ISO published the second edition of ISO 37001 in February 2025. To understand what changed without adding requirements, the governing transition document is IAF MD 30:2025. It lists the main changes and sets the timetable to be followed by accreditation and certification bodies covered by the IAF MLA agreement.
What changed according to the mandatory transition document
| Change listed by IAF | Auditor's interpretation |
|---|---|
| Subclauses on climate change and emphasis on compliance culture | Verify relevance, responsibilities, observed conduct and consistency between messages, incentives and controls. |
| Treatment of conflicts of interest | Examine the identification, declaration, assessment, treatment and monitoring of specific situations. |
| Clarification of the anti-bribery function | Distinguish actual independence, authority, access and responsibilities from a nominal appointment. |
| Harmonisation of the text with other standards | Integrate common processes without erasing the specific risks and controls of the anti-bribery system. |
| Adoption of the latest harmonised structure | Update the system and its evidence to reflect the current edition, rather than merely renumbering documents. |
IAF MD 30 does not present a general expansion of third-party categories or an explicit requirement concerning bribery facilitated by artificial intelligence as changes. These risks may be relevant in a specific assessment, but they must not be attributed to the 2025 edition without support from the applicable normative text.
The accredited transition has precise dates
IAF MD 30 stipulates that accredited initial certification and recertification must be conducted exclusively against ISO 37001:2025 from 31 August 2026 at the latest. The transition of certified clients must be completed by 28 February 2027, through a scheduled audit—for example, surveillance or recertification—or a special transition audit. Accredited certifications to the previous edition cease to be valid after that date.
Additional audit time is not universal. The certification body must determine and justify it based on changes to the system and how it conducts the transition. The timetable is common; the duration of the assessment depends on evidence and context.
Law 27.401 · three simultaneous conditions for exemption
Law 27.401 establishes criminal liability for legal entities for the offences included in Article 1. Article 8 lists factors for determining penalties, including internal rules and procedures, oversight, spontaneous reporting, subsequent conduct and reparation. Article 9 governs a different matter: exemption from penalties and administrative liability.
For this exemption to apply, three circumstances must exist simultaneously: spontaneous reporting arising from the entity's own detection and investigation activities; an adequate control and supervision system, implemented before the act and under the terms of Articles 22 and 23; and the return of the undue benefit. A certified system can provide evidence of its design and operation, but the law neither requires ISO 37001 nor makes the certificate an automatic exemption.
What should be finalised now
If the organisation is certified against the 2016 edition, it must obtain the transition plan, audit date and anticipated audit time from its certification body; it must then map IAF's five groups of changes against actual controls and records. If it uses ISO 37001 to support its integrity programme, it must maintain a separate matrix distinguishing the standard's requirements from those of Law 27.401. Traceability offers more protection than a hasty assumption of equivalence.