Guide · Department Responsibilities
What Does Executive Leadership Own in a C-TPAT or PIP Program?
Short answer: C-TPAT's own criteria put four things directly on upper management — a signed statement of support, a cross-functional security team, a written review component, and a point of contact who can speak to the program without a script. PIPasks for the same weight under a different label: a documented Security Policy Manual and proof the company keeps re-checking its own Security Profile. None of the four can be handed down to a department and still count as done — CBP and CBSA both wrote them as leadership's own line. The rest of this is what a validator actually checks, and what happens the morning nobody in the room can answer for it.
The signature has to survive the rest of the calendar
A GM's morning doesn't leave room for a security program. There's a board update due by noon, a customer on the phone about a shipment that's three days late, someone from HR waiting outside the office about a personnel matter, and a stack of approvals that need a signature before anyone can move. Somewhere inside that same hour, the compliance file needs an executive to sign a statement, sit through a review, or answer for a point of contact's last update — and it is very easy to treat that stack the same way as everything else that needs a signature: sign it, move on, forget it happened.
Thirty years of sitting on both sides of that same audit taught me something specific about the executives who pass a validation without a scramble: they were never the ones who signed fastest. They were the ones who could tell a validator, off the top of their head, when the last review actually happened and exactly what it changed.
The signature, the team, and the review CBP calls a requirement
C-TPAT's Section 1 puts three separate things on upper management, and only the first one is a signature. Is commitment to supply chain security demonstrated through a statement of support, signed by a senior company official and displayed somewhere in the company — not filed in a binder no one opens? Have representatives from every relevant department been built into a real cross-functional team, with the new security measures folded into procedures the company already runs, so the program reads as everyone's job rather than one department's paperwork? And is the whole thing backed by a written review component — one that documents personnel being held accountable for their piece of it, and confirms the security procedures are actually carried out the way they were designed? CBP's own wording calls that review component a requirement twice in the same criterion, and says the review plan itself has to update when the business or its risk changes — wording chosen precisely because a review that only exists on paper next to the program proves nothing about whether the program itself is real.
The point of contact carries the same weight in a smaller package: regular updates on the outcomes of any audit, exercise, or validation, and enough real knowledge of the program's requirements to answer for it without reading from a card. A named POC who cannot speak to the program is, in CBP's eyes, close to no POC at all.
PIPdoesn't use the phrase "statement of support," but the same expectation runs underneath it: a documented Security Policy Manual with real guidelines for securing cargo, corporate security policies that establish threat awareness across the supply chain, and a Security Awareness element with its own paper trail — records of who attended a security meeting, not just that one was scheduled. Its Determining Risks criterion asks the same question C-TPAT's Section 2 asks under a different name: can the company identify, analyze, and mitigate its supply chain risks, including a high-risk load before it moves. Both feed the same leadership sign-off on regular re-assessment of the company's own Security Profile. A dock crew running freight north into Canada is being held to the identical governance question — does the paper exist, is it current, and does the company actually follow it.
The part leadership owns but doesn't do the work of
Two more pieces sit under the same section of the program, and both get delegated in practice while staying leadership's to answer for. First, the risk assessment itself: has the amount of risk in the supply chain been documented, has the assessment mapped where cargo moves from origin to distribution — including every business partner touching it directly or indirectly, and where the cargo sits "at rest" long enough to become a target — and is that assessment reviewed at least annually, or sooner if the risk picture changes? Written procedures for crisis management, business continuity, and business resumption sit in the same requirement, because a risk assessment that never plans for the bad day isn't really an assessment. Second, the written policy for screening new business partners and monitoring current ones, including checks against money-laundering and terrorist-financing indicators — the policy leadership signs off on, that Procurement and the departments closer to the supplier relationship actually run day to day.
One more line belongs to leadership alone: a mechanism to report security issues anonymously, and a real commitment that when an allegation comes in, it gets investigated and, where it holds up, acted on. There is no department to delegate that one to — it only works if people trust it goes to someone who will use it.
What a validator actually asks the person in the room
None of this gets checked by reading the policy binder cover to cover. It gets checked by putting a question directly to whoever is sitting across the table:
“Who signed the statement of support, and when was it last updated?”
“Who's on the cross-functional security team, and how often does it actually meet?”
“When did the review component last run, and what did it change?”
“Walk me through the risk assessment — where does the cargo sit at rest, and who reviewed that this year?”
“If someone wanted to report a concern without giving their name, how would they do it?”
“Can the point of contact answer these questions without pulling up a document first?”
Every one of those is answerable two ways: with a specific name, a specific date, and a specific change — or with a pause, and then a promise to follow up. The second answer doesn't just cost one line item. Because the review component's whole purpose is proving the program is real, a vague answer on it puts the credibility of everything else the company just walked the validator through back on the table, in the same meeting.
Depth over the minimum was never optional for me
I have a 100% success rate on C-TPAT, PIP and AEO — at Tier II, not the minimum. I was never someone who gave the bare minimum to my clients. The companies that treat the statement of support as a formality and the review component as an annual calendar reminder are the ones scrambling the week before a validation, rebuilding evidence for a governance structure that was supposed to have existed all year. The ones that treat it as leadership's actual job — a real team, a real review, a real answer for the point of contact — walk into that same meeting having nothing to rebuild.
One signed review, on one cadence, can feed both programs at once: the record that satisfies C-TPAT's cross-functional team requirement is the same record PIP's Security Profile re-assessment draws from. XFACTOR VERIFIED builds that record out of the underlying full five-step risk assessment itself, so the one layer that has to be signed by a real name is never rebuilt from nothing twice a year.
Free guide
Free guide: How to Evaluate Supplier Risk
The business-partner screening policy leadership signs off on runs on the same evidence discipline as the rest of the program. This plain-English guide shows what that evidence actually needs to hold up.
The review your leadership team signs has to answer to both programs at once.
See how XFACTOR COMMANDCENTER gives leadership one review cadence across C-TPAT and PIP, or start with the program you're closest to a deadline on — C-TPAT or PIP.
The programs this maps to: C-TPAT · PIP · The platform this maps to: XFACTOR COMMANDCENTER