ISO 37301:2021 – Compliance Management Systems – Requirements with Guidance for Use

SmartSuite provides the system for managing controls, evidence, mappings, assessments, and reporting. Framework text may require a separate license unless explicitly provided.
Overview
ISO 37301:2021, Compliance management systems – Requirements with guidance for use, is the international standard for a compliance management system (CMS). It specifies the requirements and provides guidance for establishing, developing, implementing, evaluating, maintaining, and improving an effective and responsive compliance management system, so that an organization can identify its compliance obligations and demonstrate that it meets them.
The International Organization for Standardization (ISO) published the first edition in April 2021 through technical committee ISO/TC 309, Governance of organizations. It replaced ISO 19600:2014, the earlier guideline-only standard, and because it contains requirements rather than guidance alone, an organization can be certified against it. The standard is voluntary and applies to organizations of any size, type, and sector, in the public, private, and nonprofit spheres.
Organizations implement ISO 37301 by identifying their compliance obligations and the risks of failing to meet them, securing governing-body and top-management commitment, assigning a compliance function with the authority and resources to act, and running the planning, support, operation, performance evaluation, and improvement cycle that the standard shares with other ISO management system standards. Certification bodies audit that cycle, and many organizations integrate the CMS with their quality, information security, and anti-bribery management systems.
Why it Matters
Compliance obligations now reach every function of an organization, from privacy and sanctions to product safety and anti-bribery, and regulators, customers, and courts increasingly ask whether a compliance program is designed and operating effectively. ISO 37301 gives that question a recognized answer: a management system with defined obligations, controls, roles, and evidence that an independent body can certify.
Key benefits include:
- Demonstrable compliance governance
Certification against ISO 37301 gives boards, regulators, and business partners independent evidence that the compliance program is designed, resourced, and reviewed.
- One system for every obligation
The standard treats legal, regulatory, contractual, and voluntary commitments alike, so an organization keeps a single register of obligations instead of parallel programs.
- Risk-based effort
Compliance risk assessment directs controls and monitoring to the obligations most likely to be breached and most damaging if they are.
- A culture that reports and learns
Requirements for leadership, awareness, raising concerns, and investigation make compliance a shared responsibility rather than a back-office task.
- Fits alongside other ISO systems
The harmonized structure lets the CMS share policies, audits, and management reviews with ISO 9001, ISO/IEC 27001, and ISO 37001 systems.
How it Works
ISO 37301 follows the harmonized structure used by ISO management system standards. Clause 4 requires the organization to understand its context, interested parties, and compliance obligations and to define the scope of the CMS; Clause 5 sets leadership, governance, policy, and role requirements, including an independent compliance function; Clause 6 covers planning, with compliance risk assessment and objectives; Clause 7 covers support, including resources, competence, awareness, communication, and documented information; Clause 8 covers operation, including controls and procedures, raising concerns, and investigation processes; Clause 9 covers performance evaluation through monitoring, measurement, internal audit, and management review; and Clause 10 covers nonconformity, corrective action, and continual improvement. Guidance for applying each requirement sits in Annex A.
Implementation starts with a register of compliance obligations and a compliance risk assessment that rates the likelihood and consequence of each failure. The organization then designs controls, assigns owners, trains staff, and establishes channels for raising concerns. Monitoring, indicators, internal audits, and management reviews test whether the system is working, and nonconformities feed corrective action. When the system is mature, an accredited certification body audits it against the standard, typically over a three-year cycle of initial audit, surveillance, and recertification.
Within SmartSuite, teams manage the ISO 37301 cycle as connected records: obligations link to the risks they carry, the controls that address them, the owners responsible, and the evidence that shows each control operated. Compliance risk assessments, monitoring results, internal audit findings, and management review actions live in the same workspace, so the certification audit trail is built as the work happens.
Key Elements
- Compliance obligations register
The organization identifies its legal, regulatory, contractual, and voluntary obligations, keeps them current, and assesses the compliance risks of failing to meet them.
- Governing body and top management commitment
Leadership is required to establish the compliance policy, provide resources, and hold the organization accountable, with the governing body overseeing the CMS.
- Independent compliance function
A compliance function with defined responsibilities, authority, independence, and direct access to the governing body coordinates the system.
- Controls and procedures
Operational controls address the obligations and risks identified, supported by documented procedures and third-party due diligence.
- Raising concerns and investigation
The organization maintains processes that let people raise concerns without fear of retaliation and that investigate and resolve suspected noncompliance.
- Performance evaluation
Monitoring, measurement, indicators, internal audit, and management review test the design and operation of the system.
- Continual improvement
Nonconformities and noncompliances are analyzed for root cause and corrected, and the system is improved over time.
Framework Scope
ISO 37301 applies to any organization, regardless of size, type, or sector, that wants to establish, operate, and improve a compliance management system. It covers the organization's full range of compliance obligations rather than a single subject, which distinguishes it from ISO 37001, which addresses anti-bribery management alone. The standard is written so that it can be implemented on its own or integrated with other ISO management systems, and its requirements are the basis for third-party certification.
Framework Objectives
ISO 37301 exists so that organizations can meet their obligations consistently and show that they do.
Identify and keep current the organization's compliance obligations and the risks of not meeting them.
Establish leadership commitment, a compliance policy, and an independent compliance function with adequate authority and resources.
Design and operate controls that address compliance risks in proportion to their significance.
Build a compliance culture in which people are aware of their responsibilities and can raise concerns safely.
Evaluate performance through monitoring, internal audit, and management review, and act on the findings.
Provide a basis for independent certification that stakeholders can rely on.
Framework in Context
ISO 37301 is the generic compliance standard in the ISO/TC 309 governance family, which also includes ISO 37001 for anti-bribery management systems and ISO 37000 for the governance of organizations. Its harmonized structure aligns it with ISO 9001, ISO/IEC 27001, ISO 22301, and ISO/IEC 42001, and its compliance risk assessment draws on the principles of ISO 31000. In practice it sits alongside the COSO Internal Control and Enterprise Risk Management frameworks and supports the compliance program expectations behind laws such as the Sarbanes-Oxley Act.
Common Framework Mappings
ISO 37301 is commonly mapped to the other ISO management system standards it shares a structure with and to the governance and risk frameworks that define compliance program expectations.
Mapped frameworks include:
ISO 9001:2026
ISO 27001:2022
ISO 22301
ISO 42001
ISO 31000:2018
COSO IC 2013
COSO ERM 2017
SOX
ISO 37001
- ClassificationCategoryCompliance / Assurance StandardDomainRisk ManagementFramework FamilyISO Management Systems
- Regulatory ContextTypeStandardLegal InstrumentStandardSectorCross-SectorIndustryCross-Industry
- Region / PublisherRegionGlobalRegion DetailInternationalPublisherInternational Organization for Standardization (ISO)
- VersioningVersion2021 (Edition 1)Effective DateApril 2021Issue DateApril 2021
- AdoptionAdoption ModelCertificationImplementation ComplexityMedium
- Official ReferenceOpen Link in New TabSource
License included / downloadable: No
ISO 37301:2021 is sold by ISO and its national member bodies, and its text is not included with the platform.
Framework text is licensed by its publisher and is included only where stated above.
How SmartSuite Supports ISO 37301
SmartSuite provides the system for managing controls, evidence, mappings, assessments, and reporting.
For ISO 37301, SmartSuite links every compliance obligation to its risk rating, controls, owner, and evidence, and runs the monitoring, internal audit, and management review cycle that certification auditors expect to see.
Compliance Obligations Register
Hold legal, regulatory, contractual, and voluntary obligations with their sources, applicability, and compliance risk ratings in one structured library.
Ownership, Cadence, and Accountability
Assign each obligation and control an owner and a review schedule, and route governing-body and management reviews through approval workflows.
Evidence Collection and Audit Trail
Attach policies, training records, and monitoring results to controls with timestamps and reviewers so the certification audit trail is always current.
Control Testing and Internal Audit
Plan Clause 9 monitoring and internal audits, record findings, and track nonconformities to closure.
Risk and Third-Party Alignment
Link compliance risks to enterprise risks and to the third parties whose conduct creates exposure, including due diligence records.
Compliance Reporting
Report compliance performance, open concerns, and corrective actions to the governing body and top management.
Related frameworks

ISO 31000 provides guidelines for identifying, assessing, and managing organizational risks to improve resilience and decision-making.

ISO 9001:2026 sets requirements for a quality management system that helps organizations consistently deliver products and services that meet customer and regulatory requirements.

ISO/IEC 27001:2022 is an international ISMS standard that helps organizations manage information security risks and protect data.

ISO/IEC 42001 is an AI management system standard for managing AI risk, ethics, security, and regulatory compliance.

ISO 22301 is a business continuity management standard helping organizations prepare for, respond to, and recover from disruptions.
Frequently Asked Questions For ISO 37301
ISO 37301:2021 is the international standard for compliance management systems. It specifies requirements and gives guidance for establishing, developing, implementing, evaluating, maintaining, and improving a compliance management system, so that an organization can meet its obligations and demonstrate that it does.
Yes. Unlike its predecessor ISO 19600, which contained guidance only, ISO 37301 is a requirements standard, so accredited certification bodies can audit and certify an organization's compliance management system against it.
ISO 37001 addresses anti-bribery management systems specifically, while ISO 37301 covers the organization's full range of compliance obligations. Many organizations run both within one integrated management system.
ISO 37301:2021 replaced ISO 19600:2014, which has been withdrawn. The new standard kept the compliance management approach of ISO 19600 but turned it into auditable requirements with guidance in Annex A.
ISO published it in April 2021 through technical committee ISO/TC 309, Governance of organizations. It is voluntary and applies to organizations of any size, type, and sector.
Top management must establish the compliance policy, provide resources, and demonstrate commitment, and the governing body must oversee the system. The organization must also appoint a compliance function with the independence, authority, and access it needs.
SmartSuite holds the compliance obligations register, risk assessments, controls, evidence, concerns, internal audit findings, and management review actions in one connected workspace, so the certification audit trail is built as the work happens.
Manage controls, risks, evidence, and audits in one platform designed for modern governance, risk, and compliance.

