How to Maintain ISO 37001 Certification: Surveillance Audits and Recertification in Malaysia

ISO 37001 certification is not a one-time achievement. To keep it, your anti-bribery management system must pass an annual surveillance audit and a full recertification every three years, all designed to confirm the system is still working in practice. This article explains how to maintain ISO 37001 certification in Malaysia, how long the certificate lasts, what surveillance and recertification audits involve, what auditors look for, what happens if certification lapses, and how to keep your system audit-ready between visits.

How Long Is ISO 37001 Certification Valid For?

ISO 37001 certification is valid for three years, provided the organisation passes an annual surveillance audit in each of the two intervening years. The three-year cycle begins on the date the certification body issues the certificate, after a successful Stage 1 and Stage 2 initial audit. The certificate is not unconditional. It stays valid only while the certification body continues to see evidence that the anti-bribery management system (ABMS) is operating as certified.

In Malaysia, certification must come from a body accredited to run the scheme, such as SIRIM QAS International, SGS Malaysia, Bureau Veritas Malaysia, TUV SUD, or LRQA. Accreditation matters after certification, not just before it, because a certificate loses its evidentiary value under MACC Section 17A if the issuing body is not recognised. For CIDB Grade G7 contractors, who must hold valid ISO 37001 certification by 1 January 2027 under CIDB Pekeliling Bil. 1/2026, valid means surveillance-maintained, not simply issued once and left to lapse.

What Is an ISO 37001 Surveillance Audit?

An ISO 37001 surveillance audit is an annual review by your certification body that confirms the anti-bribery management system remains implemented, maintained, and effective between full certification cycles. It happens in Year 1 (SA1) and Year 2 (SA2) of the three-year cycle. A surveillance audit is deliberately narrower than the initial certification audit. The auditor samples selected areas rather than re-examining every clause of ISO 37001:2025 in the same depth.

Certain elements are reviewed during every surveillance audit, including internal audits (Clause 9.2), management reviews (Clause 9.3), the status of previous nonconformities, whistleblowing or reporting mechanisms, and evidence that bribery risk assessments are regularly updated. In our experience, many Malaysian organisations underestimate the importance of surveillance audits. However, major nonconformities identified during these audits can still result in certificate suspension if they are not addressed promptly. If you’re planning to implement or maintain an anti-bribery management system, our ISO 37001 implementation guide explains the process from gap analysis through certification and ongoing compliance.

iso37001 Surveillance Audits Malaysia

What Happens During ISO 37001 Recertification?

ISO 37001 recertification is a full reassessment of the entire anti-bribery management system, conducted at the end of the three-year cycle before the current certificate expires. Unlike a surveillance audit, recertification revisits the whole standard, not a sample. Its purpose is to confirm the ABMS as a whole still conforms to ISO 37001:2025 and remains effective for a further three-year term.

Recertification should be scheduled before the expiry date so there is no gap in valid certification. A lapse can be damaging for companies that rely on the certificate for government procurement, GLC supply-chain qualification, or the MACC Section 17A adequate procedures defence. Once recertification is passed, a new three-year cycle begins and the surveillance pattern repeats. Organisations still certified to the withdrawn ISO 37001:2016 version must complete their transition to ISO 37001:2025 by 28 February 2027. In practice this transition is handled at the next surveillance or recertification audit, so planning the upgrade into your existing cycle avoids a separate, disruptive assessment.

What Do Auditors Look For in an ISO 37001 Surveillance Audit?

Auditors in an ISO 37001 surveillance audit look for evidence that the system is being used, not just maintained on paper. They test whether controls that were in place at certification are still operating: due diligence records for new third parties and associated persons, gift and hospitality declarations, training completion for new joiners, and a management review that actually took place with board-level involvement.

One of the most common issues we observe when working with Malaysian organisations is that the anti-bribery management system becomes inactive once the certificate has been issued. Training refreshers are overlooked, bribery risk assessments are not updated as the business evolves, and whistleblowing channels are rarely promoted, resulting in low awareness among employees. These are precisely the types of weaknesses surveillance auditors are trained to identify. Where nonconformities are found, organisations must implement corrective actions under Clause 10, address the root cause, and provide objective evidence of closure. While minor nonconformities are generally verified at the next surveillance audit, unresolved major findings may lead to suspension of the certificate. This is one reason why ISO 37001 is essential for SMEs, helping businesses establish effective anti-bribery controls that remain practical, sustainable, and compliant beyond initial certification.

To assess your organisation’s readiness before a surveillance or certification audit, use an ISO 37001 audit checklist to verify that all key requirements, records, and controls are in place.

What Happens If Your ISO 37001 Certification Lapses or Is Suspended?

If your ISO 37001 certification lapses or is suspended, the organisation loses the independent evidence it relies on to prove adequate procedures under MACC Section 17A, and any tender or supply-chain qualification that requires valid certification is immediately at risk. Suspension usually follows an unresolved major non-conformity or a missed surveillance audit. The certification body sets a defined window to close the finding, and if that deadline passes the certificate can be withdrawn entirely. Reinstatement may then require a fresh certification audit rather than a simple correction.

The commercial consequences arrive faster than most companies expect. A CIDB Grade G7 contractor that lets certification lapse after 1 January 2027 could be disqualified from tenders that list ISO 37001 as a condition. A supplier to a GLC or listed company may be dropped from an approved-vendor list at the next review. In a Section 17A prosecution, a lapsed certificate is arguably worse than none, because it shows the organisation once had a system and then allowed it to fail. Continuity, not just certification, is what protects the business.

How Do You Keep an ISO 37001 System Audit-Ready Between Audits?

Keeping an ISO 37001 system audit-ready between audits means running the management system continuously, not reviving it a month before the surveillance visit. The organisations that pass surveillance audits cleanly treat the ABMS as a live operational process throughout the year.

Practical maintenance covers a few consistent activities. Hold the management review at least annually under Clause 9.3, with genuine board or top-management participation and documented decisions. Refresh the bribery risk assessment whenever the business changes materially, such as entering a new market, taking on high-risk agents, or bidding for government contracts. Run the internal audit programme under Clause 9.2 so issues are found and fixed before the external auditor arrives. Keep training current for new employees and business associates, and retain the records. Monitor and log activity in the whistleblowing channel, even nil returns. This discipline is what separates a certificate that proves adequate procedures under MACC Section 17A from one that a court or a MACC investigator could dismiss as a paper exercise.

ISO 37001 Is a Three-Year Commitment, Not a Single Event

The certificate stays valid only through annual surveillance audits and a full recertification at the end of each cycle, and it carries real weight under MACC Section 17A only while the underlying system stays operational. Companies that maintain the discipline of regular management reviews, current risk assessments, live training, and an active reporting channel pass their audits with minimal friction and hold a defensible anti-bribery position at all times. Those that let the system lapse risk non-conformities, certificate suspension, and a weakened Section 17A defence exactly when they need it most. Remember that organisations certified to ISO 37001:2016 must transition to ISO 37001:2025 by 28 February 2027, and CIDB G7 contractors must hold valid certification by 1 January 2027.

Protect your business from bribery risks. Get ISO 37001 certified with Connext.

FAQs

How long is ISO 37001 certification valid for?

ISO 37001 certification is valid for three years from the date of issue, subject to passing an annual surveillance audit in each of the two intervening years. At the end of the three years, a full recertification audit is required to renew it for a further cycle.

How often is an ISO 37001 surveillance audit conducted?

ISO 37001 surveillance audits are conducted annually, in Year 1 and Year 2 of the three-year certification cycle. They are narrower than the initial audit, sampling selected areas such as internal audits, management review, previous non-conformities, and the reporting channel to confirm the system is still operating.

What is the difference between a surveillance audit and a recertification audit?

A surveillance audit is an annual, sampled check that the anti-bribery management system is still working. A recertification audit is a full reassessment of the entire standard at the end of the three-year cycle, needed to renew the certificate for another three years.

What happens if you fail an ISO 37001 surveillance audit?

A failed surveillance audit usually means a major non-conformity was raised. The organisation must submit a corrective action plan, fix the root cause, and provide evidence of closure. Unresolved major non-conformities can lead the certification body to suspend or withdraw the certificate until they are addressed.

Do I need to recertify ISO 37001, and how does the 2025 version affect it?

Yes. ISO 37001 must be recertified every three years to stay valid. Organisations still certified to ISO 37001:2016 must also transition to ISO 37001:2025 by 28 February 2027, which is normally handled at a scheduled surveillance or recertification audit rather than as a separate assessment.