EDIH, EEN, Interreg: the platform for European programmes.Find out more

ISO 37001 Maturity · Anti-bribery Management Systems

Your anti-bribery framework, benchmarked against ISO 37001 and turned into a costed action plan.

10 themes, a 5-level scale. And the action that moves each level to the next.

The framework’s 10 themes, already written from L1 to L5. One company, one business unit, or 300 at once.

ISO 37001 Maturity · Anti-bribery Management Systems

Leadership commitment and governanceN1 → N5
Anti-bribery compliance functionN1 → N5
Bribery risk assessmentN1 → N5
Policy, code of conduct and proceduresN1 → N5

10 themes, 5-level scale.

Nordhavn Industries

53 / 100

Leadership commitment and governance6484
Anti-bribery compliance function5379
Bribery risk assessment6182
Policy, code of conduct and procedures3773
IAIndustrialised: your interview notes are enough, the AI fills in the audit.

They measure their maturity with Datamensio

  • CNES
  • Docaposte
  • ANITI
  • Pôle SCS
  • Cetim
  • Cap'Tronic

An example

This could be your situation.

Take one company as an example: three sites, three spreadsheets, no shared answer.

01

Nobody can consolidate.

Nordhavn Industries, 2,400 people in Hamburg, Lyon and Porto. A client asks where the group stands. Each site answers in its own spreadsheet, with its own scales.

02

Three weeks, a single base.

One ISO 37001:2016 assessment launched across all three sites at once, from the managers’ interview notes. The framework was already written, its 10 themes and levels L1 to L5 too.

03

Two costs avoided before being committed.

A score of 53 out of 100, with the gap concentrated on three themes. The AI companion spotted that two actions duplicated those of another audit. The committee report took one sentence to request.

What it saved them

  • 3sites measured on the same base, instead of three questionnaires to reconcile
  • 2duplicate actions caught before the spend
  • 1committee report, with no manual rework

These figures are an example. They could be yours.

The standard imposes processes. Datamensio says where you stand.

01

The framework is already written

Themes, questions and levels L1 to L5, all written. You do not start from an empty spreadsheet.

02

The score lands the same day

Online, by self-assessment link or in interview. Theme by theme, comparable over time.

03

The gap becomes a costed plan

Every step up carries its action. The AI prioritises on expected effect, not on the order of the standard.

04

Progress can be demonstrated

Campaign after campaign, against your target and against your own past. That is what your board asks for.

The maturity scale

One level, the next, and the action that links the two.

This mechanism, one level, the next level up, and the action linking the two, is what turns a finding into a trajectory.

Is due diligence on business associates proportionate to the level of risk?

  1. N1

    No structured vetting before entering into a relationship. Third parties are onboarded based on operational needs.

  2. N2

    Checks exist for some major contracts, at the initiative of teams, with no common trigger criteria.

  3. N3

    Third parties are segmented by risk level and a vetting level is defined for each segment. The procedure is generally applied, with occasional gaps.

  4. N4

    Due diligence is systematic, recorded in a file per third party, with anti-bribery contractual clauses and formal validation of sensitive cases by the compliance function.

  5. N5

    High-risk third parties undergo periodic review and ongoing monitoring throughout the relationship. Segmentation criteria are re-examined based on incidents and changes in the portfolio.

Action to move from L2 to L3

Define three third-party risk levels with their trigger criteria, embed them in the supplier onboarding form within the procurement tool, and verify their application on new relationships during the quarterly compliance committee.

« With Datamensio, we meet our objectives far more efficiently. The ERDF inspection services and our supervising ministry particularly appreciated an approach that gives them reliable data. »
Chambre de commerce et d'industrie

Director, CCI 94CCI Île-de-France

« We believe this is the most suitable solution to scale our transformation project and measure impact according to our needs. »
Interreg Danube Region

Maja SucekChief Operating Officer, Interreg Danube

Take your first measurementon ISO 37001.

What this framework covers

ISO 37001 is a certifiable management system standard, published in 2016, dedicated to preventing, detecting and addressing bribery. It covers active and passive bribery, direct and indirect, including bribery committed by business associates on the organisation’s behalf. It requires a defined core: an anti-bribery policy approved by the governing body, an anti-bribery compliance function with authority and independence, a documented bribery risk assessment, proportionate due diligence on third parties, financial and non-financial controls, training, a reporting and investigation procedure, and management review.

In practice, the framework is difficult to steer because its components sit with different departments. Bribery risk mapping belongs to compliance, controls to finance, due diligence to procurement, training to human resources. Three questions come up repeatedly. Is the risk map actually used to calibrate controls, or does it remain an annual document? Is due diligence on third parties proportionate to risk, or applied uniformly for lack of criteria? Are reports handled with a traceable process, including a decision and feedback, or do they stop at the inbox?

In France, ISO 37001 intersects with the Sapin II law, whose article 17 lists eight pillars, and with the recommendations of the French Anti-corruption Agency (AFA). The two frameworks overlap substantially but are not equivalent: Sapin II is legally binding and enforced by the AFA, whereas ISO 37001 is voluntary and certifiable by an accredited body. A common misconception is that ISO 37001 certification amounts to a presumption of compliance with Sapin II. It does not. It provides an element of organisation and evidence, useful but distinct.

The maturity assessment answers a different question from the certification audit. The audit checks the presence and effectiveness of requirements, then concludes with a compliance or a gap finding. The assessment places each practice on a progressive scale and points to the specific action that moves it to the next level. It is conducted upstream, with no verdict at stake, and produces a trajectory rather than a finding. In Datamensio, the gap between the score and the target directly generates the action plan, which the AI groups into a prioritised roadmap.

The framework is ready to use and adaptable. You can amend the themes, questions and levels, or ask the AI to build a tailored version from your code of conduct, your risk map and your existing procedures. Entities within the same group can be assessed on the same grid, then compared against each other and over time.

Reference standard: ISO 37001:2016

The themes assessed

  • Leadership commitment and governance

    Policy approval by the governing body, leadership example and communication, allocated resources, management review, board reporting.

  • Anti-bribery compliance function

    Appointment, scope, authority and independence, direct access to the governing body, skills and resources, coordination with subsidiaries.

  • Bribery risk assessment

    Mapping by activity, geography and third-party type, scoring method, update frequency, actual use to calibrate controls.

  • Policy, code of conduct and procedures

    Rules on gifts and hospitality, sponsorship and patronage, facilitation payments, conflicts of interest, political contributions, local rollout.

  • Third-party due diligence

    Segmentation of business associates, vetting levels, anti-bribery contractual clauses, audit rights, traceability of decisions and periodic review.

  • Financial and non-financial controls

    Segregation of duties, authorisation thresholds, control of payments and expense claims, tendering and supplier selection, hiring for exposed roles.

  • Training and awareness

    Targeting by exposure, content adapted to real situations, frequency, tracking of completion rates, awareness for business associates.

  • Reporting and investigation

    Accessible whistleblowing channel, whistleblower protection, confidentiality, handling timelines and traceability, conduct of investigations, disciplinary and corrective follow-up.

  • Monitoring, indicators and internal audit

    Framework performance indicators, dedicated internal audit plan, second-line controls, escalation of anomalies, tracking of corrective actions.

  • Continuous improvement

    Lessons learned from incidents and reports, updating of procedures, comparison of entities and progress over time, maturity of the framework itself.

A short version of the framework is available for the online self-assessment.

Frequently asked questions

Is ISO 37001 certifiable?

Yes, by an accredited certification body. The Datamensio assessment is not a certification and does not stand in for one: it measures the maturity of your framework, identifies gaps and prepares you for the audit. The certification decision rests solely with the certification body.

What is the difference between this assessment and a certification audit?

The audit checks requirements one by one and concludes with a compliance or a gap finding. The assessment places each practice on a maturity scale and points to the action that moves it to the next level. The two are complementary: the assessment prepares, the audit validates.

Is ISO 37001 enough to meet the requirements of the Sapin II law?

No. The two frameworks overlap substantially, notably on risk mapping, the code of conduct, the whistleblowing channel and accounting controls, but Sapin II is legally binding and enforced by the AFA. Certification is an element of organisation and evidence, not a presumption of compliance.

How long does the assessment take?

The short version can be completed in a single working session. The full version, run collaboratively with compliance, procurement, finance and human resources, typically takes one to two weeks, most of the time being spent gathering input from the various departments.

Can the framework be adapted to our organisation?

Yes. You can amend the questions, levels and themes, or start from a blank slate. The AI can also build a tailored version from your code of conduct and your procedures. The framework is yours.

How do we compare several subsidiaries on the same framework?

The same framework is rolled out to each business unit, then scores are compared by theme and over time. A cross-entity roadmap consolidates the assessments to distinguish local fixes from issues requiring a group-level decision.

Is legal expertise required to complete the assessment?

The questions concern management practices, not legal qualification. A compliance officer or internal auditor can answer them. Some questions fall under procurement or finance: the collaborative mode allows them to be assigned to the right contributor.

Where is the data hosted?

In France, with OVH, backed up with Scaleway. No transfer outside the European Union. The AI models used can be selected, including from European providers.

Take your first measurementon ISO 37001.