Overview - ISO 37303:2025 in brief
ISO 37303:2025, "Compliance management systems - Guidance for competence management," is an ISO guidance standard (first edition, 2025) that helps organizations determine and develop the competences needed to meet their compliance management objectives. It is applicable to all organizations - public, private and non-profit - and covers internal functions and relevant third parties. ISO 37303:2025 supports the competence and training requirements of ISO 37301 and does not change or add to existing mandatory requirements.
Key topics and technical highlights
- Scope and applicability: Guidance for competence determination and development across organizations of any size or sector.
- Competence concepts: Definitions for competence, knowledge and skill (references include ISO 37301 and ISO 30401).
- Competence management process: A PDCA (Plan–Do–Check–Act) approach for integrating competence into the compliance management system.
- Determining competence needs:
- Organizational competence and role-based criteria (governing body, top management, compliance function, managers, risk-exposed personnel).
- Competence requirements for third parties and contractors.
- Assessment and gap analysis: Methods for assessing current competence status, identifying development needs and assessing related compliance risks.
- Competence development:
- Planning and structuring development programmes (training, on-the-job learning, experience-building).
- Practical activities and programme governance, including roles and responsibilities.
- Evaluation and continuous improvement: Measuring effectiveness, maintaining documented information and improving competence management over time.
- Documentation and evidence: Guidance on records to demonstrate competence determination, individual qualifications, training outcomes and impact evaluation.
Practical applications - who uses ISO 37303:2025
- Compliance officers and compliance functions - to set role-specific competence criteria and training plans.
- Governance and top management - to ensure leadership has required capabilities to oversee compliance.
- HR and learning & development - to design hiring, onboarding and professional development aligned to compliance risks.
- Risk managers and operations leads - to identify risk-exposed roles and address competence gaps.
- Procurement and third‑party managers - to evaluate vendor/contractor competence where they pose compliance risk.
- Internal auditors and external advisors - to assess the effectiveness of competence programmes and recommend improvements.
Related standards
- ISO 37301:2021 - Compliance management systems - Requirements with guidance for use (primary normative reference).
- ISO 30401 - Knowledge management (referenced for knowledge/skill definitions).
ISO 37303:2025 is a practical tool for embedding competence into compliance management, strengthening compliance culture, reducing compliance risk, and aligning people capability with organizational objectives.