Quick Read
ISO/DIS 37200 separates governing body duties from top management duties into distinct clauses with materially different responsibilities, requiring boards to actively approve modern slavery policies, exercise oversight, and allocate resources rather than delegate the issue to compliance functions. Annex B explicitly addresses how corporate group structures create criminal liability exposure that individual functional owners cannot manage alone, making board-level ownership of this risk a governance imperative rather than a compliance option. Read against the EU Forced Labour Regulation's enforcement framework, which treats governance quality as a penalty factor, the paper demonstrates why modern slavery risk must be treated as a board accountability issue, not a departmental compliance problem.
Executive Summary
Modern slavery risk is routinely treated as a compliance-department problem in practice, even though the frameworks governing it are built around a different assumption entirely. ISO/DIS 37200's Clause 6 addresses governing bodies and top management directly and separately, with distinct duties for each, and its Annex B — Risk of Criminal Liability — is unusually direct for an ISO annex, describing how group corporate structures create criminal exposure that individual functional owners typically lack the authority to manage. Read against the EU Forced Labour Regulation's penalty framework, which explicitly treats governance quality as a factor in enforcement outcomes, the case for board-level ownership of this risk becomes difficult to avoid.
This paper works through ISO/DIS 37200's leadership requirements, examines Annex B's criminal liability analysis in detail, and sets out how SPK DDMS2000:2026's accountability structure is designed to close the authority gap Annex B identifies.
1. Two Distinct Roles, Two Distinct Duty Sets
ISO/DIS 37200 does something many governance-adjacent standards do not: it separates the governing body's duties from top management's duties into two distinct subclauses, 6.1 and 6.2, with materially different content in each — rather than treating "leadership" as a single undifferentiated tier, with a note in 6.1 that in a small organization the two may be the same person.
Clause 6.1 sets out ten governing-body duties: approving the organization's values and principles to reflect commitment against unethical behaviour; approving the modern slavery policy itself; exercising oversight over top management's operations relating to modern slavery; ensuring resources are allocated for effective risk management; ensuring top management is measured against modern slavery risk management objectives; exercising oversight over implementation and evaluating effectiveness through risk and performance indicators; ensuring whistleblowing and grievance mechanisms are in place; providing training and regulatory updates for governing body members themselves; approving reporting mechanisms such as a modern slavery statement; and receiving and reviewing information on the operation of the organization's risk management approach at planned intervals.
Clause 6.2 sets out top management's duties separately, and at greater length — seventeen distinct items spanning strategic alignment, embedding values into culture, establishing and reviewing the modern slavery policy and objectives, deploying resources, internal and external communication, directing workers, promoting zero tolerance, supporting other management roles, encouraging whistleblowing and grievance use, removing barriers to reporting, reporting to the governing body at planned intervals, implementing mandatory role-tailored training, accounting for relevant laws and conventions, and preparing and publishing the organization's reporting mechanisms. The clause is explicit — unusually so for this kind of document — that top management must clarify that human trafficking and modern slavery are serious crimes carrying heavy custodial sentences for individuals and a range of penalties for organizations, a duty framed as a communication obligation rather than merely a legal fact to be aware of.
2. The Modern Slavery Policy as a Governance Artefact
Clause 6.3 treats the modern slavery policy itself as a specific governance artefact with defined content requirements, not a generic values statement. The policy should align with the organization's objectives and obligations; state top management's intention and direction at a high level; be appropriate to the organization's size, nature, complexity, and culture; specify the scope of the organization's risk management processes including any limitations and exclusions; establish how risk management is implemented; identify internal authorities and delegations, including who is responsible for the policy itself; reference related standards, guidelines, and policies such as remediation, whistleblowing, and procurement policies; commit to responding to and resolving identified cases; commit to ongoing review; and be monitored, evaluated, and communicated to relevant stakeholders, particularly rights-holders.
The requirement to specify limitations and exclusions is worth flagging specifically, because it is a discipline many organizational policies skip. A modern slavery policy that does not state what it does not cover — certain business units, certain geographies, certain categories of business associate — is harder to audit and easier to misrepresent, whether deliberately or through simple drift, than one that states its boundaries explicitly and requires those boundaries to be periodically reviewed.
3. Roles, Responsibilities, and the Authority Question
Clause 6.4 requires top management to assign and communicate responsibilities for modern slavery risk management roles at all levels of the organization, taking into account the internal and external context set out earlier in Clause 4 and the organization's modern slavery risk across its own operations and supply chain. This clause is brief relative to 6.1 and 6.2, but it is the clause that Annex B's analysis makes clear is the one most commonly implemented badly in practice.
4. Annex B: Why This Is a Board Issue, Not Just a Compliance One
Annex B, Risk of Criminal Liability, is written with a directness that stands out from the rest of the document. It opens by stating that group corporations operating large multinational intragroup networks — subsidiaries, affiliates, and third-party supply relationships — carry substantially increased modern slavery risk, and frames human trafficking and modern slavery explicitly as financially motivated criminal activity involving deception, fraud, wage theft, unlawful financial penalties, unlawful restriction of movement, and physical and sexual violence.
Two points in Annex B deserve particular attention. First, it states that any employee committing these acts may be doing so on behalf of the organization, for their own benefit, or both — and that an employee personally benefiting from practices such as wage theft or unlawful penalties on workers may, in substance, be misappropriating money from the organization itself. This reframes modern slavery risk as a financial control failure as much as a human rights failure, which is a framing likely to resonate more directly with audit committees and boards than a purely human-rights-framed presentation of the same risk.
Second, and more structurally significant, Annex B states that human trafficking is a predicate offence for the separate and distinct crime of money laundering — meaning organizations engaged in or benefiting from human trafficking face compounding criminal liability under anti-money-laundering statutes, independent of and in addition to whatever liability attaches to the underlying labour exploitation itself. For any organization already operating an anti-money-laundering or financial crime compliance function, this is a direct and underappreciated point of intersection: modern slavery risk indicators are, in a subset of cases, also money laundering predicate indicators, and the two risk functions should not operate in isolation from one another.
5. The Authority Gap: Annex B's Sharpest Observation
Annex B's most operationally useful observation is also its bluntest. It states that top management must identify internal intragroup relationships — cross-functional departmental relationships, management and supervisory hierarchies, and three-lines-of-defence structures — that own, share, compete for, or avoid authority and responsibility over decisions relating to production worker treatment, supply chain relationship management, and financial flows. Its illustrative example is precise: the Chief Sustainability Officer is often identified as the person responsible for modern slavery issues, but frequently has no authority to intervene in or suspend operations or business activities.
This authority gap — responsibility assigned without operational authority to act on it — is, in Speeki's experience across ISO 37001 and compliance management system assurance work, one of the most common structural weaknesses auditors encounter, and Annex B's willingness to name it explicitly is unusual for an ISO annex. The practical fix Annex B points toward is assigning modern slavery risk and liability explicitly to a Chief Risk Officer, embedding it in the organization's enterprise risk management model, framework, and monthly dashboards, and making it a standing agenda item at risk management committee meetings — locating the risk within a function that typically does carry intervention authority, rather than leaving it with a sustainability or ESG function that typically does not.
6. Annex B's Risk Indicator List
Annex B closes with a distinct set of governance-focused risk indicators, separate from the operational indicators in Clause 5.4.2: no assignment of modern slavery risk to a Chief Risk Officer; modern slavery risk absent from the group risk management model, framework, dashboard, and risk committee agenda; weak governance and control functions specifically across legal, financial, human resources, procurement, risk management, and compliance in intragroup companies; poor supervision of production workers and weak reporting frameworks; absent or inconsistent worker contracts; absent, variable, or inconsistent worker payments; worker payments to recruitment agents; retention of worker documentation; sexual violence; physical threats; the presence of financial penalties on workers; and inaccurate or fraudulent disclosure and reporting.
This list functions, in practice, as a governance-level early warning system distinct from the worker-level risk indicators covered in the previous paper in this series. An internal audit or risk committee reviewing intragroup structure against this list is testing organizational design and control adequacy, not testing individual supplier relationships — a distinct and necessary layer of assurance that many modern slavery risk programmes, built bottom-up from supplier questionnaires, never actually reach.
7. Connecting Governance Structure to FLR Penalty Exposure
The European Commission's June 2026 guidelines on the FLR set out a penalty methodology built around the gravity and duration of a confirmed violation, together with aggravating and mitigating factors. Governance quality — whether an organization has clear accountability, adequate authority allocation, and functioning risk oversight — is precisely the kind of factor that shapes an authority's assessment of gravity: a violation occurring despite a genuinely functioning governance structure reads very differently, from an enforcement perspective, than one occurring in the presence of the authority gap Annex B describes, where a designated owner had responsibility on paper but no real power to prevent the outcome.
This gives Annex B's governance analysis direct, practical relevance to FLR exposure, beyond its value as general good governance practice. An organization able to demonstrate — with board minutes, risk committee records, and a documented Chief Risk Officer mandate — that modern slavery risk sits within a function with real intervention authority is in a materially stronger position, both in avoiding an investigation being opened and in any penalty calculation that follows, than one that can only point to a policy document and a compliance officer with no operational reach.
8. How DDMS2000 Closes the Authority Gap
SPK DDMS2000:2026's leadership and accountability clauses are built specifically to close the gap Annex B identifies. Where ISO/DIS 37200 recommends that responsibility and authority be aligned, DDMS2000 requires organizations to document the specific role, authority, and escalation pathway for due diligence decisions as an auditable element of the certified system — not merely to name a responsible individual, but to evidence that the individual named has the operational authority the role requires, including the ability to pause or decline a transaction, relationship, or operational activity where due diligence findings warrant it.
This is, in practical terms, the difference between a Chief Sustainability Officer with a modern slavery mandate and no intervention power, and a role within DDMS2000's governance structure whose authority is itself part of what an independent certification audit verifies. Speeki's certification process examines this authority allocation directly, because a due diligence management system with a documented owner who cannot act on findings is not, in any meaningful sense, a functioning system — regardless of how complete its policy documentation looks on paper.
Conclusion
ISO/DIS 37200's Clause 6 and Annex B together make a case that is easy to state and consistently hard to implement: modern slavery risk management requires governing-body and top-management ownership with real operational authority behind it, not a policy assigned to a function that lacks the power to act on what it finds. Annex B's willingness to name this failure mode explicitly, and to connect it to genuine criminal and money-laundering liability rather than only reputational risk, gives boards a reason to treat this as more than a routine compliance briefing item.
The next paper in this series moves from governance to operations: how ISO/DIS 37200's Clause 8.2 and 8.3 translate this governance foundation into concrete recruitment, employment, and procurement controls — the practical layer where forced labour risk is actually created or prevented.
Speeki is an accredited certification body providing independent assurance and certification of due diligence management systems, including against SPK DDMS2000:2026. Current accreditation scope and certification details are available at speeki.com.
References
ISO/DIS 37200:2025(en), Managing the risk of modern slavery — Guidance for the prevention, identification and response to human trafficking and forced labour, ISO/TC 309 Governance of organizations, Secretariat: BSI, Clause 6 (Leadership and commitment) and Annex B (Risk of Criminal Liability). Version dated 2025-12-08, Draft International Standard status; content subject to change prior to publication.
European Commission, Guidelines on Regulation (EU) 2024/3015 on prohibiting products made with forced labour on the Union market, published 30 June 2026.
Regulation (EU) 2024/3015 of the European Parliament and of the Council of 27 November 2024.
UN Convention against Transnational Organised Crime and its Protocols, Article 3(a) (definition of human trafficking, as referenced in ISO/DIS 37200 Clause 3.20).
SPK DDMS2000:2026, Speeki Due Diligence Management System Standard, leadership and accountability provisions (internal Speeki standard).
ISO 37001:2016/2025, Anti-bribery management systems — Requirements with guidance for use.