ISO 37301 Compliance Management Systems Training
ISO 37301:2021 is the international requirements standard for a compliance management system. Unlike ISO 19600:2014, the guidance document it replaced, it is a Type A standard, which means an organisation can be certified against it and an auditor can raise a nonconformity. This two-day programme works through the standard clause by clause and converts it into something an organisation can actually build and operate.
It is aimed at organisations whose compliance obligations are real but scattered: a licence condition owned by operations, a regulator's guideline owned by finance, a contractual commitment sitting with legal, and a code of conduct nobody has revisited in three years. The standard's value is that it forces those obligations into one register with named owners, assessed risk and evidence of monitoring. Participants leave with a populated obligations register and a risk assessment for their own function, not a set of slides.
HRD Corp SBL-Khas Claimable
Programme Agenda
Day 1, 9:00 AM - 9:15 AM
Welcome and Programme Overview
Introduction to the session, objectives, and housekeeping.
Day 1, 9:15 AM - 10:15 AM
Why ISO 37301, and What Changed
The move from ISO 19600:2014 guidance to a certifiable Type A requirements standard, and what that changes in practice. The Annex SL high level structure shared with ISO 9001, ISO 14001, ISO 27001 and ISO 37001, and why that makes integration with existing management systems straightforward. How ISO 37301 relates to ISO 37001 anti-bribery: overlapping architecture, different scope.
Day 1, 10:15 AM - 10:30 AM
Break
Day 1, 10:30 AM - 11:45 AM
Clause 4: Context, Interested Parties and Scope
Determining internal and external issues, identifying interested parties and their requirements, and defining the boundaries of the compliance management system. Building the compliance obligations register: statutes and regulations, licences and permits, regulator guidelines, contractual commitments, industry codes and voluntary commitments. Distinguishing obligations the organisation must meet from commitments it has chosen to make, and why both belong in the register.
Day 1, 11:45 AM - 12:45 PM
Clause 5: Leadership, Governance and the Compliance Function
What the standard requires of the governing body as distinct from top management. The compliance policy, the compliance function's authority, independence and direct access to the governing body, and adequate resourcing. Roles and responsibilities across the organisation, and the governance principles the standard sets out including integrity, transparency, accountability and sustainability.
Day 1, 12:45 PM - 1:45 PM
Lunch
Day 1, 1:45 PM - 3:00 PM
Clause 6: Compliance Risk Assessment and Objectives
Identifying compliance risks against each obligation, analysing likelihood and consequence, and evaluating against defined criteria. Setting compliance objectives that are measurable and assigned, planning to achieve them, and managing planned changes to the system. Where compliance risk assessment differs from enterprise risk assessment and where the two should connect.
Day 1, 3:00 PM - 3:15 PM
Break
Day 1, 3:15 PM - 4:15 PM
Clause 7: Support
Resources, competence and the evidence an auditor expects that people are actually competent rather than merely trained. Awareness, internal and external communication, and control of documented information including version control, retention and access. Practical guidance on the document set a certification auditor will ask for.
Day 1, 4:15 PM - 5:00 PM
Clause 8: Operation
Operational planning and control, establishing controls and procedures proportionate to assessed risk, and embedding compliance into business processes rather than bolting it on. Raising concerns and whistleblowing channels, protection from retaliation, and investigation processes. Day 1 wrap-up.
Day 2, 9:00 AM - 9:15 AM
Recap and Day 2 Objectives
Review of the clause requirements covered on Day 1 and the plan for the workshop day.
Day 2, 9:15 AM - 10:30 AM
Clause 9: Performance Evaluation
Monitoring, measurement, analysis and evaluation, and choosing compliance indicators that reveal something rather than confirm what you hoped. The internal audit programme: scope, auditor competence and independence, and audit planning. Management review inputs and outputs, and reporting to the governing body in a form it can act on.
Day 2, 10:30 AM - 10:45 AM
Break
Day 2, 10:45 AM - 11:30 AM
Clause 10: Nonconformity and Continual Improvement
Handling nonconformity and noncompliance, correction against corrective action, root cause analysis that goes past the immediate failure, and demonstrating continual improvement to an auditor.
Day 2, 11:30 AM - 12:45 PM
Workshop: Building a Compliance Obligations Register
Participants build a register for their own function: identifying obligations from source, recording the requirement rather than the citation alone, assigning owners, linking existing controls, and flagging obligations with no owner or no control. Facilitated review of the output.
Day 2, 12:45 PM - 1:45 PM
Lunch
Day 2, 1:45 PM - 3:00 PM
Workshop: Compliance Risk Assessment
Working from the register built in the morning, participants set assessment criteria, score inherent risk, evaluate control effectiveness, arrive at residual risk and decide treatment. Discussion of scoring disputes and how to keep an assessment defensible when the numbers are judgement calls.
Day 2, 3:00 PM - 3:15 PM
Break
Day 2, 3:15 PM - 4:15 PM
Gap Analysis and Certification Readiness
Running a self-assessment against the standard, the documented information set required, and what happens in a stage 1 and stage 2 certification audit. Common nonconformities and how to close them. Integrating ISO 37301 with an existing ISO 37001, ISO 9001 or ISO 27001 system to avoid running parallel bureaucracies.
Day 2, 4:15 PM - 5:00 PM
Implementation Roadmap and Wrap-Up
Groups present a phased implementation roadmap for their own organisation with owners and sequencing. Key takeaways, next steps, and close.
Key Outcomes
- Explain the requirements of ISO 37301:2021 clause by clause and how they connect as a system
- Build and maintain a compliance obligations register that survives an audit
- Run a compliance risk assessment and link each risk to a control and a named owner
- Define the compliance function's mandate, independence and reporting line to the governing body
- Design monitoring, internal audit and management review that produce usable evidence
- Run a gap analysis and plan a realistic route to certification readiness
Training Mode Physical / Online / Hybrid / e-learning
HRD Corp SBL-Khas Claimable
Level Intermediate, suitable for compliance officers, risk and internal audit teams, legal counsel, quality and management system professionals, and managers accountable for regulated obligations
Duration 2 Days (16 Hours) | 9:00 AM to 5:00 PM daily
Venue In-house at the client's premises, or delivered via the client's preferred platform (Microsoft Teams, Zoom, or equivalent)
Assessment Knowledge assessment covering all clauses, two facilitated workshops, and a group implementation roadmap presentation
Certificate Certificate of Completion issued to all participants upon full attendance