Contact us
Illustration for ISO management-system services

ISO 28001

ISO 28001 supply-chain security management guidance

ISO 28001 consulting helps manufacturers, traders, logistics providers and warehouse operators in international supply chains assess security, select controls and develop plans for an agreed scope. Vosurein reviews existing processes and evidence, then helps assign responsibilities, implement the plan and review it internally.

Discuss ISO 28001 supply chain security management consulting needs

For Your Business

Who this service is for and when to start

Manufacturers, traders, logistics providers and warehouse operators in international supply chains. Start by identifying gaps and priorities when responsibilities at handover points are unclear, procedures differ from records, or new transport routes have not been assessed.

The Challenge

Common challenges faced by businesses

A company may know how its warehouse operates but not who takes custody after goods leave, when handovers occur or how seal irregularities are reported. Where different providers handle successive supply chain segments, the security plan must address the points the company can manage so responsibilities remain traceable.

Our Approach

Methods and applicable requirements

The adopted version is ISO 28001:2007. Version history: formerly ISO/PAS 28001:2006; PAS is identified separately from the formal international standard.

This standard incorporates both requirements and guidance, focusing on defining the international supply chain scope, conducting security assessments, establishing security plans, and personnel training. It supports compiling evidence applicable for customs security programs, but does not directly grant AEO or other qualifications.

The following consulting tasks can be arranged to suit your needs.

Scope and Responsibilities

Identify the flow of goods, nodes, outsourced activities, and manageable boundaries.

Security Assessment

Organize threats, vulnerabilities, existing measures, and priority issues.

Safety plan

Arrange countermeasures, responsible persons, schedules, and evidence.

Partners and Handover

Review information and cargo handovers involving carriers, warehouse operators and suppliers.

Training and Improvement

Assist with trial implementation, incident reporting and review of implementation records.

Process

Consulting scope and process

  1. Definition of Supply Chain Start/End and Nodes

    Map the points the company is responsible for along the cargo route, including interfaces with carriers and warehouse operators. Define where the security plan applies and where other organisations take over.

  2. Node Security Assessment

    Examine each node’s threats, vulnerabilities, and existing measures, determine priority items based on incidents and customer requirements, and retain assessment evidence.

  3. Countermeasures and Security Plan Trial

    Translate countermeasures into responsibilities, timing, and records in the security plan, and select an actual flow of goods to confirm whether handovers and abnormal reporting can be coordinated.

  4. Partner Handover and Training Review

    Check that partners have received and understood security requirements. Review personnel training and handover incidents, then update arrangements that no longer fit the supply chain.

Preparation

What documents do companies need to prepare?

  • Flow of Goods: Supply chain start and end, nodes, and routes.
  • Responsibility Interface: Carriers, warehousing, and outsourced contracts.
  • Security Assessment: Threats, vulnerabilities, measures, and customer requirements.
  • Implementation evidence: Records of handovers, training, anomalies, and improvements.

For the initial discussion, you can provide a summary. Handle customer, personal and confidential business information within the necessary scope and agreed access permissions.

Project Planning

Estimating time and cost

Workload is evaluated based on the selected supply chain segments, handover nodes, and number of partners. Cross-border or multi-segment outsourcing requires time for external data verification.

We help with assessments, security plans, training and evidence. Applications and eligibility reviews for AEO, C-TPAT or other programmes must be checked separately.

FAQ

Frequently asked questions

Can the scope cover only the part of the supply chain we manage?

You can first define the scope that can be controlled or influenced, but must clearly explain the start and end, nodes, and external responsibilities, without claiming partial evaluation as full compliance of the entire supply chain.

Can AEO or C-TPAT qualification be obtained directly?

No. We can help organise relevant security evidence, but eligibility, applications and audits for customs or other programmes require separate checks.

Does containing guidelines mean it cannot be verified?

That conclusion does not follow. The standard contains both requirements and guidance. Confirm the scheme, assessment body and scope for any third-party assessment; do not assume it follows the same arrangements as ISO 28000.

Can existing systems and records be reused?

You can first review existing supply chain processes, nodes, responsibilities, customer requirements, and de-identified incident data, confirm applicable period, scope, and evidence quality, and then fill in gaps; rewriting all documents is not a prerequisite for implementation.

How should we manage information from external carriers?

Agree on the handover, incident and training information required under the contracts and working relationship. State which activities the company cannot control and assess measures it can take itself.

How are consulting and third-party certification responsibilities divided?

Vosurein supports system implementation and preparation but does not issue third-party certificates. Confirm the applicable certification scheme, accreditation scope, fees and schedule separately. A certificate does not constitute product approval or proof of compliance with every regulation.

Can a single security contract replace a security plan?

No. The plan must define the supply chain scope, assessment results, controls and implementation responsibilities. A security services contract covers only some of that work and must connect with transport and handover procedures.

Related

Related services and enquiries

Please provide the industry, activities, locations, main requirements, and expected completion time.Contact Vosurein

Content checked: . Applicable versions and requirements depend on the company’s circumstances.

Let's Talk

Start a conversation about your needs.

Tell us how the work is done today and when you hope to finish,
so we can agree the scope and way of working together.

Discuss your service needsBack to ISO management-system contents