Established model
ISO 37301 compliance management systems
International Organization for Standardization · 2021
A standard for running compliance as a managed system rather than a series of reactions to the last incident.
Its place in the frameworkBusiness Core›Compliance
What it does
It asks an organisation to identify its compliance obligations, assess the risk of failing them, assign responsibility, train, monitor, investigate and improve — and, unlike its predecessor, it can be certified. Its most practical demand is the register of obligations itself, which many companies discover they have never written down.
- Reach for it when
- When compliance is organised around whichever regulator last got in touch, and when a customer or partner asks for evidence rather than assurances.
- Where it stops
- Certification proves a system exists, not that the organisation behaves well. A company can be certified and still reward the conduct the system is meant to prevent.
ISO 37301, Compliance management systems — Requirements with guidance for use, International Organization for Standardization, 2021; replacing ISO 19600, 2014.
Why it sits at Compliance
The obligations the organisation has no choice about — legal, regulatory, contractual and financial, environmental law included — and the controls that keep them met.
A model is only useful when you reach for it at the right moment. This one answers a question that arises here — so it is filed here, and nowhere else. These are the working areas it serves:
- Regulatory mappingCompliance management practice on obligation registers, which underpin everything downstream.
- ControlsInternal control frameworks such as COSO, and the preventive-detective-corrective distinction.
- MonitoringInternal audit practice on control testing, and the three-lines model separating operation, oversight and assurance.
- Incident responseIncident response practice, including statutory notification windows such as the seventy-two hours required under GDPR.
What it touches elsewhere
Nothing in a business is decided on its own. A conclusion reached with this model at Compliance lands in these other cores, whether or not anyone follows it there.
- Business CoreControls live inside operational systems; obligations often flow through partners and the supply chain.
- Data CoreData governance is where much of modern compliance actually sits.
- Brand CoreA compliance failure is a brand event before it is a legal one.
- ResponsibilityVoluntary commitments, sustainability targets and ethics above the legal minimum are owned there; this object keeps what the organisation has no choice about.
- GovernanceThe enterprise risk register is held there; compliance risks are entered in it, not kept in a register of their own.
Filed at the same place
These answer questions that arise at Compliance too. Where they disagree with this one, the disagreement is the useful part.
- COSO Internal Control — Integrated FrameworkA shared definition of internal control, broken into the components that all have to be present and working.
Elsewhere in Business Core
- Tuckman’s stages of group development
- Belbin Team Roles
- Herzberg’s two-factor theory
- Jobs to be done
- The Kano model
- The value proposition canvas
- The business model canvas
- The Van Westendorp price sensitivity meter
- Value-based pricing
- Core competence
- VRIO
- The resource-based view
- The theory of constraints
- Lean thinking
- Co-opetition and the value net
- Transaction cost economics
- Stakeholder theory
- The power–interest grid
- DuPont analysis
- Break-even and cost–volume–profit analysis
- Unit economics
- The Kraljic Matrix
- The bullwhip effect
- The SCOR Model
- On-time in-full
- Overall equipment effectiveness
- Value stream mapping
- The three lines model
- ISO 31000 risk management
- Maslow’s hierarchy of needs
- Kotter’s eight-step change model
- Situational leadership
- The Lean Startup
- Design thinking
- Porter’s value chain
- The McKinsey 7S framework
- Six Sigma and DMAIC
- Stage-gate
- Beyond budgeting
- Dynamic capabilities
- Intangible assets
- The four S’s of intangible investment
- Net present value and discounted cash flow
- The Modigliani–Miller theorem
- The pecking order theory
- COSO Enterprise Risk Management
- Agency theory
- Mintzberg’s organisational configurations
- The Star Model
- Lewin’s change model
- The ADKAR model
- Effectuation
- Open innovation
- The technology acceptance model
- The NIST Cybersecurity Framework
- The TOGAF Standard
- Wardley mapping
- Failure mode and effects analysis
These are other people’s models, named here so you can go to the source and use them properly. The Omnigoal is not affiliated with their authors and is not endorsed by them; nothing of theirs is reproduced here — no canvas, no diagram, no wording. Each is described in our own words, with the originator credited, because the framework is a place to put thinking, not a replacement for the people who did it. Model names and trademarks belong to their respective owners and are used here only to refer to the work itself.
All 166 models