Skip to content

Evidence request lists

ISO 28001:2007 Supply Chain Security Management

Evidence request list. 36 controls, 36 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.

Audit

ISO28001-4.17
Internal audit

Conduct internal audits of the supply chain security management system.

Artefacts an auditor will ask for
  • Audit plan
  • Audit reports
  • Findings register
Where this commonly fails
  • Audits not risk based

CAPA

ISO28001-4.15
Nonconformity, corrective and preventive action

Manage nonconformities with corrective and preventive actions.

Artefacts an auditor will ask for
  • NCR log
  • CAPA tracker
  • Effectiveness review
Where this commonly fails
  • Effectiveness not verified

Cargo

ISO28001-A.5
Cargo integrity and conveyance security

Protect cargo integrity through seals, locks, inspection, and conveyance security.

Artefacts an auditor will ask for
  • Seal log
  • Inspection checklists
  • CCTV footage
Where this commonly fails
  • Seal numbers not reconciled

Communication

ISO28001-4.8
Communication and consultation

Maintain communication with internal and external stakeholders on security matters.

Artefacts an auditor will ask for
  • Stakeholder map
  • Communication plan
  • Meeting minutes
Where this commonly fails
  • No external escalation path

Compliance

ISO28001-4.13
Evaluation of compliance

Periodically evaluate compliance with applicable legal and regulatory requirements.

Artefacts an auditor will ask for
  • Legal register
  • Compliance evaluation report
Where this commonly fails
  • Customs rules missing

Context

ISO28001-4.1
Supply chain security context

Define the organisation's role, scope, and assets within the supply chain to be secured.

Artefacts an auditor will ask for
  • Scope statement
  • Supply chain map
  • Asset register
Where this commonly fails
  • Partial supplier coverage
  • Missing transit nodes

Documentation

ISO28001-4.9
Documentation control

Control security related documents and records for currency and access.

Artefacts an auditor will ask for
  • Document register
  • Version history
  • Access controls
Where this commonly fails
  • Obsolete docs accessible

Governance

ISO28001-4.18
Management review

Top management reviews the security management system at planned intervals.

Artefacts an auditor will ask for
  • Review minutes
  • Action register
Where this commonly fails
  • Review skipped years
  • No actions tracked

Incident

ISO28001-4.14
Related security incident investigation

Investigate security related incidents and implement corrective actions.

Artefacts an auditor will ask for
  • Incident log
  • Root cause analysis
  • CAPA
Where this commonly fails
  • No root cause
  • Repeat incidents

Information

ISO28001-A.7
Information and IT security

Protect shipment and supply chain information from unauthorised disclosure or alteration.

Artefacts an auditor will ask for
  • Access control matrix
  • Encryption evidence
  • EDI logs
Where this commonly fails
  • Shared accounts in use

Monitoring

ISO28001-4.12
Performance monitoring and measurement

Monitor and measure security controls and report against objectives.

Artefacts an auditor will ask for
  • KPI reports
  • Inspection trends
  • Dashboard
Where this commonly fails
  • Metrics not reviewed by management

Operations

ISO28001-4.10
Operational control

Implement operational controls to manage security risks in day to day activities.

Artefacts an auditor will ask for
  • SOPs
  • Inspection logs
  • Seal records
Where this commonly fails
  • SOPs not followed at remote sites

Partners

ISO28001-A.8
Business partner and AEO compatibility

Assess and contract business partners against compatible security standards including AEO.

Artefacts an auditor will ask for
  • Partner questionnaires
  • Contract clauses
  • AEO certificates
Where this commonly fails
  • Tier 2 partners unassessed

People

ISO28001-4.7
Competence and training

Ensure personnel performing security tasks are competent and trained.

Artefacts an auditor will ask for
  • Training records
  • Competence matrix
  • Refresher schedule
Where this commonly fails
  • Contractors untrained
  • No refresher
ISO28001-A.6
Personnel security and access

Verify personnel backgrounds and control access to secure areas.

Artefacts an auditor will ask for
  • Background check records
  • Access logs
  • Badge inventory
Where this commonly fails
  • No periodic recheck

Personnel and Information Security

ISO28001-PI-01
Personnel Security Screening

Implement pre-employment and periodic background screening for personnel with access to supply chain assets. Define screening criteria based on sensitivity of role.

Artefacts an auditor will ask for
  • Personnel screening records
  • Security awareness curriculum
  • Information security clauses
  • Business partner questionnaire
Where this commonly fails
  • Screening not refreshed
  • Partner attestations stale
  • Information clauses absent from contracts
ISO28001-PI-02
Security Awareness and Training

Provide supply chain security awareness training to all personnel. Include threat recognition, reporting procedures, and security responsibilities specific to supply chain roles.

Artefacts an auditor will ask for
  • Personnel screening records
  • Security awareness curriculum
  • Information security clauses
  • Business partner questionnaire
Where this commonly fails
  • Screening not refreshed
  • Partner attestations stale
  • Information clauses absent from contracts
ISO28001-PI-03
Information Security in Supply Chain

Protect supply chain information including shipping documentation, routing plans, customer data, and security procedures from unauthorized access and disclosure.

Artefacts an auditor will ask for
  • Personnel screening records
  • Security awareness curriculum
  • Information security clauses
  • Business partner questionnaire
Where this commonly fails
  • Screening not refreshed
  • Partner attestations stale
  • Information clauses absent from contracts
ISO28001-PI-04
Business Partner Security Requirements

Establish security requirements for business partners in the supply chain. Conduct security assessments of business partners and include security clauses in contracts.

Artefacts an auditor will ask for
  • Personnel screening records
  • Security awareness curriculum
  • Information security clauses
  • Business partner questionnaire
Where this commonly fails
  • Screening not refreshed
  • Partner attestations stale
  • Information clauses absent from contracts

Physical

ISO28001-A.9
Physical security of facilities

Implement physical security at facilities handling goods in the supply chain.

Artefacts an auditor will ask for
  • Site survey
  • Perimeter inspection
  • Alarm test logs
Where this commonly fails
  • Lighting gaps
  • Unmonitored gates

Physical Security Countermeasures

ISO28001-PS-01
Facility Security

Implement physical security measures for supply chain facilities including perimeter protection, access control systems, surveillance, lighting, and intrusion detection.

Artefacts an auditor will ask for
  • Facility security assessment
  • Conveyance inspection log
  • Cargo seal register
  • Key control procedure
Where this commonly fails
  • Seal verification skipped at handoff
  • Key control register incomplete
  • Conveyance inspection not documented
ISO28001-PS-02
Conveyance Security

Secure transport conveyances (containers, trucks, vessels, aircraft) against unauthorized access, tampering, and contraband introduction. Implement seal management programs.

Artefacts an auditor will ask for
  • Facility security assessment
  • Conveyance inspection log
  • Cargo seal register
  • Key control procedure
Where this commonly fails
  • Seal verification skipped at handoff
  • Key control register incomplete
  • Conveyance inspection not documented
ISO28001-PS-03
Cargo Security

Implement cargo security measures including secure packaging, tamper-evident seals, cargo tracking, and chain of custody documentation throughout the supply chain.

Artefacts an auditor will ask for
  • Facility security assessment
  • Conveyance inspection log
  • Cargo seal register
  • Key control procedure
Where this commonly fails
  • Seal verification skipped at handoff
  • Key control register incomplete
  • Conveyance inspection not documented
ISO28001-PS-04
Key and Seal Management

Establish procedures for the management of keys, locks, and tamper-evident seals used to secure cargo and facilities. Document seal application and verification processes.

Artefacts an auditor will ask for
  • Facility security assessment
  • Conveyance inspection log
  • Cargo seal register
  • Key control procedure
Where this commonly fails
  • Seal verification skipped at handoff
  • Key control register incomplete
  • Conveyance inspection not documented

Planning

ISO28001-4.4
Security objectives and targets

Set measurable security objectives consistent with the policy and risk profile.

Artefacts an auditor will ask for
  • Objectives register
  • KPI dashboard
  • Target review minutes
Where this commonly fails
  • Objectives not measurable
  • No owner
ISO28001-4.5
Security plan

Develop a security plan covering personnel, physical, information, and cargo controls.

Artefacts an auditor will ask for
  • Security plan
  • Control matrix
  • Implementation schedule
Where this commonly fails
  • Plan not exercised
  • Outdated controls

Policy

ISO28001-4.2
Security management policy

Document and approve a supply chain security policy aligned to business objectives.

Artefacts an auditor will ask for
  • Security policy
  • Approval record
  • Communication log
Where this commonly fails
  • Policy not signed
  • No review cadence

Process and Procedural Controls

ISO28001-PC-01
Customs and Trade Compliance

Ensure compliance with customs regulations, trade security programs (C-TPAT, AEO), and applicable international trade agreements. Maintain accurate trade documentation.

Artefacts an auditor will ask for
  • Customs compliance procedure
  • Manifest verification log
  • Supply chain incident report
  • Continuity plan
Where this commonly fails
  • Manifest discrepancies not investigated
  • Incident reports delayed to customs
  • Continuity plan not exercised
ISO28001-PC-02
Manifest and Documentation Procedures

Establish procedures for accurate and timely preparation, submission, and reconciliation of shipping manifests, bills of lading, and customs declarations.

Artefacts an auditor will ask for
  • Customs compliance procedure
  • Manifest verification log
  • Supply chain incident report
  • Continuity plan
Where this commonly fails
  • Manifest discrepancies not investigated
  • Incident reports delayed to customs
  • Continuity plan not exercised
ISO28001-PC-03
Supply Chain Incident Reporting

Establish incident reporting procedures for supply chain security events including cargo theft, smuggling attempts, unauthorized access, and suspicious activities.

Artefacts an auditor will ask for
  • Customs compliance procedure
  • Manifest verification log
  • Supply chain incident report
  • Continuity plan
Where this commonly fails
  • Manifest discrepancies not investigated
  • Incident reports delayed to customs
  • Continuity plan not exercised
ISO28001-PC-04
Supply Chain Continuity Planning

Develop and maintain supply chain continuity plans addressing disruptions from security incidents, natural disasters, and other events affecting supply chain operations.

Artefacts an auditor will ask for
  • Customs compliance procedure
  • Manifest verification log
  • Supply chain incident report
  • Continuity plan
Where this commonly fails
  • Manifest discrepancies not investigated
  • Incident reports delayed to customs
  • Continuity plan not exercised

Records

ISO28001-4.16
Control of records

Maintain security records to demonstrate conformity and effectiveness.

Artefacts an auditor will ask for
  • Record retention schedule
  • Sample records
Where this commonly fails
  • Records not retained per schedule

Resilience

ISO28001-4.11
Emergency preparedness and response

Establish procedures to respond to security incidents and emergencies.

Artefacts an auditor will ask for
  • Emergency plan
  • Exercise reports
  • Contact lists
Where this commonly fails
  • Plan untested
  • Stale contacts

Risk

ISO28001-4.3
Security risk assessment

Identify and assess threats, vulnerabilities, and consequences across the supply chain.

Artefacts an auditor will ask for
  • Threat register
  • Vulnerability assessment
  • Risk treatment plan
Where this commonly fails
  • Single point assessment
  • No reassessment after change

Roles

ISO28001-4.6
Resources, roles, responsibility

Assign responsibility, authority, and resources for supply chain security activities.

Artefacts an auditor will ask for
  • RACI
  • Org chart
  • Job descriptions
Where this commonly fails
  • No backup designee
  • Unclear authority

Supply Chain Security Assessment

ISO28001-SA-04
Security Risk Treatment Planning

Develop risk treatment plans specifying countermeasures for identified supply chain security risks. Include implementation timelines, responsible parties, and resource requirements.

Artefacts an auditor will ask for
  • Security risk assessment
  • Threat scenario register
  • Treatment plan
  • Coverage gap analysis
Where this commonly fails
  • Risk assessment not refreshed annually
  • Threat scenarios miss insider
  • Treatment plan owners unassigned
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does.