ISO 37001 Due Diligence: Anti-Bribery Risk Assessment
ISO 37001 due diligence is the cornerstone of an effective Anti-Bribery Management System (ABMS). Clause 7.2 of the standard requires organisations to conduct due diligence on all business partners and transactions that pose a bribery risk. This is not a one-off exercise. It is a continuous, risk-based process that must be proportionate to the nature of the relationship and the bribery risk involved. Done correctly, it protects your organisation from legal liability, regulatory penalties, and reputational damage.
Due Diligence Requirements Under ISO 37001
ISO 37001:2016 addresses due diligence primarily through Clause 7.2 (Due diligence) and Clause 8.2 (Due diligence of business partners). The standard requires organisations to:
- Establish and maintain a due diligence process that is proportionate to the nature and level of bribery risk
- Conduct due diligence on business partners before entering into or continuing a relationship
- Document the due diligence process and its outcomes
- Define when enhanced due diligence is required
- Periodically review existing business partner relationships
| ISO 37001 Reference | Requirement | Implementation |
|---|---|---|
| Clause 7.2 (a) | Establish a due diligence process proportionate to risk | Risk-based due diligence policy and procedures |
| Clause 7.2 (b) | Apply due diligence to business partners | Screening, background checks, risk scoring |
| Clause 7.2 (c) | Apply due diligence to transactions and projects | Transaction review, enhanced scrutiny for high-risk deals |
| Clause 8.2 | Control over business partner due diligence | Defined roles for due diligence approval |
| Clause 8.3 | Financial controls over high-risk transactions | Enhanced approval, dual signatories, audit trail |
| Clause 9.2 | Monitor and review due diligence effectiveness | Periodic audits of the due diligence process |
The standard deliberately does not prescribe a specific due diligence methodology. This allows organisations to design a process that matches their size, sector, and risk profile. However, auditors will expect to see a clearly documented process with consistent application and clearly defined escalation points.
Risk-Based Due Diligence: Proportionate and Effective
The principle of proportionality is central to ISO 37001 due diligence. The level of due diligence should reflect the level of bribery risk. A standardised one-size-fits-all approach wastes resources on low-risk relationships while providing insufficient scrutiny for high-risk ones.
| Risk Level | Due Diligence Type | When Applied | Key Activities |
|---|---|---|---|
| Low | Basic | Standard suppliers with limited government interaction, small transaction values | Identity verification, sanctions screening, negative media check |
| Medium | Standard | Contractors with moderate government interface, regular business partners | All basic activities plus financial review, reference checks, ownership structure review |
| High | Enhanced | Agents, intermediaries, JV partners, public procurement, high-value deals | All standard activities plus beneficial ownership analysis, on-site visits, enhanced financial review, regulatory checks |
Risk factors that should trigger enhanced due diligence include: operations in countries with high corruption risk as measured by Transparency International’s Corruption Perceptions Index, involvement of politically exposed persons (PEPs), complex ownership structures, use of intermediaries or consultants to secure business, large or unusual commission payments, and transactions involving government procurement or licences.
For GCC organisations, additional risk factors include interactions with government entities across the region (where procurement processes may involve multiple intermediaries), operations in free zones with varying regulatory oversight, and cross-border transactions between GCC states with different anti-bribery enforcement levels.
Third-Party Due Diligence
Third-party due diligence is the most critical component of ISO 37001 compliance. Under the standard and under most anti-bribery laws globally (including the UAE Federal Law 3 of 1987 as amended, Saudi Arabia’s Anti-Bribery Law, and the UK Bribery Act), organisations can be held liable for bribery committed by third parties acting on their behalf.
The third-party due diligence process should follow a structured lifecycle:
- Pre-engagement screening: Before entering any agreement, screen the third party against sanction lists, PEP databases, adverse media, and previous compliance incidents
- Risk assessment: Score the third party based on geography, sector, ownership structure, nature of services, and value of engagement
- Due diligence investigation: Scale the investigation to the risk level, from basic verification (low risk) to forensic financial review (high risk)
- Contractual controls: Include anti-bribery clauses, audit rights, termination rights, and compliance certification requirements in all contracts
- Ongoing monitoring: Periodically review the third party’s risk profile and compliance status throughout the relationship
- Re-engagement due diligence: Conduct fresh due diligence at contract renewal or when significant changes occur in the third party’s ownership or operations
Common third-party risks in the GCC include agents and intermediaries used to secure government contracts, distributors in regulated sectors (pharmaceuticals, medical devices, defence), joint venture partners in markets where foreign ownership is restricted, and consultants who interact with government officials on behalf of your organisation.
M&A Due Diligence on Anti-Bribery Risk
ISO 37001 applies to mergers and acquisitions. When acquiring or merging with another entity, the acquiring organisation must conduct anti-bribery due diligence on the target. The standard does not require a full ISO 37001 audit of every target, but it expects proportionate due diligence based on the target’s bribery risk profile.
M&A due diligence should assess the target’s exposure to bribery risk through review of its anti-bribery policies, past incidents, third-party relationships, government contract portfolio, financial controls, and culture. Any red flags must be addressed before the transaction closes, either through remediation, indemnities, or price adjustment.
In the GCC context, M&A due diligence is particularly important when acquiring entities that work extensively with government clients, operate in high-corruption-risk sectors, or have complex ownership structures that may obscure beneficial ownership.
Enhanced Due Diligence
Enhanced due diligence (EDD) is required when the initial risk assessment identifies elevated bribery risk. EDD goes deeper than standard due diligence and typically includes:
- Beneficial ownership identification: Identify the natural persons who ultimately own or control the business partner, using corporate registry searches, ownership documentation, and public records
- Source of funds and wealth: Understand where the business partner’s funds originate, particularly for high-value transactions or investments
- On-site visits: Physical inspection of premises, interviews with management, review of operational controls
- Independent financial review: Audit or review of the business partner’s financial statements, with focus on unusual transactions, commission payments, and expense patterns
- Regulatory and law enforcement checks: Direct inquiries with regulators and law enforcement agencies where permissible
- Social media and network analysis: Broader investigation into the business partner’s connections, including links to PEPs or known corruption cases
EDD findings must be documented in a formal report with a clear risk conclusion and recommendation. If EDD confirms high risk and the risk cannot be mitigated through contractual controls or structural changes, the organisation should decline or terminate the relationship.
Ongoing Monitoring
Due diligence is not a one-time event. ISO 37001 requires ongoing monitoring of business partners throughout the relationship. The monitoring frequency and intensity should match the risk level.
| Risk Level | Monitoring Frequency | Monitoring Activities | Trigger for Re-DD |
|---|---|---|---|
| Low | Annual | Sanctions re-screening, negative media check | Change of ownership, major contract value increase, adverse media alert |
| Medium | Six-monthly | All low activities plus financial review, transaction monitoring | Any of above plus regulatory change, new jurisdiction entry |
| High | Quarterly or continuous | All medium activities plus enhanced transaction monitoring, periodic on-site visits | Any material change in risk profile |
Ongoing monitoring should also include transaction surveillance. Unusual payment patterns, such as payments to intermediaries that are disproportionate to the service provided, requests for payment to third-country accounts, or unusual urgency in payment processing, should trigger immediate review and potential suspension of the relationship.
Documentation: The Audit Trail
Documentation is where most due diligence failures occur. An ISO 37001 auditor will ask to see evidence that due diligence was conducted before the relationship began, that the risk assessment was appropriate, and that ongoing monitoring is taking place. Without documentation, the process did not happen.
The minimum documentation requirements include:
- Due diligence policy and procedure document
- Risk assessment methodology and scoring criteria
- Completed due diligence questionnaires for each business partner
- Screening results (sanctions, PEP, adverse media)
- Risk rating and rationale for each business partner
- Enhanced due diligence reports (where applicable)
- Contractual anti-bribery clauses
- Monitoring records and review decisions
- Outcome of any relationship termination due to adverse findings
For GCC organisations, it is important that documentation is available in English (the language of most ISO certifications) and in Arabic where local regulators require it. Documents should be retained for at least the duration of the relationship plus any applicable legal limitation periods, which in GCC jurisdictions typically range from five to fifteen years depending on the nature of the claim.
Common Audit Findings on Due Diligence
External auditors regularly cite the following due diligence weaknesses during ISO 37001 certification and surveillance audits across the region:
- No risk-based approach: All business partners receive the same level of due diligence regardless of risk
- Incomplete coverage: Due diligence is only conducted for new partners, not for existing relationships
- No enhanced due diligence trigger: High-risk relationships receive only standard due diligence
- Documentation gaps: Decisions (including decisions not to proceed) are not documented
- No ongoing monitoring: Business partners are approved once and never reviewed again
- Siloed process: Due diligence is managed by procurement or legal without compliance oversight
Frequently Asked Questions
Is due diligence required for all business partners under ISO 37001?
Yes, but the extent of due diligence must be proportionate to risk. Low-risk business partners (e.g. a long-established local supplier with no government interface) may require only basic identity verification and sanctions screening. High-risk partners (e.g. an intermediary in a high-corruption jurisdiction) require enhanced due diligence.
How often should we refresh due diligence on existing business partners?
The frequency depends on the risk level. Low-risk partners can be reviewed annually. High-risk partners should be reviewed at least quarterly. Any significant change in the partner’s ownership, jurisdiction, or business activities should trigger an immediate re-assessment regardless of the regular cycle.
Does ISO 37001 require us to use external due diligence providers?
No. In-house due diligence is perfectly acceptable. The standard requires that the due diligence is effective and documented, not that it is outsourced. Many organisations use a combination of in-house screening (using commercial databases and public records) with external providers for complex enhanced due diligence investigations.
What should we do if due diligence identifies red flags?
Red flags must be escalated through your defined decision-making process. Depending on the severity, options include: enhanced due diligence to investigate further, contractual controls (anti-bribery clauses, audit rights, compliance certifications), approval at a higher management level, or declining the relationship entirely. All decisions must be documented with justification.
Does ISO 37001 due diligence apply to customers as well as suppliers?
Yes, the standard applies to all business partners. In practice, customer due diligence is often lighter than supplier due diligence unless the customer relationship involves high-risk factors such as large cash payments, complex payment structures, or links to high-corruption jurisdictions. Your risk assessment methodology should determine the scope for each category.
How do we integrate due diligence with our existing procurement processes?
Due diligence should be embedded into the procurement and onboarding workflow, not added as a separate parallel process. This means including compliance screening at the vendor registration stage, adding anti-bribery assessment to the supplier evaluation criteria, and making approval contingent on due diligence clearance. Integration reduces friction and improves compliance rates.
Strengthen Your Due Diligence with Bitrixme
Implementing ISO 37001 due diligence that satisfies auditors and genuinely reduces bribery risk requires a carefully designed process, proportionate to your organisation’s risk profile and integrated with your procurement and compliance workflows. Bitrixme works with organisations across Bahrain, Saudi Arabia, and the UAE to design and implement anti-bribery due diligence frameworks. Contact us to review your current approach or build a compliant ABMS from scratch.