Governance DocsGovernance Docs
Browse Toolkits

CART

No products in the cart.

ISO Compliance Insights & Best Practices

supply chain security risk assessment explained

Supply Chain Security Risk Assessment: A Complete ISO 28000 Guide

A supply chain security risk assessment is the document everything else in ISO 28000:2022 depends on: clause 8.3 requires security risks to be assessed and treated, clause 8.4 requires the controls to be determined from that treatment, and clauses 8.5 and 8.6 require the procedures and security plans that deliver them — so a thin assessment produces a thin system, and an auditor who finds a control with no risk behind it, or a risk with no control in front of it, has found the assessment. What makes it different from a safety, continuity or information security assessment is intent. The threats in scope — theft, diversion, tampering, smuggling, sabotage, unauthorised access, insider collusion — are deliberate, adaptive and aimed at the weakest handover in the chain, which is why the assessment has to follow the goods rather than the org chart. This guide sets out the method: scoping the chain, identifying the processes and activities clause 8.2 requires, building the threat and vulnerability picture at each node and link, scoring, treating, and turning the result into the controls, procedures and plans that C-TPAT, AEO and ISO 28000 auditors all test.

Supply chain security risk assessment: follow the goods through every handover
Scope the chain (8.2) → nodes and links → threats × vulnerabilities × consequence → score → treat (8.3) → controls (8.4), procedures (8.5), security plans (8.6) → review annually and on change.

Where the supply chain security risk assessment sits in ISO 28000

Clause (ISO 28000:2022) Requirement What the assessment supplies
4.1, 4.2 Context; needs and expectations of interested parties — customers, customs administrations, insurers, regulators The security requirements the assessment must satisfy: customer clauses, C-TPAT or AEO criteria, insurance conditions
6.1 Actions to address risks and opportunities (to the management system) Risks to the SMS itself — not the security risks; those are 8.3
8.2 Identification of processes and activities The map of what is actually done, where, by whom — including subcontracted legs and informal workarounds
8.3 Risk assessment and treatment The assessment: threats, vulnerabilities, consequences, scores, treatment decisions, residual risk accepted by name
8.4 Controls Each control traceable to a treatment decision
8.5, 8.6 Security strategies, procedures, processes and treatments; security plans Procedures for the controls; plans for the incidents the assessment says are credible
9.1, 9.3 Monitoring; management review Incident data feeding the next assessment; review of residual risk

ISO 28000’s 2022 foreword records that recommendations on principles were added in clause 4 “to give better coordination with ISO 31000”, so the risk vocabulary — likelihood, consequence, treatment, residual risk — is ISO 31000’s. Our guide to ISO 28000:2022 covers the clauses around the assessment.

Supply chain security risk assessment step 1: scope the chain and map the handovers

Start from clause 8.2, not from the site plan. List the processes and activities the organisation performs or controls: receiving, storage, picking, loading, sealing, transport legs including subcontracted ones, cross-dock, customs handling, returns. Then draw the chain as nodes (sites, yards, terminals, partner premises) and links (transport legs, data exchanges), and mark every handover — gate, yard, transfer, driver change, subcontractor pickup — because custody is lost at handovers and most incidents originate there. The C-TPAT importer criteria ask for the same map: the risk assessment “should document or map the movement of the Member’s cargo throughout its supply chain”. Our guide to the Authorised Economic Operator covers the customs view of the same chain.

Step 2: build the supply chain security risk assessment register

Column What to record Example
Node or link Where in the chain Yard B, overnight staging; subcontracted leg port–DC
Asset at risk Goods, conveyance, seal integrity, data, people, site High-value electronics on staged trailers
Threat Deliberate act, with the actor where known Theft by organised crime; insider tip-off; contraband insertion in transit
Vulnerability The weakness the threat exploits Unlit yard; seals applied but not verified at receipt; no driver identity check
Existing controls What is in place today, and whether it works CCTV (two cameras out); gate log (paper, incomplete)
Likelihood Scale with defined anchors; use incident history, industry data, route and country risk 4 of 5 — two attempts in twelve months on this route
Consequence Loss, injury, regulatory, customs status, customer, reputational 4 of 5 — loss of C-TPAT status; customer contract clause
Score and rating Likelihood × consequence against a defined matrix 16 — high
Treatment Avoid, reduce (control), transfer (insurance, contract), accept Reduce: lighting, seal verification at receipt, driver ID; transfer residual via insurance
Residual risk and owner The score after treatment and the person who accepted it 6 — medium; operations director, dated

Step 3: the threats a supply chain security risk assessment must consider

Threat class Typical vulnerability Typical control (8.4) Where customs programmes test it
Theft and pilferage Staging, night operations, weak yards Physical barriers, lighting, CCTV, staged-cargo checks C-TPAT Physical Security; Procedural Security
Diversion and fraud Documentation controls, driver identity, release procedures Verified release, driver ID and manifest matching Procedural Security; Business Partners
Tampering and contraband insertion Unverified seals, unchecked conveyances, long dwell times ISO 17712 high-security seals, seal verification, conveyance inspection Seal Security; Conveyance and IIT Security
Unauthorised access Open gates, no visitor control, shared badges Manned or monitored gates, photo ID, visitor logs, badge control Physical Access Controls
Insider threat No screening, concentration of access in one role Screening, separation of duties, supervision, reporting route Personnel Security
Cyber-enabled attack Booking, tracking and release systems exposed Patching, access control, monitoring, incident response Cybersecurity
Partner and subcontractor failure Unscreened partners, no flow-down of requirements Risk-based screening, contract requirements, monitoring Business Partners
Sabotage and terrorism Symbolic or critical cargo and sites The above, plus liaison with authorities and plans (8.6) Programme rationale

Step 4: treat, then trace

  1. Decide the treatment per risk and record why. A control without a risk behind it is a cost; a risk rated high with “accept” and no owner is a finding.
  2. Write the control into 8.4 with a name, an owner and a verification method, and cite the risk register row.
  3. Write the procedure (8.5) and the plan (8.6). The procedure says how the control is operated every day; the security plan says what happens when the threat materialises — broken seal, missing trailer, unauthorised person on site.
  4. Check the customs criteria. Every C-TPAT Must or AEO requirement should map to a control; if the assessment did not produce one, the assessment is incomplete rather than the criterion optional.
  5. Get the residual risk accepted by name and date, at a level that can accept it.

Keeping the supply chain security risk assessment alive

Review annually and on trigger: a new route, country, partner or site; a change in cargo value or type; an incident anywhere in the chain; a customer or customs requirement change; intelligence from authorities. C-TPAT’s criteria say the same — risk assessments “must be reviewed annually, or more frequently as risk factors dictate”. Feed incident and near-miss data from 9.1 into the likelihood column, and take the residual-risk table to management review under 9.3. Our guide to the ISO 22301 risk assessment covers the continuity assessment the same events feed.

Frequently asked questions

What is a supply chain security risk assessment?
The assessment of deliberate-act threats — theft, diversion, tampering, smuggling, unauthorised access, insider and cyber threats — against the assets, nodes and handovers of a supply chain, with vulnerabilities, consequences, scores and treatment decisions. Under ISO 28000:2022 it is clause 8.3, and the controls (8.4), procedures (8.5) and plans (8.6) derive from it.

How is it different from a business continuity risk assessment?
Intent. Continuity assesses disruption whatever its cause; security assesses adversaries who adapt to controls and target the weakest handover. The same incident can be both, which is why ISO 28000 and ISO 22301 share incident and exercise machinery.

Does C-TPAT require one?
Yes. The Risk Assessment category of the Minimum Security Criteria requires members to conduct and document an overall risk assessment of their supply chains, map the international movement of cargo, and review the assessment annually or more often as risk factors dictate.

How often should it be reviewed?
At least annually and on trigger — new route, partner, site or cargo type, an incident, or a change in customer or customs requirements.

Who should own it?
The security or operations lead, with input from transport, warehouse, IT, HR and procurement, and residual risk accepted by someone with authority over the budget the treatments need.

Where this leaves you

Run the supply chain security risk assessment by following the goods: map the processes and handovers, assess deliberate threats against each, score with defined anchors, treat with named controls, and trace every control, procedure and plan back to a register row. Then keep it current, because the adversary the assessment describes is watching for the change you did not reassess.

References

More on supply chain security

The Supply Chain Security Risk Assessment and Treatment workbook, the process and activity register, the control procedures and the security plan templates are in the ISO 28000 Supply Chain Security Toolkit, or start with the free templates.

When a standard changes, know first

One email a month: edition changes, new deadlines, and what they mean for documentation you already have. No sales sequence.

We don’t spam! Read our privacy policy for more info.