What the standard is for
ISO 37301 is the international standard for compliance management systems. Strip away the management-system language and it asks a compliance function five questions: What are your obligations? What are the risks of not meeting them? What controls treat those risks? How do you know the controls are operating? What do you report, to whom, and what do you do about what you learn?
Those are also the five questions a regulator asks on a visit, which is why the standard is worth understanding even if you never intend to certify to it.
The shape it describes
Obligations. Identify them, keep them current, and know which apply to which part of the business. In practice that is a register of obligations by source (a code, a handbook, a law, an internal policy), maintained as the sources change.
Compliance risk. Assess the risk of not meeting each obligation, using a recognised risk method (the standard points at ISO 31000). Inherent and residual scoring against a stated appetite is the common expression of this (see Inherent, residual and appetite).
Controls. Put in place the policies, procedures and checks that treat those risks, and map them to the obligations they satisfy, so coverage can be shown.
Monitoring. Test that the controls operate, on a plan, with evidence, and raise and track corrective actions when they do not. The plan itself is the compliance monitoring programme.
Reporting and improvement. Report to the governing body on the state of compliance, and feed what monitoring finds back into the obligations, risks and controls.
Around those sit the things every management-system standard asks for: leadership commitment, defined roles, competence, documentation, and a periodic review of the whole.
What alignment means, and what it does not
A compliance function or a piece of software can be aligned to ISO 37301 without being certified. Aligned means the structure follows the standard: obligations connect to risks, risks to controls, controls to monitoring, monitoring to reporting, and there is a trail through all of it. It does not mean an external body has audited the firm against the standard, and it does not mean the firm is compliant with any particular regulation. Software cannot make that claim on a firm’s behalf and should not imply it.
The honest way to describe it: the standard is the spine, and the surface speaks the language a compliance officer uses every day.
Why the structure matters more than the badge
The value of ISO 37301 to most compliance functions is not the certificate. It is the discipline of the connections. A function that keeps obligations in one file, risks in another, controls in a policy folder and monitoring in a calendar has all the parts of the standard and none of the system, because the parts do not know about each other. A rule change does not update the risk; a failed test does not lower a control rating; a board report is assembled by hand and disagrees with the register beside it.
Put the parts on one data model and the standard’s shape appears without ceremony: coverage reports (obligations without controls, controls without tests) answer themselves, and the audit trail runs from the obligation to the board paper.
Where ISO 27001 and ISO 31000 fit
ISO 31000 is the risk management method the standard leans on: identify, analyse, evaluate, treat, monitor. A compliance function uses it to score compliance risk. ISO/IEC 27001 is a different thing altogether: information security management for the organisation running the software. A software vendor certified to 27001 is telling you about its own security estate, not about your compliance.
How Vantage Point relates to it
Vantage Point is aligned to ISO 37301 (the methodology spine: obligations, risks, controls, CMP, actions and reports on one data model with one audit trail) and to ISO 31000 for the risk method. It does not claim certification to either, and it does not claim your firm is compliant with anything. Vantage Point Limited is certified to ISO/IEC 27001 for information security management. See About, Security and the CMP module.
Questions
- What is ISO 37301?
- ISO 37301 is the international standard for [compliance management systems](/glossary#compliance-management-system) (published by ISO in 2021, [ISO 37301:2021](https://www.iso.org/standard/75080.html)). It describes how an organisation identifies its compliance obligations, assesses the risks of not meeting them, puts controls in place, monitors whether they operate, and reports and improves. It is a management-system standard, in the same family as ISO 27001 for information security.
- Does a compliance function need to be certified to ISO 37301?
- No. Certification is optional and comparatively rare in financial services. Most firms use the standard as a structure: a way to check that obligations, risks, controls, monitoring and reporting connect. Software that is aligned to it uses the same structure without any certification claim on the firm's behalf.
- What is the difference between ISO 37301 and ISO 31000?
- ISO 37301 is the compliance management system: obligations through to reporting. ISO 31000 is the risk management method: how risk is identified, analysed, evaluated and treated. A compliance function uses 31000's method inside 37301's structure to assess compliance risk.
- Is Vantage Point certified to ISO 37301?
- No, and it does not claim to be. Vantage Point is aligned to ISO 37301 (its structure shapes how obligations, risks, controls, monitoring and reporting connect in the product) and to ISO 31000 for the risk method. Vantage Point Limited is certified to ISO/IEC 27001 for information security.