Bidding for a public tender without ISO 37001 certification today means starting with a real competitive handicap. Italian contracting authorities increasingly include scoring criteria linked to anti-bribery management systems, and companies without them lose valuable points when the technical bid is evaluated. ISO 37001 certification is no longer a mere reputational badge: it has become an operational tool that unlocks public contracts, NRRP-funded tenders and contracts with large private buyers replicating public sector models. In this article we look at what is concretely needed to obtain it, which requirements must be met, how the bonus scoring mechanism works in tenders, and which mistakes to avoid so the certification process is not compromised. The aim is to give you an operational map, not a lesson in regulatory theory.
What ISO 37001 is and why it was created
ISO 37001 is the international standard defining the requirements for an Anti-Bribery Management System (ABMS) that can be certified by an accredited third-party body. It was published in 2016 by the International Organization for Standardization as a structured response to bribery, a phenomenon the OECD estimates costs more than 5% of global GDP.
The standard was created with a practical goal: to give organisations a recognised model for preventing, detecting and addressing bribery risks. It is not limited to bribery in the strict sense, but also covers extortion, incitement, facilitation payments and conflicts of interest. It applies to companies of any size and sector, from multinationals to SMEs bidding for public tenders.
The High Level Structure and integration with other systems
ISO 37001 follows the High Level Structure (HLS) shared by all modern ISO standards. It therefore has the same logical architecture as ISO 9001, ISO 14001, ISO 27001 and ISO 45001: context of the organisation, leadership, planning, support, operation, performance evaluation and improvement. Companies that already run other management systems start with an advantage.
Integration is a strategic point. A company already certified to ISO 9001 can reuse procedures for internal audit, document control, nonconformity management and staff training. This drastically reduces implementation work and the indirect costs of running parallel documentation. The same applies to the “231 model” required by Italian rules on corporate administrative liability: many controls overlap and can be managed jointly.
The difference between ISO 37001 and the 231 model
Many companies confuse the two instruments, but they serve different purposes. The 231 model is an organisational measure required by Italian law to exempt the entity from administrative liability where offences are committed by directors or employees in the company’s interest. ISO 37001 is a voluntary international standard, focused specifically on bribery prevention, which is validated by an accredited third-party body.
The two do not exclude each other: they reinforce each other. The 231 model remains necessary for criminal liability protection, while ISO 37001 provides documented, certified evidence of the effectiveness of anti-bribery controls, increasingly requested by contracting authorities, the Italian anti-corruption authority and large buyers.
What ISO 37001 certification guarantees to those who obtain it
ISO 37001 certification confirms that the organisation has implemented, and keeps active, a system of anti-bribery controls compliant with a recognised international standard. It is not insurance against bribery, nor a legal free pass, but objective evidence of organisational due diligence.
Concretely, a certified organisation demonstrates that it has put in place:
a documented bribery risk assessment across processes, counterparties, geographies and transaction types
financial and non-financial controls proportionate to the risk identified
an anti-bribery compliance function with sufficient authority and independence
due diligence procedures on business partners, agents, suppliers and third parties
protected, accessible whistleblowing channels
periodic training programmes for all relevant staff
internal investigation procedures and nonconformity management
These elements are verified by a certification body accredited by Accredia in Italy, which runs periodic audits to confirm the system stays effective over time.
Evidential value during inspections and investigations
An often underestimated aspect is the evidential value of certification. In the event of investigations, challenges from the anti-corruption authority or criminal proceedings involving the company, holding an active ISO 37001 is objective evidence supporting the defence. It shows the organisation diligently adopted the measures reasonably expected to prevent bribery, even where controls were circumvented by individuals.
This is not an automatic exemption from liability, but it shifts the evidential balance. In many recent proceedings, courts have viewed certified systems positively as an indicator of organisational rigour, reducing penalties or excluding failure-to-supervise findings. The combination of ISO 37001 and an up-to-date 231 model is today the most solid defensive standard for companies exposed to bribery risk.
Why ISO 37001 has become decisive in public tenders
The turning point came with the new Italian Public Contracts Code (Legislative Decree 36/2023) and with the anti-corruption authority guidance that strengthened the weight of reputational criteria and certified management systems in award procedures. Today ISO 37001 is almost never a mandatory participation requirement, but it is almost always a scoring criterion that awards extra points in the technical bid.
The mechanism is simple and powerful. In a tender awarded on the most economically advantageous offer basis, the technical score can be worth up to 70 points out of 100. Within those points, contracting authorities reserve growing shares for certified management systems. A company holding ISO 9001, 14001, 45001 and 37001 can build a competitive advantage of 8-15 technical points over a competitor with no certifications, a gap that is often decisive.
The tenders where ISO 37001 weighs most
Some sectors apply particularly strong scoring criteria on anti-bribery:
healthcare and pharmaceutical tenders, where bribery risk has historically been high
major infrastructure works and NRRP-funded tenders, subject to reinforced controls
waste collection and environmental management services
supplies of goods and services to central public administration
tenders in the energy and utilities sector
contracts with large local authorities
In these areas ISO 37001 is no longer optional: it is a competitive tool that separates the companies winning contracts from those left off the short list.
The role of the anti-corruption authority and the legality rating
The Italian anti-corruption authority has progressively strengthened the role of certified anti-bribery systems in its checks and in its recommendations to contracting authorities. ISO 37001 certification also helps raise the legality rating issued by the Italian competition authority, another element generating bonus points in many tenders and easing access to public funding and bank credit.
The combination of ISO 37001 and a high legality rating has become the standard configuration for companies that treat the public sector as a strategic revenue channel.
How bonus scoring works in tenders
The criteria for awarding bonus points vary from tender to tender, but they follow recurring patterns worth knowing in order to plan your certification strategy. Contracting authorities build evaluation grids that award points based on the presence of specific certifications, their scope (company-wide or site-level) and how long they have been held.
Typical scoring pattern in Italian public tenders
A representative grid of the scoring criteria applied in tenders that value ISO 37001 can be summarised as follows:
ISO 9001 – Quality: 1 to 3 points
ISO 14001 – Environment: 2 to 4 points
ISO 45001 – Health and safety: 2 to 4 points
ISO 37001 – Anti-bribery: 3 to 6 points
ISO 27001 – Information security: 2 to 5 points
Legality rating (2 or 3 stars): 2 to 5 points
SA 8000 – Social accountability: 1 to 3 points
UNI/PdR 125 gender equality certification: 2 to 5 points
Adding these components together, a company with a complete set of certifications can take home up to 25-30 extra technical points compared with a competitor without certified management systems. In highly competitive tenders, where the difference between first and second place is measured in tenths of a point, that advantage is often decisive.
Bonus scoring: how to read tender documents
The environmental and anti-bribery scoring criteria are described in a specific section of the tender rules, usually called criteria for evaluating the technical bid. To capture bonus points correctly it is essential to:
read the full tender rules before bidding, not just the notice
check for clauses on certified management systems
make sure the certificate is valid at the bid deadline (having it in progress is not enough)
attach a copy of the Accredia certificate with the technical documentation
check that the certification scope matches the subject of the tender (an ISO 37001 limited to one production site may not cover the activity being tendered)
A recurring mistake is thinking it is enough to have started the certification process. Contracting authorities require an active certificate, and no self-declaration about the intention to certify earns bonus points.
The operational requirements for obtaining ISO 37001
Obtaining ISO 37001 certification requires a structured path touching governance, processes, controls and organisational culture. It is not a documentary exercise: it is an operational transformation that must be visible to auditors both on paper and on site.
Governance and leadership requirements
The standard requires explicit, verifiable commitment from company leadership. It is not about signing a generic policy, but about demonstrating that management understands bribery risks, has allocated adequate resources and has appointed an anti-bribery compliance function with genuine autonomy. That function must have direct access to leadership and be able to act without hierarchical filters that would compromise its independence.
The anti-bribery policy must be formalised, communicated to all staff and to relevant partners and suppliers, and updated periodically. It must explicitly prohibit every form of bribery, state the disciplinary consequences, provide reporting channels and commit to continuous improvement of the system.
Bribery risk assessment
This is the heart of the system. The company must systematically map every process exposed to bribery risk, identify the types of possible events (offers of money, excessive gifts, facilitation payments, conflicts of interest, favouritism in hiring) and assign each a likelihood and an impact. The assessment must be documented, updated at least annually and whenever significant changes occur (new markets, acquisitions, regulatory change).
On that basis you build the control plan, which must be proportionate to the level of risk identified. A company working only with Italian private buyers will need different controls from one bidding internationally in high-risk countries.
Due diligence on third parties
Much bribery risk flows through agents, intermediaries, consultants and business partners. ISO 37001 requires formal due diligence procedures on all third parties that can create exposure. The depth varies with risk: for a stationery supplier a basic company check is enough, while a commercial agent in a foreign market needs in-depth reputational checks, specific contractual clauses and continuous monitoring.
The concrete phases of the certification journey
The route to ISO 37001 certification unfolds in well-defined phases, each with specific objectives and outputs. Understanding their logic helps plan timelines, resources and the involvement of company functions.
Initial analysis and gap assessment
The first phase is a snapshot of the current state. An experienced auditor analyses processes, existing documentation, controls in place and organisational culture, comparing them with the requirements of the standard. The output is a gap assessment listing precisely the distances to close and the priorities for action.
This step is crucial because it avoids wasting time on requirements already met (especially if the company holds other ISO certifications) and focuses effort on the real gaps. A well-executed gap assessment noticeably reduces total implementation time.
Designing and implementing the system
Based on the gap assessment you design the anti-bribery management system. This phase includes:
drafting or updating the anti-bribery policy
defining the compliance function and its responsibilities
building the risk assessment matrix
drafting operating procedures (due diligence, gifts and hospitality, donations, sponsorships, conflict of interest management)
implementing a whistleblowing channel compliant with Italian Legislative Decree 24/2023
designing the training and communication plan
integration with the 231 model and other existing management systems
Implementation requires direct involvement of HR, legal, purchasing, sales, finance and IT. It is not the compliance officer’s job alone: it is a cross-functional project touching the whole organisation.
Training, internal audit and management review
Before facing the certification audit, the system must run for at least three months (often six) and produce concrete evidence. You need to have delivered training to all relevant staff, completed at least one full internal audit, documented any nonconformities and the related corrective actions, and held the management review. The certification body checks each of these specifically.
A two-stage certification audit
The certification audit takes place in two phases. Stage 1 is documentary: the auditor verifies that the system documentation is complete and consistent with the standard. Stage 2 is operational: the auditor visits the company, interviews staff, verifies on site that procedures are actually applied and gathers objective evidence. If no major nonconformities emerge, the certification body issues the certificate, valid for three years with annual surveillance audits.
Typical mistakes that stretch timelines and how to avoid them
Many companies underestimate the complexity of the journey and make recurring mistakes that lengthen certification and generate significant indirect costs. Knowing them in advance means you can avoid them.
A purely documentary approach
The most frequent mistake is treating ISO 37001 as a collection of procedures to write and file. Experienced auditors spot façade systems immediately: they interview operational staff, verify that due diligence procedures are actually applied, check that the whistleblowing channel is genuinely accessible and used, and examine gift and hospitality registers. A paper-only system does not pass stage 2 and comes back with major nonconformities.
Underestimating training
Anti-bribery training is not a 30-minute e-learning course at the start of the year. It must be differentiated by role (top management, sales, purchasing, administrative and operational staff), documented with attendance records and learning checks, and repeated periodically. If at audit time staff cannot explain what to do if offered a bribe or how to use the whistleblowing channel, the system is considered ineffective.
Confusing the 231 model with ISO 37001
Some companies think having an up-to-date 231 model automatically equals a system compliant with ISO 37001. It does not. The 231 model covers administrative liability for a broad catalogue of offences; ISO 37001 focuses specifically on bribery with stricter requirements on due diligence, financial controls and monitoring. The two structures integrate but do not overlap.
Choosing the wrong certification body
Not all certification bodies are Accredia-accredited for ISO 37001. A certificate issued by a non-accredited body has limited value and, crucially, does not generate bonus points in public tenders. Checking accreditation specifically for the ISO 37001 scheme is a mandatory step before signing any contract.
Realistic timelines for obtaining certification
Overall timelines for ISO 37001 depend on company size, process complexity, the presence of other certified management systems and the maturity of the anti-bribery culture. On traditional routes, run with external consultants and a documentary approach, the full journey from decision to certificate typically takes 8 to 14 months.
With a structured, digital approach such as the one Complaion uses with Italian and Spanish SMEs, timelines shorten noticeably thanks to tools that automate document management, standardise repeatable procedures and let dedicated auditors work in parallel with the company team. Time savings come mainly from three fronts:
a guided gap assessment producing immediately usable output
pre-configured templates for policies, procedures and registers
an evidence management platform that reduces the administrative load on internal staff
dedicated auditors with specific ISO 37001 experience who speed up technical decisions
The goal is to reach the certification audit with a robust system, not merely a formally compliant one, so you clear stage 2 without major nonconformities and obtain the certificate first time.
The indirect economic value beyond tenders
Reading ISO 37001 only through the lens of public tenders is short-sighted. Certification delivers indirect economic benefits which, over the medium term, often exceed the value of the public contracts won.
Access to credit and banking relationships
Banks increasingly assess the ESG and compliance profile of the companies they finance. A company with ISO 37001 and a high legality rating obtains better financing terms, easier access to credit lines and lower premiums on D&O (Directors and Officers) policies. The anti-bribery system reduces the risk perceived by financial stakeholders.
Relationships with large private buyers
Many large private companies replicate public sector criteria in their supplier qualification processes. Multinationals, banking groups, insurers and utilities require anti-bribery declarations, periodic audits or ISO 37001 itself as a condition for entering the supplier register. Companies without certification are excluded from significant commercial opportunities.
International expansion
ISO 37001 is a global standard recognised in all major markets. For an Italian company expanding into Europe, North America or South America, certification makes accreditation with foreign partners and clients easier, because they immediately recognise the level of controls implemented. It is a common language that reduces friction in international commercial onboarding.
Frequently asked questions about ISO 37001 certification
Is ISO 37001 required by law?
No, ISO 37001 is not required by law in Italy. It is a voluntary certification. However, in many public tenders it is effectively necessary to access scoring points and stay competitive, and some large private buyers require it to enter their supplier register. Formally voluntary, in substance it is increasingly indispensable for companies working with public administration.
How long is the certificate valid?
The ISO 37001 certificate is valid for three years from issue. During this period the certification body carries out annual surveillance audits to verify the system stays active and effective. At the end of the three years a renewal audit takes place, with a full review of the system. If major nonconformities emerge during surveillance audits, the certificate can be suspended or withdrawn.
Does ISO 37001 replace the 231 model?
No, the two instruments have different, complementary purposes. The 231 model is required by Italian law to exempt the entity from administrative liability in case of offences, and covers a broad catalogue of them. ISO 37001 is an international standard focused on bribery, with stricter requirements on specific controls. The optimal configuration includes both, integrated into a single compliance system.
Can a small company obtain ISO 37001?
Yes, the standard is designed to apply to organisations of any size. For SMEs the system can be proportionate to real risk levels and operational complexity, without the heavy structures typical of large corporations. The anti-bribery compliance function, for example, can be assigned to an existing role with adequate training and autonomy, without creating a dedicated department.
How much does ISO 37001 certification cost?
The cost depends on company size, process complexity, the presence of other certified management systems and the starting maturity. There are no standard price lists applicable to every case. Complaion prepares tailored quotes after a preliminary analysis of the organisation’s specific situation, so the proposed path is genuinely calibrated on business needs.
Is ISO 37001 needed for NRRP-funded projects?
Many tenders linked to the National Recovery and Resilience Plan include reinforced integrity checks on implementing bodies and specific scoring criteria for certified anti-bribery systems. ISO 37001 is not formally mandatory to access those funds, but it is strongly valued in award procedures and subsequent checks. For companies that want to bid consistently for NRRP tenders, holding the certification is an almost obligatory strategic choice.
What happens if an employee commits bribery even though we hold ISO 37001?
Certification does not prevent individuals from committing offences, but it shows the company adopted the measures reasonably expected to prevent them. In criminal or administrative proceedings, holding an active ISO 37001 system together with an up-to-date 231 model is objective evidence supporting the defence and can reduce or exclude the entity’s liability for failure to supervise.
How do you prove certification in a tender?
You prove it by attaching a copy of the certificate issued by the Accredia-accredited body, valid at the bid deadline. The certificate must clearly state the certification scope, which must be consistent with the subject of the tender. In some cases contracting authorities also require the most recent audit report or additional declarations on system maintenance.
Turn ISO 37001 into a real competitive advantage
ISO 37001 certification is no longer a topic reserved for large corporations: it has become an operational tool that decides which companies win public tenders and which are left off the short list. Shortening implementation, avoiding the typical mistakes and reaching the certification audit with a robust system are the three conditions for turning this investment into concrete tender points and contracts won.
Complaion supports Italian and Spanish SMEs throughout the journey, from the initial bribery risk assessment to obtaining the certificate, shortening timelines noticeably compared with traditional routes thanks to a digital approach and dedicated auditors with specific ISO 37001 experience. Every project is calibrated on the company’s real situation, with a tailored quote prepared after a preliminary analysis. Request a dedicated consultation from Complaion to see how to structure your ISO 37001 journey and start collecting scoring points in your next tenders.









