rulesmate.com.au — Compliance reference
https://rulesmate.com.au/insights/iso-37301-compliance-management-system-australia
Printed 28 August 2026
ISO 37301 compliance management systems: the standard for the compliance function itself
ISO 37301 sets certifiable requirements for a compliance management system: the obligations register, independence of the compliance function, culture, and Australian uses.
ISO 37301:2021 specifies requirements for a compliance management system (CMS). It is the standard aimed squarely at the compliance function itself — how obligations are identified, who owns them, how the function is resourced and kept independent, how culture is evidenced, and how the whole thing is evaluated.
Unlike ISO 31000, it is certifiable. Unlike ISO 9001 or ISO 27001, almost nobody in Australia is asked for the certificate. That combination makes it the most useful and least understood standard in the family: valuable as a blueprint even where certification is never pursued.
What ISO 37301 is and what it replaced
ISO 37301:2021 replaced ISO 19600:2014, which was guidance only. The change from guidance to requirements is the whole point.
The catalogue entry is ISO 37301:2021. It follows the harmonised clause 4 to 10 structure and, like the other Type A standards, carries the 2024 climate action amendment — see ISO 37301:2021/Amd 1:2024.
What it requires that other management-system standards do not:
- A compliance obligations register derived from an analysis of the organisation's activities, and a compliance risk assessment built on it.
- A compliance function with defined responsibilities, authority, competence and independence, and direct access to the governing body.
- Compliance culture requirements — the standard makes behaviour, tone and incentive structures part of the auditable system.
- Controls and procedures proportionate to compliance risk, including for outsourced and third-party activities.
- Raising concerns processes — mechanisms to report suspected or actual non-compliance without fear of reprisal.
- Investigation processes for reported non-compliance.
- Performance evaluation including compliance-specific indicators and reporting to the governing body.
The compliance obligations register is the core artefact
The obligations register is where ISO 37301 implementations succeed or fail, because everything downstream is derived from it.
A register that satisfies the standard records, for each obligation:
| Field | Purpose |
|---|---|
| Source | Legislation, regulation, licence, code, contract, or voluntary commitment |
| Requirement | What must be done, in operational terms — not a citation alone |
| Applicability | Which entities, jurisdictions, business lines and activities it binds |
| Owner | A named accountable individual, not a department |
| Controls | What the organisation does to meet it |
| Evidence | Where the proof of compliance lives |
| Trigger or frequency | Event-driven, periodic, or continuous |
| Change monitoring | How you learn the obligation has changed |
Two fields are consistently absent in registers that fail review. Evidence location — because "we comply" is not evidence, and an auditor will ask to see the record. And change monitoring — because an obligations register is a perishable asset. Australian obligations move constantly: commencement dates, threshold indexation, new codes, and regulator guidance updates.
The register also has to be built from the actual regulatory surface, which for a multi-entity, multi-state Australian business is wide. Start with the obligation checker to establish which obligations apply to your operations, then use the compliance calendar and the deadline register to give date-driven obligations a live cadence rather than a static entry.
Governance: independence, resourcing and reporting lines
ISO 37301 requires the compliance function to have direct access to the governing body and to be free from conflicts that would compromise it. This is the clause with the sharpest organisational consequences.
The requirements in practice:
- Defined authority. The function must be able to require information, investigate, and escalate without permission from the business line being examined.
- Adequate resourcing. Assessed against the compliance risk profile, not against convenience. Under-resourcing relative to assessed risk is a finding.
- Independence. A compliance officer who reports solely to the executive whose conduct they may need to report on does not meet the requirement.
- Competence. Documented, maintained, and matched to the obligations in scope.
- Direct reporting line to the governing body or a committee of it.
Australian law reaches the same conclusions in specific regimes. AML/CTF requires a designated AML/CTF compliance officer at management level — see the obligation aml-compliance-officer and our guide to the AMLCO role. AFS licensees must have adequate resources and risk management systems under their general obligations. The pattern is consistent: the regulator wants a named person with authority and a line to the board.
Compliance culture as an auditable requirement
ISO 37301 treats culture as part of the system, and auditors sample it. This surprises organisations used to standards that stop at process.
The evidence auditors look for:
- Tone from the top — governing body and executive statements, and whether behaviour matched them when compliance conflicted with commercial pressure.
- Incentive alignment — whether remuneration, targets and recognition reward or penalise compliance behaviour. A sales incentive that pays on volume with no compliance gate is an adverse finding.
- Consequence management — evidence that breaches by senior people were treated the same as breaches by junior people.
- Raising concerns — usage data for the reporting channel, evidence of non-retaliation, and outcomes of reported matters.
- Training — not attendance registers, but evidence of effectiveness and role-specific content.
The raising-concerns requirement overlaps directly with Australian whistleblower law. Public companies and large proprietary companies must have a compliant whistleblower policy — see whistleblower protections under Part 9.4AAA, the obligation whistleblower-protection-corporate, and the whistleblower policy tool. Build one channel that satisfies both the statutory requirements and the standard; running two confuses staff and halves the usage data.
Where ISO 37301 fits Australian regulatory expectations
No Australian regulator requires ISO 37301 certification. Several require, in substance, what it describes.
- AML/CTF program obligations require a documented program with risk assessment, controls, oversight, employee due diligence, training and independent review. The independent review obligation is an evaluation requirement with the same purpose as the standard's performance evaluation clause.
- Financial services licensing requires adequate arrangements for managing conflicts, adequate resources, and compliance measures.
- Enforceable undertakings and court-ordered compliance programs frequently specify components that read like an ISO 37301 clause list: obligations identification, training, reporting, independent review, and board reporting.
- Directors' duties. A board asked whether it exercised care and diligence in overseeing compliance is on stronger ground when it can point to a structured system with reporting into it.
The most common Australian use is therefore not certification but architecture: adopting the ISO 37301 clause structure as the design for a compliance program, so that when a regulator or an acquirer asks how compliance is managed, the answer has a recognisable shape.
ISO 37301, ISO 37302 and ISO 37001
Three related standards, frequently confused.
| Standard | What it is | Certifiable |
|---|---|---|
| ISO 37301:2021 | Compliance management systems — requirements | Yes |
| ISO 37302:2025 | Compliance management systems — guidance for evaluating effectiveness | No, it is guidance |
| ISO 37001 | Anti-bribery management systems | Yes, but scoped to bribery only |
ISO 37302:2025 is the newest of the three and addresses the question boards actually ask: not "do we have a compliance system" but "is it working". Its evaluation guidance is useful whether or not you pursue certification, because it forces the distinction between activity metrics (training completed) and effectiveness metrics (breaches detected internally versus externally, time to remediate, repeat findings).
ISO 37001 is narrower. An organisation with material bribery exposure — offshore operations, government contracting, high-risk jurisdictions — may certify to it specifically, but it does not cover the rest of the compliance surface.
Implementing it without duplicating what you already run
The risk with ISO 37301 is building a second compliance system beside the one you already operate. Four rules prevent it.
- One obligations register. If AML, privacy, WHS and financial services each keep their own, consolidate into a single register with jurisdiction and domain tags. Duplicate registers diverge, and the divergence is where obligations get missed.
- One raising-concerns channel that satisfies the Corporations Act whistleblower requirements and the standard's requirement together.
- One risk method. Use the same risk criteria and scales as your enterprise risk framework — see ISO 31000 applied to a compliance program. Two scales produce two answers to the same question.
- One evaluation cycle. Internal audit, management review and any statutory independent review should be sequenced so each feeds the next rather than running as three unrelated exercises.
If you already hold another management-system certificate, the shared clauses — context, leadership, competence, documented information, internal audit, management review, nonconformity and corrective action — should be operated once across all of them. That integration is also what keeps external audit days down when certification is pursued, a point developed in maintaining certification between recertification cycles.
Frequently asked
Can an organisation be certified to ISO 37301?
Yes. ISO 37301:2021 is a requirements standard, unlike its predecessor ISO 19600:2014 which was guidance only, and accredited certification is available. Demand for the certificate in Australia is low compared with ISO 9001 or ISO 27001, so most organisations use the standard as an architecture rather than pursuing certification.
Do any Australian regulators require ISO 37301?
No. No Australian regulator mandates ISO 37301 certification. Several regimes require, in substance, what the standard describes — AML/CTF program obligations, financial services licensing arrangements, and the components typically specified in enforceable undertakings and court-ordered compliance programs.
What is the difference between ISO 37301 and ISO 37001?
ISO 37301 covers compliance management across the whole obligations surface. ISO 37001 is an anti-bribery management system standard covering bribery risk only. Both are certifiable. An organisation with material bribery exposure may hold ISO 37001 specifically, but it leaves the rest of the compliance surface uncovered.
What does ISO 37301 require in terms of compliance function independence?
The compliance function must have defined responsibilities and authority, appropriate competence and resourcing, and direct access to the governing body. A compliance officer whose only reporting line is to an executive whose conduct they may need to report on does not satisfy the requirement.
How is compliance culture audited under ISO 37301?
Through evidence rather than assertion: tone-from-the-top statements tested against behaviour under commercial pressure, incentive structures examined for whether they reward or penalise compliance, consequence management applied consistently across seniority, raising-concerns channel usage and outcomes, and training effectiveness rather than attendance.
What is ISO 37302 and do I need it?
ISO 37302:2025 is guidance on evaluating the effectiveness of a compliance management system. It is not certifiable. It is useful whether or not you pursue ISO 37301 certification because it forces the distinction between activity metrics such as training completion and effectiveness metrics such as internally versus externally detected breaches and time to remediate.
Related
Related reading
Whistleblower protection under Part 9.4AAA of the Corporations Act
Eligible whistleblowers in the corporate sector have legal protection for disclosures under Part 9.4AAA of the Corporations Act 2001. Here's who's eligible, who can receive disclosures, and the protections.
AML/CTF Compliance Officer (AMLCO) — role and statutory responsibilities
Why every reporting entity must appoint an AML/CTF Compliance Officer and what the role covers under the AML/CTF Rules.
ISO 31000 risk management: applying the standard to an Australian compliance program
ISO 31000 is guidance, not a certifiable standard. How to apply its principles, framework and process to an Australian compliance program that regulators will accept.
Surveillance audits, non-conformances and keeping certification between recertification cycles
How the three-year certification cycle works: surveillance audit scope, major vs minor non-conformances, root cause and corrective action, and suspension or withdrawal.
Obligations covered
© Rules Mate · Source citations at the end · Information current as at 28 August 2026
Printed from https://rulesmate.com.au/insights/iso-37301-compliance-management-system-australia