Anti-Bribery Management System Consultants in Dubai, Abu Dhabi & Saudi Arabia
Nathan ISO Consulting implements and certifies ISO 37001:2016 Anti-Bribery Management Systems for contractors, energy services companies, healthcare groups, trading businesses and government suppliers across the UAE, Saudi Arabia and the wider GCC.
An agent in a third market secures a contract and submits a large consultancy fee invoice with no supporting deliverable. A procurement manager approves a supplier owned by a relative. A gift to a government official is logged as client entertainment because nobody wanted the conversation. Each is survivable in isolation. What makes them dangerous is the absence of a system designed to catch them — because when a regulator or a client compliance team asks what controls existed, the honest answer determines whether the organisation faces a manageable issue or an existential one.
What Is ISO 37001:2016?
ISO 37001:2016 is the international standard for Anti-Bribery Management Systems. It specifies requirements for establishing, implementing, maintaining and improving a programme designed to prevent, detect and respond to bribery — both bribery by the organisation and bribery of it.
The standard was published against a backdrop of expanding extraterritorial enforcement. The US Foreign Corrupt Practices Act and the UK Bribery Act both reach conduct occurring well outside their home jurisdictions, and both have been enforced against companies with modest connections to the US or UK. For Gulf-based organisations with international clients, foreign shareholders, cross-border transactions or overseas listings, that reach is not theoretical.
The UK Bribery Act is particularly relevant to how the standard is structured. It created a corporate offence of failing to prevent bribery, with a defence available where the organisation demonstrates adequate procedures were in place. ISO 37001 is in substance an auditable articulation of what adequate procedures look like — which is why legal advisers frequently recommend it even to clients facing no direct certification requirement.
| Requirement | What it means in practice |
|---|---|
| Bribery risk assessment | Systematic identification of where bribery risk exists — by country, sector, transaction type, counterparty and interaction with public officials |
| Anti-bribery policy | Prohibiting bribery, requiring compliance with applicable law, stating consequences, communicated to staff and business associates |
| Compliance function | A designated function with competence, resources, authority and direct access to the governing body |
| Due diligence | Risk-proportionate checks on personnel in exposed roles, business associates, agents, intermediaries and specific transactions |
| Financial and non-financial controls | Payment approval thresholds, segregation of duties, procurement controls and documentation for higher-risk transactions |
| Gifts, hospitality and donations | Defined limits, approval routes and a maintained register — not a blanket prohibition, which tends to be ignored rather than followed |
| Raising concerns | A reporting channel with anti-retaliation protection, accessible to staff and ideally to external parties |
| Investigation and response | A defined process for investigating suspected bribery and acting on findings, including reporting where legally required |
Internal controls are the easier half. Most established organisations already have payment approval thresholds, segregation of duties and a gifts policy of some kind. Where implementations struggle is Clause 8.2 due diligence on business associates — agents, distributors, consultants, joint venture partners and any third party acting on the organisation’s behalf.
The risk is structural rather than incidental. In most bribery enforcement cases worldwide, the payment was not made by an employee of the company facing penalties. It was made by an agent or local partner, and the company’s exposure came from engaging that party without adequate scrutiny and without contractual anti-bribery protections. An agent operating in a market where you have no direct presence, paid on success fees, with limited visibility into how results are achieved, is the single highest-risk arrangement most organisations maintain.
Risk-proportionate due diligence means a tiered approach — light verification for a low-risk local supplier, genuine scrutiny for a commission-based agent in a high-risk market, including beneficial ownership, political exposure, reputational screening and periodic re-checks rather than a single check at onboarding.
Why ISO 37001 Certification Matters in the UAE and GCC
The UAE has substantially strengthened its financial crime and anti-money laundering framework, with expanded regulatory expectations around beneficial ownership transparency, suspicious transaction reporting and compliance governance across designated sectors. Saudi Arabia’s Oversight and Anti-Corruption Authority, Nazaha, has pursued an active enforcement agenda, and Vision 2030 governance reforms have raised expectations across state-linked entities and their supply chains. Qatar, Kuwait, Oman and Bahrain each maintain anti-corruption authorities and legislation moving in the same direction.
Multinational clients, development finance institutions and state-linked entities now routinely include anti-bribery questionnaires in supplier onboarding. A certified ABMS shortcuts most of that process, and some categories of work — development-funded infrastructure projects, contracts with international primes, and supply relationships with companies under compliance monitoring — are effectively closed to suppliers who cannot evidence structured controls.
For organisations with UK or US nexus, demonstrable adequate procedures carry real legal weight. A certified, independently audited management system is materially stronger evidence than an internal policy nobody outside the company has reviewed.
Construction, energy, healthcare, defence and public procurement are the highest-risk categories globally for bribery exposure, and they dominate GCC commercial activity. Permitting and approvals, inspection sign-offs, agent-mediated market entry, customs interfaces, tender participation and state-owned counterparties all create points where informal payment pressure arises.
Compliance governance is examined during fundraising, acquisition and listing due diligence. Organisations with a certified ABMS answer those questions from existing evidence rather than assembling it under deadline pressure while a transaction is live.
Nathan ISO Consulting’s ISO 37001 Services
The foundation of everything else. We run it with your commercial, procurement and finance teams rather than as a desk exercise, because the people who know where genuine pressure points sit are those negotiating contracts and approving payments. The output determines due diligence tiering, control thresholds and where training effort concentrates.
Policy development, compliance function structure, resourcing and reporting lines — including the direct access to the governing body the standard requires, which is a structural point auditors examine closely.
Tiered due diligence procedures, screening criteria covering beneficial ownership and political exposure, documentation standards, and periodic re-verification cycles rather than one-time onboarding checks.
Anti-bribery obligations, audit rights, termination provisions and warranty language for agent agreements, distributor contracts, joint venture arrangements and supplier terms.
Payment approval thresholds tied to risk, segregation of duties, procurement controls, documentation requirements for higher-risk transactions, and integration with your existing finance systems rather than a parallel process.
Defined thresholds, approval routes and register design that staff will actually use. Blanket prohibitions are counterproductive because people quietly ignore rules that make normal business relationships impossible.
A reporting route that does not depend on raising a concern with someone potentially implicated, with anti-retaliation protection and defined triage and escalation.
General awareness across the organisation, and substantially deeper sessions for procurement, sales, agent management and any role interacting with public officials — using realistic regional scenarios and giving staff a usable script for declining without damaging a relationship.
We assess whether commission schemes, procurement targets and performance reviews quietly contradict your compliance messaging. Staff read incentives more clearly than policy statements.
Full ABMS internal audit, properly minuted management review, certification body selection, Stage 1 and Stage 2 attendance, and nonconformity closure.
Our ISO 37001 Certification Process
Confidential consultation and fixed proposal. Initial discussion of your markets, agent network, sector exposure and objectives, followed by a fixed written quotation.
Bribery risk assessment. Workshops with commercial, procurement and finance teams identifying where risk genuinely sits.
Scope definition. Which entities, geographies and business lines the certificate covers — a decision with real commercial weight.
Policy and governance design. Anti-bribery policy, compliance function structure and reporting lines to the governing body.
Due diligence framework build. Tiered procedures, screening criteria and documentation standards proportionate to assessed risk.
Control implementation. Financial controls, procurement controls, gifts framework and contractual clause rollout.
Whistleblowing channel launch. Reporting route established with triage, escalation and anti-retaliation protections.
Training delivery. Organisation-wide awareness plus deeper role-based sessions for higher-exposure functions.
Due diligence backlog clearance. Screening of the existing agent and business associate network — frequently the longest single activity.
Internal audit. Full ABMS audit with genuine findings and verified corrective action.
Management review. Structured review covering every required input, properly minuted.
Stage 1 and Stage 2 audits, then ongoing support. Documentation review, implementation audit with our consultant present, nonconformity closure and surveillance support.
Why Choose Nathan ISO Consulting
Risk assessment run with commercial teams. Not a desk exercise. Leadership teams routinely learn something about their own operation during this stage.
Practical due diligence tiering. Proportionate checks that survive contact with real workload, rather than a uniform standard that gets abandoned within two months.
Regional scenario-based training. The agent who cannot explain how a deal was won, the customs delay resolving after an unofficial payment, the official requesting conference sponsorship. Staff rarely fail because they did not know bribery was wrong — they fail because nobody gave them a way to say no.
Incentive structure honesty. We will tell you where commission schemes and procurement targets undermine your compliance messaging, because auditors and regulators notice this too.
Compliance function independence. We design reporting lines that give the function genuine authority rather than placing it under the people whose deals it must scrutinise.
Confidential engagement. Initial discussions are treated in confidence. Where risk assessment surfaces something concerning, we advise obtaining independent legal counsel — that is a legal matter, not a management system one.
One dedicated lead consultant throughout. Continuity from risk assessment through surveillance audits.
Integration with existing systems. Built on your ISO 9001, ISO 27001 or ISO 31000 governance infrastructure where it exists, rather than duplicating it.
Fixed written pricing. Agreed upfront with audit attendance included.
Independent of certification bodies. Certification is issued independently under ISO/IEC 17021, which is what gives the certificate weight with clients and regulators.
Industries We Serve
Construction and infrastructure. Permitting and approvals, inspection sign-offs, subcontractor award and variation approvals under project timeline pressure.
Oil, gas and energy services. High contract values, agent-mediated market entry, customs and logistics interfaces and state-owned counterparties.
Healthcare and pharmaceuticals. Prescriber interactions, formulary decisions, public health tender participation and sponsorship or educational funding arrangements.
Defence, aviation and government supply. Offset arrangements, agent commissions and long procurement cycles involving public officials.
Trading, logistics and free zone operations. Customs clearance, licensing and inspection interfaces creating facilitation payment pressure.
Financial services. Overlap with AML obligations, counterparty due diligence and beneficial ownership verification.
Engineering and professional services. Tender participation, agent-led business development and public sector client relationships.
Real estate and development. Land approvals, permitting, contractor award and regulatory interactions across multiple authorities.
Locations We Serve
ISO 37001 consultants across Dubai — Business Bay, Deira, Jebel Ali, Dubai Investment Park and Dubai South — plus DIFC, DMCC, JAFZA, DAFZA and Dubai Internet City, serving organisations with international client bases, agent networks and cross-border transaction exposure.
Abu Dhabi city, Mussafah, ICAD, KEZAD, Khalifa Port, Ruwais, Masdar City, Abu Dhabi Global Market and Al Ain — including ADNOC group suppliers and government and semi-government contractors.
Sharjah city, Hamriyah Free Zone and SAIF Zone; Ajman and Ajman Free Zone; Ras Al Khaimah and RAKEZ; Umm Al Quwain Free Trade Zone; Fujairah and Fujairah Free Zone.
Riyadh, Jeddah, Dammam, Al Khobar, Dhahran, Jubail, Yanbu, Mecca, Medina and Tabuk — including Aramco and SABIC supply chain contractors, NEOM, Qiddiya and Red Sea project participants, and organisations operating within Nazaha’s enforcement environment and Vision 2030 governance expectations.
Qatar — Doha, Lusail, Ras Laffan and the Qatar Financial Centre. Kuwait — Kuwait City, Shuwaikh and Ahmadi. Oman — Muscat, Sohar, Salalah and Duqm. Bahrain — Manama, Seef and Bahrain International Investment Park.
What Determines the Cost of ISO 37001 Certification?
Certification body audit fees follow mandatory audit-day tables based on headcount, sites and assessed bribery risk category — a defence contractor with an international agent network sits in a higher band than a domestic services business.
Our consultancy fee is separate and fixed in writing before engagement, driven by the number of jurisdictions and business lines in scope, the size of your agent and business associate network requiring due diligence, sector risk profile, and whether the ABMS is built standalone or extended from existing governance infrastructure. Where an existing agent network has never been screened, that backlog alone can occupy several weeks and occasionally surfaces relationships requiring commercial decisions before certification proceeds.
Get Started with ISO 37001 Certification
For ISO 37001 certification in Dubai, Abu Dhabi, Sharjah, Saudi Arabia, Qatar, Kuwait, Oman or Bahrain, call +971 50 258 5024, email info@nathanisoconsulting.com, or visit our contact page. Initial discussions are confidential, and we will give you a candid assessment of your current exposure before proposing any programme of work.
Frequently Asked Questions About ISO 37001 Certification
No, and any provider suggesting otherwise is misrepresenting the standard. Certification demonstrates that a system designed to prevent, detect and respond to bribery is in place and operating. ISO is explicit that certification does not guarantee no bribery has occurred or will occur. What it provides is credible evidence of adequate procedures, which is precisely what matters under legislation like the UK Bribery Act.
No. Anti-bribery and anti-corruption law is mandatory; certification against this standard is voluntary. It is increasingly requested contractually, particularly by multinational clients, state-linked entities and organisations subject to FCPA or UK Bribery Act exposure needing supply chain assurance.
They address related but distinct risks. AML frameworks focus on movement and legitimisation of criminal proceeds and carry specific regulatory obligations in designated sectors. ISO 37001 focuses on preventing bribery. Many controls overlap — counterparty due diligence, beneficial ownership verification, transaction monitoring — and we build them to share infrastructure rather than run in parallel.
Yes. Scope can be defined by entity, geography or business line, though scope wording matters commercially. A certificate covering a low-risk domestic subsidiary while the group’s international agent network sits outside scope offers limited assurance to a client conducting serious due diligence.
The certification body is not conducting a forensic investigation, and auditors assess management system conformity rather than hunting for historic misconduct. If an auditor encounters evidence of a serious issue, they will raise it, and certification cannot proceed while a material unaddressed concern remains open. Where our risk assessment surfaces something concerning, we advise obtaining independent legal counsel before proceeding.
No, and blanket prohibitions are counterproductive because staff quietly ignore rules making normal business relationships impossible. The standard requires defined limits, clear approval routes above threshold, and a maintained register. Reasonable, transparent, proportionate and recorded hospitality is compatible with certification.
Twelve to sixteen weeks for a single-entity organisation with moderate exposure, extending to four to six months for groups operating through agent networks across multiple jurisdictions or in higher-risk sectors. Clearing the due diligence backlog on an unscreened agent network is usually the pacing factor.
The standard requires direct access to the governing body — board, audit committee or equivalent. A compliance function reporting solely into a commercial line with no independent route to the board is a structural weakness auditors identify, because it places the person scrutinising deals under the authority of those closing them.
A facilitation payment is a small payment to expedite a routine action a person is already obliged to perform — clearing goods, issuing a permit. Some jurisdictions historically treated them differently, but most applicable legislation including the UK Bribery Act treats them as bribery regardless of size or local custom. ISO 37001 requires you to address them explicitly rather than leaving the position ambiguous.
Through layered evidence — corporate registry checks where available, beneficial ownership declarations, political exposure screening, reputational database searches, reference checks, site verification where warranted, and contractual audit rights. Where verification is genuinely limited, that limitation itself becomes a risk factor influencing whether and how you engage.
Both. The standard covers bribery by the organisation, by its personnel and business associates acting on its behalf, and bribery of the organisation and its personnel. Procurement staff receiving inducements from suppliers falls squarely within scope, and controls should address both directions.
Yes. It shares the Annex SL structure, so context, leadership, competence, documented information, internal audit and management review overlap substantially. Where an ISO 31000 enterprise risk framework exists, bribery risk becomes one domain within it rather than an isolated register.
Proportionate to exposure. General awareness for all staff covering the policy, what bribery looks like and how to report concerns. Substantially deeper, scenario-based training for procurement, sales, agent management, finance approvers and anyone interacting with public officials. Policy acknowledgement forms alone do not satisfy the competence requirement.
Your reporting channel must not route through the person potentially implicated — which is exactly why the standard expects an escalation path to the compliance function and governing body. The investigation process should define who investigates when seniority creates a conflict, including provision for external investigators where necessary.
Look for accreditation from a recognised IAF member — EIAC, ENAS, GAC in Saudi Arabia, UKAS or ANAB — with ISO 37001 in the accreditation scope. Because this is a specialised standard, accreditation scope availability is narrower than for ISO 9001, and we confirm this during scoping.
No, but joint venture partners are business associates requiring due diligence, and where you exercise control or influence, your ABMS should extend appropriate expectations to the venture. Where you hold a minority position without control, the standard recognises your influence is limited and expects proportionate action rather than the impossible.
Certification is evidence of organisational adequate procedures; it does not confer personal immunity, and no consultant should suggest otherwise. Individual liability depends on the conduct and knowledge of the individual and on the applicable law. This is a question for your legal advisers rather than your ISO consultant.
Risk-proportionate, but as a working principle: high-risk business associates reviewed annually, medium-risk every two to three years, and all tiers re-screened on trigger events such as contract renewal, ownership change, adverse media, or a material change in the relationship. A single check at onboarding provides diminishing assurance across a multi-year relationship.
Yes, included in our full implementation programmes and available standalone. We also deliver compliance function training and scenario-based commercial team workshops, which are often the more valuable capability for an organisation with an active agent network.
By running the due diligence refresh cycle, maintaining the gifts and hospitality register, keeping the whistleblowing channel active and responsive, updating the bribery risk assessment when you enter new markets or engage new agents, delivering refresher training, and holding management review on schedule. A risk assessment that has not moved despite entry into a new market is a common surveillance finding.





















0
Projects
0
Services
0
Clients Serving
0
Countries Serving