Bribery risk is not limited to an obvious cash payment. It can enter a business through an agent’s commission, a procurement decision, an expensive gift, a conflict of interest, a sponsorship, a consultant, or an intermediary whose role has never been properly questioned.
ISO 37001 certification in Oman provides a structured way for organisations to identify and manage these risks through an Anti-Bribery Management System (ABMS). The current standard is ISO 37001:2025, published in February 2025. It replaced ISO 37001:2016, which has now been withdrawn.
For organisations considering certification in 2026, that distinction matters. ISO Consultancy Oman follows the current ISO 37001 framework when examining anti-bribery management developments relevant to businesses in Oman, including the transition from the previous edition. A current implementation should be built around the 2025 requirements rather than a standard that has already been superseded.
What Is ISO 37001:2025?
ISO 37001:2025 is the international standard for establishing, implementing, maintaining and continually improving an Anti-Bribery Management System.
It is designed to help organisations prevent, detect and respond to bribery while supporting compliance with applicable anti-bribery laws and commitments. Its scope can address direct and indirect bribery involving the organisation, its personnel and relevant business associates.
The standard can be applied by private companies, public bodies and not-for-profit organisations of different sizes. It does not assume that every organisation faces the same level of bribery risk. The management system and its controls should reflect the organisation’s activities, relationships and actual exposure.
What Changed in ISO 37001:2025?
ISO 37001:2025 is the second edition of the standard. The revision goes beyond simply updating terminology. It places additional emphasis on how anti-bribery controls operate within the wider culture and governance of an organisation.
| Area | What the 2025 Edition Emphasises |
| Compliance culture | Greater emphasis on building and maintaining an effective compliance culture |
| Conflicts of interest | More explicit treatment of identifying and managing conflicts |
| Anti-bribery function | Clarification of the role and concept of the anti-bribery function |
| Climate change | New management-system considerations relating to climate change |
| Management-system structure | Alignment with the latest harmonised ISO structure |
| Integration | Clearer compatibility with other ISO management systems |
For a business starting its ISO 37001 Oman programme now, the 2025 edition should therefore be the reference point rather than the withdrawn 2016 standard.
Why Does ISO 37001 Matter in Oman?
ISO 37001 sits alongside Oman law; it does not replace it.
Oman’s Penal Law contains specific bribery offences involving public officials. For example, Article 208 provides for imprisonment of between three and ten years in specified circumstances where a public official requests or accepts consideration in return for an act contrary to official duties, together with other sanctions.
That legal environment makes the distinction between certification and legal compliance important. An ISO 37001 certificate shows conformity of an Anti-Bribery Management System with the certification criteria assessed. It does not give an organisation immunity from Omani law, nor does it establish that bribery could never occur.
For businesses involved in public contracts, procurement, construction, infrastructure, energy, logistics or other activities involving agents, government interaction and complex supply chains, the practical question is therefore not simply whether an anti-bribery policy exists. It is whether the organisation understands where influence and improper payments could enter its operations.
Where Does Bribery Risk Actually Enter an Oman Business?
Bribery risk often develops at the points where money, influence, discretion and third-party relationships meet. A useful ABMS therefore looks beyond employee conduct and examines how the organisation wins work, buys goods and services, obtains approvals and manages external relationships.
Agents and Business Intermediaries
Agents, consultants and intermediaries can create risk when their role is unclear or their compensation is difficult to justify. Large success fees, unusual commissions, vague descriptions of services or requests for payment to unrelated accounts deserve closer examination.
The organisation should understand why an intermediary is needed, what work will actually be performed, who ultimately owns or controls the business and whether the proposed compensation is commercially reasonable.
Government and Public-Sector Procurement
Government interaction can arise through tenders, permits, inspections, customs processes, approvals or public-sector contracts. The presence of a legitimate procurement process does not remove bribery risk if employees or intermediaries attempt to improperly influence decisions.
Controls therefore need to address both direct employee conduct and third parties representing the organisation during bids, negotiations, approvals and other interactions with public officials.
Gifts, Hospitality and Entertainment
Business hospitality can be legitimate, but risk increases when a benefit is excessive, poorly documented, unusually timed or connected to someone who can influence a commercial or official decision.
A functioning ABMS should distinguish acceptable business courtesies from prohibited or high-risk benefits through defined criteria, approval requirements and records rather than relying entirely on individual judgement.
Conflicts of Interest
A conflict may arise where an employee, decision-maker or business associate has a personal, financial or family interest that could interfere with objective judgement. The 2025 revision gives conflicts of interest more explicit attention within the anti-bribery framework.
The important control is not simply asking whether conflicts exist. Organisations need a way to disclose them, assess their significance, determine appropriate safeguards and maintain evidence of how identified conflicts were managed.
Donations and Sponsorships
Charitable donations and sponsorships may have legitimate purposes, but they can become problematic if used to disguise a benefit intended to influence a customer, official or decision-maker.
Risk-based review should consider the recipient, purpose, timing, beneficiary, approval process and relationship to pending business. Payments should also be traceable to the approved recipient and supported by appropriate documentation.
Recruitment and Employment Decisions
Improper influence does not always involve transferring money. Offering employment, internships or other opportunities to relatives or associates of influential individuals can create bribery concerns when the intention is to obtain an improper advantage.
Recruitment controls should therefore preserve objective selection criteria and identify situations where a candidate’s relationship with a customer, official or other influential person could create an anti-bribery concern.
How Should an ISO 37001 Bribery Risk Assessment Work?
A bribery risk assessment should identify where bribery could realistically occur, how serious the exposure is and which controls are needed in response. It should not be a generic register copied from another organisation.
An Oman-based contractor dealing extensively with government tenders may have a different risk profile from a professional-services firm with limited government interaction. Geography, industry, transaction values, business associates, payment methods and the degree of interaction with public officials can all change the assessment.
| Risk factor | What should be examined |
| Business activity | Where influence could affect commercial or regulatory decisions |
| Transactions | Tenders, contracts, licences, approvals and high-value purchases |
| Third parties | Agents, consultants, distributors, suppliers and intermediaries |
| Payment arrangements | Commissions, success fees, reimbursements and unusual payment requests |
| Government interaction | Public contracts, permits, inspections and official approvals |
| Geography | Locations and markets associated with different bribery exposures |
| Value and frequency | Size, repetition and commercial rationale of transactions |
| Existing controls | Whether current controls adequately reduce the identified exposure |
Risk assessment should also be dynamic. New markets, acquisitions, major contracts, new intermediaries or significant changes in business activity can create risks that were not present when the previous assessment was completed.
What Controls Does ISO 37001 Require?
The Anti-Bribery Management System turns identified risks into practical safeguards. The precise level of control should be proportionate to the organisation’s bribery exposure.
- Anti-bribery policy: Establishes the organisation’s commitments and expected conduct
- Risk assessment: Identifies and evaluates relevant bribery exposure
- Due diligence: Examines higher-risk transactions, projects, personnel and business associates
- Financial controls: Reduces opportunities for improper or disguised payments
- Non-financial controls: Introduces safeguards around procurement, contracting and other operational decisions
- Training and awareness: Ensures relevant personnel understand risks, responsibilities and prohibited conduct
- Reporting mechanisms: Provide appropriate ways to raise suspected or actual bribery concerns
- Investigation arrangements: Define how credible concerns are assessed and investigated
- Monitoring and review: Test whether controls remain suitable and effective
- Corrective action: Addresses failures and improves the management system when weaknesses are identified
What Does Top Management Need to Do?
ISO 37001 cannot operate effectively as a compliance department’s isolated project. Leadership has to support the anti-bribery policy, allocate appropriate resources and reinforce the expected culture through actual decisions and behaviour.
Management involvement also needs evidence. Reviews, decisions, resource allocation, escalation of serious issues and responses to control failures can demonstrate whether leadership oversight exists in practice. A policy signed by senior management is useful, but it is not a substitute for ongoing accountability.
Who Should Manage the Anti-Bribery Function?
Responsibility for the ABMS needs to sit with people who can challenge questionable conduct rather than simply administer compliance documents.
Independence and Authority
The anti-bribery function needs sufficient authority and independence to perform its responsibilities effectively. A person responsible for challenging high-risk conduct cannot be effective if commercial pressure prevents concerns from being escalated.
The organisational arrangement can differ according to size and complexity, but the function should have the standing and access necessary to oversee the ABMS and raise significant issues appropriately.
Competence and Reporting
Responsibility should sit with people who understand the organisation’s bribery risks and the controls used to manage them. Competence may involve knowledge of compliance, risk, internal controls, investigations and relevant legal obligations.
Reporting arrangements should also allow significant concerns to reach the appropriate level of leadership without being filtered by people whose interests may conflict with an independent assessment.
Why Is Third-Party Due Diligence One of the Most Important Controls?
A company may have strong internal policies and still face significant exposure through people acting on its behalf. Agents, distributors, consultants, suppliers and other business associates can therefore require risk-based scrutiny.
Due diligence should not become a mechanical exercise where every third party receives the same questionnaire. The depth of review should respond to the nature and level of the identified risk.
Higher-risk reviews may examine:
- Ownership and control: Who ultimately owns or controls the third party
- Commercial purpose: Why the relationship is required
- Qualifications and experience: Whether the party can genuinely perform the proposed work
- Government connections: Whether relevant relationships create heightened exposure
- Reputation: Credible adverse information or previous misconduct concerns
- Compensation: Whether commissions and fees are reasonable for the work performed
- Payment instructions: Whether the recipient, account and payment jurisdiction make commercial sense
- Subcontracting: Whether other parties will perform material parts of the engagement
- Contract terms: Whether anti-bribery expectations and appropriate rights are clearly addressed
Financial Controls vs Non-Financial Controls
Bribery prevention is not exclusively an accounting exercise. Financial controls can make improper payments harder to process, while non-financial controls address the commercial decisions through which improper influence may arise.
| Financial controls | Non-financial controls |
| Payment authorisation | Supplier selection |
| Segregation of duties | Tender review |
| Expense verification | Contract approval |
| Bank-account controls | Recruitment decisions |
| Commission checks | Business-associate appointment |
| Supporting documentation | Gifts and hospitality approval |
| Transaction review | Procurement controls |
The two need to work together. A payment can be perfectly documented in the accounting system while the underlying supplier appointment or commercial decision remains improper.
How Should Gifts and Hospitality Be Controlled?
ISO 37001 does not create one universal monetary threshold that makes every gift below it acceptable and every gift above it a bribe. Organisations need controls appropriate to their own legal obligations, risk profile and operating environment.
A gifts and hospitality framework can distinguish prohibited situations from benefits requiring approval and lower-risk routine items. Value matters, but so do timing, frequency, recipient, purpose and context. Hospitality offered during a sensitive tender decision, for example, may present a different risk from an ordinary low-value business courtesy.
Registers and approval records are particularly useful because they allow patterns to be identified. Several individually modest benefits involving the same recipient may create a risk that would not be visible if every transaction were reviewed in isolation.
What Should Happen When Someone Reports Suspected Bribery?
A reporting mechanism is useful only when concerns can move into a controlled, credible response. The exact investigation procedure should reflect the organisation and applicable legal requirements, but a structured response commonly needs to:
- Receive and protect the report while maintaining appropriate confidentiality
- Assess the allegation and determine its seriousness, credibility and immediate risks
- Preserve relevant evidence before documents, records or electronic information can be lost
- Assign an appropriate investigation with sufficient competence and independence
- Escalate serious matters to the appropriate governance or management level
- Determine necessary action based on findings and applicable requirements
- Identify control failures that allowed or failed to detect the issue
- Update the risk assessment and controls where the investigation reveals wider weaknesses
The purpose is not merely to close a case. An investigation can reveal weaknesses in due diligence, approvals, supervision, training or organisational culture that need wider correction.
What Evidence Will an ISO 37001 Auditor Look For?
Certification is evidence-based. Policies establish expectations, but auditors also need to determine whether the Anti-Bribery Management System has been implemented and is operating.
| Area | Examples of evidence |
| Bribery risk assessment | Current assessments, methodology and review records |
| Leadership | Policy approval, oversight and management-review evidence |
| Due diligence | Completed higher-risk third-party or transaction reviews |
| Competence | Training and awareness records |
| Financial controls | Approval, payment and transaction records |
| Non-financial controls | Procurement, tender and contracting evidence |
| Gifts and hospitality | Registers and approvals |
| Reporting | Procedures and evidence that reporting arrangements exist |
| Investigations | Appropriate case-handling records where applicable |
| Monitoring | Internal audit, reviews and performance evaluation |
| Improvement | Nonconformities, corrective actions and follow-up |
The important distinction is between having a document and demonstrating a functioning control. An organisation may have a well-written due diligence procedure, for example, but certification readiness depends on whether relevant due diligence is actually performed and evidenced.
How Does ISO 37001 Certification Work in Oman?
ISO develops the standard, but ISO itself does not certify individual organisations. Certification is performed by independent certification bodies.
The certification journey generally follows several stages rather than beginning with the external audit.
Prepare the Anti-Bribery Management System
The organisation establishes the scope of its ABMS, assesses bribery risks and implements the policies, responsibilities, due diligence arrangements and controls required for its circumstances.
The system also needs time to operate so that there is evidence demonstrating implementation rather than documentation created immediately before an audit.
Complete Internal Audit and Management Review
Before external certification, the organisation evaluates its own system. Internal audit can identify gaps between intended controls and actual implementation, while management review examines whether the ABMS remains suitable and effective.
Findings should lead to correction where necessary rather than being treated simply as documents needed for the certification file.
Complete the Stage 1 Audit
Stage 1 is principally concerned with understanding the organisation, its management system, scope and readiness for the more detailed certification assessment.
Problems identified at this stage may require attention before the organisation proceeds to the full Stage 2 assessment.
Complete the Stage 2 Audit
Stage 2 examines implementation and effectiveness in greater depth. Auditors can review records, interview relevant personnel and sample controls to determine whether the ABMS conforms to the applicable certification requirements.
The focus is therefore wider than whether the organisation possesses the required policies.
Address Nonconformities
Where the audit identifies nonconformities, the organisation needs to address them in accordance with the certification process. Corrective action should deal with the underlying cause rather than simply replacing a missing document.
Certification can proceed once applicable certification requirements and outstanding issues have been satisfactorily addressed.
Maintain the System After Certification
Certification is not the end of the management system. The organisation continues operating, monitoring, auditing and improving its ABMS, while the certification cycle includes ongoing surveillance and subsequent recertification activity.
Changes in operations, personnel, markets and business relationships should continue feeding back into bribery risk assessment and control design.
How Long Does ISO 37001 Certification Take?
There is no single certification timeline that applies to every Oman organisation. A relatively small company with mature compliance controls and limited complexity may reach readiness much faster than a multi-site organisation with numerous agents, government contracts and international operations.
Timing can be influenced by organisational size, locations, employee numbers, existing management systems, the maturity of current anti-bribery controls, third-party complexity, the quality of the initial risk assessment and the number or seriousness of gaps discovered before or during certification.
A realistic timetable should therefore separate implementation readiness from certification-body audit time. The external audit may occupy only part of the overall journey; designing controls, operating them and generating credible evidence can require considerably more preparation.
How Much Does ISO 37001 Certification Cost in Oman?
A credible ISO 37001 certification Oman cost estimate should be based on the organisation’s actual scope rather than a generic advertised package price.
Major cost drivers include:
- Organisation size: Larger operations normally require greater assessment effort
- Number of locations: Multi-site certification can increase audit complexity
- Employee numbers: Workforce size can affect audit-time calculations
- Scope: A narrow certification scope differs from organisation-wide coverage
- Bribery risk profile: Complex or higher-risk activities can require greater assessment depth
- Existing controls: Mature compliance systems may reduce the amount of implementation work required
- Certification audit time: Audit duration directly affects certification-body charges
- Travel and site requirements: Multiple or remote locations can influence assessment costs
- Remediation: Significant readiness gaps can create additional internal or external implementation costs
What Happens to Existing ISO 37001:2016 Certificates?
This is especially important for organisations planning their compliance work in 2026.
ISO 37001:2016 has been withdrawn and replaced by ISO 37001:2025. The IAF transition period ends on 28 February 2027.
IAF MD 30:2025 identifies several changes that need to be considered during transition, including compliance culture, conflicts of interest, clarification of the anti-bribery function, climate-change considerations and adoption of the latest harmonised structure.
An organisation already certified against the previous edition should therefore treat transition as a defined management-system project rather than simply changing the standard number on existing documentation. The revised requirements need to be assessed against the current ABMS, relevant gaps addressed and the transition completed within the applicable certification arrangements.
For organisations beginning implementation in 2026, building the system around ISO 37001:2025 avoids designing a new ABMS around a standard that has already been superseded.
What ISO 37001 Certification Does Not Prove
The certificate needs to be understood in proportion to what a management-system standard can actually demonstrate.
- It does not guarantee that bribery will never occur: Management systems reduce and manage risk; they cannot make misconduct impossible
- It does not provide immunity under Oman law: Criminal and other legal obligations continue to apply independently of certification
- It does not replace legal compliance: The organisation still needs to identify and comply with applicable anti-bribery requirements
- It does not make every transaction trustworthy: Individual conduct and third-party activity still require appropriate controls and monitoring
- It does not remove management responsibility: Leadership remains accountable for the effectiveness of the management system
- It does not make every business associate risk-free: Third-party relationships require ongoing risk-based management
- It does not mean controls can stop evolving: Changes in the business can create new bribery risks after certification
Can ISO 37001 Work With Other Compliance Standards?
Yes. ISO 37001 can operate independently, but its management-system structure also allows it to complement wider governance and compliance frameworks.
| Standard | Relationship to ISO 37001 |
| ISO 37301 | Extends management-system thinking across broader compliance obligations |
| ISO 37002 | Provides guidance for whistleblowing management |
| ISO 37003 | Provides guidance for organisational fraud-control management |
| ISO 9001 | Can align quality-management governance and management-system processes |
| ISO/IEC 27001 | Can complement governance through information-security management |
Integration can be particularly useful where organisations already operate ISO management systems and want common processes for areas such as document control, competence, internal audit, management review and corrective action.
Who Should Consider ISO 37001 in Oman?
ISO 37001 is not limited to one industry or organisation size. The more useful question is whether the organisation’s activities expose it to bribery risks that require structured management.
Relevance may be greater where an organisation regularly participates in high-value procurement, deals with government bodies, uses agents or intermediaries, operates complex supply chains, enters joint ventures, makes significant sponsorships or donations, works across multiple jurisdictions or relies on third parties to obtain business.
Smaller organisations should not assume that the standard is only for multinational groups. Their controls can be proportionate to their size and risk. What matters is whether the resulting system is appropriate to the bribery exposure and actually functions.
What Should an Oman Business Fix Before Seeking Certification?
A readiness review should reveal whether the organisation has a functioning system or mainly a collection of policies.
| Question | If the answer is no |
| Have bribery risks been formally assessed? | Develop a risk-based assessment |
| Are higher-risk third parties subject to due diligence? | Strengthen business-associate controls |
| Are conflicts of interest disclosed and managed? | Establish disclosure and treatment arrangements |
| Are gifts and hospitality controlled and recorded? | Define approval and recording rules |
| Are financial and non-financial controls connected to identified risks? | Redesign controls around the risk assessment |
| Can personnel raise concerns appropriately? | Establish an effective reporting mechanism |
| Can allegations be investigated independently? | Strengthen investigation governance |
| Has the ABMS been internally audited? | Complete an objective internal assessment |
| Does management formally review the system? | Establish and evidence management review |
| Are corrective actions followed through? | Introduce root-cause and closure monitoring |
ISO 37001 Certification Is About Control, Not a Clean-Business Label
ISO 37001 certification in Oman should be understood as evidence of a structured Anti-Bribery Management System, not as a declaration that an organisation is incapable of bribery. Its substance lies in risk assessment, leadership, due diligence, financial and operational controls, reporting, investigation and continual improvement.
The move to ISO 37001:2025 makes that distinction even more relevant in 2026. Compliance culture, conflicts of interest and the anti-bribery function receive clearer emphasis, while organisations certified against the previous edition face a defined transition deadline. ISO Consultancy Oman will continue tracking these developments as Oman organisations move from the previous ISO 37001 framework to the current edition and reassess what effective anti-bribery controls should look like in practice.
FAQs
Is ISO 37001 Mandatory in Oman?
ISO 37001 is an international voluntary management-system standard rather than a general statutory certification requirement for every business in Oman. Organisations must still comply with applicable Omani anti-bribery laws and any sector, contractual or procurement requirements relevant to them. A particular tender or customer may also establish additional compliance expectations.
Is ISO 37001:2016 Still Valid in 2026?
ISO 37001:2016 has been withdrawn by ISO and replaced by ISO 37001:2025. Organisations holding accredited certification against the previous edition are within the formal transition period, which ends on 28 February 2027. New implementation work in 2026 should therefore be based on the current edition.
What Is the Difference Between ISO 37001:2025 and ISO 37001:2016?
ISO 37001:2025 retains the core Anti-Bribery Management System approach but introduces or strengthens several areas. These include greater emphasis on compliance culture, explicit treatment of conflicts of interest, clarification of the anti-bribery function, climate-change considerations and alignment with the latest harmonised ISO management-system structure.
Does ISO 37001 Certification Protect a Company From Bribery Liability?
No. ISO 37001 certification does not provide immunity from Oman law or guarantee that bribery cannot occur. It demonstrates that an Anti-Bribery Management System has been assessed against the applicable certification criteria. Legal responsibility depends on applicable law and the facts of the particular matter.
How Long Is ISO 37001 Certification Valid?
Management-system certification commonly operates through a multi-year certification cycle involving surveillance and recertification, but organisations should confirm the precise arrangements with their selected accredited certification body. Maintaining certification also depends on the ABMS continuing to conform and operate effectively rather than simply passing the initial audit.
