September 21, 2026 | 14:30

ISO 37001: When anti-bribery governance becomes part of investor confidence before an IPO

Huynh Dung

Dr. Saman Bandara, Forensics Leader at Ernst & Young Vietnam Limited, explains to VET’s Huynh Dung how ISO 37001 can help companies translate their anti-bribery commitments into a structured, evidence-based governance system that supports pre-investment or pre-listing due diligence.

ISO 37001: When anti-bribery governance becomes part of investor confidence before an IPO
Dr. Saman Bandara, Forensics Leader at Ernst & Young Vietnam Limited

Why is an anti-bribery management system an important consideration when a company is preparing for an IPO?

Vietnam’s capital markets are seeing growing interest in IPOs, strategic investment and cross-border capital raising. As transparency and corporate governance receive greater attention, a company’s readiness is no longer judged solely by its financial indicators.

Audited financial statements, profitability, legal compliance and growth prospects remain essential. However, investor due diligence may also extend to the quality of a company’s governance, its risk management capabilities and its ethical culture.

An anti-bribery management system can be an indicator of governance maturity. When a company can demonstrate how it prevents, detects and responds to bribery risks through policies, procedures, records and oversight, investors have a stronger basis for assessing how governance operates in practice.

How should ISO 37001 be understood, and how can it support a company in preparing for pre-IPO due diligence?

According to the International Organization for Standardization (ISO), ISO 37001 sets out requirements and guidance for establishing, implementing, maintaining and improving an anti-bribery management system. The standard is designed to help organizations prevent, detect and respond to bribery, while also complying with applicable anti-bribery laws and voluntary commitments.

In cross-border transactions, some international investors, particularly those from the United States, Europe, Japan, Korea, Singapore and Australia, may be subject to anti-bribery laws outside of their territory, including the U.S. Foreign Corrupt Practices Act (FCPA) and the UK Bribery Act. These laws provide for significant penalties for bribery occurring anywhere within their investment ecosystems. Anti-bribery and corruption risk may therefore form part of the investment due diligence process.

During due diligence, investors may ask practical questions: How does the board oversee integrity and compliance risks? Are procurement decisions transparent and properly documented? How are conflicts of interest identified and managed? Are third parties subject to appropriate due diligence? Can management provide evidence that ethical standards are implemented in practice, rather than merely referring to policies? Can employees report misconduct without fear of retaliation?

If a company cannot provide appropriate answers and supporting evidence, due diligence may take longer, additional reviews may be required, or the risk assessment profile of the transaction might be impaired.

For companies preparing for an IPO, implementing a management system aligned with ISO 37001 can support the development of systematic evidence showing how bribery risks are identified, managed and monitored. However, implementing or obtaining certification to ISO 37001 does not eliminate bribery risk and does not replace legal due diligence, investigations or assessments of the operating effectiveness of controls.

During pre-IPO or capital-raising due diligence, which areas of anti-bribery risk may investors examine?

Based on our experience advising organizations across sectors, governance reviews often focus on three groups of issues. First are procurement processes, including supplier due diligence, approvals and payment records. Second is the management of conflicts of interest, gifts, hospitality, sponsorships and donations. Third is the due diligence and oversight of agents, consultants, distributors and other third parties.

Procurement is one of the areas that should be prioritized for assessment. Supplier selection, contract negotiations, pricing decisions, quality assessments and project procurement can create risks where delegation, approval, recordkeeping and oversight mechanisms are insufficient. Misconduct may also be difficult to detect when concealed within seemingly legitimate transactions.

Third-party risk is another key area. Distributors, customs brokers, logistics providers, consultants, sales representatives, marketing agencies and contractors may interact with government authorities, public officials or customers on behalf of organizations. Without appropriate due diligence and oversight mechanisms, companies may remain exposed to legal, financial and reputational risks.

Reviewing these risks before an IPO enables companies to identify and remediate internal weaknesses proactively, while also preparing appropriate records and evidence for due diligence.

For Vietnamese companies, particularly those preparing for an IPO or international capital raising, where should they begin to strengthen their anti-bribery management systems in accordance with the principles of ISO 37001?

Companies do not necessarily need to begin with a large-scale project. A practical approach is to proceed in four steps.

First, conduct a gap assessment between the company’s existing system and the core requirements of ISO 37001. The scope of the assessment may include policies, risk assessment, allocation of responsibilities, third-party due diligence, financial and non-financial controls, training, reporting channels, investigations and continuous improvement.

Second, identify priority risk areas. These will vary from one company to another, but businesses should generally review processes involving high-value transactions, multiple stakeholders, frequent exception approvals or significant interaction with third parties.

Third, standardize the records and documentation required for due diligence. These may include policies, risk assessment results, approval records, third-party due diligence files, contractual clauses, training materials, internal review findings and records showing how the company has handled reports or allegations.

Fourth, strengthen oversight by the board and executive management. Anti-bribery governance should not be viewed solely as the responsibility of the compliance function. It should be integrated with corporate governance, risk management, finance, legal, procurement and internal audit.

IPO readiness does not end on the listing date. After becoming public, companies remain subject to scrutiny from regulators, investors and other stakeholders. Governance shortcomings after listing may lead to adverse market reactions, regulatory reviews or investigations, legal disputes and reputational damage.

For companies preparing for an IPO, the question is not only whether anti-bribery policies have been issued, but whether the board and executive management can demonstrate that those policies are being implemented, monitored and improved consistently. ISO 37001 can provide a framework to support companies in achieving this objective.

Disclaimer: The views reflected in this article are the views of the interviewee and do not necessarily reflect the views of the global EY organization or its member firms.

Attention
The original article is written and published on VnEconomy in Vietnamese, then translated into English by Askonomy – an AI platform developed by Vietnam Economic Times/VnEconomy – and published on En-VnEconomy. To read the full article, please use the Google Translate tool below to translate the content into your preferred language.
However, VnEconomy is not responsible for any translation by the Google Translate.

Google translateGoogle translate