Business inquiry
Home · Compliance · ISO 37001
ISO certification · ISO 37001

Bond prepares ISO 37001 certification in Iraq and Kurdistan.

The anti-bribery management system. It sets the policy, the due diligence on agents and suppliers, the rules on gifts and payments, and the way a report of bribery is investigated, and it is what international operators and lenders check before they clear a company.

ISO 37001 Anti-bribery management systems · Governance

At a glance
Published
March 2025. ISO 37001:2025 is the current edition. It replaced ISO 37001:2016, and certificates held against the 2016 edition move across during the transition period the accreditation bodies set.
Structure
Annex SL high level structure. 10 clauses, and clauses 4 to 10 carry the auditable requirements. Annex A is guidance on implementing the controls and is not audited as a requirement.
Certifiable
Yes. The company is certified for a defined scope. The certificate says the anti-bribery system meets the standard. It does not say that no bribery has happened or that none will happen.
Certificate validity
3 years from the date the body issues it.
Surveillance
One audit by the certification body every year, and a recertification audit in year three.
Audit days, 10 to 50 people
About 3 to 5 auditor days for stage 1 and stage 2 together. Auditor competence is set by ISO/IEC TS 17021-9, and the body adds days when the bribery risk rating is high. The certification body sets the final number.
Accredited bodies active in Iraq
Bureau Veritas has an Erbil office. SGS and TUV operate in Iraq. KQC in Erbil is accredited by IQAS, and IQAS is not an IAF MLA member.
Who certifies
An independent accredited certification body issues the certificate.
Language of the system
We write the policy, the procedures and the training material in Arabic, Kurdish and English, because the reporting channel has to work in the language the employee actually speaks.

What ISO 37001 is

ISO 37001 is the international standard for an anti-bribery management system. It asks a company to rate where bribery risk actually sits in its business, put controls on the payments, permits, tenders and third parties where that risk is highest, train the people exposed to it, and record what happens when someone reports a concern. The certification body issues the certificate to the company, and it says the system meets the standard.

What the standard requires

  1. Clauses 1 to 3 cover scope, normative references and terms. Clauses 4 to 10 are the requirements an auditor checks, and Annex A is guidance rather than a requirement.
  2. Clause 4.5, bribery risk assessment. Rate the bribery risk of every country, contract type, agent, customs step and public official contact the company deals with, and review the rating when the business changes.
  3. Clause 5, leadership. The governing body and the general manager own the system, sign the anti-bribery policy, and appoint an anti-bribery compliance function with direct access to the board.
  4. Clause 6, planning. Set anti-bribery objectives with numbers and dates, and plan the controls against the rated risks.
  5. Clause 7, support. Employment checks on staff in exposed roles, an anti-bribery clause in contracts, training for everyone exposed to the risk, and a channel for raising concerns.
  6. Clause 8.2, due diligence. Record a documented check on every agent, distributor, consultant, joint venture partner and high risk supplier before the contract is signed.
  7. Clauses 8.3 and 8.4, controls. Financial controls over payments, petty cash and approval limits, and non-financial controls over procurement, tendering, customs handling and permits.
  8. Clause 8.7, gifts and hospitality. A written rule with a value limit, a register of what was given and received, and an approval step for anything above the limit.
  9. Clauses 8.9 and 8.10, concerns and investigation. A reporting channel that protects the person who reports, and a recorded investigation for every report received.
  10. Clauses 9 and 10, evaluation and improvement. Internal audit, a review by the anti-bribery compliance function, a management review by top management and by the governing body, and a closed corrective action for every finding.

Who needs ISO 37001 in Iraq and Kurdistan

Oil and gas service companiesInternational operators run third party due diligence on every supplier, and the compliance file asks for the anti-bribery policy, the training records and the gifts register.
Construction and EPC contractorsPublic projects run on permits, inspections and payment approvals, and each of those steps puts staff in front of a public official.
Agents, distributors and local representativesA foreign company that appoints an Iraqi agent is liable for what that agent does under the US Foreign Corrupt Practices Act and the UK Bribery Act 2010.
Customs clearance and logistics companiesFacilitation payments at Ibrahim Khalil, Umm Qasr and the Erbil and Baghdad airports are the most common finding in a due diligence review.
Medical and pharmaceutical distributorsMinistry of Health tenders and hospital supply contracts put sales staff in direct contact with public buyers and prescribers.
NGOs and UN implementing partnersGrant agreements carry anti-corruption clauses, a right to audit and a right to terminate on a single substantiated report.
Banks, exchange and payment companiesCorrespondent banks abroad ask who approves a payment, what the limits are, and how an exception is recorded.
Security and manpower companiesLicences, site passes and work permits are issued by officials, so every one of those approvals is a risk point that has to be controlled.

The buyers that ask for ISO 37001

Buyer or listWhat they ask for
International operatorsDNO, Genel Energy, Gulf Keystone and HKN run compliance due diligence on suppliers. DNO is Norwegian and Genel Energy and Gulf Keystone are listed in London, so the UK Bribery Act 2010 reaches into their supply chain in Kurdistan.
Foreign parent companies and joint venture partnersUS companies are covered by the Foreign Corrupt Practices Act and check the Iraqi partner's controls before the joint venture or agency agreement is signed.
UN agencies through UNGMungm.org. The UN Supplier Code of Conduct bans bribery and facilitation payments. One free registration covers UNDP, UNICEF, WFP, UNHCR, IOM and FAO.
Donors and development lendersThe World Bank and the IFC apply anti-corruption guidelines and publish a debarment list. A debarred company is excluded from every project they finance.
EPC contractorsSubcontractor prequalification files on projects in Kurdistan and Basra carry a compliance section next to the quality and HSE sections.
Ministry of Natural Resources Approved Vendor Listmnronline.com/avl. It scores finances, quality system and HSE, and anti-bribery is not one of its criteria. The operators that draw suppliers from the list ask for it in their own compliance files.
Gulf and international buyersState buyers in Saudi Arabia, the UAE and Qatar ask bidders for a written anti-bribery policy, and on large packages for an ISO 37001 certificate from a body accredited under an IAF member.

Two tracks, you choose one

Certificate track

5 days

A company that has to clear an operator's compliance due diligence or answer an anti-bribery clause in a tender or an agency agreement before the deadline. We prepare the compliance system in five working days. The certification body then issues the certificate, and its calendar sits outside the five days.

Steps
  1. We read the compliance questionnaire or the tender clause on day one and confirm the scope and the body the buyer accepts.
  2. We run the bribery risk assessment on day one and day two with the owner, the finance manager and the people who deal with officials.
  3. We write the document set on day two and day three: policy, due diligence procedure, gifts rule, payment controls and the investigation procedure.
  4. We set up the reporting channel in Arabic, Kurdish and English on day three and write the rule that protects the person who reports.
  5. We train the exposed roles on day four in half day sessions and record who attended and what they were told.
  6. We run the first internal audit and the management review with the governing body on day five, then close the findings.
  7. We book the certification body at the end of the five days, and the body sets the stage 1 and stage 2 dates on its own calendar. We prepare the site, attend both stages, and answer the findings with your team.
Deliverables
  • The anti-bribery system, complete in five working days
  • Scope statement and bribery risk assessment with rated risks
  • Anti-bribery policy signed by the governing body and the compliance function appointment
  • Due diligence procedure and completed files on agents and high risk suppliers
  • Gifts and hospitality rule and register
  • Financial and procurement control procedures with approval limits
  • Reporting channel, investigation procedure and internal audit report
  • The certification body booking and a three year surveillance and renewal calendar

Implementation track

6 to 14 weeks

A company whose records will be read by a foreign parent, an operator's compliance team or a lender, and that wants the due diligence and approval controls running before the auditor arrives.

Steps
  1. We analyse what the company does and what its buyers and tenders require, then send a proposal.
  2. We run the bribery risk assessment business line by business line with the people who face the risk.
  3. We design the financial and procurement controls with the finance manager and set the approval limits in writing.
  4. We write the documentation in Arabic, Kurdish and English and build the due diligence file format the company will use for every third party.
  5. We run the due diligence on the existing agents, distributors and high risk suppliers and record the result for each one.
  6. We train every exposed department, launch the reporting channel, and let the controls run live for three to four weeks.
  7. We run the internal audit programme and the management review with the governing body, then prepare the site and attend stage 1 and stage 2.
Deliverables
  • Bribery risk assessment covering every business line and country of operation
  • Anti-bribery policy and full documented system in Arabic, Kurdish and English
  • Completed due diligence files on the existing agents, distributors and high risk suppliers
  • Anti-bribery clauses added to contracts and purchase orders
  • Gifts and hospitality register with live entries
  • Training records for every exposed role
  • Reporting channel with a log and a recorded investigation for each report
  • Internal audit programme, compliance function report and management review minutes

The certification body issues the certificate.

The implementation track, week by week

PhaseWeeksWhat happens
Scope and bribery risk assessmentWeeks 1 to 2We confirm which entities, sites and business lines the certificate covers, then rate the bribery risk of each contract type, third party and dealing with officials.
Governance and compliance functionWeeks 2 to 3The governing body signs the policy and appoints the anti-bribery compliance function with written authority and direct access to the board.
Controls and documentationWeeks 3 to 6Payment and petty cash limits, procurement and tendering controls, the gifts and hospitality rule, and the investigation procedure, written in Arabic, Kurdish and English.
Due diligence on third partiesWeeks 5 to 8We run and record the check on every existing agent, distributor, consultant and high risk supplier, and add the anti-bribery clause to their contracts.
Training and reporting channelWeeks 7 to 9A session for each exposed department, a separate session for finance and procurement, and the launch of the reporting channel in three languages.
Records running liveWeeks 8 to 11The controls run in daily operations for three to four weeks so there are real approvals, register entries and due diligence files for the auditor to sample.
Internal audit and management reviewWeeks 11 to 12We audit every clause, the compliance function reports on the system, and the management review is held with top management and the governing body.
Certification auditWeeks 12 to 14The accredited body runs stage 1 on the documents and the risk assessment, then stage 2 on site. We prepare the site, attend both, and answer the findings.

What we do, what you do

We do

  • Confirm which scope, which entities and which certification body the buyer accepts, before any work starts.
  • Run the bribery risk assessment with the owner, finance and the staff who deal with officials.
  • Write the whole documented system in Arabic, Kurdish and English.
  • Build the due diligence file format and run the checks on the existing agents and high risk suppliers.
  • Set up the reporting channel and the investigation procedure that protects the person who reports.
  • Train the exposed roles, finance, procurement and management on the controls and the records.
  • Run the first internal audit against every clause and chair the management review with the governing body.
  • Select certification bodies, collect their quotes, book the audit dates, prepare the site and attend stage 1 and stage 2.
  • Write the corrective actions for every finding and keep the surveillance and recertification dates in a calendar.

You do

  • Have the owner or the board sign the anti-bribery policy and appoint the compliance function in writing.
  • Name one compliance representative who can give about five hours a week.
  • Give us the agent and distributor list, the supplier list, the payment approval rules and the contracts already in force.
  • Release the finance manager for a full day on payment controls and approval limits.
  • Release each exposed department for a half day of training and a half day for the internal audit.
  • Have the owner or general manager and one board member attend the management review, which takes about two hours.
  • Pay the certification body directly, or through us at cost with the receipts.
  • Have the owner or general manager present at the opening and closing meetings of the certification audit.

What moves the price

The proposal names the scope, the deliverables and the dates before work starts.

ISO 37001 questions we are asked

We prepare the compliance system in five working days on the certificate track. The implementation track runs six to fourteen weeks. The certification body then issues the certificate. Bodies working in Erbil and Baghdad set their own audit dates.

The proposal names the scope, the deliverables and the dates before work starts.

A certificate from a body accredited by IQAS, for example KQC in Erbil, is valid in Iraq and accepted for KRG lists. IQAS is not a member of the IAF Multilateral Recognition Arrangement. Operators such as DNO, Genel Energy and Gulf Keystone, UN agencies and lenders normally require a body accredited under an IAF member, such as Bureau Veritas, SGS or TUV. We confirm which one the buyer accepts before any body is booked.

International operators in Kurdistan and Basra ask for it in their supplier compliance files, and DNO, Genel Energy, Gulf Keystone and HKN all run third party due diligence. UN agencies contracting through ungm.org apply the UN Supplier Code of Conduct. The World Bank and the IFC apply anti-corruption guidelines and exclude any company on their debarment list from the projects they finance. Suppliers bidding to those operators are usually asked for ISO 9001, ISO 14001 and ISO 45001 first, then for ISO 37001 in the compliance section.

Three years from the date of issue. The certification body runs a surveillance audit each year and a recertification audit in year three. We keep those dates in a calendar and prepare the company for each one. If a surveillance audit is missed the body can suspend the certificate, and a suspended certificate will not clear an operator's annual compliance review in Kurdistan or Basra.

No. The certificate says the anti-bribery management system meets the standard on the date the accredited body audited it. It does not say that no bribery has happened or that none will happen. What it gives a buyer is evidence of the controls: the bribery risk assessment, the due diligence files on agents and suppliers, the approval limits, the gifts register, and a recorded investigation for every report received.

Yes. We work anywhere in Iraq, in Basra, Baghdad, Kirkuk, Erbil, Sulaymaniyah and Duhok, and in the Gulf. The office is in Erbil and the team travels to the site.

Business inquiry

Select a target. Two questions follow, and the file reaches the desk on WhatsApp. A reply comes within four working hours.