+971528732160
enquiry@iascertification.com

ISO 37001 Certification in UAE: Due Diligence on Agents and Intermediaries

Most bribery risk in a UAE business is not carried by its staff. It is carried by people who act for it without being on the payroll. Local partners. Sponsors. Agents on commission. Distributors. Clearing agents. The consultant who “knows someone” at the buyer. ISO 37001 sets the international benchmark for an anti-bribery management system, and the part that catches applicants out is always the same: proving what is done in your name by people you do not employ.

  • ISO 37001:2025 current edition
  • Free zone, mainland or a group of both
  • Audits across all seven emirates
  • Issued by IAS under UQAS accreditation

This page is for the person assembling the file, not the one signing the budget. It takes no position on legal obligation here. The pressure behind ISO 37001 certification in UAE is commercial: a tender clause, a buyer’s questionnaire, a parent company pushing policy down to its subsidiaries.

Working out where you stand? Send your entity list, your agent list and the clause that started this. We will tell you what scope is realistic. Talk to the IAS UAE team or browse certification services in the Emirates.

ISO 37001 certification in UAE — a payment made on your behalf in a market you never visit

Where does your bribery exposure actually sit?

Ask a UAE finance director where bribery could happen and you hear about procurement staff or petty cash. Not wrong. Just incomplete, and not where the auditor spends time.

Much commercial activity here runs through someone standing between you and the counterparty. An agent opens a door to a government-sector buyer. A distributor holds a relationship in a market you have never visited. A clearing agent settles charges you never see itemised. Each acts on your instruction, with your money, under your name.

ISO 37001 calls them business associates. A bribe paid by one of them for your benefit is your problem, and you must show what you did about it. Not what you intended. What you did.

Most applicants produce a policy in a week. Few can answer these on audit day, with documents:

  • Who acts for us, as opposed to merely selling to us?
  • What did we find out about each before appointing them?
  • What are we paying them, on what basis, and does that basis create a reason to pay a bribe?
  • What did they do to earn the last payment?
  • What in the contract lets us audit them, stop paying, or terminate?
  • Who reviews all this, and when did they last do it?

Get those six written down and the intermediary part of the audit is uneventful. Nothing else predicts how smoothly ISO 37001 certification in UAE goes.

What do you need to know first?

  • ISO 37001 sets requirements for an anti-bribery management system, or ABMS.
  • The current edition is ISO 37001:2025, published February 2025. Existing 2016 certificates must transition by 28 February 2027.
  • It covers bribery in four directions, including bribery by business associates acting for you. Due diligence on those associates is where UAE applicants are weakest.
  • One certificate can name a free zone entity, a mainland entity, or a group covering both.
  • Certification never proves bribery has not happened. The standard says so about itself.
  • The cycle: two-stage initial audit, certificate, annual surveillance, recertification. IAS issues certificates under UQAS accreditation, which belongs to IAS, not to you.

What does ISO 37001 ask of you?

ISO 37001 does not grade your ethics. It asks whether you have built a system that finds bribery risk, controls it proportionately, checks the controls work, and fixes them when they do not. Four directions of risk form the spine:

  • Bribery by the organisation — a payment made to win or keep business.
  • Bribery by your own personnel for the organisation’s benefit.
  • Bribery by business associates acting for you: agents, distributors, sponsors, sub-contractors, consultants, joint venture partners.
  • Bribery directed at the organisation — someone inducing your buyer, your inspector or your tender evaluator.

The last is the one applicants forget. If a supplier is offering your procurement officer something, that is in scope and needs its own controls. The requirement areas built around this spine, and the evidence each needs, are in the table further down.

ISO 37001 certification in UAE — what an agent does in your name is still your risk

What does a certificate not say about you?

Settle this before you spend money, because a customer will ask.

A certificate does not say nobody in your company has paid a bribe. It does not say nobody will. The standard is explicit that conformity cannot assure that no bribery has occurred or will occur. What it says is narrower: an independent body examined your system against a published standard and found it conformed at the time of audit. But if a bid asks you to warrant that your agents never made an improper payment, a certificate is not that warranty.

What does an auditor ask to see on business associate due diligence?

No auditor asks whether you “do due diligence”. They ask to see the file for a named third party, picked off your own list — usually the awkward one: highest commission, riskiest market. What belongs in it:

  • Who you are dealing with: legal name, registration, ownership, ultimate control, directors.
  • Political exposure and conflicts. Does anyone connected sit on the buyer’s side? Is a relative of your own employee an owner?
  • Dated screening results — sanctions, adverse media, watchlists — showing who ran them.
  • A written risk rating with reasoning. Not “medium”. Why medium.
  • Approval by someone with authority, recorded before appointment.
  • The signed contract, with anti-bribery terms in it.
  • Evidence of what the party has done since, and a dated next review.

Usually missing, in the order we find it: the reasoning behind the rating; proof the approval preceded the appointment; anything on beneficial ownership; any refresh of a file opened four years ago.

“Risk-based” is not permission to do less. It is doing the right amount in the right place. With 400 suppliers and 6 agents, an enhanced process on the stationery supplier is absurd. So is doing nothing on 394 parties because they are “low risk”.

The pattern that works is tiered. A short standard check on the long tail: identity, ownership, screening, standard clause. A full file, refreshed annually, on the few who face your customers or public officials for you, who are paid only if something is won, or who work where you have no visibility. Write down the rule that sorts parties into tiers. Auditors do not object to a light touch on low risk, only to one you cannot explain.

How do you keep control over contracts and commissions?

Once appointed, control of a third party moves into the contract and the payment process. Three things draw attention.

Commission and success fees. Paying only on a win is not forbidden, and plenty of honest agency works that way. But it concentrates incentive at the moment of decision, so it attracts scrutiny. Justify the rate against market norm, scope of work, or comparable arrangements of your own. An unusually high percentage with no documented rationale is the classic finding. So is a fee raised just before an award.

Expenses and reimbursements. Here money leaves without being called commission. Round-sum “facilitation” claims, unitemised “local charges”, cash advances to a clearing agent, hospitality booked to a project code. Demand itemisation at the standard you apply to your own staff.

Gifts and hospitality given through someone else. A gift your policy would refuse is not acceptable because a distributor bought it and invoiced you. Your rules must reach through the intermediary, and your register must capture what is given on your behalf.

The contract terms auditors look for are practical: a clear anti-bribery obligation, rights to information and audit, disclosure of conflicts, no sub-delegation without consent, and a right to suspend payment or terminate on credible grounds. A clause you have never invoked is fine. No clause at all, for a top-tier party, is not.

ISO 37001 certification in UAE — a commission with no identifiable work behind it

What records does ISO 37001 certification in UAE put on file?

Each requirement below is paired with the record that usually carries it, framed for a business running on intermediaries.

Requirement areaThe record that proves it
Bribery risk assessmentA dated assessment naming real exposures, including agent markets and public-sector touchpoints
Anti-bribery policyThe signed current policy, plus proof it reached third parties, not only staff
Anti-bribery function and leadershipAn appointment showing authority and a clean reporting line, plus board minutes acting on bribery risk
Due diligence on business associatesCompleted files for named agents, with ratings, reasoning and dated approvals
Due diligence on transactions, projects and personnelScreening for sensitive roles, and a documented risk view of a named bid
Financial and non-financial controlsApproval limits, segregation of duties, itemised third-party invoices, tender procedures, M&A checks
Gifts, hospitality, donationsA register with real entries, including items given on your behalf
Raising concerns and investigationThe channel, written protection for whoever uses it, any case handling record
TrainingAttendance and content records showing role-appropriate coverage, conflicts included
Monitoring, internal audit and reviewAudit reports, minutes with named owners, corrective actions with a root cause

Which entities go on the certificate?

A certificate names the organisation, its activities and its sites. One free zone registration and nothing else is simple. It gets interesting when a group spreads across a free zone entity handling exports, a mainland entity holding the trading activity, a second free zone entity elsewhere, and a holding company above them. Three workable shapes:

  • Single entity. One registration, one certificate. Often enough if only one entity bids for the work in question.
  • Several entities, one system. A group certificate can cover free zone and mainland entities together, if they genuinely run one system: one policy, one risk method, one anti-bribery function with authority over all of them, common due diligence rules, one internal audit programme. Common ownership is not enough. Shared control is.
  • Separate certificates. Where entities appoint their own agents and answer to different management, separate certificates are more honest and easier to keep.

Two practical points. Check what the tender asks for — a certificate naming the free zone entity is useless if the mainland entity bids. And watch shared intermediaries: if one agent works for two group entities under one agreement, that agent must sit inside the scope you certify. Map it before applying, through our UAE system certification pages or on contact.

What changed in the 2025 edition, and what should you do?

ISO 37001:2025 is a refresh, not a rebuild. A 2016 system gets updated, not rewritten.

What changedWhy it was changedWhat to do about it
Restructured to the harmonized common ISO formatTo match the structure shared across management system standardsRe-map clause references and audit checklists; content moves rather than disappears
“Stakeholders” became “interested parties”Consistent terminology across the ISO familyUpdate the wording; the analysis behind it is unchanged
Clauses 4.1 and 4.2 require climate change to be consideredCarried in from the 2024 amendment applied across these standardsNote honestly whether it affects your context and interested party expectations. Do not invent a link
Clause 5.1.3 makes anti-bribery culture explicitPolicies alone did not change behaviourShow what leaders do: messages sent, decisions taken, a refusal that cost money
Clause 7.2.2 adds conflict of interest awareness to employment processesConflicts sit behind many cases, and hiring is where they enterBuild declarations into recruitment and role changes, and keep them
The anti-bribery function’s role and independence stated more clearlyToo many functions existed on paper with no authorityRe-check who it reports to and whether it can escalate past those it reviews
Clause 8.4 adds mergers and acquisitions as a non-financial control areaAcquisitions import the target’s agents and history wholesaleAdd bribery checks to your acquisition process, covering the target’s third parties
Clause 10 reordered: improvement at 10.1, nonconformity at 10.2To put improvement first and match the common structureRenumber procedures and forms; what you must do is unchanged

Two matter most to an intermediary-led business. Clause 8.4 catches the acquisition arriving with an inherited agent network. Clause 7.2.2 catches the conflict walking in with a new hire whose relative sits on the customer’s side.

When must you move off a 2016 certificate?

Certificates against ISO 37001:2016 must transition by 28 February 2027. After that they no longer stand.

Do not treat that as distant. Transition is normally done at a surveillance or recertification visit, so your real deadline is the last scheduled audit before February 2027.

For a working system the effort is modest: a gap review against the 2025 text, updated documented information, a leadership and culture evidence pack for 5.1.3, conflict declarations in hiring, an M&A control where acquisitions are realistic, a climate consideration in your context analysis, and one internal audit against the new numbering.

How does the audit run?

Stage 1 is a readiness review. The auditor reads your documented system, checks scope, and looks at your risk assessment, internal audit and management review. Findings here are useful, not fatal; most first-time applicants get a list.

Stage 2 tests whether the system is used. Third-party files are sampled, payments traced, and people outside the management team interviewed — someone in finance, someone commercial — and asked what they would do if an agent requested cash.

The certificate decision is taken by an independent reviewer inside IAS, not the auditor, and nonconformities close with evidence first. Surveillance follows annually; recertification is a fuller assessment before expiry. The process is described in how IAS certification works, and any issued certificate can be checked through the IAS certificate search.

What drives the cost and timing of ISO 37001 certification in UAE?

We publish no price, because a number without your details is a guess. What moves it:

  • How many legal entities go on the certificate, and whether they share one system.
  • How many sites, and how far apart. Four emirates cost more than one building.
  • Headcount, which sets sampling.
  • The number and risk profile of your business associates. Six agents in difficult markets take more time than sixty domestic suppliers, and public-sector exposure adds more.
  • The state of your records, and whether this is a first certification or a transition.

On timing, your readiness is the honest driver. The audit takes days. Reconstructing files for agents appointed years ago takes months. Start there.

Where does IAS audit across the Emirates?

IAS audits clients in Dubai, Abu Dhabi and Sharjah, and across the northern emirates — Ajman, Ras Al Khaimah, Umm Al Quwain and Fujairah.

For an intermediary-heavy business, plan around where the evidence sits, not where the buildings are. A company running fifteen agents from one Dubai office does not need a tour of fifteen premises. It needs an auditor sitting with the third-party files, commission schedules and payment approvals, beside whoever signs them. Where operations genuinely differ — a warehouse using its own clearing agents, a branch appointing its own consultants — a site visit earns its place. See our UAE services overview or the wider IAS certification range.

Who issues the certificate, and on what authority?

The certificate comes from IAS, working under accreditation held with UQAS. Behind that word sits a check on IAS rather than on you — covering impartiality, whether its auditors know the subject, and whether auditing is kept clear of the certification decision.

One distinction gets confused constantly. Accreditation applies to IAS, not to clients. You become certified; you do not become accredited, and writing otherwise in a bid is the small error a sharp evaluator notices. More sits on the IAS accreditation page and in about IAS in the UAE. If you plan to put the mark on a bid document or a website, read the rules for using the logo first — misuse is a finding at your next audit.

Training is separate from certification, deliberately. Where it helps, it is run by IAS and EAS together under that same UQAS accreditation, by a team with no part in your audit. Training run in the UAE covers both the internal auditor and lead auditor routes, with EAS online courses and auditor training for the UAE alongside. No course substitutes for certification.

Where do first-time applicants lose time?

  • No single list of business associates. Names sit across sales, finance, logistics and legal. Building one list is often two weeks of work.
  • Treating suppliers and intermediaries alike. A company selling you goods is not the risk a company fronting you to a customer is.
  • Files that stop at a trade licence copy. Identity with no ownership, screening or rating is not due diligence, and approvals dated after the appointment are worse. Auditors check dates.
  • Contracts with no anti-bribery terms, usually the oldest agency agreements, which are the riskiest.
  • Scope decided late, after finding the tender names a different group entity.
  • No internal audit and no management review — an automatic finding whatever else is in place.

Ready to scope it properly? Send your entity list, your business associate list and your deadline. We will come back with a scope, a plan and a quotation. Contact IAS in the UAE, or see system certification and product certification.

How this page was checked

Technical content was checked against the published text of ISO 37001:2025 and what IAS auditors report from UAE assessments. Transition date, clause numbering and edition details are as published.

Nothing here is a statement about UAE law. We do not say, and do not suggest, that anything obliges you to hold this certificate in the Emirates, and no legal instrument, official body or authority is named on this page. Every pressure described here is commercial: tender conditions, customer requirements, partner expectations, parent company policy. For legal questions, consult a qualified professional.

Next step

Send three things: your entity list, the list of third parties who act in your name, and the requirement driving this. That is enough for us to say what scope makes sense for ISO 37001 certification in UAE and where your gaps are, before you commit.

Contact the IAS UAE team · UAE certification services · how the certification process runs · the audit procedure in detail · UAE home · common questions · UAE blog

Frequently asked questions

Are our agents and distributors covered by our certificate?

Not as certified organisations. Your certificate covers your organisation and your system. What it covers about your agents is how *you* manage them: selection, checks, contract terms, monitoring, and what you do when something looks wrong. An agent cannot present your certificate as theirs. But the auditor tests your controls over that agent, and weakness there is your finding.

Can a free zone entity and a mainland entity share one certificate?

Yes, if they genuinely run one system: shared policy, shared risk method, one function with authority over both, common due diligence rules, one internal audit programme. If they operate independently, with separate management and separate third parties, separate certificates make more sense. Decide before applying: it changes the plan.

What language is the audit conducted in?

English in most cases. Where records or the people we interview work mainly in Arabic, we plan for that. Tell us at application which language your records are kept in. Either works, but it must be the version people use, not one translated for the audit.

A long-standing agent will not complete our due diligence questionnaire. What now?

Escalate first. Refusals often come because the request arrived from a junior contact with no explanation. A direct approach from your commercial lead, saying a customer requires it, usually resolves it.

If refusal continues, treat it as risk information. Record the request, the refusal and the dates. Gather what you can elsewhere: ownership records, screening, transaction history. Raise the risk rating, tighten the controls you hold, and get a written decision from senior management on whether to continue. An auditor accepts a difficult relationship handled deliberately, but not a blank.

We have offices in several emirates. Do you visit them all?

Not necessarily. Where sites share one system, one management team and one set of third-party controls, sampling is appropriate. A site appointing its own agents or running its own procurement is more likely to be visited.

Is ISO 37001 legally required here?

We take no position on legal obligation in the Emirates. We are a certification body, not a legal adviser. Applicants come to us because of a tender clause, a buyer’s assessment or a parent company policy.

What is the difference between certified and accredited?

You become certified. IAS is accredited, by UQAS, as a certification body. It never transfers to a client, and claiming it in a bid is a mistake evaluators pick up.

Does the audit look at acquisitions?

If acquisitions are part of your business, yes. Clause 8.4 adds them as a non-financial control area. Buying a company means buying its contracts, history and agents. Expect questions about what was checked before you signed.