What is ISO 37001?
ISO 37001 is the international standard for an Anti-Bribery Management System (ABMS). First published in 2016 and revised in 2025, it specifies the requirements for establishing, implementing, maintaining, and continually improving a management system that prevents, detects, and responds to bribery. The standard is published by ISO.
Its scope is deliberately wide: bribery by the organisation, bribery by its personnel or business associates acting on its behalf or for its benefit, and bribery of the organisation. The core mechanisms are a bribery risk assessment (where and how bribery could occur, by whom, through which relationships), risk-tiered due diligence on personnel, projects, and business associates, financial and non-financial controls, rules for gifts, hospitality, donations, and conflicts of interest, and channels for raising concerns and investigating them.
The 2025 revision folded climate change considerations into bribery risk assessment, strengthened the emphasis on compliance culture, clarified the scope and independence of the anti-bribery function, and added explicit treatment of conflicts of interest. It shares the Annex SL clause structure with ISO 27001, ISO 9001, and ISO 37301 — so an organisation that already runs a management system extends it rather than starting over.
Who needs ISO 37001 certification in Australia?
Two distinct audiences: individuals building an anti-bribery career capability, and organisations whose bribery exposure now carries a corporate-criminal price tag. The roles that hold the credential:
- Compliance managers and heads of integrity — whoever owns the anti-bribery programme internally. Lead Implementer is the credential for the person who builds the risk assessment, the due diligence framework, and the controls an auditor will test.
- Internal auditors and second-line assurance — assurance over anti-bribery controls is moving from an occasional review to a standing programme. Lead Auditor adds ABMS competence to an existing audit practice using the same ISO 19011 method.
- Legal counsel and financial-crime teams — the failure-to-prevent offence sits in the Criminal Code, but the defence is a management system. Counsel who understand ABMS structure can direct the programme rather than review it after the fact.
- Procurement and third-party risk leads — bribery risk concentrates in agents, distributors, intermediaries, and joint-venture partners. The due diligence discipline in ISO 37001 is the standard answer to that exposure.
On the organisational side, demand clusters where exposure does: companies with offshore operations or third-party agent networks, mining, energy, and construction groups navigating permits and customs across jurisdictions, government suppliers facing integrity conditions in tenders, and financial services firms whose financial-crime remit now extends beyond AML/CTF.
Why ISO 37001 matters in Australia right now
The Crimes Legislation Amendment (Combatting Foreign Bribery) Act 2024 created a new corporate offence in the Commonwealth Criminal Code, in force since September 2024: a company commits an offence if an associate — an employee, agent, contractor, subsidiary, or anyone performing services on its behalf — bribes a foreign public official for the company's profit or gain. Liability is absolute. The company does not need to have known, authorised, or been wilfully blind.
There is exactly one defence: adequate procedures to prevent bribery. The Attorney-General's Department has published guidance on what adequate procedures involve — proportionate risk assessment, top-level commitment, due diligence, communication and training, monitoring and review — and those principles map, element for element, onto the clauses of ISO 37001. The standard is the reference framework for the defence, which is why it moved from a procurement nice-to-have to a board agenda item within a year.
Penalties scale to make the point: the greatest of 100,000 penalty units, three times the benefit obtained, or 10 per cent of annual turnover. For any company of size, an undefended charge is an existential event.
Domestically, the National Anti-Corruption Commission (operating since mid-2023) holds jurisdiction over Commonwealth officials and the contractors and service providers who deal with them. Suppliers to government now face integrity scrutiny from both directions — the NACC on conduct, and tender panels on the programme that prevents it. The career consequence is straightforward: anti-bribery competence has become a hiring criterion in compliance, legal, procurement, and internal audit roles across Australia.
Mapping ISO 37001 to Australian anti-bribery law
ISO 37001 is not Australian law, but it is the management-system structure most often used to answer Australian anti-bribery obligations. The table summarises the mapping Aegentra is most often asked about.
| Law or framework | What it requires | How ISO 37001 helps |
|---|---|---|
| Criminal Code — failure to prevent foreign bribery | Absolute corporate liability when an associate bribes a foreign public official for the company's benefit. Sole defence: adequate procedures. | ISO 37001 is the international reference framework for adequate procedures — a certified ABMS is the strongest documentary starting position for the defence. |
| Attorney-General's adequate procedures guidance | Principles-based guidance: proportionate risk assessment, top-level commitment, due diligence, training, monitoring and review. | Each principle maps onto ISO 37001 clauses. The standard operationalises the guidance into an auditable system with third-party evidence. |
| National Anti-Corruption Commission Act 2022 | NACC investigates corruption issues involving Commonwealth officials, contractors, and service providers. | An operating ABMS — concerns channels, investigation procedure, records — is the evidence base a supplier produces when conduct questions arise. |
| Commonwealth Procurement Rules | Ethical supplier conduct is a condition of Commonwealth procurement; integrity questions appear in tender qualification. | A certified ABMS is the increasingly practical way to evidence integrity conditions during qualification and contract review. |
| State anti-corruption bodies (ICAC NSW, IBAC Vic, CCC Qld) | Investigate corrupt conduct in state public sectors — including the private parties who deal with them. | The same ABMS controls — gifts registers, conflicts of interest, due diligence — answer state-level scrutiny without a separate programme. |
| UK Bribery Act / US FCPA | Extraterritorial reach over Australian companies with UK or US listings, operations, or counterparties. | ISO 37001 was modelled on the same adequate-procedures concept as the UK Bribery Act s 7 defence. One system answers all three regimes. |
| AML/CTF Act (Tranche 2 reforms) | Financial-crime obligations extending to lawyers, accountants, and real estate professionals from 2026. | Anti-bribery sits alongside AML/CTF in the financial-crime remit. The ABMS supplies the management-system structure for the bribery component. |
The pattern is consistent: no Australian law names ISO 37001 as mandatory, but when a regulator, prosecutor, or tender panel asks "show me the procedures that prevent bribery," a certified ABMS is the most efficient documentary answer available.
The three PECB ISO 37001 course tiers
PECB structures ISO 37001 training the same way as ISO 27001: Foundation (overview), Lead Implementer (build and run the ABMS), Lead Auditor (independently assess one). All three are delivered Self-Study or eLearning through the official PECB platform, with instructor-led classes in Melbourne and Sydney available on request.
| Course | Best for | Effort | Exam | Price (+ GST) |
|---|---|---|---|---|
| ISO 37001 Foundation | Compliance, procurement, and finance staff building anti-bribery literacy; newcomers to management systems | 10–15 hours self-paced (2-day equivalent), 14 CPD credits | 1 hour, multiple-choice, 2 domains | $730 + GST Self-Study / $810 + GST eLearning |
| ISO 37001 Lead Implementer | The person who owns the anti-bribery programme — compliance managers, heads of integrity, GRC consultants | 35–45 hours self-paced (5-day equivalent), 31 CPD credits | 3 hours, open-book, 7 domains | $1,020 + GST Self-Study / $1,090 + GST eLearning |
| ISO 37001 Lead Auditor | Internal auditors, certification-body auditors, and assurance professionals forming an independent opinion | 35–45 hours self-paced (5-day equivalent), 31 CPD credits | 3 hours, open-book, 7 domains | $1,020 + GST Self-Study / $1,090 + GST eLearning |
Foundation is not a prerequisite for the Lead courses — anyone with a compliance or risk background goes straight to Lead Implementer, which teaches the standard from the ground up at implementer depth. Lead Auditor uses the ISO 19011 audit method, which transfers directly to ISO 37301, ISO 27001, and ISO 42001 audits — auditors accumulate schemes rather than relearn the craft.
Aegentra Academy is an official PECB authorised training partner in Australia (verifiable on the PECB partner directory). Every enrolment includes the official PECB exam voucher and one free resit within 12 months.
How much does ISO 37001 certification cost in Australia?
Individual PECB training (Aegentra Academy)
- ISO 37001 Foundation — from $730 + GST
- ISO 37001 Lead Implementer — from $1,020 + GST
- ISO 37001 Lead Auditor — from $1,020 + GST
Every price includes the official PECB exam voucher, one free resit within 12 months, 12 months of myPECB access, and the CPD attestation. There is no separate exam fee to discover later.
Organisational ABMS certification
Ranges are typical for an Australian SMB of 20–100 staff with a moderate third-party network. Organisations already running an Annex SL management system (ISO 9001, ISO 27001, ISO 37301) sit at the lower end because the system skeleton exists.
| Component | Typical AUD | Frequency |
|---|---|---|
| Readiness (risk assessment, due diligence framework, controls, documentation) | $20,000–$45,000 | Once |
| Stage 1 + Stage 2 certification audit | $10,000–$20,000 | Once (every 3 years) |
| Annual surveillance audit | Starting at $2,500 | Year 1 + Year 2 |
| Three-year re-certification | $10,000–$18,000 | Year 3 |
The exams, in detail
The Foundation exam is one hour, multiple-choice, covering two competency domains — ABMS principles and concepts, then the ISO 37001 requirements themselves. Pass mark 70 per cent. On passing you become a PECB Certificate Holder in ISO 37001 Foundation; no professional experience is required.
The Lead Implementer and Lead Auditor exams are three hours, open-book, mixing multiple-choice with scenario-based questions across seven competency domains. Pass mark 70 per cent, remotely proctored — you sit them from anywhere in Australia. The Lead Implementer domains run from fundamental anti-bribery concepts through planning, implementation, performance evaluation, continual improvement, and preparing for the certification audit. The Lead Auditor domains cover the same fundamentals, then audit method under ISO 19011 and ISO/IEC 17021-1 — preparing, conducting, and closing an audit, and managing an audit programme.
Every Aegentra enrolment includes the exam voucher in the course price and one free retake within 12 months of the first attempt — the same terms across Foundation, Lead Implementer, and Lead Auditor.
Credential tiers and experience requirements
PECB separates the exam from the credential. You sit one exam; the credential you hold then rises with attested professional experience. All tiers require at least secondary education and signing the PECB Code of Ethics.
- 01Implementer track
Provisional Implementer — no experience required. Implementer — one year of experience in anti-bribery management plus 200 hours of project activities. Lead Implementer — two years plus 300 hours. Senior Lead Implementer — seven years plus 1,000 hours.
- 02Auditor track
Provisional Auditor — no experience required. Auditor — two years of experience, one in anti-bribery management, plus 200 hours of audit activities. Lead Auditor — five years, two in anti-bribery management, plus 300 hours. Senior Lead Auditor — ten years, seven in anti-bribery management, plus 1,000 hours.
- 03Master credential
Holding both Lead Implementer and Lead Auditor makes you eligible to apply for ISO 37001 Master — with four additional Foundation exams, 15 years of professional experience including 10 in anti-bribery management, and 700 hours each of audit and project activities.
The practical read: a compliance professional two years into an anti-bribery role can hold the full Lead Implementer credential; a career changer earns Provisional immediately and upgrades on the same exam pass as experience accrues. Accreditation varies by credential. PECB publishes applicable personnel-certification and certificate-program scopes separately, so verify the published scope for this credential.
Thinking about it as a career rather than a one-off credential? Our guide to becoming a ISO 37001 Lead Auditor in Australia sets out the PECB credential tiers, the audit hours each one needs, the exam, and the roles it opens.
ISO 37001 vs ISO 37301 — which one first?
ISO 37301 is the general compliance management system standard: one framework for the full obligation set — privacy, safety, financial services, modern slavery, everything. ISO 37001 is the deep, bribery-specific system. They share the Annex SL clause structure, so they layer rather than compete: the typical Australian pattern is a CMS as the umbrella with the ABMS as its most rigorous module. Our ISO 37301 certification guide covers the compliance side in the same depth as this page.
Choose ISO 37001 first when bribery is your concentrated exposure — offshore operations, agent networks, government contracts — because the failure-to-prevent offence prices that risk specifically. Choose ISO 37301 first when the obligation register is broad and no single risk dominates. Practitioners increasingly hold both; the second implementation is substantially faster because the clause skeleton is identical.
The method also connects sideways: bribery risk assessment is a specialised application of the risk discipline in ISO 31000, and organisations that already run an ISO 27001 ISMS will recognise every clause of the ABMS skeleton — the management-system craft transfers directly.
FAQs
No. ISO 37001 is voluntary. But since September 2024 the Criminal Code has contained a corporate offence of failing to prevent foreign bribery, and the only defence is proving the company had adequate procedures in place to prevent it. ISO 37001 is the international reference framework for what adequate procedures look like, which is why Australian boards and general counsel are now asking for it by name.
Not automatically. The Attorney-General’s Department guidance is principles-based and no certificate is a safe harbour — a court decides adequacy on the facts. What ISO 37001 provides is the auditable management-system structure (risk assessment, due diligence, controls, monitoring) that the guidance principles map onto, plus independent third-party evidence that the programme operates. It is the strongest documentary starting position a company can hold.
The 2025 revision — the first since 2016 — folded climate change considerations into bribery risk assessment, strengthened the emphasis on compliance culture, clarified the scope and responsibilities of the anti-bribery function, and added explicit treatment of conflicts of interest. All three PECB ISO 37001 courses Aegentra delivers are aligned to the 2025 edition.
If you have any compliance, risk, audit, or legal background, go straight to Lead Implementer — it teaches the standard from the ground up at implementer depth and Foundation is not a prerequisite. Foundation (10–15 hours) suits people who are new to management systems entirely, or procurement and finance staff who need working literacy rather than build capability.
None to train or sit the exam. After passing, you can apply for the Provisional Implementer credential. Implementer requires one year of experience in anti-bribery management plus 200 hours of project activities; Lead Implementer requires two years plus 300 hours; Senior Lead Implementer requires seven years plus 1,000 hours. All tiers require signing the PECB Code of Ethics and PECB approval of the certification application.
Yes. Certification and examination fees are included in every course price, covering a first exam attempt plus one free retake within 12 months. Prices are exclusive of GST — Australian GST is added at checkout and a compliant tax invoice is issued automatically.
ISO 37301 is the general compliance management system standard covering the full obligation set; ISO 37001 is the bribery-specific management system. They share the Annex SL clause structure, so an organisation running a CMS can extend it to anti-bribery rather than build a parallel system — and practitioners credentialled in both are well positioned for integrated integrity roles. See our ISO 37301 certification guide for the compliance side.
No. The course certifies you as an individual practitioner. Certifying the organisation requires building the ABMS, running an internal audit, and passing a Stage 1 / Stage 2 audit by an accredited certification body. The Lead Implementer course teaches exactly that work, including preparation for the certification audit.