Registrations

ISO 37001 Certification (Anti-Bribery)

ISO 37001:2025 replaced the 2016 edition on 28 February 2025, and every certificate issued under the old standard must transition by 28 February 2027 — months away. We prepare the anti-bribery management system; an accredited body certifies it.

Why founders pick CapEasy

5.0★ across 335+ Google reviews

2,700+ founders served across India

Overview

ISO 37001 is the international standard for an anti-bribery management system (ABMS) — a documented set of controls, due-diligence checks and reporting channels designed to prevent, detect and respond to bribery within an organisation and by the people who act on its behalf. ISO published a revised second edition, ISO 37001:2025, on 28 February 2025, replacing ISO 37001:2016. If your organisation already holds a 2016-edition certificate, the transition deadline is fixed: every certified site must complete the move to the 2025 edition by 28 February 2027. That is closer than it looks once you account for a gap analysis, any control changes and a fresh audit cycle.

No Indian law requires ISO 37001. There is no statutory trigger comparable to FSSAI for food businesses or CDSCO for medical devices. What is driving Indian demand is procurement, not legislation: large corporates and public-sector undertakings increasingly write anti-bribery expectations into vendor undertakings and supplier codes, and some ask suppliers to demonstrate alignment with ISO 37001 specifically. Steel Authority of India Limited (SAIL) has reportedly implemented an anti-bribery management system aligned to ISO 37001 across its plants, and its vendor undertakings are reported to reference the standard’s anti-bribery expectations for suppliers. We flag this as reported practice at one large PSU, not as a government-wide mandate — treat it as evidence of the direction procurement is moving, not a rule that applies to every tender.

The certificate itself has to come from a body accredited for this specific scheme — in India that means NABCB (the National Accreditation Board for Certification Bodies, under the Quality Council of India) or another IAF-MLA-signatory accreditation body. An unaccredited "ISO 37001 certificate" is paper a large-corporate or PSU compliance team can reject on sight, because it carries none of the peer-reviewed assurance an accredited scheme does. If a certifier cannot show you their NABCB or equivalent IAF accreditation scope covering ISO 37001, walk away regardless of price.

CapEasy is not a certification body and does not issue, award or assign ISO 37001 certificates. We build the anti-bribery management system your organisation actually needs — policies, risk assessments, due-diligence procedures, a reporting and investigation channel, training — and prepare you for audit by an accredited certifier. If you are already certified to the 2016 edition, we can also scope the gap to the 2025 edition so your transition audit is a formality rather than a scramble.

Who it’s for

  • Businesses that supply, or want to supply, PSUs and large corporates whose vendor undertakings ask for anti-bribery controls or alignment with ISO 37001
  • Organisations already certified to ISO 37001:2016 that need to plan the transition to the 2025 edition before the 28 February 2027 deadline
  • Companies operating in sectors exposed to bribery risk in sales, procurement or government-facing dealings — construction, infrastructure, defence-adjacent supply, distribution
  • Businesses that already hold ISO 9001 or ISO 27001 and want to add anti-bribery controls onto an existing management-system discipline
  • Exporters and companies with overseas customers who ask about anti-bribery compliance as part of vendor due diligence

Eligibility & requirements

  • Top management commitment to an anti-bribery policy, with a named person or function given authority over the anti-bribery management system
  • A documented bribery risk assessment covering your sectors, markets, transactions and business relationships
  • Due-diligence procedures for third parties — agents, distributors, joint-venture partners, contractors — proportionate to the bribery risk each poses
  • Financial and non-financial controls: gifts and hospitality limits, controls on facilitation payments, procurement and expense controls designed to prevent bribery
  • A confidential reporting channel (a whistleblowing or "speak up" mechanism) and an investigation procedure for concerns raised
  • Internal audit and management review of the ABMS, consistent with how ISO management-system standards are normally operated
  • Certification only through a body accredited for the ISO 37001 scheme — NABCB in India, or an equivalent IAF-MLA-signatory accreditation body

How CapEasy handles it

  1. Scope the ABMS — which entities, sites and business relationships the anti-bribery management system will cover, and what your specific bribery risks look like
  2. Gap analysis against ISO 37001:2025, including a specific transition gap check if you currently hold a 2016-edition certificate
  3. Build the risk assessment and the third-party due-diligence framework, sized to how you actually engage agents, distributors and contractors
  4. Draft the anti-bribery policy, financial and gift/hospitality controls, and the reporting and investigation procedure
  5. Train staff and relevant third parties on the policy and reporting channel, and run the internal audit and management review the standard expects
  6. Help you shortlist and engage a NABCB (or equivalent IAF-accredited) certification body and prepare for Stage 1 (documentation review) and Stage 2 (implementation audit)
  7. Support you through any nonconformities raised at audit and the corrective actions needed to close them
  8. For existing 2016-edition holders, plan the transition audit so it lands comfortably ahead of the 28 February 2027 deadline

Documents you’ll typically need

  • Existing anti-bribery, gifts-and-hospitality, and code-of-conduct policies, if any
  • A list of third parties you engage — agents, distributors, contractors, joint-venture partners — and how they are currently vetted
  • Records of any prior compliance training, internal audits or whistleblowing reports
  • Your current ISO 37001:2016 certificate and audit reports, if you already hold one and are transitioning
  • Organisation chart showing who holds authority over compliance, procurement and finance functions
  • Any vendor undertakings or supplier codes from PSU or large-corporate customers that reference anti-bribery expectations

CapEasy is a private consultancy and is not affiliated with any government authority. We help you assess eligibility and prepare and file your application; eligibility and approval depend on your specifics and the relevant department’s discretion.

Frequently asked

ISO 37001 Certification (Anti-Bribery) — questions founders ask

No. There is no Indian law that mandates ISO 37001 for any sector. Demand comes from procurement, not legislation — large corporates and some PSUs write anti-bribery expectations into vendor undertakings, and a certificate is one way to demonstrate you meet them. If a supplier tells you it is a legal requirement, that is not accurate.

ISO published the revised second edition on 28 February 2025, replacing the 2016 edition. Every organisation certified under the 2016 edition has until 28 February 2027 to complete its transition to the 2025 edition; after that date, a 2016-edition certificate is no longer valid. We run a gap analysis specific to your existing ABMS so the transition audit confirms what already works rather than rebuilding from scratch.

CapEasy does not. An independent, accredited certification body audits your anti-bribery management system and issues the certificate if you meet the standard. In India that body should hold NABCB accreditation for the ISO 37001 scheme, or accreditation from another IAF-MLA-signatory body. We prepare your organisation for that audit; we do not certify, issue or assign the credential ourselves.

For the certificate to carry weight with a PSU or large-corporate compliance team, yes — accreditation is the point. An unaccredited certifier can sell you a document that says "ISO 37001" on it, but it was never peer-reviewed against the scheme, and a sophisticated buyer can and does reject it. Ask any certifier to show you their accreditation scope covering ISO 37001 before you engage them.

No, and it is worth being precise here. SAIL has reportedly implemented its own anti-bribery management system aligned to ISO 37001 across its plants, and its vendor undertakings are reported to reference the standard’s expectations for suppliers. That tells you where PSU procurement is heading, not that SAIL requires every vendor to hold a formal ISO 37001 certificate — check the specific tender or vendor undertaking that applies to you rather than assuming a blanket rule.

It helps operationally. If you already run a management-system discipline — documented policies, internal audit, management review — much of that structure carries over, and building an anti-bribery layer on top is faster than starting from nothing. ISO 37001 is still its own certification with its own audit; holding another ISO certificate does not substitute for it.

Your CapEasy experts

Connect with us

Talk to the people who handle this work every day — no call centre, no hand-offs.

Ayush Joshi

Ayush Joshi

Co-Founder

Ex-OYO and Tenaciousfly. 7+ years in business development, strategic acquisitions, financing and debt syndication.

Aditya Jain

Aditya Jain

Co-Founder

Ex-Bank of America. 4+ years in investment banking, EU & Indian compliances, ESG compliances, and project management.

Manav Raval

Virtual CFO & Tax Specialist

Section 80-IAC, tax planning and startup compliance. Previously at Toyota Motor Corporation and Jaguar Land Rover.

Book a free consultation.

An honest assessment of where you are and what comes next — no cost, no pressure, no inflated promises.