Call Us Now!
Facebook and Twitter
Subscribe to blog
Blog index
RSS
« Federal Government Gets Serious About Trade Enforcement | Main | Importer Tools: ITRAC and Freedom of Information Act »
Friday
Sep032010

New 5 Steps for C-TPAT Supply Chain Risk Assessments

Companies applying for C-TPAT certification must complete a supply chain security risk assessment and report the findings to CBP, and companies enrolled in C-TPAT must complete and report risk assessments annually.  The problem has always been that CBP never properly explained how to conduct these risk assessments.

Now it has.  

US Customs and Border recently outlined a Five Step Risk Assessment Process.  While not required to follow them blindly or at all (because “The C-TPAT program clearly understands there are a wide variety of business models”), companies applying to C-TPAT would be smart to hew as closely as possible to the five steps to increase their chances of getting certified, and companies already in C-TPAT should do the same to avoid putting their certification at risk.  

CBP claims that the five steps are not new, but if not new, the information has never before been set out so clearly.  In exchange for providing a “how to,” it certainly appears that CBP is expecting a great deal more from C-TPAT members.  C-TPAT is no longer for companies that treat supply chain security with armchair indifference.  

For example, you are now supposed to grade the threat level of your sourcing country based on six indicia: 

  1. Terrorism (Political, Bio, Agro, Cyber)
  2. Contraband Smuggling
  3. Human Smuggling
  4. Organized Crime
  5. Conditions within a country which may foster any of the aforementioned threats (e.g. poverty, social unrest, political instability)
  6. Other: theft, pilferage, hijacking, piracy, and IPR. 

You must assign a grade, or at least find a way to measure, the threat level.  CBP suggests the following grades:  

  1. Low Risk - No recent incidents/intelligence/information. 
  2. Medium Risk – No recent incidents/some intelligence/information on possible activity. 
  3. High Risk – Recent incidents and intelligence/information.  

While CBP offers a list of free resources to help you assess the threat level to your supply chain, it is clear that your company must expend a great deal of energy and resources collecting and analyzing intelligence on each country that you source from and on every entity in your supply chain.  It is hard to imagine that companies will be able to do this on their own without the assistance of legal experts and consultants.  

All C-TPAT members (brokers, consolidators, carriers, etc.), not just importers, are expected to abide by the five steps as much as possible.  Small companies are not excused, and importers cannot rely on INCOTERMS to get around having to control and ensure supply chain security.  

The five steps emphasize that subcontracting logistics and transportation increases your threat level and requires that you take additional due diligence steps to control your “business partners” (a C-TPAT term that does not have the same limited meaning as the legal term).  Many international shipments are handled by third party logistics providers who, in turn, may further contract out transportation companies.  The five steps do not describe how these companies would remedy the supply chain failing of “business partners,” but do suggest that education plays an important part.  Some 3PLs also do not qualify for C-TPAT because they “double broker” and do not own any of the warehousing facilities or means of transportation.

The five steps provide wiggle room for companies that have not quite achieved all the C-TPAT criteria, but are committed to making improvements by “prescribing corrective actions with follow-up procedures to ensure weaknesses have been mitigated.”

CBP prepared an FAQ and a memo on how to do an a risk assessment. The publication offers five sample templates or checklists to help you make sure you are on target.   

Here are the five steps: 

  1. Mapping Cargo and Business Partners: Identify Business Partners and how cargo moves throughout the supply chain to include modes of transportation (air, sea, rail, or truck) and nodes (country of origin, transit points).
  2. Conducting a Threat Assessment: Identify such threats as Terrorism, Contraband / Human Smuggling, Organized Crime, or other Conditions which may increase the probability of a security breach.
  3. Conducting a Security Vulnerability Assessment: Based on C-TPAT minimum security criteria, determine if Business Partners have gaps, vulnerabilities, or weaknesses which may lead to a security breach.
  4. Preparing an Action Plan to Address Vulnerabilities: Developing a written strategy to address potential gaps, vulnerabilities, and weaknesses.
  5. Documenting How the Security Risk Assessment is Conducted: Writing the policies / procedures on who will be responsible for conducting the assessment; what will be included in the assessment; why the assessment must be conducted; when (how often) the assessment will be conducted; where the assessments will be conducted; and how the assessment will be conducted. 

 

PrintView Printer Friendly Version

EmailEmail Article to Friend

Reader Comments (3)

I live in Asia and now C-TPAT is extending to some of manufacturing companies here. This program is very difficult to pass.

August 26, 2011 | Unregistered CommenterBen Benjabutr

The particular content is very helpful with regard to new bloggers and provides an excellent starting place to start with. May talk about your posting on my subsequent post. Many thanks.
african mango

November 28, 2011 | Unregistered Commenterroderickmerr1229

Hi: I just completed the 5 step risk assessment outline for a friend. It turned into a 450 response anual exam- and this is just for the first of 100 customers. I have found lifetime employment in this program.

Franko

January 16, 2012 | Unregistered CommenterFranko

PostPost a New Comment

Enter your information below to add a new comment.

My response is on my own website »
Author Email (optional):
Author URL (optional):
Post:
 
Some HTML allowed: <a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <code> <em> <i> <strike> <strong>