ISO 37301 sets out the requirements and provides guidelines for establishing, developing, implementing, evaluating, maintaining, and improving an effective compliance management system (CMS) within an organization.
Leadership should promote compliant behavior within the organization based on the organization’s core values and the implementation of the required measures to foster such behavior. This ensures a positive culture of compliance in line with ISO standards.
When jurisdictions have occurred in an organization, many courts have considered the organization’s commitment to compliance based on their Compliance Management System (CMS) before deciding on the appropriate penalty to be imposed for contraventions of relevant laws and regulations. Thus, not only organizations but also regulatory and judicial bodies can benefit from this standard as a benchmark for good governance and proportionality.
This standard is intended to be adaptable, and implementation can differ depending on the size and level of maturity of an organization’s compliance management system and on the context, nature, and complexity of the organization’s activities and objectives. It promotes continuous improvement to ensure the effective compliance management systems are maintained and aligned with evolving ISO 37301:2021 requirements.
– Source: Howard Shaw, Chair of the ISO technical committee on Governance (ISO TC 309)