ISO 37301: what a compliance management system actually contains

Ask most business owners what their compliance management system is and they will point at a shared drive full of policies. That is a filing cabinet, not a system. The international standard for the real thing, ISO 37301, published in 2021, describes something that moves: a loop that finds out what you are obliged to do, puts a name against each obligation, builds controls to meet it, and then checks and improves itself over time.1 You do not need to certify to the standard to use its structure, and the structure is genuinely useful.

00.20.50.811Know yourobligations1Assign themto owners1Control them1Check andimprove
A compliance management system is a loop, not a binder. Four moving parts. Indicative. Source: ISO 37301:2021

The four things a real system does

Underneath the clauses, a compliance management system does four jobs, and if any one is missing you have a binder, not a system. First, it knows your obligations: the laws, regulations, standards and promises you are actually bound by, kept current as they change. Second, it assigns them: every obligation has an owner who is accountable, not a vague reference to "the business". Third, it controls them: there is a specific control for each significant obligation, and someone checks the control works. Fourth, it improves: findings, incidents and changes feed back in, so the system gets better instead of drifting out of date.

Why the first job is the one everyone skips

The step almost every organisation is weakest on is the first: actually knowing, in one place, what you are obliged to do. Most firms have never written down their full obligation register. They know the big ones and discover the rest when a regulator points them out. You cannot control an obligation you have not identified, and you cannot prove you took it seriously if it was never on your list. Building that register, boring as it sounds, is the single highest-value move in the whole standard, because everything else hangs off it.

The solution, as a build checklist

Stand up a compliance management system in six moves

  • Write the obligation register: every law, regulation, standard and material promise you are bound by. Keep it current.
  • Assess the risk of each: how likely, how damaging, so you focus effort where it matters.
  • Assign an owner to each significant obligation, by name, who is accountable for it.
  • Put a control against each, and define how you would know the control is working.
  • Set the leadership and reporting: who sees what, how often, and who answers to the board or owner.
  • Close the loop: feed incidents, findings and legal changes back in, and review on a schedule.

The part the standard insists on: leadership

ISO 37301 is unusually blunt that a compliance system cannot be delegated to a corner office and forgotten. Leadership has to set the tone, provide the resources, and be seen to back the compliance function even when it is inconvenient. This is the standard formalising what every failure case teaches: a compliance system with no real authority behind it becomes theatre. The clauses about leadership are not filler. They are the standard admitting that structure without backing does nothing.

Questions to test your compliance system

  • Do we have a single, current list of everything we are actually obliged to do?
  • Does every significant obligation have a named owner, not just a policy?
  • For each, is there a control, and does anyone check it works?
  • When the law changes or something goes wrong, does the system update, or drift?
  • Does leadership actually back compliance when it is inconvenient?

A compliance management system is not a set of documents. It is a living loop: know your obligations, own them, control them, improve them, with leadership behind it. ISO 37301 is simply the tidiest description of that loop, tested internationally. Borrow its structure even if you never certify. Start with the obligation register, because a system that does not know what it must do cannot do it, and end with the feedback loop, because a system that cannot learn will be out of date the moment the law moves. Everything in between is just making sure each obligation has an owner and a working control.

Notes and sources

  1. ISO 37301:2021, Compliance management systems, requirements with guidance for use. International Organization for Standardization. Link. ↩
Cover of Compliance

From the book

Key Compliance Models

Fifty-eight models of governance, risk and compliance, each explained in plain language and anchored to a real, sourced case.

View on Amazon →

← Back to Writing