ISO 37301:2021 — Compliance Management
The international standard for compliance management systems — audited and certified by CAS per ISO/IEC TS 17021-13:2021. Demonstrating systematic compliance governance across legal, regulatory, and contractual obligations.
Standard
ISO 37301:2021
Service type
By CAS
Issued under
CAS — own authority
Standards & technical basis
Certified standard
ISO 37301:2021
Certification-body competence
ISO/IEC 17021-1:2015 · ISO/IEC TS 17021-13:2021
CAS audits and certifies to the requirements of ISO/IEC 17021-1:2015 and ISO/IEC TS 17021-13:2021 — which sets the competence requirements for auditing and certification of compliance management systems.
Mark & recognition
Issued by CAS under its own authority — carries the CAS mark and does not bear the EGAC or IAF marks.
What it is
ISO 37301:2021 specifies requirements and provides guidelines for establishing, developing, implementing, evaluating, maintaining, and improving an effective compliance management system (CMS) within an organisation. It replaced ISO 19600:2014 (Compliance management systems — Guidelines) with a fully certifiable requirements-based standard. ISO 37301:2021 is audited and certified per ISO/IEC TS 17021-13:2021, which specifies competence requirements for auditing and certification of compliance management systems. The standard covers all types of compliance obligations — legal, regulatory, industry codes, contractual commitments, and ethical standards — providing a systematic framework for compliance risk identification, assessment, and control.
Who needs it
Financial institutions, banks, and regulated financial services; pharmaceutical and healthcare companies; public sector organisations and government entities; multinational corporations with complex regulatory environments; any organisation seeking to demonstrate systematic compliance governance to regulators, investors, and customers.
Benefits of certification
- Internationally recognised compliance management system certification
- Audited and certified per ISO/IEC TS 17021-13:2021 — the dedicated CMS audit standard
- Demonstrates systematic compliance governance to regulators and investors
- Covers all compliance obligation types: legal, regulatory, contractual, ethical
- Reduces risk of regulatory violations, fines, and reputational damage
- Replaces ISO 19600:2014 — now a fully certifiable requirements-based standard
- Integrates with ISO 37001 (anti-bribery), ISO 9001, and other management systems
- ISO Harmonized Structure enables easy integration with other ISO MSS
Frequently asked questions
Common questions
What is the difference between ISO 37301 and ISO 37001?
ISO 37001 addresses specifically anti-bribery management systems. ISO 37301 is broader — it covers all types of compliance obligations including legal, regulatory, contractual, and ethical requirements across the whole organisation. The two standards are designed to be complementary and can be implemented together as an integrated compliance and anti-bribery system.
What replaced ISO 19600?
ISO 37301:2021 replaced ISO 19600:2014. The key change is that ISO 37301 is a requirements-based standard (using "shall") making it certifiable, whereas ISO 19600 was a guidelines-based standard (using "should") and was not certifiable. ISO 19600 was withdrawn upon publication of ISO 37301.
What audit standard applies to ISO 37301 certification?
ISO/IEC TS 17021-13:2021 specifies the competence requirements for auditing and certification of compliance management systems per ISO 37301. CAS applies this technical specification for all ISO 37301 certification audits.
Who benefits most from ISO 37301 certification?
Organisations in heavily regulated industries — banking, financial services, pharmaceuticals, healthcare, and public sector — gain the most direct value. However, any organisation wishing to demonstrate systematic compliance governance and reduce regulatory risk can benefit from ISO 37301 certification.
Ready to certify against ISO 37301:2021?
Send us a brief description of your organisation — we’ll come back with a quotation within one working day.
Request a quotation →