ISO 37001 Lead Auditor

The PECB Certified ISO 37001 Lead Auditor training course equips you with the knowledge and skills to conduct anti-bribery management system (ABMS) audits using widely recognized audit principles, procedures, and techniques. Organizations worldwide seek skilled auditors to evaluate the effectiveness of anti-bribery policies and controls within an ISO 37001:2025-based ABMS. This course prepares you to assess, plan, and execute audits effectively while ensuring compliance with ISO 19011 (guidelines for auditing management systems) and ISO/IEC 17021-1 (certification process requirements).

Through interactive sessions, practical exercises, and discussions, you will gain deep insights into ABMS audit techniques while enhancing essential auditing skills.

Upon completing the course, you can take the certification exam. After passing the exam, you will earn the internationally recognized “PECB Certified ISO 37001 Lead Auditor” credential, validating your ability to audit organizations for compliance with ISO 37001 requirements.  

Learning objectives:

By the end of this training course, the participants will be able to:

  • Explain the fundamental concepts and principles of an anti-bribery management system (ABMS) based on ISO 37001
  • Interpret the ISO 37001 requirements for an ABMS from the perspective of an auditor
  • Evaluate the ABMS conformity to ISO 37001 requirements, in accordance with the fundamental audit concepts and principles
  • Plan, conduct, and close an ISO 37001 compliance audit, in accordance with ISO/IEC 17021-1 requirements, ISO 19011 guidelines, and other best practices of auditing
  • Manage an ISO 37001 audit program

Audience:

The ISO 37001 Lead Auditor training course is intended for:

  • Auditors seeking to perform and lead ABMS audits
  • Managers or consultants seeking to master the ABMS audit process
  • Individuals responsible for maintaining conformity to ISO 37001 requirements in an organization
  • Technical experts seeking to prepare for an ABMS audit
  • Expert advisors in anti-bribery management

Prerequisites:

Participants who attend this training course are required to have a fundamental understanding of anti-bribery concepts and a comprehensive knowledge of audit principles.
 

Day 1 – Introduction to the Anti-Bribery Management System (ABMS) and ISO 37001

The course begins with an overview of the training objectives and structure, giving participants a clear understanding of what to expect throughout the programme.

Participants are introduced to ISO 37001 and the fundamentals of management systems, including how anti-bribery management systems are structured and how they integrate into organisational governance frameworks.

The certification process is explained to ensure clarity around requirements, assessment criteria and professional expectations.

The day continues with a review of the fundamental concepts and principles of anti-bribery, including definitions, ethical foundations and the importance of risk-based approaches.

Finally, participants explore the overall structure and key requirements of ISO 37001 to establish a strong foundation for audit-focused learning in the following days.

Day 2 – Audit Principles and Preparation for and Initiation of an Audit

This day focuses on fundamental audit concepts and principles, ensuring participants understand auditing objectives, independence, integrity and professional conduct.

The course addresses how trends and technology impact modern auditing practices, including digital tools, automation and evolving compliance environments.

Participants explore evidence-based auditing techniques and risk-based auditing approaches, learning how to plan audits that focus on material risks and organisational exposure.

The initiation of the audit process is examined in detail, including defining scope, objectives and criteria.

The day concludes with an in-depth review of the Stage 1 audit, focusing on documentation review, readiness assessment and determining preparedness for Stage 2 activities.

Day 3 – On-Site Audit Activities

Participants prepare for the Stage 2 audit, including planning logistics, defining sampling methods and confirming audit plans.

The Stage 2 audit process is examined in detail, with emphasis on conducting interviews, reviewing evidence, observing processes and evaluating control effectiveness within the organisation.

Communication during the audit is addressed as a critical skill, ensuring auditors can engage constructively with stakeholders and maintain professional dialogue.

The course also covers structured audit procedures and how to create effective audit test plans that align with ISO 37001 requirements and risk priorities.

Day 4 – Closing of the Audit

This day focuses on drafting audit findings and nonconformity reports, ensuring clarity, objectivity and alignment with ISO 37001 requirements.

Participants learn how to manage audit documentation and conduct quality reviews to ensure consistency and professionalism in reporting.

The formal closing of the audit is covered, including conducting closing meetings and presenting findings to management.

The evaluation of corrective action plans by the auditor is addressed, along with expectations for follow-up and verification.

The course also explores activities beyond the initial audit, including surveillance audits and continual improvement.

Managing an internal audit programme is examined, providing participants with the skills needed to coordinate long-term audit activities within organisations.

The training course concludes with a structured wrap-up and final review.

Day 5 – Certification Exam

The final day is dedicated to exam preparation, including review of key concepts, clarification of complex topics and discussion of exam structure and expectations.

Participants then complete the certification examination in accordance with the certification body’s procedures.

After successfully completing the exam, you can apply for the credentials shown on the table below. You will receive a certificate once you comply with all the requirements related to the selected credential. For more information about ISO/IEC 27001 certifications and the PECB certification process, please refer to the Certification Rules and Policies.

37001 Lead Auditor Certification

Exam

The exam is will take place at the end of the course on onsite classroom courses

For Virtual courses we will send out a voucher that gives you access to an online exam. This can be booked and taken home monitored by a proctor via camera. More information about the exam rules will be send from PECB.

Test details:

  • The exam duration is three (3) hours. Non-native speakers receive an additional half an hour.
  • The exam contains essay type questions. 

As the exam is an Multiple Choice exam, candidates are authorized to use:

  • A copy of the General Data Protection Regulation;
  • Course notes from the Participant Handout;
  • Any personal notes made by the student during the course; and
  • A hard copy dictionary

Examination rules and policies

RECEIVE YOUR EXAM RESULTS

Results will be communicated by email in a period of 6 to 8 weeks, after taking the exam. The results will not include the exact grade of the candidate, only a mention of pass or fail.

Candidates who successfully complete the examination will be able to apply for a certified scheme which is explained in the course description.

In the case of a failure, the results will be accompanied with the list of domains in which the candidate had failed to provide guidance for exams’ retake preparation.

Candidates, who disagree with the exam results, may file a complaint by writing to examination@pecb.com or through PECB ticketing system.

EXAM RETAKE POLICY

There is no limit on the number of times a candidate may retake an exam. However, there are some limitations in terms of allowed time-frame in between exam retakes, such as:

  • Students, who have completed the full training but failed the written exam, are eligible to retake the exam once for free within a 12 month period from the initial date of the exam.
  • If a candidate does not pass the exam on the second attempt, he/she must wait 3 months (from the initial date of the exam) for the next attempt (2nd retake). Retake fee applies.
  • If a candidate does not pass the exam on the third attempt, he/she must wait 6 months (from the initial date of the exam) for the next attempt (3rd retake). Retake fee applies.

After the fourth attempt, a waiting period of 12 months from the last session date is required, in order for candidate to sit again for the same exam. Regular fee applies.

For the candidates that fail the exam in the 2nd retake, PECB recommends to attend an official training in order to be better prepared for the exam.

To arrange exam retakes (date, time, place, costs), the candidate needs to contact Glasspaper.

Practical information

Duration: 5 days
Price: 29 900
Language: English
Format: Open course and corporate training

FAQ

Hva lærer jeg på dette kurset?
Du lærer hvordan du planlegger, gjennomfører, rapporterer og følger opp revisjoner av et Anti-Bribery Management System i tråd med ISO/IEC 37001.

Hva kreves for å delta?
Det anbefales at du har grunnleggende kjennskap til ISO/IEC 37001 og revisjonsprinsipper. Erfaring med compliance eller anti-bestikkelsesarbeid er en fordel.

Hvordan gjennomføres eksamen?
Eksamen gjennomføres enten fysisk på kursstedet eller som online prøve ved bruk av voucher og online eksamensvakt.

Hva skjer hvis jeg ikke består første eksamen?
Du får vanligvis ett nytt eksamensforsøk som gjennomføres online.

Får jeg ekstra tid på eksamen?
Ja, ekstra tid kan gis dersom engelsk ikke er ditt morsmål, i tråd med sertifiseringsreglene.

Hvilken sertifisering får jeg?
Etter godkjent eksamen oppnår du PECB Certified ISO/IEC 37001 Provisional Auditor sertifiseringen. For å få full sertifisering kan det også stilles krav til dokumentert arbeidserfaring. Sjekk tabellen under sertifisering for mer informasjon.

Får jeg ISO-standaren?
Nei, men du får tilgang til en lånestandar som du kan bruke under kurset og eksamen. 

Hva er forskjellen på Lead Implementer og Lead Auditor?
Lead Implementer gir ferdigheter for å planlegge og drifte et anti-bestikkelsessystem, mens Lead Auditor fokuserer på å evaluere, vurdere og revidere systemet gjennom revisjonsprosesser.

Er dette kurset relevant for ledere?
Ja, kurset er relevant for ledere, revisorer, compliance-ansvarlige og konsulenter som jobber med etterlevelse, styring og anti-bestikkelses arbeid.

Kan jeg ta dette kurset som e-læring eller selvstudium?
Ja, dette kurset tilbys også som e-læring. Påmelding kan registreres på høyre side.

Andre relevante kurs

13. april
5 dager
Classroom Virtual On Demand Startgaranti
23. mars
2 dager
Classroom Virtual Startgaranti
13. april
5 dager
Classroom Virtual
15. juni
5 dager
Classroom Virtual