Skip to product information
1 of 1

Information Security, Risk & Business ContinuityAGS-08-006

ISO 37301 2021 CMS

ISO 37301 2021 CMS

Know every obligation the organisation is bound by, who owns it, and how a breach would come to light.

Regular price $790USD
Regular price USD Sale price $790USD
Taxes included.
Secure checkout American Express Apple Pay Diners ClubDiscoverGoogle Pay JCBMastercard Visa

Written by practising auditors with 20+ years in the field.

Preview free samples

View full details
46 ready-to-use documents 46 Word · plus the AGS license

By document type

Total 46
CategoryFiles
Manuals2
Policies1
Procedures & SOPs10
Forms & Records22
Checklists & Audit Tools3
Registers, Logs & Matrices3
Training & Awareness4
Guides & Work Instructions1

Key documents

ReferenceDocumentFormat
CMS-01Compliance Management System Manual Word
Policy 01 Compliance Policy Word
PRO-SYS-10Procedure for Compliance Risk Management Word
PRO-SYS-06Procedure for Compliance with Legal & Other Requirements Word
ROR Register of Rules & Regulations Word
CK-SYS-01ISO 37301-2021 Clause-wise Implementation Checklist Word

Overview

ISO 37301:2021 sets out requirements and guidelines for establishing, implementing, evaluating, maintaining and improving a compliance management system. Compliance obligations, in its terms, are both mandatory — laws and regulations — and voluntary: codes of conduct, contractual commitments, standards and the organisation's own values. It applies across all types, sizes and sectors, public, private and not-for-profit, and concerns boards, senior management, compliance and legal functions, risk teams and all personnel with compliance duties. It supersedes ISO 19600 and, as a type A management system standard, contains auditable requirements.

The structure is the harmonised one — context, leadership, planning, support, operation, performance evaluation and improvement — driven by Plan-Do-Check-Act and grounded in good governance, integrity, transparency, accountability and sustainability. The standard asks an organisation to identify and assess its obligations and compliance risks, set a policy supported by top management and a defined compliance function, put controls in place, train and communicate, provide routes for raising concerns and whistleblowing, investigate what is reported, then monitor and improve. The risk-based approach aligns with ISO 31000, the system integrates with ISO 9001, ISO 37001 for anti-bribery and ISO 27001, and accredited certification is open to those wanting independent assurance.

What this system covers

  • Compliance obligations — a maintained register of applicable rules, and tracking of legal change
  • Compliance risk management — assessing obligations by likelihood and consequence, assigning controls
  • Policy, governance and culture — the compliance function, management commitment, code of conduct
  • Raising concerns and whistleblowing — reporting routes, protection of the reporter, case handling
  • Incident management and investigation — recording and remedying suspected non-compliance
  • Training, communication and competence — awareness for all personnel and role-specific duties
  • Evaluation and improvement — clause-wise review, internal audit and corrective action

Who it's for

Compliance officers, general counsel, company secretaries and governance managers in regulated and multi-jurisdiction organisations. The purchase tends to follow a decision to certify, a regulator's enquiry, a parent company requiring a documented compliance management system, or the move on from ISO 19600. The end state is a maintained register of rules and regulations, risks assessed and owned by name, working channels for concerns, and audit records showing the system operates rather than merely exists.

Everything you get

Every toolkit gives you a full set of working documents for your standard, ready to edit and use.

Editable Word and Excel

Native Microsoft files. Add your logo and adapt every document to how you work.

Instant download

Your full toolkit arrives as a ZIP the moment payment clears.

Unlimited users

One purchase covers everyone in your organisation. No per-seat fees.

Written by auditors

Built by people who run real audits, so the content matches what assessors check.

Yours to keep

One payment, perpetual licence for your organisation. No subscriptions, no renewals.

Refund guarantee

Full refund if your files are faulty, incomplete or not as described and we can't put it right

Frequently asked questions

What exactly do I receive?

A downloadable ZIP containing the full set of ready-to-use documents for this toolkit — manuals, procedures, forms, records, checklists, guidance and training material, all in editable Word and Excel format. The exact document count is shown at the top of this page.

Are the documents really editable?

Yes. Every file is native Microsoft Word or Excel — no locked PDFs. Add your logo, change wording, and tailor the content to your organisation. The toolkit is yours to keep and reuse.

Does this certify my organisation?

No. These are documentation toolkits aligned to the relevant standard to help you prepare. Certification itself is issued by an accredited certification body after their audit. Our toolkits give you a strong, audit-ready starting point.

How is it delivered?

Instantly and digitally. There's no physical shipment — you download the files right after payment and receive a backup link by email.

Do I get updates?

Yes. If we revise this toolkit, you're entitled to the updated version at no extra cost — just contact us with your order details.

What is your refund policy?

These are digital products, so once a toolkit has been downloaded we cannot take it back. If you have not downloaded yet, contact us and we will cancel the order and refund you in full. We also refund in full if the files are damaged, incomplete, or not what the product page described.

Cannot find your standard?

Tell us which scheme you work to. We will point you to the right toolkit.

Request a toolkit