Overview
ISO 37001 is the international standard for an anti-bribery management system (ABMS) — a documented set of controls, due-diligence checks and reporting channels designed to prevent, detect and respond to bribery within an organisation and by the people who act on its behalf. ISO published a revised second edition, ISO 37001:2025, on 28 February 2025, replacing ISO 37001:2016. If your organisation already holds a 2016-edition certificate, the transition deadline is fixed: every certified site must complete the move to the 2025 edition by 28 February 2027. That is closer than it looks once you account for a gap analysis, any control changes and a fresh audit cycle.
No Indian law requires ISO 37001. There is no statutory trigger comparable to FSSAI for food businesses or CDSCO for medical devices. What is driving Indian demand is procurement, not legislation: large corporates and public-sector undertakings increasingly write anti-bribery expectations into vendor undertakings and supplier codes, and some ask suppliers to demonstrate alignment with ISO 37001 specifically. Steel Authority of India Limited (SAIL) has reportedly implemented an anti-bribery management system aligned to ISO 37001 across its plants, and its vendor undertakings are reported to reference the standard’s anti-bribery expectations for suppliers. We flag this as reported practice at one large PSU, not as a government-wide mandate — treat it as evidence of the direction procurement is moving, not a rule that applies to every tender.
The certificate itself has to come from a body accredited for this specific scheme — in India that means NABCB (the National Accreditation Board for Certification Bodies, under the Quality Council of India) or another IAF-MLA-signatory accreditation body. An unaccredited "ISO 37001 certificate" is paper a large-corporate or PSU compliance team can reject on sight, because it carries none of the peer-reviewed assurance an accredited scheme does. If a certifier cannot show you their NABCB or equivalent IAF accreditation scope covering ISO 37001, walk away regardless of price.
CapEasy is not a certification body and does not issue, award or assign ISO 37001 certificates. We build the anti-bribery management system your organisation actually needs — policies, risk assessments, due-diligence procedures, a reporting and investigation channel, training — and prepare you for audit by an accredited certifier. If you are already certified to the 2016 edition, we can also scope the gap to the 2025 edition so your transition audit is a formality rather than a scramble.
Who it’s for
- Businesses that supply, or want to supply, PSUs and large corporates whose vendor undertakings ask for anti-bribery controls or alignment with ISO 37001
- Organisations already certified to ISO 37001:2016 that need to plan the transition to the 2025 edition before the 28 February 2027 deadline
- Companies operating in sectors exposed to bribery risk in sales, procurement or government-facing dealings — construction, infrastructure, defence-adjacent supply, distribution
- Businesses that already hold ISO 9001 or ISO 27001 and want to add anti-bribery controls onto an existing management-system discipline
- Exporters and companies with overseas customers who ask about anti-bribery compliance as part of vendor due diligence
Eligibility & requirements
- Top management commitment to an anti-bribery policy, with a named person or function given authority over the anti-bribery management system
- A documented bribery risk assessment covering your sectors, markets, transactions and business relationships
- Due-diligence procedures for third parties — agents, distributors, joint-venture partners, contractors — proportionate to the bribery risk each poses
- Financial and non-financial controls: gifts and hospitality limits, controls on facilitation payments, procurement and expense controls designed to prevent bribery
- A confidential reporting channel (a whistleblowing or "speak up" mechanism) and an investigation procedure for concerns raised
- Internal audit and management review of the ABMS, consistent with how ISO management-system standards are normally operated
- Certification only through a body accredited for the ISO 37001 scheme — NABCB in India, or an equivalent IAF-MLA-signatory accreditation body
How CapEasy handles it
- Scope the ABMS — which entities, sites and business relationships the anti-bribery management system will cover, and what your specific bribery risks look like
- Gap analysis against ISO 37001:2025, including a specific transition gap check if you currently hold a 2016-edition certificate
- Build the risk assessment and the third-party due-diligence framework, sized to how you actually engage agents, distributors and contractors
- Draft the anti-bribery policy, financial and gift/hospitality controls, and the reporting and investigation procedure
- Train staff and relevant third parties on the policy and reporting channel, and run the internal audit and management review the standard expects
- Help you shortlist and engage a NABCB (or equivalent IAF-accredited) certification body and prepare for Stage 1 (documentation review) and Stage 2 (implementation audit)
- Support you through any nonconformities raised at audit and the corrective actions needed to close them
- For existing 2016-edition holders, plan the transition audit so it lands comfortably ahead of the 28 February 2027 deadline
Documents you’ll typically need
- Existing anti-bribery, gifts-and-hospitality, and code-of-conduct policies, if any
- A list of third parties you engage — agents, distributors, contractors, joint-venture partners — and how they are currently vetted
- Records of any prior compliance training, internal audits or whistleblowing reports
- Your current ISO 37001:2016 certificate and audit reports, if you already hold one and are transitioning
- Organisation chart showing who holds authority over compliance, procurement and finance functions
- Any vendor undertakings or supplier codes from PSU or large-corporate customers that reference anti-bribery expectations
CapEasy is a private consultancy and is not affiliated with any government authority. We help you assess eligibility and prepare and file your application; eligibility and approval depend on your specifics and the relevant department’s discretion.



