
ISO 28001
ISO 28001 supply-chain security management guidance
ISO 28001 consulting helps manufacturers, traders, logistics providers and warehouse operators in international supply chains assess security, select controls and develop plans for an agreed scope. Vosurein reviews existing processes and evidence, then helps assign responsibilities, implement the plan and review it internally.
Discuss ISO 28001 supply chain security management consulting needs
For Your Business
Who this service is for and when to start
Manufacturers, traders, logistics providers and warehouse operators in international supply chains. Start by identifying gaps and priorities when responsibilities at handover points are unclear, procedures differ from records, or new transport routes have not been assessed.
The Challenge
Common challenges faced by businesses
A company may know how its warehouse operates but not who takes custody after goods leave, when handovers occur or how seal irregularities are reported. Where different providers handle successive supply chain segments, the security plan must address the points the company can manage so responsibilities remain traceable.
Our Approach
Methods and applicable requirements
The adopted version is ISO 28001:2007. Version history: formerly ISO/PAS 28001:2006; PAS is identified separately from the formal international standard.
This standard incorporates both requirements and guidance, focusing on defining the international supply chain scope, conducting security assessments, establishing security plans, and personnel training. It supports compiling evidence applicable for customs security programs, but does not directly grant AEO or other qualifications.
The following consulting tasks can be arranged to suit your needs.
Scope and Responsibilities
Identify the flow of goods, nodes, outsourced activities, and manageable boundaries.
Security Assessment
Organize threats, vulnerabilities, existing measures, and priority issues.
Safety plan
Arrange countermeasures, responsible persons, schedules, and evidence.
Partners and Handover
Review information and cargo handovers involving carriers, warehouse operators and suppliers.
Training and Improvement
Assist with trial implementation, incident reporting and review of implementation records.
Process
Consulting scope and process
Definition of Supply Chain Start/End and Nodes
Map the points the company is responsible for along the cargo route, including interfaces with carriers and warehouse operators. Define where the security plan applies and where other organisations take over.
Node Security Assessment
Examine each node’s threats, vulnerabilities, and existing measures, determine priority items based on incidents and customer requirements, and retain assessment evidence.
Countermeasures and Security Plan Trial
Translate countermeasures into responsibilities, timing, and records in the security plan, and select an actual flow of goods to confirm whether handovers and abnormal reporting can be coordinated.
Partner Handover and Training Review
Check that partners have received and understood security requirements. Review personnel training and handover incidents, then update arrangements that no longer fit the supply chain.
Preparation
What documents do companies need to prepare?
- Flow of Goods: Supply chain start and end, nodes, and routes.
- Responsibility Interface: Carriers, warehousing, and outsourced contracts.
- Security Assessment: Threats, vulnerabilities, measures, and customer requirements.
- Implementation evidence: Records of handovers, training, anomalies, and improvements.
For the initial discussion, you can provide a summary. Handle customer, personal and confidential business information within the necessary scope and agreed access permissions.
Project Planning
Estimating time and cost
Workload is evaluated based on the selected supply chain segments, handover nodes, and number of partners. Cross-border or multi-segment outsourcing requires time for external data verification.
We help with assessments, security plans, training and evidence. Applications and eligibility reviews for AEO, C-TPAT or other programmes must be checked separately.
FAQ
Frequently asked questions
Can the scope cover only the part of the supply chain we manage?
You can first define the scope that can be controlled or influenced, but must clearly explain the start and end, nodes, and external responsibilities, without claiming partial evaluation as full compliance of the entire supply chain.
Can AEO or C-TPAT qualification be obtained directly?
No. We can help organise relevant security evidence, but eligibility, applications and audits for customs or other programmes require separate checks.
Does containing guidelines mean it cannot be verified?
That conclusion does not follow. The standard contains both requirements and guidance. Confirm the scheme, assessment body and scope for any third-party assessment; do not assume it follows the same arrangements as ISO 28000.
Can existing systems and records be reused?
You can first review existing supply chain processes, nodes, responsibilities, customer requirements, and de-identified incident data, confirm applicable period, scope, and evidence quality, and then fill in gaps; rewriting all documents is not a prerequisite for implementation.
How should we manage information from external carriers?
Agree on the handover, incident and training information required under the contracts and working relationship. State which activities the company cannot control and assess measures it can take itself.
How are consulting and third-party certification responsibilities divided?
Vosurein supports system implementation and preparation but does not issue third-party certificates. Confirm the applicable certification scheme, accreditation scope, fees and schedule separately. A certificate does not constitute product approval or proof of compliance with every regulation.
Can a single security contract replace a security plan?
No. The plan must define the supply chain scope, assessment results, controls and implementation responsibilities. A security services contract covers only some of that work and must connect with transport and handover procedures.
Related
Related services and enquiries
Please provide the industry, activities, locations, main requirements, and expected completion time.Contact Vosurein
Content checked: . Applicable versions and requirements depend on the company’s circumstances.
Let's Talk
Start a conversation about your needs.
Tell us how the work is done today and when you hope to finish,
so we can agree the scope and way of working together.
Blog
Sustainability and AI insights
Start with understanding,
and see where change can lead.

