Back to Frameworks

ISO 37303:2025

International
v2025 (first edition)
4 domains
33 controls

ISO 37303:2025 gives guidance for managing the competence needed to achieve a compliance management system's objectives under ISO 37301, whose clause 7 requires the organization to determine, secure and evidence the competence of persons doing work under its control. Clause 4 covers competence management: identifying and assessing needs and setting competency criteria for the system and for compliance risk areas (4.1), objectives that keep competence management consistent with the compliance objectives and business strategy and sustain a compliance culture (4.2), determining competence needs through an integrated four-dimension model (personal, methodological, technical, social) for each function, the organization as a whole, the governing body and top management, the compliance function, management, risk-exposed personnel and third parties (4.3), and assessing the current state of competence and relating the gaps to the compliance risk assessment (4.4). Clause 5 covers competence development: planning, programme structure, activities including training at the start of employment and at planned intervals, and roles and responsibilities. Clause 6 covers evaluation, maintenance and continual improvement of the competence management programme. Annex A gives an informative competence portfolio: how to determine a competence matrix, design indicators and measure competence, and the competence to determine for each function, including for the compliance function knowledge of the system, of compliance risk management, of organizational governance and of relevant laws, skills for operating the system and behaviour supporting compliance culture. Guidance, not certifiable; the competence companion to ISO 37301 certification and to ISO 37302 effectiveness evaluation.

Verified

ISO 37303:2025 is a compliance framework from International with 4 domains and 33 controls. The largest domains are Annex A (informative): Competence portfolio – ISO 37303:2025 (13 controls), Clause 4: Competence management – ISO 37303:2025 (11 controls), Clause 5: Competence development – ISO 37303:2025 (6 controls). Every control below carries what it requires and what an assessor expects to see.

Maintained by Gerard Blokdyk

Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.

Framework Domains (4)

Annex A (informative): Competence portfolio – ISO 37303:2025

13 controls
Controls in the Annex A (informative): Competence portfolio – ISO 37303:2025 domain of ISO 37303:202513 controls
CodeTitle
iso-37303-2025::A.1.1Determining the matrix of competence
iso-37303-2025::A.1.2Designing indicators
iso-37303-2025::A.1.3Measuring competence
iso-37303-2025::A.2.1Governing body and top management
iso-37303-2025::A.2.2.2Knowledge of the compliance management system
iso-37303-2025::A.2.2.3Knowledge of compliance risk management
iso-37303-2025::A.2.2.4Knowledge of organizational governance
iso-37303-2025::A.2.2.5Knowledge of relevant laws and regulations
iso-37303-2025::A.2.2.6Skills for operating the compliance management system
iso-37303-2025::A.2.2.7Behaviour for supporting compliance culture
iso-37303-2025::A.2.3Management
iso-37303-2025::A.2.4Risk-exposed personnel
iso-37303-2025::A.2.5Third parties

Clause 4: Competence management – ISO 37303:2025

11 controls
Controls in the Clause 4: Competence management – ISO 37303:2025 domain of ISO 37303:202511 controls
CodeTitle
iso-37303-2025::4.1General: identify, assess and improve competence for compliance performance
iso-37303-2025::4.2Objectives of competence management
iso-37303-2025::4.3.1General: functions, roles and the four dimensions of competence
iso-37303-2025::4.3.2Organizational competence
iso-37303-2025::4.3.3Governing body and top management competence
iso-37303-2025::4.3.4Compliance function competence
iso-37303-2025::4.3.5Management competence
iso-37303-2025::4.3.6Risk-exposed personnel competence
iso-37303-2025::4.3.7Third party competence
iso-37303-2025::4.4.1Status needs of competence
iso-37303-2025::4.4.2Risk assessment in relation to determination of status and needs of competence

Clause 5: Competence development – ISO 37303:2025

6 controls
Controls in the Clause 5: Competence development – ISO 37303:2025 domain of ISO 37303:20256 controls
CodeTitle
iso-37303-2025::5.1General: developing the competence identified as needed
iso-37303-2025::5.2Planning
iso-37303-2025::5.3Programme structure
iso-37303-2025::5.4.1General: selecting development activities
iso-37303-2025::5.4.2Competence development activities
iso-37303-2025::5.5Roles and responsibilities

Clause 6: Evaluation of competence management programme – ISO 37303:2025

3 controls
Controls in the Clause 6: Evaluation of competence management programme – ISO 37303:2025 domain of ISO 37303:20253 controls
CodeTitle
iso-37303-2025::6.1General: evaluating the competence management programme
iso-37303-2025::6.2Evaluating competence management
iso-37303-2025::6.3Maintaining and continuous improvement of competence management

What is ISO 37303:2025 and who does it apply to?

ISO 37303:2025 is a compliance framework from International with 4 domains and 33 controls. ISO 37303:2025 gives guidance for managing the competence needed to achieve a compliance management system's objectives under ISO 37301, whose clause 7 requires the organization to determine, secure and evidence the competence of persons doing work under its control. Clause 4 covers competence management: identifying and assessing needs and setting competency criteria for the system and for compliance risk areas (4.1), objectives that keep competence management consistent with the compliance objectives and business strategy and sustain a compliance culture (4.2), determining competence needs through an integrated four-dimension model (personal, methodological, technical, social) for each function, the organization as a whole, the governing body and top management, the compliance function, management, risk-exposed personnel and third parties (4.3), and assessing the current state of competence and relating the gaps to the compliance risk assessment (4.4). Clause 5 covers competence development: planning, programme structure, activities including training at the start of employment and at planned intervals, and roles and responsibilities. Clause 6 covers evaluation, maintenance and continual improvement of the competence management programme. Annex A gives an informative competence portfolio: how to determine a competence matrix, design indicators and measure competence, and the competence to determine for each function, including for the compliance function knowledge of the system, of compliance risk management, of organizational governance and of relevant laws, skills for operating the system and behaviour supporting compliance culture. Guidance, not certifiable; the competence companion to ISO 37301 certification and to ISO 37302 effectiveness evaluation. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.

What does ISO 37303:2025 actually require?

ISO 37303:2025 has 33 controls organised across 4 domains. The largest domains are Annex A (informative): Competence portfolio – ISO 37303:2025 (13 controls), Clause 4: Competence management – ISO 37303:2025 (11 controls), Clause 5: Competence development – ISO 37303:2025 (6 controls). Each control defines specific requirements that organisations must implement to achieve compliance.

If I already comply with another framework, how much of ISO 37303:2025 do I already cover?

ISO 37303:2025 does not currently have cross-framework mappings in our system. Check back as we continuously expand our mapping database.

How do I implement ISO 37303:2025?

Start your ISO 37303:2025 compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about ISO 37303:2025 requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 33 controls and track your progress.

Start Your Compliance Journey

Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 704 frameworks.

Get Started Free →

Free forever — no credit card required