Guide · Running Multiple Programs

Who Owns Supplier Vetting Under Both C-TPAT and PIP?

Short answer: it's the same desk under two different labels. C-TPAT's own criteria call the function Procurement; PIP's own criteria call the identical job Purchasing — two customs agencies, one desk, and PIP already accepts the C-TPAT evidence that desk already built. But if you're the one holding both files, you already know the overlap isn't total — PIP still wants things C-TPAT's file doesn't carry, and C-TPAT wants a criterion PIP never asks for. The two files describing the same supplier drift apart more often than either agency would probably like to know.

The same supplier, two customs agencies, and a desk that never gets told to slow down

A new supplier lands on your desk, and before the actual vetting even starts you are already juggling two separate onboarding checklists that ask for nearly the same thing in a different order. Finance still wants sign-off before the vendor goes live. Ops is waiting on that same purchase order to close so the material can move. And somewhere inside that same week, C-TPAT wants a supplier file — and PIP wants what reads like the same file, built over again, under a different department name.

I've watched this from both the C-TPAT and the PIP side of the desk for thirty years, and the pattern never changes: the second file always gets rebuilt at the worst possible time, usually the week before a renewal is due, because nobody flagged that the first file already answered the question.

One scope note before the rest of this: everything below is the file for goods and material suppliers — the piece that sits with Procurement or Purchasing, whichever label your company happens to use for the same function. Vetting a staffing agency you use for personnel is usually a different file, held by HR. Vetting an on-site contractor who comes in for ventilation, cleaning or maintenance work usually sits with Ops, sometimes alongside HR. Both programs still expect that vetting to happen — it just doesn't run through this desk, and this article isn't the place that pretends it does. The screening and evidence work described below is VERIFIED doing its job: proving a supplier meets the bar, once. Making sure that proof shows up correctly on both the C-TPAT side of the file and the PIP side, without anyone re-entering it twice, is what CommandCenter is built to do.

The paper trail C-TPAT wants from Procurement

C-TPAT's business-partner section is specific about what it wants proven, and it wants it proven on paper:

“Does the business-partner screening process take into account whether a partner is a C-TPAT Member or a member in an approved Authorized Economic Operator program with a Mutual Recognition Arrangement — and is that certification continuously monitored?”
“Where the company outsources or contracts elements of its supply chain, is due diligence exercised — visits, questionnaires — to confirm those partners meet the Minimum Security Criteria?”
“If weaknesses are found during a partner's security assessment, are they corrected in a timely manner, with documentary evidence the deficiency was mitigated?”
“Are those assessments updated on a regular basis, or as circumstances and risk dictate?”
“Is a documented social-compliance program in place confirming the goods were not produced with forced, imprisoned, indentured or child labor?”

Every one of those is a paper question. A validator is not asking Procurement to describe its philosophy on ethical sourcing — they are asking to see the screening record, the questionnaire, the correction log, the certificate that has not lapsed.

What the Canada Border Services Agency wants from Purchasing

Cross the border the other direction and the requirement comes from a different regulator with a different name for it. The Canada Border Services Agency runs PIP, and its Business Partner Requirements section asks a version of the same question, in its own words and its own order:

“Do you have a written, verifiable process for selecting business partners — manufacturers, product suppliers, vendors, carriers?”
“Can the business partner demonstrate it is meeting your supply-chain security obligations?”
“Does the business partner develop security procedures consistent with PIP's own criteria at the point of origin, with periodic risk assessments of their facilities and procedures?”
“Was the selection risk-based — financial soundness, ability to meet contractual security requirements, ability to identify and correct deficiencies?”

Read the two lists side by side and the shape is unmistakable: screen the partner on evidence, confirm the evidence holds up at the point of origin, reassess it on a rhythm instead of once and done, correct what's wrong and keep the record of the correction — a CBSA officer and a CBP validator asking the same four things in a different accent. A side-by-side comparison of C-TPAT and PIP's own criteria lists, including where AEO fits alongside them, is in what actually separates the three programs.

PIP already accepts the work you did for C-TPAT

This is the part that gets missed because it sits inside a single criterion instead of a headline. PIP-BP-02 lists the acceptable ways a business partner can demonstrate it meets PIP's security requirements, and one of them is a written statement showing compliance with C-TPAT — or an equivalent World Customs Organization-accredited program administered by another country's customs authority. The criterion names C-TPAT specifically, as a recognized substitute for redoing the work from scratch.

C-TPAT's own criteria name the mechanism behind that recognition directly: a business partner's certification counts if they hold C-TPAT membership, or membership in an Authorized Economic Operator program under a Mutual Recognition Arrangement with the United States. That named arrangement — an MRA — is why PIP-BP-02 can point back at evidence you already built instead of demanding a second, unrelated proof of the same thing.

What breaks that recognition in practice isn't the criterion; it's that the C-TPAT file and the PIP file usually live in two different places, kept by two different people, neither aware the other one already answered the question. The full requirement list, for building a record that carries over cleanly, is in PIP's own Business Partner criteria.

When the PIP file doesn't know what the C-TPAT file already fixed

This is the meeting that catches people who did nothing wrong. A PIP renewal comes due, someone pulls the supplier's file to reconfirm the business-partner evidence, and the file reads thin — no recent reassessment on record, no updated screening note. Except the supplier was reassessed, four months earlier, because a C-TPAT validator asked for it and the C-TPAT file was updated the same week. Nobody carried that update into the PIP tracker, because carrying it isn't written down as anyone's job — it is nobody's task to notice that two folders about the same company stopped agreeing with each other.

Whoever is holding the PIP file that quarter is the one explaining the gap — not because they did anything wrong, but because their name is on the renewal, and the room in front of them does not care which folder the missing update was actually filed under. The work was real. It just wasn't in the file the room was reading from.

One record, tracked once, instead of two folders drifting apart

Before any platform helps with this, the work itself does not shrink. Someone still has to hold one supplier record that both programs can read from — not two folders that happen to describe the same company. Someone has to track two renewal rhythms on one calendar, because C-TPAT and PIP were never going to schedule their reassessments on the same day just because the supplier is the same. And someone has to know, criterion by criterion, where the overlap actually stops — PIP's seal and container detail is not something C-TPAT's business-partner section carries, and C-TPAT's social-compliance criterion is not something PIP's list restates.

Inside XFACTOR COMMANDCENTER, a supplier is entered once and tagged against every program the client is running — the C-TPAT business-partner evidence and the PIP business-partner evidence draw from the same record instead of drifting apart in two trackers that never compare notes. When a C-TPAT reassessment updates a supplier's file, the PIP side of that same supplier sees it too, because it is the same supplier record, not a second one waiting to fall behind.

Free guide

Free guide: How to Evaluate Supplier Risk

The same evidence file both programs are actually asking for. This plain-English guide shows what a real supplier record needs to hold up under either one.

We’ll email it to you. No spam, no list-selling. Unsubscribe anytime.


One supplier record. Every program it needs to answer to.

See how XFACTOR COMMANDCENTER runs C-TPAT and PIP from the same supplier file, or start with the program you're closest to a deadline on — C-TPAT or PIP.

The programs this maps to: C-TPAT · PIP · The platform this maps to: XFACTOR COMMANDCENTER