ISO 28001:2007 Supply Chain Security Management
Evidence request list. 36 controls, 36 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.
Audit
Conduct internal audits of the supply chain security management system.
- Audit plan
- Audit reports
- Findings register
- Audits not risk based
CAPA
Manage nonconformities with corrective and preventive actions.
- NCR log
- CAPA tracker
- Effectiveness review
- Effectiveness not verified
Cargo
Protect cargo integrity through seals, locks, inspection, and conveyance security.
- Seal log
- Inspection checklists
- CCTV footage
- Seal numbers not reconciled
Communication
Maintain communication with internal and external stakeholders on security matters.
- Stakeholder map
- Communication plan
- Meeting minutes
- No external escalation path
Compliance
Periodically evaluate compliance with applicable legal and regulatory requirements.
- Legal register
- Compliance evaluation report
- Customs rules missing
Context
Define the organisation's role, scope, and assets within the supply chain to be secured.
- Scope statement
- Supply chain map
- Asset register
- Partial supplier coverage
- Missing transit nodes
Documentation
Control security related documents and records for currency and access.
- Document register
- Version history
- Access controls
- Obsolete docs accessible
Governance
Top management reviews the security management system at planned intervals.
- Review minutes
- Action register
- Review skipped years
- No actions tracked
Incident
Investigate security related incidents and implement corrective actions.
- Incident log
- Root cause analysis
- CAPA
- No root cause
- Repeat incidents
Information
Protect shipment and supply chain information from unauthorised disclosure or alteration.
- Access control matrix
- Encryption evidence
- EDI logs
- Shared accounts in use
Monitoring
Monitor and measure security controls and report against objectives.
- KPI reports
- Inspection trends
- Dashboard
- Metrics not reviewed by management
Operations
Implement operational controls to manage security risks in day to day activities.
- SOPs
- Inspection logs
- Seal records
- SOPs not followed at remote sites
Partners
Assess and contract business partners against compatible security standards including AEO.
- Partner questionnaires
- Contract clauses
- AEO certificates
- Tier 2 partners unassessed
People
Ensure personnel performing security tasks are competent and trained.
- Training records
- Competence matrix
- Refresher schedule
- Contractors untrained
- No refresher
Verify personnel backgrounds and control access to secure areas.
- Background check records
- Access logs
- Badge inventory
- No periodic recheck
Personnel and Information Security
Implement pre-employment and periodic background screening for personnel with access to supply chain assets. Define screening criteria based on sensitivity of role.
- Personnel screening records
- Security awareness curriculum
- Information security clauses
- Business partner questionnaire
- Screening not refreshed
- Partner attestations stale
- Information clauses absent from contracts
Provide supply chain security awareness training to all personnel. Include threat recognition, reporting procedures, and security responsibilities specific to supply chain roles.
- Personnel screening records
- Security awareness curriculum
- Information security clauses
- Business partner questionnaire
- Screening not refreshed
- Partner attestations stale
- Information clauses absent from contracts
Protect supply chain information including shipping documentation, routing plans, customer data, and security procedures from unauthorized access and disclosure.
- Personnel screening records
- Security awareness curriculum
- Information security clauses
- Business partner questionnaire
- Screening not refreshed
- Partner attestations stale
- Information clauses absent from contracts
Establish security requirements for business partners in the supply chain. Conduct security assessments of business partners and include security clauses in contracts.
- Personnel screening records
- Security awareness curriculum
- Information security clauses
- Business partner questionnaire
- Screening not refreshed
- Partner attestations stale
- Information clauses absent from contracts
Physical
Implement physical security at facilities handling goods in the supply chain.
- Site survey
- Perimeter inspection
- Alarm test logs
- Lighting gaps
- Unmonitored gates
Physical Security Countermeasures
Implement physical security measures for supply chain facilities including perimeter protection, access control systems, surveillance, lighting, and intrusion detection.
- Facility security assessment
- Conveyance inspection log
- Cargo seal register
- Key control procedure
- Seal verification skipped at handoff
- Key control register incomplete
- Conveyance inspection not documented
Secure transport conveyances (containers, trucks, vessels, aircraft) against unauthorized access, tampering, and contraband introduction. Implement seal management programs.
- Facility security assessment
- Conveyance inspection log
- Cargo seal register
- Key control procedure
- Seal verification skipped at handoff
- Key control register incomplete
- Conveyance inspection not documented
Implement cargo security measures including secure packaging, tamper-evident seals, cargo tracking, and chain of custody documentation throughout the supply chain.
- Facility security assessment
- Conveyance inspection log
- Cargo seal register
- Key control procedure
- Seal verification skipped at handoff
- Key control register incomplete
- Conveyance inspection not documented
Establish procedures for the management of keys, locks, and tamper-evident seals used to secure cargo and facilities. Document seal application and verification processes.
- Facility security assessment
- Conveyance inspection log
- Cargo seal register
- Key control procedure
- Seal verification skipped at handoff
- Key control register incomplete
- Conveyance inspection not documented
Planning
Set measurable security objectives consistent with the policy and risk profile.
- Objectives register
- KPI dashboard
- Target review minutes
- Objectives not measurable
- No owner
Develop a security plan covering personnel, physical, information, and cargo controls.
- Security plan
- Control matrix
- Implementation schedule
- Plan not exercised
- Outdated controls
Policy
Document and approve a supply chain security policy aligned to business objectives.
- Security policy
- Approval record
- Communication log
- Policy not signed
- No review cadence
Process and Procedural Controls
Ensure compliance with customs regulations, trade security programs (C-TPAT, AEO), and applicable international trade agreements. Maintain accurate trade documentation.
- Customs compliance procedure
- Manifest verification log
- Supply chain incident report
- Continuity plan
- Manifest discrepancies not investigated
- Incident reports delayed to customs
- Continuity plan not exercised
Establish procedures for accurate and timely preparation, submission, and reconciliation of shipping manifests, bills of lading, and customs declarations.
- Customs compliance procedure
- Manifest verification log
- Supply chain incident report
- Continuity plan
- Manifest discrepancies not investigated
- Incident reports delayed to customs
- Continuity plan not exercised
Establish incident reporting procedures for supply chain security events including cargo theft, smuggling attempts, unauthorized access, and suspicious activities.
- Customs compliance procedure
- Manifest verification log
- Supply chain incident report
- Continuity plan
- Manifest discrepancies not investigated
- Incident reports delayed to customs
- Continuity plan not exercised
Develop and maintain supply chain continuity plans addressing disruptions from security incidents, natural disasters, and other events affecting supply chain operations.
- Customs compliance procedure
- Manifest verification log
- Supply chain incident report
- Continuity plan
- Manifest discrepancies not investigated
- Incident reports delayed to customs
- Continuity plan not exercised
Records
Maintain security records to demonstrate conformity and effectiveness.
- Record retention schedule
- Sample records
- Records not retained per schedule
Resilience
Establish procedures to respond to security incidents and emergencies.
- Emergency plan
- Exercise reports
- Contact lists
- Plan untested
- Stale contacts
Risk
Identify and assess threats, vulnerabilities, and consequences across the supply chain.
- Threat register
- Vulnerability assessment
- Risk treatment plan
- Single point assessment
- No reassessment after change
Roles
Assign responsibility, authority, and resources for supply chain security activities.
- RACI
- Org chart
- Job descriptions
- No backup designee
- Unclear authority
Supply Chain Security Assessment
Develop risk treatment plans specifying countermeasures for identified supply chain security risks. Include implementation timelines, responsible parties, and resource requirements.
- Security risk assessment
- Threat scenario register
- Treatment plan
- Coverage gap analysis
- Risk assessment not refreshed annually
- Threat scenarios miss insider
- Treatment plan owners unassigned
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does.