Back to Frameworks

ISO 37003:2025

International
v2025 (first edition)
7 domains
78 controls

ISO 37003:2025 gives guidance for developing, implementing and maintaining a fraud control management system (FCMS) covering internal and external fraud against the organization, fraud in collaboration between insiders and outsiders, and fraud by the organization itself. On the harmonized structure: context and a regular fraud risk assessment conducted with the other risk functions (clause 4); leadership by the governing body and top management, a fraud control policy, delegated decision-making free of conflicts of interest, and the roles of the fraud control, information security and internal audit functions (clause 5); risks, objectives and planned changes (clause 6); resources, competence, the employment process, awareness and training of personnel and business associates, communication and promotion of the FCMS, documented information and confidential record keeping (clause 7); and operation in three blocks: preventing fraud (an integrity framework, conflicts of interest, internal controls and the control environment, pressure testing, performance targets, personnel and business-associate screening, technology-enabled fraud, physical security), detecting fraud (post-transactional review, management accounting analysis, early warning indicators, data analytics, fraud reporting, artificial intelligence systems, complaints, exit interviews) and responding to fraud events (immediate actions, digital evidence, investigation, grievances, discipline, separation of investigation from decision, crisis management, escalation, the fraud event register, analysis and external reporting, recovery, business associates, insurance, post-event control assessment, impact on interested parties, disruption); performance evaluation with internal and external audit and management review, and improvement. Guidance, not certifiable, though certification bodies attest implementation against it; the fraud counterpart of ISO 37001 and the operational elaboration of ISO 37000 6.9.

Verified

ISO 37003:2025 is a compliance framework from International with 7 domains and 78 controls. The largest domains are Clause 8: Operation: preventing, detecting and responding to fraud – ISO 37003:2025 (38 controls), Clause 7: Support – ISO 37003:2025 (14 controls), Clause 5: Leadership – ISO 37003:2025 (8 controls). Every control below carries what it requires and what an assessor expects to see.

Maintained by Gerard Blokdyk

Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.

Framework Domains (7)

Clause 10: Improvement – ISO 37003:2025

2 controls
Controls in the Clause 10: Improvement – ISO 37003:2025 domain of ISO 37003:20252 controls
CodeTitle
iso-37003-2025::10.1Continual improvement
iso-37003-2025::10.2Nonconformity and corrective action

Clause 4: Context of the organization and fraud risk assessment – ISO 37003:2025

6 controls
Controls in the Clause 4: Context of the organization and fraud risk assessment – ISO 37003:2025 domain of ISO 37003:20256 controls
CodeTitle
iso-37003-2025::4.1Understanding the organization and its context
iso-37003-2025::4.2Understanding the needs and expectations of interested parties
iso-37003-2025::4.3Determining the scope of the fraud control management system (FCMS)
iso-37003-2025::4.4Fraud control management system (FCMS)
iso-37003-2025::4.5.1General: the fraud risk assessment
iso-37003-2025::4.5.2Collaboration with other risk management functions

Clause 5: Leadership – ISO 37003:2025

8 controls
Controls in the Clause 5: Leadership – ISO 37003:2025 domain of ISO 37003:20258 controls
CodeTitle
iso-37003-2025::5.1.1Governing body
iso-37003-2025::5.1.2Top management
iso-37003-2025::5.2Fraud control policy
iso-37003-2025::5.3.1General: roles and responsibilities
iso-37003-2025::5.3.2Delegated decision-making to managers and organizational functions
iso-37003-2025::5.3.3Fraud control function
iso-37003-2025::5.3.4Information security management system function
iso-37003-2025::5.3.5Internal audit function

Clause 6: Planning – ISO 37003:2025

3 controls
Controls in the Clause 6: Planning – ISO 37003:2025 domain of ISO 37003:20253 controls
CodeTitle
iso-37003-2025::6.1Actions to address risks and opportunities
iso-37003-2025::6.2Fraud control objectives and planning to achieve them
iso-37003-2025::6.3Planning of changes

Clause 7: Support – ISO 37003:2025

14 controls
Controls in the Clause 7: Support – ISO 37003:2025 domain of ISO 37003:202514 controls
CodeTitle
iso-37003-2025::7.1.1General: resources
iso-37003-2025::7.1.2Information security management system function
iso-37003-2025::7.2.1General: competence
iso-37003-2025::7.2.2Employment process
iso-37003-2025::7.3.1Awareness of personnel
iso-37003-2025::7.3.2Training for personnel
iso-37003-2025::7.3.3Training for business associates
iso-37003-2025::7.3.4Awareness and training programmes
iso-37003-2025::7.4.1General: communication
iso-37003-2025::7.4.2Promoting the FCMS
iso-37003-2025::7.5.1General: documented information
iso-37003-2025::7.5.2Creating and updating documented information
iso-37003-2025::7.5.3Control of documented information
iso-37003-2025::7.5.4Record keeping and confidentiality of information

Clause 8: Operation: preventing, detecting and responding to fraud – ISO 37003:2025

38 controls
Controls in the Clause 8: Operation: preventing, detecting and responding to fraud – ISO 37003:2025 domain of ISO 37003:202538 controls
CodeTitle
iso-37003-2025::8.1Operational planning and control
iso-37003-2025::8.2.1General: preventing fraud
iso-37003-2025::8.2.10Physical security and asset management
iso-37003-2025::8.2.2Developing and promoting an effective integrity framework
iso-37003-2025::8.2.3Managing conflicts of interest
iso-37003-2025::8.2.4Internal controls and the internal control environment
iso-37003-2025::8.2.5Pressure testing the internal control system
iso-37003-2025::8.2.6Managing performance-based targets
iso-37003-2025::8.2.7Personnel screening
iso-37003-2025::8.2.8Screening and management of business associates
iso-37003-2025::8.2.9Preventing technology-enabled fraud
iso-37003-2025::8.3.1General: detecting fraud
iso-37003-2025::8.3.2Post-transactional review
iso-37003-2025::8.3.3Analysis of management accounting reports
iso-37003-2025::8.3.4Identification of early warning indicators
iso-37003-2025::8.3.5Data analytics
iso-37003-2025::8.3.6Fraud reporting
iso-37003-2025::8.3.7Artificial intelligence systems
iso-37003-2025::8.3.8Complaint management
iso-37003-2025::8.3.9Exit interviews
iso-37003-2025::8.4.1General: responding to fraud events
iso-37003-2025::8.4.10Fraud event register
iso-37003-2025::8.4.11Analysis and reporting of fraud events
iso-37003-2025::8.4.12External reporting
iso-37003-2025::8.4.13Recovery of stolen funds or property
iso-37003-2025::8.4.14Responding to fraud events involving business associates
iso-37003-2025::8.4.15Insuring against fraud events
iso-37003-2025::8.4.16Assessing internal controls, systems and processes post-detection of a fraud event
iso-37003-2025::8.4.17Impact of fraud on other interested parties
iso-37003-2025::8.4.18Disruption of fraud
iso-37003-2025::8.4.2Immediate actions in response to discovery of fraud
iso-37003-2025::8.4.3Digital evidence first response
iso-37003-2025::8.4.4Investigation of a detected fraud event
iso-37003-2025::8.4.5Consideration of grievances
iso-37003-2025::8.4.6Disciplinary procedures
iso-37003-2025::8.4.7Separation of investigation and decision-making processes
iso-37003-2025::8.4.8Crisis management following discovery of a fraud event
iso-37003-2025::8.4.9Internal reporting and escalation

Clause 9: Performance evaluation – ISO 37003:2025

7 controls
Controls in the Clause 9: Performance evaluation – ISO 37003:2025 domain of ISO 37003:20257 controls
CodeTitle
iso-37003-2025::9.1Monitoring, measurement, analysis and evaluation
iso-37003-2025::9.2.1General: internal audit
iso-37003-2025::9.2.2Internal audit programme
iso-37003-2025::9.3External audit
iso-37003-2025::9.4.1General: management review
iso-37003-2025::9.4.2Management review inputs
iso-37003-2025::9.4.3Management review results

What is ISO 37003:2025 and who does it apply to?

ISO 37003:2025 is a compliance framework from International with 7 domains and 78 controls. ISO 37003:2025 gives guidance for developing, implementing and maintaining a fraud control management system (FCMS) covering internal and external fraud against the organization, fraud in collaboration between insiders and outsiders, and fraud by the organization itself. On the harmonized structure: context and a regular fraud risk assessment conducted with the other risk functions (clause 4); leadership by the governing body and top management, a fraud control policy, delegated decision-making free of conflicts of interest, and the roles of the fraud control, information security and internal audit functions (clause 5); risks, objectives and planned changes (clause 6); resources, competence, the employment process, awareness and training of personnel and business associates, communication and promotion of the FCMS, documented information and confidential record keeping (clause 7); and operation in three blocks: preventing fraud (an integrity framework, conflicts of interest, internal controls and the control environment, pressure testing, performance targets, personnel and business-associate screening, technology-enabled fraud, physical security), detecting fraud (post-transactional review, management accounting analysis, early warning indicators, data analytics, fraud reporting, artificial intelligence systems, complaints, exit interviews) and responding to fraud events (immediate actions, digital evidence, investigation, grievances, discipline, separation of investigation from decision, crisis management, escalation, the fraud event register, analysis and external reporting, recovery, business associates, insurance, post-event control assessment, impact on interested parties, disruption); performance evaluation with internal and external audit and management review, and improvement. Guidance, not certifiable, though certification bodies attest implementation against it; the fraud counterpart of ISO 37001 and the operational elaboration of ISO 37000 6.9. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.

What does ISO 37003:2025 actually require?

ISO 37003:2025 has 78 controls organised across 7 domains. The largest domains are Clause 8: Operation: preventing, detecting and responding to fraud – ISO 37003:2025 (38 controls), Clause 7: Support – ISO 37003:2025 (14 controls), Clause 5: Leadership – ISO 37003:2025 (8 controls). Each control defines specific requirements that organisations must implement to achieve compliance.

If I already comply with another framework, how much of ISO 37003:2025 do I already cover?

ISO 37003:2025 does not currently have cross-framework mappings in our system. Check back as we continuously expand our mapping database.

How do I implement ISO 37003:2025?

Start your ISO 37003:2025 compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about ISO 37003:2025 requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 78 controls and track your progress.

Start Your Compliance Journey

Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 704 frameworks.

Get Started Free →

Free forever — no credit card required