Udemy
    •  
    •  
    •  
    •  
    •  
    •  
    •  
    •  
Turn what you know into an opportunity and reach millions around the world.
Learn More
Your cart is empty.
Keep shopping
ISO 37301:2021 Compliance Management Systems
Role Play
Rating: 3.6 out of 5(10 ratings)
116 students

ISO 37301:2021 Compliance Management Systems

Master the global standard for compliance management — from Clause 4 context to Clause 10 improvement and certification
Created byISO Horizon
Last updated 6/2026
English

What you'll learn

  • Apply every clause of ISO 37301:2021 from context (Clause 4) through improvement (Clause 10)
  • Build a compliance obligations register and conduct a defensible compliance risk assessment
  • Design a compliance function with the independence, authority, and reporting lines ISO 37301 demands
  • Establish good faith reporting channels with strong non-retaliation protections
  • Run credible investigations that withstand regulatory and legal scrutiny
  • Implement risk-based third-party due diligence across vendors, distributors, and intermediaries
  • Prepare for Stage 1 and Stage 2 certification audits and manage surveillance cycles
  • Integrate ISO 37301 with ISO 37001 anti-bribery and other management system standards
  • Transition cleanly from ISO 19600 guidance to ISO 37301 certifiable requirements
  • Foster a measurable culture of compliance using behavioral science and culture metrics

Course content

24 sections33 lectures
  • What Is ISO 37301 and Why It Matters9:46
    This lecture introduces ISO 37301:2021, the international standard for compliance management systems (CMS), published by ISO in April 2021. The student will learn what a CMS actually is, why ISO 37301 is classified as a Type A management system standard (meaning organizations can be certified against it), and how it provides a structured, auditable framework for identifying, preventing, detecting, and responding to compliance failures. The lecture explains the business case for adopting ISO 37301, including reduced regulatory enforcement risk, demonstrable due diligence, improved organizational reputation, lower insurance costs, and tangible signals to regulators, investors, and customers. It also positions compliance not as a cost center but as a value driver and explores the surge in demand for certified CMS programs across financial services, healthcare, energy, manufacturing, and the public sector.
  • From ISO 19600 to ISO 37301: The Evolution8:57
    This lecture traces the lineage from ISO 19600:2014, the original guidance standard for compliance management systems, to its successor ISO 37301:2021. The student will learn why ISO 19600 was deliberately written as a non-certifiable guidance document, why the market demanded a certifiable equivalent, and what concrete changes the technical committee introduced when upgrading it. Topics include the migration to the Harmonized Structure (formerly the High-Level Structure) used across all modern ISO management system standards, the addition of normative shall-clauses that make certification possible, expanded requirements around the independence and authority of the compliance function, sharper expectations on raising concerns and non-retaliation, and stronger language on compliance culture. The lecture also discusses what organizations already aligned with ISO 19600 must do to transition cleanly to ISO 37301.
  • Core Principles of an Effective Compliance Management System9:54
    This lecture unpacks the principles that underpin every clause of ISO 37301: integrity, good governance, proportionality, transparency, accountability, and sustainability. The student will learn how these principles translate into design choices for a real CMS, including risk-based prioritization, the segregation of duties, the tone from the top, the freedom to raise concerns without fear, and the commitment to continual improvement through the Plan-Do-Check-Act cycle. The lecture grounds each principle in recognizable scenarios, such as how proportionality means a small nonprofit and a global bank can both achieve certification with very differently scaled systems, and how accountability is operationalized through documented roles, escalation paths, and board-level oversight. It also previews how each principle reappears throughout Clauses 4 through 10.
  • ISO 37301 and ISO 37001: How They Work Together10:11
    This lecture clarifies the relationship between ISO 37301 (compliance management systems) and ISO 37001:2016 (anti-bribery management systems), two standards that are often confused or treated as alternatives. The student will learn that ISO 37301 is the broad umbrella covering all compliance obligations an organization faces, while ISO 37001 is a deep, specialized standard focused exclusively on bribery risk. The lecture explains how the two share the same Harmonized Structure, making integration straightforward, and how an organization with mature ISO 37301 processes can layer ISO 37001 controls on top to address bribery-specific risks such as facilitation payments, gifts and hospitality, and third-party intermediaries. It also covers when to certify against one, the other, or both, and how regulators and prosecutors view each.
  • Section 1 Quiz: Foundations of ISO 37301:2021
  • Roleplay: Foundations of ISO 37301:2021

Requirements

  • Basic familiarity with corporate governance or organizational risk management concepts
  • General awareness of regulatory or legal obligations applicable to organizations
  • No prior knowledge of ISO standards or the Harmonized Structure required
  • Working English comprehension to follow regulatory terminology and definitions
  • Access to your organization's policies or compliance program documents will help you apply the concepts

Description

This course contains the use of artificial intelligence.

Regulatory pressure is at an all-time high, enforcement penalties are climbing into the billions, and stakeholders from boards to investors to employees expect organizations to demonstrate that compliance is more than a slogan. ISO 37301:2021 has emerged as the global benchmark for compliance management systems, replacing the earlier guidance-only ISO 19600 with a certifiable Type A standard that regulators, prosecutors, customers, and insurers increasingly recognize as credible evidence of good faith compliance efforts. Whether you are building a compliance program from scratch, modernizing a legacy framework, or preparing for certification, fluency in ISO 37301 has become an indispensable skill for compliance professionals.

This course provides comprehensive, clause-by-clause coverage of ISO 37301:2021, walking you through every requirement from the context of the organization (Clause 4) through leadership and the compliance function (Clause 5), planning and compliance risk assessment (Clause 6), support including competence, awareness, communication and documented information (Clause 7), operation including controls, raising concerns, investigations, and third-party due diligence (Clause 8), performance evaluation through monitoring, internal audit, and management review (Clause 9), and continual improvement (Clause 10). You will learn how to identify compliance obligations, design risk-based controls, build a credible speak-up culture with non-retaliation protections, conduct fair investigations, and prepare for the formal certification audit process.

This course is built for compliance officers, ethics and compliance managers, legal counsel, internal auditors, risk professionals, governance specialists, and anyone tasked with implementing or auditing a compliance management system. You will gain practical understanding of the relationship between ISO 37301 and ISO 37001 anti-bribery, the transition from ISO 19600, and how to integrate compliance with adjacent management systems. By the end you will be equipped to design, implement, monitor, and continually improve a CMS that withstands regulatory scrutiny and certification audits.

What makes this course different is its uncompromising focus on the actual text of ISO 37301 paired with the practical implementation wisdom regulators and certification auditors expect to see. Every lecture maps directly to a clause or topic the standard requires, and every concept is grounded in concrete examples drawn from regulated industries. Enroll now to gain the structured knowledge you need to lead compliance with confidence.

Who this course is for:

  • Compliance officers and chief compliance officers building or maturing a CMS
  • Ethics and compliance managers preparing for ISO 37301 certification
  • Legal counsel and regulatory affairs professionals advising on compliance frameworks
  • Internal auditors and risk professionals assessing compliance management systems
  • Governance professionals and board members overseeing compliance and ethics programs