Third-Party ISO Certification Body in UK, Europe, UAE, MENA & Globally. (MENA HO: UAE)
SCS KNOWLEDGE CENTRE

ISO 37001 UAE: Requirements, Cost & Certification Guide

Learn ISO 37001 requirements in UAE, including cost, certification process, UAE law, industries, tenders, third-party due diligence and audits.

  1. Home
  2. Knowledge Centre
  3. ISO 37001 UAE: Requirements, Cost & Certification Guide

ISO 37001 Certification in UAE: Requirements, Cost, Process and Industry Guide

ISO 37001 Certification in UAE: Requirements, Cost, Process and Industry Guide
Understand ISO 37001 requirements in UAE, including anti-bribery controls, UAE legal considerations, certification cost, process, industries, tenders and third-party due diligence.

ISO 37001 Certification in UAE: Requirements, Cost, Process and Industry Guide- Get certified with SCS

http://www.scscertification.com/contactus.php

ISO 37001 Certification in UAE

Running a business in the UAE often means dealing with many different parties at the same time. A company may purchase materials from overseas suppliers, appoint local agents, work with contractors, respond to government tenders or negotiate with distributors. Each relationship brings its own level of business risk.

This is where an Anti-Bribery Management System can become useful.

ISO 37001:2025 gives organizations a practical framework for managing bribery risks. The standard covers the establishment, implementation, maintenance and improvement of an Anti-Bribery Management System (ABMS), and applies across public, private and not-for-profit organizations.

For a UAE company, the system can be built around the way the business actually operates. A construction company may concentrate on subcontractors, project approvals and procurement. A trading company may pay closer attention to agents, distributors and commissions. A healthcare organization may have different concerns involving suppliers, consultants and regulatory interactions.

ISO 37001 certification can therefore be considered for many different reasons: a customer may request it, a tender may specify it, a group company may require it, or management may want a stronger approach to business integrity.

What ISO 37001:2025 Covers

ISO 37001 is not simply an anti-bribery policy placed in an employee handbook. It connects the policy with the organization's everyday activities.

Depending on the company's circumstances, an ABMS can address:

  • Anti-bribery policy and objectives
  • Management responsibilities
  • Bribery risk assessment
  • Due diligence
  • Financial controls
  • Non-financial controls
  • Business-associate management
  • Gifts and hospitality
  • Contractual safeguards
  • Employee awareness and training
  • Reporting channels
  • Investigation arrangements
  • Monitoring
  • Internal audit
  • Management review
  • Corrective action
  • Continual improvement

The controls should make sense for the business. A small professional-services firm will not necessarily need the same arrangements as a large EPC contractor operating across several countries.

ISO itself describes ISO 37001:2025 as a standard designed to help organizations prevent, detect and respond to bribery and address both direct and indirect bribery involving the organization, its personnel and business associates.

Why UAE Companies Consider ISO 37001 Certification

The UAE business environment includes mainland companies, free-zone businesses, multinational groups, government suppliers, manufacturers, professional firms and rapidly growing technology companies.

Many of these businesses have relationships with:

  • Government customers
  • Private-sector customers
  • Suppliers
  • Agents
  • Distributors
  • Contractors
  • Consultants
  • Joint-venture partners
  • Brokers
  • Overseas business associates

The risks are not identical.

For example, a construction company may need to look closely at subcontractor appointments, procurement decisions, project approvals and contract variations. A trading company may have greater exposure through sales agents, distributors, commissions and international intermediaries.

ISO 37001 gives management a way to look at those situations systematically instead of relying only on individual judgment.

UAE Legal Considerations for ISO 37001

ISO 37001 should be implemented alongside the laws and regulatory requirements that apply to the organization.

One important federal reference is Federal Law by Decree No. 31 of 2021 Promulgating the Crimes and Penalties Law. The UAE legislation includes provisions addressing bribery and related conduct.

However, ISO certification and legal compliance are not the same thing.

An ISO 37001 certificate demonstrates conformity with the applicable requirements of the standard within the certified scope. It does not mean that every legal obligation applicable to the company has automatically been satisfied.

A UAE organization should therefore identify the requirements relevant to its own operations. These may include:

  • UAE federal legislation
  • Local authority requirements
  • Government procurement conditions
  • Contractual obligations
  • Industry-specific requirements
  • Free-zone requirements
  • Customer conditions
  • Financial-control requirements

The legal review should be based on what the company actually does rather than using a generic list copied from another organization.

ISO 37001 for UAE Tenders and Prequalification

For some companies, the interest in ISO 37001 starts with a tender.

A procurement document may ask for evidence of an anti-bribery policy, compliance controls, third-party due diligence or an ISO 37001 certificate. In other cases, the requirement may come from a major customer or from a supplier-registration process.

Before beginning certification, it is worth checking the exact wording of the requirement.

Look at:

  • The requested ISO standard
  • Required certification scope
  • Number of sites
  • Certification-body requirements
  • Accreditation requirements, where specified
  • Certificate validity
  • Submission deadline
  • Customer acceptance conditions

Having an ISO 37001 certificate does not automatically satisfy every tender condition. The actual procurement document remains the reference point.

ISO 37001 and Third-Party Due Diligence

Third parties deserve particular attention because a company's exposure does not stop at its own employees.

Depending on the business, relevant parties may include:

  • Agents
  • Distributors
  • Consultants
  • Brokers
  • Suppliers
  • Contractors
  • Subcontractors
  • Joint-venture partners
  • Sales representatives
  • Intermediaries

The amount of due diligence can vary according to the relationship.

For a higher-risk business associate, the organization may need to understand ownership, beneficial interests, reputation, qualifications, business experience, reason for appointment, remuneration, conflicts of interest and relevant public-official relationships.

The point is not to create unnecessary paperwork for every supplier. The checks should be sensible and proportionate to the risk.

Gifts and Hospitality Under ISO 37001

Gifts, entertainment and hospitality can become sensitive when they are connected to a business decision.

A company can establish practical rules covering:

  • Gifts that are permitted
  • Gifts that are prohibited
  • Hospitality limits
  • Approval levels
  • Record keeping
  • Public-official interactions
  • Business entertainment
  • Sponsorship
  • Travel and accommodation
  • Charitable contributions

Employees should know what to do when they are offered something that could place them in an uncomfortable position.

A clear process is usually easier to follow than a vague instruction to “act ethically.”

ISO 37001 and Conflicts of Interest

A conflict of interest can affect a decision even when no payment is involved.

Consider a procurement employee whose close relative owns a supplier, or a manager involved in selecting a contractor in which they have a personal financial interest.

Other examples can include:

  • Personal relationships with suppliers
  • Undisclosed family connections
  • Interests in contractors
  • Connected individuals participating in supplier selection
  • Sales arrangements involving personal interests
  • Recruitment decisions involving related parties

Organizations can establish a process for declaring, reviewing and managing these situations.

ISO 37001 Certification for UAE Business Sectors

ISO 37001 can be relevant to almost any UAE business where bribery risk exists. The important point is to connect the management system with the organization's actual work.

ISO 37001 Certification for Manufacturing Companies

Manufacturers can encounter risk through purchasing, supplier selection, equipment procurement, licensing, distributors and sales arrangements.

This can apply to:

  • Steel manufacturing
  • Aluminium manufacturing
  • Chemical manufacturing
  • Pharmaceutical manufacturing
  • Plastic manufacturing
  • Packaging
  • Textile manufacturing
  • Electronics
  • Electrical products
  • Cement
  • Glass
  • Paper
  • Furniture
  • Food manufacturing

ISO 37001 Certification for Construction Companies

Construction businesses often manage large procurement budgets and numerous third-party relationships.

Areas worth examining include tendering, subcontractor selection, consultant appointments, project approvals, payment processes, contract variations and government interactions.

The standard can be relevant to building contractors, civil contractors, infrastructure companies, MEP contractors and specialist construction firms.

ISO 37001 Certification for Engineering and EPC Companies

Engineering and EPC companies can have extensive networks of suppliers, consultants, contractors and project partners.

Potential risk areas include tender preparation, purchasing, consultant selection, contractor appointment, commissions, project approvals, joint ventures and government-related projects.

ISO 37001 Certification for Oil and Gas Companies

Oil and gas businesses often operate through complicated contracting and supply arrangements.

ISO 37001 may be relevant to:

  • Oil and gas companies
  • Oilfield service providers
  • EPC contractors
  • Drilling contractors
  • Engineering companies
  • Equipment suppliers
  • Energy-service providers
  • Maintenance contractors

ISO 37001 Certification for Energy and Utilities Companies

Power companies, electricity-service providers, renewable-energy businesses, solar companies and utility contractors can use anti-bribery controls around procurement, consultants, suppliers, contractors and public-sector relationships.

ISO 37001 Certification for Logistics Companies

The UAE's logistics sector includes freight forwarders, road transport operators, warehouses, shipping companies, courier businesses, last-mile operators and supply-chain service providers.

Relationships with freight agents, brokers, transport contractors, warehouse providers and port-related businesses can be considered within the risk assessment.

ISO 37001 Certification for Trading Companies

Trading companies often depend on agents, distributors and international partners.

Common areas for review include:

  • Sales commissions
  • Distributor appointments
  • Supplier selection
  • Customs-related activities
  • Customer entertainment
  • Agent payments
  • International intermediaries

ISO 37001 Certification for Real Estate Companies

Developers, brokers, property-management companies and real-estate consultants can encounter risk around property transactions, commissions, contractors, consultants, procurement and regulatory interactions.

ISO 37001 Certification for Financial Services Companies

Financial-service organizations operate within a heavily regulated environment. Relevant anti-bribery considerations may include third-party relationships, procurement, consultants, business development, gifts and hospitality and conflicts of interest.

Sector-specific regulatory requirements should be considered separately.

ISO 37001 Certification for Healthcare Organizations

Healthcare organizations can include:

  • Hospitals
  • Clinics
  • Medical centres
  • Laboratories
  • Pharmaceutical companies
  • Medical-device companies
  • Healthcare suppliers
  • Healthcare service providers

Potential risk areas include purchasing, suppliers, consultants, distributors and relationships involving public-sector organizations.

ISO 37001 Certification for Pharmaceutical Companies

Pharmaceutical companies can have relationships with distributors, consultants, healthcare professionals, suppliers and regulatory bodies.

Their controls may cover distributor due diligence, supplier approval, gifts and hospitality, sales commissions, procurement and third-party relationships.

ISO 37001 Certification for IT and Technology Companies

The technology sector includes software companies, IT service providers, cloud businesses, data-centre operators, cybersecurity firms, system integrators, technology consultants, resellers and digital-service providers.

These organizations may deal with resellers, distributors, consultants and public-sector customers, making third-party controls particularly relevant.

ISO 37001 Certification for Telecommunications Companies

Telecommunications businesses can have large supplier and contractor networks. Procurement, sales channels, commissions, third-party due diligence, gifts and contractual controls can all form part of the company's anti-bribery framework.

ISO 37001 Certification for Data Centres and Cloud Companies

Data-centre and cloud operators may purchase expensive infrastructure and work with specialist contractors and technology suppliers.

The management system can consider equipment purchasing, contractors, consultants, technology partners, service providers and major customer contracts.

ISO 37001 Certification for Food Industry Companies

Food manufacturers, processors, caterers, distributors, traders, restaurants and food-service organizations can encounter risks around suppliers, purchasing, licensing, inspections and commercial relationships.

ISO 37001 Certification for Hospitality Companies

Hotels and resorts work with suppliers, contractors, travel agencies, event partners and corporate customers.

Procurement, commissions, event contracts, supplier selection, gifts and hospitality can all be considered when assessing bribery risk.

ISO 37001 Certification for Educational Institutions

Schools, universities, colleges, training institutes and education-service providers can use ISO 37001 to address risks involving procurement, contractors, consultants, suppliers and other business relationships.

ISO 37001 Certification for Professional Services Companies

The standard can also be relevant to:

  • Management consultants
  • Engineering consultants
  • Accounting firms
  • Business consultants
  • Recruitment companies
  • Corporate advisers
  • Professional support providers

Third-party appointments, commissions and procurement arrangements can be assessed according to their actual risk.

ISO 37001 Certification for Government and Public-Sector Organizations

Government authorities, municipalities, public utilities, regulatory bodies, government-owned enterprises and public healthcare or educational organizations may consider anti-bribery management as part of wider governance arrangements.

The applicable legal and public-sector requirements should be considered alongside ISO 37001.

ISO 37001 Certification for Government Contractors

Government contractors may encounter bribery risks during:

  • Tendering
  • Procurement
  • Project execution
  • Contract administration
  • Contractor selection
  • Supplier management
  • Government interactions

This can affect infrastructure, construction, engineering, IT, healthcare and facility-management contractors.

ISO 37001 Certification for Defence and Security Companies

Defence and security businesses may operate under strict contractual and procurement conditions. Their risk assessment can include government contracts, suppliers, consultants, agents, international partners and tendering.

ISO 37001 Certification for Marine and Offshore Companies

Marine contractors, shipping companies, offshore service providers, port-service companies and marine engineering firms may need to consider agents, contractors, suppliers, port interactions and international partners.

ISO 37001 Certification for Mining Companies

Mining and mineral-related businesses can face risks involving equipment purchases, contractors, government approvals, consultants, agents and infrastructure projects.

ISO 37001 Certification for Waste Management Companies

Waste-management businesses can work with municipalities, transport contractors, suppliers and treatment facilities. Procurement, contractor management and third-party checks can therefore form part of the anti-bribery system.

ISO 37001 Certification for Water Treatment Companies

Water-treatment companies may deal with engineering contractors, equipment suppliers, consultants and infrastructure projects. These relationships can be assessed for bribery exposure.

ISO 37001 Certification for Facility Management Companies

Facility-management companies commonly appoint maintenance contractors, suppliers and subcontractors.

Their controls may cover supplier selection, contractor appointments, procurement, commissions, customer relationships and gifts or hospitality.

ISO 37001 Certification for Automotive Companies

The automotive sector includes manufacturers, parts suppliers, dealers, workshops and fleet-service providers.

Supplier selection, dealers, distributors, procurement and sales channels can all be examined as part of the risk assessment.

ISO 37001 Certification for Aviation and Airport Services

Relevant organizations include aviation service providers, ground handlers, airport contractors, cargo operators, aviation suppliers and aircraft-support companies.

Their risk profile can include suppliers, agents, contractors and government-related relationships.

ISO 37001 Certification for Media, Advertising and Marketing Companies

Advertising and media businesses may work with agencies, sponsors, customers, consultants and public-sector organizations.

Commissions, client selection, sponsorships, procurement, hospitality and third-party relationships may require suitable controls.

ISO 37001 Certification for E-Commerce Companies

An e-commerce company may depend on payment providers, logistics partners, technology vendors, distributors and marketing agencies.

The anti-bribery system can focus on those relationships where the risk assessment identifies a genuine concern.

ISO 37001 Certification for BPO and Shared-Service Companies

BPO and shared-service operations often have relationships with customers, suppliers, consultants and sales partners.

Depending on their activities, the company may need controls around procurement, sales commissions, agents, consultants, customer relationships and hospitality.

ISO 37001 Certification Across UAE Emirates

ISO 37001 is not restricted to one emirate. Companies throughout the UAE can consider certification, provided the proposed scope accurately describes their activities and the locations covered by their Anti-Bribery Management System.

ISO 37001 Certification in Dubai

Dubai's business environment covers construction, engineering, real estate, logistics, hospitality, manufacturing, technology, trading, facility management, professional services and financial services.

Potential business locations include:

  • Jebel Ali
  • JAFZA
  • DMCC
  • DIFC
  • DAFZA
  • Dubai South
  • Dubai Industrial City
  • Dubai Investment Park
  • Dubai Healthcare City
  • Dubai Internet City
  • Dubai Media City
  • Dubai Silicon Oasis
  • Dubai Science Park
  • Dubai Maritime City
  • Dubai Design District
  • Dubai Knowledge Park

The certification scope should reflect the company's actual operations rather than simply listing every location where it has a presence.

ISO 37001 Certification in Abu Dhabi

Abu Dhabi has major activity in oil and gas, energy, EPC, engineering, construction, manufacturing, government contracting, logistics, healthcare and financial services.

Relevant business locations include:

  • Abu Dhabi
  • Al Ain
  • Mussafah
  • KIZAD
  • KEZAD
  • Khalifa Port
  • ADGM
  • Masdar City
  • Ruwais
  • ICAD

 

ISO 37001 Certification in Sharjah

Sharjah businesses operate across manufacturing, logistics, trading, construction, education and professional services.

Locations can include:

  • Sharjah
  • SAIF Zone
  • Hamriyah Free Zone
  • Sharjah Publishing City
  • Sharjah Research Technology and Innovation Park
  • Port Khalid
  • Kalba
  • Sharjah Industrial Areas

 

ISO 37001 Certification in Ajman

Businesses in Ajman can consider ISO 37001 based on their activities and risk profile.

Relevant locations include:

  • Ajman
  • Ajman Free Zone
  • Al Jurf
  • Al Jurf Industrial Area

 

ISO 37001 Certification in Ras Al Khaimah

Ras Al Khaimah has businesses across manufacturing, construction, tourism, logistics, trading and industrial activities.

Relevant locations include:

  • Ras Al Khaimah
  • RAKEZ
  • Al Hamra
  • Industrial Areas
  • Commercial districts

 

ISO 37001 Certification in Fujairah

Fujairah has strong activity in ports, shipping, logistics, marine services, trading, energy, construction and hospitality.

Relevant locations include:

  • Fujairah
  • Fujairah Free Zone
  • Fujairah Port
  • Industrial Areas

 

ISO 37001 Certification in Umm Al Quwain

Organizations in Umm Al Quwain can consider ISO 37001 according to their business activities and certification scope.

Relevant locations include:

  • Umm Al Quwain
  • Umm Al Quwain Free Trade Zone
  • Industrial Areas
  • Commercial districts

 

ISO 37001 Certification for UAE Free Zones

ISO 37001 is not limited to mainland businesses.

Companies operating in UAE free zones can also consider certification when the standard fits their activities and risk profile.

Examples include:

  • JAFZA
  • DMCC
  • DIFC
  • DAFZA
  • Dubai South
  • Dubai Silicon Oasis
  • Dubai Healthcare City
  • Dubai Internet City
  • Dubai Media City
  • ADGM
  • KIZAD
  • KEZAD
  • SAIF Zone
  • Hamriyah Free Zone
  • RAKEZ
  • Fujairah Free Zone
  • Ajman Free Zone

The free-zone name does not, by itself, determine the certification scope. The scope should describe the actual activities, functions and locations managed through the organization's ABMS.

ISO 37001 Certification for UAE Industrial Areas

Industrial businesses can face anti-bribery exposure through procurement, contractors, suppliers, agents, licensing and government-related activities.

Relevant industrial locations include:

  • Dubai Industrial City
  • Dubai Investment Park
  • Mussafah
  • ICAD
  • KIZAD
  • KEZAD
  • Al Jurf Industrial Area
  • Sharjah Industrial Areas
  • Ras Al Khaimah Industrial Areas
  • Fujairah Industrial Areas

 

ISO 37001 Requirements for UAE Organizations

Before applying for certification, it helps to understand what the organization is trying to achieve.

The preparation can begin with a few practical questions:

What business activities are included?

Identify the legal entity, departments, functions, sites and locations that will fall within the ABMS.

Where could bribery occur?

Review procurement, sales, commissions, government dealings, third parties, gifts, hospitality and other activities relevant to the company.

Which controls are already working?

Look at existing policies, approval procedures, financial controls, supplier checks and reporting arrangements.

Which business associates require closer scrutiny?

Agents, distributors, contractors, consultants and other third parties can be assessed according to their risk.

Do employees understand their responsibilities?

Training and awareness should relate to situations employees are likely to encounter in their actual work.

How will management know whether the system works?

Monitoring, internal audit and management review provide evidence about how the system is performing.

These preparation areas are reflected in the attached article's implementation framework.

How to Get ISO 37001 Certification in UAE

The certification route can be straightforward when the scope is clearly defined from the beginning.

Step 1: Discuss the Requirement

Provide basic information about:

  • Company activity
  • Number of employees
  • UAE locations
  • Number of sites
  • Proposed certification scope
  • Customer requirements
  • Tender requirements
  • Contractor requirements

Step 2: Establish the Certification Scope

The scope should identify the activities, functions and locations covered by the ABMS.

Step 3: Request a Certification Quotation

SCS can review the company's information and proposed scope to discuss the applicable certification arrangements and quotation.

Step 4: Implement the ABMS

The organization puts the relevant ISO 37001 requirements into practice, using controls that fit its business and identified risks.

Step 5: Complete the Certification Assessment

The certification body assesses the implemented management system against the applicable requirements within the agreed scope.

Step 6: Deal With Any Nonconformities

If findings are raised, the organization addresses them through the applicable certification process.

Step 7: Certification Decision

The certification decision is completed in accordance with the relevant certification arrangements.

Step 8: Continue Maintaining the System

Certification is not the end of the process. The organization continues operating, monitoring and improving its Anti-Bribery Management System throughout the certification cycle.

ISO 37001 Certification Cost in UAE

There is no sensible single price for every ISO 37001 certification project.

A company with one office and a small workforce may have a very different audit requirement from a large EPC, manufacturing or logistics organization operating across several locations.

The quotation can be influenced by:

  • Number of employees
  • Business activities
  • Certification scope
  • Number of sites
  • Number of locations
  • Organizational complexity
  • Third-party relationships
  • Existing management systems
  • Audit requirements

That is why a company-specific quotation is more useful than publishing an arbitrary “ISO 37001 certification price” for the UAE.

ISO 37001 Audit in UAE

During certification, the organization needs to demonstrate that its Anti-Bribery Management System is not merely documented but actually being used.

The assessment can take account of the organization's size, activities, number of employees, sites, locations, third-party relationships and operational complexity.

Evidence may include:

  • Bribery risk assessments
  • Due-diligence records
  • Training records
  • Contracts
  • Approval records
  • Gifts and hospitality registers
  • Conflict-of-interest declarations
  • Internal audit records
  • Investigation records
  • Management-review records

 

ISO 37001 and ISO 37301 in UAE

ISO 37001 and ISO 37301 are related, but they are not the same standard.

ISO 37001 concentrates specifically on anti-bribery management.

ISO 37301 has a wider focus: it provides a framework for managing an organization's broader compliance obligations.

A UAE company may use ISO 37301 as its broader compliance framework and ISO 37001 where it needs a dedicated anti-bribery system. The two approaches can work together.

ISO 37001 and Other ISO Management Systems

An organization does not necessarily have to manage every ISO system as a completely separate project.

Where appropriate, ISO 37001 can be coordinated with systems such as:

  • ISO 9001 – Quality Management
  • ISO 14001 – Environmental Management
  • ISO 27001 – Information Security
  • ISO 22301 – Business Continuity
  • ISO 37301 – Compliance Management

Common activities such as internal audits, management reviews, corrective action and continual improvement can be coordinated while retaining the individual requirements of each standard.

Why Choose SCS for ISO 37001 Certification in UAE?

Choosing a certification provider should begin with the actual certification requirement rather than simply comparing certificate prices.

A UAE organization should have a clear understanding of:

  • Certification scope
  • Quotation
  • Audit process
  • Applicable requirements
  • Number of sites
  • Customer requirements
  • Tender conditions
  • Continuing certification arrangements

When making an enquiry, it is useful to provide the company activity, locations, employee numbers, number of sites and proposed certification scope. If ISO 37001 has been requested by a customer or tender, sharing that requirement can make the discussion more precise.

Start Your ISO 37001 Certification in UAE

If your company is considering ISO 37001 because of a customer requirement, tender, supplier qualification, contractor approval or an internal governance objective, the first practical step is to discuss the scope.

Provide:

  • What your company does
  • Where it operates
  • Number of employees
  • Main business activities
  • Number of locations
  • Proposed certification scope
  • Customer or tender requirements

SCS can then discuss the appropriate certification route and quotation for your organization.

Contact SCS Certification:
http://www.scscertification.com/contactus.php

UAE

Saudi Arabia

UK

Canada

India

SCS Certification6th Floor Salaam Bldg, Office 9 Al Marakib St, Al Danah, Zone 1,Abu Dhabi, UAE.

SCS Certification (Partners)7713, King Abdulaziz Street, Al Dawasir, Dammam, 32416Kingdom of Saudi Arabia

SCS CERTIFICATION EUROPE LIMITED Office 6996,58 Peregrine Road, Hainault, Ilford, Essex, United Kingdom IG6 3SZ.

SCS Certification (E) Limited Oaklea Blvd, Brampton, ONL6Y 5A2, Canada.

Chennai: Building bearing No.19/35, V 270,Situated on First Floor, Mount Road, Little Mount, Chennai – 600015, India.

Bangalore: Bangalore, Karnataka, India.

Share this article

Need ISO Certification for Your Business?

Speak with our certification specialists to understand certification requirements, audit process, implementation timelines and accredited certification services.

Frequently Asked Questions

It means the company has had its Anti-Bribery Management System independently assessed against ISO 37001 requirements. The certification scope defines which activities, sites and locations are covered.
ISO 37001:2025 is the current edition of the international standard for Anti-Bribery Management Systems. It gives organizations a practical framework for managing bribery-related risks.
Many companies deal with suppliers, agents, contractors, customers and government-related transactions. ISO 37001 gives them a formal way to identify bribery risks and put suitable controls around those relationships.
Not generally. Certification may become necessary when a customer, tender, contract, group company or other business requirement specifically asks for it.
Its purpose is to help an organization prevent, detect and respond to bribery. It does this through policies, risk assessment, due diligence, controls, reporting and regular review.
It can give customers and business partners greater confidence in the company's approach to ethical business. It can also strengthen internal controls and support supplier or tender prequalification where certification is requested.
Yes. The standard brings management responsibility, risk assessment, approvals, reporting and monitoring into a structured system rather than leaving anti-bribery practices as informal company rules.
A well-run anti-bribery system can reduce the chance of inappropriate payments or business practices becoming a serious reputational issue. Certification also gives an organization independent evidence of its management-system arrangements.
It can be useful when dealing with multinational customers, overseas suppliers or international business partners that expect formal anti-bribery controls.
No. No management standard can make that promise. ISO 37001 gives the organization a systematic way to identify exposure, reduce opportunities for bribery and respond when concerns arise.
The requirements cover areas such as organizational context, leadership, anti-bribery policy, risk assessment, due diligence, financial and non-financial controls, training, reporting, investigation, internal audit, management review and improvement.
Yes. The organization needs a clear policy showing its commitment to preventing bribery and explaining the principles that employees and relevant business associates are expected to follow.
Yes. The organization needs to understand where bribery could occur in its own operations and business relationships. The controls should then reflect the level of risk identified.
Senior management needs to demonstrate that anti-bribery is taken seriously, provide suitable resources and ensure that responsibilities are clearly assigned.
The organization needs appropriate responsibility and authority for overseeing the Anti-Bribery Management System. How that responsibility is arranged will depend on the organization's size and structure.
Relevant personnel need appropriate awareness and competence. Training can cover the company's policy, reporting routes, conflicts of interest, gifts, hospitality and other issues relevant to their work.
Yes. Suppliers can fall within the organization's anti-bribery controls when the relationship presents a relevant risk.
Yes. Contractors and subcontractors may require due diligence, contractual controls or monitoring depending on the nature of the work and the risk involved.
Agents and intermediaries can be an important part of an organization's third-party risk assessment. The company can apply appropriate due diligence and contractual controls to higher-risk relationships.
Yes. Where distributors represent or sell on behalf of an organization, their appointment, compensation and activities may need appropriate anti-bribery controls.
Yes. Companies can establish rules for accepting, offering, recording and approving gifts, entertainment and hospitality where these activities could create an improper influence.
Conflicts of interest can form part of the organization's anti-bribery controls. Companies may require employees and relevant third parties to disclose situations that could affect impartial business decisions.
The organization should identify the laws and regulatory requirements relevant to its own activities. UAE Federal Law by Decree No. 31 of 2021, the Crimes and Penalties Law, includes provisions concerning bribery.
No. ISO 37001 is a management-system standard. It does not replace UAE law, regulatory requirements or professional legal advice.
No. Certification confirms conformity with the applicable ISO 37001 requirements within the certified scope. It should not be presented as blanket legal compliance.
Yes. Contractors supplying government departments or public-sector organizations may find formal anti-bribery controls useful, particularly where tender or prequalification documents request them.
It can. Where a tender specifically asks for ISO 37001 certification, holding a valid certificate can help the organization demonstrate that requirement.
A tender may be the reason a company starts the process, but the system should still be implemented properly. A certificate is much more useful when the controls are actually part of day-to-day business.
Start by defining the company activities and locations that need certification. Then review existing controls, address gaps, implement the management system and arrange the certification assessment.
The process normally begins with application and scope review, followed by assessment of the management system. Any applicable findings are addressed before the certification decision is completed.
The answer depends largely on how prepared the organization already is. A small company with established compliance controls may be ready sooner than a large business with several sites and complex third-party relationships.
There is no single implementation period for every company. Employee numbers, existing procedures, business complexity, locations and the amount of work required to close gaps all affect the timeline.
Depending on the company, these may include the anti-bribery policy, risk assessment, due-diligence records, procedures, training records, reporting arrangements, monitoring records, internal audit results and management-review information.
Yes. A gap assessment gives management a clearer picture of what is already in place and what still needs attention before the certification audit.
It can look at the company's policy, risk assessment, third-party controls, financial controls, training, reporting process, investigations, internal audits, management review and other applicable requirements.
The price varies from one organization to another. Employee numbers, activities, certification scope, number of sites and audit requirements are among the main factors.
A single-site company with a straightforward scope will usually require a different level of audit effort from a large organization operating across several UAE locations. Business complexity and the number of employees also matter.
Smaller organizations can have a simpler certification scope, which may reduce the audit effort. The actual cost still needs to be calculated from the company's activities, people, sites and scope.
Yes. A certification quotation can normally be discussed using information such as business activity, employee count, locations, number of sites and intended certification scope.
It is the certification of an Anti-Bribery Management System for an eligible organization operating in Dubai, with the exact scope determined by its activities, sites and management-system arrangements.
Construction, engineering, real estate, logistics, trading, manufacturing, hospitality, healthcare, technology, professional services and many other sectors can consider the standard where bribery risks are relevant.
Yes. A JAFZA company can seek certification for an appropriate scope covering its relevant activities and locations.
Yes. DMCC-based businesses can establish an Anti-Bribery Management System and seek certification for an appropriate scope.
It can be. DIFC companies should define their certification scope carefully and consider the legal and regulatory requirements that apply to their business.
Yes. Companies operating in Dubai South can consider ISO 37001 where the standard is relevant to their business and third-party risks.
It is certification of an organization's Anti-Bribery Management System for a defined scope in Abu Dhabi. The scope can cover particular activities, departments, sites or locations.
Yes. ADGM organizations can consider ISO 37001 where an anti-bribery management system fits their business requirements.
Yes. Industrial and commercial organizations operating in KIZAD or KEZAD can seek certification when the standard is appropriate to their activities and risk profile.
Organizations in Sharjah can obtain certification for an Anti-Bribery Management System covering their defined business activities and locations.
Yes. SAIF Zone businesses can implement the standard and seek certification based on their activities and proposed scope.
Yes. Manufacturing, trading, logistics and other companies operating in Hamriyah Free Zone can consider ISO 37001 where relevant.
It is an independent assessment of an organization's anti-bribery management arrangements against ISO 37001 requirements within an agreed scope.
Yes. Companies in Ajman Free Zone can consider certification according to their business activities, locations and anti-bribery risks.
Organizations in Ras Al Khaimah can use ISO 37001 to establish a structured approach to bribery risk and seek certification for the activities covered by their management system.
Yes. RAKEZ-based companies can seek certification when their activities and management-system scope are suitable for ISO 37001.
Fujairah companies can seek ISO 37001 certification for relevant activities such as logistics, shipping, marine services, trading, energy, construction and other sectors.
Yes. Organizations operating in Fujairah Free Zone can consider certification according to their business activities and defined scope.
Yes. Mainland, industrial and free-zone businesses in Umm Al Quwain can consider certification where anti-bribery controls are relevant to their operations.
It can. Multi-site arrangements may be possible where the certification structure and scope meet the applicable requirements. The certification body determines the appropriate audit arrangements.
Yes. ISO 37001 is suitable for mainland organizations across the Emirates when the standard fits their business and the management system is properly implemented.
Yes. The standard is not limited to mainland businesses. Free-zone companies can seek certification for an appropriate scope.
Manufacturing businesses may find it useful for controlling risks around purchasing, supplier selection, distributors, sales arrangements, contractors and other commercial relationships.
Construction companies often work with contractors, subcontractors, consultants, suppliers and tender processes. These relationships can make a structured anti-bribery system particularly relevant.
Yes. Oil and gas organizations can apply the standard to relevant procurement, EPC, contractor, supplier, consultant and intermediary relationships.
Yes. Engineering firms can use it for areas such as tendering, procurement, consultants, contractors, commissions and third-party relationships.
Yes. Freight forwarders, transport companies, warehouse operators, shipping businesses and logistics providers can consider the standard for relevant third-party and commercial risks.
Yes. Hospitals, clinics, laboratories, pharmaceutical businesses, medical suppliers and other healthcare organizations can use it where their activities create relevant bribery risks.
Yes. The standard can be applied to areas such as distributor relationships, consultants, suppliers, procurement, commercial arrangements and other third-party interactions.
It can be. Financial-sector organizations need to consider ISO 37001 alongside the laws, regulations and governance requirements that apply specifically to their activities.
Yes. IT companies can apply the standard to supplier relationships, resellers, system integrators, consultants, sales partners and public-sector business.
Yes. Developers, property managers, brokers and other real estate businesses can use it to address relevant risks involving commissions, contractors, suppliers and business relationships.
Yes. Hotels, resorts, restaurants and hospitality groups can consider the standard for procurement, contractors, suppliers, commissions, sponsorships and other relationships.
Yes. Educational institutions can apply anti-bribery controls to procurement, contractors, suppliers, consultants and other relevant business relationships.
Yes. Consulting, engineering, recruitment, accounting, advisory and similar professional-service businesses can establish controls proportionate to their own bribery risks.
Yes. Government-owned organizations can consider the standard where it fits their governance and risk-management arrangements, while also meeting applicable public-sector requirements.
Yes. ISO 37001 can be applied to organizations outside the commercial sector when they have bribery risks that need to be managed systematically.
Yes. A company can coordinate common processes such as internal audits, management reviews, corrective actions and document control while maintaining the separate requirements of both standards.
ISO 37001 is specifically focused on anti-bribery management. ISO 37301 has a wider focus on compliance management, so the two standards can work alongside each other.
Yes. Where appropriate, an organization can align shared management-system processes while continuing to meet the separate requirements of information security and anti-bribery management.
Yes. Appropriate financial controls help reduce opportunities for improper payments and can form an important part of the organization's anti-bribery arrangements.
Yes. Controls may also be built into procurement, recruitment, sales, contracting, approvals and other non-financial business activities.
The organization needs suitable ways for relevant concerns to be raised and handled. The exact reporting arrangements should fit its size, structure and risk profile.
The organization should have a defined approach for dealing with allegations or concerns, including appropriate investigation, action and follow-up.
Yes. Auditors may review evidence showing how the management system operates, such as risk assessments, due diligence, training, approvals, monitoring and internal audit records.
The organization needs to respond through the certification process and take suitable corrective action. The certification body evaluates the response and evidence provided.
Yes. Internal audits help the organization determine whether its Anti-Bribery Management System is working as intended and meeting applicable requirements.
Yes. Management review gives leadership an opportunity to examine performance, risks, audit results, changes and improvement needs.
ISO itself does not issue certificates. Certification is carried out by independent certification bodies that assess organizations against the applicable standard.
No. ISO develops and publishes standards but does not directly certify organizations. Certification is performed by independent conformity-assessment organizations.
Consider the certification body's competence, experience with the applicable standard, certification scope, audit arrangements and accreditation status where accreditation is required by a customer or contract.
The International Organization for Standardization identifies ISO 37001:2025 as the current Anti-Bribery Management System standard and explains that it provides requirements and guidance for establishing, implementing, maintaining and improving an anti-bribery management system.
Give SCS your business sector, number of employees, UAE locations, number of sites, proposed certification scope and any customer or tender requirement. This makes it easier to determine the appropriate certification arrangements.
Companies can contact SCS to discuss their ISO 37001 requirements, certification scope, locations, industry, implementation status and quotation requirements: http://www.scscertification.com/contactus.php