+971528732160
enquiry@iascertification.com

24 Sep 2026

Mergers and Acquisitions as a Bribery Control Area in ISO 37001:2025

/
Posted By
/
Comments0

ISO 37001:2025 came out in February 2025 and takes over from the 2016 edition. Among the changes, one is easy to skim past and hard to implement: clause 8.4 now names mergers and acquisitions as a control area alongside the older non-financial controls. If your organisation buys businesses, sells them, or forms joint ventures, that single addition changes what an auditor will ask you for.

This post covers that clause and nothing else. Risk assessment, due diligence on business associates, and the reporting clauses are all connected to it, but they belong to their own conversations.

Planning your transition to the 2025 edition? Certificates issued against ISO 37001:2016 run until 28 February 2027. See how ISO 37001 certification in the UAE is carried out by IAS, and what stage 1 and stage 2 actually look at.

What does clause 8.4 add?

The 2016 edition had a family of controls under the operational planning clauses: gifts and hospitality, donations, sponsorships, and similar transactions where value moves for reasons other than a straight commercial exchange. These are the non-financial controls. The 2025 edition adds mergers and acquisitions to that family.

In practice the organisation must decide what its anti-bribery controls are when it acquires, merges with, or takes a stake in another entity. Not what its lawyers do. What the anti-bribery management system does.

That is a different question from the one most deal teams answer. A legal team asks whether the target has a problem that creates liability. An ABMS asks something broader: what bribery risk are we importing, who owns it after close, and how does the system extend over the new part of the organisation.

Why does the addition matter more than it looks?

A merger is the fastest way to change an organisation’s bribery risk profile. Everything else moves slowly. A new supplier is one contract. An acquisition can double your headcount, add jurisdictions, inherit an agent network you have never met, and hand you contracts negotiated by people you did not hire.

None of that shows up in a risk assessment done last year. And here is the practical problem auditors see: the ABMS is owned by compliance, while the deal is owned by corporate development or the board. The two are on different clocks. Deals move fast and quietly. Management systems move on annual cycles. Clause 8.4 forces them to meet.

How do the four directions of bribery apply to a deal?

Four directions of bribery fall within ISO 37001: bribery committed by the organisation itself, bribery by the people it employs, bribery by business associates acting for it, and bribery aimed at the organisation. A transaction can expose all four at once.

Suppose a distribution business is acquired. Bribery by the entity might sit in its historic dealings. Bribery by personnel might sit with a regional sales manager who has an arrangement nobody documented. Bribery by a business associate might sit with a commission agent whose contract renews automatically. And bribery directed at the organisation could arrive during the deal itself — an inducement to move a valuation, clear an approval, or lose a finding.

That last direction is the one most deal processes ignore. Write it into your controls explicitly.

ISO 37001 mergers and acquisitions — a transaction the deal process must be designed to detect

How is anti-bribery due diligence different from ordinary due diligence?

Most organisations already run commercial, financial and legal due diligence. Clause 8.4 does not ask you to duplicate that. It asks whether bribery risk is deliberately scoped into it, proportionate, and documented.

A weak answer in an audit sounds like this: “Our lawyers do due diligence on every deal.” Fine. Show me the scope. Show me where bribery risk was assessed, who assessed it, what they found, and what was done with it.

A good answer names the trigger. Deals above a risk threshold get an anti-bribery workstream, the anti-bribery function is notified at a defined point, and there is a record of what was looked at. Then it shows you two live examples.

AreaA weak deal-stage controlWhat good looks like
TriggerCompliance hears about the deal when it is announcedA defined point in the deal process where the anti-bribery function is formally notified
ScopeBribery folded silently into general legal reviewA named bribery risk scope, proportionate to country, sector and counterparty profile
Agents and intermediariesTarget’s agent list not requestedAgent, consultant and introducer contracts reviewed, with commission structures examined
FindingsRaised verbally in a deal meetingRecorded, rated, and tracked to a decision with an owner
Deal termsNo anti-bribery provisionsWarranties, disclosure obligations and remediation conditions considered before signing
Post-completionAssumed the target will “adopt our policies”A dated integration plan with responsibilities, checkpoints and an end state
EvidenceNothing retained after closeA retained file the auditor can open two years later

Where does the risk actually sit across a transaction?

It helps to stop treating a deal as one event. It is a sequence, and the control you need is different at each point.

Target identification. Risk here is mostly informational — who is introducing this deal, and are they being paid? An unusual introducer fee is a classic warning sign, and often the only thing visible at this stage.

Diligence. Risk is what you fail to look at. Access is limited, time is short, and the seller controls the data room. Record what you could not see as carefully as what you did see.

Negotiation and signing. Risk is the pressure to close. This is where findings get downgraded because a deadline is near. It is also where inducements aimed at your own people are most likely.

Completion to integration. Risk is inherited and now yours. Anything the acquired entity does after close is your organisation’s conduct.

Steady state. Risk becomes ordinary operational risk — but only once the entity is genuinely inside the management system, not just on the org chart.

What happens post-completion, and why is it the gap nobody plans for?

The most common finding in this area is not a failed due diligence. It is the silence after completion.

The deal closes. The integration plan covers finance systems, payroll and branding. Anti-bribery appears as one line: “roll out group policies.” Nobody sets a date. Nobody names an owner. A year and a half later the acquired entity is still paying the same agents on the same terms, its staff have never had anti-bribery training, and its gift register does not exist. At that point the organisation has a current problem it created, not a historic one it inherited.

A credible integration plan answers four things: when the acquired entity comes under the ABMS, who is accountable for getting it there, what is checked at each milestone, and what happens if one is missed. It should also say what happens to relationships that cannot be brought into line.

How do joint ventures and minority stakes limit your control?

Acquisitions are the easy case. You buy it, you control it, you integrate it. Joint ventures and minority holdings are harder, and this is where audit conversations get interesting.

If you hold a minority stake and cannot impose your policies, what does your ABMS require? The honest answer is influence, documented. You can require anti-bribery provisions in the agreement, seek board representation, require reporting, and set out in advance what you will do if conduct falls short — including exit.

What you cannot credibly do is claim the venture is covered because your policy says all group entities are. An auditor will ask how that policy reaches an entity you do not control. If it doesn’t, say so and show what you do instead. A documented limit is defensible. A pretended control is not.

What is the anti-bribery function’s role in a deal?

Where the 2016 text was vaguer, the 2025 edition spells out what the anti-bribery function does and how independent it has to be. In a transaction, that independence gets tested directly.

The function needs to be brought in before terms are agreed, not after. It needs authority to escalate to the governing body without going through the person whose bonus depends on the deal closing. And it needs to be able to say, in writing, that a risk has not been resolved — even when nobody in the room wants to hear it.

Deal confidentiality is the usual objection. It is a real constraint and a manageable one. Restricted circulation, named individuals, controlled documents: all normal in transactions. “We couldn’t tell compliance because of confidentiality” is a design failure, not a control.

This connects to clause 5.1.3, which now makes anti-bribery culture an explicit requirement. How a deal team behaves when a finding is inconvenient tells you more about culture than any policy document.

ISO 37001 mergers and acquisitions — pressure to close is when findings get flattened

Who does what?

Deal work fails when everyone assumes someone else is holding the anti-bribery thread. Write it down before the next transaction, not during it.

StageDeal teamAnti-bribery functionGoverning body
Before diligenceNotify the function when a target is identifiedSet the bribery risk scope for this dealConfirm the risk appetite that applies
During diligenceProvide access, data room and contactsAssess bribery risk, record findings and gapsReceive escalations without filtering
Before signingReflect findings in terms and conditionsState clearly what is unresolvedDecide on deals where risk is not resolved
After completionExecute the integration plan on scheduleVerify the entity is genuinely inside the ABMSHold the plan to its milestones
OngoingManage the relationship commerciallyInclude the entity in monitoring and internal auditReview effectiveness in management review

What will the auditor ask to see?

Expect a simple opening question: has the organisation acquired, merged with, or invested in anything since the last audit? If the answer is yes, everything after that is evidence — the point where anti-bribery was engaged, the scope of the risk work, the findings and their ratings, how those findings influenced the decision to proceed, and the integration plan with dates, owners and proof it was followed. If the answer is no deals, the auditor still wants the control to exist. A control you have not needed yet still has to be designed.

Note the difference between a plan and an intention. “We will align the new entity with group policy” is an intention. “Anti-bribery training delivered to all commercial staff at the acquired entity, verified by the anti-bribery function, by a stated date” is a plan.

How do you do this proportionately?

Clause 8.4 does not demand the same depth for every transaction. A small asset purchase in a low-risk sector is not a cross-border acquisition of a business that runs on public-sector contracts and local agents.

What the standard expects is that the difference is decided on purpose, using criteria you can explain. Set a few factors — country risk, sector, use of intermediaries, public-sector exposure, deal size — and define what each tier triggers. Then apply it consistently. The failure mode is not doing too little on a small deal. It is having no rule, so depth tracks whoever happened to be free that week.

Where do training and certification fit?

Understanding clause 8.4 well enough to build a control is one thing. Auditing it is another.

The foundation route is half a day, four hours, self-paced online with 30 days’ access. It teaches you to understand the standard. What it will not do is make anyone qualified to audit. The ISO 37001 internal auditor training in the UAE is 2 days and 16 hours, available classroom or in-house, live virtual, or self-paced online with 30 days’ access — that is the route for auditing your own organisation. The ISO 37001 lead auditor training runs 5 days, 40 hours, through the same three delivery routes, for auditing other organisations. A live virtual internal auditor option is available too, and dates sit on the training schedule.

On the auditor courses you are assessed continuously as the course proceeds, and there is a written examination on the last day. None of these courses ask you to have experience beforehand. IAS and EAS issue the certificates jointly, under the UQAS accreditation held by IAS, which extends to training schemes and not only to certification.

Whoever delivers the training sits in a different team from whoever performs the audit. Impartiality requires that; it is not simply something IAS prefers.

IAS carries out ISO 37001 certification under UQAS accreditation. There are two stages to the audit: stage 1 looks at documentation and whether you are ready, and stage 2 at whether the system actually works day to day. A certificate lasts three years, with surveillance audits spaced through that period and recertification at the end of it. The audit procedure page sets out how.

  • ISO 37001:2025 current edition
  • Transition deadline 28 February 2027
  • IAS certification under UQAS accreditation
  • Training and audit teams kept separate

What claim does a certificate make, and what does it never make?

Proof that bribery has not happened, or will not happen, is not something a certificate provides. Its statement is narrower: at the date of the audit, a management system conforming to the standard was found to exist. That distinction matters in M&A more than anywhere else: a certified target is not a clean target. It is a target whose system was found conforming on a date. The due diligence still has to happen.

Equally, your own certificate does not cover an entity you acquired last month. Scope is scope. If the acquired entity is outside the certified scope, say so, and know when it will be inside.

This post makes no claim about the law in the United Arab Emirates or anywhere else. Legal duties arising from a transaction are a matter for your own advisers. Nothing here is legal advice.

Nobody becomes an IAS auditor by reading this post or by finishing any of the courses set out on this site, and no registration of any sort follows from either.

ISO 37001 mergers and acquisitions — where acquisition findings are really settled

Build the control before the next deal, not during it. Look at ISO 37001 certification in the UAE and how system certification works, or start with the lead auditor training route if you audit for a living.

Frequently asked questions

Does clause 8.4 apply if we have never made an acquisition?

Yes. The control has to exist and be proportionate. If transactions are genuinely outside your business model, document that assessment. An auditor will accept a reasoned position. Not silence.

What if the seller refuses access to the information we need?

Record the refusal, record what you could not examine, and treat the gap as a risk to be decided on rather than ignored. Restricted access is a finding in itself.

What is our deadline for moving off the 2016 edition?

Certificates issued against ISO 37001:2016 run to 28 February 2027. Building the M&A control is part of that transition work, not something to leave to the end.

Does a target’s ISO 37001 certificate mean we can skip due diligence?

No. A certificate reflects a management system found in place at the time of audit. It is useful information. It is not a substitute for looking.

Which course should a corporate development lead take?

If the aim is to understand the requirements and work sensibly with compliance, the foundation route is usually enough. If the aim is to audit, the internal auditor training is the right level.

Can the same person train us and then audit us?

No. Keeping the training team apart from the audit team is something impartiality requires.

How soon after completion should the acquired entity be inside our ABMS?

The standard sets no fixed period. What matters is a dated plan with an owner, checkpoints, and evidence it was followed. An undated plan is the problem.

Does the anti-bribery function need to see confidential deal information?

It needs enough to assess the risk and escalate. Confidentiality is managed through controlled access, not by excluding the function.

Leave a Reply