
Explore the basics of a compliance management system under iso 37301:2021, for compliance professionals, including structure, purpose, and guidance, and learn how noncompliance drives organizational compliance.
Discover a compliance management system aligned with iso 37301, detailing compliance obligations, risks, controls, responsibilities, and how the pdca cycle guides planning, doing, checking, and acting to mitigate noncompliance.
Explore the possible consequences of noncompliance, including reputational disasters, large fines, and criminal proceedings, illustrated by Airbus and Volkswagen, and learn how a better compliance management system mitigates risks.
Understand the purpose and structure of ISO 37301:2021, a compliance management standard for all organizations. Replaces ISO 19600 and offers Annex A guidelines to implement the system.
Identify internal and external issues relevant to the organization's purpose and the compliance management system, and monitor how they affect the system's ability to achieve its intended outcomes.
Identify relevant interested parties and determine their requirements for the ISO 37301:2021 compliance management system. Monitor evolving needs and decide which requirements to address, keeping documentation to support audit readiness.
Define the boundaries of the compliance management system by considering internal and external context, obligations, and risks, then document the scope and adjust it if needed across the organization.
Learn how to establish, implement, and continually improve a compliance management system under ISO 37301, integrating processes, policies, procedures, and a risk assessment process to prevent, detect, and remediate noncompliance.
Identify systematically and assess mandatory and voluntary compliance obligations under ISO 37301 using a risk-based approach, and maintain an up-to-date register of obligations with their impacts and controls.
Identify, analyze, and evaluate compliance risks using a flexible risk assessment methodology; quantify probability and consequences to classify risks and guide actions, controls, and resource allocation.
Address compliance risks through avoidance, sharing, acceptance, or mitigation, assess residual risk after controls, and plan periodic reassessment for outsourced processes and changing contexts.
Demonstrate leadership and commitment to the ISO 37301 compliance management system, clause 5, by aligning top management and the governing body, integrating the system into processes, and enabling whistleblowing.
Embed a compliance culture by leadership commitment, clear values, induction and ongoing training, open communication, fair noncompliance handling, and a performance appraisal system aligned with ISO 37301:2021.
Understand compliance governance as the system that directs and holds an organization accountable, with direct access of the compliance function to the governing body, independence, authority, competence, and adequate resources.
The course explores how a compliance policy expresses leaders' commitment within the compliance management system, defines objectives, aligns with strategy, and guides implementation, communication, and continual improvement.
Governing body and top management assign, supervise, and allocate resources for compliance, integrate it into performance appraisals, and encourage reporting while all managers and personnel engage with the compliance function.
Explore the compliance function under ISO 37301, including roles, authority, and independence; learn how the function identifies obligations, conducts risk assessments, monitors performance, ensures training, and coordinates audits and reporting.
Explore how ISO 37301's planning stage identifies risks and opportunities for the compliance management system itself, not compliance risks, and requires actions to address them with management involvement.
Learn how ISO 37301 requires organizations to set objectives aligned with policy, make them measurable with KPIs, document and communicate them, and plan resources, actions, and timelines to achieve compliance.
Learn how to plan and control changes to a compliance management system under ISO 37301, considering purpose, consequences, resources, allocation of responsibilities, outsourcing or insourcing, and strategies to avoid noncompliance.
Explore ISO 37301's resources requirement, mandating providing people, time, money, external advice, training, technology, and infrastructure to establish, implement, maintain, and continually improve compliance management system, led by top management.
Define competence and implement an employment process to ensure all personnel and third parties have needed knowledge, skills, and compliance training, with documented records and ongoing due diligence.
Raise compliance awareness by clarifying responsibilities and authorities, outlining acceptable behavior, and enabling contributions to the organization's compliance performance through training and ongoing top-level communication.
Coordinate internal and external communication to share and receive information on compliance with diverse audiences, enable whistleblowing. Maintain two-way internal communication that raises concerns and retains documented information as evidence.
Explore ISO 37301's documented information framework for a compliance management system, distinguishing required vs. supplementary documents and detailing identification, language considerations, and review and approval processes.
Explore how ISO 37301 requires controls for documented information—procedures, policies, and records—ensuring availability, protection, and proper access, versioning, and retention, including external documents.
Plan, implement, and control processes to meet requirements and address compliance risks and objectives, using a code of conduct and documented information, with controls for changes and external providers.
Explore how organizations establish and maintain controls and procedures to manage compliance obligations and risks. See examples like segregation of duties, documented procedures, automation, and testing to ensure effective compliance.
Present a visible whistleblowing procedure under ISO 37301, enabling anonymous reports, protection from retaliation, confidential handling, guidance on reporting rights, and escalation.
Explore how ISO 37301:2021 requires an investigation process to assess, evaluate, investigate, and close reports of noncompliance with fairness and independence, and use findings to improve the compliance management system.
Explore how organizations monitor and measure their compliance performance and management system, analyze results, and use documented information to evaluate the effectiveness of training, controls, and responsibility allocation.
Identify sources of feedback on compliance performance from personnel, customers, suppliers, contractors, authorities, and regulators, and establish processes to seek, classify, analyze, and act on feedback to update risk assessments.
Develop and maintain indicators to monitor and evaluate compliance performance using key performance indicators aligned with organizational risks, such as training rates, regulator contacts, and noncompliance trends.
Learn to implement ISO 37301 compliance reporting and record-keeping, including ad hoc and regular reporting to management and regulators, with secure, accurate records.
Understand how internal audits assess conformity to ISO 37301 within the compliance management system. Establish an audit programme with planned intervals, determine objectives, scope, criteria, and actions for improvement.
Conduct a management review with top leadership to assess the compliance management system via inputs on issues, performance, nonconformities, and opportunities for improvement.
Explore how ISO 37301 handles nonconformities and noncompliances, guiding correction, cause analysis, and corrective actions to prevent recurrence, with documentation and trend analysis.
Learn about ISO 37301 certification for organizations and individuals, including audits by a competent certification body and yearly surveillance checks. Understand why self-certification is not credible.
Explore ISO 37301:2021 compliance management by reviewing all clauses and subclauses, understanding the requirements, and learning how an organization can comply.
ISO 37301 is the international standard for compliance management systems (CMS) — the certifiable framework that helps organizations identify their compliance obligations, assess and treat compliance risks, and build a culture of integrity. It applies to any organization, in any industry, and it has become the global reference point for structuring corporate compliance programs.
Every organization in the world has compliance obligations, the regulatory landscape changes constantly, and the consequences of noncompliance — fines, prosecutions, lost contracts, reputational damage — can be catastrophic. A systematic approach to compliance management is how organizations keep up. This course teaches you that approach, requirement by requirement.
What the course covers
The course follows the structure of ISO 37301:
Foundations — what a compliance management system is, the purpose and structure of ISO 37301, and who can use it
Context of the organization — identifying compliance obligations and conducting the compliance risk assessment
Leadership and the compliance function — why senior management support is critical, the requirements for the compliance policy, and the role and responsibilities of the compliance function (the compliance officer and compliance team)
Planning — compliance objectives, plans to achieve them, and the risks and opportunities relevant to the CMS
Support and operation — the controls that ensure compliance requirements are met, supporting documentation, competence, training and awareness, and the whistleblowing system: how employees raise concerns and how reports must be investigated
Performance evaluation and improvement — internal audits of the CMS, the management review, and managing nonconformities
The course closes with the certification paths — how an organization achieves ISO 37301 certification, and how compliance professionals can certify their own competence.
Who this course is for
Compliance officers, compliance managers and members of compliance teams
Legal, risk and internal audit professionals whose work intersects with regulatory compliance
Managers and business owners who need to understand what an effective compliance program looks like
ISO management system professionals (ISO 9001, ISO/IEC 27001, ISO 37001) adding compliance management to their scope
Anyone building a career in governance, risk and compliance (GRC) or ethics and compliance
After completing the course you will have a solid understanding of what a compliance management system is and how an organization meets the requirements of ISO 37301 — knowledge you can apply to implement a CMS, support certification, or advance your compliance career.