التفاصيل

Compliance management system certification

GB/T 35770-2022 ISO37301:2021

01

مقدمة الخدمة

Compliance management system certification is an authoritative evaluation mechanism for organizations to systematically establish, implement, maintain and improve compliance management capabilities. It aims to help organizations effectively manage compliance risks through standardized management framework, cultivate a culture of integrity and compliance, and ensure continuous compliance with compliance obligations such as laws and regulations, regulatory provisions, industry standards and ethics. This certification is mainly based on ISO 37301:2021 "Guidelines for Requirements and Use of Compliance Management System" and the equivalent national standard GB/T 35770-2022, which comprehensively inspects the whole process of the organization's compliance management system, and finally grants the organization a certification certificate with a validity period of three years.

Certification core content

The certification of compliance management system focuses on the systematic management of compliance risks, and the core inspection is as follows:

Organizational environment and leadership role: understand the organization and its internal and external environment, identify the needs of relevant parties, the commitment and leadership role of top management, formulate compliance policies, and clarify responsibilities and authorities.

Compliance risk assessment: the system identifies and evaluates the compliance risks faced by the organization (such as anti-corruption, anti-monopoly, data protection, labor and employment, bidding and procurement, etc.) and determines the risk priority.

Compliance planning: formulating compliance objectives, planning measures to achieve the objectives, and coping with compliance risks.

Support process: resource allocation, personnel ability and training, compliance awareness training, communication mechanism and documented information control.

Operation control: establishing compliance process, integrating compliance requirements into business process, outsourcing process control and supplier compliance management.

Performance evaluation: compliance performance monitoring and measurement, internal audit, management review and compliance reporting mechanism.

Improvement mechanism: correction of nonconformities, continuous improvement measures, reporting and investigation mechanism (whistle blower system), and handling of nonconformities.

Certification process

Compliance management system certification is usually divided into the following stages:

Application and acceptance: submit application materials (business license, system documents, etc.), and the certification body will conduct application review to confirm that the organization has the basic conditions for certification (the system has been in operation for 3 months, internal audit and management review have been completed, and there is no record of serious dishonesty).

Gap analysis (optional): the organization can choose to carry out gap analysis to understand the compliance of current practices with ISO 37301 requirements and identify the improvement direction.

First-stage audit (document audit): conduct document audit and site preparation evaluation, review the compliance of compliance system documents with standard requirements, and confirm the adequacy of second-stage audit preparation.

The second stage of audit (on-site audit): conduct on-site audit, including personnel interview, document record inspection, practice inspection of compliance risk assessment, verification of compliance control measures, evaluation of compliance and effectiveness of the system, and identification of nonconformities.

Rectification and review: for the nonconformities found in the audit, the organization shall complete the rectification within the specified time limit and submit the evidence, which will be reviewed by the audit team.

Certification decision and certification: certification certificate will be issued after the technical review is passed, confirming that the organization meets the standard requirements, and the certificate is valid for three years.

Supervision and audit: conduct supervision and audit once a year after obtaining the certificate (within 12 months for the first time and within 24 months for the second time) to confirm that the system continues to meet the certification requirements.

Re-certification audit: Re-certification audit is conducted before the certificate expires, and the certification qualification is extended, usually for three years.

Audit core evaluation criteria

Certification audit usually systematically evaluates the actual effectiveness of the compliance management system through the following four standards:

Compliance: verify whether the system documents completely cover the provisions of ISO 37301 standard and the requirements of applicable laws and regulations, check whether the system operation records are consistent with the provisions of the documents, and ensure the closed-loop management of "writing, doing and writing".

Suitability: evaluate whether the compliance management system fits the business characteristics, organizational structure and risk characteristics of the enterprise, and investigate the operability of the document terms and the continuous adaptability of the system to the dynamic regulatory environment.

Adequacy: review whether the system documents fully cover the core elements required by the standards, fully identify the compliance risk points of key business processes, and confirm whether the resource allocation is sufficient to support the effective operation of the system.

Effectiveness: To verify whether the system achieves the expected result of "prevention-discovery-response to non-compliance" through multi-dimensions such as compliance target achievement rate, risk control effect and employee compliance awareness survey.

Certification value

Enhance business opportunities and sustainability: certified enterprises can show their compliance management ability in line with international standards to customers and partners, convey business trust in customer cooperation, multilateral cooperation and government cooperation, and enhance market competitiveness.

Protect and strengthen the reputation of the organization: through systematic compliance management, effectively prevent and respond to non-compliance behaviors, and protect and strengthen the reputation and credibility of the organization.

Reduce the risk of illegal acts: systematically identify and manage compliance risks, and reduce the probability of illegal acts and the resulting costs, fines and reputation losses.

Obtaining administrative supervision incentives: the operation of the compliance management system can be used as a consideration factor for regulators and judicial institutions to measure the punishment, and provide a reference for regulators to adopt the compliance rectification plan of the organization.

Control operating costs: Improve compliance management ability, optimize resource allocation and control operating costs through systematic management methods.

Enhance the trust of interested parties: consider and meet the expectations of interested parties, and enhance the confidence of third parties in the ability of the organization to succeed continuously.

03

عملية الخدمة

04

ملف القواعد

هل تحتاج إلى هذه الشهادة؟

اتصل بنا