International ISO Standard IS037302 Compliance management First edition systems Guidance for the 2025-07 evaluation of effectiveness Systemes de management de la conformite - Lignes directrices pour I'évaluation de I'efficacité Referencenumber ISO 37302:2025(en) @ ISO 2025 IS0 37302:2025(en) COPYRIGHT PROTECTED DOCUMENT CIS02025 All rights reserved. Unless otherwise specified, or required in the context of its implementation, no part of this publication may be reproduced or utilized otherwise in any form or by any means, electronic or mechanical, including photocopying, or posting on the internet or an intranet, without prior written permission. Permission can be requested from either ISO at the address below orIso's memberbody inthe countryofthe requester. ISO copyright office CP 40i:Ch.de Blandonnet 8 CH-1214 Vernier, Geneva Phone: +41 22 749 01 11 Email:
[email protected] Website: www.iso.org Published in Switzerland @ IS0 2025 - All rights reserved i IS0 37302:2025(en) Contents Page Foreword. .iv Introduction. .V 1 Scope. .1 2 Normative references 1 3 Terms and definitions .1 4 General principles 2 5 Evaluation methodology. 2 5.1 General. 2 5.2 Evaluation scales. 3 5.3 Evaluation indicator framework 3 6 Evaluation criteria. 5 6.1 Planning and establishment of the compliance management system 5 6.1.1 Analysis of the context of the organization, including requirements of interested parties. .5 6.1.2 Identification and update of compliance obligations. 7 6.1.3 Determination of the scope of the compliance management system and assessment of compliance risk. .8 6.1.4 Leadership and commitment of governing body and top management .10 6.1.5 Implementation of compliance governance principles . 12 6.1.6 Maintenance and promotion of compliance culture. .14 6.1.7 Assignment of the roles, responsibilities, and authorities for personnel at differentlevels. 15 6.1.8 Compliance policy and setting of objectives 17 6.1.9 Planning of actions to address risk and opportunity and the resources required 19 6.2 Implementation of the planned compliance management system. 20 6.2.1 Operational actions to address risk and opportunity 20 6.2.2 Allocation of resources 21 6.2.3 Competences, capacity building and raising awareness 23 6.2.4 Employment process, rewards and disciplinary actions 25 6.2.5 Training 26 6.2.6 Internal and external communication 28 6.2.7 Establishment of a mechanism for raising concerns 29 6.2.8 Implementationofprocessesforinvestigation 30 6.2.9 Management of documented information. .32 6.3 Evaluating performance and improvement of the compliance management system 33 6.3.1 Monitoring, measurement, analysis and evaluation of performance. 33 6.3.2 Internal audit 34 6.3.3 Management review... 36 6.3.4 Actions to address nonconformity and/or noncompliance and correction .37 6.3.5 Continual improvement in a planned manner 39 7 Evaluation process 40 7.1 Objectives 40 7.2 Structured approach 40 7.3 Evaluators .41 7.4 Evaluation method .41 7.4.1 Design. .41 7.4.2 Implementation .41 7.4.3 Reporting and response. .42 Annex A (informative) Figure of the evaluation indicator framework 43 @ IS0 2025 - All rights reserved iii IS0 37302:2025(en) Foreword IsO (the International Organization for Standardization) is a worldwide federation of national standards bodies (IsO member bodies). The work of preparing International Standards is normally carried out through IsO technical committees. Each member body interested in a subject for which a technical committee has been established has the right to be represented on that committee. International organizations governmental and non-governmental, in liaison with IsO, also take part in the work. IsO collaborates closely The procedures used to develop this document and those intended for its further maintenance are described in the ISO/IEC Directives, Part 1. In particular, the different approval criteria needed for the different types of IsO document should be noted. This document was drafted in ac