SCRM Supplier Compliance & Risk Management

Home

ISO 28000:2022 · security management system

Supply chain security also means physical security.

Theft, tampering, smuggling, sabotage – ISO 28000 addresses the risks that arise while goods are in transit and pass through other people’s hands.

ISO 28000 describes a security management system tailored to supply chains. The 2022 edition follows the Annex SL structure and therefore runs alongside ISO 9001 or ISO 27001. It considers threats along the entire chain, including transport, handling and storage at third parties.

For companies with high-value, hazardous or regulated goods it closes a gap: information security covers data, quality management covers conformity – but who has access to the goods between the gate and the customer is answered by neither.

Where the risks sit

  • Transfer points where goods stand unattended.
  • Transport subcontractors engaged by your forwarder whom you have never seen.
  • Storage at third parties without documented access control.
  • Returns, where the chain runs backwards.

What the standard requires

Context
Determine security-relevant threats along the chain.
Risk assessment
Assess where goods are exposed and derive measures.
Govern partners
Set and verify requirements for transport, storage and handling partners.
Incidents
Record and investigate security incidents and feed them back into assessment.
Exercise and improve
Test effectiveness rather than describing it.

How SCRM covers it

Partners in the chain

Forwarder, warehouse operator and their subcontractors as separate records.

Requirements per class

Security conditions graded by value and exposure of the goods.

Incident history

Spot patterns: same route, same transfer point, repeatedly.

Evidence with expiry

Partner certificates and confirmations, with reminders.

Frequently asked

How does ISO 28000 relate to AEO status?

They overlap heavily. A system run to ISO 28000 covers many authorised economic operator requirements but does not replace the customs authorisation.

Do we need it alongside ISO 27001?

ISO 27001 protects information, ISO 28000 the physical chain. For high-value or regulated goods they complement each other.

Is certification necessary?

Only where customers or insurers require it. The structure is a useful framework without a certificate.

Contact

Request a consultation

A few details is all we need. We reply within one working day with an honest read on whether SCRM fits your situation.

  • A free seven-day demo account on request
  • Reply within one working day
  • No newsletter, no sharing with third parties
  • An honest read, including when we are not the fit
What drives your supply chain monitoring? *

Select all that apply

How can we reach you? *

Either one of the two is enough.

No leading zero, e.g. 79 123 45 67

* Required