C-tpat audit - english

Template Information

Internal general audit ctpat

Category: general

Template Questions

  • 1. RISK ASSESSMENT
  • 1.2 Does the company have written procedures on how to identify risk and how to conduct a 5 step risk assessment?
  • 1.4 How often is the Risk Assessment conducted?
  • Specify date of last risk assessment. Date
  • 1.6 Who conducts the Risk Assessment; if it's conducted by an external company please specify the name of the company.
  • 1.7 Complete Supply Chain List: (Manufacturing Company/s, Transportation Company, Mexican Broker, US broker, Importer, etc.) Please specify which companies belong to the C-TPAT program.
  • OBSERVATIONS/RECOMMENDATIONS/COMMENTS
  • 2. BUSINESS PARTNER REQUIEREMENTS
  • 2.8 (Continuing with previous question) How does the company receive such information? (security questionnaire, e-mail, contractual agreement, other)
  • 2.11 If the previous question was answered OTHER please specify:
  • 2.13 Type of confirmation none CTPAT business partners have with the company, to specify that they will comply with the minimum security criteria stipulated by the program.
  • 2.14 If the previous question is answered OTHER, please specify:
  • 2.19 Name or Names of Transportation Companies used for crossing, percentage of crossings they realize for the company and their CTPAT current status.
  • 2.22 Please provide a copy of security questionnaire.
  • OBSERVATIONS/COMMENTS/ RECOMMENDATION
  • 3A. TRANSPORTATION SECURITY.
  • 3.3 What type of inspection sheet does the company use?
  • 3.4 If the answer to the previous question was "OTHER", please specify what type of inspection sheet is used.
  • 3.5 Who does the vehicle inspections?
  • 3.6 If the previous question was answered "OTHER" please specify who does the vehicle inspections?
  • 3.7 Please specify what type of vehicles the company uses to transport merchandise to the United States.
  • 3.8 When are inspections to vehicles done?
  • If the previous question is NO, please specify what stops the vehicles are instructed to do.
  • 3.16 Referring to the previous question where are written procedures found?
  • 3.18 What type of seals are used? Please pick more than one.
  • 3.19 If more than one seal is used, please specify when each seal is used and why.
  • 3.20 Who is your seal provider?
  • 3.23 If the previous answer is YES, please specify what type of tracking device or procedure does the company follow?
  • 3.24 If the company uses a tracking log, please specify what type of information is filled in. (Date, Driver's Name, Vehicle Plates, Time of arrival at International Border, etc.)
  • 3.28 What type of communication do the drivers have with them? (Please choose more than one, if necessary).
  • 3.43 Please specify where seals are stored?
  • 3.44 Please specify all documents (referring to shipments) that have the seal number. (P.O, E-Manifest, Inspection Checklist, etc.)
  • 3.45 Where is seal verified? (Please select more than one if applicable)
  • 3.48 Since when is the company Certified with the C-TPAT program? If not yet certified, since when did the company begin with procedures to obtain such certification? Date
  • OBSERVATIONS/RECOMENDATIONS
  • 3B. DOCUMENT SECURITY
  • 3B.3 Please specify where the company information is stored?
  • 4B.8 Who is in charge of loading the conveyances bound to the US? (Please select more than one if applicable)
  • 4B.9 Please specify what type of documents is the company responsible of? (Purchase Order, E-Manifest, etc.)
  • Especifique los procedimientos de conteo de mercancia y pesado de mercancia, previo a la carga.
  • 4. PHYSICAL ACCESS CONTROLS
  • 4.2 If the previous answer is YES, specify if they are company owned or subcontracted by an external company.
  • 4.2.1 If subcontracted: specify what company provides this service.
  • 4.5 Specify what hours and how many shifts do security guards have. (ONLY SECURITY GUARDS IF APPLICABLE)
  • 4.6.1 If the previous answer is YES, please specify how many and where they are located.
  • 4.12 Please specify how many employees (TOTAL) does the company have and how many shifts.
  • 4.15 Please specify what type of information do EMPLOYEE ID BADGES have: (Name, Employee Number, Department, Photo, etc.)
  • 4.18 Please specify what type of access controls does the company have (ID Badges, Biometric, Electronic Key Cards, Keys, etc.)
  • 4.26 Referring to the previous question, please specify what type of information is logged into the visitors log?
  • 5.1 Who is in charge of recruiting? (Specify if physical person or department)
  • 5. PERSONNEL SECURITY
  • 5.3 Specify what type of documents are inside each employee file? (Application, Resume, Drug Screening Test, Photo ID, VISA or Passport, etc.)
  • 5.6 On who does the company conduct a back ground check? (Please select more than one if Applicable)
  • 5.9 What type of system does the company use to recruit new personnel, or how does the company inform future prospects about job openings? (Please select more then one if Applicable)
  • 7.1 Describe what type of surroundings does the company have? (Commercial, Residential, Rural, etc.)
  • 7.2 Please specify measurements of the premises (Building and Building Including Grounds).
  • 7. PHYSICAL SECURITY
  • 7.5 Please specify of what material is the perimeter barrier made of and how high it is?
  • 7.9 Please specify of what material is the building made of?
  • 7.14 How many loading docks does the company have? And how many are used?
  • 7.16 Referring to the previous question please specify where locking mechanisms are (doors, windows, gates, docks, etc.)
  • 7.17 How monitors these locking mechanisms? Select more than one if applicable.
  • 7.24 If the previous answer is Yes, who is your alarm provider and what type of alarm system does the company have?
  • 7.26 If the previous answer is YES, how many cameras does the company have? Internal and External?
  • 7.27 Who monitors the CCTV security system?
  • 7.28 How long does the company store CCTV footage? Where is this information stored? (DVR's videocassette, etc.)
  • 8. SECURITY TRAINING AND THREAT AWARENESS PROGRAMS.
  • 8.2 Please specify what type of information (regarding security) is given in such training sessions.
  • 8.6 How often are employees trained?
  • 8.11 If the previous answer is YES, please specify what type of incentives does the company offer?
  • OBSERVATIONS/RECOMENDATIONS.
  • 9. IT SECURITY
  • 9.3 If the previous answer is NO, who is in charge of the company's IT?
  • 9.5 Do employees assign their own passwords? If NO, who assigns the passwords for each username?
  • 9.6 How often are passwords changed?
  • 9.12 How often are BACKUPS done? (Please select more than one if applicable)
  • 10.1 Who is in charge of ordering the company's Transponders?
  • 10.2 How many Transponders does the company have?
  • 11. EFFECTIVITY TESTS
  • 11.2 Please describe the effectivity test, when it was held, who it was held to, if or not it was successful, etc.
  • Photo Log