C-TPAT - Customs-Trade Partnership Against Terrorism
Evidence request list. 12 controls, 12 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.
CTPAT Focus Area 1: Corporate Security
Corporate Security. The member's supply chain security program must have upper-management support, with security instilled as a companywide priority and a designated person responsible for the CTPAT program.
- Documented supply chain security program with senior-management endorsement
- Designated CTPAT program officer and responsibilities
- Statement of security policy/commitment
- No management support for the program
- No designated CTPAT officer
- Security not a companywide priority
Corporate Security. The member must conduct and document a risk assessment of its international supply chain (e.g. the CBP Five Step Risk Assessment), considering business model, supplier geography and threats.
- Documented international supply chain risk assessment (Five Step model)
- Mapping of cargo flow and identification of business partners
- Annual review/update of the risk assessment
- No documented risk assessment
- Cargo flow not mapped
- Assessment not reviewed annually
Corporate Security. The member must have written, risk-based processes for screening business partners and ensuring they meet CTPAT security criteria, including documentation of their security (SVI/certification or security questionnaires).
- Written business-partner screening and vetting procedures
- Evidence of partners' CTPAT/AEO status or security questionnaires
- Risk-based monitoring of business partners
- Business partners not screened
- No evidence of partner security
- No ongoing monitoring
Corporate Security. The member must have comprehensive written cybersecurity policies and procedures to protect IT systems, aligned with a cybersecurity framework, covering access control, malware protection, monitoring, backups, and periodic review.
- Written cybersecurity policies aligned to a recognised framework
- Access control, malware protection, logging/monitoring and backup evidence
- Periodic review of cybersecurity policies
- Cybersecurity awareness training records
- No written cybersecurity policy
- No access control/malware/backup controls
- Policies not reviewed
CTPAT Focus Area 2: Transportation Security
Transportation Security. The member must maintain security and inspection processes for conveyances and Instruments of International Traffic to prevent, detect and deter tampering or unauthorised access (including a documented inspection process).
- Documented conveyance/IIT inspection process (e.g. 17-point/agriculture inspections)
- Secure storage of conveyances and IIT
- Records of inspections performed
- No documented inspection process
- Conveyances/IIT not securely stored
- Inspections not recorded
Transportation Security. The member must have a comprehensive written seal policy ensuring continuous seal integrity, using ISO 17712 high-security seals, with controlled seal access, inventory/tracking, and procedures for seal discrepancies.
- Written seal policy covering ISO 17712 high-security seals
- Seal inventory, distribution and tracking log
- Procedures for seal discrepancies and seals broken in transit
- Seals not ISO 17712
- No seal log/tracking
- No discrepancy procedure
Transportation Security. The member must have procedures covering the import/export process, documentation accuracy, cargo handling and storage, manifesting, and incident reporting and notification to law enforcement.
- Documented import/export and cargo-handling procedures
- Documentation accuracy and manifest controls
- Incident reporting and law-enforcement notification procedures
- No documented procedures
- Documentation/manifest errors uncontrolled
- No incident reporting procedure
Transportation Security. The member must have written procedures to prevent visible pest contamination, including inspections of conveyances, IIT and cargo for agricultural pests and contaminants.
- Written agricultural-contamination prevention procedures
- Records of pest/contamination inspections of conveyances and cargo
- Wood packaging material (WPM) controls
- No agricultural-contamination procedures
- Pest inspections not performed/recorded
- WPM not controlled
CTPAT Focus Area 3: People and Physical Security
People and Physical Security. The member must maintain access controls that prevent unauthorised entry to facilities, including employee/visitor/vendor identification, badge issuance and removal, and challenge procedures for unauthorised persons.
- Employee/visitor/vendor identification and badge management
- Access logs and visitor sign-in records
- Procedures to challenge and remove unauthorised persons
- Access not controlled by identification
- No visitor logs
- Badges not recovered on separation
People and Physical Security. The member must have written processes to screen prospective employees and, consistent with law, conduct periodic background checks for employees in sensitive positions.
- Pre-employment screening and verification procedures
- Background checks for sensitive positions (consistent with local law)
- Employee code of conduct and separation procedures
- No pre-employment screening
- No background checks for sensitive roles
- No separation/badge-recovery process
People and Physical Security. The member must establish and maintain a security training and awareness program so employees understand threats (terrorism, smuggling, internal conspiracies) and the procedures to address them, including how to report incidents.
- Security training and threat-awareness program and completion records
- Role-specific training for staff in the supply chain
- Records of incident-reporting awareness
- No security training program
- Training not role-specific
- Staff unaware of how to report incidents
People and Physical Security. Cargo handling and storage facilities must have physical barriers and deterrents (fencing, gates, lighting, alarms, CCTV) commensurate with risk to prevent unauthorised access.
- Physical security measures (fencing, gates, lighting, alarms, CCTV) at facilities
- CCTV coverage and retention of footage
- Periodic inspection/maintenance of physical security
- Inadequate physical barriers
- No/insufficient CCTV coverage
- Physical security not maintained
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the C-TPAT - Customs-Trade Partnership Against Terrorism framework page.