Quick answer
ISO 37001:2016 is the international standard for anti-bribery management systems. In Malaysia, Section 17A of the Malaysian Anti-Corruption Commission Act 2009 makes a commercial organisation liable if a person associated with it gives a bribe for its benefit, with a defence where the organisation had adequate procedures in place. Our service covers gap assessment, documentation, training and coordination of certification by an accredited certification body, followed by surveillance audits in a three-year cycle.
Last reviewed: · Reviewed by:ONEKEY BIZ compliance team
01
Overview
Since corporate liability for bribery came into force in Malaysia, companies can be held responsible when someone associated with them — an employee, agent or contractor — pays a bribe to obtain or keep business. Section 17A of the Malaysian Anti-Corruption Commission Act 2009 sets out that liability and a defence: the organisation had adequate procedures to prevent it.
ISO 37001:2016 is the international standard for building those procedures into a management system: anti-bribery policy, risk assessment, due diligence on business associates, controls over gifts and hospitality, financial and procurement controls, whistleblowing, training and internal audit. Certification by an accredited body gives independent evidence the system exists and works.
Government-linked tenders and large clients increasingly ask for ISO 37001. The work is less about paperwork than about fitting controls to how the company actually wins and delivers business, so we start with a gap assessment and build from there.
Who needs this
- Contractors bidding for government and GLC projects
- Companies with agents, intermediaries or high-risk markets
- Organisations asked by clients for ISO 37001 certification
02
Documents you need to prepare
Organisation
- Organisation chart and key processes
- Existing policies: code of conduct, gifts, procurement
Risk
- Business associates, agents and high-risk activities
- Past incidents or audit findings
People
- Top management and compliance function contacts
- Staff groups to be trained
- Certification is issued by an accredited certification body, not by us.
- After certification, annual surveillance audits and a recertification in year three maintain the certificate.
03
How to get it done with ONEKEY BIZ
- 1Gap assessment Month 1
Current controls compared with ISO 37001.
- 2System design Month 1–3
Policies, risk assessment and procedures developed.
- 3Implementation & training Month 3–5
Controls rolled out; staff trained.
- 4Internal audit Month 5
Internal audit and management review.
- 5Certification audit Month 6
Certification body audit coordinated.
You do
- Commit top management and a compliance function
- Implement controls in operations
We do
- Assess gaps against ISO 37001
- Develop policies and procedures
- Train staff and run internal audit
- Coordinate the certification audit
04
What you receive
Policy, risk assessment, procedures and records.
Evidence staff were trained.
Issued by the accredited certification body on passing the audit.
Official sources
Frequently asked questions
Does ISO 37001 guarantee a s.17A defence?
No standard guarantees a defence, but a certified system is strong evidence of adequate procedures.
How long does certification last?
Three years, with annual surveillance audits.
Who issues the certificate?
An accredited certification body after its audit.