Skip to main content
Rules Mate

ISO 37301 compliance management systems: the standard for the compliance function itself

Rules Mate Editorial7 min read

ISO 37301 sets certifiable requirements for a compliance management system: the obligations register, independence of the compliance function, culture, and Australian uses.

ISO 37301:2021 specifies requirements for a compliance management system (CMS). It is the standard aimed squarely at the compliance function itself — how obligations are identified, who owns them, how the function is resourced and kept independent, how culture is evidenced, and how the whole thing is evaluated.

Unlike ISO 31000, it is certifiable. Unlike ISO 9001 or ISO 27001, almost nobody in Australia is asked for the certificate. That combination makes it the most useful and least understood standard in the family: valuable as a blueprint even where certification is never pursued.

What ISO 37301 is and what it replaced

ISO 37301:2021 replaced ISO 19600:2014, which was guidance only. The change from guidance to requirements is the whole point.

The catalogue entry is ISO 37301:2021. It follows the harmonised clause 4 to 10 structure and, like the other Type A standards, carries the 2024 climate action amendment — see ISO 37301:2021/Amd 1:2024.

What it requires that other management-system standards do not:

  • A compliance obligations register derived from an analysis of the organisation's activities, and a compliance risk assessment built on it.
  • A compliance function with defined responsibilities, authority, competence and independence, and direct access to the governing body.
  • Compliance culture requirements — the standard makes behaviour, tone and incentive structures part of the auditable system.
  • Controls and procedures proportionate to compliance risk, including for outsourced and third-party activities.
  • Raising concerns processes — mechanisms to report suspected or actual non-compliance without fear of reprisal.
  • Investigation processes for reported non-compliance.
  • Performance evaluation including compliance-specific indicators and reporting to the governing body.

The compliance obligations register is the core artefact

The obligations register is where ISO 37301 implementations succeed or fail, because everything downstream is derived from it.

A register that satisfies the standard records, for each obligation:

FieldPurpose
SourceLegislation, regulation, licence, code, contract, or voluntary commitment
RequirementWhat must be done, in operational terms — not a citation alone
ApplicabilityWhich entities, jurisdictions, business lines and activities it binds
OwnerA named accountable individual, not a department
ControlsWhat the organisation does to meet it
EvidenceWhere the proof of compliance lives
Trigger or frequencyEvent-driven, periodic, or continuous
Change monitoringHow you learn the obligation has changed

Two fields are consistently absent in registers that fail review. Evidence location — because "we comply" is not evidence, and an auditor will ask to see the record. And change monitoring — because an obligations register is a perishable asset. Australian obligations move constantly: commencement dates, threshold indexation, new codes, and regulator guidance updates.

The register also has to be built from the actual regulatory surface, which for a multi-entity, multi-state Australian business is wide. Start with the obligation checker to establish which obligations apply to your operations, then use the compliance calendar and the deadline register to give date-driven obligations a live cadence rather than a static entry.

Governance: independence, resourcing and reporting lines

ISO 37301 requires the compliance function to have direct access to the governing body and to be free from conflicts that would compromise it. This is the clause with the sharpest organisational consequences.

The requirements in practice:

  • Defined authority. The function must be able to require information, investigate, and escalate without permission from the business line being examined.
  • Adequate resourcing. Assessed against the compliance risk profile, not against convenience. Under-resourcing relative to assessed risk is a finding.
  • Independence. A compliance officer who reports solely to the executive whose conduct they may need to report on does not meet the requirement.
  • Competence. Documented, maintained, and matched to the obligations in scope.
  • Direct reporting line to the governing body or a committee of it.

Australian law reaches the same conclusions in specific regimes. AML/CTF requires a designated AML/CTF compliance officer at management level — see the obligation aml-compliance-officer and our guide to the AMLCO role. AFS licensees must have adequate resources and risk management systems under their general obligations. The pattern is consistent: the regulator wants a named person with authority and a line to the board.

Compliance culture as an auditable requirement

ISO 37301 treats culture as part of the system, and auditors sample it. This surprises organisations used to standards that stop at process.

The evidence auditors look for:

  • Tone from the top — governing body and executive statements, and whether behaviour matched them when compliance conflicted with commercial pressure.
  • Incentive alignment — whether remuneration, targets and recognition reward or penalise compliance behaviour. A sales incentive that pays on volume with no compliance gate is an adverse finding.
  • Consequence management — evidence that breaches by senior people were treated the same as breaches by junior people.
  • Raising concerns — usage data for the reporting channel, evidence of non-retaliation, and outcomes of reported matters.
  • Training — not attendance registers, but evidence of effectiveness and role-specific content.

The raising-concerns requirement overlaps directly with Australian whistleblower law. Public companies and large proprietary companies must have a compliant whistleblower policy — see whistleblower protections under Part 9.4AAA, the obligation whistleblower-protection-corporate, and the whistleblower policy tool. Build one channel that satisfies both the statutory requirements and the standard; running two confuses staff and halves the usage data.

Where ISO 37301 fits Australian regulatory expectations

No Australian regulator requires ISO 37301 certification. Several require, in substance, what it describes.

  • AML/CTF program obligations require a documented program with risk assessment, controls, oversight, employee due diligence, training and independent review. The independent review obligation is an evaluation requirement with the same purpose as the standard's performance evaluation clause.
  • Financial services licensing requires adequate arrangements for managing conflicts, adequate resources, and compliance measures.
  • Enforceable undertakings and court-ordered compliance programs frequently specify components that read like an ISO 37301 clause list: obligations identification, training, reporting, independent review, and board reporting.
  • Directors' duties. A board asked whether it exercised care and diligence in overseeing compliance is on stronger ground when it can point to a structured system with reporting into it.

The most common Australian use is therefore not certification but architecture: adopting the ISO 37301 clause structure as the design for a compliance program, so that when a regulator or an acquirer asks how compliance is managed, the answer has a recognisable shape.

ISO 37301, ISO 37302 and ISO 37001

Three related standards, frequently confused.

StandardWhat it isCertifiable
ISO 37301:2021Compliance management systems — requirementsYes
ISO 37302:2025Compliance management systems — guidance for evaluating effectivenessNo, it is guidance
ISO 37001Anti-bribery management systemsYes, but scoped to bribery only

ISO 37302:2025 is the newest of the three and addresses the question boards actually ask: not "do we have a compliance system" but "is it working". Its evaluation guidance is useful whether or not you pursue certification, because it forces the distinction between activity metrics (training completed) and effectiveness metrics (breaches detected internally versus externally, time to remediate, repeat findings).

ISO 37001 is narrower. An organisation with material bribery exposure — offshore operations, government contracting, high-risk jurisdictions — may certify to it specifically, but it does not cover the rest of the compliance surface.

Implementing it without duplicating what you already run

The risk with ISO 37301 is building a second compliance system beside the one you already operate. Four rules prevent it.

  1. One obligations register. If AML, privacy, WHS and financial services each keep their own, consolidate into a single register with jurisdiction and domain tags. Duplicate registers diverge, and the divergence is where obligations get missed.
  2. One raising-concerns channel that satisfies the Corporations Act whistleblower requirements and the standard's requirement together.
  3. One risk method. Use the same risk criteria and scales as your enterprise risk framework — see ISO 31000 applied to a compliance program. Two scales produce two answers to the same question.
  4. One evaluation cycle. Internal audit, management review and any statutory independent review should be sequenced so each feeds the next rather than running as three unrelated exercises.

If you already hold another management-system certificate, the shared clauses — context, leadership, competence, documented information, internal audit, management review, nonconformity and corrective action — should be operated once across all of them. That integration is also what keeps external audit days down when certification is pursued, a point developed in maintaining certification between recertification cycles.

Frequently asked

Can an organisation be certified to ISO 37301?

Yes. ISO 37301:2021 is a requirements standard, unlike its predecessor ISO 19600:2014 which was guidance only, and accredited certification is available. Demand for the certificate in Australia is low compared with ISO 9001 or ISO 27001, so most organisations use the standard as an architecture rather than pursuing certification.

Do any Australian regulators require ISO 37301?

No. No Australian regulator mandates ISO 37301 certification. Several regimes require, in substance, what the standard describes — AML/CTF program obligations, financial services licensing arrangements, and the components typically specified in enforceable undertakings and court-ordered compliance programs.

What is the difference between ISO 37301 and ISO 37001?

ISO 37301 covers compliance management across the whole obligations surface. ISO 37001 is an anti-bribery management system standard covering bribery risk only. Both are certifiable. An organisation with material bribery exposure may hold ISO 37001 specifically, but it leaves the rest of the compliance surface uncovered.

What does ISO 37301 require in terms of compliance function independence?

The compliance function must have defined responsibilities and authority, appropriate competence and resourcing, and direct access to the governing body. A compliance officer whose only reporting line is to an executive whose conduct they may need to report on does not satisfy the requirement.

How is compliance culture audited under ISO 37301?

Through evidence rather than assertion: tone-from-the-top statements tested against behaviour under commercial pressure, incentive structures examined for whether they reward or penalise compliance, consequence management applied consistently across seniority, raising-concerns channel usage and outcomes, and training effectiveness rather than attendance.

What is ISO 37302 and do I need it?

ISO 37302:2025 is guidance on evaluating the effectiveness of a compliance management system. It is not certifiable. It is useful whether or not you pursue ISO 37301 certification because it forces the distinction between activity metrics such as training completion and effectiveness metrics such as internally versus externally detected breaches and time to remediate.

Related

Related reading