ISO 37009:2025
ISO 37009:2025 gives guidance for organizations of all types on understanding conflict of interest and identifying, assessing, resolving and monitoring it on the principles of trust, integrity, transparency and accountability. Clause 4 explains the nature of interest (personal: business, financial, family, professional, religious or political; organizational: that of a team, department or affiliate) and the three categories, actual, apparent and potential. Clause 5 sets the management framework and the four principles; clause 6 leadership, policy and the roles of the governing body and top management; clause 7 resources, competence, awareness and training, and communication; clause 8 the process of identification with timely disclosure, assessment, resolution and monitoring; clause 9 review and the evaluation of the framework's effectiveness; Annex A gives examples of interests, at-risk situations, passive interest and information barriers. Unmanaged conflict of interest is named as a key contributor to corruption and to the perception of wrongdoing; the framework is meant to be embedded in culture and business processes and integrated with governance, risk and compliance. Guidance, not certifiable; the conflict-of-interest companion to ISO 37000, 37001, 37002, 37003 and 37301.
ISO 37009:2025 is a compliance framework from International with 7 domains and 39 controls. The largest domains are Clause 8: Process: identification, assessment, resolution and monitoring – ISO 37009:2025 (10 controls), Clause 4: Understanding conflict of interest – ISO 37009:2025 (8 controls), Clause 5: Framework and principles – ISO 37009:2025 (6 controls). Every control below carries what it requires and what an assessor expects to see.
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (7)
Annex A (informative): Managing conflict of interest – ISO 37009:2025
| Code | Title |
|---|---|
| iso-37009-2025::A.1 | Example of internal and external personal and organizational interests |
| iso-37009-2025::A.2 | At-risk situations |
| iso-37009-2025::A.3 | Passive interest |
| iso-37009-2025::A.4 | Information barriers |
| iso-37009-2025::A.5 | Physical information barriers |
Clause 4: Understanding conflict of interest – ISO 37009:2025
| Code | Title |
|---|---|
| iso-37009-2025::4.1 | General: understanding conflict of interest |
| iso-37009-2025::4.2.1 | General: the nature of the interest |
| iso-37009-2025::4.2.2 | Personal interest |
| iso-37009-2025::4.2.3 | Organizational interest |
| iso-37009-2025::4.3.1 | General: the three categories |
| iso-37009-2025::4.3.2 | Actual conflict of interest |
| iso-37009-2025::4.3.3 | Apparent conflict of interest |
| iso-37009-2025::4.3.4 | Potential conflict of interest |
Clause 5: Framework and principles – ISO 37009:2025
| Code | Title |
|---|---|
| iso-37009-2025::5.1 | General: the conflict-of-interest management framework |
| iso-37009-2025::5.2.1 | General: the four principles |
| iso-37009-2025::5.2.2 | Trust |
| iso-37009-2025::5.2.3 | Integrity |
| iso-37009-2025::5.2.4 | Transparency |
| iso-37009-2025::5.2.5 | Accountability |
Clause 6: Leadership – ISO 37009:2025
| Code | Title |
|---|---|
| iso-37009-2025::6.1 | Leadership and commitment |
| iso-37009-2025::6.2 | Policy |
| iso-37009-2025::6.3.1 | Governing body |
| iso-37009-2025::6.3.2 | Top management |
Clause 7: Support – ISO 37009:2025
| Code | Title |
|---|---|
| iso-37009-2025::7.1 | Resources |
| iso-37009-2025::7.2 | Competence |
| iso-37009-2025::7.3 | Awareness and training |
| iso-37009-2025::7.4 | Communication |
Clause 8: Process: identification, assessment, resolution and monitoring – ISO 37009:2025
| Code | Title |
|---|---|
| iso-37009-2025::8.1 | General: the conflict-of-interest management process |
| iso-37009-2025::8.2.1 | General: identification |
| iso-37009-2025::8.2.2 | Identification process |
| iso-37009-2025::8.2.3 | Disclosure |
| iso-37009-2025::8.3.1 | General: assessment |
| iso-37009-2025::8.3.2 | Assessment process |
| iso-37009-2025::8.4.1 | General: resolution |
| iso-37009-2025::8.4.2 | Resolution process |
| iso-37009-2025::8.5.1 | General: monitoring |
| iso-37009-2025::8.5.2 | Monitoring strategies |
Clause 9: Performance evaluation – ISO 37009:2025
| Code | Title |
|---|---|
| iso-37009-2025::9.1 | Review, assessment and compliance |
| iso-37009-2025::9.2 | Evaluating framework effectiveness |
What is ISO 37009:2025 and who does it apply to?
ISO 37009:2025 is a compliance framework from International with 7 domains and 39 controls. ISO 37009:2025 gives guidance for organizations of all types on understanding conflict of interest and identifying, assessing, resolving and monitoring it on the principles of trust, integrity, transparency and accountability. Clause 4 explains the nature of interest (personal: business, financial, family, professional, religious or political; organizational: that of a team, department or affiliate) and the three categories, actual, apparent and potential. Clause 5 sets the management framework and the four principles; clause 6 leadership, policy and the roles of the governing body and top management; clause 7 resources, competence, awareness and training, and communication; clause 8 the process of identification with timely disclosure, assessment, resolution and monitoring; clause 9 review and the evaluation of the framework's effectiveness; Annex A gives examples of interests, at-risk situations, passive interest and information barriers. Unmanaged conflict of interest is named as a key contributor to corruption and to the perception of wrongdoing; the framework is meant to be embedded in culture and business processes and integrated with governance, risk and compliance. Guidance, not certifiable; the conflict-of-interest companion to ISO 37000, 37001, 37002, 37003 and 37301. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
What does ISO 37009:2025 actually require?
ISO 37009:2025 has 39 controls organised across 7 domains. The largest domains are Clause 8: Process: identification, assessment, resolution and monitoring – ISO 37009:2025 (10 controls), Clause 4: Understanding conflict of interest – ISO 37009:2025 (8 controls), Clause 5: Framework and principles – ISO 37009:2025 (6 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
If I already comply with another framework, how much of ISO 37009:2025 do I already cover?
ISO 37009:2025 does not currently have cross-framework mappings in our system. Check back as we continuously expand our mapping database.
How do I implement ISO 37009:2025?
Start your ISO 37009:2025 compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about ISO 37009:2025 requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 39 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 704 frameworks.
Get Started Free →Free forever — no credit card required