Financial and Non-Financial Controls in ISO 37001: What Clauses 8.3 and 8.4 Require
Most bribery does not look like bribery in the ledger. It looks like a consultancy fee, a rounding on a freight invoice, a sponsorship, a slightly generous scope variation. That is the whole reason ISO 37001 splits its control requirements in two. Clause 8.3 deals with the money. Clause 8.4 deals with everything that surrounds the money — the sourcing, the approvals, the contract, the deal. Get one right and miss the other, and you have a system that catches the payment after the decision has already been sold.
This post works through both clauses as they read in ISO 37001:2025, what auditors actually look for, and where organisations in Iraq most often come unstuck.
Planning an ISO 37001 audit? See how ISO 37001 certification in Iraq is assessed by IAS, or start with the ISO 37001 internal auditor training that teaches you to test these controls in your own organisation.
What do ISO 37001 clauses 8.3 and 8.4 ask for?
Clause 8.3 requires the organisation to implement financial controls that manage bribery risk. Clause 8.4 requires non-financial controls that manage bribery risk in areas such as procurement, operations, sales, commercial activity and — new in the 2025 edition — mergers and acquisitions.
Both clauses are risk-driven. Neither hands you a checklist. The standard expects you to have identified where bribery could plausibly happen, and to have controls proportionate to that risk. A trading company with two suppliers has a different control set from a contractor running forty subcontracts. The word “proportionate” does a lot of work here, and it is where most arguments with auditors begin.
What does clause 8.3 require of financial controls?
Financial controls are the ones that make a suspicious payment hard to make and easy to see. In practice, an audit will expect to see some combination of:
- Segregation of duties. The person who raises a payment is not the person who approves it, and neither of them controls the supplier master file.
- Authority limits that mean something. A limit only works if the system enforces it and nobody has a standing override.
- Supporting documentation as a condition of payment. No invoice, no contract reference, no goods receipt — no payment.
- Controls over cash and petty cash. Tighter limits, counter-signing and periodic surprise counts.
- Scrutiny of payment method and destination. Third-country accounts, a payee name that differs from the contracting party, and requests to split payments all deserve a second look.
- Review of high-risk expense categories. Gifts, hospitality, donations, sponsorships and “consultancy”.
- Periodic independent review. Someone outside the transaction stream looks at samples and asks why.
A weak version of all this exists in nearly every organisation: the approval matrix is written down, but a director signs everything over a threshold with no attached evidence. The control exists on paper. It does nothing.

What does clause 8.4 require of non-financial controls?
Non-financial controls cover the decisions that happen before any money moves. This is where an improper advantage is usually agreed.
Typical areas:
- Procurement. Tender rules, evaluation by more than one person, recorded reasons for the award, and controls on single-source awards and post-award variations.
- Pre-qualification of suppliers, agents and intermediaries. Ownership, beneficial ownership, and whether the party actually has the capability being paid for.
- Contract terms. Anti-bribery clauses, audit rights, termination rights, disclosure of subcontractors.
- Commission and success-fee arrangements. Justified rates, defined deliverables, evidence the work happened.
- Operational approvals. Permits, clearances, inspections, sign-offs — anywhere a decision-maker can be leaned on.
- Conflicts of interest. Declared, recorded, and acted upon rather than filed.
- Mergers, acquisitions and joint ventures. The 2025 addition, covered below.
An organisation that has solid financial controls and no non-financial controls tends to fail in a predictable way. The payment is perfectly documented. The problem is that the contract it pays for should never have been awarded.
How do financial and non-financial controls differ?
| Aspect | Financial controls (8.3) | Non-financial controls (8.4) |
|---|---|---|
| Point in the process | After the commitment is made | Before and during the commitment |
| Typical owner | Finance, treasury, accounts payable | Procurement, legal, commercial, operations |
| Main evidence type | Transaction records, approvals, reconciliations | Tender files, due diligence records, contracts, minutes |
| What it catches | Improper or disguised payments | Improper award, selection or specification |
| Common failure | Approvals granted without supporting documents | Sole-source awards with no recorded justification |
| Easiest to test | Yes — sampling is straightforward | Harder — requires judgement about the decision |
| How it is usually defeated | Splitting invoices below a threshold | Writing a specification only one bidder can meet |
| Blind spot if used alone | The decision that caused the payment | The money that leaves by another route |
The point of the table is not that one clause matters more. It is that the two are designed to close each other’s gaps, and an audit will look at whether they actually connect.
What changed for mergers and acquisitions in 2025?
February 2025 saw the publication of ISO 37001:2025, which supersedes the 2016 edition. Certificates issued to the 2016 version need to transition by 28 February 2027.
One of the substantive changes sits directly in your topic: clause 8.4 now names mergers and acquisitions as a non-financial control area. The logic is plain. When you buy a company, you buy its history. A target with an unmanaged agent network, undisclosed intermediaries or a pattern of unexplained commissions becomes your exposure on completion day.
In practice, bribery risk should feature in pre-acquisition due diligence, not only the financial and legal review. The scope should be proportionate to the target’s markets and sectors. After completion, there should be a plan with a realistic timeline for bringing the acquired entity inside the ABMS. Joint ventures deserve the same thinking, even where you cannot impose your controls outright.
Two other 2025 changes feed this area. Clause 5.1.3 makes anti-bribery culture an explicit requirement, and clause 7.2.2 adds conflict-of-interest awareness to employment processes. Both underpin the non-financial controls you rely on.
How do you decide what is proportionate, and defend it?
Auditors do not expect a small distributor to run the control set of a multinational. They do expect the control set to match the risk assessment.
The test is simple. Take your three highest-rated bribery risks. Point to the specific financial and non-financial controls that address each one. If a high risk has no named control, or the control is “staff are aware of the policy”, that is a finding waiting to happen.
Suppose a trading company’s risk assessment rates “agents dealing with customs clearance” as high. A proportionate response looks like: documented due diligence on each agent, a written contract with anti-bribery terms and audit rights, a defined fee schedule, a prohibition on cash advances, and invoices supported by the official receipts they claim to cover. A disproportionate response is a policy statement and nothing else.

What do auditors ask for, and what satisfies them?
During a certification audit, stage 1 examines readiness and documentation, and stage 2 examines whether the system works in practice. Clauses 8.3 and 8.4 are largely a stage 2 conversation, because both are about behaviour, not text. The certification process and the ISO audit procedure set out how the stages fit together.
Expect an auditor to pull samples and follow them end to end. A payment to an agent, backwards to the contract, backwards to the due diligence, backwards to the decision to appoint. A tender award, forwards to the contract, forwards to the variations, forwards to the payments.
| Control area | Weak evidence | Strong evidence |
|---|---|---|
| Supplier due diligence | A signed self-declaration form on file | Screening output, ownership check, a written risk conclusion, and a dated re-check |
| Authority limits | A matrix in the manual | System-enforced limits, plus a log of overrides with reasons |
| Gifts and hospitality | A register with six entries for the year | A register with refusals recorded, thresholds applied, and evidence of escalation |
| Agent commissions | A percentage stated in the contract | Deliverables defined, work evidenced, rate benchmarked against comparable engagements |
| Tender awards | A signed award recommendation | Evaluation scores from more than one evaluator, plus recorded reasons for rejecting others |
| Conflicts of interest | An annual declaration exercise | Declarations that led to recusal, reassignment or a documented decision |
| M&A screening | The target passed legal due diligence | A bribery-specific due diligence scope, findings, and an integration plan with owners |
| Cash controls | Petty cash reconciled monthly | Surprise counts, dual custody, a cash limit tied to the risk assessment |
The pattern in the right-hand column is the same throughout: the control produced a decision, and the decision left a record.
Where do these controls usually fail?
A few failures come up again and again.
Thresholds treated as targets. Once staff learn the approval limit, invoices start arriving just below it. Splitting is the oldest trick in accounts payable, and it is easy to detect if anyone looks.
Due diligence that never gets refreshed. An agent checked years ago has been re-approved by silence ever since. Ownership changes. So does risk.
The urgent-deal exception. Controls suspended because a bid deadline is tomorrow. If the exception is never recorded and never reviewed, it is not an exception — it is the real process.
Registers that only record approvals. A gifts register with no refusals in it usually means nothing is being refused, or nothing is being reported.
Variations after award. The tender was competitive. The scope then tripled through variations that nobody evaluated. That is the award decision being made again, without any of the controls.
Who should own which control?
Ownership is where 8.4 quietly collapses. Finance owns authority limits and the payment run. Procurement owns supplier and agent due diligence. Legal owns contract terms. The commercial or technical panel owns tender evaluation. Human resources and line managers own conflict-of-interest declarations. Corporate development owns bribery due diligence on acquisitions. Internal audit owns independent testing.
The anti-bribery function does not run any of these controls. It sets the methodology, reviews the high-risk conclusions, and escalates what needs escalating. That separation is what keeps it able to say no — and the 2025 edition states its role and independence more clearly than the 2016 text did.
How do you test whether the controls actually work?
Documented controls and working controls are different things, and clause 8.4 in particular rewards testing.
Practical methods that hold up in an audit:
- Sample payments in high-risk categories and trace them to their originating decision.
- Re-run a closed tender file and ask whether the evaluation record would convince a stranger.
- Take a sample of agents and check that the fee paid matches work you can evidence.
- Test the override log. If there is no override log, that is the finding.
- Interview people outside finance. Ask them what they would do if a customer’s representative asked for a personal benefit.
ISO 37001 internal auditor training runs two days, sixteen hours, and is built around exactly this kind of testing inside your own organisation. It is available as classroom or in-house delivery, live virtual or self-paced online with thirty days’ access. If you need to audit other organisations rather than your own, the ISO 37001 lead auditor course runs five days, forty hours, through the same three routes. Assessment on both auditor courses runs through the course, with a written examination on the final day, and no prior experience is required.

Where does ISO 37001 certification fit?
Certification to ISO 37001 is delivered by IAS, which holds UQAS accreditation. A certificate runs on a three-year cycle, with surveillance audits in between and recertification at the end. You can read more about IAS accreditation and system certification.
Be clear about what the certificate says. What it states is that, on the date the audit took place, a management system conforming to the standard was found to exist. It is not proof that no bribery has occurred, and it is not a clean bill of health, an endorsement or a legal defence. Organisations that already hold ISO 9001 certification will recognise the shape of the clauses, since the harmonized structure is common to both.
Four directions of bribery fall within the scope of ISO 37001: bribery committed by the organisation, bribery committed by its own personnel, bribery committed by business associates acting on its behalf, and bribery aimed at the organisation itself. Clauses 8.3 and 8.4 carry much of the weight for the first three.
Legal position and course status
This post makes no claim about the law in Iraq or in any other country. Legal duties, reporting obligations and the consequences of getting them wrong are matters for your own legal advisers, not for a blog post or a standard.
Reading this article and completing any course described here does not make anyone an IAS auditor and confers no registration of any kind. Training certificates are issued by IAS together with EAS under IAS’s UQAS accreditation, which covers training schemes as well as certification. Whoever delivers the training sits apart from whoever carries out the audits. Impartiality rules oblige that split; it is not a matter of preference.
- Accredited by UQAS
- Training and audit teams kept separate
- Classroom, live virtual and self-paced routes
- Certificates issued by IAS with EAS
Ready to test your 8.3 and 8.4 controls properly? Talk to the team through contact us, or look at how ISO 37001 certification assesses those controls in stage 2.
Frequently asked questions
Is clause 8.3 just a financial audit requirement?
No. A financial audit checks whether the numbers are right. Clause 8.3 asks whether your financial controls make improper payments hard to make and visible when attempted. A clean external audit opinion does not satisfy it.
Do small organisations need all of this?
No. Controls must be proportionate to the bribery risk you have identified. A small company with low-risk customers and no intermediaries can justify a lean control set — provided the risk assessment supports it and you can explain the reasoning.
What is the most common finding against clause 8.4?
Sole-source awards with no recorded justification. The award may have been entirely legitimate, but if nobody wrote down why, there is nothing to audit.
Does 8.4 apply if we do not use agents?
Yes. Non-financial controls cover procurement, operations, sales, commercial activity and M&A. Agents are one high-risk area among several, not the whole clause.
How far back does M&A due diligence need to go?
The standard does not set a period. Scope it to the risk — the target’s markets, sectors, customer types and use of intermediaries. Record why you chose that scope.
Can we exclude a newly acquired subsidiary from the certified scope?
Scope is agreed with the certification body. What you cannot do is treat an excluded entity as invisible. If it acts for you, business associate controls still apply.
Who should approve exceptions to a financial control?
Somebody senior enough to carry it, outside the transaction, and the decision must be recorded with its reasons. An unlogged override is worse than no limit at all.
Does ISO 37001 require us to stop all gifts and hospitality?
No. It requires controls proportionate to risk. Many organisations set thresholds, require pre-approval above them, and record both approvals and refusals.
Which course should our procurement lead take?
If they need to understand the standard, the Foundation course is half a day, four hours, self-paced online, with thirty days’ access. It teaches understanding, not auditing. If they will test controls internally, the internal auditor route is the right one.
Can these controls be audited by our own internal auditors?
Yes, and they should be. Internal audit is the natural owner of independent testing. Lead auditor training is for people who audit other organisations, not their own.
Where do I find other ISO training options?
The full ISO training in Iraq listing covers other standards, and the online course platform holds the self-paced routes. General queries are answered on the FAQ page.
*Written for compliance, procurement and internal audit professionals working with ISO 37001:2025.*
