Skip to content

Evidence request lists

C-TPAT - Customs-Trade Partnership Against Terrorism

Evidence request list. 12 controls, 12 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.

CTPAT Focus Area 1: Corporate Security

CTPAT-MSC-1
Security Vision and Responsibility

Corporate Security. The member's supply chain security program must have upper-management support, with security instilled as a companywide priority and a designated person responsible for the CTPAT program.

Artefacts an auditor will ask for
  • Documented supply chain security program with senior-management endorsement
  • Designated CTPAT program officer and responsibilities
  • Statement of security policy/commitment
Where this commonly fails
  • No management support for the program
  • No designated CTPAT officer
  • Security not a companywide priority
CTPAT-MSC-2
Risk Assessment

Corporate Security. The member must conduct and document a risk assessment of its international supply chain (e.g. the CBP Five Step Risk Assessment), considering business model, supplier geography and threats.

Artefacts an auditor will ask for
  • Documented international supply chain risk assessment (Five Step model)
  • Mapping of cargo flow and identification of business partners
  • Annual review/update of the risk assessment
Where this commonly fails
  • No documented risk assessment
  • Cargo flow not mapped
  • Assessment not reviewed annually
CTPAT-MSC-3
Business Partners

Corporate Security. The member must have written, risk-based processes for screening business partners and ensuring they meet CTPAT security criteria, including documentation of their security (SVI/certification or security questionnaires).

Artefacts an auditor will ask for
  • Written business-partner screening and vetting procedures
  • Evidence of partners' CTPAT/AEO status or security questionnaires
  • Risk-based monitoring of business partners
Where this commonly fails
  • Business partners not screened
  • No evidence of partner security
  • No ongoing monitoring
CTPAT-MSC-4
Cybersecurity

Corporate Security. The member must have comprehensive written cybersecurity policies and procedures to protect IT systems, aligned with a cybersecurity framework, covering access control, malware protection, monitoring, backups, and periodic review.

Artefacts an auditor will ask for
  • Written cybersecurity policies aligned to a recognised framework
  • Access control, malware protection, logging/monitoring and backup evidence
  • Periodic review of cybersecurity policies
  • Cybersecurity awareness training records
Where this commonly fails
  • No written cybersecurity policy
  • No access control/malware/backup controls
  • Policies not reviewed

CTPAT Focus Area 2: Transportation Security

CTPAT-MSC-5
Conveyance and Instruments of International Traffic (IIT) Security

Transportation Security. The member must maintain security and inspection processes for conveyances and Instruments of International Traffic to prevent, detect and deter tampering or unauthorised access (including a documented inspection process).

Artefacts an auditor will ask for
  • Documented conveyance/IIT inspection process (e.g. 17-point/agriculture inspections)
  • Secure storage of conveyances and IIT
  • Records of inspections performed
Where this commonly fails
  • No documented inspection process
  • Conveyances/IIT not securely stored
  • Inspections not recorded
CTPAT-MSC-6
Seal Security

Transportation Security. The member must have a comprehensive written seal policy ensuring continuous seal integrity, using ISO 17712 high-security seals, with controlled seal access, inventory/tracking, and procedures for seal discrepancies.

Artefacts an auditor will ask for
  • Written seal policy covering ISO 17712 high-security seals
  • Seal inventory, distribution and tracking log
  • Procedures for seal discrepancies and seals broken in transit
Where this commonly fails
  • Seals not ISO 17712
  • No seal log/tracking
  • No discrepancy procedure
CTPAT-MSC-7
Procedural Security

Transportation Security. The member must have procedures covering the import/export process, documentation accuracy, cargo handling and storage, manifesting, and incident reporting and notification to law enforcement.

Artefacts an auditor will ask for
  • Documented import/export and cargo-handling procedures
  • Documentation accuracy and manifest controls
  • Incident reporting and law-enforcement notification procedures
Where this commonly fails
  • No documented procedures
  • Documentation/manifest errors uncontrolled
  • No incident reporting procedure
CTPAT-MSC-8
Agricultural Security

Transportation Security. The member must have written procedures to prevent visible pest contamination, including inspections of conveyances, IIT and cargo for agricultural pests and contaminants.

Artefacts an auditor will ask for
  • Written agricultural-contamination prevention procedures
  • Records of pest/contamination inspections of conveyances and cargo
  • Wood packaging material (WPM) controls
Where this commonly fails
  • No agricultural-contamination procedures
  • Pest inspections not performed/recorded
  • WPM not controlled

CTPAT Focus Area 3: People and Physical Security

CTPAT-MSC-10
Physical Access Controls

People and Physical Security. The member must maintain access controls that prevent unauthorised entry to facilities, including employee/visitor/vendor identification, badge issuance and removal, and challenge procedures for unauthorised persons.

Artefacts an auditor will ask for
  • Employee/visitor/vendor identification and badge management
  • Access logs and visitor sign-in records
  • Procedures to challenge and remove unauthorised persons
Where this commonly fails
  • Access not controlled by identification
  • No visitor logs
  • Badges not recovered on separation
CTPAT-MSC-11
Personnel Security

People and Physical Security. The member must have written processes to screen prospective employees and, consistent with law, conduct periodic background checks for employees in sensitive positions.

Artefacts an auditor will ask for
  • Pre-employment screening and verification procedures
  • Background checks for sensitive positions (consistent with local law)
  • Employee code of conduct and separation procedures
Where this commonly fails
  • No pre-employment screening
  • No background checks for sensitive roles
  • No separation/badge-recovery process
CTPAT-MSC-12
Education, Training and Awareness

People and Physical Security. The member must establish and maintain a security training and awareness program so employees understand threats (terrorism, smuggling, internal conspiracies) and the procedures to address them, including how to report incidents.

Artefacts an auditor will ask for
  • Security training and threat-awareness program and completion records
  • Role-specific training for staff in the supply chain
  • Records of incident-reporting awareness
Where this commonly fails
  • No security training program
  • Training not role-specific
  • Staff unaware of how to report incidents
CTPAT-MSC-9
Physical Security

People and Physical Security. Cargo handling and storage facilities must have physical barriers and deterrents (fencing, gates, lighting, alarms, CCTV) commensurate with risk to prevent unauthorised access.

Artefacts an auditor will ask for
  • Physical security measures (fencing, gates, lighting, alarms, CCTV) at facilities
  • CCTV coverage and retention of footage
  • Periodic inspection/maintenance of physical security
Where this commonly fails
  • Inadequate physical barriers
  • No/insufficient CCTV coverage
  • Physical security not maintained
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the C-TPAT - Customs-Trade Partnership Against Terrorism framework page.