2025-01-17 | DOF 5747310Added
Annex 1 to the General Rules of Foreign Trade for 2025 establishes the official formats, models, and auxiliary documents required for foreign trade operations in Mexico. It defines the specific types of official identification and proof of address accepted for administrative procedures, and provides a comprehensive catalog of authorization forms, notices, certificates, declarations, and applications, specifying the competent authority and submission method for each. The annex also details the content and instructions for specific forms, such as the Temporary Import Authorization for goods and boats, and outlines the requirements for proving domicile through various financial, utility, or contractual documents.
Formats and Models of Foreign Trade
For the purposes of Article 31, first paragraph of the Federal Tax Code (CFF), in relation to Rule 1.2.1., the auxiliary formats and models used by foreign trade users are made known, as follows:
I. Official identifications and proof of address. II. Foreign trade formats:
| Indicative References | Format Name | Authority Before Which It Is Presented | Submission Medium |
|---|---|---|---|
| A. Authorizations | |||
| Name of the Authorization | |||
| A1. Temporary import authorization. | Corresponding Customs | Free writing | |
| A2. Temporary import authorization of boats / Authorization for temporal importation of boats. | Corresponding Customs | Free writing | |
| A3. Temporary import authorization of goods, intended for the maintenance and repair of goods temporarily imported. | Customs or entry section | Free writing | |
| A4. Authorization to import goods only once, without having concluded the registration procedure or being suspended in the Importers Registry, (Rule 1.3.5.). | DGOA | Free writing | |
| A5. Authorization to natural persons to import goods only once, without being registered in the Importers Registry, (Rule 1.3.6.). | ACNCE / Corresponding ADJ | Free writing | |
| A6. Registration authorization for the Sectoral Exporters Registry (Rule 1.3.7.). | AGSC/ADSC | Free writing | |
| A7. Authorization for the importation of specially constructed or transformed vehicles, equipped with various devices or apparatus to fulfill a contract derived from a public bid, (Rule 4.2.9.). | ACAJACE | Free writing | |
| A8. Rectification authorization of customs declarations. | ACAJACE | Free writing | |
| A9. Authorization to import goods for national security purposes. | ACAJACE | Free writing |
| Indicative References | Notice Name | Authority Before Which It Is Presented | Submission Medium |
|---|---|---|---|
| B. Notices | |||
| B1. Notice of compensation of contributions and revenues to foreign trade. | Corresponding Customs | Free writing | |
| B2. Temporary export notice. | Corresponding Customs | Free writing | |
| B3. Temporary import or export notice and return of containers. | Entry or exit Customs | Free writing | |
| B4. Notice of introduction of donated goods to the country's border strip (Rule 3.3.6., fraction II). | Customs where the operation will be processed. | Free writing | |
| B5. Notice to extend the term granted by SE to change to the definitive import regime or return goods temporarily imported to abroad (4.3.8.). | ACAJACE | Free writing | |
| B6. Notice for the transfer of auto parts located in the border strip or region to the automotive or vehicle manufacturing industry in the rest of the national territory. | ACAJACE | Free writing | |
| B7. Notice of option for the determination of provisional value (global transport insurance). | ADACE | Digital Window | |
| B8. Notice of registration of electronic devices and work instruments. | Entry Customs | Free writing | |
| B9. Notice of transfer of goods subject to the Duty Free fiscal deposit regime. | Entry or exit Customs | Free writing | |
| B10. Notice of transfer of goods from companies with IMMEX Program, RFE or Authorized Economic Operator. | ADACE or customs as applicable | SAAI | |
| B11. Notice of transfer of goods from companies with IMMEX Program in the Authorized Economic Operator modality, item: holding company of companies. | AGACE | SAAI | |
| B12. Electronic notice of import and export. | Customs | SAAI | |
| B13. Volumetric Storage Capacity Notice (Rule 2.3.8.). | Corresponding Customs | Free writing | |
| B14. Assignment conferred on the customs broker to carry out foreign trade operations or its revocation. | * Electronic Format: RFC Procedures/Importers and Exporters/Update your assigned tasks | AGSC | SAT Portal |
| B15. Assignment conferred on the customs agency to carry out foreign trade operations or its revocation. | * Electronic Format: Procedures/RFC/Importers and Specific Sectors/Update of Assigned Tasks | AGSC | SAT Portal |
| B16. Electronic notice of rejection (Rule 1.8.2.). | DGIA | SAT Portal | |
| B17. Notice of safe return of foreign vehicles. | ADACE | Digital Window |
| Indicative References | Certificate Name | Authority Before Which It Is Presented | Submission Medium |
|---|---|---|---|
| C. Certificates | |||
| C1. Certificate of temporary import, return or transfer of containers. | Customs | Digital Window | |
| C2. Certificate of origin of agricultural products. | Customs Authority | Upon request | |
| C3. Certificate of transfer of goods. | Customs Authority | Upon request |
| Indicative References | Declaration Name | Authority Before Which It Is Presented | Submission Medium |
|---|---|---|---|
| D. Declarations | |||
| D1. Postal Form. | Customs Personnel | ||
| D2. Customs declaration for passengers coming from abroad (Spanish and English). | Customs | Free writing | |
| D3. Passenger money departure declaration (Spanish and English). | Customs | Free writing | |
| D4. Declaration of Internment or Extraction of cash amounts and/or documents for payment (Spanish and English). | Customs | Free writing / SAT Portal | |
| D5. Declaration for Movement in Customs Account of Goods, Imported to Return in the Same State in accordance with Art. 86 of the L.A. | Customs | Free writing | |
| D6. Document of origin of extracted, industrialized or manufactured mineral products. | Corresponding Customs | ||
| D7. Payment of contributions to foreign trade (Spanish, English and French). | Customs | Free writing / SAT Portal | |
| D8. Temporary import declaration for trailers, semi-trailers and container carriers. | Customs | Free writing / SAAI | |
| D9. Multiple payment form for foreign trade. | * Simplified electronic format at the electronic address: https://pccem.mat.sat.gob.mx/PTSC/cet/FmpceContr/faces/resources/pages/pagos/formularioMultiplePago.jsf. | SAT Portal |
| Indicative References | Format Name | Authority Before Which It Is Presented | Submission Medium |
|---|---|---|---|
| E. Formats | |||
| E1. Official gummed label for internal transit control by air. | Customs | ||
| E2. Value Manifestation. | Customs Authority | Digital Window | |
| E3. Company Profile. | AGACE | Digital Window | |
| E4. Customs Broker Profile. | AGACE | Digital Window | |
| E5. Land Transporter Profile. | AGACE | Digital Window | |
| E6. Courier and Package Profile. | AGACE | Digital Window | |
| E7. Controlled Premises Profile. | AGACE | Digital Window | |
| E8. Strategic Controlled Premises Profile. | AGACE | Digital Window | |
| E9. Railway Transporter Profile. | AGACE | Digital Window | |
| E10. Industrial Parks Profile. | AGACE | Digital Window | |
| E11. General Warehouse Profile. | AGACE | Digital Window | |
| E12. Manifestation of will to assume joint liability in terms of Rule 7.3.3., fraction XIII. | ACAJACE | SAT Portal | |
| E13. Request for issuance of advance ruling. | ACAJACE/ACNCE | Free writing | |
| E14. Format to present the Report on compensation or reduction of expenses against the revenue due. | AGACE | Digital Window |
| Indicative References | Request Name | Authority Before Which It Is Presented | Submission Medium |
|---|---|---|---|
| F. Requests | |||
| F1. Request for Issuance of Certified Copies of Customs Declarations and their Annexes. | ANAM / DGIA | Digital Window | |
| F2. User and password request to enter the Integrated Customs Operation System (SOIA). | DGMEIA | Free writing | |
| F3. Request for Security Matrix for Delivery of Foreign Trade Information. | DGMEIA | Free writing |
| Indicative References | Model Name | Authority Before Which It Is Presented | Submission Medium |
|---|---|---|---|
| M1.1. Customs Declaration (Pedimento). | Customs | Free writing | |
| M1.2. Import Customs Declaration. Part II. Partial shipment of goods. | Customs | Free writing | |
| M1.3. Export Customs Declaration. Part II. Partial shipment of goods. | Customs | Free writing | |
| M1.4. Transit Customs Declaration for transshipment. | Corresponding Customs | Free writing | |
| M1.5. Simplified Form of the Customs Declaration. | Corresponding Customs | Free writing | |
| M1.6. Consolidated Notice Format. | Corresponding Customs | Free writing | |
| M1.7. Operation Document for Customs Clearance (DODA). | Corresponding Customs | Free writing | |
| M1.8. Electronic Capacity Letter. | Corresponding Customs | SAAI | |
| M1.9. Capacity Letter for international exhibitions. | Corresponding Customs | Annexed to the customs declaration | |
| M1.10. Report of exports of submanufacturing or submaquila operations. | None | ||
| M1.11. List of documents. | Customs | Free writing |
a) For the purposes of the procedures contained in the General Rules of Foreign Trade (RGCE) and its Annexes, official identification shall be understood as any of the following valid documents:
b) Likewise, for the purposes of foreign trade formats and procedures, proof of address shall be understood as any of the following documents:
The presentation of any of the documents referred to in the preceding subsection shall only have an indicative value regarding the location of the address indicated by the taxpayer for the purposes of the procedures presented in accordance with this Resolution; therefore, they shall not be understood as proof of fiscal address in procedures resulting from the exercise of verification powers by customs authorities, nor for the purposes of Article 10 of the Federal Tax Code (CFF) and other applicable legal provisions.
Date of entry ||||||| Expiration date ||||||| day month year day month year
Customs/customs section
Key
1. Owner's Data. Full name (paternal surname/maternal surname/first name(s)), trade name or corporate name ___________________________________________________________________________________ Address ________________________________________________________________________________
2. Importer's Data. Full name (paternal surname/maternal surname/first name(s)), trade name or corporate name ___________________________________________________________________________________ Address ________________________________________________________________________________ Driver's License No. ___________________________________________________________________ Passport No. ____________________________ S.S.N. __________________________________________
Signature
3. Description of the goods.
4. Customs/customs section authorization. Name _________________________________________________________ Employee badge No. __________________________________________
Signature
Stamp
Customs/Customs Section
5. Return Data. Date ________________________________ day month year
Customs/customs section ______________________________ Key ___________________________________________________ Place ___________________________________________________
Front
Instructions
I. Write clearly, in block letters and with a ballpoint pen. II. This application must be presented in original and copy. III. Keep your application to be delivered at the BANJERCITO vehicle control office through which you will effect your return. It is your proof of the legal stay of your goods. IV. This document is not valid if it shows erasures or alterations. V. Remember that by providing inaccurate or false data, you will be subject to sanctions related to the presumption of smuggling.
Fields 1, 2 and 3 will be filled out by the importer; the rest are for exclusive use of the customs authority.
These data must be filled out by the customs authority:
Folio No. - The customs authority will note the folio number of the corresponding internal registry. Date of entry - Will note the date of entry of the goods into national territory, starting with the day, month and year. Expiration date - The date on which the temporary import of the goods expires will be noted, starting with the day, month and year. Customs/customs section - Will note the name of the customs or customs section through which the goods are introduced. Key - Will note the key of the customs or customs section through which the goods are introduced.
The importer will provide the following data:
1. Owner's Data: Full name (paternal surname/maternal surname/first name(s)), trade name or corporate name. Will note the name of the owner or trade name, starting with the paternal surname, maternal surname and first name(s), as well as their complete address.
2. Importer's Data: Full name (paternal surname/maternal surname/first name(s)), trade name or corporate name. Will note the name of the importer or trade name, resident abroad if applicable, starting with the paternal surname, maternal surname and first name(s), as well as their complete address. Driver's License No. - Will note the driver's license number. Passport No. - Will note the passport number. S.S.N. - Will note the social security card number. Signature - Will affix their autograph signature.
3. Description of the goods: In this box, will note the description, nature, state, origin and other characteristics of the goods, as well as other data that allow their identification, or in their absence, the technical or commercial specifications necessary for their identification, such as brand, model, type, serial number, size, color, etc.
The following data must be filled out by the customs authority:
4. Customs/customs section authorization: Name - Will note the full name of the person granting the authorization on behalf of the customs. Employee badge No. - Will note the personal identification (badge) number of the customs employee granting the authorization. Signature - The employee who authorized the application will affix their signature. Stamp of the Customs/customs section - In this space, the stamp of the customs or customs section granting the authorization will be placed.
5. Return Data: Date - Will note the date of return of the goods, starting with the day, month and year. Customs/customs section - Will note the name of the customs or customs section through which the goods will be returned. Key - Will note the key of the corresponding customs or customs section. Place - Will note the name of the city, municipality and state corresponding to the customs or customs section.
Back
Folio No./No. Of Folio:
TO BE FILLED OUT BY THE IMPORTER/THE IMPORTER WILL PROVIDE THE FOLLOWING INFORMATION
1. Date of entry / Date of entry Expiration date / Expiring date ||||||| ||||||___| day/day month/month year/year day/day month/month year/year
2. Owner's generals. Full name (Last name/name) or company's name.
Address___________________________________________________________________________
3. Importer's generals.
Last name Middle name Name Address
Driver's license
Passport number _________________________________________________________________ Mexican citizen ( ) Non Mexican citizen ( ) If non Mexican, indicate your migratory status:
Owner ( ) Spouse ( ) Ancestor ( ) Descendant ( ) Other ( )
4. Boat's information. Class of boat
Name___________________________________Trademark __________________________ Length__________________________________Model _________________________________ Model year ________________________ Registry number
Motor (motors) ________________________ Hull's series __________________ Color ______________________________________Ownership's title
22 DIARIO OFICIAL Viernes 17 de enero de 2025 Número de serie/ Serial number _________________________Número de matrícula/Enrol number
VIN/VIN _________________________________________________________________________________ Finalidad a la que será destinada la embarcación/The object of boats
Exploración/Exploration
Firma/ Signature ESTE FORMATO DEBIDAMENTE REQUISITADO AMPARA LA LEGAL ESTANCIA EN EL PAÍS DE LA EMBARCACION/ THIS FORM, ONCE STAMPED, COVERS THE LEGAL STAY OF THE BOAT IN MEXICO. 7. Autorización de la aduana o sección aduanera/Customs office or customs section authorization. Nombre/Name _______________________________________________________ No. de gafete del empleado/Employee gafet number
Firma/Signature Sello Aduana o sección aduanera/ Seal Customs office or customs Section 8. Datos del retorno/Return information. Fecha/Date _______________ ______________ _______________ día /day mes/month año/year Aduana o Sección aduanera/Customs office or customs section
Clave/Code______________________________________________________________________________ Lugar/Place______________________________________________________________________________ REVERSO/BEHIND REVERSE
Viernes 17 de enero de 2025 DIARIO OFICIAL 23 Instrucciones / Instructions -Escribir con claridad, letra de molde y bolígrafo/Write clearly with ballpoint pen. -Esta solicitud se debe de presentar en original y copia/This form should be submitted in original and a copy. -Conserve su solicitud autorizada para ser entregada en la oficina de control de la aduana por donde vaya a efectuar su retorno. Este documento es su comprobante de la estancia legal de su embarcación/This form is your legal importation document, and it should be provided to the customs control office when returning abroad. -Este documento no es válido si presenta raspaduras o enmendaduras/This document is not valid if it presents scratchings or amendments. -Recuerde usted que al proporcionar datos inexactos o falsos se hará acreedor a sanciones relacionadas con la presunción de contrabando/You are liable for any false statements or inaccurate information provided in this document to penalties related to smuggling presumption. -No. de Folio/No. of Folio.- La autoridad aduanera anotará el número de folio del registro interno que corresponda/Custom´s authority will provide each form with its corresponding number. Los campos 1, 2, 3, 4, 5 y 6 serán llenados por el importador, los campos 7 y 8 son de uso exclusivo de la autoridad aduanera/Camp 1, 2, 3, 4, 5 and 6 must be completed by the importer, camp 7 and 8 are for official use only. Estos datos deberán ser llenados por el importador/The importer will provide the following information:
24 DIARIO OFICIAL Viernes 17 de enero de 2025 Si es extranjero, indique su calidad migratoria: Indicará mediante número asignado a su calidad migratoria/If Non Mexican, state your migratory status: Indicate by your assigned number your migratory status. Marcará con una X si la persona que solicita la importación temporal de la embarcación es el propietario, cónyuge, ascendiente o descendiente/Mark with an X whether the person that requires the temporal importation of the boat is the owner, spouse, ancestor or descendant. 4. Datos de la embarcación/Boat´s information.- En este recuadro anotará los datos de la embarcación, tales como: clase de embarcación, nombre, marca, eslora, tipo, modelo, número de registro, número de motor, número de serie del casco, color, número del título de propiedad, número de serie, número de matrícula NIV /The boat´s information should be written down, such as class, name, trademark, length, model, model year, registry number, motor number, hull´s series number, color, real state property, serial number, enrol number, vehicle identification number. 5. Destino de la embarcación/Boat´s destination: Señalará con una X la opción correspondiente al destino de la embarcación, pudiendo ser: explotación o exploración/An X mark should be marked at the correspondant boat destination (Exploitation or exploration). Finalidad a la que será destinada la embarcación/The object of boats: El importador señalará el uso que le dará a la embarcación/The importer´s object of boats should be written down. 6. Firma/Signature.- Asentará su firma autógrafa/Your signature should be written down. Notas/Notes: Deberá acreditar la propiedad de la embarcación para lo cual deberá anexar a la presente solicitud copia de cualquiera de los siguientes documentos: el documento equivalente, el contrato de fletamento, título de propiedad, o bien del certificado de registro otorgado por la autoridad competente/The boats ownership should be proved by annexing to this application form any of the following documents: invoice, transport contract, ownership´s title or the registry certificate granted by the competent authority. Deberá anexar copia de la siguiente documentación/A copy of the following documents should be attached: I. Las características técnicas de las mercancías antes descritas/The technical characteristics of the above mentioned merchandise are indicated; II. Acta constitutiva en la que se establezca dentro del objeto social de la empresa, que se dedicará a la prestación de los servicios de exploración o explotación, y /Company´s by-laws in which exploration or exploitation should be included at the company´s purpose, and III. En su caso, el contrato, concesión o autorización correspondiente, para la prestación de los servicios que requieran de dichas mercancías para su cumplimiento/If the case may be, the contract, concession or correspondant authorization which demonstrates that with the above mentioned merchandise, the services will be rendered.
Viernes 17 de enero de 2025 DIARIO OFICIAL 25 A3. Autorización de importación temporal de mercancías, destinadas al mantenimiento y reparación de las mercancías importadas temporalmente Importación temporal. ( ) Retorno. ( ) Fecha ||||||| día mes año Aduana/Sección aduanera ______________________________ Clave: ________________________________________
Fecha y No. del acta de destrucción: Autoridad ante la que se presentó el aviso de destrucción:
Declaro bajo protesta de decir verdad que los datos asentados en la presente solicitud son ciertos.
Nombre y firma del importador o su representante legal
26 DIARIO OFICIAL Viernes 17 de enero de 2025 Instrucciones No. de folio: La aduana de entrada, asignará un número consecutivo a la solicitud de la operación. Operación: Se deberá marcar con una X la operación que se va llevar a cabo, importación temporal o retorno, según se trate. Fecha: Se deberá anotar la fecha de presentación de la solicitud ante la autoridad aduanera. Aduana/sección aduanera: Se deberá declarar la aduana y/o sección aduanera, por la cual se llevará a cabo la operación. Clave: Se deberá declarar la clave de la aduana y sección aduanera, por la cual se llevará a cabo la operación de mantenimiento o reparación, conforme al apéndice 1 del Anexo 22.
Viernes 17 de enero de 2025 DIARIO OFICIAL 27 3. Datos de las partes o refacciones, o bienes destinados al mantenimiento o reparación: Descripción de la mercancía: Se deberá señalar la descripción comercial de la mercancía objeto del mantenimiento o reparación. Especificaciones técnicas o comerciales: Se deberá señalar la descripción comercial de la mercancía objeto del mantenimiento o reparación. Marca: Se deberá anotar la marca comercial del bien. Modelo, Tipo, No. de serie: En caso de contar con la información del Modelo, Tipo y/o número de serie, deberá ser declarada en la solicitud. Cantidad: Se deberá declarar la cantidad de bienes que serán objeto de la autorización. 4. Destino que se le dará a las partes o refacciones reemplazadas: Destino: En este caso se deberá marcar con una X el uso al que será(n) sometida(s) la(s) mercancía(s) que fueron objeto del reemplazo, retornadas, destruida o importada definitivamente. 5. Datos de la destrucción o importación definitiva de las partes o refacciones reemplazadas: Pedimento de importación definitiva: Se declara el número del pedimento con el cual se efectuó el cambio de régimen de las mercancías reemplazadas. Aduana/sección/clave: Fecha y No. del acta de destrucción: Se deberá señalar la fecha y No. del acta de destrucción, de las partes o refacciones reemplazadas. Autoridad ante la que se presentó el aviso de destrucción: Se deberá declarar el Nombre de la autoridad aduanera a la que se presentó el aviso de destrucción de las partes o refacciones. 6. Nombre y firma del importador o su representante legal: Se deberá declarar el apellido paterno, materno y el nombre, del importador o el representante legal de la empresa que presenta la solicitud y asentar la firma autógrafa. Observaciones: En la presente solicitud se deberá escribir con claridad, letra de molde y bolígrafo, se debe de presentar en original para la aduana, copia para el importador y copia para quien en su caso tenga la custodia de la mercancía. Este documento no es válido si presenta raspaduras o enmendaduras. Recuerde usted que al proporcionar datos inexactos o falsos se hará acreedor a sanciones relacionadas con la presunción de contrabando. Deberá anexar los documentos que, en su caso, demuestren el destino de las partes o refacciones reemplazadas. En el caso de refacciones para aeronaves, se deberá presentar una autorización por aeronave. Sólo se podrá hacer uso de esta solicitud, cuando las partes o refacciones puedan ser susceptibles de ser identificadas plenamente. No están sujetas a este tipo de operaciones las mercancías consumibles, tales como aceites, remaches, tornillos, cintas adhesivas, material sellante, líquidos, cables, entre otros.
28 DIARIO OFICIAL Viernes 17 de enero de 2025 A4. Autorización para importar mercancía por única vez, sin haber concluido el trámite de inscripción o estando suspendidos en el Padrón de Importadores (Regla 1.3.5.) Información General del Solicitante.
Viernes 17 de enero de 2025 DIARIO OFICIAL 29 Información General de la Mercancía.
b) Cantidad de mercancía: __________________________________________________________________
c) Valor de la mercancía según el documento equivalente que corresponda:
d) Fracción (es) arancelaria (s) y número (s) de identificación comercial de la mercancía (s) a importar:
Firma autógrafa del solicitante o representante legal DIA________MES__________________AÑO __________
30 OFFICIAL GAZETTE Friday, January 17, 2025 Instructions This application shall be filled out in two copies, either typed or in block letters, using a black or blue ink pen, and the figures must not invade the limits of the boxes.
General Information of the Applicant
General Information of the Merchandise
Data of the Legal Representative
Friday, January 17, 2025 OFFICIAL GAZETTE 31 Procedure Instruction for the Authorization to import merchandise only once, without having concluded the registration process or being suspended in the Importers Registry (Rule 1.3.5.) Who presents it? Natural and legal persons obliged to register in the Importers Registry who have not yet concluded the registration process or who are suspended in the said Registry. To whom is it directed? To the DGOA. Sending options: You can also send the application and documents via SEPOMEX or using the services of courier companies. When is the authorization application presented? After five days have passed since presenting through the SAT Portal, the application for registration in the Importers Registry or in the case of being suspended, the application to lift said suspension in the Importers Registry, according to the procedure sheets 5/LA Application for registration in the Importers Registry and 7/LA Application to lift the suspension in the Importers Registry, Sectoral Importers Registry or both or, in its case, of a sector or specific sectors of the latter. How is it presented? In writing through the form called Authorization to import merchandise only once without having concluded the registration process or being suspended in the Importers Registry (Rule 1.3.5.), attaching the documents provided for in the form: I. Copy of the document that accredits that the merchandise is in deposit at the customs. II. Documents that accredit that the merchandise is explosive, flammable, contaminating, radioactive, corrosive, perishable or easily decomposable or live animals. III. Copy of the equivalent document or document that justifies the ownership of the merchandise to be imported, or in its case, a declaration under oath of telling the truth, that it is its legitimate owner. IV. Copy of the registration folio of the application for registration in the Importers Registry or in the case of being suspended, of the application to lift said suspension in the Importers Registry, which is presented electronically on the SAT Portal, according to the procedure sheets 5/LA Application for registration in the Importers Registry and 7/LA Application to lift the suspension in the Importers Registry, Sectoral Importers Registry or both or, in its case, of a sector or specific sectors of the latter, in which the date of sending is stated. V. Original or certified copy and copy for comparison, of the official identification of the legal representative or of the natural person who presents the application. VI. Certified copy and copy for comparison, of the public deed or power of attorney through which legal representation is accredited. What document is obtained? Copy of the official letter of Authorization by which the DGOA is requested to allow the importation of the merchandise only once without having concluded the registration process or being suspended in the Importers Registry. In what time frame is the authorization issued? In a period not greater than three months, counted from the date on which the application was duly filled out together with the corresponding documentation. Applicable legal provisions Articles 59, fraction IV, of the Law, 86 of the Regulation and rule 1.3.5.
32 OFFICIAL GAZETTE Friday, January 17, 2025 A5. Authorization to natural persons to import merchandise only once, without being registered in the Importers Registry, (Rule 1.3.6.) Before filling out this form, read the instructions on the back. Indicate, if applicable, the number of the official letter with which you were granted registration in the Importers Registry:
Indicate, if applicable, the number of the official letter if you have initiated the process for registration in the Importers Registry and it has not concluded:
Indicate if you have made a request previously in the current fiscal year, if affirmative state the number with which you obtained the authorization:
First Name(s) First Last Name Second Last Name 1.1. Address for hearing and receiving notifications, as well as the persons authorized for such effects Street ___________________________ No. and/or letter exterior __________ No. and/or letter interior ________ Neighborhood ________________ Postal Code _________ Municipality or Delegation ______________________ Locality ___________ Federal Entity _____________________ Phones ______________________ Authorized personnel to hear and receive notifications:
Phones
First Name(s) First Last Name Second Last Name
Friday, January 17, 2025 OFFICIAL GAZETTE 33 Indicate with an x, that you declare, under oath of telling the truth, that the legal representative has the faculties to carry out acts of administration or those necessary to carry out the procedures of this procedure. 3. Information related to the procedure 3.1. Description of the merchandise: Detailed description of the merchandise to import, indicating the data that allow its individual identification (serial number, part, brand or model), or in its absence, the technical or commercial specifications. When it is about more than one merchandise, the description must be made for each of them. Quantity of the merchandise to be imported, indicating the unit of measurement for marketing (kilo, gram, meter, piece, liter, pair, set, etc.). Value of each of the merchandise, of according to the equivalent document that corresponds: Tariff fraction(s) of the merchandise to be imported: Customs Office through which the merchandise will enter: Reason or justification of the necessity of the procedure. 3.2. Indicate with an x, that you declare, under oath of telling the truth, that the merchandise that is intended to be imported will be destined for the personal use of the interested party or to carry out the purposes of its corporate object and will not be commercialized. 3.3. Indicate with an x, that you declare, to be the legitimate owner of the merchandise described in this format in case of not having the equivalent document that justifies the ownership. I declare under oath of telling the truth, that the data recorded in this format are true.
Name and signature of the applicant (Natural person applicant or legal representative)
34 OFFICIAL GAZETTE Friday, January 17, 2025 Instructions General Information This form is freely printable and must be filled out in two copies or in block letters, using a black or blue ink pen, and the figures must not invade the limits of the boxes. Presentation Options The procedure must be presented at the official office of the ACNCE in person or using the services of SEPOMEX as well as those of Courier companies or before the ADJ that corresponds to the tax address of the applicant, through the tax mailbox. When the procedure is presented via tax mailbox, the present format duly filled out and the requirements indicated in these instructions must be attached digitally. The procedure takes effect from the date of receipt of the application in accordance with the means of presentation. Specific Indications When the space is insufficient for the item General Information related to the procedure, item 3.1., the merchandise can be described in an attached document referencing it in this format. Requirements I. Proof of address. II. Equivalent document that supports the ownership of the merchandise to be imported. If the information is in a language other than Spanish, attach a translation of it. III. Notarial power of attorney authorizing the legal representative to carry out acts of administration. IV. Official identification of the legal representative and of the natural person who presents the application. In the case that the procedure is presented before the ACNCE, it must be attached to the documentation referred to in this section. For items III and IV, the documentation can be presented in certified copy. When presented in certified copy or in original, a simple copy for comparison must be attached. Additional Information of the Procedure The authorization will be granted in a period not greater than three months, counted from the date on which the application was duly filled out together with the corresponding documentation, provided that there is no request for additional information and documentation. A copy of the authorization official letter will be obtained by which the DGOA is requested to allow the importation of the merchandise without being registered in the Importers Registry. For any doubt about the filling of the format and/or requirements, as well as any consultation about the applications presented, you can obtain information on the SAT Portal or contact MarcaSAT 55 627 22 728 and the phone (55) 5802-1335.
Friday, January 17, 2025 OFFICIAL GAZETTE 35 A6. Registration Authorization for the Sectoral Exporters Registry (Rule 1.3.7.) FILL CLEARLY THE INDICATED FIELDS: DATE OF PRESENTATION: DAY _____ MONTH _____ YEAR ________ MARK WITH AN X THE PROCEDURE YOU REQUEST: APPLICATION FOR REGISTRATION LIFT THE SUSPENSION A) CURRENT IDENTIFICATION DATA OF THE APPLICANT. RFC KEY NATURAL PERSON LEGAL ENTITY PATERNAL SURNAME, MATERNAL SURNAME, FIRST NAME(S), OR CORPORATE NAME OR BUSINESS NAME STREET NUMBER AND/OR LETTER EXTERIOR NUMBER AND/OR LETTER INTERIOR NEIGHBORHOOD POSTAL CODE PHONE LOCALITY MUNICIPALITY FEDERAL ENTITY MAIN TRADE OR ACTIVITY: MARK WITH AN X IF IT IS 100% EXPORTER SELLER (VENDOR) IN NATIONAL TERRITORY, OF THE MERCHANDISE INDICATED IN THE REQUESTED SECTORS INDICATE WITH AN X IF IT IS PRODUCER PACKAGER MARKETER B) MARK WITH AN X THE NAME OF THE SECTOR OR SECTORS IN WHICH YOU WISH TO REGISTER OR REINCORPORATE.
AUTOGRAF SIGNATURE OF THE LEGAL REPRESENTATIVE OR APPLICANT
36 OFFICIAL GAZETTE Friday, January 17, 2025 Instructions I. Fill clearly the fields indicated. II. Do not exceed the limits of the boxes. III. Present 2 copies of this application duly filled out, comply with the requirements established in article 87 of the Regulation, rule 1.3.7., as well as with the procedure sheets 141/LA Application for registration in the Sectoral Exporters Registry or 142/LA Application to lift the suspension in the Sectoral Exporters Registry, contained in Annex 2. IV. Write the date on which you present your application dd/mm/yyyy. V. Mark with an X the procedure you request: Application for Registration or Application for authorization to lift the suspension. A) CURRENT IDENTIFICATION DATA OF THE APPLICANT. I. Mark with an X if the promoter is a natural person or a legal entity. II. Write the full name, business name or corporate name as appropriate, exactly as it is registered with the RFC; in case of change of corporate name or business name or capital regime, you will write the new data assigned by the ADSC. III. Write the RFC key of the exporter, which is twelve or thirteen positions depending on the case. IV. Write the complete tax address specifying Street, Exterior and interior number, Neighborhood, Delegation or Municipality, postal code, Locality, Federal Entity and Phones. V. Write the main trade or activity. VI. Mark with an X, if you are 100% Exporter or if you are a Seller (Vendor) in National Territory, of the merchandise indicated in the Requested Sectors. VII. Indicate with an X if you are, producer, packager or marketer. B) SECTORS IN WHICH YOU WISH TO REGISTER OR REINCORPORATE. I. Mark with an X the name of the sector or sectors in which you wish to register or lift the suspension to reincorporate, according to the merchandise listed in Annex 10, fraction II, relative to the Sectoral Exporters Registry. C) DATA OF THE LEGAL REPRESENTATIVE. I. Write the full name and the RFC key. II. Write email address and phone number. III. The applicant (interested party or legal representative) shall sign their autograph signature. Documents you must attach: I. Copy of valid official identification and/or notarial instrument that accredits the legal personality of the applicant of the procedure, as appropriate (natural person or legal entity). II. If the legal representative is foreign, attach a copy of the document that proves their legal stay in the country and that accredits that their migratory situation allows them to hold the positions mentioned in the constitutive act or corresponding power of attorney, in accordance with article 65 of the Migration Law. III. Regarding foreign natural persons residing in national territory, include, in addition, a copy of the document through which they prove their migratory situation in the country and that they are authorized to carry out business activities. IV. If the natural person is represented by a third person, attach notarial power of attorney or power of attorney in which they are authorized to carry out this procedure, in accordance with article 19 of the CFF. V. If you changed the corporate name or business name of the company, you must send a copy of the public deed notarized before a Notary Public, in which said change is stated. VI. For the case of the application for registration in the Sectoral Exporters Registry, of Annex 10, fraction II, sectors 8 to 15, the specific requirements indicated in the procedure sheets 141/LA Application for registration in the Sectoral Exporters Registry and 142/LA Application to lift the suspension in the Sectoral Exporters Registry, contained in Annex 2 and in accordance with what is established in the respective Registration Guides for the Sectoral Exporters Registry must be met. Reports and Result Consultation: I. By phone to MarcaSAT: 55 627 22 728 and 01-87-74-48-87-28 for United States and Canada options 7-3. II. Personal attention in the SAT offices located in various cities in the country, on the days and hours established in the following electronic address: https://sat.gob.mx/personas/directorio-nacional-de-modulos-de-servicios-tributarios III. Via Chat: http://chat.sat.gob.mx
Friday, January 17, 2025 OFFICIAL GAZETTE 37 A7. Authorization for the importation of vehicles especially constructed or transformed, equipped with devices or diverse apparatus to fulfill a contract derived from public bidding, (Rule 4.2.9.) Before filling out this form, read the instructions on the back. Resident in territory national. Resident in the foreign country
First Name(s) First Last Name Second Last Name
Business name or corporate name. 1.2. Address for hearing and receiving notifications, as well as the persons authorized for such effects. Street _________________________ No. and/or letter exterior __________ No. and/or letter interior ______________ Neighborhood ________________________ Postal Code _______ Municipality or Delegation __________________ Locality _________________ Federal Entity _____________________ Phones ____________________ Authorized personnel to hear and receive notifications:
Phones _______________________________________________________________________________ 2. Data of the legal representative. RFC Key:
First Name(s) First Last Name Second Last Name Indicate with an x, that you declare, under oath of telling the truth, that the legal representative has the faculties to carry out acts of administration or those necessary to carry out the procedures of this procedure. 3. Information related to the procedure. 3.1. Description of the vehicle to be imported temporarily: Brand: Serial Number: Model: Year: 3.2. Tariff fractions and NICO in which the vehicle object of the authorization is classified: 8705.20.01 00 8705.20.99 00 8705.90.99 00 3.3. In the case of being a resident in the foreign country, indicate the data of the joint responsible in national territory who is up to date with the fulfillment of their tax obligations. Natural Person Legal Entity RFC Key: RFC Key:
First Name(s) First Last Name Second Last Name
Business name or corporate name.
38 OFFICIAL GAZETTE Friday, January 17, 2025 4. Reason or justification for the need to import merchandise:
I declare under oath that the data entered in this form is true.
Name and signature of the applicant (The resident in national territory or the resident abroad or the legal representative) Instructions General Information This form is freely printable and must be filled out in two copies, typed or in block letters, with a black or blue ink pen, and the figures must not invade the limits of the boxes. Presentation Options The procedure must be submitted at the official registry office of the ACAJACE. Via SEPOMEX or using the services of courier and package companies. The procedure takes effect from the date of receipt of the application in accordance with the means of presentation. Specific Indications In the general information section of the applicant, when it concerns a resident abroad, the box must be left blank unless they have an RFC key. Requirements I. Favorable opinion from the SE. II. Service provision contract. When the service provision contract is in a language other than Spanish, it must be accompanied by its translation. III. Call for international public bidding carried out under the free trade treaties to which the Mexican State is a party and which are in force, and the award of the corresponding contract. IV. When the applicant is a resident abroad, they must attach a free-form letter in which a resident in national territory, up to date in the fulfillment of their tax obligations, assumes joint and several liability in accordance with Article 26, fraction VIII of the CFF, for tax credits that may arise in the event of non-compliance with the obligation to return the authorized vehicles. V. Notarial power or articles of incorporation authorizing the legal representative to perform administrative acts, when the applicant is a legal entity. Additional Information on the Procedure Once the form has been submitted duly filled out in compliance with its instructions, the authority will respond via a letter addressed to the applicant, within a period of three months in accordance with Article 37 of the CFF, counted from the date of receipt of the application. For any clarification in filling out this form, you can obtain information on the SAT Portal or contact via 55 12 03 1000 extension 43236, or visit the Taxpayer Assistance Modules of the Decentralized Administration corresponding to your tax domicile. Complaints and reports at 55-88-52-22-22.
Friday, January 17, 2025 OFFICIAL GAZETTE 39 A8. Authorization for rectification of customs declarations
40 OFFICIAL GAZETTE Friday, January 17, 2025 4. Data to be rectified for the declaration: 4.1 Number(s) of declaration(s) 4.2 Field(s) to be rectified (Location and description, as well as fields related to the requested rectification) 4.3 Says 4.4 Must say 5. Indicate the cause of the error in the declaration(s) or the justification for the rectification: 6. List the documentation that supports the error in the declaration(s) or the justification for the rectification: 7. Describe the considerations by which the attached documentation proves the error in the declaration(s) or the justification for the rectification: 8. Indicate, if applicable, the amount of the payment of undue amounts of the operation or operations: 9. State the business reasons that motivated the request: 10. Mark with an X the corresponding option, as appropriate. If affirmative, describe the situation in which it is found: Yes No 10.1. The promotion has been previously raised before the same authority or another different one. 10.2. The promotion has been the subject of any administrative or judicial process. 10.3. It is subject to the exercise of verification powers by the SHCP. 10.4. If item 10.3 is affirmative, indicate whether the declaration(s) of this request are subject to verification powers. 10.5. It is within the period for tax authorities to issue the resolution. 10.6. It is up to date in the fulfillment of its tax obligations and is not published in the lists referred to in articles 69, with the exception of fraction VI and 69-B, fourth paragraph of the CFF. 10.7. It is located at its tax domicile with the RFC. 10.8. It has a tax mailbox. 10.9. It has defense mechanisms filed against the tax mailbox. Once the above has been stated, the ACAJACE is requested to carry out the authorization for rectification in terms of rule 6.1.1.
Name and signature of the applicant or of the legal representative
Friday, January 17, 2025 OFFICIAL GAZETTE 41 Instructions Information that must be provided in each field:
42 OFFICIAL GAZETTE Friday, January 17, 2025 10. Indicate whether the individual or legal entity requesting the procedure is located in any of the following situations and, if affirmative, explain the situation in which it is found. 10.1. Indicate whether the facts or circumstances on which the promotion is based have been previously raised before the same authority or another different one. 10.2. Indicate whether the facts or circumstances on which the promotion is based have been the subject of defense mechanisms before administrative or jurisdictional authorities and, if applicable, the sense of the resolution. 10.3. Indicate whether it is subject to the exercise of verification powers, established in Article 42 of the CFF, indicating the periods and the contributions subject to review. 10.4. Indicate whether the declaration(s) of this request are subject to verification powers, established in Article 42 of the CFF. 10.5. Indicate whether it is within the period for tax authorities to issue the resolution to which Article 50 of the CFF refers. 10.6. It is up to date in the fulfillment of its tax obligations and is not published in the lists referred to in articles 69, with the exception of fraction VI and 69-B, fourth paragraph of the CFF. 10.7. It is located at its tax domicile with the RFC. 10.8. It has a tax mailbox. 10.9. Indicate whether the individual or legal entity requesting has defense mechanisms filed against the tax mailbox. Documents that must be attached: I. Simple copy of the notarial instrument, from which it is evident that the person signing the request for rectification is authorized to carry out the corresponding procedures before the respective authority. II. Simple copy of the official document where the name, photograph and signature appear, which coincides with the physical profile of the legal representative. III. Simple copy of the CFDI or equivalent documents that cover the merchandise described in the declaration(s). IV. The documents referred to in Article 36-A of the Law and, if applicable, the other necessary documents that support its request, which must be contained in a storage device. Additional Information on the Procedure: The resolution letter will be notified to the applicant via tax mailbox, personally or by certified mail. For any clarification in filling out this form, you can obtain information through MarcaSAT at 55 627 22 728; or visit the Taxpayer Assistance Modules of the Decentralized Administration corresponding to your tax domicile. Complaints and reports at 55 88 52 22 22.
Friday, January 17, 2025 OFFICIAL GAZETTE 43 A9. Authorization to import merchandise for national security purposes Before filling out this form, read the instructions on the back.
Telephones
44 OFFICIAL GAZETTE Friday, January 17, 2025 2.2. Reason or justification for the need to import the merchandise:
2.3. Total value of the merchandise (according to the CFDI, equivalent document or letter of donation, as corresponds). ____________________________________________________________________________
2.4. Customs, customs section or place designated for the entry of the merchandise.
2.5. Customs, customs section or place designated for the clearance of the merchandise.
2.6. In case of not having the CFDI or equivalent document or document with which ownership of the merchandise to be imported is demonstrated, indicate with an x that, declares under oath to be the legitimate owner of the merchandise described in the present form: 2.7. Data of the officials authorized to receive the merchandise. RFC Key:
Name(s) First surname Second surname Email
Telephone(s)_______________________________________________________________________________ I declare, under oath, that the data entered in this form is true.
Name and signature of the applicant (Head of the Instance referred to in the National Security Law authorized/ANAM)
Friday, January 17, 2025 OFFICIAL GAZETTE 45 Instructions General Information This form is freely printable and must be filled out in two copies, typed or in block letters, with a black or blue ink pen and the figures must not invade the limits of the boxes. Presentation Options The procedure must be submitted at the official registry office of the ACAJACE. Via SEPOMEX or using the services of courier and package companies. The procedure takes effect from the date of receipt of the application in accordance with the means of presentation. Specific Indications I. In the Section Related to the Procedure: a) In item 2.1., you will indicate the detailed description of the merchandise to be imported, indicating the technical or commercial specifications of the merchandise to be imported, as well as indicating the total quantity (in letters and numbers) of the merchandise to be imported mentioning the unit of measurement of commercialization (kilo, gram, meter, piece, liter, pair, set, etc.). When the space is insufficient, the merchandise can be described in an attached document referencing it in this form. b) In item 2.7., you will indicate the data of the officials authorized to receive the merchandise. In case the space is insufficient, additional boxes can be added to the form. Requirements I. Certificate of appointment of the head of the instance referred to in the National Security Law, of the person designated by him or of the one with powers to represent said head. II. CFDI, equivalent document or document with which ownership of the merchandise to be imported is demonstrated or, if applicable, letter of donation issued by the foreign donor where it indicates the merchandise and the data of said donor [name, Tax Identification Number, address, telephone(s) and email]. III. Catalogs, photographs and other documentation containing data that allow the authority to identify the merchandise subject to importation. IV. Certificate of appointment or letter of designation of the official authorized to receive the merchandise at the customs, customs section or designated place, which must be issued by the instance referred to in the competent National Security Law. V. The documentation with which the exemption or compliance with the regulations or non-tariff restrictions that the merchandise must meet for its definitive importation is accredited. Additional Information on the Procedure Once the form has been submitted duly filled out in compliance with its instructions, the authority will respond via a letter addressed to the applicant, within a period of three months in accordance with Article 37 of the CFF, counted from the date of receipt of the application. Likewise, the authority will send a copy in electronic or digital document to the customs through which the clearance will be carried out. When the ACAJACE detects merchandise that is not necessary to carry out the actions destined to National Security, it will communicate it within five days, counted from the day following the day the authorization request is duly integrated. For any clarification in filling out this form, you can obtain information on the SAT Portal or contact via 55 12 03 1000 extension 43236, or visit the Taxpayer Assistance Modules of the Decentralized Administration corresponding to your tax domicile. Complaints and reports at 55-88-52 -22-22.
46 OFFICIAL GAZETTE Friday, January 17, 2025 B1.
Friday, January 17, 2025 OFFICIAL GAZETTE 47 Instructions I. This form will be filled out typed or in block capital letters, with a black or blue ink pen. II. This form will be filled out in pesos without cents and the amount will be rounded so that amounts of 1 to 50 cents adjust to the unit of the immediate preceding peso and amounts of 51 to 99 cents adjust to the unit of the immediate superior peso. Example: 1) $150.50 = 150 2) $150.51 = 151 III. This form is presented before the customs and its annexes for validation in register 514 of the SAAI and to be able to make the corresponding payment. IV. Individuals when represented for the first time and present a promotion, must attach two copies of the notarial power of attorney that accredits the personality of the applicant and in the case of legal entities they must present two copies of the testimony of the articles of incorporation of the same and two copies of the power that accredits the personality of its representative. V. When another legal representative is designated, they must attach the original and two copies of the power that accredits their appointment. VI. The RFC key will be noted, according to twelve or thirteen positions and the CURP, in the case of individuals who have the Population Registration Key provided by the SEGOB. VII. This form will not be valid if it has strikethroughs, scrapes or amendments. Note: Regarding amounts paid for IGI, DTA, and, if applicable, compensatory quotas, the amount actually paid will be noted in accordance with appendix 13 of Annex 22. In no case can IVA and IEPS in Foreign Trade Operations be compensated, in accordance with Article 138 of the Regulation. Filling out:
48 OFFICIAL GAZETTE Friday, January 17, 2025 3. Data of the original declaration: In this table you will note the No. of declaration to 15 digits, customs section, date of payment of the declaration, IGI, DTA and, if applicable, the Compensatory Quota, noting the total of these concepts in the respective row and finally the key of the operation under the international treaty to which the Mexican State is a Party and which is in force, if applicable, according to appendix 8 of Annex 22. 4. Data of the rectification declaration: In this table you must note the data, following the instructions of point number 3, with the exception of the date of payment of the declaration. 5. Amount susceptible to compensation: In this table you will note the No. of declaration, customs section and date of payment of the declaration on which the compensation is made. The compensation number field is used in the case where the balance in favor obtained from the import is not exhausted when compensating against a single tax, requiring filling out another compensation notice for the remainder of the balance pending to be compensated, in which case they will note the compensation number that is being made. (Example: 1, 2, 3). 6. Data of the legal representative: You will note the paternal surname, maternal surname and name(s) of the legal representative, their RFC key to thirteen digits, their CURP, as well as their signature. Attachments: I. Two copies of the declaration that gave rise to the compensation. II. Two copies of the rectification declaration of the importer. III. Copy of the certificate of origin or certification of origin, if applicable. IV. Two copies of the notice of withdrawal, if applicable. V. Two copies of the notarial power of attorney that accredits the legal personality of the applicant (Individual or Legal Entity). VI. Two copies of the testimony of the articles of incorporation of the legal entity. VII. Tariff Fractions.
Friday, January 17, 2025 OFFICIAL GAZETTE 49 B2. Temporary Export Notice Folio No.: Export Date: ||||||| Return Date: ||||||| Day Month Year Day Month Year Customs/Customs Section: Key:
(Last name paternal/maternal/first name(s), corporate name or business name) Address:
RFC 2. Description and quantity of the merchandise:
Signature of the exporter or legal representative 3. Authorization of the customs/customs section: Name:
Employee badge No.: ___________________________________________
Signature Seal Reviewed by Customs 4. Return Data: Date: _______________________________ Day Month Year Customs/customs section: ______________________________________________________________ Key: ________________________________________ Name: ________________________________________________________________________________ Employee badge No.: _________________
Signature This notice shall be presented in duplicate: the original for the customs office and the copy for the exporter.
50 OFFICIAL GAZETTE Friday, January 17, 2025 Instructions This Notice shall be presented, when there is no obligation to present a petition, in accordance with Article 116, penultimate paragraph of the Law. I. Write clearly, in block letters, with a ballpoint pen (blue or black ink). II. This application must be presented in original and copy. III. Keep your application to be shown at the customs office through which you will effect its return. IV. This document is not valid if it presents scratches or erasures. V. Remember that by providing inaccurate or false data you will be subject to sanctions related to the presumption of smuggling. VI. The folio number will be recorded by the customs authority receiving the temporary export notice. VII. Export Date.- You will record the date of exit of the merchandise from the national territory, indicating the day, month and year. VIII. Return Date.- The date on which the maximum term allowed by the Law or Chapter 4.4. of the RGCE, for the temporary export of the merchandise, will be recorded, indicating the day, month and year. IX. Customs/Customs Section.- You will record the name of the customs or customs section through which the merchandise is exported. X. Key.- You will record the key of the customs or customs section through which the merchandise is exported.
Friday, January 17, 2025 OFFICIAL GAZETTE 51 B3. Notice of temporary import or export and return of containers IMPORT ( ) EXPORT ( ) RETURN ( ) Folio No. DATE OF ENTRY, EXIT OR RETURN: EXPIRATION DATE: ( DD / MM / YY ): ( DD / MM / YY ):
52 OFFICIAL GAZETTE Friday, January 17, 2025 4. CONTAINER DATA: Number of containers: Description: Unit value: SIGNATURE: ______________________________ 5. VALIDATION OF THE IMPORT, EXPORT OR RETURN NOTICE: DATE: Customs/customs section: Key: ( DD / MM / YY ): Name: Employee badge No. Signature Customs/customs section SIGNATURE:
Friday, January 17, 2025 OFFICIAL GAZETTE 53 Instructions General Notes. This application must be presented to the entry or exit customs office in triplicate for validation. I. Complete with block letters and ballpoint pen. II. This document is not valid if it presents scratches or erasures. Whoever performs the operation must indicate the type of operation to be performed (import, export or return) and fill in fields 1, 2, 3, 4 and 6; the remaining fields are for exclusive use of the customs authority. The following data must be filled out by the customs authority: Date of import, export or return. You will record the date of entry, exit or return of the containers to/from national territory, starting with the day, month and year. Expiration Date.- The date on which the temporary import or export expires will be recorded starting with the day, month and year. The importer or exporter will provide the following data: Folio No.- The importer/exporter must assign the folio number, which will consist of a key of 8 digits, as follows: the first 3 digits will correspond to the key and section of the customs office where the procedure is carried out and the following 5 digits will correspond to the consecutive order number of the internal registration of the importer/exporter.
54 OFFICIAL GAZETTE Friday, January 17, 2025 4. Description of the containers: In this box you will record the quantity, unit value, description and other characteristics that allow their identification. Signature.- The person who imports, exports or returns the containers must record their autograph signature. Fields 5 and 7 must be filled out by the customs authority: 5. Authorization of the Customs/Customs Section of the import, export or return: a) Date, Customs, Customs Section and Key.- You will record the date of import, export or return of the containers to/from national territory, starting with the day, month and year; the name and key of the Customs or Customs Section through which the containers are imported, exported or returned. b) Name.- You will record the full name of the person granting the authorization on behalf of the customs. c) Employee badge No.- You will record the personal identification number (badge) of the customs employee who validates the notice. d) Signature.- The employee who validated the notice will record their signature. e) Customs/Customs Section Seal.- In this space the seal of the Customs or Customs Section that validates the import, export or return notice will be placed. 6. Rectification: This field must be filled in for the case of return of containers when some clarification regarding them is appropriate, indicating the folio number involved in the clarification and the observations that apply. 7. Customs/Customs Section intervening in case of rectification: a) Date, Customs, Customs Section and key.- You will record the date on which the rectification is carried out in relation to the return of the containers starting with the day, month and year; the name and key of the Customs or Customs Section through which it is carried out. b) Name.- You will record the full name of the person intervening in the rectification on behalf of the customs. c) Employee badge No.- You will record the personal identification number (badge) of the customs employee intervening in the rectification. d) Signature.- The customs employee intervening in the rectification will record their signature. e) Customs/Customs Section Seal.- In this space the seal of the customs or customs section intervening in the rectification will be placed.
Friday, January 17, 2025 OFFICIAL GAZETTE 55 B4. Notice of introduction of donated merchandise to the country's border strip (Rule 3.3.6., fraction II) REGISTRATION NUMBER:
56 OFFICIAL GAZETTE Friday, January 17, 2025 4. Description of the merchandise. Mark with an X if the merchandise is: New Used Part of your patrimony Description and value: Quantity: Unit Measure: Tariff fraction, and NICO: Brand: Model: Serial number: 5. Purposes to which the merchandise will be destined. Indicate with an X the purposes to which the merchandise will be destined. Cultural Teaching Public health Social service Research Specify. 6. Protest of telling the truth and signature of the person presenting the declaration: I DECLARE UNDER PROTEST OF TELLING THE TRUTH, THAT THE INFORMATION AND DOCUMENTATION PROVIDED IS COMPLETE, CORRECT AND TRUE. NAME AND SIGNATURE: PLACE: DATE: DD MM YYYY 7. FOR OFFICIAL USE ONLY. DD MM YYYY Customs Employee (Name, signature and badge number): Seal of the Customs or Customs Section.
Friday, January 17, 2025 OFFICIAL GAZETTE 57 Instructions This Notice must be filled out electronically, by machine or with block letters if filled out by hand, using blue or black ink and uppercase letters. It must be filled out in duplicate, keeping one copy with the donee and one with the customs or customs section. The format and annexes must be presented at the official office of the customs office through which the operation will be processed. Registration Number.- You must record the Registration Number of the Donee that the Customs assigned to you.
58 OFFICIAL GAZETTE Friday, January 17, 2025 B5. Notice to extend the term granted by the SE to change to the definitive import regime or return to the foreign country temporarily imported merchandise (imported temporarily) (4.3.8.) Before filling out this form, read the instructions on the back.
Corporate name or business name. 1.1. Address for hearing and receiving notifications, as well as the persons authorized for such effects. Street_________________ and/or outer letter _________________ No. and/or inner letter ___________________ Neighborhood ___________________________________________________ Postal Code___________________ Municipality or Territorial Demarcation _________________________ Locality__________________________ Federal Entity ________________________________________ Phones______________________________ Authorized personnel for hearing and receiving notifications_______________________________________________ Phones________________________________________________________________________________ 2. Data of the Legal Representative. Key in the RFC
First Name(s) First Last Name Second Last Name Indicate with an x, that you declare, under protest of telling the truth, that the legal representative has the faculties to perform acts of administration or those necessary to perform the procedures of the present procedure. 3. Information related to the procedure. 3.1. Cancellation of the IMMEX Program. Means of notification of the IMMEX Program cancellation Number of Office or folio Date of notification Day Month Year By Office (personal notification) By Acknowledgment of VUCEM Expiration date of the sixty natural days granted by the SE. Day: Month: Year:
Friday, January 17, 2025 OFFICIAL GAZETTE 59 3.2. If you have a new IMMEX Program, indicate the following: IMMEX Program Number: Date on which the new IMMEX Program was authorized: Day: Month: Year: 3.3. Of the Extension. Indicate the expiration date of the one hundred eighty natural days, of the extension requested in the present form. Day: Month: Year: I declare, under protest of telling the truth, that the data recorded in this form are true.
Name and signature of the applicant (Legal Representative of the Company with IMMEX Program) Instructions General Information. The present form is freely printable and must be filled out in two copies by machine or with block letters, with a ballpoint pen in black or blue ink and the limits of the boxes must not be invaded. Presentation Options. The procedure may be presented at the official office of the ACAJACE. Via SEPOMEX or using the services of courier and package companies. Requirements: I. Office or acknowledgment of cancellation of the IMMEX Program. II. Notification of the cancellation of the IMMEX Program, or the acknowledgment of receipt of the procedure of cancellation issued by the Digital Window. III. Notarial power or articles of incorporation where the legal representative is authorized to perform acts of administration. IV. Authorization of the new IMMEX Program, in case the SE authorizes it within the term of sixty days. Additional information of the procedure. No document is obtained, nevertheless, the acknowledgment of receipt will be obtained. When the notice is presented after the sixty natural days following the date of notification of the cancellation of the respective IMMEX Program, is not accompanied by all the documents indicated in the requirements section and does not comply with the indicated instructions, this will have no legal effect whatsoever. That the IMMEX Program has not been cancelled in terms of article 25 of the IMMEX Decree. When the space is insufficient, the missing information can be written on an attached document, making reference to it. For any clarification in the filling out of this form, you can obtain information on the SAT Portal or contact MarcaSAT 55 627 22 728. Complaints and reports to 55 885 22 222.
60 OFFICIAL GAZETTE Friday, January 17, 2025 B6. Notice for the transfer of auto parts located in the border strip or region to the final automotive or vehicle manufacturing industry for road transport in the rest of the national territory Before filling out this form, read the instructions on the back.
Corporate name or business name. 1.1. Address for hearing and receiving notifications, as well as the persons authorized for such effects. Street No. and/or outer letter No. and/or inner letter ___________ Neighborhood Postal Code ___________________________________ Municipality or Territorial Demarcation___________________________________________________________ Locality ________________________________________________________________________________ Federal Entity ________________________________________________________________________ Phones _______________________________________________________________________________ Authorized personnel for hearing and receiving notifications:
Phones _______________________________________________________________________________ 2. Data of the Legal Representative Key in the RFC:
First Name(s) First Last Name Second Last Name Indicate with an X that you declare, under protest of telling the truth, that the legal representative has the faculties to perform acts of administration or those necessary to perform the procedures of the present procedure.
Viernes 17 de enero de 2025 DIARIO OFICIAL 61 3. Related information with the procedure 3.1. Data of the automotive terminal industry or manufacturing company of transport vehicles that receives the transported merchandise. Legal Entity RFC Key:
Trade name or corporate name. 3.2. Detailed description of the merchandise subject to transport.
3.3. Supply period of the merchandise that has been sold to the automotive terminal industry or manufacturing company of transport vehicles.
dd/mm/yyyy 3.4. Address of the automotive terminal industry or manufacturing company of transport vehicles where the merchandise transport will take place. Street __________________ No. and/or exterior letter ______________ No. and/or interior letter _______________ Neighborhood __________________________________________ Postal Code ___________________________ Municipality or Delegation ___________________________ Locality _________________________________ Federal Entity ________________________________ Phones _______________________________ 3.5. In the case of merchandise susceptible to being individually identified, the following information must be indicated, in order to distinguish them from other similar ones. Serial Number: Part: Brand: Model: The technical or commercial specifications necessary to distinguish said merchandise from other similar ones. I declare, under oath, that the data recorded in this form are true.
Name and signature of the applicant (Legal representative of the legal entity of the Auto Parts Industry Company).
62 DIARIO OFICIAL Viernes 17 de enero de 2025 Instructions General Information This form is freely printable and must be filled out in two copies by machine or with block letters, using a black or blue ink ballpoint pen, and the figures must not invade the limits of the boxes. Presentation Options The procedure may be presented at the official records office of the ACAJACE. It can also be submitted via SEPOMEX or using courier and package delivery services. The procedure takes effect from the date of receipt of the application in accordance with the means of presentation. Specific Indications When the space is insufficient in items 3.2. or 3.5. of the section Related information with the procedure, the missing information can be written on an attached document referencing it. Requirements I. Declaration under oath by the legal representative of the automotive terminal industry or manufacturing company of transport vehicles that receives the merchandise, where it declares: a) That the merchandise has been acquired by the automotive terminal industry or manufacturing company of transport vehicles and assumes joint liability, under article 26, fraction VIII, of the CFF, in case of non-compliance. b) The supply period of the merchandise that has been sold to the automotive terminal industry or manufacturing company of transport vehicles. c) The address of the automotive terminal industry or manufacturing company of transport vehicles where the merchandise transport will take place. d) Detailed description of the merchandise subject to transport for the automotive terminal industry or manufacturing company of transport vehicles located in the rest of the national territory. II. Notarial power of attorney or articles of incorporation authorizing the legal representative of the automotive terminal industry or manufacturing company of transport vehicles to perform acts of administration. III. Notarial power of attorney or articles of incorporation authorizing the legal representative of the auto parts industry company to perform acts of administration. IV. Authorization of the IMMEX Program, issued by the SE, currently valid. Additional Procedure Information No document is obtained, nevertheless, the receipt acknowledgment is granted. The documents that must accompany during the transport of parts and components from the border strip or region to the rest of the country are: I. Original of the acknowledgment of the notice of transport of parts and components from the border strip or region to the rest of the country. II. Original of the CFDI or equivalent document of the merchandise in question, which contains the IMMEX Program number, data of the vehicle in which the merchandise transport is effected, address to which the merchandise will be transported, and it must state that under oath this operation is carried out in terms of rule 4.3.12. For any clarification in filling out this form, you can obtain information on the SAT Portal or contact MarcaSAT: 55 627 22 728. Complaints and reports to 55 885 22 222.
Viernes 17 de enero de 2025 DIARIO OFICIAL 63 B8. Notice of registration of electronic devices and work instruments Customs: __________________________________________ Folio No.: _______________ Each resident in the country must fill out this form. Name: ||_________________ Paternal Surname Maternal Surname First Name(s) Address: || Street No. Neighborhood ___________________|| Postal Code City State R.F.C.____________________________ Date of departure: l__________||_________l Day Month Year Traffic: a) Air ( ) b) Land ( ) c) Maritime ( ) d) Rail ( ) a) Airline and flight number: ______________________________________________________________ b) Passenger road transport line and run: _______________________________________________ c) Maritime line and registration number: ________________________________________________________ d) Railway line and train number: __________________________________________________________ Name of the merchandise Brand Model Serial No. Quantity Made in Observations and/or accessories of the merchandise: I declare under oath that the data recorded in this notice are true. Customs Seal
Signature Name and signature of the customs authority
64 DIARIO OFICIAL Viernes 17 de enero de 2025 Instructions I. If you are a resident in the country and travel abroad or to the border strip or region, you may carry with you electronic devices, or work instruments, necessary for the development of your activity, provided they are instruments or devices that can normally and commonly be transported by a person, in accordance with article 103 of the Regulation. II. If you comply with what is stated in the previous point, you must fill out the registration form for electronic devices or work instruments. III. Once filled out, you must go to the customs module of the airport hall of the locality, to the entry customs by land route, the maritime terminal customs, or the railway terminal customs, in order for it to be stamped and signed by the customs authority. IV. You must record the following data: a) Personal data: you must record the personal data of the resident in the country. b) Date of departure: you will record the date of departure abroad or date of entry into the border strip or region. c) Traffic: you will mark with an X the type of transport you use: air, land, sea, or rail. If by air route: indicate the airline and flight number you are traveling on. If by land route: indicate the passenger road transport line and the run you are traveling on. If by sea route: indicate the maritime line you are traveling on and the Control or Registration No., and if by rail: indicate the railway line you are traveling on and the train number. d) Name of the merchandise: indicate the common name of the merchandise. e) Brand: record the commercial brand of the merchandise. f) Model: to which the merchandise belongs. g) Serial Number: registered on the device or instrument. h) Quantity: record the number of products you are carrying with you. i) Made in: record the country where the merchandise was made. j) Observations: you can record in this field any other data that helps identify the device or instrument. k) Signature: the resident signs this notice. l) Name and signature: in this field, the name and signature of the customs authority authorizing this notice will be recorded. m) Seal: the customs authority will stamp this notice. V. The folio number will be recorded by the customs authority authorizing the notice. If you wish to report any irregularity in the behavior of the customs authority, you can communicate it to the following phone number 55 88 52 22 22.
Viernes 17 de enero de 2025 DIARIO OFICIAL 65 B9.
66 DIARIO OFICIAL Viernes 17 de enero de 2025 Instructions Main header of the notice: Field Content
Viernes 17 de enero de 2025 DIARIO OFICIAL 67 Merchandise Block:
68 DIARIO OFICIAL Viernes 17 de enero de 2025 B10. Notice of transport of merchandise from companies with IMMEX Program, RFE or Authorized Economic Operator Folio of the notice Type of Operation Type of Transport Date of Preparation Data of the Company that transfers Certification RFC Key Program Number Corporate name or trade name Address of the origin plant or warehouse Data of the Receiving Company RFC Key Program Number Corporate name or trade name Barcode Address of the destination plant or warehouse Data of the merchandise that is transferred Sequence Commercial Description Unit of Measure of commercialization Quantity Value in dollars Customs of exit of the merchandise Data of the person who prepares the notice e.firma Name CURP Serial Number Notice of transport of merchandise from companies with IMMEX Program, RFE or Authorized Economic Operator, in accordance with rules 4.3.6., 4.8.11. and 7.3.3., fraction XXI. Page of
Viernes 17 de enero de 2025 DIARIO OFICIAL 69 Instructions Header of the transport notice, for the main page and secondary pages, if applicable. Field Content
70 DIARIO OFICIAL Viernes 17 de enero de 2025 Data of the receiving company: 9. RFC Key RFC Key of the company that receives the merchandise. 10. Program Number IMMEX Program Number of the company that receives the merchandise, if applicable. In case of submanufacturing or subcontracting operations or repair or maintenance company it is declared null. 11. Corporate name or trade name Corporate name or trade name of the company that receives the merchandise. 12. Address of the plant or warehouse destination Address of the plant or warehouse where the transferred merchandise is received. Data of the merchandise that is transferred: 13. Sequence Number of the sequence of the merchandise in the notice. 14. Commercial description Commercial description of the merchandise necessary and sufficient, to physically identify the merchandise. 15. Unit of measure of commercialization Key corresponding to the unit of measure of commercialization of the merchandise, according to Appendix 7 of Annex 22. 16. Quantity Quantity of merchandise according to the unit of measure of commercialization. 17. Value in dollars Commercial value of the merchandise expressed in dollars of the United States of America. 18. Exit Customs. Indicate the Customs through which the temporary export of the merchandise will be carried out, in accordance with rule 7.3.3., fraction XXI. General Data: 19. Barcode The barcode formed by must be recorded: Folio of the notice: 1 digit, corresponds to the last digit of the current year. 7 digits, annual consecutive number assigned by the person who transfers the merchandise. This numbering must start with 0000001. RFC Key of the person who transfers the merchandise. Validation acknowledgment generated by the SAAI. After each field, including the last one, the control characters, carriage return and line feed must be presented. NOTE: Does not apply, regarding the field Type of operation, item 3. Data of the person who prepares the notice: 20. Name Name of the person who prepares the notice. 21. CURP CURP of the person who prepares the notice. 22. Serial Number Serial number of the certificate of their e.firma of the person who prepares the notice. 23. e.firma Electronic signature of the electronic notice, generated by the person who prepares it.
Viernes 17 de enero de 2025 DIARIO OFICIAL 71 B11. Notice of transport of merchandise from companies with IMMEX Program in the modality of Authorized Economic Operator subject control of companies Folio of the Notice RFC Key and corporate name or trade name of the Corporate Controller Program Number Data of the company that transfers Certification RFC Key Corporate name or trade name Address of the origin plant or warehouse Data of the receiving company RFC Key Corporate name or trade name Electronic validation acknowledgment Date and time of validation Address of the destination plant or warehouse Barcode Data of the merchandise that is transferred Sequence Unit of measure Quantity Description Name and CURP of the legal representative who authorizes the notice Notice of transport of merchandise from companies with IMMEX Program in the modality of corporate controller in accordance with rule 7.3.4., fraction II, subsection b). Page of
72 DIARIO OFICIAL Viernes 17 de enero de 2025 Instructions Header of the transfer notice, for the main page and the secondary pages if applicable Field Content
Friday, January 17, 2025 OFFICIAL GAZETTE 73 B12. Import and Export Electronic Notice Patent or Authorization Dispatch Customs Entry No. Notice Folio Certification Means of Transport RFC Key of the Carrier Economic Number License Plates Description of the merchandise Barcode Unit of Commercialization Measure Quantity e.firma Instructions Header of the notice for the main page and secondary pages, if applicable Field Content
74 OFFICIAL GAZETTE Friday, January 17, 2025 4. Notice Folio. Consecutive number per entry that the customs broker or customs agency, customs attorney, importer or exporter, assigns to the shipment. General Data: Field Content
Friday, January 17, 2025 OFFICIAL GAZETTE 75 B13. Volumetric Storage Capacity Notice (Rule 2.3.8.) Before filling out this request, read the instructions on the back. Number of official document with which the authorization or concession was granted Date of the official document dd/mm/yyyy
RFC Key including the homoclave
LEGAL REPRESENTATIVE DATA 2. Legal representative data Paternal surname Maternal surname Name RFC Key including the homoclave
Phone Email Indicate with an x, that you declare, under oath, that the legal representative has the authority to perform acts of administration or those necessary to carry out the procedures for this process. AUTHORIZED SURFACE AND OCCUPIED VOLUMETRIC CAPACITY DATA 3. Authorized surface and occupied space Total authorized surface m2 Volumetric storage capacity m3 Occupied volumetric space 18% 20% Attach the following documentation: I.- Photographic support where the 18% space as well as the 20% of the volumetric capacity of occupied storage is visible. II.- Copy of the Authorization official document and, if applicable, official document of extension or of surface expansion. III.- Copy of the notarial testimony of the power, by which the person signing the document is authorized, to perform acts of administration or power of attorney signed before two witnesses and ratified the signatures of the grantor and witnesses before the tax authorities, notary or public official. IV.- Copy of the taxpayer or legal representative's identification, prior to checking with the original. I declare, under oath, that the data entered in this application is true.
Name and signature of the applicant (Legal Representative of the Legal Entity)
76 OFFICIAL GAZETTE Friday, January 17, 2025 Filling Instructions The form must be presented before the Customs corresponding to the territorial jurisdiction where the authorized or concessioned party is located. For the purposes of article 15, fraction IV of the Law, legal entities that have authorization or concession to provide the services of handling, storage and custody of merchandise, must indicate the following: Provide the number and date of the official document with which the authorization was granted, and if applicable, the corresponding extension: I. Data of the holder of the authorization or concession. The Name, Denomination or Trade Name and their twelve-position RFC key must be entered. II. You must provide the full name, RFC key, phone and email of the legal representative of the authorized or concessioned legal entity. III. You must register the total authorized surface taking into account, if applicable, the expansion or reduction of: a) The surface expressed in square meters (m 2 ), b) The volumetric storage capacity expressed in cubic meters* c) The volumetric space effectively occupied (18% and 20%)
Friday, January 17, 2025 OFFICIAL GAZETTE 77 B16. Electronic Rejection Notice (Rule 1.8.2.) GENERAL DATA RFC Key Pre-validator Trade Name REJECTION DETAIL LEVEL Name Provider Rejection Reason Rejection Date Instructions for filling out the Electronic Rejection Notice format (Rule 1.8.2.) Those authorized to provide the services of electronic pre-validation of the data entered in the entries according to rule 1.8.1., have the obligation to fill out this format, if as a result of the review of the vehicle history, the vehicle does not meet the conditions to be imported in accordance with rule 3.5.1., fraction II. · Columns and/or rows cannot be added or removed. · Sheets cannot be added or the name changed (Rejection). · Use one file per rejection. · All data is required. The following fields will be filled in, as indicated below: General Data: Field Content RFC Key Indicate the RFC key of the authorized (13 positions) to provide the services of electronic pre-validation of the data entered in the entries according to the rule 1.8.1. Example: AAAA010101XXX. Trade Name Indicate the Trade Name corresponding to the RFC key of the Authorized who provides the services of electronic pre-validation of the data entered in the entries according to rule 1.8.1. Rejection Detail: NIV Indicate the Vehicle Identification Number, which corresponds to the combination of alphanumeric characters assigned by the manufacturers or assemblers of vehicles, for identification purposes.
78 OFFICIAL GAZETTE Friday, January 17, 2025 Provider Name Indicate the name of the company providing vehicle background information in the country of origin, with which the consultation was made, as it appears on the internet page of said provider. Example: Carfax. Rejection Reason Indicate only the numeral corresponding to the reason for rejection, using for this the Rejection Reasons catalog. Rejection Date Write the rejection date of the vehicle with a date format dd/mm/yyyy (already configured in the format file). Example: 15/10/2016. Rejection Reasons Catalog: Numeral Description 1 Stolen. 2 Damaged. 3 Restricted or prohibited for circulation in the country of origin, in any of the following conditions: 3.01 Parts only. 3.02 Assembled parts. 3.03 Total loss. Except when it concerns vehicles whose title is of the Salvage type, as well as those that additionally bear the labels clean; rebuilt/reconstructed; or corrected. 3.04 Dismantlers. 3.05 Destruction. 3.06 Non repairable. 3.07 Non rebuildable. 3.08 Non street legal. 3.09 Flood. Except when it additionally bears the labels clean; rebuilt/reconstructed; or corrected. 3.10 Junk. 3.11 Crush. 3.12 Scrap. 3.13 Seizure / Forfeiture. 3.14 Off-highway use only. 3.15 Water damage / water damage. 3.16 Not eligible for road use.
Friday, January 17, 2025 OFFICIAL GAZETTE 79 3.17 Recovered (Salvage), when it concerns the following types: Except when it concerns vehicles whose title is of the Salvage type different from those indicated here, as well as those that additionally bear the labels clean; rebuilt/reconstructed; or corrected. 3.17.1 - DLR SALVAGE. 3.17.2 - SALVAGE-PARTS ONLY. 3.17.3 - LEMON SALVAGE. 3.17.4 - SALVAGE LETTER-PARTS ONLY. 3.17.5 - FLOOD SALVAGE. 3.17.6 - SALVAGE CERT-LEMON LAW BUYBACK. 3.17.7 - SALVAGE CERTIFICATE-NO VIN. 3.17.8 - SALVAGE TITLE W/ NO PUBLIC VIN. 3.17.9 - DLR/SALVAGE TITLE REBUILDABLE. 3.17.10 - SALVAGE THEFT. 3.17.11 - SALVAGE TITLE-MANUFACTURE BUYBACK. 3.17.12 - COURT ORDER SALVAGE BOS. 3.17.13 - SALVAGE / FIRE DAMAGE. 3.17.14 - SALVAGE WITH REPLACEMENT VIN. 3.17.15 - BONDED SALVAGE. 3.17.16 - WATERCRAFT SALVAGE. 3.17.17 - SALVAGE KATRINA. 3.17.18 - SALVAGE TITLE WITH ALTERED VIN. 3.17.19 - SALVAGE WITH REASSIGNMENT. 3.17.20 - SALVAGE NON REMOVABLE. 3.18 Stolen (Stolen). Only when the title indicates that it was recovered (recovered), and this last state remains in force. 3.19 Frame Damage. 3.20 Fire Damage. 3.21 Recycled. 3.22 Crash Test Vehicle. 4 Others.
80 OFFICIAL GAZETTE Friday, January 17, 2025 C2. Certificate of Origin of Agricultural Products Date: ||||||| Day Month Year Fill in by machine or block letters. 1.- Name and address of the ejidal commissioner, the representative of the colonists or communal members, of the agricultural or livestock association. Name:
Address:
RFC Key, if applicable:
2.- Population to which they are destined:
Municipality:
State:
3.- Description of the merchandise 4.- Quantity 5.- Weight 6.- Volume I declare under oath that:
Signature Seal
Friday, January 17, 2025 OFFICIAL GAZETTE 81 C3. Certificate of Transfer of Goods
82 OFFICIAL GAZETTE Friday, January 17, 2025 B. PARTS AND COMPONENTS EXPORTED TO COUNTRIES OTHER THAN THE UNITED STATES OF AMERICA, CANADA, MEMBER STATES OF THE COMMUNITY OR OF THE EFTA. 21. PART NUMBER 22. DESCRIPTION 23. EXPORTED QUANTITY 24. NO. EXPORT ENTRY 25. DATE OF THE EXPORT ENTRY 26. CUSTOMS OF THE EXPORT ENTRY 27. NAME AND SIGNATURE OF THE LEGAL REPRESENTATIVE BACK
Friday, January 17, 2025 OFFICIAL GAZETTE 83 C. PARTS AND COMPONENTS EXPORTED TO THE UNITED STATES OF AMERICA, CANADA, MEMBER STATES OF THE COMMUNITY OR OF THE EFTA.
PART NUMBER 29. DESCRIPTION 30. EXPORTED QUANTITY 31. NO. EXPORT ENTRY 32. DATE OF THE EXPORT ENTRY 33. CUSTOMS OF THE EXPORT ENTRY 2. MEMBER STATES OF THE COMMUNITY PART NUMBER DESCRIPTION EXPORTED QUANTITY NO. EXPORT ENTRY DATE OF THE EXPORT ENTRY CUSTOMS OF THE EXPORT ENTRY 3. MEMBER STATES OF THE EFTA PART NUMBER DESCRIPTION EXPORTED QUANTITY NO. EXPORT ENTRY DATE OF THE EXPORT ENTRY CUSTOMS OF THE EXPORT ENTRY 34. NAME AND SIGNATURE OF THE LEGAL REPRESENTATIVE BACK
84 OFFICIAL GAZETTE Friday, January 17, 2025 Instructions This form must be filled in by machine or with uppercase block letters, with a black or blue ink ballpoint pen and the digits must not invade the limits of the boxes. This form will not be valid if it presents strikethroughs, scratches or amendments.
Friday, January 17, 2025 OFFICIAL GAZETTE 85 B. Parts and components exported to countries other than the United States of America, Canada, Member States of the Community or of the EFTA: 21. Part number: write the part number, series or lot that corresponds to the part or component acquired from the auto parts industry company, which must coincide with that indicated in the CFDI, equivalent document or document that covers the physical delivery of the part or component. 22. Description of the part or component: you will write the description of the part or component, in case the space is insufficient you may present attached sheet(s), always that you write the number of sheets that make up the annex, in the corresponding box. 23. Exported Quantity: you will write the total quantity of each part or component exported. 24. Export Entry: the one corresponding to the entry that covers the export of the part or component or of the vehicle to which each part or component is incorporated. 25. Date of the export entry. 26. Customs of the export entry: you will write the name of the customs or customs section corresponding. 27. Name and Signature of the Legal Representative. Original: for the receiving company. Copy: for the person issuing the certificate. Important note: The certificate must be printed on letterhead paper of the issuing company. C. Parts and components exported to the United States of America, Canada, Member States of the Community or of the EFTA: 28. Part number: you will write the part number, series or lot that corresponds to the part or component acquired from the auto parts industry company, which must coincide with that indicated in the CFDI, equivalent document or document that covers the physical delivery of the part or component. 29. Description of the part or component: you will write the description of the part or component, in case the space is insufficient you may present attached sheet(s), always that you write the number of sheets that make up the annex, in the corresponding box. 30. Exported Quantity: you will write the total quantity of each part or component exported. 31. Export Entry: the one corresponding to the entry that covers the export of the part or component or of the vehicle to which each part or component is incorporated. 32. Date of the export entry. 33. Customs of the export entry: you will write the name of the Customs or Section corresponding. 34. Name and Signature of the Legal Representative. Original: for the receiving company. Copy: for the person issuing the certificate. Important note: The certificate must be printed on letterhead paper of the issuing company.
86 OFFICIAL GAZETTE Friday, January 17, 2025 D2.
Friday, January 17, 2025 OFFICIAL GAZETTE 87
88 OFFICIAL GAZETTE Friday, January 17, 2025
Friday, January 17, 2025 OFFICIAL GAZETTE 89
90 OFFICIAL GAZETTE Friday, January 17, 2025 D3.
Friday, January 17, 2025 OFFICIAL GAZETTE 91
92 OFFICIAL GAZETTE Friday, January 17, 2025 D4.
Friday, January 17, 2025 OFFICIAL GAZETTE 93
94 OFFICIAL GAZETTE Friday, January 17, 2025
Friday, January 17, 2025 OFFICIAL GAZETTE 95
96 OFFICIAL GAZETTE Friday, January 17, 2025
Friday, January 17, 2025 OFFICIAL GAZETTE 97
98 OFFICIAL GAZETTE Friday, January 17, 2025
Friday, January 17, 2025 OFFICIAL GAZETTE 99
100 OFFICIAL GAZETTE Friday, January 17, 2025 D5.
Friday, January 17, 2025 OFFICIAL GAZETTE 101
102 OFFICIAL GAZETTE Friday, January 17, 2025
Friday, January 17, 2025 OFFICIAL GAZETTE 103 D6. Origin document for extracted, industrialized or manufactured mineral products Date: ||||||| Day Month Year Fill in by machine or block letters. TO BE FILLED BY THE INTERESTED PARTY 1.- Name, trade name or corporate name and tax domicile of the individual or legal entity: Name:
Address:
RFC Key:
2.- Population to which they are destined:
Municipality:
State: _________________________________________________________________________________ 3.- Place where the products subject to the entry of the border strip or region to the rest of the country are extracted, manufactured, or industrialized.
4.- Description of the merchandise 5.- Quantity 6.- Weight 7.- Volume 8.- I declare under oath that:
Signature of the interested party or their legal representative EXCLUSIVE FOR OFFICIAL USE 9.- Signature of presentation before the customs office. Name of the customs office:___________________________________________ Customs office key: ____________________________________________ Employee name: __________________________________________ Employee badge number:
Signature Seal
104 OFFICIAL GAZETTE Friday, January 17, 2025 D7.
Friday, January 17, 2025 OFFICIAL GAZETTE 105
106 OFFICIAL GAZETTE Friday, January 17, 2025
Friday, January 17, 2025 OFFICIAL GAZETTE 107
108 OFFICIAL GAZETTE Friday, January 17, 2025
Friday, January 17, 2025 OFFICIAL GAZETTE 109
110 OFFICIAL GAZETTE Friday, January 17, 2025 D8. Temporary import entry for trailers, semi-trailers and container chassis Entry Number Consecutive Number by Transport Company Economic Number Data of the Transport Company. Certifications Name, trade name or corporate name: R.F.C.: Tax Domicile: Data of the Authorized Company. Name, trade name or corporate name: R.F.C.: Data of the Unit. Transport Date of issue Brand Model Time of issue Line Economic No. Electronic Signature Serial No. License Plate No. Barcode Nominal value Tariff fraction. Type Unit This document must be presented by the interested party, both at the time of its introduction to national territory, and upon RETURN of the vehicle, for certification by the electronic computing system printer of the SAT, without which the annotations of introduction and return appearing in this Temporary Import Entry will not be valid; based on articles 16-B and 107 of the Law, 19 and 21 of the Internal Regulations of the SAT, as well as rule 4.2.1. I declare under oath that I will return, within the legal deadline, the vehicle described above, aware that if I do so late I will be subject to the sanction established in article 183, fraction II of the Law, and that I will abstain from committing infractions or crimes related to the improper use or destination of said vehicle during its stay in national territory. Likewise, I declare under oath that the data recorded is true.
Name and Signature
Friday, January 17, 2025 OFFICIAL GAZETTE 111 Instructions Field Content I. Name, trade name or corporate name of the transport company. Name, trade name or corporate name of the transport company that requests the temporary import. II. RFC Key of the transport company. RFC Key of the transport company. In cases where the temporary import is carried out by a foreigner, the key EXTR920901TS4 will be noted. III. Tax domicile of the transport company. Tax domicile of the transport company, or, if it is a foreigner, the address that appears in the official documents, composed in case of the street, number exterior, interior number, postal code, municipality, city Federative Entity and country. IV. Name, trade name or corporate name of the authorized company. The name, trade name or corporate name of the company authorized by the ANAM, in terms of article 16- B of the Law, must be noted. V. RFC Key of the authorized company. RFC Key of the company authorized by the ANAM, in terms of article 16-B of the Law. VI. Data of the unit. The type of transport (road, railway, maritime), brand, model, line, economic number, serial number, license plate number, nominal value, tariff fraction, unit type (trailer, semi-trailer or container chassis) must be noted. In the case of the serial number, only the digits should be printed in parentheses. VII. Entry number. Folio number integrated by: I. A digit to indicate the Authorized Company key. II. Three digits to indicate the Customs Office Key. III. A digit to indicate the last digit of the current year. IV. Six more digits for the annual consecutive number by Customs Office assigned by the authorized company issuing the entry. Each of these groups of digits must be separated two blank spaces, except between the digit that corresponds to the last digit of the current year and the six digits of the progressive numbering. VIII. Consecutive by transport company. Consecutive entry number processed by the Transport Company per year. IX. Date of Issue. Day, month and year in which the validation of the Entry is carried out by the Integrated Administrative Software (SAIT). X. Time of Issue. Hours, minutes and seconds in which the validation of the Entry is carried out by the SAIT. XI. Electronic Signature. Electronic Signature generated by the SAIT. XII. Barcode. SAIT Key with 2 characters (numeric), Customs Office key with 3 characters (numeric), folio of the temporary import entry for trailers, semi-trailers and container chassis up to 7 characters (alphanumeric) and Electronic Signature generated by the SAIT up to 7 characters (alphanumeric). After each field, including the last, the control characters, carriage return and line feed must be presented. XIII. Name and signature. Signature of the transporter, legal representative or person authorized by the legal representative.
112 OFFICIAL GAZETTE Friday, January 17, 2025 E1. Official seal for internal air transit control MINISTRY OF FINANCE AND PUBLIC CREDIT United Mexican States National Agency of Customs of Mexico Merchandise in Transit Warning: The merchandise contained in this package is under fiscal control and must be delivered to the destination customs office personnel. Whoever violates, alters or destroys the content of this package or detaches this label, will be sanctioned in accordance with articles 186, fractions I and II and 187, fraction I of the Law and 113, fraction I of the CFF. The same sanctions will be imposed to those who tolerate these acts. Dimensions: 7cm. Width. 14 cm. Length. Color: Fluorescent orange background. Legends in black color.
E3. Company Profile Acknowledgment of Receipt First Time: Renewal: Addition: Modification: The data provided will replace the data provided when you requested your authorization. General Information. The objective of this Profile is to ensure that companies implement security practices and processes that ensure their supply chain to mitigate the risk of contamination of their merchandise with illicit products. Companies interested in obtaining their registration in the Registry of the Company Certification Scheme in the Authorized Economic Operator modality under the headings of Importer and/or Exporter, Holding Company, Aircraft, SECIIT, Textile and Logistics Outsourcing referred to in rule 7.1.4., must demonstrate that they have documented and verifiable processes required in this document according to the model or business design they have established according to a risk management, seeking during the implementation of minimum security standards the application of a culture of analysis that supports preventive and reactive decision-making against threats and/or risk circumstances in accordance with the values, mission, vision, codes of ethics and conduct of the company itself. Filling Instructions: I. You must fill out a Profile for each of the facilities that operate under the same RFC, where they carry out manufacturing processes of products of foreign trade and, in their case, of those facilities related as: industrial and/or manufacturing plants, warehouses, distribution centers, consolidation among others. This information must coincide with what is stated in your Registration Request in the Company Certification Scheme. II. Detail how the company complies with or exceeds what is established in each of the numerals as indicated. III. The format of this document is divided into two sections, as detailed below:
Installation Information. Profile Number of the company: of RFC Key: Name and/or Corporate Name: Name and/or Denomination of the Installation Type of Installation Street Number and/or exterior letter Number and/or interior letter Neighborhood Postal Code Municipality/Delegation Federative Entity Age of the plant (years of operation): Predominant activity of the plant: Products that it manufactures or handles in this plant: (As applicable) Avg. number of monthly shipments (EXP): (By means of transport) Avg. number of monthly shipments (IMP): (By means of transport) Total number of employees in this installation: Installation surface (m2 ): Certifications in security programs: (Indicate if this installation has a certification from any of the following programs) CTPAT Yes No Level: Pre-Applicant: Applicant: Certified: Certified/Validated: CTPAT Account number (8 digits): Manufacturer Identification Code (MID): Date of last visit in this installation: Authorized Economic Operator from other countries (AEO): Yes No Program: Registration: Other supply chain security programs: Yes No Program: Registration:
Certifications: (Indicate if you have certifications that you consider impact your supply chain process, for example: ISO 9000; Reliable Logistics Processes, among others) Name: Category: Validity: Name: Category: Validity:
Response: Explanatory Notes: Indicate which are the sources of information used to qualify risks during the analysis phase. Attach the risk matrix, as well as the documented procedure to identify risks in the supply chain and the installations of your company, which must include as a minimum the following points: I. Periodicity with which it reviews and/or updates the risk analysis. II. Aspects and/or areas of the company that are incorporated into the risk analysis. III. Methodology or techniques used to perform the risk analysis. IV. Responsible for reviewing and/or updating the risk analysis of the company. Likewise, the documented procedure to identify risks in the supply chain and its facilities, should contemplate the risk appreciation and management process, and include the following aspects: I. Establishment of a context (cultural, political, legal, economic, geographic, social, etc.). II. Identification of risks in its supply chain and its facilities. III. Risk analysis (causes, consequences, probabilities and existing controls to determine the level of risk as high, medium and low). IV. Risk evaluation (decision making to determine the risks to be treated and priority to implement the treatment). V. Risk treatment (application of alternatives to change the probability that risks occur).
VI. Risk monitoring and review (monitoring of the results of the risk analysis and verification of the effectiveness of its treatment). It is suggested to use the administration, management and risk evaluation techniques according to the international standards ISO 31000, ISO 31010 and ISO 28000 that, according to your business model, you should implement. 1.2 Security policies. The company must have a policy oriented to prevent, ensure and recognize threats in the security of the supply chain and installations of the company, such as drug trafficking, money laundering, arms trafficking, human trafficking, prohibited merchandise and acts of terrorism. To promote a culture of security, companies must demonstrate their commitment to supply chain security and the Authorized Economic Operator Program through a statement highlighting the importance of protecting the flow of national and international commerce from criminal activities, established through the security policy. The senior officials or executives of the company who must endorse and sign the security policy, can be the president of the company, the director executive, the general manager or personnel with a homologue position with decision-making authority. Response: Explanatory Notes: State the security policy oriented to prevent, ensure and recognize threats in the supply chain and installations of the company, indicate who is responsible for its review, signature and dissemination to employees, as well as the periodicity with which its update is carried out. This policy must be communicated to employees through a program and/or dissemination campaign. The security policy must be signed by a senior official of the company and be displayed in various areas of the company, including the company website, posters in key areas of the company (reception, shipments, receipts, warehouse, etc.), and as part of the company's initial and reinforcement training.
1.3 Internal Audits in the Supply Chain. In addition to routine monitoring in control and security, it is necessary to schedule and conduct periodic audits, which allow for the evaluation of all processes regarding security in the company's supply chain in a more critical and in-depth manner, as well as to ensure that employees follow the company's security procedures. Audits must be carried out by the Company's Security Committee, establishing a documented procedure, as well as a program or schedule for their execution. Although it is necessary that the audits be focused on supply chain security and based on the evaluation, review, and execution of minimum security standards, their focus must be adjusted to the size of the organization, risk level, business model, and variations between facilities. Audits can be general or focus on specific areas or processes according to their work program. The objective of an internal audit focused on the Authorized Economic Operator Program is to verify and ensure that employees follow the company's security procedures. The review process does not have to be complex; however, the formats and records used for the application of these reviews must evidence that the application and execution of the evaluated processes were validated, as well as the follow-up and closure of preventive, corrective, and improvement actions identified. The organization's senior management must review the results of the audits and undertake the required corrective or preventive actions. The audit process must ensure that the necessary information is collected to allow management to perform this evaluation. The review must be documented, and the company's Security Committee must provide and register periodic updates on the progress or results of any audit, exercise, or validation. Answer: Explanatory Notes: Describe the documented procedure to carry out an internal audit focused on supply chain security; ensure you include the following points: I. Indicate how the company carries out the scheduling or calendarization to perform an internal audit on supply chain security. II. Indicate who participates in them, the records kept thereof, and the frequency with which they are carried out. III. Indicate how the company's management verifies the results of security audits, how it carries out and/or implements preventive, corrective, and improvement actions, as well as the follow-up and closure thereof. IV. The formats used during internal audits must be duly completed, and through them, evidence that security procedures and measures are being put into practice.
1.4 Contingency and/or Emergency Plans. A documented contingency and/or emergency plan must exist; this plan must address crisis management, security recovery plans, and the resumption of operations to ensure business continuity in the event of a situation that affects the normal development of activities and foreign trade operations of the company in its supply chain. A crisis or contingency may include the interruption of the transmission and exchange of commercial data due to a cyberattack, a fire, the kidnapping of a transport driver by armed persons, (a customs closure, a bomb threat, the detection of suspicious packages, a power outage, theft and/or damage to goods, threats or extortion, blockades or road closures, among others). Such plans must be communicated to personnel through periodic training, as well as conducting tests, practical exercises, and annual drills of the contingency and emergency plans to verify their effectiveness; records must be kept of these, duly completed and signed (for example: result reports, minutes, or reports, which must be supported by video recordings, photographs, etc., that demonstrate their execution). The contingency and/or emergency plan must be updated as necessary, based on changes in operations and the organization's risk level. Answer: Explanatory Notes: Attach the documented contingency and/or emergency plan to ensure business continuity in the event of an emergency or security situation that affects the normal development of the company's foreign trade activities. This procedure must include, by way of example and not limitation, the following: I. What situations it covers, describing the action plan and steps to be followed in case of crisis, as well as the tasks assigned to personnel during the handling of such contingencies. II. What mechanisms it uses to disseminate and ensure that these plans are effective. III. Include the scheduling and execution of tests, practical exercises, and annual drills and how they are documented (for example: result reports, minutes, or reports, which must be accompanied by video recordings, photographs, etc., that demonstrate their execution).
2.3 Perimeter Fences. Perimeter fences and/or peripheral barriers must be installed to ensure the parameters of the company's facilities, according to a risk analysis. Fences, interior barriers, or a mechanism must be used to identify and segregate international cargo, as well as high-value and dangerous cargo. These must be inspected regularly and carry a record of the review with the aim of ensuring their integrity and identifying damage, which must be repaired as soon as possible by the personnel designated for these tasks. Storage areas, high-value, dangerous, and/or restricted-access areas must be clearly identified and monitored to prevent unauthorized entry. Answer: Explanatory Notes: Describe the type of fence, peripheral barrier, and/or walls that the company has; ensure you include the following points: I. Specify which areas are segregated. II. Indicate their characteristics (material, dimensions, etc.). III. In case of not having walls, justify the reason in detail. IV. Frequency with which the integrity of the perimeter walls is verified and the records kept with the aim of ensuring their integrity and identifying damage, which must be repaired as soon as possible. V. Indicate the personnel or area responsible for carrying out the tasks of inspection and repair of damage. Describe how the cargo destined for foreign countries, dangerous material, and high-value material are segregated; ensure you include the following points: I. Indicate how you separate national merchandise and foreign trade merchandise, and if it is additionally identified (for example: different packaging, labels, wrapping, among others). II. Identify and indicate the restricted-access areas (dangerous goods, high value, confidential, etc.).
The procedure for inspecting perimeter fences could include: I. Personnel responsible for carrying out the process. II. How and how often inspections of fences, perimeter walls, and/or peripheral barriers and buildings are carried out. III. How the inspection record is kept. IV. Who is responsible for verifying that repairs and/or modifications meet the technical specifications and necessary security requirements. 2.4 Parking Lots. Access to the facility parking lots must be controlled and monitored by security personnel or personnel designated for this task. Private vehicles (of employees, visitors, suppliers, contractors, among others) must be prohibited from parking within the merchandise handling and storage areas, as well as in adjacent areas. Answer: Explanatory Notes: Describe the procedure for the control and monitoring of parking lots; ensure you include the following points: I. Those responsible for controlling and monitoring access to the parking lots. II. Identification of the parking lots (specify if the visitor and employee parking is separated from the merchandise storage and handling areas). III. How entry and exit of vehicles to the facilities is controlled. Indicate the records made for parking control, the existing control mechanisms (for example: key cards, card readers, badges, etc.), how they are assigned, and the responsible area for doing so. IV. Policies or mechanisms to prevent the entry of private vehicles into the merchandise storage and handling areas.
2.5 Key and Lock Device Control. Windows, doors, as well as interior and exterior fences, according to their risk analysis, must be secured with locking devices. The company must have a documented procedure for the handling and control of keys and/or locking devices for interior areas considered critical. Likewise, they must keep a record and establish signed responsibility letters by persons who have keys or authorized access according to their level of responsibility and duties within their work area. Answer: Explanatory Notes: Indicate if all doors, windows, interior and exterior entrances have closing or security mechanisms. Attach the documented procedure for the handling and control of keys and/or locking devices; ensure it includes the following points: I. Those responsible for administering and controlling key security. II. Format and/or control record for key lending. III. Treatment of loss or non-return of keys. IV. Indicate if there are areas where access is gained with electronic devices and/or any other access mechanism. 2.6 Lighting. Lighting inside and outside the facilities must allow for clear identification of people, material, and/or equipment located therein, including the following areas: entrances and exits, handling, loading, unloading, and storage areas for merchandise, perimeter and/or peripheral fences, interior fences, and parking areas, and must have an emergency and/or backup system in sensitive areas. Answer: Explanatory Notes: Describe the procedure for the operation and maintenance of the lighting system; ensure you include the following points: I. Indicate which areas are illuminated and which have a backup system (indicate if you have an auxiliary power plant or any other mechanism to supply electricity in case of any contingency).
II. How you ensure that the lighting system is appropriate in each of the company's areas, so as to allow clear identification of personnel, material, and/or equipment located therein. III. Person responsible for the control and maintenance of lighting systems. IV. Maintenance and review program (if it coincides with another process, indicate it). The procedure may include: I. How the lighting system is controlled. II. Operating hours. III. Identification of areas with permanent lighting. 2.7 Communication Devices. The company must have communication devices and/or systems in order to contact security personnel and/or authorities immediately in the event of an emergency and security situation. Additionally, a backup system must be available and its proper functioning verified periodically. Answer: Explanatory Notes: Describe the procedure that personnel must follow to contact the company's security personnel or, in their case, the corresponding authority in the event of any security incident. Indicate if operational and administrative personnel have or have access to devices (landline phones, mobile phones, alert and/or emergency buttons, etc.) to communicate with security personnel and/or the appropriate person (these must be accessible to users, to be able to react promptly). Indicate what type of communication devices the company's security personnel uses (landline phones, cell phones, radios, alarm system, etc.).
Describe the procedure for the control and maintenance of communication devices; ensure you include the following points: I. Policies for the assignment of mobile communication devices. II. Maintenance or replacement program for fixed and mobile communication devices. III. Indicate if you have backup communication devices, in case the permanent system fails, and, if so, describe them briefly. The procedure may include: I. Person responsible for the proper functioning and maintenance of communication devices. II. Record of verification and maintenance of devices. III. Method of assignment of communication devices. 2.8 Alarm Systems and Closed-Circuit Television and Video Surveillance. Alarm systems, closed-circuit television, video surveillance, and security technologies must be used to monitor, notify, or deter unauthorized access and prohibited activities in the facilities and other areas considered sensitive, notify the corresponding area, and also be used as evidence in investigations derived from any security incident. These systems and security technologies must be placed according to a prior risk analysis, in such a way that areas involving the handling, loading, unloading, and storage of merchandise, raw materials, and packaging materials, security inspections of cargo vehicles, as well as the access of personnel, visitors, suppliers, passenger and cargo vehicles, and other areas considered sensitive, are monitored and watched. These systems must allow clear identification of the area or environment being monitored, be recording permanently, and keep a backup of the recordings for at least one month, considering that, if your logistical processes exceed this period, the period for maintaining these backups must be increased, with the aim of having the necessary elements to assign corresponding responsibilities in the event of a security incident. Alarm systems, closed-circuit television, video surveillance, and security technologies must have a documented operation procedure that includes supervision of the good condition of the equipment, verification of the correct position of the cameras, indicate the frequency with which recordings must be backed up, as well as those responsible for their operation. Such a system and all security technology infrastructure must have restricted access.
Answer: Explanatory Notes: Mention the documented procedure in which the operation of the external alarm central or sensors is indicated, and if applicable, describe the following points: I. Indicate if all doors and windows have alarm sensors, as well as the areas where motion sensors are available. II. Procedure to follow in the event of an alarm activation. Describe the documented procedure for the operation of alarm systems, closed-circuit television, video surveillance, and security technologies (this must be reviewed and updated annually and according to the risk analysis or circumstances); ensure you include the following points: I. Indicate the number of security cameras of the alarm and closed-circuit television and video surveillance systems installed, and their location by area (Detail if it covers the loading and unloading zones, including the entry and exit points of the facilities, to cover the movement of vehicles and individuals, and where the inspection mentioned in sub-standard 7.2 is carried out). Attach a layout or map of the distribution of security cameras. II. Indicate the location of the alarm systems, closed-circuit television, video surveillance, and security technologies, where the monitors are located, who reviews them, as well as the operating hours, and if applicable, if there are remote monitoring stations. All security technology infrastructure must be physically protected against unauthorized access.
III. Periodic and random reviews of recordings must be carried out. Indicate how they review them (random, every week, special events, restricted areas, etc.), who the designated personnel are, and how management is involved in the reviews. The results of the reviews must be documented to include corrective actions for audit purposes. IV. Indicate for how long these recordings are kept (must be at least one month). V. Alarm systems, closed-circuit television, video surveillance, and security technologies must have an alternative energy source that allows them to continue functioning in the event of an unexpected loss of direct power. For the above, indicate if the alarm and closed-circuit television and video surveillance systems and security technologies are backed up by an electrical power plant or any other mechanism to supply electricity, which guarantees their operation. These systems should have an alarm/notification function, indicating a failure condition in operation and/or recording; indicate if your systems have this function. VI. Indicate if, in addition to the alarm and closed-circuit television and video surveillance systems, you use any other type of technology to strengthen the security measures you already have.
VII. Describe the procedure that has been implemented to regularly test and inspect alarm systems, closed-circuit television and video surveillance systems, and security technologies, and to ensure their proper functioning. The results of the inspections and operational tests must be documented, as well as any necessary corrective actions (which must be implemented as soon as possible). Additionally, the documented results of these inspections must be retained for a sufficient period for audit purposes.
VIII. Indicate whether the alarm provider and providers of alarm and closed-circuit television and video surveillance systems have access to the security cameras, if they are responsible for monitoring them, how access is controlled, and who is responsible for said monitoring.
3.1 Security personnel. The company must have security and surveillance personnel. This personnel plays an important role in the physical protection of the facilities and merchandise during its transport, handling, and storage within the company, as well as for controlling the entry and exit of all people to the building. Security personnel must have a documented procedure to carry out their functions and have full knowledge of the mechanisms and procedures in emergency situations, detection of unauthorized persons, or any security incident at the facility. Management must periodically verify compliance with procedures, policies, and functions through internal audits with the objective of verifying their correct execution.
Response: Explanatory Notes: Describe the documented procedure for the operation of security personnel and ensure you include the following points: I. Indicate the number of security personnel working at the company. II. Specify the positions and/or functions of the personnel and operating hours. III. In case of hiring an external service, provide the general data of the company (tax ID key, trade name, address), and specify the number of employees, operational details, records, and reports they use to perform their functions. IV. In case of having armed personnel, describe the procedure for the control and storage of weapons.
3.2 Employee identification. There must be an employee identification system for access to the facilities. Employees should only have access to those areas they need to perform their functions. The management or the company's security personnel must adequately control the delivery and return of badges, ID cards, and/or employee identification credentials. Procedures for the delivery, return, and change of access devices (for example, keys, badges, and/or credentials, proximity cards, etc.) must be documented. Access to sensitive areas must be restricted according to the job description or assigned tasks.
Response: Explanatory Notes: Describe the procedure for employee identification and ensure you include the following points: I. Identification mechanisms (badge and/or photo ID, access control, biometrics, proximity cards, etc.). II. Indicate if employees use uniforms, how they are assigned (by position, area, functions, etc.) and withdrawn (if applicable). III. Indicate how personnel hired by a business partner, working within the facilities (contractors, subcontractors, in-house services, sub-maquila, etc.) are identified.
Describe how the company delivers, changes, and withdraws employee identification and access controls and ensure you include the responsible areas for authorizing and administering them. Indicate how you ensure that access to sensitive areas is restricted according to the job description or assigned tasks (include the type of records and controls you use). Attach the documented procedure for the control of identifications.
3.3 Identification of visitors and suppliers. To access the facilities, visitors and suppliers must present official identification with a photo for documentation upon arrival and a record must be kept. All visitors and suppliers must receive a temporary identification, must be accompanied by company personnel during their stay at the facilities, and ensure that the visitor/supplier always wears the provisional identification provided in a visible place. This procedure must be documented.
Response: Explanatory Notes: Describe the procedure for access control of visitors and suppliers, ensure you include the following points: I. Specify what records are kept (personal forms for each visit, logbooks, among others). II. The visitor and supplier record must include the following: a) Date of the visit. b) Visitor's name. c) Identification number with photo (official documents such as: driver's license, passport, INE, etc.). d) Entry and exit time. e) In the case of vehicular access, the form must include the data of the private or cargo vehicle (model, license plate, trailer number, etc.). III. Specify who is the person responsible for accompanying the visitor and/or supplier and if there are restricted areas for their entry.
3.4 Procedure for identification and withdrawal of unauthorized persons or vehicles. The company must have documented procedures that specify how to identify, confront, or report unauthorized or identified persons and/or vehicles. This procedure must be communicated to responsible personnel through training. The training must be documented.
Response: Explanatory Notes: Attach the documented procedure to identify, confront, or report unauthorized or identified persons and/or vehicles. The procedure must include: I. Responsible personnel. II. Designate a person or area responsible for being informed of security incidents. III. Instructions for confronting and addressing unidentified personnel. IV. Specify in which cases the corresponding authorities must be reported. V. How the registration of security incidents and the measures adopted in each case is carried out.
3.5 Courier and package deliveries. Courier and package deliveries intended for company personnel must be examined upon arrival and departure, before being distributed to the corresponding areas and destinations. Likewise, the company must have a documented procedure for the receipt and review of courier and packages, which must be communicated to responsible personnel through training. The training must be documented.
Response: Explanatory Notes: Describe the procedure for the receipt and review of courier and packages and ensure you include the following: I. Personnel in charge of carrying out the procedure. II. Indicate how the personnel or supplier of the courier and package service is identified (indicate if an additional procedure to supplier access is required).
III. Specify how the review of the courier and/or packages is carried out, what mechanism is used, the records kept, and in case, the incidents detected. IV. Describe the characteristics or elements to determine which courier and/or packages are suspicious. V. Specify what action is taken in case of detecting suspicious courier and/or packages.
4.1 Selection criteria. There must be documented procedures for the selection, follow-up, and renewal of commercial relationships with business associates or suppliers, which include interviews, reference verification, evaluation methods, and use of provided information. The information derived from the investigation and/or evaluation of business associates and/or suppliers must be documented and integrated into a file (physical or electronic). The procedure for the selection of business partners must include indicators to detect clients or suppliers that may not be legitimate or with unlocated addresses, in addition to investigations, reviews, or evaluations of said partners for the identification and control of activities related to money laundering and terrorist financing. If the investigation and/or evaluation of any business partner leads to substantial doubts about the veracity of their operations or services, the company must avoid hiring them and, if applicable, notify their security specialist or Authorized Economic Operator Program contact and the corresponding authority about their suspicions.
Response: Explanatory Notes: Attach the documented procedure for the selection and contracting of new business partners and monitoring of partners already working with them. This includes any type of supplier that has a commercial relationship with the company and, if applicable, with the service outsourcing company, in its supply chain (it is in the next sub-standard where it is requested to differentiate those at risk in its supply chain), ensure you include the following points: I. What information is required from your business partner. II. What aspects are reviewed and investigated. III. Indicators to identify clients or suppliers that may not be legitimate (payments above standard rate, in cash; having little knowledge of the merchandise to be shipped; being evasive; minimal contact information (cell phone, contact points, emails, among others); recently created companies or businesses without commercial history, etc.) or with unlocated addresses. This point refers to pointing out all those alerts to determine that a business partner is not reliable and thus, conduct a deeper investigation and evaluate if you should work with them. IV. Indicate if you maintain a physical or electronic file of each of your business partners, as well as the information it must contain. V. Specify how the services of your business partner are evaluated and what points you review.
The file must include at least the following: I. Company data (name, tax ID key, activity, etc.). II. Legal representative data. III. Proof of address. IV. Commercial references (if applicable). V. Contracts, agreements, and/or confidentiality agreements and security policies. VI. If applicable, certificate or certification number in the security programs to which they belong.
4.2 Security requirements. The company must have a documented procedure in which, according to its risk analysis, it requests additional security requirements from those business partners that intervene in its supply chain, whether as suppliers of materials for the elaboration, packaging, or packing of merchandise subject to foreign trade, as well as transport service providers (long haul, cross-dock or transfer, Ex Works, subcontractors, etc.), for the transport and/or distribution of merchandise subject to foreign trade, customs brokers, logistics outsourcing providers (3PL, third-party logistics or 4PL, main logistics provider), warehouses, sub-maquila companies, manufacturers, sellers, national and foreign suppliers of parts and raw materials, direct and indirect, cleaning service providers, private security, personnel hiring, high-security seal providers, collection and recycling, IT systems and Technology providers, among others. The requirements must be based on the company Profile established by the AGACE, or in case it exists, the specific Profile for each actor in the supply chain that corresponds to them. The company must request from its business partners the documentation that accredits and proves that they comply with the minimum security standards established in the company Profile, either through a written declaration issued by the legal representative of the partner, agreements or contractual clauses, backed by documentation supporting compliance with the requirements established in the Authorized Economic Operator Program. For the case of the Service Outsourcing Company that has business partners contracted to provide customs management, storage, handling, transport, and/or distribution of merchandise subject to foreign trade services on its behalf, they must be registered in the Registry in the Certification of Companies Scheme, in the modalities of Authorized Economic Operator and Certified Commercial Partner in any of its areas or have the CTPAT Program, granted by the CBP. Likewise, the company must take into account and know the specific requirements of the Authorized Economic Operator Program that will be applicable to each of its business partners, based on their activity within the supply chain. In the case of the company's business partners that provide their services within the facilities, they must be obliged to comply with these supply chain security requirements.
Response: Explanatory Notes: Describe the procedure that indicates how you carry out the identification of business partners that require compliance with minimum security standards. Ensure you include the following points: I. A register of business partners that must comply with security requirements, and mention what type of providers these are (carriers for the transport and/or distribution of merchandise subject to foreign trade, warehouses, custody service, private security company, customs brokers, etc.). II. Indicate in what documentary form (agreements, accords, contractual clauses, and/or addenda) you ensure that your business partners comply with security requirements. III. Indicate if there are agreements, accords, contractual clauses, and/or addenda regarding the implementation of security measures with your service providers inside your company, such as: private security, cafeteria, gardening, cleaning and maintenance services, IT providers, etc. IV. Indicate if you have business partners to whom membership in a supply chain security program is required (for example: CTPAT or any other WCO Authorized Economic Operator Program), as well as the information and documentation requested from them.
4.3 Business partner reviews. The company, through the Security Committee, must perform periodic security evaluations (as well as those derived from risk situations) of the processes and facilities of business associates based on a risk analysis to guarantee that they have minimum security standards required by the company based on the Authorized Economic Operator Program, keep records of them, which allow verifying that the processes and security measures are being executed, as well as the corresponding follow-up. When inconsistencies are found, the company must communicate them to its partner and/or supplier and provide a justified period to address the observations or areas of opportunity identified or, in case, have the necessary measures to sanction it. Performing security evaluations of business partners is important to guarantee that there is a solid security program and that it functions correctly, which is why, in addition to a documented procedure, there must be a program or calendar for the execution of said reviews or security evaluations, prioritizing partners that are more critical according to their risk analysis. If a member is not evaluated and the company does not know if the processes and facilities of its business partners function correctly, it puts its supply chain at risk.
Response: Explanatory Notes: Describe the procedure to carry out evaluations for the verification of security requirements (processes and facilities) of your business partners, ensure you include the following points: I. Periodicity with which you make visits to the business partner (these must be at least once a year and derived from risk situations). II. Program or calendar for the execution of security reviews. III. Record or report of the verification, and in case, the corresponding follow-up. IV. The verification formats must be duly filled out, placing the date, name, and position of those who participate in the review, signatures, etc. V. Specify what action measures are taken when business partners do not comply with the established security requirements. In case of having business partners with CTPAT certification or another supply chain security certification program, indicate the periodicity with which their status is reviewed, how you register it, and the actions you take in case it is detected that it is suspended and/or cancelled, according to what is established in your procedure.
The procedure must include: I. Periodicity of visits. II. Points of review in security matters. III. Preparation of reports. IV. Feedback and agreements with the business partner. V. Follow-up to agreements. VI. Measures in case of detection of non-compliance with requirements. VII. Record of evaluations. VIII. Area or person responsible for carrying out this procedure.
5.1 Process mapping. There must be a map that shows step by step the logistical process of the flow of merchandise and the required documentation through your international supply chain. The company must take into account and include within its mapping all parties involved in its supply chain, containing those that handle import and export documentation, such as customs brokers, others that may not handle the cargo directly but may have operational control such as carriers (long haul, cross-dock or transfer, Ex Works, subcontractors, etc.), logistics outsourcing providers (3PL/4PL), storage, sub-maquila, national and foreign suppliers, direct and indirect, etc. If within your supply chain any part of the transport is subcontracted, it is indispensable that it be considered within your risk analysis and process mapping, since, the more direct and indirect suppliers, the greater the risk involved.
Response: Explanatory Notes: Attach the document where the mapping of processes through which your import and export merchandise passes is illustrated and described, from the point of origin to the destination, with the purpose of having correctly identified each of the steps that involve the elaboration and delivery of the final product.
Process mapping must include the names (RFC key and corporate name) of the companies that provide services in their logistics chain. This mapping must contain at least the following aspects: I. Origin of: a) Raw materials. b) Packaging, wrapping, and/or crating. c) Container and/or semi-trailer. II. Delivery and/or receipt of the merchandise. III. Transfer of the merchandise. a) Indicate the points and areas for rest or safeguarding of cargo vehicles during the transfer of merchandise subject to foreign trade (import and export), as well as the documentation generated when the cargo enters and leaves the facilities. b) Indicate the estimated times that said vehicles remain in the rest (reposo) or safeguarding areas (company yards, exit customs, customs broker or agency facilities, warehouses, transfer yards or transport, among others). IV. Storage and/or distribution. V. Customs clearance. VI. Delivery to final destination. VII. Information flow related to the merchandise. If applicable, indicate if there is a sub-manufacturing process and provide the general data of the company (Name, RFC key, and address) and the SE permit in which authorization as a sub-manufacturing company is granted, as well as the productive process they carry out.
5.2 Warehouses and distribution centers. When the company has warehouses and distribution centers for merchandise subject to foreign trade, outside the production and/or manufacturing facilities belonging to it, these must be subject, according to their characteristics, to what is established in this document, in order to maintain integrity in their supply chain. Answer: Explanatory Notes: According to the process mapping of their merchandise, if the logistics chain of foreign trade merchandise involves moving to a warehouse or distribution center, these must comply with the minimum security requirements established by the AGACE. In this way, they are obligated to fill out a Company Profile for each of these installations mentioned here. For the above, indicate how many warehouses and/or distribution centers are used, provide their general data (name and address), and briefly explain what activity is carried out in this installation. Additionally, include also those warehouses and/or distribution centers that are used for national products or fixed assets, as a reference (these do not need to fill out a Company Profile). Likewise, indicate if these belong to the company or if it is a service contracted through a third party. In this case, according to the supplier selection criteria mentioned in the section regarding Commercial Partners, indicate how you ensure that they meet the minimum security requirements (warehouses and/or distribution centers managed by a third party are not obligated to present a Company Profile).
5.3 Delivery and receipt of cargo. The company must ensure the identification of transport medium operators who carry out the delivery or receipt of the cargo. Likewise, the company must designate a person responsible for supervising the loading or unloading of the shipment, verifying the detailed description of the merchandise, weight, labels, marks, and quantity, cross-referencing this information with the corresponding purchase or delivery orders. In the same way, the driver transporting the merchandise must be provided with the required documentary information for its correct transfer, which includes, by way of example and not limitation, destination, route to be maintained, contact data, and/or procedure in case of any security incident or inspection by any authority, among others. When the cargo is stored overnight or for a prolonged period in the shipping area, measures must be taken to secure the cargo against unauthorized access; this area must be monitored by its alarm systems, closed-circuit television, and video surveillance systems and have restricted access. The cargo preparation areas and the immediate surrounding areas must be inspected regularly to ensure that these areas remain free of visible pest contamination. During the loading and unloading process of merchandise, the company's security area (supervisor or security guard) must be present to validate that the process is being carried out correctly, mitigate the risk of shipment contamination (prohibited, illicit merchandise, or pests), and register said review (incident reports, records, reports, etc.). As evidence that the high-security seal and/or lock was placed correctly, digital photographs must be taken at the moment of loading the vehicles. Whenever possible, these images should be sent electronically to the destination or delivery contact point of the merchandise for verification. Also, the personnel responsible for the shipping and/or receiving area must review the information included in the import and/or export documents to identify or recognize suspicious cargo shipments. Likewise, specific training must be provided on identifying common errors in export shipment documentation, with the objective of preventing these from resulting in security incidents or suspicious merchandise. If the company has its own cargo transport, it must provide training to transport operators to review import and/or export documentation in order to identify or recognize suspicious cargo shipments, such as: I. Originating from or destined to unusual places; II. Different routes; III. Cash payments; IV. Observing unusual shipping and/or receiving practices; V. Lack of information.
Answer: Explanatory Notes: Attach the documented procedure indicating the procedure for the delivery and receipt of cargo and ensure that the following points are included: I. Method to identify transport operators. II. Documentation delivered to operators. In addition to transport documents and customs documents (Bill of Lading, manifests, etc., which must be presented to the authority in a legible, complete, accurate, and timely manner), there must be a record accompanying the entry and exit of merchandise, which includes: a) Date. b) Driver's name. c) Photo identification number (official documents such as: driver's license, passport, INE, etc.). d) Address of the origin point (location/installation) where the transporter collects the cargo destined for abroad. e) High-security seal or lock number. f) Entry and exit time (the cargo record must be kept secure and drivers must not have access to it). g) In the case of vehicular access, the format must include the data of the cargo vehicle (model, license plate, trailer number, etc.). This record must be kept secure and drivers must not have access to it.
III. The delivery and receipt of cargo should be by appointment, whenever the company's operation allows it and in a specific area or place so that it is monitored by security personnel, an employee, or closed-circuit television and video surveillance systems. IV. The transporter must notify the installation of the estimated arrival time for the scheduled collection, the driver's name, and the truck number. V. Person responsible for supervising the loading or unloading of the merchandise and cross-referencing the information. VI. How it verifies and guarantees that the cargo preparation areas and the immediate surrounding areas remain free of visible pest contamination. In case of identifying any type of visible pest, contamination, trash, insects, grass, weeds, or overgrown grass, how it is reported and what actions are taken regarding it. VII. Indicate who is responsible for taking digital photographs of the place and the placement of the high-security seal and/or lock, as well as of the merchandise loading process, and, if applicable, how they send them to the destination contact point or cargo delivery (including the seal and/or lock number(s)). VIII. Indicate how it controls or what security measures it has implemented to mitigate the risk of collusion or complicity between employees, such as the driver and personnel in the dispatch or shipping, receiving, warehouse, security guards areas, etc.
IX. Indicate if it carries out permanent or random reviews of the luggage of transport operators who enter its facilities to deliver or pick up cargo. In case of identifying any anomaly or having a suspicion, describe the actions taken regarding it and how it reports to the authority. X. In high-risk areas, when feasible from an operational point of view, the land transporter should use a convoy method (e.g., a minimum of two trucks traveling together) to transport the cargo, in addition to having communication between the other cargo vehicles and the personnel responsible for the transfer of the merchandise. The merchandise delivery and receipt procedure must include: I. Inspection method at the access point to the company. II. Designation of personnel responsible for receiving the driver and merchandise upon arrival. III. Maintenance of a schedule of expected arrivals and treatment of unexpected arrivals. IV. Registration of transport documents and customs documents accompanying the entry and exit of merchandise (Bill of Lading, manifests, etc., which must be presented to the authority in a timely manner), which accompany the entry and exit of merchandise, showing the origin point (location/installation) where the transporter collects the cargo destined for abroad. V. Designate personnel responsible for supervising the loading and/or unloading of merchandise. VI. Weighing, counting, measuring, and marking of merchandise (compare with provided documentation).
VII. In the case of merchandise exit, verify if there are additional security requirements imposed by clients. VIII. Verification of the integrity of any lock and/or seals on the loading and/or unloading (how locks or seals are used and recorded in documents, placed according to the procedure established in the standards and according to current legal requirements). IX. Identification and reporting of discrepancies. X. In the case of merchandise exit, indicate what documentation will be delivered to the transporter. XI. Report to the corresponding department of the receipt and/or exit of merchandise. 5.4 Merchandise tracking procedure. The company is responsible for monitoring and supervising the integrity of its merchandise throughout the supply chain, so it must have documented procedures that establish the use of technology for the tracking and supervision of activities of the transport medium movement that transfers foreign trade merchandise. For land transfers, companies must have a documented policy prohibiting unscheduled stops. The company must establish documented internal or provider procedures to ensure at all times the location of the transit transporter's vehicle. These procedures must be carried out under a risk analysis that includes, by way of example and not limitation, the identification of predetermined routes, estimated delivery times between intermediate points, as well as overnight stay and/or rest (yards, exit customs, customs broker or agency facilities, freight agents, among others), which must be registered and incorporated into the tracking process. Likewise, measures and actions to be taken in case of identifying any delay in the route due to weather conditions, traffic, route changes, or inspection by any authority or any security incident must be included. If services of a provider are contracted, the company must have access to the transporter's GPS monitoring system, so that it can track the movement of its shipments. If the driver makes stops during their journey, they must register them and carry out inspections of the transport means, containers, trailers, and semi-trailers used as International Traffic Instruments, as well as of the closing devices, seals, and/or locks to verify their integrity and identify signs of manipulation before resuming the trip. The supervision data and registration of all vehicles in transit carrying foreign trade merchandise, as well as route histories, must be preserved for one year when the authority and/or the transporter must carry out an evaluation due to a security incident or for audit purposes.
Answer: Explanatory Notes: Attach the documented procedure to monitor the transfer of merchandise. This procedure must include, among other aspects according to its operation: I. Have GPS whose external hardware is hidden and can resist attempts to remove it, indicate the type of system implemented by the units used and, if it is a third-party or subcontracted service, describe the consultation tools available to monitor the merchandise. II. Identification of predetermined routes, estimated delivery times between intermediate points, as well as overnight stay and/or rest (yards, exit customs, customs broker or agency facilities, freight agents, among others). Once the time between assigned points has been determined, there must be a tracking process (route audit) and the corresponding records. III. In the case of geofences, within their parameters, minimum tolerances allowed for the preset transit route must exist or be established. IV. There must be systems or procedures with instructions in case of a delay in the route (stops, changes or diversions of route, mechanical failures, accidents, etc.). Likewise, drivers must notify (their supervisor and, if applicable, the sender or consignee of the merchandise) any significant delay in the route due to weather, traffic, accidents, mechanical failures, route change, etc. And on its part, the company must independently verify the cause of said delay.
V. Detail if it has a means that allows communication with the transporter during their transfer and if it has more than one form of communication. VI. When tracking is carried out by a third party, indicate who is responsible, and how it verifies that it is being carried out correctly, according to the procedures that the company indicates to it. VII. In case of having own cargo transport, GPS or equivalent technology should be used to ensure that the trailer is also monitored and tracked. Describe how this tracking is performed. VIII. GPS records or route histories must be safeguarded for cases of security incidents and audits. The procedure must also include that, in case of identifying a real or concrete threat to the security of a shipment or transport medium; how the company informs its commercial partners in its supply chain that may be affected and, if applicable, to the authority as appropriate, about this type of incidents or presumptions. Indicate if the company uses custody services for its shipments and, if applicable, indicate if there is a documented process for their operation in which policies and restrictions are indicated, as well as the means of communication between the escort and the transporters (if applicable, indicate the RFC key and corporate name of the company providing the service). 5.5 Report of discrepancies in cargo. There must be documented procedures to detect and report missing, excess, prohibited merchandise, or any other discrepancy in the delivery or receipt of merchandise, which must be investigated and resolved. It must be verified that the cargo matches what is indicated in the description declared in the packing list or the shipping document, specifying the detailed description of the merchandise and the data that allow its correct identification and quantification.
Answer: Explanatory Notes: Attach the documented procedure to detect and report discrepancies in the delivery or receipt of merchandise and ensure that it includes the following points: I. Persons responsible for carrying out the review. II. Documents to cross-reference. III. Areas to which the information is reported. This procedure must be applied both to the merchandise received from import; if applicable, in the review at intermediate points; as well as in the final delivery of merchandise to its client. 5.6 Processing of information and cargo documentation. The company must have documented procedures to ensure that the electronic and/or documentary information used during the movement and clearance of cargo, as well as the information received from business associates, is legible, complete, accurate, reported in time, and protected against changes, losses, or introduction of erroneous information. Likewise, forms and documentation related to import and/or export should be secured to prevent unauthorized use. Answer: Explanatory Notes: Describe the procedure for the processing of information and cargo documentation, ensure to include the following points: I. Detail how it transmits relevant information and documentation for the transfer of its cargo with all those involved in its supply chain (indicate if it uses a specific computer control system and briefly explain its function). Likewise, detail how it validates that the provided information is legible, complete, accurate, reported in time, and protected against changes, losses, or introduction of erroneous information. II. Forms and documentation related to import and/or export must be secured to prevent unauthorized use. III. Indicate how business associates transmit information with the company and how they ensure its protection.
5.7 Inventory Management, control of packaging, container, and crating material. The company must have documented procedures for inventory control and cargo storage, and periodic reviews and audits must be carried out to verify their correct management. Likewise, it must have a documented procedure for the control of packaging, container, and crating material of the merchandise, which must also include the control, dissemination, and prevention procedure of visible pest contamination, in the case of using wooden crating materials (such as pallets, boxes, crates, cages, reels, dunnage, chocks, supports, or platforms) to stack, move, and protect the cargo throughout its entire supply chain. Answer: Explanatory Notes: Attach the documented procedure for inventory management. This must include, among other aspects according to its operation: I. The frequency with which it carries out stock verification (periodic inventory). Indicate if there is a scheduled calendar documented to carry them out. II. Indicate what is done in case of surpluses and shortages in inventories. III. Indicate the treatment given to the control and handling of packaging, container, and crating material, and if applicable, of shrinkage, waste, or excess material, which must also include the control, dissemination, and prevention procedure of visible pest contamination, in the case of using wooden crating materials (such as pallets, boxes, crates, cages, reels, dunnage, chocks, supports, or platforms) to stack, move, and protect the cargo. This point is also focused on reducing the risk of introduction or dissemination of quarantine pests of importance to the country through packaging (imports), for which reason, describe how it complies with the provisions indicated by SEMARNAT and NOM-144 SEMARNAT-2017, in concordance with International Standard for Phytosanitary Measures No. 15 denominated Regulation of Wood Packaging Material used in International Trade, which emanate from the Food and Agriculture Organization of the United Nations. IV. Indicate how the fumigation process is to kill, inactivate, sterilize, desiccate, or eliminate pests. What actions are taken in case of requiring quarantine of crating materials. V. Indicate the area responsible for carrying out this process, as well as the documentation or certificate. The applicant's procedures may include: I. Warehouse only accessible to authorized personnel. II. Frequency of stock control. III. Control of incoming merchandise, transfers to other warehouses, permanent and temporary withdrawals. IV. Actions taken if irregularities, discrepancies, losses, or thefts are identified. V. Treatment of deterioration or destruction of merchandise. VI. Separation of various types of merchandise, for example, high value or dangerous. 6. Customs Management. The company must have documented procedures in which internal and operational policies are established, as well as the necessary controls for the due compliance of customs obligations. Likewise, it must have specialized personnel and documented procedures that establish the verification of the information and documentation generated by the customs broker or, if applicable, ensure the processes carried out by the customs representative. 6.1 Customs clearance management. The company must have a documented procedure in which criteria are established for the selection of a customs broker or, if applicable, a customs representative, who, according to national legislation, are authorized to promote on behalf of others the clearance of merchandise.
Answer: Explanatory Notes: Describe the selection and evaluation procedure for the customs agent or representative and ensure it includes the following points: I. Selection criteria. II. Evaluation methods and frequency. III. Describe the indicators with which you evaluate the service of customs agents. Indicate the full name and patent number and/or authorization of the customs agent or representative authorized to promote your foreign trade operations.
6.2 Customs Obligations. The company must have a documented procedure that establishes how it maintains updated inventory control of foreign trade merchandise in accordance with what is established in Article 59, fraction I of the Law and the information referred to in Annex 24 sections A and B, as applicable. The company must have a documented procedure for compliance with customs obligations arising from the foreign trade operations it carries out. This must include, at least, compliance with what is established in Article 59, fractions II and III of the Law, which will allow verification of the origin and provenance of the merchandise, through a control that allows identifying the country of origin, the Free Trade Agreement or Commercial Agreement under which the tariff preference was applied, and the document that supports said preference, in case of applying a tariff preference according to self-certification, having all the elements that certify the origin of the merchandise, as well as the correct determination of the customs value. These procedures regarding the origin of the merchandise must describe the cases in which the origin of the same is declared and the documentation with which the originating character must be demonstrated. In the case of companies that introduce merchandise into the national territory under a deferral or tariff refund program, the company must have a procedure in which it describes how it determines the payment of taxes on foreign trade, in accordance with the Treaties of which Mexico is a party, in accordance with what is established in Article 63-A of the Law. In the case of having a development program authorized by the SE, it must have documented procedures to comply with what is required in the same, among which are inventory control, return deadlines and restrictions regarding the change of destination of the temporarily imported merchandise, among others established in Article 24 of the IMMEX Decree, as well as the Annual Report of Foreign Trade Operations referred to in Article 25 of said decree.
Answer: Explanatory Notes: Attach the procedure by which it establishes how it maintains updated inventory control in terms of fraction I of Article 59 of the Law. Attach the procedure to comply with customs obligations that result in the verification of the country of origin and the valuation of foreign trade merchandise in terms of fractions II and III of Article 59 of the Law. Regarding this, for the purposes of restrictions on the refund of customs duties on exported products and on tariff deferral programs, only the origin must be demonstrated when the imported merchandise is originating and is subsequently sent to another signatory party of the International Treaty or Commercial Agreement in question. With regard to countervailing duties, the origin must be demonstrated when the tariff fraction of the imported merchandise is subject to such measures. And the origin must also be demonstrated in the case of merchandise that is imported with preferential tariff treatment under an International Treaty or Commercial Agreement of which Mexico is a party. The origin will be considered demonstrated when the company has the certificate of origin or other document provided for in the applicable provisions. Indicate if you have an IMMEX Program authorized by the SE, and if so, attach the procedure to comply with the obligations established in Articles 24 and 25 of the IMMEX Decree, among which are, by way of example and not limitation, the following: I. Register where production processes are carried out. II. Return of merchandise within authorized deadlines. III. Automated inventory control. IV. Annual Operations Report, among others. In case of having any other export promotion program, attach the procedure to comply with the obligations derived from it.
6.3 Customs Verification. The company, in order to guarantee compliance with the mandate entrusted to a third party, as well as to verify the truthfulness of the information declared in its name before the competent authorities, must have documented procedures so that the personnel designated by the company periodically verifies that the customs declarations registered in its accounting match what appears registered in SAAI Web and, if applicable, report to the customs authority any discrepancy in said information. The company, likewise, must have a procedure for the filing of customs declarations for their adequate control. Likewise, the company must have documented procedures, in which the periodic verification of the correct tariff classification of merchandise subject to foreign trade and the verification of tariff and non-tariff regulations and restrictions to which they are subject are established.
Answer: Explanatory Notes: Attach the procedure established to verify the information that appears registered in SAAI Web, and cross-reference with the customs declarations and documentation requested from the customs agent and/or customs representative. Attach the documented procedure for the verification of the correct tariff classification and NICO. This must include, among other aspects according to your operation: I. Method for the review and verification of the tariff classification and NICO of the merchandise and their corresponding tariff rates, non-tariff regulations and restrictions. II. Maintenance of an updated file of foreign trade products. Detail what items you concentrate in it (tariff fraction, NICO, Rates, Regulations, Opinions, among others) and with what frequency it is updated. III. The tools, systems, programs or technical information that you use to classify your merchandise. IV. Report to the corresponding areas the changes in the tariff fractions and the implications that are generated in rates and regulations; likewise when it comes to changes in the NICO.
7.1 Cargo Integrity and Use of Seals in Containers and Trailers. The company must have a documented procedure where the means of transport are identified and, if applicable, the containers, train cars and/or semi-trailers used in its international logistics chain and indicate how their integrity is maintained. For this reason, as one of the security mechanisms, the company must use high-security padlocks or seals that comply with or exceed the ISO 17712 Standard in all containers and loaded trailers that are subject to foreign trade and maintain their integrity until delivery at the final destination. For this, the company must have documented procedures to place and verify the correct application of seals, their inspection at intermediate points, final destination and their replacement when they are opened by any authority. In the event of such an inspection, drivers must notify and record any unusual anomaly or structural modification found in the means of transport derived from said review. The procedures must include the steps to follow if it is discovered that a seal is altered, manipulated or there is an incorrect seal number in the documentation, the communication protocols to the commercial partners involved in the supply chain and the investigation of the security incident. These must be notified to security personnel, commercial partners that may be part of the affected supply chain, security specialist or contact of the Authorized Economic Operator Program. Likewise, it is necessary to have a documented procedure for the administration of the same which includes control, assignment, safeguarding, handling of discrepancies and destruction of seals and padlocks. Regarding the supplier of the seals and/or padlocks, it must be demonstrated how these comply with the ISO 17712 Standard. The company's management or a security supervisor must carry out periodic and documented audits of the high-security seals and/or padlocks, these reviews must include the verification of the inventory of stored seals and/or padlocks and the cross-check with inventory records and shipping documents. Also, the supervisors of the shipping area and/or warehouse managers must periodically verify the seal numbers used in the means of transport and Instruments of International Traffic to corroborate that the information is correct.
Answer: Explanatory Notes: Detail the type of vehicles, means of transport, as well as containers and semi-trailers that the company uses to transport its merchandise (maritime containers, dry boxes, railway containers, tanks, among others). Indicate if the transport units, containers and/or trailers are owned by the company or a third party. Indicate the transport companies hired to carry out the transfer of foreign trade merchandise, indicating their name or corporate name, RFC key and fiscal address. Attach the documented procedure for the placement and review of seals and/or padlocks in vehicles, means of transport, containers, train cars, trailers and/or semi-trailers. This must include, among other aspects according to your operation: I. Verify that the seal or padlock is intact and determine if there is evidence of improper manipulation. In case of using a high-security padlock, (bottle type, cable, padlock, etc.), you must use the VVTT inspection method: a) V- View the seal and lock mechanisms of the container (View). b) V- Verify the seal number (Verify). c) T- Pull the seal to ensure it is correctly placed (Tug). d) T- Twist and turn the seal to ensure it has closed (Twist and Turn). II. Review and cross-reference the documentation containing the original seal or padlock number and, if applicable, the additional ones carried in the transport of the merchandise. In case of using the replacement seal and/or padlock, said number must be registered within the company's control. If altered seals and/or padlocks are identified, they must be kept to help carry out the investigation of said incident or discrepancy and, as appropriate, report the compromised seals and/or padlocks to the foreign authority. III. If the company uses cable seals, they must be placed on the two vertical bars of the container. IV. Review that the closing devices, hinges and pins are attached to the trailer or container and welded or riveted. Likewise, protective plates can be placed on the door hinges and/or a seal/adhesive tape can be placed on at least each side. Likewise, the correct functioning of handles, latches and all other locking or closing mechanisms of the cargo vehicles must be verified to detect manipulations and any inconsistency before placing any sealing device. V. Indicate how they assign and replace high-security padlocks, in case that, during the route, it is inspected by another authority. If a seal and/or padlock breaks in transit, the cargo must be examined, the replacement seal and/or padlock number must be registered and the driver must immediately notify business associates when this happens, indicate who broke it and provide the new seal number. Attach the documented procedure for the control and handling of seals and/or padlocks. This must include, among other aspects according to your operation: I. What type of seals and/or padlocks you use in your operations (foreign trade, transit, storage, etc.).
II. Who has access and how padlocks and/or seals are safeguarded. The management of seals and/or padlocks must be restricted only to authorized personnel; stored in a safe place, have an inventory, control of their distribution and tracking (record of seals used, as well as of the receipt of new seals and/or padlocks). III. Describe how the company's management or security supervisor participate in audits of high-security seals and/or padlocks, the reviews they perform, the records they generate and the actions they take in case of identifying discrepancies. Also, how the supervisors of the shipping area and/or warehouse managers verify seal numbers used in means of transport and Instruments of International Traffic to corroborate that the information is correct (this process can also be included within the internal audits referred to in sub-standard 1.3 of this document). IV. How discrepancies in seal and/or padlock numbers are addressed. V. Indicate who the supplier(s) is/are and how it is proven that the specifications of the seals and/or padlocks comply with the ISO 17712 Standard (attach certificate issued by the certifying company responsible for verifying compliance with the corresponding ISO). All written procedures must be disseminated and maintained at the operational level so that they are easily accessible to employees in charge of carrying out the tasks described above, reviewed at least once a year and updated as necessary.
7.2 Inspection of means of transport, containers, train cars, trailers and semi-trailers. There must be procedures established to verify the physical integrity of the structure of the means of transport, container, train cars, trailers and/or semi-trailer used as Instruments of International Traffic, even the reliability of the door lock mechanisms, in order to identify natural or hidden compartments. The inspections of means of transport or cargo vehicles, containers and trailers (land or railway cargo) must be systematic and carried out upon entry and exit of the company and, if applicable, at the merchandise loading point; and if the infrastructure allows, before arriving at the dispatch customs using the VVTT inspection method. A record of these inspections must be kept in an area with controlled access and carried out in a place monitored by alarm systems and closed-circuit television and video surveillance said system must cover the inspection process in its entirety. The documented procedure for its inspection must include, by way of example and not limitation, the following review points: Means of Transport Trailers, Train Cars, Semi-trailers and Containers I. Bumper; II. Tires; III. Floor (Tractor); IV. Fuel tanks; V. Cabin interior (bedroom and tool compartment); VI. Air tanks; VII. Chassis; VIII. Fifth wheel area; IX. Drive shafts; X. Exhaust pipe; XI. Engine. I. Exterior and interior doors; II. Side walls (left and right); III. Intermediate and external roof; IV. Front wall; V. Internal floor; VI. Refrigeration system. For means of transport with trailer or integrated cargo compartment, the points indicated in the Trailers section must be added to the means of transport points. Likewise, before loading the means of transport, containers, train cars, trailers and semi-trailers used as Instruments of International Traffic, they must undergo agricultural and security inspections to guarantee that their structures have not been modified to hide contraband or that they have been contaminated with visible agricultural pests, keep a record and be backed up by a documented procedure. If visible pest contamination is found during the inspection or transport of merchandise subject to foreign trade, it must be cleaned (washed, vacuumed, etc.) to eliminate said contamination. The driver must ensure before crossing that the cabin is clean and free of trash.
Answer: Explanatory Notes: Attach the documented procedure to carry out the security and agricultural inspection of means of transport, containers, trailers and semi-trailers. This must include, among other aspects according to your operation: I. Those responsible for carrying out the inspection. II. Definition of the place or places where the inspection is carried out and indicate how the monitoring is carried out by alarm systems and closed-circuit television and video surveillance. III. The review points for means of transport, trailers, semi-trailers and containers both for security and those for quality and agricultural inspections whose purpose is to look for visible pests. IV. Instructions for the driver to ensure before crossing that the cabin is clean and free of trash. Attach the established format for the inspection of means of transport or cargo vehicles, containers, train cars, trailers and/or semi-trailers. If you use other types of cargo vehicles to transport your merchandise (vans, pickups, 3.5 tons, tankers, etc.), your procedure and inspection format must include the process and review points. Likewise, the security and agricultural inspection format must include the following information: I. Inspection date; II. Inspection time; III. Vehicle license plates (tractor and trailer); IV. Container/trailer number;
V. Specific areas of the cargo vehicles that were inspected; and VI. Name and signature of the employee who performs the inspection and the supervisor. The security and agricultural inspection format of containers and Instruments of International Traffic must be part of the import and export documentation. The documentation must be kept for one year for an investigation in case of any security incident, as well as to demonstrate continuous compliance with these inspection requirements. Additionally, and according to the risk analysis, the company should carry out periodic random reviews of cargo vehicles after the transport personnel has carried out security inspections to verify that they have been carried out correctly, counteract internal conspiracies and prevent security incidents. The reviews must be carried out randomly, without prior notice, so that they do not become predictable, in addition to being carried out in different places where the means of transport may be susceptible to contamination. Indicate if the repair or maintenance of transport units, containers or trailers is carried out in the same facilities or is carried out with an external provider. Describe how it validates that the cargo vehicles, containers, trailers and semi-trailers used as Instruments of International Traffic, that transport its merchandise, meet the necessary physical-mechanical conditions for their transfer and crossing, in addition to validating that they have records of this type of maintenance for at least one year.
7.3 Storage of vehicles, means of transport, containers, train cars, trailers, and semi-trailers. When means of transport, containers, trailers, and/or semi-trailers intended to transport foreign trade goods are empty and must be stored in parking areas, they must be secured with a padlock and/or indicative seal, or in a safe area that is guarded and/or monitored. When it is necessary to store or overnight a loaded container, trailer, and/or semi-trailer, it must be located in a safe area with perimeter barriers and monitored by alarm and closed-circuit television systems to prevent unauthorized access and manipulation of the goods; therefore, it must be closed with a high-security padlock in accordance with ISO 17712 Standard. Response: Explanatory Notes: Indicate whether the company stores containers, trailers, and/or semi-trailers for subsequent dispatch, or those that are empty, and how it maintains their integrity within its facilities: I. In the case of using padlocks and/or seals for empty containers, trailers, and semi-trailers, indicate which type is used. II. In the case of using any container, trailer, and/or semi-trailer as a warehouse for raw materials and/or any other type of goods, indicate how it maintains their integrity and security.
8.1 Employment background verification. The company must have documented procedures to investigate and verify the information stated in candidates' resumes, criminal records (if local legislation and company policies allow), and job applications, in accordance with local legislation, either independently or through an external company. Similarly, for positions that, due to their sensitivity, require it and affect the security of shipments subject to foreign trade, in accordance with the previously conducted risk analysis, stricter hiring requirements must be considered, which must be carried out periodically. Regarding personnel already working in the company, periodic investigations must be conducted based on the activities and/or sensitivity of the employee's position. All information regarding personnel must be kept in personal files, which must have restricted access.
Response: Explanatory Notes: Describe the documented procedure for personnel hiring, and ensure you include the following: I. Requirements and documentation demanded. II. Tests and exams requested. Indicate the areas and/or critical positions identified as risky, according to your analysis, and indicate the following: I. Indicate what additional requirements are necessary for specific areas and/or job positions, such as: criminal records (if legislation and company policies allow), certificate of non-criminal record, socioeconomic studies, clinical studies, toxicological (drug use) studies, etc. If applicable, indicate the positions or work areas where they are required and with what frequency they are carried out. II. Indicate whether, prior to hiring, the candidate must sign a confidentiality agreement or a similar document. In the case of hiring a service agency for personnel hiring, indicate if this agency has documented procedures for personnel hiring and how it ensures compliance with the same. Briefly explain what they consist of. The procedures for personnel hiring and contractors may include: I. Thorough investigations of the work and personal backgrounds of new employees. II. Confidentiality and liability clauses in employee contracts. III. Specific requirements for critical positions. IV. If applicable, the periodic update of the socioeconomic and physical/medical study of employees working in critical and/or sensitive areas. V. Hiring process and requirements requested for temporary employees and contractors. The company may consider the results of background verifications of candidates, as allowed by current legislation, to make hiring decisions. Background verifications are not limited to identity and criminal record verification. In higher-risk areas, deeper investigations may be justified.
8.2 Personnel termination procedure. Documented procedures must exist for personnel termination that include the delivery of identification and any other item provided to perform their functions (keys, uniforms, badges and/or credentials, computer equipment, passwords, tools, etc.). Likewise, this procedure must include the termination of access in any computer systems, access systems, among others that may exist. Response: Explanatory Notes: Describe the procedure for personnel termination, and ensure you include the following: I. Who is responsible for carrying out and following up on this procedure. II. How the delivery of identification, uniforms, keys, and other equipment is performed and confirmed. III. Indicate the control, record, and/or format in which the delivery of material and termination in computer systems (if applicable, attach) is identified and secured. IV. Indicate the type of records of personnel who ended their employment relationship with the company, so that when it was for security reasons, their service providers and/or business associates are warned.
8.3 Personnel administration. The company must maintain an updated system, control, or database of active employees. Likewise, it must carry out and maintain updated records of affiliation to social security institutions and other legal labor records. In the case where the company has personnel hired by its commercial partners and working within the facilities, it must ensure that they comply with the requirements established for the rest of its employees. Response: Explanatory Notes: Indicate whether the company has an updated system, control, or database, both of personnel employed directly and that hired through a service provider company, and ensure it includes, by way of example and not limitation, the following information: I. Full name. II. Updated photograph at least every 5 years. III. Personal data (age, name, date of birth, phone number, address, CURP, social security number, blood type, allergies, etc.). IV. Affiliation. V. Work background. VI. Diseases. VII. Medical exams. VIII. Training. IX. Results of periodic evaluations. X. Observations. XI. This personnel must be hired in accordance with current labor laws and regulations.
9.1 Document classification and handling. Procedures must exist to classify documents according to their sensitivity and/or importance. Sensitive and important documentation must be stored in a secure area that only allows access to authorized personnel. The useful life of the documentation must be identified, and procedures for its destruction must be established. The company must conduct regular reviews to verify access to information and ensure that it is not used improperly. Response: Explanatory Notes: Attach the documented procedure for the registration, control, and storage of printed documentation (classification and filing of documents), which must include: I. Control register for delivery, loan, among others of documentation. II. Restricted access to the archive area. III. Storage and classification policies. IV. An updated security plan describing the measures in force regarding the protection of documents against unauthorized access, as well as against deliberate destruction or loss of the same. V. In the case of electronic or digital information, it must adhere to the security criteria of sub-standard 9.2 Information Technology Security.
9.2 Information Technology Security. To protect Information Technology systems against common cybersecurity threats, a company must have sufficient protection that promotes security in Information Technology infrastructure (software and hardware) against malware (viruses, spyware, worms, trojans, etc.), baiting, phishing, and internal/external intrusions (firewalls) in the companies' computer systems. Likewise, companies must ensure that their security software is active and receives periodic updates. In the case of automated systems and computer equipment, individual accounts requiring periodic password changes must be used. In order to protect the confidentiality, integrity, and availability of information, the company must have policies, procedures, and information technology standards established, which must be communicated through a training program for all employees who handle computer equipment and systems, which includes topics to prevent attacks through social engineering and all those threats to which they are exposed (malware, baiting, phishing, etc.). Companies that allow their employees to connect remotely to a network must use secure technologies, such as virtual private networks (VPN), to allow employees to access the company intranet securely when they are outside the office, as well as procedures designed to prevent unauthorized remote access.
For the above, there must be written procedures and infrastructure to protect the company against loss, theft, leakage, hacking, and/or ransomware of information, this includes the procedure for the recovery (or replacement) of Information Technology systems and/or data, as well as a system or software established to identify the abuse of Information Technology systems and detect inappropriate access and/or improper manipulation or alteration of commercial and business data, as well as a written procedure for the application of appropriate disciplinary measures to all offenders. Access to Information Technology systems must be protected against infiltration through the use of secure passwords, which include passphrases or other forms of authentication. Users of said Information Technology systems must safeguard and not share their access keys or passwords. All Information Technology infrastructure must be physically protected against unauthorized access. If a data leak or other unexpected event occurs resulting in the loss of data and/or equipment, the procedures must include the recovery or replacement of Information Technology systems and/or data. Response: Explanatory Notes: Attach the procedure for the recovery or replacement of Information Technology systems and/or data, which includes how it backs up and guarantees the security of its information, in addition to protecting it from possible losses. Ensure you include the following points: I. Indicate the frequency with which information backups are carried out. II. Who has access to them and who authorizes the recovery of information. III. Indicate what type of tests it performs and how often, to verify the security of the network, systems, and infrastructure. IV. Mention if, to carry out this type of tests or vulnerability scans, it does so through software, a third party or provider, and if so, indicate the name or corporate name. V. In case of finding vulnerabilities, describe the corrective actions that must be implemented. VI. Indicate if it shares information about cybersecurity threats with its commercial partners participating in its supply chain (for example: communications, bulletins, emails, etc.).
VII. Systems must be protected with passwords and must be modified frequently, therefore indicate the procedure to change them. VIII. Indicate if there are information security policies for their protection. IX. There must be a system or software to detect and identify the abuse, intrusion, or unauthorized access of persons to its systems and/or Information Technology data (any system used by the company), as well as the abuse of the policies and procedures established by the company, including unauthorized access to internal systems, external websites, and the manipulation or alteration of commercial data by employees or contractors. X. All offenders must be subject to the application of disciplinary measures, therefore, indicate the corrective policies and/or sanctions in case of the detection of any violation of Information Technology systems and security policies. The policies and procedures for information technology and cybersecurity must be reviewed annually and updated due to an attack or according to situations that may put the company's systems at risk. Describe the security measures used to allow employees to connect remotely to a network (VPN), to allow employees to access the company intranet remotely when they are outside the office.
In the case of allowing employees to use personal devices to perform the company's work, such devices must comply with the company's cybersecurity policies and procedures, security updates must be periodic, and there must be a method to access the company network securely. Indicate if commercial partners have access to the company's computer systems. If so, indicate what programs and how they control access to them. Indicate if the computer equipment has a backup power supply system that allows business continuity. The procedures regarding the backup of the company's information must also include: I. How and for how long data is stored (data should be backed up once a week or as appropriate). II. Business continuity plan in case of incident and how to recover information. III. Frequency and location of backup copies and archived information. IV. If backup copies are stored in sites alternative to the facilities where the data processing center is located. V. Tests of the validity of data recovery from backup copies.
The procedures regarding the protection of the company's information must also include: I. An updated and documented policy for the protection of the company's computer systems against unauthorized access and deliberate destruction or loss of information. All sensitive and confidential data must be stored in an encrypted or encoded format. II. Detail if it operates with multiple systems (sites/locations) and how these systems are controlled. III. Who is responsible for the protection of the company's computer system (responsibility should not be limited to one person, but to several, so that each can control the actions of the rest). IV. Each user's access must be assigned through individual accounts and restricted according to the job description or assigned tasks. For this reason, describe how access authorizations and access levels to computer systems are granted (access to sensitive information must be limited to authorized personnel to make modifications and use the information). Authorized access must be monitored by the area responsible for granting it, to verify or, if applicable, report that access to confidential systems is based on job requirements. V. Indicate the elements or format that passwords for access to Information Technology systems and computer equipment must have, frequency of changes, if there are other authentication methods, and who or what area provides those passwords.
VI. Indicate the name of the firewall and antivirus used (include licensing related), evidencing that this security software is active and receives periodic updates. For the above, cybersecurity policies and procedures should include measures to prevent the use of counterfeit technological products or with incorrect licenses (software and hardware). All computer equipment, electronic media (hard drives, cell phones, etc.), and information technology hardware containing confidential information related to the import and export process must be counted through periodic inventories and have such evidence. When these technological equipment must be discarded, there must be a documented procedure that includes how they must be formatted, disinfected, or destroyed appropriately to prevent information leakage. VII. In the case of personnel termination, access to computer equipment, telecommunications, and network must be eliminated at the moment of the employee's separation, this includes email accounts, system access accounts, software, programs, etc. VIII. Measures planned to handle incidents when the system is compromised.
10.1 Training and awareness on threats. The company must have a training and awareness program on security policies in the supply chain directed at all its employees (operational and administrative), and additionally, make available informational material regarding the procedures established in the company to consider a situation that threatens its security and know how to report it. In the same way, specific training must be offered according to their functions to help employees maintain cargo integrity, perform container, trailer and/or semi-trailer reviews for agricultural and security purposes, receipt and review of mail and packages, prevention of operations with proceeds of illicit origin (money laundering, terrorism financing, etc.), how to recognize and how to report internal conspiracies, protect access controls, as well as training regarding smuggling, cargo theft, placement of high-security seals and locks (VVTT inspection method), prevention of visible contamination by pests, etc. These topics must be established as part of new employee onboarding and periodically maintain update programs. Update training must be carried out periodically, after a security incident and when there are changes in the company's procedures. In addition to security training programs, an awareness program on alcohol and drug consumption must be included. Also, disseminate and train staff on the company's cybersecurity policies, procedures and standards (theft, leakage, hacking and/or information kidnapping), including access to computer equipment and systems via passwords or phrases. The personnel who operate and administer security technology systems must receive training related to their operation and maintenance, including self-training through operational manuals and other methods. These topics must be established as part of new employee onboarding and periodically maintain update programs. Training programs must encourage active employee participation in security controls and mechanisms, as well as maintain records of all training efforts provided by the company and the list of those who participated in them (videos, photographs, minutes, attendance lists, intranet or other system, didactic material, PowerPoint presentations, brochures, etc.). Training records must include the date of the training, the names of the attendees, the topics taught, in addition to having measures to verify that the training provided met all training objectives. Response: Explanatory Notes: They must have a training program on security and prevention of security incidents in the supply chain for all employees who work for the company (administrative, operational, direct or indirect). Briefly explain what the training program consists of and make sure to include the following: I. Brief description of the topics taught in the program. II. When they are taught (onboarding, specific periods, resulting from audits, security incidents, etc.). III. Frequency of training, as well as updates and reinforcement. IV. Indicate how participation in supply chain security training is documented (videos, photographs, minutes, attendance lists, intranet or other system, didactic material, PowerPoint presentations, brochures, etc.). Training records must include the date, the names of the attendees, the topics taught, in addition to having measures to verify that the training provided met all the objectives of the same. V. Explain how employee participation in supply chain security issues is encouraged. Training to perform the review of cargo vehicles, containers, trailers and/or semi-trailers for agricultural and security purposes must include the following topics: I. Signs of hidden compartments; II. Smuggling hidden in natural compartments; III. Signs of pest contamination; IV. Procedures to follow if something is found during an inspection of the means of transport or if a security incident occurs during transit; and V. Agricultural review training must cover pest prevention measures, the regulatory requirements applicable to wooden packaging materials in accordance with International Phytosanitary Measure Standard No. 15, known as Regulation of wooden packaging used in International Trade, which emanate from the Food and Agriculture Organization of the United Nations and the identification of infested wood.
10.2 Awareness for transport medium operators. The company must make known to the operators of the means of transport it uses for the transfer of goods destined for foreign trade, the security policies regarding agricultural and security inspection procedures of means of transport, loading and unloading, handling of security incidents, change of locks in case of inspection by other authorities, among others, that are implemented. The operators and the personnel who perform agricultural and security inspections of means of transport must be trained to inspect cargo vehicles for such purposes. In the case that the transport service is provided by a business partner, it must ensure that the operators and/or drivers know all the security policies and procedures established. Response: Explanatory Notes: Describe the dissemination program on supply chain security focused on transport medium operators and make sure to include the following: I. Indicate how this dissemination is carried out. II. Point out the topics covered. III. In case of using the services of a business partner for the transfer of your goods, indicate how the operators are informed of the company's security policies and procedures. IV. Indicate how participation in supply chain security training for transport medium operators is documented (videos, attendance lists, brochures, etc.). The topics that must include, by way of illustration and not limitation, are: I. Access and security policies at the facilities. II. Cargo delivery-receipt (including suspicious cargo shipments). III. Confidentiality of cargo information. IV. Transfer instructions. V. Accident and emergency reports. VI. Instructions for the placement of high-security locks and/or seals in case of inspection by other authorities, as well as the control and use of high-security seals and locks in transit (placement of a new one, review after any authorized stop, etc.). VII. Installation and testing of security and unit tracking alarms, when applicable. VIII. Identification of authorized formats and documents to be used. IX. Signs of hidden compartments. X. Smuggling hidden in natural compartments. XI. Signs of pest contamination. XII. Procedures to follow if something is found during an inspection of the means of transport or if a security incident occurs during transit.
11.1 Reporting of anomalies and/or suspicious activities. In the event of detection of anomalies and/or suspicious activities related to supply chain security and in accordance with its logistical processes (related to access control, delivery, receipt and storage of goods, security inspections of cargo vehicles and transport operators, etc.), these must be notified to security personnel, business partners that may be part of the affected supply chain, security specialist or contact of the Authorized Economic Operator Program and the other competent authorities, keeping a record of said anomalies and/or unusual activities. Response: Explanatory Notes: Describe the procedure to report or report anomalies and/or suspicious activities, as well as those that contain mechanisms to anonymously report problems related to security, make sure to include the following: I. Who is responsible for reporting incidents. II. Detail how it determines and identifies with which authority to communicate in different scenarios or presumption of suspicious activities. III. Mention if it keeps a record of the report of these activities and/or suspicions and briefly describe what it consists of.
11.2 Investigation and analysis. There must be written procedures to report or report anomalies and/or suspicious activities, as well as for the analysis and investigation of security incidents in the supply chain to determine their cause, in addition to corrective actions to prevent them from happening again, which must be implemented as soon as possible. The information derived from this investigation must be documented and available at all times for the authorities that require it. This information must include the documentation generated to carry out the foreign trade operation of the affected goods that allows identifying each of the processes through which the goods went, up to the point where the incidence was detected and that allows recognizing the vulnerability of the chain.
Response: Explanatory Notes: Describe the documented procedure to initiate an investigation in the event of any security incident and make sure to include the following: I. Responsible for carrying out the investigation. II. Documentation that integrates the investigation file. The documents to be included in the file derived from the investigation, by way of illustration and not limitation, may be: I. General information of the shipment, purchase order. II. Transport request; confirmation of means of transport; identification of transport operator (access records, exit, record of security inspections, etc.). III. Container inspection formats; exit order; delivery records. IV. Videos from alarm systems and closed-circuit television and video surveillance. V. Documentation generated for the carrier (packing list, bill of lading, instruction sheet). VI. Documentation generated for business partners (description of goods, proformas, CFDI or equivalent documents, etc.) and customs authorities. VII. Documentation generated by the business partner (customs declarations, manifests, tracking and inspection reports, videos if applicable, etc.). VIII. Unit tracking and monitoring report (GPS tracking).
E4. Customs Broker Profile Acknowledgment of Receipt First Time: Renewal: Addition: Modification: The data you provide will replace the data you provided when you requested your authorization. General Information. The objective of this Profile is to ensure that the Customs Broker implements security practices and processes, which help strengthen the supply chain by mitigating the risk of contamination in shipments with illicit products and likewise reducing the risk of incurring incidents during the customs clearance of goods. Customs brokers interested in obtaining the authorization referred to in rule 7.1.5., must have documented and verifiable processes. Likewise, the Customs Broker who is interested in the authorization must integrate the criteria required in this document into the business model or design that it has established, seeking during the implementation of security standards, the application of an analysis culture that supports decision-making in accordance with the values, mission, vision, codes of ethics and conduct of the Customs Broker itself. It is important to mention that the scope of the minimum security criteria required in this Profile is applicable to the essential operation performed by the Customs Broker, mainly to the processes related to the customs clearance of goods. Likewise, and taking into account the variety of integrated logistical services that a Customs Broker can currently provide to its clients, certain additional criteria are contemplated to be met, specifically for customs brokers who concentrate or have holding yards and/or maneuvers for the means of transport of goods subject to foreign trade in the same facilities where they provide their services. Filling Instructions: I. You must fill out a Profile for each of the facilities associated with the customs office of assignment, as well as for each of the facilities associated with the additional customs offices of the customs patent. This information must coincide with what is stated in your application for Certified Business Partner of Customs Broker. II. Detail how the Customs Broker complies with or exceeds what is established in each of the numerals as indicated. III. The format of this document is divided into two sections, as detailed below:
Facility Data A Customs Broker Profile must be filled out for each of the facilities associated with the customs office of assignment, as well as for each of the facilities associated with the additional customs offices under the customs patent. Customs Broker Information. Customs Broker Profile Number: from: Customs Broker Name: ____________________ Patent: _______________ Authorization: Assignment: _________ Assignment: ________________ Authorized Customs Offices (name): Name and/or Denomination of the installation: Type of Installation (administrative offices, facilities with merchandise storage or transport service, etc.): Street Number and/or exterior letter Number and/or interior letter Neighborhood Postal Code Municipality/Delegation Federal Entity Age of the Installation (years of operation) Predominant activity Types of services: Does it perform validation of customs declarations in this installation: No. of average monthly operations (EXP): (By means of transport, maritime, air, land, rail, etc.) No. of average monthly operations (IMP): (By means of transport, maritime, air, land, rail, etc.) Total number of employees at this installation: Surface area of the Installation (m2):
Certifications in security programs: (Indicate if this installation has a certification for any of the following programs) Supply Chain Security Programs Yes No Program: Registration: Certifying Body: Certifications: (Indicate if you have certifications that you consider impact your supply chain process, for example: ISO 9000; Reliable Logistics Processes, among others) Name: Category: Validity: Name: Category: Validity: Name: Category: Validity:
1.1 Risk analysis. The Customs Broker must have measures to identify, analyze and mitigate security risks throughout the supply chain, including its facilities. For this reason, it must have a written and verifiable procedure to determine the risk in all its operations, based on its organization's model (example: location of facilities, type of merchandise and country of origin, volume, clients, suppliers, routes, hiring of personnel, classification and handling of documents, Information Technologies, potential threats, etc.) that allows it to implement and maintain appropriate security measures. In accordance with the above, the Customs Broker must also have a written process based on its risk analysis to select new business partners and monitor those with whom it is already working.
This procedure must be executed at least once a year, so as to allow the permanent identification of other threats or risks considered in its operation and in the supply chain, resulting from some incident or when they originate from changes in the initial conditions of the facilities and processes of the Customs Broker, as well as to identify that the policies, procedures, and other control and security mechanisms are being complied with. It is important to note that the Company's Security Committee designated by the Customs Broker must participate in the preparation and updating of the risk analysis and the maintenance of the Authorized Economic Operator Program.
Response: Explanatory Notes: Indicate which are the sources of information used to qualify risks during the analysis phase. Attach the risk matrix, as well as the documented procedure to identify risks in its daily operations throughout the supply chain and in its facilities, which must include at least the following points. I. Periodicity with which it reviews and/or updates the risk analysis. II. Aspects and/or areas that the Customs Broker incorporates into the risk analysis. III. Methodology or techniques used to perform the risk analysis. IV. Persons responsible for reviewing and/or updating the company's risk analysis. Likewise, the documented procedure to identify risks in the supply chain and its facilities must contemplate the process of risk appreciation and management, and include the following aspects: I. Establishment of a context (cultural, political, legal, economic, geographic, social, etc.). II. Identification of risks in its supply chains and its facilities. III. Risk analysis (causes, consequences, probabilities, and existing controls to determine the level of risk as high, medium, and low). IV. Risk evaluation (decision-making to determine the risks to be treated and priority for implementing treatment). V. Risk treatment (application of alternatives to change the probability of risks occurring). VI. Risk monitoring and review (monitoring of the results of the risk analysis and verification of the effectiveness of its treatment). It is suggested to use risk administration, management, and evaluation techniques in accordance with international standards ISO 31000, ISO 31010, and ISO 28000 that, according to its business model, must be implemented.
1.2 Security Policies. The customs broker must have policies oriented towards preventing, securing, and recognizing threats to the security of the supply chain and facilities, such as drug trafficking, money laundering, arms trafficking, human smuggling, prohibited goods, acts of terrorism, as well as in the exchange of information, reflected in the corresponding procedures. To promote a culture of security, the Customs Broker must demonstrate its commitment to the security of the supply chain and the Authorized Economic Operator Program through a statement highlighting the importance of protecting the flow of national and international commerce from criminal activities, established through the security policy. The Customs Broker must endorse and sign the security policy.
Response: Explanatory Notes: State the policies in matters of security oriented towards preventing, securing, and recognizing threats in the supply chain and facilities of the Customs Broker, who is responsible for their review, signature, and dissemination to employees, as well as the periodicity with which its update is carried out. This policy must be communicated to employees through a dissemination program and/or campaign. The security policy must be signed by the Customs Broker and be displayed in various areas of the facility, including the Customs Broker's website, posters in key areas of the facility (reception, import and/or export, human resources, etc.), and as part of initial and reinforcement training.
1.3 Internal Audits in the Supply Chain. In addition to routine monitoring in control and security, it is necessary to schedule and carry out audits at least once a year that allow evaluating all processes in matters of security in the supply chain in a more critical and profound way, as well as guaranteeing that its employees follow the security procedures of the Customs Broker. The audits must be carried out by the Security Committee and a documented procedure must be established, as well as a program or calendar for their execution. Although it is necessary that the audits be focused on the security of the supply chain and based on the evaluation, review, and execution of minimum standards in matters of security, their focus must be adjusted to the size of the organization, level of risk, business model, and variations between facilities. The objective of an internal audit focused on the Authorized Economic Operator Program is to verify and guarantee that employees follow the security procedures of the Customs Broker. The review process does not have to be complex; however, the formats and records used for the application of such reviews must evidence that the application and execution of the evaluated processes were validated, in addition to the follow-up and closure of preventive, corrective, and improvement actions identified. The senior management of the organization must review the results of the audits, analyze the causes, and undertake the corrective and/or preventive actions required. The audit process must guarantee that the necessary information is collected to allow management to perform this evaluation. The review must be documented, in addition to the fact that the Customs Broker's Security Committee must provide and register periodic updates on the progress or results of any audit, exercise, or validation.
Response: Explanatory Notes: Describe the documented procedure to carry out an internal audit, focused on security in the supply chain; ensure you include the following points: I. Indicate how the scheduling or calendarization is carried out to perform an internal audit in matters of security in the supply chain, which has been implemented by the Customs Broker. II. Indicate who participates in it, and the records that are made of it, as well as the periodicity with which they are carried out. III. Indicate how the management or the Customs Broker verifies the results of the security audits, how it performs and/or implements preventive, corrective, and improvement actions, in addition to the follow-up and closure of the same. IV. The formats used during internal audits must be properly filled out, and through them, evidence that the procedures and security measures are being put into practice.
1.4 Contingency and/or Emergency Plans. There must be a documented contingency and/or emergency plan; this plan must address crisis management, security recovery plans, and the resumption of the organization related to the security of the supply chain and its facilities to ensure business continuity in the event of a situation that affects the normal development of activities and foreign trade operations. A crisis or contingency may include the interruption of commercial data movement due to a cyberattack, a fire, the kidnapping of a transport driver by armed individuals, a customs closure, a bomb threat, the detection of suspicious packages, a power outage, theft and/or damage to goods, threats or extortion, blockades or road closures, among others. Such plans must be communicated to administrative and operational personnel through dissemination programs and periodic trainings, as well as carrying out tests, practical exercises, and annual simulations of the contingency and emergency plans to verify their effectiveness, from which it must maintain a properly filled-out and signed record (for example: result reports, minutes, or reports which must be backed up by video recordings, photographs, etc., demonstrating their execution). The contingency and/or emergency plan must be updated as necessary, based on changes in operations and the organization's risk level.
Response: Explanatory Notes: Attach the documented contingency and/or emergency procedure or plan related to the security of the supply chain and its facilities, to ensure business continuity in case of an emergency or security situation that affects the normal development of foreign trade activities (cancellation or suspension of patent, closure of customs, foreign trade activities considered risky according to its analysis, acts of terrorism, blockades, robberies, accidents, etc.). This procedure must include, by way of enumeration but not limitation, the following: I. What situations it contemplates by describing the action plan and steps to be followed in case of crisis, as well as the tasks assigned to personnel during the handling of such contingencies. II. What mechanisms it uses to disseminate and ensure that these plans are effective. III. Contemplate the scheduling and carrying out of tests, practical exercises, and annual simulations and how they are documented (for example: result reports, minutes, or reports, which must be accompanied by video recordings, photographs, etc., demonstrating their execution).
2.1 Facilities. Facilities must be constructed with materials that can resist unauthorized access. Periodic documented inspections must be carried out to maintain the integrity of the structures, and in the event that an irregularity has been detected, the corresponding repair must be carried out as soon as possible by the personnel designated for these tasks. Likewise, the territorial limits, as well as the various accesses, internal routes, and the location of the buildings must be fully identified.
Response: Explanatory Notes: Indicate the predominant materials with which the facilities are constructed (for example, metal structure and sheet metal walls, brick walls, concrete, cyclone mesh, among others), and indicate how the review and maintenance of the structures is carried out. Indicate the personnel or area responsible for carrying out the tasks of inspection, maintenance, and repair of damages to the facilities. Attach a distribution or architectural plan of the facilities, where the limits of the facilities, access routes, emergency exits, location of buildings or offices, critical areas, parking lots, and boundaries can be identified.
2.2 Accesses in Doors and Booths. The entrance or exit doors for personnel and/or vehicles of the Customs Broker's facilities or, in its case, access to the yards for freight transport means located in the same place, must be attended, controlled, watched, and/or supervised either by its own properly trained personnel or by private security personnel. The number of access doors must be kept to the minimum necessary. Access to sensitive areas must be restricted according to the job description or assigned tasks.
Response: Explanatory Notes: Indicate how many doors and/or accesses exist in the facilities, as well as the operating hours of each one and indicate how they are monitored (in case of having assigned personnel, indicate the quantity). Detail if there are blocked and/or permanently closed doors and/or accesses. Describe how it ensures that access to sensitive areas is restricted according to the job description or assigned tasks (include the type of records and controls it uses).
2.3 Perimeter Fences. Perimeter fences and/or peripheral barriers must be installed to secure the perimeters of the Customs Broker's facilities, according to a risk analysis. In the case of having a yard for freight transport means located in the same facilities, it must be delimited, as well as the place where any maneuver and/or handling of cargo takes place as appropriate. These must be inspected regularly and keep a record of the review with the purpose of ensuring their integrity and identifying damages, which must be repaired as soon as possible by the personnel designated for these tasks.
Response: Explanatory Notes: Describe the type of fence, peripheral barrier, and/or walls that the Customs Broker's facilities have; ensure you include the following points: I. Indicate the characteristics of the same (material, dimensions, etc.). II. In case of not having fences, justify the reason in detail. III. Periodicity with which the integrity of the perimeter fences is verified, and the records that are kept with the purpose of ensuring their integrity and identifying damages, which must be repaired as soon as possible. IV. Indicate the personnel or area responsible for carrying out the tasks of inspection and repair of damages.
In case of having a yard for transport means in its facilities, describe how it is delimited. The procedure for the inspection of perimeter fences may include: I. Personnel responsible for carrying out the process. II. How and with what frequency the inspections of the fences, perimeter fences, and/or peripheral barriers and the buildings are carried out. III. How the inspection record is carried out. IV. Who is responsible for verifying that the repairs and/or modifications meet the technical specifications and necessary security requirements.
2.4 Parking Lots. In the case of having parking lots in the facilities, access to them must be controlled and monitored by security personnel or designated for this task. It must be prohibited for private vehicles (of employees, visitors, suppliers, and contractors, among others) to park in its case within the yard for transport means, as well as in adjacent areas.
Response: Explanatory Notes: Describe the procedure for the control and monitoring of parking lots; ensure you include the following points: I. Persons responsible for controlling and monitoring access to the parking lots. II. Identification of the parking lots (in its case) specify if the employee, visitor parking is separated from the storage and merchandise handling areas. III. How the control of entry and exit of vehicles to the facilities is carried out. Indicate the records that are made for the control of parking, the existing control mechanisms, for example: badges, card readers, lanyards, etc., how they are assigned and the responsible area for doing so. IV. Policies or mechanisms (in its case) to not allow the entry of private vehicles to the storage and merchandise handling areas.
2.5 Key and Lock Device Control. Windows, doors, as well as inner and outer fences must be secured with locking devices; these devices must be implemented according to the Customs Broker's risk analysis. Likewise, the Customs Broker must have documented procedures for the handling, storage, assignment, and control of keys in the facilities, keeping a record and establishing signed responsibility letters by the persons who have keys or authorized accesses according to their level of responsibility and work within their area of work.
Response: Explanatory Notes: Indicate if all doors, windows, inner and outer entrances have locking or security mechanisms. Attach the documented procedure or procedures for the control, storage, assignment, and handling of keys and/or locking devices of the facilities, offices, and inner areas. Ensure that these procedures include the following points: I. Persons responsible for administering and controlling the security of the keys. II. Format and/or control record for the loan of keys. III. Treatment of loss or non-return of keys. IV. Indicate if there are areas in which access is gained with electronic devices and/or any other access mechanism.
2.6 Lighting. Lighting inside and outside the facilities must allow clear identification of people, material, and/or equipment located there, including the following areas: entrances, exits, perimeter and/or peripheral fences, inner fences, and parking areas in its case. An emergency and/or backup system must be available in sensitive areas.
Response: Explanatory Notes: Describe the procedure for the operation and maintenance of the lighting system. Ensure you include the following points: I. Indicate which areas are illuminated and which have a backup system (Indicate if it has an auxiliary power plant or any other mechanism to supply electricity in case of any contingency). II. How it ensures that the lighting system has continuity in the event of lack of supply in each of the areas of the facilities, in such a way as to allow clear identification of the personnel, material, and/or equipment located there. III. Person responsible for the control of the lighting systems. IV. Maintenance and review program (in case it coincides with another process, indicate it). The procedure may include: I. How the lighting system is controlled. II. Operating hours. III. Identification of areas with permanent lighting.
2.7 Alarm Systems and Closed-Circuit Television and Video Surveillance. Alarm systems, closed-circuit television, and video surveillance systems and security technologies must be used to watch, notify, or deter unauthorized accesses and prohibited activities in the facilities and other considered sensitive areas, notify the corresponding area, in addition to being used as a tool of proof in investigations derived from some security incident. These security systems and technologies must be placed according to a prior risk analysis in such a way that areas involving the access of personnel, visitors, and suppliers are kept under watch and monitored, and in its case, the access areas for passenger vehicles and cargo vehicles and others considered sensitive. Such systems must allow clear identification of the area or environment being watched, be permanently recording, and keep a backup of the recordings for at least one month, with the purpose of having the necessary elements to disclaim responsibilities in case of a security incident. Alarm systems, closed-circuit television, and video surveillance systems and security technologies must have a documented operation procedure that includes the supervision of the good condition of the equipment and the verification of the correct position of the cameras, indicating the frequency with which the backup of the recordings must be performed, as well as the persons responsible for their operation. Such a system and all security technology infrastructure must have restricted access.
Response: Explanatory Notes: Mention the documented procedure that indicates the functioning of the external alarm central system or sensors, and in its case, describe the following points: I. Indicate if the doors and windows have alarm sensors, as well as the areas where motion sensors are available. II. Procedure to follow in case an alarm is activated. III. Indicate the personnel, responsible area, or service provider to give maintenance, how failures are reported, and the records they use. Describe the documented procedure for the operation of alarm systems, closed-circuit television, and video surveillance systems and security technologies (this must be reviewed and updated annually and according to the risk analysis or circumstances); ensure you include the following points:
I. Indicate the number of security cameras of the alarm systems, closed-circuit television, and video surveillance systems installed, technical characteristics, and their location. Detail if it covers the entry and exit points of the facilities, to cover the movement of vehicles and individuals, as well as the place of storage of the vehicles). Attach a layout or map of the distribution of the security cameras. II. Indicate the location of the alarm systems, closed-circuit television, and video surveillance systems and security technologies, where the monitors are located, who reviews them, as well as the operating hours, and in its case, if there are remote monitoring stations. All security technology infrastructure must be physically protected against unauthorized access. III. Periodic and random reviews of the recordings must be carried out. Indicate how they review them (random, every week, special events, restricted areas, etc.), who is the designated personnel, and how they are involved in the reviews. The results of the reviews must be documented to include corrective actions for audit purposes. IV. Indicate for how long these recordings are kept (being at least one month). V. The alarm systems, closed-circuit television, and video surveillance systems and security technologies must have an alternative energy source that allows these to continue functioning in case of an unexpected loss of energy.
directa. Therefore, indicate whether the alarm systems, closed-circuit television, video surveillance systems, and security technologies are backed by an electrical power plant or some other mechanism to supply electricity that guarantees their operation. These systems should have an alarm/notification function, indicating a failure condition in operation and/or recording; indicate whether your systems have such a function.
VI. Indicate whether, in addition to the alarm systems, closed-circuit television, and video surveillance, you use any other type of technology to strengthen the security measures already in place.
VII. Describe the procedure implemented to regularly test and inspect the alarm systems, closed-circuit television, video surveillance systems, and security technologies to ensure their proper operation. The results of the inspections and operational tests must be documented, as well as any necessary corrective actions (which must be implemented as soon as possible). Additionally, the documented results of these inspections must be retained for a sufficient period for audit purposes.
VIII. Indicate whether the provider of the alarm systems, closed-circuit television, and video surveillance has access to the security cameras, if they are responsible for monitoring them, how access is controlled, and who is responsible for said monitoring.
Access controls must include the identification of all employees, visitors, and providers at all entry points. Furthermore, records must be maintained and the documented mechanisms or procedures for entry into the facilities must be permanently evaluated, serving as the basis for beginning to integrate security as one of the primary functions within them.
3.1 Security personnel. Based on your risk analysis, the Customs Broker must have security and surveillance personnel or designated personnel. This personnel plays an important role in the physical protection of the facilities and, as applicable, the yard where cargo vehicles are stored, as well as in controlling access of all persons to the property.
The security personnel or designated personnel for these tasks must have a documented procedure to carry out their functions and have full knowledge of the mechanisms and procedures in emergency situations, detection of unauthorized persons, or any security incident at the facility. The Customs Broker must periodically verify compliance with procedures, policies, and functions through internal audits with the objective of verifying their correct execution.
Likewise, the Customs Broker must have devices and/or communication systems in order to have immediate contact with security personnel and/or the corresponding authorities.
Response: Explanatory Notes: Describe the documented procedure for the operation of security personnel, and ensure you include the following points:
I. Describe the procedure that personnel must follow to contact security personnel, designated personnel, or as applicable, the corresponding authority.
II. Indicate what communication devices are used by security personnel or designated personnel (landlines, cell phones, radios, alarm systems, etc.).
III. Indicate the number of security personnel working at the Customs Broker's facilities.
IV. Specify the positions and/or functions of the personnel, and operating hours.
V. In the event of hiring an external service, provide the general data of the company (RFC key, corporate name, and address), specify the number of employees, operational details, records, and reports they use to perform their functions.
VI. In the event of having armed personnel; describe the procedure for the control and safeguarding of weapons.
3.2 Identification of employees, visitors, and providers. There must be an identification system for employees, visitors, and providers for the purpose of accessing the facilities. Employees should only have access to those areas they need to perform their functions. Access to sensitive areas must be restricted according to the job description or assigned tasks.
Visitors and providers must present official photo identification for documentation upon arrival, and a record must be kept. All visitors and providers must receive temporary identification, be accompanied by personnel working with the Customs Broker during their stay at the facilities, and ensure that the visitor/provider always wears the provided provisional identification in a visible place.
The management or security personnel of the Customs Broker must properly control the delivery and return of identification badges for employees, visitors, and providers, and ensure that they always wear the provided identification in a visible place. This procedure must be documented, as well as the procedures for the delivery, return, and change of access devices (for example, keys, badges and/or credentials, proximity cards, etc.).
Response: Explanatory Notes: Attach the documented procedure for the control of identifications. Describe the procedure for the identification of employees and ensure you include the following points:
I. Identification mechanisms (badge and/or photo credential, uniform, access control, biometrics, proximity cards, etc.).
II. Identify whether employees use uniforms, how they are assigned (by position, area, functions, etc.) and withdrawn (as applicable).
III. Indicate how personnel contracted by a business partner, working within the facilities (contractors, subcontractors, etc.), are identified.
The procedure must also describe how the Customs Broker delivers, changes, and withdraws employee identifications and access controls, and ensure you include the responsible areas for authorizing and administering them.
Indicate how you ensure that access to sensitive areas is restricted according to the job description or assigned tasks (include the type of records and controls you use).
Describe the procedure for controlling access for visitors and providers, ensure you include the following points:
I. Specify what records are kept (personal forms for each visit, logbooks, etc.).
II. The record of visitors and providers must include the following: a) Date of the visit; b) Name of the visitor; c) Identification number with photo (official documents, such as: driver's license, passport, INE, etc.). d) Time of entry and exit; e) In the case of vehicular access, the format must include the data of the private or cargo vehicle (model, license plate, trailer number, etc.).
III. Specify who is the person responsible for accompanying the visitor and/or provider, and if there are restricted areas for their entry.
3.3 Procedure for identification and removal of unauthorized persons or vehicles. The Customs Broker must have documented procedures that specify how to identify, confront, or report unauthorized or identified persons and/or vehicles. This procedure must be communicated to responsible personnel through training. The training must be documented.
Response: Explanatory Notes: Attach the documented procedure to identify, confront, or report unauthorized or identified persons and/or vehicles. The procedure must include:
I. Responsible personnel.
II. Designate a person or area responsible for being informed of security incidents.
III. Instructions for confronting and addressing unidentified personnel.
IV. Specify in which cases the corresponding authorities must be reported.
V. Specify how the recording of incidents and the measures adopted in each case is carried out.
3.4 Delivery of mail and packages. Mail and packages destined for the Customs Broker or their personnel must be examined upon arrival and before being distributed to the corresponding areas and destinations. Likewise, the Customs Broker must have a documented procedure for the receipt and review of mail and packages, which must be communicated to responsible personnel through training. The training must be documented.
Response: Explanatory Notes: Describe the procedure for the receipt and review of mail and packages and ensure you include the following:
I. Personnel in charge of carrying out the procedure.
II. Indicate how the personnel or provider of the mail and package service is identified (indicate if an additional procedure to the provider access procedure is required).
III. Specify how the review of the mail and/or packages is carried out, what mechanism is used, the records kept, and as applicable, detected incidents.
IV. Describe the characteristics or elements to determine which mail and/or packages are suspicious.
V. Specify what action is taken in the event of detecting suspicious mail and/or packages.
The risk analysis performed by the Customs Broker regarding their commercial partners (clients and providers) must include risks related to the identification of activities related to money laundering and terrorism financing. Additionally, the Customs Broker must foster a documented social compliance policy and program that, at a minimum, addresses how among their employees and commercial partners they could guarantee that goods, supplies, or merchandise from Mexico or imported for the manufacture of products or merchandise do not originate from extraction, production, or manufacturing, totally or partially, using prohibited forms of labor, that is, forced or compulsory labor, including forced or compulsory child labor, under Article 23.6 of the USMCA and the Labor and Social Welfare Agreement that establishes the merchandise whose importation is subject to regulation by the Secretariat of Labor and Social Welfare, published in the Official Gazette of the Federation on February 17, 2023.
4.1 Selection criteria. There must be documented procedures for the selection, follow-up, and renewal of commercial relationships with business associates or providers, which include interviews, reference verification, evaluation methods, and use of provided information. The information derived from the investigation and/or evaluation of business associates and/or providers must be documented and integrated into a file (physical or electronic). The procedure for the selection of commercial partners must include indicators to detect clients or providers that may not be legitimate or with unlocated addresses, as well as investigations, reviews, or evaluations of said partners for the identification and control of activities related to money laundering and terrorism financing. If the investigation and/or evaluation of any commercial partner leads to substantial doubts about the veracity of their operations or services, the Customs Broker must avoid their hiring and, as applicable, notify their security specialist or Authorized Economic Operator Program contact and the corresponding authority about their suspicions.
The Customs Broker must have a written procedure for the identification of vulnerable activities established in Article 17, fraction XIV, as well as for compliance with the obligations established in Article 18 of the Federal Law for the Prevention and Identification of Operations with Resources of Illicit Origin (LFPIORPI).
Response: Explanatory Notes: Attach the documented procedure for the selection and contracting of new commercial partners, and monitoring of partners already working with them. This comprises any type of client and provider that has a commercial relationship with the Customs Broker, and ensure you include the following points:
I. What information is required from your commercial partner.
II. What aspects are reviewed and investigated (the result of the investigation must be integrated into the file).
III. Indicators to identify clients or providers that may not be legitimate (payments above the standard rate, in cash; having little knowledge of the merchandise to be dispatched; being evasive; minimal contact information (cell phone, contact points, emails, etc.); recently created companies or businesses without commercial history, etc.) or with unlocated addresses. This point refers to pointing out all those alerts to determine that a commercial partner is not reliable, thus conducting a deeper investigation and evaluating whether to work with them.
IV. Indicate if you maintain a physical or electronic file for each of your commercial partners, as well as the information it must contain.
V. For the case of providers, specify how the services of your commercial partner are evaluated and what points you review.
Likewise, the files for each of them must contain at least the documents that identify them fiscally and administratively depending on the type of relationship with the commercial partner. Considering the following:
I. Granted mandate: It will be issued in original independent of the one delivered electronically, for each foreign trade operation performed.
II. Copy of the mandate or power of attorney of the legal representative, as applicable.
III. Certified copy of the company's articles of incorporation (properly identified before the Public Registry of Property and Commerce).
IV. Registration in the RFC of the importer or exporter.
V. Notice of change of fiscal address, as applicable.
VI. Copy of official photo identification of the importer/exporter and of the legal representative, in case of being a legal entity.
Attach the documented procedure for compliance with the LFPIORPI, which must contain at a minimum:
I. Actions to take when any of the vulnerable activities marked in the cited Law are identified.
II. Notices to the SHCP (Ministry of Finance and Public Credit).
III. Integration of files of clients susceptible to this Law.
The file must include at a minimum the following:
I. Company data (name, RFC key, activity, etc.).
II. Legal representative data.
III. Proof of address.
IV. Commercial references.
V. Contracts, agreements, and/or confidentiality agreements.
VI. Security policies.
VII. As applicable, certificate or certification number in the security programs to which they belong.
4.2 Security requirements. The Customs Broker must have a documented procedure in which, according to their risk analysis, they request additional security requirements from those commercial partners that intervene in their supply chain such as transporters, private security companies, providers of loading and unloading services, correspondent agencies, as well as those resulting from the analysis performed. As well as providers of cleaning services, cafeteria, private security, personnel contracting, high-security seal providers, collection and recycling, among others.
The requirements must be based on the minimum security requirements established by the AGACE, or in case they exist, the specific Profile for each actor of the supply chain corresponding to them.
The Customs Broker must request from their commercial partners the documentation that accredits and proves that they comply with the minimum security standards established in the Customs Broker Profile, either through a written declaration issued by the legal representative of the partner, agreements or contractual clauses, backed by documentation that validates compliance with the requirements established in the Authorized Economic Operator Program. Likewise, the Customs Broker must take into account and know the specific requirements of the Authorized Economic Operator Program that will be applicable to each of their commercial partners, based on their activity within the supply chain.
In the case of commercial partners that provide a service within the facilities of the Customs Broker, they must be obligated to comply with these supply chain security requirements.
Response: Explanatory Notes: Describe the procedure that indicates how you carry out the identification of commercial partners that require compliance with minimum security standards. Ensure you include the following points:
I. A register of commercial partners that must comply with security requirements, and mention what type of providers these are (transport, storage, custodian service, private security company, correspondent agencies, loading and unloading service, etc.).
II. Indicate in what documentary form (agreements, accords, contractual clauses and/or addenda) you ensure that your commercial partners comply with security requirements.
III. Indicate if there are agreements, accords, contractual clauses and/or addenda regarding the implementation of security measures with your service providers inside the installation, such as: private security, cafeteria, gardening, cleaning and maintenance services, Information Technology providers, etc.
IV. Indicate if you have commercial partners to whom membership in a supply chain security program is required (for example: CTPAT or some other World Customs Organization Authorized Economic Operator Program) as well as the information and documentation requested of them.
Indicate the total annual number of declarations and the global value of those performed for each of the facilities from which you transmit the validation of declarations in each of the authorized customs offices of the customs patent.
In the case of partnerships with other customs brokers, there must be a list of the clients of the certified Customs Broker that are managed by said partnership.
Indicate the total annual number of declarations and the global value of those managed by each of the partnerships with other customs brokers to which they belong and indicate the following:
I. Name and denomination of the partnership.
II. Customs offices through which the partnership operates.
III. Complete address of the installation(s).
Describe how you ensure that the partnerships you have with other customs brokers, in which your patent is not an attachment or additional, comply with the minimum requirements in terms of security.
4.3 Commercial partner reviews. The Customs Broker through the Security Committee must perform periodic security evaluations (as well as derived from risk situations), of the processes and installations of business associates based on a risk analysis, to guarantee that they have the minimum security standards required by the Customs Broker based on the Authorized Economic Operator Program, keep records of them, which allow verifying that the processes and security measures are being executed, as well as the corresponding follow-up.
When inconsistencies are found, the Customs Broker must communicate them to their partner and/or provider and provide a justified period established in a procedure to address the observations or areas of opportunity identified, or in case of failure, have the necessary measures to sanction them.
Performing security evaluations of commercial partners is important to guarantee that there is a solid and functioning security program. Therefore, in addition to a documented procedure, there must be a program or calendar for the execution of these reviews or security evaluations, prioritizing partners that are more critical according to their risk analysis. If a member is not evaluated and the Customs Broker does not know if the processes and installations of their commercial partners function correctly, it puts their supply chain at risk.
Response: Explanatory Notes: Describe the procedure to perform evaluations to verify the security requirements (processes and installations) of your commercial partners, ensure you include the following points:
I. Periodicity with which you make visits to the commercial partner (these must be at least once a year and derived from risk situations).
II. Program or calendar for the execution of security reviews.
III. Registration or reporting of the verification and, where applicable, the corresponding follow-up. IV. The verification format(s) must be properly completed, including the date, name, and position of those participating in the review, signatures, etc. V. Indicate what action measures are taken when business partners do not meet the established security requirements. VI. In the event of having business partners with CTPAT certification or another supply chain security certification program, indicate the frequency with which their status is reviewed, how it is recorded, and the actions taken in case it is detected that it is suspended and/or cancelled in accordance with what is established in your procedure. For partners who have such security certification (granted by an authority), it will not be necessary to carry out visits, provided that the status of the certification is valid in accordance with what is established in your procedure. The procedure must include: I. Review points on security matters. II. Preparation of reports. III. Feedback and agreements with the business partner. IV. Follow-up on agreements. V. Measures in case of detection of non-compliance with requirements. VI. Record of evaluations. VII. Area or person responsible for carrying out this procedure.
5.1 Process Mapping. There must be a process map that describes step by step the information and operational flow for the transfer of foreign trade goods throughout the supply chain, allowing for a broad view of their foreign trade operations. The Customs Agent must take into account and include in their mapping all parties involved in their supply chain, containing those that handle import and export documentation, others who may not handle the cargo directly, but who may have operational control such as carriers (long-haul, cross-border or transfer, subcontracted, etc.), storage, sub-maquila, national and foreign suppliers, direct and indirect, etc. If any part of the transport is subcontracted within their supply chain, it is essential that it be considered within their risk analysis and process mapping, since, the more direct and indirect suppliers, the greater the risk involved. Response: Explanatory Notes: Attach the document where the mapping of processes through which the flow of information and import and export goods passes is illustrated and described, from the point where they receive them until their delivery, with the purpose of having each of the steps involved in the receipt, dispatch of the goods until their delivery at the final destination well identified. This process mapping must contain at least the following aspects: I. Verification of the corresponding registry. II. Granted mandate. III. Revalidation of the transport document, if applicable. IV. Pre-dispatch review. V. Tariff classification.
VI. Entry of the customs declaration (pedimento). VII. Compliance with regulations and non-tariff restrictions (obligation to have permits from the competent authority before presenting the goods for dispatch). VIII. Generation of the COVE (if applicable). IX. Value declaration. X. Determination of contributions. XI. Review of information transmitted to the SEA with the documentation generated from the shipment (Gloss). XII. Payment of contributions. XIII. Payment of maneuvers. XIV. Validation of the customs declaration. XV. Presentation of goods before the automated selection mechanism. XVI. Free customs clearance. XVII. Customs Inspection. XVIII. Procedure in case of taking samples (The importer may provide them through their Customs Agent at the time of dispatch provided that the samples contain the seals, stamps or any means that manifest that the laboratory result is preserved sterile or well it can be carried out by the authority). XIX. Handling and control of security means, high-security padlocks/seals and others. XX. Verification of the delivery of the goods at the agreed destination, if applicable. XXI. Procedure for re-dispatch of goods.
XXII. Procedure for the promotion of the withdrawal of an import or export. XXIII. Subdivision of the shipment. XXIV. Effective communication to customs authorities for cases that represent a risk in terms of security. XXV. Account of expenses of the shipment. XXVI. Measurement for customer satisfaction. XXVII. Treatment for complaints. XXVIII. Verification of goods in transport. XXIX. Consolidation of the shipment. XXX. Formation of the electronic file of each of the customs declarations or customs documents (article 167 of the Law).
5.2 Delivery, receipt and discrepancies in the cargo. The Customs Agent must supervise, according to the type of operations they perform and based on their risk analysis, the loading or unloading of the shipment, verifying the detailed description of the goods, weight, labels, marks, quantities and other data that help to quantify and fully identify the goods, comparing such information with the corresponding invoices, bill of lading, air waybill or packing list. Considering and derived from these reviews, the documented procedures to detect and report missing, surplus, prohibited goods or any other discrepancy in the delivery or receipt of the goods, which must be investigated and resolved. Likewise, the driver who transports the goods must be delivered the required documentary information for their correct transfer (for example: customs declaration, packing list, invoice, contact data and/or procedure in case of any security incident or inspection by any authority, among others). Response: Explanatory Notes: Attach the documented procedure in which it indicates step by step how the delivery and receipt of the cargo is carried out, indicating how it controls or what security measures it has implemented to mitigate the risk of collusion or complicity between employees, such as the driver and the personnel of the dispatch areas (if applicable), warehouse, security guards, etc.
Attach the documented procedure to detect and report discrepancies in the delivery or receipt of the goods and ensure that it includes the following points: I. Persons responsible for carrying out the review. II. Documents to be compared. III. Areas to which the information is reported. This procedure must be applied to the merchandise received for import, export; and if applicable, in the review at intermediate points.
5.3 Processing of cargo information and documentation. The Customs Agent must have documented procedures to ensure that the electronic and/or documentary information sent by their clients from their service request, during the movement and dispatch of goods, as well as the information received from business associates is legible, complete, accurate, reported in time and protected against changes, losses or introduction of erroneous information. The Customs Agent must have the information of each shipment of goods they carry out, in an accessible and secure manner, in written or electronic form. Likewise, the forms and documentation related to the dispatch should be secured to prevent unauthorized use. Response: Explanatory Notes: Attach the documented procedure for the processing of cargo information and documentation. Briefly explain what it consists of. I. Detail how you receive and transmit relevant information and documentation for the transfer of foreign trade goods with your business partners (indicate if you use a specific computer control system and briefly explain its function). Likewise, detail how you ensure that the information provided is legible, complete, accurate, reported in time and protected against changes, losses or introduction of erroneous information.
II. The electronic information of the shipments and cargo in general must include the seal number and/or padlock with which the cargo was secured and in case of changes due to the review of any authority. III. Indicate in what way business associates transmit information to the Customs Agent, and how they ensure its protection.
5.4 Inventory Management, control of packaging, container and packing material. If applicable, documented procedures must be in place for inventory control and storage of the cargo and periodic reviews must be carried out to verify its correct management (for example, for the case of subdivision of invoices or shipping documents, etc.). Likewise, if applicable, you must have a documented procedure for the control and supervision of the packaging and packing material of the goods (for example in the labeling processes of the goods), in which the control, dissemination and prevention procedure of visible pest contamination is also included, in the case of use of wooden packing materials (such as pallets, boxes, crates, cages, reels, dunnage, supports or platforms) to stack the cargo, move it and protect it throughout its entire supply chain. Response: Explanatory Notes: Attach the documented procedure for inventory management. This must include among other aspects according to your operation: I. The frequency with which you carry out the verification of stock (periodic inventory). Indicate if there is a documented scheduled calendar to carry them out. II. Indicate what is done, in the case of excesses and shortages in inventories. III. Indicate the treatment given to the control and handling of packaging, container and packing material, in which the control, dissemination and prevention procedure of visible pest contamination is also included, in the case of use of wooden packing materials (such as pallets, boxes, crates, cages, reels, dunnage, supports or platforms) to stack the cargo, move it and protect it.
IV. This point is also focused on reducing the risk of introduction or dissemination of pests of quarantine importance to the country through packaging (imports), therefore, describe how you comply with the provisions indicated by SEMARNAT and NOM-144 SEMARNAT-2017, in concordance with the International Standard for Phytosanitary Measures No.15 called Regulation of wooden packaging used in International Trade, which emanate from the Food and Agriculture Organization of the United Nations. Regarding waste or surplus packaging and packing material, indicate the procedure carried out for its handling and/or destruction. The applicant's procedures may include: I. Warehouse only accessible to authorized personnel. II. Frequency of stock control. III. Control of incoming goods, transfers to other warehouses, consolidation or deconsolidation. IV. Actions taken if irregularities, discrepancies, losses or thefts are identified. V. Treatment of deterioration or destruction of goods. VI. Separation of the various types of goods for example high value, dangerous.
5.5 Internal Communication. The Customs Agent must have devices and/or communication systems in order to have immediate contact with the personnel of the different areas in charge of carrying out the customs dispatch of the goods. Additionally, a backup system must be available and its proper functioning must be verified periodically. Response: Explanatory Notes: Describe in detail how the Customs Agent communicates with the personnel in charge of carrying out the dispatch of the goods, mainly with those who have direct contact with the goods and with the means of transport (agents, assistants, classifiers, etc.), in case of any security incident. Indicate if operational and administrative personnel have or have access to devices (radios, mobiles, landline phones, etc.), to communicate with each other and/or with whom it corresponds. These must be accessible to users, to be able to react promptly. Describe the procedure for the control and maintenance of communication devices, ensure you include the following points: I. Policies for the assignment of mobile communication devices. II. Maintenance or replacement program for fixed and mobile communication devices. III. Indicate if you have backup communication devices when the permanent system fails and in case, briefly describe them. The procedure may include: I. Person responsible for the proper functioning and maintenance of communication devices. II. Record of verification and maintenance of devices. III. Method of assignment of communication devices.
6.1 Customs Dispatch Management. The Customs Agent must have documented procedures that detail each of the steps shown in their process map established in sub-standard 5.1. Response: Explanatory Notes: Attach the documented procedures that describe each of the points or steps that your process map (5.1) contemplates. These procedures must include the following points: I. Persons responsible for each procedure. II. Formats and documents used. III. Systems used. IV. Actor in the logistics chain with which information is exchanged. The review of these procedures that detail the operation of the customs dispatch of the goods must at all times coincide with the information and/or documentation provided by the client. Mainly on the following topics: I. Tariff classification (support of information or technical sheets of the merchandise that the client sends to the Customs Agent for its correct classification). II. Compliance with regulations and non-tariff restrictions. [Interaction with your clients and the different government departments for the compliance of regulations and non-tariff restrictions (RRNA)].
III. Value declaration (The verification and confirmation of the information provided by the client will serve as support for the use of the valuation methods established in the Law). IV. Payment of contributions (the exchange of information generated for the payment of contributions must be clear and precise with the client).
6.2 Control in facilities. The Customs Agent must have documented procedures in which the control of the official badges requested for personnel entering the fiscal facilities is contemplated, such as: customs agent, assistant, etc. Likewise, one of the customs obligations is the evaluation and certification of the figure of the customs agent, so you must have a documented procedure to comply with what is established in the Law. Response: Explanatory Notes: Attach the documented procedure that describes the control of the official badges for personnel entering the fiscal facilities, ensure you include the following points: I. Procedure for requesting badges with the Associations or Confederations. II. Badge use policies. III. Infractions related to the improper use of badges. IV. Fines applicable to infractions related to the improper use of badges. An updated list of the badges requested, as well as those that have been cancelled, must be available.
Describe the process that the customs agent must follow to apply the evaluations and keep their certifications of activities such as: I. The supervision of previous and derived acts of customs dispatch. II. Preparation of the customs declaration. III. The set of acts and formalities related to the entry of goods into the national territory and their exit from it. The Customs Agent must have the corresponding evidence that supports the evaluations and certifications of the aforementioned topics.
7.1 Use of seals and/or padlocks in containers and trailers. The Customs Agent must have, if applicable, a documented procedure, where the means of transport, containers, trailers and/or semi-trailers and high-security seals used in the international logistics chain are identified, indicating how their integrity is maintained. For this reason, as one of the security mechanisms, the Customs Agent, if applicable, must use padlocks or high-security seals that comply with or exceed the ISO 17712 Standard in all containers and loaded trailers that are subject to foreign trade and maintain their integrity until their dispatch. For this, the Customs Agent must have documented procedures to correctly place the high-security seals and verify their integrity.
The procedures must include the steps to follow if a seal is found to be altered, manipulated, or if there is an incorrect seal number in the documentation, the communication protocols with business partners involved in the supply chain, and the investigation of the security incident. These must be reported to security personnel, business partners who may be part of the affected supply chain, the security specialist, or the Authorized Economic Operator Program contact.
Likewise, in said procedure, the Customs Broker must include matters related to the administration of high-security seals, which must include the control, assignment, safeguarding, handling of discrepancies, and destruction of seals and locks (the latter is mandatory whenever seals are broken at their facilities). Regarding the supplier of the seals and/or locks, it must be demonstrated how these comply with ISO Standard 17712. The Customs Broker or a security supervisor must perform periodic and documented audits of the high-security seals and/or locks. These reviews must include the verification of the inventory of stored seals and/or locks and the reconciliation with inventory records and shipping documents. Also, the Customs Broker must periodically verify the seal numbers used in means of transport and International Traffic Instruments to corroborate that the information is correct.
In the event of having a yard for storing cargo vehicles at the Customs Broker's facilities, empty containers must be secured with a lock and/or indicative seal, or in a secure area that is guarded and monitored by alarm systems and closed-circuit television and video surveillance.
When it is necessary to store (overnight) any loaded container, trailer, and/or semi-trailer, it must be in a secure area and monitored by alarm systems and closed-circuit television and video surveillance to prevent access and manipulation, and must be closed with a high-security lock.
Response: Explanatory Notes: Indicate whether the Customs Broker has its own or third-party transport units, containers, and/or trailers. Attach the documented procedure for the placement and review of seals and/or locks on vehicles, means of transport, containers, train cars, trailers, and/or semi-trailers. This must include, among other aspects according to its operation: I. Verify that the seal or lock is intact and determine if there is evidence of improper manipulation. Use the VVTT inspection method: a) V - View the seal and lock mechanisms of the container (View). b) V - Verify the seal number (Verify). c) T - Pull on the seal to ensure it is correctly placed (Tug). d) T - Twist and turn the seal to ensure it is secure (Twist and Turn).
II. Review and compare the documentation containing the number of the original seal or lock and, if applicable, any additional ones carried during the transport of the goods. In the event of using a replacement seal and/or lock, the number must be registered within the Customs Broker's control. If altered seals and/or locks are identified, they must be kept to help conduct the investigation of said incident or discrepancy and, as appropriate, report the compromised seals and/or locks to the foreign authority. III. Review that the closing devices, hinges, and pins are attached to the trailer or container and welded or riveted. Also, protective plates can be placed on the door hinges and/or a seal/adhesive tape placed on at least each side. Likewise, the correct functioning of handles, latches, and all other locking or closing mechanisms of the cargo vehicles must be verified to detect manipulations and any inconsistencies before placing any sealing device. IV. Indicate how they assign and replace high-security locks, in the event that, during the journey, it is inspected by another authority. If a seal and/or lock is broken in transit, the cargo must be examined, the number of the replacement seal and/or lock must be registered, and the driver must immediately notify business associates when this happens, indicating who broke it and providing the new seal number.
In its case, attach the documented procedure for the control and handling of seals and/or locks. This must include, among other aspects according to its operation: I. Inventory of locks and/or seals. II. Who has access and how locks and/or seals are safeguarded. The management of seals and/or locks must be restricted only to authorized personnel; stored in a safe place, have an inventory, control of their distribution and tracking (record of seals used, as well as the receipt of new seals and/or locks). III. Describe how the Customs Broker participates in audits of high-security seals and/or locks, the reviews they perform, the records they generate, and the actions they take in case of identifying discrepancies. Also, how dependents verify seal numbers used in means of transport and International Traffic Instruments to corroborate that the information is correct (this process can also be included within the internal audits referred to in sub-standard 1.3 of this document). IV. How discrepancies in seal and/or lock numbers are addressed. V. Record of seals and/or locks used at the time of customs recognition. For the case of lost or stolen seals and/or locks, describe the procedure followed by the Customs Broker. Indicate who the supplier(s) are and how they prove that the specifications of the seals and/or locks comply with ISO Standard 17712 (attach certificate of conformity, issued by the certifying company responsible for verifying compliance with the corresponding ISO).
In the case of having a yard for storing cargo vehicles at the Customs Broker's facilities, describe how they ensure the integrity of the means of transport is cared for. All written procedures must be disseminated and maintained at the operational level so that they are easily accessible to employees responsible for executing the tasks described above, reviewed at least once a year, and updated as necessary.
7.2 Inspection of means of transport, containers, trailers, and semi-trailers. In the event of having a yard for storing means of transport, the Customs Broker must have established procedures to verify the physical integrity of the structure of the means of transport, container, trailers, and/or semi-trailers used as International Traffic Instruments, even the reliability of the door lock mechanisms, with the purpose of identifying natural or hidden compartments. Inspections of means of transport or cargo vehicles, containers, and trailers (land cargo) must be systematic and have records of these inspections, in an access-controlled area and carried out in a place monitored by alarm systems and closed-circuit television and video surveillance, said system must cover the inspection process in its entirety. The documented procedure for its inspection must include, by way of example and not limitation, the following review points:
| Means of Transport | Trailers, Train Cars, Semi-trailers, and Containers |
|---|---|
| I. Bumper; | I. Exterior and interior doors; |
| II. Tires and rims (tractor and trailer); | II. Side walls (left and right); |
| III. Floor (tractor); | III. Interior and exterior roofs; |
| IV. Fuel tanks; | IV. Front wall; |
| V. Cab interior (bedroom and tool compartment); | V. Internal floor; |
| VI. Air tanks; | VI. Refrigeration system, if applicable. |
| VII. Chassis; | |
| VIII. Fifth wheel area; | |
| IX. Drive axles; | |
| X. Exhaust pipe; and | |
| XI. Engine. |
Likewise, before loading the means of transport, containers, train cars, trailers, and semi-trailers used as International Traffic Instruments, they must undergo agricultural and security inspections to guarantee that their structures have not been modified to hide smuggling or have been contaminated with visible agricultural pests, keep a record, and be backed by a documented procedure. If visible pest contamination is found during the inspection or transport of goods subject to foreign trade, it must be cleaned (washed, vacuumed, etc.) to eliminate said contamination.
Response: Explanatory Notes: Attach the documented procedure to carry out the security and agricultural inspection of means of transport, containers, trailers, and semi-trailers. This must include, among other aspects according to its operation: I. Those responsible for carrying out the inspection. II. Definition of the place(s) where the inspection is carried out and indicate how the monitoring is performed by alarm systems and closed-circuit television and video surveillance. III. The review points for means of transport, trailers, semi-trailers, and containers both for security and those for quality and agricultural inspections with the purpose of searching for visible pests. Attach the established format for the inspection of means of transport or cargo vehicles, containers, train cars, trailers, and/or semi-trailers. Likewise, the security and agricultural inspection format must include the following information: I. Date of inspection; II. Time of inspection; III. Vehicle license plates (tractor and trailer); IV. Container/trailer number; V. Specific areas of the cargo vehicles that were inspected; and VI. Name of the employee performing the inspection and of the supervisor.
The security and agricultural inspection formats may be signed by the supervisor to corroborate their information and be part of the import and export documentation. The documentation must be kept for one year for an investigation in the event of any security incident, as well as to demonstrate continuous compliance with these inspection requirements. Indicate whether the repair or maintenance of transport units, containers, or trailers is performed at the same facilities or is carried out with an external provider.
8.1 Employment Background Verification. The Customs Broker must have documented procedures to investigate and verify the information stated in the curriculum, criminal records (if local legislation and company policies allow), and applications of candidates with potential for employment, in accordance with local legislation, either on their own or through an external company. Likewise, for positions that require it due to their sensitivity and affect the security of shipments subject to foreign trade, in accordance with their previously conducted risk analysis, they must consider requesting stricter requirements for their hiring and during their employment when hired, which must be carried out periodically at least once a year. Regarding personnel already working in the company, periodic investigations must be carried out based on the activities and/or sensitivity of the employee's position. All information regarding personnel must be kept in personal files, which must have restricted access.
Response: Explanatory Notes: Describe the documented procedure for personnel hiring and ensure you include the following: I. Requirements and documentation required. II. Tests and exams requested. III. Indicate the areas and/or critical positions identified as risky, according to your analysis. IV. Indicate what the additional requirements are for specific areas and/or jobs, such as criminal records (if legislation and company policies allow), non-criminal record letter, socioeconomic studies, clinical studies, toxicological (drug use) studies, etc. In its case, indicate the positions or work areas where they are required and with what frequency they are carried out. V. Indicate if prior to hiring, the candidate must sign a confidentiality agreement or a similar document. VI. In the event of hiring through a staffing agency, indicate if this has documented procedures for personnel hiring and how it ensures they comply with the same. Briefly explain what they consist of. The procedures for personnel hiring and contractors may include: I. Thorough investigations of the work and personal backgrounds of new employees. II. Confidentiality and liability clauses in employee contracts. III. Specific requirements for critical positions. IV. In its case, the periodic update of the socioeconomic and physical/medical study of employees who work in critical and/or sensitive areas. V. Hiring process and requirements requested for temporary employees and contractors. The Customs Broker may consider the results of background verifications of candidates, as allowed by current legislation, to make hiring decisions. Background verifications are not limited to identity and criminal record verification. In higher-risk areas, deeper investigations may be justified.
8.2 Personnel Termination Procedure. There must be documented procedures for personnel termination, which must include the delivery of identification, and any other item that has been provided to perform their functions (keys, uniforms, badges and/or credentials, computer equipment, passwords, tools, etc.). Likewise, this procedure must include the termination in those information and access systems, among others that may exist.
Response: Explanatory Notes: Describe the procedure for personnel termination and ensure you include the following: I. Who is responsible for carrying out and following up on this procedure. II. How the delivery of identification, uniforms, keys, and other equipment is performed and confirmed. III. Indicate the control, record, and/or format, in which the delivery of material is identified and secured, and termination in information systems (if applicable, attach). IV. Indicate the type of records of personnel who ended their labor relationship with the Customs Broker, so that when it was for security reasons, their service providers and/or business associates are prevented.
8.3 Personnel Administration. The Customs Broker must maintain an updated system, control, or database of active employees. Likewise, they must perform and keep updated the records of affiliation to social security institutions and other legal labor records. In the event that the Customs Broker has personnel hired by its business partners and works within the facilities, it must ensure that they comply with the requirements established for the rest of its employees.
Response: Explanatory Notes: Indicate if the Customs Broker has an updated system, control, or database, both of personnel hired directly, as well as that hired through a service provider company, and ensure it includes, by way of example and not limitation, the following points: I. Full name. II. Updated photograph at least every five years. III. Personal data (age, name, date of birth, phone number, address, CURP, social security number, blood type, allergies, etc.). IV. Affiliation. V. Work background. VI. Diseases. VII. Medical exams. VIII. Training. IX. Psychometric tests. X. Toxicological tests. XI. Results of periodic evaluations. XII. Observations. This personnel must be hired in accordance with the current labor laws and regulations.
9.1 Classification and Handling of Documents. There must be procedures to classify documents according to their sensitivity and/or importance. Sensitive and important documentation must be stored in a secure area that only allows access to authorized personnel. The useful life of the documentation must be identified and procedures for its destruction established in accordance with the corresponding legislation. The Customs Broker must conduct regular reviews to verify access to information and ensure that it is not used improperly. Some of the sensitive information referred to in the previous paragraph and depending on the case may be: I. Integration of documentation prior to customs clearance. II. Export/import declaration. III. Packing list. IV. The bill of lading (air waybill, bill of lading, and bill of lading) as applicable. V. Copy of the documents that prove compliance with non-tariff restrictions and regulations on imports that have been issued in accordance with the corresponding laws. VI. The document on the basis of which the provenance and origin of the goods are determined for the application of tariff preferences. VII. The document in which the guarantee granted by deposit made in the guarantee customs account referred to in Article 84-A of the Law is recorded, when the declared value is lower than the estimated price established by the SE. VIII. The weight or volume certificate issued by the certifying company authorized by the Secretariat through rules, regarding the clearance of bulk goods at maritime traffic customs, in the cases established by the Regulation. IX. The information that allows the identification, analysis, and control indicated by the Secretariat through rules. X. Manifestation of the value of the goods. XI. Calculation sheet for the determination of contributions, proceeds, and/or accessories. XII. Responsive letter (technical and MSDS safety data sheet for materials, if applicable). XIII. Insurance policy for the goods that were cleared. XIV. The Customs Broker must conduct regular reviews to verify access to information and ensure that it is not used improperly.
Answer: Explanatory Notes: Attach the documented procedure for the registration, control, and storage of printed documentation (classification and filing of documents), which must include: I. Control register for delivery, loan, and other documents. II. Restricted access to the archive area. III. Storage and classification policies. IV. An updated security plan describing the measures in place regarding the protection of documents against unauthorized access, as well as against deliberate destruction or loss of said documents. V. In the case of electronic or digital information, it must adhere to the security criteria of sub-standard 9.2 Information Technology Security.
9.2 Information Technology Security. To protect Information Technology systems against common cybersecurity threats, the Customs Broker must have sufficient protection to preserve the confidentiality, integrity, availability, and auditability of the information generated from foreign trade operations carried out with authorities, their clients, and other actors. Likewise, it must promote security in the Information Technology infrastructure (software and hardware) against malware (viruses, spyware, worms, trojans, etc.), baiting, phishing, and internal/external intrusions (firewalls) in the companies' computer systems. Similarly, companies must ensure that their security software is active and receives periodic updates.
In the case of automated systems and computer equipment, individual accounts requiring periodic password changes must be used. In order to protect the confidentiality, integrity, and availability of information, the Customs Broker must have established information technology policies, procedures, and standards that must be communicated through a training program for all employees who handle computer equipment and systems, which includes topics to prevent attacks through social engineering and all those threats to which they are exposed (malware, baiting, phishing, etc.). Customs brokers that allow their employees to connect remotely to a network must use secure technologies, such as virtual private networks (VPN), to allow employees to access the company intranet securely when they are outside the office, as well as procedures designed to prevent unauthorized remote access by users.
For the above, there must be written procedures and infrastructure to protect the Customs Broker against losses, theft, leakage, hacking, and/or information kidnapping. This includes the procedure for the recovery (or replacement) of Information Technology systems and/or data, as well as a system or software established to identify the abuse of Information Technology Systems and detect inappropriate access and/or improper manipulation or alteration of commercial and business data, as well as a written procedure for the application of appropriate disciplinary measures to all offenders.
Sensitive information must be protected through these computer security policies, in addition to having backup copies. Access to Information Technology Systems must be protected against infiltration through the use of secure passwords, which include phrases or other forms of authentication. Users of said Information Technology systems must safeguard and not share their access keys or passwords. All Information Technology infrastructure must be physically protected against unauthorized access.
If a data leak or other unexpected event occurs resulting in the loss of data and/or equipment, the procedures must include the recovery or replacement of Information Technology systems and/or data.
Answer: Explanatory Notes: Attach the procedure for the recovery or replacement of Information Technology systems and/or data, which includes how it backs up and guarantees the security of its information, in addition to protecting it from possible losses. Make sure to include the following points: I. Indicate the frequency with which information backups are carried out. II. Who has access to them and who authorizes the recovery of the information. III. Indicate what type of tests are performed and how often, to verify the security of the network, systems, and infrastructure. IV. Mention if, to carry out this type of tests or vulnerability scans, it is done through software, a third party, or provider, and if so, indicate the name or corporate name. V. In case vulnerabilities are found, describe the corrective actions that must be implemented. VI. Indicate if you share information about cybersecurity threats with your business partners who participate within your supply chain (for example: communications, bulletins, emails, etc.).
VII. Systems must be protected with passwords and must be modified frequently; therefore, indicate the procedure for changing them. VIII. Indicate if there are information security policies for their protection. IX. There must be a system or software to detect and identify the abuse, intrusion, or access of unauthorized persons to your systems and/or Information Technology data (any system used by the company), as well as the abuse of the policies and procedures established by the company, including unauthorized access to internal systems, external websites, and the manipulation or alteration of commercial data by employees or contractors. X. All offenders must be subject to the application of disciplinary measures; therefore, indicate the corrective policies and/or sanctions in case of detection of any violation of Information Technology security systems and policies.
Information Technology and cybersecurity policies and procedures must be reviewed annually and updated due to an attack or according to situations that may put the Customs Broker's systems at risk. Describe the security measures used to allow employees to connect remotely to a network (VPN), to allow employees to access the company intranet remotely when they are outside the office.
In case of allowing employees to use personal devices to perform company work, such devices must comply with the company's cybersecurity policies and procedures, security updates must be periodic, and there must be a method to access the company network securely.
XI. Indicate if business partners have access to the Customs Broker's computer systems. If so, indicate what programs they use and how they ensure access control to them. XII. Indicate if the computer equipment has a backup power supply system that allows business continuity.
Procedures regarding the backup of the Customs Broker's information must also include at least the following: I. How and for how long data is stored (data should be backed up once a week or as appropriate). II. Business continuity plan in case of incident and how to recover the information. III. Frequency and location of backup copies and archived information. IV. If backup copies are stored in sites alternative to the facilities where the data processing center is located. V. Tests of the validity of data recovery from backup copies.
Procedures regarding the protection of the Customs Broker's information must also include: I. An updated and documented policy for the protection of the Customs Broker's computer systems against unauthorized access and deliberate destruction or loss of information. All sensitive and confidential data must be stored in an encrypted or encoded format. II. Detail if you operate with multiple systems (branches/sites) and how such systems are controlled. III. Who is responsible for the protection of the Customs Broker's computer system (responsibility should not be limited to one person but to several so that each can control the actions of the rest). IV. Each user's access must be assigned through individual accounts and restricted according to the job description or assigned tasks. For this reason, describe how access authorizations and access levels to computer systems are granted (access to sensitive information must be limited to authorized personnel to make modifications and use the information). Authorized access must be monitored by the area responsible for granting it, to verify or, if necessary, report that access to confidential systems is based on job requirements. V. Indicate the elements or format that passwords must have for access to Information Technology systems and equipment, methods of authentication, and who provides those passwords.
VI. Indicate the name of the firewall and anti-virus used (include information related to licensing), evidencing that this security software is active and receives periodic updates. For the above, cybersecurity policies and procedures should include measures to prevent the use of counterfeit products or those with incorrect licenses (software and hardware).
All computer equipment, electronic media (hard drives, cell phones, etc.), and Information Technology hardware containing confidential information related to the import and export process must be accounted for through periodic inventories and have such evidence. When these technological equipment must be disposed of, there must be a documented procedure that includes how they must be formatted, disinfected, or destroyed properly to avoid information leakage.
VII. In case of staff turnover, access to computer equipment, telecommunications, and networks must be eliminated at the time of the employee's separation; this includes email accounts, system access accounts, software, programs, etc. VIII. Measures planned to handle security incidents when the system is compromised.
Administrative and operational employees must know the procedures established by the Customs Broker to consider a risk situation and know how to report it. Specific training must be provided to employees who, due to their functions, are in direct contact with goods and/or means of transport, as well as to employees who are in critical and/or sensitive areas determined under their risk analysis (security areas, shipments and receipts, if applicable, as well as those who receive and open mail and packages, among others).
10.1 Training and awareness on threats. The Customs Broker must have a training and awareness program on supply chain security policies, directed to all its employees (operational and administrative), and additionally make informational material available regarding the procedures established by the Customs Broker to consider a situation that threatens its security and know how to report it.
These training programs must encourage active employee participation in security controls and mechanisms. The Customs Broker must ensure that all its employees know, understand, and apply supply chain security policies, as well as keep records of all training efforts provided and the list of those who participated in them.
Likewise, and with the purpose of maintaining the integrity of operations and processes related to the customs clearance of goods, personnel must receive specific training according to their functions. The topics that must include are the following: maintain cargo integrity, conduct container, trailer, and/or semi-trailer reviews for agricultural and security purposes (if applicable), receive and review mail and packages, prevent operations with proceeds of illicit origin (money laundering, terrorist financing, etc.), how to recognize and how to report internal conspiracies, protection of access controls, as well as training regarding smuggling, cargo theft, placement of seals, control of high-security seals (VVTT inspection method), prevention of visible contamination by pests, use of official badges, etc. These topics must be established as part of new employee onboarding and periodically maintain update programs. Update training must be carried out periodically, after a security incident, and when there are changes in the Customs Broker's procedures.
In addition to security training programs, a program on awareness of alcohol and drug consumption must be included. Also, disseminate and train personnel on the Customs Broker's cybersecurity policies, procedures, and standards (theft, leakage, hacking, and/or information kidnapping), including access to computer equipment and systems via passwords or phrases. Personnel who operate and administer security technology systems must receive training related to their operation and maintenance, including self-training through operational manuals and other methods.
These topics must be established as part of new employee onboarding and periodically maintain update programs.
Training programs must encourage active employee participation in security controls and mechanisms, as well as keep records of all training efforts provided by the Customs Broker and the list of those who participated in them (videos, photographs, minutes, attendance lists, intranet or other system, didactic material, PowerPoint presentations, brochures, etc.). Training records must include the date of the training, the names of the attendees, the topics taught, in addition to having measures to verify that the training provided met all training objectives.
Answer: Explanatory Notes: Must have a training program on security and prevention of security incidents in the supply chain for all employees working for the Customs Broker (administrative, operational, direct or indirect). Briefly explain what the training program consists of and make sure to include the following: I. Brief description of the topics taught in the program. II. When they are taught (Onboarding, specific periods, due to audits, security incidents, etc.). III. Frequency of training, as well as updates and reinforcement. IV. Indicate how participation in supply chain security training is documented (videos, photographs, minutes, attendance lists, intranet or other system, didactic material, PowerPoint presentations, brochures, etc.). Training records must include the date, the names of the attendees, the topics taught, in addition to having measures to verify that the training provided met all the objectives of the same. V. Explain how employee participation in security matters is encouraged.
Training to perform reviews of cargo vehicles, containers, trailers, and/or semi-trailers for agricultural and security purposes must include the following topics:
I. Signs of hidden compartments; II. Smuggling hidden in natural compartments; III. Signs of pest contamination; and IV. Procedures to follow if something is found during a transport medium inspection or if a security incident occurs during transit.
Training on agricultural reviews must cover pest prevention measures, regulatory requirements applicable to wooden packaging materials, in accordance with the International Standard for Phytosanitary Measures No. 15 called Regulation for Wood Packaging Used in International Trade, which emanate from the Food and Agriculture Organization of the United Nations and the identification of infested wood.
In the case where the Customs Broker identifies that any foreign trade shipment is involved in a situation that puts the supply chain security at risk, due to suspicion of a business partner or person, it must inform the competent authority, business partners who may be part of the affected supply chain, security specialist or Authorized Economic Operator Program contact, as well as the competent authority, and if possible, before the border crossing, exit, or customs clearance (import and export). Procedures must include the steps to follow if it is discovered that a seal is altered, manipulated, or there is an incorrect seal number in the documentation, the communication protocols to business partners involved in the supply chain, and the investigation of the incident. All the aforementioned procedures must be reviewed periodically or at least once a year to ensure that contact information and action protocols are correct.
11.1 Reporting of anomalies and/or suspicious activities. In case of detection of anomalies and/or suspicious activities related to supply chain security and in accordance with its logistical processes (related to access control, delivery, receipt, and storage of goods, security inspections of cargo vehicles and transport operators, etc.), these must be reported to security personnel, business partners who may be part of the affected supply chain, security specialist or Authorized Economic Operator Program contact, and other competent authorities, keeping a record of said anomalies and/or unusual activities.
Answer: Explanatory Notes: Describe the procedure to denounce or report anomalies and/or suspicious activities, as well as the mechanisms to anonymously report problems related to security. Make sure to include the following: I. Who is responsible for reporting security incidents. II. Detail how it determines and identifies with which authority to communicate in different scenarios or presumption of suspicious activities. III. Mention if it keeps a record of the report of these activities and/or suspicions and briefly describe what it consists of.
11.2 Investigation and analysis. There must be written procedures to denounce or report anomalies and/or suspicious activities, the analysis and investigation of security incidents in the supply chain to determine their cause, in addition to corrective actions to prevent them from happening again, which must be implemented as soon as possible. The information derived from this investigation must be documented and available at all times for authorities that require it.
This information and documentation generated to carry out the foreign trade operation of the affected goods must be included in a file for the purpose of identifying each of the processes through which that operation went until the point where the incidence was detected and that allows recognizing the vulnerability of the chain.
Answer: Explanatory Notes: Describe the documented procedure to initiate an investigation in case of a security incident, and make sure to include the following: I. Person responsible for carrying out the investigation. II. Documentation that integrates the investigation file of the foreign trade operation.
The documents to be included in the file derived from the investigation, in an enumerative but not limiting manner, may be: I. General information of the shipment, purchase order. II. Transport request; confirmation of transport medium; identification of the transport operator (access records, exit records, records of security inspections, etc.). III. Container Inspection Formats; exit order; delivery records. IV. Videos from alarm systems and closed-circuit television and video surveillance. V. Documentation generated for the carrier (packing list, bill of lading, instruction sheet). VI. Documentation generated for business partners (description of goods, proformas, invoices, etc.). VII. Documentation generated by business partners (customs declarations, manifests, tracking and inspection reports, videos if applicable, etc.).
E5. Land Auto Carrier Profile Acknowledgment of Receipt First Time: Renewal: Addition: Modification: The data you provide will replace the data you provided when you requested your authorization.
General Information. The objective of this Profile is to ensure that the land auto carrier implements security practices and processes that ensure their supply chain, mitigating the risk of contamination of their vehicles with illicit products, as well as loss, theft, and/or any other factor that could compromise the security of the supply chain.
Land auto carriers interested in obtaining the authorization referred to in Rule 7.1.5. must have documented and verifiable processes. Likewise, the transport company interested in the aforementioned authorization must integrate the criteria required in this document into the business model or design it has established, seeking during the implementation of security standards the application of an analysis culture that supports decision-making consistent with the company's values, mission, vision, codes of ethics, and conduct.
As an example of the points or topics requested of interested parties during the completion of this document, which require analysis to identify risks affecting the supply chain and help detect their treatment, are the following: origin and destination points, routes, facilities, volume of operations, yard security, previous security incidents, interaction with business partners, among others.
Filling Instructions: I. You must fill out a Land Auto Transport Profile of the main facility, as well as each of the main facilities where vehicles are used and safeguarded for the transfer of foreign trade merchandise. In the case of yards and/or branches that are also under the same RFC, a Profile must be developed for each of them, strictly following what is established in sub-standard 7.3. of this document. This information must match what was stated in your application for Certified Business Partner.
II. Detail how the company complies with or exceeds what is established in each of the sections as indicated.
III. The format of this document is divided into two sections, as detailed below:
IV. Indicate how you comply with what is established in each of the sub-standards; therefore, you must attach the procedures in Spanish. These procedures must be characterized by describing or defining the objective the document pursues, the start and end of the process, measurement indicators, requirements, documents or formats to be used, responsible parties, among others.
V. In cases where only an explanation of the procedure is required, it must be detailed and placed in the Response field. The field regarding Explanatory Notes is a guide regarding the points that must be included in the Response of each sub-standard, indicating in an indicative manner those points that should not be excluded from your response.
VI. Once this Land Auto Carrier Profile is completed, it must be attached to the Application for registration in the Certified Business Partner registry referred to in the first paragraph of Rule 7.1.5., fraction I, subsection b).
VII. For the purpose of verifying what was stated in the previous paragraph, the SAT through AGACE may conduct an inspection of the facility indicated here, with the exclusive purpose of verifying what is stated in this document.
VIII. Any incomplete Land Auto Carrier Profile will not be processed.
IX. Any questions regarding the Application for Certified Business Partner and the Land Auto Carrier Profile should be directed to the contacts appearing on the SAT Portal.
X. In the event of being authorized as a Certified Business Partner, this format must be kept updated and notice must be given when the circumstances under which the registration was granted have varied and, as a result, changes or modifications are required in the information provided in this Land Auto Carrier Profile to the authority in accordance with what is established in Rule 7.2.1., fourth paragraph, fractions I, II, and VII.
XI. When, as a result of the inspection visit, non-compliance related to minimum security standards results, the applicant may remedy them before the issuance of the resolution established in Rule 7.1.6., for which they will have a maximum period of three months counted from the notification of the indicated non-compliances.
Facility Data. A Land Auto Transport Profile must be filled out for the main facility, as well as each of the main facilities where vehicles are used and safeguarded for the transfer of foreign trade merchandise. And in the case of yards and/or branches that are also under the same RFC, a Profile must be developed for each of them, as well as strictly following what is established in sub-standard 7.3. of this document. This information must match what was stated in your application for Certified Business Partner.
Facility Information. Land Auto Carrier Profile Number: from: RFC Key: Name and/or Business Name: Name and/or Denomination of the Facility Type of Facility: Street: Exterior Number and/or Letter Interior Number and/or Letter Neighborhood: Postal Code: Municipality/Delegation: Federal Entity: Facility Age (years of operation): Predominant Activity (Transfer / Long Distance): Service Type (General/Specialized Cargo): Average number of monthly shipments (EXP): (Long distance and/or crossing) Average number of monthly shipments (IMP): (Long distance and/or crossing) Total number of employees at this facility: Facility Surface Area (m2 ): Total number of yards and/or branches (owned and/or subleased) that are enabled and used for the storage of transport means:
Certifications in security programs: (Indicate if this facility has a certification from any of the following programs) CTPAT: Yes No Level: Pre-Applicant: Applicant: Certified: Certified/ Validated: CTPAT Account number (Eight digits): Date of last visit at this facility: Authorized Economic Operator from other countries (AEO) Yes No Program: Registration: Other Supply Chain Security Programs Yes No Program: Registration: Certifications: (Indicate if you have certifications that you consider impact your supply chain process, for example: ISO 9000; Reliable Logistics Processes, among others) Name: Category: Validity: Name: Category: Validity: Name: Category: Validity:
1.1 Risk Analysis. The transport company must establish measures to identify, analyze, and mitigate security risks throughout the supply chain, including its facilities. Therefore, it must develop a written procedure in which risks are determined based on its organizational model (e.g., volume, units, yards, routes, potential threats, etc.), which allows it to implement and maintain appropriate security measures. In accordance with the above, the company must also have a written process based on its risk analysis to select new business partners and monitor those with whom it is already working. This procedure must be carried out at least once a year, so that it allows identifying other risks or threats in the operation that may arise as a result of an incident or that originate from changes in the company's initial conditions, as well as to identify whether policies, procedures, and other control and security mechanisms are being complied with. It is important to note that the company's Security Committee must participate in the preparation and updating of the risk analysis and the maintenance of the Authorized Economic Operator Program. Response: Explanatory Notes: Attach the risk matrix and the documented procedure you use to identify risks in your daily operations throughout the supply chain and its facilities (yards and/or branches, offices, boarding houses, mechanical workshops, etc.) must include at minimum the following points: I. Periodicity with which this procedure is carried out. II. What aspects and/or areas of the transport company are incorporated into the risk analysis. III. Service Type: a) Long distance. b) Internal and international transit. c) Transfer. d) Consolidated. IV. Methodology or techniques used to perform the risk analysis. V. Responsible parties for reviewing and/or updating the risk analysis of the company.
Likewise, the documented procedure for identifying risks in the supply chain and its facilities must contemplate the process of risk appreciation and management, and include the following aspects: I. Establishment of a context (cultural, political, legal, economic, geographic, social, etc.). II. Identification of risks in its supply chain and its facilities. III. Risk analysis (causes, consequences, probabilities, and existing controls to determine the risk level as high, medium and low). IV. Risk evaluation (decision-making to determine the risks to be treated and priority for implementing the treatment). V. Risk treatment (application of alternatives to change the probability of risks occurring). VI. Risk monitoring and review (monitoring of the results of the risk analysis and verification of the effectiveness of its treatment). It is suggested to use risk evaluation techniques in accordance with the current international standard ISO 31000, and specifically ISO 31010, where according to your business model you must implement.
1.2 Security Policies. Companies must have a manual of policies oriented towards preventing, ensuring, and recognizing threats to the security of the supply chain and company facilities, such as drug trafficking, arms trafficking, human smuggling, prohibited merchandise, and acts of terrorism. To promote a security culture, companies must demonstrate their commitment to supply chain security and the Authorized Economic Operator Program through a statement highlighting the importance of protecting the flow of national and international commerce from criminal activities, established through the security policy. Senior officials or executives of the company who must endorse and sign the security policy may include the company president, the executive director, the general manager, the security director, or personnel with equivalent rank with decision-making authority.
Response: Explanatory Notes: State the security policy oriented towards preventing, ensuring, and recognizing threats in the supply chain and company facilities focused on guaranteeing the integrity of its resources (units, operators, facilities, yards and/or branches, etc.) as well as to ensure the transfer of goods, property of third parties or own, and indicate who is responsible for its review and signature and dissemination to employees, as well as the periodicity with which its update is carried out. This policy must be communicated to employees through a program and/or dissemination campaign. The security policy must be signed by a senior official of the company and be displayed in various areas of the company, including the company website, posters in key areas of the company (reception, shipments, receipts, warehouse, etc.), and as part of initial and reinforcement training.
1.3 Internal Audits in the Supply Chain. In addition to routine monitoring in control and security, it is necessary to schedule and carry out audits, at least once a year, that allow evaluating all processes regarding supply chain security in a more critical and profound way, as well as guaranteeing that employees follow the company's security procedures. Audits must be carried out by the company's Security Committee and a documented procedure must be established, as well as a program or calendar for their execution. Although it is necessary that audits are focused on supply chain security and based on the evaluation, review, and execution of minimum security standards, their focus must be adjusted to the size of the organization, risk level, business model, and variations between facilities. Audits can be general or focus on specific areas or processes according to their work program. The objective of an internal audit focused on the Authorized Economic Operator Program is to verify and guarantee that employees follow the company's security procedures. The review process does not have to be complex; however, the formats and records used for the application of these reviews must evidence that the application and execution of the evaluated processes were validated, in addition to the follow-up and closure of preventive, corrective, and improvement actions identified. The senior management of the organization must review the results of the audits and undertake the required corrective or preventive actions. The audit process must guarantee that the necessary information is collected to allow management to make this evaluation. The review must be documented, in addition to the fact that the company's Security Committee must provide and register periodic updates on the progress or results of any audit, exercise, or validation.
Response: Explanatory Notes: Describe the documented procedure to carry out an internal audit, focused on security in the supply chain, ensure you include the following points: I. Indicate how the company carries out the scheduling or calendarization to perform an internal audit, in terms of security, in the supply chain. II. Indicate who participates in them, and the records that are made of them, as well as the periodicity with which they are carried out. III. Indicate how the Company Management verifies the results of security audits, how it carries out and/or implements preventive, corrective, and improvement actions in addition to the follow-up and closure of the same. IV. The formats used during internal audits must be properly filled out, and through them, evidence that procedures and security measures are being put into practice.
1.4 Contingency and/or Emergency Plans. There must be a documented contingency and/or emergency plan. This plan must address crisis management, security recovery plans, and business resumption, to ensure business continuity in the event of a situation that affects the normal development of activities and operations of the transport company. A crisis or contingency may include the interruption of the transmission and exchange of commercial data due to a cyberattack, a fire, the kidnapping of a transport driver by armed individuals, a customs closure, a bomb threat, the detection of suspicious packages, a power outage, theft and/or damage to merchandise, threats or extortion, blockages or road closures, and when the operator identifies that they are being observed or followed during the transfer of merchandise, among others. Such plans must be communicated to personnel through periodic training, as well as carrying out tests, practical exercises, and annual simulations of the contingency and emergency plans to verify their effectiveness, from which a properly filled out and signed record must be maintained (for example: result reports, minutes or reports, which must be backed up by video recordings, photographs, etc., demonstrating their execution). The contingency and/or emergency plan must be updated as necessary, based on changes in operations and the organization's risk level.
Response: Explanatory Notes: Attach the documented contingency and/or emergency procedure or plan, to ensure the continuity of the business in the event of an emergency or security situation, that affects the normal development of the company's foreign trade activities. This procedure must include, by way of example but not limitation, the following: I. What situations it contemplates by describing the action plan and steps to be followed in case of crisis, as well as the tasks that personnel have assigned during the handling of such contingencies. II. What mechanisms it uses to disseminate and ensure that these plans are effective. III. Contemplate the scheduling and execution of tests, practical exercises, and annual simulations and how they are documented (for example: result reports, minutes or reports, which must be accompanied by video recordings, photographs, etc., demonstrating their execution). In the case of transport companies of Hazardous Materials and Waste, an emergency sheet must be attached indicating the actions to be taken for cases of incident or accident (leaks, spills, explosions, fires, etc.).
2.1 Facilities. Facilities must be constructed with materials that can resist unauthorized access. Periodic documented inspections must be carried out to maintain the integrity of the structures, and in the event that an irregularity has been detected, the corresponding repair must be carried out as soon as possible by the personnel designated for these tasks. Likewise, territorial limits, as well as various accesses, internal routes, and the location of buildings must be fully identified. Response: Explanatory Notes: Indicate the predominant materials with which the facilities are constructed (for example, metal structure and sheet metal walls, brick walls, wood, among others and indicate how the review and maintenance of the integrity of the structures is carried out. Indicate the personnel or area responsible for carrying out the tasks of inspection, maintenance, and repair of damage to the facilities. Explain how you carry out the review and maintenance of the integrity of the structures. Attach a general distribution or architectural plan, where limits, access routes, the location of offices, parking lots, critical areas, boundaries, yards and /or boarding houses can be identified.
2.2 Accesses at Gates and Booths. The entrance or exit doors of vehicles and/or personnel accessing the yards and/or boarding houses of cargo vehicles and administrative offices must be attended and/or supervised either by own personnel or by security personnel. The number of access doors must be kept to the minimum necessary. Access to sensitive areas must be restricted according to the job description or assigned tasks. Response: Explanatory Notes: Indicate how many doors and/or accesses exist in the facilities, as well as the operating hours of each one, and indicate how they are monitored (In case of having assigned personnel, indicate the quantity). Detail if there are doors and/or accesses blocked, or permanently closed. Describe how you ensure that access to sensitive areas is restricted according to the job description or assigned tasks (include the type of records and controls you use).
2.3 Perimeter Walls. Perimeter walls and/or peripheral barriers must be installed to secure the company's perimeters, in accordance with a risk analysis. The areas of the yards and/or parking lots must be delimited for cargo vehicles (tractors), trailers and/or semi-trailers and/or containers as appropriate. These must be inspected regularly and maintain a record of the review in order to ensure their integrity and identify damage, which must be repaired as soon as possible by the personnel designated for these tasks. In the case of providing cargo storage services, this zone must be clearly delimited, identified and monitored according to the required service (national or international, as well as high-value and dangerous) to prevent unauthorized entry. Response: Explanatory Notes: Describe the type of fence, peripheral barrier and/or walls that the company has, make sure to include the following points: I. Indicate the characteristics of the same (material, dimensions, etc.). II. In case of not having walls, justify in detail the reason. III. Frequency with which the integrity of the perimeter walls is verified, and the records that are carried out in order to ensure their integrity and identify damage, which must be repaired as soon as possible. IV. Indicate the personnel or area responsible for performing inspection and repair tasks damage. V. Indicate how your yards are divided (describe briefly, how they separate tractors, containers, trailers and/or semi-trailers domestic and/or international cargo, empty, in repair and/or maintenance; vehicles cargo; workshops; offices; among others).
The procedure for the inspection of the walls perimeter could include: I. Responsible personnel to carry out the process. II. How and how often the inspections of the fences, perimeter walls and/or peripheral and buildings. III. How the inspection record is kept. IV. Who is responsible for verifying that repairs and/or modifications comply with the technical specifications and security requirements necessary. 2.4 Parking. Access to the parking lots of the facilities must be controlled and monitored by security personnel or designated for this task. Private vehicles (of employees, visitors, suppliers and contractors, among others) must be prohibited from parking within the areas for handling and storage of means of transport, containers, trailers and semi-trailers, as well as in adjacent areas. Response: Explanatory Notes: Describe the procedure for the control and monitoring of parking, make sure to include the following points: I. Those responsible for controlling and monitoring the access to parking lots. II. Identification of parking lots (specify if employee parking, visitors, is separated from means of transport, containers, trailers semi-trailers and cargo handling). III. How entry and exit control is carried out vehicles to the facilities. Indicate the records that are made for the control of the parking and the existing control mechanisms (for example: badges, cards readers, badges, etc.), how they are assigned and the responsible area for doing so. IV. Policies or mechanisms to not allow the entry of private vehicles to the areas of storage of means of transport and in its case cargo handling.
2.5 Control of keys and lock devices. According to the risk analysis, windows, doors and inner and outer fences must be secured with locking devices. The transport company must have documented procedures for the handling, safeguarding, assignment and control of the keys of the facilities, of the inner areas that have been considered as critical and of the cargo vehicles, designating those responsible for the administration, control and registration of these. Likewise, a record must be kept and establish signed responsibility letters from the people who based on their functions have keys or authorized access. Response: Explanatory Notes: Indicate if all doors, windows, entries inner and outer have closure mechanisms or security. Attach the documented procedure(s) for the control, safeguarding, assignment and handling of the keys of the means of transport and of the facilities, offices and inner areas. Ensure that these procedures include the following points: I. Those responsible for administering and controlling the security of the keys. II. Format and/or control record for the loan of keys. III. Treatment of loss or non-return of keys. IV. Indicate if there are areas in which access with electronic devices and/or some other access mechanism. In case of using key locks that are placed in containers, trailers and/or semi-trailers within the facilities describe in detail the criteria for the handling, control and safeguarding of the keys of said locks.
2.6 Lighting. Lighting inside and outside the facilities must allow clear identification of people, material and/or equipment that is there, including the following areas: entrances, exits, parking or storage areas for tractors, trailers, rolling stock, perimeter walls and/or peripheral, inner fences, loading, unloading, handling and storage of cargo (in case of providing this service). An emergency and/or backup system must be available in sensitive areas. Response: Explanatory Notes: Describe the procedure for the operation and maintenance of the lighting system. Make sure to include the following points: I. Indicate which areas are illuminated and which have a backup system (Indicate if you have an auxiliary power plant or any other mechanism to supply electricity in case of any contingency). II. How do you ensure that the system of lighting is appropriate in each of the areas of the company, in such a way that it allows a clear identification of personnel, material and/or equipment it covers. III. Person responsible for the control and maintenance of the lighting systems. IV. Maintenance and review program (in case of coinciding with another process, indicate it). The procedure may include: I. How the lighting system is controlled. II. Operating hours. III. Identification of areas with lighting permanent. 2.7 Communication devices. The transport company must have devices and/or communication systems in order to have immediate contact with the personnel of security and/or with emergency and security authorities when required. Additionally, a backup communication system must be available and verify its good functioning periodically.
Response: Explanatory Notes: Describe the procedure that personnel must perform to contact security personnel or in case, with the corresponding authority in case of any incident. Indicate if operational and administrative personnel have or dispose of devices (landline phones, mobile phones, alert and/or emergency buttons), to communicate with the security personnel and/or whoever corresponds (these must be accessible to users, to be able to have a quick reaction). Indicate what communication devices the personnel of security in the transport company (landline phones, cellulars, radios, alarm system, etc.). Describe the procedure for the control and maintenance of communication devices, make sure to include the following points: I. Policies for the assignment of devices of mobile communication. II. Maintenance or replacement program of fixed and mobile communication devices. III. Indicate if you have communication devices backup when the permanent system fails, and if so, detail briefly. IV. Indicate if the operators/drivers of the company use phones, radios, cell phones, civil band (CB), or any other means for their communication internal and the assignment policies of the same. The procedure may include: I. Responsible for the good functioning and maintenance of communication devices. II. Verification and maintenance record of the apparatus. III. Method of assignment of devices of communication.
2.8 Alarm systems and closed circuit television and video surveillance. Alarm systems and closed circuit television and video surveillance and security technologies, must be used to monitor, notify or deter unauthorized access and prohibited activities in the facilities and other areas considered sensitive, notify the corresponding area, in addition to being used as a tool of proof in investigations derived from any incident. These systems and security technologies must be placed according to a prior risk analysis, in such a way that they remain watched and monitored areas that imply the access of personnel, visitors, suppliers cargo, loading and unloading and cargo and passenger vehicles and other areas considered sensitive, also, the areas where vehicles and containers are usually located (parking lots, storage where they stay overnight) and in case where they store the goods (if you provide this service). Such systems must allow clear identification of the area or environment being monitored, be permanently recording and maintain a backup of the recordings for at least one month, considering that, in the case that your logistics processes exceed this period, the period of maintenance of these backups, in order to have the necessary elements to disclaim the corresponding responsibilities in case of a security incident. Alarm systems and closed circuit television and video surveillance and security technologies, must have a documented procedure of operation that includes supervision of the good condition of the equipment and verification of the correct position of the cameras, indicating the frequency with which the backup of the recordings must be performed, as well as those responsible for their operation. Such a system and all the infrastructure of security technology must have restricted access. Response: Explanatory Notes: Mention the documented procedure in which indicates the functioning of the external alarm system or sensors, and if so, describe the following points: I. Indicate if doors and windows have sensors of alarm or motion sensors. II. Procedure to follow in case of activating a alarm. Describe the documented procedure for the operation of alarm systems and closed circuit television and video surveillance and technologies of security, (this must be reviewed and updated annually and according to the risk analysis or the circumstances), make sure to include the following points: I. Indicate the number of cameras of the systems of alarm and closed circuit television and video surveillance installed, technical characteristics and their location (detail if it covers the entry points and exit of the facilities, to cover the movement of vehicles and individuals, as well as the place of storage of vehicles). II. Indicate the location of the alarm systems and closed circuit television and video surveillance and security technologies, where the monitors are located, who reviews them, as well as the operating hours, and if there are remote monitoring stations. All the security technology infrastructure must be physically protected against unauthorized access. III. Perform periodic and random reviews of the recordings. Indicate how they are reviewed (random, every week, special events, restricted areas, etc.), who is the personnel designated and if management is involved in the reviews. The results of the reviews must be documented to include actions corrective for audit purposes. IV. Indicate for how long these are kept recordings (must be at least one month). V. The alarm systems and closed circuit television and video surveillance and security technologies must have a source of alternative energy that allows these to continue functioning in case of an unexpected loss of direct energy. For this reason, indicate if the alarm systems and closed circuit television and video surveillance and security technologies are backed up by an electrical power plant or any other mechanism to supply electricity energy, that guarantees its functioning. These systems should have a function of alarm/notification, indicating a condition of failure in the functioning and/or recording, indicate if your systems have such a function.
VI. Indicate if in addition to the systems of alarm and closed circuit television and video surveillance, uses any other type of technology to strengthen the security measures with which it already has. VII. Describe the procedure that has been implemented to test and inspect regularly the alarm systems and closed circuit television and video surveillance and security technologies and ensure their good functioning. The results of the inspections and the functional tests are documented, as well as the actions corrective necessary (these must be implemented as soon as possible). Additionally, that the documented results of these inspections are kept for a time sufficient for audit purposes. VIII. Indicate if the alarm provider and alarm systems and closed circuit television and video surveillance, has access to the cameras of security, if it is in charge of performing the monitoring of the same, in what way the accesses are controlled and who is responsible for said monitoring. 3. Physical access controls. Physical access controls are mechanisms or procedures that prevent and prevent unauthorized entry to the facilities (administrative offices, yards and/or parking lots of the means of transport, cargo warehouse (in case of providing this service), as well as maintaining control of entry to the operators/drivers, administrative personnel and/or visitors and protect the company's assets. Access controls must include the identification of all employees, visitors and suppliers at all entry points. Likewise, they must be maintain records and permanently evaluate the mechanisms or documented procedures for entry to the facilities, being the basis for starting to integrate security as one of the primary functions within any company. 3.1 Security personnel. The transport company must have security and surveillance personnel. This personnel plays an important role in the physical protection of the facilities, of the yards and/or parking lots where the cargo vehicles (tractors), trailers and containers are stored, as well as for controlling the access of all people to the property. Security personnel must have a documented procedure to carry out their functions, and have full knowledge of the mechanisms and procedures in emergency situations, detection of unauthorized persons, or any incident in the facilities. Management must verify periodically the compliance of procedures policies and functions through internal audits in order to verify their correct execution.
Response: Explanatory Notes: Describe the documented procedure for the operation of security personnel, and make sure to include the following points: I. Indicate the number of security personnel that works in the company. II. Indicate the positions and/or functions of the personnel, and operating hours. III. In case of hiring an external service, specify number of personnel employed, operating details, records, reports, etc. IV. In case of having armed personnel; describe the procedure for the control and safeguarding of weapons. 3.2 Identification of employees, visitors and suppliers. There must be an identification system for employees, visitors and suppliers for the purpose of access to the facilities. Employees should only have access to those areas they need to perform their functions. Visitors and suppliers must present an official identification with a photograph upon their arrival and a record must be kept. All visitors and suppliers must receive a temporary identification and be accompanied by company personnel during their stay in the facilities and ensure that the visitor/supplier always wears the provisional identification provided in a visible place. This procedure must be documented. The management or security personnel of the company must properly control the delivery and return of identification badges for employees, visitors and suppliers and ensure that they always wear the identification provided in a visible place. This procedure must be documented, as well as the procedures for the delivery, return and change of access devices (for example, keys, proximity cards, etc.). Access to the sensitive areas must be restricted according to the job description or assigned tasks. Response: Explanatory Notes: Attach the documented procedure for the control of identifications. Describe the procedure for the identification of the employees, and make sure to include the following points: I. Identification mechanisms (photo ID, uniform, etc.). II. Indicate if employees use uniforms, how they are assigned (by position, area, functions, etc.) and withdrawn (if applicable).
III. Indicate how contracted personnel is identified by a business partner, who works within the facilities (contractors, sub-contractors, etc.). The procedure must also describe how the company delivers, changes and withdraws employee identifications and access controls and make sure to include the responsible areas for authorizing and administering. Indicate how you ensure that access to the areas sensitive is restricted according to the job description or assigned tasks (include the type of records and controls you use). Describe the procedure for the access control of visitors and suppliers, make sure to include the following points: I. Indicate what records are kept (Formats personal for each visit, logbooks). II. The record of visitors and suppliers must include the following: a) Date of the visit; b) Visitor's name; c) Identification number with photo (official documents such as: driver's license, passport, INE, etc.); d) Time of entry and exit. e) In the case of vehicular access, the format must include the data of the vehicle private or cargo (model, plate, trailer number, etc.). III. Indicate who is the person responsible for accompanying the visitor and/or supplier, and if there are restricted areas for their entry.
3.3 Procedure for identification and removal of unauthorized persons or vehicles. The company must have documented procedures that specify how to identify, confront or report unauthorized or identified persons and/or vehicles. Response: Explanatory Notes: Attach the documented procedure to identify, confront or report persons and/or vehicles not authorized or identified. The procedure must include: I. Responsible personnel. II. Designate a person or area responsible for being informed of incidents. III. Instructions for confronting and addressing the personnel unidentified. IV. Indicate in what cases it should be reported to the corresponding authorities. V. How the record of the incidents and the measures adopted in each case. 3.4 Courier and package deliveries. Courier and packages intended for company personnel must be examined upon arrival and before being distributed to the corresponding area. Likewise, the transport company must have a documented procedure for the receipt and review of courier and packages, which must be communicated to the responsible personnel through training. The training must be documented. Response: Explanatory Notes: Describe the procedure for the receipt and review of courier and packages and make sure to include the following: I. Personnel in charge of carrying out the procedure. II. Indicate how the personnel or provider of the courier and package service is identified (indicate if it requires additional procedure to supplier access).
III. Indicate how packages are reviewed and/or what mechanism is used, as well as the records kept and, where applicable, the incidents detected.
IV. Indicate what action is taken in the case of detecting a suspicious package.
V. Indicate how the inspection record is kept and, where applicable, the incidents detected.
The transport company must have written and verifiable procedures for the selection and hiring of new commercial partners and monitoring of partners already working with them, such as: manufacturing companies, manufacturers or assemblers, parts and/or spare parts suppliers, mechanical suppliers, high-security seal suppliers, Information Technology systems suppliers, installation and maintenance of alarm systems, closed-circuit television and video surveillance systems, or any other service, and according to their risk analysis, require them to comply with security measures to strengthen the international supply chain.
The risk analysis carried out by the transport company regarding its commercial partners (clients and suppliers) must include risks related to the identification of activities related to money laundering and terrorism financing. Additionally, the transport company must foster a documented social compliance policy and program that, at a minimum, addresses how among its employees and commercial partners they could guarantee that goods, inputs, or merchandise from Mexico for the manufacture of products or merchandise do not come from extraction, production, or manufacturing, totally or partially, with prohibited forms of labor, that is, forced or compulsory, including forced or compulsory child labor, under Article 23.6 of the T-MEC and the Agreement that establishes the merchandise whose importation is subject to regulation by the Secretariat of Labor and Social Welfare, published in the Official Gazette of the Federation (DOF) on February 17, 2023.
4.1 Selection Criteria.
There must be documented procedures for the selection, follow-up, or renewal of commercial relationships with business associates or suppliers, which include interviews, reference verification, evaluation methods, and use of provided information. The procedure for the selection of commercial partners must include, indicators to detect clients or suppliers that may not be legitimate or with unlocated addresses, in addition to investigations, reviews, or evaluations of said partners for the identification and control of activities related to money laundering and terrorism financing. If the investigation and/or evaluation of any commercial partner leads to substantial doubts about the veracity of their operations or services, the company must avoid hiring them and, where applicable, notify its security specialist or Authorized Economic Operator Program contact and the corresponding authority about its suspicions.
Response: Explanatory Notes: Attach the documented procedure for the selection and hiring of new commercial partners and monitoring of partners already working with them (this includes any type of provider that has a commercial relationship with your company; it is in the following sub-standard where it is requested to differentiate those at risk in your supply chain) and ensure it includes the following points:
I. What information is required from your commercial partner.
II. What aspects are reviewed and investigated.
III. The indicators to identify clients or suppliers that may not be legitimate or with unlocated addresses. This point refers to indicating all those alerts to determine that a commercial partner is not reliable and thus, conduct a deeper investigation and evaluate whether to work with them.
IV. Indicate if you maintain a file for each of your commercial partners, as well as the information it must contain.
V. Indicate how the services of your commercial partner are evaluated and what points you review.
The file must include at least the following:
I. Company data (name, tax ID key (RFC), activity, etc.).
II. Legal representative data.
III. Proof of address.
IV. Commercial references (where applicable).
V. Contracts, agreements, and/or confidentiality agreements.
VI. Security policies.
VII. Where applicable, certificate or certification number in the security programs to which it belongs.
4.2 Security Requirements.
The transport company must have a documented procedure in which, according to its risk analysis, it requests additional security requirements from those commercial partners that intervene in its supply chain such as, Sub-contracted Transporters, Customs Brokers, Private Security, warehouses, pensions, companies that provide the service of Repair of Transport Means, Service Providers for Loading and Unloading of merchandise, cleaning service providers, private security, hiring of personnel, high-security seal suppliers, collection and recycling, as well as those resulting from the analysis carried out.
The requirements must be based on the Land Auto Transporter Profile established by the AGACE, or in case it exists, the specific Profile for each actor in the supply chain that corresponds to them.
The company must request from its commercial partners the documentation that accredits and proves that they comply with the minimum security standards established in this Land Auto Transporter Profile, either through a written declaration issued by the legal representative of the partner, agreements or contractual clauses backed by documentation that supports compliance with the requirements established in the Authorized Economic Operator Program.
Likewise, the transport company must take into account and know the specific requirements of the Authorized Economic Operator Program that will be applicable to each of its commercial partners, based on their activity within the supply chain.
In the case of the company's commercial partners that provide their services within the facilities, they must be obliged to comply with these supply chain security requirements, for example, companies that provide gardening, cleaning, cafeteria services, etc.
Response: Explanatory Notes: Describe the procedure that indicates how you carry out the identification of commercial partners that require compliance with minimum security standards and how these comply with such requirements. Ensure you include the following points:
I. A register of commercial partners that must comply with security requirements, and mention what type of providers these are (transporters, warehouses, custodian services, security company, transport means repair services, loading and unloading service, customs brokers, etc.).
II. Indicate how documentation (agreements, accords, contractual clauses, and/or addenda) ensures that your commercial partners comply with security requirements.
III. Indicate if there are agreements, accords, contractual clauses, and/or addenda regarding the implementation of security measures with your service providers inside your company, such as: security guards, cleaning and maintenance services, etc.
IV. Indicate if you have commercial partners to whom it is required to belong to a supply chain security program, either by certification by a foreign authority or the private sector (For example: CTPAT or any other World Customs Organization Authorized Economic Operator Program) as well as the information and documentation requested of them.
4.3 Commercial Partner Reviews.
The company, through the Security Committee, must carry out periodic security evaluations (as well as derived from risk situations), of the processes and installations of business associates based on a risk analysis, to guarantee that they have minimum security standards required by the company based on the Authorized Economic Operator Program, keep records of them, which allow verifying that the processes and security measures are being executed, as well as the corresponding follow-up.
When inconsistencies are found, the transport company must communicate this to its commercial partner and provide a justified period to attend to the observations or areas of opportunity identified, or otherwise, implement the necessary measures to sanction them.
Carrying out security evaluations of commercial partners is important to guarantee that there is a solid security program that functions correctly, which is why, in addition to a documented procedure, there must be a program or calendar for the execution of such security reviews or evaluations, prioritizing partners that are more critical according to their risk analysis. If a member is not evaluated and the company does not know if the processes and installations of its commercial partners function correctly, it puts its supply chain at risk.
Response: Explanatory Notes: Describe the procedure to carry out security evaluations for the verification of security requirements of your commercial partners, ensure you include the following points:
I. Periodicity with which visits to the commercial partner are made (these must be at least once a year and derived from risk situations).
II. Record or report of the verification and, where applicable, the corresponding follow-up.
III. Program or calendar for the execution of security reviews.
IV. The verification formats must be duly filled out, placing the date, name, and position of those participating in the review, signatures, etc.
V. Indicate what action measures are taken when commercial partners do not comply with the established security requirements.
In case of having commercial partners with CTPAT certification or another supply chain security certification program, indicate the periodicity with which their status is reviewed, how you register it, and the actions you take in case it is detected that it is suspended and/or cancelled, according to what is established in your procedure.
The procedure must include:
I. Periodicity of visits.
II. Points of review in security matters.
III. Preparation of reports.
IV. Feedback and agreements with the commercial partner.
V. Follow-up to agreements.
VI. Measures in case of detection of non-compliance with requirements.
VII. Record of evaluations.
VIII. Area or person responsible for carrying out this procedure.
Control measures must be established to guarantee the integrity and security of processes related to transport means (in any of their modalities), handling, storage of foreign trade merchandise (where applicable), manufacturing companies, manufacturers or assemblers, parts and/or spare parts suppliers, mechanical suppliers, or any other service along the supply chain.
Likewise, there must be established procedures to prevent, detect, or dissuade undeclared materials or unauthorized personnel from having access to transport means and containers. These control measures and procedures must be documented with the intention and objective of maintaining at all times the integrity of the transport means and the import and export shipment from the point of origin to its final destination.
5.1 Process Mapping.
There must be a process map, which describes step by step the operational flow for the transfer of foreign trade merchandise, along the supply chain that includes, in an illustrative but not exhaustive manner, and regarding the service requested by the contractor, the following: assignment of the transport means, container, trailer, inside and outside of yards according to availability, entry to the facilities of the manufacturer, supplier, or seller that describes the loading and unloading of merchandise, the transfer with authorized routes and rest points. If within your supply chain any part of the transport is subcontracted, it is indispensable that it be considered within your risk analysis and process mapping, since, the more direct and indirect suppliers, the greater the risk involved.
Likewise, the land transporter must have written procedures for the designation of operators/drivers, previously designed routes, collection of cargo and delivery of foreign trade merchandise to the final destination; handling of documentation specific to the shipment during loading and/or unloading maneuvers or in advance; communication during the route of the shipment between intermediate or final points, its relationship with other actors in the supply chain such as logistics operators, Customs Brokers among others, and contracting clients.
Response: Explanatory Notes: Attach the documented procedure where you describe in detail the process mapping or operational flow of your general transport service and the type of service you provide, which includes the designation of operators/drivers, vehicles/units, previously designed routes, cargo collection and delivery, handling of documentation, communication during the operation with other actors in the supply chain handling, storage of foreign trade merchandise (where applicable), manufacturing companies, manufacturers or assemblers, parts and/or spare parts suppliers, mechanical suppliers, or any other service including your contracting clients. In order to have well identified each of the steps involved in the transportation of the merchandise until delivery at the final destination.
The process mapping must include, the names (tax ID key (RFC) and corporate name) of the companies that provide you with services in your logistical process. This mapping must include, at least the following aspects:
I. Service request.
II. Assignment of Unit and container or Trailer.
III. Assignment of Operator.
IV. Confirmation of service.
V. Instructions to the Transporter.
VI. Cargo collection.
a) Identification before the company.
b) Instructions Letters for delivery.
VII. Consolidation of merchandise/Seal of the container (if applicable).
VIII. Storage during waiting for shipping instructions or dispatch order.
IX. Transfer of merchandise to port, border, exit customs:
a) Indicate the points and areas of rest or custody of the cargo vehicles during the transfer of merchandise subject to foreign trade (import and export).
b) Indicate the estimated times that said vehicles remain in the rest or custody areas (company yards, exit customs, customs broker agency facilities, warehouses, transfer yards or transport, among others).
X. Constant communication means with the transport company and the contracting company (during the transfer and at the end of the service).
XI. Transfer to de-consolidation point (if applicable).
XII. Waiting storage.
XIII. De-consolidation.
XIV. Transfer to final destination.
XV. Information flow associated with the shipment. Administrative management process (General process of sending documentary information, and billing).
For the purposes of the administrative management and billing process, the transport company must have a documented procedure to receive and register the service request that the user will require, which must contain, at least the service request, which includes, in an illustrative but not exhaustive manner, at least the following information:
I. Origin (Collection).
II. Destination.
III. Cargo specifications (domestic, international, dangerous, high value, etc.).
IV. Delivery time and date.
V. Cost per freight.
VI. Insurance:
a) Designation of unit and operator.
b) Preparation and delivery of documentation:
Instructions to coordinate with other service providers that intervene in customs clearance and border crossing (customs brokers, DOT, consolidators/de-consolidators, among others).
Documentation that is required to present at customs.
Personal protective equipment, or any special request from the customs broker or customs agency.
VII. Guideline for loading and unloading of merchandise at customs and/or with the client.
5.2 Delivery and Receipt of Cargo.
The transport company must inform the operators/drivers of the transport that carry out the delivery or receipt of foreign trade cargo of the criteria and conditions that their clients (manufacturers, suppliers, etc.) demand for the handling of their cargo, as well as comply with the security guidelines that the company has to enter their facilities at the time of collection and/or delivery of foreign trade cargo. The transport company must give its clients, previously before these deliver the shipment and maneuvers of loading and unloading are carried out in the vehicles designated for such effects, the information regarding the operators/drivers so that they can be fully identified upon arrival at their facilities. The transport company must have an updated database with detailed information of its operators/drivers.
The operator/driver must know the documents that will be delivered to them, which cover the ownership of the cargo to be transported, such as the dispatch order or transfer, as well as the instruction sheet that will precisely establish the contact data of the person to whom they must direct themselves in case of any incident, inspection by another authority, or modification of the original conditions of the shipment, routes marked by the client among others.
Likewise, with the documentation that was delivered to them, they must corroborate at the time of loading and unloading of the merchandise the number of packages and the assigned locks described in them.
Furthermore, the transport company must issue for each shipment, a duly documented bill of lading (carta porte), which must contain, in addition to fiscal requirements, the applicable provisions contained in the Federal Auto Transport and Auxiliary Services Regulations.
Prior to the loading of the merchandise, the operator must inspect the vehicle to guarantee that the transport means is free of visible pest contamination.
Additionally, training must be provided to transport operators to review import and/or export documentation in order to identify or recognize suspicious cargo shipments, such as:
I. Originating or destined to unusual places;
II. Different routes;
III. Cash payments;
IV. Observe unusual sending and/or receiving practices;
V. Lack of information.
Response: Explanatory Notes: Attach the documented procedure in which you indicate step by step how the delivery and receipt of the cargo is carried out, including: how you assign the operator and the transport means, how the arrival time at the companies' facilities is established for the collection and delivery of the cargo, and how you guarantee that the transport means is free of visible pest contamination, in case of identifying any type of visible pest, contamination, trash, insects, grass, herbs, or weeds, how it is reported and what actions you take regarding it.
5.3 Cargo Tracking Procedure. The carrier company is responsible for monitoring the integrity of the means of transport, as well as the cargo, from the moment of loading until its delivery at the destination established. Therefore, it must have documented procedures that establish the use of technology for the tracking and supervision of activities related to the movement of the means of transport carrying foreign trade cargo for land transfers. A device capable of tracking the position of the vehicles in which the cargo is transported via GPS/Satellite Link must be available during the entire duration of the transfer, with continuous geographic coverage throughout the route. Said device must have the following characteristics: I. Ensure that the device cannot be removed from the unit to which it was fixed without this being detected and authorized. II. Recognize a Geofence (deviation limit). III. Know the position of the vehicle at all times. IV. The device must have a Unique Identification Number (serial number). V. When an alert is detected, the device must be able to automatically change the transmission of the vehicle's position so that it is reported every fifteen minutes, as long as the condition that triggered the alert remains. VI. The device must be autonomous in its operation; that is, it does not require energy from the vehicle during its journey. The device must have an alert scheme, at least for the following cases: I. Device outside Geofence. II. Device exceeds idle time. III. Vehicle exceeds time of stay in the country. IV. Unauthorized removal of the device. Likewise, the carrier company should have a coupling device, sensor connector, or equivalent technology from the tractor to the trailer to guarantee that the latter is also monitored and tracked, preventing said device from being removed and having alerts that indicate the place, date, and time of hooking and unhooking. Similarly, the company must establish documented procedures to ensure at all times the location of the carrier's vehicle in transit. These procedures must be carried out under a risk analysis that includes, by way of example and not limitation, the identification of predetermined routes, estimated delivery times, as well as intermediate points, as well as overnight and/or rest (yards, pensions, exit customs, customs broker's facilities or customs agency, freight agents, authorized meal stops, fuel loading, routine mechanical inspections, among others), which must be recorded and incorporated into the tracking process. Similarly, measures and actions to be taken in the event of identifying any delay in the route due to weather conditions, traffic, mechanical incident, route changes, or inspection by any authority or any security incident must be included. There must be trained and authorized personnel to carry out the permanent monitoring and/or traceability of shipments that transport foreign trade cargo. The monitoring, tracking, supervision, and registration data of all vehicles in transit carrying foreign trade cargo (whether they cross into the United States of America and/or to any other country) must be preserved for one year when the authority and/or the carrier must carry out an evaluation due to a security incident and/or for audit purposes. If they have contracted the services of a subcontracted provider for the cargo transport service, the company must have access to its carrier's GPS monitoring system, so that it can track the movement of its shipments.
If, as a result of monitoring and tracking, a real (or actual) threat to the security of a shipment or means of transport is identified, the company must alert (as soon as possible) the business partners in the supply chain that may be affected and, where appropriate, the authority as applicable. If the driver makes stops during their journey, they must register them and carry out inspections of the means of transport, containers, trailers, and semi-trailers used as Instruments of International Traffic, as well as of the closing devices, seals, and/or padlocks to verify their integrity and identify signs of manipulation before resuming the journey. Similarly, the driver must be able to recognize, act, and report when threats arise during the transport of the units, such as: attempted theft, kidnapping, among others. With the aim of guaranteeing that tracking and monitoring procedures are followed, in addition to supervising the correct completion of related records, management must involve itself in the surveillance and monitoring of cargo vehicles on the route, so it must participate in the periodic performance of documented random reviews of the tracking and control procedures. These random reviews must include the verification of the tracking records carried out by the responsible area against GPS records or route histories, to verify delivery time indicators, intermediate points, overnight, and/or rest. Response: Explanatory Notes: Describe how you carry out the review of predetermined routes based on your risk analysis, individually or collectively with your clients, and how it is documented. Likewise, the monitoring of shipments must be documented, and this record must contain the following information: I. Operator Name. II. Origin and destination of the service. III. Client. IV. Type of cargo. V. Records of the unit's location. VI. Driver's hours of service log, which is a daily record containing the necessary data to know the effective driving time and determine rest in accordance with the Regulation for Federal Highways Traffic. Attach the documented procedure to monitor the vehicles or means of transport that transport foreign trade cargo.
The procedure must include, by way of example and not limitation, the following: I. The area and person(s) responsible in the carrier company for tracking and monitoring shipments. II. Indicate who the people authorized to monitor and/or track foreign trade operations are and how they have been instructed and trained to perform this task. III. Indicate by what means and/or systems they perform the monitoring of shipments. IV. Have GPS whose external hardware is hidden and can resist attempts to remove it, indicate the type of system implemented in the units used and, in case of a third-party or subcontracted service, describe the consultation tools available to monitor the cargo. V. In the case of geofences, within their parameters, minimum tolerances allowed for the predetermined transit route must exist or be established. VI. Frequency to review the status of shipments and according to your risk analysis. VII. Indicate the means of communication that exist with the transport unit operator (indicate if there is more than one way to communicate: Cell phone, tracking system, global positioning systems (GPS), fixed supervision points, etc.). VIII. Indicate the frequency with which clients are informed of the location of their shipments, or if they share any tracking system.
IX. Have systems or procedures with instructions to respond to significant route deviations and in case of any delay (stops, changes or route deviations, mechanical failures, accidents, etc.) for arrival at the loading area, transfer points (exchange of boxes and semi-trailers) or final destination. Likewise, drivers must notify (to their supervisor and where appropriate to the sender or consignee of the cargo) any significant delay in the route due to weather, traffic, accidents, mechanical failures, route change, when the operator identifies that they are being observed or followed during the transport of the cargo, unit custody, etc. And on its part, the company must independently verify the cause of said delay. X. The procedure must also include that, in case of identifying a real or actual threat to the security of a shipment or means of transport; how the company informs the business partners of its supply chain that may be affected and, where appropriate, the authority as applicable, about this type of incidents or presumptions. 5.4 Processing of Information and Cargo Documentation. Carrier companies must have written procedures to ensure that both the electronic and/or documentary information sent by their clients from their service request, during the movement and transfer of the cargo, as well as the information received by business associates is legible, complete, accurate, reported in time, and protected against changes, losses, or the introduction of erroneous information. Similarly, forms and documentation related to import and/or export should be secured to prevent unauthorized use. Response: Explanatory Notes: Attach the documented procedure for the processing of cargo documentation. Briefly explain what it consists of. I. Detail how you receive and transmit relevant information and documentation for the transfer of foreign trade cargo with your business partners (Indicate if you use a specific control computer system and briefly explain its function). Likewise, detail how you guarantee that the information provided is legible, complete, accurate, reported in time, and protected against changes, losses, or the introduction of erroneous information. II. The electronic information of shipments and cargo in general must include the seal and/or padlock number with which the cargo was secured. 6. Customs Management. The carrier company must have documented procedures, in which internal and operational policies are established, as well as the necessary controls for the due compliance of customs obligations. 6.1 Customs Obligations. For the case of carrier companies that enter fiscal or supervised premises to transfer foreign trade cargo, they must have a documented procedure for obtaining the CAAT registration, in accordance with what is established in articles 1 and 20 of the Law and rule 2.4.5. Carrier companies that have registration in the registry of carrier companies for cargo in transit, in accordance with rule 4.6.11., must have a documented procedure with the objective of complying with what is established in rule 4.6.18. Regarding internal transits of foreign trade cargo referred to in articles 127 of the Law and rule 4.6.11., the carrier company must have a documented procedure that guarantees the notice to customs authorities caused by late arrival, indicating the causes that originated the delay, the place where the means of transport is located, the transit petition number, and the state in which the official padlocks are, if applicable (article 188 of the Regulation). For the purposes of what is stipulated in article 128 of the Law and rule 4.6.17., the carrier company, where applicable, must have a documented procedure that guarantees that the internal transit of the goods must be carried out within the maximum time limits established in Annex 15. For cases of destruction of goods provided for in article 94 of the Law and 141 of the Regulation, the carrier company must have a documented procedure by which it guarantees the delivery of notices in a clear, precise, and exact manner to the customs of destination. Response: Explanatory Notes: Indicate if you have the CAAT and, if so, indicate your registration number. Attach the procedure that describes the steps to follow to obtain the CAAT (this procedure must include the steps to follow to obtain the radiofrequency identification device number (transponder), in addition to including, who and how the information related to your vehicle fleet and transport operators is updated.
Indicate if you have the Registry to carry out the transit of Goods, if affirmative, attach the following procedures: I. Documented procedure to comply with rule 4.6.18, which must include, by way of example and not limitation, the following: a) Notices to the authority, of changes in the information provided for obtaining the registration. b) Integrate and maintain updated an automated daily register of service users. c) Integration of a file for each service user. II. Attach the documented procedure that guarantees the notice to customs authorities caused by late arrival in accordance with article 188 of the Regulation. III. Attach the documented procedure referred to in article 128 of the Law in relation to rule 4.6.17, and where appropriate, describe how you guarantee compliance with the transfer time limits referred to in Annex 15. 7. Security of Cargo Vehicles, Containers, Trailers, and/or Semi-Trailers. The security of means of transport, tractors, containers, trailers, and semi-trailers (including cargo vehicles, pickup truck type, van, or van, among others) must be maintained to protect them from the introduction of unauthorized persons and/or materials. For this reason, it is necessary to have documented procedures to inspect, seal, and maintain their integrity. Similarly, the process of inspecting said means of transport, containers, train cars, trailers, and semi-trailers used as Instruments of International Traffic, must include a procedure for agricultural inspections to look for visible pests and serious structural deficiencies. Pest contamination is defined as visible forms of animals, insects, or other invertebrates (living or dead, at any stage of the life cycle, including eggs, etc.), or any organic material of animal origin (including blood, bones, hair, meat, secretions, excretions, etc.); plants or vegetable products (including fruits, seeds, leaves, twigs, roots, bark, etc.); or other organic material, including fungi, dirt, or water; when such products are not the declared cargo within the Instruments of International Traffic. In case of using high-security seals, it is necessary to have procedures to correctly seal and maintain the integrity of containers and trailers from the loading point. A high-security seal must be applied to all containers and trailers for foreign trade shipments, which must meet or exceed Standard ISO 17712 for high-security seals. With the aim of maintaining supply chain security, the carrier company must inspect all cargo vehicles systematically upon entry and exit of its facilities (domestic and international traffic), in addition to keeping a record.
7.1 Use of Seals and/or Padlocks in Containers and Trailers. The use and placement of seals or padlocks on means of transport (containers, trailers, and semi-trailers) is considered a critical and necessary process to maintain the integrity of shipments that transport foreign trade cargo. Therefore, the carrier company must document procedures that include the control, custody, assignment, handling of discrepancies, replacement, and destruction of padlocks and seals that meet or exceed Standard ISO 17712. The carrier company must have a documented procedure where the means of transport are identified and, where applicable, the containers, train cars, and/or semi-trailers used in its international logistics chain, and indicate how their integrity is maintained. For this reason, as one of the security mechanisms, the carrier company must use High Security padlocks or seals that meet or exceed Standard ISO 17712 in all loaded containers and trailers that are subject to foreign trade and maintain their integrity until delivery at the final destination. For this, the carrier company must have documented procedures to place and verify the correct application of seals, their inspection at intermediate points, final destination, and their replacement when they are opened by any authority. In case of such an inspection, drivers must notify and register any anomaly or unusual structural modification found in the means of transport derived from said review. The procedures must include the steps to follow if it is discovered that a seal is altered, manipulated, or there is an incorrect seal number in the documentation, the communication protocols to business partners involved in the supply chain, and the investigation of the security incident; these must be notified to security personnel, business partners that may be part of the affected supply chain, security specialist, or Authorized Economic Operator Program contact. The carrier company must verify and evidence that during loading points, as well as in reviews by any authority or due to changes in the original conditions of the shipment, high-security seals or padlocks that meet or exceed Standard ISO 17712 are correctly applied and placed; for the case of consolidated cargo collection and delivery operations that do not use consolidation centers to sort or consolidate the cargo before arriving at the destination, the carrier company must, at each stop and before arriving at the destination, place high-security seals on the trailer, semi-trailer, or container. The company's management or a security supervisor must carry out periodic and documented audits of high-security seals and/or padlocks; these reviews must include the verification of the inventory of stored seals and/or padlocks and the cross-check with inventory records and shipping documents. Likewise, the company must have documented procedures that clearly describe how high-security seals will be controlled by the carrier during route transit, and that include, by way of example and not limitation, the following: I. Verify the correct placement of seals or padlocks according to the VVTT inspection method to evidence and discard improper manipulations: a) V - View the seal and lock mechanisms of the container. b) V - Verify the seal number. c) T - Pull the seal to ensure it is correctly placed. d) T - Twist and turn the seal to ensure. II. Review and cross-check the documentation containing the number of the original seal or padlock and the additional ones carried during the transport of the cargo. III. If the company uses cable seals, they must be placed on the two vertical bars of the container.
IV. Review that closing devices, hinges, and pins are attached to the trailer or container, and welded or riveted. V. Consider the type of reports and records that will be made if the seal is removed, even by official authorities or due to an incident during the transport of the cargo, contemplating the installation of a second seal as a replacement and its proper notification to the owner of the cargo. VI. If the company uses cable seals, they must be placed on the two vertical bars of the container. VII. Review that closing devices, hinges, and pins are attached to the trailer or container, and welded or riveted. VIII. Consider the type of reports and records that will be made if the seal is removed, even by official authorities or due to an incident during the transport of the cargo, contemplating the installation of a second seal as a replacement and its proper notification to the owner of the cargo. Response: Explanatory Notes: Describe the documented procedure for the review of seals and/or padlocks in vehicles, means of transport, containers, trailers, and/or semi-trailers. This must include, among other aspects according to your operation: I. Verify that the seal or padlock is intact and determine if there is evidence of improper manipulation. II. Use the VVTT inspection method. III. Review and cross-check the documentation containing the number of the original seal or padlock and, where applicable, the additional ones carried in the transport of the cargo. In case of using the replacement seal and/or padlock, said number must be registered within the carrier company's control. If altered seals and/or padlocks are identified, they must be kept to help carry out the investigation of said incident or discrepancy and, as applicable, report the compromised seals and/or padlocks to the foreign authority. IV. Review that closing devices, hinges, and pins are attached to the trailer or container, and welded or riveted. Also, protective plates can be placed on the door hinges and/or a seal/adhesive tape can be placed on at least each side. Also,
must verify the correct functioning of handles, locks, and all other locking or closing mechanisms of cargo vehicles to detect manipulations and any inconsistencies before placing any sealing device.
V. Indicate how they assign and replace high-security padlocks, in the event that, during the trip, they are inspected by another authority. If a seal and/or padlock is broken in transit, the cargo must be examined, the number of the replacement seal and/or padlock must be registered, and the driver (as well as the transport company) must immediately notify business associates when this happens, indicate who broke it, and provide the new seal number.
Attach the documented procedure for the control and handling of seals and/or padlocks. This must include, among other aspects according to their operation:
I. What type of seals and/or padlocks they use in their operations (foreign trade, transit, storage, etc.).
II. Who has access and how padlocks and/or seals are safeguarded. The management of seals and/or padlocks must be restricted only to authorized personnel; stored in a safe place, have an inventory, control of their distribution and tracking (record of seals used, as well as the receipt of new seals and/or padlocks).
III. Describe how the company's management or security supervisor participate in audits of high-security seals and/or padlocks, the reviews they perform, the records they generate, and the actions they take in case of identifying discrepancies. Also, how supervisors in the shipping area and/or warehouse managers verify the numbers of seals used in transport means and International Traffic Instruments to corroborate that the information is correct (this process can also be included within the internal audits referred to in sub-standard 1.3 of this document).
IV. How discrepancies in seal and/or padlock numbers are addressed.
V. Indicate who the supplier(s) are and how it is verified that the specifications of the seals and/or padlocks comply with ISO 17712 Standard (attach certificate issued by the certifying company responsible for verifying compliance with the corresponding ISO).
All written procedures must be disseminated and maintained at the operational level so that they are easily accessible to employees responsible for carrying out the tasks described above, reviewed at least once a year, and updated as necessary.
7.2 Inspection of transport means, containers, trailers, and semi-trailers.
The transport company must have procedures to permanently carry out a review of the transport means (tractors), containers, trailers, and semi-trailers used as International Traffic Instruments, including the reliability of the door locking mechanisms, in order to identify natural or hidden compartments, using a checklist or format that includes the main points to be reviewed. This review must be carried out by operators/drivers or personnel designated by the company for this purpose. Likewise, the physical-mechanical conditions of the transport means must be periodically reviewed to verify their proper functioning.
Inspections of transport means or cargo vehicles, containers, and trailers must be systematic, and carried out at the entrance and exit of yards or storage sites and, where applicable, at the loading point of the goods (contracting company); and if the infrastructure allows, before arriving at the customs office for clearance using the VVTT inspection method. A record of these inspections must be kept in an area with controlled access and carried out in a place monitored by alarm systems, closed-circuit television, and video surveillance systems; this system must cover the entire inspection system.
The documented procedure for its inspection must include, by way of example and not limitation, the following review points:
| Transport Means | Containers, Trailers, and Semi-trailers |
|---|---|
| I. Bumper. | I. Exterior and interior doors. |
| II. Tires and rims (tractor and trailer). | II. Side walls (left and right). |
| III. Floor (tractor). | III. Internal and external roofs. |
| IV. Fuel tanks. | IV. Front wall. |
| V. Cab interior (bedroom, and tool compartment). | V. Internal floor. |
| VI. Air tanks. | VI. Refrigeration system, if applicable. |
| VII. Chassis. | |
| VIII. Fifth wheel area. | |
| IX. Drive axles. | |
| X. Exhaust pipe. | |
| XI. Engine. |
Likewise, before loading transport means, containers, train cars, trailers, and semi-trailers used as International Traffic Instruments, they must undergo agricultural and security inspections to guarantee that their structures have not been modified to hide contraband or have been contaminated with visible agricultural pests, keep a record, and be backed by a documented procedure. If visible pest contamination is found during the inspection or transport of goods subject to foreign trade, it must be cleaned (washed, vacuumed, etc.) to eliminate said contamination. The driver must ensure before crossing that the cab is clean and free of trash.
Response: Explanatory Notes:
Attach the documented procedure to carry out the security and agricultural inspection of transport means, containers, trailers, and semi-trailers. This must include, among other aspects according to their operation:
I. Those responsible for carrying out the inspection.
II. Definition of the place(s) where the inspection takes place and indicate how it is monitored by alarm systems, closed-circuit television, and video surveillance.
III. The review points for transport means, trailers, semi-trailers, and containers, both for security and for quality and agricultural inspections with the purpose of searching for visible pests.
IV. Instructions for the driver to ensure before crossing that the cab is clean and free of trash.
Attach the format used to perform the inspection that complies with the minimum requirements indicated in this sub-standard. If you use other types of cargo vehicles for the transport of goods (vans, pickups, 3.5 tons, tankers, etc.), your procedure and inspection format must include the process and review points. Likewise, the security and agricultural inspection format must include the following information:
I. Date of inspection; II. Time of inspection; III. License plates of the vehicle (tractor and trailer); IV. Container/trailer number; V. Specific areas of the cargo vehicles that were inspected; and VI. Name of the employee who performs the inspection and the supervisor.
The security and agricultural inspection formats may be signed by the supervisor to corroborate their information and be part of the import and export documentation:
I. In the case of transport companies for hazardous materials and waste, each vehicle must have a daily visual review log of the auto-transport unit.
The documentation must be kept for one year for investigation in case of any security incident, as well as to demonstrate continuous compliance with these inspection requirements.
Additionally, and according to the risk analysis, the transport company should carry out periodic random reviews of cargo vehicles to verify that they have been carried out correctly, counteract internal conspiracies, and prevent security incidents. The reviews must be carried out randomly, without prior notice, so that they do not become predictable, in addition to being carried out in different places where the transport means could be susceptible to contamination (maneuvering yard, loading and unloading areas, after loading the unit, and on the route to the border of the United States of America).
Description of the place(s) where the inspection takes place and indicate if it is monitored by alarm systems, closed-circuit television, and video surveillance.
Likewise, describe the procedure carried out on transport means, cargo vehicles, trailers, semi-trailers, and/or containers used as International Traffic Instruments, to validate that they meet the physical-mechanical conditions for daily operation on roads and bridges under federal jurisdiction, in addition to validating that they have records of this type of maintenance for at least one year.
This procedure must additionally include the following:
I. Responsible personnel. II. Places where inspections are carried out. III. In case any physical-mechanical condition and/or anomaly is detected that affects the proper functioning of the units, how they are reported, and what measures must be taken. IV. Indicate what type of record is kept.
In cases where, due to major structural modifications in transport means such as axles, springs, chassis modifications, and even cabin adaptations, among others, the owner and person responsible for the vehicle fleet must contemplate, in accordance with their risk analysis, a more exhaustive review of the vehicle in question to ensure its integrity, in this regard:
I. Indicate whether the repair or maintenance of transport units (tractors), containers, or trailers is carried out in the same facilities, or is carried out with an external provider. II. Briefly describe how the delivery-receipt of vehicles that suffered a modification as mentioned in the previous paragraph is carried out.
7.3 Storage of vehicles, transport means, containers, trailers, and semi-trailers.
The transport company must maintain the integrity at all times of the transport means (tractors, containers, trailers, and/or semi-trailers, among others) by establishing controls within its facilities. If they are empty and must be stored in parking areas, they must be secured with a padlock and/or indicative seal, or, where applicable, in a secure area that is guarded and/or monitored.
When it is necessary to store or overnight any container, trailer, and/or semi-trailer with foreign trade goods, it must be in a secure area with perimeter barriers and monitored by alarm systems, closed-circuit television, and video surveillance, to prevent unauthorized access and manipulation of the unit and the merchandise, so it must be closed with a high-security padlock according to ISO 17712 Standard.
If during the trip on the authorized route to the final destination, it is considered necessary to move to a facility that is authorized as a storage yard for vehicles, transport means, containers, trailers, and semi-trailers, whether owned by the company or through a third party, the transport company must guarantee that these facilities meet the minimum criteria in terms of security based on this Ground Transport Operator Profile established by the AGACE, or in its case, by some other Authorized Economic Operator Program.
Response: Explanatory Notes:
Describe how you ensure the integrity of the transport means that transport foreign trade merchandise (boxes, containers, trailers, and/or semi-trailers).
Indicate the types of seals and/or padlocks used for boxes, containers, trailers, and/or semi-trailers.
Indicate how many facilities the company contemplates for the storage of vehicles, transport means, containers, trailers, and semi-trailers and add the following data for each of these:
I. Name or denomination of the facility. II. Full address of the facility. III. Surface area of the facility marked in m2. IV. Indicate how many foreign trade shipments enter the facility (import/export). V. Number of people working in this facility. VI. When any facility has been visited by CTPAT, indicate the date on which the visit was carried out. VII. Indicate in each of the facilities which one belongs to the company or is a service contracted through a third party. VIII. Describe how you ensure that your commercial partner who provides the storage service complies with the minimum requirements in terms of security.
There must be documented procedures for the registration and evaluation of people who wish to obtain employment within the transport company and establish methods to carry out periodic verifications of current employees.
Likewise, there must be continuous training programs for administrative and operational personnel that disseminate the company's security policies, as well as the consequences and actions to be taken in case of any misconduct.
8.1 Verification of work history.
The transport company must have documented procedures to investigate and verify the information recorded in the curriculum, criminal records (if local legislation and company policies allow), and applications of candidates with potential for employment, in accordance with local legislation, either on their own or through an external company.
Likewise, for positions that, due to their sensitivity, require it and affect the security of shipments subject to foreign trade, in accordance with their previously carried out risk analysis, they must consider requesting stricter requirements for their hiring, which must be carried out periodically.
Regarding personnel who already work in the company, periodic investigations must be carried out based on the activities and/or sensitivity of the employee's position.
This procedure must contemplate the creation and updating of personnel files, which must have restricted access and contain the following information, by way of example and not limitation:
I. Job application. II. Updated photograph (in electronic or printed format). III. Copy of official identification. IV. Copy of the current federal driver's license issued by the SICT according to the type of service to be provided. V. Copy of updated proof of address. VI. Copy of birth certificate. VII. Registration with Social Security Institutions. VIII. Recommendation letters. IX. Evaluations (Toxicological Exam mandatory for operators/drivers) at least every six months. X. Terms of hiring. XI. Minimum mechanical knowledge exam.
Likewise, for sensitive positions identified in the previously carried out risk analysis and directly affecting the security of transport means, they must consider requesting stricter requirements for their hiring, which must be carried out periodically (e.g., Operators/drivers).
Response: Explanatory Notes:
Describe the documented procedure for personnel hiring and ensure you include the following:
I. Requirements and documentation required. II. Tests and exams requested.
Indicate the areas and/or critical positions identified as risky, according to your analysis, and indicate the following:
I. Indicate what are the additional requirements for specific areas and/or jobs such as criminal records (if local legislation and company policies allow), non-criminal record letter, socioeconomic studies, clinical studies, toxicological (drug use), etc. Where applicable, indicate the jobs or work areas where they are required and with what frequency they are carried out.
II. Indicate if, prior to hiring, the candidate must sign a confidentiality agreement or a similar document.
The procedures for personnel hiring and contractors may include:
I. Exhaustive investigations of the work and personal backgrounds of new employees. II. Confidentiality and responsibility clauses in employee contracts. III. Specific requirements for critical positions. IV. Where applicable, the periodic update of the socioeconomic and physical/medical study of employees who work in critical and/or sensitive areas. V. Hiring process and requirements requested for temporary employees and contractors. VI. Indicate the medical and toxicological exams carried out on operators/drivers. VII. In case of hiring a service agency for personnel hiring, indicate if this has documented procedures for personnel hiring and how you ensure they comply with the same. Briefly explain what they consist of. VIII. The company may consider the results of background verifications of candidates, as allowed by current legislation, to make hiring decisions.
Background verifications are not limited to identity and criminal record verification. In higher-risk areas, deeper investigations may be justified.
8.2 Personnel dismissal procedure.
There must be documented procedures for personnel dismissal, which include the delivery of identification, and any other item that has been provided to them to perform their functions (keys, uniforms, badges and/or credentials, computer equipment, passwords, tools, etc.). Likewise, this procedure must include the deactivation in those information and access systems, among others that may exist.
Response: Explanatory Notes:
Describe the procedure for personnel dismissal, and ensure you include the following:
I. Who is responsible for carrying out and following up on this procedure. II. How the delivery of identification, uniforms, keys, and other equipment is carried out and confirmed. III. Indicate the control, record, and/or format, in which the delivery of material is identified and ensured, and deactivation in information systems (where applicable, attach). IV. Indicate the type of records of personnel who ended their labor relationship with the transport company, so that when it has been for security reasons, their service providers and/or business associates are warned.
8.3 Personnel administration.
The transport company must maintain an updated system, control, or database of active employees. Likewise, affiliation records with Social Security Institutions and other legal labor records must be carried out and kept updated.
In the case that the company has personnel hired by its commercial partners and working within the facilities, it must ensure that they comply with the requirements established for the rest of its employees.
Response: Explanatory Notes:
Indicate if the company has an updated system, control, or database, both for personnel hired directly, and that hired through a service provider company, and ensure it includes, by way of example and not limitation, the following points:
I. Full name. II. Updated photograph at least every five years. III. Personal data (age, name, date of birth, phone number, address, CURP, social security number, blood type, allergies, etc.). IV. Family ties. V. Work history. VI. Diseases. VII. Medical exams. VIII. Training. IX. Type of license and status thereof (they must have a record of transport licenses with the corresponding validity, in order to prevent their drivers from traveling with expired licenses). X. Results of periodic evaluations. XI. Observations. XII. This personnel must be hired in accordance with the current labor laws and regulations.
There must be prevention measures to maintain the confidentiality and integrity of information and documentation related to shipments that transport foreign trade merchandise, including those used for the exchange of information with other members of the supply chain. Likewise, there must be comprehensive documented policies and/or procedures to protect Information Technology systems, which include measures against misuse, in addition to identifying and prioritizing actions to reduce cybersecurity risk. They could also address how a member shares information about cybersecurity threats with the government and other commercial partners.
9.1 Classification and handling of documents.
There must be procedures to classify documents according to their sensitivity and/or importance, with special emphasis on that received from their contractors where information related to routes, materials, merchandise, and/or goods being transported, instruction letters, schedules, names of clients and/or contacts, among others, is described. Sensitive and important documentation must be stored in a secure area that only allows access to authorized personnel. Reviews must be conducted regularly to ensure that documents are not used improperly.
The useful life of documentation and/or files must be identified, and procedures established for their destruction.
I. The company must have updated and secured files for means of transport, containers, trailers, and semi-trailers, containing the following: a) Proof of ownership or legal possession of the vehicle with invoice, proforma invoice, customs entry permit, lease contract, or document from the National Vehicle Registry. b) Circulation card.
II. Valid civil liability insurance policy for damages to third parties or guarantee fund.
III. Certificate of low pollutant emissions.
IV. In the case of the transport of hazardous materials and waste, the transport company must have an insurance policy for environmental damage.
The foregoing in accordance with what is stipulated in the Federal Autotransport and Auxiliary Services Regulations and the Regulations for the Land Transport of Hazardous Materials and Waste.
Response: Explanatory Notes: Attach the documented procedure for the registration, control, and storage of printed documentation (classification and filing of documents), which must include: I. Control register for delivery, loan, among others, of documentation. II. Restricted access to the archive area. III. Storage and classification policies. IV. An updated security plan that describes the measures in force regarding the protection of documents against unauthorized access, as well as against deliberate destruction or loss thereof. V. In the case of electronic or digital information, it must adhere to the security criteria of sub-standard 9.2 Information Technology Security.
9.2 Information Technology Security. To protect Information Technology systems against common cybersecurity threats, a company must have sufficient protection that promotes security in Information Technology infrastructure (software and hardware) against malware (viruses, spyware, worms, trojans, etc.), baiting, phishing, and internal/external intrusions (firewalls) in the companies' computer systems. Likewise, companies must ensure that their security software is active and receives periodic updates.
In the case of automated systems and computer equipment, individual accounts that require periodic password changes must be used. In order to protect the confidentiality, integrity, and availability of information, the company must have policies, procedures, and information technology standards established, which must be communicated through a training program for all employees who handle computer equipment and systems, which includes topics to prevent attacks through social engineering and all those threats to which they are exposed (malware, baiting, phishing, etc.). Companies that allow employees to connect remotely to a network must employ secure technologies, such as virtual private networks (VPN), to allow employees to access the company intranet securely when they are outside the office, as well as procedures designed to prevent unauthorized remote user access.
For the above, there must be written procedures and infrastructure to protect the company against losses, theft, leakage, hacking, and/or ransomware of information, this includes the procedure for the recovery (or replacement) of Information Technology systems and/or data, as well as a system established to identify the abuse of Information Technology systems and detect inappropriate access and/or improper manipulation or alteration of commercial and business data, as well as a written procedure for the application of appropriate disciplinary measures to all offenders. Access to Information Technology systems must be protected against infiltration through the use of secure passwords, which include phrases or other forms of authentication. Users of said Information Technology systems must safeguard and not share their access keys or passwords. All Information Technology infrastructure must be physically protected against unauthorized access.
Response: Explanatory Notes: Attach the procedure for the recovery or replacement of Information Technology systems and/or data, which includes how it backs up and guarantees the security of its information, in addition to protecting it from possible losses. Be sure to include the following points: I. State the frequency with which backups are carried out. II. Who has access to them, and who authorizes the recovery of information. III. Indicate what type of tests are performed and how often, to verify the security of the network, systems, and infrastructure. IV. Mention if, to carry out this type of tests or vulnerability scans, it is done through software, a third party or provider, and if so, indicate the name or corporate name.
V. In case vulnerabilities are found, describe the corrective actions that must be implemented. VI. Indicate if you share information about cybersecurity threats with your business partners who participate within your supply chain (for example: communications, bulletins, emails, etc.). VII. Systems must be protected with passwords and must be modified frequently, for the above, indicate the procedure to change them. VIII. State if there are information security policies for their protection. IX. Have a system or software to detect and identify the abuse, intrusion, or access of unauthorized persons to your systems and/or Information Technology data, as well as the abuse of the policies and procedures established by the company, including unauthorized access to internal systems, external websites, and the manipulation or alteration of commercial data by employees or contractors. X. All offenders must be subject to the application of disciplinary measures, for the above, indicate the corrective policies and/or sanctions in case of detection of any violation of Information Technology security systems and policies.
Information Technology and cybersecurity policies and procedures must be reviewed annually and updated resulting from an attack or according to situations that may put the company's systems at risk.
Describe the security measures used to allow employees to connect remotely to a network (VPN), to allow employees to access the company intranet remotely when they are outside the office. In case of allowing employees to use personal devices to perform the company's work, such devices must comply with the company's cybersecurity policies and procedures, security updates must be periodic, and have a method to access the company network securely. Indicate if the computer equipment has a backup power supply system that allows business continuity. The procedures regarding the backup of the transport company's information must also include: I. How and for how long the data is stored. II. Business continuity plan in case of incident and how to recover the information. III. Frequency and location of backup copies and archived information. IV. If backup copies are stored in sites alternative to the facilities where the data processing center is located. V. Tests of the validity of data recovery from backup copies. The procedures regarding the protection of the company's information must also include: I. An updated and documented policy for the protection of the company's computer systems against unauthorized access and deliberate destruction or loss of information. All sensitive and confidential data must be stored in an encrypted or encoded format.
II. Detail if you operate with multiple systems (sites/locations) and how these systems are controlled. III. Who is responsible for the protection of the company's computer system (responsibility should not be limited to one person but to several so that each can control the actions of the rest). IV. Each user's access must be assigned through individual accounts and restricted according to the job description or assigned tasks. For the above, describe how access authorizations and access levels to computer systems are granted (access to sensitive information must be limited to authorized personnel to perform modifications and use of information). Authorized access must be monitored by the area responsible for granting it, to verify or in case report that access to confidential systems is based on job requirements. V. Indicate the elements or format that passwords must have for access to Information Technology systems and computer equipment, frequency of changes, if there are other authentication methods, and who or what area provides those passwords. VI. Indicate the name of the firewall and antivirus used (include licensing related), evidencing that this security software is active and receives periodic updates. For the above, cybersecurity policies and procedures should include measures to prevent the use of counterfeit technological products or with incorrect licenses (software and hardware).
All computer equipment, electronic media (hard drives, cell phones, etc.) and Information Technology hardware that contain confidential information related to the import and export process, must be accounted for through periodic inventories and have such evidence. When these technological equipment must be discarded, there must be a documented procedure that includes how they must be formatted, disinfected, or destroyed appropriately to avoid information leakage.
VII. In case of staff turnover, access to computer equipment, telecommunications, and network must be eliminated at the moment of the employee's separation, this includes email accounts, system access accounts, software, programs, etc. VIII. Elimination, maintenance, or updating of user details. IX. Measures planned to deal with incidents when the system is compromised.
10.1 Training and awareness on threats. The transport company must have a training and awareness program on supply chain security policies directed at all its employees (operational and administrative) and, additionally, make informational material available regarding the procedures established in the company to consider a situation that threatens its security and know how to report it. The company must have an additional program for its operators/drivers that it uses for the transport of goods destined for foreign trade, which includes specific topics according to their functions that allow them to maintain the integrity of the means of transport and their cargo, handling of incidents, changing locks in case of inspection by other authorities, when the operator identifies that they are being watched or followed during the transport of goods, among others, that are implemented.
Likewise, specific training must be offered according to their functions to help employees maintain the integrity of trailers and tractors for agricultural and security purposes, receipt and review of mail and packages, prevention of operations with proceeds of illicit origin (money laundering, terrorism financing, etc.), how to recognize and how to report internal conspiracies and protect access controls, as well as training regarding smuggling, cargo theft, placement of high-security seals and locks (VVTT inspection method), prevention of visible contamination by pests, etc. These topics must be established as part of new employee onboarding and periodically maintain update programs. Update training must be carried out periodically, after a security incident and when there are changes in the transport company's procedures.
In addition to security training programs, an awareness program on alcohol and drug consumption must be included. Also, disseminate and train staff on the company's cybersecurity policies, procedures, and standards (theft, leakage, hacking, and/or ransomware of information), including access to computer equipment and systems via passwords or phrases. Personnel who operate and administer security technology systems must receive training related to their operation and maintenance, including self-training through operational manuals and other methods. These topics must be established as part of new employee onboarding and periodically maintain update programs. Update training must be carried out periodically, after a security incident and when there are changes in the company's procedures.
Training programs must encourage active employee participation in security controls and mechanisms, as well as maintain records of all training efforts provided by the company, and the list of those who participated in them (videos, photographs, minutes, attendance lists, intranet or other system, didactic material, PowerPoint presentations, brochures, etc.). Records must include the date of the training, the names of the attendees, the topics taught, in addition to having measures to verify that the training provided met all training objectives.
The foregoing, in accordance with the regulation established by SICT, which establishes that permit holders will have the obligation to provide their drivers with training and coaching to achieve that the provision of services is efficient, safe, and effective.
Response: Explanatory Notes: Must have a training program on security and prevention in the supply chain for all employees (administrative and operational). Briefly explain what it consists of and be sure to include the following: I. Brief description of the topics taught in the program. II. When they are taught (onboarding, specific periods, etc.). III. Frequency of training and, if applicable, updates. IV. Indicate how participation in supply chain security training is documented (videos, photographs, minutes, attendance lists, intranet or other system, didactic material, PowerPoint presentations, brochures, etc.). Training records must include the date of the training, the names of the attendees, the topics taught, in addition to having measures to verify that the training provided met all objectives of the same. V. Explain how employee participation in security matters is encouraged.
The topics that must be included, by way of example and not limitation: I. Access and security policies at the facilities. II. Delivery-receipt of merchandise. III. Confidentiality of cargo information. IV. Transport instructions. V. Accident and emergency reports. VI. Instructions for placing locks and/or seals in case of inspection by other authorities. VII. Installation and testing of security alarms and unit tracking, when applicable. VIII. Identification of authorized formats and documents to be used.
Training to perform the review of cargo vehicles, containers, trailers, and/or semi-trailers for agricultural and security purposes must include the following topics: I. Signs of hidden compartments; II. Hidden smuggling in natural compartments; III. Signs of pest contamination;
IV. Procedures to follow if something is found during an inspection of the means of transport or if a security incident occurs during transit; V. Training on agricultural reviews must cover pest prevention measures, regulatory requirements applicable to wooden packaging materials, and the identification of infested wood. Operators and personnel who perform agricultural and security inspections of means of transport must be trained to inspect cargo vehicles for such purposes, for the above, describe how you comply with the provisions established by SEMARNAT and NOM-144 SEMARNAT-2017, in concordance with International Phytosanitary Measure No. 15 called. Regulation of wooden packaging used in International Trade, which emanate from the United Nations Organization for Food and Agriculture and the identification of infested wood.
In the case that the strategic fiscalized facility identifies that any of the foreign trade shipments is involved in a situation that puts the security of the supply chain at risk, due to the suspicion of a business partner or person, it must inform security personnel, business partners who may be part of the affected supply chain, security specialist or Authorized Economic Operator Program contact, as well as the competent authority, and, if possible, before the border crossing, exit, or customs dispatch (import and export). The procedures must include the steps to follow if it is discovered that a seal is altered, manipulated, or there is an incorrect seal number in the documentation, the communication protocols to the business partners involved in the supply chain, and the investigation of the incident. All the aforementioned procedures must be reviewed periodically or at least once a year to ensure that contact information and action protocols are correct.
11.1 Report of anomalies and/or suspicious activities. In case of detection of anomalies and/or suspicious activities, related to the security of the supply chain and in accordance with your logistical processes (related to access control, delivery, receipt, and storage of merchandise, security inspections of cargo vehicles and transport operators, etc.), these must be notified to security personnel, business partners who may be part of the affected supply chain, security specialist or Authorized Economic Operator Program contact and/or other competent authorities, keeping a record of said anomalies and/or unusual activities.
Response: Explanatory Notes: Describe the procedure to denounce or report anomalies and/or suspicious activities, as well as those that contain mechanisms to anonymously report problems related to security, be sure to include the following: I. Who is responsible for reporting incidents. II. Detail how you determine and identify with which authority to communicate in different scenarios or presumption of suspicious activities. III. Mention if you keep a record of the report of these activities and/or suspicions and briefly describe what it consists of.
11.2 Investigation and analysis. There must be written procedures to denounce or report anomalies and/or suspicious activities, as well as for the analysis and investigation of security incidents in the supply chain to determine their cause, in addition to corrective actions to prevent them from happening again, which must be implemented as soon as possible. The information derived from this investigation must be documented and available at all times for the authorities that require it.
This information and documentation generated to carry out foreign trade operations, must be included in a file for the purpose of allowing the identification of each of the processes that the means of transport went through, up to the point where the incidence was detected and that allows recognizing the vulnerability of the chain.
Response: Explanatory Notes: Describe the documented procedure to initiate an investigation in the event of any security incident, and ensure you include the following: I. Person responsible for conducting the investigation. II. Documentation comprising the investigation file. III. Information related to the driver(s)/operators, vehicles (tractors), containers, trailers and/or semi-trailers, cargo, and routes. The documents to be included in the file derived from the investigation, in an illustrative but not exhaustive manner, may be: I. General shipment information, Purchase Order. II. Transport request; Confirmation of transport means; Identification of the transport operator (Access records, etc.). III. Container Inspection Formats; Exit Order; delivery records. IV. Videos from alarm systems, closed-circuit television, and video surveillance. V. Documentation generated for the carrier (Packing list, Bill of Lading, instruction sheet). VI. Documentation generated for commercial partners (Description of goods, Proformas, invoices, etc.). VII. Documentation generated by the commercial partner (Customs declarations, Manifests, Tracking and inspection reports, videos if applicable, etc.). VIII. Unit tracking and monitoring report (GPS tracking).
E6. Courier and Package Profile Receipt Acknowledgment First Time: Renewal: Addition: Modification: The data you provide will replace the data you provided when you requested your authorization.
General Information The objective of this Profile is to ensure that courier and package companies have security practices and processes implemented in their facilities, focused on strengthening the supply chain and mitigating the risk of contamination of shipments with illicit products. Courier and package companies interested in obtaining the authorization referred to in Rule 7.1.5. must demonstrate that they have documented and verifiable processes; likewise, they must integrate the criteria required in this document according to the business model or design they have established, seeking during the implementation of security standards the application of a risk analysis culture supported by decision-making consistent with the values, mission, vision, codes of ethics, and conduct of the company itself. When the courier and package company holds an authorization for a Fiscalized Facility or Strategic Fiscalized Facility; in addition to complying with this document, it must accredit the requirements and guidelines established for the control, surveillance, access routes, infrastructure, equipment, and security of foreign trade goods established by ANAM, and may prove its compliance with that which coincides with what is established in this Profile.
Filling Instructions: I. A Courier and Package Profile must be filled out for each of the main facilities where foreign trade cargo is consolidated and, where applicable, for related facilities such as warehouses, distribution centers, etc. The number of Profiles submitted must match the facilities declared in your application for registration as a Certified Commercial Partner under the courier and package category and with the addresses registered with the RFC (Taxpayer Registry Code). II. In each sub-standard, the courier and package company must detail how it complies with or exceeds what is established in each of the sections as indicated. III. The format of this document is divided into two sections, as detailed below:
Installation Data A Courier and Package Profile must be filled out for each of the cargo consolidation facilities that handle foreign trade goods, and, where applicable, for related facilities such as warehouses, distribution centers, consolidation points, etc.
Installation Information Profile Number of Courier and Package Profiles: of RFC Key Name and/or Corporate Name Name and/or Denomination of the Installation Type of Installation Street Number and/or Exterior Letter Interior Number and/or Letter Neighborhood Postal Code Municipality/Delegation Federal Entity Age of the installation (years of operation): Activity performed in the installation: Preponderant products handled in the courier and package company's installation: (As applicable) Average number of monthly shipments (EXP): (By maritime, air, land, rail, etc. transport means) Average number of monthly shipments (IMP): (By maritime, air, land, rail, etc. transport means) Total number of employees at this installation: Installation surface area (m2): Certifications in security programs: (Indicate if this installation has a certification from any of the following programs) CTPAT Yes No Level: Pre-Applicant: Applicant: Certified: Certified/Validated: CTPAT Account number (8 digits): Date of last visit at this installation: Authorized Economic Operator from other countries (OEA) Yes No Program: Registration: Other Supply Chain Security Programs Yes No Program: Registration: Certifications: (Indicate if you have certifications that you consider impact your supply chain process, for example: ISO 9000; Reliable Logistics Processes, among others) Name: Category: Validity: Name: Category: Validity: Name: Category: Validity: Name: Category: Validity:
1.1 Risk Analysis. The courier and package company must establish measures to identify, analyze, and mitigate security risks that could result in alterations to foreign trade cargo during its handling, guarding, custody, and transport in its supply chain and facilities, under the guideline of a documented procedure. This analysis must be based on the company's organizational model (e.g., facility locations, type of cargo, volume and country of origin, customers, suppliers, routes, information leakage, personnel hiring, classification and handling of documents, Information Technology, potential threats, etc.), so as to allow it to implement and maintain appropriate security measures. In accordance with the above, the company must also have a written process based on its risk analysis to select new commercial partners and monitor those with whom it is already working. This procedure must be updated at least once a year, so as to allow the permanent identification of new threats or risks considered in the operation, resulting from any security incident or originating from changes in initial conditions, as well as to identify whether the policies, procedures, control mechanisms, and security are being complied with. It is important to note that the company's Security Committee must participate in the preparation and updating of the risk analysis, as well as in the maintenance of the Authorized Economic Operator Program. Response: Explanatory Notes: Indicate which information sources are used to qualify risks during the analysis phase. Attach the risk matrix, as well as the documented procedure to identify risks in the supply chain and the company's facilities, ensure you include the following points:
I. Indicate the frequency with which you review and/or update the risk analysis. II. Indicate which aspects and/or areas of the company are incorporated into the risk analysis. III. Describe the methodology or techniques used to perform the risk analysis. IV. Mention who are the responsible parties for reviewing and updating the risk analysis. Likewise, the documented procedure to identify risks in the supply chain and its facilities must contemplate the risk assessment and management process, and include the following aspects: I. The context (cultural, political, legal, economic, geographic, social, etc.) of the installation. II. Identify risks in your supply chains and facilities. III. Risk analysis (causes, consequences, probabilities, and existing controls to determine the level of risk as high, medium, and low). IV. Risk evaluation (decision-making to determine risks to be treated and priority for implementing treatment). V. Risk treatment (application of alternatives to change the probability of risks occurring). VI. Risk monitoring and review (monitoring the results of the risk analysis and verifying the effectiveness of its treatment). It is suggested to use Administration, management, and risk evaluation techniques in accordance with international standards ISO 31000, ISO 31010, and ISO 28000, which, according to your business model, you should implement.
1.2 Security Policies. The courier and package company must have a policy oriented towards preventing, securing, and recognizing threats to the security of the supply chain and company facilities, such as drug trafficking, money laundering, arms trafficking, human smuggling, prohibited goods, acts of terrorism. To promote a security culture, companies must demonstrate their commitment to supply chain security and the Authorized Economic Operator Program through a statement highlighting the importance of protecting the flow of national and international commerce from criminal activities, established through the security policy. The senior officials or executives of the company who must endorse and sign the security policy may be the company president, executive director, general manager, security director, or personnel with a homologous position with decision-making authority. Response: Explanatory Notes: Enumerate the security policy oriented towards preventing, securing, and recognizing threats in the supply chain and company facilities, indicate who is responsible for its review, signature, and dissemination to employees, as well as the frequency with which it is updated. This policy must be communicated to employees through a dissemination program and/or campaign. The security policy must be signed by a senior official of the company and be displayed in various areas of the company, including the company website, posters in key areas of the company (reception, shipments, receipts, warehouse, etc.), and as part of the company's initial and reinforcement training.
1.3 Internal Audits in the Supply Chain. In addition to routine monitoring in control and security, it is necessary to schedule and conduct audits at least once a year, under the guidelines of a documented procedure that allows evaluating all supply chain security processes and its facilities in a more critical and deep manner, as well as guaranteeing that employees follow the company's security procedures. Audits must be carried out by the company's Security Committee, establishing a documented procedure, as well as a program or calendar for their execution. Although it is necessary that audits are focused on supply chain security and based on the evaluation, review, and execution of minimum security standards, their focus must be adjusted to the size of the organization, level of risk, business model, and variations between facilities. Audits can be general or focus on specific areas or processes according to their work program. The objective of an internal audit focused on the Authorized Economic Operator Program is to verify and guarantee that employees follow the company's security procedures. The review process does not have to be complex; however, the formats and records used for the application of these reviews must evidence that the application and execution of the evaluated processes were validated, in addition to the corresponding follow-up of identified observations. Senior management must review the audit results, analyze the causes, and undertake required corrective or preventive actions. The review process must guarantee that the necessary information is collected to allow management to perform this evaluation. The review must be documented, in addition to the fact that the courier and package company's points of contact must provide and register periodic updates on the progress or results of any audit, exercise, or validation. Response: Explanatory Notes: Describe the documented procedure to carry out an internal audit, focused on supply chain security, ensure you include the following points: I. Indicate how the courier and package company carries out the scheduling or calendarization to conduct an internal audit, in terms of supply chain security. II. Indicate who participates in them, the records generated, and the frequency with which they are carried out. III. Indicate how the company's management verifies the results of supply chain security audits and how it carries out/implements preventive, corrective, and improvement actions, as well as their follow-up and closure. IV. The formats used during internal audits must be properly filled out, and through them, evidence that security procedures and measures are being put into practice.
1.4 Contingency and/or Emergency Plans Related to Supply Chain Security. There must be a documented contingency and/or emergency plan; this plan must address crisis management, security recovery plans, and business resumption to ensure business continuity in the event of an impact on the normal development of the company's foreign trade activities and operations in its supply chain (during the transport, handling, storage, and custody of foreign trade cargo according to its logistics process). A crisis or contingency may include the interruption of commercial data movement due to a cyberattack, a fire, the kidnapping of a transport driver by armed individuals, customs closure, a bomb threat, the detection of suspicious packages, power outage, theft and/or damage to cargo, threats or extortion, blockades or road closures, among others. The courier and package company must communicate these plans to personnel through periodic training, as well as conduct tests, practical exercises, and annual drills of the contingency and emergency plans to verify their effectiveness, from which a properly filled-out and signed record must be maintained (for example: result reports, minutes, or reports, which must be backed by video recordings, photographs, etc., demonstrating their execution). The contingency and/or emergency plan must be updated as necessary, based on changes in operations and the organization's risk level. Response: Explanatory Notes: Attach the documented contingency and/or emergency procedure or plan, to ensure business continuity in the event of an emergency or security situation that affects the normal development of the courier and package company's foreign trade activities. This procedure must include, in an illustrative but not exhaustive manner, the following: I. What situations it contemplates, describing the action plan and steps to be followed in case of crisis, as well as the tasks assigned to personnel during the handling of such contingencies. II. What mechanisms it uses to guarantee that the business continuity plan is effective. III. Contemplate the scheduling and execution of annual drills and how they are documented (for example: result reports, minutes, or reports, which must be accompanied by video recordings, photographs, etc., demonstrating their execution).
2.1 Facilities. Facilities must be constructed with materials that can resist unauthorized access. Periodic documented inspections must be carried out to maintain the integrity of the structures, and in the event that an irregularity is detected, the corresponding repair must be carried out as soon as possible by the personnel designated for these tasks. Likewise, territorial boundaries, as well as various accesses, internal routes, and the location of buildings, must be fully identified. Response: Explanatory Notes: Indicate the predominant materials with which the installation is constructed (for example, metal structure and sheet metal walls, brick walls, wood, among others), and indicate how the review and maintenance of structural integrity is carried out. Indicate the personnel or area responsible for carrying out inspection, maintenance, and repair tasks for facility damages. Attach a general distribution or architectural plan, where the installation boundaries, access routes, emergency exits, location of buildings, critical areas, parking lots, and adjacent properties can be identified.
2.2 Access at Doors and Booths. Entry or exit doors for personnel and/or vehicles must be attended, controlled, watched, and/or supervised. The number of access doors must be kept to the minimum necessary. Access to sensitive areas must be restricted according to the job description or assigned tasks. Response: Explanatory Notes: Indicate how many doors and/or accesses exist in the facilities, as well as the operating hours of each, and indicate how they are monitored (in case of having assigned security personnel, indicate the quantity). Detail if there are blocked or permanently closed doors and/or accesses and their location. Describe how you ensure that access to sensitive areas is restricted according to the job description or assigned tasks (include the type of records and controls you use).
2.3 Perimeter Walls. Perimeter walls and/or peripheral barriers must be installed to secure the perimeters of the courier and package company's facilities, based on a risk analysis. Fences, interior barriers, or a mechanism to identify and segregate international cargo, as well as high-value and dangerous cargo, must be used. These must be inspected regularly and maintain a record of the review to ensure their integrity and identify damage, which must be repaired as soon as possible by the personnel designated for these tasks. The storage areas, high-value, dangerous, and/or restricted-access areas must be clearly identified and monitored to prevent unauthorized entry. Response: Explanatory Notes: Describe the type of peripheral barrier and/or walls that the installation has, ensuring you include the following points: I. Describe which areas are segregated. II. Point out their characteristics (material, dimensions, etc.). III. In case of not having walls, justify the reason in detail. IV. Frequency with which the integrity of the perimeter walls is verified, and the records that are kept to ensure their integrity and identify damage, which must be repaired as soon as possible. Indicate the personnel or area responsible for carrying out inspection and damage repair tasks. Describe how the cargo destined for foreign countries, dangerous material, and high-value cargo is segregated; ensure you include the following points: I. Indicate how national merchandise and foreign trade merchandise are separated, and if it is additionally identified (for example: different packaging; labels; packing, among others). II. Identify and point out restricted-access areas (dangerous goods, high value, confidential, etc.).
The procedure for the inspection of perimeter walls could include: I. Responsible personnel to carry out the review. II. How and how often the inspections of fences, perimeter walls and/or peripheral walls and buildings are carried out. III. How the inspection record is kept. IV. Who is responsible for verifying that repairs and/or modifications meet the technical specifications and necessary security requirements. 2.4 Parking Lots. Access to the facilities' parking lots must be controlled and monitored by security personnel or personnel designated for this task. Private vehicles (of employees, visitors, suppliers, and contractors, among others) must be prohibited from parking within the merchandise handling and storage areas, as well as in adjacent areas. Response: Explanatory Notes: Describe the procedure for the control and monitoring of parking lots, ensuring you include the following points: I. Those responsible for controlling and monitoring access to the parking lots. II. Identification of the parking lots (specify if the visitor parking is separated from the merchandise storage and handling areas). III. How the entry and exit of vehicles to the facilities is controlled, indicate the records made for parking control, the existing control mechanisms (for example: ticket machines, card readers, badges, etc.), how they are assigned, and the responsible area for doing so. IV. Policies or mechanisms to prevent the entry of private vehicles into the merchandise storage and handling areas.
2.5 Key and Lock Device Control. Windows, doors, and interior and exterior fences, according to their risk analysis, must be secured with locking devices. The company must have a documented procedure for the handling and control of keys and/or locking devices for interior areas considered critical. Likewise, they must keep a record and establish control through signed responsibility letters from persons who have keys or authorized access according to their level of responsibility and tasks within their work area. Response: Explanatory Notes: Indicate if all doors, windows, interior and exterior entrances have closing or security mechanisms. Attach the documented procedures for the handling and control of keys and/or locking devices, ensuring they include the following points: I. Those responsible for administering and controlling key security. II. Format and/or control record for key lending. III. Treatment of loss or non-return of keys. IV. Point out if there are areas where access is with electronic devices and/or some other access mechanism. 2.6 Lighting. Lighting inside and outside the facilities must allow for clear identification of people, material, and/or equipment located there, including the following areas: entrances and exits, handling, loading, unloading, and storage areas for merchandise, perimeter walls and/or peripheral walls, interior fences, and parking areas, and must have an emergency and/or backup system in sensitive areas. Response: Explanatory Notes: Describe the procedure for the operation and maintenance of the lighting system, ensuring you include the following points: I. Point out which areas are illuminated and which have a backup system (indicate if you have an auxiliary power plant or some other mechanism to supply electrical energy in case of any contingency).
II. How do you ensure that the lighting system is appropriate in each of the company's areas so that it allows clear identification of the personnel, material, and/or equipment located there. The procedure may include: I. How the lighting system is controlled. II. Operating hours. III. Identification of areas with permanent lighting. 2.7 Communication Devices. The courier and package company must have communication devices and/or systems to contact security personnel and/or emergency and security authorities as required immediately. Additionally, it must have a backup system and verify its proper functioning periodically. Response: Explanatory Notes: Describe the procedure that personnel must perform to contact the company's security personnel or, in their case, the corresponding authority in case of any security incident. Indicate if operational and administrative personnel have or have access to devices (landline phones, mobile phones, alert and/or emergency buttons, etc.) to communicate with security personnel and/or the corresponding person (these must be accessible to users to be able to react promptly). Indicate what type of communication devices the company's security personnel uses (landline phones, cell phones, radios, alarm system, etc.). Describe the procedure for the control and maintenance of communication devices, ensuring you include the following points: I. Policies for the assignment of mobile communication devices. II. Maintenance or replacement program for fixed and mobile communication devices.
III. Indicate if you have backup communication devices, when the permanent system fails and, in its case, detail briefly. The procedure may include: I. Responsible for the proper functioning and maintenance of communication devices. II. Verification and maintenance record of the devices. III. Method of assignment of communication devices. 2.8 Alarm Systems and Closed-Circuit Television and Video Surveillance Systems. Alarm systems, closed-circuit television, and video surveillance systems, and security technologies, must be used to monitor, notify, or deter unauthorized access and prohibited activities in the facilities and other considered sensitive areas, notify the corresponding area, and also be used as a tool of evidence in investigations derived from any security incident. These security systems and technologies must be placed according to a prior risk analysis so that areas involving the handling, loading, unloading, and storage of merchandise, security inspections of cargo vehicles, as well as the access of personnel, visitors, suppliers, passenger and cargo vehicles, and other considered sensitive areas are permanently and uninterruptedly monitored, supervised, and supervised in accordance with what is established for this effect by the ANAM and simultaneous operation with the customs or area in question. The foregoing is applicable in cases where courier and package companies are located within a supervised facility and/or outside of it. Such systems must allow clear identification of the area or environment being monitored and maintain a backup of the recordings for at least one month, considering that, in the case where their logistics processes exceed this period, the period for maintaining these backups must be increased, in order to have the necessary elements to assign corresponding responsibilities in case of a security incident. The courier and package company must have a documented operation procedure. In the case of alarm systems, closed-circuit television, and video surveillance systems, and security technologies, they must include supervision of the good condition of the equipment, verification of the correct position of the cameras, indicate the frequency with which the backup of the recordings must be performed for at least sixty days in accordance with rule 2.3.8., for those that have supervised facility and strategic supervised facility authorizations, for other cases the recording period must be at least thirty days, as well as those responsible for their operation. Such systems and all security technology infrastructure must have restricted access. Response: Explanatory Notes: Mention the documented procedure in which the functioning of the external alarm system or sensors is indicated, and in its case, describe the following points: I. Indicate if doors and windows have alarm sensors, as well as the areas where motion sensors are available.
II. Procedure to follow in case an alarm is activated. III. Indicate the personnel or area responsible for maintenance, how failures are reported, and the records they use. Describe the documented procedure for the operation of alarm systems, closed-circuit television, and video surveillance systems, and security technologies, (this must be reviewed and updated annually and according to the risk analysis or circumstances), ensure you include the following points: I. Indicate the number of security cameras of the alarm and closed-circuit television and video surveillance systems installed, and their location by area (detail if it covers the loading and unloading zones, including the entry and exit points of the facilities, to cover the movement of vehicles and individuals, and where the inspection mentioned in sub-standard 7.2 is carried out). Attach a layout or map of the distribution of security cameras. II. Point out the location of the alarm systems, closed-circuit television, and video surveillance systems, and security technologies, where the monitors are located, who reviews them, as well as the operating hours, and in its case, if there are remote monitoring stations. All security technology infrastructure must be physically protected against unauthorized access. III. Periodic and random reviews of the recordings must be carried out. Indicate how they review them (random, every week, special events, restricted areas, etc.), who is the designated personnel, and how management is involved in the reviews. The results of the reviews must be documented to include corrective actions for audit purposes. IV. Indicate for how long these recordings are kept (it must be at least one month).
V. The alarm systems, closed-circuit television, and video surveillance systems, and security technologies must have an alternative energy source that allows them to continue functioning in case of an unexpected loss of direct energy. Therefore, indicate if the closed-circuit television and video surveillance system and security technologies are backed up by an electrical power plant or some other mechanism to supply electrical energy, which guarantees their functioning. These systems should have an alarm/notification function, which indicates a failure condition in the functioning and/or recording, point out if your systems have this function. VI. Indicate if, in addition to the alarm systems, closed-circuit television, and video surveillance systems, you use some other type of technology to strengthen the security measures you already have. VII. Describe the procedure that has been implemented to regularly test and inspect the alarm systems, closed-circuit television, and video surveillance systems, and security technologies and ensure their proper functioning. The results of the inspections and the functional tests must be documented, as well as the necessary corrective actions (these must be implemented as soon as possible). Additionally, that the documented results of these inspections are kept for a sufficient time for audit purposes. VIII. Indicate if the provider of the alarm systems, closed-circuit television, and video surveillance systems, has access to the security cameras, if they are in charge of monitoring them, how access is controlled, and who is responsible for said monitoring.
3.2 Employee Identification. The management or security personnel of the company must properly control the delivery and return of badges, ID cards, and/or employee, visitor, and supplier identification credentials. Procedures for the delivery, return, and change of access devices (for example, keys, badges, and/or proximity cards, etc.) must be documented. Access to sensitive areas must be restricted according to the job description or assigned tasks. Response: Explanatory Notes: Describe the procedure for employee identification and ensure you include the following points: I. Identification mechanisms (badge and/or photo ID, biometrics, proximity cards, etc.). II. Indicate if employees use uniforms, how they are assigned (by position, area, functions, etc.) and withdrawn (if applicable). III. Indicate how personnel contracted by a business partner, who works within the facilities (contractors, subcontractors, in-house services, personnel from merchandise handling companies, etc.) is identified. The procedure must also describe how the company delivers, changes, and withdraws employee identification and access controls and ensure you include the responsible areas for authorizing and administering them. Indicate how you ensure that access to sensitive areas is restricted according to the job description or assigned tasks (include the type of records and controls you use). Attach the documented procedure for the control of identifications. 3.3 Visitor and Supplier Identification. To have access to the facilities, visitors and suppliers must present official identification with a photograph for documentation purposes upon arrival and a record must be kept. All visitors and suppliers must receive a temporary identification, be accompanied by company personnel during their stay in the facilities, and ensure that the visitor/supplier always wears the provisional identification provided in a visible place. This procedure must be documented.
Response: Explanatory Notes: Describe the procedure for the access control of visitors and suppliers, ensure you include the following points: I. Point out what records are kept (personal forms for each visit, logbooks, among others). II. The record of visitors and suppliers must include the following: a) Date of the visit. b) Name of the visitor. c) Identification number with photo (official documents such as: driver's license, passport, INE, etc.). d) Entry and exit time. e) In the case of vehicle access, the format must include the data of the private or cargo vehicle (model, plate, trailer number, etc.). III. Point out who is the person responsible for accompanying the visitor and/or supplier and if there are restricted areas for their entry. 3.4 Procedure for Identification and Removal of Unauthorized Persons or Vehicles. The courier and package company must have documented procedures that specify how to identify, confront, or report unauthorized or identified persons and/or vehicles, said procedure must be communicated to responsible personnel through training. The training must be documented. Response: Explanatory Notes: Attach the documented procedure to identify, confront, or report unauthorized or identified persons and/or vehicles. The procedure must include: I. Responsible personnel. II. Designate a person or area responsible for being informed of security incidents.
III. Instructions for confronting and addressing unidentified personnel. IV. Point out in which cases the corresponding authorities must be reported. V. How the record of security incidents and the measures adopted in each case is carried out. 3.5 Courier and Package Deliveries. Courier and package deliveries destined for company personnel must be examined upon arrival and departure, before being distributed to the corresponding areas and destinations. Likewise, the company must have a documented procedure for the receipt and review of courier and package deliveries, which must be communicated to responsible personnel through training. The training must be documented. Response: Explanatory Notes: Describe the procedure for the receipt and review of courier and package deliveries and ensure you include the following: I. Personnel in charge of carrying out the procedure. II. Indicate how the personnel or provider of the courier and package delivery service is identified (point out if an additional procedure to the supplier access procedure is required). III. Point out how the review of the courier and/or packages is carried out, what mechanism you use, the records that are kept, and in its case, the detected incidents. IV. Describe the characteristics or elements to determine what courier and/or package is suspicious. V. Point out what action you take in case of detecting suspicious courier and/or packages.
4.1 Selection Criteria. There must be documented procedures for the selection, follow-up or renewal of business relationships with business associates or suppliers, which include interviews, reference checks, evaluation methods and use of provided information. The information derived from the investigation and/or evaluation of business associates and/or suppliers must be documented and integrated into a file (physical or electronic). The procedure for the selection of commercial partners must include indicators to detect customers or suppliers who may not be legitimate or with unlocated addresses. If the investigation and/or evaluation of any commercial partner leads to substantial doubts about the truthfulness of their operations or services, the company must avoid hiring them and, if applicable, notify its security specialist or Authorized Economic Operator Program contact and the corresponding authority about its suspicions.
Response: Explanatory Notes: Attach the information collected for the selection and hiring of new commercial partners and monitoring of partners already working with you, this includes any type of commercial relationship they have with your company and ensure you include the following points: I. What information is required from your commercial partner. II. What aspects are reviewed and investigated. III. Indicators to identify customers or suppliers who may not be legitimate (payments above standard rate, in cash; having little knowledge of the merchandise to be shipped; being evasive; minimal contact information (cell phone, contact points, emails, etc.); recently created companies or businesses without commercial history, etc.) or with unlocated addresses. This point refers to indicating all those alerts to determine that a commercial partner is not reliable and thus conduct a deeper investigation and evaluate whether to work with them. IV. Indicate if you maintain a physical or electronic file for each of your commercial partners, as well as the information it must contain. V. Indicate how you evaluate your commercial partner's services and what points you review. The file must include at least the following: I. Company data (name, tax ID key, activity, etc.). II. Legal representative data. III. Proof of address. IV. Commercial references (if applicable). V. Contracts, agreements and/or confidentiality agreements, security policies. VI. If applicable, certificate or certification number in security programs to which they belong.
4.2 Security Requirements. The courier and package company must have a documented procedure in which, according to its risk analysis, it requests additional security requirements from those commercial partners involved in its supply chain, such as: the services it provides as courier and package, as well as service providers such as cleaning, security, staffing, installation and maintenance of alarm systems, closed-circuit television and video surveillance, IT system and Technology providers, high-security seal suppliers, freight handling, unloading, storage and maneuvering service providers, contractors, airlines, among others. The requirements must be based on the Courier and Package Profile established by AGACE, or if it exists, the specific Profile for each actor in the supply chain that corresponds to them. The courier and package company must request from its commercial partners documentation that certifies and proves that they meet the minimum security standards established in this Courier and Package Profile, either through a written statement issued by the legal representative of the partner, agreements or contractual clauses, backed up with documentation supporting compliance with the requirements established in another Authorized Economic Operator Program. Similarly, the company must take into account and know the specific requirements of the Authorized Economic Operator Program that will be applicable to each of its commercial partners, based on their activity within the supply chain. In the case of commercial partners of the company that provide their services inside the facilities, they must be obliged to comply with these supply chain security requirements.
Response: Explanatory Notes: Describe the procedure that indicates how you carry out the identification of commercial partners that require compliance with minimum standards in terms of security. Ensure you include the following points: I. A register of commercial partners that must comply with security requirements, and mention what type of providers these are (carriers, warehouses, security companies, customs brokers, companies authorized to provide freight, unloading and merchandise handling services, etc.). II. Indicate in what documentary form (agreements, accords, contractual clauses and/or addenda) you ensure that your commercial partners comply with security requirements. III. Indicate if there are agreements, accords, contractual clauses, and/or addenda regarding the implementation of security measures with your service providers inside your company, such as customs brokers, private security guards, cleaning services, gardening, cafeteria, maintenance, Information Technology providers, etc. IV. Indicate if you have commercial partners who are required to belong to a supply chain security program, either certified by a foreign authority or the private sector (for example: CTPAT, or any other World Customs Organization Authorized Economic Operator Program), as well as the information and documentation requested from them.
4.3 Commercial Partner Reviews. The courier and package company, through the Security Committee, must carry out periodic evaluations and those derived from risk situations, of the processes and installations of business associates based on a risk analysis, to guarantee that they have minimum security standards required by the company based on the Authorized Economic Operator Program, keep records of them, which allow verifying that processes and security measures are being executed, as well as the corresponding follow-up. When inconsistencies are found, the company must communicate this to its partner or supplier and provide a justified period to address identified observations or areas of opportunity; otherwise, take necessary measures to sanction them. Carrying out security evaluations of commercial partners is important to guarantee that there is a solid security program and that it functions correctly, which is why, in addition to a documented procedure, there must be a program or calendar for the execution of said reviews or security evaluations, prioritizing partners that are more critical according to their risk analysis. If a member is not evaluated and the company does not know if the processes and installations of its commercial partners function correctly, it puts its supply chain at risk.
Response: Explanatory Notes: Describe the procedure to carry out evaluations to verify requirements (processes and installations) of your commercial partners, ensure you include the following points: I. Frequency with which you visit the commercial partner (this must be at least once a year and derived from risk situations). II. Program or calendar for the execution of security reviews. III. Record or report of the verification and, if applicable, the corresponding follow-up. IV. The verification formats must be properly filled out, placing the date, name and position of those participating in the review, signatures, etc. V. Indicate what action measures are taken when commercial partners do not comply with the established security requirements. VI. In case of having commercial partners with CTPAT certification or another supply chain security certification program, indicate the frequency with which their status is reviewed, how you record it and the actions you take in case it is detected that it is suspended and/or cancelled as established in your procedure.
The procedure must include: I. Visit frequency; II. Review points in terms of security; III. Report preparation; IV. Feedback and agreements with the commercial partner; V. Follow-up to agreements; VI. Measures in case of detection of non-compliance with requirements; VII. Evaluation records. Area or person responsible for carrying out this procedure.
5.1 Process Mapping. The courier and package company must have a map that shows step by step the logistical process of the flow of foreign trade merchandise and the required documentation through its international supply chain. The company must take into account and include within its mapping all parties involved in its supply chain, containing those that handle import and export documentation, such as customs brokers, others that may not directly handle the cargo but may have operational control such as carriers, freight, unloading, storage and merchandise maneuvering service providers and airlines. If any part of the transport is subcontracted within your supply chain, it is essential that it be considered within your risk analysis and process mapping, since the more direct and indirect suppliers, the greater the risk involved.
Response: Explanatory Notes: Attach the document where you illustrate and describe the process mapping through which your import and export merchandise passes, from the point of origin to the destination, with the aim of having clearly identified each of the steps involving the reception, storage, handling, custody and delivery of courier and package cargo.
The process mapping must include, the names (tax ID key and corporate name) of the companies that provide services in your logistics chain. This mapping must contain at least the following aspects: I. Collection, delivery and/or reception of foreign trade merchandise at the (the) distribution center(s) and/or collection points. II. Security in the transfer of merchandise to a fiscalized or supervised facility: a) Indicate the rest or holding points and areas for cargo vehicles during the transfer of foreign trade merchandise (import and export), as well as the documentation generated when cargo enters and leaves the facilities b) Indicate the estimated times that said vehicles remain in rest (reposo) or holding areas (company yards, exit customs, customs broker agency facilities, warehouses, transfer yards or transport, among others). III. Security in storage and/or distribution in a fiscalized or supervised facility. IV. Process security during customs clearance. V. Security in international transport (air, land, sea or multimodal). VI. Security in de-customs and/or de-consolidation in the destination country. VII. Delivery to final destination.
5.2 Warehouses and Distribution Centers. When the courier and package company has external warehouses and/or distribution centers registered under the same tax ID, they must be subject, according to their characteristics, to what is established in this document, with the object of maintaining integrity in its supply chain. Similarly, indicate if you have commercial partners providing some warehouse, distribution center or other service inside your facilities, which must at all times comply with the minimum security standards established by the company itself.
Response: Explanatory Notes: According to your process mapping, if foreign trade merchandise is transferred or moved to another alternate warehouse and/or distribution center different from the one operated by the courier and package company, you must indicate if they are registered under your Tax ID providing their general data (Name and address) and briefly explaining what activity is carried out in that or those installations (Cross Dock, temporary warehouse, etc.). Likewise, indicate if these belong to the company or is a service contracted through a third party and are part of a shareholder group. In this case, according to the supplier selection criteria mentioned in the section on Commercial Partners of this document, indicate how you ensure compliance with minimum security requirements (warehouses managed by a third party are not obligated to present a Courier and Package Profile).
Installations that have a concession or authorization of Fiscalized Facility or Strategic Fiscalized Facility; registered under your Tax ID must fill out for each authorized installation, the Profile of the corresponding modality and item.
5.3 Cargo Delivery and Reception. The courier and package company must guarantee the supervision of the identification of operators of own or subcontracted transport means, who carry out the collection, delivery or reception of foreign trade merchandise inside or outside your facilities, warehouses and/or distribution centers. Likewise, it must designate a person responsible for supervising the loading or unloading of the shipment, even according to instructions received from clients for its handling and transfer. On the other hand, it must supervise, inspect and verify through mechanisms, tools or non-intrusive technology available, the integrity of the transport means and of the foreign trade merchandise entering or leaving the courier and package company, checking the information described in the exchange lists received previously according to the traffic or transport modality in question. Similarly, it must guarantee that the driver transporting foreign trade merchandise, during delivery or reception, has the required documentary information before submitting to customs clearance formalities and authorizing its exit. The cargo preparation areas and the immediate surrounding areas must be inspected regularly to guarantee that these areas remain free of visible contamination by pests. During the loading and unloading process of merchandise, the company's security area (supervisor or security guard) must be present to validate that the process is being carried out correctly, mitigate the risk of shipment contamination (prohibited, illicit merchandise or pests) and register said review (incident reports, records, reports, etc.). As evidence that the high-security seal and/or lock was placed correctly, digital photographs must be taken at the time of loading the vehicles. To the extent possible, these images should be sent electronically to the destination or delivery contact point of the merchandise for verification purposes. Also, the personnel responsible for the shipping and/or receiving area must review the information included in import and/or export documents to identify or recognize suspicious cargo shipments. Likewise, specific training must be provided on identifying common errors in export shipment documentation, with the aim of preventing these from resulting in security incidents or suspicious merchandise. In case of having own cargo transport, it must provide training to transport operators to review import and/or export documentation in order to identify or recognize suspicious cargo shipments, such as: I. Originating or destined to unusual places; II. Different routes; III. Cash payments; IV. Observing unusual sending and/or receiving practices; V. Lack of information.
Response: Explanatory Notes: Attach the documented procedure for cargo delivery and reception, including the following: I. Inspection method at the access point to the courier and package company. II. Designation of personnel responsible for receiving the driver and the merchandise upon arrival. III. Coordination of the areas of the courier and package company who receive the exchange lists from transporters prior to their arrival and with the customs offices where customs clearance formalities are fulfilled. IV. Record of the introduction to the courier and package company of merchandise with complete and consolidated cargo. V. Release deadlines. VI. Prior requests. VII. Services offered by the courier and package company for the movement of merchandise prior to its customs clearance. VIII. How it guarantees that the transport means is free of visible pest contamination, in case any type of visible pest, contamination, trash, insects, grass, weeds or brush is identified, how it is reported and what actions are taken regarding it. Attach the documented procedure to detect and report discrepancies in the delivery or reception of transport means that transports merchandise and ensure it includes the following points: I. Persons responsible for carrying out the review. II. Documents to check. III. Areas to which the information is reported.
5.4 Merchandise Tracking Procedure. The courier and package company is responsible for monitoring and supervising the integrity of foreign trade merchandise throughout the supply chain, so it must have documented procedures in which the use of technology for tracking and supervision of activities (during collection; arrival at its cargo consolidation centers, storage, custody and release of merchandise, object of foreign trade), with the aim of guaranteeing compliance with customs clearance formalities, guaranteeing at all times having the following information: bill of lading number and information, packing list, waybill or other transport documents, as applicable, name and address of consignee or sender, description, value and origin of the merchandise, physical location in the installation, among others in accordance with applicable regulations. For the purposes of tracking units via land, the company must include in the aforementioned procedure, the identification of predetermined routes, estimated times for collection and delivery at warehouses and/or distribution centers or collection points, if applicable, intermediate points. Likewise, describe the measures in case of identification of delays on the route due to weather conditions, traffic, route changes, authority inspection or incidents related to security. The supervision data and record of all maneuvers in the courier and package company, as well as route histories must be preserved for one year when the authority and/or transporter must carry out an evaluation due to a security incident.
Response: Explanatory Notes: Attach the documented procedure to monitor internal transfers in the courier and package company of complete and/or consolidated foreign trade merchandise. This procedure must include, among other aspects according to your operation: I. Have GPS whose external hardware is hidden and can resist attempts to remove it, indicate the type of system implemented in the units you use and, if applicable, the consultation tools you have available to monitor the merchandise. II. Identify predetermined routes, estimated delivery times, between intermediate points and maneuvers in courier and package companies according to the transport in question. Once the time between assigned points has been determined, they must have a tracking process (route audit) and the corresponding records.
There must be systems or procedures with instructions in case of delays in the route; likewise, drivers must notify their supervisor of any significant delay in the route due to weather, traffic, accidents, mechanical failures, route changes, etc. And for its part, the company must independently verify the cause of said delay.
III. Detail if you have a means to communicate with the carrier during transport and if you have more than one form of communication.
IV. When the tracking is carried out by a third party, indicate who is responsible, and how it is verified that it is being carried out correctly, in accordance with the procedures established by the company.
V. In case of having own freight transport, GPS or equivalent technology must be used to guarantee that the trailer is also monitored and tracked. Describe how you carry out this tracking.
VI. GPS records or route histories must be safeguarded for cases of security incidents and audits.
5.5 Report of discrepancies in the cargo.
There must be documented procedures to detect and report missing, excess, prohibited merchandise, or any other discrepancy in the delivery or receipt of the goods collected prior to fulfilling the customs clearance formalities, in order to have information that contributes to the corresponding investigations by authorized consignees and, where applicable, by competent authorities. Likewise, you must describe the measures and actions to be taken in case of identifying the transport and handling of illicit, undeclared, and prohibited merchandise or those that, due to their nature, put the safety of users at risk, possibly during the following processes: reception, delivery, warehouse for prior inspections, consolidations, de-consolidations, transport medium yards, and where applicable, according to the services offered.
Response: Explanatory Notes: Attach the documented procedure to detect and report discrepancies in the delivery or receipt of the merchandise and ensure it includes the following points: I. Those responsible for carrying out the review. II. Documents to be checked. III. Areas to which the information is reported. This procedure must be applied to consolidated merchandise located in the warehouse.
5.6 Processing of information and documentation of the cargo.
The courier and package company must have documented procedures to ensure that the electronic and/or documentary information used during the movement, storage, custody, handling, and clearance of the cargo, as well as the information received from business associates, is legible, complete, accurate, reported in real-time, and protected against changes, loss, or introduction of erroneous information.
In the same way, there must be documented procedures to corroborate that the information received from business associates is reported accurately and timely. Likewise, forms and documentation related to import and/or export should be safeguarded to prevent unauthorized use.
Response: Explanatory Notes: Describe the procedure for processing cargo documentation, ensure you include the following points: I. Detail how you transmit relevant information and documentation regarding the transport and handling of cargo, as well as all those involved in the supply chain of the courier and package company, indicate if you use a specific computer control system and briefly explain its function. Likewise, detail how you validate that the provided information is legible, complete, accurate, reported in real-time, and protected against changes, loss, or introduction of erroneous information.
II. The electronic information of shipments and cargo in general must include the seal and/or lock number with which the cargo was secured.
III. Indicate how business associates transmit information to the courier and package company and ensure its accuracy, for example: the use of the institutional application "Consulta Remota de Pedimentos" to corroborate the payment of contributions and/or compensatory fees for exit authorization.
5.7 Inventory management, control of packaging, container, and packing material.
The courier and package company must have documented procedures for inventory control and cargo storage; these must involve periodic reviews and audits to verify their correct management. Likewise, it must have a documented procedure for the control of packaging, container, and packing material of the merchandise, which also includes the procedure for control, dissemination, and prevention of visible pest contamination, in the case of using wooden packing materials (such as pallets, boxes, crates, cages, reels, dunnage, chocks, supports, or platforms) to stack, move, and protect the cargo throughout its entire supply chain.
Response: Explanatory Notes: Attach the documented procedure for inventory management. This must include, among other aspects according to your operation: I. The frequency with which you carry out stock verification (periodic inventory). Indicate if there is a scheduled calendar documented to carry them out.
II. Indicate what is done in case of excesses and shortages in inventories.
III. Indicate the treatment given to the control and handling of packaging, container, and packing material, and, where applicable, of shrinkage, waste, or excess material, which also includes the procedure for control, dissemination, and prevention of visible pest contamination, in the case of using wooden packing materials (such as pallets, boxes, crates, cages, reels, dunnage, chocks, supports, or platforms) to stack, move, and protect the cargo.
IV. This point is also focused on reducing the risk of introduction or dissemination of quarantine pests of importance to the country through packaging (imports); therefore, describe how you comply with the provisions established by SEMARNAT and NOM-144-SEMARNAT-2017, in accordance with International Standard for Phytosanitary Measures No. 15, known as "Regulation for Wood Packaging Material used in International Trade," which emanate from the Food and Agriculture Organization of the United Nations.
V. Indicate how the fumigation process is to kill, inactivate, sterilize, desiccate, or eliminate pests. What actions do you take in case quarantine of packing materials is required?
VI. Indicate the area responsible for carrying out this process, as well as the documentation or certificates obtained. The applicant's procedures may include: I. Warehouse only accessible to authorized personnel.
II. Frequency of stock control.
III. Control of incoming merchandise, transfers to other warehouses, permanent and temporary withdrawals.
IV. Actions taken if irregularities, discrepancies, losses, or thefts are identified.
V. Treatment of deterioration or destruction of merchandise.
VI. Separation of various types of merchandise, for example: high value or hazardous.
The courier and package company must have documented procedures in which internal and operational policies are established, as well as the necessary controls for the due compliance of customs obligations.
Likewise, it must have specialized personnel and documented procedures that establish the verification of the information and documentation generated by the customs broker or, where applicable, ensure the processes carried out by the customs representative.
6.1 Customs Clearance Management.
The courier and package company must have a documented procedure in which the criteria for the selection of a customs broker or, where applicable, a customs representative are established, who, in accordance with national legislation, are authorized to promote on behalf of others the clearance of merchandise.
Response: Explanatory Notes: Describe the selection and evaluation procedure for the customs broker or customs representative and ensure it includes the following points: I. Selection criteria.
II. Evaluation methods and periodicity.
III. Describe the indicators with which you evaluate the service of customs brokers.
Indicate the full name and patent and/or authorization number of the customs broker or customs representative authorized to promote your foreign trade operations.
6.2 Customs Obligations.
The courier and package company must have a documented procedure for the compliance of customs obligations arising from the foreign trade operations carried out. This must include at least the following: the communication process with customs authorities when they are aware of the transport and custody of values greater than that determined by the authority in accordance with Article 9 of the Law. The transmission of cargo manifests through the SEA (Digital Window) and the established deadlines, in accordance with Article 38 of the Law Regulation and Rule 1.9.15.; notices in cases of destruction, loss, and decomposition of merchandise; the clearance process through the legal representative of the courier and package company whenever they do not exceed the determined amounts, the established exceptions, and the determination of payment of the global rate that corresponds. For cases where the electronic pre-validation of data service is provided, establish how you comply with the obligations foreseen in Rule 1.8.2; the notices that must be sent to the authorities regarding explosive merchandise and firearms; the update of data in the CAAT registry and its periodicity. The return processes of merchandise when it is in deposit before customs; regarding the use of the generic RFC in case of global operations and the use of RFC for individual operations.
In addition to the above, the courier and package company, in case of having authorization as a Strategic Fiscalized Premises, Fiscal Deposit, elaboration, transformation, or repair in a Fiscalized Premises, must have a documented procedure for the compliance of customs obligations arising from the foreign trade operations they handle. This must include at least the following: a) the annual guarantee that must be paid to the fiscal interest in accordance with the average value of the merchandise they handle; b) The identification of the physical space for the customs inspection carried out by customs authorities; c) the physical space designated for handling, storage, and custody services regarding merchandise that has become property of the federal treasury; d) the free storage and custody of merchandise in accordance with regulations; e) process of transfer of merchandise between warehouses; f) process to prove payment on the revenues for being a fiscalized premises; g) regarding the authorization for merchandise to be subject to elaboration, transformation, or repair, where applicable.
On the other hand, it must include in the procedure, the communication process with consignees in case of destruction or loss of merchandise; guarantee the exchange of information through a simultaneous system containing the data indicated in Rule 2.3.8 and establish protocols related to the treatment, communication, storage, and custody of foreign trade merchandise under the internal transit regime.
Response: Explanatory Notes: Attach the procedure to comply with your customs obligations.
6.3 Customs Verification.
The courier and package company, in order to guarantee the compliance of the information of the operations for the customs clearance of foreign trade merchandise, as well as to verify the truthfulness of the information declared to the competent authorities, must have documented procedures to verify that the customs declarations it receives for its release processing from the company match what appears registered in SAAI Web and, where applicable, report to the customs authority any discrepancy in said information. The company, likewise, must have a procedure for archiving the corresponding release records.
Response: Explanatory Notes: Attach the established procedure to verify the information registered in SAAI Web, and cross-check that the contributions and/or compensatory fees had been paid prior to the release of the shipments to submit to the customs clearance formalities.
The courier and package company must maintain the security of the transport means, tractors, containers, trailers, and semi-trailers (including freight vehicles, pick-up truck type, van type, or van, among others), to protect them from the introduction of unauthorized persons and/or materials. For this reason, it is necessary to have documented procedures to inspect, seal, and maintain their integrity. Likewise, the inspection process of said transport means, tractors, containers, trailers, and semi-trailers (including freight vehicles, pick-up truck type, van type, or van, among others), used as Instruments of International Traffic, must include a procedure for agricultural inspections to look for visible pests and serious structural deficiencies. Pest contamination is defined as visible forms of animals, insects, or other invertebrates (alive or dead, at any stage of the life cycle, including eggs, etc.), or any organic material of animal origin (including blood, bones, hair, meat, secretions, excretions, etc.); plants or plant products (including fruits, seeds, leaves, twigs, roots, bark, etc.); or other organic material, including fungi, soil, or water; when such products are not the declared cargo within the Instruments of International Traffic.
In case of using high-security seals, it is necessary to have procedures to correctly seal and maintain the integrity of containers and trailers from the moment they leave your facilities. A high-security seal must be applied to all containers and trailers for foreign trade shipments, which must comply with or exceed Standard ISO 17712 for high-security seals.
With the objective of maintaining supply chain security, the courier and package company must inspect all freight vehicles systematically upon entry and exit of its facilities (domestic and international traffic), in addition to keeping a record.
7.1 Use of seals and/or locks.
The courier and package company, where applicable, must identify the transport means of its own or subcontracted freight that transport foreign trade merchandise that may be: maritime, air, national land, cross-border, rail, and/or multimodal, which are subject to the placement of seals and/or locks that comply with or exceed Standard ISO 17712 in order to guarantee at all times the integrity of the cargo.
For this reason, as one of the security mechanisms, the fiscalized premises, where applicable, must use high-security locks or seals that comply with or exceed Standard ISO 17712 in all containers and trailers loaded for foreign trade and maintain their integrity until delivery at the final destination. For this, the premises must have documented procedures to place and verify the correct application of seals, their inspection at intermediate points, final destination, and their replacement when opened by any authority. In case of such an inspection, drivers must notify and record any anomaly or unusual structural modification found in the transport medium resulting from said review. The procedures must include the steps to follow if it is discovered that a seal is altered, manipulated, or there is an incorrect seal number in the documentation, the communication protocols to the commercial partners involved in the supply chain, and the investigation of the security incident; these must be notified to security personnel, commercial partners who may be part of the affected supply chain, security specialist, or Authorized Economic Operator Program contact.
Likewise, it is necessary to have a documented procedure for their administration which includes control, assignment, safeguarding, handling of discrepancies, and destruction of seals and locks (the latter is mandatory whenever seals are broken in your facilities). Regarding the provider of the seals and/or locks, it must be demonstrated how these comply with Standard ISO 17712. The company's management or a security supervisor must carry out periodic and documented audits of the high-security seals and/or locks; these reviews must include the verification of the inventory of stored seals and/or locks and the cross-check with inventory records and shipping documents. Likewise, the supervisors of the shipping area and/or warehouse managers must periodically verify the seal numbers used in the transport means and Instruments of International Traffic to corroborate that the information is correct.
For this case, the courier and package company must have a documented procedure in which, in accordance with its risk analysis, it supervises the placement of seals and/or locks on the transport means that transport foreign trade merchandise in accordance with its logistics process and in those traffics that require it due to their high probability of occurrence and impact of the identified risk. In it, it must evidence controls that allow accrediting that it supervises the portability of seals and/or locks resulting from entries or exits of the strategic fiscalized premises in the transport means. In all cases, it must use the VVTT inspection method to mitigate improper manipulations as follows:
I. V - View the seal and lock mechanisms of the container. II. V - Verify the seal number. III. T - Pull the seal to ensure it is correctly placed. IV. T - Twist and turn the seal to ensure.
Response: Explanatory Notes: List, according to your risk analysis and logistics process, the transport means that are subject to the placement of high-security seals and/or locks. Attach the documented procedure for the placement and review of seals and/or locks on the transport means that transport foreign trade merchandise. This must include, among other aspects according to your operation: I. Verify that the seal or lock is intact and determine if there is evidence of improper manipulation.
II. In case of using high-security locks, bottle type, use the VVTT inspection method. a) V - View the seal and lock mechanisms of the container (View). b) V - Verify the seal number (Verify). c) T - Pull the seal to ensure it is correctly placed (Tug). d) T - Twist and turn the seal to ensure it has closed (Twist and Turn).
III. Review and cross-check the documentation containing the number of the original seal or lock and, where applicable, of the additional ones for purposes of entries or exits of the courier and package company.
IV. Review that the closing devices, hinges, and pins are attached to the trailer or container and welded or riveted. Also, they can place protective plates on the door hinges and/or place a seal/adhesive tape on at least each side. Also, the correct functioning of handles, latches, and all other locking or closing mechanisms of the freight vehicles must be verified to detect manipulations and any inconsistency before placing any sealing device.
V. Indicate how you assign and replace high-security locks, in the case of maneuvers such as prior inspection, replacement, among others.
Where applicable, attach the documented procedure for the control and handling of seals and/or locks; this must include, among other aspects according to your operation: I. What type of seals and/or locks you use in your operations (foreign trade, transit, storage, etc.).
II. Who has access and how the locks and/or seals are safeguarded. The management of seals and/or locks must be restricted only to authorized personnel; stored in a secure place, have an inventory, control of their distribution and tracking (record of seals used, as well as of the receipt of new seals and/or locks).
III. Describe how the company's management or the security supervisor participate in the audits of high-security seals and/or locks, the reviews they carry out, the records they generate, and the actions they take in case of identifying discrepancies. Also, how the supervisors of the shipping area and/or warehouse managers verify the seal numbers used in the transport means and Instruments of International Traffic to corroborate that the information is correct (this process can also be included within the internal audits referred to in sub-standard 1.3 of this document).
IV. How discrepancies in seal and/or lock numbers are addressed.
V. Indicate who the supplier(s) is/are and how it proves that the specifications of the seals and/or locks comply with Standard ISO 17712 (attach certificate issued by the certifying company responsible for verifying compliance with the corresponding ISO).
All written procedures must be disseminated and maintained at the operational level so that they are easily accessible to employees responsible for carrying out the tasks described above, reviewed at least once a year, and updated as necessary.
7.2 Inspection of transport means, containers, trailers, and semi-trailers. There must be established procedures to verify the physical integrity of the structure of the transport means, containers, train cars, trailers, and/or semi-trailers used as Instruments of International Traffic, which enter or leave the courier and package company, according to their nature, including the reliability of the door locking mechanisms, with the aim of identifying natural or hidden compartments.
The inspections of the transport means must be systematic and carried out upon entry and exit from the company, and where applicable, at the point of loading of the goods, using the VVTT inspection method. A record of these inspections must be kept in an area with controlled access and carried out in a place monitored by closed-circuit television and video surveillance systems, said system must cover the entire inspection process.
The documented procedure for its inspection must include, by way of example and not limitation, the following review points:
Transport Means Trailers, Train Cars, Semi-trailers, and Containers I. Bumper. II. Tires and rims (tractor and trailer). III. Floor (tractor). IV. Fuel tanks. V. Interior of the cabin (bedroom and tool compartment). VI. Air tanks. VII. Chassis. VIII. Fifth wheel area. IX. Drive shafts. X. Exhaust pipe. XI. Engine. I. Exterior and interior doors. II. Side walls (left and right). III. Internal and external roofs. IV. Front wall. V. Internal Floor. VI. Where applicable, the refrigeration system.
For transport means with a trailer or integrated cargo compartment, the points indicated in the trailers section must be added to the transport means points.
Likewise, before loading the transport means, containers, train cars, trailers, and semi-trailers used as Instruments of International Traffic, they must undergo agricultural and security inspections to guarantee that their structures have not been modified to hide contraband or have been contaminated with visible agricultural pests, keeping a record and being backed by a documented procedure. If visible contamination by pests is found during the inspection or transport of goods subject to foreign trade, it must be cleaned (washed, vacuumed, etc.) to eliminate said contamination.
Response: Explanatory Notes: Attach the documented procedure to carry out the security and agricultural inspection of the transport means according to their nature and logistical process to be handled at the entries and exits of the courier and package company. This must include, among other aspects according to its operation: I. Those responsible for carrying out the inspection. II. Definition of the place(s) where the inspection takes place and indicate how the monitoring is carried out by alarm systems and closed-circuit television and video surveillance. III. The security review points for transport means, trailers, semi-trailers, containers, rail transport, and/or multimodal transport, both security and quality and agricultural inspections with the purpose of searching for visible pests. IV. Instructions for the driver to ensure that before crossing, the cabin is clean and free of trash.
Attach the established format for the inspection of transport means or cargo vehicles, containers, trailers, and/or semi-trailers. If you use other types of cargo vehicles for the transport of your goods (vans, pickups, 3.5 tons, tankers, etc.), your procedure and inspection format must include the process and review points.
Likewise, the security and agricultural inspection format must include the following information: I. Date of inspection; II. Time of inspection; III. License plates of the vehicle (tractor and trailer); IV. Container/trailer number; V. Specific areas of the cargo vehicles that were inspected; and, VI. Name and signature of the employee who performs the inspection and the supervisor.
The security and agricultural inspection formats may be signed by the supervisor to corroborate their information and be part of the import and export documentation. The documentation must be kept for one year for an investigation in case of any security incident, as well as to demonstrate continuous compliance with these inspection requirements.
Additionally, and according to the risk analysis, the courier and package company should carry out periodic random reviews of cargo vehicles, after the transport personnel has carried out security inspections to verify that they have been carried out correctly, counteract internal conspiracies, and prevent security incidents. The reviews must be carried out randomly, without prior notice, so that they do not become predictable, in addition to being carried out in different places where the transport means may be susceptible to contamination.
7.3 Storage of vehicles, transport means, containers, train cars, trailers, and semi-trailers. When the transport means, containers, trailers, and/or semi-trailers that will be destined to transport foreign trade goods are empty and must be stored in the parking areas, they must be secured with a lock and/or indicative seal or, where applicable, in a safe area that is guarded and/or monitored.
When it is necessary to store or overnight any loaded container, trailer, and/or semi-trailer, it must be in a safe area that has physical barriers and is monitored by alarm systems and closed-circuit television and video surveillance systems to prevent unauthorized access and manipulation of the merchandise, so it must be closed with a high-security lock according to ISO 17712 Standard. When the cargo is stored overnight or for a prolonged period, measures must be taken to secure the cargo against unauthorized access.
Response: Explanatory Notes: Indicate if the company stores containers, trailers, and/or semi-trailers for subsequent dispatch or, where applicable, those that are empty and how it maintains their integrity within its facilities. I. In case of using locks and/or seals, indicate what type you use. II. In case of using any container, trailers, and/or semi-trailers as a warehouse for raw materials and/or any other type of merchandise, indicate how it maintains their integrity and security.
8.1 Employment background checks. The courier and package company must have documented procedures to investigate and verify the information recorded in the resume, criminal records (if local legislation and company policies allow it), and applications of candidates with potential for employment, in accordance with local legislation, either on their own or through an external company. Likewise, for positions that by their sensitivity so require and affect the security of shipments, in accordance with their previously carried out risk analysis, they must consider requesting stricter requirements for their hiring, which must be carried out periodically. Regarding personnel who already work in the company, periodic investigations must be carried out based on the functions and/or sensitivity of the employee's position. All information regarding personnel must be kept in personal files, which must have restricted access.
Response: Explanatory Notes: Describe the documented procedure for the hiring of personnel and ensure you include the following: I. Requirements and documentation required. II. Tests and exams requested.
Indicate the areas and/or critical positions that have been identified as risky, according to your analysis and indicate the following: I. Indicate if there are additional requirements for specific areas and/or jobs, such as criminal records, (if local legislation and company policies allow it), socioeconomic studies, clinical studies, toxicological (drug use), etc. Where applicable, indicate the positions or work areas where they are required and with what frequency they are carried out. II. Indicate if, prior to hiring, the candidate must sign a confidentiality agreement or a similar document.
In case of hiring a service agency for personnel hiring, indicate if this has documented procedures for personnel hiring and how it ensures compliance with the same. Briefly explain what they consist of. The procedures for the hiring of personnel and contractors may include: I. Thorough investigations of the work and personal backgrounds of new employees. II. Confidentiality and liability clauses in employee contracts. III. Specific requirements for critical positions. IV. Where applicable, the periodic update of the socioeconomic and physical/medical study of employees who work in critical and/or sensitive areas. V. Hiring process and requirements requested for temporary employees and contractors. The company may consider the results of the background checks of candidates, as allowed by current legislation, to make hiring decisions. Background checks are not limited to identity and criminal record verification. In higher risk areas, deeper investigations may be justified.
8.2 Personnel dismissal procedure. There must be documented procedures for the dismissal of personnel, which include the delivery of identification and any other item that has been provided to perform their functions (keys, uniforms, badges and/or credentials, computer equipment, passwords, tools, etc.). Likewise, this procedure must include the deactivation in those computer systems and accesses, among others that may exist.
Response: Explanatory Notes: Describe the procedure for personnel dismissal and ensure you include the following: I. Who is responsible for carrying out and following up on this procedure. II. How the delivery of identification, uniforms, keys, and other equipment is carried out and confirmed. III. Indicate the control, record, and/or format, in which the delivery of material and deactivation in computer systems (where applicable, attach) is identified and ensured. IV. Indicate the type of records of personnel who ended their labor relationship with the company, so that when it has been for security reasons, their service providers and/or business associates are warned.
8.3 Personnel administration. The courier and package company must maintain an updated system, control, or database of active employees. Likewise, it must carry out and maintain updated records of affiliation to social security institutions and other legal labor records. In the case that the company has personnel hired by its commercial partners and works within the facilities, it must ensure that they meet the requirements established for the rest of its employees.
Response: Explanatory Notes: Indicate if the courier and package company has an updated system, control, or database, both of personnel hired directly, as well as that hired through a service provider company and ensure it includes, by way of example and not limitation, the following points:
I. Full name. II. Updated photograph at least every five years. III. Personal data (age, name, date of birth, phone number, address, CURP, social security number, blood type, allergies, etc.). IV. Affiliation. V. Work history. VI. Diseases. VII. Medical exams. VIII. Training. IX. Psychometric tests. X. Toxicological tests. XI. Results of periodic evaluations. XII. Observations. This personnel must be hired in accordance with the current labor laws and regulations.
9.1 Classification and handling of documents. There must be procedures to classify documents according to their sensitivity and/or importance. Sensitive and important documentation must be stored in a secure area that only allows access to authorized personnel. The useful life of the documentation must be identified and procedures for its destruction must be established. The company must conduct regular reviews to verify access to information and ensure that it is not used improperly.
Response: Explanatory Notes: Attach the documented procedure for the registration, control, and storage of printed and electronic documentation (classification and filing of documents), including: I. Control register for delivery, loan, among other documents. II. Restricted access to the archive area. III. Storage and classification policies. IV. An updated security plan that describes the measures in force regarding the protection of documents against unauthorized access, as well as against deliberate destruction or loss of the same. V. In the case of electronic or digital information, it must adhere to the security criteria of sub-standard 9.2. Information Technology Security.
9.2 Information Technology Security. To protect Information Technology systems against common cybersecurity threats, a company must have sufficient protection that promotes security in the Information Technology infrastructure (software and hardware) against malware (viruses, spyware, worms, trojans, etc.), baiting, phishing, and internal/external intrusions (firewalls) in the companies' computer systems. Likewise, companies must ensure that their security software is active and receives periodic updates.
In the case of automated systems and computer equipment, individual accounts that require periodic password changes must be used. In order to protect the confidentiality, integrity, and availability of information, the courier and package company must have policies, procedures, and IT technology standards established that must be communicated through a training program for all employees who handle computer equipment and systems, which includes topics to prevent attacks through social engineering and all those threats to which they are exposed (malware, baiting, phishing, etc.). Companies that allow their employees to connect remotely to a network must use secure technologies, such as virtual private networks (VPN), to allow employees to access the company intranet securely when they are outside the office, as well as procedures designed to prevent unauthorized remote user access.
For the above, there must be written procedures and infrastructure to protect the company against information loss, this includes the procedure for the recovery (or replacement) of Information Technology systems and/or data, as well as a system or software established to identify the abuse of information technology systems and detect inappropriate access and/or improper manipulation or alteration of commercial and business data, as well as a written procedure for the application of appropriate disciplinary measures to all offenders. Access to Information Technology systems must be protected against infiltration through the use of secure passwords, which include phrases or other forms of authentication.
Users of said Information Technology systems must safeguard and not share their access keys or passwords. All Information Technology infrastructure must be physically protected against unauthorized access. If a data leak or other unexpected event occurs that results in the loss of data and/or equipment, the procedures must include the recovery or replacement of Information Technology systems and/or data.
Response: Explanatory Notes: Attach the procedure for the recovery or replacement of Information Technology systems and/or data, which includes how it backs up and ensures the security of its backup and ensures the security of its information, in addition to protecting it from possible losses. Ensure you include the following points: I. Indicate the frequency with which backups are carried out. II. Who has access to them, and who authorizes the recovery of information. III. Indicate what type of tests it performs and how often, to verify the security of the network, systems, and infrastructure. IV. Mention if to carry out this type of tests or vulnerability scans, it does so through software, a third party or provider, and, where applicable, indicate the name or corporate name. V. In case of finding vulnerabilities, describe the corrective actions that must be implemented. VI. Indicate if it shares information about cybersecurity threats with its commercial partners participating within its supply chain (for example: communications, bulletins, emails, etc.). VII. The systems must be protected under passwords and frequently modified, therefore indicate the procedure to change them. VIII. Indicate if there are information security policies for their protection. IX. There must be a system or software to detect, identify the abuse, intrusion, or access of unauthorized persons to its systems and/or information technology data, as well as the abuse of the policies and procedures established by the company, including improper access to internal systems, external websites, and the manipulation or alteration of commercial data by employees or contractors. X. All offenders must be subject to the application of disciplinary measures, therefore, indicate the corrective policies and/or sanctions in case of the detection of any violation to the Information Technology security systems and policies.
Describe the security measures you use to allow your employees to connect remotely to a network (VPN), to allow employees to access the company intranet remotely when they are outside the office. In case of allowing employees to use personal devices to perform the company's work, such devices must comply with the company's cybersecurity policies and procedures, security updates must be periodic and have a method to access the company network securely.
Indicate if commercial partners have access to the company's computer systems. Where applicable, indicate what programs and how they ensure access control to them. Indicate if the computer equipment has a backup power supply system that allows business continuity. The procedures regarding the backup of the courier and package company's information must also include: I. How and for how long the data is stored (data should be backed up once a week or as appropriate).
II. Business continuity plan in case of incident and how to recover information. III. Frequency and location of backup copies and archived information. IV. Whether backup copies are stored in sites alternative to the facilities where the data processing center is located. V. Tests of the validity of data recovery from backup copies. The procedures regarding the protection of the information of the courier and package company must also include: I. An updated and documented policy for the protection of computer systems against unauthorized access and deliberate destruction or loss of information. All sensitive and confidential data must be stored in an encrypted or encoded format. II. Detail if it operates with multiple systems (sites/locations) and how these systems are controlled. III. Who is responsible for the protection of the computer system (responsibility should not be limited to one person but to several so that each can control the actions of the others). IV. Access for each user must be assigned through individual accounts and restricted according to the job description or assigned tasks. For this reason, describe how access authorizations and access levels to computer systems are granted (access to sensitive information must be limited to personnel authorized to modify and use the information). Authorized access must be monitored by the area responsible for granting it, to verify or, if necessary, report that access to confidential systems is based on job requirements.
V. Indicate the elements or format that passwords must have for access to Information Technology systems and computing equipment, frequency of changes, if there are other authentication methods, and who or what area provides these passwords. VI. Indicate the name of the firewall and antivirus used (including licensing-related information), demonstrating that this security software is active and receives periodic updates. For this reason, cybersecurity policies and procedures should include measures to prevent the use of counterfeit products or those with incorrect licenses (software and hardware). All computing equipment, electronic media (hard drives, cell phones, etc.) and Information Technology hardware containing confidential information related to the import and export process must be accounted for through periodic inventories and have such evidence. When these technological equipment must be discarded, there must be a documented procedure that includes how they must be formatted, disinfected, or destroyed appropriately to avoid information leakage. VII. In case of staff turnover, access to computing equipment, telecommunications, and the network must be eliminated at the moment of the employee's separation; this includes email accounts, system access accounts, software, programs, etc. VIII. Measures planned to handle incidents when the system is compromised.
Explain briefly what it consists of, and ensure to include the following: I. Brief description of the topics taught in the program. II. When they are taught (onboarding, specific periods, resulting from audits, security incidents, etc.). III. Frequency of training, as well as updates and reinforcement. IV. Indicate how participation in supply chain security training is documented (videos, photographs, minutes, attendance lists, intranet or other system, didactic material, PowerPoint presentations, brochures, etc.). Records must include the date of the training, the names of attendees, the topics taught, in addition to having measures to verify that the training provided met all its objectives. V. Explain how employee participation in security matters is encouraged. Training to perform inspections of cargo vehicles, containers, trailers, and/or semi-trailers for agricultural and security purposes must include the following topics: I. Signs of hidden compartments. II. Smuggling hidden in natural compartments. III. Signs of pest contamination. IV. Procedures to follow if something is found during an inspection of the transport means or if a security incident occurs during transit.
V. Training on agricultural reviews must cover pest prevention measures, regulatory requirements applicable to wooden packaging materials in accordance with International Standard for Phytosanitary Measures No. 15, titled "Regulation of wooden packaging used in International Trade," which emanate from the Food and Agriculture Organization of the United Nations, and the identification of infested wood. 10.2 Awareness for transport medium operators. The courier and package company must inform the operators of the transport means it uses for the transfer of goods originating from or destined for foreign trade, regarding security policies concerning agricultural and security inspection procedures of cargo transport means, incident handling, changing locks in case of inspection by other authorities, among others, that are implemented. Operators and personnel who perform agricultural and security inspections of transport means must be trained to inspect cargo vehicles for these purposes. In the case where the transport service is provided by a business partner, it must ensure that operators know all established security policies and procedures. Response: Explanatory Notes: Describe the dissemination program on supply chain security focused on transport medium operators and ensure to include the following: I. Indicate how this dissemination is carried out. II. Point out the topics covered. III. In case of using the services of a business partner for the transfer of its goods, indicate how operators are informed about the company's security policies and procedures. IV. Indicate how participation in supply chain security training of transport medium operators is documented (videos, attendance lists, brochures, etc.).
The topics that must be included, in an illustrative but not exhaustive manner, are: I. Access and security policies at facilities. II. Delivery-receipt of goods (including suspicious cargo shipments). III. Confidentiality of cargo information. IV. Transfer instructions. V. Accident and emergency reports. VI. Instructions for the placement of high-security locks and/or seals in case of inspection by other authorities, as well as the control and use of high-security seals and locks in transit (placement of a new one, inspection after an authorized stop, etc.). VII. Installation and testing of security alarms and unit tracking, when applicable. VIII. Identification of authorized formats and documents to be used. IX. Signs of hidden compartments. X. Smuggling hidden in natural compartments. XI. Signs of pest contamination. XII. Procedures to follow if something is found during an inspection of the transport means or if a security incident occurs during transit. 11. Handling and investigation of incidents. There must be documented procedures to report and investigate security incidents in the supply chain, actions to be taken to prevent their recurrence, as well as notifying security personnel, business partners who may be part of the affected supply chain, security specialist or Authorized Economic Operator Program contact, and other competent authorities. Reporting and investigation procedures must include updated contact information or directory listing the names and phone numbers of personnel requiring notification. The investigation and analysis of incidents must be documented (physical and/or electronic file) as well as corrective actions to prevent recurrence, which must be implemented as soon as possible.
In the case where the courier and package company identifies that any of its foreign trade shipments is involved in a situation that puts the supply chain security at risk, due to suspicion of a business partner or person, it must inform security personnel, business partners who may be part of the affected supply chain, security specialist or Authorized Economic Operator Program contact, as well as the competent authority, and, if possible, before the border crossing, exit, or dispatch (import and export). Procedures must include the steps to follow if it is discovered that a seal is altered, manipulated, or there is an incorrect seal number in the documentation, communication protocols with business partners involved in the supply chain, and the investigation of the incident. All the aforementioned procedures must be reviewed periodically or at least once a year to ensure that contact information and action protocols are correct. 11.1 Report of anomalies and/or suspicious activities. In case of detection of anomalies and/or suspicious activities related to supply chain security and in accordance with its logistical processes (related to access control, delivery, receipt, and storage of goods, security inspections of cargo vehicles and transport operators, etc.), these must be reported to security personnel, business partners who may be part of the affected supply chain, security specialist or Authorized Economic Operator Program contact, and other competent authorities, keeping a record of such anomalies and/or unusual activities. Response: Explanatory Notes: Describe the procedure to denounce or report anomalies and/or suspicious activities, as well as mechanisms to anonymously report problems related to security, ensure to include the following: I. Who is responsible for reporting incidents. II. Detail how it determines and identifies with which authority to communicate in different scenarios or presumption of suspicious activities. III. Mention if it keeps a record of reporting these activities and/or suspicions and briefly describe what it consists of. 11.2 Investigation and analysis. There must be written procedures to denounce or report anomalies and/or suspicious activities, as well as for the analysis and investigation of security incidents in the supply chain to determine their cause, as well as corrective actions to prevent recurrence, which must be implemented as soon as possible. The information derived from this investigation must be documented and available at all times for authorities that require it. This information must include the documentation generated to carry out the foreign trade operation of the affected goods, which will allow identifying each of the processes the goods went through, up to the point where the incidence was detected, and allowing recognition of the vulnerability of the chain.
Response: Explanatory Notes: Describe the documented procedure to initiate an investigation in case any incident occurs, and ensure to include the following: I. Responsible for carrying out the investigation. II. Documentation that integrates the file of the security incident investigation. The documents to be included in the file derived from the investigation, in an illustrative but not exhaustive manner, may be: I. General information of the shipment, service order. II. Transport request; confirmation of transport means; identification of the transport operator (access records, exit records, records of security inspections, etc.). III. Transport means inspection formats; exit orders; records of collection, delivery, and receipt of foreign trade goods. IV. Videotapes from closed-circuit television and video surveillance systems. V. Documentation generated for the carrier (bill of lading, waybill, instruction sheet). VI. Documentation generated for business partners (service order, description of goods, proformas, CFDI or equivalent documents, etc.). VII. Documentation generated by business partners and customs authorities. VIII. Unit tracking and monitoring report (GPS tracking).
E7. Profile of the Tax-Inspected Premises Acknowledgment of Receipt First Time: Renewal: Addition: Modification: The data provided will replace the data provided when requesting authorization. General Information The objective of this Profile is to ensure that tax-inspected premises have security practices and processes implemented at their facilities, focused on strengthening the supply chain and mitigating the risk of contamination of shipments with illicit products. Tax-inspected premises interested in obtaining the authorization referred to in Rule 7.1.5., must demonstrate that they have documented and verifiable processes; likewise, they must integrate the criteria required in this document according to the business model or design they have established, seeking during the implementation of security standards, the application of a risk analysis culture supported by decision-making consistent with the values, mission, vision, codes of ethics, and conduct of the company itself. What is established in this Profile must be accredited independently of the requirements and provisions established for the control, surveillance, access routes, infrastructure, equipment, and security of foreign trade goods established by ANAM, to grant the Tax-Inspected Premises authorization, and compliance can be proven with that which coincides with what is established in this Profile. Filling Instructions: I. A Profile of the Tax-Inspected Premises must be filled out for each of the facilities that have a concession or authorization as a tax-inspected premises. The number of Profiles presented must coincide with the facilities that have a concession or authorization to provide handling, storage, and custody services for foreign trade goods in accordance with articles 14 and 14-A of the Law, manifested in their application for registration as a certified business partner under the tax-inspected premises modality, as well as indicating all domiciles registered with the RFC. II. In each sub-standard, the tax-inspected premises must detail how it complies with or exceeds what is established in each of the numerals as indicated. III. The format of this document is divided into two sections, as detailed below:
Facility Information Profile Number of the Supervised Premises:
From:
RFC Key
Name and/or Corporate Name:
Name and/or Denomination of the Facility
Type of Facility
Street Number and/or exterior letter Number and/or interior letter
Neighborhood Postal Code Municipality/Delegation Federal Entity
Age of the facility (years of operation):
Activity carried out in the facility:
Preponderant products that they handle in the supervised premises: (As applicable)
Average number of monthly shipments (EXP):
Average number of monthly shipments (IMP):
Total number of employees at this facility:
Facility Surface Area (M2):
Certifications in security programs: (indicate if this facility has a certification from any of the following programs)
CTPAT. Yes No Level: Pre-Applicant: Applicant: Certified: Certified/ Validated:
CTPAT. Account number (8 digits): Date of last visit to this facility:
Authorized Economic Operator from other countries (AEO)
Yes No Program: Registration:
Other Supply Chain Security Programs
Yes No Program: Registration:
Certifications: (indicate if you have certifications that you consider impact your supply chain process, for example: ISO 9000; Reliable Logistics Processes, among others)
Name: Category: Validity:
Name: Category: Validity:
Name: Category: Validity:
Name: Category: Validity:
1.1 Risk Analysis. The supervised premises must establish measures to identify, analyze, and mitigate security risks that could result in alterations of foreign trade merchandise during its handling, guarding, and custody in its supply chain and facilities. It must develop a written process to determine risks based on its organization's model (e.g., type of merchandise, volume, clients, routes, information leakage, potential threats, etc.), so that it allows implementing and maintaining appropriate security measures. In accordance with the above, the company must also have a written process based on its risk analysis to select new business partners and monitor those with whom it is already working. This procedure must be updated at least once a year, so that it allows permanently identifying new threats or risks that are considered in the operation and in the supply chain, as a result of some incident or that originate from changes in initial conditions, as well as to identify that the policies, procedures, control mechanisms, and security are being complied with. It is important to note that the Security Committee of the supervised premises must participate in the preparation and updating of the risk analysis and the maintenance of the Authorized Economic Operator Program.
Response: Explanatory Notes: Indicate which are the sources of information used to qualify risks during the analysis phase. Attach the risk matrix, as well as the documented procedure to identify risks in the supply chain and the facilities of the premises, which must contemplate the risk assessment and management process of the premises, including the following points: I. Indicate the periodicity with which it reviews and, if applicable, updates the procedure and its risk matrix. II. Indicate which aspects and/or areas of the premises are incorporated into the risk analysis. III. Describe the methodology used to determine a risk analysis. IV. Mention who are the responsible parties for updating the risk analysis of the premises. Likewise, the documented procedure to identify risks in the supply chain and its facilities, should contemplate the risk assessment and management process, and include the following aspects: I. Establishment of a context (cultural, political, legal, economic, geographic, social, etc.). II. Indicate the risks identified in the installation and in its supply chain or logistics. III. Risk analysis of causes, consequences, probabilities, and existing controls to determine the level of risk as high, medium and low. IV. Risk evaluation (decision making to determine the risks to be treated and priority for implementing the treatment). V. Risk treatment (application of alternatives to change the probability of risks occurring).
Risk follow-up and review (monitoring of the results of the risk analysis and verification of the effectiveness of its treatment). I. Indicate the review and/or update period of the results of the risk analysis. It is suggested to use the Administration, management and risk evaluation techniques according to the international standards ISO 31000, ISO 31010, and ISO 28000 that, according to its business model, it should implement.
1.2 Security Policies. The supervised premises must have a policy oriented towards preventing, securing, and recognizing threats in the security of the supply chain and facility installations, such as drug trafficking, money laundering, arms trafficking, human smuggling, prohibited merchandise, and acts of terrorism. Such policies must be reflected in the corresponding procedures and/or manuals. To promote a security culture, supervised premises must demonstrate their commitment to supply chain security and the Authorized Economic Operator Program through a statement highlighting the importance of protecting the flow of national and international commerce from criminal activities, established through the security policy. The senior officials or executives of the supervised premises who must endorse and sign the security policy may include the president of the premises, the executive director, the general manager, the security director, or personnel with an equivalent position with authority to make decisions.
Response: Explanatory Notes: Enunciate the security policy oriented towards preventing, securing, and recognizing threats in the supply chain and facilities of the supervised premises, indicate who is responsible for its review, signature, and dissemination to employees, as well as the periodicity with which its update is carried out. Such policy must be communicated to employees through a program and/or dissemination campaign. The security policy must be signed by a senior official of the company and be displayed in various areas of the supervised premises, including the premises' website, posters in key areas of the company (reception, shipments, receipts, warehouse, etc.), and as part of the company's initial and reinforcement training.
1.3 Internal Audits in the Supply Chain. In addition to routine monitoring in control and security, it is necessary to schedule and carry out audits at least once a year, under the guidelines of a documented procedure that allows evaluating all processes regarding supply chain security and its facilities in a more critical and deep manner, as well as guaranteeing that its employees follow the security procedures of the premises. Audits must be carried out by the Security Committee of the premises. A documented procedure must be established, as well as a program or calendar for their execution. Although it is necessary that audits are focused on supply chain security and based on the evaluation, review, and execution of minimum security standards, their focus must be adjusted to the size of the organization, risk, business model, and variations between facilities. Audits can be general or focus on specific areas or processes according to their work program. The objective of an internal audit focused on the Authorized Economic Operator Program is to verify and guarantee that employees follow the company's security procedures. The review process does not have to be complex; however, the formats and records used for the application of these reviews must evidence that the application and execution of the evaluated processes were validated, in addition to the corresponding follow-up of identified observations. Senior management must review the results of the audits, analyze the causes, and undertake required corrective or preventive actions. The audit process must guarantee that the necessary information is collected to allow management to perform this evaluation. The review must be documented, in addition to the fact that the Security Committee of the supervised premises must provide and register periodic updates on the progress or results of any audit, exercise, or validation.
Response: Explanatory Notes: Describe the documented procedure to carry out an internal audit, focused on supply chain security. Ensure you include the following points: I. Indicate how the premises carry out the scheduling or calendarization to perform an internal audit, regarding supply chain security. II. Indicate who participates in them, and the records that are generated, as well as the periodicity with which they are carried out. III. Indicate how the management of the supervised premises verifies the results of the audits regarding security and how it carries out and/or implements preventive, corrective, and improvement actions, in addition to the follow-up and closure of the same. IV. The formats used during internal audits must be properly filled out, and through them, evidence that the procedures and security measures are being put into practice.
1.4 Contingency and/or Emergency Plans related to Supply Chain Security. There must be a documented contingency and/or emergency plan. This plan must address crisis management, security recovery plans, and business resumption, to ensure business continuity when a situation affects the normal development of activities and foreign trade operations in the facilities and during the transfer, handling, storage, and custody of foreign trade merchandise according to its logistics process in the supply chain. A crisis or contingency may include the interruption of commercial data movement due to a cyberattack, a fire, the kidnapping of a transport driver by armed individuals, a bomb threat, the detection of suspicious packages, power outages, theft and/or damage to merchandise, threats or extortion, among others). Such plans must be communicated to personnel through periodic training, as well as carrying out tests, practical exercises, or annual simulations of the contingency and emergency plans to verify their effectiveness. Records must be maintained, properly filled out and signed (for example: result reports, minutes, or reports, which must be backed by video recordings, photographs, etc.), demonstrating their execution. The contingency and/or emergency plan must be updated as necessary, based on changes in operations and the organization's risk level.
Response: Explanatory Notes: Attach the documented procedure or contingency and/or emergency plan, to ensure business continuity in case of an emergency or security situation, that affects the normal development of foreign trade activities of the supervised premises. This procedure must include, in an enumerative but not limiting manner, the following: I. What situations it contemplates. Describing the action plan and steps to be followed in case of crisis, as well as the tasks that personnel have assigned during the handling of such contingencies. II. What mechanisms it uses to guarantee that the business continuity plan is effective. III. Contemplate the scheduling and carrying out of tests, practical exercises, and annual simulations and how they are documented (for example: result reports, minutes, or reports, which must be accompanied by video recordings, photographs, etc., that demonstrate their execution).
2.1 Installations. Installations must be constructed with materials that can resist unauthorized access. Periodic documented inspections must be carried out to maintain the integrity of the structures, and in case an irregularity is detected, the corresponding repair must be carried out as soon as possible by the personnel designated for these tasks. Likewise, territorial limits, as well as various accesses, internal routes, and the location of buildings must be fully identified.
Response: Explanatory Notes: Indicate the predominant materials with which the installation is constructed (for example, metal structure and sheet metal walls, brick walls, wood, among others), and indicate how the review and maintenance of the integrity of the structures is carried out. Indicate the personnel or area responsible for carrying out the tasks of inspection, maintenance, and repair of damages to the installations. Attach a general distribution or architectural plan, where the limits of the installations, access routes, emergency exits, traffic flow, the location of buildings, critical areas, parking lots, and boundaries can be identified.
2.2 Accesses at doors and booths. The entrance or exit doors of personnel and/or vehicles of the company's installations must be attended, controlled, supervised, and monitored. The number of access doors must be kept to the minimum necessary. Access to sensitive areas must be restricted according to the job description or assigned tasks.
Response: Explanatory Notes: Indicate how many doors and/or accesses exist in the installations, as well as the operating hours of each one, and indicate how they are monitored (in case of having assigned security personnel, indicate the quantity). Detail if there are blocked and/or permanently closed doors and/or accesses and their location. Describe how you ensure that access to sensitive areas is restricted according to the job description or assigned tasks (include the type of records and controls you use).
2.3 Perimeter Fences. Perimeter fences and/or peripheral barriers must be installed to secure the perimeters of the supervised premises' facilities, and particularly, the areas for storage, custody, and warehousing of foreign trade merchandise, high value, hazardous, according to applicable regulations, areas with restricted access, and others determined according to its risk analysis, with the objective of preventing unauthorized entries. These must be inspected regularly and carry a record of the review with the purpose of ensuring their integrity and preventing or identifying damages, which must be repaired as soon as possible by the personnel designated for these tasks. The storage, high value, hazardous, and/or restricted access areas must be clearly identified and monitored to prevent unauthorized entries.
Response: Explanatory Notes: Describe the type of peripheral barrier and/or fences with which the installation has. Ensure you include the following points: I. Specify which areas it segregates in the installation as being considered critical and/or sensitive. II. Indicate the characteristics of the same (material, dimensions, etc.). III. In case of not having fences, justify detailedly the reason. IV. Periodicity with which the integrity of the perimeter fences is verified, and the records that are carried out, with the purpose of ensuring their integrity and identifying damages, which must be repaired as soon as possible. V. Indicate the personnel or area responsible for carrying out the tasks of inspection and repair of damages.
Describe how the cargo destined for foreign countries, hazardous material, and high value cargo is segregated. Ensure you include the following points: I. Indicate how it separates national merchandise and foreign trade merchandise, and if it is additionally identified (for example: different packaging; labels; packaging, among others). II. Identify and indicate the restricted access areas (hazardous merchandise, high value, confidential, etc.). The procedure for the inspection of perimeter fences could include: I. Personnel responsible for carrying out the process. II. How and how often the inspections of the fences, perimeter fences and/or peripheral barriers and the buildings are carried out. III. How the inspection record is kept. IV. Who is responsible for verifying that repairs and/or modifications comply with the technical specifications and security requirements necessary.
2.4 Parking Lots. Access to the parking lots of the installations must be controlled and monitored by security personnel or designated for this task. Private vehicles (of employees, visitors, suppliers, and contractors, among others) must be prohibited from parking within the merchandise handling and storage areas, as well as in adjacent areas.
Response: Explanatory Notes: Describe the procedure for the control and monitoring of the parking lots. Ensure you include the following points: I. Those responsible for controlling and monitoring the access to the parking lots. II. Identification of the parking lots (specify if the visitor parking is separated from the storage and merchandise handling areas).
III. How the entry and exit control of vehicles to the installations is carried out. Indicate the records that are made for the control of the parking, the existing control mechanisms (for example: badges, card readers, lanyards, etc.), how they are assigned and the responsible area for doing so. IV. Policies or mechanisms to not allow the entry of private vehicles to the areas of storage and merchandise handling.
2.5 Key and Lock Device Control. Windows, doors, and inner and outer fences, according to your risk analysis, must be secured with locking devices. The company must have a documented procedure for the handling and control of keys and/or locking devices of the inner areas that have been considered critical. Likewise, a record must be kept and responsibility letters signed by persons who have keys or authorized accesses according to their level of responsibility and work within their work area.
Response: Explanatory Notes: Attach the documented procedure or procedures for the handling, safeguarding, assignment, control, and non-return of keys, in the installations, offices, interiors, and critical and/or sensitive areas. Ensure that these procedures include the following points: I. Those responsible for administering and controlling the security of the keys. II. Control record for the loan of keys. III. Indicate the treatment of loss or non-return of keys. IV. Indicate if there are areas in which access is with electronic devices and/or any other access mechanism.
2.6 Lighting. Lighting inside and outside the facilities must allow for clear identification of people, materials, and/or equipment located there, including the following areas: entrances and exits, handling, loading, unloading, and storage areas for merchandise, perimeter and/or peripheral walls, interior fences, and parking areas, which must have an emergency and/or backup system in sensitive areas. Response: Explanatory Notes: Describe the procedure for the operation and maintenance of the lighting system. Ensure you include the following points: I. Indicate which areas are illuminated and which have a backup system (indicate if you have an auxiliary power plant). II. How do you ensure that the lighting system is appropriate in each of the areas of the supervised facility, as well as that it has continuity in the event of a lack of supply in each of the areas of the installation and with special emphasis on the areas considered critical and/or sensitive, in such a way that it allows clear identification of the personnel, materials, and/or equipment it covers. III. Person responsible for the control and maintenance of the lighting systems. IV. Maintenance and review program (in case it coincides with another process, indicate it). The procedure may include: I. How the lighting system is controlled. II. Operating hours. III. Identification of areas with permanent lighting.
2.7 Communication devices. The supervised facility must have communication devices and/or systems for the purpose of contacting security personnel and/or emergency and security authorities as required. Additionally, it must have a backup system and verify its proper functioning periodically. Response: Explanatory Notes: Describe the procedure that personnel must follow to contact the company's security personnel or, in their case, the corresponding authority in the event of any security incident. Indicate whether operational and administrative personnel have or have access to devices (landline phones, mobile phones, alert and/or emergency buttons) to communicate with security personnel and/or whoever corresponds (these must be accessible to users, to be able to react promptly). Indicate what communication devices the company's security personnel use (landline phones, cell phones, radios, alarm system, etc.). Describe the procedure for the control and maintenance of communication devices, ensure you include the following points: I. Policies for the assignment of mobile communication devices. II. Maintenance or replacement program for fixed and mobile communication devices. III. Indicate if you have backup communication devices, in case the permanent system fails, and, if applicable, detail briefly. The procedure may include: I. Person responsible for the proper functioning and maintenance of communication devices. II. Verification and maintenance records of the devices. III. Method of assignment of communication devices.
2.8 Alarm systems and closed-circuit television and video surveillance systems. Alarm systems, closed-circuit television, and video surveillance systems, and security technologies, must be used to monitor, notify, or deter unauthorized access and prohibited activities in the facilities and other areas considered sensitive, notify the corresponding area, in addition to being used as a tool of evidence in investigations derived from any incident. These security systems and technologies must be placed according to a prior risk analysis and applicable regulations, in such a way that they allow clear identification of the areas that involve the handling, storage, custody, loading, and unloading of foreign trade merchandise, security inspections of cargo vehicles, as well as the access and exit of authorized personnel, visitors, suppliers, passenger vehicles, and other areas considered sensitive on a permanent and uninterrupted basis in accordance with their operation and the coordination established with the customs office, the DGIA, or the AGCTI, as applicable. The supervised facility must have documented operating procedures for the aforementioned systems. In the case of alarm and closed-circuit television and video surveillance systems, it must include supervision of the good condition of the equipment, verification of the correct position of the cameras, maintenance for the backup of recordings for at least sixty days in accordance with rule 2.3.8, continuity in operation in case of power supply failures, as well as those responsible for their operation. These systems must have restricted access. Response: Explanatory Notes: Mention the documented procedure in which it indicates the functioning of the external alarm system or sensors, and if applicable, describe the following points: I. Indicate if all doors and windows have alarm sensors or motion sensors. II. Procedure to follow in case an alarm is activated. III. Indicate the personnel or area responsible for maintenance, how failures are reported, and the records they use. Describe the documented procedure for the operation of alarm and closed-circuit television and video surveillance systems and security technologies (this must be reviewed and updated annually and according to the risk analysis or circumstances), ensure you include the following points: I. Indicate the number of security cameras of the alarm and closed-circuit television and video surveillance systems installed, and their location by area, (detail if it covers the entry and exit points of the facilities, to cover the movement of vehicles and individuals, as well as the place of storage of foreign trade merchandise) and where the inspection mentioned in sub-standard 7.2 is carried out). Attach a layout or map of the distribution of security cameras. II. Indicate the location of the closed-circuit television and video surveillance systems and security technologies, where the monitors are located, who reviews them, as well as the operating hours, and if applicable, if there are remote monitoring stations. All security technology infrastructure must be physically protected against unauthorized access. III. Periodic and random reviews of recordings must be carried out. Indicate how they review them (random, every week, special events, restricted areas, etc.), who is the designated personnel, and if management is involved in the reviews. The results of the reviews must be documented to include corrective actions for audit purposes. IV. Indicate for how long these recordings are kept, which must be at least 60 days. V. The alarm and closed-circuit television and video surveillance systems and security technologies must have an alternative energy source that allows them to continue functioning in the event of an unexpected loss of direct power. For the above, indicate if the alarm and closed-circuit television and video surveillance systems and security technologies are backed up by an electrical power plant, or any other mechanism to supply electrical energy, that guarantees their operation. These systems should have an alarm/notification function, which indicates a failure condition in operation and/or recording, indicate if your systems have such a function.
VI. Indicate if, in addition to the closed-circuit television and video surveillance system, you use any other type of technology to strengthen the security measures you already have. VII. Describe the procedure that has been implemented to regularly test and inspect the closed-circuit television and video surveillance system and security technologies and ensure their proper functioning. The results of the inspections and the operational tests must be documented, as well as the necessary corrective actions (these must be implemented as soon as possible). Additionally, that the documented results of these inspections are kept for a sufficient time for audit purposes. VIII. Indicate if the provider of the alarm and closed-circuit television and video surveillance systems has access to the security cameras, if they are in charge of monitoring them, how access is controlled, and who is responsible for said monitoring. 3. Physical access controls. Physical access controls are mechanisms or procedures that prevent and impede unauthorized entry to the facilities, maintain control of the entry of employees and visitors, and protect the company's assets. Access controls must include the identification of all employees, visitors, and suppliers at all entry points. Likewise, the mechanisms or documented procedures for entry into the facilities must be maintained and evaluated permanently, being the basis for beginning to integrate security as one of the primary functions within any company. The evaluation of what is stated in this sub-standard will be carried out in accordance with the applicable regulatory provisions for the supervised facility. 3.1 Security personnel. The supervised facility must have security and surveillance personnel. This personnel plays an important role in the physical protection of the facilities and of the merchandise during its transport and handling within the company, as well as for controlling the access of all people to the property. Security personnel must have a documented procedure to carry out their functions and have full knowledge of the mechanisms and procedures in emergency situations, detection of unauthorized persons, or any incident in the installation. Management must periodically verify compliance with procedures, policies, and functions through internal audits with the objective of verifying their correct execution.
Response: Explanatory Notes: Describe the documented procedure for the operation of security personnel and ensure you include the following points: I. Indicate the number of security personnel working in the company. II. Indicate the positions and/or functions of the personnel and operating hours. III. In case of hiring an external service, provide the general data of the company (RFC key, Trade Name, address), and specify the number of employees employed, operational details, records, reports, etc. IV. In case of having armed personnel, describe the procedure for the control and storage of weapons. 3.2 Employee identification. There must be an employee identification system for access to the facilities. Employees should only have access to those areas they need to perform their functions. Management or the security personnel of the supervised facility must properly control the delivery and return of badges, ID cards, and/or employee identification credentials. Procedures for the delivery, return, and change of access devices (for example, keys, proximity cards, etc.) must be documented. Access to sensitive areas must be restricted according to the job description or assigned tasks. Response: Explanatory Notes: Describe the procedure for employee identification and ensure you include the following points: I. Identification mechanisms (badge and/or photo ID, access control, biometrics, proximity cards, etc.). II. Indicate if employees use uniforms, how they are assigned (by position, area, functions, etc.) and withdrawn (if applicable).
III. Indicate how personnel hired by a business partner, who works within the facilities (contractors, subcontractors, in-house services, personnel from merchandise handling companies, etc.) are identified. IV. Describe how the company delivers, changes, and withdraws employee identification and access controls and ensure you include the areas responsible for authorizing and administering them. The procedure must also describe how the company delivers, changes, and withdraws employee identification and access controls and ensure you include the areas responsible for authorizing and administering them. Indicate how you ensure that access to sensitive areas is restricted according to the job description or assigned tasks (include the type of records and controls you use). 3.3 Visitor and supplier identification. To access the facilities, visitors and suppliers must present official identification with a photograph for documentation upon arrival and a record must be kept. All visitors and suppliers must receive a temporary identification, be accompanied by facility personnel during their stay in the facilities, and ensure that the visitor/supplier always wears the provisional identification provided in a visible place. This procedure must be documented. In the case of suppliers and users who work regularly in the facility, the company must have a physical validation system for identification badges as established by the customs office of its jurisdiction to grant entry and exit authorizations, if applicable. Response: Explanatory Notes: Describe the procedure for visitor and supplier access control, ensure you include the following points: I. Indicate what records are kept (personal formats for each visit, logbooks). II. The visitor and supplier record must include the following: a) Date of the visit. b) Visitor's name.
c) Identification number with photo (official documents such as: driver's license, passport, INE, etc.). d) Time of entry and exit. e) In the case of vehicle access, the format must include the data of the private or cargo vehicle (model, license plate, trailer number, etc.). III. Indicate who is the person responsible for accompanying the visitor and/or supplier and if there are restricted areas for their entry. 3.4 Procedure for identification and removal of unauthorized persons or vehicles. The supervised facility must have documented procedures that specify how to identify, confront, or report unauthorized or identified persons and/or vehicles. Response: Explanatory Notes: Attach the documented procedure to identify, confront, or report unauthorized or identified persons and/or vehicles. The procedure must include: I. Responsible personnel. II. Designate a person or area responsible for being informed of incidents. III. Instructions for confronting and addressing unidentified personnel. IV. Indicate in which cases the corresponding authorities must be notified. V. How the registration of incidents and the measures adopted in each case is carried out. 3.5 Courier and package deliveries. Courier and packages intended for facility personnel must be examined upon arrival and before being distributed to the corresponding area. Likewise, the company must have a documented procedure for the receipt and review of courier and packages, which must be communicated to the responsible personnel through training. The training must be documented.
Response: Explanatory Notes: Describe the procedure for the receipt and review of courier and packages and ensure you include the following: I. Indicate the personnel in charge of carrying out the procedure. II. Indicate how the service provider is identified (indicate if an additional procedure to the supplier access procedure is required). III. Indicate how the review of the courier and/or packages is carried out, what mechanism it uses, the records kept, and if applicable, the incidents detected. IV. Describe the characteristics or elements to determine what courier and/or packages are suspicious. V. Indicate what action you take in the event of detecting suspicious courier and/or packages. 4. Business partners. The supervised facility must have written and verifiable procedures for the selection and contracting of new business partners and monitoring of partners already working with them, such as: Transporters for the transport and/or distribution of foreign trade merchandise, warehouses, suppliers of cleaning services, private security, personnel contracting, placement and maintenance of alarm and closed-circuit television and video surveillance systems, suppliers of Information Systems and Technologies, providers of loading, unloading, and merchandise handling services, contractors; shipping or airline lines, among others, and according to their risk analysis, require them to comply with security measures to strengthen the international supply chain. The risk analysis carried out by the facility regarding its business partners (clients and suppliers) must include risks related to the identification of activities related to money laundering and terrorism financing. Additionally, the facility must foster a documented social compliance policy and program that, at a minimum, addresses how among its employees and business partners they could guarantee that goods, inputs, or merchandise imported into Mexico for the manufacture of products or merchandise do not come from extraction, production, or manufacturing, total or partial, with prohibited forms of labor, that is, forced or compulsory labor, including forced or compulsory child labor, under Article 23.6 of the USMCA and the Agreement establishing the merchandise whose importation is subject to regulation by the Ministry of Labor and Social Welfare, published in the DOF on February 17, 2023.
4.1 Selection criteria. There must be documented procedures for the selection, follow-up, and renewal of commercial relationships with business associates or suppliers, which include interviews, reference verification, evaluation methods, and use of provided information. The information derived from the investigation and/or evaluation of business associates and/or suppliers must be documented and integrated into a file (physical or electronic). The procedure for the selection of business partners must include, indicators to identify clients or suppliers that may not be legitimate or with unlocated addresses, in addition to investigations, reviews, or evaluations of said partners for the identification and control of activities related to money laundering and terrorism financing. If the investigation and/or evaluation of any business partner leads to substantial doubts about the veracity of their operations or services, the facility must avoid their contracting and, if applicable, notify their security specialist or Authorized Economic Operator Program contact and the corresponding authority about their suspicions. Response: Explanatory Notes: Attach the documented procedure for the selection and contracting of new business partners and monitoring of partners already working with them, this comprises any type of business associates, suppliers that have a commercial relationship with the company and if applicable with their logistical process and with the supply chain, as well as potential and predominant clients to hire their service frequently and/or those that have a commercial relationship with the supervised facility and ensure it includes the following points: I. What information is required from your business partner. II. What aspects are reviewed and investigated (the result of the investigation must be integrated into the file). III. The indicators to identify clients or suppliers that may not be legitimate or with unlocated addresses. This point refers to indicating all those alerts to determine that a business partner is not reliable and thus, carry out a deeper investigation and evaluate if you should work with them.
IV. Indicate whether you maintain a file for each of your commercial partners, as well as the information it must contain. V. Specify how you evaluate your commercial partner's services and what points you review. The file must include at least the following: I. Company data (name, tax ID key (RFC), activity, etc.). II. Legal representative data. III. Proof of address. IV. Commercial references (if applicable). V. Confidentiality agreements and security policies. VI. If applicable, certificate or certification number in the security programs to which they belong.
4.2 Security requirements. The supervised premises must have a documented procedure in which, based on its risk analysis, it requests additional security requirements from those commercial partners that intervene in its supply chain, as well as from service providers that similarly intervene in the control, handling, transport, and/or coordination of merchandise subject to foreign trade, such as: transport, warehouses, service providers for cleaning, private security, hiring of personnel, installation and maintenance of alarm and closed-circuit television and video surveillance systems, IT system and technology providers, providers of loading, unloading, and maneuvering services for merchandise, collection and recycling, contractors, among others). The requirements must be based on the Supervised Premises Profile established by the AGACE or the specific Profile for each actor in the supply chain that corresponds to them, if one exists. The supervised premises must request from its commercial partners documentation that certifies or proves that they comply with the minimum security standards established in the Supervised Premises Profile, either through a written declaration issued by the partner's legal representative, agreements, or contractual clauses with documentation supporting compliance with the requirements established in the Authorized Economic Operator Program. Likewise, the premises must take into account and know the specific requirements of the Authorized Economic Operator Program that will be applicable to each of its commercial partners, based on their activity within the supply chain. In the case of the premises' commercial partners that provide their services within the facilities, they must be obligated to comply with these supply chain security requirements.
Response: Explanatory Notes: Describe the procedure that indicates how you carry out the identification of commercial partners that require compliance with minimum security standards. Ensure you include the following points: I. A register of commercial partners that must comply with security requirements, and mention what type of providers these are (transporters, warehouses, private security companies, customs brokers, companies authorized to provide loading, unloading, and merchandise handling services, etc.). II. Indicate in what documentary way (agreements, contracts, contractual clauses, and/or addenda) you ensure that your commercial partners comply with security requirements. III. Indicate if there are agreements, contracts, contractual clauses, and/or addenda regarding the implementation of security measures with your service providers inside your company, such as: customs brokers, security guards, cleaning services, gardening, cafeteria, maintenance, IT providers, etc. IV. Indicate if you have commercial partners to whom membership in a supply chain security program is required, either certification by a foreign authority or the private sector (for example: CTPAT or another Authorized Economic Operator Program), as well as the information and documentation requested of them.
4.3 Commercial partner reviews. The supervised premises, through the Security Committee, must carry out periodic security evaluations (as well as those derived from risk situations) of the processes and installations of business associates based on risk to guarantee that they have the minimum security standards required by the premises, based on the Authorized Economic Operator Program, maintain records that allow verifying that security processes and measures are being executed as well as the corresponding follow-up. When inconsistencies are found, the company must communicate this to its partner or supplier and provide a justified period to address the observations or areas for improvement identified, or otherwise, take the necessary measures to sanction them. Conducting security evaluations of commercial partners is important to guarantee that there is a solid and functioning security program; therefore, in addition to a documented procedure, there must be a program or calendar for the execution of these security reviews or evaluations, prioritizing partners that are more critical according to their risk analysis. If a member is not evaluated and the company does not know if the processes and installations of its commercial partners function correctly, it puts its supply chain at risk.
Response: Explanatory Notes: Describe the procedure to carry out security evaluations for the verification of security processes and installations of commercial partners; ensure you include the following points: I. Frequency with which visits to the commercial partner are made (this must be at least once a year and derived from risk situations). II. Program or calendar for the execution of security reviews. III. Record or report of the verification and, if applicable, the corresponding follow-up. IV. The verification format(s) must be properly filled out, including the date, name, and position of those participating in the review, signatures, etc. V. Indicate what action measures are taken when commercial partners do not comply with the established security requirements. VI. In case of having commercial partners with CTPAT certification or another supply chain security certification program, indicate the frequency with which their status is reviewed and the actions taken in case it is detected that it is suspended and/or cancelled, in accordance with what is established in their procedure.
The procedure must include: I. Frequency of visits. II. Points to review regarding security. III. Preparation of reports. IV. Feedback and agreements with the commercial partner. V. Follow-up on agreements. VI. Measures in case of detecting non-compliance with requirements. VII. Record of evaluations. VIII. Area or person responsible for carrying out this procedure.
5.1 Process mapping. There must be a map that shows step by step the logistical process of the flow of foreign trade merchandise and the required documentation through its international supply chain. The premises must take into account and include in its mapping all parties involved in its supply chain, which may not handle the cargo directly but may have operational control such as transporters, handling, customs clearance, storage, and providers of loading, unloading, and merchandise maneuvering services. If any part of the transport is subcontracted within its supply chain, it is indispensable that it be considered within its risk analysis and process mapping, since the more direct and indirect suppliers, the greater the risk involved.
Response: Explanatory Notes: Attach the document where the process mapping through which merchandise entering and leaving the supervised premises passes is illustrated and described, with the purpose of having each of the steps involving storage, custody, loading, and unloading of the merchandise well identified. This mapping must contain at least the following aspects:
I. Origin of the merchandise: a) National or nationalized merchandise. b) Foreign merchandise for exhibition, sale, or distribution. c) Merchandise for manufacturing, transformation, or repair. d) Merchandise whose origin or destination is the transfer to companies with SE programs. II. Customs of clearance. III. Transport of the merchandise. IV. Indicate the points and areas for rest or safeguarding of cargo vehicles during the transport of merchandise subject to foreign trade (import and export). V. Indicate the estimated times that said vehicles remain in the rest or safeguarding areas (company yards, exit customs, customs broker or agency installations, warehouses, transfer yards or transport, among others). VI. Delivery and/or receipt of the merchandise. VII. Customs Clearance. VIII. Delivery to the consignee. IX. Information flow related to the merchandise. X. Abandonments, destruction of merchandise, among others.
5.2 Warehouses and distribution centers. When the supervised premises has commercial partners that provide any warehouse, distribution center, or other services inside its facilities, they must be subject, according to their characteristics, to what is established in this document, in order to maintain integrity in its supply chain.
Response: Explanatory Notes: According to its logistical process mapping, if foreign trade merchandise is transferred or moved to another warehouse and/or alternative distribution center different from the one operated under its authorization or concession as a supervised premises, it must indicate if they are registered with its RFC, providing their general data (name and address) and briefly explaining what activity is carried out in that or those installations (cross-dock, temporary warehouse, etc.). Likewise, indicate if these belong to the company or is a service contracted through a third party and/or are part of a shareholder group. In this case, according to the supplier selection criteria mentioned in the section on Commercial Partners of this document, indicate how you ensure compliance with minimum security requirements. Installations that have a Supervised Premises concession or authorization must match the number of Profiles presented, as well as indicate all addresses registered with the RFC.
5.3 Loading and unloading delivery and receipt. The supervised premises must guarantee the supervision of the identification of operators of own or subcontracted transport means that carry out the collection, delivery, or receipt of foreign trade merchandise inside or outside its facilities, warehouses, and/or distribution centers. Likewise, it must designate the area responsible for supervising the loading or unloading of the shipment, even in accordance with instructions received from clients for its handling and transport. On the other hand, it must supervise, inspect, and verify through mechanisms, tools, or non-intrusive technology available to it, the integrity of the transport means and the merchandise subject to foreign trade that enters or leaves the supervised premises, checking the information described in the exchange lists received previously in accordance with the traffic or transport mode in question. Likewise, it must guarantee that the driver transporting foreign trade merchandise, during delivery or receipt, has the required documentary information before undergoing customs clearance formalities and authorizing its exit.
The cargo preparation areas and the immediate surrounding areas must be inspected regularly to ensure that these areas remain free of visible pest contamination. During the loading and unloading process of merchandise, the company's security area (supervisor or security guard) must be present to validate that the process is being carried out correctly, mitigate the risk of shipment contamination (prohibited, illicit merchandise, or pests), and register said review (incident reports, records, reports, etc.). Also, the personnel responsible for the entry and exit areas of the merchandise must review the information included in import and/or export documents to identify or recognize suspicious cargo shipments. Likewise, specific training on identifying common errors in export shipment documentation must be provided, with the objective of preventing these from resulting in security incidents or suspicious merchandise.
Response: Explanatory Notes: Attach the documented procedure in which you indicate how you carry out the delivery and receipt of cargo and ensure that the following points are included: I. Method to identify transport operators. II. Documentation delivered to operators. III. Person responsible for supervising the identification numbers of transport means during the loading or unloading of containers, dry vans, UDLS, railway platforms, air waybills, if applicable, in the case of consolidated merchandise, de-consolidation process, and checking of information. Inspection method at the facility access point. I. Designation of personnel responsible for receiving the driver and merchandise upon arrival. II. Coordination of the facility areas that receive exchange lists from transporters prior to their arrival and with the customs where customs clearance formalities are fulfilled. III. Record of the introduction of consolidated merchandise into the supervised premises. IV. Release deadlines.
V. Prior requests. VI. Services offered by the facility for the movement of merchandise prior to customs clearance. VII. How it guarantees that the transport means is free of visible pest contamination; in case any type of visible pest, contamination, trash, insects, grass, weeds, or brush is identified, how it is reported and what actions are taken regarding it. Attach the documented procedure to detect and report discrepancies in the delivery or receipt of transport means carrying merchandise and ensure it includes the following points: I. Persons responsible for carrying out the review. II. Documents to check. III. Areas to which the information is reported.
5.4 Merchandise tracking procedure. In accordance with its risk analysis, the supervised premises must monitor the movement of foreign trade merchandise in its installation through a diary of activity monitoring and supervision or a technology during the arrival, storage, custody, and release of foreign trade merchandise to comply with customs clearance formalities, guaranteeing at all times to have the following information: number and information of the bill of lading, packing list, waybill, or other transport documents, as applicable, name and address of the consignee or sender, description, value, origin of the merchandise, and physical location in the premises. The above must be accredited in accordance with the guidelines of a documented procedure. The supervision data and record of all maneuvers in the supervised premises must be preserved for one month when the authority must carry out an evaluation when so required.
Response Explanatory Notes: Attach the documented procedure to monitor transfers, internal transfers in the supervised premises of consolidated and/or de-consolidated foreign trade merchandise. This procedure must include, among other aspects according to its operation: I. Indicate the type of system implemented, if any, the query tools available to monitor the merchandise.
II. Identification of estimated transfer times and maneuvers in supervised premises according to the transport in question. III. Detail the communication means available. IV. When the tracking is carried out by a third party, indicate who is responsible, and how it is verified that it is being carried out correctly, in accordance with the procedures the company indicates to them.
5.5 Cargo discrepancy report. There must be documented procedures to detect and report missing, excess, prohibited merchandise, or any other discrepancy in the delivery or receipt of containerized, consolidated, and/or de-consolidated merchandise prior to complying with customs clearance formalities, with the purpose of having information that contributes to the corresponding investigations by authorized consignees and, if applicable, by competent authorities. Likewise, it must describe the measures and actions to be taken in case of identifying the transport and handling of illicit, undeclared, and prohibited merchandise or those that by their nature put the safety of users at risk, which could be during the following processes: reception, delivery, warehouse for prior inspections, consolidated, de-consolidated, transport means yards, and if applicable, according to the services offered.
Response: Explanatory Notes: Attach the documented procedure to detect and report discrepancies in the delivery or receipt of merchandise and ensure it includes the following points: I. Persons responsible for carrying out the review. II. Documents to check. III. Areas to which the information is reported. This procedure must be applied to consolidated merchandise and located in the warehouse. Describe and enumerate the risk areas identified in the supervised premises.
5.6 Processing of cargo information and documentation. The supervised premises must have documented procedures to ensure that the electronic and/or documentary information used during the movement, storage, custody, maneuvers, and clearance of the cargo, as well as the information received from business associates, is legible, complete, accurate, reported in time, and protected against changes, losses, or introduction of erroneous information. Likewise, forms and documentation related to import and/or export should be secured to prevent unauthorized use.
Response: Explanatory Notes: Describe the procedure for processing cargo documentation; ensure you include the following points: I. Detail how you transmit and/or receive information related to the transport and maneuvers of cargo in the supervised premises (indicate if you use a specific computer control system and briefly explain its function). Likewise, detail how you validate that the information provided by foreign trade users, transporters, shipping lines, railway companies, among others that converge in the premises, is legible, complete, accurate, reported in time, and protected against changes, losses, or introduction of erroneous information. II. The electronic information of shipments and cargo in general must include the seal and/or lock number with which the cargo was secured. III. Indicate in what way business associates transmit information with the supervised premises and ensure its protection.
5.7 Inventory management, control of packaging, container, and packing material. The supervised premises must have documented procedures for automated inventory control, in accordance with its authorization to provide services for handling, storage, and custody of foreign trade merchandise; likewise, they must include abandonments, destructions, among others in accordance with applicable regulations and conduct reviews periodically. Packaging, container, and packing materials, if applicable, must be controlled and supervised to prevent them from being susceptible to manipulation prior to their use, which also includes, the control, dissemination, and prevention procedure of visible pest contamination, in the case of use of wooden packing materials (such as pallets, boxes, crates, cages, reels, dunnage, chocks, supports, or platforms) to stack the cargo, move it, and protect it throughout its entire supply chain.
Response: Explanatory Notes: Attach the documented procedure for inventory management. This must include, according to its operation among other aspects, the following: I. Mention what type of system it uses for information exchange with the authority for inventory purposes. II. Who is its provider. III. Indicate if it has a contingency plan in case of system failures. IV. Mention where it is physically located and who are the responsible for its operation. V. The frequency with which it carries out stock verification (periodic inventory). Indicate if there is a scheduled documented calendar to carry them out. VI. Indicate what is done, in case there are excesses and shortages in the inventories. VII. Indicate the treatment given to the control and handling of packaging, container, and packing material, and if applicable, of shrinkage, waste, or excess material, which also includes the control, dissemination, and prevention procedure of visible pest contamination, in the case of use of wooden packing materials (such as pallets, boxes, crates, cages, reels, dunnage, chocks, supports, or platforms) to stack the cargo, move it, and protect it. VIII. This point is also focused on reducing the risk of introduction or dissemination of quarantine pests of importance to the country through packaging (imports); therefore, describe how it complies with the provisions indicated by SEMARNAT and NOM-144-SEMARNAT-2017, in concordance with International Standard for Phytosanitary Measures No. 15, known as Regulation of
packaging of wood used in International Trade, which emanate from the United Nations Organization for Food and Agriculture. IX. Indicate how the fumigation process is carried out to kill, inactivate, sterilize, desiccate, or eliminate pests. What actions are taken if quarantine of packaging materials is required. X. Indicate the responsible area for carrying out this process, as well as the documentation or certificates obtained. The applicant's procedures may include: I. Warehouse only accessible to authorized personnel. II. Control of incoming goods, transfers to other warehouses, consolidation or de- consolidation. III. Actions taken if irregularities, discrepancies, losses, or thefts are identified. IV. Treatment of deterioration or destruction of goods. V. Separation of different types of goods, for example: high value, hazardous. 6. Customs management. The supervised facility must have documented procedures that establish internal and operational policies, as well as the necessary controls for the proper compliance with customs obligations. 6.1 Customs obligations. The supervised facility must have a documented procedure for compliance with customs obligations due to having federal authorization. This must include at least the following: a) the annual guarantee that must be paid to the tax authority according to the average value of the goods they handle; b) The identification of the physical space for the customs inspection carried out by customs authorities; c) the physical space designated for handling, storage, and custody services regarding goods that have become property of the federal treasury; d) the free storage and custody of goods in accordance with regulations; e) process for transferring goods between warehouses; f) process to prove payment of fees for being a supervised facility; g) regarding the authorization for goods to be subject to manufacturing, transformation, or repair, if applicable. On the other hand, the procedure mentioned in the previous paragraph must include the communication process with consignees in case of destruction or loss of goods, guarantee the exchange of information through a simultaneous system containing the data indicated in rule 2.3.8. and establish protocols related to the treatment, communication, storage, and custody of foreign trade goods under the internal transit regime.
Answer: Explanatory Notes: Attach the procedure to comply with your customs obligations, which must include the following: I. The annual guarantee that must be paid to the tax authority according to the average value of the goods they handle. II. The identification of the physical space for the customs inspection carried out by customs authorities. III. The physical space designated for services of handling, storage, and custody regarding goods that have become property of the federal treasury. IV. The free storage and custody of goods in accordance with regulations. V. Process for transferring goods between warehouses. VI. Process to prove payment of fees for being a supervised facility. VII. The communication process with consignees in case of destruction or loss of goods. 6.2 Customs verification. The supervised facility, in order to guarantee compliance with the information of operations for the customs clearance of foreign trade goods, as well as to verify the truthfulness of the information declared to the competent authorities, must have documented procedures to verify that the customs declarations it receives for release from the facility match what is registered in the SAAI Web system and, if applicable, report to the customs authority any discrepancy in said information. The facility, likewise, must have a procedure for archiving the corresponding release records and safeguarding them for at least one month. Answer: Explanatory Notes: Attach the established procedure to verify the information registered in the SAAI Web system, and cross-check that contributions and/or compensatory duties had been paid prior to the release of shipments to undergo the formalities of customs clearance.
Indicate how business partners transmit information with the supervised facility and ensure its accuracy, for example: the use of the institutional application Remote Declaration Inquiry to corroborate the payment of contributions and/or compensatory duties, identification of means of transport, weight, among others, for exit authorization. 7. Security of cargo vehicles, containers, trailers, and/or semi-trailers. The supervised facility must contribute with users and competent authorities to maintain the security of means of transport, to protect them from the introduction of people, illicit materials, prohibited or unauthorized items. For this reason, it is necessary to have documented procedures to inspect, seal, and maintain their integrity. Likewise, the process of inspecting said means of transport, containers, train cars, trailers, and semi-trailers used as Instruments of International Traffic, must include an agricultural inspection procedure to look for visible pests and serious structural deficiencies. Pest contamination is defined as visible forms of animals, insects, or other invertebrates (living or dead, at any stage of the life cycle, including eggs, etc.), or any organic material of animal origin (including blood, bones, hair, meat, secretions, excretions, etc.); plants or plant products (including fruits, seeds, leaves, twigs, roots, bark, etc.); or other organic material, including fungi, soil, or water; when such products are not the declared cargo within the Instruments of International Traffic. In case of using high-security seals, it is necessary to have procedures to correctly seal and maintain the integrity of containers and trailers from the moment they leave their facilities. A high-security seal must be applied to all containers and trailers for foreign trade shipments, which must meet or exceed Standard ISO 17712 for high-security seals. With the aim of maintaining supply chain security, the facility must inspect all cargo vehicles systematically upon entry and exit of its facilities (domestic and international traffic), in addition to keeping a record. 7.1 Use of seals and/or padlocks. The supervised facility, if applicable, must identify the cargo transport means, own or subcontracted, that transport complete or consolidated foreign trade goods that may be: maritime, air, national land, cross-border, railway, and/or multimodal, which are subject to the placement of seals and/or padlocks that meet or exceed Standard ISO 17712 with the aim of guaranteeing at all times the integrity of the cargo. For this reason, as one of the security mechanisms, the supervised facility, if applicable, must use high-security padlocks or seals that meet or exceed Standard ISO 17712 in all containers and loaded trailers that are subject to foreign trade and maintain their integrity until delivery at the final destination. For this, the facility must have documented procedures to place and verify the correct application of seals, their inspection at intermediate points, final destination, and their replacement when opened by any authority. In case of such an inspection, drivers must notify and register any unusual anomaly or structural modification found in the transport means resulting from said review. The procedures must include the steps to follow if it is discovered that a seal is altered, manipulated, or if there is an incorrect seal number in the documentation, the communication protocols to the business partners involved in the supply chain, and the investigation of the security incident. These must be notified to security personnel, business partners who may be part of the affected supply chain, security specialist, or contact of the Authorized Economic Operator Program.
Likewise, it is necessary to have a documented procedure for their administration that includes control, assignment, safeguarding, handling of discrepancies, and destruction of seals and padlocks (the latter is mandatory whenever seals are broken in their facilities). Regarding the provider of seals and/or padlocks, it must be demonstrated how these comply with Standard ISO 17712. The company management or a security supervisor must carry out periodic and documented audits of the high-security seals and/or padlocks, these reviews must include the verification of the inventory of stored seals and/or padlocks and the cross-check with inventory records and shipping documents. Also, supervisors of the shipping area and/or warehouse managers must periodically verify the seal numbers used in transport means and Instruments of International Traffic to corroborate that the information is correct. For this case, the supervised facility must have a documented procedure in which, in accordance with its risk analysis, it supervises the placement of seals and/or padlocks on transport means that transport foreign trade goods in accordance with its logistics process and in those traffics that require it due to their high probability of occurrence and impact of the identified risk and during maneuvers in the facility. In it, it must evidence controls that allow accrediting that it supervises the portability of seals and/or padlocks resulting from entries or exits of the supervised facility. In all cases, it must use the VVTT inspection method to mitigate improper manipulations as follows: I. V - View the seal and lock mechanisms of the container. II. V - Verify the seal number. III. T - Pull the seal to ensure it is correctly placed. IV. T - Twist and turn the seal to ensure. Answer: Explanatory Notes: List according to your risk analysis and logistics process, the transport means that are subject to the placement of high-security seals and/or padlocks. Attach the documented procedure for the supervision of placement and review of seals and/or padlocks on transport means that transport foreign trade goods. This must include, among other aspects according to your operation: I. The use of seals and/or padlocks that meet or exceed Standard ISO 17712. II. If applicable, use the VVTT inspection method. a) V - View the seal and lock mechanisms of the container (View). b) V - Verify the seal number (Verify).
c) T - Pull the seal to ensure it is correctly placed (Tug). d) T - Twist and turn the seal to ensure it has closed (Twist and Turn). III. Review and cross-check the documentation containing the original seal or padlock number for purposes of entries or exits of supervised facilities. Review that the closing devices, hinges, and pins are attached to the trailer or container and welded or riveted. Also, protective plates can be placed on the door hinges and/or a seal/adhesive tape can be placed on at least each side. Also, the correct functioning of handles, latches, and all other locking or closing mechanisms of cargo vehicles must be verified to detect manipulations and any inconsistency before placing any sealing device. IV. Indicate how you assign and replace high-security padlocks, in the case of maneuvers such as prior inspection, replacement, among others. If applicable, attach the documented procedure for the control and handling of seals and/or padlocks, this must include, among other aspects according to your operation: I. What type of seals and/or padlocks you use in your operations (foreign trade, transit, storage, etc.). II. Who has access and how padlocks and/or seals are safeguarded. The management of seals and/or padlocks must be restricted only to authorized personnel; stored in a safe place, have an inventory, control of their distribution and tracking (record of seals used, as well as of the receipt of new seals and/or padlocks). III. Describe how the facility management or security supervisor participate in audits of high-security seals and/or padlocks, the reviews they perform, the records they generate, and the actions they take in case of identifying discrepancies. Also, how supervisors of the shipping area and/or warehouse managers verify seal numbers used in transport means and Instruments of International Traffic to corroborate that the information is correct (this process can also be included within the internal audits referred to in sub-standard 1.3 of this document). IV. How discrepancies in seal and/or padlock numbers are addressed. V. Indicate who the provider(s) are and how it is proven that the specifications of seals and/or padlocks comply with Standard ISO 17712 (attach certificate issued by the certifying company responsible for verifying compliance with the corresponding ISO). All written procedures must be disseminated and maintained at the operational level so that they are easily accessible to employees responsible for executing the tasks described above, reviewed at least once a year, and updated as necessary.
7.2 Inspection of transport means, containers, trailers, and semi-trailers. There must be established procedures to verify the physical integrity of the structure of transport means, containers, train cars, trailers, and/or semi-trailers used as Instruments of International Traffic, that enter or leave the supervised facility according to their nature, even the reliability of the lock mechanisms in them with the aim of identifying natural or hidden compartments. Inspections of transport means or cargo vehicles, containers, and trailers must be systematic and carried out upon entry and exit of the supervised facility and, if applicable, at the cargo loading point; a record of these inspections must be kept in an access-controlled area and carried out in a place monitored by alarm systems and closed-circuit television and video surveillance systems, said system must cover the entire inspection process. The documented procedure for its inspection must include, by way of example and not limitation, the following review points for road transport: Means of Transport Trailers, Train Cars, Semi-trailers and Containers I. Bumper; II. Tires and rims (tractor and trailer); III. Floor (tractor); IV. Fuel tanks; V. Cabin interior (bedroom and tool compartment); VI. Air tanks; VII. Chassis; VIII. Fifth wheel area; IX. Drive axles; X. Exhaust pipe; and XI. Engine. I. Exterior and interior doors; II. Side walls (left and right); III. Internal and external roofs; IV. Front wall; V. Internal floor; VI. If applicable, the refrigeration system. For transport means with trailer or integrated cargo compartment, the points indicated in the Trailers section must be added to the transport means points. Likewise, before loading transport means, containers, train cars, trailers, and semi-trailers used as Instruments of International Traffic, they must undergo agricultural and security inspections to guarantee that their structures have not been modified to hide smuggling or that they have been contaminated with visible agricultural pests, keep a record, and be backed by a documented procedure. If visible pest contamination is found during the inspection or transport of foreign trade goods, it must be cleaned (washed, vacuumed, etc.) to eliminate said contamination.
Answer: Explanatory Notes: Attach the documented procedure to carry out the security and agricultural inspection of the means of transport according to their nature and logistics process to be handled at the entries and exits of the supervised facility. This must include, among other aspects according to your operation: I. Those responsible for carrying out the inspection. II. Definition of the place(s) where the inspection is carried out and indicate how it is monitored by alarm systems and closed-circuit television and video surveillance. III. The security review points for transport means, trailers, semi-trailers, containers, railway transport, and/or multimodal according to official provisions, both of security and those of quality and agricultural inspections with the aim of looking for visible pests. IV. Established formats for the inspection of transport means. V. Attach the established format for the inspection of transport means or cargo vehicles, containers, train cars, trailers, and/or semi-trailers. If you use other types of cargo vehicles for the transport of your goods (van-type trucks, pickup, 3.5 tons, tankers, etc.), your procedure and inspection format must include the process and review points. Likewise, the security and agricultural inspection format must include the following information: I. Date of inspection; II. Time of inspection; III. License plates of the vehicle (tractor and trailer);
IV. Container/trailer number; V. Specific areas of the cargo vehicles that were inspected; and, VI. Name of the employee who performs the inspection and of the supervisor. The security and agricultural inspection formats can be signed by the supervisor to corroborate their information and be part of the documentation of import and export. The documentation must be kept for one year for an investigation in case of any security incident, as well as to demonstrate continuous compliance with these inspection requirements. Additionally, and according to the risk analysis, the supervised facility should carry out periodic random reviews of cargo vehicles, after the transport personnel has carried out security inspections to verify that they have been carried out correctly, counteract internal conspiracies, and prevent security incidents. The reviews must be carried out randomly, without prior notice, so that they do not become predictable, in addition to being carried out in different places where the transport means may be susceptible to contamination. 7.3 Storage of vehicles, transport means, containers, train cars, trailers, and semi-trailers. When the transport means, containers, trailers, and/or semi-trailers that will be destined to transport foreign trade goods are empty and must be stored in parking areas, they must be secured with a padlock and/or indicative seal or, if applicable, in a safe area that is guarded and/or monitored. When it is necessary to store any loaded container, trailer, and/or semi-trailer, it must be in a safe area and monitored by alarm systems and closed-circuit television and video surveillance, to prevent unauthorized access and manipulation of the goods, so it must be closed with a high-security seal and/or padlock according to Standard ISO 17712.
Answer: Explanatory Notes: Indicate if the company stores containers, trailers, and/or semi-trailers for subsequent clearance, or in the case of those that are empty and how it maintains their integrity within its facilities. I. In case of using padlocks and/or seals, indicate what type you use. II. In case of using any container, trailers and/or semi-trailers as a warehouse of raw material and/or any other type of goods, indicate how it maintains the integrity and security of the same. 8. Personnel security. The supervised facility must have documented procedures for the registration and evaluation of people who wish to obtain employment within the supervised facility, establishing methods to carry out periodic verifications of current employees. Likewise, there must be continuous training programs for administrative and operational staff in which the company's supply chain security policies, consequences, and actions to consider in case of any offense are disseminated. 8.1 Employment background checks. The supervised facility must have documented procedures to investigate and verify the information recorded in the resume, criminal records (if local legislation and company policies allow it), and applications of candidates with possible employment, in accordance with local legislation, either on their own or through an external company. Likewise, for positions that require it due to their sensitivity and affect the security of shipments, in accordance with their previously carried out risk analysis, they must consider requesting stricter requirements for their hiring, which must be carried out periodically. Regarding personnel who already work in the company, periodic investigations must be carried out based on the activities and/or sensitivity of the employee's position. All information regarding personnel must be kept in personal files, which must have restricted access. Answer: Explanatory Notes: Describe the documented procedure for personnel hiring, and make sure to include the following: I. Requirements and documentation required. II. Tests and exams requested.
Indicate the areas and/or critical positions that have been identified as risky, according to your analysis, and indicate the following:
I. Indicate if there are additional requirements for specific areas and/or job positions, such as criminal records (if company legislation and policies allow), non-criminal background certificates, socioeconomic studies, clinical toxicological studies (drug use), etc. If applicable, specify the job positions or work areas where these are required and the frequency with which they are conducted.
II. Indicate if, prior to hiring, the candidate must sign a confidentiality agreement or a similar document.
If hiring a service agency for personnel recruitment, indicate if this agency has documented procedures for personnel recruitment and how it ensures compliance with them. Briefly explain what they consist of.
The procedures for hiring personnel and contractors must include:
I. Thorough investigations of the work and personal backgrounds of new employees.
II. Confidentiality and liability clauses in employee contracts.
III. Specific requirements for critical positions.
IV. If applicable, the periodic update of the socioeconomic and physical/medical study of employees who work in critical and/or sensitive areas.
V. The hiring process and requirements requested for temporary employees and contractors.
The facility may consider the results of background checks on candidates, as permitted by current legislation, to make hiring decisions. Background checks are not limited to identity and criminal record verification. In higher-risk areas, deeper investigations may be justified.
8.2 Procedure for employee termination. There must be documented procedures for employee termination, which include the handover of identification and any other items provided to perform their functions (keys, uniforms, badges/credentials, IT equipment, passwords, tools, etc.). Furthermore, this procedure must include the deactivation of access to computer systems and other systems that may exist.
Response: Explanatory Notes: Describe the procedure for employee termination, and ensure you include the following:
I. Who is responsible for carrying out and following up on this procedure.
II. How the handover of identification, uniforms, keys, and other equipment is performed and confirmed.
III. Indicate the control, record, and/or format in which the handover of materials and deactivation of computer systems are identified and ensured (attach if applicable).
IV. Specify the type of records of personnel who ended their employment relationship with the company, so that in case of security reasons, their service providers and/or business associates are warned.
8.3 Personnel administration. The audited facility must maintain an updated system, control, or database of active employees. Furthermore, it must carry out and maintain updated records of affiliation with social security institutions and other legal labor records.
In the case where the company has personnel hired by its business partners and working within the facilities, it must ensure that they meet the requirements established for the rest of its employees.
Response: Explanatory Notes: Indicate that the facility has an updated system, control, or database, both for personnel hired directly and that hired through a service provider company, and ensure it includes, among other things, the following points:
I. Full name.
II. Updated photograph, at least every 5 years.
III. Personal data (age, name, date of birth, phone number, address, CURP, social security number, blood type, allergies, etc.).
IV. Family ties.
V. Work background.
VI. Diseases.
VII. Medical exams.
VIII. Training.
IX. Psychometric exams.
X. Toxicological exams.
XI. Results of periodic evaluations.
XII. Observations.
This personnel must be hired in accordance with current labor laws and regulations.
9.1 Classification and handling of documents. There must be procedures to classify documents according to their sensitivity and/or importance. Sensitive and important documentation must be stored in a secure area that only allows access to authorized personnel. The useful life of the documentation must be identified, and procedures for its destruction must be established.
The audited facility must conduct regular reviews to verify access to information and ensure that it is not used improperly.
Response: Explanatory Notes: Attach the documented procedure for the registration, control, and storage of printed and electronic documentation (classification and filing of documents), which must include:
I. Control register for delivery, loan, and other documents.
II. Restricted access to the archive area.
III. Storage and classification policies.
IV. An updated security plan that describes the measures in force regarding the protection of documents against unauthorized access, as well as against deliberate destruction or loss.
V. In the case of electronic or digital information, it must adhere to the security criteria of sub-standard 9.2. Information Technology Security.
9.2 Information Technology Security. To protect Information Technology systems against common cybersecurity threats, a company must have sufficient protection to promote security in Information Technology infrastructure (software and hardware) against malware (viruses, spyware, worms, trojans, etc.), baiting, phishing, and internal/external intrusions (firewalls) in company computer systems. Similarly, companies must ensure that their security software is active and receives periodic updates.
In the case of automated systems and computer equipment, individual accounts must be used that require periodic password changes. To protect the confidentiality, integrity, and availability of information, the company must have established information technology policies, procedures, and standards that must be communicated through a training program for all employees who handle computer equipment and systems, which includes topics to prevent attacks through social engineering and all other threats to which they are exposed (malware, baiting, phishing, etc.). Companies that allow employees to connect remotely to a network must use secure technologies, such as virtual private networks (VPN), to allow employees to access the company intranet securely when outside the office, as well as procedures designed to prevent unauthorized remote user access.
For the above, there must be written procedures and infrastructure to protect the company against information loss, which includes the procedure for the recovery (or replacement) of Information Technology systems and/or data, as well as an established system to identify the abuse of Information Technology systems and detect inappropriate access and/or improper manipulation or alteration of commercial and business data, as well as a written procedure for the application of appropriate disciplinary measures to all offenders. Access to Information Technology systems must be protected against infiltration through the use of secure passwords, which include phrases or other forms of authentication. Users of such Information Technology systems must safeguard and not share their access keys or passwords. All Information Technology infrastructure must be physically protected against unauthorized access.
If a data leak or other unexpected event occurs resulting in data and/or equipment loss, procedures must include the recovery or replacement of Information Technology systems and/or data.
Response: Explanatory Notes: Attach the procedure for the recovery (or replacement) of Information Technology systems and/or data, which includes how it backs up and ensures the security of its information, as well as protecting it from potential losses. Ensure you include the following points:
I. Specify the frequency with which backups are performed.
II. Who has access to them, and who authorizes the recovery of information.
III. Indicate what type of tests are performed and how often, to verify the security of the network, systems, and infrastructure.
IV. Mention if, to perform this type of tests or vulnerability scans, it is done through software, a third party, or provider, and if so, indicate the name or corporate name.
V. In case vulnerabilities are found, describe the corrective actions that must be implemented.
VI. Indicate if you share information about cybersecurity threats with your business partners participating in your supply chain (for example: communications, bulletins, emails, etc.).
VII. Systems must be protected by passwords and must be modified frequently; therefore, indicate the procedure for changing them.
VIII. Specify if there are information security policies for protection.
IX. Have a system or software to detect and identify abuse, intrusion, or unauthorized access to your Information Technology systems and/or data, as well as the abuse of policies and procedures established by the company, including unauthorized access to internal systems, external websites, and the manipulation or alteration of commercial data by employees or contractors.
X. All offenders must be subject to the application of disciplinary measures; therefore, indicate the corrective policies and/or sanctions in case of detection of any violation of Information Technology security systems and policies.
Information Technology and cybersecurity policies and procedures must be reviewed annually and updated following an attack or according to situations that may put the company's systems at risk.
Describe the security measures used to allow employees to connect remotely to a network (VPN), to allow employees to access the company intranet remotely when outside the office.
If allowing employees to use personal devices to perform company work, such devices must comply with the company's cybersecurity policies and procedures, security updates must be periodic, and there must be a method to access the company network securely.
Specify if business partners have access to the company's computer systems. If so, indicate what programs they use and how they ensure access control.
Indicate if the computer equipment has a backup power supply system that allows business continuity.
The procedures regarding the backup of the audited facility's information must also include at least the following:
I. How and for how long data is stored (data should be backed up once a week or as appropriate).
II. Business continuity plan in case of incident and how to recover information.
III. Frequency and location of backup copies and archived information.
IV. If backup copies are stored in sites alternative to the facilities where the Data Processing Center is located.
V. Tests of the validity of data recovery from backup copies.
The procedures regarding the protection of the audited facility's information must also include:
I. An updated and documented policy for the protection of computer systems against unauthorized access and deliberate destruction or loss of information. All sensitive and confidential data must be stored in an encrypted format.
II. Detail if you operate with multiple systems (sites/locations) and how these systems are controlled.
III. Who is responsible for the protection of the computer system (responsibility should not be limited to one person but to several so that each can control the actions of the others).
IV. Each user's access must be assigned through individual accounts and restricted according to the job description or assigned tasks. Therefore, describe how access authorizations and access levels to computer systems are granted (access to sensitive information should be limited to authorized personnel to make modifications and use the information). Authorized access must be monitored by the area responsible for granting it, to verify or, if necessary, report that access to confidential systems is based on job requirements.
V. Indicate the elements or formats that passwords must have for access to Information Technology systems and computer equipment, frequency of changes, if there are other authentication methods, and who or what area provides those passwords.
VI. Indicate the name of the firewall and anti-virus used (include licensing information), evidencing that this security software is active and receives periodic updates.
For the above, cybersecurity policies and procedures should include measures to prevent the use of counterfeit technological products or those with incorrect licenses.
All computer equipment, electronic media (hard drives, cell phones, etc.), and Information Technology hardware containing confidential information related to the import and export process must be accounted for through periodic inventories and have such evidence. When these technological equipment must be discarded, there must be a documented procedure that includes how they must be formatted, disinfected, or destroyed appropriately to avoid information leakage.
VII. In case of employee termination, access to computer equipment, telecommunications, and the network must be eliminated at the moment of the employee's separation; this includes email accounts, system access accounts, software, programs, etc.
VIII. Measures planned to handle incidents when the system is compromised.
Employees must know the established procedures of the audited facility to consider a risk situation and know how to report it. Specific training must be provided to employees who, due to their functions, are in direct contact with merchandise and/or transport means, as well as to employees who are in critical and/or sensitive areas determined under your risk analysis, security areas, loading and unloading; as well as to those who receive and open mail and packages, among others.
10.1 Training and awareness on threats. The audited facility must have a training and awareness program on supply chain security policies directed to all its employees, and additionally, make informational material available regarding the procedures established in the company to consider a situation that threatens its security and how to report it. Training records must include the date of the training, the names of the attendees, and the training topics.
Similarly, specific training must be offered according to their functions to help employees maintain cargo integrity, perform container, trailer, and/or semi-trailer reviews for agricultural and security purposes, receive and review mail and packages, prevent operations with proceeds of illicit origin (money laundering, terrorist financing, etc.), how to recognize and report internal conspiracies, protect access controls, as well as training regarding smuggling, merchandise theft, placement of high-security seals and locks (VVTT inspection method), prevention of visible pest contamination, etc. These topics must be established as part of new employee onboarding and maintain periodic update programs. Update training must be performed periodically, after a security incident, and when there are changes in the audited facility's procedures.
In addition to security training programs, a program on awareness of alcohol and drug consumption must be included. Furthermore, disseminate and train personnel on the company's cybersecurity policies and procedures, including access to computer equipment and systems via passwords or phrases. Personnel who operate and administer security technology systems must receive training related to their operation and maintenance, including self-training through operational manuals and other methods. These topics must be established as part of new employee onboarding and maintain periodic update programs.
Training programs must encourage active employee participation in security controls and mechanisms, as well as maintain records of all training efforts provided by the company and the list of those who participated in them (videos, photographs, minutes, attendance lists, intranet or other system, didactic material, PowerPoint presentations, brochures, etc.). Training records must include the date of the training, the names of the attendees, the topics taught, in addition to having measures to verify that the training provided met all training objectives.
Response: Explanatory Notes: Must have a training program on security and prevention in the supply chain for all direct and indirect employees.
Explain briefly what it consists of and ensure you include the following:
I. Brief description of the topics taught in the program.
II. When they are taught (Onboarding, specific periods, etc.).
III. Frequency of training and, if applicable, updates.
IV. Indicate how participation in supply chain security training is documented (videos, photographs, minutes, attendance lists, intranet or other system, didactic material, PowerPoint presentations, brochures, etc.). Records must include the date of the training, the names of the attendees, the topics taught, in addition to having measures to verify that the training provided met all its objectives.
V. Explain how employee participation in security matters is encouraged.
Training to perform reviews of cargo vehicles, containers, trailers, and/or semi-trailers for agricultural and security purposes must include the following topics:
I. Signs of hidden compartments.
II. Smuggling hidden in natural compartments.
III. Signs of pest contamination.
IV. Procedures to follow if something is found during a transport medium inspection or if a security incident occurs during transit.
V. Agricultural review training must cover pest prevention measures, regulatory requirements applicable to wooden packaging materials in accordance with International Standard for Phytosanitary Measures No. 15, titled "Regulation of Wood Packaging Used in International Trade," which emanates from the Food and Agriculture Organization of the United Nations, and the identification of infested wood.
10.2 Awareness for transport medium operators. The supervised premise must inform the operators of the transport media used to transfer goods destined for foreign trade about the security policies regarding agricultural inspection procedures and transport medium, loading and unloading, incident handling, lock changes in case of inspection by other authorities, among others, that are implemented. Operators and personnel performing agricultural and transport medium security inspections must be trained to inspect cargo vehicles for these purposes. In the case where the transport service is provided by a business partner, the premise must ensure that operators are aware of all established security policies and procedures.
Response: Explanatory Notes: Describe the dissemination program regarding security in the supply chain focused on transport medium operators and ensure you include the following:
I. Indicate how this dissemination is carried out. II. Point out the topics covered. III. In case of using the services of a business partner to transfer your goods, indicate how the operators are informed about the company's security policies and procedures.
IV. Indicate how participation in supply chain security training for transport medium operators is documented (videos, attendance lists, brochures, etc.).
The topics that must be included, by way of example and not limitation, are:
I. Access and facility security policies. II. Cargo delivery-receipt (including suspicious cargo shipments). III. Cargo information confidentiality. IV. Transport instructions. V. Accident and emergency reports. VI. Instructions for placing high-security locks and/or seals in case of inspection by other authorities, as well as the control and use of high-security seals and locks in transit (placing a new one, review after an authorized stop, etc.). VII. Installation and testing of security and unit tracking alarms, where applicable. VIII. Identification of authorized formats and documents to be used. IX. Signs of hidden compartments. X. Concealed smuggling in natural compartments. XI. Signs of pest contamination. XII. Procedures to follow if something is found during a transport medium inspection or if a security incident occurs during transit.
In the case where the supervised premise identifies that any of its foreign trade shipments is involved in a situation that puts the supply chain security at risk, due to suspicion of a business partner or person, it must inform security personnel, business partners who may be part of the affected supply chain, security specialist or Authorized Economic Operator Program contact, as well as the competent authority, and, if possible, before border crossing, exit, or dispatch (import and export). Procedures must include the steps to follow if a seal is found to be altered, manipulated, or if there is an incorrect seal number in the documentation, the communication protocols to involved business partners in the supply chain, and the incident investigation. All the aforementioned procedures must be reviewed periodically or at least once a year to ensure that contact information and action protocols are correct.
11.1 Reporting of anomalies and/or suspicious activities. In case of detection of anomalies and/or suspicious activities related to supply chain security and in accordance with your logistical processes (related to access control, delivery, receipt, and storage of goods, security inspections of cargo vehicles and transport operators, etc.), these must be reported to security personnel, business partners who may be part of the affected supply chain, security specialist or Authorized Economic Operator Program contact, and other competent authorities, keeping a record of such anomalies and/or unusual activities.
Response: Explanatory Notes: Describe the procedure to denounce or report anomalies and/or suspicious activities, as well as the mechanisms to anonymously report problems related to security, ensure you include the following:
I. Who is responsible for reporting incidents. II. Detail how you determine and identify with which authority to communicate in different scenarios or presumption of suspicious activities. III. Mention if you keep a record of anomaly and/or suspicious activity reports and briefly describe what it consists of.
11.2 Investigation and analysis. There must be written procedures to denounce or report anomalies and/or suspicious activities, as well as for the analysis and investigation of security incidents in the supply chain to determine their cause, in addition to corrective actions to prevent recurrence, which must be implemented as soon as possible. The information derived from this investigation must be documented and available at all times for authorities that require it.
This information must include the documentation generated to carry out the foreign trade operation of the affected goods that allows identifying each of the processes the goods went through until the point where the incident was detected and that allows recognizing the vulnerability of the chain.
Response: Explanatory Notes: Describe the documented procedure to initiate an investigation in case of any security incident, and ensure you include the following:
I. Person responsible for carrying out the investigation. II. Documentation that integrates the security incident file.
The documents in the file derived from the investigation must include at least the following:
I. General information of the shipment, service order. II. Transport request; confirmation of transport medium; identification of the transport operator (access records, exit records, security inspection records, etc.). III. Transport medium inspection formats; exit orders; records of collection, delivery, and receipt of foreign trade goods. IV. Videos from alarm systems, closed-circuit television, and video surveillance. V. Documentation generated by and for business partners, and customs authorities. VI. Unit tracking and monitoring report (GPS tracking).
E8. Profile of the Strategic Supervised Premise Acknowledgment of Receipt First Time: Renewal: Addition: Modification: The data you provide will replace the data you provided when you requested your authorization.
General Information The objective of this Profile is to ensure that strategic supervised premises have security practices and processes implemented in their facilities, focused on strengthening the supply chain and mitigating the risk of contamination of shipments with illicit products.
Interested parties seeking enrollment in the Certified Companies Registry under the Strategic Supervised Premise modality referred to in rule 7.1.4., must demonstrate that they have documented and verifiable processes; likewise, they must integrate the criteria required in this document according to the business model or design they have established, seeking during the implementation of security standards, the application of a risk analysis culture supported by decision-making in accordance with the values, mission, vision, codes of ethics, and conduct of the company itself.
What is established in this Profile must be accredited independently of the requirements and guidelines established for control, surveillance, access routes, infrastructure, equipment, and security of foreign trade goods established by ANAM to grant the Strategic Supervised Premise authorization, and compliance can be proven with that which coincides with what is established in this Profile.
Filling Instructions:
I. You must fill out a Profile of the Strategic Supervised Premise for each of the facilities that have authorization as a strategic supervised premise. The number of Profiles presented must coincide with the facilities that have authorization for the temporary introduction of foreign, national, or naturalized goods into strategic supervised premises, to be subject to handling, storage, custody, exhibition, sale, distribution, elaboration, transformation, or repair in accordance with articles 14, 14-D, and 135-A of the Law manifested in your application for enrollment as a certified company under the strategic supervised premise modality, as well as indicating all domiciles registered with the RFC.
II. Detail how you comply with or exceed what is established in each of the subsections as indicated.
III. The format of this document is divided into two sections, as detailed below:
a) Points to highlight...
IV. Indicate how you comply with what is established in each of the sub-standards, therefore you must attach the procedures in Spanish that are required, if applicable, or provide a detailed explanation of what is requested in the Response field.
The section regarding Explanatory Notes is intended to be used as a guide regarding the points that must be included in the Response or in the attached procedures, as appropriate, each sub-standard, indicating indicatively those points that should not be excluded from your response.
V. Once the Profile of the Strategic Supervised Premise is answered, you must attach it to the Application for Registration in the Company Certification Scheme referred to in the first paragraph of rule 7.1.4., fraction IV.
For the purpose of verifying what is stated in the previous paragraph, the SAT through the AGACE may carry out an inspection of the installation indicated here, with the exclusive purpose of verifying what is stated in this document.
VI. Any incomplete Profile of the Strategic Supervised Premise will not be processed.
VII. Any question related to the Application for Registration in the Company Certification Scheme and the Profile of the Strategic Supervised Premise, direct it to the contacts that appear on the SAT Portal.
VIII. In the case of being authorized with the Registration in the Company Certification Scheme, this format must be kept updated and notify when the circumstances under which the registration was granted have varied and as a result changes or modifications are required in the information provided and given in this Profile of the Strategic Supervised Premise to the authority in accordance with what is established in rule 7.2.1., third paragraph, fractions III and IV.
IX. When, as a result of the inspection visit, non-compliances related to minimum security standards result, the applicant may remedy them before the issuance of the resolution established in rule 7.1.6., for which they will have a maximum period of three months counted from the notification of the non-compliances indicated.
Installation Data A Profile of the Strategic Supervised Premise must be filled out for each of the facilities that operate under the Strategic Supervised Premise authorization and that carry out handling, storage, custody, exhibition, sale, distribution, elaboration, transformation, or repair processes of foreign trade goods.
Installation Information Profile Number of the Strategic Supervised Premise: of RFC Key Name and/or Trade Name: Name and/or Denomination of the Installation Type of Installation Street Number and/or exterior letter Number and/or interior letter Neighborhood Postal Code Municipality/Delegation Federal Entity Age of the installation (years of operation): Activity performed in the installation: Preponderant products handled in the Strategic Supervised Premise: (As applicable) Avg. number of monthly shipments (EXP): Avg. number of monthly shipments (IMP): Total number of employees at this installation: Installation surface (m2): Certifications in security programs: (Indicate if this installation has a certification from any of the following programs) CTPAT. Yes No Level: Pre-Applicant: Applicant: Certified: Certified/ Validated: CTPAT Account number (8 digits): Date of last visit at this installation: Authorized Economic Operator from other countries (AEO) Yes No Program: Registration: Other Supply Chain Security Programs Yes No Program: Registration:
Certifications: (Indicate if you have certifications that you consider impact your supply chain process, for example: ISO 9000; Reliable Logistics Processes, among others) Name: Category: Validity: Name: Category: Validity: Name: Category: Validity: Name: Category: Validity:
Similarly, the company must have designated points of contact for the Authorized Economic Operator Program, such personnel must be involved and know the requirements of the Authorized Economic Operator, belong to the company, and prove their relationship with it, as well as respond to their supply chain security specialist, (this is assigned once the company already has the Authorized Economic Operator Program).
If, as a result of the risk analysis, new security measures arise to be incorporated into the premise, these must be included in the premise's existing procedures and, if applicable, new procedures must be elaborated, which creates a more sustainable structure and emphasizes that supply chain security is everyone's responsibility.
1.1 Risk analysis. The strategic supervised premise must establish measures to identify, analyze, and mitigate security risks that could result in alterations of foreign trade goods during their handling, storage, custody, and transport in its supply chain and installations, under the guideline of a documented procedure. Such analysis must be based on its organization's model (example: type of goods, volume, clients, routes, information leakage, potential threats, etc.), so that it allows implementing and maintaining security measures. In accordance with the above, the strategic supervised premise must also have a written process based on its risk analysis to select new business partners and monitor those with whom it is already working.
This procedure must be updated at least once a year, so that it allows permanently identifying other risks or threats considered in its operation and in the supply chain, as a result of a security incident or when changes originate in the initial conditions of the premise, as well as to identify that policies, procedures, and other control and security mechanisms are being complied with. It is important to note, that the premise's Security Committee must participate in the elaboration and update of the risk analysis and the maintenance of the Authorized Economic Operator Program.
Response: Explanatory Notes: Indicate what are the sources of information used to qualify risks during the analysis phase.
Attach the risk matrix, as well as the documented procedure to identify risks in the supply chain and the premise's installations, which must include at least the following points:
I. Periodicity with which it reviews and/or updates the risk analysis. II. Aspects and/or areas of the premise that are incorporated into the risk analysis. III. Methodology or techniques used to perform the risk analysis. IV. Persons responsible for reviewing and/or updating the premise's risk analysis.
Likewise, the documented procedure to identify risks in the supply chain and its installations must contemplate the risk appreciation and management process, and include the following aspects:
I. Establishment of a context (cultural, political, legal, economic, geographic, social, etc.). II. Identification of risks in its supply chains and its installations. III. Risk analysis (causes, consequences, probabilities, and existing controls to determine the level of risk as high, medium, and low). IV. Risk evaluation (decision-making to determine the risks to be treated and priority to implement treatment). V. Risk treatment (application of alternatives to change the probability of risks occurring).
It is suggested to use administration, management, and risk evaluation techniques in accordance with international standards ISO 31000, ISO 31010, and ISO 28000 that, according to your business model, should be implemented.
1.2 Security policies. Strategic supervised premises must have a policy oriented to prevent, secure, and recognize threats in the security of the supply chain and company installations, such as drug trafficking, money laundering, arms trafficking, human trafficking, prohibited goods, and acts of terrorism.
To promote a culture of security, companies must demonstrate their commitment to supply chain security and the Authorized Economic Operator Program through a statement highlighting the importance of protecting the flow of national and international commerce from criminal activities, established through the security policy.
Senior officials or executives of the company who must endorse and sign the security policy can be the premise's president, chief executive officer, general manager, or personnel with equivalent rank with decision-making authority.
Response: Explanatory Notes: Enumerate the security policy oriented to prevent, secure, and recognize threats in the supply chain and company installations, indicate who is responsible for its review, signature, and dissemination to employees, as well as the periodicity with which its update is carried out.
Such policy must be communicated to employees through a dissemination program and/or campaign.
The security policy must be signed by a senior official of the company and be displayed in various areas of the company, including the company website, posters in key areas of the premise company (reception, shipments, receipts, warehouse, etc.), and as part of the company's initial and reinforcement training.
1.3 Internal audits in the supply chain. In addition to routine monitoring in control and security, it is necessary to schedule and carry out periodic audits that allow evaluating all processes regarding security in the supply chain in a more critical and deep manner, as well as guaranteeing that employees follow the premise's security procedures.
Audits must be carried out by the company's Security Committee establishing a documented procedure, as well as a program or calendar for their realization. Although it is necessary that audits are focused on supply chain security and based on the evaluation, review, and execution of minimum security standards, their focus must be adjusted to the size of the organization, level of risk, business model, and variations between installations. Audits can be general or focus on specific areas or processes according to their work program.
The objective of an internal audit focused on the Authorized Economic Operator Program is to verify and guarantee that employees follow the premise's security procedures. The review process does not have to be complex, however, the formats and records used for the application of such reviews must evidence that the application and execution of the evaluated processes were validated, in addition to the corresponding follow-up of identified observations.
Senior management of the organization must review audit results, analyze causes, and undertake required corrective or preventive actions. The audit process must ensure that the necessary information is collected to allow management to perform this evaluation. The review must be documented, and the Facility Security Committee must provide and register periodic updates on the progress or results of any audit, exercise, or validation.
Response: Explanatory Notes: Describe the documented procedure to carry out an internal audit, focused on supply chain security, ensuring you include the following points: I. Indicate how the company carries out the scheduling or calendarization to perform an audit on supply chain security. II. Indicate who participates in them, the records kept thereof, and the frequency with which they are carried out. III. Indicate how the senior management of the facility verifies the results of security audits, how it carries out and/or implements preventive, corrective, and improvement actions, as well as the follow-up and closure thereof. IV. The formats used during internal audits must be properly filled out, and through them, evidence that security procedures and measures are being put into practice.
1.4 Contingency and/or emergency plans related to supply chain security. A documented contingency and/or emergency plan must exist; this plan must address crisis management, security recovery plans, and business resumption, to ensure business continuity in the event of a situation that affects the normal development of activities and foreign trade operations of the facility in its supply chain (on the premises and during the transport, handling, storage, and custody of foreign trade merchandise in accordance with its logistical process). A crisis or contingency may include the interruption of the transmission and exchange of commercial data due to a cyberattack, a fire, the kidnapping of a transport driver by armed persons, a customs closure, a bomb threat, the detection of suspicious packages, a power outage, theft and/or damage to merchandise, threats or extortion, blockades or road closures, among others.
Such plans must be communicated to personnel through periodic training, as well as conducting tests, practical exercises, and annual simulations of the contingency and emergency plans to verify their effectiveness; records of these must be kept, properly filled out and signed (for example: result reports, minutes, or reports, which must be backed by video recordings, photographs, etc., demonstrating their execution).
Response: Explanatory Notes: Attach the documented contingency and/or emergency procedure or plan, to ensure business continuity in the event of an emergency or security situation that affects the normal development of foreign trade activities of the facility in its supply chain (on the premises, during the transport, handling, storage, and custody of foreign trade merchandise in accordance with its logistical process). This procedure must include, by way of example and not limitation, the following: I. What situations it contemplates, describing the action plan and steps to be followed in case of crisis, as well as the tasks assigned to personnel during the handling of such contingencies. II. What mechanisms it uses to disseminate and ensure that these plans are effective. III. Contemplate the scheduling and carrying out of tests, practical exercises, and annual simulations, and how they are documented (for example: result reports, minutes, or reports, which must be accompanied by video recordings, photographs, etc., demonstrating their execution).
2.1 Facilities. Facilities must be constructed with materials that can resist unauthorized access. Periodic documented inspections must be carried out to maintain the integrity of the structures, and in the event that an irregularity is detected, the corresponding repair must be carried out as soon as possible by the personnel designated for these tasks. Likewise, territorial limits, various access points, internal routes, and the location of buildings must be fully identified.
Response: Explanatory Notes: Indicate the predominant materials with which the installation is constructed (for example, metal structure and sheet metal walls, brick walls, wood, among others), and indicate how the review and maintenance of the integrity of the structures is carried out. Indicate the personnel or area responsible for carrying out inspection, maintenance, and repair tasks for facility damages. Attach a general distribution or architectural plan, where the limits of the facilities, access routes, emergency exits, location of buildings, critical areas, parking lots, and boundaries can be identified.
2.2 Access at doors and booths. The entry or exit doors for personnel and/or vehicles must be attended, controlled, watched, and/or supervised. The number of access doors must be kept to the minimum necessary. Access to sensitive areas must be restricted according to the job description or assigned tasks.
Response: Explanatory Notes: Indicate how many doors and/or accesses exist in the facilities, as well as the operating hours of each, and indicate how they are monitored (in case of having assigned personnel, indicate the quantity). Detail if there are blocked or permanently closed doors and/or accesses. Describe how you ensure that access to sensitive areas is restricted according to the job description or assigned tasks (include the type of records and controls you use).
2.3 Perimeter walls. Perimeter walls and/or peripheral barriers must be installed to secure the perimeters of the strategic supervised facility's premises, based on a risk analysis. Fences, interior barriers, or a mechanism must be used to identify and segregate in a particular manner, the areas for storage, custody, and warehousing of high-value foreign trade merchandise, hazardous materials, areas with restricted access, and others determined in accordance with your risk analysis. These must be inspected regularly and carry a record of the review with the aim of ensuring their integrity and identifying damage, which must be repaired as soon as possible by the personnel designated for these tasks.
Storage, high-value, hazardous, and/or restricted access areas must be clearly identified and monitored to prevent unauthorized entry.
Response: Explanatory Notes: Describe the type of fence, peripheral barrier, and/or walls with which the installation is equipped, ensuring you include the following points: I. Specify which areas are segregated. II. Indicate the characteristics thereof (material, dimensions, etc.). III. In the event of not having walls, justify the reason in detail. IV. Frequency with which the integrity of perimeter walls is verified, and the records kept, with the aim of ensuring their integrity and identifying damage, which must be repaired as soon as possible. V. Indicate the personnel or area responsible for carrying out inspection and damage repair tasks. Describe how the cargo destined for foreign countries, hazardous material, and high-value material is segregated; ensure you include the following points: I. Indicate how you separate national merchandise and foreign trade merchandise, and if it is additionally identified (for example: different packaging, labels, wrapping, among others). II. Identify and indicate restricted access areas (hazardous merchandise, high value, confidential, etc.).
The procedure for inspecting perimeter walls could include: I. Personnel responsible for carrying out the process. II. How and with what frequency inspections of fences, perimeter walls, and/or peripheral barriers and buildings are carried out. III. How the inspection record is kept. IV. Who is responsible for verifying that repairs and/or modifications comply with the technical specifications and necessary security requirements.
2.4 Parking lots. Access to the facility's parking lots must be controlled and monitored by security personnel or personnel designated for this task. Private vehicles (of employees, visitors, suppliers, and contractors, among others) must be prohibited from parking within the merchandise handling and storage areas, as well as in adjacent areas.
Response: Explanatory Notes: Describe the procedure for the control and monitoring of parking lots, ensuring you include the following points: I. Those responsible for controlling and monitoring access to the parking lots. II. Identification of the parking lots (specify if the visitor and employee parking is separated from the merchandise storage and handling areas). III. How entry and exit of vehicles to the facilities is controlled. Indicate the records kept for parking control, the existing control mechanisms (for example: ticket stubs, card readers, badges, etc.), how they are assigned, and the responsible area for doing so. IV. Policies or mechanisms to prevent the entry of private vehicles into merchandise storage and handling areas.
2.5 Key and lock device control. Windows, doors, as well as interior and exterior fences, according to your risk analysis, must be secured with locking devices. The facility must have a documented procedure for the handling and control of keys and/or locking devices for interior areas considered critical. Likewise, a record must be kept and responsibility letters signed by persons who have keys or authorized access according to their level of responsibility and tasks within their work area.
Response: Explanatory Notes: Indicate if all doors, windows, interior and exterior entrances have closure or security mechanisms. Attach the documented procedure for the handling and control of keys and/or locking devices, ensuring they include the following points: I. Those responsible for administering and controlling key security. II. Format and/or control record for key lending. III. Treatment of loss or non-return of keys. IV. Indicate if there are areas where access is with electronic devices and/or some other access mechanism.
2.6 Lighting. Lighting inside and outside the facilities must allow clear identification of persons, material, and/or equipment located therein, including the following areas: entrances and exits, merchandise handling and storage areas, perimeter and/or peripheral walls, interior fences, and parking areas, and must have an emergency and/or backup system in sensitive areas.
Response: Explanatory Notes: Describe the procedure for the operation and maintenance of the lighting system. Ensure you include the following points: I. Indicate which areas are illuminated and which have a backup system (indicate if you have an auxiliary power plant or some other mechanism to supply electricity in the event of a contingency). II. How you ensure that the lighting system is appropriate in each of the facility's areas so as to allow clear identification of the personnel, material, and/or equipment located therein. III. Person responsible for controlling and maintaining the lighting systems. IV. Maintenance and review program (in case it coincides with another process, indicate it). The procedure may include: I. How the lighting system is controlled. II. Operating hours. III. Identification of areas with permanent lighting.
2.7 Communication devices. The strategic supervised facility must have communication devices and/or systems with the aim of contacting security personnel and/or authorities immediately in the event of an emergency and security situation. Additionally, it must have a backup system and verify its proper functioning periodically.
Response: Explanatory Notes: Describe the procedure that personnel must carry out to contact the facility's security personnel or, in their case, the corresponding authority in the event of any security incident. Indicate if operational and administrative personnel have or have access to devices (landlines, mobile phones, alert and/or emergency buttons, etc.) to communicate with security personnel and/or whoever corresponds (these must be accessible to users, to be able to react promptly). Indicate what communication devices the company's security personnel uses (landlines, cell phones, radios, alarm system, etc.).
Describe the procedure for the control and maintenance of communication devices, ensuring you include the following points: I. Policies for the assignment of mobile communication devices. II. Maintenance or replacement program for fixed and mobile communication devices. III. Indicate if you have backup communication devices, in the event that the permanent system fails, and, if applicable, describe them briefly. The procedure may include: I. Person responsible for the proper functioning and maintenance of communication devices. II. Record of verification and maintenance of devices. III. Method of assignment of communication devices.
2.8 Alarm systems, closed-circuit television, and video surveillance systems. Alarm systems, closed-circuit television, video surveillance systems, and security technologies must be used to monitor, notify, or deter unauthorized access and prohibited activities in the facilities and other considered sensitive areas, and to notify the corresponding area, as well as to be used as evidence in investigations derived from any incident.
These security systems and technologies must be placed according to a prior risk analysis, such that areas involving the access of personnel, visitors, suppliers, loading and unloading areas, storage, custody, and warehousing of foreign trade merchandise, security inspections of cargo vehicles, and other considered sensitive areas remain watched and monitored. Such systems must allow clear identification of the area or environment being watched and must be permanently recording and keep a backup of recordings for at least sixty days in accordance with what ANAM establishes for such effects, in relation to rule 4.8.17., and with the aim of having the necessary elements to disclaim corresponding responsibilities in the event of a security incident.
Alarm systems, closed-circuit television, video surveillance systems, and security technologies must have a documented operation procedure that includes supervision of the good condition of the equipment, verification of the correct position of the cameras, indicate the frequency with which recordings must be backed up, as well as those responsible for their operation. Such a system and all security technology infrastructure must have restricted access.
Response: Explanatory Notes: Mention the documented procedure in which the operation of the external alarm system or sensors is indicated, and if applicable, describe the following points: I. Indicate if doors and windows have alarm sensors, as well as the areas where motion sensors are available. II. Procedure to be followed in the event of an alarm activation. III. Indicate the personnel or area responsible for maintenance, how failures are reported, and the records they use. Describe the documented procedure for the operation of alarm systems, closed-circuit television, video surveillance systems, and security technologies (this must be reviewed and updated annually and in accordance with the risk analysis or circumstances), ensuring you include the following points: I. Indicate the number of security cameras of the alarm, closed-circuit television, and video surveillance systems installed, and their location by area (detail if it covers the entry and exit points of the facilities, to cover the movement of vehicles and individuals, as well as the place of foreign trade merchandise storage). Attach a layout or map of the distribution of security cameras. II. Indicate the location of the alarm, closed-circuit television, and video surveillance systems and security technologies, where the monitors are located, who reviews them, as well as the operating hours, and if applicable, if there are remote monitoring stations. All security technology infrastructure must be physically protected against unauthorized access. III. Periodic and random reviews of recordings must be carried out. Indicate how they review them randomly, each week, special events, restricted areas, etc., who is the designated personnel, and if management is involved in the reviews. The results of the reviews must be documented to include corrective actions for audit purposes. IV. Indicate for how long these recordings are kept (must be at least sixty days). V. Alarm, closed-circuit television, and video surveillance systems and security technologies must have an alternative energy source that allows these to continue functioning in the event of an unexpected loss of direct power. For the above, indicate if the alarm, closed-circuit television, and video surveillance systems and security technologies are backed up by an electrical power plant or some other mechanism to supply electricity, that guarantees their functioning. These systems should have an alarm/notification function, indicating a failure condition in functioning and/or recording; indicate if your systems have such a function. VI. Indicate if, in addition to the alarm, closed-circuit television, and video surveillance systems, you use some other type of technology to strengthen the security measures you already have. VII. Describe the procedure implemented to regularly test and inspect alarm, closed-circuit television, and video surveillance systems and security technologies and ensure their proper functioning. The results of the inspections and functional tests must be documented, as well as the necessary corrective actions (these must be implemented as soon as possible). Additionally, that the documented results of these inspections are kept for a sufficient time for audit purposes. VIII. Indicate if the provider of the alarm, closed-circuit television, and video surveillance systems has access to the security cameras, if they are in charge of monitoring them, how access is controlled, and who is responsible for said monitoring.
3.1 Security Personnel. The strategic supervised facility must have security and surveillance personnel. This personnel plays an important role in the physical protection of the facilities and merchandise during their transport and handling within the company, as well as for controlling the access of all persons to the premises. Security personnel must have a documented procedure to carry out their functions and have full knowledge of the mechanisms and procedures in emergency situations, detection of unauthorized persons, or any incident in the facility. Management must periodically verify compliance with procedures, policies, and functions through internal audits with the aim of verifying their correct execution.
Response: Explanatory Notes: Describe the documented procedure for the operation of security personnel, ensuring you include the following points: I. Indicate the number of security personnel working in the facility. II. Indicate the positions and/or functions of the personnel and operating hours.
III. In the event of hiring an external service, provide the general data of the company (RFC key, trade name, address), and specify the number of employees, operational details, records, reports, etc., that they use to perform their functions.
IV. In the event of having armed personnel, describe the procedure for the control and safeguarding of weapons.
3.2 Identification of employees. The management or security personnel of the premises must adequately control the delivery and return of badges, ID cards, and/or employee identification credentials. Procedures for the delivery, return, and exchange of access devices (for example, keys, badges, and/or credentials, proximity cards, etc.) must be documented. Access to sensitive areas must be restricted according to the job description or assigned tasks.
Response: Explanatory Notes: Describe the procedure for the identification of employees and ensure you include the following points:
I. Identification mechanisms (badge and/or photo credential, access control, biometrics, proximity cards, etc.).
II. How contracted personnel by a commercial partner, who work within the facilities (contractors, subcontractors, in-house services, personnel from merchandise handling companies, etc.) are identified.
III. The procedure must also describe how the premises deliver, change, and withdraw employee identification and access controls, and ensure you include the responsible areas for authorizing and administering them.
IV. Indicate how you ensure that access to sensitive areas is restricted according to the job description or assigned tasks (include the type of records and controls you use).
Attach the documented procedure for the control of identifications.
3.3 Identification of visitors and suppliers. To have access to the facilities, visitors and suppliers must present official identification with a photograph for documentation purposes upon arrival, and a record must be kept. All visitors and suppliers must receive a temporary identification, be accompanied by premises personnel during their stay in the facilities, and ensure that the visitor/supplier always wears the provided provisional identification in a visible place. This procedure must be documented. In the case of suppliers and users who work regularly in the premises, the company must have a physical validation system for identification badges in accordance with the control guidelines established by the customs office of its jurisdiction to grant entry and exit authorizations as applicable.
Response: Explanatory Notes: Describe the procedure for the access control of visitors and suppliers, ensure you include the following points:
I. Indicate what records are kept (personal formats for each visit, logbooks).
II. The record of visitors and suppliers must include the following: a) Date of the visit; b) Name of the visitor; c) Identification number with photo (official documents such as: driver's license, passport, INE, etc.). d) Time of entry and exit. e) In the case of vehicular access, the format must include the data of the private or cargo vehicle (model, license plate, trailer number, etc.).
III. Indicate who is the person responsible for accompanying the visitor and/or supplier and if there are restricted areas for their entry.
3.4 Procedure for identification and removal of unauthorized persons or vehicles. The strategic supervised premises must have documented procedures that specify how to identify, confront, or report unauthorized or identified persons and/or vehicles. This procedure must be communicated to responsible personnel through training. The training must be documented.
Response: Explanatory Notes: Attach the documented procedure to identify, confront, or report unauthorized or identified persons and/or vehicles. The procedure must include:
I. Responsible personnel.
II. Designate a person or area responsible for being informed of security incidents.
III. Instructions for confronting and addressing unidentified personnel.
IV. Indicate in which cases the corresponding authorities must be reported to.
V. How security incidents and measures adopted in each case are recorded.
3.5 Courier and package deliveries. Courier and package deliveries intended for the personnel of the strategic supervised premises must be examined upon arrival and before being distributed to the corresponding areas. Likewise, the premises must have a documented procedure for the receipt and review of courier and packages, which must be communicated to responsible personnel through training. The training must be documented.
Response: Explanatory Notes: Describe the procedure for the receipt and review of courier and packages and ensure you include the following:
I. Personnel in charge of carrying out the procedure.
II. Indicate how the courier and package service provider is identified (indicate if an additional procedure to the supplier access procedure is required).
III. Indicate how the review of the courier and/or packages is carried out, what mechanism is used, what records are kept, and in case, the detected incidents.
IV. Describe the characteristics or elements to determine which courier and/or packages are suspicious.
V. Indicate what action is taken in the event of detecting a suspicious package.
The risk analysis carried out by the premises regarding its commercial partners (clients and suppliers) must include risks related to the identification of activities related to money laundering and terrorism financing. Additionally, the premises must have a documented social compliance policy and program among its employees and commercial partners that, at a minimum, addresses how the company guarantees that the goods, inputs, or merchandise national and imported to Mexico for the elaboration of its final product, were not extracted, produced, or manufactured, totally or partially, with prohibited forms of work, that is, forced or compulsory, including forced or compulsory child labor under Article 23.6 of the T-MEC and the Agreement establishing the merchandise whose importation is subject to regulation by the Secretariat of Labor and Social Welfare, published in the DOF on February 17, 2023.
4.1 Selection criteria. There must be documented procedures for the selection, follow-up, and renewal of commercial relationships with business associates or suppliers, which include interviews, reference verification, evaluation methods, and use of provided information. The information derived from the investigation and/or evaluation of business associates and/or suppliers must be documented and integrated into a file (physical or electronic). The procedure for the selection of commercial partners must include, indicators to detect clients or suppliers that may not be legitimate or with unlocated addresses, in addition to investigations, reviews, or evaluations of said partners for the identification and control of activities related to money laundering and terrorism financing. If the investigation and/or evaluation of any commercial partner leads to substantial doubts about the veracity of their operations or services, the premises must avoid their hiring and, in case, notify its security specialist or Authorized Economic Operator Program contact and the corresponding authority about its suspicions.
Response: Explanatory Notes: Attach the documented procedure for the selection and contracting of new commercial partners and monitoring of partners with whom they are already working, this includes any type of supplier, this includes any type of supplier that has a commercial relationship with the premises (with its logistical process, with the supply chain, as well as with potential and predominant clients of hiring its service frequently and/or those that have a commercial relationship with your company), ensure you include the following points:
I. What information is required from your commercial partner.
II. What aspects are reviewed and investigated. The indicators to identify clients or suppliers that may not be legitimate (payments above the standard rate, in cash; having little knowledge of the merchandise to be sent; being evasive; minimal contact information (cell phone, contact points, emails, among others); recently created companies or businesses without commercial history, etc.) or with unlocated addresses. This point refers to pointing out all those alerts to determine that a commercial partner is not reliable and thus, carry out a deeper investigation and evaluate if you should work with them.
III. Indicate if you maintain a physical or electronic file of each of your commercial partners, as well as the information it must contain.
IV. Indicate how the services of your commercial partner are evaluated and what points you review. The file must include at least the following:
I. Company data (name, RFC key, activity, etc.).
II. Legal representative data.
III. Proof of address.
IV. Commercial references (if applicable).
V. Contracts, agreements, and/or confidentiality agreements, security policies.
VI. In case, certificate or certification number in the security programs to which they belong.
4.2 Security requirements. The strategic supervised premises must have a documented procedure in which, according to their risk analysis, request additional security requirements from those commercial partners who intervene in the service provided by the strategic supervised premises, as well as from service providers that likewise intervene in the control, manipulation, transport, and/or coordination of the merchandise subject to foreign trade such as: Transport, warehouses, providers of cleaning services, private security, personnel hiring, installation and maintenance of alarm and closed-circuit television and video surveillance systems, providers of Information Systems and Technologies, providers of loading, unloading, and merchandise handling services, collection and recycling, contractors, among others). The requirements must be based on the Profile of the Strategic Supervised Premises established by the AGACE, or in case, the specific Profile for each actor of the supply chain that corresponds to them. The company must request from its commercial partners the documentation that accredits and proves that they comply with the minimum security standards established in this Profile of the Strategic Supervised Premises, either through a written declaration issued by the legal representative of the partner, agreements or contractual clauses, backed by documentation that supports compliance with the requirements established in the Authorized Economic Operator Program. Likewise, the premises must take into account and know the specific requirements of the Authorized Economic Operator Program that will be applicable to each of its commercial partners, based on their activity within the supply chain.
In the case of commercial partners of the premises that provide their services within the facilities, they must be obliged to comply with these supply chain security requirements.
Response: Explanatory Notes: Describe the procedure that indicates how you carry out the identification of commercial partners that require compliance with minimum security standards. Ensure you include the following points:
I. Indicate if you have a register of commercial partners that must comply with security requirements, and mention what type of providers these are (carriers, warehouses, security companies, customs brokers, companies authorized to provide loading, unloading, and merchandise handling services, etc.).
II. Indicate in what documentary way (agreements, accords, contractual clauses, and/or addenda) you ensure that your commercial partners comply with security requirements.
III. Indicate if there are agreements, accords, contractual clauses, and/or addenda, regarding the implementation of security measures with your
service providers inside the premises, such as: private security, cafeteria, landscaping, cleaning and maintenance services, Information Technology providers, etc.
IV. Indicate if you have commercial partners to whom membership in a supply chain security program is required, (for example: CTPAT, or any other Authorized Economic Operator Program of the WCO) as well as the information and documentation that are requested of them.
4.3 Commercial partner reviews. The strategic supervised premises through the Security Committee must carry out periodic security evaluations (as well as derived from risk situations), of the processes and installations of business associates based on a risk analysis, to guarantee that they have minimum standards in terms of security required by the premises based on the Authorized Economic Operator Program, keep records of them, which allow to verify that the processes and security measures are being executed, as well as the corresponding follow-up.
When inconsistencies are found, the company must communicate them to its partner or supplier and provide a justified period to address the observations or areas of opportunity identified, or in case, have the necessary measures to sanction them.
Carrying out security evaluations of commercial partners is important to guarantee that there is a solid security program and functions correctly, that is why, in addition to a documented procedure, there must be a program or calendar for the execution of said reviews or security evaluations prioritizing partners that are more critical according to their risk analysis. If a member is not evaluated and the company does not know if the processes and installations of its commercial partners function correctly, they put their supply chain at risk.
Response: Explanatory Notes: Describe the procedure to carry out evaluations for the verification of security requirements (processes and installations) of your commercial partners, ensure you include the following points:
I. Periodicity with which visits to the commercial partner are made (these must be at least once a year and derived from risk situations).
II. Program or calendar for the execution of security reviews.
III. Record or report of the verification and in case the corresponding follow-up.
IV. The verification format(s) must be duly filled out, placing the date, name, and position of those participating in the review, signatures, etc.
V. Indicate what action measures are taken when commercial partners do not comply with the established security requirements.
VI. In case of having commercial partners with CTPAT certification or another supply chain security certification program, indicate the periodicity with which their status is reviewed, how you register it, and the actions you take in case it is detected that it is suspended and/or cancelled, according to what is established in your procedure. The procedure must include:
I. Periodicity of visits.
II. Points of review in terms of security.
III. Preparation of reports.
IV. Feedback and agreements with the commercial partner.
V. Follow-up to agreements.
VI. Measures in case of detecting non-compliance with requirements.
VII. Record of evaluations.
VIII. Area or person responsible for carrying out this procedure.
5.1 Process mapping. There must be a map that shows step by step the logistical process of the flow of merchandise and the required documentation through its international supply chain. The strategic supervised premises must take into account and include within its mapping all parties involved in its supply chain, containing those that handle import and export documentation, such as customs brokers, carriers, material suppliers, providers of loading, unloading, and merchandise handling services, among others.
Response: Explanatory Notes: Attach the document where the mapping of processes through which import and export merchandise passes is illustrated and described, from the point of origin until its delivery with the purpose of having well identified each of the steps that involve the elaboration and delivery of the final product. This mapping must contain at least the following aspects:
I. Origin of the merchandise: a) National or nationalized merchandise. b) Foreign merchandise for exhibition, sale, or distribution. c) Merchandise for elaboration, transformation, or repair. d) Merchandise whose origin or destination is the transfer to companies with SE programs.
II. Customs of clearance.
III. Transfers of merchandise.
IV. Delivery and/or receipt of the merchandise in national territory or return shipment to foreign countries including the process of acquisition of national goods.
V. Customs clearance that include provisions to designate merchandise subject to elaboration, transformation, repair, handling, storage, custody, exhibition, sale, distribution, and courier for the introduction of foreign, national, or
nationalized merchandise in strategic supervised premises and in case the return of processed goods in their same state.
VI. Destruction of waste or destination to the national market.
VII. Delivery to the consignee.
VIII. Management and operation of the Notice of transfer of merchandise from companies with IMMEX Program, RFE or Authorized Economic Operator.
IX. Information flow related to the merchandise.
5.2 Warehouses and distribution centers. When the strategic supervised premises has commercial partners that provide any warehouse, distribution center, or other service within its facilities, they must be subject to, according to their characteristics, what is established in this document, with the object of maintaining integrity in its supply chain.
Response: Explanatory Notes: According to the mapping of your logistical process, if foreign trade merchandise is transferred or moved to another warehouse and/or alternative or different distribution center that operates under your authorization as a strategic supervised premises, you must indicate if they are registered under your R.F.C. providing their general data (name and address) and briefly explaining what activity is carried out in that or those facilities (cross dock, temporary warehouse, etc.). Likewise, indicate if these belong to the company or is a service contracted through a third party and/or are part of a shareholder group. In this case, according to the supplier selection criteria mentioned in the section on Commercial Partners of this document, indicate how you ensure that they comply with minimum security requirements.
Facilities that have authorization as a Strategic Supervised Premises must coincide with the number of Profiles presented, as well as indicate all addresses that are registered under the RFC.
5.3 Delivery and receipt of cargo. The Strategic Supervised Premises must ensure the identification of transport medium operators who collect, deliver, or receive foreign trade merchandise within or outside their facilities, warehouses, and/or distribution centers. Likewise, the premises must designate the area responsible for supervising the loading or unloading of the shipment, including in accordance with instructions received from clients for its handling and transfer. On the other hand, the company must verify the detailed description of the merchandise, weight, labels, marks, and quantity, cross-referencing this information with the corresponding legal and customs documentation. The Strategic Supervised Premises, in accordance with its risk analysis, must have a process for the release and extraction of merchandise, establish parameters to inspect and verify through mechanisms, tools, or non-intrusive technology available, the foreign trade merchandise to be dispatched, independent of the official reviews that authorities may carry out with the purpose of identifying illicit, prohibited, undeclared merchandise, or merchandise with discrepancies, including those that, according to their nature, are subject to additional regulations or restrictions for customs compliance and transfer. Likewise, it must guarantee that the driver transporting foreign trade merchandise, during delivery or receipt, has the required documentary information for its transfer, which includes, destination, route to be maintained, contact data, and/or procedure in case of an incident or inspection by any authority, among others. The cargo preparation areas and the immediate surrounding areas must be inspected regularly to ensure that these areas remain free of visible pest contamination. During the loading and unloading process of merchandise, the company's security area (supervisor or security guard) must be present to validate that the process is being carried out correctly, mitigate the risk of shipment contamination (prohibited, illicit merchandise, or pests), and register said review (incident reports, records, reports, etc.) as evidence that the high-security seal and/or lock was placed correctly. Digital photographs must be taken at the moment of loading vehicles. Whenever possible, these images should be sent electronically to the destination or delivery contact point of the merchandise for verification purposes. Also, the personnel responsible for the shipping and/or receiving area must review the information included in import and/or export documents to identify or recognize suspicious cargo shipments. Likewise, specific training must be provided on the identification of common errors in export shipment documentation, with the aim of preventing these from resulting in security incidents or suspicious merchandise.
Response: Explanatory Notes: Attach the documented procedure indicating the procedure for the delivery and receipt of cargo and ensure that the following points are included: I. Method to identify transport operators. II. Documentation delivered to operators. III. Person responsible for supervising the loading or unloading of the merchandise and cross-checking the information. In addition to transport documents and customs documents (Bill of Lading, manifests, etc., which must be presented to the authority in a timely manner), there must be a record accompanying the entry and exit of merchandise, which includes: a) Date. b) Driver's name. c) Photo identification number (official documents such as: driver's license, passport, INE, etc.). d) High-security seal or lock number. e) Entry and exit time (the cargo record must be kept secure and drivers must not have access to it). f) In the case of vehicular access, the format must include the data of the cargo vehicle (model, license plate, trailer number, etc.). This record must be kept secure and drivers must not have access to it. The delivery and receipt of cargo should be by prior appointment, whenever the company's operation allows it and in a specific area or place so that it is monitored by security personnel, an employee, or alarm and closed-circuit television and video surveillance systems. IV. Management and operation of the Notice of Transfer of Merchandise from companies with IMMEX Program, RFE, or Authorized Economic Operator status. V. How it verifies and guarantees that the cargo preparation areas and the immediate surrounding areas remain free of visible pest contamination. In case any type of visible pest, contamination, trash, insects, grass, weeds, or tall grass is identified, how it is reported and what actions are taken regarding it. VI. Indicate who is responsible for taking digital photographs of the location and the placement of the high-security seal and/or lock, as well as of the merchandise loading process, and, if applicable, how they send them to the destination contact point or cargo delivery (including the seal and/or lock number(s)). VII. Indicate how it controls or what security measures it has implemented to mitigate the risk of collusion or complicity between employees, such as the driver and personnel in the dispatch, shipping, receiving, warehouse, security guards, etc. areas. VIII. Indicate if it performs permanent or random reviews of the luggage of transport operators who enter its facilities to deliver or pick up cargo. In case any anomaly is identified or there is suspicion, describe the actions taken regarding it. IX. How it validates that the cargo vehicles, containers, trailers, and semi-trailers used as International Traffic Instruments, which transport its merchandise, meet the necessary physical-mechanical conditions for their transfer and crossing. The cargo delivery and receipt procedure must include: I. Inspection method at the company's access point. II. Designation of the personnel responsible for receiving the driver and the merchandise upon arrival. III. Registration of the introduction of received merchandise into the Strategic Supervised Premises.
Attach the documented procedure to detect and report discrepancies in the delivery or receipt of merchandise and ensure that it includes the following points: I. Persons responsible for carrying out the review. II. Documents to be cross-referenced. III. Areas to which the information is reported. This procedure must be carried out on merchandise received from import, export; and if applicable, in the review at intermediate points.
5.4 Merchandise tracking procedure. In accordance with its risk analysis, the Strategic Supervised Premises must monitor the movement of foreign trade merchandise in its installation through a tracking and supervision diary of activities or technology during the arrival, storage, custody, and release of foreign trade merchandise to comply with customs clearance formalities, guaranteeing at all times to have the following information: number and information of the bill of lading, packing list, waybill, or other transport documents, as applicable, name and address of the consignee or sender, description, value, origin of the merchandise, and physical location in the premises. The foregoing must be accredited in accordance with the guidelines of a documented procedure. The supervision data and registration of all maneuvers in the Strategic Supervised Premises must be preserved for one year when the authority must carry out an evaluation due to a security incident or for audit purposes.
Response: Explanatory Notes: Attach the documented procedure to monitor internal transfers in the Strategic Supervised Premises of foreign trade merchandise. This procedure must include, among other aspects according to its operation: I. Have GPS whose external hardware is hidden and that can resist attempts to remove it, indicating the type of system implemented in its case, the query tools available to monitor the merchandise. II. Identification of estimated transfer times and maneuvers in Strategic Supervised Premises according to the type of transport involved. III. Detail the communication means available. IV. When the tracking is carried out by a third party, indicate who is responsible and how it is verified that it is being carried out correctly, in accordance with the procedures indicated by the company.
5.5 Report of discrepancies in cargo. There must be documented procedures that describe measures and actions to identify, detect, and report measures and/or actions to be taken in case of missing, excess, prohibited, illicit, undeclared merchandise during handling and transfer in the Strategic Supervised Premises or any other discrepancy in the delivery or receipt of containerized, consolidated, and/or de-consolidated merchandise prior to complying with customs clearance formalities or those that by their nature put the safety of users at risk, which could be during the following processes: reception, delivery, storage, prior reviews, consolidations, de-consolidations, transport medium yards, and if applicable, according to the services offered, with the purpose of having information that contributes to the corresponding investigations by authorized consignees and, if applicable, by competent authorities.
Response: Explanatory Notes: Attach the documented procedure to detect and report discrepancies in the delivery or receipt of merchandise and ensure that it includes the following points: I. Persons responsible for carrying out the review. II. Documents to be cross-referenced. III. Areas to which the information is reported. This procedure must apply both to merchandise received from import; if applicable, in the review at intermediate points; as well as in the final delivery of merchandise to its client.
5.6 Processing of cargo information and documentation. The Strategic Supervised Premises must have documented procedures to ensure that the electronic and/or documentary information used during the movement, storage, custody, maneuvers, and dispatch of cargo, as well as the information received from business associates, is legible, complete, accurate, reported in real time, and protected against changes, losses, or introduction of erroneous information. Likewise, forms and documentation related to import and/or export should be secured to prevent unauthorized use.
Response: Explanatory Notes: Describe the procedure for the processing of cargo information and documentation, ensure that you include the following points: I. Detail how you transmit relevant information and documentation for the transfer of your cargo with all those involved in your supply chain (indicate if you use a specific computer control system and briefly explain its function). Likewise, detail how you validate that the information provided is legible, complete, accurate, reported in real time, and protected against changes, losses, or introduction of erroneous information. II. Likewise, forms and documentation related to import and/or export should be secured to prevent unauthorized use. III. Indicate how business associates transmit information to the Strategic Supervised Premises and ensure its protection.
5.7 Inventory management, control of packaging, container, and packing material. The Strategic Supervised Premises must have documented procedures for automated inventory control, in accordance with its authorization to provide services for handling, storage, and custody of foreign trade merchandise; likewise, they must include abandonments, destructions, among others, in accordance with applicable regulations and conduct periodic reviews. Likewise, it must have a documented procedure for the control of packaging, container, and packing materials of the merchandise, which also includes the control, dissemination, and prevention procedure of visible pest contamination, in the case of use of wooden packing materials (such as pallets, boxes, crates, cages, spools, dunnage, chocks, supports, or platforms) to stack, move, and protect the cargo throughout its entire supply chain.
Response: Explanatory Notes: Attach the documented procedure for inventory management. This must include, according to its operation among other aspects, the following: I. Mention what type of system is used for information exchange with the authority for inventory purposes and its clients. II. Who is your supplier. III. Indicate if you have a contingency plan in case of system failures. IV. Mention where it is physically located and who are the responsible for its operation. V. The frequency with which it carries out stock verification (Periodic Inventory). Indicate if there is a scheduled documented calendar to carry them out or in accordance with the operational provisions of its clients. VI. Indicate what is done, in case of excesses and shortages in inventories and communication with its clients. VII. Indicate the treatment given to the control and handling of packaging, container, and packing material, which also includes the control, dissemination, and prevention procedure of visible pest contamination, in the case of use of wooden packing materials (such as pallets, boxes, crates, cages, spools, dunnage, chocks, supports, or platforms) to stack, move, and protect the cargo. VIII. This point is also focused on reducing the risk of introduction or dissemination of pests of quarantine importance to the country through packaging (imports), therefore, describe how it complies with the provisions indicated by SEMARNAT and NOM-144-SEMARNAT-2017, in concordance with International Standard for Phytosanitary Measures No. 15, known as Regulation of Wood Packaging Material Used in International Trade, which emanate from the Food and Agriculture Organization of the United Nations. IX. Indicate how the fumigation process is to kill, inactivate, sterilize, desiccate, or eliminate pests. What actions are taken in case quarantine of packing materials is required. X. Indicate the area responsible for carrying out this process, as well as the documentation or certificates obtained. The applicant's procedures may include: I. Warehouse only accessible to authorized personnel. II. Control of incoming merchandise, transfers to other warehouses, consolidation or de-consolidation. III. Actions taken if irregularities, discrepancies, losses, or thefts are identified. IV. Treatment of deterioration or destruction of merchandise. V. Separation of various types of merchandise, for example, high value, hazardous.
6.1 Customs clearance management. The Strategic Supervised Premises must have a documented procedure in which criteria are established for the selection of a customs broker or, if applicable, a customs representative, who, in accordance with national legislation, are authorized to promote on behalf of others the clearance of merchandise.
Response: Explanatory Notes: Describe the selection and evaluation procedure of the customs broker/representative and ensure that it includes the following points: I. Selection criteria. II. Evaluation methods and periodicity. III. Describe the indicators with which you evaluate the service of customs brokers. Indicate the full name and patent number and/or authorization of the customs broker or representative authorized to promote your foreign trade operations.
6.2 Customs obligations. The Strategic Supervised Premises must have a documented procedure that establishes how it maintains updated control of automated inventories of foreign trade merchandise and online with the authority permanently and uninterruptedly, in accordance with what is established in article 59, fraction I, of the Law and the information referred to in rule 4.8.3. and Annex 24. Additionally, it must include at least the following: a) the process to comply with security measures, control surveillance, access routes, infrastructure, and surface equipment; b) processes related to equipment to expedite customs clearance relative to electronic systems for the control of merchandise, persons, or vehicles that enter or leave the premises. The foregoing in accordance with provisions specific to its authorization. On the other hand, it must include in the procedure the process of destruction of waste or destination in the national market or loss of merchandise in accordance with current regulations, transfers of merchandise to supervised and/or strategic premises, transfers for maintenance, repair, or calibration of machinery and/or equipment.
Response: Explanatory Notes: Attach the procedure to comply with your customs obligations. Attach the procedure(s) for compliance with rules 1.5.3., 1.6.13., and 1.6.17., as applicable.
6.3 Customs verification. The Strategic Supervised Premises, in order to verify the truthfulness of the information declared in its name before competent authorities, must have documented procedures so that the personnel designated by the company periodically verifies that the customs entries registered in its accounting match what appears registered in SAAI Web and, if applicable, report to the customs authority any discrepancy in said information. The company, likewise, must have a procedure for the filing of customs entries for their proper control.
Response: Explanatory Notes: Attach the procedure established to verify the information registered in SAAI Web, and cross-reference with the customs entries and documentation requested from the customs broker and/or customs representative.
In the event of using high-security seals, it is necessary to have procedures to correctly seal and maintain the integrity of containers and trailers from the moment they leave your facilities. A high-security seal must be applied to all containers and trailers for foreign trade shipments, which must meet or exceed the ISO 17712 standard for high-security seals.
With the aim of maintaining supply chain security, the controlled facility must systematically inspect all cargo vehicles upon entry and exit from its facilities (domestic and international traffic), in addition to keeping a record.
7.1 Use of seals and/or padlocks on containers. The strategic controlled facility, where applicable, must identify the means of transport, own or subcontracted, that transport foreign trade merchandise that may be: maritime, air, national land, cross-border, rail, and/or multimodal, which are subject to the placement of seals and/or padlocks to meet or exceed the ISO 17712 Standard with the aim of guaranteeing the integrity of the cargo at all times.
Therefore, as one of the security mechanisms, the strategic controlled facility, where applicable, must use padlocks or high-security seals that meet or exceed the ISO 17712 Standard in all loaded containers and trailers that are subject to foreign trade and maintain their integrity until delivery at the final destination. To this end, the facility must have documented procedures for placing and verifying the correct application of seals, their inspection at intermediate points, final destination, and their replacement when opened by any authority. In the event of such an inspection, drivers must notify and register any unusual anomaly or structural modification found in the means of transport resulting from said review. The procedures must include the steps to follow if it is discovered that a seal is altered, manipulated, or if there is an incorrect seal number in the documentation, the communication protocols with the commercial partners involved in the supply chain, and the investigation of the security incident; these must be notified to security personnel, commercial partners who may be part of the affected supply chain, security specialist, or contact of the Authorized Economic Operator Program.
Likewise, it is necessary to have a documented procedure for the administration of same, which includes control, assignment, safeguarding, handling of discrepancies, and destruction of seals and padlocks (the latter is mandatory whenever seals are broken within your facilities). Regarding the provider of the seals and/or padlocks, it must be demonstrated how these comply with the ISO 17712 Standard. The company's management or a security supervisor must perform periodic and documented audits of the high-security seals and/or padlocks; these reviews must include the verification of the inventory of stored seals and/or padlocks and the cross-checking with inventory records and shipping documents. Also, supervisors of the shipping area and/or warehouse managers must periodically verify the seal numbers used in the means of transport and International Traffic Instruments to corroborate that the information is correct.
For this case, the strategic controlled facility must have a documented procedure in which, in accordance with its risk analysis, it supervises the placement of seals and/or padlocks on the means of transport that transfer foreign trade merchandise in accordance with its logistics process and in those traffics that require it due to their high probability of occurrence and impact of the identified risk and during maneuvers within the facility. In it, it must evidence controls that allow accrediting that it supervises the portability of seals and/or padlocks derived from entries or exits of the strategic controlled facility in the means of transport. In all cases, it must use the VVTT inspection method to mitigate improper manipulations as follows:
I. V - View the seal and lock mechanisms of the container. II. V - Verify the seal number. III. T - Pull the seal to ensure it is correctly placed. IV. T - Twist and turn the seal to ensure.
Response: Explanatory Notes: List, according to your risk analysis and logistics process, the means of transport that are subject to the placement of high-security seals and/or padlocks. Attach the documented procedure for the supervision of placement and review of seals and/or padlocks on vehicles, means of transport, containers, trailers, and/or semi-trailers that transport foreign trade merchandise. This must include, among other aspects according to your operation: I. The use of seals and/or padlocks that meet or exceed the ISO 17712 standard. II. If applicable, use the VVTT inspection method. III. Review and cross-check the documentation containing the number of the original seal or padlock for purposes of entry or exit of strategic controlled facilities. If a replacement seal and/or padlock is used, said number must be registered within the control of the strategic controlled facility. If altered seals and/or padlocks are identified, they must be kept to help carry out the investigation of said incident or discrepancy. IV. Indicate how you assign and replace high-security padlocks, in the case of maneuvers such as prior recognition, replacement, among others.
If applicable, attach the documented procedure for the control and handling of seals and/or padlocks; this must include, among other aspects according to your operation: I. What type of seals and/or padlocks you use in your operations (foreign trade, transit, storage, etc.). II. Who has access and how the padlocks and/or seals are safeguarded. The management of seals and/or padlocks must be restricted only to authorized personnel; stored in a secure place, have an inventory, control of their distribution and tracking (record of seals used, as well as of the receipt of new seals and/or padlocks). III. Describe how the company's management or the security supervisor participate in the audits of high-security seals and/or padlocks, the reviews they perform, the records they generate, and the actions they take in case of identifying discrepancies. Also, how the supervisors of the shipping area and/or warehouse managers verify the seal numbers used in the means of transport and International Traffic Instruments to corroborate that the information is correct (this process can also be included within the internal audits referred to in sub-standard 1.3 of this document). IV. How discrepancies in seal and/or padlock numbers are addressed. V. Indicate who the supplier(s) are and how it is proven that the specifications of the seals and/or padlocks comply with the ISO 17712 Standard (attach certificate issued by the certifying company responsible for verifying compliance with the corresponding ISO).
All written procedures must be disseminated and maintained at the operational level so that they are easily accessible to employees responsible for executing the tasks described above, reviewed at least once a year, and updated as necessary.
7.2 Inspection of means of transport, containers, trailers, and semi-trailers. There must be established procedures to verify the physical integrity of the structure of the means of transport container, train cars, trailers, and/or semi-trailers used as International Traffic Instruments, according to their nature, including the reliability of the lock mechanisms in them, with the aim of identifying natural or hidden compartments, as applicable.
The inspections of the means of transport or cargo vehicles, containers, and trailers must be systematic and carried out upon entry and exit from the company and, where applicable, at the cargo loading point; and if the infrastructure allows, before arriving at the dispatch customs using the VVTT inspection method, a record of these inspections must be kept in an access-controlled area and carried out in a place monitored by alarm and closed-circuit television and video surveillance systems; said system must cover the entire inspection process.
The documented procedure for its inspection must include, by way of example and not limitation, the following review points:
| Means of Transport | Trailers, Train Cars, Semi-trailers, and Containers |
|---|---|
| I. Bumper. | I. Exterior and interior doors. |
| II. Tires and rims (tractor and trailer). | II. Side walls (left and right). |
| III. Floor (tractor). | III. Internal and external roofs. |
| IV. Fuel tanks. | IV. Front wall. |
| V. Cabin interior (bedroom and tool compartment). | V. Internal floor. |
| VI. Air tanks. | VI. If applicable, the refrigeration system. |
| VII. Chassis. | |
| VIII. Fifth wheel area. | |
| IX. Drive axles. | |
| X. Exhaust pipe. | |
| XI. Engine. |
For means of transport with a trailer or integrated cargo compartment, the items indicated in the Trailers section must be added to the means of transport points.
Likewise, before loading the means of transport, containers, train cars, trailers, and semi-trailers used as International Traffic Instruments, they must undergo agricultural and security inspections to guarantee that their structures have not been modified to hide contraband or that they have not been contaminated with visible agricultural pests, keep a record, and be backed by a documented procedure. If visible pest contamination is found during the inspection or transport of merchandise subject to foreign trade, it must be cleaned (washed, vacuumed, etc.) to eliminate said contamination.
Response: Explanatory Notes: Attach the documented procedure to carry out the security and agricultural inspection of the means of transport according to their nature and logistics process involved in the entries and exits of the controlled facility. This must include, among other aspects according to your operation: I. Those responsible for carrying out the inspection. II. Definition of the place(s) where the inspection is carried out and indicate how the monitoring is performed by alarm and closed-circuit television and video surveillance systems. III. The security review points for means of transport, trailers, semi-trailers, containers, rail transport, and/or multimodal according to official provisions and agricultural inspections whose purpose is to search for visible pests.
Attach the format for the inspection of means of transport or cargo vehicles, containers, train cars, trailers, and/or semi-trailers. If you use other types of cargo vehicles for the transport of your merchandise (vans, pickup, 3.5 tons, tankers, etc.), your procedure and inspection format must include the process and review points.
Likewise, the security and agricultural inspection format must include the following information: I. Date of inspection; II. Time of inspection; III. License plates of the vehicle (tractor and trailer); IV. Container/trailer number; V. Specific areas of the cargo vehicles that were inspected; and, VI. Name of the employee who performs the inspection and the supervisor.
The security and agricultural inspection formats may be signed by the supervisor to corroborate their information and be part of the import and export documentation. The documentation must be kept for one year for an investigation in case of any security incident, as well as to demonstrate continuous compliance with these inspection requirements.
If deemed necessary, the vehicle inspection format could be part of the shipping documentation. Additionally, and according to the risk analysis, the company should perform random reviews of means of transport after the transport personnel has carried out means of transport inspections to verify that they have been carried out correctly, counteract internal conspiracies, and prevent security incidents. The reviews must be carried out randomly, without prior notice, so that they do not become predictable, in addition to being carried out in different places where the means of transport may be susceptible to contamination.
7.3 Storage of vehicles, means of transport, containers, train cars, trailers, and semi-trailers. When the means of transport, containers, trailers, and/or semi-trailers that will be destined to transport foreign trade merchandise are empty and must be stored in parking areas, they must be secured with a padlock and/or indicative seal, or in a secure area that is guarded and/or monitored.
When it is necessary to store any loaded container, trailer, and/or semi-trailer, it must be in a secure area that has physical barriers and is monitored by alarm and closed-circuit television and video surveillance systems, to prevent unauthorized access and manipulation of the merchandise, so it must be closed with a high-security padlock according to the ISO 17712 Standard.
Response: Explanatory Notes: Indicate if the company stores the containers, trailers, and/or semi-trailers for subsequent dispatch, or in the case of those that are empty and how it maintains their integrity within its facilities. I. In case of using padlocks and/or seals, indicate what type you use. II. In case of using any container, trailers, and/or semi-trailers as a storage area for raw material and/or any other type of merchandise, indicate how it maintains their integrity and security.
Likewise, there must be continuous training programs for personnel that disseminate the facility's security policies, as well as the consequences and actions to be taken in case of any breach or security incident.
8.1 Employment background verification. The strategic controlled facility must have documented procedures to investigate and verify the information stated in the resume, criminal records (if local legislation and company policies allow it), and applications of candidates with possible employment, in accordance with local legislation, either on their own or through an external company.
Likewise, for positions that by their sensitivity so require and affect the security of shipments that are subject to foreign trade, in accordance with their previously carried out risk analysis, they must consider requesting stricter requirements for their hiring, which must be carried out periodically. Regarding personnel who already work in the company, periodic investigations must be carried out based on the activities and/or sensitivity of the employee's position.
All information regarding personnel must be kept in personal files, which must have restricted access.
Response: Explanatory Notes: Describe the documented procedure for personnel hiring, and ensure you include the following: I. Requirements and documentation required. II. Tests and exams requested.
Indicate the areas and/or critical positions that have been identified as risky, according to your analysis, and indicate the following: I. Indicate what the additional requirements are for areas and/or specific jobs such as criminal records (if local legislation and company policies allow it), non-criminal record certificate, socioeconomic studies, clinical studies, toxicological (drug use), etc. If applicable, indicate the jobs or work areas in which they are required and with what frequency they are carried out. II. Indicate if, prior to hiring, the candidate must sign a confidentiality agreement or a similar document.
In case of hiring a service agency for personnel hiring, indicate if this has documented procedures for personnel hiring and how it ensures compliance with the same. Briefly explain what they consist of.
The procedures for personnel hiring and contractors may include: I. Thorough investigations of the work and personal backgrounds of new employees. II. Confidentiality and liability clauses in employee contracts. III. Specific requirements for critical positions. IV. If applicable, the periodic update of the socioeconomic and physical/medical study of employees who work in critical and/or sensitive areas. V. Hiring process and requirements requested for temporary employees and contractors.
The facility may consider the results of the background verifications of candidates, as allowed by current legislation, to make hiring decisions. Background verifications are not limited to identity and criminal record verification. In higher-risk areas, deeper investigations may be justified.
8.2 Personnel dismissal procedure. There must be documented procedures for personnel dismissal, which include the delivery of identification, and any other item that has been provided to perform their functions (keys, uniforms, badges and/or credentials, computer equipment, passwords, tools, etc.). Likewise, this procedure must include the dismissal in computer and access systems, among others that may exist.
Response: Explanatory Notes: Describe the procedure for personnel dismissal, and ensure you include the following: I. Who is responsible for carrying out and following up on this procedure. II. How the delivery of identification, access controls, and other equipment is carried out and confirmed. III. Indicate the control record and/or format, in which the delivery of material and dismissal in computer systems is identified and ensured (if applicable, attach). IV. Indicate the type of records of personnel who ended their labor relationship with the company, so that when it was for security reasons, their service providers and/or business associates are warned.
8.3 Personnel administration. The strategic controlled facility must maintain an updated system, control, or database of active employees. Likewise, it must carry out and keep updated the records of affiliation to social security institutions and other legal labor records.
In the event that the company has personnel contracted by its commercial partners and works within the facilities, it must ensure that they comply with the requirements established for the rest of its employees.
Response: Explanatory Notes: Indicate if the facility has an updated system, control, or database, both of personnel employed directly, as well as that contracted through a service provider company, and ensure it includes, by way of example and not limitation, the following points: I. Full name. II. Updated photograph at least every five years. III. Personal data (age, name, date of birth, phone number, address, CURP, social security number, blood type, allergies, etc.). IV. Affiliation. V. Work background. VI. Diseases. VII. Medical exams. VIII. Training. IX. Results of periodic evaluations. X. Observations.
This personnel must be hired in accordance with the current labor laws and regulations.
9.1 Classification and handling of documents. There must be procedures to classify documents according to their sensitivity and/or importance. Sensitive and important documentation must be stored in a secure area that only allows access to authorized personnel. The useful life of the documentation must be identified and procedures for its destruction must be established.
The company must conduct regular reviews to verify access to information and ensure that it is not used improperly.
Answer: Explanatory Notes: Attach the documented procedure for the registration, control, and storage of printed documentation (classification and filing of documents) which must include: I. Control register for delivery, loan, and other documents. II. Restricted access to the archive area. III. Storage and classification policies. IV. An updated security plan describing the measures in place regarding the protection of documents against unauthorized access, as well as against deliberate destruction or loss thereof. V. In the case of electronic or digital information, it must adhere to the security criteria of sub-standard 9.2 Information Technology Security.
9.2 Information Technology Security. To protect Information Technology systems against common cybersecurity threats, a company must have sufficient protection that promotes security in the Information Technology infrastructure (software and hardware) against malware (viruses, spyware, worms, trojans, etc.), baiting, phishing, and internal/external intrusions (firewalls) in the companies' computer systems. Likewise, companies must ensure that their security software is active and receives periodic updates.
In the case of automated systems and computer equipment, individual accounts requiring periodic password changes must be used. In order to protect the confidentiality, integrity, and availability of information, the company must have established information technology policies, procedures, and standards, which must be communicated through a training program for all employees who handle computer equipment and systems, including topics to prevent attacks through social engineering and all those threats to which they are exposed (malware, baiting, phishing, etc.). Companies that allow employees to connect remotely to a network must use secure technologies, such as virtual private networks (VPN), to allow employees to access the company intranet securely when they are outside the office, as well as procedures designed to prevent unauthorized remote access by users.
For the above, there must be written procedures and infrastructure to protect the company against loss, theft, leakage, hacking, and/or ransomware of information; this includes the procedure for the recovery (or replacement) of information technology systems and/or data, as well as a system or software established to identify the abuse of information technology systems and detect inappropriate access and/or improper manipulation or alteration of business and commercial data, as well as a written procedure for the application of appropriate disciplinary measures to all offenders. Access to Information Technology systems must be protected against infiltration through the use of secure passwords, which include phrases or other forms of authentication. Users of said Information Technology systems must safeguard and not share their access keys or passwords. All Information Technology infrastructure must be physically protected against unauthorized access.
If a data leak or other unexpected event occurs resulting in the loss of data and/or equipment, the procedures must include the recovery or replacement of Information Technology systems and/or data.
Answer: Explanatory Notes: Attach the procedure for the recovery or replacement of information technology systems and/or data, which includes how it backs up and ensures the security of its information, in addition to protecting it from possible losses. Ensure you include the following points: I. Indicate the frequency with which information backups are carried out. II. Who has access to them and who authorizes the recovery of the information. III. Indicate what type of tests are performed and how often, to verify the security of the network, systems, and infrastructure. IV. Mention whether, to perform this type of tests or vulnerability scans, it is done through software, a third party, or provider, and if so, indicate the name or corporate name. V. In case vulnerabilities are found, describe the corrective actions that must be implemented. VI. Indicate if you share information about cybersecurity threats with your business partners participating within your supply chain (for example: press releases, bulletins, emails, etc.). VII. Systems must be protected by passwords and must be modified frequently; therefore, indicate the procedure for changing them. VIII. Indicate if there are information security policies for their protection.
IX. There must be a system or software to detect and identify the abuse, intrusion, or access of unauthorized persons to your systems and/or Information Technology data (any system that is used by the premises), as well as the abuse of policies and procedures established by the company, including unauthorized access to internal systems, external websites, and the manipulation or alteration of commercial data by employees or contractors. X. All offenders must be subject to the application of disciplinary measures; therefore, indicate the corrective policies and/or sanctions in case of detection of any violation of Information Technology security systems and policies. The Information Technology and cybersecurity policies and procedures must be reviewed annually and updated following an attack or according to situations that may put the premises' systems at risk. Describe the security measures used to allow employees to connect remotely to a network (VPN), to allow employees to access the premises' intranet remotely when they are outside the office. In case of allowing employees to use personal devices to perform the company's work, such devices must comply with the premises' cybersecurity policies and procedures, security updates must be periodic, and there must be a method to access the premises' network securely. Indicate if business partners have access to the premises' computer systems. If so, indicate what programs they use and how they ensure access control to them.
Indicate if the computer equipment has a backup power supply system that allows business continuity. The procedures regarding the backup of the premises' information must also include: I. How and for how long the data is stored (data should be backed up once a week or as appropriate). II. Business continuity plan in case of incident and how to recover the information. III. Frequency and location of backups and archived information. IV. If backups are stored in alternative sites to the facilities where the data processing center is located. V. Tests of the validity of data recovery from backups. The procedures regarding the protection of the premises' information must also include at least the following: I. An updated and documented policy for the protection of the premises' computer systems against unauthorized access and deliberate destruction or loss of information. All sensitive and confidential data must be stored in an encrypted or encoded format. II. Detail if you operate with multiple systems (branches/sites) and how such systems are controlled. III. Who is responsible for the protection of the premises' computer system (responsibility should not be limited to one person, but to several, so that each can control the actions of the others).
IV. Each user's access must be assigned through individual accounts and restricted according to the job description or assigned tasks. Therefore, describe how access authorizations and access levels to computer systems are granted (access to sensitive information must be limited to authorized personnel to make modifications and use the information). Authorized access must be monitored by the area responsible for granting it, to verify or, if applicable, report that access to confidential systems is based on job requirements. V. Indicate the elements or format that passwords must have for access to Information Technology systems and computer equipment, frequency of changes, if there are other authentication methods, and who or what area provides those passwords. VI. Indicate the name of the firewall and antivirus used (include licensing-related information), evidencing that this security software is active and receives periodic updates. For the above, cybersecurity policies and procedures should include measures to prevent the use of counterfeit technological products or those with incorrect licenses (software and hardware). All computer equipment, electronic media (hard drives, cell phones, etc.), and Information Technology hardware containing confidential information related to the import and export process must be accounted for through periodic inventories and have such evidence. When these technological equipment must be disposed of, there must be a documented procedure that includes how they must be formatted, disinfected, or destroyed appropriately to avoid information leakage. VII. In case of employee departure, access to computer equipment, telecommunications, and the network must be eliminated at the moment of the employee's separation; this includes email accounts, system access accounts, software, programs, etc. VIII. Measures planned to handle incidents when the system is compromised.
10.1 Training and awareness on threats. The strategic supervised premises must have a training and awareness program on supply chain security policies directed at all its employees (operational and administrative) and, additionally, make available informational material regarding the procedures established in the company to consider a situation that threatens its security and know how to report it. Likewise, specific training must be offered according to their functions to help employees maintain cargo integrity, perform container, trailer, and/or semi-trailer reviews for agricultural and security purposes, receive and review mail and packages, prevent operations with proceeds of illicit origin (money laundering, terrorist financing, etc.), how to recognize and report internal conspiracies, protect access controls, as well as training regarding smuggling, cargo theft, placement of high-security seals and locks (VVTT inspection method), prevention of visible pest contamination, etc. These topics must be established as part of new employee onboarding and periodically maintain update programs. Update training must be carried out periodically, after a security incident, and when there are changes in the premises' procedures. In addition to security training programs, an awareness program on alcohol and drug consumption must be included. Also, disseminate and train staff on the company's cybersecurity policies, procedures, and standards (theft, leakage, hacking, and/or ransomware of information), including access to computer equipment and systems via passwords or phrases. Personnel who operate and administer security technology systems must receive training related to their operation and maintenance, including self-training through operational manuals and other methods. These topics must be established as part of new employee onboarding and periodically maintain update programs.
Training programs must foster active employee participation in security controls and mechanisms, as well as maintain records of all training efforts provided by the company and the list of those who participated in them (videos, photographs, minutes, attendance lists, intranet, or other system, didactic material, PowerPoint presentations, brochures, etc.). Records must include the date of the training, the names of attendees, the topics taught, in addition to having measures to verify that the training provided met all training objectives. Answer: Explanatory Notes: You must have a training program on security and prevention in the supply chain for all employees working for the company (administrative, operational, direct, and indirect). Briefly explain what the training program consists of and ensure you include the following: I. Brief description of the topics taught in the program. II. When they are taught (onboarding, specific periods, following audits, security incidents, etc.). III. Frequency of training, as well as updates and reinforcement. IV. Indicate how participation in supply chain security training is documented (videos, photographs, minutes, attendance lists, intranet, or other system, didactic material, PowerPoint presentations, brochures, etc.). Training records must include the date, the names of attendees, the topics taught, in addition to having measures to verify that the training provided met all its objectives. V. Explain how employee participation in supply chain security matters is fostered.
Training to perform reviews of cargo vehicles, containers, trailers, and/or semi-trailers for agricultural and security purposes must include the following topics: I. Signs of hidden compartments. II. Smuggling hidden in natural compartments. III. Signs of pest contamination. IV. Procedures to follow if something is found during a transport medium inspection or if a security incident occurs during transit. V. Training on agricultural reviews must cover pest prevention measures, the regulatory requirements applicable to wooden packaging materials in accordance with the International Standards for Phytosanitary Measures known as Regulation of Wooden Packaging Used in International Trade, which emanate from the United Nations Organization for Food and Agriculture and the identification of infested wood.
10.2 Awareness for transport medium operators. The strategic supervised premises must inform the operators of the transport means used for the transfer of goods destined for foreign trade about the security policies regarding agricultural and transport medium security inspection procedures, loading and unloading, security incident management, lock changes in case of inspection by other authorities, among others, that are implemented. Operators and personnel who perform agricultural and security inspections of transport means must be trained to inspect cargo vehicles for such purposes. In the case where the transport service is provided by a business partner, you must ensure that operators know all established security policies and procedures.
Answer: Explanatory Notes: Describe the dissemination program on supply chain security focused on transport medium operators and ensure you include the following: I. Indicate how this dissemination is carried out. II. Indicate the topics covered. III. In case of using a business partner's services for the transfer of your goods, indicate how operators are informed about the premises' security policies and procedures. IV. Indicate how participation in supply chain security training of transport medium operators is documented (videos, attendance lists, brochures, etc.). The topics that must be included, by way of example and not limitation, are: I. Access and security policies at the facilities. II. Delivery-receipt of goods (including suspicious cargo shipments). III. Confidentiality of cargo information. IV. Transfer instructions. V. Accident and emergency reports. VI. Instructions for the placement of high-security locks and/or seals in transit (placement of a new one, review after any authorized stop, etc.). VII. Installation and testing of security alarms and unit tracking, where applicable. VIII. Identification of authorized formats and documents to be used. IX. Signs of hidden compartments. X. Smuggling hidden in natural compartments.
XI. Signs of pest contamination. XII. Procedures to follow if something is found during a transport medium inspection or if a security incident occurs during transit.
11.1 Reporting of anomalies and/or suspicious activities. In case of detection of anomalies and/or suspicious activities related to supply chain security and in accordance with your logistical processes (related to access control, delivery, receipt, and storage of goods, security inspections of cargo vehicles and transport operators, etc.), these must be reported to security personnel, business partners who may be part of the affected supply chain, security specialist or Authorized Economic Operator Program contact, and other competent authorities, keeping a record of said anomalies and/or unusual activities. Answer: Explanatory Notes: Describe the procedure to denounce or report anomalies and/or suspicious activities, as well as the mechanisms to anonymously report problems related to security, and ensure you include the following: I. Who is responsible for reporting incidents. II. Detail how you determine and identify with which authority to communicate in different scenarios or presumption of suspicious activities. III. Mention if you keep a record of anomaly and/or suspicious activity reports and briefly describe what it consists of.
11.2 Investigation and Analysis. Written procedures must exist to report or flag anomalies and/or suspicious activities, as well as the analysis and investigation of security incidents in the supply chain to determine their cause, as well as corrective actions to prevent them from recurring, which must be implemented as quickly as possible. The information derived from this investigation must be documented and available at all times to authorities that so require. This information must include the documentation generated to carry out the foreign trade operation of the affected goods, allowing identification of each of the processes the goods went through until the point where the incidence was detected and allowing recognition of the vulnerability of the chain. Response: Explanatory Notes: Describe the documented procedure to initiate an investigation in case any security incident occurs and ensure you include the following: I. Person responsible for carrying out the investigation. II. Documentation that makes up the investigation file. The documents to be included in the file resulting from the investigation, in an enumerative but not exhaustive manner, may be: I. General information about the shipment, service order. II. Transport request; confirmation of means of transport; identification of the transport operator (access records, exit records, security inspection records, etc.). III. Inspection forms for means of transport; exit orders; records of collection, delivery and receipt of foreign trade merchandise. IV. Videos from alarm systems, closed-circuit television and video surveillance. V. Documentation generated for the carrier (packing list, bill of lading, instruction sheet). VI. Documentation generated by and for commercial partners and customs authorities.
E9. Railway Carrier Profile Acknowledgment of Receipt First Time: Renewal: Addition: Modification: The data provided will replace the data provided when requesting your authorization. General Information The objective of this Profile is to ensure that the railway transport concessionaire company develops and implements security practices and processes that secure its supply chain by mitigating the risk of contamination of its traction and trailing equipment (boxcars, gondolas, hoppers, tank cars, containers, chassis, trailers, platforms, etc., which do not have their own traction and circulate on railway tracks and are used to transport merchandise inside them and in containers) with illicit products, as well as loss or theft of merchandise and/or any other factor that could compromise the security of the supply chain. Concessionaire railway transport companies interested in obtaining the authorization referred to in rule 7.1.5. must have documented and verifiable processes. Likewise, the railway transport concessionaire company interested in the aforementioned authorization must integrate the criteria required in this document into the business model or design it has established, seeking during the implementation of security standards the application of an analytical culture that supports decision-making consistent with the company's values, mission, vision, codes of ethics and conduct. During the completion of this document, those interested in obtaining certification will analyze their logistical processes, identifying risks that affect the supply chain and providing treatment to reduce these risks. Primarily those related to origin and destination points, routes, facilities, volume of operations, yard security, previous security incidents, and interaction with commercial partners. Filling Instructions: I. You must fill out a Railway Carrier Profile of the main installation and/or terminal where services for export and import are generated, railway equipment is used and safeguarded, and yards are used for storing containers with foreign trade merchandise. II. Describe in detail how the railway carrier complies with or exceeds what is established in each of the subsections as indicated. III. The format of this document is divided into two sections, as detailed below:
Installation Information Railway Carrier Profile Number: of RFC Key Name and/or Business Name: Name and/or Installation Designation Type of Installation Street Number and/or exterior letter Interior number and/or interior letter Neighborhood Postal Code Municipality/Delegation Federal Entity Age of Installation (years of operation) Predominant activity Type of service (General/Specialized Cargo): Avg. No. of monthly shipments (EXP): Avg. No. of monthly shipments (IMP): Total No. of employees at this installation: Installation surface area (m2): Certifications in security programs: (Indicate if this installation has a certification from any of the following programs) CTPAT Yes No CTPAT Account Number (8 digits): ______________________________ Date of the Last Visit: ____________________ Level: Pre-Applicant: Applicant: Certified: Certified/Validated: Authorized Economic Operator from other countries (AEO) Yes No Program: ______________________________________________________________ Other Supply Chain Security Programs Yes No Program ______________________________
Registration: ____________________
Certifications: (Indicate if you hold certifications that you consider impact your supply chain process, e.g.: ISO 9000; Reliable Logistics Processes, among others) Name: Category: Validity: Name: Category: Validity:
Response: Explanatory Notes: Attach the risk matrix and the documented procedure used to identify risks in your daily operations throughout the supply chain and its facilities. It must include at minimum the following points: I. Frequency with which this procedure is carried out. II. Indicate which segments, routes, and/or areas of the railway transport concessionaire company are incorporated into the risk analysis. III. Type of service: Domestic and international transit. Likewise, the documented procedure to identify risks in the supply chain and its facilities must contemplate the risk assessment and management process and include the following aspects: I. Establishment of a context (cultural, political, legal, economic, geographic, social, etc.). II. Identification of risks in its supply chains and its facilities. III. Risk analysis (causes, consequences, probabilities, and existing controls to determine the level of risk as high, medium, and low). IV. Risk evaluation (decision-making to determine risks to be treated and priority for implementing treatment). V. Risk treatment (application of alternatives to change the probability of risks occurring). VI. Risk monitoring and review (monitoring the results of the risk analysis and verifying the effectiveness of its treatment). It is suggested to use administration, management, and risk evaluation techniques in accordance with international standards ISO 31000, ISO 31010, and ISO 28000 that, according to your business model, must be implemented.
1.2 Security Policies. The Railway Transport Concessionaire Company must have policies oriented towards preventing, securing, and recognizing threats to the security of the supply chain and the company's facilities, such as drug trafficking, arms trafficking, human smuggling, prohibited merchandise, acts of terrorism, as well as information exchange, reflected and supported in the applicable procedures. To promote a security culture, companies must demonstrate their commitment to supply chain security and the Authorized Economic Operator Program through a statement highlighting the importance of protecting the flow of national and international commerce from criminal activities, established through the security policy. Senior officials or executives of the company who must endorse and sign the security policy may include the company president, chief executive officer, general manager, security director, or personnel with equivalent rank with decision-making authority. Response: Explanatory Notes: State the railway carrier's security policy oriented towards preventing, securing, and recognizing threats to the supply chain and all of the company's facilities. Indicate who is responsible for its review, signature, and dissemination to employees, as well as the frequency with which its update is carried out. The security policy must be signed by a senior official of the company and displayed in various areas of the enterprise, including the website, posters in key areas (reception, loading, receiving, warehouse, etc.), and as part of initial and reinforcement training. 1.3 Internal Audits in the Supply Chain. In addition to routine monitoring in control and security, it is necessary to schedule and carry out audits at least once a year that allow evaluating all supply chain security processes in a more critical and profound way, as well as ensuring that employees follow the company's security procedures. Audits must be carried out by the company's Security Committee and a documented procedure must be established, as well as a program or calendar for their execution. Although it is necessary that audits are focused on supply chain security and based on the evaluation, review, and execution of minimum security standards, their focus must be adjusted to the size of the organization, level of risk, business model, and variations between facilities. Audits can be general or focus on specific areas or processes according to their work program. The objective of an internal audit focused on the Authorized Economic Operator Program is to verify and guarantee that employees follow the company's security procedures. The review process does not have to be complex; however, the forms and records used for the application of these reviews must evidence that the application and execution of the evaluated processes were validated, in addition to the follow-up and closure of preventive, corrective, and improvement actions identified. The senior management of the organization must review the results of the audits and undertake the required corrective or preventive actions. The audit review process must guarantee that the necessary information is collected to allow management to make this evaluation. The review must be documented, and the company's Security Committee must provide and record periodic updates on the progress or results of any audit, exercise, or validation.
Response: Explanatory Notes: Describe the documented procedure to carry out an internal audit, focused on supply chain security. Ensure you do not exclude the following points: I. Indicate how the company carries out the scheduling or calendarization to perform an internal audit on supply chain security. II. Indicate who participates in them, the records made thereof, and the frequency with which they are carried out. III. Indicate how the company's management verifies the results of security audits, how it performs and/or implements preventive, corrective, and improvement actions, in addition to the follow-up and closure of same. IV. The forms used during internal audits must be properly filled out, and through them, evidence that security procedures and measures are being put into practice. 1.4 Contingency and/or Emergency Plans. A documented contingency and/or emergency plan must exist. This plan must address crisis management, security recovery plans, and business resumption to ensure business continuity against incidents of any kind that affect the normal development of the operations of the railway transport concessionaire company. A crisis or contingency may include the interruption of commercial data movement due to a cyberattack, a fire, the kidnapping of a transport driver by armed individuals, a customs closure, a bomb threat, the detection of suspicious packages, a power outage, theft and/or damage to merchandise, threats or extortion, blockades or road closures, among others. Such plans must be communicated to administrative and operational staff through periodic training, as well as conducting tests, practical exercises, and annual drills of the contingency and emergency plans to verify their effectiveness. Records of these must be properly filled out and signed (for example: result reports, minutes, or reports, which must be backed by video recordings, photographs, etc., demonstrating their execution). The contingency and/or emergency plan must be updated as necessary, based on changes in operations and the organization's risk level.
Response: Explanatory Notes: Attach the contingency and/or emergency procedure or plan focused on the supply chain and its facilities, relating those risk events that can affect the carrier's functioning, such as accidents during the route (derailments, fires, runovers, blockages, robberies, accidents, mechanical failures, customs closures, etc.) to ensure business continuity. This procedure must include, in an enumerative but not exhaustive manner, the following: I. What situations it contemplates, describing the action plan and steps to be taken in case of crisis, as well as the tasks assigned to personnel during the handling of such contingencies. II. What mechanisms it uses to disseminate and ensure that these plans are effective. III. Contemplate the scheduling and execution of tests, practical exercises, and annual drills and how they are documented (for example: result reports, minutes, or reports, which must be accompanied by video recordings, photographs, etc., demonstrating their execution). In the case of transporting Hazardous Materials and Waste, an emergency sheet indicating the actions to be taken in case of incident or accident (leaks, spills, explosions, fires, etc.) must be attached. 2. Physical Security. The railway transport concessionaire company must have established mechanisms to prevent, detect, or dissuade unauthorized personnel from entering its facilities, terminals, yards, where traction and trailing equipment (boxcars, gondolas, hoppers, tank cars, chassis, trailers, platforms that do not have their own traction and circulate on railway tracks and are used to transport merchandise inside them and in containers) are safeguarded. All sensitive areas of the company must have physical barriers, control elements, and deterrents against unauthorized access.
2.1 Installations. Installations must be constructed with materials capable of resisting unauthorized access. Documented periodic inspections must be carried out to maintain the integrity of the structures, and in the event that an irregularity is detected, the corresponding repair must be carried out as soon as possible by the personnel designated for these tasks. Likewise, the territorial boundaries, as well as the various accesses, internal routes, and the location of the buildings, must be fully identified. Response: Explanatory Notes: Indicate the predominant materials with which the installations are constructed (for example, metal structure and sheet walls, brick walls, wood, among others) and indicate how the review and maintenance of the integrity of the structures is carried out. Indicate the personnel or area responsible for carrying out the inspection, maintenance, and repair of damage to the installations. Attach a general distribution or architectural plan, where the boundaries, access routes, parking lots, critical areas, borders, and the location of the offices, and the terminal's classification yards can be identified.
2.2 Accesses at doors and booths. The entrance or exit doors of vehicles and/or personnel accessing the railway operation yards and/or administrative offices must be attended and/or supervised either by own personnel or by a private security company. The number of access doors must be kept to the minimum necessary. Access to sensitive areas must be restricted according to the job description or assigned tasks. Response: Explanatory Notes: Indicate how many doors and/or accesses exist in the installations, as well as the operating hours of each, and indicate how they are monitored (if personnel is assigned, indicate the quantity). Detail if there are doors and/or accesses that are blocked or permanently closed. Describe how you ensure that access to sensitive areas is restricted according to the job description or assigned tasks (include the type of records and controls you use).
2.3 Perimeter walls. Perimeter walls and/or peripheral barriers must be installed to ensure the company's parameters, based on a risk analysis. These must be inspected regularly and keep a record of the review in order to ensure their integrity and identify damage, which must be repaired as soon as possible by the personnel designated for these tasks. In the case of providing railcar storage services, this zone must be clearly delimited, identified, and monitored according to the service required (national or international, as well as high-value and dangerous) to prevent unauthorized entry. Response: Explanatory Notes: Describe the type of fence, peripheral barrier, and/or walls that the company has, ensuring that the following points are not excluded: I. Indicate their characteristics (material, dimensions, etc.). II. In case of not having walls, justify the reason in detail. III. Frequency with which the integrity of the perimeter walls is verified, and the records that are kept in order to ensure their integrity and identify damage, which must be repaired as soon as possible. IV. Indicate the personnel or area responsible for carrying out the inspection and repair of damage tasks. V. Indicate how your railway operation yards are divided. VI. Briefly describe how you separate railcars or domestic and/or international cargo containers, empty, under repair and/or maintenance, workshops, among others. The procedure for the inspection of perimeter walls could include: I. Personnel responsible for carrying out the process. II. How and with what frequency the inspections of the fences, perimeter walls and/or peripheral walls and buildings are carried out. III. How the inspection record is kept. IV. Who is responsible for verifying that the repairs and/or modifications meet the technical specifications and necessary security requirements.
2.4 Parking lots. Access to the parking lots of the installations must be controlled and monitored by security personnel or personnel designated for this task. Private vehicles (of employees, visitors, suppliers, and contractors, among others) must be prohibited from parking within the operational areas for handling and storage of traction and towing equipment (boxcars, gondolas, hoppers, tank cars, chassis, trailers, platforms that do not have their own traction that circulate on the railway tracks and that are used to transport cargo inside and in containers), as well as in adjacent areas. Response: Explanatory Notes: Describe the procedure for the control and monitoring of parking lots, ensuring that the following points are not excluded: I. Those responsible for controlling and monitoring access to the parking lots. II. Identification of the parking lots (specify if the parking lot for employees, visitors, is separated from the traction and towing equipment, (boxcars, gondolas, hoppers, tank cars, chassis, trailers, platforms that do not have their own traction that circulate on the railway tracks and that are used to transport cargo inside and in containers) and cargo handling. III. How the entry and exit of vehicles to the installations is controlled. Indicate the records that are made for the control of the parking lot and the existing control mechanisms, (for example: badges, card readers, lanyards, etc.), how they are assigned and the responsible area for doing so. IV. Policies or mechanisms to not allow the entry of private vehicles to the areas for storing means of transport and, in their case, handling of cargo.
2.5 Control of keys and lock devices. According to the risk analysis, windows, doors, and interior and exterior fences must be secured with locking devices. The railway carrier must have documented procedures for the handling, safeguarding, assignment, and control of keys in the installations of the interior areas that have been considered critical, keeping a record and establishing signed responsibility letters from the persons who have keys or authorized access according to their level of responsibility and work within their work area. The management of the railway transport concessionaire company will be responsible for controlling the keys of the sensitive or restricted areas of its installations. Response: Explanatory Notes: Indicate if all doors, windows, interior and exterior entrances have locking or security mechanisms. Attach the documented procedure or procedures for the control, safeguarding, assignment, and handling of the keys of the installations, offices, and interior areas. Ensure that these procedures do not exclude the following points: I. Those responsible for administering and controlling the security of the keys. II. Format and/or control record for the loan of keys. III. Treatment of loss or non-return of keys. IV. Indicate if there are areas where access is gained with electronic devices and/or some other access mechanism.
2.6 Lighting. Lighting inside and outside the installations must allow for clear identification of people, material, and/or equipment located there, including the following areas: entrances, exits, parking areas, repair and maintenance yards, rolling stock, perimeter walls and/or peripheral barriers, interior fences, loading and unloading, etc. An emergency and/or backup system must be available in sensitive areas. Response: Explanatory Notes: Describe the procedure for the operation and maintenance of the lighting system. Ensure that the following points are included: I. Indicate which areas are illuminated and which have a backup system (indicate if you have an auxiliary power plant) or some other mechanism to supply electrical energy in case of any contingency. II. How do you ensure that the lighting system is appropriate in each of the company's areas, so that it allows for clear identification of the personnel, material, and/or equipment it covers. III. Person responsible for the control and maintenance of the lighting systems. IV. Maintenance and review program (if it coincides with another process, indicate it). The procedure may include: I. How the lighting system is controlled. II. Operating hours. III. Identification of areas with permanent lighting.
2.7 Communication devices. The railway transport concessionaire company must have devices and/or communication systems in order to have immediate contact with security personnel and/or emergency and security authorities when required. Additionally, a backup communication system must be available and its proper functioning must be verified periodically. Response: Explanatory Notes: Describe the procedure that personnel must carry out to contact security personnel or, in their case, the corresponding authority in case of any incident. Indicate if operational and administrative personnel have or have access to devices (landline phones, mobile phones, alert and/or emergency buttons) to communicate with security personnel and/or whoever corresponds (these must be accessible to users, to be able to react promptly). Indicate what communication devices the security personnel of the railway transport concessionaire company use (landline phones, cell phones, radios, alarm system, etc.). Describe the procedure for the control and maintenance of communication devices, ensuring that the following points are not excluded: I. Policies for the assignment of mobile communication devices. II. Maintenance or replacement program for fixed and mobile communication devices. III. Indicate if you have backup communication devices when the system fails permanently, and in its case, detail briefly. IV. Indicate if the company's crew uses telephones, radios, cell phones, citizen band (CB), or some other means for their internal communication and the policies for the assignment of the same. The procedure may include: I. Person responsible for the proper functioning and maintenance of communication devices. II. Record of verification and maintenance of the devices. III. Method of assignment of communication devices.
2.8 Alarm systems and closed-circuit television and video surveillance systems. Alarm systems, closed-circuit television, and video surveillance systems, and security technologies, must be used to monitor, notify, or deter unauthorized access and prohibited activities in the installations and other considered sensitive areas, notify the corresponding area, in addition to being used as a tool of proof in investigations derived from any incident. These security systems and technologies must be placed, monitored, and monitored according to a prior risk analysis in such a way that areas involving the access of personnel, visitors, suppliers, loading, unloading, and cargo vehicles are kept under surveillance and monitoring, as well as sensitive areas, and also the areas where traction and towing equipment (boxcars, gondolas, hoppers, tank cars, chassis, trailers, platforms that do not have their own traction that circulate on the railway tracks and that are used to transport cargo inside and in containers) are normally located. Such systems must allow for clear identification of the area or environment being monitored, be recording permanently, and keep a backup of the recordings for at least one month, considering that, in the case that your logistical processes exceed this period, the period for maintaining these backups must be increased, in order to have the necessary elements to assign corresponding responsibilities in case of a security incident. Alarm systems, closed-circuit television, and video surveillance systems, and security technologies, must have a documented operation procedure that includes the supervision of the good condition of the equipment and the verification of the correct position of the cameras, indicating the frequency with which the backup of the recordings must be performed, as well as those responsible for their operation. Such a system and all security technology infrastructure must have restricted access. Response: Explanatory Notes: Mention the procedure in which it indicates the functioning of the external alarm system or sensors, and in its case, describe the following points: I. Indicate if doors and windows have alarm sensors or motion sensors. II. Procedure to follow in case an alarm is activated. Describe the documented procedure for the operation of alarm systems, closed-circuit television, and video surveillance systems, and security technologies, (this must be reviewed and updated annually and according to the risk analysis or circumstances), ensure that the following points are included: I. Indicate the number of cameras of the alarm systems, closed-circuit television, and video surveillance systems installed, technical characteristics, and their location (detail if it covers the entry and exit points of the installations, to cover the movement of vehicles and individuals, as well as the place of storage of the vehicles). II. Indicate the location of the alarm systems, closed-circuit television, and video surveillance systems, and security technologies where the monitors are located, who reviews them, as well as the operating hours, and in its case, if there are remote monitoring stations. All security technology infrastructure must be physically protected against unauthorized access. III. Periodic and random reviews of the recordings must be carried out. Indicate how they are reviewed (random, every week, special events, restricted areas), who is the designated personnel, and if management is involved in the reviews. The results of the reviews must be documented to include corrective actions for audit purposes. IV. Indicate for how long these recordings are kept (it must be at least one month). V. Alarm systems, closed-circuit television, and video surveillance systems, and security technologies, must have an alternative energy source that allows them to continue functioning in case of an unexpected loss of direct power. For the above, indicate if the alarm system, closed-circuit television, and video surveillance system, and security technologies, are backed up by an electrical power plant, which guarantees their functioning. These systems should have an alarm/notification function, which indicates a failure condition in the functioning and/or recording, indicate if your systems have such a function. VI. Indicate if, in addition to the alarm systems, closed-circuit television, and video surveillance systems, you use some other type of technology to strengthen the security measures you already have. VII. Describe the procedure that has been implemented to regularly test and inspect the alarm systems, closed-circuit television, and video surveillance systems, and security technologies, and ensure their proper functioning. The results of the inspections and the functional tests must be documented, as well as the necessary corrective actions (these must be implemented as soon as possible). Additionally, that the documented results of these inspections are kept for a sufficient time for audit purposes. VIII. Indicate if the provider of alarm systems, closed-circuit television, and video surveillance systems, has access to the security cameras, if they are in charge of monitoring them, how access is controlled, and who is responsible for said monitoring.
3.1 Security personnel. The railway transport concessionaire company must have security and surveillance personnel. This personnel plays an important role in the physical protection of the installations, of the yards and/or the place where the traction and towing equipment (boxcars, gondolas, hoppers, tank cars, containers, chassis, trailers, platforms that do not have their own traction that circulate on the railway tracks and that are used to transport cargo inside and in containers) are stored, as well as for controlling the access of all people to the property. Security personnel must have a documented procedure to carry out their functions, and have full knowledge of the mechanisms and procedures in emergency situations, detection of unauthorized persons, or any incident in the installations. Management must periodically verify compliance with procedures, policies, and functions through internal audits with the objective of verifying their correct execution. Response: Explanatory Notes: Describe the documented procedure for the operation of security personnel, and ensure that the following points are not excluded: I. Indicate the number of security personnel working in the company. II. Indicate the positions and/or functions of the personnel, and operating hours. III. In case of hiring an external service, specify the number of personnel employed, operational details, records, reports, etc. IV. In case of having armed personnel, describe the procedure for the control and safeguarding of weapons.
3.2 Identification of employees, visitors, and providers. There must be an identification system for employees, visitors, and providers for the purpose of access to the installations. Employees should only have access to those areas they need to perform their functions. Visitors and providers must present official identification with a photograph upon arrival and a record must be kept. All visitors and providers must receive a temporary identification, be accompanied by company personnel during their stay in the installations, and ensure that the visitor/provider always wears the provisional identification provided in a visible place. This procedure must be documented. The management or security personnel of the railway transport concessionaire company must properly control the delivery and return of identification badges for employees, visitors, and providers, and ensure that they always wear the provided identification in a visible place. This procedure must be documented, as well as the procedures for the delivery, return, and change of access devices (for example, keys, proximity cards, etc.). Access to sensitive areas must be restricted according to the job description or assigned tasks. Response: Explanatory Notes: Attach the documented procedure for the control of identifications. Describe the procedure for the identification of employees, and ensure that the following points are not excluded: I. Identification mechanisms (Badge with photo, uniform, etc.). II. Indicate if employees use uniforms, how they are assigned (by position, area, functions, etc.) and withdrawn (in their case). III. Indicate how personnel hired by a business partner, who works within the installations (contractors, Sub-contractors, etc.) is identified. The procedure must also describe how the company delivers, changes, and withdraws employee identifications and access controls, and ensure that you include the responsible areas for authorizing and administering them. Indicate how you ensure that access to sensitive areas is restricted according to the job description or assigned tasks (include the type of records and controls you use). Describe the procedure for the access control of visitors and providers, ensuring that the following points are included: I. Indicate what records are kept (personal forms for each visit, logbooks). II. The record of visitors and providers must include the following: a) Date of the visit; b) Name of the visitor; c) Identification number with photo (official documents such as: driver's license, passport, INE, etc.); d) Time of entry and exit. e) In the case of vehicle access, the format must include the data of the private or cargo vehicle (model, plate, number of trailer, etc.). III. Indicate who is the person responsible for accompanying the visitor and/or provider, and if there are restricted areas for their entry.
3.3 Procedure for identifying and removing unauthorized persons or vehicles. The railway transport concessionaire company must have documented procedures that specify how to identify, confront, or report unauthorized or unidentified persons and/or vehicles.
Response: Explanatory Notes: Attach the documented procedure to identify, confront, or report unauthorized or unidentified persons and/or vehicles. The procedure must include: I. Responsible personnel. II. Designate a person or area responsible for being informed of incidents. III. Instructions for confronting and addressing unidentified personnel. IV. Indicate in which cases the corresponding authorities must be reported to. V. How the recording of incidents and the measures taken in each case is carried out.
3.4 Courier and package deliveries. Courier and package deliveries intended for personnel of the railway transport concessionaire company must be examined upon arrival and before being distributed to the corresponding area. Likewise, the company must have a documented procedure for the receipt and review of courier and package deliveries, which must be communicated to responsible personnel through training. The training must be documented.
Response: Explanatory Notes: Describe the procedure for the receipt and review of courier and package deliveries and ensure that you do not exclude the following: I. Personnel in charge of carrying out the procedure. II. Indicate how the personnel or provider of the courier and package delivery service is identified (indicate if an additional procedure to the supplier access procedure is required).
III. Indicate how packages are reviewed and/or what mechanism is used, as well as the records kept and, if applicable, the incidents detected. IV. Indicate what action is taken in the event of detecting a suspicious package. V. Indicate how the inspection record is carried out and, if applicable, the incidents detected.
The risk analysis carried out by the company regarding its commercial partners (clients and suppliers) must include risks related to the identification of activities related to money laundering and terrorism financing. Additionally, the railway transport company must foster a documented social compliance policy and program that, at a minimum, addresses how its employees and commercial partners could ensure that national and imported goods, inputs, or merchandise for Mexico for the manufacture of products or merchandise do not originate from extraction, production, or manufacturing, total or partial, using prohibited forms of labor, that is, forced or compulsory labor, including forced or compulsory child labor, under Article 23.6 of the T-MEC and the Agreement establishing the goods whose importation is subject to regulation by the Ministry of Labor and Social Welfare, published in the DOF on February 17, 2023.
4.1 Selection criteria. There must be documented procedures for the selection, follow-up, or renewal of commercial relationships with business associates or suppliers, which include interviews, reference verification, evaluation methods, and use of provided information. The information derived from the investigation and/or evaluation of business associates and/or suppliers must be documented and integrated into a file (physical or electronic). The procedure for the selection of commercial partners must include indicators to detect clients or suppliers who may not be legitimate or with unlocated addresses, in addition to investigations, reviews, or evaluations of said partners for the identification and control of activities related to money laundering and terrorism financing. If the investigation and/or evaluation of any commercial partner leads to substantial doubts about the veracity of their operations or services, the company must avoid hiring them and, if applicable, notify its security specialist or Authorized Economic Operator Program contact and the corresponding authority about its suspicions.
Response: Explanatory Notes: Attach the documented procedure for the selection of new commercial partners and monitoring of partners with whom it is already working (this includes any type of supplier that has a commercial relationship with the company, which is in the following sub-standard where it is requested to differentiate those at risk in their supply chain) and ensure that you include the following points: I. What information is required from its commercial partner. II. What aspects are reviewed and investigated. III. The indicators to identify clients or suppliers who may not be legitimate (payments above the standard rate, in cash; having little knowledge of the merchandise to be shipped; being evasive; minimal contact information (cell phone, contact points, emails, among others), recently created companies or businesses without commercial history, etc.) or with unlocated addresses. This point refers to indicating all those alerts to determine that a commercial partner is not reliable and thus, carry out a deeper investigation and evaluate whether to work with them. IV. Indicate if it maintains a file for each of its commercial partners, as well as the information it must contain. V. Indicate how the services of its commercial partner are evaluated and what points it reviews. The file must include at a minimum the following: I. Company data (name, RFC key, activity, etc.). II. Legal representative data.
III. Proof of address. IV. Commercial references (if applicable). V. Contracts, agreements, and/or confidentiality agreements and security policies. VI. Security policies. VII. If applicable, certificate or certification number in the security programs to which it belongs.
4.2 Security requirements. The railway transport concessionaire company must have a documented procedure in which, according to its risk analysis, it requests additional security requirements from those commercial partners that intervene in its supply chain, such as companies providing terminal operation services, parts and/or spare parts suppliers, mechanical suppliers or any other service, customs brokers, land transporters, private security, companies providing vehicle repair services, cargo loading and unloading service providers, in addition to those resulting from the analysis carried out. The requirements must be based on the criteria and objectives of this Profile, or in case of existence, the specific Profile for each actor in the supply chain that corresponds to them. The railway transport concessionaire company must request from its commercial partners the documentation that accredits and proves that they comply with the minimum security standards established in this Railway Transport Profile, either through a written declaration issued by the legal representative of the partner, agreements or contractual clauses backed by documentation that supports compliance with the requirements established by another Authorized Economic Operator Program. Likewise, the company must take into account and know the specific requirements of the Authorized Economic Operator Program that will be applicable to each of its commercial partners, based on their activity within the supply chain. In the case of the company's commercial partners that provide their services within the facilities, they must be obliged to comply with these supply chain security requirements.
Response: Explanatory Notes: Describe the procedure that indicates how it carries out the identification of commercial partners that require compliance with minimum security standards and how these comply with such requirements. Ensure that you include the following points: I. Indicate a register of commercial partners that must comply with security requirements, and mention what type of providers these are (Transporters, Warehouses, Custody Service, Security Company, Vehicle Repair Service, Loading and Unloading Service, Customs Brokers, etc.). II. Indicate how it documents (agreements, accords, contractual clauses, and/or addenda) that its commercial partners comply with security requirements. III. Indicate if there are agreements, contractual accords, contractual clauses, and/or addenda regarding the implementation of security measures with its service providers inside its company, such as: private security, cafeteria, gardening, cleaning and maintenance services, Information Technology suppliers, etc. IV. Indicate if it has commercial partners to whom it is required to belong to a supply chain security program (for example: CTPAT or another Authorized Economic Operator Program of the WCO), as well as the information and documentation requested of them.
4.3 Commercial partner reviews. The railway transport concessionaire company through the Security Committee must carry out periodic security evaluations (as well as those derived from risk situations) of the processes and installations of business associates based on a risk analysis to guarantee that they have minimum security standards required by the company based on the Authorized Economic Operator Program, keep records of them, which allow verifying that the processes and security measures are being executed, as well as the corresponding follow-up. When inconsistencies are found, the railway transporter must communicate them to its partner and/or supplier and provide a justified period to address the observations or areas of opportunity identified, or otherwise, have the necessary measures to sanction it. Carrying out security evaluations of commercial partners is important to guarantee that there is a solid and functioning security program, which is why, in addition to a documented procedure, there must be a program or calendar for the execution of such reviews or security evaluations, prioritizing partners that are more critical according to their risk analysis. If a member is not evaluated and the company does not know if the processes and installations of its commercial partners function correctly, it puts its supply chain at risk.
Response: Explanatory Notes: Describe the procedure to carry out evaluations for the verification of security requirements (processes and installations) of its commercial partners, ensure that you do not exclude the following points: I. Periodicity with which it visits the commercial partner (these must be at least once a year and derived from risk situations). II. Program or calendar for the execution of security reviews. III. Record or report of the verification and, if applicable, the corresponding follow-up. IV. The verification formats must be duly filled out, placing the date, name, and position of those participating in the review, signatures, etc. V. Indicate what action measures are taken when commercial partners do not comply with the established security requirements. VI. In case of having commercial partners with CTPAT certification or another supply chain security certification program, indicate the periodicity with which its status is reviewed, how it is recorded, and the actions taken in case it is detected that it is suspended and/or cancelled, according to what is established in its procedure. The procedure must include: I. Periodicity of visits; II. Points of review in terms of security; III. Preparation of reports;
IV. Feedback and agreements with the commercial partner; V. Follow-up to agreements; VI. Measures in case of detecting non-compliance with requirements; VII. Record of evaluations; VIII. Area or person responsible for carrying out this procedure.
5.1 Process mapping. There must be a process map that describes step by step the operational flow for the transfer of freight cars with foreign trade merchandise throughout the supply chain, including in an illustrative but not limiting manner the following: client request, crew assignment, if applicable, entry to the client's, supplier's, or seller's facilities (spur) that describes the delivery and withdrawal of freight cars, the transfer to terminals, the car classification process, routes, sidings, or spurs. Likewise, the railway transporter must have written procedures for the designation of the crew (Line Engineers, Train Drivers, Line Switchman, Yard Engineer, Yard Master, Yard Switchman, Track Inspector), train dispatchers, previously designed routes, collection or delivery of loaded freight cars, and exchange of freight cars with foreign trade merchandise with the connecting railroad; handling of freight car documentation; communication during the train route between intermediate or final points, its relationship with other actors in the supply chain such as customs brokers, logistics operators, contracting clients, among others.
Response: Explanatory Notes: I. Attach the documented procedure where you describe in detail the operational flow of your general transport service and the type of service you provide, which includes the designation of the crew, rolling stock/units, routes, collection and delivery of loaded freight cars, handling of documentation, communication during operation with other actors in the supply chain including your contractors. This process must include at least the following: II. Service request. III. Assignment of traction equipment (locomotives). IV. Crew assignment. V. Service confirmation to the crew. VI. Instructions to the crew. VII. Collection of loaded freight cars: a) Identification before the company; b) Instruction Letters for delivery. VIII. Container seal (if applicable). IX. Transfer to the freight car classification yard. X. Creation of work orders and train classification. XI. Confirmation of what was classified. XII. Crew assignment for departure from terminal or classification yard. XIII. Documentation generated for the transfer service. XIV. Transfer of loaded freight cars to the port, border, or exit customs. XV. Instructions to coordinate with other service providers involved in customs clearance and border crossing (customs brokers). a) Documentation to be presented at customs. b) Personal protective equipment.
XVI. Guideline for loading and unloading merchandise at customs and/or with the client. XVII. Constant means of communication with the railway transport concessionaire company. XVIII. Transfer to final destination. XIX. Information flow associated with the shipment. XX. Administrative management process (general process of sending documentary information, and billing). For the purposes of the administrative management and billing process, the railway transport concessionaire company must have a documented procedure to receive and register the service request that the user will require, which must contain, at least the following: I. Service Request, which includes in an illustrative but not limiting manner at least the following information: a) Origin (collection). b) Destination. c) Cargo specifications (domestic, international, dangerous, high value, etc.). d) Delivery time and date. e) Cost per freight car operation. f) Insurance per loaded freight car. II. Crew designation. III. Preparation and delivery of documentation. IV. Instructions to coordinate with other service providers involved in customs clearance and border crossing (authorities, customs brokers, DOT, consolidators/de-consolidators, among others).
V. Documentation to be presented at customs. VI. Assembly and disassembly of trains, as well as coupling and uncoupling of freight cars in yards or terminals on classification tracks at customs and/or with the client (transfer terminals, automotive terminals, etc.).
5.2 Delivery and receipt of freight cars. The railway transport concessionaire company must make known to the crew (personnel) the criteria and conditions that its clients demand for the handling of their cargo, as well as comply with the security guidelines that the company has to enter their facilities at the time of collection and/or delivery of freight cars with foreign trade cargo. The crew (personnel) must know the documents that will be delivered to them, which cover the ownership of the loaded cars that will be transported, likewise with the documentation delivered to them, they must corroborate the number of the trailing equipment (wagons or containers) assigned. When the cargo is stored overnight or during a prolonged period in railway terminals, measures must be taken to secure the cargo against unauthorized access; such area must be monitored by its alarm and closed-circuit television and video surveillance systems and have restricted access. The cargo preparation areas and the immediate surrounding areas must be inspected regularly to ensure that these areas remain free of visible pest contamination.
Response: Explanatory Notes: Attach the documented procedure in which you indicate the procedure for the delivery and receipt of the cargo and ensure that it includes the following points: I. How it verifies and guarantees that the cargo preparation areas and the immediate surrounding areas remain free of visible pest contamination. In case of identifying any type of visible pest, contamination, trash, insects, grass, weeds, or overgrown grass, how it is reported and what actions are taken regarding it. In case of identifying any type of visible pest, contamination, trash, insects, grass, weeds, or overgrown grass, how it is reported and what actions are taken regarding it. II. Indicate how it controls or what security measures it has implemented to mitigate the risk of collusion or complicity among employees.
Describe in detail the procedure for the assembly and disassembly of trains, as well as the coupling and uncoupling of railroad cars in yards or terminals on classification tracks, clients (transfer terminals, automotive terminals, etc.), and at customs when the automated selection mechanism determines customs inspection.
5.3 Freight tracking procedure. The railway transport concessionaire is responsible for monitoring and ensuring the integrity of traction and rolling stock equipment, as well as the merchandise contained within the railroad cars, from the moment of loading until delivery at the established destination. Therefore, it must have documented procedures that establish the use of technology for the transport of foreign trade merchandise. A device capable of tracking the position of the railroad cars carrying the merchandise via GPS/Satellite Link must be available during the entire duration of the transport, with continuous geographic coverage along the route.
The company must establish documented procedures to ensure the location of the trains at all times. These procedures must be carried out under a risk analysis that includes, by way of example and not limitation, the identification of predetermined routes, estimated delivery times, intermediate points, as well as overnight stays and/or rest (classification yards, exit customs, railway spurs, fuel loading, routine mechanical inspections, leaks or side tracks, among others). Similarly, measures and actions to be taken in the event of identifying any delay in the route due to weather conditions, mechanical incident, authority inspection, or any security incident must be included. There must be trained and authorized personnel to perform the monitoring and/or permanent traceability of trains carrying railroad cars with foreign trade merchandise.
Supervision and registration data of all trains in transit with railroad cars transporting foreign trade merchandise must be preserved for one month when the authority and/or the railway carrier must perform an evaluation due to a security incident. If, as a result of monitoring and tracking, a real (or confirmed) threat to the security of a shipment is identified, the company must alert (as soon as possible) the commercial partners in the supply chain that may be affected and, where applicable, the authority as appropriate.
Response: Explanatory Notes: Detail if a review of predetermined routes is carried out based on their risk analysis and how it is documented. Likewise, train monitoring must be documented, and this record must contain the following information: I. Crew name. II. Origin and destination of the service. III. Clients. IV. Type of cargo. V. Unit location records. VI. Crew service log.
Attach the documented procedure for monitoring trains with railroad cars transporting foreign trade merchandise. The procedure must include, by way of example and not limitation, the following: The area and person(s) responsible in the company for tracking and monitoring the trains. I. Indicate who are the authorized persons to monitor and/or track the trains and how they have been instructed and trained to perform this task. II. Indicate how and/or which systems are used to perform train monitoring. III. Frequency for reviewing the status of the trains and, according to their risk analysis, indicate the means of communication available with the crew (indicate if there is more than one way to communicate: cell phone, tracking system, global positioning systems (GPS), fixed supervision points, etc.). IV. Indicate the frequency with which clients are informed of the location of the railroad cars containing their shipments, or if they share any tracking system. V. Indicate if there are documented procedures to act or report in case of a delay in the route (stops, mechanical failures, accidents, etc.). Indicate if the crew is trained to handle mechanical failures of traction and rolling stock equipment. VI. The procedure must also include that, in the event of identifying a real or concrete threat to the security of a shipment or means of transport; how the company informs the commercial partners of its supply chain that may be affected and, where applicable, the authority as appropriate, regarding this type of incidents or presumptions.
5.4 Processing of information and documentation of train cars. The railway transport concessionaire must have written procedures to ensure that both the electronic and/or documentary information sent by its clients starting from their service request, during the movement and dispatch of the transport of railroad cars containing their merchandise, as well as the information received from business associates, is legible, complete, accurate, reported in time, and protected against changes, loss, or introduction of erroneous information. Likewise, forms and documentation related to import and/or export should be secured to prevent unauthorized use.
Response: Explanatory Notes: Attach the documented procedure for the processing of information and documentation of railroad cars. Briefly explain what it consists of. I. Detail how you receive and transmit relevant information and documentation for the transport of railroad cars with foreign trade merchandise with your commercial partners (indicate if you use a specific computer control system and briefly explain its function). Likewise, detail how you validate that the provided information is legible, complete, accurate, reported in time, and protected against changes, loss, or introduction of erroneous information. II. Indicate how business associates transmit information to the company and how they ensure its protection.
6.1 Customs Obligations. The railway transport concessionaire must have a documented procedure with the objective of complying with what is established in rule 1.9.11, transmitting electronically to the entry or exit customs, or in case of transit, the dispatch customs, the exchange list within the times established in the RGCE before the arrival of the railway, which must contain, in addition to the requirements provided in rule 4.2.14, the key and number of the customs declaration covering the merchandise, as well as its description, according to what is stated in the declaration, in the COVE or bill of lading respectively, as applicable.
They must have a documented procedure with the objective of complying with rule 2.4.13, for the purposes of articles 20, fraction III and 53 of the Law. In the case of internal transits, they must have a documented procedure that clearly, precisely, and accurately contemplates notices to customs authorities caused by late arrival, as well as for cases of destruction of merchandise. For the purposes of what is stipulated in article 128 of the Law and rule 4.6.17., these procedures must contemplate the deadlines established in Annex 15.
A documented procedure must be available in cases of temporary import, return, and transfer of railroad cars, the railway company according to what is stated in rule 4.2.14, as well, in the case of temporary export of national or naturalized locomotives carried out by railway transport concessionaires, they must comply with the terms of articles 115 and 116 of the Law, as stated in rule 4.4.3.
They must have a documented procedure for cases where railroad cars suffer damage and must be destroyed or changed to definitive import regime according to articles 94 and 106, fraction V, subsections a) and e) of the Law, in accordance with rule 4.2.18.
Response: Explanatory Notes: Attach the procedure for the electronic transmission of data with customs. Attach the procedure to follow when any railway equipment suffers damage. Describe the procedure to comply with customs in cases of temporary exports and imports of locomotives. Describe the procedure to follow in the case of merchandise transit. Describe the procedure to comply with customs in cases of temporary import, return, and transfer of railroad cars of the railway company.
7.1 Use of seals and/or locks on traction and rolling stock equipment. The use and placement of seals or locks on traction and rolling stock equipment (boxcars, gondolas, hoppers, tank cars, chassis, trailers, platforms that do not have their own traction circulating on railway tracks and used to transport merchandise inside and in containers) is considered a critical and necessary process to maintain the integrity of shipments transporting foreign trade merchandise. Therefore, the railway transport concessionaire must document procedures that include the control, safeguarding, assignment, and replacement of high-security locks and seals that meet or exceed Standard ISO 17712. For this, the railway company must have documented procedures to place and verify the correct application of seals, their inspection at intermediate points, final destination, and their replacement when opened by any authority.
In the event of such an inspection, drivers must notify and register any unusual anomaly or structural modification found in containers, wagons, etc., resulting from said review. The procedures must include the steps to follow if it is discovered that a seal is altered, manipulated, or if there is an incorrect seal number in the documentation, the communication protocols to the commercial partners involved in the supply chains, and the investigation of the security incident. These must be notified to security personnel, commercial partners that may be part of the affected supply chain, security specialist, or Authorized Economic Operator Program contact.
The railway carrier must verify and evidence that, during loading points, as well as in reviews by any authority or due to changes in the original conditions of the shipment, high-security seals or locks are correctly applied and placed. For the case of consolidated cargo collection and delivery operations that do not use consolidation centers to sort or consolidate the cargo before arriving at the destination, the transport company must, at each stop and before arriving at the destination, place high-security seals on the traction and rolling stock equipment. The company's management or a security supervisor must perform periodic and documented audits of the high-security seals and/or locks; these reviews must include the verification of the inventory of stored seals and/or locks and the cross-check with inventory records and shipping documents. Also, supervisors of the shipping area and/or warehouse managers must periodically verify the seal numbers used in the means of transport and International Traffic Instruments to corroborate that the information is correct.
Likewise, in said procedure, it is necessary for the railway carrier to include what relates to the administration of high-security seals, which includes, control, assignment, safeguarding, handling of discrepancies, and destruction of seals and locks. Regarding the provider of the seals and/or locks, it must be demonstrated how these comply with Standard ISO 17712. It must also have documented procedures that clearly describe how high-security seals will be controlled by the railway company during transit on the route, and by way of example and not limitation, contain the following:
I. Verify the correct placement of seals or locks according to the VVTT inspection method to evidence and discard improper manipulations: a) V - View the seal and lock mechanisms of the container. b) V - Verify the seal number. c) T - Pull the seal to ensure it is correctly placed. d) T - Twist and turn the seal to ensure. II. Review and compare the documentation containing the number of the original seal or lock and the additional ones carried during the transport of the merchandise. If a replacement seal and/or lock is used, that number must be registered within the company's control. If altered seals and/or locks are identified, they must be kept to help carry out the investigation of said incident or discrepancy. III. Place the high-security seal on the right door of the rolling stock cars (when the client's seal is incorrectly placed or damaged), or in case the company uses cable seals, these must be placed on both vertical bars of the container. IV. Review that closing devices, hinges, and pins are attached by welding or with some type of rivet to the traction and rolling stock equipment. Consider the type of reports and records that will be made if the seal is removed, even by official authorities or due to an incident during the transport of the cargo, contemplating the installation of a second seal as a replacement and its proper notification to the owner of the merchandise.
Response: Explanatory Notes: Attach the documented procedure for the placement and review of seals and/or locks on traction and rolling stock equipment (boxcars, gondolas, hoppers, tank cars, chassis, trailers, platforms that do not have their own traction circulating on railway tracks and used to transport merchandise inside and in containers). This must include, among other aspects according to your operation: I. Verify that the seal or lock is intact and determine if there is evidence of improper manipulation. II. Use the VVTT inspection method. III. Review and compare the documentation containing the number of the original seal or lock and, where applicable, the additional ones carried in the transport of the merchandise. In case of using a replacement seal and/or lock, that number must be registered within the company's control. If altered seals and/or locks are identified, they must be kept to help carry out the investigation of said incident or discrepancy. IV. Review that closing devices, hinges, and pins are attached to the trailer or container by welding or rivet. Also, protective plates can be placed on the door hinges and/or a seal/adhesive tape placed on at least each side. Also, the correct functioning of handles, latches, and all other locking or closing mechanisms of the cargo vehicles must be verified to detect manipulations and any inconsistency before placing any sealing device. V. Indicate how you assign and replace high-security locks, in the event that, during the route, it is inspected by another authority. If a seal and/or lock breaks in transit, the cargo must be examined, the replacement seal and/or lock number must be registered, and the driver must notify immediately when this happens, indicate who broke it, and provide the new seal number.
Attach the documented procedure for the control and handling of seals and/or locks. This must include, among other aspects according to your operation: I. What type of seals and/or locks are used in your operations (foreign trade, transit, storage, etc.). II. Who has access and how locks and/or seals are safeguarded. The management of seals and/or locks must be restricted only to authorized personnel; stored in a secure place, have an inventory, control of their distribution, and tracking (record of seals used, as well as of the receipt of new seals and/or locks). III. Describe how the company's management or security supervisor participate in audits of high-security seals and/or locks, the reviews they perform, the records they generate, and the actions they take in case of identifying discrepancies. Also, how supervisors of the shipping area and/or warehouse managers verify seal numbers used in means of transport and International Traffic Instruments to corroborate that the information is correct (this process can also be included within the internal audits referred to in sub-standard 1.3 of this document). IV. How discrepancies in seal and/or lock numbers are addressed. V. Indicate who the supplier(s) is/are and how it proves that the specifications of the seals and/or locks comply with Standard ISO 17712 (attach certificate issued by the certifying company responsible for verifying compliance with the corresponding ISO).
All written procedures must be disseminated and maintained at the operational level to be easily accessible for employees responsible for executing the tasks described above, reviewed at least once a year, and updated as necessary.
7.2 Inspection of traction and rolling stock equipment. The railway transport concessionaire must have procedures to permanently review traction and rolling stock equipment (boxcars, gondolas, hoppers, tank cars, chassis, trailers, platforms that do not have their own traction circulating on railway tracks and used to transport merchandise inside and in containers) used as International Traffic Instruments, with the purpose of identifying natural or hidden compartments, using a checklist or format that includes the main points to review. This review must be carried out by operators or personnel designated by the company for such effect. Likewise, the physical-mechanical conditions of the means of transport must be periodically reviewed to prove their good functioning, and if applicable, that they meet or exceed the safety standards of NOM-064-SCT2-2001.
Inspections of traction and rolling stock equipment must be systematic, and carried out at the entry and exit of operational yards or storage sites; and where applicable, at the merchandise loading point (contracting company); and if the infrastructure allows, before arriving at the dispatch customs using the VVTT inspection method. A record of these inspections must be kept in an area with controlled access and monitored by alarm systems, closed-circuit television, and video surveillance.
The documented procedure for inspection must include, enumeratively but not limitatively, the following review points:
Traction equipment (locomotive and cab)
Rolling stock equipment (boxcars, gondolas, hoppers, tank cars, chassis, trailers, platforms that do not have their own traction that travel on railway tracks and are used to transport merchandise inside and in containers)
I. Machine. II. Floor (platforms). III. Fuel tanks. IV. Cab interior compartments /bathroom / doors and tool compartments/crew section and roof.
I. Platform base. II. Exterior and interior doors. III. Side walls (right and left). IV. Internal and external roofs. V. Front wall. VI. Internal floor. VII. Axles or plates.
Likewise, before loading the traction and rolling stock equipment used as Instruments of International Traffic, they must undergo agricultural and security inspections to guarantee that their structures have not been modified to hide smuggling or have been contaminated with visible agricultural pests, maintain a record and be backed by a documented procedure. If visible pest contamination is found during the inspection or transport of merchandise subject to foreign trade, it must be cleaned (washed, vacuumed, etc.) to eliminate said contamination. The driver must ensure before crossing that the locomotive and cab are clean and free of trash.
Response: Explanatory Notes: Attach the documented procedure to carry out the security and agricultural inspection of the equipment (boxcars, gondolas, hoppers, tank cars, chassis, trailers, platforms that do not have their own traction that travel on railway tracks and are used to transport merchandise inside and in containers). This must include, among other aspects according to your operation:
I. Those responsible for carrying out the inspection. II. Formats used to carry out the inspection that comply with the minimum requirements indicated in this sub-standard; likewise, in the case of transport companies for materials and hazardous waste, each piece of equipment must have a daily visual review log of the traction and rolling stock units.
Description of the place or places where the inspection takes place and indicate how monitoring is carried out by alarm systems and closed-circuit television and video surveillance.
I. The review points for means of transport, trailers, semi-trailers and containers both for security and those for quality and agricultural inspections with the purpose of searching for visible pests. II. Instructions for the driver to ensure before crossing that the locomotive and cab are clean and free of trash.
Attach the established format for the inspection of traction and rolling stock equipment (boxcars, gondolas, hoppers, tank cars, chassis, trailers, platforms that do not have their own traction that travel on railway tracks and are used to transport merchandise inside and in containers). Likewise, the security and agricultural inspection format must include the following information:
I. Date of inspection; II. Time of inspection; III. Vehicle license plates (tractor and trailer); IV. Container/trailer number; V. Specific areas of the cargo vehicles that were inspected, and VI. Name of the employee performing the inspection and the supervisor.
The security and agricultural inspection formats may be signed by the supervisor to corroborate their information and be part of the import and export documentation.
The documentation must be kept for one year for an investigation in case of any security incident, as well as to demonstrate continuous compliance with these inspection requirements.
Likewise, describe the procedure carried out on traction and rolling stock equipment (boxcars, gondolas, hoppers, tank cars, chassis, trailers, platforms that do not have their own traction that travel on railway tracks and are used to transport merchandise inside and in containers) that contemplates the physical-mechanical conditions for safe operation on the railway infrastructure within the country. In addition to validating that they have records of this type of maintenance for at least one year.
This procedure must additionally include the following:
I. Responsible personnel. II. Places where inspections are carried out. III. In case any physical-mechanical condition and/or anomaly affecting the proper functioning of traction and rolling stock equipment is detected, how it is reported, and what measures must be taken. IV. Indicate what type of record is kept.
In cases where, due to major structural modifications in traction and rolling stock equipment such as axles, springs, modifications to the structure or body of the railroad car and even adaptations in the cabins, among others, the owner and responsible party of the railroad car must contemplate, in accordance with their risk analysis, a more exhaustive review of the railway equipment in question to ensure its integrity, regarding this:
I. Indicate whether the repair or maintenance of traction and rolling stock equipment (boxcars, gondolas, hoppers, tank cars, chassis, trailers, platforms that do not have their own traction that travel on railway tracks and are used to transport merchandise inside and in containers) is carried out in the same facilities, or is carried out with an external provider. II. Briefly describe how the delivery-receipt of traction and rolling stock equipment that underwent a modification as mentioned in the previous paragraph is carried out.
7.3 Storage of traction and rolling stock equipment. The railway transport concessionaire company must maintain the integrity at all times of the traction and rolling stock equipment (boxcars, gondolas, hoppers, tank cars, chassis, trailers, platforms that do not have their own traction that travel on railway tracks and are used to transport merchandise inside and in containers) by establishing controls within its facilities. If these are empty and must be stored on tracks designated for that purpose, they must be secured with a lock and/or indicative seal, or in its case, in a secure area that is guarded and/or monitored.
When any traction or rolling stock equipment (boxcars, gondolas, hoppers, tank cars, chassis, trailers, platforms that do not have their own traction that travel on railway tracks and are used to transport merchandise inside and in containers) with foreign trade merchandise must be stored, it must be in a secure area with perimeter barriers and monitored by alarm systems and closed-circuit television and video surveillance, to prevent unauthorized access and manipulation of the merchandise, therefore it must be closed with a high-security lock in accordance with ISO 17712 Standard.
If during the journey on the authorized route to the final destination, it is considered to move to a facility that is authorized as a storage yard for traction or rolling stock equipment (boxcars, gondolas, hoppers, tank cars, chassis, trailers, platforms that do not have their own traction that travel on railway tracks and are used to transport merchandise inside and in containers), whether owned by the company or through a third party, the railway carrier must guarantee that these facilities meet the minimum criteria in terms of security based on the Railway Carrier Profile established by AGACE, or in its case, of any other Authorized Economic Operator Program.
Response: Explanatory Notes: Describe how the integrity of traction and rolling stock equipment transporting foreign trade merchandise (boxcars, gondolas, hoppers, tank cars, chassis, trailers, platforms that do not have their own traction that travel on railway tracks and are used to transport merchandise inside and in containers) is secured.
Indicate the types of seals and/or locks used for the traction and rolling stock equipment (boxcars, gondolas, hoppers, tank cars, chassis, trailers, platforms that do not have their own traction that travel on railway tracks and are used to transport merchandise inside and in containers).
Indicate how many tracks at the terminals or stations the railway company contemplates for the storage of traction and rolling stock equipment (boxcars, gondolas, hoppers, tank cars, chassis, trailers, platforms that do not have their own traction that travel on railway tracks and are used to transport merchandise inside and in containers) and add the following data for each of these:
I. Name or denomination of the track at the station or terminal. II. Location of the track at the station or terminal. III. Length of the storage track. IV. Indicate how many railroad cars with foreign trade merchandise enter the storage track (imp/expo). V. Number of people working at this station or terminal. VI. When a station or terminal has been visited by CTPAT, indicate the date the visit was made. VII. Indicate in each of the installations which belongs to the concessionaire company or is a service contracted through a third party. VIII. Describe how you ensure that your commercial partner providing the storage service meets the minimum security requirements.
7.4 Security on railway tracks. The railway company must maintain the integrity of the railway tracks at all times by establishing review and conservation controls for both concessioned railway tracks and signage in yards, crossings, and streets.
The use and placement of signage on railway tracks is considered a necessary process to maintain the integrity of railroad cars transporting foreign trade merchandise, which is why the company must document procedures that include the control, review, assignment, conservation, and replacement of signage that comply with or exceed the Official Mexican Standard NOM-050-SCT2-2017, provision for the signage of level crossings of roads and streets with railway tracks, published in the DOF on July 11, 2017.
The railway carrier must verify and evidence that during the review and conservation of railway tracks and signage, a log is kept of the state in which the railway tracks and signage are found.
Response: Explanatory Notes: Describe how the integrity and maintenance of railway tracks is secured.
Indicate the types of signage used and how it complies with or exceeds the Official Mexican Standard NOM-050-SCT2-2017, provision for the signage of level crossings of roads and streets with railway tracks, published in the DOF on July 11, 2017.
Indicate the signage contemplated by the company within its concession.
Likewise, there must be continuous training programs for personnel that disseminate the security policies of the concessionaire company, as well as the consequences and actions to be taken in case of any security breach or incident.
8.1 Employment background verification. The railway transport concessionaire company must have documented procedures to investigate and verify the information stated in resumes, criminal records (if local legislation and company policies allow it) and applications of candidates with potential for employment, in accordance with local legislation, either on their own or through an external company.
Likewise, for positions that by their sensitivity so require and affect the security of means of transport, in accordance with the risk analysis previously carried out, they must consider requesting stricter requirements for their hiring, which must be carried out periodically (e.g. Train Dispatchers, Road Engineers, Train Drivers, Road Swingers, Yard Engineers, Foreman, Yard Swingers, Track Inspector operators/engineers).
Regarding personnel already working in the company, periodic investigations must be carried out based on the activities and/or sensitivity of the employee's position.
This procedure must contemplate the creation and updating of personnel files, which must have restricted access and contain the following information:
I. Employment application. II. Updated photograph (in electronic or printed format). III. Copy of official identification. IV. Copy of the Federal Railway License (Train Dispatchers, Road Engineers, Train Drivers, Road Swingers, Yard Engineers, Foreman, Yard Swingers, Track Inspector, etc.) valid issued by SICT according to the type of service to be provided. V. Copy of updated proof of address. VI. Copy of birth certificate. VII. Registration with Social Security Institutions. VIII. Recommendation letters. IX. Evaluations (Mandatory Toxicological Exam for Train Dispatchers, Road Engineers, Train Drivers, Road Swingers, Yard Engineers, Foreman, Yard Swingers, Track Inspector, operators/engineers) at least every six months. X. Hiring terms. XI. Minimum mechanical knowledge exam.
Likewise, for sensitive positions identified in the previously carried out risk analysis and directly affecting the security of means of transport, stricter requirements for their hiring must be considered, which must be carried out periodically (e.g. Train Dispatchers, Road Engineers, Train Drivers, Road Swingers, Yard Engineers, Foreman, Yard Swingers, Track Inspector operators/engineers).
Response: Explanatory Notes: Describe the documented procedure for personnel hiring and ensure to include the following:
I. Requirements and documentation demanded. II. Tests and exams requested.
Indicate the areas and/or critical positions identified as risky, according to your analysis and indicate the following:
I. Indicate which are the additional requirements for specific areas and/or work positions, such as criminal records (if legislation and company policies allow it), non-criminal background letters, socioeconomic studies, clinical, toxicological (drug use), etc. In its case, indicate the positions or work areas where they are required and with what periodicity they are carried out.
II. Indicate if prior to hiring, the candidate must sign a confidentiality agreement or a similar document. III. Indicate the medical and toxicological exams performed on train dispatchers, road engineers, train drivers, road swingers, yard engineers, foremen, yard swingers, track inspectors, operators/engineers. IV. In case of hiring a service agency for personnel hiring, indicate if this has documented procedures for personnel hiring and how you ensure they comply with the same. Briefly explain what they consist of.
The procedures for personnel hiring and contractors may include:
I. Thorough investigations of the work and personal backgrounds of new employees. II. Confidentiality and responsibility clauses in employee contracts. III. Specific requirements for critical positions. IV. In its case, the periodic update of the socioeconomic and physical/medical study of employees working in critical and/or sensitive areas. V. Hiring process and requirements requested for temporary employees and contractors.
The company may consider the results of background verifications of candidates, as allowed by current legislation, to make hiring decisions. Background verifications are not limited to identity and criminal record verification. In higher-risk areas, deeper investigations may be justified.
8.2 Personnel termination procedure. Documented procedures for personnel termination must exist, in which the delivery of identifications, and any other item provided to perform their functions (keys, uniforms, badges and/or credentials, computer equipment, passwords, tools, etc.) is included. Likewise, this procedure must include the termination in those systems such as computer access systems, among others that may exist.
Response: Explanatory Notes: Describe the personnel termination procedure and ensure to include the following:
I. Who is responsible for carrying out and following up on this procedure. II. How the delivery and confirmation of identifications, uniforms, keys and other equipment is carried out. III. Indicate the control, record and/or format, in which the delivery of material is identified and secured, and termination in computer systems (in its case, attach). IV. Indicate the type of records of personnel who ended their labor relationship with the railway company, so that when it was for security reasons, their service providers and/or business associates are warned.
8.3 Personnel administration. The railway transport concessionaire company must maintain an updated system, control or database of active employees. Likewise, the registration of affiliation with social security institutions and other legal labor records must be carried out and kept updated.
In the case that the company has personnel contracted by its commercial partners and working within the facilities, it must ensure that they meet the requirements established for the rest of its employees.
Response: Explanatory Notes: Indicate if the company has an updated system, control or database, both of personnel hired directly, as well as that hired through a service provider company and ensure it includes enumeratively but not limitatively the following points:
I. Full name. II. Updated photograph at least every five years. III. Personal data (age, name, date of birth, phone number, address, CURP, social security number, blood type, allergies, etc.). IV. Affiliation. V. Work background. VI. Diseases. VII. Medical exams. VIII. Training. IX. Type of license and status thereof (they must have a record of federal railway licenses with the corresponding validity, in order to prevent their Train Dispatchers, Road Engineers, Train Drivers, Road Swingers, Yard Engineers, Foreman, Yard Swingers, Track Inspectors, engineers and operators from traveling with expired licenses). X. Results of periodic evaluations. XI. Observations. XII. This personnel must be hired in accordance with the current labor laws and regulations.
9.1 Classification and handling of documents. Procedures must exist to classify documents according to their sensitivity and/or importance, with special emphasis on that received from their contractors where information related to routes, materials, merchandise and/or goods being transported, instruction letters, schedules, customer and/or contact names, among others, is described. Sensitive and important documentation must be stored in a secure area that only allows access to authorized personnel. Reviews must be conducted regularly to ensure that documents are not used improperly. The useful life of the documentation must be identified and procedures for its destruction must be established.
The railway company must conduct regular reviews to verify access to information and ensure that it is not used improperly.
Reports, books, cargo guides, work orders, train consists, track listings, statistics and any other document related to railway transport activity.
The foregoing, in accordance with what is stipulated in the Regulatory Law of the Railway Service, the Federal Auto-transport and Auxiliary Services Regulation and the Regulation for the Land Transport of Hazardous Materials and Waste.
Response: Explanatory Notes: Attach the documented procedure for the registration, control and storage of printed documentation (classification and filing of documents), including:
I. Control register for delivery, loan, among others, of documentation. II. Restricted access to the archive area. III. Storage and classification policies. IV. An updated security plan describing the measures in force regarding the protection of documents against unauthorized access, as well as against deliberate destruction or loss thereof. V. In the case of electronic or digital information, it must adhere to the security criteria of sub-standard 9.2 Information Technology Security.
9.2 Information Technology Security. To protect Information Technology systems against common cybersecurity threats, a company must have sufficient protection that promotes security in Information Technology infrastructure (software and hardware) against malware (viruses, spyware, worms, trojans, etc.), baiting, phishing, and internal/external intrusions (firewalls) in the companies' computer systems. Likewise, companies must ensure that their security software is active and receives periodic updates. In the case of automated systems and computer equipment, individual accounts requiring periodic password changes must be used. In order to protect the confidentiality, integrity, and availability of information, the company must have established information technology policies, procedures, and standards that must be communicated through a training program for all employees who handle computer equipment and systems, which includes topics to prevent attacks through social engineering and all those threats to which they are exposed (malware, baiting, phishing, etc.). Companies that allow their employees to connect remotely to a network must employ secure technologies, such as virtual private networks (VPN), to allow employees to access the company intranet securely when they are outside the office, as well as procedures designed to prevent unauthorized remote access. For the foregoing, there must be written procedures and infrastructure to protect the company against losses, theft, leakage, hacking, and/or ransomware of information; this includes the procedure for the recovery (or replacement) of Information Technology systems and/or data, as well as a system or software established to identify the abuse of Information Technology systems and detect inappropriate access and/or improper manipulation or alteration of business and commercial data, as well as a written procedure for the application of appropriate disciplinary measures to all offenders. Access to Information Technology systems must be protected against infiltration through the use of secure passwords, which include passphrases or other forms of authentication. Users of said Information Technology systems must safeguard and not share their access keys or passwords. All Information Technology infrastructure must be physically protected against unauthorized access. If a data leak or other unexpected event occurs resulting in the loss of data and/or equipment, the procedures must include the recovery or replacement of Information Technology systems and/or data. Response: Explanatory Notes: Attach the procedure for the recovery or replacement of Information Technology systems and/or data that includes how it backs up and guarantees the security of its information in addition to protecting it from possible losses. Ensure you include the following points: I. Indicate the frequency with which information backups are carried out. II. Who has access to them and who authorizes the recovery of information. III. Indicate what type of tests it performs and how often, to verify the security of the network, systems, and infrastructure. IV. Mention whether, to perform this type of tests or vulnerability scans, it is done through software, a third party, or provider, and, if so, indicate the name or legal name. V. In case vulnerabilities are found, describe the corrective actions that must be implemented. VI. Indicate whether it shares information about cybersecurity threats with its commercial partners participating within its supply chain (for example: communications, bulletins, emails, etc.). VII. Systems must be protected by passwords and must be modified frequently; therefore, indicate the procedure for changing them. VIII. Indicate if there are information security policies for their protection. IX. Have a system or software to detect and identify abuse, intrusion, or unauthorized access to its systems, and/or Information Technology data (any system used by the railway company), as well as the abuse of policies and procedures established by the company, including unauthorized access to internal systems, external websites, and the manipulation or alteration of commercial data by employees or contractors. X. All offenders must be subject to the application of disciplinary measures; therefore, indicate the corrective policies and/or sanctions in case of detection of any violation of Information Technology security systems and policies.
Information technology and cybersecurity policies and procedures must be reviewed annually and updated following an attack or according to situations that may put the company's systems at risk. Describe the security measures used to allow employees to connect remotely to a network (VPN), to allow employees to access the company intranet remotely when they are outside the office. In case of allowing employees to use personal devices to perform the company's work, such devices must comply with the company's cybersecurity policies and procedures, security updates must be periodic, and they must have a method to access the company network securely. Indicate whether commercial partners have access to the company's computer systems. If so, indicate what programs they use and how they control access to them. Indicate if the computer equipment has a backup power supply system that allows business continuity. The procedures regarding the company's information backup must also include: I. How and for how long data is stored (data should be backed up once a week or as appropriate). II. Business continuity plan in case of incident and how to recover information. III. Frequency and location of backups and archived information. IV. If backups are stored in sites alternative to the facilities where the data processing center is located.
Tests of the validity of data recovery from backups. The procedures regarding the protection of the company's information must also include: I. An updated and documented policy for the protection of the company's computer systems against unauthorized access and deliberate destruction or loss of information. All sensitive and confidential data must be stored in an encrypted or encoded format. II. Detail if it operates with multiple systems (branches/sites) and how these systems are controlled. III. Who is responsible for the protection of the company's computer system (responsibility should not be limited to one person but to several so that each can control the actions of the rest). IV. Each user's access must be assigned through individual accounts and restricted according to the job description or assigned tasks. Therefore, describe how access authorizations and access levels to computer systems are granted (access to sensitive information must be limited to authorized personnel to perform modifications and use of information). Authorized access must be monitored by the area responsible for granting it, to verify or, if necessary, report that access to confidential systems is based on job requirements. V. Indicate the elements or format that passwords must have for access to Information Technology systems and computer equipment, frequency of changes, if there are other authentication methods, and who or what area provides those passwords.
VI. Indicate the name of the firewall and antivirus used, (include licensing-related information), evidencing that this security software is active and receives periodic updates. For the foregoing, cybersecurity policies and procedures should include measures to prevent the use of counterfeit technological products or those with incorrect licenses (software and hardware). All computer equipment, electronic media (hard drives, cell phones, etc.), and Information Technology hardware containing confidential information related to the import and export process must be accounted for through periodic inventories and have such evidence. When these technological equipment must be discarded, there must be a documented procedure that includes how they must be formatted, disinfected, or destroyed appropriately to avoid information leakage. VII. In case of employee termination, access to computer equipment, telecommunications, and network must be eliminated at the moment of the employee's separation; this includes email accounts, system access accounts, software, programs, etc. VIII. Measures planned to handle incidents when the system is compromised. 10. Security Training and Awareness. There must be an established, designed, and updated awareness program on threats by the Security Committee to recognize and create awareness about threats from terrorists and smugglers at each point in the supply chain. The training program must be comprehensive and cover all security requirements of the Authorized Economic Operator Program. Administrative and operational employees must know the company's established procedures to consider a risk situation and know how to report it. Specific training must be provided to employees who, due to their functions, are in direct contact with goods and/or traction and drag equipment, as well as to employees who are in critical and/or sensitive areas determined under their risk analysis (in security areas, operators/engineers, among others).
10.1 Training and Awareness on Threats. The railway transport concessionaire must have a training and awareness program on security policies in the supply chain directed to all its employees (operational and administrative) and, additionally, make available informational material regarding the procedures established in the company to consider a situation that threatens its security and know how to report it. Likewise, specific training must be offered according to their functions to help employees maintain the integrity of traction and drag equipment for agricultural and security purposes, incident management, receipt and review of messaging and packages, prevention of operations with proceeds of illicit origin (money laundering, terrorism financing, etc.), how to recognize and report internal conspiracies, protect access controls, as well as training regarding smuggling, theft of goods, placement of high-security seals and locks (VVTT inspection method), prevention of visible pest contamination, etc. These topics must be established as part of new employee onboarding and maintain periodic update programs. Update training must be carried out periodically, after a security incident, and when there are changes in the company's procedures. In addition to security training programs, a program on awareness of alcohol and drug consumption must be included. Also, disseminate and train staff on the company's cybersecurity policies, procedures, and standards (theft, leakage, hacking, and/or ransomware of information), including access to computer equipment and systems via passwords or passphrases. Personnel who operate and administer security technology systems must receive training related to their operation and maintenance, including self-training through operational manuals and other methods. These topics must be established as part of new employee onboarding and maintain periodic update programs. Training programs must encourage active employee participation in security controls and mechanisms, as well as maintain records of all training efforts provided by the company, and the list of those who participated in them (videos, photographs, minutes, attendance lists, intranet or other system, didactic material, PowerPoint presentations, brochures, etc.). Training records must include the date of the training, the names of attendees, the topics taught, in addition to having measures to verify that the training provided met all training objectives. The foregoing, in accordance with the regulation established by SICT, which establishes that permit holders will have the obligation to provide their operators with training and coaching to achieve that the provision of services is efficient, safe, and effective. Response: Explanatory Notes: Must have a training program on security and prevention of security incidents in the supply chain for all employees working for the concessionaire company (administrative, operational, direct or indirect). Briefly explain what the training program consists of and ensure you include the following: I. Brief description of the topics taught (onboarding, specific periods, following audits, security incidents, etc.). II. When they are taught (onboarding, specific periods, following audits, security incidents, etc.).
III. Frequency of training, as well as updates and reinforcement. IV. Indicate how participation in supply chain security training is documented (videos, photographs, minutes, attendance lists, intranet or other system, didactic material, PowerPoint presentations, brochures, etc.). Training records must include the date, the names of attendees, the topics taught, in addition to having measures to verify that the training provided met all its objectives. V. Explain how employee participation in supply chain security matters is encouraged. Training to perform reviews of traction and drag equipment for agricultural and security purposes must include the following topics: I. Signs of hidden compartments. II. Smuggling hidden in natural compartments. III. Signs of pest contamination. IV. Procedures to follow if something is found during a transport vehicle inspection or if a security incident occurs during transit. V. Training on agricultural reviews must cover pest prevention measures, the regulatory requirements applicable to wooden packaging materials, in accordance with the International Standard for Phytosanitary Measures called Regulation of wooden packaging used in International Trade which emanate from the Food and Agriculture Organization of the United Nations and the identification of infested wood.
Operators and personnel who perform agricultural and security inspections of traction and drag equipment must be trained to inspect cargo vehicles for such purposes. Indicate if you have a training program on security in the supply chain, focused on operators/engineers. Briefly explain what it consists of. I. Indicate how participation in supply chain security training is documented. II. Explain how employee participation in security matters is encouraged. III. Indicate how you keep records of participants in training. Frequency of training and, if applicable, updates. The topics that may include, by way of example and not limitation: I. Access and security policies at facilities. II. Handover/receipt of railroad cars. III. Confidentiality of cargo information. IV. Transfer instructions, train documents, work orders. V. Accident and emergency reports. VI. Instructions for placing locks and/or seals in case of inspection by other authorities. VII. Installation and testing of security alarms and unit tracking, when applicable. Identification of authorized formats and documents that will be used.
Response: Explanatory Notes: Describe the documented procedure to initiate an investigation in case of a security incident occurring, and ensure you include the following: I. Responsible for carrying out the investigation. II. Documentation that integrates the investigation file. The documents to be included in the file derived from the investigation, by way of example and not limitation, may be: I. Information related to the Train Dispatchers, Locomotive Engineers, Train Conductors, Yard Swingers, Yard Engineers, Foreman, Yard Swingers, Track Inspector, personnel in charge, railroad cars with cargo, and routes. II. General information of the shipment, Purchase Order. III. Transport request; Confirmation of transport medium; Identification of transport operator (Access records, etc.). IV. Container Inspection Formats; Exit Order; delivery records. V. Videos from alarm systems and closed-circuit television and video surveillance. VI. Documentation generated for the railway carrier (packing list, bill of lading, BL, instruction sheet). VII. Documentation generated for commercial partners (Description of goods, Proformas, invoices, etc.). VIII. Documentation generated by the commercial partner (Customs declarations, Manifests, Tracking and inspection reports, videos if applicable, etc.). IX. Unit tracking and monitoring report (GPS Tracking).
E10. Industrial Park Profile Acknowledgment of Receipt First Time: Renewal: Addition: Modification: The data you provide will replace the data you provided when you requested your authorization.
General Information The objective of this Profile is to ensure that the industrial park develops and implements security practices and processes that ensure its supply chain by mitigating the risk of contamination of its facilities.
Industrial parks interested in obtaining the authorization referred to in Rule 7.1.5 must have documented and verifiable processes. Furthermore, the industrial entity interested in the aforementioned authorization must integrate the criteria required in this document into the business model or design it has established, seeking during the implementation of security standards the application of an analysis culture that supports decision-making consistent with the company's own values, mission, vision, codes of ethics, and conduct.
During the completion of this document, those interested in obtaining certification will analyze and identify threats that allow them to implement security practices and processes that ensure their supply chains and minimize the risk of contamination or substitution with illicit goods from the companies they house.
Filling Instructions: I. You must fill out an Industrial Park Profile for each industrial park where companies carrying out foreign trade operations are housed. II. Describe in detail how the industrial park complies with or exceeds what is established in each of the subsections as indicated. III. The format of this document is divided into two sections, as detailed below:
IV. Indicate how you comply with what is established in each of the sub-standards; therefore, you must attach the procedures in Spanish. These procedures must be characterized by describing or defining the objective the document pursues, the start and end of the process, measurement indicators, requirements, documents or formats to be used, responsible parties, among others. The section regarding Explanatory Notes is a guide regarding the points that must be included in the Response for each sub-standard, indicating in an indicative manner those points that must not be excluded from your response. V. Once this Industrial Park Profile has been answered, you must attach it to the Application for registration in the Certified Commercial Partner registry referred to in the first paragraph of Rule 7.1.5, fraction IV, subsection a). VI. For the purpose of verifying what is stated in the previous paragraph, the SAT through AGACE may conduct an inspection of the installation indicated here, with the exclusive purpose of verifying what is stated in this document. VII. Any incomplete Industrial Park Profile will not be processed. VIII. Any questions related to the Application for registration in the registry of certified companies and the Industrial Park Profile should be directed to the contacts appearing on the SAT Portal. IX. In the event of being authorized as a Certified Commercial Partner, this format must be kept updated and notify when the circumstances under which the registration was granted have changed and, as a result, changes or modifications are required in the information provided and submitted in this Industrial Park Profile to the authority, in accordance with what is established in Rule 7.2.1, fourth paragraph, fractions I, II, and VII. X. When non-compliance related to minimum security standards results from the inspection visit, the applicant may remedy them before the issuance of the resolution established in Rule 7.1.6, for which they will have a maximum period of three months counted from the notification of the indicated non-compliances.
Installation Data An Industrial Park Profile must be filled out for each of the installations that belong to and operate under the same RFC and carry out manufacturing processes of products subject to foreign trade, and in their case, for those installations related as industrial and/or manufacturing plants, warehouses, distribution centers, consolidation, etc.
Installation Information Number of Industrial Park Profiles: from RFC Key Name and/or Trade Name: Name and/or Denomination of the Installation Type of Installation Street Number and/or exterior letter Number and/or interior letter Colony Postal Code Municipality/Delegation Federal Entity Age of the installation (years of operation) Predominant Activity Total number of employees at this installation: Installation surface area (M2): Certifications: (indicate if you have certifications that you consider impact your supply chain process, for example: ISO 9000; Reliable Logistics Processes, among others) Name: Category: Validity: Name: Category: Validity: Name: Category: Validity: Name: Category: Validity:
1.1 Risk Analysis. Industrial parks must establish measures to identify, analyze, and mitigate security risks within their facilities, particularly in areas that are common or shared by the companies domiciled within them. For this reason, a written analysis must be developed to determine risks based on the organization's model (e.g., geographic location, crime index, predominant activity of co-owners and/or tenants, type of merchandise, hazardous, high value, etc.), which allows implementing and maintaining appropriate security measures. In accordance with the above, there must also be a written process based on the risk analysis to select new commercial partners and monitor those with whom the park is already working. This procedure must be updated at least once a year, so that it allows identifying other risks or threats in the Park's facilities due to the result of a security incident or arising from changes in initial operating conditions, as well as to identify whether policies, procedures, and other control and security mechanisms are being complied with. It is important to note that the company's Security Committee must participate in the preparation and updating of the risk analysis and the maintenance of the Authorized Economic Operator Program.
Response: Explanatory Notes: Indicate what sources of information are used to qualify risks during the analysis phase. Attach the risk matrix, as well as the documented procedure to identify risks in the Industrial Park facilities, which must include at least the following points: I. Periodicity with which the risk analysis is reviewed and/or updated. II. Areas and/or companies of the Industrial Park that are incorporated into the risk analysis. III. Methodology or techniques used to perform the risk analysis. IV. Responsible parties for reviewing and/or updating the company's risk analysis. Likewise, the documented procedure to identify risks in the supply chain and its installations must contemplate the risk appreciation and management process, and include the following aspects: I. Establishment of a context (cultural, political, legal, economic, geographic, social, etc.). II. Identification of risks in its supply chains and its installations. III. Risk analysis (causes, consequences, probabilities, and existing controls to determine the level of risk as high, medium, and low). IV. Risk evaluation (decision-making to determine the risks to be treated and priority for implementing treatment). V. Risk treatment (application of alternatives to change the probability of risks occurring). VI. Risk monitoring and review (monitoring the results of the risk analysis and verifying the effectiveness of its treatment). It is suggested to use administration, management, and risk evaluation techniques in accordance with international standards ISO 31000, 31010, and ISO 28000, which, according to its business model, should be implemented.
1.2 Security Policies. Industrial parks must have a policy oriented towards preventing, securing, and recognizing threats in the supply chain and company installations, such as drug trafficking, money laundering, arms trafficking, human trafficking, prohibited goods, and acts of terrorism. On their part, the co-owner and/or tenant companies operating in the industrial park must sign and comply with their security policy. The foregoing, regardless of whether some companies do not carry out foreign trade operations or are already certified in supply chain security. To promote a security culture, companies must demonstrate their commitment to supply chain security and the Authorized Economic Operator Program through a statement highlighting the importance of protecting the flow of national and international commerce from criminal activities, established through the security policy. Senior officials or executives of the company who must endorse and sign the security policy may include the company president, executive director, general manager, security director, or personnel with an equivalent position with decision-making authority.
Response: Explanatory Notes: State the security policy oriented towards preventing, securing, and recognizing threats in the supply chain and company installations; indicate who is responsible for its review, signature, and dissemination to employees, as well as the periodicity with which its update is carried out. This policy must be communicated to employees through a dissemination program and/or campaign. The security policy must be signed by a senior official of the company and be displayed in various areas of the company, including the company website, posters in key areas of the company (reception, shipments, receipts, warehouse, etc.), and as part of the company's initial and reinforcement training. There must be records of the security policy signed by co-owner and/or tenant companies operating with knowledge and acceptance.
1.3 Internal Audits in the Supply Chain. In addition to routine monitoring and supervision of security controls, it is necessary to schedule and carry out periodic audits that allow evaluating all supply chain security processes in a more critical and profound manner, as well as ensuring that employees follow the company's security procedures. Audits must be carried out by the company's Security Committee, establishing a documented procedure, as well as a program or calendar for their execution. Although it is necessary that audits are focused on supply chain security and based on the evaluation, review, and execution of minimum security standards, their focus must be adjusted to the size of the organization, the nature of risks, business model, and variations between installations. Audits can be general or focus on specific areas or processes according to their work program. The objective of an internal audit focused on the Authorized Economic Operator Program is to verify and ensure that employees follow the company's security procedures. The review process does not have to be complex; however, the formats and records used for the application of said reviews must evidence that the application and execution of the evaluated processes were validated, in addition to the corresponding follow-up of identified observations. The senior management of the Industrial Park Corporate entity must review the results of the audits and undertake the required corrective or preventive actions. The audit process must guarantee that the necessary information is collected to allow management to make this evaluation. The review must be documented, in addition to the fact that the company's Security Committee must provide and record periodic updates on the progress or results of any audit, exercise, or validation.
Response: Explanatory Notes: Describe the documented procedure to carry out an internal audit, focused on supply chain security; ensure you include the following points: I. Indicate how the company carries out the scheduling or calendarization to perform an internal audit on supply chain security and installation security. II. Indicate who participates in them, and the records made thereof, as well as the periodicity with which they are carried out. III. Indicate how the management of the Industrial Park Corporate entity verifies the results of security audits, how it carries out and/or implements preventive, corrective, and improvement actions, in addition to the follow-up and closure thereof. IV. The formats used during internal audits must be properly filled out, and through them, evidence that security procedures and measures are being put into practice.
1.4 Contingency and/or Emergency Plans. There must be a documented contingency and/or emergency plan; said plan must address crisis management, security recovery plans, and business resumption, to ensure business continuity in the event of a situation that affects the normal development of activities and foreign trade operations of the industrial park in its supply chain. A crisis or contingency may include the interruption of commercial data movement due to a cyberattack, a fire, a bomb threat, the detection of suspicious packages, power outages, theft and/or damage to merchandise (e.g., roadblocks, internal roadway blockages, urban roadways, shootings, threats, or extortions, entry of unauthorized personnel, damage to facilities, among others, customs closures). Such plans must be communicated to the industrial park personnel, as well as to the security managers of the companies established therein, through periodic training, as well as conducting tests, practical exercises, and annual simulations of the contingency and emergency plans to verify their effectiveness, from which properly filled out and signed records must be maintained (e.g., result reports, minutes, or reports, which must be backed by video recordings, photographs, etc., demonstrating their execution). The contingency and/or emergency plan must be updated as necessary, based on changes in operations and the organization's risk level.
Response: Explanatory Notes: Attach the documented contingency and/or emergency procedure or plan to ensure business continuity in the event of an emergency or security situation that affects the normal development of foreign trade activities of companies installed in the industrial park. This procedure must include, by way of enumeration but not limitation, the following: I. What situations it contemplates, describing the action plan and steps to be followed in case of crisis, as well as the tasks assigned to personnel during the handling of such contingencies. II. What mechanisms it uses to disseminate and ensure that these plans are effective. III. Contemplate the scheduling and execution of annual simulations and how they are documented (e.g., result reports, minutes, or reports, which must be accompanied by video recordings, photographs, etc., demonstrating their execution).
2.1 Installations. Installations (administrative offices, industrial sheds, warehouses, etc.) must be built with materials that can resist unauthorized access. Periodic documented inspections must be carried out to maintain the integrity of the structures, and in the event that an irregularity is detected, the corresponding repair must be carried out as soon as possible by the personnel designated for these tasks. Likewise, territorial limits, as well as various accesses, internal and external roadways, and the location of administrative buildings, industrial sheds, warehouses, parking areas for employee and cargo vehicles, vacant lots, railroad spurs, and short or medium-term expansion projects must be fully identified.
Response: Explanatory Notes: Indicate the predominant materials with which the installations are built (e.g., metal structure, sheet metal walls, brick walls, concrete, cyclone mesh, among others), and indicate how the review and maintenance of the integrity of the structures is carried out. Indicate the personnel or area responsible for carrying out inspection, maintenance, and repair tasks for installation damages. Attach a distribution or architectural plan of the complex, where the limits, access routes, of the installations, the location of the buildings, critical areas, parking, and boundaries can be identified. In the event that two owners or tenants of the Industrial Park carry out foreign trade operations and share a Warehouse or cargo vehicle maneuvering yard, this must be indicated in the overall architectural plan.
2.2 Accesses at Gates and Booths. The entrance or exit doors for vehicles and/or personnel must be attended, controlled, watched, and/or supervised. The number of access doors must be kept to the minimum necessary. Access to sensitive areas must be restricted according to the job description or assigned tasks.
Response: Explanatory Notes: Indicate how many doors and/or accesses (pedestrian, private cars, cargo vehicles, railroad spur) exist in the industrial park, as well as the operating hours of each, and indicate how they are monitored (Must have security personnel and indicate the number of elements). Detail if there are doors and/or accesses permanently blocked or closed. Describe how you ensure that access to sensitive areas is restricted according to the job description or assigned tasks (include the type of records and controls you use).
2.3 Perimeter Fences. Perimeter fences must be installed to secure the perimeters of the industrial park, based on a risk analysis carried out by the corporate entity. Fences that prevent and deter intrusions into the industrial park must be used. These must be inspected regularly and carry a record of the review with the purpose of ensuring their integrity and identifying damages, which must be repaired as soon as possible by the personnel designated for these tasks.
Response: Explanatory Notes: Describe the type of fence, peripheral barrier, and/or walls with which the industrial park is equipped; ensure you include the following points: I. Specify what areas it encloses. II. Indicate the characteristics of the same (material, dimensions, etc.). III. In case of not having fences, justify the reason in detail and explain how this situation is remedied. IV. Periodicity with which the integrity of the perimeter fences is verified and the records that are kept, with the purpose of ensuring their integrity and identifying damages, which must be repaired as soon as possible.
V. Indicate the personnel or area responsible for carrying out inspection and damage repair tasks. VI. Identify and mark restricted access areas. The procedure for inspecting perimeter walls may include: I. Responsible personnel to carry out the review. II. How and how often inspections of fences and/or perimeter walls are carried out. III. How inspection records are kept. IV. Who is responsible for verifying that repairs and/or modifications comply with the necessary technical specifications and security requirements.
2.4 Parking. Access to parking areas must be controlled and monitored by security personnel or those designated for this task. Private vehicles (of employees, visitors, suppliers, and contractors, among others) must be prohibited from parking outside assigned spaces, obstructing internal roadways, access to control and inspection points, and, where applicable, any other access point to the same.
Response: Explanatory Notes: Describe the procedure for controlling and monitoring parking, ensuring you include the following points: I. Those responsible for controlling and authorizing access to parking areas in common areas. II. Identify signage for common or shared parking (specify if parking assigned to park owners and tenants is separated from the maneuvering yard for cargo vehicles).
III. How vehicle entry and exit control is carried out at the facilities (indicate the records kept for controlling common or shared parking, existing control mechanisms (e.g., tokens, card readers, badges, etc.), how they are assigned, and the responsible area for doing so.). IV. Identify and mark common or shared parking.
2.5 Key and lock device control. Windows, doors, booths, access gates, interior and exterior grilles, according to their risk analysis, must be secured with locking devices. All companies in the industrial park, without exception, must have a documented procedure for the management and control of keys and/or locking devices for interior and exterior areas considered critical. Furthermore, they must keep a register and establish signed responsibility letters from persons who have keys or authorized access according to their level of responsibility and duties within their work area.
Response: Explanatory Notes: Indicate if all doors, windows, booths, access gates, windows, and interior and exterior grilles have manual or electronic opening and closing mechanisms. Attach the documented procedure for the management and control of keys and/or locking devices, ensuring it includes the following points: I. Those responsible for administering and controlling key security. II. Format and/or control register for key lending. III. Treatment of lost or undelivered keys. IV. Indicate if there are areas where access is gained with electronic devices and/or other access mechanisms.
2.6 Lighting. The lighting of the interior and exterior perimeter of the industrial park must allow for clear identification of persons, materials, and/or equipment located there, including the following areas: entrances and exits, perimeter walls, interior fences, loading and unloading, and parking areas, and must have an emergency and/or backup system in sensitive common-use areas.
Response: Explanatory Notes: Describe the procedure for operating and maintaining the lighting system, ensuring you include the following points: I. Indicate which common or shared areas are illuminated and which have a backup system (indicate if you have an auxiliary power plant or other mechanism to supply electricity in case of any contingency). II. How do you ensure that the lighting system is appropriate in each of the areas where the companies in the industrial park are located, so as to allow clear identification of personnel, materials, and/or equipment located there. III. Person responsible for controlling and maintaining lighting systems. IV. Maintenance and review program (if it coincides with another process, indicate it). V. Emergency protocol of the industrial park monitoring center in case of power outage, natural disasters, or sabotage. The procedure may include: I. How the lighting system is controlled. II. Operating hours. III. Identification of areas requiring permanent lighting.
2.7 Communication devices. All companies in the industrial park, without exception, must have communication devices and/or systems to immediately contact their security personnel, the park monitoring center, and authorities in case of an emergency and security situation. Additionally, a backup system must be available and its proper functioning verified periodically.
Response: Explanatory Notes: Describe the procedure that personnel must follow to contact the security personnel of the industrial park monitoring center or, where applicable, the corresponding authority in case of any security incident. Indicate if the operational and administrative personnel of the companies in the park have or have access to devices (landline phones, mobile phones, alert and/or emergency buttons, etc.) to communicate with security personnel and/or whoever is appropriate (these must be accessible to users to ensure a prompt reaction). Indicate what type of communication devices the industrial park security personnel use (landline phones, cell phones, radios, alarm systems, etc.). Describe the procedure for controlling and maintaining communication devices, ensuring you include the following points: I. Policies for assigning mobile communication devices. II. Maintenance or replacement program for fixed and mobile communication devices. III. Indicate if you have backup communication devices in case the permanent system fails, and where applicable, describe briefly. The procedure may include: I. Person responsible for the proper functioning and maintenance of communication devices. II. Verification and maintenance records of the devices. III. Method of assigning communication devices.
2.8 Alarm systems, closed-circuit television, and video surveillance systems. Alarm systems, closed-circuit television, video surveillance, and security technologies must be used to monitor, notify, or deter unauthorized access and prohibited activities in the facilities and other considered sensitive areas, notify the corresponding area, and also be used as evidence in investigations derived from any security incident. The Industrial Park must have its own monitoring center or outsourced administration. Furthermore, these security systems and technologies must be placed according to a prior risk analysis, so that personnel, visitor, supplier, passenger vehicle, cargo access areas, and other considered sensitive areas remain monitored. These alarm, closed-circuit television, and video surveillance systems must allow clear identification of the area or environment being monitored, record permanently, and maintain a backup of recordings for at least one month, in order to have the necessary elements to assign corresponding responsibilities in case of a security incident. Alarm systems, closed-circuit television, video surveillance, and security technologies must have a documented operating procedure that includes supervision of the equipment's good condition and verification of the correct position of cameras, indicating the frequency with which recording backups must be made, as well as those responsible for their operation. This system and all security technology infrastructure must have restricted access.
Response: Explanatory Notes: Mention the documented procedure indicating the functioning of the external alarm system or sensors, and where applicable, describe the following points: I. Indicate if all doors and windows have alarm sensors, as well as the areas where motion sensors are available. II. Procedure to follow in case an alarm is activated. III. Indicate the personnel or area responsible for maintenance, how failures are reported, and the records they use. Describe the documented procedure for operating alarm systems, closed-circuit television, video surveillance, and security technologies (this must be reviewed and updated annually and according to risk analysis or circumstances), ensuring you include the following points: I. Indicate the number of security cameras in the installed alarm, closed-circuit television, and video surveillance systems, and their location by area (detail if it covers the entry and exit points of the facilities, to cover the movement of vehicles and individuals). Attach a layout or map of the distribution of security cameras. II. Indicate the location of alarm systems, closed-circuit television, video surveillance, and security technologies, where monitors are located, who reviews them, as well as operating hours, and where applicable, if there are remote monitoring stations. All security technology infrastructure must be physically protected against unauthorized access. III. Periodic and random reviews of recordings must be carried out. Indicate how they review them (randomly, weekly, special events, restricted areas, etc.), who the designated personnel are, and how management is involved in the reviews. The results of the reviews must be documented to include corrective actions for audit purposes. IV. Indicate for how long these recordings are kept (must be at least one month). V. Alarm systems, closed-circuit television, video surveillance, and security technologies must have an alternative energy source that allows them to continue functioning in case of unexpected loss of direct power. Therefore, indicate if the alarm and closed-circuit television systems are backed up by a power plant or other mechanism to supply electricity, guaranteeing their operation. These systems should have an alarm/notification function that indicates a failure condition in operation and/or recording; indicate if your systems have this function. VI. Indicate if, in addition to alarm and closed-circuit television/video surveillance systems, you use any other type of technology to strengthen the security measures already in place. VII. Describe the procedure implemented to regularly test and inspect alarm, closed-circuit television, video surveillance, and security technologies and ensure their proper functioning. The results of the inspections and functional tests must be documented, as well as necessary corrective actions (these must be implemented as soon as possible). Additionally, the documented results of these inspections must be kept for a sufficient time for audit purposes. VIII. Indicate if the alarm and closed-circuit television/video surveillance system provider has access to security cameras, if they are in charge of monitoring them, how access is controlled, and who is responsible for said monitoring.
3.1 Security Personnel. The industrial park must have security and surveillance personnel. This personnel plays an important role in the physical protection of the facilities and the security of the assets of the industrial park and the companies installed in it, as well as for controlling the access and exit of all people and vehicles to the property. Security personnel must have a documented procedure to carry out their functions and have full knowledge of the mechanisms and procedures in emergency situations, detection and removal of unauthorized persons, or any security incident that occurs within the industrial park. Management must periodically verify compliance with procedures, policies, and functions through internal audits with the objective of verifying their correct execution.
Response: Explanatory Notes: Attach the documented procedure for the operation of security personnel (roles or instructions) and ensure you include the following points: I. Indicate the number of security personnel guarding the industrial park. II. Indicate the positions and/or functions of the personnel and operating hours. III. In case of hiring an external service, provide general data of the company (RFC key, corporate name, address), and specify the number of employed personnel, operational details, records, and reports they use to perform their functions. IV. In case of having armed personnel, describe the procedure for the control and safeguarding of weapons, present evidence of records and permits issued by the competent authorities in the matter.
3.2 Employee Identification. There must be an employee identification system for access to the industrial park facilities. Employees should only have access to those areas they need to perform their duties. Management or the industrial park security personnel, and the companies installed in it, must adequately control the delivery and return of badges, ID cards, and/or employee identification credentials. Procedures for the delivery, return, and change of access devices (e.g., keys, badges, and/or credentials, proximity cards, etc.) must be documented. Access to sensitive areas must be restricted according to the job description or assigned tasks.
Response: Explanatory Notes: Describe the procedure for employee identification and ensure you include the following points: I. Identification mechanisms (ID card and/or badge with photo, access control, biometrics, proximity cards, etc.). II. Indicate if employees use uniforms, how they are assigned (by position, area, functions, etc.) and withdrawn (where applicable). III. Indicate how personnel contracted by a business partner working within the facilities is identified (security, cleaning, maintenance, contractors, etc.). The procedure must also describe how the industrial park delivers, changes, and withdraws employee identification and access controls, and ensure you include the responsible areas for authorizing and administering them. Indicate how you ensure that access to sensitive areas is restricted according to the job description or assigned tasks (include the type of records and controls you use). Attach the documented procedure for controlling identifications.
3.3 Visitor and Supplier Identification. To access the facilities, visitors, suppliers, and contractors must present official identification with a photo for documentation upon arrival and a record must be kept. All visitors, suppliers, and contractors must receive a temporary identification, be accompanied by company personnel during their stay in the facilities, and ensure that the visitor/supplier/contractor always wears the provisional identification provided in a visible place. This procedure must be documented. Regarding cargo vehicles entering the industrial park, there must be a control that allows verifying the means of transport, container, train cars, trailers, and/or semi-trailers, in order to identify and mitigate the risk of park contamination with illicit products.
Response: Explanatory Notes: Attach the procedure for controlling access for visitors, suppliers, and contractors, ensuring you include the following points: I. Indicate what records are kept (personal forms for each visit, logbooks, among others). II. The visitor and supplier record must include the following: a) Date of the visit. b) Visitor's name. c) Identification number with photo (official documents such as: driver's license, passport, INE, etc.). d) Entry and exit time. e) In the case of vehicle access, the form must include vehicle data (model, license plate, trailer number, etc.). III. Indicate who is the person responsible for accompanying the visitor and/or supplier and if there are restricted areas for their entry. IV. Describe the type of control or security measures implemented regarding the entry of cargo vehicles (means of transport, containers, train cars, trailers, and/or semi-trailers, etc.), in order to identify and mitigate the risk of park contamination with illicit products.
3.4 Procedure for identifying and removing unauthorized persons or vehicles. The Industrial Park monitoring center must have a documented procedure specifying how to identify, confront, or report unauthorized or identified persons and/or vehicles. This procedure must be communicated to responsible personnel through training. The training must be documented.
Response: Explanatory Notes: Attach the documented procedure to identify, confront, or report unauthorized or identified persons and/or vehicles. The procedure must include: I. Responsible personnel. II. Designate a person or area responsible for being informed of security incidents. III. Instructions for confronting and addressing unidentified personnel. IV. Indicate in which cases the corresponding authorities must be reported. V. How security incidents and measures adopted for each case are recorded.
3.5 Messenger and package deliveries. Monitoring center personnel must identify personnel from messenger and package companies and authorize their entry to distribute and deliver correspondence addressed to companies located inside the industrial park.
Response: Explanatory Notes: Attach the procedure to identify and authorize the entry of personnel from messenger companies that distributes and delivers correspondence intended for companies installed in the industrial park, and ensure you include the following: I. How you identify the personnel or provider of the messenger and package service (indicate if an additional procedure to supplier access is required).
4.1 Selection Criteria. There must be documented procedures for the selection, follow-up, and renewal of commercial relationships with business associates or suppliers, which include interviews, reference verification, evaluation methods, and use of provided information. The information derived from the investigation and/or evaluation of business associates and/or suppliers must be documented and integrated into a file (physical or electronic). The procedure for the selection of commercial partners must include indicators to identify clients or suppliers that may not be legitimate or with unlocated addresses, in addition to investigations, reviews, or evaluations of said partners for the identification and control of activities related to money laundering and terrorist financing. If the investigation and/or evaluation of any commercial partner leads to substantial doubts about the veracity of their operations or services, the company must avoid hiring them and, if applicable, notify its security specialist or Authorized Economic Operator Program contact and the corresponding authority about its suspicions.
Response: Explanatory Notes: Attach the documented procedure for the selection and hiring of new commercial partners and monitoring of partners with whom it is already working, this includes any client or supplier of goods or services that has a commercial relationship with the industrial park (it is in the following sub-standard where it is requested to differentiate those at risk in your supply chain), make sure to include the following points: I. What information is required from the commercial partner. II. What aspects are reviewed and investigated in the selection and hiring of suppliers, as well as for the sale of a property, or the rental of an industrial warehouse, storage, etc. III. Indicators to identify clients or suppliers that may not be legitimate (payments above the standard rate, in cash; having little knowledge of the merchandise to be shipped; being evasive; minimal contact information (cell phone, contact points, emails, among others); recently created companies or businesses without commercial history, etc.) or with unlocated addresses. This point refers to pointing out all those alerts to determine that a commercial partner is not reliable and thus, carry out a deeper investigation and evaluate whether to work with them. IV. Indicate if you maintain a file for each of your commercial partners (co-owners, tenants, and suppliers). V. Point out how the services of your suppliers are evaluated and what points are reviewed. VI. Updated list with the general data of the companies operating in the industrial park at the time of submitting the enrollment request (name, RFC key, predominant trade or activity, indicate if they carry out or not foreign trade operations, etc.), in case of high or low of co-owners or tenants you must notify the authority. The file must include at least the following: I. Data of the hosting company (name, RFC key, predominant trade or activity, etc.). II. Simple copy of the articles of incorporation. III. Identification and simple copy of the notarial power of the legal representative. IV. Proof of address. V. Commercial references (if applicable). VI. Contracts, agreements, and/or confidentiality agreements. VII. Security policies. VIII. If applicable, certificate or certification number in the security programs to which they belong.
4.2 Security Requirements. The industrial park must have a documented procedure in which, according to its risk analysis, it requests additional security requirements from those commercial partners (co-owning companies or tenants) that carry out foreign trade operations. In the case of commercial partners that intervene in your supply chain, whether as suppliers that provide their services inside the industrial park such as: private security companies, cleaning, maintenance, staffing, landscaping, contractors, installation and maintenance of alarm systems and closed-circuit television and video surveillance, IT systems and Technology providers, among others, are obliged to comply with the same supply chain security requirements. The requirements must be based on the Industrial Park Profile established by AGACE, or if it exists, the specific Profile for each actor in the supply chain that corresponds to it. The industrial park must request from its commercial partners the documentation that accredits and proves that they comply with the minimum security standards established in this Industrial Park Profile, either through a written declaration issued by the legal representative of the partner, agreements or contractual clauses, backed by documentation that supports compliance with the requirements established in the Authorized Economic Operator Program. Likewise, the company must take into account and know the specific requirements of the Authorized Economic Operator Program that will be applicable to each of its commercial partners, based on their activity within the supply chain. All co-owning or tenant companies must adhere - without exception - to the general security policy and protocol established by the industrial park.
Response: Explanatory Notes: Describe the procedure that indicates how you carry out the identification of commercial partners that require compliance with minimum standards in terms of security. Make sure to include the following points: I. A register of commercial partners (co-owning companies or tenants and suppliers) that carry out foreign trade operations, intervene in your supply chain and must comply with security requirements. Mention what type of companies these are. II. Indicate in what documentary way (agreements, contractual clauses and/or addenda) you ensure that your commercial partners (co-owning companies or tenants and suppliers) comply with security requirements. III. Indicate if there are agreements, accords, contractual clauses and/or addenda regarding the implementation of security measures with service providers inside the industrial park, such as: private security, cleaning and maintenance service, cafeteria, landscaping, Information Technology provider, etc. IV. Indicate if you have commercial partners to whom it is required to belong to a supply chain security program (for example: CTPAT or any other Authorized Economic Operator Program of the WCO), as well as the information and documentation requested of them.
4.3 Commercial Partner Reviews. The industrial park, through the Security Committee, must carry out periodic security evaluations (as well as derived from risk situations), of the processes and facilities of business associates based on a risk analysis, to guarantee that they have minimum standards in terms of security required by the industrial park, based on the Authorized Economic Operator Program, keep records of the same that allow verifying that the processes and security measures are being executed, as well as the corresponding follow-up. When inconsistencies are found, the industrial park must communicate them to its partner and supplier and provide a reasonable period to address the observations or areas of opportunity identified or, otherwise, have the necessary measures to sanction it. Carrying out security evaluations of commercial partners is important to guarantee that there is a solid and functioning security program, which is why, in addition to a documented procedure, there must be a program or calendar for the execution of said security reviews or evaluations prioritizing partners that are more critical according to their risk analysis. If a member is not evaluated and the company does not know if the processes and facilities of its commercial partners work correctly, it puts your supply chain at risk.
Response: Explanatory Notes: The industrial park must have a documented procedure to carry out evaluations for the verification or review of security requirements in the processes and facilities of commercial partners. Describe the procedure to carry out the reviews of your commercial partners, make sure to include the following points: I. Periodicity with which you make visits to the commercial partner (this must be at least once a year and derived from risk situations). II. Program or calendar for the execution of security reviews. III. Record or report of the verification or review and, if applicable, the corresponding follow-up. IV. The verification formats must be properly filled out, placing the date, name and position of those participating in the review, signatures, etc. V. Point out what action measures are taken when commercial partners do not comply with the established security requirements. In case of having commercial partners that have CTPAT certification or another supply chain security certification program, indicate the periodicity with which their status is reviewed, how you register it and the actions you take in case it is detected that it is suspended and/or canceled, according to what is established in your procedure. The procedure must include: I. Periodicity of visits. II. Points of review in terms of security. III. Preparation of reports. IV. Feedback and agreements with the commercial partner. V. Follow-up to agreements. VI. Measures in case of non-compliance with requirements. VII. Record of evaluations. VIII. Areas or responsible for carrying out this procedure.
5.1 Delivery and receipt of cargo. The industrial park must inform the operators/drivers of transport companies that deliver or receive foreign trade merchandise of the security policies and guidelines when entering, circulating, and carrying out loading/unloading maneuvers inside the park. On the other hand, all companies - without exception - must previously inform the industrial park security personnel of the names of the transport companies, the type of cargo vehicles and characteristics of the seals or locks normally used and, if applicable, the operator data so that they can be fully identified from entry into the industrial park and until the facilities of the co-owning or tenant companies. The industrial park must have an updated database containing all the previous information.
Response: Explanatory Notes: Security personnel must permanently update the data of transport companies, operators, types of cargo vehicles that daily enter and exit the Industrial Park, as well as the distinctive characteristics of the high-security seals or locks used by the companies located inside.
6.1 Storage of vehicles, transport means, containers, train cars, trailers, and semi-trailers. When tractors, pickup trucks, vans, vans, dry boxes, refrigerated boxes, box trucks, gondolas, tank cars, rail hoppers, etc., that transport foreign trade merchandise are empty and must overnight and be protected inside the industrial park, they must be secured with an indicative seal, or placed in a common supervised and monitored area to prevent unauthorized access and manipulation. Transport means must not obstruct the internal roadways of the Industrial Park. If due to force majeure, containers, trailers, or semi-trailers must remain more than one day in the Park, they must remain inside the company that requested the service, or if the extension and infrastructure of the Park allow it, in a common area that complies with the aforementioned security measures. When due to operational needs it is necessary to safeguard any container, trailer, or semi-trailer loaded with foreign trade merchandise, it must be positioned in a secure area and monitored by alarm systems and closed-circuit television and video surveillance, to prevent unauthorized access and manipulation of the merchandise, so it must be closed with a high-security padlock according to ISO 17712 Standard. When the cargo is stored overnight or for a prolonged period, measures must be taken to secure the cargo against unauthorized access.
Response: Explanatory Notes: Indicate if inside the Industrial Park containers, trailers, and/or semi-trailers full or empty are stored for subsequent dispatch, and explain how their integrity is maintained within your facilities.
7.1 Employment background verification. The Industrial Park must have documented procedures to investigate and verify the information recorded in the resume, criminal records (if the legislation and company policies allow it) and application of candidates with possible employment, in accordance with local legislation, either on their own or through an external company. Likewise, for positions that due to their sensitivity so require and affect the security of the Industrial Park, in accordance with the previously carried out risk analysis, they must consider requesting stricter requirements for their hiring, which must be updated periodically. Regarding personnel who already work in the company, periodic investigations must be carried out based on the functions and/or sensitivity of the employee's position. All information regarding personnel must be kept in personal files, which must have restricted access.
Response: Explanatory Notes: Describe the documented procedure for personnel hiring, and make sure to include the following: I. Requirements and documentation demanded. II. Tests and exams requested. Indicate the areas and/or critical positions that have been identified as risky, according to your analysis and point out the following: I. Indicate if there are additional requirements for specific areas and/or jobs. Such as criminal records (if the legislation and company policies allow it), non-criminal background letter, socioeconomic studies, clinical toxicological studies (drug use), etc. If applicable, point out the jobs or work areas in which they are required and with what periodicity they are carried out. II. Indicate if prior to hiring, the candidate must sign a confidentiality agreement or a similar document. In case of using the services of an agency for personnel hiring, indicate if this has a documented procedure for personnel hiring and how you ensure that they comply. The procedures for personnel hiring and contractors may include: I. Thorough investigations of the work and personal backgrounds of new employees. II. Confidentiality and responsibility clauses in employee contracts. III. Specific requirements for critical positions. IV. If applicable, the periodic update of the socioeconomic or clinical laboratory study of employees who work in critical and/or sensitive areas. V. Hiring process and requirements requested for temporary employees and contractors.
7.2 Personnel dismissal procedure. There must be documented procedures for personnel dismissal in which the delivery of identification and any other item that has been provided to perform their functions (keys, uniforms, badges and/or credentials, computer equipment, passwords, communication devices, tools, etc.) is included. Likewise, this procedure must include the dismissal in those computer systems, access, among others that may exist.
Response: Explanatory Notes: Describe the procedure for personnel dismissal, and make sure to include the following: I. Who is responsible for carrying out and following up on this procedure. II. How the delivery of identification, uniforms, keys, and other equipment is carried out and confirmed. III. Indicate the control, record, and/or format, in which the delivery of material and dismissal in computer systems is identified and ensured (if applicable, attach). IV. Point out the type of personnel records of those who ended their labor relationship with the Industrial Park, so that when it has been for security reasons, it prevents tenant companies, service providers, and/or business associates.
7.3 Personnel administration. The Industrial Park Corporation must maintain an updated system, control, or database of active employees. Likewise, it must carry out and keep updated the records of affiliation to social security institutions and other legal labor records. In the case that the Industrial Park has personnel hired by its commercial partners and works within its facilities, it must ensure that they comply with the same requirements as the rest of its employees.
Response: Explanatory Notes: Indicate if the industrial park has an updated system, control, or database, both of personnel hired directly, as well as that hired through a service provider company and make sure it includes in an enumerative but not exhaustive manner the following points: I. Full name. II. Updated photograph at least every five years. III. Personal data (age, name, date of birth, phone number, address, CURP, social security number, blood type, allergies, etc.). IV. Affiliation. V. Work background. VI. Diseases. VII. Medical exams. VIII. Training. IX. Psychometric exams. X. Toxicological exams. XI. Results of periodic evaluations. XII. Observations. This personnel must be hired in accordance with the current labor laws and regulations.
8.1 Classification and handling of documents. Procedures must exist to classify documents according to their sensitivity and/or importance. Sensitive and important documentation must be stored in a secure area that only allows access to authorized personnel. The useful life of the documentation must be identified and procedures established for its destruction. The Industrial Park must have safeguarded and updated files of the co-owner and tenant companies with which it has a business relationship, as well as all information related to the security of its supply chain. The Industrial Park must conduct regular reviews to verify access to information and ensure that it is not used improperly. Response: Explanatory Notes: Attach the documented procedure for the registration, control, and storage of printed documentation (classification and filing of documents), which must include: I. Control register for delivery, loan, etc., of documentation. II. Restricted access to the archive area. III. Storage and classification policies. IV. An updated security plan that describes the measures in force regarding the protection of documents against unauthorized access, as well as against deliberate destruction or loss thereof. V. In the case of electronic or digital information, it must adhere to the security criteria of sub-standard 8.2. Information Technology Security.
8.2 Information Technology Security. To protect Information Technology systems against common cybersecurity threats, a company must have sufficient protection that promotes security in the Information Technology infrastructure (software and hardware) against malware (viruses, spyware, worms, trojans, etc.), baiting, phishing, and internal/external intrusions (firewalls) in the companies' computer systems. Likewise, companies must ensure that their security software is active and receives periodic updates. In the case of automated systems and computer equipment, individual accounts must be used that require periodic password changes. In order to protect the confidentiality, integrity, and availability of information, the company must have policies, procedures, and IT standards established, which must be communicated through a training program, for all employees who handle computer equipment and systems, including topics to prevent attacks through social engineering and all those threats to which they are exposed (malware, baiting, phishing, etc.). Companies that allow their employees to connect remotely to a network must use secure technologies, such as virtual private networks (VPN), to allow employees to access the company intranet securely when they are outside the office, as well as procedures designed to prevent unauthorized remote access. For the above, there must be written procedures and infrastructure to protect the Industrial Park Headquarters against loss, theft, leak, hacking, and/or ransomware of information, this includes the procedure for the recovery (or replacement) of Information Technology systems and/or data, as well as a system or software established to identify the abuse of systems, detect inappropriate access, improper manipulation or alteration of commercial and business data, as well as a written procedure for the application of appropriate disciplinary measures to all offenders. Access to Information Technology systems must be protected against infiltration through the use of secure passwords, which include phrases or other forms of authentication. Users of said Information Technology systems must safeguard and not share their access keys or passwords. All Information Technology infrastructure must be physically protected against unauthorized access. Response: Explanatory Notes: Attach the procedure for recovery that supports and guarantees the security of your information, in addition to protecting it from possible losses. Make sure to include the following points: I. Indicate the frequency with which backups are carried out. II. Who has access to them and who authorizes the recovery of information. III. Indicate what type of tests are performed and how often to verify the security of the network, systems, and infrastructure. IV. Mention if, to carry out this type of tests or vulnerability scans, it is done through software, a third party or provider, and if so, indicate the name or corporate name. V. In case vulnerabilities are found, describe the corrective actions that must be implemented. VI. Indicate if you share information about cybersecurity threats with your business partners who participate within your supply chain (for example: communications, bulletins, emails, etc.).
VII. Systems must be protected by passwords and must be modified frequently; indicate the procedure for changing them. VIII. Indicate if there are information security policies for their protection. IX. There must be a system to detect and identify the abuse, intrusion, or access of unauthorized persons to your systems, and/or Information Technology data, as well as the abuse of the policies and procedures established by the company, including unauthorized access to internal systems, external websites, and the manipulation or alteration of commercial data by employees or contractors. X. All offenders must be subject to the application of disciplinary measures; therefore, indicate the systems and policies of Information Technology security policies. Information Technology and cybersecurity policies and procedures must be reviewed annually and updated following an attack or according to situations that may put the company's systems at risk. Describe the security measures you use to allow employees to connect remotely to a network (VPN), to allow employees to access the company intranet remotely when they are outside the office. In case of allowing employees to use personal devices to perform the company's work, such devices must comply with the company's cybersecurity policies and procedures, security updates must be periodic, and there must be a method to access the company network securely.
Indicate if business partners have access to the Industrial Park's computer systems. If so, indicate what programs they use and how they control access to them. Indicate if the computer equipment has a backup power supply system that allows for business continuity. The procedures regarding the backup of the company's information must also include: I. How and for how long the data is stored (data should be backed up once a week or as appropriate). II. Business continuity plan in case of incident and how to recover the information. III. Frequency and location of backup copies and archived information. IV. If backup copies are stored in sites alternative to the facilities where the data processing center is located. V. Tests of the validity of data recovery from backup copies. The procedures regarding the backup of the Industrial Park's information must also include: I. How and for how long the data is stored (data should be backed up once a week or as appropriate). II. Business continuity plan in case of incident and how to recover the information. III. Frequency and location of backup copies and archived information. IV. If backup copies are stored in sites alternative to the facilities where the data processing center is located. V. Tests of the validity of data recovery from backup copies.
The procedures regarding the protection of the Industrial Park's information must also include: I. An updated and documented policy for the protection of the Industrial Park's computer systems against unauthorized access and deliberate destruction or loss of information. All sensitive and confidential data must be stored in an encrypted or encoded format. II. Detail if you operate with multiple systems (branches/sites) and how such systems are controlled. III. Who is responsible for the protection of the Industrial Park's computer system (responsibility should not be limited to one person, but to several, so that each can control the actions of the rest). IV. Each user's access must be assigned through individual accounts and restricted according to the job description or assigned tasks. For this reason, describe how access authorizations and access levels to computer systems are granted (access to sensitive information should be limited to authorized personnel to perform modifications and use of the information). Authorized access must be monitored by the area responsible for granting it, to verify or, if necessary, report that access to confidential systems is based on job requirements. V. Indicate the elements or format that passwords must have to access Information Technology systems and computer equipment, frequency of changes, if there are other authentication methods, and who or which area provides those passwords.
VI. Indicate the name of the firewall and antivirus used, providing evidence that this security software is active and receives periodic updates. For the above, cybersecurity policies and procedures should include measures to prevent the use of counterfeit products or those with incorrect licenses. All computer equipment, electronic media (hard drives, cell phones, etc.), and Information Technology hardware containing confidential information related to the import and export process must be accounted for through periodic inventories and have such evidence. When these technological equipment must be discarded, there must be a documented procedure that includes how they must be formatted, disinfected, or properly destroyed to avoid information leaks. VII. In case of staff turnover, access to computer equipment, telecommunications, and the network must be eliminated at the time of the employee's separation; this includes email accounts, system access accounts, software, programs, etc. VIII. Measures planned to handle incidents when the system is compromised.
9.1 Training and awareness on threats. The Industrial Park must have a training and awareness program on supply chain security policies directed at all its administrative and security employees; additionally, make informational material available regarding the procedures established in the Industrial Park to consider a situation that threatens its security and how to report it. Training records must include the date of the training, the names of the attendees, and the topics of the training. Likewise, security personnel must be offered training according to their functions to help the companies installed in the Industrial Park maintain the integrity of their cargo, recognize internal conspiracies, and protect access controls. In addition to security training programs, a program on awareness of alcohol and drug consumption must be included. Also, personnel must be trained in the company's cybersecurity policies and procedures, including access to computer equipment and systems via passwords or phrases; personnel who operate and administer security technology systems must receive training related to their operation and maintenance, including self-training through operational manuals and other methods. These topics must be established as part of new employee onboarding and periodic update programs must be maintained. Training programs must encourage active employee participation in security controls and mechanisms, as well as maintain records of all training efforts provided by the Industrial Park Headquarters and the list of those who participated in them (videos, photographs, minutes, attendance lists, intranet or other system, didactic material, PowerPoint presentations, brochures, etc.). Training records must include the date of the training, the names of the attendees, the topics taught, in addition to having measures to verify that the training provided met all training objectives. Response: Explanatory Notes: You must have a training program on security and prevention in the supply chain for all employees. Briefly explain what it consists of and make sure to include the following: I. Brief description of the topics taught in the program. II. When they are taught (onboarding, specific periods, etc.). III. Frequency of training and, if applicable, updates. IV. Indicate how participation in supply chain security training is documented.
V. Explain how employee participation in security matters is encouraged (videos, photographs, minutes, attendance lists, intranet or other system, didactic material, PowerPoint presentations, brochures, etc.). Records must include the date of the training, the names of the attendees, the topics taught, in addition to having measures to verify that the training provided met all the objectives of the same. Training to perform reviews of cargo vehicles, containers, trailers, and/or semi-trailers for agricultural and security purposes must include the following topics: I. Signs of hidden compartments. II. Hidden smuggling in natural compartments. III. Signs of pest contamination. IV. Procedures to follow if something is found during a transport medium inspection or if a security incident occurs during transit. V. Training on agricultural reviews must cover pest prevention measures, applicable regulatory requirements for wooden packaging materials, and the identification of infested wood (imports); for this reason, describe how you comply with the provisions established by SEMARNAT and NOM-144 SEMARNAT-2017, in accordance with International Standard for Phytosanitary Measures No. 15, known as Regulation of wooden packaging used in international trade, which emanate from the Food and Agriculture Organization of the United Nations.
Response: Explanatory Notes: Describe the documented procedure to initiate an investigation in case of any incident related to cargo security and make sure to include the following: I. Person responsible for carrying out the investigation. II. Documentation that integrates the incident security investigation file. The documents in the file derived from the investigation must include at least the following: I. General information of the shipment, service order. II. Transport request; confirmation of transport medium; identification of the transport operator (access records, exit, registration of security inspections, etc.). III. Transport medium inspection formats; exit orders; records of collection, delivery, and receipt of foreign trade merchandise. IV. Videos from alarm systems, closed-circuit television, and video surveillance. V. Documentation generated by and for business partners and customs authorities. VI. Follow-up and monitoring report of the unit (GPS tracking).
E11. Profile of the General Warehouse Deposit Receipt Acknowledgment First Time: Renewal: Addition: Modification: The data you provide will replace the data you provided when you requested your authorization. General Information The objective of this Profile is to ensure that general warehouses have security practices and processes implemented in their facilities, focused on strengthening the supply chain and mitigating the risk of contamination of shipments with illicit products. General warehouses interested in obtaining the authorization referred to in rule 7.1.5. must demonstrate that they have documented and verifiable processes; likewise, they must integrate the criteria required in this document according to the business model or design they have established, seeking during the implementation of security standards, the application of a risk analysis culture supported by decision-making in accordance with the values, mission, vision, codes of ethics, and conduct of the general warehouse itself. Filling Instructions: I. You must fill out a General Warehouse Deposit Profile for each of the installations that the general warehouse determines will be subject to certification, whether direct or enabled for a third party to operate them under the authorization. The Profile presented must coincide with the installation manifested in your application for registration as a certified business partner under the general warehouse deposit modality and with the registered address(es) with the RFC. II. In each sub-standard, the general warehouse must detail how it complies with or exceeds what is established in each of the sections as indicated. III. The format of this document is divided into two sections, as detailed below:
Installation Information: General Warehouse for Deposit Profile Number: From Key in the RFC: Name and/or Trade Name: Name and/or Denomination of the Installation: (If it does not exist, make the corresponding clarification and justification) Type of Installation: Street Number and/or exterior letter Interior Number and/or letter Neighborhood Postal Code Municipality/Alcaldía Federal Entity Age of the installation (years of operation to provide the services of warehousing of goods operated by the promoter): Activities carried out in the installation: Preponderant products that handle in the General Warehouse for Deposit (as applicable): No. of capacity letters issued monthly average: No. of extraction customs declarations monthly average: No. of total employees of this installation: Surface area of the Installation (m2 ): Certifications in security programs (indicate if this installation has a certification under any of the following programs). CTPAT Yes No Level: Pre-Applicant: Applicant: Certified: Certified/Validated: CTPAT Account number (Eight digits): Date of last visit to this installation: Authorized Economic Operator from other countries (AEO) Yes No Program: Registration: Other Supply Chain Security Programs Yes No Program: Registration:
Certifications (indicate if you have certifications that you consider impact your supply chain process, example: ISO 9000, ISO 28000, between others). Name: Category: Validity: Name: Category: Validity:
Response: Explanatory Notes: Indicate what are the sources of information used to qualify risks during the analysis phase. Attach the risk matrix, as well as the documented procedure to identify risks in the supply chain and the installations of the general warehouse for deposit, which must include as a minimum the following points: I. Periodicity with which the risk analysis is reviewed and/or updated. II. Aspects and/or areas of the general warehouse for deposit that are incorporated into the risk analysis. III. Methodology or techniques used to perform the risk analysis. IV. Persons responsible for reviewing and/or updating the risk analysis of the general warehouse for deposit. Likewise, the documented procedure to identify risks in the supply chain and its installations should contemplate the process of appreciation and management of risk, and include the following aspects: I. Establishment of a context (cultural, political, legal, economic, geographic, social etcetera). II. Identification of risks in your supply chain and its installations. III. Risk analysis (causes, consequences, probabilities and existing controls to determine the level of risk as high, medium and low). IV. Risk evaluation (decision making to determine the risks to be treated and priority to implement the treatment). V. Risk treatment (application of alternatives to change the probability that the risks occur).
VI. Risk monitoring and review (monitoring of the results of the risk analysis and verification of the effectiveness of its treatment). It is suggested to use the techniques of administration, management and risk evaluation according to the international standards ISO 31000, ISO 31010 and ISO 28000 that, according to your business model, you must implement. 1.2 Security policies. The general warehouse for deposit must have a policy oriented to prevent, secure and recognize threats to the security of the supply chain and warehouse installations, such as drug trafficking, human smuggling, money laundering, arms trafficking, prohibited goods, acts of terrorism, as well as those threats associated with the exchange of information. Such policies must be reflected in the corresponding procedures and/or manuals. To promote a culture of security, the general warehouse for deposit must demonstrate its commitment to supply chain security and the Authorized Economic Operator Program through a statement highlighting the importance of protecting the flow of national and international trade from criminal activities, established through the security policy. The senior officials or executives of the warehouse who must endorse and sign the security policy can be the president of the company, the director executive, the general manager or personnel with a homologous position with decision-making authority. Response: Explanatory Notes: State the security policy oriented to prevent, secure and recognize threats in the supply chain and installations of the general warehouse for deposit, indicate who is responsible for its review, signature and dissemination to employees, as well as the periodicity with which its update is carried out. Such policy must be communicated to employees through a program and/or dissemination campaign. The security policy must be signed by a senior official of the general warehouse for deposit and be exhibited in various areas of the company, including the company website, posters in key areas of the company (reception, shipments, receipts, warehouse, etcetera), and as part of the initial and reinforcement training of the company.
1.3 Internal audits in the supply chain. In addition to routine monitoring in control and security, it is necessary to schedule and carry out audits at least once a year, under the guidelines of a documented procedure that allows evaluating all processes in terms of security in the supply chain and its installations in a more critical and deep way, as well as guaranteeing that its employees follow the warehouse's security procedures. The audits must be carried out by the Security Committee of the general warehouse for deposit and a documented procedure must be established, as well as a program or calendar for their realization. Although it is necessary that the audits are focused on supply chain security and based on the evaluation, review and execution of the minimum standards in terms of security, their focus must be adjusted to the size of the organization, business model, variation between installations and level of risk, identified during the analysis according to sub-standard 1.1. The audits can be general or focus on specific areas or processes according to your work program. The objective of an internal audit focused on the Authorized Economic Operator Program is to verify and guarantee that employees follow the security procedures of the general warehouse for deposit. The review process does not have to be complex, however, the formats and records used for the application of such reviews must evidence that the application and execution of the evaluated processes were validated, in addition to the corresponding follow-up of the identified observations. The senior management of the warehouse must review the results of the audits, analyze the causes and undertake corrective or preventive actions required. The audit process must guarantee that the necessary information is collected to allow management to perform this evaluation. The review must be documented, in addition to the fact that the company's points of contact must provide and register periodic updates on the process or the results of any audit, exercise or validation. Response: Explanatory Notes: Describe the documented procedure to carry out an internal audit, focused on security in the supply chain, make sure to include the following points: I. Indicate how the general warehouse for deposit carries out the scheduling or calendarization to carry out internal audits in terms of security in the supply chain. II. Indicate who participates in them and the records that are generated, as well as the periodicity with which they carry them out. III. Indicate how the management of the warehouse general deposit verifies the result of the audits in terms of security of the supply chain and how it carries out and/or implements actions preventive, corrective and improvement as well as follow-up and closure of the same.
IV. The formats used during the internal audits must be duly requisitioned and through them, evidence that the procedures and security measures are being put into practice. 1.4 Contingency and/or emergency plans. There must be a documented contingency and/or emergency plan, said plan must address crisis management, security recovery plans and business resumption to ensure business continuity in the event of a situation that affects the normal development of activities and operations of foreign trade of the warehouse in its supply chain (installations and during the receipt, storage, custody and extraction of goods intended for the tax deposit regime and national goods according to its logistical process). A crisis or contingency may include the interruption of the movement of commercial data due to a cyber attack, a fire, the kidnapping of a transport driver by armed persons, the theft and/or damage of goods, theft of labels and/or tags, chemical spills, a bomb threat, the detection of suspicious packages, the cut of electrical energy, non-arrival of the goods, blockages or closure of highways, threats or extortions, a customs closure, among others. Such plans must be communicated to employees through a program and/or dissemination campaign, as well as carry out tests, practical exercises and annual simulations of the supply chain contingency and emergency plans to verify their effectiveness, and of which you must keep a record duly requisitioned and signed (for example: result reports, minutes or reports, which must be backed up by video recordings, photographs, etcetera) that demonstrate their execution. The contingency and/or emergency plan must be updated as necessary, based on changes in operations and the level of risk of the warehouse general deposit. Response: Explanatory Notes: Attach the documented contingency and/or emergency procedure or plan, to ensure continuity of business in the event of an emergency or security situation, that affects the normal development of activities in the installations, during receipt, storage, custody and extraction of goods intended for the tax deposit regime and national, according to its logistical process in the supply chain. This procedure must include, in an enumerative but not limiting manner, the following: I. What situations it contemplates, describing the plan of action and steps to be followed in case of crisis, as well as the tasks that the personnel have assigned during the handling of such contingencies.
II. What mechanisms it uses to disseminate and guarantee that the business continuity plan is effective. III. Contemplate the scheduling and realization of tests, practical exercises and annual simulations and how they are documented (for example: reports of results, minutes or reports, which must be accompanied by video recordings, photographs, etcetera, that demonstrate their execution). 2. Physical security. The general warehouse for deposit must have established mechanisms and documented processes to prevent, detect or dissuade the entry of unauthorized personnel into the installations. All sensitive areas of the general warehouse for deposit must have physical barriers, as well as control and dissuasion elements against unauthorized access. 2.1 Installations. The installations must be constructed with materials that can resist unauthorized access. Periodic documented inspections must be carried out to maintain the integrity of the structures and in the event that an irregularity has been detected, carry out the corresponding repair and as soon as possible by the personnel designated for these tasks. Likewise, the territorial limits must be fully identified, as well as the various accesses, internal routes and the location of the buildings. Response: Explanatory Notes: Indicate the predominant materials with which the installation is constructed (for example: steel structure with cement walls, brick walls, concrete, among others), and indicate how the review and maintenance of the integrity of the structures is carried out. Indicate the personnel or area responsible for carrying out the tasks of inspection, maintenance and repair of damages to the installations. Attach a distribution or architectural plan of the whole, where the limits of the installation, access routes, emergency exits, location of buildings, critical areas, parking and adjacencies can be identified.
2.2 Accesses in doors and booths. The entrance or exit doors of personnel and/or vehicles of the installations of the general warehouses for deposit must be attended, controlled, watched and/or supervised either by means of own personnel or well by security personnel. The number of access doors must be kept to the minimum necessary. Access to sensitive areas must be restricted according to the job description or assigned tasks. Response: Explanatory Notes: Indicate how many doors and/or accesses exist in the installations, as well as the operating hours of each one and indicate how they are monitored and/or supervised (if you have assigned surveillance personnel, indicate the quantity). Detail if there are doors and/or blocked accesses, or permanently closed and their location. Describe how you ensure that access to the sensitive areas is restricted according to the job description or assigned tasks (include the type of records and controls you use). 2.3 Perimeter fences. The perimeter fences and/or peripheral barriers must be installed to secure the perimeters of the installations of the general warehouse for deposit, and in particular, the areas of receipt, storage, custody and extraction of goods intended for the tax deposit regime, national goods, high value, hazardous, areas with restricted access and others that you determine according to your risk analysis, with the object of preventing theft of goods and unauthorized entries. These must be inspected regularly and keep a record of the review with the purpose of ensuring their integrity and identifying damages, which must be repaired as soon as possible by the personnel designated for these tasks. The storage, high value, hazardous, and/or restricted access areas, must be clearly identified and monitored to prevent unauthorized entries. Response: Explanatory Notes: Describe the type of peripheral barrier and/or fences with which the installation has, make sure to include the following points: I. Specify what areas segregate in the installation by being considered critical and/or sensitive. II. Point out their characteristics (material, dimensions, etcetera).
III. In case of not having fences, please justify detailedly the reason. IV. Periodicity with which the integrity of the perimeter fences is verified, and the records that are carried out with the purpose of ensuring their integrity and identifying damages, which must be repaired as soon as possible. V. Indicate the personnel or area responsible for carrying out the tasks of inspection and repair of damages. Describe how the cargo destined for foreign countries, hazardous material and high value cargo is segregated; make sure to include the following points: I. Indicate how you control and separate the goods destined for the tax deposit regime, national goods, and if it is additionally identified (for example: labels, different packaging, slips, among others). II. Identify and point out the restricted access areas (hazardous goods, high value, placement of labels, labeling, sub-maquila, confidential, etcetera). The procedure for the inspection of the perimeter fences could include: I. Personnel responsible for carrying out the process. II. How and with what frequency the inspections of the fences, perimeter fences and/or peripheral fences are carried out. III. How the inspection record is kept. IV. Who is responsible for verifying that the repairs and/or modifications comply with the technical specifications and security requirements necessary.
2.4 Parking. Access to the parking areas of the facilities must be controlled and monitored by security personnel or personnel designated for this task in accordance with applicable provisions. Private vehicles (of employees, visitors, suppliers, and contractors, among others) must be prohibited from parking within the areas for handling and storing merchandise, as well as in adjacent areas. Response: Explanatory Notes: Describe the procedure for controlling and monitoring parking, ensuring you include the following points: I. Those responsible for controlling and monitoring access to the parking areas. II. Identification of the parking areas (specify if the visitor and employee parking is separated from the merchandise storage areas). III. How entry and exit of vehicles to the facilities is controlled, indicate the records kept for parking control and the existing control mechanisms (for example: tokens, card readers, badges, etc.), how they are assigned, and the responsible area for doing so. IV. Policies or mechanisms to prevent private vehicles from entering the merchandise storage areas.
2.5 Control of keys and lock devices. Windows, doors, as well as interior and exterior fences, according to their risk analysis, must be secured with locking devices. The general deposit warehouse must have a documented procedure for the handling and control of keys and/or locking devices for the interior areas considered critical. Furthermore, they must keep a register and establish signed responsibility letters from persons who have keys or authorized access according to their level of responsibility and tasks within their work area. Response: Explanatory Notes: Indicate if all doors, windows, interior and exterior entrances have closing or security mechanisms. Attach the documented procedure for the handling, safeguarding, assignment, control, and non-return of keys for the facilities, offices, and critical and/or sensitive areas.
The procedure must include the following points: I. Those responsible for administering and controlling key security. II. Format and/or control register for key lending. III. Treatment of loss or non-return of keys. IV. Indicate if there are areas where access is granted with electronic devices and/or any other access mechanism.
2.6 Lighting. Lighting inside and outside the facilities must allow for clear identification of persons, material, and/or equipment located therein, including the following areas: entrances and exits, handling, loading, unloading, and merchandise storage areas, perimeter and/or peripheral walls, interior fences, and parking areas, and must have an emergency and/or backup lighting system in sensitive areas. Response: Explanatory Notes: Describe the procedure for the operation and maintenance of the lighting system. Ensure you include the following points: I. Indicate which areas are illuminated and which have an emergency and/or backup system (indicate if you have an auxiliary power plant or any other mechanism to supply electricity in case of any contingency). II. How do you ensure that the lighting system has continuity in the event of a supply failure in each of the installation areas and with special emphasis on areas considered critical and/or sensitive, in a way that allows clear identification of the personnel, material, and/or equipment located therein. III. Person responsible for controlling and maintaining the lighting systems. IV. Maintenance and review program (if it coincides with another process, indicate it).
The procedure may include: I. How the lighting system is controlled. II. Operating hours. III. Identification of areas with permanent lighting.
2.7 Communication devices. The general deposit warehouse must have communication devices and/or systems for the purpose of contacting security personnel and/or authorities immediately when required in case of an emergency and security situation. Additionally, it must have a backup system and verify its proper functioning periodically. Response: Explanatory Notes: Describe the procedure that personnel must perform to contact the security personnel of the general deposit warehouse or, in its case, the corresponding authority in case of any security incident. Indicate if operational and administrative personnel have or have access to devices (landline phones, mobile phones, alert and/or emergency buttons, etc.) to communicate with security personnel and/or whoever corresponds (these must be accessible to users to be able to react promptly). Indicate what type of communication devices the security personnel of the general deposit warehouse uses (landline phones, cell phones, radios, alarm system, etc.). Describe the procedure for controlling and maintaining communication devices, ensure you include the following points: I. Policies for assigning mobile communication devices. II. Maintenance or replacement program for fixed and mobile communication devices. III. Indicate if you have backup communication devices when the permanent system fails, and in its case, describe them briefly.
The procedure may include: I. Person responsible for the proper functioning and maintenance of communication devices. II. Verification and maintenance register of the devices. III. Method of assigning communication devices.
2.8 Alarm systems, closed-circuit television, and video surveillance systems. Alarm systems, closed-circuit television, video surveillance systems, and security technologies must be used to monitor, notify, or deter unauthorized access and prohibited activities in the facilities and other areas considered sensitive, notify the corresponding area, and also be used as evidence in investigations derived from any security incident. These security systems and technologies must be placed according to a prior risk analysis, in such a way that it allows clear identification of the area or environment being monitored, to monitor and supervise areas involving the entry and exit of authorized personnel, visitors, suppliers, areas involving the handling, loading, unloading, custody, and storage of merchandise destined for the fiscal and national deposit regime, security inspections of cargo vehicles, yards for transport means, parking of private vehicles, as well as areas considered critical and/or sensitive on a permanent and uninterrupted basis in accordance with their operation. The general deposit warehouse must have documented operating procedures for the aforementioned systems. In the case of alarm systems, closed-circuit television, video surveillance systems, and security technologies, the procedure must include the supervision of the good condition of the equipment, indicating the frequency with which recordings must be backed up, those responsible for their operation, and the verification of the correct position of the cameras. Alarm systems, closed-circuit television, and video surveillance systems must allow clear identification of the area or environment being monitored, be recording permanently, and maintain a backup of recordings for at least one month, considering that, in the case that their logistical processes exceed this period, the period for maintaining these backups must be increased in order to have the necessary elements to assign corresponding responsibilities in case of a security incident. Such systems and all security technology infrastructure must have restricted access. The alarm systems, closed-circuit television, and video surveillance systems, and security technologies of the general deposit warehouse must comply with what is established in rule 4.5.18., so that the customs authority has access to the merchandise delivery points, as well as the exit points, as determined by ANAM. Response: Explanatory Notes: Mention the documented procedure in which Indicate the functioning of the external alarm system or sensors, and in its case, describe the following points: I. Indicate if doors and windows have alarm sensors, as well as the areas where motion sensors are available.
II. Procedure to follow in case an alarm is activated. III. Indicate the personnel or area responsible for maintenance, how failures are reported, and the records they use. Describe the documented procedure for the operation of alarm systems, closed-circuit television, and video surveillance systems, and security technologies (this must be reviewed and updated annually and according to the risk analysis or circumstances), ensure you include the following points: I. Indicate the number of security cameras of the alarm systems, closed-circuit television, and video surveillance systems installed, technical characteristics, and their location by area (detail if they cover the entry and exit points of the facilities to cover the movement of vehicles and individuals, and where the inspection mentioned in sub-standard 7.2 is carried out, as well as the merchandise storage area destined for the fiscal and national deposit regime). Attach a layout or map of the distribution of security cameras. II. Indicate the location of the alarm systems, closed-circuit television, and video surveillance systems, and security technologies, where the monitors are located, who reviews them, as well as the operating hours, and in its case, if there are remote monitoring stations. All security technology infrastructure must be physically protected against unauthorized access. III. Perform periodic and random reviews of the recordings. Indicate how they review them (random, weekly, special events, restricted areas, etc.), who is the designated personnel, and if management is involved in the reviews. The results of the reviews must be documented to include corrective actions for audit purposes.
IV. Indicate for how long these recordings are kept (must be at least one month). V. The alarm systems, closed-circuit television, and video surveillance systems, and security technologies must have an alternative energy source that allows them to continue functioning in case of an unexpected loss of direct power. For the above, indicate if the alarm systems, closed-circuit television, and video surveillance systems, and security technologies are backed up by an emergency power plant or any other mechanism to supply electricity that guarantees their functioning. These systems should have an alarm/notification function, indicating a failure condition in functioning and/or recording, indicate if their systems have such a function. VI. Indicate if, in addition to the alarm systems, closed-circuit television, and video surveillance systems, you use any other type of technology to strengthen the security measures already in place. VII. Describe the procedure implemented to regularly test and inspect the alarm systems, closed-circuit television, and video surveillance systems, and security technologies and ensure their proper functioning. The results of the inspections and functioning tests must be documented, as well as the necessary corrective actions (these must be implemented as soon as possible). Additionally, that the documented results of these inspections are kept for a sufficient time for audit purposes. VIII. Indicate if the provider of alarm systems, closed-circuit television, and video surveillance systems has access to the security cameras, if they are in charge of monitoring them, how access is controlled, and who is responsible for said monitoring.
3.2 Employee identification. There must be an employee identification system for access to the facilities. Employees should only have access to those areas they need to perform their functions. The company's management or security personnel must properly control the delivery and return of employee badges and/or identification credentials for employees, visitors, and suppliers. Procedures for the delivery, return, and change of access devices (for example, keys, badges and/or credentials, proximity cards, etc.) must be documented. Access to sensitive areas must be restricted according to the job description or assigned tasks. Response: Explanatory Notes: Describe the procedure for employee identification and ensure you include the following points: I. Identification mechanisms (badge and/or photo credential, biometric access control, proximity cards, etc.). II. Indicate if employees use uniforms, how they are assigned (by positions, areas, functions, etc.) and withdrawn (if applicable). III. Indicate how contracted personnel by a business partner working within the facilities are identified (contractors, subcontractors, in-house services, merchandise handling company personnel, sub-maquiladora, etc.). The procedure must also describe how the general deposit warehouse delivers, changes, and withdraws employee identification and access controls, ensure you include the responsible areas for authorizing and administering them. Indicate how you ensure that access to sensitive areas is restricted according to the job description or assigned tasks (include the type of records and controls you use). Attach the documented procedure for the control of identifications.
3.3 Visitor and supplier identification. To have access to the facilities, visitors and suppliers must present official identification with a photograph for documentation upon arrival and a record must be kept. All visitors and suppliers must receive a temporary identification, be accompanied by warehouse personnel during their stay in the facilities, and ensure that the visitor/supplier always wears the provisional identification provided in a visible place; this procedure must be documented. In the case of suppliers and users who work regularly in the facility, the general deposit warehouse must have a mechanism or system for controlling identification badges. Response: Explanatory Notes: Describe the procedure for controlling access by visitors and suppliers, ensure you include the following points: I. Indicate what records are kept (personal formats for each visit, logbooks, among others). II. The visitor and supplier register must include the following: a) Date of the visit. b) Name of the visitor. c) Identification number with photo (official documents such as: driver's license, passport, INE, etc.). d) Entry and exit time. e) In the case of vehicle access, the format must include the data of the private or cargo vehicle (model, license plate, trailer number, etc.). III. Indicate who is the person responsible for accompanying the visitor and/or supplier and if there are restricted areas for their entry. 3.4 Procedure for identifying and withdrawing unauthorized or identified persons or vehicles. The general deposit warehouse must have documented procedures that specify how to identify, confront, or report unauthorized or identified persons and/or vehicles; said procedure must be communicated to responsible personnel through training. The training must be documented.
Response: Explanatory Notes: Attach the documented procedure to identify, confront, or report unauthorized or identified persons and/or vehicles. The procedure must include: I. Personnel in charge of carrying out the procedure. II. Designate a person or area responsible for being informed of security incidents. III. Instructions for confronting and addressing unidentified personnel. IV. Indicate in which cases the corresponding authorities must be reported. V. How security incidents and measures adopted in each case are recorded. 3.5 Courier and package deliveries. Courier and package deliveries intended for general deposit warehouse personnel must be registered and examined upon arrival and departure before being distributed to the corresponding areas and destinations. Likewise, the company must have a documented procedure for the receipt and review of courier and packages, which must be communicated to responsible personnel through training. The training must be documented. Response: Explanatory Notes: Describe the procedure for the receipt and review of courier and packages, and ensure you include the following: I. Personnel in charge of carrying out the procedure. II. Indicate how you identify the personnel or provider of the courier and package service (indicate if an additional procedure to supplier access is required). III. Indicate how the review of courier and/or packages is carried out, what mechanism you use, the records kept, and in its case, the incidents detected. IV. Describe the characteristics or elements to determine if courier and/or packages are suspicious. V. Indicate what actions you take in case of detecting suspicious courier and/or packages.
4.1 Selection Criteria. There must be documented procedures for the selection, follow-up, or renewal of commercial relationships with business associates and/or suppliers, which include interviews, reference verification, evaluation methods, and use of provided information. The information derived from the investigation and/or evaluation of business associates and/or suppliers must be documented and integrated into a file (physical or electronic). The procedure for the selection of commercial partners must include indicators to identify clients or suppliers that may not be legitimate or with unlocated addresses, as well as investigations, reviews, or evaluations of said partners for the identification and control of activities related to money laundering and terrorism financing. If the investigation and/or evaluation of any commercial partner leads to substantial doubts about the veracity of their operations or services, the general warehousing company must avoid hiring them and, where applicable, notify its security specialist or Authorized Economic Operator Program contact and the corresponding authority about its suspicions.
Response: Explanatory Notes: Attach the documented procedure for the selection and contracting of new commercial partners and monitoring of partners already working, this includes any type of supplier that has a relationship with your logistical process and supply chain (it is in the following sub-standard where it is requested to differentiate those at risk in your supply chain), likewise, with potential and predominant clients to hire their service frequently and/or those who have a commercial relationship with the general warehousing company. Ensure you include the following points:
I. What information is required from your commercial partner. II. What aspects are reviewed and investigated (the result of the investigation must be integrated into the file). III. Indicators to identify clients or suppliers that may not be legitimate (payments above standard rate, in cash; having little knowledge of the merchandise to be shipped; being evasive; minimal contact information (cell phone, contact points, emails, etc.); recently created companies or businesses without commercial history, etc.) or with unlocated addresses. This point refers to pointing out all those alerts to determine that a commercial partner is not reliable and thus carry out a deeper investigation and evaluate whether to work with him. IV. Indicate if you maintain a physical or electronic file of each of your commercial partners, as well as the information it must contain. V. Point out how you evaluate the services of your commercial partner and what points you review. The file must include at least the following: I. Company data (name, RFC key, activity, etc.). II. Legal representative data. III. Proof of address. IV. Commercial references (where applicable). V. Contracts, agreements, and/or confidentiality agreements. VI. Security policies. VII. Where applicable, certificate or certification number in the security programs to which it belongs.
4.2 Security Requirements. The general warehousing company must have a documented procedure in which, according to its risk analysis, it requests additional security requirements from those commercial partners that intervene in the service provided by said warehouse and in its supply chain, whether as providers of pallets and supplies for packaging/boxing of merchandise, providers of high-security seals, as well as providers of services that also intervene in the control, manipulation, transport, and/or storage of merchandise destined for the fiscal deposit and national regime such as: cleaning service providers, private security, personnel hiring, storage service providers, cargo loading/unloading and handling, collection and recycling, providers of high-security seals, installation and maintenance of alarm systems and closed-circuit television and video surveillance, subcontractors, and where applicable, carriers for the transport and/or distribution of merchandise destined for the fiscal deposit regime, and those that handle import and export documentation, such as customs brokers, among others. The requirements must be based on the General Warehousing Profile established by AGACE generically, or in case it exists, the specific Profile for each actor in the supply chain that corresponds to them. The general warehousing company must request from its commercial partners the documentation that accredits and proves that they comply with the minimum security standards established in this General Warehousing Profile, either through a written statement issued by the legal representative of the partner, agreements or contractual clauses, backed up with documentation that supports compliance with the requirements established in the Authorized Economic Operator Program. Likewise, the warehouse must take into account and know the specific requirements of the Authorized Economic Operator Program that will be applicable to each of its commercial partners, depending on their activity within the supply chain. In the case of commercial partners of the general warehousing company that provide their services inside the facilities, they must be obligated to comply with these supply chain security requirements.
Response: Explanatory Notes: Describe the procedure that indicates how you carry out the identification of commercial partners that must comply with minimum standards in terms of security. Ensure you include the following points: I. A register of commercial partners that must comply with security requirements, and mention what type of providers these are (carriers for the transport and/or distribution of merchandise destined for the fiscal deposit regime, cleaning service providers, cafeteria, private security, material suppliers, personnel hiring, storage service providers, cargo loading/unloading and handling, subcontractors, etc.). II. Indicate in what documentary form (agreements, arrangements, contractual clauses and/or addenda) you ensure that your commercial partners comply with security requirements. III. Indicate if there are agreements, arrangements, contractual clauses and/or addenda regarding the implementation of security measures with your service providers inside the general warehousing company, such as: customs brokers, private security, cleaning and maintenance services, cafeteria, landscaping, Information Technology providers, etc. IV. Indicate if you have commercial partners who are required to belong to a supply chain security program (for example: CTPAT, or some other World Customs Organization Authorized Economic Operator Program) as well as the information and documentation requested of them.
4.3 Commercial Partner Reviews. The general warehousing company through the Security Committee must carry out periodic security evaluations (as well as those derived from risk situations) of the processes and installations of business associates based on a risk analysis to guarantee that they have minimum standards in terms of security required by the warehouse, based on the Authorized Economic Operator Program, keep records of the same, which allow to verify that processes and security measures are being executed, as well as the corresponding follow-up. When inconsistencies are found, the general warehousing company must communicate them to its partner and/or supplier and provide a justified period to attend to the observations or areas of opportunity identified, or otherwise, have the necessary measures to sanction it. Carrying out security evaluations of commercial partners is important to guarantee that there is a solid security program and that it works correctly, which is why, in addition to a documented procedure, there must be a program or calendar for the execution of said reviews or security evaluations prioritizing partners that are more critical according to their risk analysis. If a member is not evaluated and the company does not know if the processes and installations of its commercial partners function correctly, it puts its supply chain at risk.
Response: Explanatory Notes: The general warehousing company must have a documented procedure to carry out evaluations for the verification or review of security requirements in the processes and installations of commercial partners. Describe the procedure to carry out the reviews of your commercial partners, ensuring you include the following points: I. Periodicity with which you make visits to the commercial partner (this must be at least once a year and derived from risk situations). II. Program or calendar for the execution of security reviews. III. Records or reports of the verification or review and, where applicable, the corresponding follow-up. IV. The verification formats must be duly filled out, placing the date, name and position of those participating in the review, signatures, etc. V. Point out what action measures are taken when commercial partners do not comply with the established security requirements. In case of having commercial partners that count with CTPAT certification or another supply chain security certification program, indicate the periodicity with which its status is reviewed, how you record it and the actions you take in case it is detected that this is suspended and/or cancelled according to what is established in your procedure. The procedure must include: I. Periodicity of visits. II. Area or person responsible for carrying out this procedure. III. Points of review in terms of security. IV. Elaboration of reports. V. Feedback and agreements with the commercial partner. VI. Follow-up to agreements. VII. Measures in case of detection of non-compliance with requirements. VIII. Record of evaluations.
5.1 Process Mapping. There must be a map that shows step by step the logistical process of the flow of merchandise destined for the fiscal deposit regime during its deposit, handling, and custody, as well as the documentation required through the international supply chain (letter of credit, extraction customs declarations, etc.). The general warehousing company must take into account and include within its mapping all parties involved in its supply chain, containing warehouses, warehouses or additional distribution centers (direct and/or authorized), and where applicable, those that handle import and export documentation, such as customs brokers, others that may have operational control such as carriers, etc. If within your supply chain any part of the transport is subcontracted, it is indispensable that it be considered within your risk analysis and process mapping, since the more direct and indirect suppliers, the greater the risk involved.
Response: Explanatory Notes: Attach the process map where the flow through which import and export merchandise destined for the fiscal deposit regime passes is illustrated and described, from entry into the warehouse until the extraction of the merchandise, and where applicable, have well identified the transfer of merchandise destined for the fiscal deposit regime to a different warehouse or storage facility (authorized or direct) due to a client's requirement, as well as the transfer or handover of cargo when applicable. Likewise, it is necessary to include a procedure to carry out value-added operations on the merchandise (placement of labels, labeling, packaging for display or sale, etc.). And where applicable, those that handle import and export documentation, such as customs brokers, others that may have operational control such as carriers, etc. This process map must contain at least the following aspects: I. Quotation. II. Service contract. III. Issuance and transmission of the letter of credit through your electronic system to that of the Tax Administration Service. IV. Arrival of merchandise at the general warehousing company. V. Merchandise receipt process. VI. Generation of fiscal and/or identification labels. VII. Integration of customs documentation, for example: a) Verification of commercial information. b) Import or fiscal deposit customs declaration. c) Commercial invoice. d) Packing list. e) Packing guides. f) Import permits, Certificates of Origin, accreditation of compliance with the Mexican Official Standard. VIII. Verification where applicable of the verification unit (UVA). IX. Receipt of extraction request. X. Exit of merchandise, among others.
5.2 Direct and Authorized Warehouses, Distribution Centers, Yards, and Stores. When the general warehousing company has direct and/or authorized warehouses, they must be subject according to their characteristics to what is established in this document, with the objective of maintaining integrity in the supply chain.
Response: Explanatory Notes: According to the process mapping of merchandise destined for the fiscal deposit regime, declare if the general warehousing company has additional warehouses, stores, or distribution centers, and specify if they are direct and/or authorized.
5.3 Delivery and Receipt of Merchandise. The general warehousing company must supervise the receipt and delivery of merchandise in its facility, ensuring at all times its correct identification, registration, and handling according to the procedures established by the warehouse, including instructions or specifications received from clients, where applicable, for their handling and transport. For the above, the general warehousing company must have documented procedures that allow it to safely carry out the delivery and receipt of cargo in distribution centers or warehouses (direct and/or authorized), said procedures must include the reception, generation of letter of credit registration in system, handling according to client specifications, scheduling of tasks for entry into the warehouse, unloading, correct identification and conditioning of the merchandise until location in warehouse, documentation generated for the carrier, client, and service personnel. Likewise, the general warehousing company must have control mechanisms for the reception of transport units, in addition to the identification and registration of operators who effect the delivery or receipt of merchandise in the facilities. Likewise, it must guarantee that operators who transport the merchandise, during delivery and/or receipt have all the required documentation to authorize their entry or extraction from the general warehousing company and where applicable, the documentary information required for its correct transport which includes, in an enumerative but not limiting manner, destination, route that must be maintained, contact data and/or procedure in case of any security incident or inspection by any authority, among others. The cargo preparation areas and the immediate surrounding areas must be inspected regularly to guarantee that these areas remain free of visible contamination by pests. During the process of loading and unloading merchandise, the company's security area (supervisor or security guard) must be present to validate that the process is being carried out correctly, mitigate the risk of shipment contamination (prohibited, illicit merchandise or pests) and register said review (novelty report, records, reports, etc.), as evidence that the high-security seal and/or lock was placed correctly, digital photographs must be taken at the moment of loading vehicles. To the extent possible, these images should be sent electronically to the destination or delivery point of the merchandise for verification purposes. Also, the personnel responsible for the shipping and/or receiving area must review the information included in import and/or export documents to identify or recognize suspicious cargo shipments. Likewise, specific training must be provided on the identification of common errors in export shipment documentation, with the aim of preventing these from resulting in security incidents or suspicious merchandise.
Response: Explanatory Notes: Attach the documented procedure in which you indicate the process for the receipt and delivery of merchandise in the facilities, verifying at all times its correct identification, registration, and handling according to the procedures established by the warehouse and ensure you include the following points: I. Method of receipt, unloading, and verification of merchandise. II. Method for identifying transport operators. III. Generation of letter of credit. IV. Registration in system (corporate). V. Warehouse or client specifications. VI. Identification of merchandise. VII. Documentation generated for the carrier, client, and service personnel. VIII. Merchandise extraction process. IX. Documentation delivered to operators. X. How you verify and guarantee that cargo preparation areas and immediate surrounding areas remain free of visible pest contamination. In case of identifying any type of visible pest, contamination, trash, insects, grass, weeds or overgrown grass, how it is reported and what actions you take regarding it. XI. Indicate how you control or what security measures you have implemented to mitigate the risk of collusion or complicity between employees, such as the driver and personnel in dispatch areas (where applicable) warehouse, security guards, etc. XII. Indicate if you carry out permanent or random reviews of the luggage of transport operators who enter your facilities to deliver or pick up cargo. In case of identifying any anomaly or having a suspicion, describe the actions you take regarding it and how you report it to the authority. The merchandise delivery and receipt procedure must include: I. Inspection method at the access point to the warehouse. II. Designation of personnel responsible for identifying and registering operators of transport means upon arrival. III. Registration of introduction to the general warehousing company of merchandise. IV. Exit from the general warehousing company.
5.4 Cargo tracking procedure. When the transfer of goods is carried out at the expense of the general warehouse, in accordance with its risk analysis, the integrity and traceability of the goods destined for the fiscal deposit regime must be ensured during their transfer between warehouses, distribution centers, and warehouses previously authorized for this type of goods. The general warehouse must monitor at all times the transfer of the goods (provided it is its responsibility) to another authorized warehouse of the same warehouse or transferred to a different one, verifying that, for its transfer, the documentation supporting the goods is generated (copy of the import or export petition for fiscal deposit, as well as with the tax receipt issued by the same general warehouse) and must give the corresponding transfer notice to the authority through electronic transmission to the SAAI, indicating the necessary information (folio of the electronic capacity letter, number of authorization or key of the authorized warehouse to which the goods will be transferred, tariff fraction, etc.), in accordance with what is established in rules 4.5.13. and 4.5.14. If as a result of monitoring and tracking, a real (or realized) threat to the security of a shipment or means of transport is identified, the general warehouse must alert (as soon as possible) the business partners in the supply chain that may be affected and, if applicable, to the authority as appropriate. Response: Explanatory Notes: Attach the documented procedure to monitor the transfer of goods destined for the fiscal deposit regime, to another authorized warehouse of the same warehouse or transferred to a different one, in accordance with what is established in rules 4.5.13. and 4.5.14. This procedure must include, among other aspects according to its operation: I. Indicate the type of system implemented by the units used to control the goods destined for the fiscal deposit regime and, if applicable, if it is a third-party or subcontracted service, describe the consultation tools available to monitor the goods. II. Identification of predetermined routes and estimated transfer/delivery times, between intermediate points, as well as overnight and/or rest (yards, exit customs, customs broker or customs agency facilities, freight agents, among others). Once the time between the assigned points has been determined, they must have a tracking process (route audit) and the corresponding records.
III. In the case of geofences, within their parameters, minimum tolerances allowed for the predetermined transit route must exist or be established. IV. There must be systems or procedures with instructions in case of a delay in the route (stops, changes or diversions of route, mechanical failures, accidents, etc.). Likewise, drivers must notify (to their supervisor and, if applicable, to the sender or consignee of the goods) any significant delay in the route due to weather, traffic, accidents, mechanical failures, route change, etc. And on its part, the company must independently verify the cause of said delay. V. Detail if it has communication means for the tracking of the goods. VI. Indicate the area or person responsible for supervising this process. The procedure must also include that, in case of identifying a real or realized threat to the security of a shipment or means of transport; how the company informs the business partners of its supply chain that may be affected and, if applicable, to the authority as appropriate, about this type of incidents or presumptions. 5.5 Report of discrepancies in the load. There must be documented procedures to detect and report missing, excess, prohibited, or any other discrepancy in goods during delivery and/or receipt of the goods, with the purpose of having information that contributes to the corresponding investigations by the competent authorities in case of any security incident. Likewise, it must describe the measures and actions to be taken in case of identifying illicit, undeclared, and prohibited goods (in accordance with what is provided for in article 123 of the Law) or those that by their nature put the safety of the personnel at risk during the processes of receipt, delivery, transfer, handover, storage, and if applicable, according to the services offered.
Response: Explanatory Notes: Attach the documented procedure to detect and report discrepancies of missing, excess, prohibited, or any other discrepancy in goods during delivery and/or receipt of the same and ensure that it includes the following points: I. Persons responsible for carrying out the review. II. Documents to be checked. III. Areas to which the information is reported. IV. What actions they take in case of detecting any discrepancy. 5.6 Processing of information and documentation of the load. The general warehouse must have documented procedures to ensure that the electronic and/or documentary information used during the receipt, storage, custody, and extraction of goods destined for the fiscal deposit regime, as well as the information received from business associates, is legible, complete, accurate, reported in time, and protected against changes, losses, or introduction of erroneous information. Likewise, forms and documentation related to import and/or export should be secured to prevent unauthorized use. Response: Explanatory Notes: Describe the procedure for the processing of information and documentation of the goods, ensure that you include the following points: I. Detail how it transmits and/or receives information and documentation related to the receipt and delivery of the goods in the general warehouse. II. Indicate if it uses a specific computer control system and explain briefly how it works. III. Likewise, detail how it validates that the information provided by the different actors in the supply chain (transporters, customs brokers, shipping lines, railway companies, among others) that converge in the warehouse, is legible, complete, accurate, reported in time, and protected against changes, losses, or introduction of erroneous information. IV. Indicate how business associates transmit information to the company and how they ensure its protection.
5.7 Inventory management, control of packaging, container, and packing material. The general warehouse must have documented procedures to carry out automated inventory control in accordance with its authorization to provide fiscal deposit services for goods; likewise, said control must contemplate what refers to fiscal deposit auctions, fiscal donations to the Federal Treasury, return of goods to foreign countries, transfers and handovers, destructions, among others, in accordance with applicable regulations and guarantee that cyclic inventories are carried out on the goods. Packaging, container, and packing materials, if applicable, must be controlled and supervised to prevent them from being susceptible to manipulation prior to their use. Response: Explanatory Notes: Attach the documented procedure for the management of goods inventories. This must include, according to its operation among other aspects, the following: I. Mention what type of system it uses for the exchange of information with the authority for inventory purposes. II. Who is its supplier. III. Indicate if it has a contingency plan in case of system failures. IV. Mention where the system is physically located and who are the responsible for its operation. V. The frequency with which it carries out stock verification (cyclic inventory). Indicate if there is a scheduled calendar to carry them out and if it is documented. VI. Indicate what actions it takes in case of surpluses and shortages in inventories. VII. Indicate the treatment given to the control and handling of packaging, container, and packing material. VIII. Treatment of goods when they present deterioration, as well as what is related to their destruction. IX. This point is also focused on reducing the risk of introduction or dissemination of quarantine pests of importance to the country through packaging (imports), for which reason, describe how it complies with the provisions indicated by
SEMARNAT and NOM-144 SEMARNAT-2017, in concordance with International Standard for Phytosanitary Measures No. 15 called Regulation of wood packaging used in International Trade, which emanate from the Food and Agriculture Organization of the United Nations. X. Indicate how the fumigation process is to kill, inactivate, sterilize, desiccate, or eliminate pests. What actions does it take in case of requiring quarantine of packaging materials. XI. Indicate the responsible area for carrying out this process, as well as the documentation or certificates obtained. The applicant's procedures may include: I. Access restrictions to the warehouse so that only authorized personnel enters. II. Actions taken if irregularities, discrepancies, losses, or thefts are identified. III. Separation of the various types of goods, for example, high value, dangerous. 6. Customs management. The general warehouse must have documented procedures in which internal and operational policies are established, as well as the necessary controls for the due compliance of customs obligations. Likewise, it must have specialized personnel and documented procedures that establish the verification of the information and documentation generated for the compliance of customs obligations derived from its authorization. 6.1 Customs obligations. The general warehouse must have documented procedures for the compliance of customs obligations derived from its authorization, in accordance with what is stated in Chapter 4.5., applicable to general warehouses, said procedure must include at least the following: I. Definition of the areas designated within the warehouse, which meet the specifications indicated by the authority to provide the service of storage of goods in fiscal deposit and/or place labels or seals. II. Process for the request of addition, modification, and/or exclusion of installations from the authorization (of the same premises, warehouse, yard, cold chamber, silo or tank, between two general warehouses simultaneously, etc.) to provide the service of storage of goods in fiscal deposit.
III. Permanent and simultaneous registration of entry and exit of goods to the general warehouses (designation of the computer equipment and data transmission equipment so that the respective customs and the administrative units of the AGACE can perform the consultation of the permanent and simultaneous registration in the system that the general warehouse has for this purpose). IV. Joint liability. V. Rectification of capacity letter (notice of surpluses and shortages within twenty-four hours following the arrival of the goods through electronic transmission to the SAAI, notice of late arrival, and notice of non-arrival of goods). VI. Identification of fiscal deposit goods (adhesive labels). VII. Goods not susceptible to fiscal deposit. VIII. Auction. IX. Donation to the Federal Treasury. X. Returns. XI. Transfer (in this case, the customs of jurisdiction of the general warehouse in which the goods are located must be modified). XII. Handover. XIII. Notices corresponding to the authority. XIV. Destruction or loss of goods. Response: Explanatory Notes: Attach the procedure established to comply with the customs obligations derived from its authorization as a general warehouse, in accordance with what is stated in Chapter 4.5., applicable to general warehouses. Likewise, said procedure must also contemplate the following points: I. Process that goods that are the subject of conservation acts, exhibition, placement of commercial identification signs, packaging, examination, demonstration, and taking of samples must comply with. II. Reports to the authority within the period of twenty days following the issuance of the capacity letter, the surpluses or shortages of the goods manifested in the petition with respect to those effectively received.
III. Compliance with the contributions and compensatory quotas that are incurred by the import and export of goods that have in fiscal deposit and the obligation to pay them to the authority. IV. Process of communication with the authority and the client, in case of damage or loss of goods. 6.2 Customs verification. In order to verify the truthfulness of the information declared by the general warehouse before the competent authorities, there must be documented procedures so that the personnel designated by the warehouse periodically verifies that the registered petitions and the information of electronic capacity letters coincide with what is declared in the SAAI Web and, if applicable, report to the customs authority any discrepancy in said information. The general warehouse, likewise, must have a procedure for the archiving of petitions for their adequate control. Response: Explanatory Notes: Attach the procedure established to verify that the information registered in the SAAI Web is checked and coincides with the information of the registered petitions, the capacity letters, and other documentation generated by the general warehouse. 7. Security of cargo vehicles, containers, train cars, trailers, and/or semi-trailers. The general warehouse must cooperate with users and competent authorities to maintain the security of means of transport, containers, train cars, trailers, and semi-trailers (including cargo vehicles, pickup trucks, vans, or vans, among others), that enter and leave its facilities, to protect them from the introduction of persons, illicit, prohibited, and/or unauthorized materials. For this reason, it is necessary to have documented procedures to verify the physical integrity of the structure of the means of transport that enter and leave its facilities, as well as to review, seal, and maintain their integrity during the transfers or handovers of goods destined for the fiscal deposit regime. Likewise, the process of inspection of means of transport, containers, train cars, trailers, and semi-trailers used as International Traffic Instruments, must include a procedure for agricultural inspections to look for visible pests and serious structural deficiencies. Pest contamination is defined as visible forms of animals, insects, or other invertebrates (living or dead, at any stage of the life cycle, including eggs, etc.), or any organic material of animal origin (including blood, bones, hair, meat, secretions, excretions, etc.); plants or vegetable products (including fruits, seeds, leaves, twigs, roots, bark, etc.); or other organic material, including fungi, soil, or water; when said products are not the declared cargo within the International Traffic Instruments. In case of using high-security seals, it is necessary to have procedures to seal correctly and maintain integrity from the point of origin of the goods. A high-security seal must be applied to all containers and trailers for foreign trade shipments, which must comply with or exceed the ISO 17712 Standard for high-security seals. With the objective of maintaining the security of the supply chain, the general warehouse must inspect all cargo vehicles systematically upon entry and exit of its facilities (domestic and international traffic), in addition to keeping a record.
7.1 Integrity of the load and use of seals in containers and trailers. The general warehouse must ensure that the cargo transport means owned and/or subcontracted by the warehouse to carry out transfers or handovers of goods destined for the fiscal deposit regime (which can be: maritime, air, national land, cross-border, railway, and/or multimodal, etc.), use seals and/or locks that comply with the ISO 17712 Standard in order to comply with the provisions of the customs authority and guarantee at all times the integrity of the load. For this case, the general warehouse must have a documented procedure in which, in accordance with its risk analysis, it supervises the placement of seals and/or locks that comply with the ISO 17712 Standard in the cargo transport means owned and/or subcontracted for transfers or handovers of goods destined for the fiscal deposit regime. In it, it must evidence the controls that allow accrediting that it supervises the portability of seals and/or locks, resulting from entries and exits of the general warehouse. In all cases, it must use the VVTT inspection method to mitigate improper manipulations in accordance with the following: I. V- View the seal and lock mechanisms of the container (View). II. V- Verify the seal number (Verify). III. T- Pull the seal to ensure it is correctly placed (Tug). IV. T- Twist and turn the seal to ensure it has been closed (Twist and Turn). Likewise, it is necessary to have a documented procedure for the administration of the same where it includes the control, assignment, safeguarding, handling of discrepancies, and destruction of seals and locks (the latter is mandatory whenever seals are broken in its facilities). Regarding the supplier of the seals and/or locks, it must be demonstrated how these comply with the ISO 17712 Standard. In case of such an inspection, drivers must notify and register any anomaly or unusual structural modification found in the means of transport resulting from said review. The procedures must include the steps to follow if it is discovered that a seal is altered, manipulated, or there is an incorrect seal number in the documentation, the communication protocols to the business partners involved in the supply chain, and the investigation of the security incident, these must be notified to security personnel, business partners that may be part of the affected supply chain, security specialist, or contact of the Authorized Economic Operator Program. The warehouse management or a security supervisor must carry out periodic and documented audits of the high-security seals and/or locks, these reviews must include the verification of the inventory of seals and/or locks stored and the cross-check with the inventory records and shipping documents. Also, the supervisors of the shipping area and/or warehouse managers must periodically verify the seal numbers used in the means of transport and International Traffic Instruments to corroborate that the information is correct. Response: Explanatory Notes: Attach the documented procedure to supervise the placement and review of high-security seals and/or locks on the cargo means owned and/or subcontracted (cargo vehicles, containers, train cars, trailers, and/or semi-trailers) to carry out transfers or handovers of goods destined for the fiscal deposit regime. According to its operation, said procedure must include among other aspects:
I. What type of seals and/or locks it uses and how it verifies that they comply with or exceed the ISO 17712 Standard. II. The use of the VVTT inspection method. III. Review and check the documentation containing the number of the original seal and/or lock upon entry of the general warehouses. In case of using the replacement seal and/or lock, said number must be registered within the control of the general warehouse. If altered seals and/or locks are identified, they must be kept to help carry out the investigation of said incident or discrepancy. IV. Review that the closing devices, hinges, and pins are attached to the trailer or container and welded or riveted. Also, they can place protective plates on the door hinges and/or place a seal/adhesive tape at least on each side. Also, the correct functioning of the handles, locks, and all other locking or closing mechanisms of the cargo vehicles must be verified to detect manipulations and any inconsistency before placing any sealing device. If applicable, attach the documented procedure for the control and handling of seals and/or locks. This must include, among other aspects according to its operation: I. What type of seals and/or locks it uses in its operations (foreign trade, transit, storage, etc.). II. Indicate who has access and how the high-security locks and/or seals are safeguarded. The management of seals and/or locks must be restricted only to authorized personnel; stored in a safe place, have an inventory, control of their distribution and tracking (record of seals that are used, as well as of the receipt of new seals and/or locks.
III. Describe how the management of the general warehouse of deposit or the security supervisor participates in the audits of high-security seals and/or locks, the reviews they perform, the records kept, and the actions taken in case discrepancies are identified. Also, how the supervisors of the shipping area and/or warehouse managers verify the seal numbers used in transport means and International Traffic Instruments to corroborate that the information is correct (this process can also be included within the internal audits referred to in sub-standard 1.3 of this document).
IV. Indicate how they control and manage high-security locks and/or seals (inventory).
V. How discrepancies in the numbers of high-security locks and/or seals are addressed.
All written procedures must be disseminated and maintained at the operational level so that they are easily accessible to employees responsible for carrying out the tasks described above, reviewed at least once a year, and updated as necessary.
7.2 Inspection of transport means, containers, rail cars, trailers, and semi-trailers.
There must be established procedures to verify the physical integrity of the structure of transport means, containers, rail cars, trailers, and/or semi-trailers entering and leaving the general warehouse of deposit, including the reliability of their locking mechanisms, with the aim of identifying natural or hidden compartments, as appropriate.
Inspections of transport means or cargo vehicles, containers, trailers, and semi-trailers (for land or rail cargo) must be systematic and carried out upon entry and exit from the general warehouse of deposit and, where applicable, at the cargo loading point and, if the infrastructure allows, before reaching the customs office for clearance using the VVTT inspection method. A record of these inspections must be kept in an area with controlled access and carried out in a place monitored by alarm systems, closed-circuit television, and video surveillance; said system must cover the entire inspection process.
The documented procedure for inspection must include, enumeratively but not limitatively, the following review points:
Transport Means: Trailers, rail cars, semi-trailers, and containers I. Defense; II. Tires and rims (tractor and trailer); III. Floor (tractor); IV. Fuel tanks; V. Cabin interior (bedroom, tool compartment); VI. Air tanks; VII. Chassis; VIII. Fifth wheel area; IX. Drive shafts; X. Exhaust pipe; XI. Engine.
I. Exterior and interior doors; II. Side walls (left and right); III. Interior and exterior roofs; IV. Front wall; V. Internal floor; VI. Where applicable, the refrigeration system.
For transport means with a trailer or integrated cargo compartment, the points indicated in the trailers section must be added to the transport means points.
Likewise, before loading transport means, containers, rail cars, trailers, and semi-trailers used as International Traffic Instruments, they must undergo agricultural and security inspections to guarantee that their structures have not been modified to hide contraband or contaminated with visible agricultural pests, maintaining a record and being backed by a documented procedure. If visible pest contamination is found during the inspection or transport of goods subject to foreign trade, it must be cleaned (washed, vacuumed, etc.) to eliminate said contamination.
Response: Explanatory Notes: Attach the documented procedure to carry out the systematic security and agricultural inspection of transport means or cargo vehicles, containers, rail cars, trailers, and/or semi-trailers during entry and exit from the general warehouse of deposit and/or at the cargo loading point. This must include, among other aspects according to your operation:
I. Those responsible for carrying out the inspection. II. Define the location(s) where the inspection takes place and indicate how monitoring is performed by alarm systems, closed-circuit television, and video surveillance.
III. The review points for transport means, trailers, semi-trailers, containers, rail transport, and/or multimodal transport, both for security and quality and agricultural inspections whose purpose is to search for visible pests in accordance with official regulations.
IV. Attach the established format for the inspection of transport means or cargo vehicles, containers, rail cars, trailers, and/or semi-trailers. If another type of cargo vehicle enters your facility for the transport of goods (vans, pickups, 3.5-ton trucks, tankers, etc.), your procedure and inspection format must include the process and review points.
Likewise, the security and agricultural inspection format must include the following information: I. Date of inspection; II. Time of inspection; III. License plates of the vehicle (tractor and trailer); IV. Container/trailer number; V. Specific areas of the cargo vehicles that were inspected, and VI. Name and signature of the employee performing the inspection and the supervisor.
The security and agricultural inspection formats may be signed by the supervisor to corroborate their information and become part of the import and export documentation.
Documentation must be kept for one year for investigation in case of any security incident, as well as to demonstrate continuous compliance with these inspection requirements.
Additionally, and in accordance with risk analysis, the warehouse should carry out periodic random reviews of cargo vehicles after transport personnel have performed security inspections to verify that they have been carried out correctly, counteract internal conspiracies, and prevent security incidents.
Reviews must be carried out randomly, without prior notice, so that they do not become predictable, in addition to being carried out in different places where the transport means may be susceptible to contamination.
Indicate whether the repair or maintenance of transport units, containers, or trailers is performed in the same facilities or carried out with an external provider.
7.3 Custody of vehicles, transport means, containers, rail cars, trailers, and semi-trailers.
When transport means or cargo vehicles, containers, trailers, and semi-trailers (for land or rail cargo) destined to transport goods subject to the fiscal deposit regime are empty and, where applicable, are stored in parking areas, they must be secured with a lock and/or indicative seal, or in a secure area protected and/or monitored by alarm systems, closed-circuit television, and video surveillance.
When it is necessary to store any container, trailer, and/or semi-trailer loaded with goods subject to the fiscal deposit regime, it must be in a secure area with perimeter barriers and monitored by alarm systems, closed-circuit television, and video surveillance to prevent unauthorized access and manipulation of the goods; therefore, it must be closed with a high-security seal and/or lock in accordance with ISO 17712 Standard.
Response: Explanatory Notes: Indicate whether the general warehouse of deposit stores containers, trailers, and/or semi-trailers for subsequent clearance, or where applicable, those that are empty, and how it maintains their integrity within its facilities.
In case of using locks and/or seals for empty containers, trailers, and semi-trailers, indicate what type is used.
In case of using any container, trailer, and/or semi-trailer as a warehouse for raw material and/or any other type of goods, indicate how the integrity and security of the same are maintained.
The general warehouse of deposit must have documented procedures for the registration and evaluation of persons wishing to obtain employment within the warehouse, establishing methods to carry out periodic verifications of current employees.
Likewise, there must be continuous training programs for administrative and operational staff in which the security policies of the general warehouse of deposit's supply chain, consequences, and actions to consider in case of any breach or security incident are disseminated.
8.1 Verification of work history.
The general warehouse of deposit must have documented procedures to investigate and verify the information recorded in the curriculum, criminal records (if local legislation and the general warehouse of deposit's policies allow it), and applications of candidates with potential employment, in accordance with local legislation, either on their own or through an external company.
Likewise, for positions that require it due to their sensitivity and affect the security of shipments with goods subject to the fiscal deposit regime, in accordance with their previously conducted risk analysis, stricter requirements for hiring must be requested, which must be carried out periodically (at least once a year). Regarding personnel already working in the company, periodic investigations must be carried out based on the activities and/or sensitivity of the employee's position.
All information regarding personnel must be kept in personal files, which must have restricted access.
Response: Explanatory Notes: Describe the documented procedure for personnel hiring, and ensure you include the following: I. Requirements and documentation required. II. Tests and exams requested.
Indicate the areas and/or critical positions identified as risky according to your analysis and indicate the following: I. Indicate what the additional requirements are for specific areas and/or job positions, such as criminal records (if company legislation and policies allow it), certificate of non-criminal record, socioeconomic studies, clinical studies, toxicological (drug use) studies. Where applicable, indicate the positions or work areas where they are required and with what frequency they are carried out.
II. Indicate whether, prior to hiring, the candidate must sign a confidentiality agreement or a similar document.
In case of hiring a service agency for personnel hiring, indicate if this agency has documented procedures for personnel hiring and how it ensures compliance with them. Explain briefly what they consist of.
The procedures for personnel hiring and contractors must include: I. Thorough investigations of the work and personal backgrounds of new employees. II. Confidentiality and responsibility clauses in employee contracts. III. Specific requirements for critical positions. IV. Where applicable, the periodic update of the socioeconomic and physical/medical study of employees working in critical and/or sensitive areas. V. Hiring process and requirements requested for temporary employees and contractors. VI. The company may consider the results of background checks of candidates, as allowed by current legislation, to make hiring decisions. Background checks are not limited to identity and criminal record verification. In higher-risk areas, more in-depth investigations may be justified.
8.2 Personnel termination procedure.
There must be documented procedures for personnel termination, which include the delivery of identification and any other item provided to perform their functions (keys, uniforms, badges and/or credentials, computer equipment, passwords, tools, etc.). Likewise, this procedure must include termination in computer and access systems, among others that may exist.
Response: Explanatory Notes: Describe the procedure for personnel termination, and ensure you include the following: I. Who is responsible for carrying out and following up on this procedure. II. How the delivery of identification, uniforms, keys, and other equipment is carried out and confirmed. III. Indicate the control, record, and/or format in which the delivery of material and termination in computer systems (where applicable) is identified and ensured. IV. Indicate the type of records of personnel who ended their labor relationship with the general warehouse of deposit, so that when it was for security reasons, their service providers and/or business associates are warned.
8.3 Personnel administration.
The general warehouse of deposit must maintain an updated system, control, or database of active employees; likewise, it must carry out and maintain updated records of affiliation to social security institutions and other legal labor records.
In the case where the general warehouse of deposit has personnel hired by its business partners and working within the facilities, it must ensure that they meet the requirements established for the rest of its employees.
Response: Explanatory Notes: Indicate whether the general warehouse of deposit has an updated system, control, or database, both of personnel employed directly and that hired through a service provider company, and ensure it includes, enumeratively but not limitatively, the following points: I. Full name. II. Updated photograph at least every five years. III. Personal data (age, name, date of birth, phone number, address, CURP, social security number, blood type, allergies, etc.).
IV. Affiliation. V. Work history. VI. Diseases. VII. Medical exams. VIII. Training. IX. Psychometric tests. X. Toxicological tests. XI. Results of periodic evaluations. XII. Observations.
This personnel must be hired in accordance with current labor laws and regulations.
There must be prevention measures to maintain the confidentiality and integrity of information and documentation generated by the general warehouse of deposit's systems, including those used for information exchange with other members of its supply chain. Likewise, there must be comprehensive documented policies and/or procedures to protect Information Technology systems, including measures against misuse, as well as identification and prioritization of actions to reduce cybersecurity risk. They may also address how a member shares information about cybersecurity threats with the government and other business partners.
9.1 Document classification and handling.
There must be written procedures to classify documents according to their sensitivity and/or importance. Sensitive and important documentation must be stored in a secure area that only allows access to authorized personnel. The useful life of the documentation must be identified, and procedures for its destruction must be established.
The general warehouse of deposit must conduct regular reviews to verify access to information and ensure that it is not used improperly.
Response: Explanatory Notes: Attach the documented procedure for the registration, control, and storage of printed and electronic documentation (classification and filing of documents), including: I. Control register for delivery, loan, among other documents. II. Restricted access to the archive area.
III. Storage and classification policies. IV. An updated security plan describing the measures in force regarding the protection of documents against unauthorized access, as well as against deliberate destruction or loss of the same. V. In the case of electronic or digital information, it must adhere to the security criteria of sub-standard 9.2 Information Technology Security.
9.2 Information Technology Security.
To protect Information Technology systems against common cybersecurity threats, the general warehouse of deposit must have sufficient protection to promote security in Information Technology infrastructure (software and hardware) against malware (viruses, spyware, worms, trojans, etc.), baiting, phishing, and internal/external intrusions (firewalls) in the companies' computer systems. Likewise, the general warehouse of deposit must ensure that its security software is active and receives periodic updates.
In the case of automated systems and computer equipment, individual accounts requiring periodic password changes must be used. In order to protect the confidentiality, integrity, and availability of information, the warehouse must have established Information Technology policies, procedures, and standards, which must be communicated through a training program for all employees who handle computer equipment and systems, including topics to prevent attacks through social engineering and all those threats to which they are exposed (malware, baiting, phishing, etc.). Warehouses that allow their employees to connect remotely to a network must use secure technologies, such as virtual private networks (VPN), to allow employees to access the warehouse intranet securely when outside the office, as well as procedures designed to prevent unauthorized remote user access.
For the above, there must be written procedures and infrastructure to protect the general warehouse of deposit against loss, theft, leakage, hacking, and/or ransomware of information; this includes the procedure for the recovery (or replacement) of Information Technology systems and/or data, as well as a system or software established to identify the abuse of Information Technology systems, detect inappropriate access and/or improper manipulation or alteration of commercial and business data, as well as a written procedure for the application of appropriate disciplinary measures to all offenders. Access to Information Technology systems must be protected against infiltration through the use of secure passwords, which include phrases or other forms of authentication. Users of said Information Technology systems must safeguard and not share their access keys or passwords. All Information Technology infrastructure must be physically protected against unauthorized access.
If a data leak or other unexpected event occurs resulting in the loss of data and/or equipment, the procedures must include the recovery or replacement of Information Technology systems and/or data.
Response: Explanatory Notes: Attach the procedure for the recovery (or replacement) of Information Technology systems and/or data, including how it backs up and ensures the security of its information, in addition to protecting it from possible losses. Ensure you include the following points:
I. Indicate the frequency with which information backups are carried out. II. Who has access to them and who authorizes the recovery of information. III. Indicate what type of tests it performs and how often, to verify the security of the network, systems, and infrastructure. IV. Mention if, to carry out this type of tests or vulnerability scans, it is done through software, a third party, or provider, and, where applicable, indicate the name or corporate name. V. In case vulnerabilities are found, describe the corrective actions that must be implemented. VI. Indicate if it shares information about cybersecurity threats with business partners participating within its supply chain (for example: press releases, bulletins, emails, etc.). VII. Systems must be protected under passwords and must be modified frequently; therefore, indicate the procedure for changing them. VIII. Indicate if there are information security policies for their protection. IX. There must be a system or software to detect and identify the abuse, intrusion, or access of unauthorized persons to its systems and/or Information Technology data (any system used by the company), as well as the abuse of the policies and procedures established by the general warehouse of deposit, including improper access to internal systems, external websites, and the manipulation or alteration of commercial data by employees or contractors.
X. All offenders must be subject to the application of disciplinary measures; therefore, indicate the corrective policies and/or sanctions in case of detection of any violation of the Information Technology systems and security policies.
Information Technology and cybersecurity policies and procedures must be reviewed annually and updated due to an attack or according to situations that may put the company's systems at risk.
Describe the security measures used to allow employees to connect remotely to a network (VPN), to allow employees to access the general warehouse of deposit intranet remotely when outside the office.
In case of allowing employees to use personal devices to perform warehouse work, such devices must comply with the company's cybersecurity policies and procedures, security updates must be periodic, and there must be a method to access the company network securely.
XI. Indicate if business partners have access to the general warehouse of deposit's computer systems. Where applicable, indicate what programs they use and how they ensure access control to them.
XII. Indicate whether the computer equipment has a backup power supply system that allows for business continuity. The procedures regarding the backup of information in the general warehouse must include: I. How and for how long data is stored (data should be backed up once a week or as appropriate). II. Business continuity plan in case of incident and how to recover information. III. Frequency and location of backups and archived information. IV. Whether backups are stored in sites alternative to the facilities where the Data Processing Center is located. V. Tests of the validity of data recovery from backups. The procedures regarding the protection of information in the general warehouse must also include at a minimum the following: I. An updated and documented policy for the protection of computer systems against unauthorized access and deliberate destruction or loss of information. All sensitive and confidential data must be stored in an encrypted or encoded format. II. Detail if multiple systems (sites/locations) are operated and how these systems are controlled. III. Who is responsible for the protection of the computer system (responsibility should not be limited to one person but to several so that each can control the actions of the others). IV. Each user's access must be assigned through individual accounts and restricted according to the job description or assigned tasks. For the above, describe how access authorizations and access levels to computer systems are granted (access to sensitive information must be limited to authorized personnel to perform modifications and use of the information). Authorized access must be monitored by the area responsible for granting it, to verify or, if applicable, report that access to confidential systems is based on job requirements. V. Indicate the elements or format that passwords must have for access to Information Technology systems and computer equipment, frequency of changes, if there are other authentication methods, and who or which area provides those passwords. VI. Indicate the name of the firewall and antivirus used (include licensing information), demonstrating that this security software is active and receives periodic updates. For the above, cybersecurity policies and procedures should include measures to prevent the use of counterfeit technological products or those with incorrect licenses (software and hardware). All computer equipment, electronic media (hard drives, cell phones, etc.) and Information Technology hardware containing confidential information related to the import and export process must be accounted for through periodic inventories and have such evidence. When these technological equipment must be discarded, there must be a documented procedure that includes how they must be formatted, disinfected, or destroyed adequately to prevent information leakage.
VII. In the event of employee termination, access to computer equipment, telecommunications, and network must be eliminated at the moment of the employee's separation; this includes email accounts, system access accounts, software, programs, etc. VIII. Measures planned to handle incidents when the system is compromised. 10. Security training and awareness. There must be an awareness program designed and updated by the general warehouse staff to recognize and create awareness about threats in their logistical processes, prevention of operations with proceeds of illicit origin and terrorism financing, as well as training regarding smuggling, merchandise theft, relevant operations, unusual operations, internal concerning operations, money laundering, shipment contamination, theft, leakage, hacking, and/or information kidnapping, etc. The training program must be comprehensive and cover all security requirements of the Authorized Economic Operator Program. Administrative and operational employees must know the established procedures of the general warehouse to identify a risk situation and know how to report it. Specific training must be provided to employees who, due to their functions, are in direct contact with computer systems, merchandise, and/or transport means, as well as to employees who are in critical and/or sensitive areas determined under their risk analysis (security areas, shipments and receipts, if applicable, as well as those who receive and open mail and packages, among others). 10.1 Training and awareness on threats. The general warehouse must have a training and awareness program on security policies in the supply chain directed to all its employees (operational and administrative) and, additionally, make available informational material regarding the established procedures in the company to consider a situation that threatens its security and know how to report it. Similarly, specific training must be offered according to their functions to help employees maintain the integrity of merchandise destined for the tax deposit regime during its receipt, handling, storage, guard, custody, and exit from the warehouse, perform the review of transport means, containers, train cars, trailers, and/or semi-trailers for agricultural and security purposes, receipt and review of mail and packages, prevention of operations with proceeds of illicit origin (money laundering, terrorism financing, etc.), how to recognize and how to report internal conspiracies, protect access controls, as well as training regarding smuggling, merchandise theft, placement of high-security seals and locks (VVTT inspection method), prevention of visible contamination by pests, etc. These topics must be established as part of new employee induction and periodically maintain update programs. Update training must be carried out periodically, after a security incident, and when there are changes in the general warehouse procedures. In addition to security training programs, an awareness program on alcohol and drug consumption must be included. Also, disseminate and train staff on the general warehouse's cybersecurity policies, procedures, and standards (theft, leakage, hacking, and/or information kidnapping), including access to computer equipment and systems via passwords or phrases. Personnel who operate and administer security technology systems must receive training related to their operation and maintenance, including self-training through operational manuals and other methods. These topics must be established as part of new employee induction and periodically maintain update programs.
Training programs must encourage active employee participation in security controls and mechanisms, as well as maintain records of all training efforts provided by the general warehouse and the list of those who participated in them (videos, photographs, minutes, attendance lists, intranet or other system, didactic material, PowerPoint presentations, brochures, etc.). Training records must include the date of the training, the names of the attendees, the topics taught, in addition to having measures to verify that the training provided met all training objectives. Response: Explanatory Notes: You must have a training program on security and prevention of security incidents in the supply chain for all employees working for the general warehouse (administrative, operational, direct, and indirect). Briefly explain what the training program consists of, and ensure you include the following: I. Brief description of the topics taught in the program. II. When they are taught (induction, specific periods, resulting from audits, security incidents, etc.). III. Frequency of training, as well as updates and reinforcement. IV. Indicate how participation in supply chain security training is documented (videos, photographs, minutes, attendance lists, intranet or other system, didactic material, PowerPoint presentations, brochures, etc.). Training records must include the date, the names of the attendees, the topics taught, in addition to having measures to verify that the training provided met all the objectives of the same. V. Explain how employee participation in supply chain security matters is encouraged.
Training to perform the review of cargo vehicles, containers, trailers, and/or semi-trailers for agricultural and security purposes must include the following topics: I. Signs of hidden compartments; II. Smuggling hidden in natural compartments; III. Signs of pest contamination; and IV. Procedures to follow if something is found during a transport medium inspection or if a security incident occurs during transit. V. Training on agricultural reviews must cover pest prevention measures, regulatory requirements applicable to wooden packaging materials in accordance with International Standard for Phytosanitary Measures No. 15, titled Regulation of Wood Packaging Used in International Trade, which emanate from the Food and Agriculture Organization of the United Nations and the identification of infested wood. 10.2 Awareness for transport medium operators. The general warehouse must make known to the operators of the transport means it uses for the transfer and transfer of merchandise destined for the tax deposit regime, the security policies regarding agricultural and security inspection procedures of transport means, loading and unloading, handling of security incidents, replacement of seals and/or locks in case of inspection by other authorities, among others, that are implemented. Operators and personnel who perform agricultural and security inspections of transport means must be trained to inspect cargo vehicles for such purposes. When the transport service is provided by a business partner, you must ensure that the operators and/or drivers who transport the merchandise know all the security policies and procedures established by the general warehouse. Response: Explanatory Notes: Describe the dissemination program on security in the supply chain focused on transport medium operators and ensure you include the following:
I. Indicate how this dissemination is carried out. II. Point out the topics covered. III. In case of using the services of a business partner for the transfer and transfers of your merchandise, indicate how you inform operators about the security policies and procedures of the general warehouse. IV. Indicate how participation in supply chain security training of transport medium operators is documented (videos, attendance lists, brochures, etc.). The topics that must be included, by way of enumeration but not limitation, are: I. Access and security policies at the facilities. II. Delivery and receipt of merchandise (including suspicious cargo shipments). III. Confidentiality of cargo information. IV. Transfer and transfer instructions. V. Accident and emergency reports. VI. Instructions for the placement of high-security locks and/or seals in case of inspection by other authorities in transit (placement of a new one, review after an authorized stop, etc.). VII. Installation and testing of security alarms and unit tracking, when applicable. VIII. Identification of authorized formats and documents to be used. IX. Signs of hidden compartments. X. Smuggling hidden in natural compartments. XI. Signs of pest contamination. XII. Procedures to follow if something is found during a transport medium inspection or if a security incident occurs during transit.
11.2 Investigation and analysis. The general warehouse must have written procedures to denounce or report anomalies and/or suspicious activities, as well as the analysis and investigation of security incidents in the supply chain and to determine their cause, in addition to corrective actions to prevent them from happening again, which must be implemented as soon as possible. The information derived from this investigation must be documented, integrated into a file (physical and/or electronic), and available at all times for authorities that so require. This information and generated documentation must be included in a file for the purpose of allowing the identification of each of the processes through which said operation went until the point where the security incident was detected, allowing recognition of what the vulnerability of the supply chain was. Response: Explanatory Notes: Describe the documented procedure to initiate an investigation in case of any security incident occurring, and ensure you include the following: I. Responsible for carrying out the investigation. II. Documentation that integrates the investigation file. The documents to be included in the file derived from the security incident investigation, by way of enumeration but not limitation, may be: I. Merchandise information. II. Information of the transport company and the operator and/or driver, entry and exit records to the general warehouse. III. Inspection formats of the transport medium, container, train car, trailer, and/or semi-trailer. IV. Records of delivery and receipt of merchandise destined for the tax deposit regime. V. Videos from alarm systems, closed-circuit television, and video surveillance. VI. Documentation generated for the transport company. VII. Documentation generated by and for business partners and customs authorities. VIII. If applicable, the unit tracking and monitoring report (GPS tracking).
622 OFFICIAL GAZETTE Friday, January 17, 2025 E12. Declaration of will to assume joint and several liability under rule 7.3.3., fraction XIII Date:
Friday, January 17, 2025 OFFICIAL GAZETTE 623 4. Declaration of will to assume joint and several liability: I declare under oath the following: a) That I am up to date in the fulfillment of my tax obligations. b) That the status of my tax domicile is Located. c) That I am active in the RFC. d) That the data entered in this form is true. e) That through this document, joint and several liability is assumed under article 26, fraction VIII of the CFF and rule 7.3.3., fraction XIII, for the tax obligations that arise from the sale carried out by the resident abroad without permanent establishment in the country, regarding the merchandise related to the definitive import customs declaration. 5. Declarations of the legal representative: a) That I am up to date in the fulfillment of my tax obligations. b) That the status of my tax domicile is Located. c) That I am active in the RFC. d) That the data entered in this form is true. e) That the powers granted to me to represent the joint and several liable party have not been modified or revoked. 6. Signature:
Name and signature of the joint and several liable party or their legal representative Instructions General Information: This form is freely printable and must be filled out by machine or in block letters, with a black or blue ink ballpoint pen, and the limits of the boxes must not be invaded. Presentation Options: The form must be presented through a clarification case on the SAT Portal. Requirements: I. Public deed with which the legal representative or legal proxy accredits their personality, if applicable. II. List of goods susceptible to seizure and easy realization, in terms of the provisions of the CFF, with which the payment of the taxes incurred is guaranteed. Additional Information: The goods owned by the person assuming joint and several liability must correspond to the type of goods indicated in article 155 of the CFF, which sufficiently guarantee the joint and several liability assumed for the tax obligations that arise from the sale carried out by the resident abroad without permanent establishment in the country.
624 OFFICIAL GAZETTE Friday, January 17, 2025 E13. Request for issuance of advance ruling Type of Advance Ruling Competent Authority before which the format must be presented Mark with an x Application of customs valuation criteria. ACNCE On matters of origin. ACAJACE Tariff classification. ACNCE
Friday, January 17, 2025 OFFICIAL GAZETTE 625 8. The natural or legal person requesting the procedure is: Importer in national territory. Producer in another country. Exporter in another country. Person with justifiable cause. 9. Mention the Commercial Agreement or Free Trade Agreement, as well as the legal basis under which the issuance of the advance ruling is requested: 10. Mark with an X the corresponding option, as appropriate. 10.1. Has the merchandise regarding which the advance ruling is requested been or is subject to an origin verification? If the answer is Yes, indicate the authority conducting said verification and/or the result thereof. If No 10.2. Has an advance ruling regarding said merchandise been previously requested or obtained? If the answer is Yes, indicate the authority that granted and/or before which the advance ruling was requested, as well as its content. If No 10.3. Have the facts or circumstances been previously raised before the same authority or a different one? If the answer is Yes, mention the authority before which the facts or circumstances were raised and/or the content of its response. If No 10.4. Is the matter in question subject to any instance of review or appeal in any of the party countries of the Commercial Agreements or Free Trade Agreements signed by Mexico and currently in force? Indicate, if applicable, the status or the result thereof. If No 10.5. Is the applicant subject to the exercise of verification powers? If the answer is Yes, indicate the periods and contributions subject to review. If No
626 OFFICIAL GAZETTE Friday, January 17, 2025 10.6. Is the applicant within the term for tax authorities to issue the ruling referred to in Article 50 of the CFF? If the answer is Yes, explain the situation. If No 10.7. Has the merchandise subject to the request for issuance of an advance ruling been previously imported into national territory? If the answer is Yes, attach the documentation that confirms the foregoing. If No 10.8. Report whether the production of the merchandise subject to the advance ruling request is currently underway. If the answer is Yes, describe in detail, through a flowchart, the production process thereof. If No 11. Describe completely all relevant facts or circumstances related to the object of the request: 12. Provide the tariff classification and description of the merchandise subject to the request, including, if considered necessary, the tariff classification, description of the materials used in the production of the merchandise, and the NICO: 13. In the case of requests for tariff classification, application of customs valuation criteria, describe in detail the technical arguments and, if applicable, legal grounds on which the request is based. When it comes to requests on matters of origin, describe in detail the justification for considering the origin of the merchandise; as well as its production process and the implementation of each of its inputs to reach the final good: 14. List the documentation attached: Once the foregoing has been stated, it is requested that the competent authority issue the advance ruling, as appropriate. I declare, under oath, that the data recorded and documentation attached in this format are true and exact.
Name and signature of the applicant or their legal representative
Friday, January 17, 2025 OFFICIAL GAZETTE 627 Instructions This request must be submitted using the format titled Request for issuance of advance ruling, complying with the provisions of the Commercial Agreement or Free Trade Agreement signed by Mexico that is in force. In the event that the issuance of advance rulings in their various matters is needed, the format must be submitted for each of them before the ACAJACE or ACNCE, as appropriate. Information that must be provided in each field:
628 OFFICIAL GAZETTE Friday, January 17, 2025 Documents that must be attached: I. Simple copy of the testimony or the notarial instrument from which it is evident that the person signing the request for issuance of the advance ruling is authorized to carry out the corresponding procedures before the respective authority. II. The request must include the information and documentation necessary to allow the authority to issue the advance ruling on matters of origin. III. Sample of the merchandise subject to consultation. When it is not possible to present the sample due to its volume or physical characteristics, catalogs, technical sheets, labels, photographs, plans, etc., that describe in detail the physical and technical characteristics allowing identification of the merchandise must be attached. IV. The other documents necessary to support the request. V. In the case of advance rulings on matters of tariff classification, the following documents must be attached: a) Original or certified copy of the general power of attorney for acts of administration of the legal representative, of the consulting person, when it comes to legal persons. b) Original or certified copy of the valid official identification of the legal representative of the legal person requesting the consultation, or of the natural person when this acts on their own behalf. c) Sample of the merchandise subject to consultation. When it is not possible to present the sample due to its volume or physical characteristics, catalogs, technical sheets, labels, photographs, plans, etc., that describe in detail the physical and technical characteristics allowing identification of the merchandise for its correct tariff classification must be attached. d) When the sample in consultation requires chemical or technical analysis by the DGJA, the payment receipt of duties, made through the electronic scheme e5cinco, for each sample subject to analysis, in accordance with Article 52 of the LFD, in relation to Annex 19 Updated Amounts of the LFD of the current RMF, must be attached. e) State the tariff fraction and, if applicable, the NICO considered applicable, the reasons supporting its appreciation and the tariff fraction or fractions and, if applicable, number or NICO with which there is doubt or, in case otherwise, indicate that you wish to know the tariff fraction and, if applicable, the NICO that the authority determines. The ruling office will be notified to the applicant, as appropriate, by tax mailbox, personally or by certified mail, if applicable, to the authorized persons and at the address indicated for hearing and receiving notifications.
Friday, January 17, 2025 OFFICIAL GAZETTE 629 F1. Request for Issuance of Certified Copies of Customs Declarations and Their Attachments
Address for Hearing and Receiving Notifications Street: No. and/or Letter Ext.: No. and/or Letter Int.: Neighborhood: Locality: Postal Code: Municipality or Delegation Federal Entity: Phone: Email
630 OFFICIAL GAZETTE Friday, January 17, 2025 DATA OF THE CUSTOMS DECLARATION Customs Declaration Number Customs Office Date of Payment of the Customs Declaration Name of the Importer/Exporter who processed the or the declarations Patent Customs Declaration Number d d m m a
Patent Customs Declaration Number d d m m a
Patent Customs Declaration Number d d m m a
Note: In case of more than 3 Customs Declarations, attach list. NUMBER OF COPIES REQUESTED FOR EACH CUSTOMS DECLARATION Number With Attachments Without Attachments (mark with an X) (mark with an X) I declare under oath that the data recorded in this request are real and exact. Autograph signature of the applicant or legal representative
Friday, January 17, 2025 OFFICIAL GAZETTE 631 DOCUMENTS THAT MUST BE ATTACHED Natural Persons Legal Persons
632 OFFICIAL GAZETTE Friday, January 17, 2025 Circumstances that materially prevent the DGIA from attending to requests for certified copies of customs declarations and their attachments: I. Request for documents related to the extinct Federal Vehicle Registry, corresponding to the years 1989 or earlier. II. Request for documents that have been permanently removed due to having fulfilled the storage and custody time by the customs authority, in accordance with the Agreement establishing the guidelines to be followed for the storage, custody and conservation period of the Government Accounting Archive, published in the DOF on August 25, 1998. III. Request for customs declarations that are not registered in the SAAI or that there are discrepancies between the information recorded in the customs declaration and the information registered in the aforementioned system. How can the interested party request information on the status of their procedure and, if applicable, the amount to be covered for the issuance of certified copies? Via email to the address copiascertificadas@anam.gob.mx. What is the timeframe for issuing the ruling? The DGIA will issue the corresponding ruling within a period not exceeding three months from the date of receipt of the request. After said period has elapsed without the ruling being notified, it will be understood to be negative in terms of Article 37, first paragraph of the CFF. Documents (requirements) to be fulfilled when the procedure is carried out through the Digital Counter: I. Payment of duties for the total number of certified copies requested (the payment receipt made through the Multiple Payment Form for Foreign Trade, in accordance with Article 5, fraction I of the LFD and rule 1.6.2., in relation to Annex 19 Updated Amounts of the LFD of the current RMF). II. Copy of the customs declaration in their name. III. Valid official identification of the applicant in the case of those persons who do not have their e.firma. Delivery of the requested customs declarations and their attachments: I. Once the necessary requirements to resolve and the payment of the total amount of the certified copies have been covered, the DGIA will deliver them personally at the management control module of said General Directorate or through the courier service, when so requested in the application. II. In the case where the delivery method was not specified in the request, it will be done personally at the management control module, to those who have declared their address in Mexico City or metropolitan area, and through courier to those who have declared their address outside said zone. After three months have elapsed from the date of receipt of the request, without the interested party having collected the certified copies at the management control module, it will result in their invalidity, and the procedure must be carried out again if they are required. III. When the delivery is personal at the management control module, it will be from Monday to Friday within the hours of 9:00 to 18:00 hours; for this, valid official identification must be presented and, if applicable, power of attorney signed before two witnesses and ratified signatures of the grantor, acceptor and witnesses before the tax authorities, Notary or Public Notary, in accordance with Article 19 of the CFF. IV. When the procedure is carried out through the Digital Counter, the delivery will be made through the same. Applicable legal provisions: Articles 19, 37 and 69 of the CFF, 144, fraction XXVI of the Law, 5, fraction I of the LFD, 19, fraction XXVII of the RIANAM, rules 1.1.10. and 1.6.2. of the RGCE and Annex 19 of the RMF.
Friday, January 17, 2025 OFFICIAL GAZETTE 633 F2. Request for user and password to access the Integrated Customs Operation System (SOIA) Place and date of request _____________________ to of of ______________ General information of the applicant. Name, denomination and/or corporate name of the natural or legal person:________
Tax Address: __________________________________________________________________________ RFC Key with homoclave: ________________________ Email: _____________________ Contact phone: ______________________________________________________________________ No. Patent/No. CAAT/No. Facility/Storage Key/Importer (please specify):
Describe in general the activities in which the applicant is engaged:
Information of the legal representative, if applicable. Name: ________________________________________________________________________________ RFC Key with homoclave: _____________________________________________________________ General data of the power or articles of incorporation granting legal representation. Notarial instrument: number: ___________________ Notary: _____________________________________ Name of notary: ______________________________________________ Date: ___________________ Authorized person and address for hearing and receiving notifications. Name: ________________________________________________________________________________ Address for hearing and receiving notifications:_______________________________________________________
Phone: _________________________Email: _______________________________________ Mark with an X the corresponding option: Indicate if the request has been previously presented before the same authority or a different one, in case of affirmative describe the situation in which it is found.
YES NO Indicate if the request has been subject to any administrative or judicial process, in case of affirmative describe the situation in which it is found.
YES NO If the procedure was carried out by courier, indicate if you require that the original documentation you presented with this format be returned. Describe what it consists of:
YES NO I declare under oath that:
Name and signature of the applicant (Natural person applicant or legal representative)
634 OFFICIAL GAZETTE Friday, January 17, 2025 Instructions General Information This form is freely printable and must be filled out by machine or in block letters, using a black or blue ink pen, without invading the limits of the boxes. Requirements: I. Original or certified copy and simple copy for comparison of the general power of attorney for acts of administration of the legal representative of the interested party, whenever the applications are not presented by their own right. II. Original or certified copy and simple copy for comparison of the valid official identification of the legal representative or of the person acting by their own right. III. Simple copy of the authorization letter for commencement of operations issued by the DGJA, in the case of supervised premises and general warehouses. IV. In the event that the original documentation presented with this form has been requested for return, a prepaid shipping label with the data to which said documentation will be sent must be attached. V. In the case of renewal, it must be requested one month before expiration using this form. Presentation Options The procedure may be presented I. At the registry office of the DGMEIA. II. Through the services of courier companies, in which case, the addressee must be indicated as the DGMEIA. Specific Instructions I. When the applicant is a public official of any government department, the request shall be made through an official letter addressed to the DGMEIA, which must contain the following data: a) Name of the public official who will safeguard the account. b) Position. c) RFC Key. d) Address. e) Telephone. f) Email. g) Signature of the immediate supervisor. h) Requests for inquiries. Additionally, the interested public official must present the original and a copy for comparison of their valid credential issued by the respective government department. Additional Information I. The authority will respond within a period not exceeding ten business days through an official letter addressed to the address indicated for hearing and receiving notifications and will send the password and user to access the SOIA to the applicant's email. II. In case of changes in the RFC key, name, denomination, or corporate name, a new request must be made covering all requirements. III. In case of forgotten password, an email must be sent to soporte.soia@sat.gob.mx requesting the resending of the user and password, which will be sent to the email registered in the SOIA, provided that the account is active. IV. For any failure or problem related to the SOIA, the SAT makes available the email soporte.soia@sat.gob.mx. V. The user and password will have a validity of up to five years.
Friday, January 17, 2025 OFFICIAL GAZETTE 635 F3. Security Matrix Request for Delivery of Foreign Trade Information
636 OFFICIAL GAZETTE Friday, January 17, 2025 Instructions General Information This form is freely printable and must be filled out by machine or in block letters, using a black or blue ink pen, and the figures must not invade the limits of the boxes. It must be presented in two original copies signed in blue ink, one for the authority and the second will be the receipt for the interested party. Presentation Options The procedure may be presented at any time at the registry office of the General Directorate of Modernization, Equipment and Customs Infrastructure in person or using the services of SEPOMEX or courier companies. Specific Instructions In the case of renewal, the procedure must be presented forty-five days before its expiration. Requirements: I. Individuals or Legal Entities: a) Legible copy of the tax identification card (RFC). b) Original or certified copy and simple copy for comparison of valid official identification (Voter ID with photo, valid passport, national military service card, professional ID, immigration ID, naturalization certificate, migratory form with photo, high-security or digital consular registration certificate). c) Original or certified copy and simple copy for comparison of valid official identification of the person receiving the security matrix. d) Present original or notary-certified copy, and simple copy for comparison of the public instrument where the legal representative is granted power of attorney for acts of administration without any limitation in terms of what is provided in article 2554, second and penultimate paragraph of the Federal Civil Code, or special power of attorney is granted for the procedure of acts of administration. e) If there is a change in corporate name or in the RFC key, present the documentation accrediting it. II. Customs Broker: a) Legible copy of the tax identification card (RFC). b) Original or certified copy and simple legible copy for comparison of the valid official identification of the customs broker (Voter ID with photo, valid passport, national military service card, professional ID, immigration ID, naturalization certificate, migratory form with photo, high-security or digital consular registration certificate). c) Legible copy of the valid customs broker badge. d) Legible copy of the patent in case of having only the customs office of assignment or authorization in case of operating by the customs office of assignment and additional customs offices. e) Original or certified copy and simple copy for comparison of valid official identification of the person receiving the security matrix. If the procedure of the individual or customs broker is carried out by a legal representative, they must present the original or certified copy and simple copy for comparison of the public instrument in which the legal representative is granted general power of attorney for acts of administration without any limitation or special power granted for the specific procedure, in terms of the second and penultimate paragraphs of article 2554 of the Federal Civil Code, respectively, attaching the original or certified copy and simple copy for comparison of the valid official identification of the legal representative. Additional Information I. The authority will respond through an official letter within a period not exceeding ten business days, counted from the date the request was presented. II. When the request is not properly filled out or any of the stated documents are omitted, a negative response will be given and the procedure must be carried out again. III. The interested party may follow up on their procedure through the phones (55) 12 03 1000 ext. 47403, 54489, 54487, 43043, or may send their inquiry to the email sianam@anam.gob.mx.
Friday, January 17, 2025 OFFICIAL GAZETTE 637 IV. The letter with the security matrix will be delivered in person at the registry office of the General Directorate of Modernization, Equipment and Customs Infrastructure. If located within the Republic, the documentation can be sent by courier, provided that the request includes a properly filled prepaid shipping label for the return of the documentation. V. The security matrix has a validity of three years, from the date of issuance of the security matrix letter. VI. Taxpayers who wish to continue receiving electronically the information of the declarations of the operations they have carried out, must present their renewal request, using the duly filled form named Security Matrix Request for Delivery of Foreign Trade Information, complying with the same requirements provided for the initial request. If the documents exhibited previously are still valid at the time of the renewal request, it will no longer be necessary to present them, provided that this situation is stated. Likewise, a renewal request must be presented when the security matrix letter is lost, or when there is a change in the legal representative, corporate name, or RFC key of the company. VII. In case of modifying email addresses, a free-form letter must be presented at the registry office of the General Directorate of Modernization, Equipment and Customs Infrastructure, indicating the update of the email addresses, provided that the representative who processed the registration or renewal is the same. III. Auxiliary models used by foreign trade users: M1.1. Customs Declaration (Pedimento) The customs declaration format is a dynamic format composed of blocks, in which only the blocks corresponding to the information that must be declared should be printed. This format must be presented in one copy destined for the importer or exporter, in the cases provided in rules 2.5.1., regarding used vehicles, trailers and semi-trailers; 2.5.2., regarding used vehicles, trailers and semi-trailers; 3.1.21., fraction III, subsection b), 3.5.1., fraction II, 3.5.4., 3.5.5., 3.5.6., 3.5.8., and 3.5.11., as well as vehicle operations under a diplomatic franchise, in accordance with article 62, fraction I of the Law. Below, the different blocks that may constitute a customs declaration are presented, citing their mandatory nature and the manner in which they must be printed. When in a specific field, the specified space is insufficient, it can be expanded by adding as many lines in the section as required. Printing should preferably be done in laser on letter-sized paper and the font sizes will be as indicated below: FORMAT FONT INFORMATION Block Headers Arial 9 Bold or other equivalent size font. Preferably, spaces where headers appear should be printed with 15% shading. Field Name Arial 8 Bold or other equivalent size font. Declared Information Arial 9 or other equivalent size font. The printing format for all dates will be: DD/MM/YYYY Where DD Is the day in two positions. Depending on the month, it can be from 01 to 31. MM Is the month number (01 to 12). YYYY Is the year in four positions.
638 OFFICIAL GAZETTE Friday, January 17, 2025 MAIN HEADER OF THE CUSTOMS DECLARATION The main header must be recorded on the first page of every customs declaration. The right part of the header must be used for the certification of automated selection. CUSTOMS DECLARATION Page 1 of N NUM. CUSTOMS DECLARATION: T. OPER CVE. CUSTOMS DECLARATION: REGIME: CERTIFICATIONS DESTINATION: EXCHANGE RATE: GROSS WEIGHT: CUSTOMS OFFICE I/S: MEANS OF TRANSPORT ARRIVAL/ DEPARTURE: ARRIVAL: DEPARTURE: CUSTOMS VALUE: PAID PRICE/COMMERCIAL VALUE: IMPORTER/EXPORTER DATA RFC Key: NAME, DENOMINATION OR CORPORATE NAME: CURP: ADDRESS: INSURABLE VALUES INSURANCE FREIGHT PACKAGING OTHERS DECREMENTABLE VALUES TRANSPORT DECREMENTABLE INSURANCE DECREMENTABLE CARGO DECREMENTABLE UNLOADING DECREMENTABLE OTHERS DECREMENTABLE ACCEPTANCE CODE: BARCODE KEY CUSTOMS SECTION KEY OF DISPATCH: MARKS, NUMBERS AND TOTAL OF PACKAGES: DATES RATES AT CUSTOMS DECLARATION LEVEL CONTRIB. CVE. T. RATE RATE LIQUIDATION TABLE CONCEPT F.P. AMOUNT CONCEPT F.P. AMOUNT TOTALS CASH OTHERS TOTAL
Friday, January 17, 2025 OFFICIAL GAZETTE 639 HEADER FOR SECONDARY PAGES OF THE CUSTOMS DECLARATION The header for pages 2 to the last page is the one presented below. ANNEX OF THE CUSTOMS DECLARATION Page M of N NUM. CUSTOMS DECLARATION: TYPE OPER: CVE. DECL: RFC Key: CURP: FOOTER OF ALL SHEETS OF THE CUSTOMS DECLARATION The footer presented below must be printed at the bottom of all sheets of the customs declaration. In all copies, their RFC key, CURP and name of the customs broker, customs agency, customs attorney, warehouse attorney or accredited legal representative must appear. When the customs declaration carries the digital signature of the principal, their RFC key and name must appear after those of the customs broker or customs agency. CUSTOMS BROKER, CUSTOMS AGENCY, CUSTOMS ATTORNEY OR WAREHOUSE ATTORNEY NAME OR CORP. NAME: RFC Key: CURP: PRINCIPAL/AUTHORIZED PERSON NAME: RFC Key: CURP: I DECLARE UNDER OATH, IN TERMS OF WHAT ESTABLISHED BY ARTICLE 81 OF THE LAW, PATENT OR AUTHORIZATION: CERTIFICATE SERIAL NUMBER: digital signature: The payment of contributions can be made through the electronic payment service, as established in rule 1.6.2., with the possibility that the bank account of the person contracting the services is directly affected by the Bank. The customs broker, customs agency or customs attorney who uses the electronic payment service must print the bank certification in the corresponding field of the customs declaration or in the official document, according to appendix 23 Electronic Payment of Annex 22. The Importer-Exporter may request certification of the information transmitted to the SAAI by the customs broker, customs agency or customs attorney at the time of preparing the customs declaration at the DGIA. NOTE: When the customs declaration carries the digital signature of the customs broker or customs agency, the data of the principal should not be printed; regarding the electronic payment legend, this must be printed in the Footer of the customs declaration, only on the first sheet. END OF CUSTOMS DECLARATION In order to identify the conclusion of the printing of the customs declaration, on the last page, the following legend must be printed, immediately after the last block of information that has been printed. **********END OF CUSTOMS DECLARATION ******TOTAL NUM. OF ITEMS: ******PREVALIDATOR KEY:
HEADER OF SUPPLIER OR BUYER DATA The value acknowledgment numbers generated with the transmission referred to in article 59-A of the Law and rule 1.9.16., which contains the information of the CFDI or equivalent documents expressing the value of the merchandise covered by the customs declaration, must be printed. SUPPLIER OR BUYER DATA VALUE ACKNOWLEDGMENT NUMBER LINKAGE INCOTERM
640 OFFICIAL GAZETTE Friday, January 17, 2025 TRANSPORT AND CARRIER DATA TRANSPORT IDENTIFICATION: COUNTRY: CARRIER RFC Key CURP ADDRESS/CITY/STATE PADLOCKS PADLOCK NUMBER 1ST INSPECTION 2ND INSPECTION GUIDES, MANIFESTS OR BILL OF LADING As many lines as necessary can be printed and in each one, information up to three guide numbers, manifest numbers, or bill of lading order numbers (number and identifier) or transport document numbers can be declared. NUMBER (GUIDE/ORDER SHIPMENT)/ID: CONTAINERS/RAILWAY CAR/ECONOMIC NUMBER OF VEHICLE As many lines as necessary can be printed and in each one, container, railway equipment, and economic vehicle number (number and type) information can be declared. NUMBER/TYPE IDENTIFIERS (DECLARATION LEVEL) As many lines as necessary can be printed. KEY/COMP. IDENTIFIER COMPLEMENT 1 COMPLEMENT 2 COMPLEMENT 3 CUSTOMS ACCOUNTS AND CUSTOMS GUARANTEE ACCOUNTS AT DECLARATION LEVEL CUSTOMS ACCOUNTS AND CUSTOMS GUARANTEE ACCOUNTS ACCOUNT TYPE: GUARANTEE KEY: ISSUING INSTITUTION: CONTRACT NUMBER: CONSTANCY FOLIO: TOTAL DEPOSIT: CONSTANCY DATE: DEFENSES DEFENSES ORIGINAL CUSTOMS DECLARATION NUM.: ORIGINAL OPERATION DATE: ORIGINAL DECLARATION CVE:
Friday, January 17, 2025 OFFICIAL GAZETTE 641 COMPENSATIONS COMPENSATIONS ORIGINAL CUSTOMS DECLARATION NUM.: ORIGINAL OPERATION DATE: KEY OF THE ENCUMBRANCE: AMOUNT OF THE ENCUMBRANCE: DOCUMENTS COVERING PAYMENT METHODS: BOND, CHARGE TO FEDERAL GOVERNMENT BUDGET LINE, SPECIAL CERTIFICATES OF PUBLIC AND PRIVATE TREASURY. VIRTUAL PAYMENT METHODS PAYMENT METHOD DEPARTMENT OR ISSUING INSTITUTION DOCUMENT IDENTIFICATION NUMBER DOCUMENT DATE AMOUNT OF THE DOCUMENT AVAILABLE BALANCE AMOUNT TO PAY As many lines as necessary can be printed and in each one, information of a document covering one of the cited payment methods can be declared. OBSERVATIONS The block corresponding to observations must be printed when this information has been sent electronically, considering that the customs broker, customs agency, customs attorney or warehouse attorney deems it appropriate to manifest any observation related to the customs declaration. OBSERVATIONS ITEM HEADER ITEMS On the first page where item information covered by the customs declaration is printed, as well as on subsequent pages containing item information, the following header must be printed, either immediately after the general information blocks of the customs declaration or immediately after the header of the subsequent pages. For each of the items of the customs declaration, the data mentioned below must be declared, according to the position in which they are in this header. ITEMS FRACTION SUBD/ NUM. COMMERCIAL IDENTIFICATION. LINK. MET VAL UMC QUANTITY UMC UMT QUANTITY UMT P. V/C P. O/D SEC DESCRIPTION (VARIABLE LINES AS REQUIRED) CON. RATE T.T. F.P. AMOUNT CUSTOMS VALUE/USD AMT. PAID PRICE UNIT PRICE ADD. VALUE BRAND MODEL PRODUCT CODE NOTE: The row corresponding to Brand, Model and Product Code only needs to be printed when this information has been transmitted electronically.
642 OFFICIAL GAZETTE Friday, January 17, 2025 MERCHANDISE VIN/SER. NUM. MILEAGE VIN/SER. NUM. MILEAGE NON-TARIFF REGULATIONS, RESTRICTIONS AND NOM KEY NUM. PERMIT OR NOM SIGNATURE DEFENSE COM. VAL. USD. QUANTITY UMT/C IDENTIFIERS (ITEM LEVEL) IDENTIF. COMPLEMENT 1 COMPLEMENT 2 COMPLEMENT 3 CUSTOMS GUARANTEE ACCOUNTS AT ITEM LEVEL GUAR. KEY INST. ISSUER DATE C. ACCOUNT NUMBER FOLIO CONSTANCY TOTAL DEPOSIT ESTIMATED PRICE QUANTITY U.M. EST. PRICE DETERMINATION AND/OR PAYMENT OF CONTRIBUTIONS BY APPLICATION OF ARTICLE 2.5 OF THE T-MEC AT ITEM LEVEL When the determination and payment of contributions by application of Article 2.5 of the T-MEC is carried out when processing the customs declaration covering the return, the following block must be added to the corresponding tariff fraction: DETERMINATION AND/OR PAYMENT OF CONTRIBUTIONS BY APPLICATION OF ARTICLES 2.5 OF THE T-MEC, 14 OF ANNEX III OF THE DECISION, 15 OF ANNEX I OF THE T-LCAELC OR ACC AT ITEM LEVEL DETERMINATION AND/OR PAYMENT OF CONTRIBUTIONS BY APPLICATION OF ARTICLES 2.5 OF THE T-MEC, 14 OF ANNEX III OF THE DECISION, 15 OF ANNEX I OF THE T-LCAELC OR ACC VALUE OF NON-ORIGINATING MERCHANDISE AMOUNT IGI OBSERVATIONS AT ITEM LEVEL The block corresponding to observations at item level must be printed when this information has been sent electronically, considering that the customs broker, customs agency, customs attorney or warehouse attorney deems it appropriate to manifest any observation related to the item. OBSERVATIONS AT ITEM LEVEL CORRECTIONS CORRECTION DATA When it is a correction customs declaration, the customs broker, customs agency or customs attorney must print the following block where the original customs declaration and the key of the correction document are mentioned immediately after the header of the first page. CORRECTION ORIGINAL CUSTOMS DECLARATION CVE. ORIG. DECL. CVE. CORR. DECL. DATE CORR. PAYMENT
Friday, January 17, 2025 OFFICIAL GAZETTE 643 BARCODES AND PAYMENT INFORMATION FOR CUSTOMS DECLARATION PRINTING FIELD DESCRIPTION BARCODE REFERENCED DEPOSIT CAPTURE LINE When payment is made using payment method 0 (zero, Cash appendix 13 Annex 22-), it shall contain a barcode described in the Code 128 standard containing the capture line and amount for payment. *** ELECTRONIC PAYMENT *** In the event of payment by electronic means, it must contain the information set forth in appendix 23 of Annex 22. QR CODE FOR PAYMENT VERIFIER AND/OR COMPLIANCE The printing of the customs declaration format and/or simplified customs declaration printing must include a two-dimensional barcode in accordance with the QR Code (Quick Response Code) format described in the ISO/IEC18004:2000 standard, containing the data, formed as follows and adding a line break: Parameter Data Characters URL https://aplicacionesc.mat.sat.gob.mx/ SOIANET/oia_consultarapd_cep.asp x? 71 pa Legal representative number, customs broker, customs agency or customs attorney. 4 dn Customs Declaration Number 7 s fill with 0. 1 ap Year of validation of the customs declaration 4 pad Customs number in accordance with SOIA Customs Catalog. 2 or 3 ad Customs name in accordance with SOIA Customs Catalog. For each space, fill with %20; example: AEROPUERTO%20INTERNAL.%20 CD.%20DE%20MEXICO,%20D.F. abierto The two-dimensional barcode must be printed in a square with dimensions of 100 px x 100 px or 3.75 x 3.75 cm that integrates the information of the customs declaration mentioned in this format. DIFFERENCES IN CONTRIBUTIONS AT THE CUSTOMS DECLARATION LEVEL After the rectification information cited in the previous paragraph, the settlement table of the total differences of the rectification customs declaration in relation to the contributions paid in the customs declaration being rectified must be printed. It should be noted that the values cited in this table, in case there are amounts to pay with payment method 0 (zero, Cash appendix 13 Annex 22), must coincide with the amount of the capture line.
644 OFFICIAL GAZETTE Friday, January 17, 2025 DIFFERENCES IN CONTRIBUTIONS AT THE CUSTOMS DECLARATION LEVEL CONCEPT F.P. DIFFERENCE CONCEPT F.P. DIFFERENCE TOTAL DIFFERENCES CASH OTHERS TOTAL DIFF. NOTE: When rectifying information at the customs declaration level, the field Observations at Customs Declaration Level must cite the correction made. COMPLEMENTARY CUSTOMS DECLARATION HEADER OF THE COMPLEMENTARY CUSTOMS DECLARATION When it is a complementary customs declaration due to the application of Articles 2.5 of the T-MEC, 14 of Annex III of the Decision, 15 of Annex I of the TLCAELC or of the ACC, the customs broker, customs agency or customs attorney must print the following block immediately after the main header of the customs declaration on the first page. COMPLEMENTARY CUSTOMS DECLARATION After the disclaimer block, the following block must be printed, this when the customs declaration requires it. SUFFICIENT PROOF SUFFICIENT PROOF DESTINATION COUNTRY NO. CUSTOMS DECLARATION USA/CAN SUFFICIENT PROOF HEADER FOR DETERMINATION OF CONTRIBUTIONS AT THE HEADING LEVEL FOR COMPLEMENTARY CUSTOMS DECLARATIONS UNDER ARTICLE 2.5 OF THE T-MEC. DETERMINATION OF CONTRIBUTIONS AT THE HEADING LEVEL SEC FRAC VALUE MERC NO ORIGIN. IGI TOTAL AMT ARAN. USA/CAN EXEMPT AMT. F.P. AMOUNT UMT QTY UTM FRAC. USA/CAN RATE USA/CAN ARAN. USA/CAN NOTE: When it is a complementary customs declaration, for which there are various goods that were destined to the USA and to Canada indistinctly, the blocks of Sufficient Proof and Header for Determination of Contributions at Heading Level for Complementary Customs Declarations under Article 2.5 of the T-MEC must be printed first, for the goods destined to the USA and immediately the same blocks will be printed for the goods destined to Canada. HEADER FOR DETERMINATION OF CONTRIBUTIONS AT THE HEADING LEVEL FOR COMPLEMENTARY CUSTOMS DECLARATIONS UNDER ARTICLES 14 OF ANNEX III OF THE DECISION, 15 OF ANNEX I OF THE TLCAELC OR OF THE ACC. DETERMINATION OF CONTRIBUTIONS AT THE HEADING LEVEL SEC FRAC VALUE MERC NO ORIGIN. IGI AMT F.P. AMOUNT
Friday, January 17, 2025 OFFICIAL GAZETTE 645 M1.2. Import Customs Declaration. Part II. Partial shipment of goods BARCODE Customs declaration number ________________ Vehicle data ___________________ Locks __________________________ Container(s)______________________ Type of goods Quantity in Units of Commercialization Quantity in Tariff Units Certificate serial number: e.firma:
Name Filling instructions for the import customs declaration form. Part II. Partial shipment of goods. Field Content
646 OFFICIAL GAZETTE Friday, January 17, 2025 3. Vehicle data. The identification data of the vehicle transporting the goods will be recorded, such as: model, license plate number and serial number. 4. Locks. 5. Containers. The numbers of the locks used to secure the access doors to the vehicle will be recorded, when applicable. The container or trailer number will be recorded, when applicable. In the case of operations through the Northern and Southern Border customs and the means of transport is Rail, the identification number of the railway equipment or container number must be declared. 6. Type of goods. The description of the goods, nature and characteristics necessary and sufficient to determine their tariff classification will be recorded, as well as the NICO corresponding to the goods. 7. Quantity in Units of Commercialization. The quantity of goods in commercialization units will be recorded, in accordance with what is stated in the equivalent document. 8. Quantity in Units of Tariff. The corresponding quantity of goods will be recorded, in accordance with the unit of measure indicated in the TIGIE. 9. Certificate serial number. Serial number of the certificate of the e.firma of the customs broker, customs agency, customs attorney, warehouse attorney or agent of the customs broker, that promotes the dispatch. 10. e.firma. e.firma of the customs broker, customs agency, customs attorney, warehouse attorney or agent of the customs broker, that promotes the dispatch, corresponding to the validation signature of the customs declaration. 11. Name. The name of the customs attorney, customs broker, customs agency or warehouse attorney, or the agent of the customs broker or of the customs agency that promotes will be recorded.
Friday, January 17, 2025 OFFICIAL GAZETTE 647 M1.3. Export Customs Declaration. Part II. Partial shipment of goods BARCODE Customs declaration number ________________ Vehicle data ___________________ Locks __________________________ Container(s)______________________ Type of goods Quantity in Unit of Measure of Commercialization Quantity in Unit of measure of Tariff Certificate serial number: e.firma:
Name Filling instructions for the export customs declaration form. Part II. Partial shipment of goods. Field Content
648 OFFICIAL GAZETTE Friday, January 17, 2025 7 digits, which will be progressive numbering by customs, in which they are authorized for dispatch, assigned by each customs broker, customs agency, customs attorney or warehouse attorney, referring to all types of customs declarations, starting each year with the number 0000001. Note: Between each of these data, two blank spaces must be preserved. 3. Vehicle data. The identification data of the vehicle transporting the goods will be recorded, such as: model, license plate number and serial number. 4. Locks. The numbers of the locks used to secure the access doors to the vehicle will be recorded, when applicable. 5. Containers. The container or trailer number will be recorded, when applicable. In the case of operations through the Northern and Southern Border customs and the means of transport is Rail, the identification number of the railway equipment or container number must be declared. 6. Type of goods. The description of the goods, nature and characteristics necessary and sufficient to determine their tariff classification will be recorded, as well as the NICO corresponding to the goods. 7. Quantity in Unit of measure of Commercialization. The quantity of goods in commercialization units will be recorded, in accordance with what is stated in the CFDI. 8. Quantity in Unit of measure of Tariff. The corresponding quantity of goods will be recorded, in accordance with the unit of measure indicated in the TIGIE. 9. Certificate serial number. Serial number of the certificate of the e.firma of the customs broker, customs agency, customs attorney, warehouse attorney or agent of the customs broker or of the customs agency, that promotes the dispatch. 10. e.firma. e.firma of the customs broker, customs agency, customs attorney, warehouse attorney or agent of the customs broker or of the customs agency, that promotes the dispatch, corresponding to the validation signature of the customs declaration. 11. Name. The name of the customs attorney, customs broker, customs agency or warehouse, or the agent of the customs broker or of the customs agency that promotes will be recorded.
Friday, January 17, 2025 OFFICIAL GAZETTE 649 M1.4. Transit Customs Declaration for transshipment SHEET _______ OF _______ NO. OF CUSTOMS DECLARATION ________________________________________________________ TYPE OF OPERATION ______________________________________________________ CUSTOMS DECLARATION KEY _____________________________________________________ ORIGIN CUSTOMS/SECTION _________________________________________________ DESTINATION CUSTOMS/SECTION ________________________________________________ COUNTRY OF ORIGIN __________________________________________________________ T.C. _____________________ ENTRY DATE _____________________________ ARRIVAL TRANSIT DATE _______________________________________________ IMPORTER/CONSIGNEE ________________________________________________ R.F.C.
ADDRESS _______________________________________________________________ AIRLINE (1) ________________ FLIGHT NO. __________ REGISTRATION No. _ AIRLINE (2) _______________ FLIGHT NO. ______________ REGISTRATION No. _ R.F.C.: __________________________ LOCAL REGISTRATION NO. __________________ ADDRESS ______________________________________________________________________________________ M.E. VALUE _____________________________________________________________________________________ DLS VALUE _____________________________________________________________________________________ QUANTITY NUMBERS/DATES INVOICING FORM CFDI OR DOCUMENTS EQUIVALENTS AIR WAYBILLS SUPPLIER(S) BUNDLES QUANTITY MARKS NUMBERS DESCRIPTION OF THE GOODS(S) UNIT PRICE VALUE IN CUSTOMS U/M QUANTITY PERMIT(S) AUTHORIZATION(S) AND IDENTIFIERS/ KEY(S)/ NUMBERS/SIGNATURE ACKNOWLEDGMENT OF RECEIPT BARCODE PROVISIONAL SETTLEMENT CVE. F/P TAXES STICKER OR LOCKS ASSIGNED OBSERVATIONS: CUSTOMS BROKER, CUSTOMS AGENCY OR CUSTOMS ATTORNEY REPRESENTATIVE OF THE AIRLINE SUPERVISOR IN CHARGE NAME AND SIGNATURE NAME AND SIGNATURE
650 OFFICIAL GAZETTE Friday, January 17, 2025 M1.5. Simplified Customs Declaration Form The simplified customs declaration form is a dynamic format composed of blocks, in which only the blocks indicated in this document must be printed, with the information transmitted to the SAAI at the time of preparing the customs declaration referred to in the Instructions for filling out the customs declaration of Annex 22. This format must be presented in one copy intended for the importer or exporter. In the lower right part, it must bear the printed legend corresponding as follows: Destination/origin: interior of the country. Destination/origin: border region. Destination/origin: border fringe. When the destination of the goods is the interior of the country, it is an export, a complementary customs declaration or transit customs declaration, the way in which the customs declaration will be printed must be white, when it is to the border fringes, yellow and in the case of the border region, green. In no case can the goods circulate with the copy through a zone of the country different from the one corresponding to the color, except for white which can circulate throughout the country. This format will not be applicable in the case of operations provided for in rules 2.5.1., regarding used vehicles, trailers and semi-trailers; 2.5.2., regarding used vehicles, trailers and semi-trailers; 3.1.21., fraction III, subsection b), 3.5.1., fraction II, 3.5.4., 3.5.5., 3.5.6., 3.5.8. and 3.5.11., as well as vehicle operations carried out under a diplomatic franchise, in accordance with article 62, fraction I of the Law. Below, the different blocks that may constitute the simplified form of a customs declaration are presented, citing their mandatory nature and the manner in which they must be printed. When in a specific field, the specified space is not sufficient, it can be expanded by adding as many lines in the section as required. The printing should preferably be done on laser paper size letter and the font sizes will be as indicated below: FORMAT FONT INFORMATION Block Headers Arial 9 Bold or other equivalent size font. Preferably, spaces where headers appear should be printed with 15% shading. Field Name Arial 8 Bold or other equivalent size font. Declared Information Arial 9 or other equivalent size font. The print format for all dates will be: DD/MM/YYYY Where DD Is the day in two positions. Depending on the month, it can be from 01 to 31. MM Is the month number. (01 to 12). YYYY Is the year in four positions. HEADER OF THE SIMPLIFIED CUSTOMS DECLARATION FORM The main header must be printed as the first block of any simplified customs declaration form. The right part of the header must be used for automated selection certification. The printing of the sub-block called SETTLEMENT TABLE is mandatory when the payment is made through Bank Window.
Friday, January 17, 2025 OFFICIAL GAZETTE 651 SIMPLIFIED CUSTOMS DECLARATION FORM Page 1 of N NO. CUSTOMS DECLARATION: T. OPER CUSTOMS DECL. KEY: CERTIFICATIONS DESTINATION: GROSS WEIGHT: CUSTOMS E/S: IMPORTER/EXPORTER DATA RFC Key: CURP: ACCEPTANCE CODE: BARCODE KEY OF THE SECTION CUSTOMS DISPATCH: MARKS, NUMBERS AND TOTAL BUNDLES: DATES SETTLEMENT TABLE CONCEPT F.P. AMOUNT CONCEPT F.P. AMOUNT TOTALS CASH OTHERS TOTAL REFERENCED DEPOSIT CAPTURE LINE 0318 21K7 98P1 0629 0292 1458 ELECTRONIC PAYMENT NOTE: In customs declarations processed in accordance with rules 3.7.5., 7.3.6., fractions I and II, 4.5.20., 4.5.31., 4.8.5., 4.8.7. and 4.8.8., fraction II, the fields DESTINATION, GROSS WEIGHT, MARKS, NUMBERS AND TOTAL BUNDLES must bear the printed legend N/A. HEADER FOR SECONDARY PAGES OF THE SIMPLIFIED CUSTOMS DECLARATION FORM The header for pages 2 to the last page is as follows. CUSTOMS DECLARATION ANNEX Page M of N NO. CUSTOMS DECLARATION: TYPE OPER: CUSTOMS DECL. KEY: RFC Key: CURP: FOOTER OF ALL SHEETS OF THE SIMPLIFIED CUSTOMS DECLARATION FORM The footer presented below must be printed at the bottom of all sheets of the customs declaration. The e.firma of the customs broker, customs agency, customs attorney or warehouse attorney must appear. When the customs declaration bears the e.firma of the agent, their RFC key and name must appear after those of the customs broker, customs agency.
652 OFFICIAL GAZETTE Friday, January 17, 2025 CUSTOMS BROKER, CUSTOMS AGENCY, CUSTOMS ATTORNEY OR WAREHOUSE ATTORNEY NAME OR COMPANY NAME: RFC Key: CURP: AGENT/AUTHORIZED PERSON NAME: RFC Key: CURP: I DECLARE UNDER OATH THAT I AM TELLING THE TRUTH, UNDER THE TERMS OF WHAT IS ESTABLISHED IN ARTICLE 81 OF THE LAW: PATENT OR AUTHORIZATION: CERTIFICATE SERIAL NUMBER: e.firma: Payment of contributions can be made through the Electronic Payment service, in accordance with what is established in rule 1.6.2., with the possibility that the bank account of the person who hires the services may be directly affected by the Bank. The customs broker or customs attorney who uses the electronic payment service must print the bank certification in the corresponding field of the simplified customs declaration form or in the official document in accordance with appendix 23 Electronic Payment of Annex 22. The Importer-Exporter may request certification of the information transmitted to the SAAI by the customs broker or customs attorney at the time of preparing the customs declaration at the DGIA. NOTE: When the customs declaration bears the e.firma of the customs broker of the customs agency, the data of the agent must not be printed; regarding the electronic payment legend, it must be printed in the Footer of the simplified customs declaration form, only on the first sheet. END OF CUSTOMS DECLARATION In order to identify the conclusion of the simplified customs declaration form, on the last page, the following legend must be printed, immediately after the last block of information that has been printed. *********END OF CUSTOMS DECLARATION *****TOTAL NO. OF LINES: *****PREVALIDATOR KEY: ********** LOCK(S) For the row named LOCK NUMBER, as many rows as necessary can be printed and in each one the information can be declared up to six lock numbers. The row 1ST REVIEW and the row 2ND REVIEW are printed only once. LOCK NUMBER 1ST REVIEW 2ND REVIEW WAYBILLS, MANIFESTS, BILL OF LADING OR TRANSPORT DOCUMENTS As many rows as necessary can be printed and in each one the information can be declared up to three numbers of waybills, manifests or bill of lading order numbers (number and identifier) or transport document numbers. NUMBER (WAYBILL/ORDER BILL OF LADING)/ID: CONTAINERS/RAILWAY EQUIPMENT/VEHICLE ECONOMIC NUMBER As many rows as necessary can be printed and in each one the information of containers, railway car and vehicle economic number (number and type) can be declared. NUMBER/TYPE
Friday, January 17, 2025 OFFICIAL GAZETTE 653 VALUE ACKNOWLEDGMENT NUMBER As many rows as necessary can be printed and in each one the information can be declared up to four numbers. VALUE ACKNOWLEDGMENT NUMBER NOTE: The value acknowledgment number information only needs to be printed when this information has been transmitted in terms of rule 1.9.16. IDENTIFIERS (CUSTOMS DECLARATION LEVEL) KEY/COMP. IDENTIFIER COMPLEMENT 1 COMPLEMENT 2 COMPLEMENT 3 NOTE: This block must only be printed with the identifier corresponding to the operations provided for in rule 3.1.21., fraction III, subsection a). E-DOCUMENTS This block must be printed only with complement 1 of the ED identifier, without it being necessary to declare the identifier key; as many rows as necessary can be printed and in each one the information can be declared up to four e-document numbers. E-DOCUMENT NUMBER NOTE: The row information only needs to be printed when documentation is attached in terms of rule 3.1.31. TRANSPORT AND CARRIER DATA TRANSPORT IDENTIFICATION: COUNTRY: CARRIER RFC Key CURP ADDRESS/CITY/STATE NOTE: This block must be printed when this information has been sent electronically. OBSERVATIONS The block corresponding to observations must be printed when this information has been sent electronically, by considering it convenient to manifest any observation related to the customs declaration. OBSERVATIONS RECTIFICATIONS RECTIFICATION DATA When it is a rectification customs declaration, the customs broker or customs attorney must print the following block where the original customs declaration and the key of the document of the rectification are mentioned immediately after the main header. RECTIFICATION ORIGINAL CUSTOMS DECLARATION ORIGINAL CUSTOMS DECL. KEY RECT. CUSTOMS DECL. KEY RECT. PAYMENT DATE
654 OFFICIAL GAZETTE Friday, January 17, 2025 BARCODES AND PAYMENT INFORMATION FOR THE PRINTING OF THE SIMPLIFIED ENTRY PERMIT FIELD DESCRIPTION BARCODE REFERENCED DEPOSIT CAPTURE LINE When payment is made using payment method 0 (zero, Cash appendix 13 Annex 22-), it shall contain a barcode described in the Code 128 standard containing the capture line and amount for payment. *** ELECTRONIC PAYMENT *** In the event that payment is made by means of electronic payment, it must contain the information set forth in appendix 23 of Annex 22. PAYMENT VERIFIER QR CODE AND/OR COMPLIANCE The printing of the entry permit format and/or simplified printing of the entry permit must include a two-dimensional barcode according to the QR Code (Quick Response Code) format described in the ISO/IEC18004:2000 standard, containing the data, formed as follows and adding a line break: Parameter Data Characters URL https://aplicacionesc.mat.sat.gob.mx/SOIANET/oia_consultarapd_cep.aspx? 71 pa Number legal representative, customs broker, customs agency or customs attorney. 4 dn Entry Permit Number 7 s fill with 0. 1 ap Year of validation of the entry permit 4 pad Number of the customs office according to the SOIA Customs Catalog. 2 or 3 ad Name of the customs office according to the SOIA Customs Catalog. For each space it must be filled with %; example. AEROPUERTO%20INTERNAL.%20CD.%20DE%20MEXICO,%20D.F. abierto The two-dimensional barcode must be printed in a square with dimensions of 100 px x 100 px or 3.75 x 3.75 cm that integrates the information of the entry permit mentioned in this format. DIFFERENCES IN CONTRIBUTIONS AT THE ENTRY PERMIT LEVEL After the rectification information, cited in the block called Rectification Data, the settlement table of the total differences of the rectification entry permit in relation to the contributions paid in the entry permit being rectified must be printed. It should be noted that the values cited in this table, in case there are amounts to pay with payment method 0 (zero, Cash appendix 13 Annex 22), must coincide with the amount of the capture line. DIFFERENCES IN CONTRIBUTIONS AT THE ENTRY PERMIT LEVEL CONCEPT F.P. DIFFERENCE CONCEPT F.P. DIFFERENCE TOTAL DIFFERENCES CASH OTHERS TOTAL DIFF.
Friday, January 17, 2025 OFFICIAL GAZETTE 655 M1.6. Consolidated Notice Format The consolidated notice format is composed of blocks, in which only the blocks indicated in this document must be printed, for the purposes provided in article 37-A of the Law and rules 1.9.17. and 3.1.32. This format must be presented in one copy intended for the importer or exporter. In the lower right part, it must bear the legend corresponding to the following: Destination/origin: interior of the country. Destination/origin: border region. Destination/origin: border strip. When the destination of the merchandise is the interior of the country, if it is an export, the way it is printed must be white, when it is to the border strips, yellow and in the case of the border region, green. In no case can the merchandise circulate with the copy through a zone of the country different from the one corresponding according to the color, except for white which can circulate throughout the country. Below, the different blocks that must constitute the consolidated notice format are presented, citing the way in which they must be printed. It should be done preferably with a laser printer on letter-sized paper and with the font format indicated below: INFORMATION FONT FORMAT Block Headers Arial 9 Bold or another equivalent size font. Preferably, the spaces where headers appear should be printed with 15% shading. Field Name Arial 8 Bold or another equivalent size font. Declared Information Arial 9 or another equivalent size font. MAIN HEADER OF THE CONSOLIDATED NOTICE FORMAT The main header must be printed as the first block in the consolidated notice format. The right part of the header must be used for automated selection certifications. CONSOLIDATED NOTICE FORMAT Page 1 of N ENTRY PERMIT NO.: OP. TYPE: ENTRY PERMIT CODE: CERTIFICATIONS VALUE ACKNOWLEDGEMENT NUMBER: CUSTOMS E/S BATCH NO.: GROSS WEIGHT IMPORTER/EXPORTER DATA RFC Key: NAME, DENOMINATION OR LEGAL NAME: ACCEPTANCE CODE: BARCODE KEY OF THE CUSTOMS SECTION OF CLEARANCE: MARKS, NUMBERS AND TOTAL PACKAGES:
656 OFFICIAL GAZETTE Friday, January 17, 2025 HEADER FOR SECONDARY PAGES OF THE CONSOLIDATED NOTICE FORMAT The header for pages 2 to the last page is as follows. ANNEX TO THE ENTRY PERMIT Page M of N ENTRY PERMIT NO.: OP. TYPE: VALUE ACKNOWLEDGEMENT NUMBER: RFC Key: FOOTER OF THE CONSOLIDATED NOTICE FORMAT The footer presented below must be printed at the bottom as the last block of the consolidated notice format. The RFC key, CURP and name of the Customs Broker, Customs Agency, Customs Attorney or Warehouse Representative must appear, the certificate serial number and the e.firma of the transmission referred to in rule 1.9.17. When the transmission is carried out by the agent, their RFC key, CURP, name, certificate serial number and e.firma of the transmission referred to in rule 1.9.17., must appear after the name, RFC key, CURP and name of the Customs Broker or Customs Agency. CUSTOMS BROKER, CUSTOMS ATTORNEY NAME: RFC Key: CURP: AGENT/AUTHORIZED PERSON NAME: RFC Key: CURP: CERTIFICATE SERIAL NUMBER: e.firma: END OF PRINTING In order to identify the conclusion of the consolidated notice format, on the last page, the following legend must be printed, immediately after the last information block that has been printed. **********END OF PRINTING
LOCKS(S) For the row named LOCK NUMBER, as many rows as necessary can be printed and in each one, information up to six lock numbers can be declared. The 1ST REVIEW row and the 2ND REVIEW row are only printed once. LOCK NUMBER 1ST REVIEW 2ND REVIEW CONTAINERS/RAILWAY EQUIPMENT/VEHICLE ECONOMIC NUMBER As many rows as necessary can be printed and in each one, container, railway equipment and vehicle economic number information can be declared. (number and type). NUMBER/TYPE OBSERVATIONS The observations block must be printed when this information has been transmitted electronically in the value acknowledgment. OBSERVATIONS
Friday, January 17, 2025 OFFICIAL GAZETTE 657 INSTRUCTIONS FOR FILLING OUT THE CONSOLIDATED NOTICE FORMAT Field Content Main Header
658 OFFICIAL GAZETTE Friday, January 17, 2025 8. NAME, DENOMINATION OR LEGAL NAME OF THE IMPORTER/EXPORTER. Name, denomination or legal name of the importer or exporter, as it was manifested for RFC purposes. 9. ACCEPTANCE CODE. Acknowledgment of acceptance, of the prior entry permit under which the merchandise is consolidated, composed of eight characters. 10. BARCODE. The barcode printed by the customs broker, customs agency or customs attorney, according to what is established in appendix 17 of this Annex 22. 11. KEY OF THE CUSTOMS SECTION OF CLEARANCE. Key of the customs office and customs section before which the clearance is promoted (three positions), according to appendix 1 of Annex 22. MARKS, NUMBERS AND TOTAL PACKAGES. Marks, numbers and total packages containing the merchandise covered by the consolidated notice format. In operations processed according to rules 3.7.5., 4.5.20. 4.5.31 and 7.3.6., fractions I and II, this field must bear the legend N/A. Header for secondary pages
Friday, January 17, 2025 OFFICIAL GAZETTE 659 6. CERTIFICATE SERIAL NUMBER. Certificate serial number of the e.firma of the customs broker or customs agency, customs attorney or agent of the customs broker or customs agency, who promotes the clearance corresponding to the signature of validation of the transmission of the value acknowledgment. AGENT/AUTHORIZED PERSON. When the transmission of the value acknowledgment is carried out by the customs broker or customs agency through its agent, with its e.firma, the following data must also be printed: 7. NAME. Full name of the agent of the customs broker or customs agency who carried out the transmission provided for in rule 1.9.17. 8. RFC Key. RFC key of the agent of the customs broker or customs agency who carried out the transmission provided for in rule 1.9.17. 9. CURP. CURP of the agent of the customs broker or customs agency who carried out the transmission provided for in rule 1.9.17. 10. END OF PRINTING It must be placed at the end of the last page of this format, the legend END OF PRINTING. Locks
660 OFFICIAL GAZETTE Friday, January 17, 2025 M1.7. DOCUMENT FOR CUSTOMS CLEARANCE OPERATION (DODA) Page 1 of N INTEGRATION NO.: PATENT OR AUTHORIZATION: TWO-DIMENSIONAL BARCODE ISSUANCE DATE: TOTAL NO. OF ENTRY PERMITS AND/OR CONSOLIDATED NOTICES OF THE OPERATION: CONTAINERS/ RAILWAY EQUIPMENT/ NO. ECONOMIC OF THE VEHICLE: LOCKS CUSTOMS SECTION OF CLEARANCE: ORIGINAL CHAIN: TAX SLIP OF CFDI WITH COMPLEMENT LETTER OF CARRIAGE: SIGNATURE OF LEGAL REPRESENTATIVE, CUSTOMS BROKER, CUSTOMS AGENCY OR ATTORNEY: CERTIFICATE SERIAL NUMBER: DIGITAL SEAL: SAT SEAL: CERTIFICATE SERIAL NUMBER: DIGITAL SEAL: I DECLARE UNDER OATH THAT THE INFORMATION IS TRUE, IN TERMS OF WHAT IS PROVIDED BY ARTICLE 81 OF THE LAW, LEGAL REPRESENTATIVE, CUSTOMS BROKER, CUSTOMS AGENCY OR ATTORNEY. *The date and time of issuance correspond to the central time of the country. HEADER FOR SECONDARY PAGES OF THE DODA The header for pages 2 to the last page is as follows. DODA Page 1 of N INTEGRATION NO.: PATENT OR AUTHORIZATION: FOOTER OF ALL SHEETS OF THE DODA The footer presented below must be printed at the bottom of all sheets. The name and signature of the legal representative, customs broker, customs agency or customs attorney must appear: I DECLARE UNDER OATH THAT THE INFORMATION IS TRUE, IN TERMS OF WHAT IS PROVIDED BY ARTICLE 81 OF THE LAW, LEGAL REPRESENTATIVE OR ATTORNEY.
Friday, January 17, 2025 OFFICIAL GAZETTE 661 Instructions When the legal representative, customs broker, customs agency or customs attorney presents their entry permits or consolidated notices according to rule 3.1.33., they must fill out the DODA format, and present it in one copy before the automated selection module, in substitution of the formats: entry permit, form simplified version of the entry permit and/or consolidated notice format, list of documents, Entry Permits Part II. The format must be generated by the legal representative, customs broker, customs agency or customs attorney when they carry out the transmission referred to in rule 3.1.33., to the web service or when the transmission is carried out by the SAT Portal, the portal will generate it with the transmitted data. The format must contain the following specifications and the fields must be filled out as indicated below: Field Description INTEGRATION NO. Integration number provided by the system, by the transmission to which rule 3.1.33. refers. PATENT OR AUTHORIZATION The number of the patent or authorization corresponding to the legal representative, customs broker, customs agency or customs attorney who carries out the clearance of the merchandise must be declared. It consists of four alphanumeric characters. TWO-DIMENSIONAL BARCODE The printing of the DODA format must include a two-dimensional barcode according to the QR Code (Quick Response Code) format described in the ISO/IEC18004:2000 standard, containing the following data: Parameter Data Characters URL https://siat.sat.gob.mx/app/qr/faces/ pages/mobile/validadorqr.jsf? 65 D1 D1=16 5 D2 D2=1 4 D3 D3= Integration Number open At the end of the URL, including the URL parameters, D1, D2 and D3, it must contain a line break. The two-dimensional barcode must be printed in a square with dimensions of 100 px x 100 px or 3.75 x 3.75 cm that integrates the link of the integration number mentioned in this format. ISSUANCE DATE The date on which the document is issued must be declared in format yyyy-mm-dd HH:MM:SS. TOTAL NO. OF ENTRY PERMITS AND/OR CONSOLIDATED NOTICES OF THE OPERATION Total quantity of entry permits and/or consolidated notices that make up the foreign trade operation. CONTAINERS/RAILWAY EQUIPMENT/NO. ECONOMIC OF THE VEHICLE The letters and numbers of the containers, railway equipment or vehicle economic number must be declared. LOCKS The lock numbers with which the doors of access to the vehicle are secured will be noted, when applicable. CUSTOMS SECTION OF CLEARANCE The key and name of the customs/section according to appendix 1 of Annex 22, in which the customs clearance is processed, must be declared. This field is composed of three numeric characters.
662 OFFICIAL GAZETTE Friday, January 17, 2025 ORIGINAL CHAIN The original chain must start and end with double pipe character (||), and be formed as follows: FIELD DEFINITION Customs section Key of the customs/section in which the customs clearance is processed, it must be declared to 3 digits. Patent or authorization The number of the patent or authorization corresponding to the legal representative, customs broker, customs agency or customs attorney who carries out the clearance of the merchandise must be declared. It consists of four alphanumeric characters. Total entry permits and/or consolidated notices Total number of entry permits that make up the document. Entry permit numbers and/or consolidated notices (value acknowledgment) Numbers of all and each of the entry permits that make up the document, separated by commas. Integration Number Integration number provided by the system. License Plate License plate number declared to cross the customs office. Box or Container(s) Box or container numbers separated by comma. Timestamp Timestamp of the generation of the document in format: yyyy-mm-dd hh:mm:ss The fields must be separated by the pipe character (|). TAX SLIP OF CFDI WITH COMPLEMENT LETTER OF CARRIAGE Tax slip of the CFDI with Complement Letter of Carriage, to which rules 2.7.7.1.1., 2.7.7.1.2., 2.7.7.2.6. or 2.7.7.2.7. refer, of the RMF as applicable, except for the subjects referred to in rule 2.7.7.1.5. of the same resolution. SIGNATURE OF THE LEGAL REPRESENTATIVE, AGENT OR ATTORNEY CERTIFICATE SERIAL NUMBER Certificate serial number of the e.firma of the legal representative, customs broker, customs agency or customs attorney. DIGITAL SEAL Digital seal of the legal representative, customs broker, customs agency or customs attorney that allows accrediting the authorship of the information transmitted for the DODA. SAT SEAL CERTIFICATE SERIAL NUMBER Certificate serial number of the e.firma of SAT DIGITAL SEAL Digital seal of SAT that guarantees that the information transmitted was received in the SEA. The font sizes will be as indicated below: INFORMATION FONT FORMAT Headers Arial 8 Bold or another equivalent size font. Preferably, the spaces where headers appear should be printed with 15% shading. Field Name Arial 8 Bold or another equivalent size font. Declared Information Arial 9 or another equivalent size font. Original Chain Arial 7 or another equivalent size font.
Friday, January 17, 2025 OFFICIAL GAZETTE 663 M1.8. Electronic Credit Letter Date of Issue Serial Number Dollar Value Day Month Year KEY. Customs section clearance Name of the customs section clearance In accordance with article 119 of the Law, this credit letter is issued regarding the merchandise that is indicated below: SEC. Tariff fraction KEY. UMT Quantity of UMT That will be cleared to the fiscal deposit regime by the customs broker, customs agency or customs attorney: NUM. Patent or authorization R.F.C. of the customs broker, customs agency or customs attorney CURP of the customs broker or customs attorney Name: And sent with destination to the general warehouse of deposit: KEY. Customs office jurisdiction Name of the jurisdictional customs office KEY. of unit authorized Denomination or legal name: Address of the authorized unit (warehouse): Importer/Exporter: R.F.C. CURP Name, denomination or legal name: Fiscal address: Electronic validation acknowledgment
664 OFFICIAL GAZETTE Friday, January 17, 2025 Instructions Field No. Content Folio. Consecutive folio of the credit letter, which is formed as follows:
Friday, January 17, 2025 OFFICIAL GAZETTE 665 CURP of the customs broker, customs attorney. CURP of the customs broker or customs attorney who carries out the procedure. Name. Full name of the customs broker, customs agency or customs attorney who carries out the procedure. General warehouse CVE. customs of jurisdiction. Key of the customs according to appendix 1 of Annex 22, in whose territorial jurisdiction the authorized unit (warehouse) of the general warehouse that issues the credit letter is located. Name of the customs of jurisdiction. Name of the customs according to appendix 1 of Annex 22, in whose territorial jurisdiction the authorized unit (warehouse) of the general warehouse that issues the credit letter is located. CVE. of authorized unit. Key assigned by the SAT to the general warehouses to operate the fiscal deposit regime. Trade name or corporate name. Trade name or corporate name of the general warehouse. Address of the authorized unit (warehouse). Address of the warehouse or premises where the goods will remain in fiscal deposit. Importer/Exporter Name, trade name or corporate name. Name, trade name or corporate name of the importer/exporter as it has been declared for RFC purposes. RFC. Key in the RFC of the importer/exporter, who carries out the foreign trade operation. In the case of foreigners, the key EXTR920901TS4 will be noted. CURP. CURP of the importer/exporter who carries out the procedure. The declaration of the CURP is optional, if the importer/exporter is an individual and has this information. Fiscal address. Fiscal address of the importer/exporter as it has been declared for RFC purposes. The address of the warehouse where the goods will remain in fiscal deposit will be noted, when the individuals or legal entities that promote this regime are residents abroad. Electronic acknowledgment of validation. Composed of eight characters with which it is proven that the customs authority has electronically received the information transmitted to process the credit letter, this acknowledgment must be printed on the authorized credit letter. Notes: The paper dimensions on which the format will be printed will be 28 cm long by 21.5 cm wide (letter size). When in a specific field the defined space is insufficient, it may be expanded by adding as many lines as required, printing the format in the number of sheets that are necessary. When there is more than one tariff fraction that covers the credit letter, it must be declared one per sequence. Name of the organizer:
666 OFFICIAL GAZETTE Friday, January 17, 2025 M1.9. Credit letter for international exhibitions (Article 121, fraction III of the Law) Folio number: Date of issue: Authorization number: Day Month Year Customs declaration number: Key: Name of the departure customs: In accordance with article 119 of the law, this credit letter is issued regarding the merchandise indicated below: Number of packages Description of the merchandise Value in national currency Which will be cleared into the fiscal deposit regime by the agent or customs attorney: Patent number or authorization Name of the customs broker, customs agency or customs attorney And sent with destination to the premises designated for the international exhibition: Name, trade name or corporate name: Authorized address: Name of the event: Period: Importer: Name, trade name or corporate name: Fiscal address: R.F.C.
Name and signature of the legal representative or head of the premises designated for the international exhibition. Note: If this document is not used within twenty days following its issue, it must be returned to the company that issued it.
Friday, January 17, 2025 OFFICIAL GAZETTE 667 Instructions Field No. Content Folio number. Consecutive folio number of the credit letter, which must be assigned by the event organizer. Note: The use of the credit letter will be exclusively for one customs declaration. Date of issue. Date on which the credit letter is issued in DD/MM/YYYY format. Authorization number. The number of the authorization letter must be noted, according to the rule 4.5.29. Customs declaration number. The progressive number assigned must be noted. CVE. Customs/customs section of departure. Key of the customs/customs section in which the clearance of the merchandise destined for fiscal deposit will be carried out, according to the appendix 1 of Annex 22. Name of the customs/customs section of departure. Name of the customs section in which the clearance of the merchandise destined for fiscal deposit will be carried out, according to the appendix 1 of Annex 22. Goods Number of packages. The number of packages that make up the shipment must be noted. Description of the merchandise. Commercial description of the merchandise. Value in N.C. The equivalent in national currency of the customs value recorded in the customs declaration at the time of issuing the credit letter. Customs broker, customs agency or customs attorney Patent number or authorization. 4 Digits, of the number of the patent or authorization granted by the ANAM to the customs broker, customs agency or customs attorney who will promote the entry of the merchandise into the premises designated for the international exhibition. Name. Full name of the customs broker, customs agency or customs attorney who carries out the procedure. Premises designated for the international exhibition Name, trade name or corporate name. Trade name or corporate name of the local organizer where the event will be held. Authorized address. Full address of the premises authorized for the international exhibition. Name of the event. Name by which the international exhibition was promoted. Period. Dates on which the merchandise will be exhibited. Note: this period must not exceed one month. Importer Name, trade name or corporate name. Name, trade name or corporate name of the importer as it has been declared for RFC purposes. Fiscal address. Address of the importer as it has been declared for RFC purposes. RFC Key in the RFC of the importer who carried out the foreign trade operation. Name and Signature. Corresponding to the head of the premises designated for the international exhibition.
668 OFFICIAL GAZETTE Friday, January 17, 2025 M1.10. Report of exports of submanufacturing or submaquila operations Folio No. Place of Issue: Date of Issue: Day Month Year
IMMEX Program Number: ____________________________________________________________ Address:
Street: ____________________________________ No. and/or ext. letter: ________ No. and/or int. letter: _______ Neighborhood: ____________________________________ C.P. ___________ Federal Entity: __________ Telephone: __________________________________ Fax: _______________________________________ Mark with an X if the proportion corresponds to: First semester Second semester 2. Data of the company carrying out the submanufacturing or submaquila operation: Trade Name or Corporate Name: ____________________________________________________________ RFC:
Address:
Street: ___________________________________ No. and/or ext. letter: ___________ No. and/or int. letter: ______ Neighborhood: ___________________________________ C.P. ________ Federal Entity: ______________ Telephone: _____________________________________ Fax: ____________________________________ 3. Proportion of export of merchandise Description of transferred merchandise: Tariff fraction, if applicable, NICO: Proportion: Description of the process: I swear under oath that the information contained in this document is true and exact. When the data contained herein are modified, I obligate myself to communicate said situation. The falsity or inaccuracy of the information contained herein, will be sanctioned in accordance with the applicable tax provisions.
Friday, January 17, 2025 OFFICIAL GAZETTE 669 4. Data of the Legal Representative Paternal surname: Maternal surname: First name(s): Key in the RFC: ____________________ Signature of the Legal Representative CURP: Instructions I. This report will be filled out by machine or with block letters, with a black or blue ink ballpoint pen and the figures must not exceed the limits of the boxes. II. It must be presented in original and a copy, the original will be delivered to the company carrying out the submanufacturing or submaquila operations and the copy will be kept by the company with IMMEX Program that issues the report. III. Folio number: The company with IMMEX Program will note the consecutive folio number that corresponds. IV. Place of issue: Place where this report is generated (State, Capital, City or Municipality). V. Date of issue: The date of filling out the report must be noted, using 2 Arabic numerals for the day, 2 for the month and 4 for the year, as follows: (March 31, 2007 example: 31 03 2007). I. Data of the company with IMMEX Program that issues the report. a) Trade Name or Corporate Name: Note the corporate name of the company with IMMEX Program. b) Key in the RFC: The key will be noted. c) IMMEX Program Number: The number assigned by the SE to the company with IMMEX Program. d) Address: Note the data relating to the fiscal address; street name, number and/or ext. letter, number and/or int. letter, neighborhood name, postal code, Federal Entity, telephone number and fax number. e) Mark with an X, if the proportion corresponds to the first or second semester. II. Data of the company carrying out the submanufacturing or submaquila operation. a) Trade Name or Corporate Name: Note the corporate name of the company. b) Key in the RFC: The key will be noted. c) Address: Note the data relating to the fiscal address; street name, number and/or ext. letter, number and/or int. letter, neighborhood name, postal code, Federal Entity, telephone number and fax number. III. Proportion of export of merchandise. a) Description of transferred merchandise: The detailed description of the merchandise transferred by the company with IMMEX Program to the company carrying out the submanufacturing or submaquila operation will be declared. b) Tariff fraction, if applicable, NICO of the transferred merchandise: Note the fraction tariff and NICO that corresponds to the merchandise that is transferred. c) Description of the process: The description of the process carried out by the company of submanufacturing or submaquila will be declared. d) Export proportion: Indicate the proportion determined according to rule 5.2.8. IV. Data of the Legal Representative. a) Note the paternal surname, maternal surname and first name(s) of the legal representative. b) Key in the RFC: The key in the RFC with thirteen positions will be noted. c) CURP: The CURP will be noted, when available.
670 OFFICIAL GAZETTE Friday, January 17, 2025 M1.11. List of documents. Barcode General Data Departure Customs Number of Patent or Authorization Name of the customs broker or customs agency, customs attorney or accredited legal representative. Date of Issue List of customs declarations or consolidated notices Consecutive Customs Declaration Number Consolidated Notice Number Number of containers 1. 2. 3. 4. Instruction for filling out the List of documents format The customs broker or customs agency, customs attorney or accredited legal representative, is who has the obligation to fill out this format, when it comes to operations carried out with a customs declaration and/or consolidated notice, or cargo consolidation according to rule 3.1.24., or when it comes to operations carried out with Part II customs declarations referred to in rule 3.1.21., fraction III, subsection a). The format must be presented before the automated selection module as the first sheet of all documents covered. The following fields will be filled out, as indicated below:
Friday, January 17, 2025 OFFICIAL GAZETTE 671 6 Container number.- This field must be filled out, in the case of operations carried out with Part II customs declaration or consolidated customs declaration, indicating the container number, when the merchandise is transported in double articulated tractors (full). 11 Alphanumeric 7 Container number.- This field must be filled out, in the case of operations carried out with Part II customs declaration or consolidated customs declaration, indicating the container number, when the merchandise is transported in double articulated tractors (full). 11 Alphanumeric After each field, the CARRIAGE RETURN and LINE FEED control characters must be presented. 2. General Data.
More like this from SHCP
SHCP published 15 documents in the last 30 days. We email you each new one the day it's published.