Guide · C-TPAT 5-Step Risk Assessment

How to Conduct a CTPAT 5-Step Risk Assessment (And Why Most Still Fail)

Short answer: a CTPAT 5-step risk assessment is the documented process CBP requires every Partner to run at least once a year, in five named parts — mapping cargo and data flow and identifying business partners, conducting a threat assessment, conducting a vulnerability assessment, preparing a written action plan, and documenting the procedure itself. What separates it from risk assessment in general is what it is measured against and who reads it: the vulnerability step is scored against the C-TPAT Minimum Security Criteria for your business type, and the finished file is opened by your assigned Supply Chain Security Specialist at a validation. The steps are not hard to understand. Most companies still fail them, because all five get produced as a document instead of run as a process, and by the time the specialist opens the file it describes a chain that moved on without it. This page is about the C-TPAT version, step by step, and then walked end to end on a single supplier; if what you need is how the same five steps work across every program that asks — the scoring, the corrective action plans, the risks themselves — start with the general 5-step methodology guide.

When is anyone supposed to actually do this?

The annual reminder never lands on a quiet week. It lands on the morning Ops needs a second-source supplier cleared today because the line is short on one component. Logistics is telling you the container that matters is sitting at the port behind a customs hold, and they need something from you before it moves. Finance wants to know what the duty exposure looks like before they release the payment. Sales already gave the customer a date. Somewhere underneath all of that is a calendar entry saying the risk assessment is due, and a folder on a shared drive with last year's version in it, written by someone who has since changed roles.

In thirty years I have never seen an assessment fail because a compliance team could not follow five steps. They fail because the five steps get run once, by one person, inside the two weeks before a deadline, and then nothing touches them again for eleven months while the chain underneath keeps moving. Routing changes. A drayage company gets swapped for a cheaper one. A supplier's certification lapses and nobody outside their office knows it. The document is still accurate as of the day it was written, which is the one day nobody is going to ask about.

What is a C-TPAT 5-step risk assessment, and who has to run one?

CBP's own definition is narrower and more useful than the phrase suggests: a risk assessment is analyzing external threats against your company procedures to identify where vulnerabilities exist, and what procedures can be implemented or improved to reduce that risk. Applicants have to be able to show a documented process for how the company assesses risk, and Partners have to conduct one at least annually to stay in the program. CBP is direct about the format too: the assessment must conform to your own business model rather than adopt a generic, externally provided template.

It is also worth knowing that this same body of work sits underneath every other program that asks about your chain. The five steps support the security profile behind C-TPAT, PIP and AEO, and the evidence they produce is the same evidence the executive summary of a Bill S-211 report — Canadian legislation, entirely separate from CBP — has to be built on. That is the argument for running one Master 5-Step Risk Assessment properly rather than four partial ones on four schedules.

One distinction worth making up front, since two different pieces of our own work sit behind this topic. Running the five steps against your suppliers, on verified evidence, is XFACTOR VERIFIED. Holding one supplier record that C-TPAT, PIP and an S-211 filing can all read from, with the renewal dates and the compliance calendar beside it, is XFACTOR COMMANDCENTER— the room that file lives in. If your search today is “how do I run the five steps,” the answer is VERIFIED. If it is “four programs keep asking about the same suppliers,” that is CommandCenter.

What are the five steps, and what does each one have to produce?

The headings below are CBP's own wording. Each step has an output — something that exists at the end of it, that another person can open and read. If a step produces nothing you can hand to someone, it did not happen.

Step 1 — Mapping Cargo/Data Flow and Identifying Business Partners

You identify every party involved in the movement of the goods and what each one actually does, across the processes CBP names: procurement, production, packing, staging and storing, loading and unloading, transportation, and document preparation. Everyone involved directly or indirectly between the point of origin and your distribution centre belongs on that map — factories and farms, suppliers, export packing facilities, buying and selling agents and trading companies, freight forwarders, NVOCCs, inland truck and rail carriers, warehouse and consolidation facilities, feeder vessels, rail depots, container yards, local drayage companies, the international carrier, and your customs broker.

Two things trip this step up. The first is that companies map who invoices them rather than who handles the goods, and in a long-standing trading relationship those are often different parties — a name you have paid every month for years can turn out to be a broker of the goods rather than a maker of them, with the production sites behind it treated as commercially confidential. The second is Incoterms. CBP's position is that Incoterms have little to do with a security assessment: the Partner responsible for bringing the goods across the border is responsible for the security of that shipment no matter where title transfers. A chain that stops at the FOB point is not mapped. The output is a supply chain map and a business partners list, and it is the foundation the other four steps are scored against.

Step 2 — Conducting a Threat Assessment

For each node on that map you assess the threats around it: terrorism, contraband smuggling, human smuggling, agricultural and public safety threats, organized crime, and the conditions in a country or region that foster any of them. The output is a ranked threat picture per node, not a single company-wide score.

The trap here is volume. CBP says it plainly — quantity does not necessarily define risk. An importer running three hundred shipments a year out of a politically stable, low-risk country should not be spending its attention there while ignoring the two shipments a year coming out of a country that just had a violent change of government and carries a high corruption index. The same logic applies inside a single supplier: a manufacturer sending you eighty percent of your volume is not automatically low risk if they pick their ground carrier on price and change trucking companies from shipment to shipment. A manufacturer who uses the same AEO-certified trucker every time is a genuinely different risk from one who does not, and a threat assessment that only counts containers cannot see the difference.

Step 3 — Conducting a Vulnerability Assessment

This one turns and looks at you, against the C-TPAT Minimum Security Criteria. CBP frames it as two questions. First, what does your company hold that a terrorist or criminal would want — for a broker that is data; for an importer, manufacturer or exporter it is access to cargo and to company information. Second, which weaknesses in your procedures would let someone reach it.

The criteria you are assessed against depend on what your company actually is. The Minimum Security Criteria differ by business type — importer, highway carrier, sea, rail or air carrier, foreign manufacturer, consolidator, licensed broker, third-party logistics provider — and a company that holds more than one of those roles answers to more than one set. Assessing yourself against the importer booklet alone, when you also run your own cross-border fleet, produces a clean report on half your exposure. The output is a gap analysis against the criteria that actually apply to you.

CBP also expects this step to cover what happens when the ordinary day stops: power outages, hurricanes and other weather events, earthquakes, civil unrest, terrorist events. Documented business resumption procedures, periodically tested, belong inside the vulnerability picture rather than in a separate binder nobody opens.

Step 4 — Preparing an Action Plan

Every vulnerability found in step three gets a written plan, and CBP names the parts: a mechanism that records the identified weaknesses, the person responsible for addressing each one, a due date, and a way of reporting completed follow-up and changes back to company officials and employees. The output is a corrective action plan with owners and deadlines on it.

This is the step most often filled in with intentions. A gap that reads “supplier security requirements to be added to contracts” with no name and no date beside it tells a specialist the weakness was found and then left where it was. Nobody assessing you is expecting a chain with nothing wrong in it; they are reading whether the things that are wrong are being carried by someone. A plan being worked and a plan written to be shown look different on the page, and the difference is almost entirely dates.

Step 5 — Documenting the Risk Assessment Process

The last step is the one people assume is clerical, and it is the one that carries the other four. You document the procedure for how the risk assessment is conducted — who runs it, on what inputs, on what cycle, against what criteria — and you review and update that procedure at least annually. The assessment itself is conducted and documented at least annually as well, and more frequently for highway carriers and high-risk chains.

The reason this step exists is that CBP is assessing your process, not your paperwork. A company that can show how it decides what to look at, and can show the decision being made the same way twice, is in a different conversation from one that produced a report. The output is the complete documented assessment — in our work, the signed Master 5-Step Risk Assessment that aggregates every individual supplier into one document, ready before anyone asks for it.

What do the five steps look like run on one supplier?

Described in the abstract the process sounds tidier than it is, so here is one supplier carried through all five. Call the supplier Northwind — a composite built to illustrate the mechanics, not a client of ours and not a real company. They are a foreign manufacturer producing a metal component, they have invoiced the importer every month for six years, and on the existing chain map they occupy one box.

Step one, mapping.The work is done by walking the process with Northwind's plant manager, node by node, from the raw material arriving to the container leaving. It turns up a subcontracted plating shop forty kilometres away that performs a finishing operation, holds the parts overnight, and appears on no document the importer has ever seen, because Northwind buys that service and bills it inside their own price. Behind that sit an export packer, a domestic trucker to the port, a consolidator, the ocean carrier and the broker. What exists at the end of the step is a chain map with eight parties on it instead of one, each recorded with what it does, how much of the annual volume passes through it, and how directly it can reach the cargo — plus a business partners list entry for the plating shop that did not exist that morning.

Step two, threats.Each of those eight nodes gets assessed on its own conditions rather than on Northwind's volume. The plant sits in a stable district with a long security record. The overnight hold at the plating shop and the road leg to the port carry the contraband and organized-crime exposure, because that is where the goods are out of anyone's sight and where a driver changes. The trucking is booked per load on price, so the carrier is different most weeks. What exists at the end is a ranked threat note per node, and the ranking does not put Northwind's plant at the top.

Step three, vulnerabilities. Now the same eight nodes get scored against the Minimum Security Criteria that apply, which for Northwind are the foreign manufacturer criteria. Three gaps surface: the plating shop has never been screened by anyone, has never been asked a security question and has access to the goods overnight; seal control is documented at the plant but stops at the plant gate, so nothing covers the leg where the parts travel to be plated and back; and the security expectations the importer believes are in place with Northwind appear in an email from 2021 and in no contract. What exists at the end is a gap list written against named criteria, which is what makes it answerable rather than a list of worries.

Step four, the action plan.Each of those three gaps takes an owner and a date. Northwind's operations manager extends the seal procedure to cover the plating leg and sends the revised written procedure by a fixed date. The importer's compliance lead sends the plating shop a security questionnaire and verifies two of its answers in person rather than accepting the form. Procurement adds the security requirements to the contract at the renewal that is already scheduled, so the fix rides on a conversation that was going to happen anyway. What exists at the end is a corrective action plan with three named people, three dates, and a line saying who gets told when each one closes.

Step five, documenting.The record captures how the assessment was conducted — who ran it, what they walked, which criteria set was used, what was found and what was decided — and it sets Northwind's next review at twelve months, with a trigger to reassess sooner if the routing or the subcontractors change. That dated record is a supplier-level input to the signed Master 5-Step Risk Assessment across the whole chain.

When a specialist later pulls Northwind's file, the plating shop is the part that matters. It is named, it was found by the importer rather than by the validator, it carries a gap with an owner and a closing date, and the map explains why it belongs there. A better questionnaire would never have surfaced it, because nobody at the importer would have known to ask Northwind about a company whose name they had never seen.

Why do most C-TPAT risk assessments still fail?

The reason is rarely the one people expect. In most files I have reviewed all five steps are physically present, and what has gone missing by the time someone else reads them is whether any of them were still true.

The map was accurate until Logistics moved to a cheaper drayage company in March and nobody told Compliance, because there was no reason anybody would think to. The supplier questionnaire was accepted during a shortage, when the honest choice was between a form answered in generalities and a production line standing still, and it has been holding up that supplier's section of the profile ever since. The certificates were real when they were collected, and a few have since lapsed the way certificates always lapse, which is silently, on a date that passed while the team was busy with something louder. The action plan has six items on it and five of the due dates are behind you. And underneath all of it, quite often, is a template someone bought or downloaded, which is exactly what CBP warns against: a generic, cookie-cutter, externally inflicted procedure that produces a false sense of security and, eventually, a breach.

There is also a standard question buried in the headline, which is what “passing” should mean. Most consultants get a client certified and stop at the line the program will accept. I was never someone who gave the bare minimum to my clients. I take them to the higher tier, because it is a stronger foundation and it carries materially more benefit than the minimum does — and the assessment underneath it has to be real to hold that weight. A 100% success rate on C-TPAT, PIP and AEO — at Tier II, not the minimum. The five steps are where that gets earned, one supplier at a time, in the eleven months when nobody is asking.

What happens when the specialist opens the file?

I've sat in validation meetings where the Supply Chain Security Specialist opens the file… the conversation changes immediately.

It is a quiet moment and everyone in the room can read it. They are not asking about security philosophy. They pick two or three suppliers off your own list and follow them through your own map: who packs this, who moves it inland, who consolidates it, who prepared the documents. Then they ask when each of those parties was last assessed, and on what evidence. When one of those answers is a company name nobody in the room recognises, your own map has just testified against your profile, and every answer after that gets weighed differently.

The cost usually arrives as a finding, an action plan running on their clock rather than yours, and a piece of the next quarter spent reassembling evidence for a chain you believed was already documented — while Ops carries on needing suppliers cleared at the same rate as before. Then the room looks at whoever signed the security profile and waits for an explanation of a gap that was created three departments away, by people doing their own jobs correctly, with what they had in front of them. I have sat with more than one compliance manager through that hour. What ends it early, every time I have seen it end early, is a record with dates on it: what was checked, by whom, when, and what happened to the gaps that turned up.

What fits inside the quarter you are already having

What this asks for is a change in timing more than a change in budget. If the evidence builds up across the year, the assessment month becomes a month of writing rather than a month of excavation. Concretely: the map gets updated at the moment a new partner is added, which is the only moment anyone actually knows the details; whatever was done to verify a supplier is stored against that supplier's record, so the next person can see it without asking you; a supplier who declines to provide something is recorded as having declined, with what you did next; expiry and re-assessment dates belong to a named owner who is not also the person clearing Ops's urgent supplier this morning; and the threat picture gets a second look whenever routing or a carrier changes, rather than waiting for the anniversary.

That is the work XFACTOR VERIFIEDdoes per supplier — the cargo and data flow mapping, the threat and vulnerability scoring against the criteria that apply to that supplier's business type, the documented action plan with owners and dates, and the assessment record that stays current — rolling up into the signed Master 5-Step Risk Assessment across your whole chain. If you want to see the shape of it first, the general 5-step methodology guide covers how scoring and corrective action plans work across any program, and what C-TPAT compliance software should actually do covers what to require of a tool before you sign for one.

One practical place to start, if the annual reminder is currently what triggers all of this in your company: take step one off that reminder entirely and attach it to supplier onboarding instead, this quarter. Threats, vulnerabilities, the action plan and the documentation are all scored against whatever the map says, so a map that is maintained in real time quietly raises the ceiling on the other four.

Free guide

Free guide: How to Evaluate Supplier Risk

The evidence discipline this article describes, in plain English — what to verify before a supplier is approved, and what the file has to hold when a specialist opens it. We'll email you the link.

We’ll email it to you. No spam, no list-selling. Unsubscribe anytime.


The program this maps to: C-TPAT · The departments this maps to: Operations · Procurement · Related reading: The 5-step methodology across every program · The C-TPAT Minimum Security Criteria · What C-TPAT compliance software should do · C-TPAT vs PIP vs AEO · What Procurement owns in a C-TPAT program · Supplier due diligence