Skip to content

Evidence request lists

Authorised Economic Operator (AEO) Programmes - Global Standards

Evidence request list. 42 controls, 42 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.

AEO Conditions and Requirements (SAFE Annex IV)

AEO-10
Education, Training and Awareness

The operator educates its personnel, and where appropriate its trading partners, on the risks associated with movements of goods in the supply chain, on recognising deviations from security policy and on the actions to take when a security lapse occurs.

Artefacts an auditor will ask for
  • training programme content covering supply chain security risks
  • attendance records by role including new starters and refreshers
  • guidance on recognising deviations and the actions required
  • awareness material extended to trading partners where appropriate
Where this commonly fails
  • training delivered at induction only
  • content generic with no reference to the operator's own procedures
  • no record of who attended so coverage is unknown
  • warehouse and driver populations excluded
AEO-12
Crisis Management and Incident Recovery

The operator and Customs develop and document contingency plans for emergency security situations and for disaster or incident recovery, with periodic training of employees so the plans can be executed.

Artefacts an auditor will ask for
  • documented contingency plans for emergency security situations
  • disaster and incident recovery procedures
  • periodic training records covering the plans
  • exercise or activation records and the lessons taken
  • coordination arrangements with the appropriate authorities
Where this commonly fails
  • plan written and filed with no training behind it
  • plans cover fire and flood but not a security incident
  • no coordination with authorities so escalation is untested
AEO-13
Measurement, Analyses and Improvement

The operator plans and implements monitoring, measurement, analysis and improvement processes to assess consistency with the guidelines, confirm the integrity and adequacy of the security management system and identify areas to improve supply chain security.

Artefacts an auditor will ask for
  • periodic assessment of security risks in the operation as set out in the national programme
  • internal audit or review records covering the security management system
  • findings register with owners and target dates
  • evidence of improvements implemented and re-measured
  • management review records
Where this commonly fails
  • assessment performed but findings not tracked to closure
  • review covering physical security only, not the management system
  • no measurement so improvement cannot be demonstrated
  • assessment frequency below what the national programme requires
AEO-2
Demonstrated Compliance with Customs Requirements

The applicant's demonstrated compliance history is taken into account, requiring an absence of disqualifying infringements over the period set by the national programme, judged on available records where the operator has been established for a shorter period.

Artefacts an auditor will ask for
  • Customs compliance history for the period set by the national programme
  • register of infringements and their disposition
  • evidence considered where the operator has been established for less than that period
  • compliance record of any designee acting for the operator
Where this commonly fails
  • compliance history reviewed for the applicant but not for its designee
  • period assessed shorter than the national programme requires
  • infringements recorded without a disposition so eligibility cannot be judged
AEO-3
Satisfactory System for Management of Commercial Records

The operator maintains timely, accurate, complete and verifiable import and export records, with a records and accounting system that permits Customs audit, full access subject to national law, internal access controls, archiving and information technology security measures.

Artefacts an auditor will ask for
  • records and accounting system permitting audit of cargo movements for import and export
  • procedure granting Customs access to necessary records
  • internal records access and control arrangements
  • authorizations, powers of attorney and licences held and available
  • archiving arrangements and retention period
  • information technology security measures protecting the records
Where this commonly fails
  • records complete for import but thin for export
  • no internal access control so records can be altered without trace
  • archived records held in a format that can no longer be read
  • licences and powers of attorney not centrally held
AEO-4
Financial Viability

The operator is in good financial standing sufficient to fulfil its commitments given the characteristics of its business model and activity, assessed using absolute and relative financial indicators within the national programme's vetting and validation procedures.

Artefacts an auditor will ask for
  • audited financial statements for the assessed period
  • financial ratios or indicators applied and the thresholds used
  • assessment record produced during vetting and validation
  • re-assessment on the cycle set by the national programme
Where this commonly fails
  • single year of accounts assessed
  • thresholds applied uniformly with no regard to business model
  • financial standing assessed at application and never revisited
AEO-5
Premises Security

The operator implements security measures and procedures to secure buildings and to monitor and control exterior and interior perimeters, in accordance with its business model and risk analysis.

Artefacts an auditor will ask for
  • site risk analysis per premises
  • physical security measures including barriers, lighting and locking arrangements
  • exterior and interior perimeter monitoring and its coverage
  • visitor and contractor control procedure
  • records of security checks and their findings
Where this commonly fails
  • risk analysis covering the main site only
  • interior perimeters uncontrolled once past the gate
  • monitoring installed but not reviewed
  • visitor control applied at reception while other entrances are unmanned
AEO-6
Cargo Security

The operator maintains cargo integrity and applies access controls at the appropriate level, with a documented security policy manual or equivalent guidance and routine procedures that contribute to the security of cargo.

Artefacts an auditor will ask for
  • security policy manual or equivalent guidance referencing WCO security guidelines
  • procedures for securing cargo at each handling stage
  • access control over cargo areas and the authorisation list
  • seal application and verification records
  • discrepancy reporting procedure and its records
Where this commonly fails
  • procedures documented centrally but not available at the handling point
  • access to cargo areas granted broadly to contractors
  • discrepancies noted informally and not escalated
  • cargo security procedures silent on the transfer between parties
AEO-7
Trading Partner Security

The operator encourages contracting parties to assess and enhance their supply chain security, including such requirements in contractual arrangements where practical for its business model.

Artefacts an auditor will ask for
  • security requirements included in contracts with trading partners
  • assessment or questionnaire records for partners in scope
  • criteria for selecting which partners are assessed
  • action taken where a partner does not meet the requirements
Where this commonly fails
  • security clauses in new contracts only, leaving legacy partners uncovered
  • questionnaires issued but responses never assessed
  • no consequence defined for a partner that fails
AEO-8
Personnel Security

The operator takes reasonable precautions when recruiting to verify prospective employees, and prohibits unauthorised access to facilities, transport conveyances, loading docks and cargo areas that could affect supply chain security.

Artefacts an auditor will ask for
  • pre-employment screening procedure and its legal basis
  • screening records for staff in security-sensitive positions
  • periodic rescreening arrangements where lawful
  • access removal procedure on termination or role change
  • access authorisation list for facilities, docks and cargo areas
Where this commonly fails
  • screening applied to permanent staff but not to agency or contract labour
  • access not revoked promptly on departure
  • authorisation lists never reconciled against the human resources record
AEO-9
Information Exchange, Access and Confidentiality

The operator and Customs protect entrusted information against misuse and unauthorised alteration, ensuring commercial and security sensitive information stays confidential and is used solely for the purpose for which it was provided, and pursuing timely electronic data exchange.

Artefacts an auditor will ask for
  • confidentiality undertakings covering commercial and security sensitive information
  • access control over systems holding that information
  • purpose limitation statement and how it is enforced
  • electronic data exchange arrangements and their protective measures
  • incident procedure for suspected misuse or unauthorised alteration
Where this commonly fails
  • confidentiality relied on contractually with no technical enforcement
  • data reused for purposes beyond the original provision
  • exchange arrangements agreed but still operating on unprotected channels
SAFE-AEO-D
Consultation, Co-operation and Communication

Customs, other competent authorities and the operator consult regularly on matters of mutual interest including supply chain security and facilitation, with the operator providing clearly identified and readily accessible points of contact.

Artefacts an auditor will ask for
  • named and readily accessible points of contact provided to Customs
  • record of regular consultation meetings and the matters covered
  • procedure for notifying Customs of irregularities or suspicious circumstances
  • evidence consultation outcomes fed into risk management
Where this commonly fails
  • contact details supplied at application and never updated
  • consultation only when a problem arises
  • no route for the operator to raise facilitation issues
SAFE-AEO-H
Conveyance Security

The operator ensures that transport conveyances used to carry cargo within its supply chain are capable of being effectively secured and maintained, and secures them against unauthorised access and tampering.

Artefacts an auditor will ask for
  • inspection procedure confirming conveyances can be effectively secured
  • conveyance inspection records before loading and on receipt
  • securing arrangements including locking, sealing and parking controls
  • procedure for reporting and handling evidence of tampering
  • arrangements extending the requirement to subcontracted hauliers
Where this commonly fails
  • inspection applied to owned vehicles but not to subcontracted hauliers
  • conveyances left unsecured during driver rest periods
  • tampering evidence handled locally with no report
  • no record that the pre-loading inspection took place

WCO SAFE Pillar 1 - Customs-to-Customs

P1-S1
Advance Electronic Information

The Customs administration requires advance electronic information on cargo and conveyances in time for risk assessment to be carried out before arrival or departure.

Artefacts an auditor will ask for
  • national legal instrument requiring advance electronic filing
  • filing deadlines by transport mode
  • computerised system receiving the filings
  • records showing assessment completed before arrival or departure
Where this commonly fails
  • data required but arriving too late to inform assessment
  • paper fallback used routinely so data is not machine readable
  • deadlines defined for sea cargo only
P1-S2
Risk-Management Systems

The Customs administration operates an automated risk-management system that identifies potentially high-risk cargo and conveyances and includes a mechanism to validate threat assessments and targeting decisions.

Artefacts an auditor will ask for
  • documented risk-management methodology
  • automated selectivity system and its rule set
  • validation records for threat assessments and targeting decisions
  • measurement of hit rates and false positives
Where this commonly fails
  • risk rules set once and never validated against outcomes
  • targeting decisions taken manually outside the system
  • no feedback loop from inspection results into the rules
P1-S3
Outbound Security Inspections

The Customs administration conducts outbound security inspection of high-risk cargo and conveyances at the reasonable request of the importing country, using non-intrusive and radiation detection equipment where available.

Artefacts an auditor will ask for
  • procedure for receiving and acting on inspection requests from importing countries
  • inspection records with the requesting country and outcome
  • non-intrusive inspection equipment availability at the point of export
  • response time measurement
Where this commonly fails
  • outbound inspection capability limited to a few ports
  • no defined channel for receiving requests
  • results not communicated back to the requesting administration
P1-S4
Targeting and Communication

The Customs administration provides for joint targeting and screening, standardised targeting criteria and compatible communication and information exchange mechanisms that support the future development of mutual recognition of controls.

Artefacts an auditor will ask for
  • standardised targeting criteria in use
  • joint targeting or screening arrangements with partner administrations
  • compatible data exchange mechanism and its message standard
  • records of controls recognised as a result
Where this commonly fails
  • targeting criteria unique to the administration so results are not portable
  • exchange mechanism agreed but never operated
  • joint arrangements limited to a single bilateral partner
SAFE-P1-S1
Integrated Supply Chain Management

The Customs administration follows integrated Customs control procedures as set out in the WCO Customs Guidelines on Integrated Supply Chain Management.

Artefacts an auditor will ask for
  • national procedures mapped to the WCO Integrated Supply Chain Management Guidelines
  • scope statement covering export, transit and import control points
  • evidence controls are applied end to end rather than at import only
  • training records for officers applying the procedures
Where this commonly fails
  • controls concentrated at import with no export-side equivalent
  • guidelines referenced but national procedure not mapped to them
  • integrated procedure applied at pilot sites only
SAFE-P1-S10
Employee Integrity

The Customs administration and other competent authorities operate programmes to prevent lapses in employee integrity and to identify and combat breaches, informed by the WCO Revised Arusha Declaration.

Artefacts an auditor will ask for
  • integrity programme documentation referencing the Revised Arusha Declaration
  • code of conduct and staff acknowledgement records
  • rotation, supervision and audit measures for high-risk posts
  • records of integrity breaches detected and action taken
Where this commonly fails
  • code of conduct published with no supporting controls
  • no rotation in posts with high discretion
  • breaches handled informally with no record
SAFE-P1-S2
Cargo Inspection Authority

The Customs administration holds the legal authority to inspect cargo originating in, exiting, transiting, remaining on board or being transhipped through the country.

Artefacts an auditor will ask for
  • legislative provision granting inspection authority and its scope
  • confirmation the authority covers transit, transhipment and remain-on-board cargo
  • procedures officers use to exercise the authority
  • records of inspections carried out under each category
Where this commonly fails
  • authority covering import and export but silent on transhipment
  • powers held but no procedure so officers do not use them
  • authority disputed at free zones or transit sheds
SAFE-P1-S3
Modern Technology in Inspection Equipment

Non-intrusive inspection equipment and radiation detection equipment are available and used for inspections in accordance with risk assessment, so high-risk cargo can be examined quickly without disrupting legitimate trade.

Artefacts an auditor will ask for
  • equipment inventory by location and type
  • utilisation and availability records including downtime
  • procedure linking risk assessment outcome to equipment selection
  • operator training and certification records
Where this commonly fails
  • equipment procured but out of service for long periods
  • scanners used as a routine percentage rather than driven by risk
  • no radiation detection at high volume entry points
SAFE-P1-S5
Selectivity, profiling and targeting

Customs uses sophisticated methods to identify and target potentially high-risk cargo, drawing on advance electronic information, strategic intelligence, automated trade data and anomaly analysis.

Artefacts an auditor will ask for
  • documented selectivity methodology and the data sources it consumes
  • profiling criteria and their review cycle
  • intelligence inputs and how they reach the targeting function
  • anomaly analysis outputs and resulting interventions
Where this commonly fails
  • selectivity driven by a single data source
  • profiles never reviewed so they decay
  • intelligence held separately from the targeting system
SAFE-P1-S8
Performance Measures

The Customs administration produces statistical reports containing performance measures covering shipments reviewed, the high-risk subset, examinations conducted and the means by which they were conducted.

Artefacts an auditor will ask for
  • periodic statistical report with the defined measures
  • definitions for each measure so figures are comparable over time
  • distribution of the report to accountable owners
  • evidence the measures inform programme changes
Where this commonly fails
  • figures produced but definitions change between periods
  • reports compiled and filed with no decision attached
  • high-risk subset not separately reported
SAFE-P1-S9
Security Assessments

The Customs administration works with other competent authorities to conduct security assessments of the movement of goods in the international supply chain and commits to resolving identified gaps expeditiously.

Artefacts an auditor will ask for
  • security assessment reports covering supply chain movements
  • list of participating competent authorities
  • gap register with owners and target dates
  • evidence gaps were closed and reassessed
Where this commonly fails
  • assessments conducted by Customs alone
  • gaps identified but no owner or date attached
  • assessment repeated without checking whether prior gaps closed

WCO SAFE Pillar 2 - Customs-to-Business

P2-S1
Partnership

The Authorized Economic Operator conducts a self-assessment against pre-determined security standards and best practices to confirm its internal policies and procedures guard against compromise of goods and containers in the supply chain.

Artefacts an auditor will ask for
  • completed AEO self-assessment against the national programme criteria
  • internal security policy and procedure set referenced by the assessment
  • evidence of periodic reassessment
  • corrective actions arising from the assessment
Where this commonly fails
  • self-assessment completed once at application and never repeated
  • assessment answers not supported by underlying procedures
  • scope of the assessment narrower than the operator's actual supply chain
P2-S2
Security

The Authorized Economic Operator incorporates pre-determined security best practices into existing business practices, implementing measures that secure buildings and monitor and control exterior and interior perimeters and access.

Artefacts an auditor will ask for
  • site security assessment per facility
  • access control system records and authorisation lists
  • perimeter monitoring arrangements including CCTV coverage and retention
  • security procedure manual referenced by staff
Where this commonly fails
  • security measures at the main site only, with satellite depots uncovered
  • access lists never reconciled against current staff
  • CCTV installed with retention too short to support an investigation
P2-S3
Authorization

The Customs administration, with the trade community, designs validation processes or quality accreditation procedures that grant Authorized Economic Operator status and define the tangible benefits that follow.

Artefacts an auditor will ask for
  • published AEO validation procedure and criteria
  • validation reports for authorised operators
  • documented benefits attached to the status
  • appeal and reconsideration process
Where this commonly fails
  • criteria published but validation applied inconsistently
  • benefits stated in general terms and not measurable
  • no defined appeal route for refused applicants
P2-S4
Technology

All parties maintain cargo and container integrity by using modern technology, conforming at a minimum to the requirements of the applicable international agreements on container security and sealing.

Artefacts an auditor will ask for
  • seal standard applied and the conformance basis cited
  • seal issue, application and verification records
  • container inspection procedure at stuffing and receipt
  • records of seal discrepancies and how they were handled
Where this commonly fails
  • seals applied but numbers not recorded against the consignment
  • seal integrity checked only at destination
  • no procedure for a broken or mismatched seal
P2-S5
Communication

The Customs administration regularly updates Customs-Business partnership programmes to promote minimum security standards and best practices, and agrees with operators the procedures to follow when queries or incidents arise.

Artefacts an auditor will ask for
  • programme update history and how changes were communicated
  • agreed procedure for queries and suspected incidents
  • consultation records with operators or their representatives
  • named contact points on both sides
Where this commonly fails
  • programme unchanged for years while risks moved on
  • incident procedure undocumented so escalation is ad hoc
  • consultation limited to the largest operators
P2-S6
Facilitation

The Customs administration works co-operatively with Authorized Economic Operators to maximise security and facilitation of the supply chain, implementing procedures that consolidate and simplify treatment for authorised operators.

Artefacts an auditor will ask for
  • documented facilitation measures granted to authorised operators
  • evidence the measures are applied in practice such as reduced inspection rates or priority treatment
  • review of whether facilitation delivered is what was promised
  • operator feedback records
Where this commonly fails
  • benefits promised in the programme but not delivered operationally
  • facilitation applied at some ports only
  • no measurement so the value of authorisation is unproven

WCO SAFE Pillar 3 - Customs-to-Government

P3-S1
Mutual Cooperation

Governments foster mutual cooperation between the Customs administration and other competent government agencies that regulate the movement of cargo across transport modes.

Artefacts an auditor will ask for
  • cooperation arrangements with the other competent agencies
  • records of joint working across transport modes
  • recognition arrangements between security certification programmes such as AEO and Regulated Agent
  • meeting or liaison records
Where this commonly fails
  • cooperation limited to one agency or one transport mode
  • arrangements signed but never operated
  • certification programmes run in parallel with no mutual recognition
P3-S2
Harmonization of data filing requirements

Customs develops cooperative arrangements with other agencies requiring data for the clearance of goods so trade data can be submitted, transferred and reused seamlessly, consistent with the Single Window concept.

Artefacts an auditor will ask for
  • single window implementation status and the agencies connected
  • harmonised data set aligned to the WCO Data Model
  • arrangements permitting transfer and reuse of submitted data
  • measurement of duplicate submissions eliminated
Where this commonly fails
  • single window covering Customs only while other agencies still take separate filings
  • data harmonised in form but not in definition so reuse fails
  • no legal basis for sharing the data between agencies
P3-S3
Cooperative Arrangements/Procedures

Governments develop and maintain cooperative arrangements or procedures among the agencies involved in international trade and security, so functions and responsibilities align and duplicated effort is avoided.

Artefacts an auditor will ask for
  • documented inter-agency coordination mechanism
  • allocation of functions and responsibilities between agencies
  • evidence of alignment such as joint risk management or shared inspection
  • review of duplicated controls removed
Where this commonly fails
  • arrangements exist on paper with no operating mechanism
  • responsibilities overlap so operators face duplicate controls
  • no forum to resolve conflicts between agency requirements
SAFE-P3-S10
Harmonization of cross-border control measures

Governments work to harmonize cross-border control measures, which may include mutual recognition of control measures and compliance programmes, sharing of resources and techniques, and accepting clearance carried out by the other party.

Artefacts an auditor will ask for
  • mutual recognition instruments covering control measures or compliance programmes
  • arrangements for sharing resources or inspection techniques
  • provisions for accepting the other party's clearance and the conditions attached
  • measured reduction in duplicate controls
Where this commonly fails
  • mutual recognition covering AEO status only, not control measures
  • acceptance of the other party's clearance agreed but not operationalised
  • no measurement so duplicate controls persist unnoticed
SAFE-P3-S11
Establishment of Mutual Cooperation among international bodies

Governments together foster cooperation between and among the international bodies involved with supply chain security, engaging through the WCO to develop and maintain harmonized international standards.

Artefacts an auditor will ask for
  • record of engagement with international bodies involved in supply chain security
  • contributions to harmonized international standards
  • national positions taken and how they were coordinated
  • adoption of the resulting standards domestically
Where this commonly fails
  • engagement limited to attendance with no contribution
  • international standards adopted internationally but not implemented nationally
  • no coordination so national positions conflict between agencies
SAFE-P3-S12
Development of cooperative arrangements or protocols with international bodies

The WCO on behalf of its Members develops and maintains cooperative arrangements with international governmental bodies involved with supply chain security, complementing Members' work on cross-cutting issues.

Artefacts an auditor will ask for
  • cooperative arrangements between the WCO and bodies such as ICAO, IMO and UPU
  • national implementation of the outputs of those arrangements
  • alignment of national requirements with the arrangements
  • review of relevance and currency
Where this commonly fails
  • arrangements known centrally but not reflected in national procedure
  • outputs adopted selectively with no rationale
  • no national owner for tracking the arrangements
SAFE-P3-S3
Alignment of security programmes

Governments align, where appropriate, the requirements of the various security programmes and regimes implemented to enhance security of the international supply chain.

Artefacts an auditor will ask for
  • inventory of the security programmes applying to operators
  • comparison of their requirements and the overlaps identified
  • alignment or mutual recognition decisions taken
  • operator-facing statement of which requirements satisfy which programme
Where this commonly fails
  • operators audited separately against near-identical criteria
  • alignment discussed but no decision recorded
  • alignment limited to two programmes while others remain separate
SAFE-P3-S4
Harmonization of national control measures

Governments harmonize the supply chain security control measures of government agencies, including risk management and risk mitigation, to limit negative impact on legitimate trade and international movement.

Artefacts an auditor will ask for
  • catalogue of national control measures by agency
  • harmonisation analysis including shared risk management approach
  • impact assessment on legitimate trade
  • record of measures consolidated or withdrawn
Where this commonly fails
  • each agency applying its own risk criteria to the same consignment
  • no impact assessment so cumulative burden is unknown
  • harmonisation agreed centrally but not implemented at the border
SAFE-P3-S5
Development of continuity and resumptions measures

Customs works with other agencies and the private sector to identify respective roles and responsibilities for trade continuity and resumption so trade can continue after a disruptive incident.

Artefacts an auditor will ask for
  • trade continuity and resumption plan
  • role and responsibility matrix covering agencies and private sector participants
  • communication arrangements for a disruptive incident
  • exercise or activation records
Where this commonly fails
  • plan drafted by Customs without private sector input
  • roles undefined so recovery decisions stall
  • plan never exercised
SAFE-P3-S7
Mutual Cooperation between governments

Governments foster mutual cooperation between Customs administrations and other competent agencies involved with supply chain security across borders or within a Customs union, including information exchange, training and technical assistance.

Artefacts an auditor will ask for
  • cooperation arrangements with neighbouring or union partner administrations
  • information exchange records and the legal basis for them
  • joint training or technical assistance delivered or received
  • review of the cooperation's effectiveness
Where this commonly fails
  • cooperation limited to formal correspondence
  • information exchange blocked by an absent legal basis
  • arrangements with one neighbour only
SAFE-P3-S8
Development of Cooperative Arrangements or Protocols across borders

Governments develop cooperative arrangements or protocols among agencies working side by side on a shared border or within a Customs union, such as memorandums of understanding or mutual assistance agreements.

Artefacts an auditor will ask for
  • signed memorandums of understanding or mutual assistance agreements
  • operating protocols for agencies working at the same border point
  • joint control or one-stop arrangements where implemented
  • review and renewal dates for the instruments
Where this commonly fails
  • instruments signed but never converted into operating protocols
  • agencies co-located but operating independently
  • instruments lapsed without renewal
SAFE-P3-S9
Harmonization of security programmes across governments

Governments harmonize, where appropriate, the requirements of the various security programmes implemented to enhance security of the international supply chain across borders.

Artefacts an auditor will ask for
  • comparison of partner countries' security programme requirements
  • harmonisation actions agreed and their implementation status
  • operator-facing guidance on which requirements are recognised across borders
  • joint review records
Where this commonly fails
  • harmonisation asserted without a requirement comparison behind it
  • agreement reached at policy level but not reflected in operator criteria
  • no review so divergence reappears over time
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the Authorised Economic Operator (AEO) Programmes - Global Standards framework page.