Skip to content

Evidence request lists

WCO SAFE Framework of Standards to Secure and Facilitate Global Trade (2021)

Evidence request list. 24 controls, 24 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.

ISCM

WCOSAFE-4
Integrated Supply Chain Management

Per WCO SAFE Framework of Standards to Secure and Facilitate Global Trade (2021): Integrated Supply Chain Management. Source-grounded summary control covering authoritative framework structure + key obligations. See manifest + log for detailed mapping.

Artefacts an auditor will ask for
  • Authoritative source-grounded evidence for WCOSAFE-4
Where this commonly fails
  • see authoritative source for detailed gap analysis

P1

WCOSAFE-1
Pillar 1 Customs-to-Customs

Per WCO SAFE Framework of Standards to Secure and Facilitate Global Trade (2021): Pillar 1 Customs-to-Customs. Source-grounded summary control covering authoritative framework structure + key obligations. See manifest + log for detailed mapping.

Artefacts an auditor will ask for
  • Authoritative source-grounded evidence for WCOSAFE-1
Where this commonly fails
  • see authoritative source for detailed gap analysis

P2

WCOSAFE-2
Pillar 2 Customs-to-Business (AEO)

Per WCO SAFE Framework of Standards to Secure and Facilitate Global Trade (2021): Pillar 2 Customs-to-Business (AEO). Source-grounded summary control covering authoritative framework structure + key obligations. See manifest + log for detailed mapping.

Artefacts an auditor will ask for
  • Authoritative source-grounded evidence for WCOSAFE-2
Where this commonly fails
  • see authoritative source for detailed gap analysis

P3

WCOSAFE-3
Pillar 3 Customs-to-Other Government Agencies

Per WCO SAFE Framework of Standards to Secure and Facilitate Global Trade (2021): Pillar 3 Customs-to-Other Government Agencies. Source-grounded summary control covering authoritative framework structure + key obligations. See manifest + log for detailed mapping.

Artefacts an auditor will ask for
  • Authoritative source-grounded evidence for WCOSAFE-3
Where this commonly fails
  • see authoritative source for detailed gap analysis

WCO SAFE Pillar 1: Customs to Customs

SAFE-P1-01
Pillar 1: Integrated Supply Chain Management (Customs-Customs)

Customs administrations apply integrated customs control procedures across the international supply chain using risk management techniques and advance electronic information to identify high risk consignments while facilitating low risk trade.

Artefacts an auditor will ask for
  • Customs operating procedures incorporating SAFE principles
  • Risk management system documentation
  • Advance Cargo Information data flow diagrams
  • Integrated control performance metrics
  • Memorandum of understanding with origin and transit customs
Where this commonly fails
  • Risk rules not aligned with SAFE indicators
  • Advance data not used for pre-arrival selection
  • No measurement of integrated control effectiveness
  • Origin customs cooperation informal only
SAFE-P1-02
Authority to Inspect Cargo and Conveyances

Customs administrations have legal authority to inspect cargo and conveyances at any point in the international supply chain and to require advance information to facilitate risk assessment, including authority to act on requests from other customs administrations.

Artefacts an auditor will ask for
  • Customs law granting inspection authority
  • Inspection procedure manuals
  • Records of inspections conducted on behalf of foreign customs
  • Bilateral or multilateral assistance agreements
  • Inspection outcome reporting templates
Where this commonly fails
  • Authority does not extend to transhipment cargo
  • Foreign requests not tracked
  • No legal basis for non intrusive inspection in some zones
  • Inspection results not shared back
SAFE-P1-03
Modern Technology in Inspection Equipment

Customs administrations deploy modern non intrusive inspection technology including X-ray, gamma ray, radiation detection, and seal verification equipment at high risk ports, airports, and land borders to enable rapid screening without disrupting flow.

Artefacts an auditor will ask for
  • NII equipment inventory by border post
  • Equipment calibration and maintenance logs
  • Operator training and certification records
  • Throughput statistics (containers scanned per hour)
  • Image library and second review procedures
Where this commonly fails
  • Equipment downtime not tracked
  • Operators not recertified annually
  • No procedure for image library retention
  • Land border posts under-equipped versus seaports
SAFE-P1-04
Risk Management System

Customs establish a documented risk management system to identify potentially high risk shipments using automated profiling, intelligence integration, and selectivity criteria, with regular evaluation of rule effectiveness and false positive rates.

Artefacts an auditor will ask for
  • Risk management framework document
  • Selectivity rule library with versioning
  • Hit rate and false positive analytics
  • Intelligence integration procedures
  • Risk committee meeting minutes
Where this commonly fails
  • Rules not retired when outdated
  • No hit rate measurement
  • Intelligence units siloed from risk teams
  • Selectivity bypassed manually without log
SAFE-P1-05
Advance Electronic Cargo Information

Require advance electronic submission of cargo information from carriers, importers, exporters, and brokers prior to loading or arrival, using WCO Data Model elements, with defined timing thresholds per transport mode (e.g. 24 hours pre-loading for maritime).

Artefacts an auditor will ask for
  • Advance cargo information regulations with timing per mode
  • WCO Data Model mapping documentation
  • Compliance dashboard for filing timeliness
  • Penalty regime for late or inaccurate filing
  • Data quality feedback loop to filers
Where this commonly fails
  • Air and road modes not covered
  • Data elements deviate from WCO Data Model
  • Late filings not penalised
  • Filer education limited
SAFE-P1-06
Targeting and Communication

Customs administrations engage in joint targeting using shared selectivity criteria, communicate targeting results between origin, transit, and destination customs, and conduct joint operations against identified high risk consignments.

Artefacts an auditor will ask for
  • Joint targeting protocols with partner administrations
  • Communication channel records (CEN, RILO, secure email)
  • Joint operation after action reports
  • Targeting effectiveness metrics
  • Personnel exchange or liaison officer records
Where this commonly fails
  • Joint targeting limited to one mode
  • No metrics on joint operation seizures
  • RILO connectivity inconsistent
  • Liaison officer positions vacant
SAFE-P1-07
Performance Measures

Customs administrations maintain statistical reports on performance measures including clearance times, inspection rates, hit rates, seizures, and operator compliance, published periodically to demonstrate facilitation and security balance.

Artefacts an auditor will ask for
  • Time Release Study reports
  • Annual customs performance report
  • Inspection and seizure statistics by mode and commodity
  • Compliance level indicators
  • Stakeholder engagement on performance results
Where this commonly fails
  • No Time Release Study performed in 3+ years
  • Statistics not segmented by mode
  • Performance not published publicly
  • Stakeholder feedback not collected
SAFE-P1-08
Security Assessments

Customs administrations conduct security assessments of borders, ports, airports, and inland clearance points, identify vulnerabilities, and implement remediation including infrastructure, technology, and procedural improvements.

Artefacts an auditor will ask for
  • Border security assessment reports
  • Vulnerability register with remediation plans
  • Capital investment plan for border infrastructure
  • Pre and post remediation effectiveness measurement
  • Cross agency border security committee minutes
Where this commonly fails
  • Assessments rely on single agency view
  • Vulnerabilities identified but not budgeted for
  • Remediation effectiveness not measured
  • Inland ports excluded
SAFE-P1-09
Employee Integrity

Customs administrations implement integrity programmes including code of conduct, anti corruption training, internal affairs investigations, rotation of high risk positions, financial disclosure, and confidential reporting channels.

Artefacts an auditor will ask for
  • Customs code of conduct signed by all staff
  • Anti corruption training completion records
  • Internal affairs case statistics
  • Job rotation policy for high risk posts
  • Confidential reporting channel statistics and investigations
Where this commonly fails
  • Code not refreshed
  • Rotation policy not enforced
  • Reporting channels not anonymous
  • Internal affairs underfunded
SAFE-P1-10
Outbound Security Inspections

Customs administrations conduct outbound security inspections of high risk cargo at the request of the importing country, with documented procedures, equipment, and reporting back to the requesting administration.

Artefacts an auditor will ask for
  • Outbound inspection procedures
  • Log of requests received from foreign customs and outcomes
  • Inspection result reporting templates
  • Equipment availability at outbound ports
  • Service level for response to requests
Where this commonly fails
  • No formal procedure
  • Requests handled ad hoc
  • Outcomes not shared back
  • Service level not measured

WCO SAFE Pillar 2: Customs to Business (AEO)

SAFE-P2-01
AEO Programme (Customs-Business)

Establish national AEO programme open to all supply chain actors meeting defined customs compliance, financial solvency, records management, and security criteria, with benefits proportionate to compliance and security investments.

Artefacts an auditor will ask for
  • Published AEO regulation
  • Application and validation procedures
  • Benefits catalogue
  • Programme statistics (applications, certifications, by operator type)
  • Industry consultation records during programme design
Where this commonly fails
  • Benefits not visible to operators
  • SME participation low
  • Validation backlog
  • Programme criteria not aligned with SAFE
SAFE-P2-02
AEO Authorisation Process

Operate a documented authorisation process including application receipt, desk review, on site validation, decision, certificate issuance, periodic re-validation, and suspension or revocation procedures, with defined timeframes.

Artefacts an auditor will ask for
  • End to end process map
  • Application processing KPI report
  • Validator training and certification records
  • Validation checklists
  • Re-validation cycle calendar
Where this commonly fails
  • Validation timeframes exceeded
  • Validators not trained consistently
  • No published service standards
  • Re-validation slippage
SAFE-P2-03
AEO Mutual Recognition Arrangements

Negotiate and implement mutual recognition arrangements with other customs administrations to extend AEO benefits across borders, including joint validation criteria comparison, benefits offered, data exchange, and dispute resolution.

Artefacts an auditor will ask for
  • List of signed MRAs
  • MRA action plans for each partner
  • Joint validation reports
  • Data exchange specifications
  • MRA review meeting minutes
Where this commonly fails
  • MRAs signed but not implemented
  • Benefits not delivered to operators
  • Data exchange not automated
  • Disputes not resolved formally

WCO SAFE Pillar 3: Customs to Other Government Agencies

SAFE-P3-01
Customs to Government Cooperation (Pillar 3)

Customs cooperate with other government agencies including border security, immigration, health, agriculture, transport, and law enforcement through coordinated border management, single window, joint risk management, and shared intelligence.

Artefacts an auditor will ask for
  • Inter agency MOUs
  • Single window implementation roadmap and status
  • Joint risk profiles with health and agriculture agencies
  • Shared intelligence protocols
  • Coordinated inspection statistics
Where this commonly fails
  • Single window partial, not all agencies onboard
  • Joint risk profiling absent
  • Intelligence sharing informal
  • Duplicated inspections continue
SAFE-P3-02
Single Window Environment

Implement a single window environment allowing traders to submit standardised information once to a single entry point fulfilling regulatory requirements across customs, sanitary, phytosanitary, and other border agencies, with results communicated back through the same channel.

Artefacts an auditor will ask for
  • Single window architecture documentation
  • Participating agency list and integration status
  • Data harmonisation mapping to WCO Data Model
  • User adoption metrics
  • Single window governance committee charter
Where this commonly fails
  • Critical agencies not connected
  • Data harmonisation incomplete
  • Manual workarounds persist
  • No measurement of trader time savings
SAFE-P3-03
Joint Risk Management with Other Agencies

Develop joint risk profiles, share intelligence, and conduct coordinated inspections with other regulatory agencies to address risks spanning customs and other domains (e.g. counterfeit medicines, illicit wildlife, dual use goods).

Artefacts an auditor will ask for
  • Joint risk profile documents
  • Intelligence sharing agreements
  • Coordinated inspection results
  • Cross agency analyst exchange records
  • Joint operation reports
Where this commonly fails
  • Profiles outdated
  • Sharing one directional only
  • No joint training
  • Operational coordination weak at field level

WCO SAFE Pillar 4: Customs to Other Stakeholders

SAFE-P4-01
Customs to Other Stakeholders Cooperation (Pillar 4)

Customs engage with non government stakeholders including industry associations, academia, and consumers through consultation, public private partnerships, transparency initiatives, and joint capacity building to improve facilitation and security.

Artefacts an auditor will ask for
  • Stakeholder consultation calendar
  • Consultative committee charters and minutes
  • Public consultation responses on draft regulations
  • Customs website transparency content
  • Industry feedback survey results
Where this commonly fails
  • Consultations symbolic without impact
  • SME voices under-represented
  • Website information outdated
  • No feedback to consultation respondents
SAFE-P4-02
Customs Communication and Information Sharing

Maintain accessible and current information for traders including tariff schedules, procedures, contact points, decisions, advance rulings, and ports of clearance, published through customs website and other channels in commonly understood languages.

Artefacts an auditor will ask for
  • Customs website content inventory and update log
  • Advance ruling register (anonymised)
  • Multilingual content coverage report
  • Helpdesk contact response time
  • Information accuracy audit
Where this commonly fails
  • Tariff updates lagging
  • Advance rulings not publicly available
  • English-only content limits SME access
  • Helpdesk response slow

WCO SAFE: Implementation and Capacity Building

SAFE-CROSS-01
Capacity Building

Customs administrations invest in capacity building for SAFE implementation including training, equipment, IT systems, and institutional reform, supported as needed by WCO capacity building programmes and donor cooperation.

Artefacts an auditor will ask for
  • Capacity building strategy document
  • Training plan with SAFE-aligned curricula
  • WCO Mercator programme engagement records
  • Donor coordination committee minutes
  • Capacity self assessment results
Where this commonly fails
  • Strategy not funded
  • Training one off without follow up
  • Donor projects duplicative
  • Capacity gains not retained after project end
SAFE-CROSS-02
Implementation Monitoring and Review

Customs administrations monitor SAFE implementation progress through self assessment, peer review, and WCO monitoring tools, with regular reporting to senior management and the WCO, identifying gaps and remediation actions.

Artefacts an auditor will ask for
  • SAFE self assessment results
  • Peer review participation records
  • Annual SAFE implementation status report
  • Gap remediation roadmap
  • WCO Council reporting submissions
Where this commonly fails
  • Self assessment dated
  • Peer review not requested
  • No remediation roadmap for identified gaps
  • Senior management not engaged in monitoring
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does.