Etas Excellent

In-House ISO 37001:2025 Internal Auditor Training Malaysia

Practical ABMS Internal Audit Training at Your Workplace

ETAS Excellent provides In-House ISO 37001:2025 Internal Auditor Training in Malaysia for organisations that need competent personnel to plan, conduct, report and follow up internal audits of their Anti-Bribery Management System (ABMS).

The training combines ISO 37001:2025 requirements with practical auditing techniques based on the principles of ISO 19011, allowing participants to practise audit planning, developing audit questions, interviewing auditees, reviewing objective evidence, identifying nonconformities and preparing meaningful audit reports.

Training can be conducted at your organisation’s workplace and customised using your actual ABMS processes, departments, policies and bribery risks.

✓ In-House Training at Your Workplace
✓ ISO 37001:2025 Current Edition
✓ Practical Internal Audit Exercises
✓ ISO 19011 Auditing Techniques
✓ Audit Checklist Development
✓ NCR & Audit Finding Writing
✓ HRD Corp Claimable – subject to eligibility
✓ Available Across Malaysia

REQUEST ISO 37001 INTERNAL AUDITOR TRAINING

WhatsApp: 018-314 4182
Email: training@etasexcellent.com


What Is ISO 37001:2025 Internal Auditor Training?

ISO 37001:2025 provides requirements and guidance for organisations to establish, implement, maintain and improve an Anti-Bribery Management System designed to prevent, detect and respond to bribery.

Internal auditing is an important part of determining whether the ABMS is:

  • Properly implemented
  • Conforming to organisational requirements
  • Conforming to ISO 37001 requirements
  • Operating effectively
  • Producing appropriate objective evidence
  • Identifying weaknesses and opportunities for improvement

An internal audit should go beyond checking whether procedures exist.

Auditors need to determine whether anti-bribery controls are actually being implemented and are effective in practice.

Participants who are new to ISO 37001 requirements may first attend our ISO 37001:2025 Awareness Training Malaysia.

Internal link:
https://etasexcellent.com.my/iso-37001-awareness-training-malaysia/


Why ISO 37001 Internal Auditing Is Important

An organisation may have an Anti-Bribery Policy, bribery risk assessment, due diligence forms and whistleblowing procedures, but documentation alone does not demonstrate that the ABMS is effective.

Internal auditors need to determine what is actually happening.

For example, an auditor may need to establish whether:

  • Due diligence is really completed before appointing high-risk business associates
  • Procurement approvals follow defined controls
  • Gifts and hospitality are declared and approved
  • Conflict-of-interest declarations are completed
  • Bribery risk assessments reflect current operations
  • Employees understand reporting channels
  • High-risk transactions receive appropriate scrutiny
  • Corrective actions from previous audits are actually implemented

A good internal audit provides management with reliable information about whether the organisation’s anti-bribery controls are functioning as intended.


Who Should Attend?

This programme is suitable for:

  • ABMS internal auditors
  • Compliance personnel
  • Integrity officers
  • ISO management representatives
  • Risk management personnel
  • Quality personnel
  • Procurement personnel
  • Governance personnel
  • Department managers
  • Internal audit team members
  • Anti-bribery compliance function personnel
  • Management system auditors
  • G7 contractor ABMS team members
  • Personnel responsible for certification preparation

Participants should ideally have a basic understanding of ISO 37001:2025 requirements before attending the Internal Auditor programme.

Where required, ETAS Excellent can combine ISO 37001 requirements training with the Internal Auditor programme.


ISO 37001:2025 Internal Auditor Training Course Content

Module 1 – Understanding the Role of an ABMS Internal Auditor

Participants learn:

  • Purpose of internal auditing
  • Auditor responsibilities
  • Independence and objectivity
  • Auditor behaviour
  • Confidentiality
  • Evidence-based auditing
  • Risk-based audit thinking

The auditor’s role is not to blame employees but to determine whether the management system is properly implemented and identify areas requiring improvement.


Module 2 – Understanding ISO 37001:2025 Audit Criteria

Participants review the ISO 37001 requirements that may form part of the internal audit criteria.

Audit areas may include:

  • Context of the organisation
  • Leadership
  • Anti-bribery policy
  • Roles and responsibilities
  • Bribery risk assessment
  • Anti-bribery compliance function
  • Competence and awareness
  • Due diligence
  • Financial controls
  • Non-financial controls
  • Gifts and hospitality
  • Business associates
  • Reporting mechanisms
  • Investigation
  • Monitoring
  • Internal audit
  • Management review
  • Corrective action
  • Continual improvement

Module 3 – ISO 19011 Auditing Principles

Participants are introduced to practical internal auditing principles based on ISO 19011 guidance.

They learn the importance of:

  • Integrity
  • Fair presentation
  • Due professional care
  • Confidentiality
  • Independence
  • Evidence-based auditing
  • Risk-based approach

These principles help auditors conduct professional and credible ABMS audits.


Module 4 – Planning the Internal Audit

Participants learn how to establish:

Audit objective → audit scope → audit criteria → departments/processes → audit timing → audit team → audit methods

The programme explains why an effective audit should focus on areas of significant bribery risk rather than simply spending equal time on every department.


Module 5 – Preparing an ISO 37001 Audit Checklist

Participants learn how to develop practical audit questions.

Instead of asking only:

“Do you comply with the Gifts and Hospitality Procedure?”

the auditor should ask questions that produce objective evidence, such as:

“Please show me three recent gifts or hospitality declarations.”

“How do you determine when approval is required?”

“What happens when a proposed gift exceeds the approved limit?”

Participants practise converting ISO requirements into process-based audit questions.


Module 6 – Conducting the Opening Meeting

Participants learn how to conduct a professional audit opening meeting covering:

  • Audit objectives
  • Scope
  • Criteria
  • Audit schedule
  • Communication arrangements
  • Confidentiality
  • Sampling
  • Reporting arrangements

The programme emphasises maintaining a constructive and professional relationship with auditees.


Module 7 – Interviewing Auditees

Effective interviewing is one of the most important internal auditor skills.

Participants practise:

  • Asking open questions
  • Asking follow-up questions
  • Avoiding leading questions
  • Listening actively
  • Testing understanding
  • Following the audit trail
  • Maintaining professional communication

Example:

Rather than asking:

“You conduct supplier due diligence, correct?”

ask:

“Please explain how a new high-risk supplier is evaluated before approval.”


Module 8 – Collecting Objective Evidence

Participants learn to distinguish between:

Statements, assumptions and objective evidence.

Evidence may include:

  • Documents
  • Records
  • Interviews
  • Electronic systems
  • Approvals
  • Risk assessments
  • Due diligence records
  • Training records
  • Gifts registers
  • Conflict-of-interest declarations
  • Investigation records
  • Procurement records
  • Monitoring results

Auditors also learn the importance of appropriate sampling.


Module 9 – Auditing Bribery Risk Assessment

Participants practise evaluating whether the organisation’s bribery risk assessment:

  • Covers relevant activities
  • Considers appropriate business associates
  • Reflects current operations
  • Identifies high-risk processes
  • Is reviewed when circumstances change
  • Leads to appropriate controls

Example audit areas may include procurement, tendering, subcontractor appointment, government interaction and high-value transactions.


Module 10 – Auditing Due Diligence

Participants learn how to audit due diligence arrangements involving:

  • Suppliers
  • Contractors
  • Agents
  • Consultants
  • Joint ventures
  • Business partners
  • High-risk personnel
  • Projects
  • Transactions

The auditor should determine not only whether a due diligence form exists, but whether the depth of review is appropriate to the identified bribery risk.


Module 11 – Auditing Financial & Non-Financial Controls

Audit examples may include:

Financial controls

Payment approvals, supporting documentation, segregation of duties, expenses and invoice verification.

Non-financial controls

Procurement, tendering, supplier appointment, contractor selection, recruitment and project approvals.

Participants practise following an audit trail across different departments rather than auditing each department in isolation.


Module 12 – Auditing Gifts, Hospitality & Conflicts of Interest

Participants learn to review evidence relating to:

  • Gifts
  • Meals
  • Hospitality
  • Entertainment
  • Travel
  • Donations
  • Sponsorship
  • Conflict-of-interest declarations

Auditors evaluate whether controls are understood and consistently implemented.


Module 13 – Reporting & Whistleblowing Controls

Participants practise auditing whether employees understand:

  • How to raise concerns
  • Available reporting channels
  • Confidentiality arrangements
  • Escalation requirements
  • Protection against retaliation

The audit should assess both the documented process and employee awareness.


Module 14 – Writing Audit Findings

One of the key practical skills developed during the course is writing clear, evidence-based findings.

Participants learn how to distinguish between:

Conformity
Nonconformity
Opportunity for Improvement
Observation, where used by the organisation

A good nonconformity should clearly identify:

Requirement + objective evidence + identified gap


Module 15 – Writing an Effective NCR

Example:

Weak finding:

Due diligence is poor.

Better finding:

The organisation’s Business Associate Due Diligence Procedure requires enhanced due diligence for high-risk suppliers. Review of three high-risk suppliers selected during the audit found that enhanced due diligence records were unavailable for two suppliers.

Participants practise producing findings that are specific, factual and supported by evidence.


Module 16 – Closing Meeting & Audit Reporting

Participants learn how to:

  • Present findings
  • Explain evidence
  • Avoid arguments
  • Clarify misunderstandings
  • Present positive practices
  • Communicate nonconformities
  • Agree on follow-up arrangements
  • Prepare the audit report

Module 17 – Corrective Action & Audit Follow-Up

Finding a problem is only part of the audit process.

Participants learn the importance of:

  • Root-cause analysis
  • Corrective-action planning
  • Implementation
  • Verification
  • Follow-up
  • Closing findings only when adequate evidence exists

The auditor should verify whether corrective action addresses the cause of the problem, rather than simply correcting the individual record identified during the audit.


Practical ISO 37001 Internal Audit Activities

ETAS Excellent places strong emphasis on practical auditing exercises.

Activities can include audit checklist development, reviewing sample ABMS documents, interview role-play, objective-evidence exercises, finding-the-nonconformity case studies, NCR-writing exercises, mock internal audits, closing-meeting simulations and corrective-action review.

For in-house training, case studies can be customised around your actual organisation and industry.


ISO 37001 Internal Audit for Contractors

Construction and government contractors may face significant bribery exposures involving:

  • Tendering
  • Procurement
  • Subcontractors
  • Project consultants
  • Government interaction
  • Licensing
  • Claims
  • Variation orders
  • Inspections
  • Project approvals
  • Gifts and hospitality

The Internal Auditor programme can therefore be customised for contractor and construction-sector ABMS processes.


ISO 37001 and CIDB G7 Contractors

ISO 37001 has become particularly relevant for G7 contractors.

CIDB published information in 2026 concerning mandatory Anti-Bribery Management System certification requirements for G7 contractors.

For contractors implementing an ABMS, developing capable internal auditors is particularly important because the organisation will need to evaluate its own system before proceeding through management review and external certification activities.

ETAS Excellent can customise its ISO 37001 Internal Auditor Training for G7 contractors using examples involving tendering, procurement, subcontractors and project management.

For broader implementation preparation, visit our ISO 37001:2025 Training & Certification Support page.


Learning Outcomes

Upon successful completion, participants should be able to:

  • Explain the purpose of an ISO 37001 internal audit
  • Apply basic ISO 19011 auditing principles
  • Plan an ABMS internal audit
  • Define audit scope, criteria and objectives
  • Prepare an effective audit checklist
  • Conduct opening and closing meetings
  • Interview auditees professionally
  • Collect and evaluate objective evidence
  • Follow audit trails
  • Evaluate implementation of ABMS controls
  • Identify nonconformities
  • Write clear audit findings
  • Prepare internal audit reports
  • Evaluate corrective actions
  • Conduct audit follow-up activities

This aligns with the typical Internal Auditor learning outcomes used by established ISO 37001 training providers, including planning, conducting, reporting and following up audits.


Benefits of In-House ISO 37001 Internal Auditor Training

Conducting the programme at your workplace allows the training to use examples based on your:

  • ABMS
  • Bribery risk assessment
  • Anti-bribery policies
  • Procurement process
  • Tender process
  • Due diligence procedures
  • Gifts and hospitality process
  • Whistleblowing arrangements
  • Departments
  • Actual audit programme

This makes the learning directly applicable when participants return to their internal audit responsibilities.


In-House ISO 37001 Internal Auditor Training Across Malaysia

ETAS Excellent provides In-House ISO 37001 Internal Auditor Training throughout Malaysia, including Kuala Lumpur, Selangor, Putrajaya, Negeri Sembilan, Melaka, Johor, Penang, Perak, Kedah, Pahang, Terengganu, Kelantan, Perlis, Sabah and Sarawak.

Training can be arranged at the client’s office, project office, training facility or other suitable workplace.


Why Choose ETAS Excellent?

Our Internal Auditor programme focuses on practical auditing skills rather than memorising clauses.

Participants learn through realistic exercises involving audit trails, objective evidence, interviewing, finding evaluation and NCR writing.

For organisations already implementing ISO 37001, the programme can also be customised to use relevant company documentation and processes.

Eligible employers may apply for applicable HRD Corp training grants, subject to current requirements and approval.


Frequently Asked Questions

What is ISO 37001:2025 Internal Auditor Training?

It is a practical programme designed to develop personnel who can conduct internal audits of an organisation’s Anti-Bribery Management System.

Is ISO 37001:2025 the latest edition?

Yes. ISO 37001:2025 is the current second edition and was published in February 2025.

How long is the training?

I recommend positioning ETAS’s Internal Auditor programme as a 2-day training course, which also aligns with the format used by established providers such as BSI Malaysia.

Do participants need ISO 37001 knowledge beforehand?

Basic understanding of ISO 37001:2025 is strongly recommended.

Participants who need the fundamentals first can attend our ISO 37001:2025 Awareness Training Malaysia

Does the programme include practical exercises?

Yes. The programme includes practical internal-audit activities such as audit planning, checklist development, interviews, evidence evaluation, NCR writing and audit reporting.

Can ETAS conduct the training at our company?

Yes. ETAS Excellent provides In-House ISO 37001 Internal Auditor Training throughout Malaysia.

Is this suitable for G7 contractors?

Yes. The training can be customised around contractor-related ABMS risks, including procurement, tendering, subcontractors and project activities.

Does ETAS issue ISO 37001 certification?

No. ETAS Excellent provides training, consultancy, internal audit and certification-readiness support. Independent certification is conducted by the relevant certification body.

For implementation assistance, visit our ISO 37001 ABMS Certification & Consultancy Malaysia page.


Continue Your ISO 37001 Development

Need ISO 37001 Awareness First?

For management and employees who need to understand ABMS requirements before internal-auditor training:

ISO 37001:2025 Awareness Training Malaysia

Need Complete ABMS Support?

For gap assessment, implementation and certification preparation:

ISO 37001:2025 Training & Certification Support

Need Consultancy?

ISO 37001 ABMS Certification & Consultancy Malaysia


Request In-House ISO 37001:2025 Internal Auditor Training

Develop your internal audit team with practical ISO 37001:2025 ABMS auditing skills.

✓ 2-Day Internal Auditor Training
✓ Training at Your Workplace
✓ ISO 37001:2025 Current Edition
✓ ISO 19011 Auditing Approach
✓ Practical Audit Exercises
✓ Audit Checklist Development
✓ NCR Writing Practice
✓ G7 Contractor Customisation Available
✓ Nationwide In-House Training
✓ HRD Corp Claimable – subject to eligibility

REQUEST A QUOTATION

WhatsApp: 018-314 4182
Email: training@etasexcellent.com

Contact ETAS Excellent to arrange In-House ISO 37001:2025 Internal Auditor Training for your organisation.