An internal auditor works with an odd mix of freedom and limits. You can walk to a colleague’s desk without an appointment. You cannot compel anyone to hand you a file. That gap decides what your audit is worth. ISO 37001 internal auditor training in the UAE is built around that gap. Over two days you learn what evidence is genuinely within reach inside your own organisation, how to ask for it, and what to do when the answer is no.
Two days, sixteen hours, one skill set. Learn to audit your own anti-bribery management system against ISO 37001:2025. Ask us how the course runs or browse the wider internal auditor training hub.
- 16 hours across two days
- In a room, live online, or at your own pace
- Open to first-time auditors
- IAS and EAS certificate of completion
Why is evidence the hard part when you audit your own employer?
Most people arrive on the course expecting to learn audit technique. Technique is the easy half. The difficult half is getting hold of something solid when the person holding it sits two desks away.
An external auditor turns up with a contract behind them. The organisation agreed to be audited, so access is part of the deal. You have no such contract. You have an audit programme, a mandate from top management, and a working relationship you would like to keep.
That changes how you plan. You stop asking “what would prove this?” and start asking “what would prove this and can I see it by Thursday?” The course spends most of its time on the second question.
You also learn to spot weak evidence dressed up as strong evidence. A signed policy is not a working control. An attendance sheet is not competence. A clean gift register may mean nobody is giving gifts, or that nobody is recording them.

What does clause 9.2 ask of you?
Clause 9.2 of ISO 37001 requires the organisation to run internal audits at planned intervals. The audits check two things. First, that the anti-bribery management system meets the organisation’s own requirements and the requirements of the standard. Second, that the system is effectively implemented and maintained.
The clause also sets conditions on how you do it. The programme must consider the importance of the processes involved and the results of earlier audits. Auditors must not audit their own work. Results go to relevant management. Records of the programme and its results must be kept.
Read that last sentence carefully. The records are part of the requirement. An audit that happened but left no trace does not satisfy clause 9.2 internal audit expectations. Delegates practise producing records that stand up later, without turning every audit into a paperwork exercise.
One more point worth stating early. Internal audit does not certify anything. It feeds the system. If your organisation later pursues ISO 37001 certification in UAE, the certification body’s auditor will look at your internal audit records as evidence that clause 9.2 is being met. Your work becomes their input. That is a good reason to do it properly.
What access can you get, and what happens when you cannot?
This is the centre of the course. We build the table below on day one. Delegates leave with their own version, filled in for their own organisation.
| Evidence type | How an internal auditor usually gets it | What to do if access is refused |
|---|---|---|
| Anti-bribery policy and its approved versions | Document control system or the anti-bribery function; usually open to all staff | Rarely refused; if the current version cannot be located, that is itself a finding |
| Due diligence files on business associates | Procurement or legal shared drive; request through the process owner | Record the refusal, sample the register entries instead, escalate the access gap to the audit sponsor |
| Gift, hospitality and donation register | Finance or compliance; often a spreadsheet with a named owner | Ask for the approval emails behind a sample of entries; note any part of the period you could not test |
| Conflict-of-interest declarations | HR file or a declarations portal; often personal data, so access is controlled | Ask HR to show redacted records or confirm completeness statistics in your presence |
| Anti-bribery training and awareness records | Learning system export or HR; usually straightforward | Cross-check with a sample of staff interviews about what they remember |
| Raising-concerns and whistleblowing reports | Compliance or the anti-bribery function; frequently restricted | Accept a summary of case volumes and handling times; do not push for identities |
| Payment approvals, petty cash and expense claims | Finance system reports; ask for a defined period, not “everything” | Narrow the sample, ask for a system-generated extract, note the scope limitation |
| Anti-bribery clauses in contracts | Contract register plus copies of a sample of signed agreements | Test the template and the clause approval trail instead of the signed originals |
| Top management minutes and reports on the ABMS | Board or management secretariat; often confidential | Request an extract limited to the anti-bribery agenda items |
| Merger and acquisition due diligence under clause 8.4 | Corporate development or legal; frequently the most closed area | Confirm the procedure exists and was followed, through the process owner’s own records |
| Anti-bribery function’s independence and reporting line | Terms of reference, appointment letters, reporting structure | Ask for the written mandate; a missing mandate is evidence, not an obstacle |
Notice the pattern in the last column. A refusal is never the end of an audit trail. It is a fork. You either find another route to the same conclusion, or you record a scope limitation and say so in the report. Both are legitimate. Silence is not.
What do you do when a manager says no?
Refusals are usually not defiance. They are caution, workload, or genuine confidentiality. Your response should match the reason, so the course teaches you to find the reason first.
Start with a simple question. “Is this something you cannot share, or something you would rather not share right now?” The answers lead in different directions.
- Genuine confidentiality. Personal data, legal privilege, live investigations. Accept it. Ask what you can be shown instead: counts, dates, redacted extracts, an on-screen view without a copy.
- Workload. The manager is busy. Narrow the request. Name a period, a system, a sample size. Offer to pull the extract yourself if you have read access.
- Uncertainty about your authority. The manager does not know whether they are allowed to give it to you. Show the audit programme and the mandate. This is the easiest refusal to resolve.
- Reluctance. Something in the file worries them. Do not argue. Record the request, the response, the date. Escalate through the programme, not through the corridor.
Escalation has a shape. You go to the person who owns the audit programme. You describe the missing evidence and its effect on your conclusion. You let the sponsor decide whether to open the door. If it stays shut, your report carries a scope limitation in plain words.
Delegates role-play all four refusals on the second day. Most say afterwards that the escalation conversation was the part they had been dreading.

How much evidence is enough?
Sufficiency is where new auditors most often go wrong, in both directions. Some accept a single document and close the line of enquiry. Others chase everything and run out of time. The table below is the rule of thumb we work from.
| What you are testing | One source is enough when | You need a second source when |
|---|---|---|
| A required document exists | You are only confirming existence, version and approval | You are claiming the document is used in practice |
| Anti-bribery training was delivered | The record names the person, the content and the date | You are testing whether people understood it |
| Due diligence was performed on an associate | The file is complete and dated before the engagement began | The risk rating looks inconsistent with the depth of the check |
| A control operated all year | The system generates the record automatically and cannot be edited | The record is manual, retrospective, or maintained by one person |
| A corrective action was closed | The closure evidence directly addresses the original cause | The same nonconformity has appeared before |
| Gifts and hospitality stayed within limits | The register is complete and approvals are attached | Interviews suggest gifts are handled outside the register |
| The anti-bribery function is independent | The written mandate sets out the reporting line | Behaviour in practice appears to contradict the mandate |
| Anti-bribery culture is being encouraged | Never — culture cannot be evidenced by one artefact | Always; combine communications, interviews, behaviour and consequences |
That last row matters more since the 2025 edition. Anti-bribery culture is spelt out as a requirement in its own right at clause 5.1.3. Culture leaves scattered traces. You look at what leaders say, what gets rewarded, what happens after a concern is raised, and whether people can describe the policy in their own words.
What evidence does ISO 37001:2025 ask for?
February 2025 brought ISO 37001:2025, which supersedes the 2016 edition. If your certificate is still written against 2016, the date to work back from is 28 February 2027. The course is taught against the current edition throughout.
The changes are not cosmetic for an auditor. Several of them create new places to look.
- The 2025 edition adopts the harmonized structure shared across management system standards. If you have audited another system, the shape will feel familiar.
- “Stakeholders” is now “interested parties”, matching the rest of the family.
- Clauses 4.1 and 4.2 require climate change to be considered as part of context and interested-party expectations. You check that the consideration happened and was recorded.
- Culture is named outright at clause 5.1.3, as described above.
- Conflict-of-interest awareness now has to feature in employment processes, under clause 7.2.2. Recruitment and onboarding records come into scope.
- The anti-bribery function’s remit, and the independence it requires, are spelled out in sharper terms. Ask for the mandate in writing.
- Mergers and acquisitions now sit inside the non-financial controls, under clause 8.4. This is often the hardest evidence to reach, and the table above says why.
- Clause 10 has changed order. Continual improvement now sits at 10.1, nonconformity and corrective action at 10.2.
The standard addresses bribery in four directions: bribery by the organisation, by its own personnel, by business associates acting on its behalf, and bribery directed at the organisation. Your sampling should cover all four. Most weak audit programmes cover only the first two, because those are the easiest to evidence.
Say it plainly: certification does not prove no bribery has occurred or will occur. Neither does a clean internal audit. Both show a system exists and is being worked.
How do you sample inside a company you already know?
Knowing the organisation is an advantage you should use deliberately, not accidentally.
You know which department rushes month-end. You know which supplier relationship predates the policy. You know where the informal approvals happen. An external auditor would need days to learn any of that.
The risk is the mirror image. You also know which finding will make the next team lunch awkward, so you quietly steer the sample away. That is the biggest threat to an ABMS internal audit, and the course names it out loud.
The discipline is simple. Draw the sample before you look at whose name is attached. Write the sampling rule down. If you change the sample, record why. A written rule is easy to defend; a feeling is not.
How do you stay objective auditing your own employer?
“Can I audit my own department?” The answer is no, and the standard is direct about it. Auditors must not audit their own work. If you wrote the procedure, approved the payment, or ran the training, you cannot audit it.
Smaller organisations in the UAE often have a real problem here. There may be only a handful of people who understand the anti-bribery management system at all. The course works through the practical options.
- Cross-audit between departments. Finance audits procurement; procurement audits finance.
- Pair a knowledgeable auditor with an independent one. Knowledge advises, independence concludes.
- Rotate auditors year on year so no one owns the same scope repeatedly.
- Use someone from a sister company or another site within the group.
Objectivity is not the same as ignorance. You are allowed to know things. You are not allowed to have a stake in the outcome.
How are the two days structured?
ISO 37001 internal auditor training is sixteen hours, split across two days. The balance leans towards doing rather than listening.
| Session | Focus | What delegates produce |
|---|---|---|
| Day 1, opening | ISO 37001:2025 requirements and the four directions of bribery | Annotated clause map for their own organisation |
| Day 1, middle | Clause 9.2, the internal audit programme, risk-based planning | A draft annual programme outline |
| Day 1, close | Evidence types and the access table | Their own completed access table |
| Day 2, opening | Interviewing process owners and asking for records | Role-played record requests, including refusals |
| Day 2, middle | Sufficiency, sampling and working papers | A worked ISO 37001 audit checklist for one process |
| Day 2, close | Writing findings, reporting to management, follow-up | Two written nonconformities and a short audit report |
| Assessment | Continuous through both days, plus a written examination | — |
The written examination sits at the end. Continuous assessment runs alongside it, because how you behave in a role-played interview tells us more than a multiple-choice answer does.

How do you write findings that get acted on?
Your report goes to your own management. Not to a certification body, not to a regulator, not to a client. That changes the writing.
A finding needs four parts. The requirement. The evidence. The gap between them. The effect. Delegates practise writing all four in two or three sentences, because long findings get skimmed.
Two habits to avoid. Do not name individuals where a process failure is the real point. Do not soften a nonconformity into an “observation” because you like the person.
Follow-up is part of the job. Under clause 10.2 the organisation must react to nonconformity and take corrective action. Your next audit checks whether the action worked, not just whether a form was signed.
Internal auditor or lead auditor: which do you need?
The distinction is simple. Two days here, and the subject is your own organisation, audited under clause 9.2. A lead auditor course is longer and prepares someone to audit other organisations, usually as part of a team on behalf of a client or a certification body. Different purpose, different length, different exercises.
If auditing other organisations is your aim, the lead auditor training routes cover several standards, including ISO 9001 lead auditor training, ISO 27001 lead auditor training and ISO 45001 lead auditor training. For anti-bribery work inside your own employer, this course is the right one.
Who should attend?
No prior auditing experience is required. Familiarity with the standard is recommended, and you will move faster if you have read it once.
The people who get most from an ISO 37001 internal auditor course tend to be:
- Compliance, legal and risk staff who now own the anti-bribery management system.
- Internal audit team members adding anti-bribery to an existing portfolio.
- Procurement and finance managers who approve payments or engage business associates.
- HR staff handling declarations, onboarding and the clause 7.2.2 requirements.
- Quality coordinators already running audits under other standards.
Teams often attend together. The access table works better when several departments fill it in at once.
What are the three ways to attend?
ISO 37001 internal auditor training comes in three delivery formats.
Classroom or in-house. Held either at your own premises or at an IAS training centre. In-house delivery lets us use your real registers and process names in the exercises.
Virtual instructor-led. Delivered live over web conferencing. Same two days, same tutor, same role-plays in breakout rooms. Useful for teams split across emirates or group companies.
Self-paced. ISO 37001 training online with 30 days of access to the course material. The online course portal hosts it.
Upcoming sessions and delivery formats appear on the training schedule, alongside the rest of our ISO training in the UAE.
How is the course assessed, and what are the certificate’s limits?
You are assessed as you go, and there is a written examination to sit as well. The certificate of completion carries the names of IAS and EAS together.
IAS runs the course with EAS, under IAS’s UQAS accreditation, which reaches training schemes as well as certification. More on the accreditation position and on who we are.
Now the part people assume away. Passing this course will not make you an auditor for IAS. Nor does it certify your employer. It is training in how to plan and run internal audits of an anti-bribery management system, gather evidence, write findings and report to your own management. Certifying an organisation is a separate process, described under our certification process and ISO audit procedure.
One more structural point. The team that delivers ISO 37001 internal auditor training is kept separate from the team that carries out certification audits. Impartiality rules require that split; it is not simply how we prefer to organise ourselves. Your tutor cannot influence a certification decision.
What this page does not claim
This page describes a training course and the requirements of ISO 37001:2025. It makes no statement about the law in the United Arab Emirates or anywhere else. Nothing here says this course, this standard or certification to it is required, approved or recognised by any authority. ISO 37001 is a voluntary international standard. For advice on legal obligations, speak to a qualified lawyer in your jurisdiction.
Ready to build an internal audit programme that stands up? Ask about ISO 37001 internal auditor training in classroom, virtual or self-paced format — get in touch, check the common questions, or start from the UAE home page.
Frequently asked questions
What is ISO 37001 internal auditor training?
ISO 37001 internal auditor training is a two-day course. It teaches you to plan and carry out internal audits of an anti-bribery management system against ISO 37001:2025, inside your own organisation.
How long is the course?
Two days, sixteen hours of instruction, plus the written examination at the end.
Do I need audit experience to attend?
No. No prior auditing experience is required. Reading the standard beforehand is recommended and will help you keep pace.
Can I record a refusal as a nonconformity?
Usually not on its own. A refusal limits your scope. If the organisation’s own procedure gives internal audit a right of access, then blocking that access may itself be a nonconformity against the procedure.
How often must internal audits be done?
The standard requires audits at planned intervals, set by the organisation. Most organisations cover the whole system across a twelve-month cycle, weighting higher-risk processes more often.
Is an internal audit checklist supplied?
You build one. Delegates produce a working ISO 37001 audit checklist for a process of their choosing during day two, so it fits their organisation rather than a template.
Does completing the course certify my employer?
No. Training an internal auditor is not certification. Organisation certification is a separate process; the system certification and ISO certification pages explain how that works, and logo use is covered in the logo usage guideline.
Will a certification auditor look at my internal audit records?
Yes. When an organisation is assessed, the certification body’s auditor reviews internal audit records as evidence that clause 9.2 is being met. Good records help. Thin records invite questions.