Your Certification Is Only as Strong
as Your Weakest Partner.
For every foreign supplier and logistics partner that isn't CTPAT or MRA certified, CBP expects documented proof that you've assessed their security. We run the entire program for you — questionnaires, expert review, corrective action plans, and a defensible audit trail — so your certification holds up when CBP shows up.
Audit My Business PartnersA Complete, Managed Compliance Program — Built to Satisfy CBP
Everything on this list is handled by us — so none of it lands on your team.
Full CTPAT MSC coverage
Every category assessed — not a partial questionnaire. Compliant with the current MSC, not the pre-2019 version most companies still use.
Plain-language questions for global suppliers
Designed for non-native English speakers — higher accuracy, less back-and-forth, faster completion.
Document uploads validated
Suppliers upload evidence — written policies, procedures, completed logs, and training materials. Our experts verify every submission.
AI-powered evidence analysis
Every uploaded document is AI-translated into English, checked against the CTPAT MSC, and tested for authenticity before an expert reviews it.
CTPAT SME reviews every submission
Human expert review — not automated software. Every submission assessed by a certified CTPAT Subject Matter Expert.
Corrective Action Plan per supplier
Gaps identified, remediation materials provided. Not just a pass/fail result — a complete CAP with the policies, forms, and training materials the supplier needs.
Defensible audit trail for CBP
Documentary evidence of due diligence, ready for any validation, SCSS review, or security incident.
We manage execution
We handle outreach, follow-up, review, and reporting. Minimal effort required from your team.
Most providers give you a tool. We give you an outcome.
Get StartedFrom Deployment to Resolution in Five Steps
One managed process. Zero administrative load on your team.
One email sent to the main contact at each foreign business partner — with secure links to the relevant sections to forward internally.
Each department answers its adaptive section and uploads required policies, procedures, and completed forms through a secure link.
Our Subject Matter Experts review all submitted responses and uploaded documentation against the full CTPAT MSC.
Gaps are identified and assessed for severity. Each supplier's overall compliance level is evaluated and risk-ranked.
A Corrective Action Plan is issued to the business partner — with all required policies, forms, and training materials they need to comply.
A Common Misunderstanding That Creates Real Risk
"We only need to assess business partners if we are the Importer of Record."
This is one of the most common misunderstandings among CTPAT members — and one of the most consequential.
When a U.S. company sources goods through a third party who acts as the Importer of Record, that transaction may still be an indirect import under CTPAT. The U.S. company retains full responsibility for supply chain security.
CBP defines an indirect import as one where the CTPAT member caused the importation through purchase orders, product specifications, or branded labeling that could only be sold to that member. Who files the entry is irrelevant.
The security obligation follows the purchase relationship — not who is named on the entry.
"Having caused the importation to take place, the ultimate consignee is responsible for ensuring the cargo is secure based on CTPAT's requirements."
— CBP 5-Step Risk Assessment Guide (Attachment A, Indirect Imports)What Most CTPAT Members Get Wrong
CBP validates members every 3–4 years. Most program deficiencies go unnoticed between cycles. Companies assume silence means compliance. It doesn't. When CBP does look, a deficient business partner screening program is one of the fastest paths to a written CAP or suspension.
Outdated questionnaire
Most companies still use a questionnaire built for the pre-2019 MSC — which no longer reflects current requirements.
Questionnaire too short
It's nearly impossible to remotely assess a foreign supplier's compliance with the full MSC using a form under five pages. The scope of the current MSC simply doesn't fit.
No documentary evidence required
Suppliers aren't asked to provide written policies, procedures, training materials, or completed logs — all of which CBP expects to see.
No one reviews the responses
Questionnaires get sent out and filed away. No expert review, no gap analysis, no accountability.
No feedback or corrective action plan
After the questionnaire is returned, suppliers hear nothing. No gaps identified, no remediation required — leaving real vulnerabilities in place.
Only a fraction of suppliers re-assessed
Every few years, most members re-assess a small percentage of foreign suppliers rather than their full population.
Why CBP Rarely Catches It
CBP validates CTPAT members every 3–4 years. Most program deficiencies — including weak or non-compliant programs — go unnoticed between cycles. Companies assume silence means compliance. It doesn't. A deficient business partner screening program is one of the fastest paths to a written CAP or suspension from the program.
MSC 3.5 is a "Must" requirement — and CBP expects a complete, documented process.
Get a Compliant BPRA ProgramCompliance Isn't Defined by What Has Been Accepted So Far.
It's defined by what you can demonstrate when it matters.
Validation Every 3–4 Years
CBP formally reviews your entire CTPAT program — including how you've managed business partner compliance. This is the most visible trigger, but not the only one.
A Change to Your SCSS
When CBP assigns a new Supply Chain Security Specialist to your account, a fresh set of eyes often reviews your program more closely than your previous SCSS ever did.
A Supply Chain Security Breach
Any incident involving your supply chain puts your certification under immediate scrutiny — regardless of where you are in the validation cycle.
Scrutiny can happen at any time. Your documentation needs to be ready before it does.
Powered by Conditional Logic
No two assessments are identical. The system dynamically adapts to each partner's responses — irrelevant sections are automatically bypassed.
- Physical security questions
- Cargo inspection procedures
- Facility access controls
Irrelevant sections automatically bypassed
Eliminates irrelevant data entry
Business partners only answer what applies to them — nothing more.
Designed for global companies
Plain language and clear instructions for non-native English speakers — higher accuracy, less back-and-forth.
Faster completion, better responses
Adaptive logic drives faster completion rates, higher quality responses, and fewer misunderstandings.
Every supplier sees only the questions relevant to them — and nothing else.
AI-Powered Evidence Analysis
Every document uploaded by a supplier is analyzed by AI before one of our experts reviews it.
Translates
AI translates all uploaded documents into English so our experts can analyze evidence from suppliers in any language — regardless of country of origin.
Verifies Compliance
AI checks each translated document against the CTPAT Minimum Security Criteria — flagging exactly where evidence falls short of the applicable requirements.
Authenticates
AI verifies that documents genuinely belong to the supplier — and flags evidence that appears to have been copied or purchased from other companies.
What AI Authentication Catches
A growing number of foreign suppliers are uploading the same images, policies, procedures, and completed logs as other unrelated companies — apparently downloaded or purchased from online marketplaces. Our system has identified identical visitor logs with the same dates and visitor names submitted by completely different suppliers. AI detects these duplicates automatically, so fabricated evidence never passes as genuine compliance.
Real evidence, not borrowed paperwork. AI ensures your suppliers are validated on documentation that is genuinely their own.
Turning Vulnerabilities into Actionable Roadmaps
"Weaknesses identified during business partner security assessments must be addressed as soon as possible. Members must confirm that deficiencies have been mitigated via documentary evidence."
CBP requires documentary evidence of every deficiency identified. We provide business partners with the necessary policies, procedures, forms, logs, checklists, and training materials — so your file is audit-ready without requiring any effort from your team.
Key Features of the Corrective Action Plan
Identifies exact security and documentation gaps
Outlines specific procedures required to meet MSC expectations
Provides all required policies, forms, and training materials
Sets clear action deadlines and responsibilities
Issued to the business partner — serving as documentary evidence per MSC 3.6
Missing visitor log procedure, incomplete seal policy
Implement access control log — address immediately (MSC 3.6)
MSC-compliant seal log, visitor registry
Re-upload completed forms — confirms deficiency mitigated
Why We're Different —
And Why the Investment Reflects That
Most providers give you a tool. We give you an outcome.
Global-Friendly, Plain-Language Assessments
We rewrote the CTPAT MSC into clear, simple questions designed for non-native English speakers — reducing errors, rework, and back-and-forth from suppliers worldwide.
We Remove the Guesswork — Completely
Suppliers receive every required policy, procedure, form, checklist, log, and training material. A complete compliance kit, ready to implement immediately.
Expert Human Review — Not Automated Software
Every submission is reviewed by one of our CTPAT Subject Matter Experts. Gaps identified, severity assessed, CAPs issued. A defensible, CBP-ready audit trail — produced for you.
The Right Investment — For a Reason
Other solutions collect answers. We verify, remediate, and document. The result is a program CBP can scrutinize at any time and find complete. That's what the investment buys.
Validated Readiness. Lower Operational Risk.
Three outcomes your company gains by implementing the BPRA:
Demonstrated Compliance
Show CBP that your organization is properly vetting and monitoring non-CTPAT / non-MRA partners.
Builds a documented, defensible record of due diligence that strengthens your certification posture.
Reduced Internal Burden
Effectively outsource your external compliance team without the overhead.
Replaces costly manual questionnaire management, internal review, and back-and-forth with a centralized, expert-backed solution.
Informed Sourcing
Make data-driven, risk-based decisions on future supplier partnerships.
Every supplier is risk-ranked based on MSC compliance level, giving your company a clear picture of where the vulnerabilities are.
CTPAT Business Partner Audit FAQs
A CTPAT Business Partner Risk Assessment (BPRA) is an assessment of a supplier or service provider's supply chain security practices to confirm whether they meet the applicable CTPAT Minimum Security Criteria (MSC) and to identify gaps that could introduce risk into your supply chain.
CTPAT requires members to determine and assess the risk business partners bring into the supply chain and to document screening and monitoring practices. This is part of maintaining compliance with the MSC and supporting annual risk assessment requirements.
Business partner assessments are most important for non-CTPAT and non-Mutual Recognition Agreement (MRA) partners — including foreign suppliers, vendors, manufacturers, and logistics service providers that handle your cargo or support your international supply chain. If your company caused an importation through purchase orders, product specifications, or branded labeling, that obligation applies regardless of who filed the entry.
Most CTPAT members assess business partners prior to doing business with them, annually for high-risk business partners, and every two years for medium-risk business partners.
We evaluate whether your business partner's security program and evidence meet the applicable MSC requirements, identify security and documentation gaps, and provide clear corrective actions so the partner can align with CTPAT expectations.
If gaps are identified, we outline what must be corrected and help the partner understand what evidence and procedures are required to meet MSC expectations. A formal Corrective Action Plan is issued — which itself serves as documentary evidence per MSC 3.6.
Yes. We provide partners with MSC-compliant policies, procedures, forms, logs, and training materials so they can implement the required controls instead of guessing or interpreting requirements incorrectly.
A questionnaire is one tool for screening, but it isn't sufficient on its own — particularly if it doesn't cover the current MSC or require documentary evidence. A business partner assessment evaluates compliance more thoroughly by reviewing procedures, evidence, and implementation to verify whether MSC requirements are actually being met.
Yes. Demonstrating documented screening, monitoring, and corrective action for business partners supports MSC compliance and strengthens validation readiness by showing CBP you are actively managing supply chain risk beyond your own facilities.
CBP provides the Status Verification Interface (SVI), a portal where CTPAT-certified members can confirm the certification status of other certified partners. Using the SVI is one of the fastest ways to validate a supplier's CTPAT participation — though it only covers CTPAT-certified companies, which is why document-based and on-site assessments remain essential for non-certified suppliers.
Ready to Get Started?
Complete the form below and an advisor will contact you.
"*" indicates required fields