ISO 37303:2025
ISO 37303:2025 gives guidance for managing the competence needed to achieve a compliance management system's objectives under ISO 37301, whose clause 7 requires the organization to determine, secure and evidence the competence of persons doing work under its control. Clause 4 covers competence management: identifying and assessing needs and setting competency criteria for the system and for compliance risk areas (4.1), objectives that keep competence management consistent with the compliance objectives and business strategy and sustain a compliance culture (4.2), determining competence needs through an integrated four-dimension model (personal, methodological, technical, social) for each function, the organization as a whole, the governing body and top management, the compliance function, management, risk-exposed personnel and third parties (4.3), and assessing the current state of competence and relating the gaps to the compliance risk assessment (4.4). Clause 5 covers competence development: planning, programme structure, activities including training at the start of employment and at planned intervals, and roles and responsibilities. Clause 6 covers evaluation, maintenance and continual improvement of the competence management programme. Annex A gives an informative competence portfolio: how to determine a competence matrix, design indicators and measure competence, and the competence to determine for each function, including for the compliance function knowledge of the system, of compliance risk management, of organizational governance and of relevant laws, skills for operating the system and behaviour supporting compliance culture. Guidance, not certifiable; the competence companion to ISO 37301 certification and to ISO 37302 effectiveness evaluation.
ISO 37303:2025 is a compliance framework from International with 4 domains and 33 controls. The largest domains are Annex A (informative): Competence portfolio – ISO 37303:2025 (13 controls), Clause 4: Competence management – ISO 37303:2025 (11 controls), Clause 5: Competence development – ISO 37303:2025 (6 controls). Every control below carries what it requires and what an assessor expects to see.
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (4)
Annex A (informative): Competence portfolio – ISO 37303:2025
| Code | Title |
|---|---|
| iso-37303-2025::A.1.1 | Determining the matrix of competence |
| iso-37303-2025::A.1.2 | Designing indicators |
| iso-37303-2025::A.1.3 | Measuring competence |
| iso-37303-2025::A.2.1 | Governing body and top management |
| iso-37303-2025::A.2.2.2 | Knowledge of the compliance management system |
| iso-37303-2025::A.2.2.3 | Knowledge of compliance risk management |
| iso-37303-2025::A.2.2.4 | Knowledge of organizational governance |
| iso-37303-2025::A.2.2.5 | Knowledge of relevant laws and regulations |
| iso-37303-2025::A.2.2.6 | Skills for operating the compliance management system |
| iso-37303-2025::A.2.2.7 | Behaviour for supporting compliance culture |
| iso-37303-2025::A.2.3 | Management |
| iso-37303-2025::A.2.4 | Risk-exposed personnel |
| iso-37303-2025::A.2.5 | Third parties |
Clause 4: Competence management – ISO 37303:2025
| Code | Title |
|---|---|
| iso-37303-2025::4.1 | General: identify, assess and improve competence for compliance performance |
| iso-37303-2025::4.2 | Objectives of competence management |
| iso-37303-2025::4.3.1 | General: functions, roles and the four dimensions of competence |
| iso-37303-2025::4.3.2 | Organizational competence |
| iso-37303-2025::4.3.3 | Governing body and top management competence |
| iso-37303-2025::4.3.4 | Compliance function competence |
| iso-37303-2025::4.3.5 | Management competence |
| iso-37303-2025::4.3.6 | Risk-exposed personnel competence |
| iso-37303-2025::4.3.7 | Third party competence |
| iso-37303-2025::4.4.1 | Status needs of competence |
| iso-37303-2025::4.4.2 | Risk assessment in relation to determination of status and needs of competence |
Clause 5: Competence development – ISO 37303:2025
| Code | Title |
|---|---|
| iso-37303-2025::5.1 | General: developing the competence identified as needed |
| iso-37303-2025::5.2 | Planning |
| iso-37303-2025::5.3 | Programme structure |
| iso-37303-2025::5.4.1 | General: selecting development activities |
| iso-37303-2025::5.4.2 | Competence development activities |
| iso-37303-2025::5.5 | Roles and responsibilities |
Clause 6: Evaluation of competence management programme – ISO 37303:2025
| Code | Title |
|---|---|
| iso-37303-2025::6.1 | General: evaluating the competence management programme |
| iso-37303-2025::6.2 | Evaluating competence management |
| iso-37303-2025::6.3 | Maintaining and continuous improvement of competence management |
What is ISO 37303:2025 and who does it apply to?
ISO 37303:2025 is a compliance framework from International with 4 domains and 33 controls. ISO 37303:2025 gives guidance for managing the competence needed to achieve a compliance management system's objectives under ISO 37301, whose clause 7 requires the organization to determine, secure and evidence the competence of persons doing work under its control. Clause 4 covers competence management: identifying and assessing needs and setting competency criteria for the system and for compliance risk areas (4.1), objectives that keep competence management consistent with the compliance objectives and business strategy and sustain a compliance culture (4.2), determining competence needs through an integrated four-dimension model (personal, methodological, technical, social) for each function, the organization as a whole, the governing body and top management, the compliance function, management, risk-exposed personnel and third parties (4.3), and assessing the current state of competence and relating the gaps to the compliance risk assessment (4.4). Clause 5 covers competence development: planning, programme structure, activities including training at the start of employment and at planned intervals, and roles and responsibilities. Clause 6 covers evaluation, maintenance and continual improvement of the competence management programme. Annex A gives an informative competence portfolio: how to determine a competence matrix, design indicators and measure competence, and the competence to determine for each function, including for the compliance function knowledge of the system, of compliance risk management, of organizational governance and of relevant laws, skills for operating the system and behaviour supporting compliance culture. Guidance, not certifiable; the competence companion to ISO 37301 certification and to ISO 37302 effectiveness evaluation. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
What does ISO 37303:2025 actually require?
ISO 37303:2025 has 33 controls organised across 4 domains. The largest domains are Annex A (informative): Competence portfolio – ISO 37303:2025 (13 controls), Clause 4: Competence management – ISO 37303:2025 (11 controls), Clause 5: Competence development – ISO 37303:2025 (6 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
If I already comply with another framework, how much of ISO 37303:2025 do I already cover?
ISO 37303:2025 does not currently have cross-framework mappings in our system. Check back as we continuously expand our mapping database.
How do I implement ISO 37303:2025?
Start your ISO 37303:2025 compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about ISO 37303:2025 requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 33 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 704 frameworks.
Get Started Free →Free forever — no credit card required