Indicator |
Risk description |
Possible solutions |
Reference |
Identification of business partners |
Lack of mechanism for clear identification of the business partners. |
procedure in place for identifying regular business partners and unknown clients/customers; procedures to select and manage business partners where the transport is carried out by a third party; implement a procedure to select subcontractors based on a list of regular and irregular subcontractors; subcontractors can be selected on the basis of selection criteria or even of a company specific certification (which can be set up on the base of a certification questionnaire). |
|
Security requirements imposed on others |
Breach of agreed security arrangements with the risk of receiving or delivering unsafe or unsecured goods. |
background checks used to select regular business partners e.g. through the use of internet or rating agencies; security requirements (e.g. that all goods must be marked, sealed, packed, labelled in a certain way, subject to X-ray checks) are written into contracts with regular business partners; requirement that contracts will not be further sub-contracted to unknown third parties particularly for the transportation of secure air cargo/air mail; conclusions provided by experts/external auditors, not related to regular business partners, on complying with security requirements; evidence that business partners hold relevant accreditations/certificates to prove they comply with international security standards; procedures for carrying out additional security checks on transactions with unknown or irregular business partners; reporting and investigation of any security incidents involving business partners and recording remedial action taken. |
SAQ – 6.10 ISO 28001:2007, section A.3 |