Written for people who will shortly audit a colleague they already know by name.
Internal auditors rarely find an empty due diligence folder. They find a half-finished one. ISO 37001 internal auditor training in Saudi Arabia is built around that moment. The file exists. Someone in your own commercial team put it together. It holds a company profile, a trade licence and a long email thread. What it does not hold is a record of who judged the risk acceptable, or on what basis. This course teaches you what to do next: test the file, describe what is missing, and say it so your colleague can act on it.
Two days, sixteen hours, one skill. Learn to plan and run an anti-bribery management system internal audit inside your own organisation. Talk to the IAS team in Saudi Arabia about classroom, in-house, virtual or self-paced delivery.
- Two-day, 16-hour course
- Classroom, in-house, virtual or self-paced
- No prior audit experience needed
- Certificate issued by IAS with EAS
What does ISO 37001 internal auditor training prepare you for?
Anti-bribery management systems have an international standard of their own: ISO 37001. An internal auditor course prepares you to audit that system where you work. You plan an audit, gather evidence, judge it against the standard and your own procedures, write findings, and report to your own management.
That is a narrower job than it sounds, and a harder one. You are not assessing a stranger's company. You are asking your own procurement lead why an agent file stops halfway. The technique is learnable in two days. The composure takes practice, which is why the course runs on exercises rather than lectures.
Why are due diligence files the hardest part to audit at home?
Every ISO 37001 control leaves a trace. Training records leave attendance sheets. Gift declarations leave a register. Due diligence on business associates leaves a folder — and folders are where judgement hides.
Three things make these files awkward:
- They are built by people you work with daily. The file owner sits two desks away. You will need a finding, not an argument.
- They are rarely absent, usually incomplete. An absent file is easy to write up. A file with four of seven expected items needs a considered judgement.
- The missing part is usually the reasoning, not the paperwork. Certificates get collected. The decision that closed the assessment often does not get written down at all.
Add one more difficulty. Due diligence should be proportionate to risk, so a thin file is not automatically a wrong one. Telling the two apart is the real skill, and this ISO 37001 internal auditor course concentrates on it.

What does clause 9.2 require of your internal audit programme?
Clause 9.2 internal audit is the clause that puts you in the room. Under it, internal audits have to happen at intervals the organisation itself has planned. Those audits tell management whether the anti-bribery management system conforms to the organisation's own requirements and to the standard, and whether it is effectively implemented and maintained.
The clause asks for a programme, not a single event. A programme sets frequency, methods, responsibilities, planning and reporting. It accounts for the importance of the processes concerned and the results of earlier audits. Business associate due diligence scores high on both counts, which is why it recurs in audit plans year after year.
Clause 9.2 also asks for objectivity and impartiality. Auditors should not audit their own work. In a large group that is straightforward. In a company of ninety people it needs thought, and the course spends real time on it.
Results go to relevant management, and to the anti-bribery compliance function, whose role and independence the 2025 edition describes more clearly than the previous one did.
Where does due diligence sit in ISO 37001:2025?
Audits today are run against ISO 37001:2025. February 2025 is when it appeared, and it takes over from ISO 37001:2016. Certificates still sitting on the 2016 edition have to be moved across by 28 February 2027.
Due diligence connects to several parts of the standard at once, and a good internal auditor follows those threads rather than treating the file as a standalone document:
- The bribery risk assessment decides which business associates are higher risk. A due diligence file that ignores the risk assessment is disconnected from the system.
- Financial and non-financial controls sit alongside due diligence as the practical defences. In the 2025 edition, clause 8.4 adds mergers and acquisitions to the non-financial control areas — which is due diligence in a different costume.
- Anti-bribery commitments from business associates follow the due diligence outcome. If a file recommends a contractual clause, the internal auditor can ask whether the clause reached the contract.
- Clause 7.2.2 pulls awareness of conflicts of interest into the way people are taken on and employed. Conflicts declared internally often explain who selected a particular supplier.
- Clause 5.1.3 writes anti-bribery culture into the standard as a requirement in its own right. Whether due diligence is treated as real work or as a form-filling chore is a culture observation with evidence behind it.
Other 2025 changes are useful background. The standard moved to the harmonized structure. "Stakeholders" became "interested parties". Climate change is something clauses 4.1 and 4.2 now oblige you to take into account. Clause 10 was reordered, with 10.1 covering continual improvement and 10.2 covering nonconformity and corrective action. The course shows where each change lands in an ISO 37001 audit checklist.
The standard addresses bribery in four directions: by the organisation, by its personnel, by business associates acting on its behalf, and bribery directed at the organisation. Due diligence touches at least three of the four.
What does a complete due diligence file hold, and what is usually missing?
This table anchors the first practical exercise: delegates work through anonymised files against a required-contents list. The right-hand column reflects what internal auditors genuinely find.
| Element a complete file should contain | What internal auditors usually find instead |
|---|---|
| The risk tier assigned to the business associate, with the date it was assigned | A tier stated verbally, or set once at onboarding and never reviewed |
| Identity evidence for the entity, and for the people who control it | Entity documents present; beneficial ownership unrecorded |
| Screening output against sanctions and adverse media sources | A screenshot with no date, no search terms and no searcher named |
| A record of any red flags raised and how each was resolved | Red flags noted in an email thread that never reached the file |
| Evidence of the intermediary's qualifications for the work paid for | A scope of work that describes "consultancy" and nothing more |
| The remuneration basis, and why it is reasonable for the service | Commission percentage on the contract, no assessment of proportionality |
| A named approver, a decision and a date | The file simply stops after the last attachment |
| A review date or trigger for re-assessment | No review cycle; the file has not been opened since signature |
| Anti-bribery commitment obtained, or a recorded reason it was not needed | A template clause the counterparty struck out, unremarked |
Two habits come out of this exercise. Check the decision before the documents. A file full of certificates with no decision is weaker than a short file with a dated, signed judgement. And check dates against events: a screening run three weeks after the contract started tells you something no contents list will.
How do you read a thin file correctly?
Proportionate due diligence is a real requirement, not an excuse. Your job is to test whether the organisation applied its own proportionality rules, and whether those rules hold up.
Ask three questions in order. What tier did the procedure require here? What must a file at that tier contain? Does this file contain it? If the answers line up, a thin file is a conforming file, and your report should say so. Reports that list only problems teach management nothing about what works.
Watch for the silent downgrade. A commission-based sales agent in an unfamiliar market is classified low risk because the annual spend is small. The procedure may not forbid it, but the risk assessment says otherwise. That finding needs careful wording, and the course supplies it.

How do you sample business associate files without distorting the result?
You cannot audit every file, and you should not try. The course covers sampling that stands up when the certification body's auditor later reviews your work.
- Weight the sample by risk tier. Draw more files from higher tiers, and record the weighting so the sample can be reproduced.
- Stratify by business unit. A sample dominated by one well-run department flatters the whole organisation.
- Mix new onboardings with long-standing associates. Fresh files show current practice. Old files show whether review triggers work.
- Trace one file forward to payments. A file that ends at approval leaves what was actually paid unexamined.
- Fix the sample before you look. Choosing files after a browse invites the accusation that you went hunting.
Tell the auditee your sampling method, not the file numbers. That protects the evidence without turning a clause 9.2 internal audit into a surprise raid.
How do you stay objective when you already know the auditee?
This is the part delegates say they came for. The course uses a decision table, deliberately practical rather than philosophical.
| Situation | Reasonable internal audit response |
|---|---|
| You wrote the due diligence procedure yourself | Do not audit it. Auditing your own work breaches the objectivity expectation in clause 9.2 |
| You work in the department that owns the files | Audit a different unit, or ask a colleague from another function to lead this part |
| You approved one of the sampled files last year | Remove that file from the sample and record why |
| Your manager owns the process being audited | Agree in advance that findings go to the audit programme owner, not through your line |
| You are the only trained auditor in a small company | Pair with a trained colleague from an unrelated function; document the arrangement |
| A friendship makes a finding uncomfortable | Write the finding from the evidence only. Remove every adjective before you send it |
Objectivity is not coldness. It is the habit of writing what you saw and leaving out what you assumed. Delegates practise it on day two.
How do you handle an incomplete file without assigning blame?
An incomplete file is a system signal before it is a personal failure. Your response decides whether the system improves, or whether the next file is tidied before you arrive.
| What you found | How to raise it | What it usually means for the system |
|---|---|---|
| Required item absent, procedure clear | Nonconformity against the internal procedure. Cite the clause and the file reference | Control not implemented; corrective action under clause 10.2 |
| Required item present but undated or unattributed | Nonconformity, worded around traceability rather than effort | Records requirement too loose to be auditable |
| File complete, decision not recorded | Nonconformity. The decision is the control | Procedure describes collection, not assessment |
| Procedure silent on what the file must hold | Finding against the procedure, not the person who built the file | Documented information gap; owner is the process, not the user |
| Risk tier applied inconsistently across units | Observation supported by the sample, escalated if it recurs | Training or criteria problem, not individual carelessness |
| One unit's files consistently strong | Note it as a positive finding with the practice described | Candidate for the wider organisation to copy |
| Red flag resolved in email, never filed | Opportunity for improvement, plus a factual note | Workflow does not end in the record |
Two rules carry the whole table. Name the process, not the person. And when the procedure is vague, say so — do not write up the colleague who followed it as best they could.
How do you write the finding so your colleague will act on it?
A finding nobody acts on is wasted audit time. The course uses a four-part structure, practised until it is automatic. State the requirement, quoting the clause of ISO 37001 or of your own procedure. State the evidence — the file, the date, what was and was not in it. State the gap in one sentence. Then stop. Recommending a fix is optional, and often unhelpful — the process owner usually knows the remedy better than you.
Grading matters too. Over-grading a minor records gap as a major nonconformity costs credibility you will need next year. Under-grading a systemic weakness hides what management most needs to see.
Your report goes to your own management, not to a certification body. But an IAS auditor may later review your internal audit records as evidence that clause 9.2 is being met. Clear, evidenced findings make that review straightforward. The IAS audit procedure page describes how external audits proceed.
Internal auditor or lead auditor: which course fits you?
The distinction is simple. An internal auditor course prepares you to audit your own organisation under its own audit programme. The lead auditor route runs longer and points outward — at auditing organisations other than your own, usually for a certification body or a major customer.
If your job is to run or contribute to your employer's internal audit programme, this two-day internal auditor course is the right one. If you want the wider qualification for auditing third parties, look at the lead auditor training routes offered in Saudi Arabia.
The broader internal auditor training portfolio covers other management system standards on the same two-day pattern, and the full ISO training catalogue lists what else is available.
How long is the course, and how is it delivered?
Two days is what the course occupies — 16 hours of instruction altogether. Delivery options are:
- Classroom or in-house. Held on your own site, or at an IAS training centre. In-house works particularly well for this subject, because your real procedure and your real risk tiers can shape the exercises.
- Virtual instructor-led. Run live through web conferencing; the exercises are identical, worked in breakout groups.
- Self-paced. A route with 30 days of access to the course material, for people who cannot commit to fixed sessions. The EAS online course platform hosts that route.
No prior auditing experience is required. Familiarity with ISO 37001 is recommended, and a reading of the standard before day one makes the exercises considerably more useful.

What does the certificate mean, and what does it not mean?
You are assessed as the course goes along, and a written examination follows. That running assessment matters here. Much of the learning shows up in exercises — how you sampled, how you worded a finding, how you handled a defensive auditee in a role-play. A written paper alone would not capture it.
Delegates who finish are issued a certificate of completion, jointly from IAS and EAS. IAS runs the course with EAS, and IAS's UQAS accreditation sits behind it — an accreditation reaching training schemes as well as certification work. The IAS accreditation page explains those arrangements.
Now the plain part. Passing this course does not turn you into an IAS auditor. It does not certify your employer either. Those are separate processes. If your organisation is pursuing certification, the route is set out under ISO 37001 certification in Saudi Arabia and in the certification process pages.
One more limit. Certification to ISO 37001 does not prove that bribery has not occurred, and does not guarantee that none will occur. It shows a management system designed to prevent, detect and respond to bribery has been implemented. Keep that boundary in view and your reports come out more honest.
Inside IAS, whoever delivers training stands apart from whoever carries out audits. Impartiality rules require that split; it is not simply how IAS prefers to arrange its staff.
A note on local law
No statement about the law of Saudi Arabia is made here, nor about any regulator, authority or legal obligation there. Nothing on this page says or implies that ISO 37001 certification or internal auditor training is legally required, expected by any authority, or sufficient for any legal purpose. The standard is voluntary. Put legal questions about anti-bribery obligations to a qualified adviser in the relevant jurisdiction.
Who should attend?
The course suits people who already carry some responsibility for how business associates are assessed, or who soon will:
- Compliance and anti-bribery function staff building an internal audit programme
- Quality and management system professionals adding ISO 37001 to their audit scope
- Procurement and supply chain staff who own or contribute to due diligence files
- Internal audit team members extending coverage into anti-bribery controls
- Legal, contracts and finance staff who see the clauses and the payments, but not the files behind them
Organisations already auditing other standards often send someone who covers ISO 9001 or ISO 27001 systems; the technique transfers well. It is the subject matter — judgement recorded in files — that needs the new training. More about the provider is on the about us page, and mark usage rules sit in the logo usage guideline.
Ready to build a credible clause 9.2 programme? Ask about classroom, in-house, virtual and self-paced ISO 37001 internal auditor training in Saudi Arabia. Contact IAS or browse the Saudi Arabia services overview.
Frequently asked questions
What is ISO 37001 internal auditor training?
The course equips you to plan internal audits of an anti-bribery management system inside your own organisation, and then to run them. You learn to gather evidence, judge it against ISO 37001 and your own procedures, write findings and report to your management.
Do I need audit experience before I start?
No prior auditing experience is required. Familiarity with ISO 37001 helps, and reading the standard beforehand makes the file exercises far more productive.
Can I audit my own department's due diligence files?
Not if you built the procedure or approved the files. Clause 9.2 expects objectivity, and auditors should not audit their own work. Small organisations usually pair auditors across functions; the course covers documenting that arrangement.
At what interval should internal audits run?
The standard does not fix a frequency. It asks for planned intervals set through the audit programme. Higher-risk processes, which for most organisations includes business associate due diligence, are usually covered more often than low-risk ones.
What if the missing item is the decision itself?
Raise it. The decision is the control. A file of collected documents with no recorded judgement, approver or date does not demonstrate that due diligence was performed.
Does an external auditor ever review what I produced internally?
Yes. Your internal audit records may be examined by an external auditor as evidence that clause 9.2 is being met. That is one reason the course insists on reproducible sampling and clearly evidenced findings.
Does completing the course certify my employer?
No. Training an internal auditor does not certify an organisation, and internal audits are not a substitute for certification. Certification is a separate process, described under system certification and the ISO certification overview.
Does the course cover ISO 37001:2025 changes?
Yes. The course works from ISO 37001:2025. It covers the changes from the 2016 edition: the harmonized structure, climate change under clauses 4.1 and 4.2, and anti-bribery culture under 5.1.3. It also covers conflict-of-interest awareness under 7.2.2, mergers and acquisitions under 8.4, and the reordering of clause 10. The deadline for shifting a 2016 certificate onto the new edition is 28 February 2027. General questions are collected on the IAS FAQ page.