Our own servers in Europe · GDPR · Support in your language

Software for ISO 37301

ISO 37301, without folders or surprises

A certifiable compliance management system, the successor to ISO 19600, with risks, controls and a whistleblowing channel in one system.

What it is and which edition applies

ISO 37301 is the certifiable standard for compliance management systems. In 2021 it replaced ISO 19600, which only offered guidelines. It requires identifying compliance obligations and their associated risks, establishing proportionate controls, giving the compliance function genuine independence, providing a channel to raise concerns without retaliation, and demonstrating the governing body's commitment through facts rather than statements.

Content reviewed on

Current edition
ISO 37301:2021 Published April 2021
Standard replaced
ISO 19600:2014 That was guidance; ISO 37301 is certifiable
Key requirement
Independence of the compliance function With direct access to the governing body
Whistleblowing channel
Required by the standard and by law Law 2/2023 in Spain, for companies with 50 or more people
Related standard
ISO 37001:2016 Anti-bribery management systems

Document control

Versions, approvals and distribution with read receipts.

Connected to your document cloud

Publish and version documents by connecting to OneDrive, Google Drive or SharePoint, without duplicating folders.

Audits

Annual program, checklists per standard, findings linked to actions.

Non-conformities

Root cause, action, owner, deadline and effectiveness check.

KPIs

Process objectives fed with real operating data.

Legal requirements

A register of legal and other requirements, with validity and compliance evaluation per standard.

Corrective actions

Root cause, action, owner, deadline and effectiveness check, all linked to the nonconformity.

Improvement actions

Improvement opportunities with an owner and tracking, beyond just fixing what already failed.

Management review

A pre-built report with indicators, audits and nonconformities, ready for the meeting.

Certifiable system

Risks, controls and a whistleblowing channel in a single system.

Whistleblowing channel

Every case with its traceability through to closure.

Risk map by area

Nonconformity risks identified and prioritized by area.

Management review

Compliance report ready for the periodic system review.

Requirements covered


What it solves for ISO 37301

  • Compliance risk map by area
  • Compliance policy and procedures
  • A whistleblowing channel with case traceability
  • Role-based compliance training
  • Nonconformities and corrective actions
  • Internal audits and management review
Quality / ISO 37301
Document control
Connected to your document cloud
Audits
Non-conformities
RECORDS

Frequently asked questions


What people ask us before getting started

Which edition of the standard is current?

The edition in force is ISO 37301:2021. When the issuing body publishes a new one, a transition period opens; once it closes, certificates issued against the previous edition stop being valid.

Does this work if we are already certified?

Yes. Your existing system — processes, documents, records, audit history — is loaded in and kept alive from day one. Nothing needs redesigning and the certification cycle does not restart.

Will the auditor accept digital records?

Yes, provided they are traceable, controlled and able to show who did what and when. No standard requires paper; every standard requires reliable evidence, and a properly controlled electronic record provides it better than a folder.

Can it be combined with other standards?

Yes, and that is the sensible route. The common Annex SL structure lets a single integrated system share the process map, document control, internal audits, nonconformities and indicators between ISO 37301 and the rest, leaving only the standard-specific parts separate.

How long does it take to be ready for an audit?

It depends on the starting point. An organisation already working with written procedures is usually ready in two or three months; one starting from scratch needs longer. The bottleneck is rarely the tool — it is the availability of the people who know the processes.

What happens to the documentation we already have?

It is migrated. Existing procedures, forms and records are loaded with their version and approver, so the history is not lost and the system starts with the memory the organisation already had.

Can the auditor look directly at the system?

Yes. They are given read-only access with a defined scope and an expiry date. It is more comfortable for both sides than preparing a folder of screenshots and exports.

What is the difference between a major and a minor nonconformity?

A major one compromises the system's ability to meet a requirement — a required process missing altogether, systematic failure, or a failure affecting the product — and usually blocks certification until it is closed. A minor one is a specific lapse resolved with an action plan.

Are the indicators calculated automatically?

Yes, from the data the processes themselves generate. That is the difference between a dashboard that reflects what is happening and a spreadsheet somebody fills in the week before the management review.

Does it work across several sites or legal entities?

Yes. The model is multi-company and multi-site: what makes sense to share is shared, and what belongs to each location stays separate — including the certificate scope where it differs.

Get ready for your ISO 37301

We'll show you the module running with data similar to yours.

Request a demo

Sources


Where each figure comes from

References to the official text in force. If a standard is revised, this page is updated and the review date says so.

  1. ISO 37301:2021 — Compliance management systems. Requirements with guidance for use ISO · April 2021
  2. Ley 2/2023 on the protection of persons who report regulatory breaches BOE-A-2023-4513 · 21 February 2023
  3. ISO 37001:2016 — Anti-bribery management systems ISO · 2016 ed.

Software for ISO 37301 — Compliance management systems

Kimobox is a software for ISO 37301 that digitizes the requirements of the standard: compliance risk map by area, compliance policy and procedures, a whistleblowing channel with case traceability, role-based compliance training, with full traceability and evidence ready for the auditor.

The platform lets you run an integrated management system that combines ISO 37301 with other ISO standards and sector protocols, sharing the process map, document control, internal audits, non-conformities and KPIs.