Governance / Anti-Bribery Certification

ISO 37001:2025 Transition for Certified Organisations

Every accredited ISO 37001:2016 certificate stops being valid after 28 February 2027. The changes in the 2025 edition are modest. The deadline is not, and neither is the queue for audit dates as it gets closer. We close the gap, update the evidence and get you ready for a transition audit you can book with confidence.

Hard deadline: 28 February 2027 under IAF MD 30:2025 Gap assessment against every change in the 2025 edition Transition audit readiness, remote or on site
Overview

ISO 37001:2025 Transition

What it is

A focused transition engagement for organisations that already hold, or are part way to, an ISO 37001:2016 anti-bribery management system certificate. We assess your system against the 2025 edition, update the policies, procedures and records that need it, and prepare you for the transition audit with your certification body.

Why organisations need it

The International Accreditation Forum set the rules in IAF MD 30:2025. Since 31 August 2026, initial certification and recertification can only be to the 2025 edition, and every certified organisation has to complete its transition by 28 February 2027, either at a scheduled audit such as surveillance or at a special transition audit. After that date an accredited 2016 certificate is simply not valid. If your certificate supports tender eligibility, a customer requirement or your Section 17A adequate procedures evidence, a lapse costs far more than the transition.

Key features

What the engagement covers

Scoped to the distance between your system and the 2025 edition. A system that has been well maintained usually needs targeted updates, not a rebuild, and we will tell you which you are.

Transition gap assessment

A clause-by-clause review of your management system against ISO 37001:2025, focused on what actually changed. Each gap is recorded with the evidence the certification body will expect to see, an owner and the effort to close it.

Conflicts of interest

The 2025 edition addresses conflicts of interest directly. We build or tighten the declaration process, the register, the review cycle and the link into due diligence, so the control operates rather than sits in a policy.

Anti-bribery culture

The new edition puts more weight on the culture that top management promotes, not only on the controls. We help you define what leadership actually does, and how you evidence it, in a way an auditor can test.

Anti-bribery function

The former anti-bribery compliance function is now the anti-bribery function, with its role clarified. We review its mandate, authority, independence, reporting line and resourcing against the revised wording.

Climate change and context

Like other management system standards, the 2025 edition asks you to consider whether climate change is a relevant issue for your system. We make sure that consideration is made and recorded, proportionately.

Harmonized structure updates

The 2025 edition adopts the latest harmonized structure used across ISO management system standards. We align your manual, objectives, planning and management review records so the system reads and works as one.

Business value

What the business gets out of it

Your certificate does not lapse

The first outcome is the simplest one. You transition before 28 February 2027 and your certificate carries on, rather than ending and forcing a fresh initial certification.

No surprises at the transition audit

The certification body audits every change from the 2016 edition. We test your system against those same changes first, so findings arrive while there is still time to fix them.

Proportionate, not a rebuild

Most of a well-run 2016 system carries forward. We change what the standard requires and leave working controls alone, which keeps the effort, and the disruption to your team, contained.

Better Section 17A evidence

Conflicts of interest, culture and a clearer anti-bribery function are also what an adequate procedures defence under the MACC Act has to show. The transition strengthens both at once.

Tenders and customer requirements stay covered

Where your certificate is a condition of a tender, a pre-qualification or a customer contract, continuity matters more than the standard itself. The transition keeps you eligible.

Your team can run it afterwards

Where your anti-bribery function needs to be brought up to date on the 2025 edition, the training component is HRD Corp claimable and delivered alongside the engagement.

How it works

How the engagement runs

01

Date check

We start with the calendar: your certificate's audit cycle, your next scheduled audit and whether it falls before 28 February 2027. If it does not, you need a special transition audit, and that shapes everything else.

02

Gap assessment

Reviewing your documented system and a sample of records against the 2025 edition, and interviewing the anti-bribery function and the process owners who operate the controls.

03

Remediation

Updating policies, procedures, registers and forms, and putting the new or changed controls into operation early enough to generate the records an auditor samples.

04

Internal audit and management review

An internal audit against the 2025 edition and a management review that considers the transition, both of which your certification body will ask to see.

05

Transition audit readiness

A readiness pack mapping each change to its evidence, a briefing for the people the auditor will interview, and support in coordinating the audit with your certification body.

Deliverables

What you receive

Transition timeline

Your audit dates set against 28 February 2027, with the decision on scheduled versus special transition audit and the dates you need to book.

Gap assessment report

Every change in the 2025 edition assessed against your system, with evidence expected, owner and effort for each gap.

Updated ABMS documentation

Revised anti-bribery policy, procedures and manual, a conflict of interest procedure and register, and an updated mandate for the anti-bribery function.

Internal audit report

An internal audit against ISO 37001:2025, with findings and corrective actions tracked to closure.

Management review record

A management review that covers the transition, in the form your certification body will expect.

Transition audit readiness pack

Change-by-change evidence map and interview briefing for the transition audit.

Who it is for

Who this is built for

Industries

Construction and G7 contractorsGovernment-linked companiesStatutory bodiesOil and gasFinancial servicesProperty developmentManufacturingSuppliers to the public sector

Company sizes

Public-listed companiesLarge enterpriseMid-marketAny certified organisation

Departments

Integrity and anti-bribery functionComplianceQuality and ISORisk managementLegal and company secretarialProcurement
Why Orbix

Why organisations choose Orbix

A governance approach, not a tool sale

We do not resell products, so nothing here is shaped by a vendor margin. The recommendation is whatever your risk and your budget actually justify, including telling you that you do not need the engagement yet.

Recommendations you can actually implement

Findings come with a sequence, an owner and a realistic effort estimate, sized to the team you have rather than the team a framework assumes. A report that cannot be acted on is an expense, not a control.

Consultants who have sat on your side of the table

Our people have carried the obligation internally, not only audited it. That shows up in what we consider proportionate, and in how much documentation we think you genuinely need.

Built for the Malaysian operating context

Work is grounded in Malaysian law and regulator expectation, from the PDPA and the Cyber Security Act 2024 to Bursa, BNM and SC requirements, rather than translated from a European or American template.

HRD Corp expertise where it applies

Where an engagement includes training, the training component is structured to be HRD Corp SBL-Khas claimable, which changes what the programme costs you in practice.

Questions

Questions we get asked

Is our ISO 37001:2016 certificate still valid?

Until 28 February 2027 at the latest. Under IAF MD 30:2025, accredited certifications to the 2016 edition are no longer valid after that date, whatever expiry date is printed on the certificate. If your certification body audits you to the 2016 edition in the meantime, it must tell you that validity ends at the close of the transition period.

Can we transition at our next surveillance audit?

Yes, if that audit takes place before 28 February 2027. IAF MD 30:2025 allows the transition at a scheduled audit such as surveillance or recertification, or at a separate transition audit. Your certification body decides how much extra audit time is needed, and may run the transition audit remotely.

What happens if we miss the deadline?

Your 2016 certificate stops being valid on 28 February 2027. Getting certified again means a new initial certification to the 2025 edition, with the full audit that involves, and a gap in between during which you cannot show a valid certificate to a tender panel or customer.

How much has actually changed?

Less than the deadline suggests. The main changes are conflicts of interest, anti-bribery culture, a clarified anti-bribery function, climate change as a context consideration and the latest harmonized structure. A well-maintained 2016 system usually needs targeted updates rather than a rebuild. The risk is leaving it too late, not the size of the change.

We are a G7 contractor. Does this affect our CIDB requirement?

CIDB Pekeliling Bil. 1/2026 names MS ISO 37001:2016. How CIDB will treat that reference once 2016 certificates stop being valid is a question for CIDB, and we recommend you confirm it with them and with your certification body. The transition itself follows the IAF timeline either way.

We are not certified yet. Should we certify to 2016 first?

No. Since 31 August 2026, initial certification can only be to the 2025 edition. Build your system to ISO 37001:2025 from the start through our Integrity & Governance engagement.

Can you certify us?

No, and deliberately. Certification has to come from an accredited certification body that is independent of the people who helped build the system. We prepare you for the audit; the certificate comes from them.

Get started

There is still time, if you start now

Tell us who certifies you, when your next audit is booked and when your certificate was last renewed. We will come back with a transition timeline, a scope and a fixed quotation, and we will say so if your system needs less work than you expect.