Governance / Anti-Bribery Certification

ISO 37001 Implementation for G7 Contractors

CIDB has made MS ISO 37001 anti-bribery certification mandatory for G7 contractors. We build the management system from the ground up for construction businesses and prepare you for the certification audit.

Built for construction bribery risks Gap assessment to certification readiness Section 17A adequate procedures evidence included
Overview

ISO 37001 Implementation for G7 Contractors

What it is

An implementation engagement for contractors seeking first-time anti-bribery management system certification: risk assessment, policy, controls, documentation, training, internal audit and certification readiness.

Why organisations need it

CIDB Pekeliling Bil. 1/2026 makes MS ISO 37001 certification mandatory for G7 contractors. Accreditation rules also moved initial certifications to the 2025 edition of the standard from 31 August 2026, and how CIDB treats the editions should be confirmed with CIDB directly. Either way, the work is the same: a functioning system that addresses construction bribery risks and supports the Section 17A adequate procedures defence.

Key features

What the engagement covers

Gap assessment

Current anti-bribery controls against the standard.

Bribery risk assessment

Tenders, approvals, variations, payments and subcontractors.

Policy and function

Anti-bribery policy and function with authority.

Controls

Due diligence, gifts, hospitality, financial and tender controls.

Training and communication

Role-based training for site and office.

Internal audit and readiness

Internal audit, management review and certification readiness.

Business value

What the business gets out of it

Tender eligibility protected

Certification ahead of CIDB deadlines.

Construction-specific

Risks your business actually faces.

Section 17A evidence

One system for certification and defence.

Audit ready

Mock audit before certification.

Built to last

A system you can run after we leave.

How it works

How the engagement runs

01

Gap assessment

Where you stand.

02

Design

Risk assessment and policy.

03

Implementation

Controls, documents and training.

04

Internal audit

Testing the system.

05

Certification readiness

Mock audit and support.

Deliverables

What you receive

Gap assessment report

Against the standard.

Bribery risk register

Construction-specific.

Management system documents

Policy, procedures and records.

Training materials

Role-based.

Internal audit report

Before certification.

Who it is for

Who this is built for

Industries

G7 contractorsContractors preparing for G7Infrastructure developersEngineering firms

Company sizes

G7 contractorsLarge contractors

Departments

IntegrityQuality and ISOContractsProcurementManagement
Why Orbix

Why organisations choose Orbix

A governance approach, not a tool sale

We do not resell products, so nothing here is shaped by a vendor margin. The recommendation is whatever your risk and your budget actually justify, including telling you that you do not need the engagement yet.

Recommendations you can actually implement

Findings come with a sequence, an owner and a realistic effort estimate, sized to the team you have rather than the team a framework assumes. A report that cannot be acted on is an expense, not a control.

Consultants who have sat on your side of the table

Our people have carried the obligation internally, not only audited it. That shows up in what we consider proportionate, and in how much documentation we think you genuinely need.

Built for the Malaysian operating context

Work is grounded in Malaysian law and regulator expectation, from the PDPA and the Cyber Security Act 2024 to Bursa, BNM and SC requirements, rather than translated from a European or American template.

HRD Corp expertise where it applies

Where an engagement includes training, the training component is structured to be HRD Corp SBL-Khas claimable, which changes what the programme costs you in practice.

Questions

Questions we get asked

We are already certified. Is this for us?

No. Certified organisations need our ISO 37001:2025 Transition service instead.

Which edition should we implement?

New certifications are now to the 2025 edition under accreditation rules. Confirm with CIDB how it treats the editions for your application.

How long does implementation take?

Typically four to six months before a certification audit, depending on size.

Do you certify us?

No. An accredited certification body certifies. We prepare you.

Does this help with Section 17A?

Yes. The system and its evidence support the adequate procedures defence.

Get started

Get certified before it costs you a tender

Tell us your grade, size and timeline. We will scope implementation and quote.