Template Information
Internal general audit ctpat
Category: general
Template Questions
- 1. RISK ASSESSMENT
- 1.2 Does the company have written procedures on how to identify risk and how to conduct a 5 step risk assessment?
- 1.4 How often is the Risk Assessment conducted?
- Specify date of last risk assessment. Date
- 1.6 Who conducts the Risk Assessment; if it's conducted by an external company please specify the name of the company.
- 1.7 Complete Supply Chain List: (Manufacturing Company/s, Transportation Company, Mexican Broker, US broker, Importer, etc.) Please specify which companies belong to the C-TPAT program.
- OBSERVATIONS/RECOMMENDATIONS/COMMENTS
- 2. BUSINESS PARTNER REQUIEREMENTS
- 2.8 (Continuing with previous question) How does the company receive such information? (security questionnaire, e-mail, contractual agreement, other)
- 2.11 If the previous question was answered OTHER please specify:
- 2.13 Type of confirmation none CTPAT business partners have with the company, to specify that they will comply with the minimum security criteria stipulated by the program.
- 2.14 If the previous question is answered OTHER, please specify:
- 2.19 Name or Names of Transportation Companies used for crossing, percentage of crossings they realize for the company and their CTPAT current status.
- 2.22 Please provide a copy of security questionnaire.
- OBSERVATIONS/COMMENTS/ RECOMMENDATION
- 3A. TRANSPORTATION SECURITY.
- 3.3 What type of inspection sheet does the company use?
- 3.4 If the answer to the previous question was "OTHER", please specify what type of inspection sheet is used.
- 3.5 Who does the vehicle inspections?
- 3.6 If the previous question was answered "OTHER" please specify who does the vehicle inspections?
- 3.7 Please specify what type of vehicles the company uses to transport merchandise to the United States.
- 3.8 When are inspections to vehicles done?
- If the previous question is NO, please specify what stops the vehicles are instructed to do.
- 3.16 Referring to the previous question where are written procedures found?
- 3.18 What type of seals are used? Please pick more than one.
- 3.19 If more than one seal is used, please specify when each seal is used and why.
- 3.20 Who is your seal provider?
- 3.23 If the previous answer is YES, please specify what type of tracking device or procedure does the company follow?
- 3.24 If the company uses a tracking log, please specify what type of information is filled in. (Date, Driver's Name, Vehicle Plates, Time of arrival at International Border, etc.)
- 3.28 What type of communication do the drivers have with them? (Please choose more than one, if necessary).
- 3.43 Please specify where seals are stored?
- 3.44 Please specify all documents (referring to shipments) that have the seal number. (P.O, E-Manifest, Inspection Checklist, etc.)
- 3.45 Where is seal verified? (Please select more than one if applicable)
- 3.48 Since when is the company Certified with the C-TPAT program? If not yet certified, since when did the company begin with procedures to obtain such certification? Date
- OBSERVATIONS/RECOMENDATIONS
- 3B. DOCUMENT SECURITY
- 3B.3 Please specify where the company information is stored?
- 4B.8 Who is in charge of loading the conveyances bound to the US? (Please select more than one if applicable)
- 4B.9 Please specify what type of documents is the company responsible of? (Purchase Order, E-Manifest, etc.)
- Especifique los procedimientos de conteo de mercancia y pesado de mercancia, previo a la carga.
- 4. PHYSICAL ACCESS CONTROLS
- 4.2 If the previous answer is YES, specify if they are company owned or subcontracted by an external company.
- 4.2.1 If subcontracted: specify what company provides this service.
- 4.5 Specify what hours and how many shifts do security guards have. (ONLY SECURITY GUARDS IF APPLICABLE)
- 4.6.1 If the previous answer is YES, please specify how many and where they are located.
- 4.12 Please specify how many employees (TOTAL) does the company have and how many shifts.
- 4.15 Please specify what type of information do EMPLOYEE ID BADGES have: (Name, Employee Number, Department, Photo, etc.)
- 4.18 Please specify what type of access controls does the company have (ID Badges, Biometric, Electronic Key Cards, Keys, etc.)
- 4.26 Referring to the previous question, please specify what type of information is logged into the visitors log?
- 5.1 Who is in charge of recruiting? (Specify if physical person or department)
- 5. PERSONNEL SECURITY
- 5.3 Specify what type of documents are inside each employee file? (Application, Resume, Drug Screening Test, Photo ID, VISA or Passport, etc.)
- 5.6 On who does the company conduct a back ground check? (Please select more than one if Applicable)
- 5.9 What type of system does the company use to recruit new personnel, or how does the company inform future prospects about job openings? (Please select more then one if Applicable)
- 7.1 Describe what type of surroundings does the company have? (Commercial, Residential, Rural, etc.)
- 7.2 Please specify measurements of the premises (Building and Building Including Grounds).
- 7. PHYSICAL SECURITY
- 7.5 Please specify of what material is the perimeter barrier made of and how high it is?
- 7.9 Please specify of what material is the building made of?
- 7.14 How many loading docks does the company have? And how many are used?
- 7.16 Referring to the previous question please specify where locking mechanisms are (doors, windows, gates, docks, etc.)
- 7.17 How monitors these locking mechanisms? Select more than one if applicable.
- 7.24 If the previous answer is Yes, who is your alarm provider and what type of alarm system does the company have?
- 7.26 If the previous answer is YES, how many cameras does the company have? Internal and External?
- 7.27 Who monitors the CCTV security system?
- 7.28 How long does the company store CCTV footage? Where is this information stored? (DVR's videocassette, etc.)
- 8. SECURITY TRAINING AND THREAT AWARENESS PROGRAMS.
- 8.2 Please specify what type of information (regarding security) is given in such training sessions.
- 8.6 How often are employees trained?
- 8.11 If the previous answer is YES, please specify what type of incentives does the company offer?
- OBSERVATIONS/RECOMENDATIONS.
- 9. IT SECURITY
- 9.3 If the previous answer is NO, who is in charge of the company's IT?
- 9.5 Do employees assign their own passwords? If NO, who assigns the passwords for each username?
- 9.6 How often are passwords changed?
- 9.12 How often are BACKUPS done? (Please select more than one if applicable)
- 10.1 Who is in charge of ordering the company's Transponders?
- 10.2 How many Transponders does the company have?
- 11. EFFECTIVITY TESTS
- 11.2 Please describe the effectivity test, when it was held, who it was held to, if or not it was successful, etc.
- Photo Log