Our own servers in Europe · GDPR · Support in your language

Module 7 of 7 · ISO 37301 · Clause 10

Improvement

The final clause closes the loop: how a report gets investigated, and how that investigation improves the system, not just closes a case.

Content reviewed on

Investigating reports and noncompliance

An impartial investigation procedure, with documented conclusions and actions proportionate to severity.

Nonconformity and corrective action

When noncompliance occurs, identify the root cause and implement the corrective action with an effectiveness check.

Continual improvement

Updating the risk map and controls based on what each investigation teaches.

What an auditor usually asks for

  • An investigation log with documented conclusions
  • Disciplinary or corrective actions proportionate to each case
  • Effectiveness verification of corrective actions
  • An updated risk map after every significant noncompliance

How to cover improvement in Kimobox

  1. 1Manage every report investigation with its conclusion and linked action in Kimobox.
  2. 2Log the corrective action for each noncompliance with its owner and date.
  3. 3Update the compliance risk map after every significant noncompliance.

Every investigation stays linked to its conclusion, its action and the risk-map update it triggered.

See nonconformities and corrective actions in Kimobox

Where each figure comes from

References to the official text in force. If a standard is revised, this page is updated and the review date says so.

  1. ISO 37301:2021 — Compliance management systems. Requirements with guidance for use ISO · April 2021
  2. Ley 2/2023 on the protection of persons who report regulatory breaches BOE-A-2023-4513 · 21 February 2023
  3. ISO 37001:2016 — Anti-bribery management systems ISO · 2016 ed.