+971528732160
enquiry@iascertification.com

ISO 37001 Internal Auditor Training in UAE: Evidence an Internal Auditor Can Actually Obtain

An internal auditor works with an odd mix of freedom and limits. You can walk to a colleague’s desk without an appointment. You cannot compel anyone to hand you a file. That gap decides what your audit is worth. ISO 37001 internal auditor training in the UAE is built around that gap. Over two days you learn what evidence is genuinely within reach inside your own organisation, how to ask for it, and what to do when the answer is no.

Two days, sixteen hours, one skill set. Learn to audit your own anti-bribery management system against ISO 37001:2025. Ask us how the course runs or browse the wider internal auditor training hub.

  • 16 hours across two days
  • In a room, live online, or at your own pace
  • Open to first-time auditors
  • IAS and EAS certificate of completion

Why is evidence the hard part when you audit your own employer?

Most people arrive on the course expecting to learn audit technique. Technique is the easy half. The difficult half is getting hold of something solid when the person holding it sits two desks away.

An external auditor turns up with a contract behind them. The organisation agreed to be audited, so access is part of the deal. You have no such contract. You have an audit programme, a mandate from top management, and a working relationship you would like to keep.

That changes how you plan. You stop asking “what would prove this?” and start asking “what would prove this and can I see it by Thursday?” The course spends most of its time on the second question.

You also learn to spot weak evidence dressed up as strong evidence. A signed policy is not a working control. An attendance sheet is not competence. A clean gift register may mean nobody is giving gifts, or that nobody is recording them.

ISO 37001 internal auditor training in UAE — the records you will need to request

What does clause 9.2 ask of you?

Clause 9.2 of ISO 37001 requires the organisation to run internal audits at planned intervals. The audits check two things. First, that the anti-bribery management system meets the organisation’s own requirements and the requirements of the standard. Second, that the system is effectively implemented and maintained.

The clause also sets conditions on how you do it. The programme must consider the importance of the processes involved and the results of earlier audits. Auditors must not audit their own work. Results go to relevant management. Records of the programme and its results must be kept.

Read that last sentence carefully. The records are part of the requirement. An audit that happened but left no trace does not satisfy clause 9.2 internal audit expectations. Delegates practise producing records that stand up later, without turning every audit into a paperwork exercise.

One more point worth stating early. Internal audit does not certify anything. It feeds the system. If your organisation later pursues ISO 37001 certification in UAE, the certification body’s auditor will look at your internal audit records as evidence that clause 9.2 is being met. Your work becomes their input. That is a good reason to do it properly.

What access can you get, and what happens when you cannot?

This is the centre of the course. We build the table below on day one. Delegates leave with their own version, filled in for their own organisation.

Evidence typeHow an internal auditor usually gets itWhat to do if access is refused
Anti-bribery policy and its approved versionsDocument control system or the anti-bribery function; usually open to all staffRarely refused; if the current version cannot be located, that is itself a finding
Due diligence files on business associatesProcurement or legal shared drive; request through the process ownerRecord the refusal, sample the register entries instead, escalate the access gap to the audit sponsor
Gift, hospitality and donation registerFinance or compliance; often a spreadsheet with a named ownerAsk for the approval emails behind a sample of entries; note any part of the period you could not test
Conflict-of-interest declarationsHR file or a declarations portal; often personal data, so access is controlledAsk HR to show redacted records or confirm completeness statistics in your presence
Anti-bribery training and awareness recordsLearning system export or HR; usually straightforwardCross-check with a sample of staff interviews about what they remember
Raising-concerns and whistleblowing reportsCompliance or the anti-bribery function; frequently restrictedAccept a summary of case volumes and handling times; do not push for identities
Payment approvals, petty cash and expense claimsFinance system reports; ask for a defined period, not “everything”Narrow the sample, ask for a system-generated extract, note the scope limitation
Anti-bribery clauses in contractsContract register plus copies of a sample of signed agreementsTest the template and the clause approval trail instead of the signed originals
Top management minutes and reports on the ABMSBoard or management secretariat; often confidentialRequest an extract limited to the anti-bribery agenda items
Merger and acquisition due diligence under clause 8.4Corporate development or legal; frequently the most closed areaConfirm the procedure exists and was followed, through the process owner’s own records
Anti-bribery function’s independence and reporting lineTerms of reference, appointment letters, reporting structureAsk for the written mandate; a missing mandate is evidence, not an obstacle

Notice the pattern in the last column. A refusal is never the end of an audit trail. It is a fork. You either find another route to the same conclusion, or you record a scope limitation and say so in the report. Both are legitimate. Silence is not.

What do you do when a manager says no?

Refusals are usually not defiance. They are caution, workload, or genuine confidentiality. Your response should match the reason, so the course teaches you to find the reason first.

Start with a simple question. “Is this something you cannot share, or something you would rather not share right now?” The answers lead in different directions.

  • Genuine confidentiality. Personal data, legal privilege, live investigations. Accept it. Ask what you can be shown instead: counts, dates, redacted extracts, an on-screen view without a copy.
  • Workload. The manager is busy. Narrow the request. Name a period, a system, a sample size. Offer to pull the extract yourself if you have read access.
  • Uncertainty about your authority. The manager does not know whether they are allowed to give it to you. Show the audit programme and the mandate. This is the easiest refusal to resolve.
  • Reluctance. Something in the file worries them. Do not argue. Record the request, the response, the date. Escalate through the programme, not through the corridor.

Escalation has a shape. You go to the person who owns the audit programme. You describe the missing evidence and its effect on your conclusion. You let the sponsor decide whether to open the door. If it stays shut, your report carries a scope limitation in plain words.

Delegates role-play all four refusals on the second day. Most say afterwards that the escalation conversation was the part they had been dreading.

ISO 37001 internal auditor training in UAE — escalating when access to a record is refused

How much evidence is enough?

Sufficiency is where new auditors most often go wrong, in both directions. Some accept a single document and close the line of enquiry. Others chase everything and run out of time. The table below is the rule of thumb we work from.

What you are testingOne source is enough whenYou need a second source when
A required document existsYou are only confirming existence, version and approvalYou are claiming the document is used in practice
Anti-bribery training was deliveredThe record names the person, the content and the dateYou are testing whether people understood it
Due diligence was performed on an associateThe file is complete and dated before the engagement beganThe risk rating looks inconsistent with the depth of the check
A control operated all yearThe system generates the record automatically and cannot be editedThe record is manual, retrospective, or maintained by one person
A corrective action was closedThe closure evidence directly addresses the original causeThe same nonconformity has appeared before
Gifts and hospitality stayed within limitsThe register is complete and approvals are attachedInterviews suggest gifts are handled outside the register
The anti-bribery function is independentThe written mandate sets out the reporting lineBehaviour in practice appears to contradict the mandate
Anti-bribery culture is being encouragedNever — culture cannot be evidenced by one artefactAlways; combine communications, interviews, behaviour and consequences

That last row matters more since the 2025 edition. Anti-bribery culture is spelt out as a requirement in its own right at clause 5.1.3. Culture leaves scattered traces. You look at what leaders say, what gets rewarded, what happens after a concern is raised, and whether people can describe the policy in their own words.

What evidence does ISO 37001:2025 ask for?

February 2025 brought ISO 37001:2025, which supersedes the 2016 edition. If your certificate is still written against 2016, the date to work back from is 28 February 2027. The course is taught against the current edition throughout.

The changes are not cosmetic for an auditor. Several of them create new places to look.

  • The 2025 edition adopts the harmonized structure shared across management system standards. If you have audited another system, the shape will feel familiar.
  • “Stakeholders” is now “interested parties”, matching the rest of the family.
  • Clauses 4.1 and 4.2 require climate change to be considered as part of context and interested-party expectations. You check that the consideration happened and was recorded.
  • Culture is named outright at clause 5.1.3, as described above.
  • Conflict-of-interest awareness now has to feature in employment processes, under clause 7.2.2. Recruitment and onboarding records come into scope.
  • The anti-bribery function’s remit, and the independence it requires, are spelled out in sharper terms. Ask for the mandate in writing.
  • Mergers and acquisitions now sit inside the non-financial controls, under clause 8.4. This is often the hardest evidence to reach, and the table above says why.
  • Clause 10 has changed order. Continual improvement now sits at 10.1, nonconformity and corrective action at 10.2.

The standard addresses bribery in four directions: bribery by the organisation, by its own personnel, by business associates acting on its behalf, and bribery directed at the organisation. Your sampling should cover all four. Most weak audit programmes cover only the first two, because those are the easiest to evidence.

Say it plainly: certification does not prove no bribery has occurred or will occur. Neither does a clean internal audit. Both show a system exists and is being worked.

How do you sample inside a company you already know?

Knowing the organisation is an advantage you should use deliberately, not accidentally.

You know which department rushes month-end. You know which supplier relationship predates the policy. You know where the informal approvals happen. An external auditor would need days to learn any of that.

The risk is the mirror image. You also know which finding will make the next team lunch awkward, so you quietly steer the sample away. That is the biggest threat to an ABMS internal audit, and the course names it out loud.

The discipline is simple. Draw the sample before you look at whose name is attached. Write the sampling rule down. If you change the sample, record why. A written rule is easy to defend; a feeling is not.

How do you stay objective auditing your own employer?

“Can I audit my own department?” The answer is no, and the standard is direct about it. Auditors must not audit their own work. If you wrote the procedure, approved the payment, or ran the training, you cannot audit it.

Smaller organisations in the UAE often have a real problem here. There may be only a handful of people who understand the anti-bribery management system at all. The course works through the practical options.

  • Cross-audit between departments. Finance audits procurement; procurement audits finance.
  • Pair a knowledgeable auditor with an independent one. Knowledge advises, independence concludes.
  • Rotate auditors year on year so no one owns the same scope repeatedly.
  • Use someone from a sister company or another site within the group.

Objectivity is not the same as ignorance. You are allowed to know things. You are not allowed to have a stake in the outcome.

How are the two days structured?

ISO 37001 internal auditor training is sixteen hours, split across two days. The balance leans towards doing rather than listening.

SessionFocusWhat delegates produce
Day 1, openingISO 37001:2025 requirements and the four directions of briberyAnnotated clause map for their own organisation
Day 1, middleClause 9.2, the internal audit programme, risk-based planningA draft annual programme outline
Day 1, closeEvidence types and the access tableTheir own completed access table
Day 2, openingInterviewing process owners and asking for recordsRole-played record requests, including refusals
Day 2, middleSufficiency, sampling and working papersA worked ISO 37001 audit checklist for one process
Day 2, closeWriting findings, reporting to management, follow-upTwo written nonconformities and a short audit report
AssessmentContinuous through both days, plus a written examination—

The written examination sits at the end. Continuous assessment runs alongside it, because how you behave in a role-played interview tells us more than a multiple-choice answer does.

ISO 37001 internal auditor training in UAE — the event your assembled evidence has to describe

How do you write findings that get acted on?

Your report goes to your own management. Not to a certification body, not to a regulator, not to a client. That changes the writing.

A finding needs four parts. The requirement. The evidence. The gap between them. The effect. Delegates practise writing all four in two or three sentences, because long findings get skimmed.

Two habits to avoid. Do not name individuals where a process failure is the real point. Do not soften a nonconformity into an “observation” because you like the person.

Follow-up is part of the job. Under clause 10.2 the organisation must react to nonconformity and take corrective action. Your next audit checks whether the action worked, not just whether a form was signed.

Internal auditor or lead auditor: which do you need?

The distinction is simple. Two days here, and the subject is your own organisation, audited under clause 9.2. A lead auditor course is longer and prepares someone to audit other organisations, usually as part of a team on behalf of a client or a certification body. Different purpose, different length, different exercises.

If auditing other organisations is your aim, the lead auditor training routes cover several standards, including ISO 9001 lead auditor training, ISO 27001 lead auditor training and ISO 45001 lead auditor training. For anti-bribery work inside your own employer, this course is the right one.

Who should attend?

No prior auditing experience is required. Familiarity with the standard is recommended, and you will move faster if you have read it once.

The people who get most from an ISO 37001 internal auditor course tend to be:

  • Compliance, legal and risk staff who now own the anti-bribery management system.
  • Internal audit team members adding anti-bribery to an existing portfolio.
  • Procurement and finance managers who approve payments or engage business associates.
  • HR staff handling declarations, onboarding and the clause 7.2.2 requirements.
  • Quality coordinators already running audits under other standards.

Teams often attend together. The access table works better when several departments fill it in at once.

What are the three ways to attend?

ISO 37001 internal auditor training comes in three delivery formats.

Classroom or in-house. Held either at your own premises or at an IAS training centre. In-house delivery lets us use your real registers and process names in the exercises.

Virtual instructor-led. Delivered live over web conferencing. Same two days, same tutor, same role-plays in breakout rooms. Useful for teams split across emirates or group companies.

Self-paced. ISO 37001 training online with 30 days of access to the course material. The online course portal hosts it.

Upcoming sessions and delivery formats appear on the training schedule, alongside the rest of our ISO training in the UAE.

How is the course assessed, and what are the certificate’s limits?

You are assessed as you go, and there is a written examination to sit as well. The certificate of completion carries the names of IAS and EAS together.

IAS runs the course with EAS, under IAS’s UQAS accreditation, which reaches training schemes as well as certification. More on the accreditation position and on who we are.

Now the part people assume away. Passing this course will not make you an auditor for IAS. Nor does it certify your employer. It is training in how to plan and run internal audits of an anti-bribery management system, gather evidence, write findings and report to your own management. Certifying an organisation is a separate process, described under our certification process and ISO audit procedure.

One more structural point. The team that delivers ISO 37001 internal auditor training is kept separate from the team that carries out certification audits. Impartiality rules require that split; it is not simply how we prefer to organise ourselves. Your tutor cannot influence a certification decision.

What this page does not claim

This page describes a training course and the requirements of ISO 37001:2025. It makes no statement about the law in the United Arab Emirates or anywhere else. Nothing here says this course, this standard or certification to it is required, approved or recognised by any authority. ISO 37001 is a voluntary international standard. For advice on legal obligations, speak to a qualified lawyer in your jurisdiction.

Ready to build an internal audit programme that stands up? Ask about ISO 37001 internal auditor training in classroom, virtual or self-paced format — get in touch, check the common questions, or start from the UAE home page.

Frequently asked questions

What is ISO 37001 internal auditor training?

ISO 37001 internal auditor training is a two-day course. It teaches you to plan and carry out internal audits of an anti-bribery management system against ISO 37001:2025, inside your own organisation.

How long is the course?

Two days, sixteen hours of instruction, plus the written examination at the end.

Do I need audit experience to attend?

No. No prior auditing experience is required. Reading the standard beforehand is recommended and will help you keep pace.

Can I record a refusal as a nonconformity?

Usually not on its own. A refusal limits your scope. If the organisation’s own procedure gives internal audit a right of access, then blocking that access may itself be a nonconformity against the procedure.

How often must internal audits be done?

The standard requires audits at planned intervals, set by the organisation. Most organisations cover the whole system across a twelve-month cycle, weighting higher-risk processes more often.

Is an internal audit checklist supplied?

You build one. Delegates produce a working ISO 37001 audit checklist for a process of their choosing during day two, so it fits their organisation rather than a template.

Does completing the course certify my employer?

No. Training an internal auditor is not certification. Organisation certification is a separate process; the system certification and ISO certification pages explain how that works, and logo use is covered in the logo usage guideline.

Will a certification auditor look at my internal audit records?

Yes. When an organisation is assessed, the certification body’s auditor reviews internal audit records as evidence that clause 9.2 is being met. Good records help. Thin records invite questions.