Secure Trade Advisors

CTPAT MSC 3.5 — Business Partner Risk Assessments

Your Certification Is Only as Strong
as Your Weakest Partner.

For every foreign supplier and logistics partner that isn't CTPAT or MRA certified, CBP expects documented proof that you've assessed their security. We run the entire program for you — questionnaires, expert review, corrective action plans, and a defensible audit trail — so your certification holds up when CBP shows up.

Audit My Business Partners

A Complete, Managed Compliance Program — Built to Satisfy CBP

Everything on this list is handled by us — so none of it lands on your team.

Full CTPAT MSC coverage

Every category assessed — not a partial questionnaire. Compliant with the current MSC, not the pre-2019 version most companies still use.

Plain-language questions for global suppliers

Designed for non-native English speakers — higher accuracy, less back-and-forth, faster completion.

Document uploads validated

Suppliers upload evidence — written policies, procedures, completed logs, and training materials. Our experts verify every submission.

AI-powered evidence analysis

Every uploaded document is AI-translated into English, checked against the CTPAT MSC, and tested for authenticity before an expert reviews it.

CTPAT SME reviews every submission

Human expert review — not automated software. Every submission assessed by a certified CTPAT Subject Matter Expert.

Corrective Action Plan per supplier

Gaps identified, remediation materials provided. Not just a pass/fail result — a complete CAP with the policies, forms, and training materials the supplier needs.

Defensible audit trail for CBP

Documentary evidence of due diligence, ready for any validation, SCSS review, or security incident.

We manage execution

We handle outreach, follow-up, review, and reporting. Minimal effort required from your team.

From Deployment to Resolution in Five Steps

One managed process. Zero administrative load on your team.

1
Deploy

One email sent to the main contact at each foreign business partner — with secure links to the relevant sections to forward internally.

2
Complete

Each department answers its adaptive section and uploads required policies, procedures, and completed forms through a secure link.

3
Assess

Our Subject Matter Experts review all submitted responses and uploaded documentation against the full CTPAT MSC.

4
Verify

Gaps are identified and assessed for severity. Each supplier's overall compliance level is evaluated and risk-ranked.

5
CAP

A Corrective Action Plan is issued to the business partner — with all required policies, forms, and training materials they need to comply.

A Common Misunderstanding That Creates Real Risk

The Misconception
"We only need to assess business partners if we are the Importer of Record."

This is one of the most common misunderstandings among CTPAT members — and one of the most consequential.

The Reality

When a U.S. company sources goods through a third party who acts as the Importer of Record, that transaction may still be an indirect import under CTPAT. The U.S. company retains full responsibility for supply chain security.

CBP defines an indirect import as one where the CTPAT member caused the importation through purchase orders, product specifications, or branded labeling that could only be sold to that member. Who files the entry is irrelevant.

The security obligation follows the purchase relationship — not who is named on the entry.

"Having caused the importation to take place, the ultimate consignee is responsible for ensuring the cargo is secure based on CTPAT's requirements."

— CBP 5-Step Risk Assessment Guide (Attachment A, Indirect Imports)

What Most CTPAT Members Get Wrong

CBP validates members every 3–4 years. Most program deficiencies go unnoticed between cycles. Companies assume silence means compliance. It doesn't. When CBP does look, a deficient business partner screening program is one of the fastest paths to a written CAP or suspension.

1

Outdated questionnaire

Most companies still use a questionnaire built for the pre-2019 MSC — which no longer reflects current requirements.

2

Questionnaire too short

It's nearly impossible to remotely assess a foreign supplier's compliance with the full MSC using a form under five pages. The scope of the current MSC simply doesn't fit.

3

No documentary evidence required

Suppliers aren't asked to provide written policies, procedures, training materials, or completed logs — all of which CBP expects to see.

4

No one reviews the responses

Questionnaires get sent out and filed away. No expert review, no gap analysis, no accountability.

5

No feedback or corrective action plan

After the questionnaire is returned, suppliers hear nothing. No gaps identified, no remediation required — leaving real vulnerabilities in place.

6

Only a fraction of suppliers re-assessed

Every few years, most members re-assess a small percentage of foreign suppliers rather than their full population.

Why CBP Rarely Catches It

CBP validates CTPAT members every 3–4 years. Most program deficiencies — including weak or non-compliant programs — go unnoticed between cycles. Companies assume silence means compliance. It doesn't. A deficient business partner screening program is one of the fastest paths to a written CAP or suspension from the program.

MSC 3.5 is a "Must" requirement — and CBP expects a complete, documented process.

Get a Compliant BPRA Program

Compliance Isn't Defined by What Has Been Accepted So Far.

It's defined by what you can demonstrate when it matters.

Validation Every 3–4 Years

CBP formally reviews your entire CTPAT program — including how you've managed business partner compliance. This is the most visible trigger, but not the only one.

A Change to Your SCSS

When CBP assigns a new Supply Chain Security Specialist to your account, a fresh set of eyes often reviews your program more closely than your previous SCSS ever did.

A Supply Chain Security Breach

Any incident involving your supply chain puts your certification under immediate scrutiny — regardless of where you are in the validation cycle.

Scrutiny can happen at any time. Your documentation needs to be ready before it does.

Powered by Conditional Logic

No two assessments are identical. The system dynamically adapts to each partner's responses — irrelevant sections are automatically bypassed.

Does your facility handle physical cargo?
YES
  • Physical security questions
  • Cargo inspection procedures
  • Facility access controls
NO

Irrelevant sections automatically bypassed

Eliminates irrelevant data entry

Business partners only answer what applies to them — nothing more.

Designed for global companies

Plain language and clear instructions for non-native English speakers — higher accuracy, less back-and-forth.

Faster completion, better responses

Adaptive logic drives faster completion rates, higher quality responses, and fewer misunderstandings.

AI-Powered Evidence Analysis

Every document uploaded by a supplier is analyzed by AI before one of our experts reviews it.

Translates

AI translates all uploaded documents into English so our experts can analyze evidence from suppliers in any language — regardless of country of origin.

Verifies Compliance

AI checks each translated document against the CTPAT Minimum Security Criteria — flagging exactly where evidence falls short of the applicable requirements.

Authenticates

AI verifies that documents genuinely belong to the supplier — and flags evidence that appears to have been copied or purchased from other companies.

What AI Authentication Catches

A growing number of foreign suppliers are uploading the same images, policies, procedures, and completed logs as other unrelated companies — apparently downloaded or purchased from online marketplaces. Our system has identified identical visitor logs with the same dates and visitor names submitted by completely different suppliers. AI detects these duplicates automatically, so fabricated evidence never passes as genuine compliance.

Turning Vulnerabilities into Actionable Roadmaps

MSC 3.6 — Must Requirement

"Weaknesses identified during business partner security assessments must be addressed as soon as possible. Members must confirm that deficiencies have been mitigated via documentary evidence."

CBP requires documentary evidence of every deficiency identified. We provide business partners with the necessary policies, procedures, forms, logs, checklists, and training materials — so your file is audit-ready without requiring any effort from your team.

Key Features of the Corrective Action Plan

Identifies exact security and documentation gaps

Outlines specific procedures required to meet MSC expectations

Provides all required policies, forms, and training materials

Sets clear action deadlines and responsibilities

Issued to the business partner — serving as documentary evidence per MSC 3.6

Sample CAP Structure
Documentation Gaps

Missing visitor log procedure, incomplete seal policy

Action Items

Implement access control log — address immediately (MSC 3.6)

Required Templates

MSC-compliant seal log, visitor registry

Documentary Evidence

Re-upload completed forms — confirms deficiency mitigated

Why We're Different —
And Why the Investment Reflects That

Most providers give you a tool. We give you an outcome.

Global-Friendly, Plain-Language Assessments

We rewrote the CTPAT MSC into clear, simple questions designed for non-native English speakers — reducing errors, rework, and back-and-forth from suppliers worldwide.

We Remove the Guesswork — Completely

Suppliers receive every required policy, procedure, form, checklist, log, and training material. A complete compliance kit, ready to implement immediately.

Expert Human Review — Not Automated Software

Every submission is reviewed by one of our CTPAT Subject Matter Experts. Gaps identified, severity assessed, CAPs issued. A defensible, CBP-ready audit trail — produced for you.

The Right Investment — For a Reason

Other solutions collect answers. We verify, remediate, and document. The result is a program CBP can scrutinize at any time and find complete. That's what the investment buys.

Validated Readiness. Lower Operational Risk.

Three outcomes your company gains by implementing the BPRA:

Demonstrated Compliance

Show CBP that your organization is properly vetting and monitoring non-CTPAT / non-MRA partners.

Builds a documented, defensible record of due diligence that strengthens your certification posture.

Reduced Internal Burden

Effectively outsource your external compliance team without the overhead.

Replaces costly manual questionnaire management, internal review, and back-and-forth with a centralized, expert-backed solution.

Informed Sourcing

Make data-driven, risk-based decisions on future supplier partnerships.

Every supplier is risk-ranked based on MSC compliance level, giving your company a clear picture of where the vulnerabilities are.

CTPAT Business Partner Audit FAQs

What is a CTPAT Business Partner Risk Assessment?

A CTPAT Business Partner Risk Assessment (BPRA) is an assessment of a supplier or service provider's supply chain security practices to confirm whether they meet the applicable CTPAT Minimum Security Criteria (MSC) and to identify gaps that could introduce risk into your supply chain.

Why does CTPAT require business partner screening and monitoring?

CTPAT requires members to determine and assess the risk business partners bring into the supply chain and to document screening and monitoring practices. This is part of maintaining compliance with the MSC and supporting annual risk assessment requirements.

Which business partners should be assessed?

Business partner assessments are most important for non-CTPAT and non-Mutual Recognition Agreement (MRA) partners — including foreign suppliers, vendors, manufacturers, and logistics service providers that handle your cargo or support your international supply chain. If your company caused an importation through purchase orders, product specifications, or branded labeling, that obligation applies regardless of who filed the entry.

How often should business partners be assessed?

Most CTPAT members assess business partners prior to doing business with them, annually for high-risk business partners, and every two years for medium-risk business partners.

What does Secure Trade Advisors evaluate during an assessment?

We evaluate whether your business partner's security program and evidence meet the applicable MSC requirements, identify security and documentation gaps, and provide clear corrective actions so the partner can align with CTPAT expectations.

What happens if a business partner is not compliant?

If gaps are identified, we outline what must be corrected and help the partner understand what evidence and procedures are required to meet MSC expectations. A formal Corrective Action Plan is issued — which itself serves as documentary evidence per MSC 3.6.

Do you provide business partners with templates and documents?

Yes. We provide partners with MSC-compliant policies, procedures, forms, logs, and training materials so they can implement the required controls instead of guessing or interpreting requirements incorrectly.

Is a business partner assessment the same as a security questionnaire?

A questionnaire is one tool for screening, but it isn't sufficient on its own — particularly if it doesn't cover the current MSC or require documentary evidence. A business partner assessment evaluates compliance more thoroughly by reviewing procedures, evidence, and implementation to verify whether MSC requirements are actually being met.

Does this help with our CTPAT validation readiness?

Yes. Demonstrating documented screening, monitoring, and corrective action for business partners supports MSC compliance and strengthens validation readiness by showing CBP you are actively managing supply chain risk beyond your own facilities.

How can we verify if a business partner is CTPAT-certified?

CBP provides the Status Verification Interface (SVI), a portal where CTPAT-certified members can confirm the certification status of other certified partners. Using the SVI is one of the fastest ways to validate a supplier's CTPAT participation — though it only covers CTPAT-certified companies, which is why document-based and on-site assessments remain essential for non-certified suppliers.

Ready to Get Started?

Complete the form below and an advisor will contact you.

"*" indicates required fields

Name*