Our own servers in Europe · GDPR · Support in your language

Module 5 of 7 · ISO 37301 · Clause 8

Operation

Operation turns policy into real controls: due diligence on partners and suppliers, and procedures that prevent noncompliance before it happens.

Content reviewed on

Operational controls

Specific controls for the identified noncompliance risks, built into everyday processes.

Third-party due diligence

Assessing the compliance risk of business partners, suppliers and other relevant third parties.

Delegation of authority

Clear authority and approval limits for decisions carrying compliance risk.

What an auditor usually asks for

  • Documented compliance controls by risk
  • A due diligence assessment for relevant third parties
  • An authority delegation matrix for critical decisions
  • An approval log for risk-bearing operations

How to cover operation in Kimobox

  1. 1Document compliance controls directly on the process map.
  2. 2Log due diligence for every relevant third party from the supplier portal.
  3. 3Set up the authority delegation matrix in the system.

Every third party's due diligence stays linked to their record, with the re-evaluation scheduled.

See Kimobox's supplier portal

Where each figure comes from

References to the official text in force. If a standard is revised, this page is updated and the review date says so.

  1. ISO 37301:2021 — Compliance management systems. Requirements with guidance for use ISO · April 2021
  2. Ley 2/2023 on the protection of persons who report regulatory breaches BOE-A-2023-4513 · 21 February 2023
  3. ISO 37001:2016 — Anti-bribery management systems ISO · 2016 ed.