Gap assessment
Current anti-bribery controls against the standard.
CIDB has made MS ISO 37001 anti-bribery certification mandatory for G7 contractors. We build the management system from the ground up for construction businesses and prepare you for the certification audit.
An implementation engagement for contractors seeking first-time anti-bribery management system certification: risk assessment, policy, controls, documentation, training, internal audit and certification readiness.
CIDB Pekeliling Bil. 1/2026 makes MS ISO 37001 certification mandatory for G7 contractors. Accreditation rules also moved initial certifications to the 2025 edition of the standard from 31 August 2026, and how CIDB treats the editions should be confirmed with CIDB directly. Either way, the work is the same: a functioning system that addresses construction bribery risks and supports the Section 17A adequate procedures defence.
Current anti-bribery controls against the standard.
Tenders, approvals, variations, payments and subcontractors.
Anti-bribery policy and function with authority.
Due diligence, gifts, hospitality, financial and tender controls.
Role-based training for site and office.
Internal audit, management review and certification readiness.
Certification ahead of CIDB deadlines.
Risks your business actually faces.
One system for certification and defence.
Mock audit before certification.
A system you can run after we leave.
Where you stand.
Risk assessment and policy.
Controls, documents and training.
Testing the system.
Mock audit and support.
Against the standard.
Construction-specific.
Policy, procedures and records.
Role-based.
Before certification.
We do not resell products, so nothing here is shaped by a vendor margin. The recommendation is whatever your risk and your budget actually justify, including telling you that you do not need the engagement yet.
Findings come with a sequence, an owner and a realistic effort estimate, sized to the team you have rather than the team a framework assumes. A report that cannot be acted on is an expense, not a control.
Our people have carried the obligation internally, not only audited it. That shows up in what we consider proportionate, and in how much documentation we think you genuinely need.
Work is grounded in Malaysian law and regulator expectation, from the PDPA and the Cyber Security Act 2024 to Bursa, BNM and SC requirements, rather than translated from a European or American template.
Where an engagement includes training, the training component is structured to be HRD Corp SBL-Khas claimable, which changes what the programme costs you in practice.
No. Certified organisations need our ISO 37001:2025 Transition service instead.
New certifications are now to the 2025 edition under accreditation rules. Confirm with CIDB how it treats the editions for your application.
Typically four to six months before a certification audit, depending on size.
No. An accredited certification body certifies. We prepare you.
Yes. The system and its evidence support the adequate procedures defence.
Tell us your grade, size and timeline. We will scope implementation and quote.