Service

GIC là tổ chức đánh giá sự phù hợp, hoạt động trong lĩnh vực Thử nghiệm - Giám định - Chứng nhận

System Certification

Anti-Bribery Management System Certification
ISO 37001:2025

I. INTRODUCTION TO ISO 37001:2025 CERTIFICATION
ABMS

An Anti-bribery Management System (ABMS) is a management tool that helps an organization proactively control bribery risks and build an operating environment based on integrity and transparency. The system translates the commitment to preventing bribery into policies, procedures and controls within everyday operations, while clearly assigning responsibilities to departments and individuals for preventing, detecting and addressing bribery.

ISO 37001:2025 (Anti-bribery management systems – Requirements with guidance for use) is an international standard that specifies requirements and provides guidance for establishing, implementing, maintaining and improving an ABMS. This second edition, published in February 2025, replaces ISO 37001:2016 and incorporates the climate change amendment issued in 2024. Further information is available on ISO’s official ISO 37001 standard page.

ISO 37001:2025 certification involves an independent assessment and confirmation by a certification body that an anti-bribery management system conforms to the standard’s requirements within a defined scope. The audit examines both the design of the system and the effectiveness of its implementation through document review, interviews and the collection of relevant evidence. Key areas include identifying and assessing bribery risks; controlling activities and transactions exposed to risk; receiving and handling reports and protecting those who raise concerns; addressing nonconformities; and improving the system.

Prevention

Identify and assess bribery risks; conduct due diligence on business associates and personnel according to risk; clearly define responsibilities and authorities; control transactions; and develop an anti-bribery culture.

Detection

Monitor warning signs; establish safe, confidential reporting channels; and conduct internal audits to identify violations and weaknesses in controls.

Response and improvement

Verify information, investigate where necessary and address incidents; identify and address causes; adjust controls and improve the system to prevent recurrence.

1. Scope of application and control principles of an ABMS

ISO 37001:2025 applies to organizations in the public, private and not-for-profit sectors, regardless of their size or field of activity. An organization may apply an ABMS to all or part of its operations, with a clearly defined scope and boundaries. The scope must be based on the organization’s context, the requirements of interested parties and the results of its bribery risk assessment.

An ABMS addresses both the risks of giving and receiving bribes, directly or indirectly through intermediaries. The system needs to consider bribery by the organization itself or by personnel and business associates acting on its behalf or for its benefit. It also needs to control the risk of the organization, its personnel or its business associates receiving bribes in connection with the organization’s activities.

Benefits used as bribes may include money, assets or non-financial advantages. An ABMS therefore needs to consider gifts, hospitality, donations, employment opportunities and preferential treatment where these could be used to improperly influence the performance of duties. The identification and control of such benefits need to take account of applicable law and the risks in each specific situation.

The core principle is to apply controls that are reasonable and proportionate to the risks. The measures must be capable of preventing, detecting and addressing bribery, while being appropriate to the organization’s size, business model, locations, business relationships and operational complexity. ISO 37001 focuses on anti-bribery management; certification does not automatically confirm that the organization has controlled every form of corruption, fraud or money laundering, or fulfilled all its other compliance obligations.

2. KEY REQUIREMENTS OF ISO 37001:2025

The requirements in Clauses 4 to 10 form a management cycle covering planning, implementation, evaluation and improvement. Within this cycle, bribery risk assessment provides the basis for selecting and adjusting controls. Leadership commitment, clearly assigned responsibilities and an anti-bribery culture help ensure that the system is implemented consistently in everyday operations.

2.1. Context, scope and bribery risk assessment – Clause 4

The organization needs to identify factors that may affect anti-bribery management, including its structure, decision-making authority, locations, sectors, business model, relationships with business associates and the extent of its interactions with public officials. It also needs to consider entities it controls, entities that exercise control over it, and relevant legal, contractual and other obligations. The scope of the ABMS must be clearly defined and documented.

  • Identifying, assessing and prioritizing risks: Identify situations in which bribery may occur; analyse, assess and prioritize risks for action using criteria established by the organization. Activities such as tendering, procurement, sales through agents, licensing procedures, acceptance of work and payments need to be considered in their actual operating context.
  • Evaluating existing controls: Assess the suitability of each control and its ability to reduce risk. Use the assessment results to select, supplement or adjust controls and improve the ABMS.
  • Reviewing and updating risks: Review risks at planned intervals and when significant changes occur in the organization’s structure or activities, such as entering new markets, undertaking major projects, changing key personnel or changing how agents and intermediaries are used.
2.2. Leadership, culture and anti-bribery responsibilities – Clause 5

Where the organization has a separate governing body, that body is responsible for approving the anti-bribery policy, overseeing implementation and requiring appropriate resources to be allocated. Where there is no separate governing body, top management carries out these responsibilities. Top management has overall responsibility for implementing and complying with the ABMS and integrating anti-bribery requirements into management and operational processes.

  • Anti-bribery policy and culture: The policy must prohibit bribery, require compliance with applicable anti-bribery laws, encourage reporting in good faith or on the basis of a reasonable belief, and explain the consequences of violations. Leaders need to demonstrate their commitment through consistent conduct, specific decisions and the way violations are addressed at every level.
  • The department or person responsible for anti-bribery: The organization must assign the anti-bribery function to persons with appropriate competence, status and authority. The organization must ensure their independence, provide sufficient resources and enable direct and prompt access to the governing body and top management. This function oversees the design and implementation of the ABMS, ensures conformity with the standard, provides guidance and reports on performance. Managers of individual units remain responsible for applying and complying with the ABMS within their units.
  • Delegated decision-making and conflicts of interest: For decisions assessed as involving more than a low bribery risk under the organization’s risk classification criteria, the organization must establish an appropriate decision-making process and levels of authority, ensuring that they are free from actual or potential conflicts of interest. Delegation does not remove management’s responsibilities.
2.3. Objectives, resources, personnel and information – Clauses 6 and 7

The organization must identify risks and opportunities that may affect the results of the ABMS, plan actions and establish anti-bribery objectives. Each objective needs to be linked to responsible persons, resources, deadlines and a method for evaluating results. Objectives must be measurable where practicable, monitored and updated as appropriate. Changes to the system must also be planned before implementation.

  • Personnel controls based on risk: For positions exposed to more than a low bribery risk and persons assigned to the anti-bribery function, due diligence is needed before recruitment, transfer or promotion. The organization must periodically review performance targets, bonuses and incentive arrangements to avoid encouraging bribery. Personnel in these groups, top management and the governing body need to confirm their compliance with the policy and the ABMS at intervals proportionate to the risks.
  • Awareness and training: Personnel need to understand the policy, their responsibilities, situations in which bribery may occur, how to recognize and respond to them, and how to raise concerns. Awareness and training activities must be appropriate to their roles and risk exposure and provided from the start of employment and at planned intervals. The organization also needs to identify training needs for business associates that pose more than a low bribery risk and act on its behalf or for its benefit.
  • Communication and records management: Communicate the policy in languages appropriate to its recipients; control the creation, updating, access, confidentiality and retention of documents and records. Retain evidence of personnel competence and the delivery of awareness and training programmes, including their content, recipients and dates.
2.4. Due diligence and controls over transactions and business associates – Clauses 8.1 to 8.6

Due diligence is the process of collecting and evaluating information to clarify the bribery risks associated with a specific transaction, project, activity, business associate or individual. Where a category of such subjects is assessed as posing more than a low bribery risk, the organization needs to determine the necessary level of due diligence for the subjects within that category and update information at a defined frequency.

  • Focused due diligence: Depending on the subject and the risks, due diligence may consider owners and beneficiaries, capacity to perform the work, relationships with public officials, information on previous violations, the justification for services, fees and payment methods. The scope of due diligence needs to be tailored to each case.
  • Financial controls: Manage bribery risks in expense approval, payments, accounting records and cash management. Examples include separating responsibility for requesting, approving and making payments; checking supporting documents against the goods or services actually provided; and examining unusual commissions or payments to third parties without a clear justification.
  • Non-financial controls: Manage risks in supplier selection, tendering, sales, recruitment, contract performance, legal affairs, mergers and acquisitions, and activities involving regulatory authorities. Measures may include transparent selection criteria, independent review and controls over conflicts of interest.
  • Controls in controlled entities and business associates: Require controlled entities to apply the organization’s ABMS or their own anti-bribery controls, as appropriate to the risks. For business associates outside its control that pose more than a low bribery risk, review their anti-bribery controls and, where practicable, require controls to be established or strengthened when these can help reduce the relevant risks.
  • Anti-bribery commitments: As far as practicable, require business associates posing more than a low bribery risk to commit to preventing bribery in connection with the transaction, and establish agreements allowing the relationship to be terminated if bribery occurs. Where these requirements cannot be met, the organization must consider the implications in its risk assessment and risk management. The standard does not require every business associate to hold ISO 37001 certification.
2.5. Gifts, benefits and inadequate controls – Clauses 8.7 and 8.8

The organization needs procedures to control the offering, provision or acceptance of gifts, hospitality, donations and similar benefits to prevent bribery. This consideration also needs to cover circumstances in which the conduct could reasonably be perceived as bribery. Control factors may include purpose, value, frequency, timing, recipients, approval authority and records.

ISO 37001 does not prescribe a universal value limit for gifts or benefits applicable to every organization. Even a benefit of low value may be associated with bribery. Unofficial payments to secure or expedite routine procedures to which the payer is entitled (facilitation payments) are treated as bribes under the standard; its guidance recommends prohibiting such payments within the ABMS.

Where due diligence shows that existing controls are insufficient to manage the risks, the organization needs to consider additional controls or changes to the transaction. If it cannot or chooses not to take the necessary measures, it must:

  • For new transactions, projects or relationships: Postpone or decline to proceed.
  • For existing transactions, projects or relationships: Take appropriate steps to suspend, terminate or withdraw as soon as practicable.
2.6. Reporting concerns, protecting reporters and investigations – Clauses 8.9 and 8.10

The ABMS needs to enable people to report actual, ongoing or suspected bribery, as well as violations and weaknesses in the system. The reporting arrangements must protect confidentiality, allow anonymous reporting and protect those who report in good faith or on the basis of a reasonable belief from retaliation. Applicable legal limitations need to be taken into account.

Reports must be reviewed, verified and investigated where necessary, with the findings used to determine appropriate action. Investigators and the recipients of investigation reports must not belong to the department or hold the role being investigated. The organization needs to give investigators sufficient authority, require cooperation from relevant personnel, protect the confidentiality of the investigation and its results, and report its status and findings to the anti-bribery function and other relevant compliance functions, as appropriate.

2.7. Evaluating effectiveness and improvement – Clauses 9 and 10

The organization must monitor, measure, analyse and evaluate performance to determine whether the ABMS is being maintained and achieving its objectives. Internal audits must be conducted as planned, ensuring objectivity and preventing auditors from auditing their own work. Top management and the governing body review the system in accordance with their assigned responsibilities. The anti-bribery function continually assesses the adequacy of controls and the effectiveness of ABMS implementation, reporting at planned intervals or on an ad hoc basis as needed.

Possible indicators include the percentage of due diligence files completed before transaction approval, training coverage for personnel in positions exposed to risk, the time taken to handle reports and the percentage of corrective actions that achieve their intended results. Few or no reports do not, on their own, demonstrate that the system is working well; the organization also needs to consider whether personnel know about, can use and trust the reporting arrangements.

When a nonconformity is identified, the organization must address the issue and its consequences, analyse the causes, take corrective action and verify the results. This information needs to be used to adjust controls, prevent recurrence and improve the system.

3. Benefits of implementation and certification
  • Improving governance: Clarify responsibilities, authorities and oversight arrangements, and integrate anti-bribery requirements into everyday decisions and activities.
  • Reducing bribery risks and related losses: Proactively control activities exposed to risk, identify warning signs and promptly address weaknesses that could lead to violations.
  • Supporting compliance with anti-bribery requirements: Help the organization systematically identify, update and fulfil relevant legal requirements, contractual obligations and voluntary commitments.
  • Increasing transparency in business relationships: Establish clear criteria for due diligence, selection, approval and monitoring of business associates, helping ensure that cooperation decisions are justified and appropriately controlled.
  • Building confidence and supporting market access: Certification provides independently assessed evidence of ABMS conformity with the standard, helping meet the anti-bribery requirements of customers, investors, procuring entities and supply chain partners.
  • Building a culture of integrity: Help personnel understand which conduct is permitted and which is prohibited, know how to refuse bribery and feel confident about raising concerns through arrangements that provide confidentiality, protection and fair treatment.
4. Which organizations is this service suitable for?
  • Organizations and businesses that are establishing or improving an anti-bribery management system and seeking assessment and certification to ISO 37001:2025.
  • Entities whose activities require particular attention to bribery risks, such as tendering, procurement, investment, construction, distribution, transactions through intermediaries or frequent dealings with public authorities.
  • Organizations that need to demonstrate that they meet the anti-bribery requirements of customers, business associates, investors or other parties in their supply chains.
  • Corporate groups and businesses with multiple sites or member entities that need consistent policies, clearly assigned responsibilities and controls appropriate to the risks at each entity.

Value and limitations of certification: ISO 37001:2025 certification confirms that the anti-bribery management system meets the standard’s requirements within the assessed scope. Certification does not guarantee that bribery has never occurred or will not occur, nor does it replace the organization’s responsibility to comply with the law. ISO publishes the standard; certification bodies conduct audits and issue certificates. When using and promoting certification, businesses need to state the correct scope and standard edition and comply with the relevant rules.

II. CERTIFICATION PROCESS
Step 1
Application & application review

1. Application & application review

The organization contacts GIC Vietnam and provides information on its legal entity, proposed certification scope, activities, sites, structure, personnel, member entities, business associates and interactions with public officials. The application needs to reflect the status of the ABMS, applicable anti-bribery obligations and existing risk assessment results. GIC Vietnam reviews its ability to undertake the work, audit team competence, audit duration and certification conditions, forming the basis for agreeing the scope, fees and contract.

Step 2
Audit planning & preparation

2. Audit planning & preparation

GIC Vietnam establishes the certification programme, assigns an audit team competent in ABMS and the relevant sector, and plans the audit based on scope and risk. The organization prepares system documentation, records demonstrating the implementation of controls, internal audit results and management review results. Both parties agree on access to sites, responsible personnel and necessary records, protecting sensitive information while ensuring sufficient audit evidence is available.

Step 3
Audit process

3. Audit process

Initial certification audits are conducted in two stages:

  • Stage 1: Review the scope, context, bribery risks, policy, assigned responsibilities, documented information and readiness; consider the status of internal audits, management reviews and issues to be addressed before Stage 2.
  • Stage 2: Assess ABMS conformity and effective implementation through interviews, observation and sampling of records. Key areas include anti-bribery culture, due diligence, financial and non-financial controls, conflicts of interest, gifts, business associates, reports, investigations where incidents have arisen, evaluation and improvement. The main sequence is: Opening meeting → Audit activities → Consolidation of findings → Closing meeting.
Step 4
Audit report & addressing nonconformities

4. Audit report & addressing nonconformities

The audit team prepares a report setting out its conclusions and any nonconformities, supported by objective evidence. The organization makes corrections where necessary, analyses causes, assesses the extent of the issue and implements corrective action within the agreed timeframe. GIC Vietnam reviews and verifies the response according to the significance of the findings and may request additional records or a follow-up audit. The requirements for addressing nonconformities must be met before a certification decision is made.

Step 5
Review & certification

5. Review & certification

Competent personnel, independent of the audit team, review the certification file and make the certification decision in accordance with their assigned responsibilities. When the requirements are met, the organization is issued an ISO 37001:2025 certificate with clearly defined scope and sites. The certificate is valid for a three-year cycle, provided that the ABMS continues to be maintained, surveillance audits are completed and the organization complies with the rules governing the use of certification.

Step 6
Surveillance & recertification

6. Surveillance & recertification

GIC Vietnam conducts periodic surveillance audits to confirm that the ABMS remains conforming and effective; the first surveillance audit takes place no later than 12 months from the initial certification decision. The audits focus on system changes, risks, control effectiveness, reports and complaints, internal audits, management reviews and corrective actions. Before the certificate expires, the organization undergoes a recertification audit to consider certification for the next cycle.

III. WHY CHOOSE GIC VIETNAM?
International credibility and recognition

GIC provides management system certification services in accordance with international standards, helping businesses demonstrate their governance capabilities and meet market requirements. For ISO 37001:2025, certificate recognition depends on the issuing body, the applicable scope of accreditation and the requirements of the receiving party. GIC Vietnam clarifies these matters during application review, helping businesses select a service suited to their objectives and markets.

Professional & cost-effective service

GIC Vietnam emphasizes independence, impartiality, confidentiality and professional competence throughout the certification audit process. Audit teams are selected to match ABMS requirements and the organization’s sector; audit plans, duration and fees are determined according to scope, size and risk. Clear and professional service delivery helps businesses prepare effectively and use their resources efficiently.

CONTACT INFORMATION
 
GIC VIETNAM
🏢 Hanoi: 12F, 14 Lang Ha Building, Giang Vo Ward
Tel: 024 6275 2268 | Hotline: 0984 609 469
Email: tuandm@gicvn.vn
🏢 Ho Chi Minh City: R502, 160 Nam Ky Khoi Nghia
Tel: 028 3930 7936
Chia sẻ:

System Certification

Verification, Validation

  • ESG Reports

    The ESG (Environmental, Social, and Governance) framework helps businesses measure their sustainability impacts, guide long-term risk management strategies, and create positive value for both the community and stakeholders.
  • GHG Inventory Reports

    Building trust - Stepping steadily into integration. Independent verification of greenhouse gas inventory reports enhances the reliability and transparency of emissions data and meets international standards.
  • Product Carbon Footprint (CFP)

    Product Carbon Footprint Verification – A solution to build trust and elevate product value in the global supply chain.
  • CBAM Embedded Emissions

    CBAM embedded emissions verification independently assesses monitoring approaches, activity data, emissions calculations and supporting evidence at installations producing CBAM goods. The process helps businesses improve data reliability, identify misstatements and prepare to meet EU CBAM reporting and verification requirements.
  • Singapore Green Labelling

    Green Label helps identify environmentally friendly products and enhances the company's image.

Product, process certification

  • Product Certification

    Product certification is the process of assessing and confirming that a product meets the technical, quality and safety requirements of the applicable standard. Achieving certification helps demonstrate product reliability, build consumer confidence and strengthen the brand’s competitiveness in the market.
  • Technical Regulation Conformity Certification

    Technical regulation compliance certification is the process of evaluating and verifying that products conform to national technical regulations. Understanding the relevant regulations and certification procedures helps businesses ensure strict legal compliance, guarantee product safety, and successfully introduce their goods into the...
  • Traceability

    Certification of the Traceability System according to the ISO 22005 helps businesses in the food and feed chain ensure transparency in the movement of goods, strictly control food safety risks, and simultaneously meet the stringent requirements of partners, consumers, and international...
  • ISO 3834 Welding Process

    ISO 3834 certification service evaluates a manufacturer’s capability to control metallic-material fusion welding against ISO 3834-2, ISO 3834-3 or ISO 3834-4. The assessment covers personnel, WPS and WPQR/PQR, materials, equipment, inspection, NDT and welding quality records.
  • CE Marking

    Affixing the CE mark is a mandatory requirement for many product groups when placed on the EEA market. This article helps Vietnamese businesses determine the scope of application, manufacturer responsibilities, cases requiring a Notified Body, technical documentation, and the conformity assessment...

Improvement Tools Certification

  • 5S Certification

    5S builds a professional image and fosters a dynamic, creative, and efficient work environment.
  • Lean Manufacturing

    Lean optimizes the production process by eliminating waste and increasing customer value.
  • KPIs

    KPI is a metric to evaluate goal achievement for a business, team, or individual.

Coaching and Training