Developed and published by the International Organization for Standardization in 2021, this standard provides guidance for establishing, developing, implementing, evaluating, maintaining, and improving an effective and responsive risk-based compliance management system within an organization. The guidelines on compliance management systems are applicable to all types of organizations. The extent of the application of these guidelines depends on the size, structure, nature, and complexity of the organization. ISO 37301 is based on the principles of good governance, proportionality, transparency, and sustainability.
Managing compliance goes beyond the mere satisfaction of legal requirements. Compliance is also related to meeting the needs and expectations of a wide range of stakeholders. Therefore, making sound choices and setting priorities appropriately is an important part of effective compliance management. The standard takes a risk-based approach to manage compliance. As a result, it aligns with ISO 31000 Risk Management – Principles and guidelines, which according to ISO, “provides principles, framework and a process for managing risk.” In conjunction with ISO Standard 31000 (Enterprise Risk Management), This standard is used to establish a formal enterprise-wide management system for Governance, Risk, and Compliance (GRC) that will effectively and measurably improve organizational performance. Since such a program is designed and operated to well-recognized international standards of best practices for GRC, the organization also achieves greater confidence and respect among stakeholders including investors, lenders, regulators, suppliers, customers, and trading partners just to name a few.
ISO 37301 integrates risk assessments, the risk management process, and compliance management. By following ISO risk management practices, organizations embed compliance within the risk-based process. This is an important characteristic of effective compliance management because it breaks down silos and allows the organization to focus on root-cause risks. This streamlines the compliance process, making it easier to meet the obligations of not only government entities, but the host organization’s own internal code of ethics and its social responsibility objectives.