ISO 37001:2016
Context of the organization – ISO 37001:2016

ISO 37001:2016 4.1: 4.1 Understanding the organization and its context

Identify the internal and external factors, tied to what the organization exists to do, that bear on whether its anti-bribery system can deliver its aims. At a minimum look at: how big it is, how it is structured and who holds delegated authority to decide; the places and industries it works in now or plans to enter; what its activities involve and how large and complex they are; how it makes its money; which entities it controls and which control it; who its business associates are; how often and in what way it deals with public officials; and the legal, regulatory, contractual and professional duties that bind it. Under Amendment 1 (2024) it must also decide whether climate change counts as one of these factors. Controlling another organization means directing its management, directly or indirectly.

Maintained by Gerard Blokdyk

What else in your programme already covers this

This control maps to 28 controls across 21 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

ISO 27701:2019 · 2 controls

  • 4.1 Structure of this document
  • 5.2.1 Understanding the organization and its context
  • ISO-39001-4.1 Understanding the organization and its context
  • ISO39001-4.1 Understanding the Organization and Its Context
  • ISO-41001-4.1 Understanding the organization and its context
  • ISO41001-4.1 Understanding the Organization and Its Context
  • ISO-50001-4.1 Understanding the organization and its context
  • 4.1 Understanding the organization and its context

ISO 56002 · 2 controls

  • ISO-56002-4.1 Understanding the organization and its context
  • ISO56002-4.1 Understanding the organization and its context

ISO/IEC 23894:2023 · 2 controls

  • 23894-5.4.1 Understanding Organization and Context
  • 5.4.1 Understanding the organization and its context

ISO/IEC 27003:2017 · 2 controls

  • 27003-4.1 Understanding the Organization and Its Context
  • ISO27003-4.1 Understanding the organization and its context
  • AS9100D-4.1 Understanding the Organization and Its Context

ISO 14001:2015 · 1 control

  • 4.1 Understanding the organization and its context

ISO 14004:2016 · 1 control

  • 4.1 Understanding the organization and its context

ISO 19011:2018 · 1 control

  • 7.6 Maintaining and improving auditor competence

ISO 22000:2018 · 1 control

  • 4.1 Understanding the organization and its context

ISO 22301:2019 · 1 control

  • 4.1 Understanding the organization and its context
  • ISO-22313-4.1 Understanding the organization and its context

ISO 31000:2018 · 1 control

  • 5.4.1 Understanding the organization and its context
  • ISO-37002-4.1 Understanding the organization and its context

ISO 37301:2021 · 1 control

  • 4.1 Understanding the organization and its context

ISO 45001:2018 · 1 control

  • 4.1 Understanding the organization and its context

ISO 55001:2014 · 1 control

  • 4.1 Understanding the organization and its context

ISO 9001:2015 · 1 control

  • 4.1 Understanding the organization and its context

ISO/IEC 42001:2023 · 1 control

  • 4.1 Understanding the organization and its context

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Context of the organization – ISO 37001:2016

Query this from an agent

The graph holds this control, the 28 it maps to, and the evidence behind each claim, over MCP and REST.