ISO 37003:2025
ISO 37003:2025 gives guidance for developing, implementing and maintaining a fraud control management system (FCMS) covering internal and external fraud against the organization, fraud in collaboration between insiders and outsiders, and fraud by the organization itself. On the harmonized structure: context and a regular fraud risk assessment conducted with the other risk functions (clause 4); leadership by the governing body and top management, a fraud control policy, delegated decision-making free of conflicts of interest, and the roles of the fraud control, information security and internal audit functions (clause 5); risks, objectives and planned changes (clause 6); resources, competence, the employment process, awareness and training of personnel and business associates, communication and promotion of the FCMS, documented information and confidential record keeping (clause 7); and operation in three blocks: preventing fraud (an integrity framework, conflicts of interest, internal controls and the control environment, pressure testing, performance targets, personnel and business-associate screening, technology-enabled fraud, physical security), detecting fraud (post-transactional review, management accounting analysis, early warning indicators, data analytics, fraud reporting, artificial intelligence systems, complaints, exit interviews) and responding to fraud events (immediate actions, digital evidence, investigation, grievances, discipline, separation of investigation from decision, crisis management, escalation, the fraud event register, analysis and external reporting, recovery, business associates, insurance, post-event control assessment, impact on interested parties, disruption); performance evaluation with internal and external audit and management review, and improvement. Guidance, not certifiable, though certification bodies attest implementation against it; the fraud counterpart of ISO 37001 and the operational elaboration of ISO 37000 6.9.
ISO 37003:2025 is a compliance framework from International with 7 domains and 78 controls. The largest domains are Clause 8: Operation: preventing, detecting and responding to fraud – ISO 37003:2025 (38 controls), Clause 7: Support – ISO 37003:2025 (14 controls), Clause 5: Leadership – ISO 37003:2025 (8 controls). Every control below carries what it requires and what an assessor expects to see.
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (7)
Clause 10: Improvement – ISO 37003:2025
| Code | Title |
|---|---|
| iso-37003-2025::10.1 | Continual improvement |
| iso-37003-2025::10.2 | Nonconformity and corrective action |
Clause 4: Context of the organization and fraud risk assessment – ISO 37003:2025
| Code | Title |
|---|---|
| iso-37003-2025::4.1 | Understanding the organization and its context |
| iso-37003-2025::4.2 | Understanding the needs and expectations of interested parties |
| iso-37003-2025::4.3 | Determining the scope of the fraud control management system (FCMS) |
| iso-37003-2025::4.4 | Fraud control management system (FCMS) |
| iso-37003-2025::4.5.1 | General: the fraud risk assessment |
| iso-37003-2025::4.5.2 | Collaboration with other risk management functions |
Clause 5: Leadership – ISO 37003:2025
| Code | Title |
|---|---|
| iso-37003-2025::5.1.1 | Governing body |
| iso-37003-2025::5.1.2 | Top management |
| iso-37003-2025::5.2 | Fraud control policy |
| iso-37003-2025::5.3.1 | General: roles and responsibilities |
| iso-37003-2025::5.3.2 | Delegated decision-making to managers and organizational functions |
| iso-37003-2025::5.3.3 | Fraud control function |
| iso-37003-2025::5.3.4 | Information security management system function |
| iso-37003-2025::5.3.5 | Internal audit function |
Clause 6: Planning – ISO 37003:2025
| Code | Title |
|---|---|
| iso-37003-2025::6.1 | Actions to address risks and opportunities |
| iso-37003-2025::6.2 | Fraud control objectives and planning to achieve them |
| iso-37003-2025::6.3 | Planning of changes |
Clause 7: Support – ISO 37003:2025
| Code | Title |
|---|---|
| iso-37003-2025::7.1.1 | General: resources |
| iso-37003-2025::7.1.2 | Information security management system function |
| iso-37003-2025::7.2.1 | General: competence |
| iso-37003-2025::7.2.2 | Employment process |
| iso-37003-2025::7.3.1 | Awareness of personnel |
| iso-37003-2025::7.3.2 | Training for personnel |
| iso-37003-2025::7.3.3 | Training for business associates |
| iso-37003-2025::7.3.4 | Awareness and training programmes |
| iso-37003-2025::7.4.1 | General: communication |
| iso-37003-2025::7.4.2 | Promoting the FCMS |
| iso-37003-2025::7.5.1 | General: documented information |
| iso-37003-2025::7.5.2 | Creating and updating documented information |
| iso-37003-2025::7.5.3 | Control of documented information |
| iso-37003-2025::7.5.4 | Record keeping and confidentiality of information |
Clause 8: Operation: preventing, detecting and responding to fraud – ISO 37003:2025
| Code | Title |
|---|---|
| iso-37003-2025::8.1 | Operational planning and control |
| iso-37003-2025::8.2.1 | General: preventing fraud |
| iso-37003-2025::8.2.10 | Physical security and asset management |
| iso-37003-2025::8.2.2 | Developing and promoting an effective integrity framework |
| iso-37003-2025::8.2.3 | Managing conflicts of interest |
| iso-37003-2025::8.2.4 | Internal controls and the internal control environment |
| iso-37003-2025::8.2.5 | Pressure testing the internal control system |
| iso-37003-2025::8.2.6 | Managing performance-based targets |
| iso-37003-2025::8.2.7 | Personnel screening |
| iso-37003-2025::8.2.8 | Screening and management of business associates |
| iso-37003-2025::8.2.9 | Preventing technology-enabled fraud |
| iso-37003-2025::8.3.1 | General: detecting fraud |
| iso-37003-2025::8.3.2 | Post-transactional review |
| iso-37003-2025::8.3.3 | Analysis of management accounting reports |
| iso-37003-2025::8.3.4 | Identification of early warning indicators |
| iso-37003-2025::8.3.5 | Data analytics |
| iso-37003-2025::8.3.6 | Fraud reporting |
| iso-37003-2025::8.3.7 | Artificial intelligence systems |
| iso-37003-2025::8.3.8 | Complaint management |
| iso-37003-2025::8.3.9 | Exit interviews |
| iso-37003-2025::8.4.1 | General: responding to fraud events |
| iso-37003-2025::8.4.10 | Fraud event register |
| iso-37003-2025::8.4.11 | Analysis and reporting of fraud events |
| iso-37003-2025::8.4.12 | External reporting |
| iso-37003-2025::8.4.13 | Recovery of stolen funds or property |
| iso-37003-2025::8.4.14 | Responding to fraud events involving business associates |
| iso-37003-2025::8.4.15 | Insuring against fraud events |
| iso-37003-2025::8.4.16 | Assessing internal controls, systems and processes post-detection of a fraud event |
| iso-37003-2025::8.4.17 | Impact of fraud on other interested parties |
| iso-37003-2025::8.4.18 | Disruption of fraud |
| iso-37003-2025::8.4.2 | Immediate actions in response to discovery of fraud |
| iso-37003-2025::8.4.3 | Digital evidence first response |
| iso-37003-2025::8.4.4 | Investigation of a detected fraud event |
| iso-37003-2025::8.4.5 | Consideration of grievances |
| iso-37003-2025::8.4.6 | Disciplinary procedures |
| iso-37003-2025::8.4.7 | Separation of investigation and decision-making processes |
| iso-37003-2025::8.4.8 | Crisis management following discovery of a fraud event |
| iso-37003-2025::8.4.9 | Internal reporting and escalation |
Clause 9: Performance evaluation – ISO 37003:2025
| Code | Title |
|---|---|
| iso-37003-2025::9.1 | Monitoring, measurement, analysis and evaluation |
| iso-37003-2025::9.2.1 | General: internal audit |
| iso-37003-2025::9.2.2 | Internal audit programme |
| iso-37003-2025::9.3 | External audit |
| iso-37003-2025::9.4.1 | General: management review |
| iso-37003-2025::9.4.2 | Management review inputs |
| iso-37003-2025::9.4.3 | Management review results |
What is ISO 37003:2025 and who does it apply to?
ISO 37003:2025 is a compliance framework from International with 7 domains and 78 controls. ISO 37003:2025 gives guidance for developing, implementing and maintaining a fraud control management system (FCMS) covering internal and external fraud against the organization, fraud in collaboration between insiders and outsiders, and fraud by the organization itself. On the harmonized structure: context and a regular fraud risk assessment conducted with the other risk functions (clause 4); leadership by the governing body and top management, a fraud control policy, delegated decision-making free of conflicts of interest, and the roles of the fraud control, information security and internal audit functions (clause 5); risks, objectives and planned changes (clause 6); resources, competence, the employment process, awareness and training of personnel and business associates, communication and promotion of the FCMS, documented information and confidential record keeping (clause 7); and operation in three blocks: preventing fraud (an integrity framework, conflicts of interest, internal controls and the control environment, pressure testing, performance targets, personnel and business-associate screening, technology-enabled fraud, physical security), detecting fraud (post-transactional review, management accounting analysis, early warning indicators, data analytics, fraud reporting, artificial intelligence systems, complaints, exit interviews) and responding to fraud events (immediate actions, digital evidence, investigation, grievances, discipline, separation of investigation from decision, crisis management, escalation, the fraud event register, analysis and external reporting, recovery, business associates, insurance, post-event control assessment, impact on interested parties, disruption); performance evaluation with internal and external audit and management review, and improvement. Guidance, not certifiable, though certification bodies attest implementation against it; the fraud counterpart of ISO 37001 and the operational elaboration of ISO 37000 6.9. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
What does ISO 37003:2025 actually require?
ISO 37003:2025 has 78 controls organised across 7 domains. The largest domains are Clause 8: Operation: preventing, detecting and responding to fraud – ISO 37003:2025 (38 controls), Clause 7: Support – ISO 37003:2025 (14 controls), Clause 5: Leadership – ISO 37003:2025 (8 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
If I already comply with another framework, how much of ISO 37003:2025 do I already cover?
ISO 37003:2025 does not currently have cross-framework mappings in our system. Check back as we continuously expand our mapping database.
How do I implement ISO 37003:2025?
Start your ISO 37003:2025 compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about ISO 37003:2025 requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 78 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 704 frameworks.
Get Started Free →Free forever — no credit card required