Indicator

Risk description

Possible solutions

Reference

Identification of business partners

Lack of mechanism for clear identification of the business partners.

procedure in place for identifying regular business partners and unknown clients/customers;

procedures to select and manage business partners where the transport is carried out by a third party;

implement a procedure to select subcontractors based on a list of regular and irregular subcontractors;

subcontractors can be selected on the basis of selection criteria or even of a company specific certification (which can be set up on the base of a certification questionnaire).

Security requirements imposed on others

Breach of agreed security arrangements with the risk of receiving or delivering unsafe or unsecured goods.

background checks used to select regular business partners e.g. through the use of internet or rating agencies;

security requirements (e.g. that all goods must be marked, sealed, packed, labelled in a certain way, subject to X-ray checks) are written into contracts with regular business partners;

requirement that contracts will not be further sub-contracted to unknown third parties particularly for the transportation of secure air cargo/air mail;

conclusions provided by experts/external auditors, not related to regular business partners, on complying with security requirements;

evidence that business partners hold relevant accreditations/certificates to prove they comply with international security standards;

procedures for carrying out additional security checks on transactions with unknown or irregular business partners;

reporting and investigation of any security incidents involving business partners and recording remedial action taken.

SAQ – 6.10

ISO 28001:2007, section A.3