International (ISO/TC 309); adopted as BS ISO 37002:2021 and others

ISO 37002:2021

109 controls. 22 other frameworks in our corpus share controls with it. Here is all of it, and how much of it you are already doing.

Page built . This page is derived from the framework corpus, which changes when the corpus is extended rather than daily.

109 controls 22 frameworks share controls with it International (ISO/TC 309); adopted as BS ISO 37002:2021 and others verified against its source document

Every control below is one this framework asks for. The right hand column counts how many other frameworks in our corpus carry the same control, which is the difference between doing this work once and doing it again for the next standard.

There is no implementation kit for this framework yet. The control list and the overlap above are free and complete.

What you already have

Frameworks whose controls overlap this one, most first. If you run any of them, the count is roughly what you have already evidenced.

Every control

CodeControlAlso in
ISO-37002-10.1Nonconformity and corrective action11
ISO-37002-10.2Continual improvement16
ISO-37002-4.1Understanding the organization and its context14
ISO-37002-4.2Understanding the needs and expectations of interested parties10
ISO-37002-4.3Determining the scope of the whistleblowing management system3
ISO-37002-4.4Whistleblowing management system0
ISO-37002-5.1Leadership and commitment15
ISO-37002-5.2Whistleblowing policy0
ISO-37002-5.3Organizational roles, responsibilities and authorities12
ISO-37002-6.1Actions to address risks and opportunities11
ISO-37002-6.2Whistleblowing management system objectives and planning0
ISO-37002-7.1Resources1
ISO-37002-7.2Competence0
ISO-37002-7.3Awareness and training1
ISO-37002-7.4Communication5
ISO-37002-7.5Documented information14
ISO-37002-8.1Receiving reports of wrongdoing0
ISO-37002-8.2Assessing reports of wrongdoing0
ISO-37002-8.3Addressing reports of wrongdoing0
ISO-37002-8.4Concluding whistleblowing cases0
ISO-37002-8.5Protection of whistleblowers0
ISO-37002-9.1Monitoring, measurement, analysis and evaluation11
ISO-37002-9.2Internal audit14
ISO-37002-9.3Management review15
ISO37002-10.1Continual Improvement16
ISO37002-10.2Nonconformity and Corrective Action11
ISO37002-4.1Organizational Context for Whistleblowing0
ISO37002-4.2Needs and Expectations of Interested Parties9
ISO37002-4.3Scope of the WBMS0
ISO37002-5.1Leadership and Commitment15
ISO37002-5.2Whistleblowing Policy0
ISO37002-5.3Roles, Responsibilities, Authorities12
ISO37002-6.1.2Whistleblowing Risk Assessment0
ISO37002-6.2Whistleblowing Objectives0
ISO37002-7.2Competence0
ISO37002-7.3Awareness1
ISO37002-7.4Communication5
ISO37002-7.5Documented Information14
ISO37002-8.2Receiving Reports of Wrongdoing1
ISO37002-8.3Assessing Reports0
ISO37002-8.4Addressing Reports of Wrongdoing0
ISO37002-8.5Concluding Whistleblowing Cases0
ISO37002-8.6Protection Against Detriment1
ISO37002-8.7Confidentiality and Data Protection3
ISO37002-9.1Monitoring, Measurement, Analysis, Evaluation10
ISO37002-9.2Internal Audit14
ISO37002-9.3Management Review15
1010 Improvement0
10.110.1 Continual improvement0
10.210.2 Nonconformity and corrective action0
44 Context of the organization0
4.14.1 Understanding the organization and its context0
4.24.2 Understanding the needs and expectations of interested parties0
4.34.3 Determining the scope of the whistleblowing management system0
4.44.4 Whistleblowing management system0
55 Leadership0
5.15.1 Leadership and commitment0
5.1.15.1.1 Governing body0
5.1.25.1.2 Top management0
5.25.2 Whistleblowing policy0
5.35.3 Roles, responsibilities and authorities0
5.3.15.3.1 Top management and governing body0
5.3.25.3.2 Whistleblowing management function0
5.3.35.3.3 Delegated decision-making0
66 Planning0
6.16.1 Actions to address risks and opportunities0
6.26.2 Whistleblowing management system objectives and planning to achieve them0
6.36.3 Planning of changes0
77 Support0
7.17.1 Resources0
7.27.2 Competence0
7.37.3 Awareness0
7.3.17.3.1 General0
7.3.27.3.2 Personnel training and awareness measures0
7.3.37.3.3 Training for leaders and other specific roles0
7.47.4 Communication0
7.57.5 Documented information0
7.5.17.5.1 General0
7.5.27.5.2 Creating and updating documented information0
7.5.37.5.3 Control of documented information0
7.5.47.5.4 Data protection0
7.5.57.5.5 Confidentiality0
88 Operation0
8.18.1 Operational planning and control0
8.28.2 Receiving reports of wrongdoing0
8.38.3 Assessing reports of wrongdoing0
8.3.18.3.1 Assessing the reported wrongdoing0
8.3.28.3.2 Assessing and preventing risks of detrimental conduct0
8.48.4 Addressing reports of wrongdoing0
8.4.18.4.1 Addressing the reported wrongdoing0
8.4.28.4.2 Protecting and supporting the whistleblower0
8.4.38.4.3 Addressing detrimental conduct0
8.4.48.4.4 Protecting the subject(s) of a report0
8.4.58.4.5 Protecting relevant interested parties0
8.58.5 Concluding whistleblowing cases0
99 Performance evaluation0
9.19.1 Monitoring, measurement, analysis and evaluation0
9.1.19.1.1 General0
9.1.29.1.2 Indicators for evaluation0
9.1.39.1.3 Information sources0
9.29.2 Internal audit0
9.2.19.2.1 General0
9.2.29.2.2 Internal audit programme0
9.39.3 Management review0
9.3.19.3.1 General0
9.3.29.3.2 Management review inputs0
9.3.39.3.3 Management review results0
STANDARDISO 37002:2021: scope, the three principles, the four steps and the harmonized structure0
STATUSStatus: guidance, not certifiable; the EU Whistleblower Directive beside it0

Tell me when ISO 37002:2021 files something new

One email when a public company newly discloses something this framework governs, naming the company and what our corpus says it puts in scope. Nothing else, and one click to stop.

What an auditor will ask you to produce

The artefacts named on the failure modes this framework speaks to.

  • Audit reports
  • Risk-based audit plan
  • Findings tracker
  • Audit programme
  • Auditor competence records
  • audit plan
  • Trend and foresight scan report
  • IMS scope statement signed by leadership
  • Innovation context register
  • Innovation maturity baseline assessment

How programmes fail on this

Failure modes named by this framework and others. Each opens the full record.

What this page is

A control-level reference for ISO 37002:2021, drawn from our framework corpus. Control codes and titles are references to the standard, not reproductions of it. The overlap counts and the auditor artefacts are our own work and are the part you will not find elsewhere.

Measure this against what you already run · All frameworks · Today's edition