on a project rarely sits inside your own payroll. It sits with the people who act for you: the local agent who opens doors, a sponsor arrangement inherited from whoever set the entity up, the specialist subcontractor brought on at short notice, the logistics agent clearing goods at a port.
ISO 37001 calls these business associates and requires due diligence proportionate to the risk each presents. In practice:
- Know who they are. Ownership, control, and who receives the money. A trading name on an invoice is not knowledge.
- Understand what they do for you. Vague scopes — "facilitation", "liaison", "business development support" — are the ones auditors open first.
- Test the commercial logic. A success fee with no identifiable work behind it is the oldest problem in this standard.
- Put anti-bribery commitments into the contract, with a right to information and a right to terminate.
- Reassess when something changes — a new package, a new counterparty, a renewal, a change of ownership.
Two warnings. Subcontractors appointed under schedule pressure are usually the least screened parties in the chain, so build a fast-track due diligence route before you need it. And if a pre-qualification asks whether you flow these requirements down to your own suppliers, the answer needs contract clauses behind it, not intentions.
Which control does the standard expect for each risk area?
This maps exposures a project business will recognise onto what ISO 37001 asks you to have. Use it as a self-check before you engage an auditor.
| Risk area | The control the standard expects |
|---|---|
| Not knowing where the exposure is | A documented bribery risk assessment, reviewed periodically and after significant change |
| Unclear position from the top | A published anti-bribery policy, plus leadership behaviour and an anti-bribery culture required by the standard |
| No one owns the issue | An anti-bribery function with defined authority, adequate resources and independence, with access to the governing body |
| Unknown counterparties | Due diligence on transactions, projects, activities, personnel in exposed roles, and business associates |
| Money leaving without scrutiny | Financial controls — segregation of duties, approval limits, payment verification, records |
| Deals and structures used as a route | Non-financial controls covering procurement, operations, commercial arrangements and mergers and acquisitions |
| Gifts, hospitality, sponsorships, donations | Documented rules with thresholds, approvals and a register that is actually maintained |
| Concerns never surface | A reporting channel, confidentiality where possible, and protection for the person who raises a concern |
| Concerns surface and nothing happens | A defined investigation process, with authority to act and records of outcomes |
| People don't recognise the situation | Role-appropriate training, including awareness of conflicts of interest |
| Drift over time | Monitoring, measurement, internal audit and management review |
What changed in the 2025 edition, and does it affect you?
ISO 37001:2025 is an evolution, not a rebuild. If you run the 2016 system well, most of the work is confirming and documenting. Each change, with a straight answer on whether it costs you effort.
- Harmonized common ISO structure. The clause framework now matches other current ISO management system standards. *Effect on you:* mostly presentational, but integration gets easier if you hold other ISO certifications.
- "Stakeholders" is now "interested parties". *Effect on you:* a terminology sweep through your documents. An hour's work.
- Clauses 4.1 and 4.2 now require climate change to be considered, following the 2024 amendment applied across ISO management system standards. *Effect on you:* small. Consider whether climate change is relevant to your context and to interested parties' expectations, and record the conclusion.
- Clause 5.1.3 makes anti-bribery culture an explicit requirement. *Effect on you:* real, if leadership has been passive. Auditors now look for evidence that senior people set and reinforce the culture, not just approve the policy.
- Clause 7.2.2 adds conflict-of-interest awareness to employment processes. *Effect on you:* moderate. Recruitment, onboarding and role changes need a conflict-of-interest step, with records.
- The anti-bribery function's role and independence are stated more clearly. *Effect on you:* significant in smaller entities where that function sits with someone who also owns commercial targets. Review it now.
- Clause 8.4 adds mergers and acquisitions as a non-financial control area. *Effect on you:* relevant if you acquire, are acquired, or take equity in project vehicles. Pre-deal bribery due diligence becomes expected.
- Clause 10 swaps its two parts: improvement moves up to 10.1, and nonconformity with corrective action moves to 10.2. *Effect on you:* renumbering in procedures and internal audit checklists.
Clause numbers that moved or gained requirements
| Clause | What sits there now |
|---|---|
| 4.1 / 4.2 | Context and interested parties, including consideration of climate change |
| 5.1.3 | Anti-bribery culture as an explicit leadership requirement |
| 7.2.2 | Conflict-of-interest awareness within employment processes |
| 8.4 | Non-financial controls, now including mergers and acquisitions |
| 10.1 | Continual improvement |
| 10.2 | Nonconformity and corrective action |
What happens at the 28 February 2027 transition deadline?
Certificates issued against ISO 37001:2016 cease to be valid on 28 February 2027. There is no extension to plan around and no credit for being close.
Fold the transition into an audit you were having anyway — a surveillance visit or recertification. One mobilisation rather than two. Leaving it late has a specific commercial consequence here: if your certificate lapses mid-way through a pre-qualification window, you don't get to explain the timing to the portal. The status field just reads expired.
If you hold a 2016 certificate, fix the transition audit date now and work backwards. You want updated documentation, one internal audit and one management review under the new edition before the auditor arrives.
How does the certification audit run?
Stage 1 is a readiness review. The auditor examines your risk assessment, policy, scope, documented information and internal audit and management review records. It finds gaps while they're cheap to fix. Applicants who treat it as a formality get findings later.
Stage 2 tests implementation through sampling and interviews: due diligence files, payment approvals, the gifts register, training records, a concern that was raised and what happened to it. Auditors follow threads. If your risk assessment names agents as high risk, expect the agent files to be opened.
Findings are raised where evidence doesn't meet a requirement. Major findings must be cleared before certification; minor ones are corrected on an agreed plan. Surveillance audits then run annually, with recertification in the third year. The full sequence is in the IAS certification process.
One tip from client audits: keep your Stage 2 report, findings and corrective action evidence in one file. When a client's compliance team asks how your system has performed, that file answers in five minutes.
How is scope set for multi-site and joint venture structures?
Scope is where certificates fail acceptance, and Saudi project structures make it harder than average. A typical applicant has a head office, a fabrication yard, two project offices and a share in a joint venture with its own commercial registration. Decide these before the audit:
- Which legal entities are covered. A certificate naming the parent does not automatically cover a separately registered joint venture. Clients check this.
- Which sites are covered. Permanent premises are straightforward. Project sites open and close, so agree how site activity is represented — commonly by covering the controlling office and sampling active sites.
- Which activities are covered. "Construction and maintenance services" reads very differently from "provision of manpower services", and a client comparing scope to contract will notice.
For joint ventures, the practical question is who operates the controls. If the JV runs its own procurement, payments and personnel, it generally belongs in the scope in its own right. If your entity provides those functions under a services agreement, the JV can often be covered as an activity of your system — but the evidence must show your controls genuinely reach it. Settle this at application. Changing scope after issue is slower and more expensive.
What drives the cost and timing of ISO 37001 certification in Saudi Arabia?
We don't publish a price, because a real quotation depends on facts about your organisation. Here's what moves the number.
- Headcount and sites in scope. Audit effort scales with people and locations.
- Number of legal entities, especially joint ventures with separate registrations.
- Your bribery risk profile — project contracting, third-party agents and cross-border payments all increase sampling.
- How much business goes through business associates. More agents means more due diligence files to review.
- Your starting point. Existing management systems, internal audit habits and clean records all speed things up.
- Whether a transition to ISO 37001:2025 is bundled with an audit you were already scheduled to have.
On timing, the honest driver is you. Scheduling is rarely the bottleneck; evidence is. The standard expects an internal audit and a management review before Stage 2, and those need the system to have run long enough to produce something to review. Tell us any pre-qualification date at first contact. Sequencing ISO 37001 certification in Saudi Arabia around a bid is possible, but only if the conversation starts early.
Get a scope and a schedule, not a brochure. Tell us your entities, sites and headcount, and we'll come back with what the audit would involve. Request a quotation or read about IAS.
Where does IAS audit for ISO 37001 certification in Saudi Arabia?
IAS audits across the Kingdom, including Riyadh, Jeddah, Makkah, Madinah, Dammam, Al Khobar, Dhahran, Jubail, Yanbu, Tabuk, Abha and Buraidah, and at project and industrial locations elsewhere. Contracting, EPC, engineering, oil and gas services, logistics, facilities management and manufacturing are all common applicants. Multi-site audits are planned as one programme so you mobilise once.
Other services for the region sit under IAS in Saudi Arabia, management system certification and product certification, with a wider overview of the group's certification services.
How is IAS certification backed?
Certificates are issued by IAS, which is accredited by UQAS. Accreditation is a judgement made about IAS by someone else — on impartiality, on competence, and on how certification decisions get taken. It applies to IAS, not to you. Once certified, you are a certified organisation, not an accredited one, and calling yourself accredited on a bid document is an error a sharp reviewer will catch.
Details are on the IAS accreditation page for Saudi Arabia and the group accreditation page. Certificates can be verified through the IAS certificate search — worth including in a pre-qualification response, so the client can confirm your status without emailing you. The audit approach is described under certification process and about IAS.
Training is separate work, run by IAS with EAS under that same UQAS accreditation, by a team kept apart from the auditors. It is not certification and does not shorten an audit. See IAS training in Saudi Arabia, EAS online courses and lead auditor training for Saudi Arabia.
Where do first-time applicants lose time?
The same patterns repeat. These cost applicants weeks.
- A generic risk assessment. Downloaded, unedited, silent on agents, sponsors and site payments. It fails Stage 1, and it fails client audits too.
- Scope written by marketing. The widest possible wording, which then doesn't match the contracting entity on the bid.
- A gifts register with no entries. Either nothing happened all year, or nobody is recording. Auditors ask which.
- Due diligence that stops at a copy of a commercial registration. No ownership, no risk rating, no conclusion, no date.
- No internal audit or management review. Both are requirements, and neither can be produced retrospectively with any credibility.
- The anti-bribery function reporting to whoever owns the sales target. Independence has to be visible.
- Starting three weeks before a bid closes. Sometimes the honest answer is that this bid goes out without the certificate and the next one doesn't.
How this page was checked, and what to do next
The technical content was written against ISO 37001:2025, which reached publication in February 2025, and against the transition date of 28 February 2027. Clause references, the four routes bribery travels, the requirement areas and the certification cycle come from the standard and from IAS audit practice.
We make no statement here about Saudi law. Nowhere does this page suggest that holding the certificate is compulsory, or that any official body calls for it. Every requirement described here is commercial — set by clients, main contractors, operators, vendor registration systems, joint venture partners or parent companies. For a legal position on your obligations, consult a qualified adviser.
No statistics, prices, audit durations or client examples have been invented. Where a number depends on your organisation, we've said what drives it instead of guessing.
Next step
Send us the pre-qualification clause you're answering, the entities and sites you want covered, and your headcount. We'll come back with a scope, an audit plan and a quotation, and tell you honestly whether your deadline is achievable. Contact IAS in Saudi Arabia to begin.
If you would rather read before you call: the audit procedure sets out how an assessment is actually run, system certification lists the other standards we certify here, common questions covers the practical ones, and our note on supplier qualification requirements is the closest thing we have to a companion piece for this page. Rules for showing the mark once you hold it are on the logo usage page.
Frequently asked questions
Is ISO 37001 certification in Saudi Arabia required by law?
We take no position on legal obligations. Where we see the standard demanded, it is commercial — set by clients, main contractors, operators, vendor registration systems or parent companies. Take legal advice separately if you need a legal position.
Can a client audit us against ISO 37001 themselves?
Yes, and many do. Clients on large projects run their own supplier audits, and a certificate doesn't stop that — it shapes what they ask about. Assume any evidence you showed our auditors may be requested again. That's why the system has to be genuine rather than presentational.
We only have project offices, no permanent site. Can we still certify?
Yes. Scope is usually built around the office controlling the activity, with sampling of active project locations. Agree the approach at application so it matches what your client expects.
Does the certificate prove no bribery has occurred?
No. It confirms a management system meeting the standard was in place and operating within the certified scope at the time of audit. The standard states this limit itself.
Can we certify in time for a bid closing next month?
Certification needs a working system, an internal audit and a management review before Stage 2. If your date is impossible, we'll say so rather than let you tell a client something that won't hold.
Do our subcontractors need to be certified too?
The standard doesn't require it. It requires proportionate due diligence and anti-bribery commitments in your arrangements with them. Some clients ask for more contractually — check the pre-qualification wording.
Who issues the certificate, and can a client verify it?
IAS issues it under UQAS accreditation, and anyone can check it through the IAS certificate search. Include that link in your submission.
Are audits conducted in English or Arabic?
Tell us your working language at application and we'll plan the audit team and interviews accordingly.